Size | 1.9KB |
---|---|
Type | Unicode text, UTF-8 text |
MD5 | 71426ecadbb79f8129db4fcbe731b2a8 |
SHA1 | c6bebba057163e23f13415817bbc0d2916c7c24a |
SHA256 | a9f160b1188b181697f5a7287c6460f15ed60ef9314d6ffebdc2a8d818473ba4 |
SHA512 |
494394c3856e03bbe98275961269d2cc5c8704ae7b45e2cb3611be748231b7e2f19ca9313144b1fc03527bfdb0e724d027ecf757ca9be4c92f872b89d90b32fe
|
CRC32 | 0588F0DE |
ssdeep | None |
Yara | None matched |
This archive shows some signs of potential malicious behavior.
The score of this archive is 1.1 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
ARCHIVE | June 15, 2025, 9:16 a.m. | June 15, 2025, 9:21 a.m. | 355 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-15 09:15:56,046 [analyzer] DEBUG: Starting analyzer from: C:\tmpriinqn 2025-06-15 09:15:56,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\czwaKjrXzwGGjGeDVLTEpphbMePixBlf 2025-06-15 09:15:56,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\cbhufzknTckbLsvIuVsNNsKCfoCwsx 2025-06-15 09:15:56,046 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-06-15 09:15:56,046 [analyzer] INFO: Automatically selected analysis package "ie" 2025-06-15 09:15:56,342 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-15 09:15:56,358 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-15 09:15:56,828 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-15 09:15:57,030 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-06-15 09:15:57,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-15 09:15:57,030 [analyzer] DEBUG: Started auxiliary module Human 2025-06-15 09:15:57,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-15 09:15:57,030 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-15 09:15:57,092 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-15 09:15:57,092 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-15 09:15:57,108 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-15 09:15:57,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-15 09:15:57,108 [modules.packages.ie] INFO: Submitted file is missing extension, adding .html 2025-06-15 09:15:57,203 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dupe-checker-1.17.3/README.md.html'] and pid 2992 2025-06-15 09:15:57,203 [analyzer] INFO: Enabled timeout enforce, running for the full timeout. 2025-06-15 09:15:57,342 [analyzer] DEBUG: Loaded monitor into process with pid 2992 2025-06-15 09:15:58,858 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2992 CREDAT:275457 /prefetch:2! 2025-06-15 09:15:58,937 [analyzer] INFO: Injected into process with pid 1464 and name u'iexplore.exe' 2025-06-15 09:15:59,000 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1464. 2025-06-15 09:15:59,108 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{949238CB-49B8-11F0-9B47-F891792EF730}.dat 2025-06-15 09:15:59,140 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\~DF70DA7B1E827A2BF4.TMP 2025-06-15 09:15:59,187 [analyzer] DEBUG: Loaded monitor into process with pid 1464 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-06-15 09:15:59,421 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-06-15 09:15:59,437 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-06-15 09:15:59,437 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-06-15 09:15:59,437 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-06-15 09:15:59,437 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-06-15 09:15:59,437 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-06-15 09:15:59,640 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{949238CD-49B8-11F0-9B47-F891792EF730}.dat 2025-06-15 09:15:59,655 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\~DF3D37DD0AA5A2433D.TMP 2025-06-15 09:15:59,717 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-06-15 09:15:59,717 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-06-15 09:15:59,717 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-06-15 09:15:59,717 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-06-15 09:15:59,717 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-06-15 09:15:59,717 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-06-15 09:15:59,717 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-06-15 08:17:59,010 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\3C428B1A3E5F57D887EC4B864FAC5DCC 2025-06-15 08:17:59,026 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3C428B1A3E5F57D887EC4B864FAC5DCC 2025-06-15 08:17:59,072 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabE711.tmp 2025-06-15 08:17:59,151 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarE712.tmp 2025-06-15 08:17:59,322 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabE7CF.tmp 2025-06-15 08:17:59,369 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarE7DF.tmp 2025-06-15 08:17:59,510 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 2025-06-15 08:17:59,510 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 2025-06-15 08:17:59,588 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabE8FA.tmp 2025-06-15 08:17:59,619 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarE90A.tmp 2025-06-15 08:17:59,697 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabE969.tmp 2025-06-15 08:17:59,760 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarE96A.tmp 2025-06-15 08:17:59,855 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEA17.tmp 2025-06-15 08:17:59,917 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEA27.tmp 2025-06-15 08:17:59,947 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEA67.tmp 2025-06-15 08:17:59,994 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEA78.tmp 2025-06-15 08:18:00,183 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEB63.tmp 2025-06-15 08:18:00,244 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEB84.tmp 2025-06-15 08:18:00,244 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEB74.tmp 2025-06-15 08:18:00,292 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEB95.tmp 2025-06-15 08:18:00,480 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEC81.tmp 2025-06-15 08:18:00,494 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEC80.tmp 2025-06-15 08:18:00,510 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEC92.tmp 2025-06-15 08:18:00,542 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEC93.tmp 2025-06-15 08:18:00,744 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabED9D.tmp 2025-06-15 08:18:00,776 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEDAF.tmp 2025-06-15 08:18:00,792 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarED9E.tmp 2025-06-15 08:18:00,822 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEDC0.tmp 2025-06-15 08:18:01,026 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEEAB.tmp 2025-06-15 08:18:01,058 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEEBD.tmp 2025-06-15 08:18:01,072 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEEBC.tmp 2025-06-15 08:18:01,105 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEECD.tmp 2025-06-15 08:18:01,338 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabEFF7.tmp 2025-06-15 08:18:01,369 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF009.tmp 2025-06-15 08:18:01,401 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarEFF8.tmp 2025-06-15 08:18:01,417 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF019.tmp 2025-06-15 08:18:01,588 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF0F5.tmp 2025-06-15 08:18:01,619 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF116.tmp 2025-06-15 08:18:01,635 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF0F6.tmp 2025-06-15 08:18:01,667 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF117.tmp 2025-06-15 08:18:01,869 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF212.tmp 2025-06-15 08:18:01,917 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF234.tmp 2025-06-15 08:18:01,917 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF213.tmp 2025-06-15 08:18:01,947 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF244.tmp 2025-06-15 08:18:02,105 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF301.tmp 2025-06-15 08:18:02,151 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF322.tmp 2025-06-15 08:18:02,151 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF302.tmp 2025-06-15 08:18:02,197 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF333.tmp 2025-06-15 08:18:02,385 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF41E.tmp 2025-06-15 08:18:02,417 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF430.tmp 2025-06-15 08:18:02,433 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF41F.tmp 2025-06-15 08:18:02,463 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF440.tmp 2025-06-15 08:18:02,667 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF52C.tmp 2025-06-15 08:18:02,697 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF54D.tmp 2025-06-15 08:18:02,713 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF53C.tmp 2025-06-15 08:18:02,744 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF55E.tmp 2025-06-15 08:18:02,947 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF659.tmp 2025-06-15 08:18:02,994 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF65A.tmp 2025-06-15 08:18:03,010 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF67A.tmp 2025-06-15 08:18:03,058 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF68A.tmp 2025-06-15 08:18:03,244 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF776.tmp 2025-06-15 08:18:03,260 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF797.tmp 2025-06-15 08:18:03,292 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF777.tmp 2025-06-15 08:18:03,322 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF798.tmp 2025-06-15 08:18:03,542 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF8B2.tmp 2025-06-15 08:18:03,588 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF8C4.tmp 2025-06-15 08:18:03,605 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF8B3.tmp 2025-06-15 08:18:03,619 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF8D5.tmp 2025-06-15 08:18:03,792 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF9B0.tmp 2025-06-15 08:18:03,838 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF9C1.tmp 2025-06-15 08:18:03,838 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabF9D2.tmp 2025-06-15 08:18:03,869 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarF9E2.tmp 2025-06-15 08:18:04,072 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabFACE.tmp 2025-06-15 08:18:04,105 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarFACF.tmp 2025-06-15 08:18:04,119 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabFAEF.tmp 2025-06-15 08:18:04,167 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarFAF0.tmp 2025-06-15 08:18:04,385 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabFC0A.tmp 2025-06-15 08:18:04,417 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarFC1B.tmp 2025-06-15 08:18:04,605 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabFCE7.tmp 2025-06-15 08:18:04,635 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarFCE8.tmp 2025-06-15 08:18:04,808 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabFDC4.tmp 2025-06-15 08:18:04,838 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarFDC5.tmp 2025-06-15 08:18:05,058 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabFEB0.tmp 2025-06-15 08:18:05,105 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarFEB1.tmp 2025-06-15 08:18:05,308 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabFFAC.tmp 2025-06-15 08:18:05,338 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarFFAD.tmp 2025-06-15 08:18:05,558 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\CabA8.tmp 2025-06-15 08:18:05,588 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\TarA9.tmp 2025-06-15 08:18:05,776 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Cab185.tmp 2025-06-15 08:18:05,808 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Tar195.tmp 2025-06-15 08:18:06,042 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Cab290.tmp 2025-06-15 08:18:06,088 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Tar291.tmp 2025-06-15 08:18:06,276 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Cab37D.tmp 2025-06-15 08:18:06,308 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Tar38D.tmp 2025-06-15 08:18:06,510 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Cab459.tmp 2025-06-15 08:18:06,542 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Tar46A.tmp 2025-06-15 08:18:06,713 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Cab546.tmp 2025-06-15 08:18:06,744 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Tar547.tmp 2025-06-15 08:18:06,901 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Cab603.tmp 2025-06-15 08:18:06,947 [analyzer] INFO: Added new file to list with pid 2992 and path C:\Users\Administrator\AppData\Local\Temp\Tar604.tmp 2025-06-15 08:21:47,385 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-15 08:21:48,072 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-15 08:21:48,072 [lib.api.process] INFO: Successfully terminated process with pid 2992. 2025-06-15 08:21:48,072 [lib.api.process] INFO: Successfully terminated process with pid 1464. 2025-06-15 08:21:48,105 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar604.tmp' does not exist, skip. 2025-06-15 08:21:48,105 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabface.tmp' does not exist, skip. 2025-06-15 08:21:48,119 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf116.tmp' does not exist, skip. 2025-06-15 08:21:48,119 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf244.tmp' does not exist, skip. 2025-06-15 08:21:48,119 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabedaf.tmp' does not exist, skip. 2025-06-15 08:21:48,119 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf54d.tmp' does not exist, skip. 2025-06-15 08:21:48,135 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfeb1.tmp' does not exist, skip. 2025-06-15 08:21:48,135 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf65a.tmp' does not exist, skip. 2025-06-15 08:21:48,135 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\taredc0.tmp' does not exist, skip. 2025-06-15 08:21:48,135 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare96a.tmp' does not exist, skip. 2025-06-15 08:21:48,135 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfc1b.tmp' does not exist, skip. 2025-06-15 08:21:48,135 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab459.tmp' does not exist, skip. 2025-06-15 08:21:48,135 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf440.tmp' does not exist, skip. 2025-06-15 08:21:48,135 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf333.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf213.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare90a.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf41e.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf117.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf777.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfacf.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarec93.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarffad.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab603.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tareb74.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf430.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe7cf.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab185.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe8fa.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar291.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfaef.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf67a.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf9d2.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tareecd.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabed9d.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf8b2.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar46a.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf8d5.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabeb84.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabffac.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabea67.tmp' does not exist, skip. 2025-06-15 08:21:48,151 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf68a.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tara9.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabeeab.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe969.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabeb63.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarea27.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf797.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar547.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf9c1.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf212.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabec81.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf234.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tareebc.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf0f5.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabeebd.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare7df.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf41f.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf0f6.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf8b3.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfdc5.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf9e2.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf9b0.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf322.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf55e.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf52c.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabeff7.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare712.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarec92.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf659.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar195.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab546.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfdc4.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabec80.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tared9e.tmp' does not exist, skip. 2025-06-15 08:21:48,167 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar38d.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf302.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf009.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfc0a.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf8c4.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tareb95.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf776.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfeb0.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabea17.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfce8.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab290.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf019.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df3d37dd0aa5a2433d.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\caba8.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab37d.tmp' does not exist, skip. 2025-06-15 08:21:48,183 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df70da7b1e827a2bf4.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe711.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarea78.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf798.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfce7.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tareff8.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfaf0.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf301.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf53c.tmp' does not exist, skip. 2025-06-15 08:21:48,197 [analyzer] INFO: Analysis completed.
2025-06-15 09:16:02,052 [cuckoo.core.scheduler] INFO: Task #6556620: acquired machine win7x6426 (label=win7x6426) 2025-06-15 09:16:02,052 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.226 for task #6556620 2025-06-15 09:16:02,263 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1311080 (interface=vboxnet0, host=192.168.168.226) 2025-06-15 09:16:02,291 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6426 2025-06-15 09:16:02,661 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6426 to vmcloak 2025-06-15 09:16:39,525 [cuckoo.core.guest] INFO: Starting analysis #6556620 on guest (id=win7x6426, ip=192.168.168.226) 2025-06-15 09:16:40,531 [cuckoo.core.guest] DEBUG: win7x6426: not ready yet 2025-06-15 09:16:45,560 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6426, ip=192.168.168.226) 2025-06-15 09:16:45,653 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6426, ip=192.168.168.226, monitor=latest, size=6660546) 2025-06-15 09:16:47,151 [cuckoo.core.resultserver] DEBUG: Task #6556620: live log analysis.log initialized. 2025-06-15 09:16:48,139 [cuckoo.core.resultserver] DEBUG: Task #6556620 is sending a BSON stream 2025-06-15 09:16:48,451 [cuckoo.core.resultserver] DEBUG: Task #6556620 is sending a BSON stream 2025-06-15 09:16:49,391 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'shots/0001.jpg' 2025-06-15 09:16:49,410 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 133393 2025-06-15 09:16:50,294 [cuckoo.core.resultserver] DEBUG: Task #6556620 is sending a BSON stream 2025-06-15 09:16:51,503 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'shots/0002.jpg' 2025-06-15 09:16:51,526 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 127626 2025-06-15 09:16:52,650 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'shots/0003.jpg' 2025-06-15 09:16:52,660 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 139794 2025-06-15 09:17:01,672 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:17:16,763 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:17:31,864 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:17:46,962 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:18:02,052 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:18:17,160 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:18:32,361 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:18:47,557 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:19:02,738 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:19:17,945 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:19:33,107 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:19:48,240 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:20:03,335 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:20:18,428 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:20:33,553 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:20:48,654 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:21:03,747 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:21:18,878 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:21:34,004 [cuckoo.core.guest] DEBUG: win7x6426: analysis #6556620 still processing 2025-06-15 09:21:47,678 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'curtain/1749968507.65.curtain.log' 2025-06-15 09:21:47,686 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 36 2025-06-15 09:21:48,021 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'sysmon/1749968508.01.sysmon.xml' 2025-06-15 09:21:48,079 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 3069500 2025-06-15 09:21:48,136 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'files/e1b8f682fced837b_{949238cd-49b8-11f0-9b47-f891792ef730}.dat' 2025-06-15 09:21:48,139 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 3584 2025-06-15 09:21:48,145 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'files/de24ebd505d98c90_recoverystore.{949238cb-49b8-11f0-9b47-f891792ef730}.dat' 2025-06-15 09:21:48,147 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 5632 2025-06-15 09:21:48,152 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'files/a2c770d32a0d972f_94308059b57b3142e455b38a6eb92015' 2025-06-15 09:21:48,154 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 73758 2025-06-15 09:21:48,186 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'files/eea8b1bd2782b5db_94308059b57b3142e455b38a6eb92015' 2025-06-15 09:21:48,189 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 344 2025-06-15 09:21:48,195 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'files/cb3ccbb76031e5e0_3c428b1a3e5f57d887ec4b864fac5dcc' 2025-06-15 09:21:48,209 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 914 2025-06-15 09:21:48,213 [cuckoo.core.resultserver] DEBUG: Task #6556620: File upload for 'files/baf5614d7c8fd58a_3c428b1a3e5f57d887ec4b864fac5dcc' 2025-06-15 09:21:48,215 [cuckoo.core.resultserver] DEBUG: Task #6556620 uploaded file length: 252 2025-06-15 09:21:48,223 [cuckoo.core.resultserver] DEBUG: Task #6556620 had connection reset for <Context for LOG> 2025-06-15 09:21:49,094 [cuckoo.core.guest] INFO: win7x6426: analysis completed successfully 2025-06-15 09:21:49,111 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-15 09:21:49,134 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-15 09:21:49,774 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6426 to path /srv/cuckoo/cwd/storage/analyses/6556620/memory.dmp 2025-06-15 09:21:49,776 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6426 2025-06-15 09:21:56,737 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.226 for task #6556620 2025-06-15 09:21:57,108 [cuckoo.core.scheduler] DEBUG: Released database task #6556620 2025-06-15 09:21:57,126 [cuckoo.core.scheduler] INFO: Task #6556620: analysis procedure completed
cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2992 CREDAT:275457 /prefetch:2 |