show submission dst <IP_address>

Prev Next

Displays the malware submission jobs based on a destination IP address. You can display up to 100 jobs by default.

Syntax

show submission dst <IP_address> [limit <number>]

Parameters

limit <number>

(Optional) Displays the specified number of entries that are based on a destination IP address. A higher number might increase command response time.

Output fields

The following table describes the output fields for the show submission dst command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Submission ID

Specific malware submission job number.

UUID

Specific universally unique identifier that is associated with the malware submission on an integrated Network Security appliance or a Network Security sensor.

Malware ID

Specific malware analysis job number.

Source IpAddress

IP address of the source.

Destination IpAddress

IP address of the destination.

File type

File type that is associated with the malware submission job.

Status

Whether the analysis succeeded or failed.

Malicious

Whether the malware submission was detected as malicious.

Examples

The following example displays the malware submission jobs based on a particular destination IP address:

hostname # show submission dst 85.175.101.221
Submission ID: 90
   UUID                  : cc83d286-de6d-4d7c-845a-aab67f2e5d40
   Malware ID            : 74
   Source IpAddress      : 245.156.62.140
   Destination IpAddress : 85.175.101.221
   md5sum                : 722c2e3cdf28d730977c5266b650f8a0
   File type             : jar
   Status                : success
   Malicious             : YES
Submission ID: 91
   UUID                  : d23f7070-dd69-4b7f-b09d-d4ecf0aea69b
   Malware ID            : 76
   Source IpAddress      : 245.156.62.140
   Destination IpAddress : 85.175.101.221
   md5sum                : be95c26c782d3298370aa6b189276d31
   File type             : exe
   Status                : success
   Malicious             : YES

User role

Administrator, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Release 7.7

  • File Protect: Release 7.7

  • Network Security: Release 7.7. The command output was enhanced to include the UUID field on an integrated Network Security appliance or a Network Security sensor in Release 7.9.

  • Email Security — Server: Release 7.8