WildFire API Malware Hashes

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L2 Linker

WildFire API Malware Hashes

I'm trying to get the file hash values for all submissions WildFire deems as malware.  Is this possible?  From what I've read you have to specify the hash value in the API call but I'd just like a list of all values.


Accepted Solutions
Highlighted
L4 Transporter

As @pulukas said, you can't do this with the WildFire API, but there are a couple other solutions:

 

1. The sha256 hashes are available on the Firewalls/Panorama.  They can output via syslog or webhook as they happen, or you can query them via the PAN-OS API.

https://www.paloaltonetworks.com/documentation/81/pan-os/xml-api/pan-os-xml-api-request-types/retrie...

 

2. AutoFocus subscribers can get a list of hashes via the AutoFocus API.  Here's an example request for hashes of all 'private' malware samples, which means all samples submitted by your organization to WildFire:

https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-s...

 

And an example result showing the sha256, md5, and sha1 hashes of one of the samples returned:

https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-s...

View solution in original post


All Replies
Highlighted
L7 Applicator

I don't think you can.  The idea of the API is to query for an Ad Hoc verdict not to pull the data for a separate or offline solution.

 

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
Highlighted
L4 Transporter

As @pulukas said, you can't do this with the WildFire API, but there are a couple other solutions:

 

1. The sha256 hashes are available on the Firewalls/Panorama.  They can output via syslog or webhook as they happen, or you can query them via the PAN-OS API.

https://www.paloaltonetworks.com/documentation/81/pan-os/xml-api/pan-os-xml-api-request-types/retrie...

 

2. AutoFocus subscribers can get a list of hashes via the AutoFocus API.  Here's an example request for hashes of all 'private' malware samples, which means all samples submitted by your organization to WildFire:

https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-s...

 

And an example result showing the sha256, md5, and sha1 hashes of one of the samples returned:

https://www.paloaltonetworks.com/documentation/autofocus/autofocus/autofocus_api/perform-autofocus-s...

View solution in original post

Highlighted
L2 Linker

Thanks for the options.  I forgot about API and will go that route as we're still on 7.1 and not yet an AutoFocus subscriber.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!