ANY.RUN announced the launch of Smart Content Analysis, an advanced mechanism within its Automated Interactivity feature that enables the service to automatically detonate complex malware and phishing attacks, helping users speed up their investigations and gain in-depth insights into malicious behavior.

ANY.RUN’s Smart Attack Analysis

Smart Content Analysis is a mechanism that allows the ANY.RUN sandbox to execute multi-stage cyber attacks without any user involvement. It does this by following three main steps:

  • Scanning uploaded files to locate critical components, such as URLs and email attachments.
  • Identifying the key components detonation of which moves the attack forward, including URLs embedded within QR codes or rewritten by security filters.
  • Engaging with the malicious content in a controlled environment, for instance, by opening URLs in a browser or running payloads found in email archive attachments to observe their behavior.

Automated Interactivity toggle inside ANY.RUN sandbox

Cyber Technology Insights: Versa Introduces Cloud Firewall on AWS Marketplace

Detonating a Multi-Stage Attack with Automated Interactivity

With this new upgrade, ANY.RUN’s sandbox can automatically execute the following types of content found at different stages of complex cyber attacks:

  • URLs inside QR codes
  • Modified links
  • Multi-stage redirects
  • Email attachments
  • Payloads with archives

Consider the following multi-stage phishing attack analyzed with Automated Interactivity.

  1. The phishing email analyzed with Automated Interactivity
  2. The system automatically opens the .eml file submitted by the user via Outlook, detects a PDF attachment, and scans its contents.
  3. The static analysis module in ANY.RUN sandbox reveals the link hidden in the QR

Cyber Technology Insights: CyberUSA Boosts Defense for U.S. Businesses Amid Crime

Adaptive to New Threats 

ANY.RUN’s Smart Content Analysis is built to adapt to the changing threat landscape. With regular attack scenario updates from the ANY.RUN threat research team, the system remains aligned with emerging attack methods, allowing it to handle even the latest and most evasive threats.

Exploring Smart Content Analysis

Automated Interactivity helps security professionals streamline and improve their threat investigations:

  • Less manual effort: No more wasted clicks. Let the sandbox handle repetitive actions so you can focus on the bigger picture.
  • Faster, deeper insights: Go beyond surface detections with simulations that bring hidden threat layers to light.
  • Speedy analysis: Accelerate your analysis with automation that moves as fast as you do, from simple phishing links to layered attack chains.

ANY.RUN serves over 500,000 cybersecurity professionals globally, offering an interactive platform for malware analysis targeting Windows and Linux environments. With advanced threat intelligence tools such as TI Lookup, YARA Search, and Feeds, ANY.RUN enhances incident response and provides analysts with essential data to counter cyber threats effectively.

Cyber Technology Insights: ColorTokens & Claroty Unite to Boost Cyber-Physical Security

Source – Globe Newswire

To participate in our interviews, please write to our CyberTech Media Room at news@intentamplify.com