Viewing malware guard alert details from a submission job using the CLI

Prev Next

Use the show submission malicious command to view malware guard alert details delivered to the Email Security - Server appliance.

For details about this command, refer to the Trellix CLI Reference.

To view the details of a Malware Guard alert:
  1. Enable the CLI enable mode.

    hostname > enable
  2. View the Malware Guard name, signature and weight of a malware submission job.

    Below is an excerpt of the command.

    hostname (config) # show submission id 10127
    
    	Submission ID: 10127
    	   UUID                  : eb4ac021-8cb7-4cba-8585-c5bf38a57ab5
    	   Malware ID            : 10479
              md5sum                : 9df0f3dbd44624003f0a8a09fe316dd5
              File type             : zip
              Status                : success
              Result                : Malicious
    
                 Analysis Object ID      : 15603
                 Analysis Object Name    : perfEmail_5ea34a10-87dc-4cc2-adf6-  2388d280761b.m
                 Analysis File Type      : zip
                 md5sum                  : 9df0f3dbd44624003f0a8a09fe316dd5
                 Dynamic Analysis weight : 100
                 Static Analysis jobs    : 2
    
                   SA engine weight       : 100
                   SA job ID              : 10127
    
                      SA sub-engine name         : avs
                      SA sub-engine signature    : Malware.Binary.FEC2
                      SA sub-engine weight       : 100
    				
                Analysis Object ID      : 15604
                Analysis Object Name    : Court_Notice_June-04_Date_2014-VBEN-DOC-CK.exe
                Analysis File Type      : exe
                md5sum                  : 4c576bfbdce71cb312af3ca65225e50c|                   Static Analysis weight  : 97
                Dynamic Analysis weight : 700
                Dynamic Analysis jobs   : 2
                Static Analysis jobs    : 3
    
                    SA engine weight       : 97
                    SA job ID              : 19285
    
                      SA sub-engine name         : malware_guard
                      SA sub-engine signature    : fe_ml_heuristic
                      SA sub-engine weight       : 97
    
                    SA engine weight       : 100
                    SA job ID              : 10127
    
                      SA sub-engine name         : avs
                      SA sub-engine signature    : Malware.Binary.FEC2
                      SA sub-engine weight       : 100
    
                    Job ID                 : 8026
                    OS name                : winxp-sp3
                    Application name       : Windows Explorer
                    OS Changes weight      : 500
                    CNC Match weight       : 0
                    Assigned time          : 2018-11-21 14:17:06.181384
                    Complete time          : 2018-11-21 14:18:12.582275
                    Job runtime            : 00:01:06.400891
                    Signature              : Asprox Bot.MVX
    
                    Job ID                 : 8027
                    OS name                : win7x64-sp1
                    Application name       : Windows Explorer
                    OS Changes weight      : 700
                    CNC Match weight       : 100
                    Assigned time          : 2018-11-21 14:17:06.214783
                    Complete time          : 2018-11-21 14:21:10.970513
                    Job runtime            : 00:04:04.75573
                    Signature              : Trojan.Asprox