Analyzer Log
2025-07-11 08:41:49,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp2zg5xi
2025-07-11 08:41:49,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\CDtEUEUXfAmRXHNlPhZsGNJm
2025-07-11 08:41:49,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\AWvhxMkFyZPpLAjEzjrPx
2025-07-11 08:41:49,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-11 08:41:49,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-11 08:41:49,453 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-11 08:41:49,453 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-11 08:41:50,015 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-11 08:41:50,217 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-07-11 08:41:50,217 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-11 08:41:50,217 [analyzer] DEBUG: Started auxiliary module Human
2025-07-11 08:41:50,217 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-11 08:41:50,217 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-11 08:41:50,328 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-11 08:41:50,328 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-11 08:41:50,328 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-11 08:41:50,328 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-11 08:41:50,483 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\a0bbe7a1d2e3c9bf_backup.exe' with arguments '' and pid 940
2025-07-11 08:41:50,687 [analyzer] DEBUG: Loaded monitor into process with pid 940
2025-07-11 08:41:50,765 [analyzer] INFO: Added new file to list with pid 940 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-07-11 08:41:50,780 [analyzer] INFO: Added new file to list with pid 940 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\System Restore.exe
2025-07-11 08:41:50,858 [analyzer] INFO: Injected into process with pid 1916 and name ''
2025-07-11 08:41:51,030 [analyzer] DEBUG: Loaded monitor into process with pid 1916
2025-07-11 08:41:51,108 [analyzer] INFO: Added new file to list with pid 940 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-07-11 08:41:51,203 [analyzer] INFO: Added new file to list with pid 940 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-07-11 08:41:52,078 [analyzer] INFO: Added new file to list with pid 1916 and path C:\backup.exe
2025-07-11 08:45:09,500 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-11 08:45:10,483 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-11 08:45:10,483 [lib.api.process] INFO: Successfully terminated process with pid 940.
2025-07-11 08:45:10,483 [lib.api.process] INFO: Successfully terminated process with pid 1916.
2025-07-11 08:45:10,500 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-16 15:01:57,303 [cuckoo.core.scheduler] INFO: Task #6719478: acquired machine win7x6410 (label=win7x6410)
2025-07-16 15:01:57,304 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.210 for task #6719478
2025-07-16 15:01:57,918 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2383397 (interface=vboxnet0, host=192.168.168.210)
2025-07-16 15:01:58,092 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6410
2025-07-16 15:01:59,287 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6410 to vmcloak
2025-07-16 15:03:53,801 [cuckoo.core.guest] INFO: Starting analysis #6719478 on guest (id=win7x6410, ip=192.168.168.210)
2025-07-16 15:03:54,811 [cuckoo.core.guest] DEBUG: win7x6410: not ready yet
2025-07-16 15:03:59,860 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6410, ip=192.168.168.210)
2025-07-16 15:03:59,984 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6410, ip=192.168.168.210, monitor=latest, size=6660546)
2025-07-16 15:04:01,902 [cuckoo.core.resultserver] DEBUG: Task #6719478: live log analysis.log initialized.
2025-07-16 15:04:02,834 [cuckoo.core.resultserver] DEBUG: Task #6719478 is sending a BSON stream
2025-07-16 15:04:03,286 [cuckoo.core.resultserver] DEBUG: Task #6719478 is sending a BSON stream
2025-07-16 15:04:03,697 [cuckoo.core.resultserver] DEBUG: Task #6719478 is sending a BSON stream
2025-07-16 15:04:04,236 [cuckoo.core.resultserver] DEBUG: Task #6719478: File upload for 'shots/0001.jpg'
2025-07-16 15:04:04,282 [cuckoo.core.resultserver] DEBUG: Task #6719478 uploaded file length: 133448
2025-07-16 15:04:16,370 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:04:31,757 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:04:47,238 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:05:02,398 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:05:17,840 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:05:33,121 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:05:48,207 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:06:03,288 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:06:18,564 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:06:33,680 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:06:48,778 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:07:03,932 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:07:19,474 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6719478 still processing
2025-07-16 15:07:22,347 [cuckoo.core.resultserver] DEBUG: Task #6719478: File upload for 'curtain/1752216309.66.curtain.log'
2025-07-16 15:07:22,350 [cuckoo.core.resultserver] DEBUG: Task #6719478 uploaded file length: 36
2025-07-16 15:07:23,076 [cuckoo.core.resultserver] DEBUG: Task #6719478: File upload for 'sysmon/1752216310.39.sysmon.xml'
2025-07-16 15:07:23,167 [cuckoo.core.resultserver] DEBUG: Task #6719478 uploaded file length: 11460606
2025-07-16 15:07:23,193 [cuckoo.core.resultserver] DEBUG: Task #6719478: File upload for 'files/5a29b425ed910fe3_system restore.exe'
2025-07-16 15:07:23,195 [cuckoo.core.resultserver] DEBUG: Task #6719478: File upload for 'files/8c99c950fa8081ef_backup.exe'
2025-07-16 15:07:23,197 [cuckoo.core.resultserver] DEBUG: Task #6719478: File upload for 'files/8cb74edeefcc4508_backup.exe'
2025-07-16 15:07:23,200 [cuckoo.core.resultserver] DEBUG: Task #6719478 uploaded file length: 176649
2025-07-16 15:07:23,201 [cuckoo.core.resultserver] DEBUG: Task #6719478 uploaded file length: 176647
2025-07-16 15:07:23,204 [cuckoo.core.resultserver] DEBUG: Task #6719478 uploaded file length: 176647
2025-07-16 15:07:23,206 [cuckoo.core.resultserver] DEBUG: Task #6719478 had connection reset for <Context for LOG>
2025-07-16 15:07:25,501 [cuckoo.core.guest] INFO: win7x6410: analysis completed successfully
2025-07-16 15:07:25,512 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-16 15:07:25,531 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-16 15:07:26,850 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6410 to path /srv/cuckoo/cwd/storage/analyses/6719478/memory.dmp
2025-07-16 15:07:26,851 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6410
2025-07-16 15:09:03,384 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.210 for task #6719478
2025-07-16 15:09:03,950 [cuckoo.core.scheduler] DEBUG: Released database task #6719478
2025-07-16 15:09:03,969 [cuckoo.core.scheduler] INFO: Task #6719478: analysis procedure completed