Extracting archived objects

Prev Next

In addition to the MD5 checksum data, all files or OS objects that were created or modified during MVX detonation for a file analysis job are available as a zipped collection, along with a full memory dump.

FX_ExtractedObject_scap.png
To view and extract a VM memory and object dump for a selected file analysis job:
  1. Open the File Analysis page as described in Viewing malware using the Web UI.

  2. Click the orange arrow to expand the malware information.

  3. Click the Archived Object link to download the .zip file.

  4. Open the .zip file to extract its contents. When prompted for a password, type "infected."