Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VolExplorer not working with Volatility2 #1

Open
asterictnl-lvdw opened this issue Feb 21, 2023 · 1 comment
Open

VolExplorer not working with Volatility2 #1

asterictnl-lvdw opened this issue Feb 21, 2023 · 1 comment

Comments

@asterictnl-lvdw
Copy link

asterictnl-lvdw commented Feb 21, 2023

No handlers could be found for logger "volatility.debug"
GL & HF <3 ATZ

Traceback (most recent call last):
File ".\volexp.py", line 15211, in
main()
File ".\volexp.py", line 15203, in main
my_ve.render_text(None, ve_calc, root)
File ".\volexp.py", line 13562, in render_text
for process, pid, ppid, cpu, pb, ws, Description, cn, dep, aslr, cfg, protection, isDebug, Prefetch, threads, handles, un, session, noh, sc, pfc, di, it, cs, winStatus, integrity, priority, ct, cycles, wsp, ppd, pwss, vs, pvs, createT, intName, ofn, wt, cl, path, cd, version, e_proc in data:
File ".\volexp.py", line 13471, in calculate
if int(self.kaddr_space.profile.metadata.get('major')) > 5 and int(self.kaddr_space.profile.metadata.get('minor')) > 1 and e_proc.Protection.Type > 0: #e_proc.Protection.Type==1: PsProtectionSingUntyMalwareLight, if 2 then is stronget and if 0 then no protection:###e_proc.Flag2&0x800 6.0-6.1#find protected process # _proc.Protection.Type==1: PsProtectionSingUntyMalwareLight, if 2 then is stronget and if 0 then no protection ###e_proc.Flag2&0x800 6.0-6.1and hasattr(e_proc, "Protection")
File "C:\volatility\V2Exp\volatility\obj.py", line 751, in getattr
return self.m(attr)
File "C:\volatility\V2Exp\volatility\obj.py", line 733, in m
raise AttributeError("Struct {0} has no member {1}".format(self.obj_name, attr))
AttributeError: Struct _EPROCESS has no member Protection

Then the LoadScreen keeps looping and nothing happens.

~ LvdW

What I did is install the following packages:
distorm3
yara
pycrypto
pillow
openpyxl
pytz
ipython
capstone
ujson==1.35
tkkthemes

Let me know if I am doing something wrong.

I have tried with both the .exe and the normal .py to run it, same results.

@memoryforensics1
Copy link
Owner

memoryforensics1 commented Feb 21, 2023 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants