Analyzer Log
2025-04-22 16:53:25,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpt1gcja
2025-04-22 16:53:25,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\zSIhOrgdzoacPBIQfWzfTRVklkgN
2025-04-22 16:53:25,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\MIWSaWDzvkWEdMQZRGVMLhI
2025-04-22 16:53:25,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-04-22 16:53:25,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-04-22 16:53:25,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-22 16:53:25,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-22 16:53:25,765 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-22 16:53:25,967 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-04-22 16:53:25,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-22 16:53:25,967 [analyzer] DEBUG: Started auxiliary module Human
2025-04-22 16:53:25,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-22 16:53:25,967 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-22 16:53:26,062 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-22 16:53:26,062 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-22 16:53:26,062 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-22 16:53:26,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-22 16:53:26,203 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\aeee94997be4baf4_microsofthelp.exe' with arguments '' and pid 2480
2025-04-22 16:53:26,390 [analyzer] DEBUG: Loaded monitor into process with pid 2480
2025-04-22 16:53:26,390 [analyzer] INFO: Added new file to list with pid 2480 and path C:\Windows\microsofthelp.exe
2025-04-22 16:53:26,467 [analyzer] INFO: Injected into process with pid 1352 and name u'microsofthelp.exe'
2025-04-22 16:53:26,625 [analyzer] DEBUG: Loaded monitor into process with pid 1352
2025-04-22 16:53:27,203 [analyzer] INFO: Process with pid 2480 has terminated
2025-04-22 16:56:45,217 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-04-22 16:56:46,108 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-04-22 16:56:46,108 [lib.api.process] INFO: Successfully terminated process with pid 1352.
2025-04-22 16:56:46,125 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-04-24 06:02:54,218 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:02:55,239 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:02:56,258 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:02:57,278 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:02:58,299 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:02:59,323 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:00,346 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:01,367 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:02,389 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:03,407 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:04,425 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:05,444 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:06,467 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:07,483 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:08,529 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:09,591 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:10,663 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:11,726 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:12,783 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:13,844 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:14,927 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:15,980 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:17,022 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:18,064 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:19,114 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:20,181 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:21,231 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:22,273 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:23,389 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:24,442 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:25,503 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:26,546 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:27,588 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:28,641 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:29,687 [cuckoo.core.scheduler] DEBUG: Task #6331004: no machine available yet
2025-04-24 06:03:30,911 [cuckoo.core.scheduler] INFO: Task #6331004: acquired machine win7x642 (label=win7x642)
2025-04-24 06:03:30,958 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.202 for task #6331004
2025-04-24 06:03:31,299 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1678010 (interface=vboxnet0, host=192.168.168.202)
2025-04-24 06:03:31,460 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x642
2025-04-24 06:03:31,971 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x642 to vmcloak
2025-04-24 06:05:22,561 [cuckoo.core.guest] INFO: Starting analysis #6331004 on guest (id=win7x642, ip=192.168.168.202)
2025-04-24 06:05:23,566 [cuckoo.core.guest] DEBUG: win7x642: not ready yet
2025-04-24 06:05:28,602 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x642, ip=192.168.168.202)
2025-04-24 06:05:28,666 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x642, ip=192.168.168.202, monitor=latest, size=6660546)
2025-04-24 06:05:29,884 [cuckoo.core.resultserver] DEBUG: Task #6331004: live log analysis.log initialized.
2025-04-24 06:05:30,785 [cuckoo.core.resultserver] DEBUG: Task #6331004 is sending a BSON stream
2025-04-24 06:05:31,189 [cuckoo.core.resultserver] DEBUG: Task #6331004 is sending a BSON stream
2025-04-24 06:05:31,430 [cuckoo.core.resultserver] DEBUG: Task #6331004 is sending a BSON stream
2025-04-24 06:05:32,053 [cuckoo.core.resultserver] DEBUG: Task #6331004: File upload for 'shots/0001.jpg'
2025-04-24 06:05:32,067 [cuckoo.core.resultserver] DEBUG: Task #6331004 uploaded file length: 133565
2025-04-24 06:05:33,506 [cuckoo.core.resultserver] DEBUG: Task #6331004: File upload for 'files/aeee94997be4baf4_aeee94997be4baf4_microsofthelp.exe'
2025-04-24 06:05:33,511 [cuckoo.core.resultserver] DEBUG: Task #6331004 uploaded file length: 48449
2025-04-24 06:05:44,729 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:05:59,841 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:06:15,062 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:06:30,193 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:06:45,301 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:07:00,402 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:07:15,642 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:07:30,763 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:07:46,019 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:08:01,309 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:08:16,455 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:08:31,568 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:08:46,670 [cuckoo.core.guest] DEBUG: win7x642: analysis #6331004 still processing
2025-04-24 06:08:50,300 [cuckoo.core.resultserver] DEBUG: Task #6331004: File upload for 'curtain/1745333805.42.curtain.log'
2025-04-24 06:08:50,303 [cuckoo.core.resultserver] DEBUG: Task #6331004 uploaded file length: 36
2025-04-24 06:08:50,913 [cuckoo.core.resultserver] DEBUG: Task #6331004: File upload for 'sysmon/1745333806.03.sysmon.xml'
2025-04-24 06:08:50,991 [cuckoo.core.resultserver] DEBUG: Task #6331004 uploaded file length: 8215608
2025-04-24 06:08:51,010 [cuckoo.core.resultserver] DEBUG: Task #6331004: File upload for 'files/10aed1925db84222_microsofthelp.exe'
2025-04-24 06:08:51,013 [cuckoo.core.resultserver] DEBUG: Task #6331004 uploaded file length: 48709
2025-04-24 06:08:51,021 [cuckoo.core.resultserver] DEBUG: Task #6331004 had connection reset for <Context for LOG>
2025-04-24 06:08:52,694 [cuckoo.core.guest] INFO: win7x642: analysis completed successfully
2025-04-24 06:08:52,715 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-04-24 06:08:52,742 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-04-24 06:08:53,485 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x642 to path /srv/cuckoo/cwd/storage/analyses/6331004/memory.dmp
2025-04-24 06:08:53,509 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x642
2025-04-24 06:11:08,985 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.202 for task #6331004
2025-04-24 06:11:09,391 [cuckoo.core.scheduler] DEBUG: Released database task #6331004
2025-04-24 06:11:09,421 [cuckoo.core.scheduler] INFO: Task #6331004: analysis procedure completed