Detonate URL - WildFire-v2 Deprecated

Deprecated. Use Detonate URL - WildFire v2.2 instead.

WildFire by Palo Alto Networks · 10 tasks · 4 inputs · 30 outputs

Details

IDDetonate URL - WildFire-v2
From Version5.0.0
Tasks10

README

Detonates a webpage or a remote file using the WildFire integration. This playbook returns relevant reports to the War Room and file reputations to the context data.

The detonation supports the following file types:
APK, JAR, DOC, DOCX, RTF, OOXLS, XLSX, PPT, PPTX, XML, PE32, PDF, DMG, PKG, RAR, 7Z.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • GenericPolling

Integrations

  • WildFire-v2

Scripts

This playbook does not use any scripts.

Commands

  • wildfire-report
  • wildfire-upload-file-url
  • wildfire-upload-url

Playbook Inputs


Name Description Default Value Source Required
URL The URL of the webpage or the file URL to detonate. The URL is taken from the context. Data URL Optional
Interval The duration for executing the pooling (in minutes). 1 - Optional
Timeout The duration after which to stop pooling and to resume the playbook (in minutes). 15 - Optional
ReportFileType The resource type to download. The default is pdf. XML is also possible. - - Optional

Playbook Outputs


Path Description Type
DBotScore The DBotScore object. unknown
DBotScore.Score The actual score. number
File.Size The file size. number
File.MD5 The MD5 hash of the file. string
File.SHA1 The SHA1 hash of the file. string
File.Type The file type. For example, “PE”. string
File.SHA256 Thas SHA256 hash of the file. string
File.EntryID The entry ID of the sample. string
File.Malicious.Vendor The vendor that made the decision that the file is malicious. string
File.Name The filename string
File.Malicious.Description The reason for the vendor to make the decision that the file is malicious. string
DBotScore.Indicator The indicator that was tested. string
DBotScore.Type The type of the indicator. string
DBotScore.Vendor The vendor used to calculate the score. string
IP.Address The IP addresses’s relevant to the sample. string
File The file object. unknown
InfoFile The report file object. unknown
InfoFile.EntryID The EntryID of the report file. string
InfoFile.Extension The extension of the report file. string
InfoFile.Name The name of the report file. string
InfoFile.Info The info of the report file. string
InfoFile.Size The size of the report file. number
InfoFile.Type The type of the report file. string
File.Malicious The malicious object. unknown
WildFire.Report The submission object. unknown
WildFire.Report.MD5 The MD5 hash of the submission. string
WildFire.Report.SHA256 The SHA256 hash of the submission. string
WildFire.Report.FileType The type of the submission. string
WildFire.Report.Status The status of the submission. string
WildFire.Report.Size The size of the submission. number
WildFire.Report.detection_reasons The detection reasons object. unknown
WildFire.Report.detection_reasons.description Reason for the detection verdict. string
WildFire.Report.detection_reasons.name Name of the detection. string
WildFire.Report.detection_reasons.type Type of the detection. string
WildFire.Report.detection_reasons.verdict Verdict of the detection. string
WildFire.Report.detection_reasons.artifacts Artifacts for the detection. string
WildFire.Report.iocs Associated IOCs. string

Playbook Image


Detonate_URL_WildFire-v2

Inputs

  • URL — URL of the webpage or file url to detonate. The URL is taken from the context.
  • Interval — Duration for executing the pooling (in minutes)
  • Timeout — The duration after which to stop pooling and to resume the playbook (in minutes)
  • ReportFileType — The resource type to download. Default is pdf. xml is also possible.

Outputs

  • DBotScore — The DBotScore object.
  • DBotScore.Score — The actual score.
  • File.Size — File size.
  • File.MD5 — MD5 hash of the file.
  • File.SHA1 — SHA1 hash of the file.
  • File.Type — File type e.g. "PE".
  • File.SHA256 — SHA256 hash of the file.
  • File.EntryID — The Entry ID of the sample.
  • File.Malicious.Vendor — For malicious files, the vendor that made the decision.
  • File.Name — Filename.
  • File.Malicious.Description — For malicious files, the reason for the vendor to make the decision.
  • DBotScore.Indicator — The indicator we tested.
  • DBotScore.Type — The type of the indicator.
  • DBotScore.Vendor — Vendor used to calculate the score.
  • IP.Address — IP's relevant to the sample.
  • File — The File object.
  • InfoFile — The report file object.
  • InfoFile.EntryID — The EntryID of the report file.
  • InfoFile.Extension — The extension of the report file.
  • InfoFile.Name — The name of the report file.
  • InfoFile.Info — The info of the report file.
  • InfoFile.Size — The size of the report file.
  • InfoFile.Type — The type of the report file.
  • File.Malicious — The malicious object.
  • WildFire.Report — The submission object.
  • WildFire.Report.MD5 — MD5 of the submission.
  • WildFire.Report.SHA256 — SHA256 of the submission.
  • WildFire.Report.FileType — The type of the submission.
  • WildFire.Report.Status — The status of the submission.
  • WildFire.Report.Size — The size of the submission.

Commands used

wildfire-report wildfire-upload-file-url wildfire-upload-url

Flowchart

yes yes yes yes Start Start WildFire Upload File URL - wildfire-upload-file-url WildFire Upload File URL wildfire-upload-file-url GenericPolling - GenericPolling GenericPolling GenericPolling Done Done Is there a URL to detonate? Is there a URL to detonate? Is WildFire-v2 enabled? Is WildFire-v2 enabled? WildFire Get Report - wildfire-report WildFire Get Report wildfire-report WildFire Upload URL - wildfire-upload-url WildFire Upload URL wildfire-upload-url Was file url submission successful? Was file url submission s... Was upload finished successfully? Was upload finished succe...
id: Detonate URL - WildFire v2.1
version: -1
name: Detonate URL - WildFire v2.1
fromversion: 5.0.0
description: |-
  Deprecated. Use Detonate URL - WildFire v2.2 instead.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 1b1b3125-d39b-4930-89fc-c9ff36ac559c
    type: start
    task:
      id: 1b1b3125-d39b-4930-89fc-c9ff36ac559c
      version: -1
      name: ""
      description: ""
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "7"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 265,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "1":
    id: "1"
    taskid: cc1e5c47-51c1-4cdb-8fb6-275c1f1fd8e7
    type: regular
    task:
      id: cc1e5c47-51c1-4cdb-8fb6-275c1f1fd8e7
      version: -1
      name: WildFire Upload File URL
      description: Uploads the URL of a remote file to WildFire for analysis.
      script: '|||wildfire-upload-file-url'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "17"
    scriptarguments:
      upload:
        complex:
          root: inputs.URL
    continueonerror: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 490,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "2":
    id: "2"
    taskid: 2ba5921c-3f35-4bef-8a5d-4965d1a211eb
    type: playbook
    task:
      id: 2ba5921c-3f35-4bef-8a5d-4965d1a211eb
      version: -1
      name: GenericPolling
      description: |-
        Use this playbook as a sub-playbook to block execution of the master playbook until a remote action is complete.
        This playbook implements polling by continuously running the command in Step \#2 until the operation completes.
        The remote action should have the following structure:

        1. Initiate the operation.
        2. Poll to check if the operation completed.
        3. (optional) Get the results of the operation.
      playbookName: GenericPolling
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      AdditionalPollingCommandArgNames: {}
      AdditionalPollingCommandArgValues: {}
      Ids:
        complex:
          root: WildFire
          accessor: Report.URL
      Interval:
        complex:
          root: inputs.Interval
      PollingCommandArgName:
        simple: url
      PollingCommandName:
        simple: wildfire-report
      Timeout:
        complex:
          root: inputs.Timeout
      dt:
        simple: WildFire.Report(val.Status != 'Success').URL
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 387.5,
          "y": 1770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "5":
    id: "5"
    taskid: 74b54d79-9464-4112-824b-e836cbce4dbc
    type: title
    task:
      id: 74b54d79-9464-4112-824b-e836cbce4dbc
      version: -1
      name: Done
      description: ""
      type: title
      iscommand: false
      brand: ""
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 2120
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "6":
    id: "6"
    taskid: d4449595-5c9b-4dfd-8960-35f1d1dc309b
    type: condition
    task:
      id: d4449595-5c9b-4dfd-8960-35f1d1dc309b
      version: -1
      name: Is there a URL to detonate?
      description: Look for file URLs to detonate
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "1"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              simple: inputs.URL
            iscontext: true
    view: |-
      {
        "position": {
          "x": 377.5,
          "y": 370
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "7":
    id: "7"
    taskid: 8089eb7a-a9e8-4efd-8c2e-74a4583af22e
    type: condition
    task:
      id: 8089eb7a-a9e8-4efd-8c2e-74a4583af22e
      version: -1
      name: Is WildFire-v2 enabled?
      description: Check if integration instance is enabled.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "6"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: WildFire-v2
                transformers:
                - operator: getField
                  args:
                    field:
                      value:
                        simple: state
            iscontext: true
          right:
            value:
              simple: active
    view: |-
      {
        "position": {
          "x": 265,
          "y": 195
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "8":
    id: "8"
    taskid: f0f4a63c-bd8b-4653-8b06-1a74ad35e376
    type: regular
    task:
      id: f0f4a63c-bd8b-4653-8b06-1a74ad35e376
      version: -1
      name: WildFire Get Report
      description: Retrieves results for a file hash using WildFire.
      script: '|||wildfire-report'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      format: {}
      hash: {}
      md5: {}
      sha256: {}
      url:
        complex:
          root: WildFire
          accessor: Report.URL
      verbose: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 602.5,
          "y": 1945
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "9":
    id: "9"
    taskid: f3212167-fc1a-48ef-8a85-2f1176cd01d5
    type: regular
    task:
      id: f3212167-fc1a-48ef-8a85-2f1176cd01d5
      version: -1
      name: WildFire Upload URL
      description: Uploads a URL of a webpage to WildFire for analysis.
      script: '|||wildfire-upload-url'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      upload:
        complex:
          root: inputs.URL
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 275,
          "y": 1245
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "11":
    id: "11"
    taskid: 41cbd423-2161-4942-80c6-d09445b3a9a4
    type: condition
    task:
      id: 41cbd423-2161-4942-80c6-d09445b3a9a4
      version: -1
      name: Was there an unsuccessful file url submission?
      description: Was the file successfully submitted using the URL provided.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "9"
      "yes":
      - "13"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualNumber
          left:
            value:
              complex:
                root: inputs.URL
                transformers:
                - operator: count
            iscontext: true
          right:
            value:
              complex:
                root: WildFire.Report
                accessor: URL
                transformers:
                - operator: count
            iscontext: true
    view: |-
      {
        "position": {
          "x": 490,
          "y": 1070
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "12":
    id: "12"
    taskid: 82a36b69-5d34-4346-85c2-7e8545cb16c1
    type: condition
    task:
      id: 82a36b69-5d34-4346-85c2-7e8545cb16c1
      version: -1
      name: Was the file uploaded successfully and is a report pending?
      description: ""
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "2"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: WildFire
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: WildFire.Report.Status
                      iscontext: true
                    right:
                      value:
                        simple: Pending
                accessor: Report.URL
            iscontext: true
    view: |-
      {
        "position": {
          "x": 275,
          "y": 1595
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "13":
    id: "13"
    taskid: 838162d1-3bac-4e12-8fdc-a9a645b35a13
    type: playbook
    task:
      id: 838162d1-3bac-4e12-8fdc-a9a645b35a13
      version: -1
      name: GenericPolling
      description: |-
        Use this playbook as a sub-playbook to block execution of the master playbook until a remote action is complete.
        This playbook implements polling by continuously running the command in Step \#2 until the operation completes.
        The remote action should have the following structure:

        1. Initiate the operation.
        2. Poll to check if the operation completed.
        3. (optional) Get the results of the operation.
      playbookName: GenericPolling
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      AdditionalPollingCommandArgNames: {}
      AdditionalPollingCommandArgValues: {}
      Ids:
        complex:
          root: WildFire
          accessor: Report.SHA256
      Interval:
        complex:
          root: inputs.Interval
      PollingCommandArgName:
        simple: sha256
      PollingCommandName:
        simple: wildfire-report
      Timeout:
        complex:
          root: inputs.Timeout
      dt:
        simple: WildFire.Report(val.Status != 'Success').SHA256
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": 817.5,
          "y": 1770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "15":
    id: "15"
    taskid: 11c1bedb-67b4-4714-85b0-cbe931920d44
    type: regular
    task:
      id: 11c1bedb-67b4-4714-85b0-cbe931920d44
      version: -1
      name: WildFire Get Report - Check If a Report already exists
      description: Checks if a report already exists for the file or URL submitted.
      script: '|||wildfire-report'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "12"
    scriptarguments:
      format: {}
      hash: {}
      md5: {}
      sha256: {}
      url:
        complex:
          root: WildFire
          accessor: Report.URL
      verbose: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 275,
          "y": 1420
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "16":
    id: "16"
    taskid: 5b04ec2c-a219-4cde-81e8-e3addccd3e8d
    type: regular
    task:
      id: 5b04ec2c-a219-4cde-81e8-e3addccd3e8d
      version: -1
      name: WildFire Get Report - Check If a Report already exists
      description: Checks if a report already exists for the file or URL submitted.
      script: '|||wildfire-report'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "11"
    scriptarguments:
      format: {}
      hash: {}
      md5: {}
      sha256: {}
      url:
        complex:
          root: WildFire
          accessor: Report.URL
      verbose: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 265,
          "y": 895
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "17":
    id: "17"
    taskid: c2ca0b0e-9cd0-499d-8076-1638adc2fb37
    type: condition
    task:
      id: c2ca0b0e-9cd0-499d-8076-1638adc2fb37
      version: -1
      name: Was there a successful file url submission?
      description: Was the file successfully submitted using the URL provided.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "11"
      "yes":
      - "16"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: WildFire.Report
                accessor: URL
            iscontext: true
    view: |-
      {
        "position": {
          "x": 490,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
system: true
view: |-
  {
    "linkLabelsPosition": {
      "7_5_#default#": 0.7
    },
    "paper": {
      "dimensions": {
        "height": 2135,
        "width": 1147.5,
        "x": 50,
        "y": 50
      }
    }
  }
inputs:
- key: URL
  value:
    complex:
      root: URL
      accessor: Data
  required: false
  description: URL of the webpage or file URL to detonate. The URL is taken from the context.
  playbookInputQuery:
- key: Interval
  value:
    simple: "1"
  required: false
  description: Duration for executing the polling (in minutes).
  playbookInputQuery:
- key: Timeout
  value:
    simple: "60"
  required: false
  description: The duration after which to stop polling and to resume the playbook (in minutes).
  playbookInputQuery:
- key: ReportFileType
  value: {}
  required: false
  description: The resource type to download. Default is PDF. XML is also possible.
  playbookInputQuery:
outputs:
- contextPath: DBotScore
  description: The DBotScore object.
  type: unknown
- contextPath: DBotScore.Score
  description: The actual score.
  type: number
- contextPath: File.Size
  description: File size.
  type: number
- contextPath: File.MD5
  description: MD5 hash.
  type: string
- contextPath: File.SHA1
  description: SHA1 hash.
  type: string
- contextPath: File.Type
  description: File type e.g. "PE".
  type: string
- contextPath: File.SHA256
  description: SHA256 hash.
  type: string
- contextPath: File.EntryID
  description: The Entry ID of the sample.
  type: string
- contextPath: File.Malicious.Vendor
  description: For malicious files, the vendor that determined that the file is malicious.
  type: string
- contextPath: File.Name
  description: Filename.
  type: string
- contextPath: File.Malicious.Description
  description: For malicious files, the reason the vendor determined that the file is malicious.
  type: string
- contextPath: DBotScore.Indicator
  description: The indicator we tested.
  type: string
- contextPath: DBotScore.Type
  description: The type of indicator.
  type: string
- contextPath: DBotScore.Vendor
  description: Vendor used to calculate the score.
  type: string
- contextPath: IP.Address
  description: IPs relevant to the sample.
  type: string
- contextPath: File
  description: The File object.
  type: unknown
- contextPath: InfoFile
  description: The report file object.
  type: unknown
- contextPath: InfoFile.EntryID
  description: The EntryID of the report file.
  type: string
- contextPath: InfoFile.Extension
  description: The extension of the report file.
  type: string
- contextPath: InfoFile.Name
  description: The name of the report file.
  type: string
- contextPath: InfoFile.Info
  description: The info of the report file.
  type: string
- contextPath: InfoFile.Size
  description: The size of the report file.
  type: number
- contextPath: InfoFile.Type
  description: The type of the report file.
  type: string
- contextPath: File.Malicious
  description: The malicious object.
  type: unknown
- contextPath: WildFire.Report
  description: The submission object.
  type: unknown
- contextPath: WildFire.Report.MD5
  description: MD5 of the submission.
  type: string
- contextPath: WildFire.Report.SHA256
  description: SHA256 of the submission.
  type: string
- contextPath: WildFire.Report.FileType
  description: The type of the submission.
  type: string
- contextPath: WildFire.Report.Status
  description: The status of the submission.
  type: string
- contextPath: WildFire.Report.Size
  description: The size of the submission.
  type: number
- contextPath: WildFire.Report.URL
  description: URL of the submission.
  type: string
- contextPath: WildFire.Report.detection_reasons
  description: The detection reasons object.
  type: unknown
- contextPath: WildFire.Report.detection_reasons.description
  description: Reason for the detection verdict.
  type: string
- contextPath: WildFire.Report.detection_reasons.name
  description: Name of the detection.
  type: string
- contextPath: WildFire.Report.detection_reasons.type
  description: Type of the detection.
  type: string
- contextPath: WildFire.Report.detection_reasons.verdict
  description: Verdict of the detection.
  type: string
- contextPath: WildFire.Report.detection_reasons.artifacts
  description: Artifacts for the detection reasons.
  type: string
- contextPath: WildFire.Report.iocs
  description: Associated IOCs.
  type: string
tests:
- No tests (deprecated)
deprecated: true
supportedModules:
- agentix
- xsiam