Analyzer Log
2025-11-21 01:32:07,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpsgyfoe
2025-11-21 01:32:07,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\LmbJOvLOjwvaijanRmststivTyxhsd
2025-11-21 01:32:07,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\notCCmEzLNzsjvZtLLCe
2025-11-21 01:32:07,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-11-21 01:32:07,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-11-21 01:32:07,342 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-21 01:32:07,342 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-21 01:32:07,812 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-21 01:32:08,015 [analyzer] DEBUG: Loaded monitor into process with pid 516
2025-11-21 01:32:08,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-21 01:32:08,015 [analyzer] DEBUG: Started auxiliary module Human
2025-11-21 01:32:08,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-21 01:32:08,015 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-21 01:32:08,078 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-21 01:32:08,078 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-21 01:32:08,078 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-21 01:32:08,092 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-21 01:32:08,233 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dd8e63ce09fe33fd_half-life 2 serial.exe' with arguments '' and pid 2872
2025-11-21 01:32:08,453 [analyzer] DEBUG: Loaded monitor into process with pid 2872
2025-11-21 01:32:08,467 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\Counter-Strike patch.exe
2025-11-21 01:32:08,467 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\Half-Life 2(codes).exe
2025-11-21 01:32:08,483 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\Quake3 cheat.exe
2025-11-21 01:32:08,515 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\Silent Hill 4_trainer.exe
2025-11-21 01:32:08,530 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\UT2004_codes.exe
2025-11-21 01:32:08,530 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\Silent Hill 4 + serial.exe
2025-11-21 01:32:08,546 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\Counter-Strike_codes.exe
2025-11-21 01:32:08,562 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\Silent Hill 4 trainer.exe
2025-11-21 01:32:08,562 [analyzer] INFO: Added new file to list with pid 2872 and path C:\Windows\win32dc\UT2004 + codes.exe
2025-11-21 01:35:27,233 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-21 01:35:28,467 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-21 01:35:28,467 [lib.api.process] INFO: Successfully terminated process with pid 2872.
2025-11-21 01:35:28,530 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-11-25 01:15:28,481 [cuckoo.core.scheduler] INFO: Task #7195935: acquired machine win7x6413 (label=win7x6413)
2025-11-25 01:15:28,481 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.213 for task #7195935
2025-11-25 01:15:28,729 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3191805 (interface=vboxnet0, host=192.168.168.213)
2025-11-25 01:15:29,033 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6413
2025-11-25 01:15:30,064 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6413 to vmcloak
2025-11-25 01:17:12,098 [cuckoo.core.guest] INFO: Starting analysis #7195935 on guest (id=win7x6413, ip=192.168.168.213)
2025-11-25 01:17:13,104 [cuckoo.core.guest] DEBUG: win7x6413: not ready yet
2025-11-25 01:17:18,128 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6413, ip=192.168.168.213)
2025-11-25 01:17:18,184 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6413, ip=192.168.168.213, monitor=latest, size=6660546)
2025-11-25 01:17:19,548 [cuckoo.core.resultserver] DEBUG: Task #7195935: live log analysis.log initialized.
2025-11-25 01:17:21,349 [cuckoo.core.resultserver] DEBUG: Task #7195935 is sending a BSON stream
2025-11-25 01:17:21,352 [cuckoo.core.resultserver] DEBUG: Task #7195935 is sending a BSON stream
2025-11-25 01:17:21,771 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'shots/0001.jpg'
2025-11-25 01:17:21,894 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 133596
2025-11-25 01:17:34,285 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:17:49,367 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:18:04,654 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:18:19,753 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:18:34,878 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:18:49,954 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:19:05,139 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:19:20,219 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:19:35,362 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:19:50,472 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:20:05,554 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:20:20,657 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:20:35,748 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7195935 still processing
2025-11-25 01:20:39,993 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'curtain/1763685327.41.curtain.log'
2025-11-25 01:20:39,996 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 36
2025-11-25 01:20:40,812 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'sysmon/1763685328.22.sysmon.xml'
2025-11-25 01:20:41,064 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 12704002
2025-11-25 01:20:41,079 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/ea6c8bb505824840_counter-strike patch.exe'
2025-11-25 01:20:41,081 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/421c3e3e7abc46e7_silent hill 4_trainer.exe'
2025-11-25 01:20:41,084 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/9f2cd8d049d88a4c_silent hill 4 + serial.exe'
2025-11-25 01:20:41,087 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 323329
2025-11-25 01:20:41,090 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 325377
2025-11-25 01:20:41,093 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 325377
2025-11-25 01:20:41,095 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/b4c8e34b9884c2a4_ut2004_codes.exe'
2025-11-25 01:20:41,097 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/b6db9f3ca3475c88_ut2004 + codes.exe'
2025-11-25 01:20:41,100 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 323329
2025-11-25 01:20:41,102 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 324353
2025-11-25 01:20:41,105 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/49722b97d67a075a_half-life 2(codes).exe'
2025-11-25 01:20:41,109 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 325377
2025-11-25 01:20:41,112 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/fb2ec92bf7b4718f_silent hill 4 trainer.exe'
2025-11-25 01:20:41,117 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 323329
2025-11-25 01:20:41,119 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/24ff52648184003f_counter-strike_codes.exe'
2025-11-25 01:20:41,123 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 324353
2025-11-25 01:20:41,127 [cuckoo.core.resultserver] DEBUG: Task #7195935: File upload for 'files/f9b49bc757fdda10_quake3 cheat.exe'
2025-11-25 01:20:41,133 [cuckoo.core.resultserver] DEBUG: Task #7195935 uploaded file length: 327425
2025-11-25 01:20:41,149 [cuckoo.core.resultserver] DEBUG: Task #7195935 had connection reset for <Context for LOG>
2025-11-25 01:20:41,793 [cuckoo.core.guest] INFO: win7x6413: analysis completed successfully
2025-11-25 01:20:41,806 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-25 01:20:41,827 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-25 01:20:43,407 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6413 to path /srv/cuckoo/cwd/storage/analyses/7195935/memory.dmp
2025-11-25 01:20:43,409 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6413
2025-11-25 01:22:38,071 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.213 for task #7195935
2025-11-25 01:22:38,604 [cuckoo.core.scheduler] DEBUG: Released database task #7195935
2025-11-25 01:22:38,639 [cuckoo.core.scheduler] INFO: Task #7195935: analysis procedure completed