Closed uncleAntik closed 7 years ago
So I install auditd and configure it to audit vbox.sh (symlink /usr/bin/VBoxManage).
When I submit file for analyse cuckoo submit filepath
ausearch show me this
time->Wed May 24 16:17:05 2017
type=PROCTITLE msg=audit(1495631825.777:195826): proctitle=2F62696E2F7368002F7573722F62696E2F56426F784D616E6167650073686F77766D696E666F006375636B6F6F3131002D2D6D616368696E657265616461626C65
type=PATH msg=audit(1495631825.777:195826): item=2 name="/lib64/ld-linux-x86-64.so.2" inode=13373821 dev=fc:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
type=PATH msg=audit(1495631825.777:195826): item=1 name="/bin/sh" inode=1179668 dev=fc:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
type=PATH msg=audit(1495631825.777:195826): item=0 name="/usr/bin/VBoxManage" inode=4852184 dev=fc:00 mode=0100745 ouid=0 ogid=0 rdev=00:00 nametype=NORMAL
type=CWD msg=audit(1495631825.777:195826): cwd="/home/anton"
type=EXECVE msg=audit(1495631825.777:195826): argc=5 a0="/bin/sh" a1="/usr/bin/VBoxManage" a2="showvminfo" a3="cuckoo11" a4="--machinereadable"
type=SYSCALL msg=audit(1495631825.777:195826): arch=c000003e syscall=59 success=yes exit=0 a0=7fce081455e0 a1=7fce08092190 a2=2db31e0 a3=97 items=3 ppid=5145 pid=6570 auid=1001 uid=1001 gid=1001 euid=1001 suid=1001 fsuid=1001 egid=1001 sgid=1001 fsgid=1001 tty=pts1 ses=2 comm="VBoxManage" exe="/bin/dash" key="vboxm"
I dont see in aurearch any try to start vm or restore to current snapshot or something more. Why cuckoo don
t start vm after submitting file?
I have the same problem,how to fix this?
why status is saved
? it should be running
@cheantik Well, you have to actually run the Cuckoo daemon (i.e., cuckoo -d
).
@weiqiangdragonite Which problem exactly?
Cuckoo daemon is running, Then I submit a file cuckoo dont start a vm for analyse a file.
2017-05-23 11:38:09,390 [cuckoo.core.scheduler] ERROR: Error starting Virtual Machine! VM: cuckoo11, error: Timeout hit while for machine cuckoo11 to change status`
At the same time (cuckoo daemon is running, file submitted) auditd shows me many times only one exec-
type=EXECVE msg=audit(1495631825.777:195826): argc=5 a0="/bin/sh" a1="/usr/bin/VBoxManage" a2="showvminfo" a3="cuckoo11" a4="--machinereadable"
@chentik I have solve this problem, I think is the virtualbox snapshot cause the cuckoo cant start the vm. I suggest you re-create the vm snapshot follow the cuckoo docs http://docs.cuckoosandbox.org/en/latest/installation/guest/saving/
@weiqiangdragonite It`s work for me too. Only after delete and re-create vm snapshot as described here http://docs.cuckoosandbox.org/en/latest/installation/guest/saving/ vm started. Thanks!
Hello friends.
First of all I
m sorry for barbarien english. I am running cuckoo on Ubuntu 16.04.2 LTS host and Windows 7 x64 as a guest under virtualbox-headless. Guest ip is 192.168.5.5, host ip is 192.168.5.1. Guest connected with hostonly connection and can ping host. At boot agent.pyw succesfully started and from host I can see an open port 8000 on guest. If I first run guest vm and after what run cuckoo my vm stoped and restoring to it
s current snapshot. Everything looks fine until I try to submit a file for analisys. I receive an error: Error starting Virtual Machine! VM: cuckoo11, error: Timeout hit while for machine cuckoo11 to change status Its seems what cuckoo can
t start guest vm after submitting file for analisys. Detailed log cuckoo -dAt the same time "vboxmanage list runningvms" shows nothing. My virtualbox.conf
So, I just don`t understand why it happens and how I can resolve my issue. Any help will be appreciated