Analysis report summary

Summary - {% if results.target %} {{ results.target.file.name }} {% endif %}

{% if results.target %}
File info
  • name: {{ results.target.file.name }}
  • type: {{ results.target.file.type }}
  • size: {{ results.target.file.size }} bytes
Checksums
  • SHA1 {{ results.target.file.sha1 }}
  • MD5 {{ results.target.file.md5 }}
{% endif %}

Detected signatures

    {% if results.signatures %} {% for sig in results.signatures|sort(attribute='severity') %} {% if sig.severity == 1 %} {% set label = "info" %} {% elif sig.severity == 2 %} {% set label = "warning" %} {% elif sig.severity >= 3 %} {% set label = "danger" %} {% else %} {% set label = "info" %} {% endif %}
  • {% set sig_template_mapping = { "creates_doc": "creates_ioc.html", "creates_exe": "creates_ioc.html", "suspicious_process": "creates_ioc.html", "persistence_autorun": "creates_ioc.html", "antivirus_virustotal": "antivirus_virustotal.html" } %} {% if sig.markcount >= 1 and sig.name in sig_template_mapping %} {% set collapse_toggle = true %} {% else %} {% set collapse_toggle = false %} {% endif %} {% if sig.markcount > 1 %} {% set event = "events" %} {% else %} {% set event = "event" %} {% endif %}

    {{ sig.description }} {{ sig.markcount }} {{ event }} {% if collapse_toggle %} {% endif %}

    {% if sig.name in sig_template_mapping %} {% include "sections/signatures/" + sig_template_mapping[sig.name] %} {% endif %}
  • {% endfor %} {% else %}
  • No signatures
  • {% endif %}
{% if screenshots %}

Screenshots ({{ screenshots|length }}/{{ results.screenshots|length }})

{% for shot in screenshots %}

{{ shot.name }}

{% endfor %}
{% endif %} {% if results.procmemory %} {% if results.procmemory[0].urls %}

Process memory dump

  • URLs found in process memory
  • {% for url in results.procmemory[0].urls %}
  • {{ url }}
  • {% endfor %}
{% endif %} {% endif %} {% if results.network %} {% if results.network.dns or results.network.hosts %}

Network

{% if results.network.dns %}
DNS (3)
{% for p in results.network.dns %} {% if "answers" in p and p.answers %} {% else %} {% endif %} {% endfor %}
Type Name Response Post-analysis lookup
{{ p.type }} {{ p.request }}{{ p.answers|length }}Empty-
{% endif %} {% if results.network.hosts %}
Hosts ({{ results.network.hosts|length }})
{% for host in results.network.hosts %} {% endfor %}
IP Address
{{ host }}
{% endif %}
{% endif %} {% endif %}