Detonate File - Trend Micro Deep Discovery Analyzer Beta
Detonates a File using the TrendAI™ Deep Discovery™ Analyzer sandbox. Deep Discovery Analyzer(version 6.0.0) supports the following File Types: bat, cell, chm, class, cmd, dll, doc, docx, exe, gul, hta, htm, html, hwp, hwpx, jar, js, jse, jtd, lnk, mov, pdf, ppt, pptx, ps1, pub, rtf, slk, svg, swf, vbe, vbs, wsf, xls, xlsx, xml
- Pack
- TrendMicroDDA
- Tasks
- 10
Inputs
- File — The file to detonate. File is taken from the context.
- interval — Polling frequency - how often the polling command should run (minutes)
- timeout — How much time to wait before a timeout occurs (minutes)
Outputs
- DBotScore.Type — The type of the indicator
- DBotScore.Vendor — Vendor used to calculate the score
- TrendMicroDDA.Submissions.SHA1 — SHA1 of the submission
- TrendMicroDDA.Submissions.RiskLevel — The Risk Level of the sample
- DBotScore.Score — The actual score
- TrendMicroDDA.Submissions.isCompleted — Stating if the detonation was complete or not
- DBotScore.Indicator — The indicator we tested
- TrendMicroDDA.Submissions.status — The status of the sample
- InfoFile.MD5 — MD5 hash of the report file
- InfoFile.SHA1 — SHA1 hash of the report file
- InfoFile.SHA256 — SHA256 hash of the report file
- InfoFile.Name — Report file name
- InfoFile.Type — Report file type e.g. "PE"
- InfoFile.Size — Report file size
- File.Malicious.Vendor — For malicious files, the vendor that made the decision
- File.Malicious.Description — For malicious files, the reason for the vendor to make the decision
- IP.Address — IPs relevant to the submission
Commands used
- trendmicro-dda-check-status
- trendmicro-dda-get-report
- trendmicro-dda-upload-file