How to Search Samples Associated with a Malware Family in AutoFocus?
0
Created On 04/04/19 03:32 AM - Last Modified 07/19/22 23:14 PM
Objective
A researcher is analyzing a malware family and wants to know how to leverage AutoFocus to get information related to samples associated with this malware family.
Procedure
Step 1: Login to AutoFocus (https://autofocus.paloaltonetworks.com/) and click Search
Step 2: Search for the malware family using Tag criteria as mentioned below (HenBox Family is used as an example):
You can choose to view only My Samples, only Public Samples, or All Samples. All Samples includes both public and private samples. However, private samples submitted by firewalls or sample sources other than those associated with your support account display with an obfuscated hash.
Additional Information
https://docs.paloaltonetworks.com/autofocus/autofocus-admin/autofocus-tags.html
https://unit42.paloaltonetworks.com/unit42-henbox-chickens-come-home-roost/