
Cuckoo Malware Analysis

We will now submit a URL as a malware document. Let us see the steps involved:
Type in the following command:
$ python utils/submit.py --url
http://ziti.cndesign.com/biaozi/fdc/page_07.htm
Please note that the URL above may not be available by the time we try it. You may look for the reported malware URL at http://www.scumware.org or another site that provides malware URL, or if we have found another suspicious malware URL we can submit it to Cuckoo to be analyzed.
Please make sure you have a Success message as shown in the preceding screenshot with task with ID 46.
Windows will open the URL with Internet Explorer.
When you open the URL you will find a web page containing a lot of design pictures. Nothing seems to be suspicious as of now:
Let's see the report.html
file from Cuckoo Sandbox. Based on the ID, we will find it at storage/analyses/46/reports
:
See on the Dropped Files section:
There is autoexec.bat which...
Change the font size
Change margin width
Change background colour