show object-analysis id <object_ID>

Prev Next

Displays information about a specific malware object analysis and malware submission job.

Syntax

show object-analysis id <object_ID>

Parameters

object_ID

The malware object ID for a specific job.

Output fields

The following table describes the output fields for the show object-analysis id command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Malware ID

Specific malware object analysis job number.

Submission ID

Specific malware submission job number.

Analysis Type

Type of malware analysis (sandbox or live) that is associated with the malware submission job number.

URL

Single URL of the malware sample.

Analysis Timeout

Number of seconds after which the malware analysis stops if the analysis is not complete.

Analysis Priority

Priority setting for the current analysis, if you add multiple analysis jobs at the same time to the MVX engine queue. The default priority is normal.

Force

Force the Network Security appliance to perform the submitted analysis even if it matches a previous submission for which forensic results have been generated.

Profile Name

Guest image profile that the MVX engine uses for the current malware analysis job.

Profile ID

Guest image profile ID number.

Application

Application used to test submitted content.

Md5Sum

Result of the MD5 checksum.

State

Whether the malware submission job has been completed, is in the queue waiting to be analyzed, or is currently running.

Submitted Time

Date and time when the malware analysis job was submitted.

Run Start Time

Start time of the analysis.

Run End Time

End time of the analysis.

IM

Whether the sample is malicious. The results can be Yes, No, or blank. If the entry is blank, the Network Security appliance cannot confirm a malicious attack. Further forensics might be required.

Number of Events

Number of events identified in the analysis.

Children Malware ID(s)

Specific child malware analysis job number that is associated with the parent malware submission.

Parent Malware ID

Specific parent malware analysis job number that is associated with the child malware submission.

Occurrence Time

Time that the event occurred.

Event Type

Type of event that is identified with the analysis.

Analysis Type

Type of analysis that is associated with the event.

Trace ID

Specific trace job number that is associated with a workorder.

Source IP

IP address of the source.

Destination IP

IP address of the destination.

Source MAC

MAC address of the source.

Destination MAC

MAC address of the destination.

VLAN ID

Network VLAN job number that is associated with an event.

Attacked Port

Port number that is associated with an attack.

IP Protocol

Type of IP protocol that is used to transport the threat.

PCAP URL

Packet capture (PCAP) link that is associated with an event.

Example

The following example displays malware analysis information for job number 1749:

hostname # show object-analysis id 1749
Malware ID 1749
Submission ID 1749
    Analysis Type:         sandbox
    URL:                   ff8f8776833cf214d1febb7f6bc8d9b8.bin
    Analysis Timeout:      240
    Analysis Priority:     normal
    Force:                 false
    Profile Name:          win7x64-sp1
    Profile ID:            66
    Application:           Windows-Explorer
    Md5Sum:                ff8f8776833cf214d1febb7f6bc8d9b8
    State:                 done
    Status:                success
    Submitted Time:        2015-09-14 00:28:21 PDT
    Run Start Time:        2015-09-14 10:27:03 PDT
    Run End Time:          2015-09-14 10:35:39 PDT
    IM:                    YES
    Number of Events:      4
    Children Malware ID(s) -
    Parent Malware ID      -
  Event 9386:
   Occurrence Time        : 2015-09-14 10:35:39 PDT 
   Event Type             : os-change-anomaly
   Analysis Type          : Binary Analysis
   Trace ID               : 1749
   Malware ID             : 1749
      Source IP           : 77.87.102.78
      Destination IP      : 100.87.80.81
      Source MAC          : 00:35:56:37:68:49
      Destination MAC     : 00:37:52:61:36:68
      VLAN ID             : 0
      Attacked Port       : unknown
      IP Protocol         : unknown
   OS Change Analysis:
     <analysis mode="malware" ftype="exe" version="1.1077" product="MPS"/>
     <application app-name="Windows Explorer" />
     <os name="windows" version="5.1.2600" sp="3"/>
     <os_monitor version="14R2.1" build="315507" date="Feb  3 2015" time="17:32:46"/>
     <end-of-report/>
     EDP URL             : https://mil.fireeye.com/edp.php?sname=Malware.Binary.exe
     PCAP URL            : https://172.16.146.41/event_stream/send_pcap_file?ev_id=9386
     PCAP (text)         : https://172.16.146.41/event_stream/send_pcap_ascii?ev_id=9386
   Event 9385:
    Occurrence Time        : 2015-09-14 10:35:39 PDT
    Event Type             : os-change-anomaly
    Analysis Type          : Binary Analysis
    Trace ID               : 1749
    Malware ID             : 1749
       Source IP           : 77.87.102.78
       Destination IP      : 100.87.80.81
       Source MAC          : 00:35:56:37:68:49
       Destination MAC     : 00:37:52:61:36:68
       VLAN ID             : 0
       Attacked Port       : unknown
       IP Protocol         : unknown
    OS Change Analysis:
      <analysis mode="malware" ftype="exe" version="1.1077" product="MPS"/>
      <application app-name="Windows Explorer" />
      <os name="windows" version="6.1.7601" sp="1"/>
      <os_monitor version="14R2.1" build="315507" date="Feb  3 2015" time="17:32:46"/>
      <end-of-report/>
      EDP URL             : https://mil.fireeye.com/edp.php?sname=Malware.Binary.exe
      PCAP URL            : https://172.16.146.41/event_stream/send_pcap_file?ev_id=9385
      PCAP (text)         : https://172.16.146.41/event_stream/send_pcap_ascii?ev_id=9385
   Event 9384:
    Occurrence Time        : 2015-09-14 10:35:39 PDT
    Event Type             : checksum-match
    Analysis Type          : Binary Analysis
    Trace ID               : 1749
    Malware ID             : 1749
       Source IP           : 77.87.102.78
       Destination IP      : 100.87.80.81
       Source MAC          : 00:35:56:37:68:49
       Destination MAC     : 00:37:52:61:36:68
       VLAN ID             : 0
       Attacked Port       : 80
       IP Protocol         : tcp
       Original Malware ID :
       Name                : Dropper.DTI.DroppedFiles
       Match Type          : malware-intrinsic-analysis
       EDP URL             : https://mil.fireeye.com/edp.php?sname=Dropper.DTI.DroppedFiles
   Event 9383:
    Occurrence Time        : 2015-09-14 10:35:39 PDT
    Event Type             : checksum-match
    Analysis Type          : Binary Analysis
    Trace ID               : 1749
    Malware ID             : 1749
    Source IP              : 77.87.102.78
    Destination IP         : 100.87.80.81
    Source MAC             : 00:35:56:37:68:49
    Destination MAC        : 00:37:52:61:36:68
    VLAN ID                : 0
    Attacked Port          : 80
    IP Protocol            : tcp
    Original Malware ID    :
    Name                   : Trojan.Generic
    Match Type             : av-suite
    EDP URL                : https://mil.fireeye.com/edp.php?sname=Trojan.Generic

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5. The command output was enhanced to display the statistics about a specific malware submission job in Release 7.7.