Analyzer Log
2025-06-09 10:27:13,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpk4d6bl
2025-06-09 10:27:13,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\GluZDsrrikEhVpkKQRtqUWgY
2025-06-09 10:27:13,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\jFqjiqUOILoTxxzsPogZvOBC
2025-06-09 10:27:13,375 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-09 10:27:13,375 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-09 10:27:13,858 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-09 10:27:14,092 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-06-09 10:27:14,092 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-09 10:27:14,092 [analyzer] DEBUG: Started auxiliary module Human
2025-06-09 10:27:14,092 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-09 10:27:14,092 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-09 10:27:14,171 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-09 10:27:14,171 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-09 10:27:14,171 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-09 10:27:14,171 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-09 10:27:14,328 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\c2af3cb8b1d5a4e8c9ae3a431f414175f8909d69b9ce564c59a66a90a6a002fb.exe' with arguments '' and pid 2728
2025-06-09 10:27:14,562 [analyzer] DEBUG: Loaded monitor into process with pid 2728
2025-06-09 10:27:14,890 [analyzer] INFO: Added new file to list with pid 2728 and path C:\Users\Administrator\AppData\Roaming\Microsoft\fohbyc.exe
2025-06-09 10:27:17,640 [analyzer] INFO: Injected into process with pid 1364 and name u'nslookup.exe'
2025-06-09 10:27:17,905 [analyzer] DEBUG: Loaded monitor into process with pid 1364
2025-06-09 10:27:20,328 [analyzer] INFO: Process with pid 1364 has terminated
2025-06-09 13:00:36,440 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-09 13:00:37,394 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-09 13:00:37,394 [lib.api.process] INFO: Successfully terminated process with pid 2728.
2025-06-09 13:00:37,410 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-09 13:56:07,550 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:08,577 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:09,619 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:10,649 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:11,673 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:12,820 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:14,078 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:15,147 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:16,214 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:17,286 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:18,331 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:19,374 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:20,407 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:21,425 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:22,442 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:23,463 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:24,482 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:25,499 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:26,520 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:27,570 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:28,602 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:29,640 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:30,678 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:31,713 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:32,740 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:33,771 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:34,808 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:35,856 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:36,898 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:37,943 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:38,990 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:40,037 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:41,165 [cuckoo.core.scheduler] DEBUG: Task #6549164: no machine available yet
2025-06-09 13:56:42,223 [cuckoo.core.scheduler] INFO: Task #6549164: acquired machine win7x6422 (label=win7x6422)
2025-06-09 13:56:42,224 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.222 for task #6549164
2025-06-09 13:56:42,435 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 61368 (interface=vboxnet0, host=192.168.168.222)
2025-06-09 13:56:42,748 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6422
2025-06-09 13:56:43,105 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6422 to vmcloak
2025-06-09 13:58:28,527 [cuckoo.core.guest] INFO: Starting analysis #6549164 on guest (id=win7x6422, ip=192.168.168.222)
2025-06-09 13:58:29,533 [cuckoo.core.guest] DEBUG: win7x6422: not ready yet
2025-06-09 13:58:34,558 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6422, ip=192.168.168.222)
2025-06-09 13:58:34,653 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6422, ip=192.168.168.222, monitor=latest, size=6660546)
2025-06-09 13:58:36,088 [cuckoo.core.resultserver] DEBUG: Task #6549164: live log analysis.log initialized.
2025-06-09 13:58:37,124 [cuckoo.core.resultserver] DEBUG: Task #6549164 is sending a BSON stream
2025-06-09 13:58:37,562 [cuckoo.core.resultserver] DEBUG: Task #6549164 is sending a BSON stream
2025-06-09 13:58:38,374 [cuckoo.core.resultserver] DEBUG: Task #6549164: File upload for 'shots/0001.jpg'
2025-06-09 13:58:38,393 [cuckoo.core.resultserver] DEBUG: Task #6549164 uploaded file length: 133491
2025-06-09 13:58:40,908 [cuckoo.core.resultserver] DEBUG: Task #6549164 is sending a BSON stream
2025-06-09 13:58:50,589 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6549164 still processing
2025-06-09 13:59:05,710 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6549164 still processing
2025-06-09 13:59:20,838 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6549164 still processing
2025-06-09 13:59:35,936 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6549164 still processing
2025-06-09 13:59:51,134 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6549164 still processing
2025-06-09 14:00:06,422 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6549164 still processing
2025-06-09 14:00:21,537 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6549164 still processing
2025-06-09 14:00:36,622 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6549164 still processing
2025-06-09 14:00:36,634 [cuckoo.core.resultserver] DEBUG: Task #6549164: File upload for 'curtain/1749466836.63.curtain.log'
2025-06-09 14:00:36,637 [cuckoo.core.resultserver] DEBUG: Task #6549164 uploaded file length: 36
2025-06-09 14:00:37,201 [cuckoo.core.resultserver] DEBUG: Task #6549164: File upload for 'sysmon/1749466837.19.sysmon.xml'
2025-06-09 14:00:37,406 [cuckoo.core.resultserver] DEBUG: Task #6549164 uploaded file length: 7586792
2025-06-09 14:00:37,424 [cuckoo.core.resultserver] DEBUG: Task #6549164: File upload for 'files/53997ac8a46f745d_fohbyc.exe'
2025-06-09 14:00:37,433 [cuckoo.core.resultserver] DEBUG: Task #6549164 uploaded file length: 75264
2025-06-09 14:00:37,435 [cuckoo.core.resultserver] DEBUG: Task #6549164 had connection reset for <Context for LOG>
2025-06-09 14:00:39,656 [cuckoo.core.guest] INFO: win7x6422: analysis completed successfully
2025-06-09 14:00:39,680 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-09 14:00:39,708 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-09 14:00:40,381 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6422 to path /srv/cuckoo/cwd/storage/analyses/6549164/memory.dmp
2025-06-09 14:00:40,387 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6422
2025-06-09 14:02:33,363 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.222 for task #6549164
2025-06-09 14:02:34,640 [cuckoo.core.scheduler] DEBUG: Released database task #6549164
2025-06-09 14:02:34,669 [cuckoo.core.scheduler] INFO: Task #6549164: analysis procedure completed