All Apps and Add-ons

generate md5 hashes in splunk stream

weicheng98
Path Finder

Hi I have a malware pcap file that I have for analysis that i have tcpreplayed and the stream data is captured using splunk stream. Now the problem is that I have a list of MD5 hashes as a lookup table and I would like to compare the md5 hashes with the lookup table and the .txt files or .exe files found in the pcap stream. I would like to generate md5 hashes of the .txt and .exe and compare with the lookup table.

I have also researched that I can extract a field as an MD5 hash, e.g. i extract the field src_content as an md5 hash. But when I tried that, it seems like the md5 hash does not match against the .txt file e.g. hi.txt that I have extracted from wireshark. I used md5sum in ubuntu linux to generate the md5 hash for hi.txt

What am I doing wrong here ?

0 Karma

weicheng98
Path Finder

Hi, let me simply the question.

I want to find out how do I generate md5 hashes of payload data in splunk stream.

E.g. the payload data is a pcap file that I have uploaded. In the pcap file, there are malware activities and the malware uploaded some .exe and .txt.

The question is how do I extract these files found in the splunk stream and generate md5 hashes out of it.

I have a lookup table that contains malicious md5 hashes of malware that I want to compare.

Once that is done, how can I compare the hashes with the lookup table ? Can you give an example of the search for this use case ?

0 Karma

weicheng98
Path Finder

I have found out that I can do this by using the content extraction in splunk stream. But the hashes does not match because in splunk stream, the dest and src content payload data contains the content headers, which I do not want. I only want to hash the file inside. How do i do it ?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...