show workorders running

Prev Next

Displays the workorders for the total number of malware submissions that are currently running and have not yet completed.

Syntax

show workorders running

Parameters

None

Output fields

The following table describes the output fields for the show workorders running command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Submission ID

Specific malware submission job number.

Source IpAddress

IP address of the source.

Destination IpAddress

IP address of the destination.

File type

File type that is associated with the malware submission job.

Status

Status of a specific malware submission job that is currently running.

Analysis Object ID

Analysis object job number that is associated with the malware submission.

Analysis Object Name

Analysis object name that is associated with the malware submission job.

Analysis File Type

Analysis file type that is associated with the malware submission job.

md5sum

MD5 checksum of the attachment.

Job ID

Job number that is associated with the malware submission.

OS name

Guest image profile.

Application name

Application used to test content.

OS Changes weight

Weight assigned based on a correlation between a set of rules and a set of operating system (OS) change activities detected by the virtual machine (VM) during dynamic analysis.

CNC Match weight

Weight that is assigned by a custom rule that is used for callback detection on a VM during dynamic analysis.

Assigned time

Timestamp generated when the malware submission started the detection operation on a VM.

Complete time

Timestamp generated when the malware submission completed the detection operation on a VM.

Job runtime

Time needed to complete the malware submission job.

Examples

The following example displays the workorders for the total number of malware submissions that are currently running and have not yet completed:

hostname # show workorders running
Submission ID: 21
   Source IpAddress      : 117.72.89.116
   Destination IpAddress : 112.82.103.51
   md5sum                : 0325eae405d86ba5b506ea0d90f49290
   File type             : exe
   Status                : running
      Analysis Object ID      : 21
      Analysis Object Name    : 0325eae405d86ba5b506ea0d90f49290.bin
      Analysis File Type      : exe
      md5sum                  : 0325eae405d86ba5b506ea0d90f49290
           SA engine weight       : 0
           SA job ID              : 82
                 SA sub-engine name         : sophos
                 SA sub-engine signature    : Troj/Zegost-GT
                 SA sub-engine weight       : 100
           Job ID                 : 40
           OS name                : winxp-sp3
           Application name       : Windows Explorer
           OS Changes weight      : 200
           CNC Match weight       : 0
           Assigned time          : 2015-09-23 00:32:26.59365
           Complete time          : 2015-09-23 00:36:30.301305
           Job runtime            : 00:04:03.707655
           Job ID                 : 41
           OS name                : win7x64-sp1
           Application name       : Windows Explorer
           OS Changes weight      : 0
           CNC Match weight       : 0

User role

Admin, Monitor, or Analyst.

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Before Release 7.5. The command output was enhanced to display the statistics about a specific malware submission job in Release 7.7.