Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Get help with cuckoo module #1978

Open
TrungAnhNguyen2k2 opened this issue Oct 1, 2023 · 2 comments
Open

Get help with cuckoo module #1978

TrungAnhNguyen2k2 opened this issue Oct 1, 2023 · 2 comments
Labels

Comments

@TrungAnhNguyen2k2
Copy link

Describe the bug
I got trouble with the yara-cuckoo module rule.
To Reproduce
Steps to reproduce the behavior:
I use module cuckoo to write this rule to test
image

And here are the behaviors in the report.json file from cuckoo that I use to write rule.

image

image

But when I ran the command, nothing happen. ( The "2280898cb29faf1785e782596d8029cb471537ec38352e5c17cc263f1f52b8ef" is the malware file that I want to scan)

image

Please tell me, where did I do wrong and how to fix it. Hope you guy answer soon. Thank you very much

  • YARA version: [4.4.0]
@plusvic
Copy link
Member

plusvic commented Oct 2, 2023

What version of cuckoo are you using? The cuckoo module works with very old versions and haven't been updated in a long time. If you are using a recent version of cuckoo the JSON format has probably changed.

@TrungAnhNguyen2k2
Copy link
Author

What version of cuckoo are you using? The cuckoo module works with very old versions and haven't been updated in a long time. If you are using a recent version of cuckoo the JSON format has probably changed.

Hi I'm using the (https://sandbox.pikker.ee/) so it's the 2.0.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants