Open pharZyde opened 5 years ago
anyone has any ideas on how to solve this? I think I configured all config files correctly but although cuckoo log tells me that it successfully created the memory.dmp it is nowhere to find
just tested it with a WinXP machine as guest but same problem occurs
tested it with Win7 Professional x32 as guest, same problem. probalby an issue on the host... anyone has any idea on what to do?
problem is because I am using nested vm which is not directly supported by cuckoo
I changed my setup now: Cuckoo is running on a physical machine now (so no nested VM anymore) and I am using Win7 Ultimate x64 instead of x86 now. Apart from that, the whole settings, versions and configurations are exactly the same. But I still get the same error when trying to get a full memory dump... Can anybody help please? It is really important for me that memory dumps are working since that is a part of my project scope. Thanks
Same issue in Ubuntu 18.04 with Virtualbox 6.0.6/8, Volatility 2.6 and Win7SP1x64. Tried with a custom Vbox and with a normal one, same problem.
Hello,
My issue is:
Cuckoo's log files telling me that a memory dump has successfully been generated but it can not access them because they can not be found. Manually looking for them in the directory confirms that.
My Cuckoo version and operating system are:
Cuckoo: 2.0.6 Host: Ubuntu 18.04.1 LTS Guest: Win7 Ultimate, Service Pack 1, 32-bit
This can be reproduced by:
Those are my config files:
cuckoo.conf
memory.conf
processing.conf
The log, error, files etc can be found at:
This is the output of the cuckoo.log:
Any kind of help is appreciated. It is my first time posting here but desperate times call for desperate measures. If you need any more information from me please let me know
Edit: Only memory dump of full machine is not being generated. If malware is injected in a new process then memory dump is generated as shown in the report.json
and I can also find the 3844-1.dmp file in the directory