Investigate malicious files and URLs in IVX Server

Prev Next

When a file or URL is submitted for analysis on the Submissions page, it appears on the Alerts page if it is classified as malicious or riskware. This page lists detected threats based on the selected date range, allowing users to filter, search, and investigate them in detail.

On the Alerts page, select a date range to filter recent alerts. The following details are displayed:

Column Name

Description

Completed At

The date and time the analysis was done.

Note

When you navigate to Alerts, the date range automatically resets to the default of 2 days, irrespective of the date range you have selected on the dashboard.

MD5

The MD5 hash of the alert. Click the hash value to view the analysis report for the alert.

Type

The type of file that contains the alert. To filter results, enter a file type in the search box under the column heading and press Enter.

File/URL

The file name or the URL of the file submitted for analysis. To search for a specific file, enter its name in the search bar under the column heading and press Enter. Click on the file link to open the analysis report for more information on that alert.

Verdict

Whether the alert is malicious or riskware. The file that is marked as “Clean” is not displayed.

Signature

The name of the threat group behind a malicious attack. To view all alerts associated with a threat, enter the signature name in the search box under the column heading and press Enter.

Artifacts

Click IVX_Server_UI_Artifacts_icon.png icon to download the artifacts associated with the submission. You will see this icon only if there are other artifacts available.

Click IVX_Server_UI_Samples_download_icon.png icon to download the samples. The password to view the file is "protected".

Submitter

The name of the user who submitted the alert. To filter alerts by a submitter, enter their name in the search bar under the column heading and press Enter.

Submissions made through ICAP are now displayed in the Submitter field as ICAP, allowing you to easily identify and track all submissions originating from ICAP.

UUID

A unique reference ID generated for each file or URL submitted for analysis.

Analysis Mode

Indicates where the analysis was performed for this submission. It displays “Sandbox” for analysis conducted in a sandbox environment and “Live” for real-time analysis.

Export table as CSV

Click CSV_format_report.png to download the report in CSV format. The maximum of 1000 records are only displayed in the report.