Detonate File - SNDBOX
Deprecated. No available replacement.
- Pack
- SNDBOX
- Tasks
- 12
Inputs
- File — The file to detonate. File is taken from the context.
- Interval — Polling frequency - how often the polling command should run (minutes)
- Timeout — How much time to wait before a timeout occurs (minutes)
Outputs
- SNDBOX.Analysis.ID — Analysis ID
- SNDBOX.Analysis.SampleName — Sample Data, could be a file name or URL
- SNDBOX.Analysis.Status — Analysis Status
- SNDBOX.Analysis.Time — Submitted Time
- SNDBOX.Analysis.Result — Analysis Results
- SNDBOX.Analysis.Errors — Raised errors during sampling
- SNDBOX.Analysis.Link — Analysis Link
- SNDBOX.Analysis.MD5 — MD5 of analysis sample
- SNDBOX.Analysis.SHA1 — SHA1 of analysis sample
- SNDBOX.Analysis.SHA256 — SHA256 of analysis sample
- DBotScore.Vendor — The name of the vendor: SNDBOX
- DBotScore.Indicator — The name of the sample file or URL
- DBotScore.Type — file
- DBotScore.Score — The actual score
- DBotScore.Malicious.Vendor — The name of the vendor: SNDBOX
- DBotScore.Malicious.Detections — The sub analysis detection statuses
- DBotScore.Malicious.SHA1 — The SHA1 of the file
- InfoFile.Name — FileName
- InfoFile.EntryID — The EntryID of the report
- InfoFile.Size — File Size
- InfoFile.Type — File type e.g. "PE"
- InfoFile.Info — Basic information of the file
- InfoFile.Extension — File Extension
- File.Size — File Size
- File.SHA1 — SHA1 hash of the file
- File.SHA256 — SHA256 hash of the file
- File.Name — The sample name
- File.SSDeep — SSDeep hash of the file
- File.EntryID — War-Room Entry ID of the file
- File.Info — Basic information of the file
- File.Type — File type e.g. "PE"
- File MD5 — MD5 hash of the file
- File.Extension — File Extension
Commands used
- sndbox-analysis-info
- sndbox-analysis-submit-sample
- sndbox-download-report