Analyzer Log
2025-06-20 15:40:44,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd
2025-06-20 15:40:44,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\jKmlpAiIWZZIJBiZDAiVJZzn
2025-06-20 15:40:44,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\pvZWURjWokBPawMopNjGeEA
2025-06-20 15:40:44,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-20 15:40:44,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-20 15:40:44,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-20 15:40:45,046 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-20 15:40:45,046 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-20 15:40:45,046 [analyzer] DEBUG: Started auxiliary module Human
2025-06-20 15:40:45,046 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-20 15:40:45,046 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-20 15:40:45,125 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-20 15:40:45,125 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-20 15:40:45,125 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-20 15:40:45,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-20 15:40:45,265 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\44b355b93ca69a24573eba2331e3864f6fad0a76baf69bb0013297864fd08ba6.exe' with arguments '' and pid 2312
2025-06-20 15:40:45,421 [analyzer] DEBUG: Loaded monitor into process with pid 2312
2025-06-20 15:40:46,265 [analyzer] INFO: Process with pid 2312 has terminated
2025-06-20 15:40:46,265 [analyzer] INFO: Process list is empty, terminating analysis.
2025-06-20 15:40:47,453 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-20 15:40:47,453 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-21 12:25:11,933 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:12,969 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:13,999 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:15,024 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:16,051 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:17,077 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:18,103 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:19,452 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:20,504 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:21,551 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:22,594 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:23,658 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:24,701 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:25,730 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:27,103 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:29,255 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:30,381 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:31,502 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:32,595 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:33,686 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:35,020 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:36,171 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:37,447 [cuckoo.core.scheduler] DEBUG: Task #6570697: no machine available yet
2025-06-21 12:25:38,620 [cuckoo.core.scheduler] INFO: Task #6570697: acquired machine win7x6412 (label=win7x6412)
2025-06-21 12:25:38,627 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.212 for task #6570697
2025-06-21 12:25:39,208 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 270445 (interface=vboxnet0, host=192.168.168.212)
2025-06-21 12:25:39,832 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6412
2025-06-21 12:25:40,833 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6412 to vmcloak
2025-06-21 12:28:44,626 [cuckoo.core.guest] INFO: Starting analysis #6570697 on guest (id=win7x6412, ip=192.168.168.212)
2025-06-21 12:28:45,632 [cuckoo.core.guest] DEBUG: win7x6412: not ready yet
2025-06-21 12:28:50,656 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6412, ip=192.168.168.212)
2025-06-21 12:28:50,755 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6412, ip=192.168.168.212, monitor=latest, size=6660546)
2025-06-21 12:28:51,971 [cuckoo.core.resultserver] DEBUG: Task #6570697: live log analysis.log initialized.
2025-06-21 12:28:52,958 [cuckoo.core.resultserver] DEBUG: Task #6570697 is sending a BSON stream
2025-06-21 12:28:53,316 [cuckoo.core.resultserver] DEBUG: Task #6570697 is sending a BSON stream
2025-06-21 12:28:54,218 [cuckoo.core.resultserver] DEBUG: Task #6570697: File upload for 'shots/0001.jpg'
2025-06-21 12:28:54,232 [cuckoo.core.resultserver] DEBUG: Task #6570697 uploaded file length: 133465
2025-06-21 12:28:55,325 [cuckoo.core.resultserver] DEBUG: Task #6570697: File upload for 'curtain/1750426847.34.curtain.log'
2025-06-21 12:28:55,328 [cuckoo.core.resultserver] DEBUG: Task #6570697 uploaded file length: 36
2025-06-21 12:28:55,426 [cuckoo.core.resultserver] DEBUG: Task #6570697: File upload for 'sysmon/1750426847.44.sysmon.xml'
2025-06-21 12:28:55,432 [cuckoo.core.resultserver] DEBUG: Task #6570697 uploaded file length: 291010
2025-06-21 12:28:56,296 [cuckoo.core.resultserver] DEBUG: Task #6570697 had connection reset for <Context for LOG>
2025-06-21 12:28:57,603 [cuckoo.core.guest] INFO: win7x6412: analysis completed successfully
2025-06-21 12:28:57,620 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-21 12:28:57,656 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-21 12:28:59,626 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6412 to path /srv/cuckoo/cwd/storage/analyses/6570697/memory.dmp
2025-06-21 12:28:59,633 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6412
2025-06-21 12:30:57,953 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.212 for task #6570697
2025-06-21 12:30:58,576 [cuckoo.core.scheduler] DEBUG: Released database task #6570697
2025-06-21 12:30:58,639 [cuckoo.core.scheduler] INFO: Task #6570697: analysis procedure completed