Analyzer Log
2025-02-13 04:25:56,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp4hzt0l
2025-02-13 04:25:56,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\qELRqTDRtUoeAWfZeVTjoJrhFhGSL
2025-02-13 04:25:56,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\lriPcaOgGCFcakDvxsY
2025-02-13 04:25:56,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-02-13 04:25:56,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-02-13 04:25:56,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-02-13 04:25:56,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-02-13 04:25:56,717 [analyzer] DEBUG: Started auxiliary module Disguise
2025-02-13 04:25:56,921 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-02-13 04:25:56,921 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-02-13 04:25:56,921 [analyzer] DEBUG: Started auxiliary module Human
2025-02-13 04:25:56,921 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-02-13 04:25:56,921 [analyzer] DEBUG: Started auxiliary module Reboot
2025-02-13 04:25:57,000 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-02-13 04:25:57,000 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-02-13 04:25:57,000 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-02-13 04:25:57,000 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-02-13 04:25:57,125 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\cfa3afd8fbb7b732_sysctl.exe' with arguments '' and pid 2908
2025-02-13 04:25:57,328 [analyzer] DEBUG: Loaded monitor into process with pid 2908
2025-02-13 04:25:57,342 [analyzer] INFO: Added new file to list with pid 2908 and path C:\Windows\SysWOW64\sysctl.exe
2025-02-13 04:25:57,358 [analyzer] INFO: Added new file to list with pid 2908 and path C:\Windows\SysWOW64\realex.exe
2025-02-13 04:25:57,421 [analyzer] INFO: Injected into process with pid 2688 and name u'sysctl.exe'
2025-02-13 04:25:57,578 [analyzer] DEBUG: Loaded monitor into process with pid 2688
2025-02-13 04:25:58,125 [analyzer] INFO: Process with pid 2908 has terminated
2025-02-13 04:29:16,125 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-02-13 04:29:17,375 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-02-13 04:29:17,375 [lib.api.process] INFO: Successfully terminated process with pid 2688.
2025-02-13 04:29:17,390 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-02-16 18:32:21,300 [cuckoo.core.scheduler] INFO: Task #5956669: acquired machine win7x6420 (label=win7x6420)
2025-02-16 18:32:21,301 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.220 for task #5956669
2025-02-16 18:32:21,738 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1447494 (interface=vboxnet0, host=192.168.168.220)
2025-02-16 18:32:22,449 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6420
2025-02-16 18:32:23,078 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6420 to vmcloak
2025-02-16 18:35:23,119 [cuckoo.core.guest] INFO: Starting analysis #5956669 on guest (id=win7x6420, ip=192.168.168.220)
2025-02-16 18:35:24,124 [cuckoo.core.guest] DEBUG: win7x6420: not ready yet
2025-02-16 18:35:29,147 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6420, ip=192.168.168.220)
2025-02-16 18:35:29,216 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6420, ip=192.168.168.220, monitor=latest, size=6660546)
2025-02-16 18:35:30,390 [cuckoo.core.resultserver] DEBUG: Task #5956669: live log analysis.log initialized.
2025-02-16 18:35:31,257 [cuckoo.core.resultserver] DEBUG: Task #5956669 is sending a BSON stream
2025-02-16 18:35:31,648 [cuckoo.core.resultserver] DEBUG: Task #5956669 is sending a BSON stream
2025-02-16 18:35:31,897 [cuckoo.core.resultserver] DEBUG: Task #5956669 is sending a BSON stream
2025-02-16 18:35:32,502 [cuckoo.core.resultserver] DEBUG: Task #5956669: File upload for 'shots/0001.jpg'
2025-02-16 18:35:32,628 [cuckoo.core.resultserver] DEBUG: Task #5956669 uploaded file length: 135652
2025-02-16 18:35:45,267 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:36:00,377 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:36:15,463 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:36:30,623 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:36:45,737 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:37:01,154 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:37:16,267 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:37:31,567 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:37:46,922 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:38:02,178 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:38:17,392 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:38:32,688 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:38:48,009 [cuckoo.core.guest] DEBUG: win7x6420: analysis #5956669 still processing
2025-02-16 18:38:50,725 [cuckoo.core.resultserver] DEBUG: Task #5956669: File upload for 'curtain/1739417356.31.curtain.log'
2025-02-16 18:38:50,729 [cuckoo.core.resultserver] DEBUG: Task #5956669 uploaded file length: 36
2025-02-16 18:38:51,691 [cuckoo.core.resultserver] DEBUG: Task #5956669: File upload for 'sysmon/1739417357.28.sysmon.xml'
2025-02-16 18:38:51,779 [cuckoo.core.resultserver] DEBUG: Task #5956669 uploaded file length: 13242650
2025-02-16 18:38:51,804 [cuckoo.core.resultserver] DEBUG: Task #5956669: File upload for 'files/be392e41a127570a_sysctl.exe'
2025-02-16 18:38:51,810 [cuckoo.core.resultserver] DEBUG: Task #5956669 uploaded file length: 434043
2025-02-16 18:38:51,815 [cuckoo.core.resultserver] DEBUG: Task #5956669 had connection reset for <Context for LOG>
2025-02-16 18:38:54,061 [cuckoo.core.guest] INFO: win7x6420: analysis completed successfully
2025-02-16 18:38:54,073 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-02-16 18:38:54,095 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-02-16 18:38:55,148 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6420 to path /srv/cuckoo/cwd/storage/analyses/5956669/memory.dmp
2025-02-16 18:38:55,173 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6420
2025-02-16 18:41:12,138 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.220 for task #5956669
2025-02-16 18:41:12,962 [cuckoo.core.scheduler] DEBUG: Released database task #5956669
2025-02-16 18:41:12,986 [cuckoo.core.scheduler] INFO: Task #5956669: analysis procedure completed