Open IceM4nn opened 4 years ago
Does anyone here got the same issue? to be specific with Windows XP. Any solution? The analyzer stuck at auxiliary module Disguise and not completing the analysis properly. The analysis hit timeout and shutdown the VM.
I'm using Windows XP as well. Seems like monitor inject-*.exe
has problems. It doesn't terminate. Procmon
confirms that monitor-*.dll
is loaded. But since inject-*.exe
doesn't stop. There's an error some where or a hangup. Which results in a not complete dll entrypoint execution.
The first time analyzer.py
tries to call inject
is in DumpTLSMasterSecrets
(dumptls.py
) auxiliary module.
These issue claimed to fix a bug - #1581, #1484.
My issue is:
Analyzer in Windows XP guest is not working properly and stuck at auxiliary module Disguise. Behavioral analysis is empty.
My Cuckoo version and operating system are:
Host is Ubuntu 18.04 amd64 Guest is Windows XP x64 SP2 Cuckoo version is 2.0.7 Machinery is KVM
This can be reproduced by:
Upload any samples to Windows XP. (pdf, docx also same)
Other information
Firewall has been disabled. The agent is running as Administrator privileged. Host and guest can communicated each other (ping and curl to guest port 8000 works fine). In this test, I upload pafish.exe. I also view the VM during the analysis and seems nothing happened. no cmd window open. if I upload other file type also seems nothing happened. no pdf reader nor ms word are opened.
The log, error, files etc can be found at:
analyzer.log
cuckoo.log