cuckoosandbox / cuckoo

Cuckoo Sandbox is an automated dynamic malware analysis system
http://www.cuckoosandbox.org
Other
5.52k stars 1.7k forks source link

Used Enable Injection feature breaks Office #2936

Open pypygeek opened 4 years ago

pypygeek commented 4 years ago

Hi, Thank you for providing a good service. I want to enable Injection to get better results.

2200 is a related issue

Please help me

My issue is:

han office

My Cuckoo version and operating system are:

Cuckoo Sandbox Version : 2.0.7 Host OS : Ubuntu Desktop 18.04.3 LTS (GNU/Linux 4.15.0-72-generic x86_64) Guest OS: Windwos 10 Pro_64Bit [Guest Office - Default Setting] Microsoft Office Professional Plus 2010 Hangul Office 2010

This can be reproduced by:

Using Enable Injection

The log, error, files etc can be found at:

Result nothing.

doomedraven commented 4 years ago

win10 isn't supported, you can extend monitor by yourself or pay for solution https://hatching.io/solutions

RicoVZ commented 4 years ago

Hey pypygeek,

Thanks for posting an issue.

As doomedraven states, the Cuckoo monitor (the component that is injected), currently has not been prepared for Windows 10. This can cause issues like yours. We are currently working on a new Python 3 version of Cuckoo, which will support Windows 10. More details about this will be shared the coming weeks.