### ## Cuckoo Install ## Major help from Santi Bassett http://santi-bassett.blogspot.com/ #### sudo apt-get update sudo apt-get upgrade ## Install VirtualBox ## ## Sadly the current kernel doesn't work with the vboxdrv. ## So grabbing it from the Virtualbox.org, and it is newer anyways. #sudo apt-get install linux-headers-generic #sudo apt-get -y install unzip #sudo apt-get -y install virtualbox #sudo apt-get install virtualbox-dkms #sudo wget http://download.virtualbox.org/virtualbox/4.1.12/Oracle_VM_VirtualBox_Extension_Pack-4.1.12.vbox-extpack #sudo vboxmanage extpack install Oracle_VM_VirtualBox_Extension_Pack-4.1.12.vbox-extpack #sudo rm /tmp/Oracle_VM_VirtualBox_Extension_Pack-4.1.12.vbox-extpack ## VirtualBox wget http://download.virtualbox.org/virtualbox/4.2.10/virtualbox-4.2_4.2.10-84104~Ubuntu~precise_amd64.deb sudo dpkg -i virtualbox-4.2_4.2.10-84104~Ubuntu~precise_amd64.deb ## VirtualBox Extension PAck sudo wget http://download.virtualbox.org/virtualbox/4.2.10/Oracle_VM_VirtualBox_Extension_Pack-4.2.10.vbox-extpack sudo vboxmanage extpack install Oracle_VM_VirtualBox_Extension_Pack-4.2.10.vbox-extpack sudo rm Oracle_VM_VirtualBox_Extension_Pack-4.2.10.vbox-extpack ## VirtualBox web interface cd /var/www/ sudo wget https://phpvirtualbox.googlecode.com/files/phpvirtualbox-4.2-4.zip sudo unzip phpvirtualbox-4.2-4.zip sudo rm phpvirtualbox-4.2-4.zip sudo mv /var/www/phpvirtualbox-4.2-4 /var/www/phpvirtualbox sudo chown -R CHANGME:CHANGME /var/www/phpvirtualbox/ sudo cp /var/www/phpvirtualbox/config.php-example /var/www/phpvirtualbox/config.php ## Setup credentials in config ^^^^^^^^^^^^ ## Python Dependencies sudo apt-get -y install python-magic sudo apt-get -y install python-dpkt sudo apt-get -y install python-mako sudo apt-get -y install python-sqlalchemy sudo apt-get -y install python-jinja2 sudo apt-get -y install python-bottle ## SSDEEP sudo apt-get -y install ssdeep sudo apt-get -y install python-pyrex sudo apt-get -y install subversion sudo apt-get -y install libfuzzy-dev cd /opt sudo svn checkout http://pyssdeep.googlecode.com/svn/trunk/ pyssdeep cd pyssdeep sudo python setup.py build sudo python setup.py install sudo apt-get -y install python-pymongo sudo apt-get -y install mongodb ## Yara and Python support sudo apt-get -y install g++ sudo apt-get -y install libpcre3-dev cd /usr/src sudo wget http://yara-project.googlecode.com/files/yara-1.6.tar.gz sudo tar -xvzf yara-1.6.tar.gz cd yara-1.6 sudo ./configure sudo make sudo make check sudo make install cd /usr/src sudo wget http://yara-project.googlecode.com/files/yara-python-1.6.tar.gz sudo tar -xvzf yara-python-1.6.tar.gz cd yara-python-1.6 sudo python setup.py build sudo python setup.py install ## Modify Tcpdump sudo apt-get -y install libcap2-bin sudo setcap cap_net_raw,cap_net_admin=eip /usr/sbin/tcpdump getcap /usr/sbin/tcpdump ## Finally installing Cuckoo Sandbox sudo useradd cuckoo sudo groupadd vboxusers sudo usermod -a -G vboxusers cuckoo sudo apt-get -y install git cd /opt sudo git clone git://github.com/cuckoobox/cuckoo.git