
Cuckoo Malware Analysis

Have you ever heard about CuckooMX? It is a project by Xavier Mertens, you can read it at http://blog.rootshell.be/2012/06/20/cuckoomx-automating-email-attachments-scanning-with-cuckoo/.
CuckooMX automatically sends all the e-mail attachments to Cuckoo Sandbox, obviously, so that it can be analyzed whether the attachments—of types such as PDF, MS Office, ZIP, or other executable files—contain malware or not.
Here is a figure that might help us get a better picture of what CuckooMX does:
In the preceding figure, we can see that CuckooMX performs these tasks:
It captures the e-mail flow at MTA (Message/Mail Transfer Agent) level.
Extracts MIME (Multipurpose Internet Mail Extensions) attachments.
If it finds any PDF, MS Office, ZIP, or other executable files attached to the e-mail, that file is submitted to Cuckoo Sandbox.
If Cuckoo found nothing interesting and it is likely safe, it will send the attachments back to the MTA.
If suspicious files are found...
Change the font size
Change margin width
Change background colour