Open jmigot-tehtris opened 9 years ago
After using the recompiled cuckoomon.dll with debug mode for x86, it appears that Office 2010 under Windows XP has the same issue now.
Cuckoomon currently logs all exceptions, even those that are handled. It's possible that the issue is unrelated to the exceptions reported.
Brad, if you have any idea on how I can debug this situation by modifying cuckoo or cuckoomon code, I can test that and post back the results here in order to help you on this issue.
The crashs of Office 2013 with Windows 7 exist from a long time (several weeks/maybe months) as far as I observed.
What would help is the confirmation of other people reading this confirming they are experiencing the same issue.
I will try doing some tests and post everything I have here (I will try upstream code for example).
You could try a binary-search strategy removal of hooks until the problem disappears. Or perhaps begin with setting the DISABLE_HOOK_CONTENT define in ntapi.h to 1 (to see if the issue is unrelated to hooks).
@brad-accuvant This does seem hook related. setting DISABLE_HOOK_CONTENT to 1 stops the crashing. In trying to track down the exception, I also tried setting setting REPORT_EXCEPTIONS and REPORT_ALL_EXCEPTIONS to 1, but I still don''t see any exceptions logged in analysis.log. Are they logged there?
Where would I start removing hooks to debug this? I know next to nothing about the win32 API.
Correction to my old post: It looks like this bug only effects 64-bit office. 32-bit office 2013 on windows7 64-bit works fine.
Very odd, as DISABLE_HOOK_CONTENT will still result in the hook being placed and none of the changes made today affected 64-bit hooking ;)
Yeah, I accidentally ran the sample on a 32-bit office box I was testing and thought the bug had been fixed for 64-bit. Seems line this bug only ever effected 64-bit office, so if anyone needs a workaround in the meantim, 32-bit office on 64-bit windows 7 works fine.
Hi,
I am running Windows 7 x64 with Microsoft Office 2013 x64 and Cuckoo inside Python x86. Whenever I upload a .doc file, I get a crash of WINWORD.EXE. Word is running fine when I launch it by hand on the same machine, and moreover I can start it through Python 32 bit command line, either with subprocess or with the KERNEL32.CreateProcess() method used in Cuckoo, with the same parameters.
I've recompiled Cuckoo with debug mode enabled and got this exception :
For the record, everything is fine with Windows XP and Office 2010. All my tests have been done with the latest Cuckoo sources taken from repository yesterday.
Do you have any idea of what's going on ? Is anyone experimenting same issue or am I the only one using Office 2013 inside Windows 7 x64 in Cuckoo ?
There is the same issue with an .xls file or a .docm file, for example. Test sample : https://www.virustotal.com/en/file/1baec98158be31c1fd6dcf2fdc849a41889f4f2a277969f7a0ed8387470a3405/analysis/
Thanks