Downloads the file at the specified URL, analyzes the file on the appliance’s virtual machine, and presents the results of the analysis. In the analysis, the malware is permitted to run and the results are permitted to leave the virtual machine. This command is only for live analysis. This command is available on the Malware Analysis appliance.
Syntax
malware analyze live url <URL> [timeout <seconds>] [priority [urgent | normal] ] [guestos <guestos_name>] [application <application_name>] [force] [no-prefetch] [password <value>]
Parameters
URL | Specifies the URL associated with the malware. |
timeout | Specifies the time interval after which the malware analysis times out if the analysis is not complete (30 - 3600 seconds). |
priority | Performs the analysis based on priority - normal or urgent. |
guestos | Specifies the guest operating system against which the malware will be analyzed. For example, winxp-sp3. |
application | Specifies the application to use for analysis; for example - Internet Explorer, Firefox, RealPlayer, Windows-Media-Player, Adobe-Reader, MS-Word, MS-Excel, MS-PowerPoint, QuickTime-Player, or Windows-Explorer. |
force | Runs an analysis on the malware even if it has already been analyzed before. |
no-prefetch | Download URL directly in virtual machine without prefiltering. |
password | Used when sample (typically a zip) is password-protected. |
Example
The following example performs a live malware analysis with normal priority on the URL "https://56561234.com/passwork23.exe" for the Guest Image “win10x64m ”
hostname (config) # malware analyze live url https://56561234.com/passwork23.exe guestos win10x64m timeout 200
priority normal force
Http options = {"priority":"0","url":"https://56561234.com/passwork23.exe","analysistype":"1","force":"true","timeout":"200","prefetch":"true","password":"","profile_details":[{"profile":"win10x64m"}]}
uuid = 93b08e94-1835-4f74-9a57-908d4e8b2c53
brokerId = 96A0C4011791