ANY.RUN, a global leader in Interactive Malware sandboxes, has upgraded its browser extension to include the Safebrowsing feature, which is now available for free to all users.
This tool is designed to help businesses and individuals combat phishing attempts, malicious redirects, and hidden malware by providing a secure, interactive environment for analyzing suspicious links.
Safebrowsing Features:
Safebrowsing operates as a fully functional virtual browser within the cloud, allowing users to safely interact with potentially harmful URLs.
This feature is particularly effective for investigating multi-stage phishing attacks and CAPTCHA-based fraud.
By isolating the browsing environment, it ensures that no malicious activity affects the local system or network.
Security teams can now analyze suspicious URLs instantly through ANY.RUN’s browser extension.
Instead of manually copying and pasting links into the platform, users can right-click on any link and select “Safebrowsing” from the context menu. This seamless integration significantly speeds up threat detection and response processes.
All you need is a registered account to start analyzing suspicious links instantly.
Safebrowsing provides a controlled environment where security analysts can explore the entire attack chain and uncover hidden threats. For example:
The Network Inspector feature further enhances investigations by offering real-time monitoring of network connections, HTTP requests, and potential threats identified by Suricata rules.
Equip Your Security Team with Instant URL Analysis Install ANY.RUN’s Browser Extension
Safebrowsing enables security analysts to interact with the entire attack chain, monitor network activity, and uncover hidden threats in a controlled, isolated environment.
In this example, we examine a phishing attack that leverages a fraudulent TransferNow link. TransferNow is a legitimate file-sharing service that allows document transfers up to 250GB.
By right-clicking the suspicious URL, the link is instantly opened within ANY.RUN’s isolated browser, eliminating the need for manual copying and pasting.
Upon execution, the link directs to a spoofed TransferNow webpage, presenting a deceptive document download prompt. Selecting the “Download File” option opens a PDF document instead of initiating a file transfer.
The displayed PDF mimics a SharePoint document, prompting users to download another file. This multi-step approach exploits psychological manipulation, gradually lowering user suspicion and increasing the likelihood of credential theft.
Upon downloading the secondary file, users are redirected to a fake Microsoft login page. However, analysis reveals the URL has no legitimate affiliation with Microsoft, a clear indicator of credential harvesting.
Indicators of Compromise (IoCs):
Cybercriminals increasingly deploy CAPTCHA mechanisms to obstruct automated security scanners while maintaining accessibility for human victims.
In this analysis, Safebrowsing allows analysts to bypass these barriers through automated interactivity, providing a direct path to analyze phishing attempts hidden behind CAPTCHA walls.
Right-clicking a suspicious link and selecting “Safebrowsing” automatically opens the URL in an isolated environment, streamlining the investigation process.
The link initially presents a Cloudflare CAPTCHA page, a common evasion tactic used to prevent automated security tools from detecting fraudulent activity.
Once the CAPTCHA is bypassed, the site redirects to a fake Google login page. A detailed examination of the URL confirms it has no legitimate association with Google, exposing the fraudulent attempt.
According to ANY.RUN Reports, Safebrowsing integrates a Network Inspector, accessible in the upper-right corner of the interface, offering comprehensive real-time analysis of network traffic, HTTP requests, and security threats.
Using Suricata rules, analysts can quickly detect phishing domains, track attacker infrastructure, and mitigate security risks with enhanced precision.
For deeper security assessments, the full version of ANY.RUN’s browser extension provides interactive sandbox analysis capabilities.
To use Safebrowsing for free, users must register for an ANY.RUN account and install the browser extension. Here’s how it works:
For organizations requiring deeper analysis, the full version of ANY.RUN’s extension offers access to its Interactive Sandbox. This includes features like file and link analysis on virtual machines, detailed threat reports, and extended session durations for comprehensive investigations. These advanced tools are available through Hunter or Enterprise subscriptions.
By offering Safebrowsing for free, ANY.RUN empowers businesses and individuals to proactively defend against cyberattacks. The tool not only enhances threat detection but also serves as a valuable training resource for employees, helping them recognize phishing schemes in a safe setting.
With this upgrade, ANY.RUN continues its mission of simplifying malware analysis and improving cybersecurity resilience worldwide.
Access all features of ANY.RUN’s Interactive Sandbox - Get a 14-day free trial
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…