Analyzer Log
2025-06-22 14:05:43,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp2pjrvv
2025-06-22 14:05:43,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\uiIBbzBXkLaKEyiSwNAWnLGJ
2025-06-22 14:05:43,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\kqBoTPlkzcVSfhvmlcvZ
2025-06-22 14:05:43,328 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-22 14:05:43,328 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-22 14:05:43,765 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-22 14:05:43,983 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-06-22 14:05:43,983 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-22 14:05:43,983 [analyzer] DEBUG: Started auxiliary module Human
2025-06-22 14:05:43,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-22 14:05:43,983 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-22 14:05:44,092 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-22 14:05:44,092 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-22 14:05:44,092 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-22 14:05:44,092 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-22 14:05:44,217 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\b548bf713704345d20f700bce6e829b0a4a7899549f728ae893d822f42ce2dc5.exe' with arguments '' and pid 3064
2025-06-22 14:05:44,453 [analyzer] DEBUG: Loaded monitor into process with pid 3064
2025-06-22 14:05:44,483 [analyzer] INFO: Added new file to list with pid 3064 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-mMD9qzGfMdkALaKQ.exe
2025-06-22 14:06:13,233 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-22 14:06:13,780 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-22 14:06:13,780 [lib.api.process] INFO: Successfully terminated process with pid 3064.
2025-06-22 14:06:13,796 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-28 15:48:13,360 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:14,400 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:15,434 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:16,464 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:17,493 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:18,533 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:19,559 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:20,587 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:21,615 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:22,635 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:23,692 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:24,768 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:25,864 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:26,945 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:28,028 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:29,120 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:30,220 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:31,298 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:32,367 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:33,472 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:34,567 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:35,641 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:36,713 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:37,895 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:38,949 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:40,049 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:41,136 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:42,209 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:43,265 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:44,450 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:48:45,717 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:12,841 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:13,872 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:14,899 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:15,928 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:16,953 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:17,977 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:19,021 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:20,054 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:21,082 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:22,111 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:23,134 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:24,150 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:25,196 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:26,225 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:27,270 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:28,315 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:29,357 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:30,385 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:31,419 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:32,456 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:33,493 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:34,533 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:35,591 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:36,658 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:37,721 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:38,790 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:39,849 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:40,909 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:41,990 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:43,077 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:44,255 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:45,359 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:46,478 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:47,766 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:48,801 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:49,854 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:50,891 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:51,923 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:52,960 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:53,999 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:55,043 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:56,134 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:57,203 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:58,295 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:49:59,449 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:00,491 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:01,530 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:02,578 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:03,620 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:04,668 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:05,709 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:06,749 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:07,937 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:08,962 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:09,982 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:11,010 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:12,042 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:13,061 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:14,094 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:15,117 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:16,152 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:17,284 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:18,309 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:19,367 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:20,528 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:21,645 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:22,810 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:23,981 [cuckoo.core.scheduler] DEBUG: Task #6607130: no machine available yet
2025-06-28 15:50:25,041 [cuckoo.core.scheduler] INFO: Task #6607130: acquired machine win7x648 (label=win7x648)
2025-06-28 15:50:25,045 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.208 for task #6607130
2025-06-28 15:50:25,415 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2652582 (interface=vboxnet0, host=192.168.168.208)
2025-06-28 15:50:25,649 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x648
2025-06-28 15:50:26,179 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x648 to vmcloak
2025-06-28 15:53:28,431 [cuckoo.core.guest] INFO: Starting analysis #6607130 on guest (id=win7x648, ip=192.168.168.208)
2025-06-28 15:53:29,437 [cuckoo.core.guest] DEBUG: win7x648: not ready yet
2025-06-28 15:53:34,471 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x648, ip=192.168.168.208)
2025-06-28 15:53:34,569 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x648, ip=192.168.168.208, monitor=latest, size=6660546)
2025-06-28 15:53:35,758 [cuckoo.core.resultserver] DEBUG: Task #6607130: live log analysis.log initialized.
2025-06-28 15:53:36,688 [cuckoo.core.resultserver] DEBUG: Task #6607130 is sending a BSON stream
2025-06-28 15:53:37,142 [cuckoo.core.resultserver] DEBUG: Task #6607130 is sending a BSON stream
2025-06-28 15:53:38,003 [cuckoo.core.resultserver] DEBUG: Task #6607130: File upload for 'shots/0001.jpg'
2025-06-28 15:53:38,016 [cuckoo.core.resultserver] DEBUG: Task #6607130 uploaded file length: 134040
2025-06-28 15:53:50,702 [cuckoo.core.guest] DEBUG: win7x648: analysis #6607130 still processing
2025-06-28 15:54:05,843 [cuckoo.core.guest] DEBUG: win7x648: analysis #6607130 still processing
2025-06-28 15:54:06,384 [cuckoo.core.resultserver] DEBUG: Task #6607130: File upload for 'curtain/1750593973.5.curtain.log'
2025-06-28 15:54:06,387 [cuckoo.core.resultserver] DEBUG: Task #6607130 uploaded file length: 36
2025-06-28 15:54:06,605 [cuckoo.core.resultserver] DEBUG: Task #6607130: File upload for 'sysmon/1750593973.72.sysmon.xml'
2025-06-28 15:54:06,660 [cuckoo.core.resultserver] DEBUG: Task #6607130 uploaded file length: 1550498
2025-06-28 15:54:06,671 [cuckoo.core.resultserver] DEBUG: Task #6607130: File upload for 'files/cd515bce6de7ac6b_rifaien2-mmd9qzgfmdkalakq.exe'
2025-06-28 15:54:06,674 [cuckoo.core.resultserver] DEBUG: Task #6607130 uploaded file length: 85156
2025-06-28 15:54:06,991 [cuckoo.core.resultserver] DEBUG: Task #6607130: File upload for 'shots/0002.jpg'
2025-06-28 15:54:07,009 [cuckoo.core.resultserver] DEBUG: Task #6607130 uploaded file length: 133476
2025-06-28 15:54:07,023 [cuckoo.core.resultserver] DEBUG: Task #6607130 had connection reset for <Context for LOG>
2025-06-28 15:54:08,857 [cuckoo.core.guest] INFO: win7x648: analysis completed successfully
2025-06-28 15:54:08,870 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-28 15:54:08,896 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-28 15:54:09,665 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x648 to path /srv/cuckoo/cwd/storage/analyses/6607130/memory.dmp
2025-06-28 15:54:09,666 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x648
2025-06-28 15:57:14,004 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.208 for task #6607130
2025-06-28 15:57:14,497 [cuckoo.core.scheduler] DEBUG: Released database task #6607130
2025-06-28 15:57:14,564 [cuckoo.core.scheduler] INFO: Task #6607130: analysis procedure completed