show web-incident malicious

Prev Next

Displays information about the Web incident jobs that are marked as malicious. You can display up to 100 jobs by default.

Syntax

show web-incident malicious [limit <number>]

Parameters

limit <number>

(Optional) Displays the specified number of entries that are marked as malicious. A higher number might increase command response time.

Output fields

The following table describes the output fields for the show web-incident malicious command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Web Incident ID

Specific Web incident job number.

Submission ID

Specific malware submission job number.

Submission name

Name of malware submission.

Source IpAddress

IP address of the source.

Destination IpAddress

IP address of the destination.

File type

File type that is associated with the malware submission job.

Status

Whether the analysis succeeded or failed.

Malicious

Whether the malware submission was detected as malicious.

Examples

The following example displays the information about the Web incident jobs that are marked as malicious:

hostname # show web-incident malicious
Web Incident ID: 5645
    Submission ID: 363
       Submission name       : http://www.sanhoapt.com/board/data/file/test/lndex.html
       Source IpAddress      : 3.124.152.157
       Destination IpAddress : 84.36.238.205
       File type             : url
       Status                : success
       Malicious             : YES
Web Incident ID: 5664
    Submission ID: 390
       Submission name       : http://www.midiaapp.com/data/css/index.html
       Source IpAddress      : 55.122.111.169
       Destination IpAddress : 40.130.48.86
       File type             : url
       Status                : success
       Malicious             : YES
Web Incident ID: 5685
    Submission ID: 416
       Submission name       : http://www.mathlove.kr/shop/log/data/index.html
       Source IpAddress      : 74.95.252.100
       Destination IpAddress : 72.115.10.202
       File type             : url
       Status                : success
       Malicious             : YES
Web Incident ID: 5666
    Submission ID: 391
       Submission name       : http://www.mirage.co.kr/
       Source IpAddress      : 6.201.100.124
       Destination IpAddress : 22.147.117.216
       File type             : url
       Status                : success
       Malicious             : YES
Web Incident ID: 5668
    Submission ID: 393
       Submission name       : http://www.chungjung.co.kr/xl/css.html
       Source IpAddress      : 64.28.181.208
       Destination IpAddress : 2.212.63.220
       File type             : url
       Status                : success
       Malicious             : YES
Web Incident ID: 5605
    Submission ID: 314
       Submission name       : http://www.mathlove.kr/shop/log/data/index.html
       Source IpAddress      : 10.48.154.65
       Destination IpAddress : 104.16.151.75
       File type             : url
       Status                : success
       Malicious             : YES
Web Incident ID: 5683
    Submission ID: 414
       Submission name       : http://www.midiaapp.com/data/css/index.html
       Source IpAddress      : 7.146.187.207
       Destination IpAddress : 71.134.202.179
       File type             : url
       Status                : success
       Malicious             : YES

User role

Admin, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 7.7

  • Email Security — Server: Release 7.8