cuckoosandbox / cuckoo

Cuckoo Sandbox is an automated dynamic malware analysis system
http://www.cuckoosandbox.org
Other
5.49k stars 1.7k forks source link

Analyzing malwares embedded in pdf files #3179

Open arunppsg opened 3 years ago

arunppsg commented 3 years ago

When a malware is embedded in a pdf file and submitted to cuckoo, cuckoo was not able to detect it. But when the same malware is submitted to cuckoo as it is, cuckoo was able to detect it successfully.

The issue is: I would like to know what part of code deals with embedded file / how embedded files are handled in cuckoo.

What I have tried so far:

Any help in the relevant directions will be helpful.

pavit939 commented 3 years ago

I had the same issue. When I tried to embed malware in a pdf file and send it to cuckoo, it was unable to detect the Malware. While, when the executable file was sent directly cuckoo was able to detect the Malware. Where you able to come out with the solution for this problem?

mfc commented 3 years ago

i can confirm this issue with Cuckoo version 2.0.7