mirror of https://github.com/MISP/misp-modules
add: Parsing communicating samples returned by domain reports
parent
c9c2027a57
commit
675e0815ff
|
@ -76,7 +76,7 @@ class DomainQuery(VirusTotalParser):
|
|||
def parse_report(self, query_result):
|
||||
hash_type = 'sha256'
|
||||
whois = 'whois'
|
||||
for feature_type in ('referrer', 'downloaded'):
|
||||
for feature_type in ('referrer', 'downloaded', 'communicating'):
|
||||
for feature in ('undetected_{}_samples', 'detected_{}_samples'):
|
||||
for sample in query_result[feature.format(feature_type)]:
|
||||
self.misp_event.add_attribute(hash_type, sample[hash_type])
|
||||
|
|
Loading…
Reference in New Issue