The invention provides a malicious code behavior analyzer which comprises a storage module, a display module, a network data flow collecting and reducing module, a central processor, an integrated management module, a network flow behavior analysis engine, a file static analysis engine, a file dynamic behavior analysis engine, a WEB threat detection module, a network behavior abnormity detection module, a threat detection module, a file threat detection module, a file abnormal behavior module and a sandbox module. According to the analyzer, the network data flow can be recombined and reduced, abnormal network behaviors are detected, suspected files can be reduced, extracted and analyzed, and placed in a sandbox template to monitor and analyze file behaviors dynamically, results of static analysis and dynamic analysis are combined to provide the degree of information safety risk of the suspected files, and the technical problem that high-level malicious code attacks which is increasingly serious cannot be handled is solved.