Downloads the file at the specified URL, analyzes the file on the virtual machine of the appliance, and presents the results of the analysis. In the analysis, malware is permitted to run, but the results are not permitted to leave the virtual machine. This command is only for sandbox analysis. This command is available on the Malware Analysis appliance.
Syntax
malware analyze sandbox url <URL> [timeout <seconds>] [priority [urgent | normal] ] [guestos <guestos_name>] [application <application_name>] [force] [password <value>]
Parameters
URL | Specifies the URL associated with the malware. |
timeout | Specifies the time interval after which the malware analysis times out if the analysis is not complete (30-3600 seconds). |
priority | Performs the analysis based on priority - normal or urgent. |
guestos | Specifies the guest operating system against which the malware will be analyzed. For example, winxp-sp3. |
application | Specifies the application to use for analysis; for example - Internet Explorer, Firefox, RealPlayer, Windows-Media-Player, Adobe-Reader, MS-Word, MS-Excel, MS-PowerPoint, QuickTime-Player, or Windows-Explorer. |
force | Runs an analysis on the malware even if it has already been analyzed before. |
no-prefetch | Download URL directly in virtual machine without prefiltering. |
no-prefetch | Used when sample (typically a zip) is password-protected. |
Example
The following example assigns a URL for sandbox analysis.
hostname (config) # malware analyze sandbox url https://56561234.com/passwork23.exe guestos win10x64m,win7-sp1m
timeout 150 priority normal force
Http options =
{"priority":"0","url":"https://56561234.com/passwork23.exe","analysistype":"2","force":"true","timeout":"150","prefetch":"true","password":"","profile_details":[{"profile":"win10x64m"},{"profile":"win7-sp1m"}]}
uuid = d8af0e25-2b18-4b11-9d3c-064d78df542d
brokerId = 96A0C4011791