Displays information about a malware submission job that matched a particular MD5 checksum attachment. You can display up to 100 jobs by default.
Syntax
show submission md5sum <MD5_checksum_attachment> [limit <number>]Parameters
MD5_checksum_attachmentlimit <number>MD5 checksum of the attachment.
(Optional) Displays the specified number of entries that matched a particular MD5 checksum attachment. A higher number might increase command response time.
Output fields
The following table describes the output fields for the show submission md5sum command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
Submission ID | Specific malware submission job number. |
UUID | Specific universally unique identifier that is associated with the malware submission on an integrated Network Security appliance or a Network Security sensor. |
Malware ID | Specific malware analysis job number. |
Source IpAddress | IP address of the source. |
Destination IpAddress | IP address of the destination. |
Status | Whether the analysis succeeded or failed. |
Malicious | Whether the malware submission was detected as malicious. |
Analysis Object ID | Analysis object job number that is associated with the malware submission. |
Analysis Object Name | Analysis object name that is associated with the malware submission job. |
Analysis File Type | Analysis file type that is associated with the malware submission job. |
md5sum | MD5 checksum of the attachment. |
Job ID | Job number that is associated with the malware submission. |
OS name | Type of guest image profile. |
Application name | Type of application. |
OS Changes weight | Weight assigned based on a correlation between a set of rules and a set of operating system change activities detected by the virtual machine (VM) during dynamic analysis. |
CNC Match weight | Weight that is assigned by a custom rule that is used for callback detection on a VM during dynamic analysis. |
Assigned time | Timestamp generated when the malware submission started the detection operation on a VM. |
Complete time | Timestamp generated when the malware submission completed the detection operation on a VM. |
Job runtime | Time needed to complete the malware submission job. |
Examples
The following example displays the statistics for the job that matched the 7d07560e49c6eaec0bbad9999f16bc1c MD5 checksum attachment:
hostname # show submission md5sum 7d07560e49c6eaec0bbad9999f16bc1c
Submission ID: 7
UUID : 9dffc29c-daad-4da6-9535-da033cb0c6be
Malware ID : 15
Source IpAddress : 108.157.161.251
Destination IpAddress : 47.47.183.145
md5sum : 7d07560e49c6eaec0bbad9999f16bc1c
File type : exe
Status : success
Malicious : YES
Analysis Object ID : 6
Analysis Object Name : 0014.exe
Analysis File Type : exe
md5sum : 7d07560e49c6eaec0bbad9999f16bc1c
Static Analysis weight : 100
Dynamic Analysis weight : 100
Dynamic Analysis jobs : 2
Static Analysis jobs : 4
SA engine weight : 100
SA job ID : 13
SA sub-engine name : avs
SA sub-engine signature : Trojan.Downloader
SA sub-engine weight : 100
SA engine weight : 80
SA job ID : 14
SA sub-engine name : clamd
SA sub-engine signature : PUA.Win.Packer.Upack-48
SA sub-engine weight : 80
Job ID : 10
OS name : win7x64-sp1
Application name : Windows Explorer
OS Changes weight : 100
CNC Match weight : 0
Assigned time : 2016-04-28 00:35:54.32882
Complete time : 2016-04-28 00:39:57.529021
Job runtime : 00:04:03.200201
Signature : Malware.Binary.exe
Job ID : 9
OS name : winxp-sp3
Application name : Windows Explorer
OS Changes weight : 100
CNC Match weight : 0
Assigned time : 2016-04-28 00:35:25.960428
Complete time : 2016-04-28 00:39:33.7778
Job runtime : 00:04:07.817372
Signature : Malware.Binary.exe
User role
Administrator, Monitor, or Analyst.
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Malware Analysis: Release 7.7
File Protect: Release 7.7
Network Security: Release 7.7. The command output was enhanced to include the UUID field on an integrated Network Security appliance or a Network Security sensor in Release 7.9.
Email Security — Server: Release 7.8