show malware mode <mode>

Prev Next

Displays the results about the live and sandbox malware analysis and submission jobs.

Syntax

show malware mode <mode> [limit <number>]

Parameters

mode

The mode used to perform malware analysis. The following mode is available:

live—Displays the results of the live malware analysis jobs.sandbox—Displays the results of the sandbox malware analysis jobs.

limit <number>

(Optional) Displays results for the specified number of malware analysis jobs. You can display up to 1000 entries.

Output fields

The following table describes the output fields for the show malware mode <mode> command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Malware ID

Specific malware analysis job number.

Submission ID

Specific malware submission job number.

Analysis Type

Type of malware analysis (sandbox or live) that is associated with the malware submission job number.

URL

Single URL of the malware sample.

Analysis Timeout

Number of seconds after which the malware analysis stops if the analysis is not complete.

Analysis Priority

Priority setting for the current analysis, if you add multiple analysis jobs at the same time to the MVX engine queue. The default priority is normal.

Force

Force the Malware Analysis appliance to perform the submitted analysis even if it matches a previous submission for which forensic results have been generated.

Profile Name

Guest image profile that the MVX engine uses for the current malware analysis job.

Profile ID

Guest image profile ID number.

Application

Application used to test submitted content.

Md5Sum

Result of the MD5 checksum.

State

Whether the malware submission job has been completed, is in the queue waiting to be analyzed, or is currently running.

Submitted Time

Date and time when the malware analysis job was submitted.

Download Start Time

Start time of the download.

Download End Time

End time of the download.

Run Start Time

Start time of the analysis.

Run End Time

End time of the analysis.

IM

Whether the sample is malicious. The results can be Yes, No, or blank. If the entry is blank, the Malware Analysis appliance cannot confirm a malicious attack. Further forensics might be required.

Number of Events

Number of events identified in the analysis.

Children Malware ID(s)

Specific child malware analysis job number that is associated with the parent malware submission.

Parent Malware ID

Specific parent malware analysis job number that is associated with the child malware submission.

Example

The following example displays the information for one sandbox malware analysis job:

hostname # show malware mode sandbox limit 1
Malware ID 800
Submission ID 800
  Analysis Type:         sandbox
  URL:                   http://172.16.146.53/AllObjects/pdf_7602255
  Analysis Timeout:      500
  Analysis Priority:     normal
  Application:           Multiple Adobe Reader X
  Force:                 true
  Profile Name:          win7x64-sp1
  Profile ID:            66
  Md5Sum:                69e9125cbee713b96c09db95188fd138
  State:                 done
  Status:                success
  Submitted Time:        2015-08-27 20:54:21 UTC
  Download Start Time:   2015-08-27 20:54:21 UTC
  Download End Time:     2015-08-27 20:54:22 UTC
  Run Start Time:        2015-08-27 23:06:02 UTC
  Run End Time:        2015-08-27 23:15:00 UTC
  IM:                  YES
  Number of Events:   (null)
  Children Malware ID(s) -
  Parent Malware ID      -

User role

Command mode

Enable

Supported appliances

This command is supported on the following appliance running the specified release or later:

  • Malware Analysis: Release 7.5. The limit option was added and the command output was enhanced to display the statistics about a specific malware submission job in Release 7.7.