Home

Awesome

EKTotal

EKTotal is an integrated analysis tool that can automatically analyze the traffic of Drive-by Download attacks. The proposed software package can identify four types of Exploit Kits such as RIG and Magnitude, and more than ten types of attack campaigns such as Seamless and Fobos. EKTotal can also extract exploit codes and malware. The proposed heuristic analysis engine is based on Exploit Kit tracking research conducted since 2017, and is known as team "nao_sec". EKTotal provides a user-friendly web interface and powerful automated analysis functions. Thus, EKTotal can assist SOC operators and CSIRT members and researchers.

Features

Requirements

Installation

Docker

  1. Git clone this repository
  2. Git clone hidd3ncod3s/pcap2saz and build it
  3. Put FiddlerCore.dll, Ionic.Zip.dll and pcap2saz.exe under ektotal/bin
  4. If you want to submit malwares to VirusTotal, set the API key to post_vt.php
  5. Run docker-compose up -d

Build

  1. Git clone this repository
  2. Git clone hidd3ncod3s/pcap2saz and build it
  3. Put FiddlerCore.dll, Ionic.Zip.dll and pcap2saz.exe under ektotal/bin
  4. If you want to submit malwares to VirusTotal, set the API key to post_vt.php
  5. Configure & run Web Server
    document_root is /frontend/dist and document_root of the URL containing /api is /
    For example, when using nginx + php-fpm
server {
  listen 80;
  server_name _;
  client_max_body_size 30M;

  location / {
      root   /path/to/directory/frontend/dist;
      index  index.html;
      try_files $uri $uri/ /index.html;
  }

  location /api {
      root   /path/to/directory;
      index  index.html index.htm index.php;
      try_files $uri /index.php?$query_string;
  }

  location ~ \.php$ {
      root           /path/to/directory;
      fastcgi_pass   127.0.0.1:9000;
      fastcgi_index  index.php;
      fastcgi_param  SCRIPT_FILENAME  $document_root$fastcgi_script_name;
      include        fastcgi_params;
  }
}

Usage

Just submit pcap or saz file

Sample Traffic Data




License

EKTotal is open-sourced software licensed under the MIT License

Change Log

TODO

Thanks