Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows 10 x86 (10.0.16299.0 / 2017-09-22) winword.exe crash #58

Open
j-mie opened this issue Dec 15, 2017 · 4 comments
Open

Windows 10 x86 (10.0.16299.0 / 2017-09-22) winword.exe crash #58

j-mie opened this issue Dec 15, 2017 · 4 comments

Comments

@j-mie
Copy link

j-mie commented Dec 15, 2017

Any time I run any .doc through my Windows 10 x86 VM I get a crash:

image
image

Using Microsoft Office 2007 Ultimate, happy to provide any additional info

@doomedraven
Copy link

win10 isn't officially supported

@celyrin
Copy link

celyrin commented Jun 25, 2024

I also tested Windows 10 guests (including Windows 11). I found that for 32-bit programs, Cuckoo can work fine and capture behavioral data. However, for 64-bit programs, I observed exception exits in the behavior logs, indicating bugs in the injection process that need adaptation.

@celyrin
Copy link

celyrin commented Jun 28, 2024

I also tested Windows 10 guests (including Windows 11). I found that for 32-bit programs, Cuckoo can work fine and capture behavioral data. However, for 64-bit programs, I observed exception exits in the behavior logs, indicating bugs in the injection process that need adaptation.

After some research, I found that the issue lies in the hook_create_stub function in hooking.c. This function did not handle jump instructions like "0x48 0xff 0x25", causing hooks on x86-64 architecture samples under Windows 10 to fail to correctly jump to the original function's execution flow. I have now fixed this bug: GitHub link.

@doomedraven
Copy link

You know that this project is not maintained for years right?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants