
Cuckoo Malware Analysis

In this section, we'll deal with PDF documents that contain malware samples and prepare to submit those. Please make sure you have installed a PDF reader application in your VM environment (I recommend you use Adobe Acrobat Reader). Internet connection in your VM environment is also needed to make sure that the malware analysis can run smoothly in your VM environment.
We will now submit a PDF file as a malware document. Let us see the steps involved:
Open a new Terminal tab (Shift + Ctrl + T) and type in the following command line:
$ python uti ls/submit.py --platform windows --package pdf shares/aleppo_plan_cercs.pdf
After that, press Tab when the typing reaches aleppo
(document real name contains Arabic characters, and unfortunately, Cuckoo Sandbox seems to not support Arabic characters so we need to rename it to aleppo_plan_crecs.pdf
). In this case the document is located inside the shares
folder. We have to change it based on where...
Change the font size
Change margin width
Change background colour