Virus Total | APIv3 | Hash enricher#
The Hash enricher provides additional intelligence connected to Hash observables.
Observable types#
This Enricher enriches hash-md5
, hash-sha1
, and hash-sha256
observables.
Endpoints & Outputs#
Endpoint |
Reponse |
Output type |
---|---|---|
Compressed parents |
File hashes of compressed packages that contain the enriched file hash. |
|
Execution parents |
All files that are known to execute the file represented by the enriched file hash. |
|
In The Wild (ITW) domains |
Domains the enriched file is known to have downloaded from. |
|
In The Wild (ITW) IPs |
IPs the enriched file is known to have downloaded from. |
|
In The Wild (ITW) URLs |
Uri’s the enriched file is known to have downloaded from. |
|
Contacted IPs |
IPs the enriched file is known to have contacted. |
|
Contacted URLs |
Uri’s the enriched file is known to have contacted. |
|
Similar files |
Files similar to the enriched file. |
|
Embedded domains |
Domains embedded in the file hash. |
|
Embedded IPs |
IPs embedded in the file hash. |
|
Embedded URLs |
Uri’s embedded in the file hash. |
|
Bundled files |
Files that are known to be bundled inside the enriched file. |
|
Dropped files |
Files that are known to be written to disk (dropped) by the enriched file when it executes. |
|
Email attachments |
Files attached to email files that are matches for the enriched file. |
|
Email parents |
Email files that contain the enriched file as an attachment. |
|
Configure#
Make sure you’ve configured your VT APIv3 key.
Required fields
Fields on the Enricher pane marked with an asterisk (“*”) are required to fill in, but may come pre-filled.
Filter the list by searching for
VirusTotal APIv3 Hash enricher
.For Source reliability, select the source reliability rating that will be applied to the Entities and Observables this enricher will produce if you haven’t configured it yet.
Under API key, enter your VirusTotal API key if you haven’t configured it yet.
Under Include Endpoints, select the Endpoints you’d like the enricher to hit.
(Optional) Change the Description.
(Optional) Change the Cache validity, Rate limit, or Monthly execution cap.
(Optional) Select Create Parent Report or SSL verification and supply a Path to SSL certificate file.
Check the Enabled box to enable the enricher when you’re done configuring it.
Select Save.