Detonate URL - Symantec Blue Coat Content and Malware Analysis Beta
Detonates a File using the Symantec Blue Coat Content and Malware Analysis. Advanced Threat Defense supports the following File Types: Microsoft (2003 and earlier) doc, dot, xls, csv, xlt, xlm, ppt, pot, pps Microsoft (2007 and later): docx, docm, dotx, dotm, dotm, xlsx, xlsm, xltx, xltm, xlsb, xla, xlam, iqy, pptx, pptm, potx, ppsx, xml Other: pe32, rtf, pdf, vbs, vbe, ps1, js, lnk, html, bat
Symantec Blue Coat Content and Malware Analysis (Beta) · 6 tasks · 2 inputs · 23 outputs
Details
| ID | Detonate URL - Symantec Blue Coat Content and Malware Analysis Beta |
|---|---|
| From Version | 5.0.0 |
| Tasks | 6 |
Inputs
URL— The URL to detonate.Timeout— How much time to wait before a timeout occurs (seconds).
Outputs
DBotScore.Vendor— The name of the vendor.DBotScore.Indicator— The indicator of the score.DBotScore.Type— The type for the score. For example, Email.DBotScore.Score— The actual score.DBotScore.Malicious.Vendor— The name of the vendor.DBotScore.Malicious.Detections— The sub analysis detection statuses.DBotScore.Malicious.SHA1— The SHA1 of the file.InfoFile.Name— The name of the file.InfoFile.EntryID— The entry ID of the report.InfoFile.Size— The size of the file.InfoFile.Type— The type of the file. For example, "PE".InfoFile.Info— Basic information of the file.InfoFile.Extension— The extension of the file.File.Size— The size of the file.File.SHA1— The SHA1 hash of the file.File.SHA256— The SHA256 hash of the file.File.Name— The name of the sample file.File.SSDeep— The SSDeep hash of the file.File.EntryID— The War Room entry ID of the file.File.Info— Basic information of the file.File.Type— The type of the file. For example, "PE".File MD5— The MD5 hash of the file.File.Extension— The extension of the file.
Commands used
symantec-cma-get-report
symantec-cma-upload-url
Flowchart
id: Detonate URL - Symantec Blue Coat Content and Malware Analysis Beta version: -1 name: Detonate URL - Symantec Blue Coat Content and Malware Analysis Beta fromversion: 5.0.0 description: |- Detonates a File using the Symantec Blue Coat Content and Malware Analysis. Advanced Threat Defense supports the following File Types: Microsoft (2003 and earlier) doc, dot, xls, csv, xlt, xlm, ppt, pot, pps Microsoft (2007 and later): docx, docm, dotx, dotm, dotm, xlsx, xlsm, xltx, xltm, xlsb, xla, xlam, iqy, pptx, pptm, potx, ppsx, xml Other: pe32, rtf, pdf, vbs, vbe, ps1, js, lnk, html, bat starttaskid: "0" tasks: "0": id: "0" taskid: 489b704c-bef9-40e7-8aa8-f74cca308a94 type: start task: id: 489b704c-bef9-40e7-8aa8-f74cca308a94 version: -1 name: "" description: '-' iscommand: false brand: "" nexttasks: '#none#': - "7" separatecontext: false view: |- { "position": { "x": 50, "y": 50 } } note: false timertriggers: [] ignoreworker: false "5": id: "5" taskid: e589b774-3cee-4dff-8e14-788ef3590dfa type: title task: id: e589b774-3cee-4dff-8e14-788ef3590dfa version: -1 name: Done description: finished type: title iscommand: false brand: "" separatecontext: false view: |- { "position": { "x": 70, "y": 1945 } } note: false timertriggers: [] ignoreworker: false "7": id: "7" taskid: 98905212-e1cc-4563-8dba-c6587d631a0c type: condition task: id: 98905212-e1cc-4563-8dba-c6587d631a0c version: -1 name: Is SCMA enabled? description: | Verify whether there is a valid instance of Symantec Blue Coat Malware Analysis enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "5" "yes": - "15" separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: Symantec Blue Coat Content and Malware Analysis - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active accessor: brand iscontext: true view: |- { "position": { "x": 50, "y": 335 } } note: false timertriggers: [] ignoreworker: false "9": id: "9" taskid: a2d1eb58-d074-4fe2-8d96-f7f04a9a4f77 type: regular task: id: a2d1eb58-d074-4fe2-8d96-f7f04a9a4f77 version: -1 name: SCMA Get Info description: Retrieves a detonation report. script: '|||symantec-cma-get-report' type: regular iscommand: true brand: "" nexttasks: '#none#': - "5" scriptarguments: task_id: complex: root: Symantec accessor: Analysis.ID separatecontext: false view: |- { "position": { "x": 387.5, "y": 1225 } } note: false timertriggers: [] ignoreworker: false "15": id: "15" taskid: 7d61b459-e783-4d52-8c96-98cfb83c0bb5 type: regular task: id: 7d61b459-e783-4d52-8c96-98cfb83c0bb5 version: -1 name: SCMA Detonate URL description: Submit a URL for analysis. script: '|||symantec-cma-upload-url' type: regular iscommand: true brand: "" nexttasks: '#none#': - "16" scriptarguments: url: complex: root: inputs.URL separatecontext: false view: |- { "position": { "x": 387.5, "y": 895 } } note: false timertriggers: [] ignoreworker: false "16": id: "16" taskid: 35997039-274c-4c2e-849f-2d6d3ab3f261 type: regular task: id: 35997039-274c-4c2e-849f-2d6d3ab3f261 version: -1 name: sleep 5 minutes description: Sleep for X seconds. scriptName: Sleep type: regular iscommand: false brand: "" nexttasks: '#none#': - "9" scriptarguments: seconds: complex: root: inputs.Timeout separatecontext: false view: |- { "position": { "x": 390, "y": 1050 } } note: false timertriggers: [] ignoreworker: false view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 1960, "width": 720, "x": 50, "y": 50 } } } inputs: - key: URL value: {} required: false description: The URL to detonate. - key: Timeout value: simple: "300" required: false description: How much time to wait before a timeout occurs (seconds). outputs: - contextPath: DBotScore.Vendor description: The name of the vendor. type: string - contextPath: DBotScore.Indicator description: The indicator of the score. type: string - contextPath: DBotScore.Type description: The type for the score. For example, Email. type: string - contextPath: DBotScore.Score description: The actual score. type: number - contextPath: DBotScore.Malicious.Vendor description: The name of the vendor. type: string - contextPath: DBotScore.Malicious.Detections description: The sub analysis detection statuses. type: string - contextPath: DBotScore.Malicious.SHA1 description: The SHA1 of the file. type: string - contextPath: InfoFile.Name description: The name of the file. type: string - contextPath: InfoFile.EntryID description: The entry ID of the report. type: string - contextPath: InfoFile.Size description: The size of the file. type: number - contextPath: InfoFile.Type description: The type of the file. For example, "PE". type: string - contextPath: InfoFile.Info description: Basic information of the file. type: string - contextPath: InfoFile.Extension description: The extension of the file. type: string - contextPath: File.Size description: The size of the file. type: number - contextPath: File.SHA1 description: The SHA1 hash of the file. type: string - contextPath: File.SHA256 description: The SHA256 hash of the file. type: string - contextPath: File.Name description: The name of the sample file. type: string - contextPath: File.SSDeep description: The SSDeep hash of the file. type: string - contextPath: File.EntryID description: The War Room entry ID of the file. type: string - contextPath: File.Info description: Basic information of the file. type: string - contextPath: File.Type description: The type of the file. For example, "PE". type: string - contextPath: File MD5 description: The MD5 hash of the file. type: string - contextPath: File.Extension description: The extension of the file. type: string tests: - No tests