CERT-Polska / drakvuf-sandbox

DRAKVUF Sandbox - automated hypervisor-level malware analysis system
https://drakvuf-sandbox.readthedocs.io/
Other
1.06k stars 143 forks source link

My behavioral graph does not show up #446

Open fareedfauzi opened 3 years ago

fareedfauzi commented 3 years ago

Hi sir, can you help me?

I have followed this instruction in docs:

image

drakvuf@drakvuf:~$ ls -la /opt/procdot/
total 4396
drwxr-xr-x 3 root root    4096 Ogos 28  2018 ./
drwxr-xr-x 4 root root    4096 Feb  25 15:42 ../
drwxr-xr-x 4 root root    4096 Dis   1  2017 plugins/
-rw-r--r-- 1 root root 3683256 Ogos 28  2018 procdot
-rwxr-xr-x 1 root root  801320 Mac   8  2018 procmon2dot*

But my sandbox not getting the graph behavior feature

image

BonusPlay commented 3 years ago

Hello! Could you pleaese provide logs, so we can narrow down the issue? You can access them by going into "logs" tab and then going into "services". We're looking for "drakrun.log" and "drak-postprocess.log" :)

fareedfauzi commented 3 years ago

Hello! Thanks for your response. Here the logs:

Drakrun.log

hostname: drakvuf
running sample sha256: 6b0bdb675b4edca05f802e4a48e879c9f0f9bcedb8bc362d77ec714f3df6baa6
analysis UID: 4879d0bc-4fe3-4212-8ffb-10967946ace8
Running file as exe
Using file name 6b0bdb675b4edca05f802e4a48e879c9f0f9bcedb8bc362d77ec714f3df6baa6.exe
Running VM 1
running monitor 1
Copying sample to VM...
Using command: C:\Users\DrakvufAnalysis\Desktop\6b0bdb675b4edca05f802e4a48e879c9f0f9bcedb8bc362d77ec714f3df6baa6.exe
Setting up network...
waiting for tcpdump to exit
uploading artifacts

Drak-postprocess.log

Postprocess failed
Skipping generate_wireshark_key_file, missing resources
Skipping generate_ipt_disasm, missing resources