cuckoosandbox / cuckoo

Cuckoo Sandbox is an automated dynamic malware analysis system
http://www.cuckoosandbox.org
Other
5.55k stars 1.71k forks source link

Cuckoo wired Error on Agent #1918

Open xyarden opened 6 years ago

xyarden commented 6 years ago

Hello, I'm using cuckoo v2.0.4, with VirtualBox I have an agent with python 2.7 in it, Windows7. been trying to run an exe file on cuckoo (all configured and installed as your guide), for example calc.exe. and I get this error: """ Error from the Cuckoo Guest: Analysis failed: Unable to execute the initial process, analysis aborted. Traceback (most recent call last): File "C:\wbkfmdd\analyzer.py", line 794, in success = analyzer.run() File "C:\wbkfmdd\analyzer.py", line 649, in run pids = self.package.start(self.target) File "C:\wbkfmdd\modules\packages\exe.py", line 23, in start return self.execute(path, args=shlex.split(args)) File "C:\wbkfmdd\lib\common\abstracts.py", line 165, in execute "Unable to execute the initial process, analysis aborted." CuckooPackageError: Unable to execute the initial process, analysis aborted. """ I saw that after running there are some wired\random strings folders with a lot of empty Python files in it, like abstracts.py (all on agent), the file that is in the error is empty.

I hope I get replication from you guys !! I`d really want to use cuckoo sandbox.

gugronnier commented 6 years ago

same error here: https://github.com/cuckoosandbox/cuckoo/issues/1672 for cuckoo 2.0.4, update your cuckoo version

but i have the same problem on cuckoo 2.0.5 (https://github.com/cuckoosandbox/cuckoo/issues/2098)

jbremer commented 6 years ago

Please share a sample. Will be closing this issue otherwise.

gugronnier commented 6 years ago

the link to my sample : https://mega.nz/#!oEkRBIwY!4kQMJI1IKbxS5M_6yDM9hZy4t4o4q3lT73vNwI1nCAk it is not coded in VB.NET, it is in C#

my version is already updated, i installed it last week (github version)

gugronnier commented 6 years ago

i also find the source code of this sample, but i can't share it here (it is not secure)

gugronnier commented 6 years ago

if you want it, contact me by mail with my public gpg key.