Detonate URL - Trend Micro Deep Discovery Analyzer Beta
Detonates a URL using the TrendAI™ Deep Discovery™ Analyzer sandbox.
- Pack
- TrendMicroDDA
- Tasks
- 8
Inputs
- URL — URL to detonate.
- interval — Polling frequency - how often the polling command should run (minutes)
- timeput — How much time to wait before a timeout occurs (minutes)
Outputs
- InfoFile.Type — Report file type e.g. "PE"
- InfoFile.SHA256 — SHA256 hash of the report file
- TrendMicroDDA.Submissions.SHA1 — The SHA1 of the submission
- TrendMicroDDA.Submissions.RiskLevel — The Risk Level of the sample
- DBotScore.Score — The actual score
- TrendMicroDDA.Submissions.isCompleted — Stating if the detonation was complete or not
- DBotScore.Indicator — The indicator we tested
- TrendMicroDDA.Submissions.status — The status of the sample
- DBotScore.Type — The type of the indicator
- DBotScore.Vendor — Vendor used to calculate the score
- InfoFile.MD5 — MD5 hash of the report file
- InfoFile.Name — Report file name
- InfoFile.Size — Report file size
- File.Malicious.Vendor — For malicious files, the vendor that made the decision
- File.Malicious.Description — For malicious files, the reason for the vendor to make the decision
- IP.Address — IPs relevant to the submission
- Domain.Name — Domains relevant to the submission
- URL.Data — URL data
- File.MD5 — MD5 hash of the file
- File.SHA1 — SHA1 hash of the file
- File.SHA256 — SHA256 hash of the file
- File.Size — File size
- File.Name — File name
Commands used
- trendmicro-dda-check-status
- trendmicro-dda-get-report
- trendmicro-dda-upload-url