Analyzer Log
2025-06-20 15:40:55,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt
2025-06-20 15:40:55,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\EnjpNwNmofhgaJueBi
2025-06-20 15:40:55,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\CPDAECmatSxpyoxfDemt
2025-06-20 15:40:55,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-20 15:40:55,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-20 15:40:55,796 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-20 15:40:56,015 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-20 15:40:56,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-20 15:40:56,015 [analyzer] DEBUG: Started auxiliary module Human
2025-06-20 15:40:56,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-20 15:40:56,015 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-20 15:40:56,108 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-20 15:40:56,108 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-20 15:40:56,108 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-20 15:40:56,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-20 15:40:56,250 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\04ad19ec4cca36d9a6684ea1e7f34a8a53599a27f2c8417c509464bc39b00f88.exe' with arguments '' and pid 2740
2025-06-20 15:40:56,453 [analyzer] DEBUG: Loaded monitor into process with pid 2740
2025-06-20 15:40:56,592 [analyzer] INFO: Injected into process with pid 1292 and name u'taskkill.exe'
2025-06-20 15:40:56,592 [analyzer] INFO: Added new file to list with pid 2740 and path C:\sys.exe
2025-06-20 15:40:56,608 [analyzer] INFO: Added new file to list with pid 2740 and path C:\Windows\sys.exe
2025-06-20 15:40:56,765 [analyzer] INFO: Injected into process with pid 2308 and name u'sys.exe'
2025-06-20 15:40:56,812 [analyzer] DEBUG: Loaded monitor into process with pid 1292
2025-06-20 15:40:56,828 [analyzer] INFO: Injected into process with pid 2944 and name u'cmd.exe'
2025-06-20 15:40:56,921 [analyzer] DEBUG: Loaded monitor into process with pid 2308
2025-06-20 15:41:25,250 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-20 15:41:25,703 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-20 15:41:25,717 [lib.api.process] INFO: Successfully terminated process with pid 2308.
2025-06-20 15:41:25,717 [lib.api.process] INFO: Successfully terminated process with pid 2944.
2025-06-20 15:41:25,733 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-21 12:31:07,067 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:08,112 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:09,235 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:10,275 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:11,303 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:12,764 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:14,149 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:15,204 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:16,255 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:17,281 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:18,312 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:19,356 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:20,453 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:21,489 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:22,534 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:23,584 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:24,653 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:25,736 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:26,796 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:27,901 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:28,980 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:30,086 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:31,212 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:32,473 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:33,583 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:34,674 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:35,748 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:36,782 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:38,148 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:39,486 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:40,571 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:41,878 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:42,918 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:43,955 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:44,999 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:46,569 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:47,604 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:48,644 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:49,672 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:50,699 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:51,722 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:52,749 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:53,789 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:55,125 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:56,297 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:57,381 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:58,430 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:59,476 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:00,513 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:01,563 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:02,599 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:03,661 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:04,862 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:06,014 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:07,120 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:08,190 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:09,262 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:10,337 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:11,408 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:12,462 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:14,078 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:15,195 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:16,310 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:17,381 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:18,443 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:19,504 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:20,567 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:21,643 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:22,708 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:23,799 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:24,862 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:25,921 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:26,958 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:27,986 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:29,020 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:30,039 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:31,633 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:33,036 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:34,161 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:35,320 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:36,444 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:37,554 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:38,638 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:39,726 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:40,798 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:41,860 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:43,237 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:44,336 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:45,389 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:46,510 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:47,812 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:48,891 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:49,976 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:51,034 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:52,102 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:53,168 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:54,212 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:55,257 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:56,705 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:57,847 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:58,954 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:00,064 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:01,179 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:02,270 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:03,619 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:04,715 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:06,107 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:07,185 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:08,271 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:09,902 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:10,949 [cuckoo.core.scheduler] INFO: Task #6570726: acquired machine win7x6423 (label=win7x6423)
2025-06-21 12:33:10,950 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6570726
2025-06-21 12:33:11,564 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 279834 (interface=vboxnet0, host=192.168.168.223)
2025-06-21 12:33:11,681 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423
2025-06-21 12:33:12,801 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak
2025-06-21 12:35:43,173 [cuckoo.core.guest] INFO: Starting analysis #6570726 on guest (id=win7x6423, ip=192.168.168.223)
2025-06-21 12:35:44,210 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet
2025-06-21 12:35:49,505 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223)
2025-06-21 12:35:49,645 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546)
2025-06-21 12:35:51,062 [cuckoo.core.resultserver] DEBUG: Task #6570726: live log analysis.log initialized.
2025-06-21 12:35:51,947 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:52,387 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:52,728 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:53,099 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:53,104 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'files/933be721c6bede96_~DF1412389143A8AD22.TMP'
2025-06-21 12:35:53,109 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 25686
2025-06-21 12:35:53,112 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:53,221 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'shots/0001.jpg'
2025-06-21 12:35:53,236 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 133465
2025-06-21 12:36:05,822 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6570726 still processing
2025-06-21 12:36:21,518 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'curtain/1750426885.52.curtain.log'
2025-06-21 12:36:21,532 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 36
2025-06-21 12:36:21,605 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6570726 still processing
2025-06-21 12:36:21,695 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'sysmon/1750426885.69.sysmon.xml'
2025-06-21 12:36:21,709 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 1199586
2025-06-21 12:36:21,721 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'files/2aa2960252e67e3b_sys.exe'
2025-06-21 12:36:21,725 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 140723
2025-06-21 12:36:21,728 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'files/b8cfc6343ca9f9b1_sys.exe'
2025-06-21 12:36:22,082 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 140723
2025-06-21 12:36:22,104 [cuckoo.core.resultserver] DEBUG: Task #6570726 had connection reset for <Context for LOG>
2025-06-21 12:36:24,631 [cuckoo.core.guest] INFO: win7x6423: analysis completed successfully
2025-06-21 12:36:24,647 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-21 12:36:24,687 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-21 12:36:25,949 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6570726/memory.dmp
2025-06-21 12:36:25,952 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423
2025-06-21 12:38:54,393 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6570726
2025-06-21 12:38:54,808 [cuckoo.core.scheduler] DEBUG: Released database task #6570726
2025-06-21 12:38:54,831 [cuckoo.core.scheduler] INFO: Task #6570726: analysis procedure completed