Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What we will lose if we don't have internet on cuckoo system #496

Open
masifpak80 opened this issue Jan 9, 2018 · 3 comments
Open

What we will lose if we don't have internet on cuckoo system #496

masifpak80 opened this issue Jan 9, 2018 · 3 comments

Comments

@masifpak80
Copy link

We have an environment where we don't have internet. I wan to know, can our cuckoo-modified can provide network communication which it DNS servers. What lose we will face?

@doomedraven
Copy link
Contributor

ROFL, all depends of the malware which you analyze, if malware is just a downloaded, you will lose payload, if malware do check for internet connection before detonate, you will lose it, I think you got the idea ;)

@masifpak80
Copy link
Author

We are a financial organization. We can not give open internet access to our Cuckoo machine. What site you think should allow for cuckoo by proxy to get maximum malware payload and traces.
Please guide me regarding these understandings,
what is ROFL?
When a malware is download, payload is not its part? I mean why it need internet for payload?

@doomedraven
Copy link
Contributor

doomedraven commented Jan 10, 2018

what you need is learn what is malware and how different malware families/types work to better understand what you really need and what you will lose without internet.

you can fake internet with inetsim, but is kinda the same as no internet

I mean why it need internet for payload?

is like if you want to see video on youtube, why do you need internet ? real example i hope will explain better

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants