show analysis intel url/sha256/md5

Prev Next

Shows the signature , source and other details of an SHA-256 hash file, URL, or MD5 checksum.

Syntax

show analysis intel url <URL>

show analysis intel sha256 <sha256>

show analysis intel md5 <md5>

Parameters

<URL>

URL address

<sha256>

The alphanumeric value of an SHA-256 hash file

<md5>

The alphanumeric value of an MD5 checksum

Output fields

The following table describes the output fields for the <show analysis intel> command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Feed Type

The type of intel that is indexed (SHA-256/MD5/URL)

Intel Class

Specifies if the URL or hash file is added to the Allowed List or Block List

Source

The source where the hash was indexed from (eg: Custom, SC, GC, FAUDE, and LOCAL)

Feed Name

The name of third party feed file or custom feed

Signature

The malware signature of the indexed hash

Example

The following example displays the details for the MD5 intel, "71189fb8eacea4299ced7b36f9d72b06".

hostname (config) # show analysis intel md5 71189fb8eacea4299ced7b36f9d72b06
Feed Type | Intel class | Source | Feed name            | Signature
-------------------------------------------------------------------
md5       | Allowlist   | Custom | custom-md5-allowlist | custom-md5-allowlist
md5       | Allowlist   | SC     | DTI                  | DTI-md5-AllowList

User role

Administrator

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 10.0.2

  • File Protect: Release 10.0.2

  • Malware Analysis: Release 10.0.2

  • Network Security: Release 10.0.2