Skip to content

Read signature inputs from where CAPEv2 stores them now - #596

Merged
doomedraven merged 2 commits into
CAPESandbox:masterfrom
voidm4p:fix-stale-report-keys
Sep 24, 2026
Merged

doomedraven merged 2 commits into
CAPESandbox:masterfrom
voidm4p:fix-stale-report-keys

Conversation

@voidm4p

@voidm4p voidm4p commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

CAPEv2 no longer fills results["static"] or results["virustotal"]. The PE, .NET, Office, PDF and Java details and file VirusTotal lookups are stored under results["target"]["file"] by file_extra_info, and URL tasks keep their WHOIS text and VirusTotal lookup under results["url"]. Signatures still reading the old keys never fire; abstracts.py itself carries a "not sure if static still exist" ToDo.

This points the signatures in 23 files at the current locations: the .NET and Themida packers, PE version info and resource language, overlay, static_authenticode, bad_certs, static_pdf, static_java, mimics_icon, the Office macro, metadata, codepage, XLM, RTF object and DDE checks, whois_create, and antivirus_virustotal for both file and URL tasks.

It also removes static_rat_config: it read results["static"]["rat"], filled by the RAT decoders of the original Cuckoo, which nothing produces now; cape_extracted_config reports CAPE's own configuration extraction.

Testing: over 68 PE, MSI, Office and PDF samples, plus RTF, DDE and WHOIS inputs shaped like parse_office and parse_url output, every changed signature gives the same verdict and data as the original code run against a report that still exposes the old keys.

CAPEv2 no longer fills results["static"] or results["virustotal"]. The
PE, .NET, Office, PDF and Java details and file VirusTotal lookups are
stored under results["target"]["file"] by file_extra_info, and URL tasks
keep their WHOIS text and VirusTotal lookup under results["url"].
Signatures still reading the old keys never fire; abstracts.py itself
carries a "not sure if static still exist" ToDo.

Point the signatures in 23 files at the current locations: the .NET and
Themida packers, PE version info and resource language, overlay,
static_authenticode, bad_certs, static_pdf, static_java, mimics_icon,
the Office macro, metadata, codepage, XLM, RTF object and DDE checks,
whois_create, and antivirus_virustotal for both file and URL tasks.

Remove static_rat_config. It read results["static"]["rat"], filled by
the RAT decoders of the original Cuckoo, which nothing produces now;
cape_extracted_config reports CAPE's own configuration extraction.

Checked over 68 PE, MSI, Office and PDF samples, plus RTF, DDE and WHOIS
inputs shaped like parse_office and parse_url output: every changed
signature gives the same verdict and data as the original run against
the old keys.
With guest_signers read from target.file, invalid_authenticode_signature
runs again, and it fired on every PE the guest found unsigned: digisig
reports "No signature found." and "file format cannot be verified" as
errors as well, and the signature took any error for a bad signature.
Over 28 reports from a production CAPEv2 it flagged 20 files, 15 of them
unsigned. Skipping those two outcomes leaves the 5 whose signature
WinVerifyTrust rejected (0x80096004, 0x80096010).
@doomedraven
doomedraven merged commit 31dd59e into CAPESandbox:master Sep 24, 2026
2 checks passed
@doomedraven

Copy link
Copy Markdown
Collaborator

thank you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants