Viewing malware using the Web UI

Prev Next

Use the File Analysis page to view and drill into details about malicious files.

FX_FileAnalysisTop_scap.png

The following columns are included on the page:

ID—The Malware Analysis ID number.

Malware—The type of malware detected: Malware.Binary, Exploit, Trojan, Worm, Infection Match, and so on.

File Type—A specific file type such as EXE, PDF, DOC, PPT, XLS, GIF, JPG, SWF, MOV, QT, MP3, MP3, ASF, ZIP, DLL, or UNK (UNKNOWN).

Name—Name of the file determined to be malicious; for example: menu4.swf.

Md5sum—The message-digest algorithm5 checksum derived from a cryptographic hash function that produces a 128-bit (16-byte) hash value used to check data integrity, expressed as a 32-digit hexadecimal number in the File Protect appliance.

Submitted—The date and time at which the file scan was submitted for analysis.

Status—The status of the file scan analysis.

Start—The date and time at which the file scan was submitted for analysis.

Complete—The date and time the malware analysis was completed.

To view malicious file details:
  1. Click a link in the File Name column of the Show Quarantined Files page.

  2. In the File Analysis page, click the orange arrow to expand the file details.

    FX_FileAnalysis_scap.png
  3. For compressed (archive) files types (RAR and ZIP), there are two sets of arrows. Click both arrows to see scan results for the files within the archive file.

    FX_ZIPDetails_scap.png

Understanding malicious file results

The status of compressed file types matches the status of the contained file with the most severe status. For example, a ZIP file contains one file with the status Success and one file with the status Submit Disabled. Because Submit Disabled is the more severe status, the ZIP file will also be marked as Submit Disabled. An exception to this is when the most severe status for a contained file is Duplicate; in this case, the ZIP or RAR file will be marked as Success, not Duplicate.

Red, underlined text in the tables and hierarchical pages indicate active hyperlinks. The results details are always displayed in three categories: Event Details, OS Changes Details, and Additional Information Details (Static File Analysis Tools). Each link displays detailed forensics information about malware behavior and OS changes caused by the attack.

FX_ScanDetails2_scap.png
Scan Results - event details and examples
  • Detected malware type

    Example: Malware: Malware.Binary.Pdf

  • File type of the malware

    Example: SWF

  • Whether suspicious behavior was observed or confirmed

    Example: Suspicious Behavior Observed

  • Application type used to analyze the malware

    Example: Adobe PDF 7.0

  • Callback attempts captured by the VM, including any communication attempts made by the malware

    Example: VM Capture pcap < 24> bytes (text link)

  • Guest Image OS used during the analysis

    Example: Analysis OS: Microsoft Windows XP Professional 5.1 SP3

  • YARA rules used to detect the malware (only if YARA is enabled)

  • Local AV or AV-Suite used to detect the malware (if enabled)

    Examples: Clam, Sophos, VirusTotal

    Note

    Sophos is enabled when the license is installed; there is no further configuration required for integration with the File Protect appliance.

  • Archived file (zip, rar, 7zip, TNEF) analysis containing detected malware

    Example: Data.encoding.zip

Scan results - OS anomalies and changes details and examples
  • Detected malware type

    Example: OS Change Details: (Path/Message/Protocol//Hostname/Qtype/ListenPort, and so on)

Scan results - static file information tools – details and examples
  • Static analysis tools used to detect the malware

    Examples: Exiftool 12345.malware, fe_peinfo.py, fesigcheck