Views:

From DDEI, download the SO from the internal Virtual Analyzer, DDAN or TMCM, and use them for virus scan.

The detection name by SO for the malicious samples are the following:

Malicious TypeSO TypeDetection Name
FileConsolidated SOCSO_SUSPICOIOUS_FILE.UMXX
FileUser-defined SOUSR_SUSPICOIOUS_FILE.UMXX
URLConsolidated SOCSO_SUSPICOIOUS_URL.UMXX
URLUser-defined SOUSR_SUSPICOIOUS_URL.UMXX