Analyzer Log
2025-08-26 13:22:39,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp4nivwu
2025-08-26 13:22:39,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\FxZsHNZWpWDWmGNn
2025-08-26 13:22:39,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\XJGHYpeMgTgevKRAfusDpUrIF
2025-08-26 13:22:39,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-08-26 13:22:39,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-08-26 13:22:39,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-08-26 13:22:39,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-08-26 13:22:39,828 [analyzer] DEBUG: Started auxiliary module Disguise
2025-08-26 13:22:40,030 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-08-26 13:22:40,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-08-26 13:22:40,030 [analyzer] DEBUG: Started auxiliary module Human
2025-08-26 13:22:40,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-08-26 13:22:40,030 [analyzer] DEBUG: Started auxiliary module Reboot
2025-08-26 13:22:40,140 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-08-26 13:22:40,140 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-08-26 13:22:40,140 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-08-26 13:22:40,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-08-26 13:22:40,280 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\c45be43927ec63cf_update.exe' with arguments '' and pid 1360
2025-08-26 13:22:40,578 [analyzer] DEBUG: Loaded monitor into process with pid 1360
2025-08-26 13:22:40,655 [analyzer] INFO: Added new file to list with pid 1360 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-08-26 13:22:40,671 [analyzer] INFO: Added new file to list with pid 1360 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-08-26 13:22:40,733 [analyzer] INFO: Injected into process with pid 2132 and name ''
2025-08-26 13:22:40,953 [analyzer] DEBUG: Loaded monitor into process with pid 2132
2025-08-26 13:22:41,030 [analyzer] INFO: Added new file to list with pid 1360 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-08-26 13:22:41,140 [analyzer] INFO: Added new file to list with pid 1360 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-08-26 13:22:42,000 [analyzer] INFO: Added new file to list with pid 2132 and path C:\backup.exe
2025-08-26 21:33:03,891 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-08-26 21:33:05,671 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-08-26 21:33:05,671 [lib.api.process] INFO: Successfully terminated process with pid 1360.
2025-08-26 21:33:05,671 [lib.api.process] INFO: Successfully terminated process with pid 2132.
2025-08-26 21:33:05,703 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-08-26 22:26:47,864 [cuckoo.core.scheduler] INFO: Task #6909746: acquired machine win7x6424 (label=win7x6424)
2025-08-26 22:26:47,865 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.224 for task #6909746
2025-08-26 22:26:48,346 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2912763 (interface=vboxnet0, host=192.168.168.224)
2025-08-26 22:26:48,430 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6424
2025-08-26 22:26:49,115 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6424 to vmcloak
2025-08-26 22:29:36,065 [cuckoo.core.guest] INFO: Starting analysis #6909746 on guest (id=win7x6424, ip=192.168.168.224)
2025-08-26 22:29:37,071 [cuckoo.core.guest] DEBUG: win7x6424: not ready yet
2025-08-26 22:29:42,135 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6424, ip=192.168.168.224)
2025-08-26 22:29:42,236 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6424, ip=192.168.168.224, monitor=latest, size=6660546)
2025-08-26 22:29:43,572 [cuckoo.core.resultserver] DEBUG: Task #6909746: live log analysis.log initialized.
2025-08-26 22:29:44,630 [cuckoo.core.resultserver] DEBUG: Task #6909746 is sending a BSON stream
2025-08-26 22:29:45,088 [cuckoo.core.resultserver] DEBUG: Task #6909746 is sending a BSON stream
2025-08-26 22:29:45,539 [cuckoo.core.resultserver] DEBUG: Task #6909746 is sending a BSON stream
2025-08-26 22:29:45,833 [cuckoo.core.resultserver] DEBUG: Task #6909746: File upload for 'shots/0001.jpg'
2025-08-26 22:29:46,180 [cuckoo.core.resultserver] DEBUG: Task #6909746 uploaded file length: 133479
2025-08-26 22:29:58,534 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:30:13,667 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:30:28,927 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:30:44,025 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:30:59,130 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:31:14,264 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:31:29,718 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:31:44,905 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:31:59,998 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:32:15,265 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:32:30,360 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:32:45,497 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:33:01,375 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6909746 still processing
2025-08-26 22:33:04,110 [cuckoo.core.resultserver] DEBUG: Task #6909746: File upload for 'curtain/1756236784.11.curtain.log'
2025-08-26 22:33:04,113 [cuckoo.core.resultserver] DEBUG: Task #6909746 uploaded file length: 36
2025-08-26 22:33:05,525 [cuckoo.core.resultserver] DEBUG: Task #6909746: File upload for 'sysmon/1756236785.52.sysmon.xml'
2025-08-26 22:33:05,676 [cuckoo.core.resultserver] DEBUG: Task #6909746 uploaded file length: 19778532
2025-08-26 22:33:05,745 [cuckoo.core.resultserver] DEBUG: Task #6909746 had connection reset for <Context for LOG>
2025-08-26 22:33:05,747 [cuckoo.core.resultserver] DEBUG: Task #6909746: File upload for 'files/59b07b9384814643_backup.exe'
2025-08-26 22:33:05,749 [cuckoo.core.resultserver] DEBUG: Task #6909746: File upload for 'files/b14f441052433951_backup.exe'
2025-08-26 22:33:05,751 [cuckoo.core.resultserver] DEBUG: Task #6909746 uploaded file length: 90416
2025-08-26 22:33:05,752 [cuckoo.core.resultserver] DEBUG: Task #6909746: File upload for 'files/cc4c639ec4d94bbb_backup.exe'
2025-08-26 22:33:05,767 [cuckoo.core.resultserver] DEBUG: Task #6909746 uploaded file length: 90414
2025-08-26 22:33:05,769 [cuckoo.core.resultserver] DEBUG: Task #6909746 uploaded file length: 90414
2025-08-26 22:33:07,419 [cuckoo.core.guest] INFO: win7x6424: analysis completed successfully
2025-08-26 22:33:07,434 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-08-26 22:33:07,449 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-08-26 22:33:08,720 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6424 to path /srv/cuckoo/cwd/storage/analyses/6909746/memory.dmp
2025-08-26 22:33:08,744 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6424
2025-08-26 22:35:55,266 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.224 for task #6909746
2025-08-26 22:35:55,700 [cuckoo.core.scheduler] DEBUG: Released database task #6909746
2025-08-26 22:35:55,712 [cuckoo.core.scheduler] INFO: Task #6909746: analysis procedure completed