Analyzer Log
2025-11-10 21:59:23,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpt1gcja
2025-11-10 21:59:23,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\kktHFAfIbtIDTfRD
2025-11-10 21:59:23,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\qLLkHcjBhUZXWICvbZ
2025-11-10 21:59:23,328 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-10 21:59:23,328 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-10 21:59:23,750 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-10 21:59:23,967 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-11-10 21:59:23,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-10 21:59:23,967 [analyzer] DEBUG: Started auxiliary module Human
2025-11-10 21:59:23,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-10 21:59:23,967 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-10 21:59:24,046 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-10 21:59:24,046 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-10 21:59:24,062 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-10 21:59:24,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-10 21:59:24,187 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\39a47f43658cedb0ecf8703f0cc3c58808cdaa4f1e59dea9718aa512b85c9e1a.exe' with arguments '' and pid 1680
2025-11-10 21:59:24,405 [analyzer] DEBUG: Loaded monitor into process with pid 1680
2025-11-10 21:59:24,421 [analyzer] INFO: Added new file to list with pid 1680 and path C:\Windows\win32dc\BattleField 1942 + nocd.exe
2025-11-10 21:59:24,467 [analyzer] INFO: Added new file to list with pid 1680 and path C:\Windows\win32dc\Half-Life 2 serial.exe
2025-11-10 21:59:24,483 [analyzer] INFO: Added new file to list with pid 1680 and path C:\Windows\win32dc\Counter-Strike + hack.exe
2025-11-10 21:59:24,483 [analyzer] INFO: Added new file to list with pid 1680 and path C:\Windows\win32dc\Quake3 + codes.exe
2025-11-10 21:59:24,530 [analyzer] INFO: Added new file to list with pid 1680 and path C:\Windows\win32dc\UT2004 cdfix.exe
2025-11-10 21:59:24,562 [analyzer] INFO: Added new file to list with pid 1680 and path C:\Windows\win32dc\UT2004 fix.exe
2025-11-10 21:59:53,233 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-10 21:59:53,687 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-10 21:59:53,687 [lib.api.process] INFO: Successfully terminated process with pid 1680.
2025-11-10 21:59:53,733 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-11-21 02:24:28,613 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:29,716 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:30,745 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:31,781 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:32,805 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:33,826 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:34,851 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:35,877 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:36,902 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:37,929 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:38,954 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:39,978 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:40,999 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:42,024 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:43,049 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:44,264 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:45,373 [cuckoo.core.scheduler] DEBUG: Task #7162516: no machine available yet
2025-11-21 02:24:46,426 [cuckoo.core.scheduler] INFO: Task #7162516: acquired machine win7x642 (label=win7x642)
2025-11-21 02:24:46,427 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.202 for task #7162516
2025-11-21 02:24:46,989 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2580765 (interface=vboxnet0, host=192.168.168.202)
2025-11-21 02:24:47,533 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x642
2025-11-21 02:24:48,749 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x642 to vmcloak
2025-11-21 02:27:54,648 [cuckoo.core.guest] INFO: Starting analysis #7162516 on guest (id=win7x642, ip=192.168.168.202)
2025-11-21 02:27:55,655 [cuckoo.core.guest] DEBUG: win7x642: not ready yet
2025-11-21 02:28:00,685 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x642, ip=192.168.168.202)
2025-11-21 02:28:01,144 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x642, ip=192.168.168.202, monitor=latest, size=6660546)
2025-11-21 02:28:02,428 [cuckoo.core.resultserver] DEBUG: Task #7162516: live log analysis.log initialized.
2025-11-21 02:28:03,346 [cuckoo.core.resultserver] DEBUG: Task #7162516 is sending a BSON stream
2025-11-21 02:28:03,751 [cuckoo.core.resultserver] DEBUG: Task #7162516 is sending a BSON stream
2025-11-21 02:28:04,684 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'shots/0001.jpg'
2025-11-21 02:28:04,701 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 133621
2025-11-21 02:28:17,431 [cuckoo.core.guest] DEBUG: win7x642: analysis #7162516 still processing
2025-11-21 02:28:32,917 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'curtain/1762808393.47.curtain.log'
2025-11-21 02:28:32,920 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 36
2025-11-21 02:28:33,104 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'sysmon/1762808393.66.sysmon.xml'
2025-11-21 02:28:33,120 [cuckoo.core.guest] DEBUG: win7x642: analysis #7162516 still processing
2025-11-21 02:28:33,126 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 1629312
2025-11-21 02:28:33,135 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'files/dd8e63ce09fe33fd_half-life 2 serial.exe'
2025-11-21 02:28:33,139 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 323328
2025-11-21 02:28:33,143 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'files/2d48396aa0392939_ut2004 cdfix.exe'
2025-11-21 02:28:33,146 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 325376
2025-11-21 02:28:33,149 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'files/9fac2482bd20f613_ut2004 fix.exe'
2025-11-21 02:28:33,153 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 323328
2025-11-21 02:28:33,157 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'files/a0483b1af6cab2a2_battlefield 1942 + nocd.exe'
2025-11-21 02:28:33,161 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 326400
2025-11-21 02:28:33,164 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'files/411b48ff3ef74f9c_counter-strike + hack.exe'
2025-11-21 02:28:33,168 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 322304
2025-11-21 02:28:33,171 [cuckoo.core.resultserver] DEBUG: Task #7162516: File upload for 'files/50241e63a56447c5_quake3 + codes.exe'
2025-11-21 02:28:33,178 [cuckoo.core.resultserver] DEBUG: Task #7162516 uploaded file length: 326400
2025-11-21 02:28:33,623 [cuckoo.core.resultserver] DEBUG: Task #7162516 had connection reset for <Context for LOG>
2025-11-21 02:28:36,134 [cuckoo.core.guest] INFO: win7x642: analysis completed successfully
2025-11-21 02:28:36,149 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-21 02:28:36,195 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-21 02:28:37,408 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x642 to path /srv/cuckoo/cwd/storage/analyses/7162516/memory.dmp
2025-11-21 02:28:37,409 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x642
2025-11-21 02:31:35,124 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.202 for task #7162516
2025-11-21 02:31:35,584 [cuckoo.core.scheduler] DEBUG: Released database task #7162516
2025-11-21 02:31:35,602 [cuckoo.core.scheduler] INFO: Task #7162516: analysis procedure completed