show submission malicious

Prev Next

Displays information about the malware submission jobs that are marked as malicious. You can display up to 100 jobs by default.

Syntax

show submission malicious [limit <number>]

Parameters

limit <number>

(Optional) Displays the specified number of entries that are marked as malicious. A higher number might increase command response time.

Output fields

The following table describes the output fields for the show submission malicious command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Submission ID

Specific malware submission job number.

UUID

Specific universally unique identifier that is associated with the malware submission on an integrated Network Security appliance or a Network Security sensor.

Malware ID

Specific malware analysis job number.

md5sum

MD5 checksum of the attachment.

File type

File type that is associated with the malware submission job.

Status

Whether the analysis succeeded or failed.

Malicious

Whether the malware submission was detected as malicious.

Analysis Object ID

Analysis object job number that is associated with the malware submission.

Analysis Object Name

Analysis object name that is associated with the malware submission job.

Analysis File Type

Analysis file type that is associated with the malware submission job.

Dynamic Analysis weight

Weight that is assigned to a dynamic analysis job on a particular object.

Dynamic Analysis jobs

Number of dynamic analysis jobs that have been processed on a particular object.

Static Analysis jobs

Number of static analysis jobs that have been processed on a particular object.

Job ID

Job number that is associated with the malware submission.

OS name

Type of guest image profile.

Application name

Type of application.

OS Changes weight

Weight assigned based on a correlation between a set of rules and a set of operating system (OS) change activities detected by the virtual machine (VM) during dynamic analysis.

CNC Match weight

Weight that is assigned by a custom rule that is used for callback detection on a VM during dynamic analysis.

Assigned time

Timestamp generated when the malware submission job started the detection operation on a VM.

Complete time

Timestamp generated when the malware submission job completed the detection operation on a VM.

Job runtime

Time needed to complete the malware submission job.

Examples

The following example displays the information about the malware submission job that is marked as malicious:

hostname # show submission malicious
Submission ID: 4
   UUID                  : 9351908a-0575-4666-9d2b-a7d5cc200a3d
   Malware ID            : 13
   Source IpAddress      : 80.156.52.181
   Destination IpAddress : 190.246.12.141
   md5sum                : 4a78c36e8be28a2fef57e69daa993d13
   File type             : exe
   Status                : success
   Malicious             : YES
      Analysis Object ID      : 2
      Analysis Object Name    : load.exe
      Analysis File Type      : exe
      md5sum                  : 4a78c36e8be28a2fef57e69daa993d13
      Static Analysis weight  : 100
      Dynamic Analysis weight : 300
      Dynamic Analysis jobs   : 2
      Static Analysis jobs    : 4
            SA engine weight       : 100
            SA job ID              : 5
                  SA sub-engine name         : avs
                  SA sub-engine signature    : Trojan.Generic
                  SA sub-engine weight       : 100
            Job ID                 : 4
            OS name                : win7x64-sp1
            Application name       : Windows Explorer
            OS Changes weight      : 100
            CNC Match weight       : 0
            Assigned time          : 2016-04-28 00:34:21.253765
            Complete time          : 2016-04-28 00:35:25.881007
            Job runtime            : 00:01:04.627242
            Signature              : Malware.Binary.exe
            Job ID                 : 3
            OS name                : winxp-sp3
            Application name       : Windows Explorer
            OS Changes weight      : 300
            CNC Match weight       : 300
            Assigned time          : 2016-04-28 00:33:15.649557
            Complete time          : 2016-04-28 00:34:58.169366
            Job runtime            : 00:01:42.519809
            Signature              : Trojan.Rootkit.MVX

User role

Administrator, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Release 7.7

  • File Protect: Release 7.7

  • Network Security: Release 7.7. The command output was enhanced to include the UUID field on an integrated Network Security appliance or a Network Security sensor in Release 7.9.

  • Email Security — Server: Release 7.8