Use the File Analysis page to view and drill into details about malicious files.
.png)
The following columns are included on the page:
ID—The Malware Analysis ID number.
Malware—The type of malware detected: Malware.Binary, Exploit, Trojan, Worm, Infection Match, and so on.
File Type—A specific file type such as EXE, PDF, DOC, PPT, XLS, GIF, JPG, SWF, MOV, QT, MP3, MP3, ASF, ZIP, DLL, or UNK (UNKNOWN).
Name—Name of the file determined to be malicious; for example: menu4.swf.
Md5sum—The message-digest algorithm5 checksum derived from a cryptographic hash function that produces a 128-bit (16-byte) hash value used to check data integrity, expressed as a 32-digit hexadecimal number in the File Protect appliance.
Submitted—The date and time at which the file scan was submitted for analysis.
Status—The status of the file scan analysis.
Start—The date and time at which the file scan was submitted for analysis.
Complete—The date and time the malware analysis was completed.
Click a link in the File Name column of the Show Quarantined Files page.
In the File Analysis page, click the orange arrow to expand the file details.
.png)
For compressed (archive) files types (RAR and ZIP), there are two sets of arrows. Click both arrows to see scan results for the files within the archive file.
.png)
Understanding malicious file results
The status of compressed file types matches the status of the contained file with the most severe status. For example, a ZIP file contains one file with the status Success and one file with the status Submit Disabled. Because Submit Disabled is the more severe status, the ZIP file will also be marked as Submit Disabled. An exception to this is when the most severe status for a contained file is Duplicate; in this case, the ZIP or RAR file will be marked as Success, not Duplicate.
Red, underlined text in the tables and hierarchical pages indicate active hyperlinks. The results details are always displayed in three categories: Event Details, OS Changes Details, and Additional Information Details (Static File Analysis Tools). Each link displays detailed forensics information about malware behavior and OS changes caused by the attack.
.png)
Scan Results - event details and examples
Detected malware type
Example: Malware: Malware.Binary.Pdf
File type of the malware
Example: SWF
Whether suspicious behavior was observed or confirmed
Example: Suspicious Behavior Observed
Application type used to analyze the malware
Example: Adobe PDF 7.0
Callback attempts captured by the VM, including any communication attempts made by the malware
Example: VM Capture pcap < 24> bytes (text link)
Guest Image OS used during the analysis
Example: Analysis OS: Microsoft Windows XP Professional 5.1 SP3
YARA rules used to detect the malware (only if YARA is enabled)
Local AV or AV-Suite used to detect the malware (if enabled)
Examples: Clam, Sophos, VirusTotal
Note
Sophos is enabled when the license is installed; there is no further configuration required for integration with the File Protect appliance.
Archived file (zip, rar, 7zip, TNEF) analysis containing detected malware
Example: Data.encoding.zip
Scan results - OS anomalies and changes details and examples
Detected malware type
Example: OS Change Details: (Path/Message/Protocol//Hostname/Qtype/ListenPort, and so on)
Scan results - static file information tools – details and examples
Static analysis tools used to detect the malware
Examples: Exiftool 12345.malware, fe_peinfo.py, fesigcheck