Analyzer Log
2025-11-21 01:32:07,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpl4240h
2025-11-21 01:32:07,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\uiMMfZePXsSBvGCdhv
2025-11-21 01:32:07,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\FeJhJhztoOVnkdlVsUJ
2025-11-21 01:32:07,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-11-21 01:32:07,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-11-21 01:32:07,328 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-21 01:32:07,342 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-21 01:32:07,905 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-21 01:32:08,108 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-11-21 01:32:08,108 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-21 01:32:08,108 [analyzer] DEBUG: Started auxiliary module Human
2025-11-21 01:32:08,108 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-21 01:32:08,108 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-21 01:32:08,187 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-21 01:32:08,187 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-21 01:32:08,187 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-21 01:32:08,187 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-21 01:32:08,328 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2d48396aa0392939_ut2004 cdfix.exe' with arguments '' and pid 2604
2025-11-21 01:32:08,546 [analyzer] DEBUG: Loaded monitor into process with pid 2604
2025-11-21 01:32:08,562 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Windows\win32dc\Sims 2_codes.exe
2025-11-21 01:32:08,592 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Windows\win32dc\Quake3(crack).exe
2025-11-21 01:32:08,625 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Windows\win32dc\FlatOut_nocd.exe
2025-11-21 01:32:08,671 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Windows\win32dc\Doom 3(cheat).exe
2025-11-21 01:32:08,687 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Windows\win32dc\Sims 2 trainer.exe
2025-11-21 01:32:08,687 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Windows\win32dc\UT2004_cheat.exe
2025-11-21 01:32:08,717 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Windows\win32dc\Half-Life 2 nocd.exe
2025-11-21 01:32:08,733 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Windows\win32dc\Quake3_nocd.exe
2025-11-21 01:35:27,342 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-21 01:35:28,217 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-21 01:35:28,217 [lib.api.process] INFO: Successfully terminated process with pid 2604.
2025-11-21 01:35:28,280 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-11-25 01:14:56,258 [cuckoo.core.scheduler] INFO: Task #7195934: acquired machine win7x649 (label=win7x649)
2025-11-25 01:14:56,259 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.209 for task #7195934
2025-11-25 01:14:56,505 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3190963 (interface=vboxnet0, host=192.168.168.209)
2025-11-25 01:14:56,762 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x649
2025-11-25 01:14:58,150 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x649 to vmcloak
2025-11-25 01:16:53,141 [cuckoo.core.guest] INFO: Starting analysis #7195934 on guest (id=win7x649, ip=192.168.168.209)
2025-11-25 01:16:54,146 [cuckoo.core.guest] DEBUG: win7x649: not ready yet
2025-11-25 01:16:59,171 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x649, ip=192.168.168.209)
2025-11-25 01:16:59,290 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x649, ip=192.168.168.209, monitor=latest, size=6660546)
2025-11-25 01:17:00,822 [cuckoo.core.resultserver] DEBUG: Task #7195934: live log analysis.log initialized.
2025-11-25 01:17:01,881 [cuckoo.core.resultserver] DEBUG: Task #7195934 is sending a BSON stream
2025-11-25 01:17:02,287 [cuckoo.core.resultserver] DEBUG: Task #7195934 is sending a BSON stream
2025-11-25 01:17:03,130 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'shots/0001.jpg'
2025-11-25 01:17:03,143 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 136572
2025-11-25 01:17:15,400 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:17:30,503 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:17:45,684 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:18:00,774 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:18:15,857 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:18:30,940 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:18:46,021 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:19:01,107 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:19:16,260 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:19:31,338 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:19:46,418 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:20:01,503 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:20:16,584 [cuckoo.core.guest] DEBUG: win7x649: analysis #7195934 still processing
2025-11-25 01:20:21,368 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'curtain/1763685327.53.curtain.log'
2025-11-25 01:20:21,372 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 36
2025-11-25 01:20:21,990 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'sysmon/1763685328.16.sysmon.xml'
2025-11-25 01:20:22,058 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 9515548
2025-11-25 01:20:22,077 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'files/4ef51838a263809d_sims 2 trainer.exe'
2025-11-25 01:20:22,082 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'files/d0191d90a48d4893_quake3(crack).exe'
2025-11-25 01:20:22,085 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'files/5fa9808a3b80a1b0_flatout_nocd.exe'
2025-11-25 01:20:22,088 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'files/5026d56fee178aef_doom 3(cheat).exe'
2025-11-25 01:20:22,091 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 329473
2025-11-25 01:20:22,094 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 325377
2025-11-25 01:20:22,096 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'files/58115ba85555aa92_half-life 2 nocd.exe'
2025-11-25 01:20:22,099 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'files/7da00700903268df_ut2004_cheat.exe'
2025-11-25 01:20:22,102 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 329473
2025-11-25 01:20:22,107 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 326401
2025-11-25 01:20:22,109 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 328449
2025-11-25 01:20:22,112 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'files/ffc4a9a9fa9ab444_sims 2_codes.exe'
2025-11-25 01:20:22,114 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 328449
2025-11-25 01:20:22,117 [cuckoo.core.resultserver] DEBUG: Task #7195934: File upload for 'files/2de24b8512a97856_quake3_nocd.exe'
2025-11-25 01:20:22,128 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 329473
2025-11-25 01:20:22,140 [cuckoo.core.resultserver] DEBUG: Task #7195934 had connection reset for <Context for LOG>
2025-11-25 01:20:22,143 [cuckoo.core.resultserver] DEBUG: Task #7195934 uploaded file length: 328449
2025-11-25 01:20:22,613 [cuckoo.core.guest] INFO: win7x649: analysis completed successfully
2025-11-25 01:20:22,625 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-25 01:20:22,646 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-25 01:20:23,497 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x649 to path /srv/cuckoo/cwd/storage/analyses/7195934/memory.dmp
2025-11-25 01:20:23,499 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x649
2025-11-25 01:22:07,593 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.209 for task #7195934
2025-11-25 01:22:08,319 [cuckoo.core.scheduler] DEBUG: Released database task #7195934
2025-11-25 01:22:08,338 [cuckoo.core.scheduler] INFO: Task #7195934: analysis procedure completed