Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hllrdm
Contributor

SandBlast Errors

We have encountered a problem with SandBlast TE250 equipment.
We have cases where letters from the MTA go to Bypass without waiting for a response from SandBlast. When such cases occur, we see the following errors in the ted.elg directory.

[TE (TD::Surprise)] te::Emulation::EmulationInvestigator::HandleFileEmulationFailed: {CA........} Failed to emulate file on image 'e........' (file status: VM assigned): Internal virtual sandbox communication error
[TE_TRACE]: {................} Run 3 for image: 'e50....' ended with verdict 'Error' (0 malicious runs, min:2), reason: Internal virtual sandbox communication error
[TE_TRACE]: {................} verdict 'Error' set for image: 'e50e...' (WinXP,Office 2003/7,Adobe 9) by: 1, reason: Internal virtual sandbox communication error
[TE_TRACE]: VM 272 KeyPoint: Terminating VM due to error: Failed to connect to SYMO client
[TE (TD::Surprise)] te::Emulation::EmulatingVM::TerminateWithError: VM 272 (Creation In Process): Terminating VM due to error: Failed to connect to SYMO client
[TE_TRACE]: VM 272 KeyPoint: Terminating (error occured? 1, detected events: 0 malicious, 0 benign)

We found similar sk120479 and sk135392, they don't fully correspond to our problem, but they are similar.
Both SKs say about TAS. Unfortunately our existing cases in TAS are going very long, so I would like to know if anyone has any experience with similar errors and how you can diagnose these errors?

0 Kudos
5 Replies
G_W_Albrecht
Legend
Legend

TE250 is from Sep-2013 and out of any support since Jun-2020 !

CCSE CCTE CCSM SMB Specialist
0 Kudos
Hllrdm
Contributor

We did further analysis, similar problems also exist on other equipment that is fresher than 250.

0 Kudos
G_W_Albrecht
Legend
Legend

sk114806: ATRG: Threat Emulation  gives treoubleshooting help.

You should ask TAC to resolve the issue on other equipment that is still supported - not on the TE250 soon out of support for 2 years already...

CCSE CCTE CCSM SMB Specialist
0 Kudos
Hllrdm
Contributor

As I wrote earlier, while we do not see the point in contacting the TAC, as cases are delayed for a long time. I wrote this thread to find out if anyone had such a problem at SandBlast and how to solve it.

0 Kudos
_Val_
Admin
Admin

I am afraid, sometimes you do have to let TAC help you. There is always an option to escalate, if you believe you are not getting enough attention. 

If you need any assistance, please feel free to PM me.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events