Analyzer Log
2025-06-21 09:34:00,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt
2025-06-21 09:34:00,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\JydLcstxMOkFYyXUsEuSUJ
2025-06-21 09:34:00,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\FKzsbtlCEOQRLxXljJG
2025-06-21 09:34:00,342 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-21 09:34:00,342 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-21 09:34:00,967 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-21 09:34:01,203 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-21 09:34:01,203 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-21 09:34:01,203 [analyzer] DEBUG: Started auxiliary module Human
2025-06-21 09:34:01,203 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-21 09:34:01,203 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-21 09:34:01,265 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-21 09:34:01,280 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-21 09:34:01,280 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-21 09:34:01,280 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-21 09:34:01,437 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\641d6e5613e2222e54c403c58d6048e16a49bd2b8a880bd747a7d30acb480f8c.exe' with arguments '' and pid 2604
2025-06-21 09:34:01,671 [analyzer] DEBUG: Loaded monitor into process with pid 2604
2025-06-21 09:34:04,750 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6064.exe
2025-06-21 09:34:04,828 [analyzer] INFO: Injected into process with pid 2836 and name u'Unicorn-6064.exe'
2025-06-21 09:34:04,983 [analyzer] DEBUG: Loaded monitor into process with pid 2836
2025-06-21 09:34:08,046 [analyzer] INFO: Added new file to list with pid 2836 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58877.exe
2025-06-21 09:34:08,155 [analyzer] INFO: Injected into process with pid 2548 and name u'Unicorn-58877.exe'
2025-06-21 09:34:08,328 [analyzer] DEBUG: Loaded monitor into process with pid 2548
2025-06-21 09:34:11,405 [analyzer] INFO: Added new file to list with pid 2548 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24233.exe
2025-06-21 09:34:11,578 [analyzer] INFO: Injected into process with pid 2752 and name u'Unicorn-24233.exe'
2025-06-21 09:34:11,750 [analyzer] DEBUG: Loaded monitor into process with pid 2752
2025-06-21 09:34:14,828 [analyzer] INFO: Added new file to list with pid 2752 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54741.exe
2025-06-21 09:34:14,905 [analyzer] INFO: Injected into process with pid 772 and name u'Unicorn-54741.exe'
2025-06-21 09:34:15,062 [analyzer] DEBUG: Loaded monitor into process with pid 772
2025-06-21 09:34:18,140 [analyzer] INFO: Added new file to list with pid 772 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29765.exe
2025-06-21 09:34:18,203 [analyzer] INFO: Injected into process with pid 2192 and name u'Unicorn-29765.exe'
2025-06-21 09:34:18,375 [analyzer] DEBUG: Loaded monitor into process with pid 2192
2025-06-21 09:34:21,453 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-15540.exe
2025-06-21 09:34:21,530 [analyzer] INFO: Injected into process with pid 2424 and name u'Unicorn-15540.exe'
2025-06-21 09:34:21,703 [analyzer] DEBUG: Loaded monitor into process with pid 2424
2025-06-21 09:34:24,780 [analyzer] INFO: Added new file to list with pid 2424 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41929.exe
2025-06-21 09:34:24,858 [analyzer] INFO: Injected into process with pid 1524 and name u'Unicorn-41929.exe'
2025-06-21 09:34:25,015 [analyzer] DEBUG: Loaded monitor into process with pid 1524
2025-06-21 09:34:28,092 [analyzer] INFO: Added new file to list with pid 1524 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29241.exe
2025-06-21 09:34:28,187 [analyzer] INFO: Injected into process with pid 2508 and name u'Unicorn-29241.exe'
2025-06-21 09:34:28,342 [analyzer] DEBUG: Loaded monitor into process with pid 2508
2025-06-21 09:34:30,453 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-21 09:34:30,812 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 2604.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 2836.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 2548.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 2752.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 772.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 2192.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 2424.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 1524.
2025-06-21 09:34:30,812 [lib.api.process] INFO: Successfully terminated process with pid 2508.
2025-06-21 09:34:30,921 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-24 21:19:07,298 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:08,323 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:09,347 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:10,368 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:11,398 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:12,425 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:13,455 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:14,504 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:15,558 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:16,768 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:17,813 [cuckoo.core.scheduler] DEBUG: Task #6585851: no machine available yet
2025-06-24 21:19:18,957 [cuckoo.core.scheduler] INFO: Task #6585851: acquired machine win7x6423 (label=win7x6423)
2025-06-24 21:19:18,960 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6585851
2025-06-24 21:19:19,599 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2784267 (interface=vboxnet0, host=192.168.168.223)
2025-06-24 21:19:23,493 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423
2025-06-24 21:19:24,227 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak
2025-06-24 21:22:45,552 [cuckoo.core.guest] INFO: Starting analysis #6585851 on guest (id=win7x6423, ip=192.168.168.223)
2025-06-24 21:22:46,823 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet
2025-06-24 21:22:52,184 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223)
2025-06-24 21:22:52,267 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546)
2025-06-24 21:22:53,675 [cuckoo.core.resultserver] DEBUG: Task #6585851: live log analysis.log initialized.
2025-06-24 21:22:54,918 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:22:55,477 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:22:56,250 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0001.jpg'
2025-06-24 21:22:56,276 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 133473
2025-06-24 21:22:58,592 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:23:01,498 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0002.jpg'
2025-06-24 21:23:01,513 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 137289
2025-06-24 21:23:01,921 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:23:04,702 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0003.jpg'
2025-06-24 21:23:04,710 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 125982
2025-06-24 21:23:05,358 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:23:06,986 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0004.jpg'
2025-06-24 21:23:07,256 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 125962
2025-06-24 21:23:08,336 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6585851 still processing
2025-06-24 21:23:08,670 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:23:10,335 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0005.jpg'
2025-06-24 21:23:10,347 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 127438
2025-06-24 21:23:11,983 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:23:13,498 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0006.jpg'
2025-06-24 21:23:13,505 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 128494
2025-06-24 21:23:15,428 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:23:16,646 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0007.jpg'
2025-06-24 21:23:16,662 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 129591
2025-06-24 21:23:17,754 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0008.jpg'
2025-06-24 21:23:17,766 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 130333
2025-06-24 21:23:18,623 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:23:18,877 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0009.jpg'
2025-06-24 21:23:18,892 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 130723
2025-06-24 21:23:19,998 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0010.jpg'
2025-06-24 21:23:20,007 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 130365
2025-06-24 21:23:21,951 [cuckoo.core.resultserver] DEBUG: Task #6585851 is sending a BSON stream
2025-06-24 21:23:23,147 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0011.jpg'
2025-06-24 21:23:23,159 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 130896
2025-06-24 21:23:23,415 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6585851 still processing
2025-06-24 21:23:24,458 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'curtain/1750491270.58.curtain.log'
2025-06-24 21:23:24,476 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 36
2025-06-24 21:23:24,489 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'sysmon/1750491270.8.sysmon.xml'
2025-06-24 21:23:24,500 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 1202526
2025-06-24 21:23:24,516 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'files/e998f63c155aafe9_unicorn-24233.exe'
2025-06-24 21:23:24,521 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 479246
2025-06-24 21:23:24,527 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'files/5da3099a1b0ee5d6_unicorn-29765.exe'
2025-06-24 21:23:24,533 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 479248
2025-06-24 21:23:24,538 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'files/9d55b529b252ca74_unicorn-15540.exe'
2025-06-24 21:23:24,544 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 479249
2025-06-24 21:23:24,570 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'files/5a76f4414ef8dcb6_unicorn-41929.exe'
2025-06-24 21:23:24,576 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 479250
2025-06-24 21:23:24,584 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'files/13cda2eeae9aa1bb_unicorn-6064.exe'
2025-06-24 21:23:24,601 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 479244
2025-06-24 21:23:24,614 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'files/ad5622ddaedd5c17_unicorn-29241.exe'
2025-06-24 21:23:24,623 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'files/8d75ed1f6ca9621e_unicorn-58877.exe'
2025-06-24 21:23:24,638 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'files/2f564f559a2f52a3_unicorn-54741.exe'
2025-06-24 21:23:24,644 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 479251
2025-06-24 21:23:24,646 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 479245
2025-06-24 21:23:24,649 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 479247
2025-06-24 21:23:25,292 [cuckoo.core.resultserver] DEBUG: Task #6585851: File upload for 'shots/0012.jpg'
2025-06-24 21:23:25,302 [cuckoo.core.resultserver] DEBUG: Task #6585851 uploaded file length: 143081
2025-06-24 21:23:25,318 [cuckoo.core.resultserver] DEBUG: Task #6585851 had connection reset for <Context for LOG>
2025-06-24 21:23:26,426 [cuckoo.core.guest] INFO: win7x6423: analysis completed successfully
2025-06-24 21:23:26,439 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-24 21:23:26,466 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-24 21:23:27,592 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6585851/memory.dmp
2025-06-24 21:23:27,593 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423
2025-06-24 21:26:12,069 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6585851
2025-06-24 21:26:12,807 [cuckoo.core.scheduler] DEBUG: Released database task #6585851
2025-06-24 21:26:12,826 [cuckoo.core.scheduler] INFO: Task #6585851: analysis procedure completed