-
Notifications
You must be signed in to change notification settings - Fork 498
Description
Prerequisites
Please answer the following questions for yourself before submitting an issue.
- I am running the latest version
- I did read the README!
- I checked the documentation and found no answer
- I checked to make sure that this issue has not already been filed
- I'm reporting the issue to the correct repository (for multi-repository projects)
- I have read and checked all configs (with all optional parts)
Expected Behavior
PCAP File beeing generated correcty and contains packet dumps. Contacted hosts and DNS Requests are beeing displayed in the analysis report.
Current Behavior
Analysis runs, gets reported but Network analysis is empty, downloading the pcap file brings up an empty dump file.
Steps to Reproduce
Please provide detailed steps for reproducing the issue.
- Start Analysis Task
- Check Reported Task
- No Contacted Hosts or DNS Requests
Context
I did check the docs more than once and can not find any issue.
I've checked the troubleshooting section regarding pcap generation as well, checked the pcap permissions for cape but still won't work.
$ ll /usr/bin/tcpdump
-rwxr-xr-x 1 root pcap 1273976 Feb 16 2025 /usr/bin/tcpdump*
$ getent group pcap
pcap:x:1002:cape
tcpdump path is correct as well:
$ whereis tcpdump
tcpdump: /usr/bin/tcpdump /usr/share/man/man8/tcpdump.8.gz
In the analysis folder, there will always be a dump.pcap file, which is empty.
"enp6s18" is the interface which provides internet connectivity. Which cape seems to be using for pcap generation.
Manually running tcpdump as cape user works fine as seen below, so this should not be an issue regarding permissions.
$ sudo -u cape tcpdump -i enp6s18
[sudo] password for sandy:
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on enp6s18, link-type EN10MB (Ethernet), snapshot length 262144 bytes
10:11:23.457190 IP madlen-sandbox.ssh > 10.10.88.1.55322: Flags [P.], seq 1874148051:1874148259, ack 3562662718, win 1431, length 208
10:11:23.512504 IP 10.10.88.1.55322 > madlen-sandbox.ssh: Flags [.], ack 0, win 254, length 0
10:11:23.539742 IP 10.10.88.1.55322 > madlen-sandbox.ssh: Flags [P.], seq 1:161, ack 208, win 253, length 160
10:11:23.540064 IP madlen-sandbox.ssh > 10.10.88.1.55322: Flags [P.], seq 208:256, ack 161, win 1452, length 48
10:11:23.550665 IP madlen-sandbox.53217 > dns9.quad9.net.domain: 32350+ [1au] PTR? 1.88.10.10.in-addr.arpa. (52)
10:11:23.578182 IP dns9.quad9.net.domain > madlen-sandbox.53217: 32350 NXDomain- 0/0/1 (52)
10:11:23.579691 IP madlen-sandbox.49724 > dns9.quad9.net.domain: 26458+ [1au] PTR? 5.195.168.192.in-addr.arpa. (55)
10:11:23.595055 IP dns9.quad9.net.domain > madlen-sandbox.49724: 26458 NXDomain- 0/0/1 (55)
Failure Logs
Cape Analysis Log:
CAPE: Config and Payload Extraction
github.com/kevoreilly/CAPEv2
XLMMacroDeobfuscator: pywin32 is not installed (only is required if you want to use MS Excel)
pip3 install certvalidator asn1crypto mscerts
2025-08-19 09:42:23,788 [modules.processing.network] INFO: Loading maxmind database from /opt/CAPEv2/modules/processing/../../data/GeoLite2-Country.mmdb
/usr/bin/tcpdump
2025-08-19 09:42:24,172 [lib.cuckoo.core.machinery_manager] INFO: Using MachineryManager[proxmox] with max_machines_count=10
2025-08-19 09:42:24,172 [lib.cuckoo.core.scheduler] INFO: Creating scheduler with max_analysis_count=unlimited
2025-08-19 09:42:24,192 [lib.cuckoo.core.machinery_manager] INFO: Loaded 1 machine
2025-08-19 09:42:24,257 [lib.cuckoo.core.machinery_manager] INFO: max_vmstartup_count for BoundedSemaphore = 5
2025-08-19 09:42:24,261 [lib.cuckoo.core.scheduler] INFO: Waiting for analysis tasks
2025-08-19 09:46:24,620 [lib.cuckoo.core.machinery_manager] INFO: Task #4: found useable machine SBX-Windows10-01 (arch=x86, platform=windows)
2025-08-19 09:46:24,620 [lib.cuckoo.core.scheduler] INFO: Task #4: Processing task
2025-08-19 09:46:24,875 [lib.cuckoo.core.analysis_manager] INFO: Task #4: File already exists at '/opt/CAPEv2/storage/binaries/4d70290367ad03399e17d5001842553fcd4d57e026eb330add0e3f28327d79a7'
2025-08-19 09:46:24,876 [lib.cuckoo.core.analysis_manager] INFO: Task #4: Starting analysis of FILE '/tmp/cuckoo-tmp/upload_kkwhui6f/ChromeSetup.exe'
2025-08-19 09:46:28,758 [lib.cuckoo.core.analysis_manager] INFO: Task #4: Enabled route 'internet'.
2025-08-19 09:46:28,773 [modules.auxiliary.Mitmdump] INFO: Mitmdump module loaded
2025-08-19 09:46:28,774 [modules.auxiliary.PolarProxy] INFO: PolarProxy module loaded
2025-08-19 09:46:28,774 [modules.auxiliary.QemuScreenshots] INFO: QEMU screenshots module loaded
/usr/bin/tcpdump
2025-08-19 09:46:28,789 [modules.auxiliary.sniffer] INFO: Started sniffer with PID 26677 (interface=enp6s18, host=192.168.99.20, dump path=/opt/CAPEv2/storage/analyses/4/dump.pcap)
2025-08-19 09:46:30,085 [lib.cuckoo.core.guest] INFO: Task #4: Starting analysis on guest (id=SBX-Windows10-01, ip=192.168.99.20)
2025-08-19 09:46:58,196 [lib.cuckoo.core.guest] INFO: Task #4: Guest is running CAPE Agent 0.11 (id=SBX-Windows10-01, ip=192.168.99.20)
2025-08-19 09:47:02,270 [lib.cuckoo.core.guest] INFO: Task #4: Uploading script files to guest (id=SBX-Windows10-01, ip=192.168.99.20)
2025-08-19 09:47:11,585 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 7584 (parent 5872): ChromeSetup.exe, path C:\Users\Peter Silie\AppData\Local\Temp\ChromeSetup.exe
2025-08-19 09:47:13,617 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 8604 (parent 7584): updater.exe, path C:\Users\Peter Silie\AppData\Local\Temp\Google7584_1487186110\bin\updater.exe
2025-08-19 09:47:14,381 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 5516 (parent 8604): updater.exe, path C:\Users\Peter Silie\AppData\Local\Temp\Google7584_1487186110\bin\updater.exe
2025-08-19 09:47:15,881 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 1188 (parent 768): svchost.exe, path C:\Windows\System32\svchost.exe
2025-08-19 09:48:08,918 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 7816 (parent 1188): taskhostw.exe, path C:\Windows\System32\taskhostw.exe
2025-08-19 09:48:58,604 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 5244 (parent 5212): explorer.exe, path C:\Windows\explorer.exe
2025-08-19 09:49:05,053 [lib.cuckoo.core.resultserver] INFO: Task 4: Process 8916 (parent 1188): taskhostw.exe, path C:\Windows\System32\taskhostw.exe
2025-08-19 09:49:18,536 [lib.cuckoo.core.guest] INFO: Task #4: Analysis completed successfully (id=SBX-Windows10-01, ip=192.168.99.20)
2025-08-19 09:49:18,682 [lib.cuckoo.core.analysis_manager] INFO: Task #4: Disabled route 'internet'
2025-08-19 09:49:21,141 [lib.cuckoo.core.analysis_manager] INFO: Task #4: Completed analysis successfully.
2025-08-19 09:49:21,147 [lib.cuckoo.core.analysis_manager] INFO: Task #4: analysis procedure completed