mlget icon indicating copy to clipboard operation
mlget copied to clipboard

hybrid-analysis failing despite dedicaed client working with the same API key

Open psifertex opened this issue 1 year ago • 4 comments

$ mlget fc17c021f18ec73d1544ad46dde6a1f1949f126bf3e75f97e241f982e2b07c86
Hashes Passed Via the Command Line:
  - fc17c021f18ec73d1544ad46dde6a1f1949f126bf3e75f97e241f982e2b07c86


Look up fc17c021f18ec73d1544ad46dde6a1f1949f126bf3e75f97e241f982e2b07c86 (sha256) - (1 of 1)
Querying all services

<SNIP>

  [*] HybridAnalysis: https://www.hybrid-analysis.com/api/v2
    [!] Not authorized.  Check the URL and APIKey in the config.
Could also be that the sample is not allowed to be downloaded.

<SNIP>

Hashes not found!
    0: fc17c021f18ec73d1544ad46dde6a1f1949f126bf3e75f97e241f982e2b07c86
    

Compared to:

$ python3 vxapi.py search_hash fc17c021f18ec73d1544ad46dde6a1f1949f126bf3e75f97e241f982e2b07c86
[]
$ python3 vxapi.py feed_get_latest|head
{
    "count": 248,
    "data": [
        {
            "analysis_start_time": "2024-07-20 06:53:40",
            "domains": [
                "apple.hkmyzs.com",
                "appleid.cdn-apple.com",
                "www.apple.com"
            ],

Same API key for both.

psifertex avatar Jul 20 '24 07:07 psifertex

Just saw this. Thanks for the report. I'm digging into it.

xorhex avatar Jul 22 '24 21:07 xorhex

Not seeing that sample in the UI. Does it render in the UI for you?

Screenshot from 2024-07-22 18-03-43

If it does, is the download functionality disabled for that sample? Sometimes you can view the report but they will have the download feature disabled (even when you are logged in).

xorhex avatar Jul 22 '24 22:07 xorhex

Sorry, I didn't meant to imply the file existed. I was pointing out that the error was incorrect. The API key is fine, there should just be no results, not an error about an invalid API key.

psifertex avatar Jul 25 '24 02:07 psifertex

Planning on updating the UI a bit. I'll make sure the error messages reflect better what is going on. Thanks

Leaving this open until the new UI is done.

xorhex avatar Aug 01 '24 13:08 xorhex

Fixed, will be available in the next release (which should be soonish depending on when Hatching gets back to me on another bug).

Added an additional check versus refactoring the UI (don't have time for that right this second).

xorhex avatar May 19 '25 01:05 xorhex