Analyzer Log
2025-11-07 11:40:39,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp2zg5xi
2025-11-07 11:40:39,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\LDgtMRRNlgwLKQkJC
2025-11-07 11:40:39,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\xHrDVxaSmvZzDLhV
2025-11-07 11:40:39,421 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-07 11:40:39,421 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-07 11:40:39,890 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-07 11:40:40,092 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-11-07 11:40:40,092 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-07 11:40:40,092 [analyzer] DEBUG: Started auxiliary module Human
2025-11-07 11:40:40,092 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-07 11:40:40,092 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-07 11:40:40,187 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-07 11:40:40,187 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-07 11:40:40,203 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-07 11:40:40,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-07 11:40:40,390 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\7051902471dd6a79ed71f8cd47a8003132cb08e728a5535e86170cd44bf66b11.exe' with arguments '' and pid 2928
2025-11-07 11:40:40,592 [analyzer] DEBUG: Loaded monitor into process with pid 2928
2025-11-07 11:40:40,655 [analyzer] INFO: Added new file to list with pid 2928 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-11-07 11:40:40,655 [analyzer] INFO: Added new file to list with pid 2928 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-11-07 11:40:40,750 [analyzer] INFO: Injected into process with pid 636 and name ''
2025-11-07 11:40:40,905 [analyzer] DEBUG: Loaded monitor into process with pid 636
2025-11-07 11:40:41,000 [analyzer] INFO: Added new file to list with pid 2928 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-11-07 11:40:41,078 [analyzer] INFO: Added new file to list with pid 2928 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-11-07 11:40:41,967 [analyzer] INFO: Added new file to list with pid 636 and path C:\backup.exe
2025-11-07 11:41:09,390 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-07 11:41:09,937 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-07 11:41:09,937 [lib.api.process] INFO: Successfully terminated process with pid 2928.
2025-11-07 11:41:09,937 [lib.api.process] INFO: Successfully terminated process with pid 636.
2025-11-07 11:41:09,967 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-11-15 15:28:59,932 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:00,960 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:02,054 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:03,119 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:04,193 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:05,265 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:06,329 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:07,402 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:08,469 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:09,518 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:10,575 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:11,616 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:12,665 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:13,715 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:14,950 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:16,128 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:17,416 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:18,460 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:19,523 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:20,598 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:21,643 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:22,697 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:23,762 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:24,846 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:25,930 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:27,005 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:28,061 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:29,134 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:30,200 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:31,511 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:32,588 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:33,647 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:34,698 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:35,744 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:36,786 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:37,901 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:38,968 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:40,038 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:41,109 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:42,202 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:43,378 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:44,429 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:45,498 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:46,565 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:47,619 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:48,669 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:49,736 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:50,809 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:51,867 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:52,934 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:54,004 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:55,078 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:56,142 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:57,192 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:58,302 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:29:59,401 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:00,433 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:01,463 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:02,489 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:03,517 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:04,532 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:05,855 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:06,935 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:08,003 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:09,089 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:10,117 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:11,143 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:12,171 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:13,196 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:14,228 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:15,251 [cuckoo.core.scheduler] DEBUG: Task #7085544: no machine available yet
2025-11-15 15:30:16,296 [cuckoo.core.scheduler] INFO: Task #7085544: acquired machine win7x6410 (label=win7x6410)
2025-11-15 15:30:16,296 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.210 for task #7085544
2025-11-15 15:30:16,707 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2908883 (interface=vboxnet0, host=192.168.168.210)
2025-11-15 15:30:16,823 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6410
2025-11-15 15:30:17,998 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6410 to vmcloak
2025-11-15 15:33:11,115 [cuckoo.core.guest] INFO: Starting analysis #7085544 on guest (id=win7x6410, ip=192.168.168.210)
2025-11-15 15:33:12,123 [cuckoo.core.guest] DEBUG: win7x6410: not ready yet
2025-11-15 15:33:17,149 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6410, ip=192.168.168.210)
2025-11-15 15:33:17,243 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6410, ip=192.168.168.210, monitor=latest, size=6660546)
2025-11-15 15:33:18,642 [cuckoo.core.resultserver] DEBUG: Task #7085544: live log analysis.log initialized.
2025-11-15 15:33:19,699 [cuckoo.core.resultserver] DEBUG: Task #7085544 is sending a BSON stream
2025-11-15 15:33:20,165 [cuckoo.core.resultserver] DEBUG: Task #7085544 is sending a BSON stream
2025-11-15 15:33:20,490 [cuckoo.core.resultserver] DEBUG: Task #7085544 is sending a BSON stream
2025-11-15 15:33:21,007 [cuckoo.core.resultserver] DEBUG: Task #7085544: File upload for 'shots/0001.jpg'
2025-11-15 15:33:21,092 [cuckoo.core.resultserver] DEBUG: Task #7085544 uploaded file length: 133487
2025-11-15 15:33:33,992 [cuckoo.core.guest] DEBUG: win7x6410: analysis #7085544 still processing
2025-11-15 15:33:49,338 [cuckoo.core.resultserver] DEBUG: Task #7085544: File upload for 'curtain/1762512069.67.curtain.log'
2025-11-15 15:33:49,342 [cuckoo.core.resultserver] DEBUG: Task #7085544 uploaded file length: 36
2025-11-15 15:33:49,468 [cuckoo.core.guest] DEBUG: win7x6410: analysis #7085544 still processing
2025-11-15 15:33:49,567 [cuckoo.core.resultserver] DEBUG: Task #7085544: File upload for 'sysmon/1762512069.91.sysmon.xml'
2025-11-15 15:33:49,584 [cuckoo.core.resultserver] DEBUG: Task #7085544 uploaded file length: 1262758
2025-11-15 15:33:49,597 [cuckoo.core.resultserver] DEBUG: Task #7085544: File upload for 'files/ca8ef14c73330706_backup.exe'
2025-11-15 15:33:49,601 [cuckoo.core.resultserver] DEBUG: Task #7085544 uploaded file length: 92906
2025-11-15 15:33:49,604 [cuckoo.core.resultserver] DEBUG: Task #7085544: File upload for 'files/6f74fd68d0eaafd2_backup.exe'
2025-11-15 15:33:49,606 [cuckoo.core.resultserver] DEBUG: Task #7085544 uploaded file length: 92908
2025-11-15 15:33:49,611 [cuckoo.core.resultserver] DEBUG: Task #7085544: File upload for 'files/1f3d4ee6ab3b5407_backup.exe'
2025-11-15 15:33:49,613 [cuckoo.core.resultserver] DEBUG: Task #7085544 uploaded file length: 92906
2025-11-15 15:33:50,009 [cuckoo.core.resultserver] DEBUG: Task #7085544 had connection reset for <Context for LOG>
2025-11-15 15:33:52,485 [cuckoo.core.guest] INFO: win7x6410: analysis completed successfully
2025-11-15 15:33:52,498 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-15 15:33:52,530 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-15 15:33:53,533 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6410 to path /srv/cuckoo/cwd/storage/analyses/7085544/memory.dmp
2025-11-15 15:33:53,535 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6410
2025-11-15 15:37:21,251 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.210 for task #7085544
2025-11-15 15:37:21,667 [cuckoo.core.scheduler] DEBUG: Released database task #7085544
2025-11-15 15:37:21,691 [cuckoo.core.scheduler] INFO: Task #7085544: analysis procedure completed