From ccdfd743bcb9c45d3c274779b04934c9f6f0fa48 Mon Sep 17 00:00:00 2001 From: marco Date: Fri, 7 Oct 2022 13:15:28 +0200 Subject: [PATCH 1/4] Add link to go to VT --- quark/webreport/analysis_report_layout.html | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/quark/webreport/analysis_report_layout.html b/quark/webreport/analysis_report_layout.html index b75cb8680..427260c5c 100644 --- a/quark/webreport/analysis_report_layout.html +++ b/quark/webreport/analysis_report_layout.html @@ -406,7 +406,9 @@

Sample Information

File name
$filename$
MD5
-
$md5$
+
+ $md5$ +
File size
$filesize$ Mb
Labels
From e28a58ac20f07e3ba242715c1ecf44ff9f7df840 Mon Sep 17 00:00:00 2001 From: marco Date: Wed, 12 Oct 2022 16:44:15 +0200 Subject: [PATCH 2/4] add icon to copy the text --- quark/webreport/analysis_report_layout.html | 66 +++++++++++++++++++-- 1 file changed, 62 insertions(+), 4 deletions(-) diff --git a/quark/webreport/analysis_report_layout.html b/quark/webreport/analysis_report_layout.html index 427260c5c..968488d5f 100644 --- a/quark/webreport/analysis_report_layout.html +++ b/quark/webreport/analysis_report_layout.html @@ -3,6 +3,7 @@ Quark Report + @@ -341,6 +342,34 @@ background-color: #939393; color: white; } + + .tooltiptext { + visibility: hidden; + width: 140px; + background-color: #555; + color: #fff; + text-align: center; + border-radius: 6px; + padding: 5px; + position: absolute; + z-index: 1; + bottom: 150%; + left: 50%; + margin-left: -75px; + opacity: 1; + transition: opacity 0.3s; + } + + .tooltiptext::after { + content: ""; + position: absolute; + top: 100%; + left: 50%; + margin-left: -5px; + border-width: 5px; + border-style: solid; + border-color: #555 transparent transparent transparent; + } @@ -405,9 +434,20 @@

Sample Information

File name
$filename$
-
MD5
-
- $md5$ +
+ MD5 +
+
+ + content_copy + + Copy to clipboard +
+
+ + $md5$ + + Go to VirusTotal report
File size
$filesize$ Mb
@@ -478,7 +518,7 @@

The labels with 100% confidence crimes

$report_data$ + \ No newline at end of file From 64864106cd85e60ed52d2ea58eb7127afb512ba0 Mon Sep 17 00:00:00 2001 From: marco Date: Wed, 12 Oct 2022 16:47:14 +0200 Subject: [PATCH 3/4] remove title attr from a tag --- quark/webreport/analysis_report_layout.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/quark/webreport/analysis_report_layout.html b/quark/webreport/analysis_report_layout.html index 968488d5f..8d52edacb 100644 --- a/quark/webreport/analysis_report_layout.html +++ b/quark/webreport/analysis_report_layout.html @@ -444,7 +444,7 @@

Sample Information

Copy to clipboard
- + $md5$ Go to VirusTotal report From 93392f8b2fc075621de7bb255e490e3ab425b107 Mon Sep 17 00:00:00 2001 From: marco Date: Wed, 12 Oct 2022 19:02:43 +0200 Subject: [PATCH 4/4] add dialog to show detail of a certain rule --- quark/webreport/analysis_report_layout.html | 93 +++++++++++++++++++++ quark/webreport/generate.py | 3 +- 2 files changed, 95 insertions(+), 1 deletion(-) diff --git a/quark/webreport/analysis_report_layout.html b/quark/webreport/analysis_report_layout.html index 8d52edacb..a31affe33 100644 --- a/quark/webreport/analysis_report_layout.html +++ b/quark/webreport/analysis_report_layout.html @@ -370,6 +370,44 @@ border-style: solid; border-color: #555 transparent transparent transparent; } + /* The Modal (background) */ + .modal { + display: none; /* Hidden by default */ + position: fixed; /* Stay in place */ + z-index: 1; /* Sit on top */ + padding-top: 100px; /* Location of the box */ + left: 0; + top: 0; + width: 100%; /* Full width */ + height: 100%; /* Full height */ + overflow: auto; /* Enable scroll if needed */ + background-color: rgb(0,0,0); /* Fallback color */ + background-color: rgba(0,0,0,0.4); /* Black w/ opacity */ + } + + /* Modal Content */ + .modal-content { + background-color: #fefefe; + margin: auto; + padding: 20px; + border: 1px solid #888; + width: 80%; + } + + /* The Close Button */ + .close { + color: #aaaaaa; + float: right; + font-size: 28px; + font-weight: bold; + } + + .close:hover, + .close:focus { + color: #000; + text-decoration: none; + cursor: pointer; + } @@ -513,6 +551,16 @@

The labels with 100% confidence crimes

+ + + $report_data$ @@ -694,6 +742,51 @@

The labels with 100% confidence crimes

tooltip.innerHTML = message; tooltip.style.visibility='visible'; } + + // Get the modal + var modal = document.getElementById("myModal"); + + // Get the element that closes the modal + var span = document.getElementsByClassName("close")[0]; + + // When the user clicks the button, open the modal + function showModal(text) { + var divTag = document.getElementById("titleModal"); + var jsonCrime = JSON.parse(text); + var confidence = jsonCrime["confidence"] + var classCrime = "" + if(confidence === "20%"){ + classCrime = "alert alert-success" + } else if (confidence === "40%") { + classCrime = "alert alert-info" + } else if (confidence === "60%") { + classCrime = "alert alert-primary" + } else if (confidence === "80%") { + classCrime = "alert alert-alert" + } else if (confidence === "100%") { + classCrime = "alert alert-danger" + } else { + classCrime = "alert alert-dark" + } + var titleRule = jsonCrime["crime"] + divTag.className = classCrime + divTag.innerText = titleRule + var ruleFormatted = JSON.stringify(jsonCrime, null, '\t'); + modal.style.display = "block"; + modal.getElementsByTagName('pre')[0].innerText = ruleFormatted + } + + // When the user clicks on (x), close the modal + function closeModal() { + modal.style.display = "none"; + } + + // When the user clicks anywhere outside of the modal, close it + window.onclick = function(event) { + if (event.target == modal) { + modal.style.display = "none"; + } + } \ No newline at end of file diff --git a/quark/webreport/generate.py b/quark/webreport/generate.py index 428477afe..27a616126 100644 --- a/quark/webreport/generate.py +++ b/quark/webreport/generate.py @@ -195,10 +195,11 @@ def insert_report_html(self, data): description = crime["crime"] confidence = crime["confidence"] rule_number = crime["rule"].split('.')[0] + crime_text = str(crime).replace("'", '\\"') contentHTML += f"""

{rule_number}

-

{description}

+

{description}

{confidence}