show object-analysis id from

Prev Next

Displays information about the malware object analysis for a specified range of malware submission jobs. You can display up to 100 jobs by default. The malware object analysis jobs are listed in descending order by malware ID.

Syntax

show object-analysis id from <object_ID> to <object_ID>

Parameters

object_ID

The malware object ID for a specific job.

Output fields

The following table describes the output fields for the show object-analysis id from command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Malware ID

Specific malware object analysis job number.

Submission ID

Specific malware submission job number.

Analysis Type

Type of malware analysis (sandbox or live) that is associated with the malware submission job number.

URL

Single URL of the malware sample.

Analysis Timeout

Number of seconds after which the malware analysis stops if the analysis is not complete.

Analysis Priority

Priority setting for the current analysis, if you add multiple analysis jobs at the same time to the MVX engine queue. The default priority is normal.

Force

Force the Network Security appliance to perform the submitted analysis even if it matches a previous submission for which forensic results have been generated.

Profile Name

Guest image profile that the MVX engine uses for the current malware analysis job.

Profile ID

Guest image profile ID number.

Application

Application used to test submitted content.

Md5Sum

Result of the MD5 checksum.

State

Whether the malware submission job has been completed, is in the queue waiting to be analyzed, or is currently running.

Submitted Time

Date and time when the malware analysis job was submitted.

Run Start Time

Start time of the analysis.

Run End Time

End time of the analysis.

IM

Whether the sample is malicious. The results can be Yes, No, or blank. If the entry is blank, the Network Security appliance cannot confirm a malicious attack. Further forensics might be required.

Number of Events

Number of events identified in the analysis.

Children Malware ID(s)

Specific child malware analysis job number that is associated with the parent malware submission.

Parent Malware ID

Specific parent malware analysis job number that is associated with the child malware submission.

Occurrence Time

Time that the event occurred.

Event Type

Type of event that is identified with the analysis.

Example

The following example displays information about malware object analysis jobs from number 1639 to 1643:

hostname # show object-analysis id from 1639 to 1643
Malware ID 1642
Submission ID 1638
     Analysis Type:         sandbox
     URL:                   fe953a86fd15840e2b4a548b9c4fb8bd.bin
     Analysis Timeout:      240
     Analysis Priority:     normal
     Force:                 false
     Profile Name:          win7x64-sp1
     Profile ID:            66
     Application:           Windows-Explorer
     Md5Sum:                fe953a86fd15840e2b4a548b9c4fb8bd
     State:                 done
     Status:                success
     Submitted Time:        2015-09-13 21:33:13 PDT
     Run Start Time:        2015-09-14 07:32:35 PDT
     Run End Time:          2015-09-14 07:43:14 PDT
     IM:                    YES
     Number of Events:      6
     Children Malware ID(s) -
     Parent Malware ID      -
Malware ID 1640
Submission ID 1635
     Analysis Type:         sandbox
     URL:                   fe944698b1fd86c126b660c152d22265.bin
     Analysis Timeout:      240
     Analysis Priority:     normal
     Force:                 false
     Profile Name:          win7x64-sp1
     Profile ID:            66
     Application:           Windows-Explorer
     Md5Sum:                fe944698b1fd86c126b660c152d22265
     State:                 done
     Status:                success
     Submitted Time:        2015-09-13 21:28:28 PDT
     Run Start Time:        2015-09-14 07:28:20 PDT
     Run End Time:          2015-09-14 07:40:43 PDT
     IM:                    YES
     Number of Events:      8
     Children Malware ID(s) -
     Parent Malware ID      -

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5. The command output was enhanced to display the statistics about a specific malware submission job in Release 7.7.