Detonate File From URL - WildFire
Deprecated. Use Detonate File From URL - WildFire v2 instead.
- Pack
- Palo_Alto_Networks_WildFire
- Tasks
- 8
Inputs
- FileURL — URL of the web file to detonate. The FileUrl is taken from the context.
- Interval — Duration for executing the pooling (in minutes)
- Timeout — The duration after which to stop pooling and to resume the playbook (in minutes)
- ReportFileType — The resource type to download. Default is pdf. xml is also possible.
Outputs
- DBotScore — The DBotScore object.
- DBotScore.Score — The actual score.
- File.Size — File size.
- File.MD5 — MD5 hash of the file.
- File.SHA1 — SHA1 hash of the file.
- File.Type — File type e.g. "PE".
- File.SHA256 — SHA256 hash of the file.
- File.EntryID — The Entry ID of the sample.
- File.Malicious.Vendor — For malicious files, the vendor that made the decision.
- File.Name — Filename.
- File.Malicious.Description — For malicious files, the reason for the vendor to make the decision.
- DBotScore.Indicator — The indicator we tested.
- DBotScore.Type — The type of the indicator.
- DBotScore.Vendor — Vendor used to calculate the score.
- IP.Address — IP's relevant to the sample.
- File — The File object.
- InfoFile — The report file object.
- InfoFile.EntryID — The EntryID of the report file.
- InfoFile.Extension — The extension of the report file.
- InfoFile.Name — The name of the report file.
- InfoFile.Info — The info of the report file.
- InfoFile.Size — The size of the report file.
- InfoFile.Type — The type of the report file.
- File.Malicious — The malicious object.
- WildFire.Report — The submission object.
- WildFire.Report.MD5 — MD5 of the submission.
- WildFire.Report.SHA256 — SHA256 of the submission.
- WildFire.Report.FileType — The type of the submission.
- WildFire.Report.Status — The status of the submission.
- WildFire.Report.Size — The size of the submission.
Commands used
- wildfire-report
- wildfire-upload-file-url