Analyzer Log
2025-07-11 08:41:49,000 [analyzer] DEBUG: Starting analyzer from: C:\tmphzbxu3
2025-07-11 08:41:49,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\NheXIMfsbBQybrqdAooDFHyIMEfS
2025-07-11 08:41:49,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\RmUiOUsjMJwZJTTeGXao
2025-07-11 08:41:49,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-11 08:41:49,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-11 08:41:49,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-11 08:41:49,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-11 08:41:49,875 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-11 08:41:50,108 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-07-11 08:41:50,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-11 08:41:50,125 [analyzer] DEBUG: Started auxiliary module Human
2025-07-11 08:41:50,140 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-11 08:41:50,140 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-11 08:41:50,203 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-11 08:41:50,203 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-11 08:41:50,217 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-11 08:41:50,217 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-11 08:41:50,342 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\e0422dc09f2d8d03_backup.exe' with arguments '' and pid 1368
2025-07-11 08:41:50,530 [analyzer] DEBUG: Loaded monitor into process with pid 1368
2025-07-11 08:41:50,578 [analyzer] INFO: Added new file to list with pid 1368 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-07-11 08:41:50,592 [analyzer] INFO: Added new file to list with pid 1368 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-07-11 08:41:50,655 [analyzer] INFO: Injected into process with pid 2020 and name ''
2025-07-11 08:41:50,828 [analyzer] DEBUG: Loaded monitor into process with pid 2020
2025-07-11 08:41:50,890 [analyzer] INFO: Added new file to list with pid 1368 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-07-11 08:41:50,967 [analyzer] INFO: Added new file to list with pid 1368 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-07-11 08:41:51,858 [analyzer] INFO: Added new file to list with pid 2020 and path C:\backup.exe
2025-07-11 08:45:09,342 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-11 08:45:10,671 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-11 08:45:10,671 [lib.api.process] INFO: Successfully terminated process with pid 1368.
2025-07-11 08:45:10,671 [lib.api.process] INFO: Successfully terminated process with pid 2020.
2025-07-11 08:45:10,687 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-16 15:01:41,736 [cuckoo.core.scheduler] INFO: Task #6719477: acquired machine win7x6425 (label=win7x6425)
2025-07-16 15:01:41,737 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.225 for task #6719477
2025-07-16 15:01:42,308 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2383140 (interface=vboxnet0, host=192.168.168.225)
2025-07-16 15:01:42,449 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6425
2025-07-16 15:01:43,691 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6425 to vmcloak
2025-07-16 15:03:42,564 [cuckoo.core.guest] INFO: Starting analysis #6719477 on guest (id=win7x6425, ip=192.168.168.225)
2025-07-16 15:03:43,570 [cuckoo.core.guest] DEBUG: win7x6425: not ready yet
2025-07-16 15:03:48,588 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6425, ip=192.168.168.225)
2025-07-16 15:03:48,664 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6425, ip=192.168.168.225, monitor=latest, size=6660546)
2025-07-16 15:03:49,994 [cuckoo.core.resultserver] DEBUG: Task #6719477: live log analysis.log initialized.
2025-07-16 15:03:51,042 [cuckoo.core.resultserver] DEBUG: Task #6719477 is sending a BSON stream
2025-07-16 15:03:51,480 [cuckoo.core.resultserver] DEBUG: Task #6719477 is sending a BSON stream
2025-07-16 15:03:51,748 [cuckoo.core.resultserver] DEBUG: Task #6719477 is sending a BSON stream
2025-07-16 15:03:52,519 [cuckoo.core.resultserver] DEBUG: Task #6719477: File upload for 'shots/0001.jpg'
2025-07-16 15:03:52,561 [cuckoo.core.resultserver] DEBUG: Task #6719477 uploaded file length: 133488
2025-07-16 15:04:04,922 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:04:20,239 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:04:35,591 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:04:50,700 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:05:05,824 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:05:21,498 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:05:36,840 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:05:51,971 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:06:07,636 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:06:23,414 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:06:38,656 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:06:53,786 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:07:08,937 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6719477 still processing
2025-07-16 15:07:10,518 [cuckoo.core.resultserver] DEBUG: Task #6719477: File upload for 'curtain/1752216309.52.curtain.log'
2025-07-16 15:07:10,522 [cuckoo.core.resultserver] DEBUG: Task #6719477 uploaded file length: 36
2025-07-16 15:07:11,325 [cuckoo.core.resultserver] DEBUG: Task #6719477: File upload for 'sysmon/1752216310.33.sysmon.xml'
2025-07-16 15:07:11,682 [cuckoo.core.resultserver] DEBUG: Task #6719477 uploaded file length: 12617938
2025-07-16 15:07:11,704 [cuckoo.core.resultserver] DEBUG: Task #6719477: File upload for 'files/a0f14e25e6c0828b_backup.exe'
2025-07-16 15:07:11,708 [cuckoo.core.resultserver] DEBUG: Task #6719477: File upload for 'files/9b33a431a17a90b0_backup.exe'
2025-07-16 15:07:11,711 [cuckoo.core.resultserver] DEBUG: Task #6719477 uploaded file length: 176651
2025-07-16 15:07:11,713 [cuckoo.core.resultserver] DEBUG: Task #6719477 uploaded file length: 176649
2025-07-16 15:07:11,716 [cuckoo.core.resultserver] DEBUG: Task #6719477 had connection reset for <Context for LOG>
2025-07-16 15:07:12,109 [cuckoo.core.guest] INFO: win7x6425: analysis completed successfully
2025-07-16 15:07:12,139 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-16 15:07:12,161 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-16 15:07:13,484 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6425 to path /srv/cuckoo/cwd/storage/analyses/6719477/memory.dmp
2025-07-16 15:07:13,487 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6425
2025-07-16 15:08:37,152 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.225 for task #6719477
2025-07-16 15:08:38,765 [cuckoo.core.scheduler] DEBUG: Released database task #6719477
2025-07-16 15:08:38,793 [cuckoo.core.scheduler] INFO: Task #6719477: analysis procedure completed