To analyze URLs, select an analyzer profile that has both sandbox and Internet access enabled.
Intelligent Sandbox uses a proprietary procedure to calculate the MD5 hash value of the URL. Then, it checks this MD5 against its local blacklist.
It is assumed that the file that the URL refers to is of a supported file type. Then Intelligent Sandbox dynamically analyzes the file using the corresponding analyzer VM. It is assumed that the MD5 of the URL is not present in the blacklist or Run All Selected option is selected in the corresponding analyzer profile.
Note
Trellix GTI File Reputation, Anti-Malware, and Gateway Anti-Malware analyze options are not relevant for URLs.
Dynamic analysis and reporting for URLs is similar to that of files. It records all activities in the analyzer VM including registry operations, process operations, file operations, runtime DLLs, and network operations. If the webpage downloads any dropper files, Intelligent Sandbox dynamically analyzes these files as well and includes the results in the same report under embedded/dropped content section.
If a dropped file connects to other URLs, all these URLs are checked with TrustedSource for URL reputation and categorization.
Intelligent Sandbox analyzes the URL samples and generates a Graph Modeling Language (GML) file. This file is in an ASCII plain text format, which contains data to generate a graphical representation of the logic execution path. You cannot directly view this file in the Intelligent Sandbox web interface.
Note
Only HTTP, HTTPS, and FTP protocols are supported for URL analysis.