Displays information about a specific malware object analysis and malware submission job.
Syntax
show object-analysis id <object_ID>
Parameters
object_ID
The malware object ID for a specific job.
Output fields
The following table describes the output fields for the show object-analysis id command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Malware ID | Specific malware object analysis job number. |
Submission ID | Specific malware submission job number. |
Analysis Type | Type of malware analysis (sandbox or live) that is associated with the malware submission job number. |
URL | Single URL of the malware sample. |
Analysis Timeout | Number of seconds after which the malware analysis stops if the analysis is not complete. |
Analysis Priority | Priority setting for the current analysis, if you add multiple analysis jobs at the same time to the MVX engine queue. The default priority is normal. |
Force | Force the Network Security appliance to perform the submitted analysis even if it matches a previous submission for which forensic results have been generated. |
Profile Name | Guest image profile that the MVX engine uses for the current malware analysis job. |
Profile ID | Guest image profile ID number. |
Application | Application used to test submitted content. |
Md5Sum | Result of the MD5 checksum. |
State | Whether the malware submission job has been completed, is in the queue waiting to be analyzed, or is currently running. |
Submitted Time | Date and time when the malware analysis job was submitted. |
Run Start Time | Start time of the analysis. |
Run End Time | End time of the analysis. |
IM | Whether the sample is malicious. The results can be Yes, No, or blank. If the entry is blank, the Network Security appliance cannot confirm a malicious attack. Further forensics might be required. |
Number of Events | Number of events identified in the analysis. |
Children Malware ID(s) | Specific child malware analysis job number that is associated with the parent malware submission. |
Parent Malware ID | Specific parent malware analysis job number that is associated with the child malware submission. |
Occurrence Time | Time that the event occurred. |
Event Type | Type of event that is identified with the analysis. |
Analysis Type | Type of analysis that is associated with the event. |
Trace ID | Specific trace job number that is associated with a workorder. |
Source IP | IP address of the source. |
Destination IP | IP address of the destination. |
Source MAC | MAC address of the source. |
Destination MAC | MAC address of the destination. |
VLAN ID | Network VLAN job number that is associated with an event. |
Attacked Port | Port number that is associated with an attack. |
IP Protocol | Type of IP protocol that is used to transport the threat. |
PCAP URL | Packet capture (PCAP) link that is associated with an event. |
Example
The following example displays malware analysis information for job number 1749:
hostname # show object-analysis id 1749
Malware ID 1749
Submission ID 1749
Analysis Type: sandbox
URL: ff8f8776833cf214d1febb7f6bc8d9b8.bin
Analysis Timeout: 240
Analysis Priority: normal
Force: false
Profile Name: win7x64-sp1
Profile ID: 66
Application: Windows-Explorer
Md5Sum: ff8f8776833cf214d1febb7f6bc8d9b8
State: done
Status: success
Submitted Time: 2015-09-14 00:28:21 PDT
Run Start Time: 2015-09-14 10:27:03 PDT
Run End Time: 2015-09-14 10:35:39 PDT
IM: YES
Number of Events: 4
Children Malware ID(s) -
Parent Malware ID -
Event 9386:
Occurrence Time : 2015-09-14 10:35:39 PDT
Event Type : os-change-anomaly
Analysis Type : Binary Analysis
Trace ID : 1749
Malware ID : 1749
Source IP : 77.87.102.78
Destination IP : 100.87.80.81
Source MAC : 00:35:56:37:68:49
Destination MAC : 00:37:52:61:36:68
VLAN ID : 0
Attacked Port : unknown
IP Protocol : unknown
OS Change Analysis:
<analysis mode="malware" ftype="exe" version="1.1077" product="MPS"/>
<application app-name="Windows Explorer" />
<os name="windows" version="5.1.2600" sp="3"/>
<os_monitor version="14R2.1" build="315507" date="Feb 3 2015" time="17:32:46"/>
<end-of-report/>
EDP URL : https://mil.fireeye.com/edp.php?sname=Malware.Binary.exe
PCAP URL : https://172.16.146.41/event_stream/send_pcap_file?ev_id=9386
PCAP (text) : https://172.16.146.41/event_stream/send_pcap_ascii?ev_id=9386
Event 9385:
Occurrence Time : 2015-09-14 10:35:39 PDT
Event Type : os-change-anomaly
Analysis Type : Binary Analysis
Trace ID : 1749
Malware ID : 1749
Source IP : 77.87.102.78
Destination IP : 100.87.80.81
Source MAC : 00:35:56:37:68:49
Destination MAC : 00:37:52:61:36:68
VLAN ID : 0
Attacked Port : unknown
IP Protocol : unknown
OS Change Analysis:
<analysis mode="malware" ftype="exe" version="1.1077" product="MPS"/>
<application app-name="Windows Explorer" />
<os name="windows" version="6.1.7601" sp="1"/>
<os_monitor version="14R2.1" build="315507" date="Feb 3 2015" time="17:32:46"/>
<end-of-report/>
EDP URL : https://mil.fireeye.com/edp.php?sname=Malware.Binary.exe
PCAP URL : https://172.16.146.41/event_stream/send_pcap_file?ev_id=9385
PCAP (text) : https://172.16.146.41/event_stream/send_pcap_ascii?ev_id=9385
Event 9384:
Occurrence Time : 2015-09-14 10:35:39 PDT
Event Type : checksum-match
Analysis Type : Binary Analysis
Trace ID : 1749
Malware ID : 1749
Source IP : 77.87.102.78
Destination IP : 100.87.80.81
Source MAC : 00:35:56:37:68:49
Destination MAC : 00:37:52:61:36:68
VLAN ID : 0
Attacked Port : 80
IP Protocol : tcp
Original Malware ID :
Name : Dropper.DTI.DroppedFiles
Match Type : malware-intrinsic-analysis
EDP URL : https://mil.fireeye.com/edp.php?sname=Dropper.DTI.DroppedFiles
Event 9383:
Occurrence Time : 2015-09-14 10:35:39 PDT
Event Type : checksum-match
Analysis Type : Binary Analysis
Trace ID : 1749
Malware ID : 1749
Source IP : 77.87.102.78
Destination IP : 100.87.80.81
Source MAC : 00:35:56:37:68:49
Destination MAC : 00:37:52:61:36:68
VLAN ID : 0
Attacked Port : 80
IP Protocol : tcp
Original Malware ID :
Name : Trojan.Generic
Match Type : av-suite
EDP URL : https://mil.fireeye.com/edp.php?sname=Trojan.Generic
User role
Admin, Operator, Monitor, or Analyst
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Before Release 7.5. The command output was enhanced to display the statistics about a specific malware submission job in Release 7.7.