Automate Static Malware analysis with the Blue Lantern Security API
In a business setting you likely will not want to leverage the UI every time you need to run static malware checks on a file. Instead, you should leverage Blue Lantern's API capabilities to build an automated workflow to send suspicious files and then make the risk determination about each file automatically.
Prerequisites
- A Blue Lantern Security API Key requested from here API Access.
- Familiarity with a scipting language and curl commands.
API Call Required to Submit Files for Analysis
The curl for the API call to submit files for analysis looks as below. You will need to provide your API key and file path in the placeholders below in the scripting language you choose. By default, all checks except for ioc extraction will run. Possible checks are included below and as examples in the curl command.
- check_malicious_strings will check against Blue Lanterns internal strings set to find any matches.
- check_extract_iocs will extract IOCs (NOTE: this may produce a lot of noise).
- check_sections will check for sectional entropy to determine if there is potential executable packing in the file.
- check_yara will run against a set of default yara rules.
- check_entropy will check will check the entropy of the entire file.
- check_file_type will check if there is a possible missmatch between the file extension and the detected file type from scanning the file internals.
curl --location 'https://dapi.bluelanternsecurity.io/runs' \
--header 'Authorization: [YOUR API KEY]' \
--form 'tool="STATICMALWAREANALYZER"' \
--form 'checkCost="false"' \
--form 'file=@"[YOUR FILE]"' \
--form 'check_malicious_strings="True"' \
--form 'check_extract_iocs="True"' \
--form 'check_sections="true"' \
--form 'check_yara="true"' \
--form 'check_entropy="true"'
--form 'check_file_type="true"'
On successful submission, you will receive a job ID for checking the status of the analysis and for fetching the results once the analysis complets.
{
"message": "Requested Analysis Job Created",
"result": {
"jobId": "[JOB ID]"
}
}
NOTE: these files are only processed for static analysis and no other types of analysis. The file itself is kept for no more than a day in our systems. The final reports are kept for no more than one week. These files must be below 4.5 MB in size to work with our API.
Collecting data
The job statis can be checked from the /runs data endpoint by passing the job ID as a path parameter with a GET request:
curl --location 'https://api.bluelanternsecurity.io/runs/[JOB ID]' \
--header 'Authorization: [API KEY HERE]'
The job will not show "COMPLETE" until the results are ready. Example data response is shown below:
{
"message": "Job run data retrieved",
"result": [
{
"id": "[JOB ID]",
"user_id": "[YOUR USER ID]",
"run_start": "2026-03-31 15:03:33.956299+00:00",
"run_type": "STATICMALWAREANALYZER",
"run_status": "COMPLETE",
"run_description": null,
"run_end": "2026-03-31 15:03:38.238808+00:00"
}
]
}
Once complete, you can fetch the results of the analysis using the POST request as shown in the curl below:
curl --location 'https://api.bluelanternsecurity.io/results' \
--header 'Content-Type: application/json' \
--header 'Authorization: [API KEY]' \
--data '{
"jobId": "[JOB ID]"
}'
The results data for the static analyzer looks as follows. The details of each result are included in their own section, and will be marked "null" if the check was not active for a particular run. These results can then be used downstream:
{
"message": "results retrieved",
"result": {
"job_id": "[YOUR JOB ID]",
"filename": "[YOUR FILE NAME]",
"analyzed_at": "2026-03-17T16:19:49.775451+00:00",
"status": "Completed",
"Status": 200,
"results": [
{
"file": "[TMP FILE NAME]",
"file_size": 85768,
"file_type": null,
"yara_matches": [],
"malicious_strings": {
"strings_count": 1431,
"ascii_strings_count": 1431,
"utf16_strings_count": 0,
"red_flags": {}
},
"extract_iocs": {
"strings_count": 1431,
"ascii_strings_count": 1431,
"utf16_strings_count": 0,
"classified_strings": {
...
}
},
"sections": {
"analysis_mode": "byte_windows",
"window_size": 4096,
"window_stride": 2048,
"total_sections": 3,
"reported_sections": 1,
"raw_reported_sections": 3,
"suppressed_normal": 0,
"sections": [
{
"name": "window_00000",
"index": 0,
"raw_size": 5107,
"virtual_size": 5107,
"entropy": 5.856,
"entropy_confidence": "full",
"severity": "elevated",
"anomalies": {
"high_entropy": false,
"wx_permissions": false,
"size_mismatch": false,
"nonstandard_name": false,
"entry_point_anomaly": false,
"zero_raw_size": false,
"packer_hint": null,
"encoded_blob_pattern": true
},
"anomaly_count": 1,
"offset_start": 0,
"offset_end": 5107,
"blob_types": [
"base64"
]
}
],
"deduplicated_overlaps": 2,
"distribution_note": "Encoded blob patterns detected in 1 windows."
},
"whole_file_entropy": 5.85,
"checks_enabled": [
"entropy",
"extract-iocs",
"malicious-strings",
"sections",
"yara"
],
"total_cost": 22
}
]
}
}