Skip to main content

Hfinger - fingerprinting malware HTTP requests stored in pcap files

Project description

Hfinger - fingerprinting malware HTTP requests

Tool for fingerprinting malware HTTP requests. Based on Tshark and written in Python3. Working prototype stage :-)

It's main objective is to provide a representation of malware requests in a shorter form than printing whole request, but still human interpretable. This representation should be unique between malware families, what means that any fingerprint should be seen only for one particular family.

Project's website: https://github.com/CERT-Polska/hfinger.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

hfinger-0.2.0.tar.gz (19.0 kB view details)

Uploaded Source

Built Distribution

hfinger-0.2.0-py3-none-any.whl (28.8 kB view details)

Uploaded Python 3

File details

Details for the file hfinger-0.2.0.tar.gz.

File metadata

  • Download URL: hfinger-0.2.0.tar.gz
  • Upload date:
  • Size: 19.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.4.1 importlib_metadata/3.10.0 pkginfo/1.7.0 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.59.0 CPython/3.6.9

File hashes

Hashes for hfinger-0.2.0.tar.gz
Algorithm Hash digest
SHA256 2ec8636f44bdf82c16d07bc54fa66ee7f1365a6e0aebe7e9d7408e355ae2c246
MD5 aa4cd7cf4464abcac87758ab82706a12
BLAKE2b-256 f7f183e1382cf0e167e500f0a6e9e4535e3e65ab4446d834e8968711f12f9d85

See more details on using hashes here.

File details

Details for the file hfinger-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: hfinger-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 28.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.4.1 importlib_metadata/3.10.0 pkginfo/1.7.0 requests/2.25.1 requests-toolbelt/0.9.1 tqdm/4.59.0 CPython/3.6.9

File hashes

Hashes for hfinger-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c2dceb61aa1a8d125044298b732199e37711e766d3154eb320f97b5b1029f3b7
MD5 0c121cc64abf8f6f4648891650113ce0
BLAKE2b-256 a0d27d375c2fe01d7152568e88aad694986464fd0a4385cfef4288fc2a3d3243

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page