malware analyze sandbox

Prev Next

Downloads the file at the specified URL, analyzes the file on the virtual machine of the appliance, and presents the results of the analysis. In the analysis, malware is permitted to run, but the results are not permitted to leave the virtual machine. This command is only for sandbox analysis. This command is available on the Malware Analysis appliance.

Syntax

malware analyze sandbox url <URL> [timeout <seconds>] [priority [urgent | normal] ] [guestos <guestos_name>] [application <application_name>] [force] [password <value>]

Parameters

URL

Specifies the URL associated with the malware.

timeout

Specifies the time interval after which the malware analysis times out if the analysis is not complete (30-3600 seconds).

priority

Performs the analysis based on priority - normal or urgent.

guestos

Specifies the guest operating system against which the malware will be analyzed. For example, winxp-sp3.

application

Specifies the application to use for analysis; for example - Internet Explorer, Firefox, RealPlayer, Windows-Media-Player, Adobe-Reader, MS-Word, MS-Excel, MS-PowerPoint, QuickTime-Player, or Windows-Explorer.

force

Runs an analysis on the malware even if it has already been analyzed before.

no-prefetch

Download URL directly in virtual machine without prefiltering.

no-prefetch

Used when sample (typically a zip) is password-protected.

Example

The following example assigns a URL for sandbox analysis.

hostname (config) #  malware analyze sandbox  url https://56561234.com/passwork23.exe guestos win10x64m,win7-sp1m
timeout 150 priority normal force


Http options =
{"priority":"0","url":"https://56561234.com/passwork23.exe","analysistype":"2","force":"true","timeout":"150","prefetch":"true","password":"","profile_details":[{"profile":"win10x64m"},{"profile":"win7-sp1m"}]}
uuid = d8af0e25-2b18-4b11-9d3c-064d78df542d
brokerId = 96A0C4011791