Analyzer Log
2025-02-10 18:28:21,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpj6atou
2025-02-10 18:28:21,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\dtQSdKlsaHGMwFxoQJqwPkbLuFPn
2025-02-10 18:28:21,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\AxFzkASmwtRaQdfaLiBCdWebdkX
2025-02-10 18:28:21,342 [analyzer] DEBUG: Started auxiliary module Curtain
2025-02-10 18:28:21,342 [analyzer] DEBUG: Started auxiliary module DbgView
2025-02-10 18:28:21,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-02-10 18:28:22,062 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-02-10 18:28:22,062 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-02-10 18:28:22,062 [analyzer] DEBUG: Started auxiliary module Human
2025-02-10 18:28:22,062 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-02-10 18:28:22,062 [analyzer] DEBUG: Started auxiliary module Reboot
2025-02-10 18:28:22,140 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-02-10 18:28:22,140 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-02-10 18:28:22,140 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-02-10 18:28:22,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-02-10 18:28:22,217 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\rundll32.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\a9e77cae1f186e59604f4d96645cf858f75e46c2994fcf983ed565459d20b46d.dll,DllMain'] and pid 364
2025-02-10 18:28:22,437 [analyzer] DEBUG: Loaded monitor into process with pid 364
2025-02-10 18:28:22,530 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService.
2025-02-10 18:28:22,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,546 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA.
2025-02-10 18:28:22,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,562 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW.
2025-02-10 18:28:22,625 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService.
2025-02-10 18:28:22,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,625 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA.
2025-02-10 18:28:22,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,640 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW.
2025-02-10 18:28:22,655 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService.
2025-02-10 18:28:22,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,655 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA.
2025-02-10 18:28:22,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2025-02-10 18:28:22,671 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW.
2025-02-10 18:28:51,280 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-02-10 18:28:51,750 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-02-10 18:28:51,750 [lib.api.process] INFO: Successfully terminated process with pid 364.
2025-02-10 18:28:51,750 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-02-12 07:13:34,688 [cuckoo.core.scheduler] INFO: Task #5926080: acquired machine win7x6416 (label=win7x6416)
2025-02-12 07:13:34,689 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.216 for task #5926080
2025-02-12 07:13:35,124 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3848685 (interface=vboxnet0, host=192.168.168.216)
2025-02-12 07:13:36,921 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6416
2025-02-12 07:13:37,622 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6416 to vmcloak
2025-02-12 07:16:57,086 [cuckoo.core.guest] INFO: Starting analysis #5926080 on guest (id=win7x6416, ip=192.168.168.216)
2025-02-12 07:16:58,093 [cuckoo.core.guest] DEBUG: win7x6416: not ready yet
2025-02-12 07:17:03,124 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6416, ip=192.168.168.216)
2025-02-12 07:17:03,218 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6416, ip=192.168.168.216, monitor=latest, size=6660546)
2025-02-12 07:17:04,616 [cuckoo.core.resultserver] DEBUG: Task #5926080: live log analysis.log initialized.
2025-02-12 07:17:05,632 [cuckoo.core.resultserver] DEBUG: Task #5926080 is sending a BSON stream
2025-02-12 07:17:05,930 [cuckoo.core.resultserver] DEBUG: Task #5926080 is sending a BSON stream
2025-02-12 07:17:06,920 [cuckoo.core.resultserver] DEBUG: Task #5926080: File upload for 'shots/0001.jpg'
2025-02-12 07:17:06,936 [cuckoo.core.resultserver] DEBUG: Task #5926080 uploaded file length: 137776
2025-02-12 07:17:19,351 [cuckoo.core.guest] DEBUG: win7x6416: analysis #5926080 still processing
2025-02-12 07:17:34,769 [cuckoo.core.guest] DEBUG: win7x6416: analysis #5926080 still processing
2025-02-12 07:17:35,221 [cuckoo.core.resultserver] DEBUG: Task #5926080: File upload for 'curtain/1739208531.5.curtain.log'
2025-02-12 07:17:35,364 [cuckoo.core.resultserver] DEBUG: Task #5926080 uploaded file length: 36
2025-02-12 07:17:35,369 [cuckoo.core.resultserver] DEBUG: Task #5926080: File upload for 'sysmon/1739208531.69.sysmon.xml'
2025-02-12 07:17:35,384 [cuckoo.core.resultserver] DEBUG: Task #5926080 uploaded file length: 1512806
2025-02-12 07:17:35,796 [cuckoo.core.resultserver] DEBUG: Task #5926080: File upload for 'shots/0002.jpg'
2025-02-12 07:17:35,808 [cuckoo.core.resultserver] DEBUG: Task #5926080 uploaded file length: 133581
2025-02-12 07:17:35,821 [cuckoo.core.resultserver] DEBUG: Task #5926080 had connection reset for <Context for LOG>
2025-02-12 07:17:37,840 [cuckoo.core.guest] INFO: win7x6416: analysis completed successfully
2025-02-12 07:17:37,866 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-02-12 07:17:37,906 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-02-12 07:17:39,058 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6416 to path /srv/cuckoo/cwd/storage/analyses/5926080/memory.dmp
2025-02-12 07:17:39,065 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6416
2025-02-12 07:20:39,512 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.216 for task #5926080
2025-02-12 07:20:39,973 [cuckoo.core.scheduler] DEBUG: Released database task #5926080
2025-02-12 07:20:39,994 [cuckoo.core.scheduler] INFO: Task #5926080: analysis procedure completed