Skip to content

Issues regarding pcap generation - pcap file is always empty #2673

@Sk4hnt42

Description

@Sk4hnt42

Prerequisites

Please answer the following questions for yourself before submitting an issue.

  • I am running the latest version
  • I did read the README!
  • I checked the documentation and found no answer
  • I checked to make sure that this issue has not already been filed
  • I'm reporting the issue to the correct repository (for multi-repository projects)
  • I have read and checked all configs (with all optional parts)

Expected Behavior

PCAP File beeing generated correcty and contains packet dumps. Contacted hosts and DNS Requests are beeing displayed in the analysis report.

Current Behavior

Analysis runs, gets reported but Network analysis is empty, downloading the pcap file brings up an empty dump file.

Steps to Reproduce

Please provide detailed steps for reproducing the issue.

  1. Start Analysis Task
  2. Check Reported Task
  3. No Contacted Hosts or DNS Requests

Context

I did check the docs more than once and can not find any issue.
I've checked the troubleshooting section regarding pcap generation as well, checked the pcap permissions for cape but still won't work.

$ ll /usr/bin/tcpdump
-rwxr-xr-x 1 root pcap 1273976 Feb 16  2025 /usr/bin/tcpdump*

$ getent group pcap
pcap:x:1002:cape

tcpdump path is correct as well:

$ whereis tcpdump
tcpdump: /usr/bin/tcpdump /usr/share/man/man8/tcpdump.8.gz

In the analysis folder, there will always be a dump.pcap file, which is empty.

"enp6s18" is the interface which provides internet connectivity. Which cape seems to be using for pcap generation.

Manually running tcpdump as cape user works fine as seen below, so this should not be an issue regarding permissions.

$ sudo -u cape tcpdump -i enp6s18
[sudo] password for sandy:
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on enp6s18, link-type EN10MB (Ethernet), snapshot length 262144 bytes
10:11:23.457190 IP madlen-sandbox.ssh > 10.10.88.1.55322: Flags [P.], seq 1874148051:1874148259, ack 3562662718, win 1431, length 208
10:11:23.512504 IP 10.10.88.1.55322 > madlen-sandbox.ssh: Flags [.], ack 0, win 254, length 0
10:11:23.539742 IP 10.10.88.1.55322 > madlen-sandbox.ssh: Flags [P.], seq 1:161, ack 208, win 253, length 160
10:11:23.540064 IP madlen-sandbox.ssh > 10.10.88.1.55322: Flags [P.], seq 208:256, ack 161, win 1452, length 48
10:11:23.550665 IP madlen-sandbox.53217 > dns9.quad9.net.domain: 32350+ [1au] PTR? 1.88.10.10.in-addr.arpa. (52)
10:11:23.578182 IP dns9.quad9.net.domain > madlen-sandbox.53217: 32350 NXDomain- 0/0/1 (52)
10:11:23.579691 IP madlen-sandbox.49724 > dns9.quad9.net.domain: 26458+ [1au] PTR? 5.195.168.192.in-addr.arpa. (55)
10:11:23.595055 IP dns9.quad9.net.domain > madlen-sandbox.49724: 26458 NXDomain- 0/0/1 (55)

Failure Logs

Cape Analysis Log:

CAPE: Config and Payload Extraction
github.com/kevoreilly/CAPEv2

XLMMacroDeobfuscator: pywin32 is not installed (only is required if you want to use MS Excel)
pip3 install certvalidator asn1crypto mscerts
2025-08-19 09:42:23,788 [modules.processing.network] INFO: Loading maxmind database from /opt/CAPEv2/modules/processing/../../data/GeoLite2-Country.mmdb
/usr/bin/tcpdump
2025-08-19 09:42:24,172 [lib.cuckoo.core.machinery_manager] INFO: Using MachineryManager[proxmox] with max_machines_count=10
2025-08-19 09:42:24,172 [lib.cuckoo.core.scheduler] INFO: Creating scheduler with max_analysis_count=unlimited
2025-08-19 09:42:24,192 [lib.cuckoo.core.machinery_manager] INFO: Loaded 1 machine
2025-08-19 09:42:24,257 [lib.cuckoo.core.machinery_manager] INFO: max_vmstartup_count for BoundedSemaphore = 5
2025-08-19 09:42:24,261 [lib.cuckoo.core.scheduler] INFO: Waiting for analysis tasks
2025-08-19 09:46:24,620 [lib.cuckoo.core.machinery_manager] INFO: Task #4: found useable machine SBX-Windows10-01 (arch=x86, platform=windows)
2025-08-19 09:46:24,620 [lib.cuckoo.core.scheduler] INFO: Task #4: Processing task
2025-08-19 09:46:24,875 [lib.cuckoo.core.analysis_manager] INFO: Task #4: File already exists at '/opt/CAPEv2/storage/binaries/4d70290367ad03399e17d5001842553fcd4d57e026eb330add0e3f28327d79a7'
2025-08-19 09:46:24,876 [lib.cuckoo.core.analysis_manager] INFO: Task #4: Starting analysis of FILE '/tmp/cuckoo-tmp/upload_kkwhui6f/ChromeSetup.exe'
2025-08-19 09:46:28,758 [lib.cuckoo.core.analysis_manager] INFO: Task #4: Enabled route 'internet'.
2025-08-19 09:46:28,773 [modules.auxiliary.Mitmdump] INFO: Mitmdump module loaded
2025-08-19 09:46:28,774 [modules.auxiliary.PolarProxy] INFO: PolarProxy module loaded
2025-08-19 09:46:28,774 [modules.auxiliary.QemuScreenshots] INFO: QEMU screenshots module loaded
/usr/bin/tcpdump
2025-08-19 09:46:28,789 [modules.auxiliary.sniffer] INFO: Started sniffer with PID 26677 (interface=enp6s18, host=192.168.99.20, dump path=/opt/CAPEv2/storage/analyses/4/dump.pcap)
2025-08-19 09:46:30,085 [lib.cuckoo.core.guest] INFO: Task #4: Starting analysis on guest (id=SBX-Windows10-01, ip=192.168.99.20)
2025-08-19 09:46:58,196 [lib.cuckoo.core.guest] INFO: Task #4: Guest is running CAPE Agent 0.11 (id=SBX-Windows10-01, ip=192.168.99.20)
2025-08-19 09:47:02,270 [lib.cuckoo.core.guest] INFO: Task #4: Uploading script files to guest (id=SBX-Windows10-01, ip=192.168.99.20)
2025-08-19 09:47:11,585 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 7584 (parent 5872): ChromeSetup.exe, path C:\Users\Peter Silie\AppData\Local\Temp\ChromeSetup.exe
2025-08-19 09:47:13,617 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 8604 (parent 7584): updater.exe, path C:\Users\Peter Silie\AppData\Local\Temp\Google7584_1487186110\bin\updater.exe
2025-08-19 09:47:14,381 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 5516 (parent 8604): updater.exe, path C:\Users\Peter Silie\AppData\Local\Temp\Google7584_1487186110\bin\updater.exe
2025-08-19 09:47:15,881 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 1188 (parent 768): svchost.exe, path C:\Windows\System32\svchost.exe
2025-08-19 09:48:08,918 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 7816 (parent 1188): taskhostw.exe, path C:\Windows\System32\taskhostw.exe
2025-08-19 09:48:58,604 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 5244 (parent 5212): explorer.exe, path C:\Windows\explorer.exe
2025-08-19 09:49:05,053 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 8916 (parent 1188): taskhostw.exe, path C:\Windows\System32\taskhostw.exe
2025-08-19 09:49:18,536 [lib.cuckoo.core.guest] INFO: Task #4: Analysis completed successfully (id=SBX-Windows10-01, ip=192.168.99.20)
2025-08-19 09:49:18,682 [lib.cuckoo.core.analysis_manager] INFO: Task #4: Disabled route 'internet'
2025-08-19 09:49:21,141 [lib.cuckoo.core.analysis_manager] INFO: Task #4: Completed analysis successfully.
2025-08-19 09:49:21,147 [lib.cuckoo.core.analysis_manager] INFO: Task #4: analysis procedure completed

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions