Detonate File - Symantec Blue Coat Content and Malware Analysis Beta
Detonates a File using the Symantec Blue Coat Content and Malware Analysis. Advanced Threat Defense supports the following File Types: Microsoft (2003 and earlier) doc, dot, xls, csv, xlt, xlm, ppt, pot, pps Microsoft (2007 and later): docx, docm, dotx, dotm, dotm, xlsx, xlsm, xltx, xltm, xlsb, xla, xlam, iqy, pptx, pptm, potx, ppsx, xml Other: pe32, rtf, pdf, vbs, vbe, ps1, js, lnk, html, bat
Symantec Blue Coat Content and Malware Analysis (Beta) · 9 tasks · 2 inputs · 23 outputs
Details
| ID | Detonate File - Symantec Blue Coat Content and Malware Analysis Beta |
|---|---|
| From Version | 5.0.0 |
| Tasks | 9 |
Inputs
File— The file to detonate. File is taken from the context.Timeout— How much time to wait before a timeout occurs (seconds).
Outputs
DBotScore.Vendor— The name of the vendor.DBotScore.Indicator— The indicator of the score.DBotScore.Type— The type for the score. For example, Email.DBotScore.Score— The actual score.DBotScore.Malicious.Vendor— The name of the vendor.DBotScore.Malicious.Detections— The sub analysis detection statuses.DBotScore.Malicious.SHA1— The SHA1 of the file.InfoFile.Name— The name of the file.InfoFile.EntryID— The entry ID of the report.InfoFile.Size— The size of the file.InfoFile.Type— The file type. For example, "PE".InfoFile.Info— Basic information of the file.InfoFile.Extension— The extension of the file.File.Size— The size of the file.File.SHA1— The SHA1 hash of the file.File.SHA256— The SHA256 hash of the file.File.Name— The name of the sample file.File.SSDeep— The SSDeep hash of the file.File.EntryID— The War Room entry ID of the file.File.Info— Basic information of the file.File.Type— The type of the file. For example, "PE".File MD5— The MD5 hash of the file.File.Extension— The extension of the file.
Commands used
symantec-cma-get-report
symantec-cma-upload-file
Flowchart
id: Detonate File - Symantec Blue Coat Content and Malware Analysis Beta version: -1 name: Detonate File - Symantec Blue Coat Content and Malware Analysis Beta fromversion: 5.0.0 description: |- Detonates a File using the Symantec Blue Coat Content and Malware Analysis. Advanced Threat Defense supports the following File Types: Microsoft (2003 and earlier) doc, dot, xls, csv, xlt, xlm, ppt, pot, pps Microsoft (2007 and later): docx, docm, dotx, dotm, dotm, xlsx, xlsm, xltx, xltm, xlsb, xla, xlam, iqy, pptx, pptm, potx, ppsx, xml Other: pe32, rtf, pdf, vbs, vbe, ps1, js, lnk, html, bat starttaskid: "0" tasks: "0": id: "0" taskid: 489b704c-bef9-40e7-8aa8-f74cca308a94 type: start task: id: 489b704c-bef9-40e7-8aa8-f74cca308a94 version: -1 name: "" description: '-' iscommand: false brand: "" nexttasks: '#none#': - "7" separatecontext: false view: |- { "position": { "x": 50, "y": 50 } } note: false timertriggers: [] ignoreworker: false "5": id: "5" taskid: e589b774-3cee-4dff-8e14-788ef3590dfa type: title task: id: e589b774-3cee-4dff-8e14-788ef3590dfa version: -1 name: Done description: finished type: title iscommand: false brand: "" separatecontext: false view: |- { "position": { "x": 70, "y": 1945 } } note: false timertriggers: [] ignoreworker: false "7": id: "7" taskid: 98905212-e1cc-4563-8dba-c6587d631a0c type: condition task: id: 98905212-e1cc-4563-8dba-c6587d631a0c version: -1 name: Is SCMA enabled? description: | Verify whether there is a valid instance of Symantec Blue Coat Malware Analysis enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "5" "yes": - "12" separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: Symantec Blue Coat Content and Malware Analysis - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active accessor: brand iscontext: true view: |- { "position": { "x": 50, "y": 195 } } note: false timertriggers: [] ignoreworker: false "9": id: "9" taskid: a2d1eb58-d074-4fe2-8d96-f7f04a9a4f77 type: regular task: id: a2d1eb58-d074-4fe2-8d96-f7f04a9a4f77 version: -1 name: SCMA Get Info description: Retrieve detonation report script: '|||symantec-cma-get-report' type: regular iscommand: true brand: "" nexttasks: '#none#': - "5" scriptarguments: task_id: complex: root: Symantec accessor: Analysis.ID separatecontext: false view: |- { "position": { "x": 387.5, "y": 1225 } } note: false timertriggers: [] ignoreworker: false "10": id: "10" taskid: c791a71f-f8c8-48ae-83cc-f761f2f98958 type: condition task: id: c791a71f-f8c8-48ae-83cc-f761f2f98958 version: -1 name: Is File type supported? description: Check if the file type is supported. type: condition iscommand: false brand: "" nexttasks: '#default#': - "5" "yes": - "15" separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: complex: root: File filters: - - operator: match left: value: simple: File.Type iscontext: true right: value: simple: .*(?:DOC|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b ignorecase: true - operator: match left: value: simple: File.Extension iscontext: true right: value: simple: .*(?:DOC|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b ignorecase: true - operator: match left: value: simple: File.Info iscontext: true right: value: simple: .*(?:DOC|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b ignorecase: true accessor: EntryID iscontext: true ignorecase: true view: |- { "position": { "x": 275, "y": 720 } } note: false timertriggers: [] ignoreworker: false "11": id: "11" taskid: 0067c0b3-3758-4016-813d-a7fb2e73c658 type: regular task: id: 0067c0b3-3758-4016-813d-a7fb2e73c658 version: -1 name: Set File to context description: Set the file object into context. scriptName: Set type: regular iscommand: false brand: "" nexttasks: '#none#': - "10" scriptarguments: append: {} key: simple: File value: complex: root: inputs.File separatecontext: false view: |- { "position": { "x": 275, "y": 545 } } note: false timertriggers: [] ignoreworker: false "12": id: "12" taskid: d1b997a7-0a10-4b0f-8365-a9e7a94870a9 type: condition task: id: d1b997a7-0a10-4b0f-8365-a9e7a94870a9 version: -1 name: Is there a File to Detonate? description: Checks that a file exists in the playbook’s input. type: condition iscommand: false brand: "" nexttasks: '#default#': - "5" "yes": - "11" separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: simple: inputs.File iscontext: true view: |- { "position": { "x": 162.5, "y": 370 } } note: false timertriggers: [] ignoreworker: false "15": id: "15" taskid: e0afa08b-1e26-4a5f-82f7-395c0fb8829b type: regular task: id: e0afa08b-1e26-4a5f-82f7-395c0fb8829b version: -1 name: SCMA Upload File description: Submit a file for analysis. script: '|||symantec-cma-upload-file' type: regular iscommand: true brand: "" nexttasks: '#none#': - "16" scriptarguments: file_id: complex: root: inputs.File filters: - - operator: match left: value: simple: inputs.File.Info iscontext: true right: value: simple: .*(?:DOC|EML|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b - operator: match left: value: simple: inputs.File.Type iscontext: true right: value: simple: .*(?:DOC|EML|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b ignorecase: true - operator: match left: value: simple: inputs.File.Extension iscontext: true right: value: simple: .*(?:DOC|EML|MSG|DOT|XLS|CSV|XLT|XLM|PPT|POT|PPS|DOCX|DOCM|DOTX|DOTM|DOTM|XLSX|XLSM|XLTX|XLTM|XLSB|XLA|XLAM|IQY|PPTX|PPTM|POTX|PPSX|XML|PE32|RTF|PDF|VBS|VBE|PS1|JS|LNK|HTML|BAT)\b ignorecase: true accessor: EntryID separatecontext: false view: |- { "position": { "x": 387.5, "y": 895 } } note: false timertriggers: [] ignoreworker: false "16": id: "16" taskid: 35997039-274c-4c2e-849f-2d6d3ab3f261 type: regular task: id: 35997039-274c-4c2e-849f-2d6d3ab3f261 version: -1 name: sleep 5 minutes description: Sleep for X seconds. scriptName: Sleep type: regular iscommand: false brand: "" nexttasks: '#none#': - "9" scriptarguments: seconds: complex: root: inputs.Timeout separatecontext: false view: |- { "position": { "x": 390, "y": 1050 } } note: false timertriggers: [] ignoreworker: false view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 1960, "width": 720, "x": 50, "y": 50 } } } inputs: - key: File value: complex: root: File required: false description: The file to detonate. File is taken from the context. - key: Timeout value: simple: "300" required: false description: How much time to wait before a timeout occurs (seconds). outputs: - contextPath: DBotScore.Vendor description: The name of the vendor. type: string - contextPath: DBotScore.Indicator description: The indicator of the score. type: string - contextPath: DBotScore.Type description: The type for the score. For example, Email. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The name of the vendor. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses. type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file. type: string - contextPath: InfoFile.Name description: The name of the file. type: string - contextPath: InfoFile.EntryID description: The entry ID of the report. type: string - contextPath: InfoFile.Size description: The size of the file. type: number - contextPath: InfoFile.Type description: The file type. For example, "PE". type: string - contextPath: InfoFile.Info description: Basic information of the file. type: string - contextPath: InfoFile.Extension description: The extension of the file. type: string - contextPath: File.Size description: The size of the file. type: number - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Name description: The name of the sample file. type: string - contextPath: File.SSDeep description: The SSDeep hash of the file. type: string - contextPath: File.EntryID description: The War Room entry ID of the file. type: string - contextPath: File.Info description: Basic information of the file. type: string - contextPath: File.Type description: The type of the file. For example, "PE". type: string - contextPath: File MD5 description: The MD5 hash of the file. type: string - contextPath: File.Extension description: The extension of the file. type: string tests: - no test