Detonate File - Symantec Blue Coat Content and Malware Analysis Beta

Detonates a File using the Symantec Blue Coat Content and Malware Analysis. Advanced Threat Defense supports the following File Types: Microsoft (2003 and earlier) doc, dot, xls, csv, xlt, xlm, ppt, pot, pps Microsoft (2007 and later): docx, docm, dotx, dotm, dotm, xlsx, xlsm, xltx, xltm, xlsb, xla, xlam, iqy, pptx, pptm, potx, ppsx, xml Other: pe32, rtf, pdf, vbs, vbe, ps1, js, lnk, html, bat

Symantec Blue Coat Content and Malware Analysis (Beta) · 9 tasks · 2 inputs · 23 outputs

Details

IDDetonate File - Symantec Blue Coat Content and Malware Analysis Beta
From Version5.0.0
Tasks9

Inputs

  • File — The file to detonate. File is taken from the context.
  • Timeout — How much time to wait before a timeout occurs (seconds).

Outputs

  • DBotScore.Vendor — The name of the vendor.
  • DBotScore.Indicator — The indicator of the score.
  • DBotScore.Type — The type for the score. For example, Email.
  • DBotScore.Score — The actual score.
  • DBotScore.Malicious.Vendor — The name of the vendor.
  • DBotScore.Malicious.Detections — The sub analysis detection statuses.
  • DBotScore.Malicious.SHA1 — The SHA1 of the file.
  • InfoFile.Name — The name of the file.
  • InfoFile.EntryID — The entry ID of the report.
  • InfoFile.Size — The size of the file.
  • InfoFile.Type — The file type. For example, "PE".
  • InfoFile.Info — Basic information of the file.
  • InfoFile.Extension — The extension of the file.
  • File.Size — The size of the file.
  • File.SHA1 — The SHA1 hash of the file.
  • File.SHA256 — The SHA256 hash of the file.
  • File.Name — The name of the sample file.
  • File.SSDeep — The SSDeep hash of the file.
  • File.EntryID — The War Room entry ID of the file.
  • File.Info — Basic information of the file.
  • File.Type — The type of the file. For example, "PE".
  • File MD5 — The MD5 hash of the file.
  • File.Extension — The extension of the file.

Commands used

symantec-cma-get-report symantec-cma-upload-file

Flowchart

yes yes yes Start Start Done Done Is SCMA enabled? Is SCMA enabled? SCMA Get Info - symantec-cma-get-report SCMA Get Info symantec-cma-get-report Is File type supported? Is File type supported? Set File to context - Set Set File to context Set Is there a File to Detonate? Is there a File to Detonate? SCMA Upload File - symantec-cma-upload-file SCMA Upload File symantec-cma-upload-file sleep 5 minutes - Sleep sleep 5 minutes Sleep
id: Detonate File - Symantec Blue Coat Content and Malware Analysis Beta
version: -1
name: Detonate File - Symantec Blue Coat Content and Malware Analysis Beta
fromversion: 5.0.0
description: |-
  Detonates a File using the Symantec Blue Coat Content and Malware Analysis.
  Advanced Threat Defense supports the following File Types:
  Microsoft (2003 and earlier)
  doc, dot, xls, csv, xlt, xlm, ppt, pot, pps

  Microsoft (2007 and later):
  docx, docm, dotx, dotm, dotm, xlsx, xlsm, xltx, xltm, xlsb, xla, xlam, iqy, pptx, pptm, potx, ppsx, xml

  Other:
  pe32, rtf, pdf, vbs, vbe, ps1, js, lnk, html, bat
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 489b704c-bef9-40e7-8aa8-f74cca308a94
    type: start
    task:
      id: 489b704c-bef9-40e7-8aa8-f74cca308a94
      version: -1
      name: ""
      description: '-'
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "7"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "5":
    id: "5"
    taskid: e589b774-3cee-4dff-8e14-788ef3590dfa
    type: title
    task:
      id: e589b774-3cee-4dff-8e14-788ef3590dfa
      version: -1
      name: Done
      description: finished
      type: title
      iscommand: false
      brand: ""
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 70,
          "y": 1945
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "7":
    id: "7"
    taskid: 98905212-e1cc-4563-8dba-c6587d631a0c
    type: condition
    task:
      id: 98905212-e1cc-4563-8dba-c6587d631a0c
      version: -1
      name: Is SCMA enabled?
      description: |
        Verify whether there is a valid instance of Symantec Blue Coat Malware Analysis enabled.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "12"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: Symantec Blue Coat Content and Malware Analysis
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
                accessor: brand
            iscontext: true
    view: |-
      {
        "position": {
          "x": 50,
          "y": 195
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "9":
    id: "9"
    taskid: a2d1eb58-d074-4fe2-8d96-f7f04a9a4f77
    type: regular
    task:
      id: a2d1eb58-d074-4fe2-8d96-f7f04a9a4f77
      version: -1
      name: SCMA Get Info
      description: Retrieve detonation report
      script: '|||symantec-cma-get-report'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      task_id:
        complex:
          root: Symantec
          accessor: Analysis.ID
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 387.5,
          "y": 1225
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "10":
    id: "10"
    taskid: c791a71f-f8c8-48ae-83cc-f761f2f98958
    type: condition
    task:
      id: c791a71f-f8c8-48ae-83cc-f761f2f98958
      version: -1
      name: Is File type supported?
      description: Check if the file type is supported.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "15"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: File
                filters:
                - - operator: match
                    left:
                      value:
                        simple: File.Type
                      iscontext: true
                    right:
                      value:
                        simple: .*(?:DOC|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b
                    ignorecase: true
                  - operator: match
                    left:
                      value:
                        simple: File.Extension
                      iscontext: true
                    right:
                      value:
                        simple: .*(?:DOC|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b
                    ignorecase: true
                  - operator: match
                    left:
                      value:
                        simple: File.Info
                      iscontext: true
                    right:
                      value:
                        simple: .*(?:DOC|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b
                    ignorecase: true
                accessor: EntryID
            iscontext: true
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 275,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "11":
    id: "11"
    taskid: 0067c0b3-3758-4016-813d-a7fb2e73c658
    type: regular
    task:
      id: 0067c0b3-3758-4016-813d-a7fb2e73c658
      version: -1
      name: Set File to context
      description: Set the file object into context.
      scriptName: Set
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "10"
    scriptarguments:
      append: {}
      key:
        simple: File
      value:
        complex:
          root: inputs.File
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 275,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "12":
    id: "12"
    taskid: d1b997a7-0a10-4b0f-8365-a9e7a94870a9
    type: condition
    task:
      id: d1b997a7-0a10-4b0f-8365-a9e7a94870a9
      version: -1
      name: Is there a File to Detonate?
      description: Checks that a file exists in the playbook’s input.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "11"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              simple: inputs.File
            iscontext: true
    view: |-
      {
        "position": {
          "x": 162.5,
          "y": 370
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "15":
    id: "15"
    taskid: e0afa08b-1e26-4a5f-82f7-395c0fb8829b
    type: regular
    task:
      id: e0afa08b-1e26-4a5f-82f7-395c0fb8829b
      version: -1
      name: SCMA Upload File
      description: Submit a file for analysis.
      script: '|||symantec-cma-upload-file'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "16"
    scriptarguments:
      file_id:
        complex:
          root: inputs.File
          filters:
          - - operator: match
              left:
                value:
                  simple: inputs.File.Info
                iscontext: true
              right:
                value:
                  simple: .*(?:DOC|EML|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b
            - operator: match
              left:
                value:
                  simple: inputs.File.Type
                iscontext: true
              right:
                value:
                  simple: .*(?:DOC|EML|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b
              ignorecase: true
            - operator: match
              left:
                value:
                  simple: inputs.File.Extension
                iscontext: true
              right:
                value:
                  simple: .*(?:DOC|EML|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b
              ignorecase: true
          accessor: EntryID
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 387.5,
          "y": 895
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
  "16":
    id: "16"
    taskid: 35997039-274c-4c2e-849f-2d6d3ab3f261
    type: regular
    task:
      id: 35997039-274c-4c2e-849f-2d6d3ab3f261
      version: -1
      name: sleep 5 minutes
      description: Sleep for X seconds.
      scriptName: Sleep
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      seconds:
        complex:
          root: inputs.Timeout
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 390,
          "y": 1050
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 1960,
        "width": 720,
        "x": 50,
        "y": 50
      }
    }
  }
inputs:
- key: File
  value:
    complex:
      root: File
  required: false
  description: The file to detonate. File is taken from the context.
- key: Timeout
  value:
    simple: "300"
  required: false
  description: How much time to wait before a timeout occurs (seconds).
outputs:
- contextPath: DBotScore.Vendor
  description: The name of the vendor.
  type: string
- contextPath: DBotScore.Indicator
  description: The indicator of the score.
  type: string
- contextPath: DBotScore.Type
  description: The type for the score. For example, Email.
  type: string
- contextPath: DBotScore.Score
  description: The actual score.
  type: number
- contextPath: DBotScore.Malicious.Vendor
  description: The name of the vendor.
  type: string
- contextPath: DBotScore.Malicious.Detections
  description: The sub analysis detection statuses.
  type: string
- contextPath: DBotScore.Malicious.SHA1
  description: The SHA1 of the file.
  type: string
- contextPath: InfoFile.Name
  description: The name of the file.
  type: string
- contextPath: InfoFile.EntryID
  description: The entry ID of the report.
  type: string
- contextPath: InfoFile.Size
  description: The size of the file.
  type: number
- contextPath: InfoFile.Type
  description: The file type. For example, "PE".
  type: string
- contextPath: InfoFile.Info
  description: Basic information of the file.
  type: string
- contextPath: InfoFile.Extension
  description: The extension of the file.
  type: string
- contextPath: File.Size
  description: The size of the file.
  type: number
- contextPath: File.SHA1
  description: The SHA1 hash of the file.
  type: string
- contextPath: File.SHA256
  description: The SHA256 hash of the file.
  type: string
- contextPath: File.Name
  description: The name of the sample file.
  type: string
- contextPath: File.SSDeep
  description: The SSDeep hash of the file.
  type: string
- contextPath: File.EntryID
  description: The War Room entry ID of the file.
  type: string
- contextPath: File.Info
  description: Basic information of the file.
  type: string
- contextPath: File.Type
  description: The type of the file. For example, "PE".
  type: string
- contextPath: File MD5
  description: The MD5 hash of the file.
  type: string
- contextPath: File.Extension
  description: The extension of the file.
  type: string
tests:
- no test