Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VirusTotal limits when different Wazuh servers generate requests to the service from the same IP address #16601

Open
d4rkrex opened this issue Apr 3, 2023 · 1 comment
Labels
type/bug Something isn't working

Comments

@d4rkrex
Copy link
Member

d4rkrex commented Apr 3, 2023

Problem

When various Wazuh servers generate requests to the VirusTotal services from the same IP addresses and with different API keys, the services reach the limit with a single request. It is presumed that the IP addresses were banned.

VirusTotal support answer

Hello,
Those IPs have not been banned, but our anti-abuse systems detected anomalous activity, thousands of requests checking files report and not uploading any hash.
Do you have more information about the integration? Can you share screenshots?
Which VirusTotal information is provided to the end customers?
Best regards,

Information provided to VirusTotal

@d4rkrex d4rkrex added the type/bug Something isn't working label Apr 3, 2023
@d4rkrex
Copy link
Member Author

d4rkrex commented Apr 10, 2023

Investigation:

Based on VirusTotal customer support response about MD5 hashes missing, we perform the following tasks:

  • Inventory of environments with VirusTotal integration.
  • Review de integration.log to find out any errors about MD5.

We didn't find md5-based errors on /var/ossec/logs/integrations.log or /var/ossec/logs/ossec.log but we found this and could be related to this problem.

2023/04/10 02:19:53 wazuh-integratord: ERROR: While running virustotal -> integrations. Output: UnicodeDecodeError: 'utf-8' codec can't decode byte 0xf3 in position 1812: invalid continuation byte

The byte 0xf3 is in latin-1 encoding the ´ character

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type/bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant