Analyzer Log
2025-04-05 03:49:05,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpj6atou
2025-04-05 03:49:05,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\hOLqwKjIkWjdouYJr
2025-04-05 03:49:05,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\RhfofXCXsUbumJoSNC
2025-04-05 03:49:05,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-05 03:49:05,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-05 03:49:05,765 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-05 03:49:05,967 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-04-05 03:49:05,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-05 03:49:05,967 [analyzer] DEBUG: Started auxiliary module Human
2025-04-05 03:49:05,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-05 03:49:05,967 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-05 03:49:06,046 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-05 03:49:06,062 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-05 03:49:06,062 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-05 03:49:06,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-05 03:49:06,140 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dfef9967a239a863732070faa916614072553456afaf581809dbaae9fbfd59f5.exe' with arguments ['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dfef9967a239a863732070faa916614072553456afaf581809dbaae9fbfd59f5.exe', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dfef9967a239a863732070faa916614072553456afaf581809dbaae9fbfd59f5.exe', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
Cuckoo Log
2025-04-06 02:16:43,368 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:44,631 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:46,140 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:47,245 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:48,319 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:49,434 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:50,504 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:51,558 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:52,595 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:53,617 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:54,641 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:55,672 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:56,698 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:57,729 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:58,747 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:16:59,769 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:00,787 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:02,130 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:03,155 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:04,175 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:05,197 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:06,220 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:07,239 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:08,262 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:09,291 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:10,307 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:11,329 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:12,348 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:13,374 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:14,398 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:15,422 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:16,455 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:17,475 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:18,502 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:19,801 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:20,869 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:22,157 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:23,210 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:24,254 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:25,297 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:26,432 [cuckoo.core.scheduler] DEBUG: Task #6230733: no machine available yet
2025-04-06 02:17:27,738 [cuckoo.core.scheduler] INFO: Task #6230733: acquired machine win7x6416 (label=win7x6416)
2025-04-06 02:17:27,741 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.216 for task #6230733
2025-04-06 02:17:28,295 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1351430 (interface=vboxnet0, host=192.168.168.216)
2025-04-06 02:17:28,434 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6416
2025-04-06 02:17:29,075 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6416 to vmcloak
2025-04-06 02:20:11,427 [cuckoo.core.guest] INFO: Starting analysis #6230733 on guest (id=win7x6416, ip=192.168.168.216)
2025-04-06 02:20:12,431 [cuckoo.core.guest] DEBUG: win7x6416: not ready yet
2025-04-06 02:20:17,491 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6416, ip=192.168.168.216)
2025-04-06 02:20:17,555 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6416, ip=192.168.168.216, monitor=latest, size=6660546)
2025-04-06 02:20:18,984 [cuckoo.core.resultserver] DEBUG: Task #6230733: live log analysis.log initialized.
2025-04-06 02:20:19,924 [cuckoo.core.resultserver] DEBUG: Task #6230733 is sending a BSON stream
2025-04-06 02:20:21,193 [cuckoo.core.resultserver] DEBUG: Task #6230733: File upload for 'shots/0001.jpg'
2025-04-06 02:20:21,207 [cuckoo.core.resultserver] DEBUG: Task #6230733 uploaded file length: 133542
2025-04-06 02:20:21,494 [cuckoo.core.guest] WARNING: win7x6416: analysis #6230733 caught an exception
Traceback (most recent call last):
File "C:/tmpj6atou/analyzer.py", line 824, in <module>
success = analyzer.run()
File "C:/tmpj6atou/analyzer.py", line 673, in run
pids = self.package.start(self.target)
File "C:\tmpj6atou\modules\packages\exe.py", line 34, in start
return self.execute(path, args=shlex.split(args))
File "C:\tmpj6atou\lib\common\abstracts.py", line 205, in execute
"Unable to execute the initial process, analysis aborted."
CuckooPackageError: Unable to execute the initial process, analysis aborted.
2025-04-06 02:20:21,514 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-04-06 02:20:21,540 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-04-06 02:20:22,483 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6416 to path /srv/cuckoo/cwd/storage/analyses/6230733/memory.dmp
2025-04-06 02:20:22,485 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6416
2025-04-06 02:23:37,306 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.216 for task #6230733
2025-04-06 02:23:37,306 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6230733
2025-04-06 02:23:37,686 [cuckoo.core.scheduler] DEBUG: Released database task #6230733
2025-04-06 02:23:37,713 [cuckoo.core.scheduler] INFO: Task #6230733: analysis procedure completed