Analyzer Log
2025-06-22 14:05:52,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4
2025-06-22 14:05:52,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ngAXIoYDlJVfputgUrbQjm
2025-06-22 14:05:52,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\RQhZxcHglTqhGMMsqGPDbS
2025-06-22 14:05:52,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-22 14:05:52,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-22 14:05:52,750 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-22 14:05:52,953 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-06-22 14:05:52,953 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-22 14:05:52,953 [analyzer] DEBUG: Started auxiliary module Human
2025-06-22 14:05:52,953 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-22 14:05:52,953 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-22 14:05:53,046 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-22 14:05:53,046 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-22 14:05:53,046 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-22 14:05:53,046 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-22 14:05:53,233 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\b5da11d0aa9140b04361cd3cafb227860eb1aa8e68957a226755a613f2ba8ece.exe' with arguments '' and pid 2136
2025-06-22 14:05:53,405 [analyzer] DEBUG: Loaded monitor into process with pid 2136
2025-06-22 14:05:53,500 [analyzer] INFO: Injected into process with pid 2964 and name ''
2025-06-22 14:05:53,578 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2964.
2025-06-22 14:05:53,750 [analyzer] DEBUG: Loaded monitor into process with pid 2964
2025-06-22 14:05:53,780 [analyzer] INFO: Added new file to list with pid 2964 and path C:\ProgramData\jv6xGfsXuxdZez\ve9SRtwcMOBC71qj.exe
2025-06-22 14:05:54,233 [analyzer] INFO: Process with pid 2136 has terminated
2025-06-22 14:05:54,983 [analyzer] INFO: Added new file to list with pid 2964 and path C:\ProgramData\jv6xGfsXuxdZez\RCXBA3D.tmp
2025-06-22 14:05:55,125 [analyzer] INFO: Injected into process with pid 2376 and name u've9SRtwcMOBC71qj.exe'
2025-06-22 14:05:55,233 [analyzer] INFO: Process with pid 2964 has terminated
2025-06-22 14:05:55,280 [analyzer] DEBUG: Loaded monitor into process with pid 2376
2025-06-22 14:06:22,233 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-22 14:06:22,655 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-22 14:06:22,655 [lib.api.process] INFO: Successfully terminated process with pid 2376.
2025-06-22 14:06:22,671 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-28 15:56:20,351 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:21,401 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:22,451 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:23,588 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:24,637 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:25,675 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:26,707 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:27,739 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:28,762 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:29,795 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:30,832 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:31,878 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:32,920 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:33,962 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:35,005 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:36,043 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:37,078 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:38,111 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:39,151 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:40,194 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:41,244 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:42,275 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:43,319 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:44,479 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:45,516 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:46,562 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:47,603 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:48,660 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:49,717 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:50,764 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:51,889 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:52,949 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:54,169 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:55,230 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:56,312 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:57,399 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:58,621 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:56:59,697 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:00,851 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:01,980 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:03,243 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:04,275 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:05,313 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:06,357 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:07,531 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:08,577 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:09,611 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:10,662 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:11,709 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:12,749 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:13,802 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:14,918 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:16,094 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:17,146 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:18,183 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:19,230 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:20,274 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:21,323 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:22,379 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:23,422 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:24,463 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:25,507 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:26,536 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:27,593 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:28,632 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:29,690 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:30,818 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:31,856 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:32,883 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:33,933 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:34,980 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:36,033 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:37,074 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:38,128 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:39,175 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:40,212 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:41,249 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:42,298 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:43,347 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:44,383 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:45,428 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:46,476 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:47,559 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:48,642 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:49,704 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:50,760 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:51,821 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:52,881 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:53,948 [cuckoo.core.scheduler] DEBUG: Task #6607164: no machine available yet
2025-06-28 15:57:55,016 [cuckoo.core.scheduler] INFO: Task #6607164: acquired machine win7x644 (label=win7x644)
2025-06-28 15:57:55,018 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #6607164
2025-06-28 15:57:55,269 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2663751 (interface=vboxnet0, host=192.168.168.204)
2025-06-28 15:57:55,745 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644
2025-06-28 15:57:56,528 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak
2025-06-28 16:01:11,236 [cuckoo.core.guest] INFO: Starting analysis #6607164 on guest (id=win7x644, ip=192.168.168.204)
2025-06-28 16:01:12,246 [cuckoo.core.guest] DEBUG: win7x644: not ready yet
2025-06-28 16:01:17,272 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204)
2025-06-28 16:01:17,363 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546)
2025-06-28 16:01:18,557 [cuckoo.core.resultserver] DEBUG: Task #6607164: live log analysis.log initialized.
2025-06-28 16:01:19,449 [cuckoo.core.resultserver] DEBUG: Task #6607164 is sending a BSON stream
2025-06-28 16:01:19,884 [cuckoo.core.resultserver] DEBUG: Task #6607164 is sending a BSON stream
2025-06-28 16:01:20,228 [cuckoo.core.resultserver] DEBUG: Task #6607164 is sending a BSON stream
2025-06-28 16:01:20,740 [cuckoo.core.resultserver] DEBUG: Task #6607164: File upload for 'shots/0001.jpg'
2025-06-28 16:01:20,753 [cuckoo.core.resultserver] DEBUG: Task #6607164 uploaded file length: 133493
2025-06-28 16:01:21,771 [cuckoo.core.resultserver] DEBUG: Task #6607164 is sending a BSON stream
2025-06-28 16:01:33,398 [cuckoo.core.guest] DEBUG: win7x644: analysis #6607164 still processing
2025-06-28 16:01:48,535 [cuckoo.core.guest] DEBUG: win7x644: analysis #6607164 still processing
2025-06-28 16:01:48,989 [cuckoo.core.resultserver] DEBUG: Task #6607164: File upload for 'curtain/1750593982.42.curtain.log'
2025-06-28 16:01:48,992 [cuckoo.core.resultserver] DEBUG: Task #6607164 uploaded file length: 36
2025-06-28 16:01:49,188 [cuckoo.core.resultserver] DEBUG: Task #6607164: File upload for 'sysmon/1750593982.62.sysmon.xml'
2025-06-28 16:01:49,217 [cuckoo.core.resultserver] DEBUG: Task #6607164 uploaded file length: 1970286
2025-06-28 16:01:49,225 [cuckoo.core.resultserver] DEBUG: Task #6607164: File upload for 'files/fa065aba84ce07da_ve9srtwcmobc71qj.exe'
2025-06-28 16:01:49,231 [cuckoo.core.resultserver] DEBUG: Task #6607164 uploaded file length: 378368
2025-06-28 16:01:49,412 [cuckoo.core.resultserver] DEBUG: Task #6607164 had connection reset for <Context for LOG>
2025-06-28 16:01:51,547 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully
2025-06-28 16:01:51,559 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-28 16:01:51,581 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-28 16:01:52,367 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/6607164/memory.dmp
2025-06-28 16:01:52,368 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644
2025-06-28 16:04:59,130 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #6607164
2025-06-28 16:04:59,737 [cuckoo.core.scheduler] DEBUG: Released database task #6607164
2025-06-28 16:04:59,756 [cuckoo.core.scheduler] INFO: Task #6607164: analysis procedure completed