Skip to content

malice-plugins/avast

Repository files navigation

malice-avast

Circle CI License Docker Stars Docker Pulls Docker Image

Malice Avast AntiVirus

This repository contains a Dockerfile of avast for Docker's trusted build published to the public DockerHub.


Dependencies

Installation

  1. Install Docker.
  2. Download trusted build from public docker store: docker pull malice/avast

Usage

docker run --rm malice/avast EICAR

Or link your own malware folder:

$ docker run --rm -v /path/to/malware:/malware:ro malice/avast FILE

Usage: avast [OPTIONS] COMMAND [arg...]

Malice Avast AntiVirus Plugin

Version: v0.1.0, BuildTime: 20180903

Author:
  blacktop - <https://github.com/blacktop>

Options:
  --verbose, -V          verbose output
  --elasticsearch value  elasticsearch url for Malice to store results [$MALICE_ELASTICSEARCH_URL]
  --table, -t            output as Markdown table
  --callback, -c         POST results back to Malice webhook [$MALICE_ENDPOINT]
  --proxy, -x            proxy settings for Malice webhook endpoint [$MALICE_PROXY]
  --timeout value        malice plugin timeout (in seconds) (default: 120) [$MALICE_TIMEOUT]
  --help, -h             show help
  --version, -v          print the version

Commands:
  update  Update virus definitions
  web     Create a Avast scan web service
  help    Shows a list of commands or help for one command

Run 'avast COMMAND --help' for more information on a command.

Sample Output

{
  "avast": {
    "infected": true,
    "result": "EICAR Test-NOT virus!!!",
    "engine": "2.1.2",
    "database": "17012800",
    "updated": "20170129"
  }
}

Avast

Infected Result Engine Updated
true EICAR Test-NOT virus!!! 2.1.2 20170129

NOTE: ⚠️ License expires in 30 days - https://www.avast.com/linux-server-antivirus

Use your own license key

docker run --rm -v `pwd`/license.avastlic:/etc/avast/license.avastlic malice/avast EICAR

Documentation

Issues

Find a bug? Want more features? Find something missing in the documentation? Let me know! Please don't hesitate to file an issue.

TODO

  • add configurable re-try count (cuz this AV is weak sauce YO!)
  • add licence expiration detection

CHANGELOG

See CHANGELOG.md

Contributing

See all contributors on GitHub.

Please update the CHANGELOG.md and submit a Pull Request on GitHub.

License

MIT Copyright (c) 2016 blacktop