Closed RebootPhoenix closed 2 weeks ago
Sorry miss clicked the close issue button!
Hopefully I've supplied all the information needed. Thank you in advance for your time! :)
Try reprocess it by hand in debug mode(see readme )
El vie, 7 jun 2024, 15:00, Phoenix @.***> escribió:
Sorry miss clicked the close issue button!
Hopefully I've supplied all the information needed. Thank you in advance for your time! :)
— Reply to this email directly, view it on GitHub https://github.com/kevoreilly/CAPEv2/issues/2159#issuecomment-2154788692, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAOFH36TXB2FSGAIFFDUXGTZGGVGTAVCNFSM6AAAAABI6TZ2Q6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDCNJUG44DQNRZGI . You are receiving this because you are subscribed to this thread.Message ID: @.***>
Following your request, I ran the command $ poetry run python3 process.py -r 9 -d This successfully processed and generated a report! Great :) (logs are rather large https://pastebin.com/cuYaHGhk )
So I submitted a new sample, and I got the same error that processing failed with the same log message for the error.
This lead me to test running the process.py again on that sample, and it successfully generated the process report when manually called with the command above.
I then tested running the process.py without the -r flag. If I do not include this flag then the processing fails with the same original error from the logs.
2024-06-07 13:36:47,673 [root] INFO: Processing analysis data for Task #13
Jun 07 13:36:47 cape python3[4678]: 2024-06-07 13:36:47,694 [root] ERROR: [13] Exception when processing task: 'info'
Jun 07 13:36:47 cape python3[4678]: pebble.common.RemoteTraceback: Traceback (most recent call last):
Jun 07 13:36:47 cape python3[4678]: File "/home/cape/.cache/pypoetry/virtualenvs/capev2-t2x27zRb-py3.10/lib/python3.10/site-packages/pebble/common.py", line 174, in process_execute
Jun 07 13:36:47 cape python3[4678]: return function(*args, **kwargs)
Jun 07 13:36:47 cape python3[4678]: File "/opt/CAPEv2/utils/process.py", line 129, in process
Jun 07 13:36:47 cape python3[4678]: RunSignatures(task=task_dict, results=results).run()
Jun 07 13:36:47 cape python3[4678]: File "/opt/CAPEv2/utils/../lib/cuckoo/core/plugins.py", line 341, in __init__
Jun 07 13:36:47 cape python3[4678]: self.signatures.append(signature(self.results))
Jun 07 13:36:47 cape python3[4678]: File "/opt/CAPEv2/utils/../modules/signatures/windows/injection_rwx.py", line 27, in __init__
Jun 07 13:36:47 cape python3[4678]: if self.results["info"]["package"] not in ["exe", "rar", "zip", "dll", "regsvr"]:
Jun 07 13:36:47 cape python3[4678]: KeyError: 'info'
Jun 07 13:36:47 cape python3[4678]: The above exception was the direct cause of the following exception:
Jun 07 13:36:47 cape python3[4678]: Traceback (most recent call last):
Jun 07 13:36:47 cape python3[4678]: File "/opt/CAPEv2/utils/process.py", line 277, in processing_finished
Jun 07 13:36:47 cape python3[4678]: _ = future.result()
Jun 07 13:36:47 cape python3[4678]: File "/usr/lib/python3.10/concurrent/futures/_base.py", line 451, in result
Jun 07 13:36:47 cape python3[4678]: return self.__get_result()
Jun 07 13:36:47 cape python3[4678]: File "/usr/lib/python3.10/concurrent/futures/_base.py", line 403, in __get_result
Jun 07 13:36:47 cape python3[4678]: raise self._exception
Jun 07 13:36:47 cape python3[4678]: KeyError: 'info'
So my guess is that I've not correctly configured something for the cape-process ?
Process and reprocess uses the same config, did you restar cape processing to try if that fixed?
About accounts on capesandbox.com
This is open source and you are getting free support so be friendly!
Prerequisites
Please answer the following questions for yourself before submitting an issue.
Expected Behavior
After submitting a sample via the web interface, it reports analysis complete in the logs and completes the report processing.
Current Behavior
Submitting a sample via the web interface works, logs report analysis completes, but the web interface reports failed_processing. I do not understand how to solve the exception message thrown in the logs
Steps to Reproduce
Context
Failure Logs
from $ journalctl -u cape-processor:
from $ journalctl -u cape: