Retrieves the submission results for the specified alert UUID.
The retrieved data helps to determine how and why an alert was triggered. This data includes appliance and configuration information, email analysis data, OS information, and so on.
GET https://<address>/wsapis/v2.0.0/submissions/v2/result/<uuid>
Availability
This command is available on the following appliances:
Malware Analysis
Headers:
X-FeApi-Token: [API-Token] (required)
Content-type: application/json (Optional)
Options
address—This is the IP address of the Malware Analysis appliance running the Web Services API.
API-Token—This token authenticates the session. By default, the session times out after 15 minutes of inactivity.
Parameters
uuid(required)— Universally unique ID of the alert.
Example request
GET https://<address>/wsapis/v2.0.0/submissions/v2/result/5e9e81e4-c48a-481e-b4ec-02c3f917f9a5
Response fields
Response Code—A standard HTML response code.
200—Request successful.
500—Request unsuccessful because the server encountered a problem.
Response Message—A standard HTML response message.
OK—Request successful.
Internal Server Error—Request unsuccessful because the server encountered a problem.
Example response
"appliance_id": "AC1F6B6E6E60",
"anomaly_types": [],
"sha256": "140417ba2238dde6de6b541ad75dae6a96fec5d7482054dc154242a1992c9b2f",
"submitted_time": "2022-01-14T05:46:34.861637",
"type": "docx",
"uuid": "5e9e81e4-c48a-481e-b4ec-02c3f917f9a5",
"mitre-mapping": [
{
"name": "Windows Service",
"id": "T1543.003",
"tactic": [
"persistence",
"privilege-escalation"
]
},
{
"name": "Rundll32",
"id": "T1218.011",
"tactic": [
"defense-evasion"
]
},
{
"name": "Native API",
"id": "T1106",
"tactic": [
"execution"
]
}
],
"extracted_objects": [],
"size": 13240,
"complete_time": "2022-01-14T05:50:32.835537",
"alert_url": "https://10.128.32.232/ax/analysis?p_uuid=5e9e81e4-c48a-481e-b4ec-02c3f917f9a5",
"verdict": "NON-MALICIOUS",
"name": "3-faude-url.docx",
"signature_name": "Binary.docx",
"analyses_start_time": "2022-01-14T05:46:36.425014",
"results": [
{
"alert_url": "https://10.128.32.232/ax/analysis?p_uuid=5e9e81e4-c48a-481e-b4ec-02c3f917f9a5", "object_uuid": "5e9e81e4-c48a-481e-b4ec-02c3f917f9a5",
" analysis_results": [
{
"engine": "Bale",
"correlation_results": [
{
"rule_id": 1542,
"rule_name": "Apicall Native API ",
"weight": 0,
"os_change_id": [
4931117
]
},
{
"rule_id": 1515,
"rule_name": "Buckets POSSIBLE_UNSIGNED ",
"weight": 0,
"os_change_id": [
4931114
]
},
{
"rule_id": 1532,
"rule_name": "Flags GenericInstaller ",
"weight": 0,
"os_change_id": [
4931160
]
},
{
"rule_id": 1000004,
"rule_name": "Live Mode Submission Set LiveMode and Bucket LIVE_MODE ",
"weight": 0,
"os_change_id": [
4931114
]
},
{
"rule_id": 1716,
"rule_name": "Process Bypass User Account Control ",
"weight": 0,
"os_change_id": [
4931119
]
},
{
"rule_id": 1632,
"rule_name": "Process Proxy Execution Rundll32 ",
"weight": 0,
"os_change_id": [
4931131
]
},
{
"rule_id": 1560,
"rule_name": "Regkey Create Modify Service ",
"weight": 0,
"os_change_id": [
4931125
]
},
{
"rule_id": 90024,
"rule_name": "Static Analysis FEBETA vm_sigmatch Hunting.Binary.TCP.443.FEBeta",
"weight": 0,
"os_change_id": [
4931114
]
}
],
"signature_name": "Binary.docx",
"dynamic_analysis_uuid": "6a213127-e43c-4169-ae90-b9f7628f1e32"
},
{
"anomaly_types": [],
"os_info": "Microsoft Windows10 64-bit 10.0 base 21.0103",
"os_body": [
{
"id": 4931113,
"analysis": {
"@product": "MAS",
"@version": "1.7016",
"@mode": "malware",
"@ftype": "docx"
}
},
{
"application": {
"@app-name": "MS Word 2019"
},
"malicious-alert": [
{
"class_type": "Possible unsigned Binary",
"diplay_message": "Possibly Unsigned Binary"
},
{
"class_type": "AnalysisType LIVE_MODE",
"diplay_message": "Track Live Mode Submissions Objects"
},
{
"class_type": "FEBETA_SA_ONLY",
"diplay_message": "Static Analysis FEBETA"
}
],
"id": 4931114
},
{
"os": {
"@name": "windows",
"@arch": "x64",
"@version": "10.0.19041",
"@sp": "0"
},
"id": 4931115
},
{
"os_monitor": {
"@time": "10:40:25",
"@version": "21R1.3",
"@date": "Jul 20 2022",
"@build": "973409"
},
"id": 4931116
},
{
"apicall": {
"dllname": "user32",
"address": "N/A",
"apiname": "ClipboardSequenceNumber",
"@timestamp": "2743",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "4036"
},
"@no_extend": "true",
"params": {
"param": {
"#text": "5",
"@id": "1"
}
}
},
"malicious-alert": [
{
"class_type": "Generic Anomaly",
"diplay_message": "Apicall Native API"
}
],
"id": 4931117
},
{
"process_informational": {
"fid": {
"#text": "281474976748427",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\svchost.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "15d0d3e45fd8312a00852a4f3e75f3e1faadd4b592c3e230e722cfefa3ddca2f",
"pid": "4292",
"filesize": "166416",
"ppid": "400",
"cmdline": "consent.exe 400 286 000001C8753D2E10",
"@timestamp": "5415",
"sha1sum": "6513c2959a876b3b5726cd938284285c8772ecfc",
"md5sum": "33beb08302f0eae71133d6254ab1dbda",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Windows\\System32\\consent.exe",
"UserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "4",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
}
},
"id": 4931120
},
{
"process_informational": {
"fid": {
"#text": "281474976749169",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\svchost.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "c546e05d705ffdd5e1e18d40e2e7397f186a7c47fa5fc21f234222d057227cf5",
"pid": "4236",
"filesize": "49664",
"ppid": "796",
"cmdline": "C:\\Windows\\System32\\FodHelper.exe -Embedding",
"@timestamp": "5591",
"sha1sum": "26d7407931b713e0f0fa8b872feecdb3cf49065a",
"md5sum": "85018be1fd913656bc9ff541f017eacd",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Windows\\System32\\fodhelper.exe",
"UserAccount": {
"UserSid": "S-1-5-21-303264690-3185377683-3950874128-500",
"SessionId": "4",
"UserAccountName": "DESKTOP-V7PD8SS\\Administrator",
"AuthenticationId": "USER_LUID (13db3d, 0)",
"SuperPrivilegesPresent": "0"
}
},
"id": 4931121
},
{
"file_informational": {
"fid": {
"#text": "281474976795673",
"@ads": ""
},
"@timestamp": "6397",
"sha1sum": "6f6c50f3682d7fc11b3f362cf3abe17192cfd8c2",
"md5sum": "ca24683818e448de9c844d1f82497254",
"processinfo": {
"imagepath": "N/A",
"pid": "4"
},
"sha256sum": "73a3d7657027b3c88a492d1d60e2ff5af9316f11a8006df8bdb3f02f89e6af11",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "24576",
"value": "C:\\Windows\\appcompat\\Programs\\Amcache.hve.LOG1",
"CreateOptions": "0x0"
},
"id": 4931123
},
{
"regkey": {
"@timestamp": "6899",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\services.exe",
"md5sum": "c9998b1fbd08ec9e2f2914ba7718f297",
"pid": "664"
},
"@suppressed": "true",
"ntstatus": "0x00000000",
"@mode": "setval",
"value": "\\REGISTRY\\MACHINE\\SYSTEM\\ControlSet001\\Services\\TrustedInstaller\\\"Start\" = 0x00000002"
},
"malicious-alert": [
{
"class_type": "Generic Anomaly",
"diplay_message": "Regkey Create Modify Service"
}
],
"id": 4931125
},
{
"file_informational": {
"fid": {
"#text": "10977524091823363",
"@ads": ""
},
"@timestamp": "7697",
"sha1sum": "1c6f7094313398250fbc027cd87b7ac7f3f0007a",
"md5sum": "dc5630231f4888866735545aafca70b3",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\AppHostRegistrationVerifier.exe",
"md5sum": "f0b221519d1419f1ccebefca4e8219bd",
"pid": "4312"
},
"sha256sum": "509d4472b86518b19117502274cbb31a675e0ce0deca29b8d01baba9a484f659",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "471",
"value": "C:\\Users\\Administrator\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\80237EE4964FC9C409AAF55BF996A292_C0427F5F77D9B3A439FC620EDAAB6177",
"CreateOptions": "0x0"
},
"id": 4931128
},
{
"process_informational": {
"fid": {
"#text": "281474976751240",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\services.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "N/A",
"pid": "384",
"filesize": "57368",
"ppid": "664",
"cmdline": "C:\\Windows\\system32\\svchost.exe -k LocalService",
"@timestamp": "9836",
"sha1sum": "66f5e6dade65d7dba979602830d58e53e60fdffb",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Windows\\System32\\svchost.exe",
"UserAccount": {
"UserSid": "S-1-5-19",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\LOCAL SERVICE",
"AuthenticationId": "LOCALSERVICE_LUID (0, 3e5)",
"SuperPrivilegesPresent": "0"
}
},
"id": 4931129
},
{
"process_informational": {
"fid": {
"#text": "281474976751681",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\svchost.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "5555a2fe747477aa9a2e8fedd3ba08ef7e512a54981dd7fc7740e8357cdf685f",
"pid": "2592",
"filesize": "227640",
"ppid": "400",
"cmdline": "C:\\Windows\\system32\\wermgr.exe -upload",
"@timestamp": "9988",
"sha1sum": "84193bc9696af5bed96ee70ab26dd8824e92e8e7",
"md5sum": "b71458fb0b478c55a5efdbeb98c04b5d",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Windows\\System32\\wermgr.exe",
"UserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
}
},
"id": 4931132
},
{
"process_informational": {
"fid": {
"#text": "281474976748734",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\svchost.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "d26defa5d3e01eac5e4ccadd9ba79f21c6b044eb2381642043a1be34b14c0599",
"pid": "4536",
"filesize": "37688",
"ppid": "400",
"cmdline": "C:\\Windows\\system32\\devicecensus.exe SystemCxt",
"@timestamp": "9992",
"sha1sum": "72b068446c47c606a257e6bfc43edd3be211f2da",
"md5sum": "594993e23161bb37e365d8784de020ea",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Windows\\System32\\DeviceCensus.exe",
"UserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
}
},
"id": 4931133
},
{
"apicall": {
"dllname": "user32",
"address": "N/A",
"apiname": "ClipboardFormatListener",
"@timestamp": "10303",
"processinfo": {
"imagepath": "C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE",
"md5sum": "e96806c095670679c761672e45b5a751",
"pid": "4476"
},
"@no_extend": "true",
"params": {
"param": {
"#text": "328742",
"@id": "1"
}
}
},
"id": 4931134
},
{
"process_informational": {
"fid": {
"#text": "281474976751681",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\svchost.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "5555a2fe747477aa9a2e8fedd3ba08ef7e512a54981dd7fc7740e8357cdf685f",
"pid": "4292",
"filesize": "227640",
"ppid": "400",
"cmdline": "C:\\Windows\\system32\\wermgr.exe -upload",
"@timestamp": "10767",
"sha1sum": "84193bc9696af5bed96ee70ab26dd8824e92e8e7",
"md5sum": "b71458fb0b478c55a5efdbeb98c04b5d",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Windows\\System32\\wermgr.exe",
"UserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
}
},
"id": 4931135
},
{
"apicall": {
"dllname": "user32",
"address": "N/A",
"apiname": "ClipboardFormatListener",
"@timestamp": "10812",
"processinfo": {
"imagepath": "C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE",
"md5sum": "e96806c095670679c761672e45b5a751",
"pid": "4476"
},
"@no_extend": "true",
"params": {
"param": {
"#text": "132170",
"@id": "1"
}
}
},
"id": 4931136
},
{
"file_informational": {
"fid": {
"#text": "562949953512930",
"@ads": ""
},
"@timestamp": "11068",
"sha1sum": "f1e0cab7a4f0ea1f0417f60d0cab08508c1b6048",
"md5sum": "a0965801cbf756173a427ae82ec5f422",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "400"
},
"sha256sum": "a64b3ea01a8c6489a3f1548fe341ae2979b106216ef3bee07b49ee747d3541d5",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "25681",
"value": "C:\\Windows\\SoftwareDistribution\\SLS\\9482F4B4-E343-43B6-B170-9A65BC822C77\\TMP13A3.tmp",
"CreateOptions": "0x0"
},
"id": 4931138
},
{
"process_informational": {
"fid": {
"#text": "281474976747864",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\svchost.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "b50c8bd4935d56f398eca98339a038f68362392f679514753f3f986b8e345186",
"pid": "2276",
"filesize": "120320",
"ppid": "400",
"cmdline": "C:\\Windows\\system32\\AppHostRegistrationVerifier.exe",
"@timestamp": "11097",
"sha1sum": "1230dc27c534fe6a1c185b8776869472a008a2b8",
"md5sum": "f0b221519d1419f1ccebefca4e8219bd",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Windows\\System32\\AppHostRegistrationVerifier.exe",
"UserAccount": {
"UserSid": "S-1-5-21-303264690-3185377683-3950874128-500",
"SessionId": "4",
"UserAccountName": "DESKTOP-V7PD8SS\\Administrator",
"AuthenticationId": "USER_LUID (13db5c, 0)",
"SuperPrivilegesPresent": "0"
}
},
"id": 4931139
},
{
"file_informational": {
"fid": {
"#text": "562949953522976",
"@ads": ""
},
"@timestamp": "12578",
"sha1sum": "6dae8c002c4c12f1f6bc64adb8c93430bfd45e65",
"md5sum": "6ebc33364af55e0bb31bd6099d229330",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "400"
},
"sha256sum": "d1a15f01aa5ff1bf3a1b4da86f2ad1e5dcda1998fc621b0a9f3f64260d4168c5",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "29542",
"value": "C:\\Windows\\SoftwareDistribution\\SLS\\855E8A7C-ECB4-4CA3-B045-1DFA50104289\\TMP198F.tmp",
"CreateOptions": "0x0"
},
"id": 4931141
},
{
"apicall": {
"dllname": "user32",
"@repeat": "3",
"address": "N/A",
"apiname": "ClipboardSequenceNumber",
"@timestamp": "13410",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "4036"
},
"@no_extend": "true"
},
"id": 4931142
},
{
"file_informational": {
"fid": {
"#text": "562949953523143",
"@ads": ""
},
"@timestamp": "13563",
"sha1sum": "171a4e5f3fc126ed213d0cefcd64639f892cb31b",
"md5sum": "f858ba1a816dd020e5af93bff48aaa7c",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "400"
},
"sha256sum": "e0cbc49b2de6d153786f381793895f2011f0f918cf9c17ccdc9fffa611546921",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "471",
"value": "C:\\Windows\\System32\\config\\systemprofile\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776",
"CreateOptions": "0x0"
},
"id": 4931143
},
{
"file_informational": {
"fid": {
"#text": "281474976796224",
"@ads": ""
},
"@timestamp": "13650",
"sha1sum": "40c12d174b45e53166906a4ffcb393abad2463d6",
"md5sum": "575b6d4e40d3409f0cae17bffefc0edd",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "400"
},
"sha256sum": "6ff292b0868be1d82ab80b497fc2d2e625ac72596ec07891b404232250405357",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "8192",
"value": "C:\\ProgramData\\Microsoft\\Network\\Downloader\\edb.chk",
"CreateOptions": "0x0"
},
"id": 4931144
},
{
"file_informational": {
"fid": {
"#text": "562949953523188",
"@ads": ""
},
"@timestamp": "14030",
"sha1sum": "7e5ee0fc44987403c5317ce74766ccb1d17556b6",
"md5sum": "10be2ff8472337d8e735d13840f5aa15",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\taskhostw.exe",
"md5sum": "536b1beba7bf2037bf27cd5bc6654696",
"pid": "3612"
},
"sha256sum": "dd99484f8514624b12bc942023d160ea58ce0c2c50cbb1bff669f407ad5b32d0",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "78213",
"value": "C:\\ProgramData\\Microsoft\\Windows\\OneSettings\\CTAC.json",
"CreateOptions": "0x0"
},
"id": 4931145
},
{
"file_informational": {
"fid": {
"#text": "562949953523150",
"@ads": ""
},
"@timestamp": "14406",
"sha1sum": "2967aa9e27dacbf805d218b844023c0a2d592c2b",
"md5sum": "ed7f527305d671c6a677d0086198cd45",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "400"
},
"sha256sum": "1d819bcb675997013872640b5d45785d551c948af668fc1027218770c10275a6",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "25704",
"value": "C:\\Windows\\SoftwareDistribution\\SLS\\8B24B027-1DEE-BABB-9A95-3517DFB9C552\\TMP20B4.tmp",
"CreateOptions": "0x0"
},
"id": 4931147
},
{
"file_informational": {
"fid": {
"#text": "562949953523480",
"@ads": ""
},
"@timestamp": "15829",
"sha1sum": "26fb0f336341f64349a5c1a1d00473446aea84dc",
"md5sum": "c68e2834d70a667b5825bf7bbae0f8c1",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\lsass.exe",
"md5sum": "a6236e9a991c5b4e450aa6f25a460bcc",
"pid": "676"
},
"sha256sum": "051c81c2e7abbd6eea7020d60d31bdb1850a8f11a9ea8221783f7d3c29e883ae",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "468",
"value": "C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\User\\e9df14a3-7adf-4bd1-8f78-0c935b1b3c69",
"CreateOptions": "0x0"
},
"id": 4931148
},
{
"file_informational": {
"fid": {
"#text": "562949953504128",
"@ads": ""
},
"@timestamp": "15837",
"sha1sum": "0279b991297f50171208d038d14b7fd3158fd3fb",
"md5sum": "be264d4cbb88d733324adcb1f911ff07",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\lsass.exe",
"md5sum": "a6236e9a991c5b4e450aa6f25a460bcc",
"pid": "676"
},
"sha256sum": "948a40f7631207207ffd57ed6fefebe63479f0bd4b76e3fe1a59392b1b84eea9",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "24",
"value": "C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\User\\Preferred",
"CreateOptions": "0x0"
},
"id": 4931149
},
{
"apicall": {
"dllname": "user32",
"address": "N/A",
"apiname": "ClipboardSequenceNumber",
"@timestamp": "16427",
"processinfo": {
"imagepath": "C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE",
"md5sum": "e96806c095670679c761672e45b5a751",
"pid": "4476"
},
"@no_extend": "true",
"params": {
"param": {
"#text": "10",
"@id": "1"
}
}
},
"id": 4931150
},
{
"apicall": {
"dllname": "user32",
"address": "N/A",
"apiname": "ClipboardSequenceNumber",
"@timestamp": "16444",
"processinfo": {
"imagepath": "C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE",
"md5sum": "e96806c095670679c761672e45b5a751",
"pid": "4476"
},
"@no_extend": "true",
"params": {
"param": {
"#text": "10",
"@id": "1"
}
}
},
"id": 4931151
},
{
"apicall": {
"dllname": "user32",
"@repeat": "3",
"address": "N/A",
"apiname": "ClipboardSequenceNumber",
"@timestamp": "16779",
"processinfo": {
"imagepath": "C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE",
"md5sum": "e96806c095670679c761672e45b5a751",
"pid": "4476"
},
"@no_extend": "true"
},
"id": 4931152
},
{
"file_informational": {
"fid": {
"#text": "1970324837076766",
"@ads": ""
},
"@timestamp": "19492",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\taskhostw.exe",
"md5sum": "536b1beba7bf2037bf27cd5bc6654696",
"pid": "3612"
},
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"value": "C:\\ProgramData\\Microsoft\\Windows\\OneSettings\\FeatureConfig.bak.json",
"CreateOptions": "0x0"
},
"id": 4931153
},
{
"file_informational": {
"fid": {
"#text": "281474976812795",
"@ads": ""
},
"@timestamp": "19505",
"sha1sum": "017dbd33bb7150fde2bf30b6954941904e4af9d8",
"md5sum": "c170c68046b72cdf978bf378aad51d61",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\taskhostw.exe",
"md5sum": "536b1beba7bf2037bf27cd5bc6654696",
"pid": "3612"
},
"sha256sum": "c057ad18299b7e86ef567f31dc248cbee702670acdffcbe4afb5b95274851bdd",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "29003",
"value": "C:\\ProgramData\\Microsoft\\Windows\\OneSettings\\FeatureConfig.json",
"CreateOptions": "0x0"
},
"id": 4931154
},
{
"process_informational": {
"fid": {
"#text": "281474976737779",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\svchost.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "N/A",
"pid": "3228",
"filesize": "3046912",
"ppid": "796",
"cmdline": "\"C:\\Program Files\\WindowsApps\\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\\GameBar.exe\" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mca",
"@timestamp": "21377",
"sha1sum": "82a30d1513d9b233d247906edc37638e5ad473a8",
"md5sum": "8a4d1bbe6f65383ad167a8c81fb19df0",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Program Files\\WindowsApps\\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\\GameBar.exe",
"UserAccount": {
"UserSid": "S-1-5-21-303264690-3185377683-3950874128-500",
"SessionId": "4",
"UserAccountName": "DESKTOP-V7PD8SS\\Administrator",
"AuthenticationId": "USER_LUID (13db5c, 0)",
"SuperPrivilegesPresent": "0"
}
},
"id": 4931155
},
{
"process_informational": {
"fid": {
"#text": "281474976737779",
"@ads": ""
},
"parentname": "C:\\Windows\\System32\\svchost.exe",
"ParentUserAccount": {
"UserSid": "S-1-5-18",
"SessionId": "0",
"UserAccountName": "NT AUTHORITY\\SYSTEM",
"AuthenticationId": "SYSTEM_LUID (0, 3e7)",
"SuperPrivilegesPresent": "1"
},
"sha256sum": "N/A",
"pid": "3852",
"filesize": "3046912",
"ppid": "796",
"cmdline": "\"C:\\Program Files\\WindowsApps\\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\\GameBar.exe\" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mca",
"@timestamp": "22239",
"sha1sum": "82a30d1513d9b233d247906edc37638e5ad473a8",
"md5sum": "8a4d1bbe6f65383ad167a8c81fb19df0",
"@no_extend": "true",
"@mode": "started",
"value": "C:\\Program Files\\WindowsApps\\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\\GameBar.exe",
"UserAccount": {
"UserSid": "S-1-5-21-303264690-3185377683-3950874128-500",
"SessionId": "4",
"UserAccountName": "DESKTOP-V7PD8SS\\Administrator",
"AuthenticationId": "USER_LUID (13db5c, 0)",
"SuperPrivilegesPresent": "0"
}
},
"id": 4931156
},
{
"file_informational": {
"fid": {
"#text": "562949953523490",
"@ads": ""
},
"@timestamp": "29892",
"sha1sum": "3985d2dd970ac10f3ce6fbaf3e6b7091a289236c",
"md5sum": "7f6a492ff1375625409a79ea29338329",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "400"
},
"sha256sum": "12319a1571cf2f654309a1e8062a67a060c0d0e050003e6fa5e2f4a9d73949ab",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "419",
"value": "C:\\Users\\Administrator\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\9E94643DE99F5621BC288D045BEA85DD",
"CreateOptions": "0x0"
},
"id": 4931157
},
{
"file_informational": {
"fid": {
"#text": "562949953523492",
"@ads": ""
},
"@timestamp": "30177",
"sha1sum": "a5c2bf9d18357868d36d21a442c88ae657360efe",
"md5sum": "8352fd5ccd7506781059a01fe7ae0dc6",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\svchost.exe",
"md5sum": "95043977365cf88a80161be9cf3281fb",
"pid": "400"
},
"sha256sum": "a728647bb459b4451d694ac12bcb702ff71b7530acc70a3217959614f38baf12",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "407",
"value": "C:\\Users\\Administrator\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\51867C3735CFAECCDB556E146BB12C28",
"CreateOptions": "0x0"
},
"id": 4931158
},
{
"file_informational": {
"fid": {
"#text": "562949953523496",
"@ads": ""
},
"@timestamp": "35671",
"sha1sum": "48a596cce2e01b7aede1a06397944a41d55b5a5f",
"md5sum": "aabbe57de87f700c0034b65bc559972b",
"processinfo": {
"imagepath": "C:\\Windows\\System32\\taskhostw.exe",
"md5sum": "536b1beba7bf2037bf27cd5bc6654696",
"pid": "3612"
},
"sha256sum": "00b703f451108362226586c9258b6e15d5b34c72c1690c700510120ce7cda960",
"ntstatus": "0x0",
"@no_extend": "true",
"@mode": "close",
"filesize": "358",
"value": "C:\\ProgramData\\Microsoft\\Windows\\OneSettings\\SCCInstallService.json",
"CreateOptions": "0x0"
},
"malicious-alert": [
{
"class_type": "Flags",
"diplay_message": "File/Folder/Apicall Unknown Installer"
}
],
"id": 4931160
}
],
"engine": "DynamicAnalysis",
"signature_name": "Binary.docx",
"weight": 0,
"dynamic_analysis_uuid": "6a213127-e43c-4169-ae90-b9f7628f1e32"
},
{
"engine": "Email Header",
"signature_name": "Binary.docx",
"weight": 0
},
{
"ip_proto": "17",
"anomaly_types": [],
"server_dns_name": "fe3cr.delivery.mp.microsoft.com",
"engine": "NetworkAnomaly",
"channel": "",
"dynamic_analysis_uuid": "6a213127-e43c-4169-ae90-b9f7628f1e32",
"service_port": "53"
},
{
"ip_proto": "17",
"anomaly_types": [],
"server_dns_name": "nexusrules.officeapps.live.com",
"engine": "NetworkAnomaly",
"channe": "",
"dynamic_analysis_uuid": "6a213127-e43c-4169-ae90-b9f7628f1e32",
"service_port": "53"
},
{
"ip_proto": "6",
"signature_id": "86300385",
"anomaly_types": [],
"server_dns_name": "52.152.108.96",
"engine": "VmSigMatch",
"channel": "FgMDANMBAADPAwNjnA2sdavmCL+NGYyx88Q5PN0lImYvUEIcsdxWolydlgAAJsAswCvAMMAvwCTA\nI8AowCfACsAJwBTAEwCdAJwAPQA8ADUALwAKAQAAgAAAACQAIgAAH2ZlM2NyLmRlbGl2ZXJ5Lm1w\nLm1pY3Jvc29mdC5jb20ABQAFAQAAAAAACgAIAAYAHQAXABgACwACAQAADQAaABgIBAgFCAYEAQUB\nAgEEAwUDAgMCAgYBBgMAIwAAABAADgAMAmgyCGh0dHAvMS4xABcAAP8BAAEA",
"signature_name": "Methodology.DomainFronting.AzureEdge.FEBeta",
"weight": 0,
"dynamic_analysis_uuid": "6a213127-e43c-4169-ae90-b9f7628f1e32",
"service_port": "443"
}
]
}
],
"md5": "aec1cb430879a35f6b56264afffddd06",
"status": "SUCCESS"
}
cURL code sample: list submission results by UUID
The following code sample can be copied and executed from any command-line interface that includes the cURL library.
Note
In this sample, line breaks are added for readability. Remove these line breaks before you paste the code sample into your command-line tool.
curl -qgsSk --header "X-FeApi-Token: xxxxxxxxxxxxxxxxxxxxxxxxx=" https://xxx.xxx.xxx.xxx/wsapis/v2.0.0/submissions/v2/result/yyy-zzz
This cURL sample includes the following options:
-q—This option specifies that thecurlrcconfig file is not read or used. Although this is an optional setting, Trellix recommends that you include this option.-g—This option turns off the URL globbing parser. Although this is an optional setting, Trellix recommends that you include this option.-s—This option turns off the progress meter and error message. Although this is an optional setting, Trellix recommends that you include this option.-S—When used with the-soption, this option shows error messages if your cURL switch fails. Although this is an optional setting, Trellix recommends that you include this option.-k—This option explicitly allows cURL to perform insecure SSL connections and transfers. This allows you to test your SSL connection without installing a CA certificate.X-FeApi-Token: xxxxxxxxxxxxxxxxxxxxxxxxx—This option specifies the API key used for authentication. Replacexxxxxxxxxxxxxxxxxxxxxxxxxwith the API key.https://xxx.xxx.xxx.xxx/wsapis/v2.0.0/submissions/v2/result/yyy-zzz—The submission-results request URL. Replacexxx.xxx.xxx.xxxwith the IP address of your appliance. Replaceyyy-zzzwith an alert UUID.
Results
The specified alert's submission result is returned as a JSON file.