IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Error App Virus Total - Upload file

    Posted Tue May 02, 2023 02:43 PM

    Dears,

    I'm using the Virus Total application to analyze a file. When trying to upload a new attachment, the Playbook throws a Virus Total application error. However, the attachment upload succeeds because I re-run the Playbook and I get the analyze.

    Also, I ran the App example Workflow "Example: VirusTotal Scan (Attachment)" and got the same error.

    Attached screenshot of the error and the application input configuration.

    Thanks and regards!



    ------------------------------
    Federico Camelino
    ------------------------------


  • 2.  RE: Error App Virus Total - Upload file

    Posted Wed May 03, 2023 10:10 AM

    Hi Federico

    I am in the process of updating the VirustTotal app from the v2 to v3 of the VT REST API and converting rules workflows from rules/workflows to playbooks.  I did see this error while testing recently.  However I am changing the logic in the code for checking the results of a scan and do not have a fix for the issue in the current integration.  Hopefully I will complete this conversion and get it released on the App Exchange soon!



    ------------------------------
    AnnMarie Norcross
    ------------------------------



  • 3.  RE: Error App Virus Total - Upload file

    Posted Wed May 03, 2023 02:28 PM

    Hi AnnMarie,

    Thank you very much for your answer. Could you please inform me when the new version of the application is released? I´m planning to implement a Playbook soon.

    Regards.



    ------------------------------
    Federico Camelino
    ------------------------------



  • 4.  RE: Error App Virus Total - Upload file
    Best Answer

    Posted Fri June 09, 2023 11:51 AM

    Hi Federico

    The VirusTotal app v1.1.0 is available on the App Exchange here

    And the content package for creating hits on artifacts from VirusTotal scans is here



    ------------------------------
    AnnMarie Norcross
    ------------------------------