Analyzer Log
2025-04-05 05:40:49,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpj6atou
2025-04-05 05:40:49,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\NPMhLUlzITnBSFulrgWOUNXSUovj
2025-04-05 05:40:49,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\yuBXLlWAZYIklxgJIrShcxXsJWS
2025-04-05 05:40:49,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-05 05:40:49,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-05 05:40:49,921 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-05 05:40:50,155 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-04-05 05:40:50,155 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-05 05:40:50,155 [analyzer] DEBUG: Started auxiliary module Human
2025-04-05 05:40:50,155 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-05 05:40:50,155 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-05 05:40:50,250 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-05 05:40:50,250 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-05 05:40:50,250 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-05 05:40:50,250 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-05 05:40:50,405 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\e17b2badefe5cbb0ed0a808d1bd7f1d8faba852ea85e214730e7ba17dca99804.exe' with arguments '' and pid 592
2025-04-05 05:40:50,640 [analyzer] DEBUG: Loaded monitor into process with pid 592
2025-04-05 05:40:50,655 [analyzer] INFO: Added new file to list with pid 592 and path C:\ProgramData\Update\wuauclt.exe
2025-04-05 05:40:50,796 [analyzer] INFO: Injected into process with pid 3020 and name u'wuauclt.exe'
2025-04-05 05:40:50,983 [analyzer] DEBUG: Loaded monitor into process with pid 3020
2025-04-05 05:41:19,421 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-04-05 05:41:19,858 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-04-05 05:41:19,875 [lib.api.process] INFO: Successfully terminated process with pid 592.
2025-04-05 05:41:19,875 [lib.api.process] INFO: Successfully terminated process with pid 3020.
2025-04-05 05:41:19,875 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-04-06 05:14:58,277 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:14:59,318 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:00,335 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:01,358 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:02,377 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:03,400 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:04,426 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:05,449 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:06,478 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:07,556 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:09,112 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:10,216 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:11,315 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:12,390 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:13,482 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:14,577 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:15,668 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:16,766 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:17,825 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:18,888 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:19,947 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:21,097 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:22,294 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:23,654 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:24,777 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:25,868 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:26,946 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:27,984 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:29,005 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:30,197 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:31,241 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:32,426 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:33,754 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:34,886 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:36,100 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:37,341 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:38,491 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:39,636 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:40,851 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:42,221 [cuckoo.core.scheduler] DEBUG: Task #6231551: no machine available yet
2025-04-06 05:15:43,906 [cuckoo.core.scheduler] INFO: Task #6231551: acquired machine win7x6416 (label=win7x6416)
2025-04-06 05:15:43,912 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.216 for task #6231551
2025-04-06 05:15:44,656 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1632618 (interface=vboxnet0, host=192.168.168.216)
2025-04-06 05:15:46,246 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6416
2025-04-06 05:15:47,605 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6416 to vmcloak
2025-04-06 05:18:36,970 [cuckoo.core.guest] INFO: Starting analysis #6231551 on guest (id=win7x6416, ip=192.168.168.216)
2025-04-06 05:18:37,975 [cuckoo.core.guest] DEBUG: win7x6416: not ready yet
2025-04-06 05:18:43,014 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6416, ip=192.168.168.216)
2025-04-06 05:18:43,137 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6416, ip=192.168.168.216, monitor=latest, size=6660546)
2025-04-06 05:18:44,687 [cuckoo.core.resultserver] DEBUG: Task #6231551: live log analysis.log initialized.
2025-04-06 05:18:45,651 [cuckoo.core.resultserver] DEBUG: Task #6231551 is sending a BSON stream
2025-04-06 05:18:46,103 [cuckoo.core.resultserver] DEBUG: Task #6231551 is sending a BSON stream
2025-04-06 05:18:46,463 [cuckoo.core.resultserver] DEBUG: Task #6231551 is sending a BSON stream
2025-04-06 05:18:46,948 [cuckoo.core.resultserver] DEBUG: Task #6231551: File upload for 'shots/0001.jpg'
2025-04-06 05:18:46,963 [cuckoo.core.resultserver] DEBUG: Task #6231551 uploaded file length: 133542
2025-04-06 05:18:59,261 [cuckoo.core.guest] DEBUG: win7x6416: analysis #6231551 still processing
2025-04-06 05:19:14,490 [cuckoo.core.guest] DEBUG: win7x6416: analysis #6231551 still processing
2025-04-06 05:19:15,207 [cuckoo.core.resultserver] DEBUG: Task #6231551: File upload for 'curtain/1743824479.64.curtain.log'
2025-04-06 05:19:15,213 [cuckoo.core.resultserver] DEBUG: Task #6231551 uploaded file length: 36
2025-04-06 05:19:15,389 [cuckoo.core.resultserver] DEBUG: Task #6231551: File upload for 'sysmon/1743824479.83.sysmon.xml'
2025-04-06 05:19:15,466 [cuckoo.core.resultserver] DEBUG: Task #6231551 uploaded file length: 1487580
2025-04-06 05:19:15,481 [cuckoo.core.resultserver] DEBUG: Task #6231551: File upload for 'files/5b022bc3a058c0a8_wuauclt.exe'
2025-04-06 05:19:15,505 [cuckoo.core.resultserver] DEBUG: Task #6231551 uploaded file length: 138596
2025-04-06 05:19:15,755 [cuckoo.core.resultserver] DEBUG: Task #6231551 had connection reset for <Context for LOG>
2025-04-06 05:19:17,507 [cuckoo.core.guest] INFO: win7x6416: analysis completed successfully
2025-04-06 05:19:17,520 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-04-06 05:19:17,554 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-04-06 05:19:18,693 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6416 to path /srv/cuckoo/cwd/storage/analyses/6231551/memory.dmp
2025-04-06 05:19:18,699 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6416
2025-04-06 05:22:16,320 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.216 for task #6231551
2025-04-06 05:22:17,022 [cuckoo.core.scheduler] DEBUG: Released database task #6231551
2025-04-06 05:22:17,040 [cuckoo.core.scheduler] INFO: Task #6231551: analysis procedure completed