Viewing the malicious embedded URL details in files using the Web UI

Prev Next

In the eAlerts page of the Email Security - Server appliance, you can drill down to identify the individual embedded URLs in the grouping for files that are detected as malicious for a malware event. The total number of malicious attachments that are detected by the URL analysis service are categorized and tracked on the eAlerts page and Alert Details page.

The following example displays the drill-down details of a malware alert on the Alert Details page for an email that contains malicious URLs that are embedded in a DOCX file.

EX_URLAUDExtractFileDetails_scap.png

For details about the malicious URLs that include LIVE.DTI.URL as the name of the malware type (malicious, exploit, or phish) for Advanced URL Defense, see About Advanced URL Defense on .

For details about URL Dynamic Analysis, see About URL Dynamic Analysis on .

For details about the malicious URLs that include Black-List-URL-Domain as the name of the malware type for typo squatting, see About typo squatting on.

For details about the malicious URLs that include Block-List-Match-Url as the name of the malware type for a blocked list, see About custom allowed and blocked lists on .