hi,
I had a case where the email was delayed for 15 minutes and I don't know where the scan was spend more times.
In the mailog, I can find that the mail arrived at 14:53:11 and sent at 15:08:04
Jun 19 14:53:11 2020 feto1n064 postfix/smtpd[32252]: 49pJd36jkGzGJr7: client=unknown[mail]
Jun 19 14:53:11 2020 feto1n064 postfix/cleanup[32255]: 49pJd36jkGzGJr7: message-id=<CAK8YdH97ND43S0LdqQYdk7xD-oPSFAWZSUxi_B1MNNXDfLyFsw@mail.gmail.com>
Jun 19 14:53:11 2020 feto1n064 postfix/qmgr[4565]: 49pJd36jkGzGJr7: from=<SRS0=DbzY=AA=plr-vd.ch=c.danselme@srs.addressix.com>, size=83166, nrcpt=1 (queue active)
Jun 19 14:53:11 2020 feto1n064 postfix/smtpd[32257]: 49pJd36sxCzGJrB: client=localhost[127.0.0.1], orig_queue_id=49pJd36jkGzGJr7, orig_client=unknown[mail]
Jun 19 15:08:04 2020 feto1n064 postfix/smtp[32256]: 49pJd36jkGzGJr7: to=<recipient>, relay=127.0.0.1[127.0.0.1]:10025, delay=893, delays=0.02/0/0/892, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 49pJd36sxCzGJrB)
Jun 19 15:08:04 2020 feto1n064 postfix/qmgr[4565]: 49pJd36jkGzGJr7: removed
In the mtad.elg I find that the file was send at 14:53:11 and finish at 15:08:04...so 16 minutes to scan the file
[mtad 17542 4043160480]@feto1n064[19 Jun 14:53:11] [EMAIL_MTA (NOTICE)] parseEmlFile() - 49pJd36jkGzGJr7 :[emailContextId=2775134773] MIME Parsing result: 0(Success)
[mtad 17542 4043160480]@feto1n064[19 Jun 14:53:11] [EMAIL_AP (NOTICE)] handle() - 49pJd36jkGzGJr7 :AP policy off
[mtad 17542 4043160480]@feto1n064[19 Jun 14:53:11] [EMAIL_TE (NOTICE)] sendAttachmentRequest() - 49pJd36jkGzGJr7 :Send to TE: Attachment name is 'attachment.doc', size=56320, teContext.m_teHandle = e1b183f8
[mtad 17542 4043160480]@feto1n064[19 Jun 15:08:04] [EMAIL_TE (NOTICE)] scanFinishedCb() - 49pJd36jkGzGJr7 :TE email scan finished, verdict=0
[mtad 17542 4043160480]@feto1n064[19 Jun 15:08:04] [EMAIL_MTA (NOTICE)] editContent() - 49pJd36jkGzGJr7 :[mta_policy_context_id=2775134773] End connection.
In the ted.el log it isn't very clear where the scan spent more times... I see only a gap in the logs between 14:53:11 and 15:05:50.. Do you have any ideas why the scan is so long ?
[Expert@feto1n064:0]# cat ted.elg | grep {46572C86-5B06-004B-AB39-D6EDE074211A}
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Handling new file "Simple question Catherine Labouchère.doc", Path: /opt/CPsuite-R80.20/fw1/tmp/email_tmp/emailtemp-1592571190-3449878024-3136697231_D/RDFQA2G01104469WTRWJ0TLCS0F05BGE3ZBYGTFF63ID, rule_number = 30, rule name = MTA traffic to Gateway portail , investigation_path = PATH_TE
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Local Partial response is enabled
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Remote Partial response is enabled
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Cloud Partial response is enabled
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'system state' (phase: 'prepare')
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'system state' reporting back (status: done)
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {system state} total duration time in milliseconds is: 1, current combined verdict is: Inert
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'url prepare handler' (phase: 'prepare')
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'url prepare handler' reporting back (status: done)
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {url prepare handler} total duration time in milliseconds is: 1, current combined verdict is: Inert
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'classifier' (phase: 'prepare')
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'classifier' reporting back (status: done)
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {classifier} total duration time in milliseconds is: 1, current combined verdict is: Inert
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'policy' (phase: 'prepare')
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} adding image '5e5de275-a103-4f67-b55b-47532918fa59' for emulation
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} adding image 'e50e99f3-5963-4573-af9e-e3f4750b55e2' for emulation
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'policy' reporting back (status: done)
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {policy} total duration time in milliseconds is: 1, current combined verdict is: Inert
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'file' (phase: 'prepare')
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Hashes: md5=36b8cef565d9b56910b1f35f0cc72709, sha1=ca226bfa49686beaca3db26a43944603d73bd7af
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'file' reporting back (status: done)
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {file} total duration time in milliseconds is: 2, current combined verdict is: Inert
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'prepare persistency' (phase: 'prepare')
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'prepare persistency' reporting back (status: done)
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {prepare persistency} total duration time in milliseconds is: 1, current combined verdict is: Inert
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'contract' (phase: 'prepare')
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'contract' reporting back (status: done)
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {contract} total duration time in milliseconds is: 1, current combined verdict is: Inert
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'cache inquirer' (phase: 'prepare')
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'cache inquirer' reporting back (status: done)
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {cache inquirer} total duration time in milliseconds is: 1, current combined verdict is: Inert
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} path in ep: /opt/CPsuite-R80.20/fw1/tmp/email_tmp/emailtemp-1592571190-3449878024-3136697231_D/MailBodyFilein response data: /opt/CPsuite-R80.20/fw1/tmp/email_tmp/emailtemp-1592571190-3449878024-3136697231_D/MailBodyFile
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Reporting back action: unknown; Confidence: 0; InvestigationPath: PATH_TE
:event_id ("{46572C86-5B06-004B-AB39-D6EDE074211A}")
[14547 4117154720][19 Jun 14:53:11] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'duplicate' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'duplicate' reporting back (status: rewind)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {duplicate} total duration time in milliseconds is: 758928, current combined verdict is: Inert
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'system state' (phase: 'prepare')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'system state' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'url prepare handler' (phase: 'prepare')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'url prepare handler' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'classifier' (phase: 'prepare')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'classifier' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'policy' (phase: 'prepare')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} adding image '5e5de275-a103-4f67-b55b-47532918fa59' for emulation
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} adding image 'e50e99f3-5963-4573-af9e-e3f4750b55e2' for emulation
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'policy' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'file' (phase: 'prepare')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Hashes: md5=36b8cef565d9b56910b1f35f0cc72709, sha1=ca226bfa49686beaca3db26a43944603d73bd7af
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'file' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'prepare persistency' (phase: 'prepare')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'prepare persistency' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'contract' (phase: 'prepare')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'contract' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'cache inquirer' (phase: 'prepare')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} verdict 'Benign' set for image: '5e5de275-a103-4f67-b55b-47532918fa59' (Win7,Office 2013,Adobe 11) by: 0, reason:
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'cache inquirer' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} path in ep: /opt/CPsuite-R80.20/fw1/tmp/email_tmp/emailtemp-1592571190-3449878024-3136697231_D/MailBodyFilein response data: /opt/CPsuite-R80.20/fw1/tmp/email_tmp/emailtemp-1592571190-3449878024-3136697231_D/MailBodyFile
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Reporting back action: accept; Confidence: 0; InvestigationPath: PATH_TE
:event_id ("{46572C86-5B06-004B-AB39-D6EDE074211A}")
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'duplicate' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'duplicate' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {duplicate} total duration time in milliseconds is: 758928, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'url handler' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'url handler' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {url handler} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'trusted source' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} url is empty, don't check in white domains
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'trusted source' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {trusted source} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:50] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'advisory' (phase: 'processing')
"referance_uid" : "{46572C86-5B06-004B-AB39-D6EDE074211A}"
{"api_name":"BDRpcScanFile","file_path":"/opt/CPsuite-R80.20/fw1/tmp/te/te_tmp_files/{4AFEA341-D3E4-F648-8661-5A16C43756E8}","last_update":"19.06.2020 09:38:43","referance_uid":"{46572C86-5B06-004B-AB39-D6EDE074211A}","status":1,"status_text":"CLEAN"}
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'advisory' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {advisory} total duration time in milliseconds is: 803, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'file analyzer' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'file analyzer' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {file analyzer} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'domain threshold' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'domain threshold' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {domain threshold} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'Web Emulation phase1' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'Web Emulation phase1' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {Web Emulation phase1} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'Web Emulation phase2' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'Web Emulation phase2' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {Web Emulation phase2} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'emulator' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'emulator' reporting back (status: done)
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {emulator} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:05:51] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'cloud emulation' (phase: 'processing')
[14547 4117154720][19 Jun 15:05:52] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} uploaded to 217.68.13.87. (cloud emulation)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} verdict 'Benign' set for image: 'e50e99f3-5963-4573-af9e-e3f4750b55e2' (WinXP,Office 2003/7,Adobe 9) by: 16, reason:
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'cloud emulation' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {cloud emulation} total duration time in milliseconds is: 132991, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'remote emulation' not mandatory, will jump to next in phase
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'false positives' (phase: 'finalizing')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'false positives' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {false positives} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'ip reputation' (phase: 'finalizing')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'ip reputation' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {ip reputation} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'decode' (phase: 'finalizing')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'decode' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {decode} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'embedded files' (phase: 'finalizing')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'embedded files' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {embedded files} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'dropped files' (phase: 'finalizing')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'dropped files' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {dropped files} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'archive' (phase: 'finalizing')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'archive' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {archive} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'classifier_holder' (phase: 'finalizing')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'classifier_holder' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {classifier_holder} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'cloud data enricher' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'cloud data enricher' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {cloud data enricher} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'forensics' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'forensics' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {forensics} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'additional emulation data' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'additional emulation data' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {additional emulation data} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'cache updater' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'cache updater' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {cache updater} total duration time in milliseconds is: 2, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'threat cloud sharing' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'threat cloud sharing' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {threat cloud sharing} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'threat cloud statistics' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'threat cloud statistics' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {threat cloud statistics} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'logger' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'logger' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {logger} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'finalize persistency' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'finalize persistency' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {finalize persistency} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'file saver' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'file saver' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {file saver} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'measurements' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'measurements' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {measurements} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'verdicts collector' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'verdicts collector' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {verdicts collector} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} calling investigator 'local filter counter' (phase: 'reporting')
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} investigator 'local filter counter' reporting back (status: done)
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} {local filter counter} total duration time in milliseconds is: 1, current combined verdict is: Benign
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} path in ep: /opt/CPsuite-R80.20/fw1/tmp/email_tmp/emailtemp-1592571190-3449878024-3136697231_D/MailBodyFilein response data: /opt/CPsuite-R80.20/fw1/tmp/email_tmp/emailtemp-1592571190-3449878024-3136697231_D/MailBodyFile
[14547 4117154720][19 Jun 15:08:04] [TE_TRACE]: {46572C86-5B06-004B-AB39-D6EDE074211A} Done with file; Reporting back action: accept; Confidence: 0; InvestigationPath: PATH_TE
:event_id ("{46572C86-5B06-004B-AB39-D6EDE074211A}")
Regards,