Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VM CPU usage at 100% when using ie URL analysis package #333

Open
seanthegeek opened this issue Apr 18, 2019 · 12 comments
Open

VM CPU usage at 100% when using ie URL analysis package #333

seanthegeek opened this issue Apr 18, 2019 · 12 comments

Comments

@seanthegeek
Copy link
Contributor

Some recent change in the analysis package is causing CPU usage to stay at 100% without IE actually opening during a URL analysis with the ie package.

@kevoreilly
Copy link
Contributor

Hi Sean, sorry not to get back to you earlier - are you still seeing this?

@seanthegeek
Copy link
Contributor Author

Yes, I'm still seeing this after pulling the latest commit this morning

@seanthegeek
Copy link
Contributor Author

@kevoreilly Bump

@seanthegeek
Copy link
Contributor Author

Also occurs on your hosted instance. https://cape.contextis.com/analysis/87836/

@kevoreilly
Copy link
Contributor

Hmm I just tried with old loader and it seemed to work. So possibly an issue with the new loader and IE. Let me look into it.

@seanthegeek
Copy link
Contributor Author

@kevoreilly Have you had a chance to look at this?

@kevoreilly
Copy link
Contributor

Yes I just spent a while digging into this and have found the problem is due to a monitor code change which was attempting to mitigate problems with IcedID samples caused by a measure put in to allow VBCrypter samples to run (kevoreilly/capemon@f4fe2d5).

I've just compiled a monitor reverting just this change and IE seems to load up again - please give the attached monitor a go and let me know.

I'm not sure how to best fix this whilst keeping compatability with VBCrypter samples - I'll need to speak to the researcher who made that mod in the first place and work out if there isn't a better way.

capemon.zip

@seanthegeek
Copy link
Contributor Author

@kevoreilly My VMs are 64 bit. Can you build a 64 bit version?

@kevoreilly
Copy link
Contributor

kevoreilly commented Sep 23, 2019 via email

@seanthegeek
Copy link
Contributor Author

Seeing the same issue. It goes in analyzer/windows/dll/, right?

@kevoreilly
Copy link
Contributor

Oh dear - no IE window?

image

@kevoreilly
Copy link
Contributor

I'm gonna have to call it a night as it's getting late over here - but progress has been made, am hopeful we will nail this bug once we get to the bottom of it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants