Analyzer Log
2025-04-06 05:25:28,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpqqrt4a
2025-04-06 05:25:28,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\sMFlVSJyUTVjSABSVAofBtNAUFaOnVW
2025-04-06 05:25:28,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\GvGJZeQLsAWaQhohvQb
2025-04-06 05:25:28,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-04-06 05:25:28,062 [analyzer] INFO: Automatically selected analysis package "exe"
2025-04-06 05:25:28,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-06 05:25:28,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-06 05:25:28,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-06 05:25:28,967 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-04-06 05:25:28,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-06 05:25:28,967 [analyzer] DEBUG: Started auxiliary module Human
2025-04-06 05:25:28,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-06 05:25:28,967 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-06 05:25:29,015 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-06 05:25:29,015 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-06 05:25:29,015 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-06 05:25:29,015 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-06 05:25:29,358 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\b35b2d0b6032a3e1_avscan.exe' with arguments '' and pid 2628
2025-04-06 05:25:29,546 [analyzer] DEBUG: Loaded monitor into process with pid 2628
2025-04-06 05:25:29,592 [analyzer] INFO: Added new file to list with pid 2628 and path C:\Windows\W_X_C.vbs
2025-04-06 05:25:29,592 [analyzer] INFO: Added new file to list with pid 2628 and path C:\Windows\W_X_C.bat
2025-04-06 05:25:29,687 [analyzer] INFO: Injected into process with pid 2728 and name u'reg.exe'
2025-04-06 05:25:29,890 [analyzer] DEBUG: Loaded monitor into process with pid 2728
2025-04-06 05:25:30,358 [analyzer] INFO: Process with pid 2728 has terminated
2025-04-06 05:25:30,703 [analyzer] INFO: Added new file to list with pid 2628 and path C:\Users\Administrator\AppData\Local\Temp\avscan.exe
2025-04-06 05:25:30,875 [analyzer] INFO: Added new file to list with pid 2628 and path C:\Windows\hosts.exe
2025-04-06 05:25:31,233 [analyzer] INFO: Injected into process with pid 2132 and name u'avscan.exe'
2025-04-06 05:25:31,405 [analyzer] DEBUG: Loaded monitor into process with pid 2132
2025-04-06 05:28:48,358 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-04-06 05:28:50,030 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-04-06 05:28:50,030 [lib.api.process] INFO: Successfully terminated process with pid 2628.
2025-04-06 05:28:50,030 [lib.api.process] INFO: Successfully terminated process with pid 2132.
2025-04-06 05:28:50,578 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-04-08 05:09:44,556 [cuckoo.core.scheduler] INFO: Task #6244032: acquired machine win7x6428 (label=win7x6428)
2025-04-08 05:09:44,557 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.228 for task #6244032
2025-04-08 05:09:44,756 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1451131 (interface=vboxnet0, host=192.168.168.228)
2025-04-08 05:09:53,243 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6428
2025-04-08 05:09:53,728 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6428 to vmcloak
2025-04-08 05:11:11,516 [cuckoo.core.guest] INFO: Starting analysis #6244032 on guest (id=win7x6428, ip=192.168.168.228)
2025-04-08 05:11:12,521 [cuckoo.core.guest] DEBUG: win7x6428: not ready yet
2025-04-08 05:11:17,546 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6428, ip=192.168.168.228)
2025-04-08 05:11:17,603 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6428, ip=192.168.168.228, monitor=latest, size=6660546)
2025-04-08 05:11:22,955 [cuckoo.core.resultserver] DEBUG: Task #6244032: live log analysis.log initialized.
2025-04-08 05:11:23,862 [cuckoo.core.resultserver] DEBUG: Task #6244032 is sending a BSON stream
2025-04-08 05:11:24,684 [cuckoo.core.resultserver] DEBUG: Task #6244032 is sending a BSON stream
2025-04-08 05:11:24,768 [cuckoo.core.resultserver] DEBUG: Task #6244032 is sending a BSON stream
2025-04-08 05:11:25,081 [cuckoo.core.resultserver] DEBUG: Task #6244032: File upload for 'shots/0001.jpg'
2025-04-08 05:11:25,104 [cuckoo.core.resultserver] DEBUG: Task #6244032 uploaded file length: 133442
2025-04-08 05:11:26,199 [cuckoo.core.resultserver] DEBUG: Task #6244032: File upload for 'shots/0002.jpg'
2025-04-08 05:11:26,219 [cuckoo.core.resultserver] DEBUG: Task #6244032 uploaded file length: 148999
2025-04-08 05:11:26,286 [cuckoo.core.resultserver] DEBUG: Task #6244032 is sending a BSON stream
2025-04-08 05:11:37,776 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:11:52,958 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:12:08,129 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:12:23,324 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:12:38,433 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:12:53,514 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:13:08,605 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:13:23,691 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:13:38,872 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:13:53,953 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:14:09,034 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:14:24,111 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:14:39,294 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6244032 still processing
2025-04-08 05:14:43,522 [cuckoo.core.resultserver] DEBUG: Task #6244032: File upload for 'curtain/1743910128.55.curtain.log'
2025-04-08 05:14:43,530 [cuckoo.core.resultserver] DEBUG: Task #6244032 uploaded file length: 36
2025-04-08 05:14:44,795 [cuckoo.core.resultserver] DEBUG: Task #6244032: File upload for 'sysmon/1743910129.81.sysmon.xml'
2025-04-08 05:14:44,996 [cuckoo.core.resultserver] DEBUG: Task #6244032 uploaded file length: 17968454
2025-04-08 05:14:45,026 [cuckoo.core.resultserver] DEBUG: Task #6244032: File upload for 'files/9b33c57725f7ccd5_w_x_c.vbs'
2025-04-08 05:14:45,029 [cuckoo.core.resultserver] DEBUG: Task #6244032 uploaded file length: 197
2025-04-08 05:14:45,123 [cuckoo.core.resultserver] DEBUG: Task #6244032: File upload for 'files/c7a29be6a60d9480_avscan.exe'
2025-04-08 05:14:45,214 [cuckoo.core.resultserver] DEBUG: Task #6244032 uploaded file length: 16102561
2025-04-08 05:14:45,328 [cuckoo.core.resultserver] DEBUG: Task #6244032: File upload for 'files/e227489697c0c904_hosts.exe'
2025-04-08 05:14:45,742 [cuckoo.core.resultserver] DEBUG: Task #6244032 uploaded file length: 16102570
2025-04-08 05:14:45,773 [cuckoo.core.resultserver] DEBUG: Task #6244032 had connection reset for <Context for LOG>
2025-04-08 05:14:45,775 [cuckoo.core.resultserver] DEBUG: Task #6244032: File upload for 'files/d2150b9e5a4ce55e_w_x_c.bat'
2025-04-08 05:14:45,776 [cuckoo.core.resultserver] DEBUG: Task #6244032 uploaded file length: 336
2025-04-08 05:14:48,349 [cuckoo.core.guest] INFO: win7x6428: analysis completed successfully
2025-04-08 05:14:48,360 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-04-08 05:14:48,389 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-04-08 05:14:49,019 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6428 to path /srv/cuckoo/cwd/storage/analyses/6244032/memory.dmp
2025-04-08 05:14:49,033 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6428
2025-04-08 05:16:44,849 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.228 for task #6244032
2025-04-08 05:16:45,199 [cuckoo.core.scheduler] DEBUG: Released database task #6244032
2025-04-08 05:16:45,220 [cuckoo.core.scheduler] INFO: Task #6244032: analysis procedure completed