The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Viewing malware submissions using the CLI

Prev Next

Use the show submission command to view detailed statistics about the number of malware submissions that were analyzed and the number submitted per minute during the past 24 hours.

Note

The fields for the total number of remote submissions are displayed only on a Network Security sensor or sensor-enabled Network Security integrated appliance.

Note

The URLs that are submitted for analysis on a Network Security sensor or sensor-enabled Network Security integrated appliance are given higher priority than suspicious or malicious objects.

Use the show submission malicious command to view detailed statistics about the malware submissions that are marked as malicious.

Use the show submission uuid command to view detailed statistics that uniquely identify analysis submission results on a Network Security sensor or sensor-enabled Network Security integrated appliance.

The analysis submission results are displayed on the Alerts > Alerts page in the Web UI. For details about each show submission command, see the CLI Command Referencee.

To view statistics of malware submissions:
  1. Enable the CLI enable mode.

    hostname > enable
  2. View the summary of malware submissions.

    hostname # show submission
    Runtime Submission Stats        :
    Total queued submission         : 91
    Total running submissions       : 122
    Total DA running submissions    : 61
    Cumulative Stats in timespan    2015-08-25 11:01:57 to 2015-08-26 11:01:57 : Total :
    Rate/minute
    Submissions                     : 1846 : 1.282
    Completed submissions           : 1721 : 1.195
    Malicious submission count      : 1414 : 0.982
    
To view statistics of the malware submissions on the Network Security sensor:
  1. Enable the CLI enable mode.

    hostname > enable
  2. View the summary of malware submissions.

    hostname # show submission
    
    Runtime Submission Stats:
        Total queued submission                         : 0
            Queued submissions(url)                     : 0
            Queued submissions(file)                    : 0
    
    Remote Submissions
        Total remote submissions                        : 26
            Remote submissions(url)                     : 13
            Remote submissions(file)                    : 13
    
    Cumulative Stats in timespan 2017-08-27 12:22:05 to 2017-08-28 12:22:05
    : Total : Rate/minute
    
    Submissions                                         : 733 : 0.509
        Submissions(url)                                : 292 : 0.203
        Submissions(file)                               : 441 : 0.306
    Completed submissions                               : 707 : 0.491
        Completed submissions(url)                      : 279 : 0.194
        Completed submissions(file)                     : 428 : 0.297
    Malicious submission count                          : 487 : 0.338
        URL Dynamic Analysis verified malicious count   : 171 : 0.119
        File Dynamic Analysis verified malicious count  : 316 : 0.219
    Remote Submissions Completed                        : 556 : 0.386
    Remote Malicious Submissions                        : 367 : 0.255
To view statistics of the malware submissions that are marked as malicious:
  1. Enable the CLI enable mode.

    hostname > enable
  2. View the summary of the malware submissions that are marked as malicious.

    hostname # show submission malicious
    Submission ID             : 4
    UUID                      : 9351908a-0575-4666-9d2b-a7d5cc200a3d
    Malware ID                : 13
    Source IpAddress          : 80.156.52.181
    Destination IpAddress     : 190.246.12.141
    md5sum                    : 4a78c36e8be28a2fef57e69daa993d13
    File type                 : exe
    Status                    : success
    Malicious                 : YES
        Analysis Object ID        : 2
        Analysis Object Name      : load.exe
        Analysis File Type        : exe
        md5sum                    : 4a78c36e8be28a2fef57e69daa993d13
        Static Analysis weight    : 100
        Dynamic Analysis weight   : 300
        Dynamic Analysis jobs     : 2
        Static Analysis jobs      : 4
            SA engine weight      : 100
            SA job ID             : 5
                SA sub-engine name         : avs
                SA sub-engine signature    : Trojan.Generic
                SA sub-engine weight       : 100
            Job ID                : 4
            OS name               : win7x64-sp1
            Application name      : Windows Explorer
            OS Changes weight     : 100
            CNC Match weight      : 0
            Assigned time         : 2016-04-28 00:34:21.253765
            Complete time         : 2016-04-28 00:35:25.881007
            Job runtime           : 00:01:04.627242
            Signature             : Malware.Binary.exe
            Job ID                : 3
            OS name               : winxp-sp3
            Application name      : Windows Explorer
            OS Changes weight     : 300
            CNC Match weight      : 300
            Assigned time         : 2016-04-28 00:33:15.649557
            Complete time         : 2016-04-28 00:34:58.169366
            Job runtime           : 00:01:42.519809
            Signature             : Trojan.Rootkit.MVX
    
To view statistics that uniquely identify analysis submission results on a ADD Product Series sensor or sensor-enabled ADD Product Series integrated appliance:
  1. Enable the CLI enable mode.

    hostname > enable
  2. View the summary of malware submissions from a universally unique identifier (UUID).

    hostname > show submission uuid 98287f74-b2b9-4536-ac7b-b3656ce00eba
    Submission ID    : 8387
    UUID             : 98287f74-b2b9-4536-ac7b-b3656ce00eba
    Malware ID       : 20842
    md5sum           : f711bb5bdcbc7c69dc63a75c0605cf00
    File type        : dll
    Status           : success
    Malicious        : NO