Analyzer Log
2025-06-21 09:34:09,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpsftntc
2025-06-21 09:34:09,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\oGBibLSWMNWDbizYwSTcljd
2025-06-21 09:34:09,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\sCAbHFBWtIPnmjUSnw
2025-06-21 09:34:09,483 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-21 09:34:09,483 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-21 09:34:09,983 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-21 09:34:10,250 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-21 09:34:10,250 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-21 09:34:10,250 [analyzer] DEBUG: Started auxiliary module Human
2025-06-21 09:34:10,250 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-21 09:34:10,250 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-21 09:34:10,328 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-21 09:34:10,328 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-21 09:34:10,328 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-21 09:34:10,328 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-21 09:34:10,467 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\7719f9c40d67dbedc1399f0019aa7077db3e48dbde1e73ef44052ef4d57afe33.exe' with arguments '' and pid 1216
2025-06-21 09:34:10,687 [analyzer] DEBUG: Loaded monitor into process with pid 1216
2025-06-21 09:34:13,765 [analyzer] INFO: Added new file to list with pid 1216 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29361.exe
2025-06-21 09:34:13,875 [analyzer] INFO: Injected into process with pid 2876 and name u'Unicorn-29361.exe'
2025-06-21 09:34:14,046 [analyzer] DEBUG: Loaded monitor into process with pid 2876
2025-06-21 09:34:17,140 [analyzer] INFO: Added new file to list with pid 2876 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53585.exe
2025-06-21 09:34:17,233 [analyzer] INFO: Injected into process with pid 640 and name u'Unicorn-53585.exe'
2025-06-21 09:34:17,405 [analyzer] DEBUG: Loaded monitor into process with pid 640
2025-06-21 09:34:20,483 [analyzer] INFO: Added new file to list with pid 640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31193.exe
2025-06-21 09:34:20,562 [analyzer] INFO: Injected into process with pid 2432 and name u'Unicorn-31193.exe'
2025-06-21 09:34:20,717 [analyzer] DEBUG: Loaded monitor into process with pid 2432
2025-06-21 09:34:23,780 [analyzer] INFO: Added new file to list with pid 2432 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-20669.exe
2025-06-21 09:34:23,875 [analyzer] INFO: Injected into process with pid 2056 and name u'Unicorn-20669.exe'
2025-06-21 09:34:24,030 [analyzer] DEBUG: Loaded monitor into process with pid 2056
2025-06-21 09:34:27,108 [analyzer] INFO: Added new file to list with pid 2056 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57145.exe
2025-06-21 09:34:27,217 [analyzer] INFO: Injected into process with pid 1724 and name u'Unicorn-57145.exe'
2025-06-21 09:34:27,390 [analyzer] DEBUG: Loaded monitor into process with pid 1724
2025-06-21 09:34:30,453 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34753.exe
2025-06-21 09:34:30,562 [analyzer] INFO: Injected into process with pid 1032 and name u'Unicorn-34753.exe'
2025-06-21 09:34:30,733 [analyzer] DEBUG: Loaded monitor into process with pid 1032
2025-06-21 09:34:33,812 [analyzer] INFO: Added new file to list with pid 1032 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61141.exe
2025-06-21 09:34:33,921 [analyzer] INFO: Injected into process with pid 2060 and name u'Unicorn-61141.exe'
2025-06-21 09:34:34,092 [analyzer] DEBUG: Loaded monitor into process with pid 2060
2025-06-21 09:34:37,171 [analyzer] INFO: Added new file to list with pid 2060 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-36201.exe
2025-06-21 09:34:37,250 [analyzer] INFO: Injected into process with pid 2448 and name u'Unicorn-36201.exe'
2025-06-21 09:34:37,437 [analyzer] DEBUG: Loaded monitor into process with pid 2448
2025-06-21 09:34:39,515 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-21 09:34:39,890 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-21 09:34:39,890 [lib.api.process] INFO: Successfully terminated process with pid 1216.
2025-06-21 09:34:39,905 [lib.api.process] INFO: Successfully terminated process with pid 2876.
2025-06-21 09:34:39,905 [lib.api.process] INFO: Successfully terminated process with pid 640.
2025-06-21 09:34:39,905 [lib.api.process] INFO: Successfully terminated process with pid 2432.
2025-06-21 09:34:39,905 [lib.api.process] INFO: Successfully terminated process with pid 2056.
2025-06-21 09:34:39,905 [lib.api.process] INFO: Successfully terminated process with pid 1724.
2025-06-21 09:34:39,905 [lib.api.process] INFO: Successfully terminated process with pid 1032.
2025-06-21 09:34:39,905 [lib.api.process] INFO: Successfully terminated process with pid 2060.
2025-06-21 09:34:39,905 [lib.api.process] INFO: Successfully terminated process with pid 2448.
2025-06-21 09:34:40,000 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-24 21:29:56,447 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:29:57,469 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:29:58,490 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:29:59,819 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:00,866 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:02,147 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:03,182 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:04,213 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:05,247 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:06,291 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:07,314 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:08,830 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:09,905 [cuckoo.core.scheduler] DEBUG: Task #6585880: no machine available yet
2025-06-24 21:30:10,944 [cuckoo.core.scheduler] INFO: Task #6585880: acquired machine win7x6421 (label=win7x6421)
2025-06-24 21:30:10,945 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.221 for task #6585880
2025-06-24 21:30:11,563 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2797440 (interface=vboxnet0, host=192.168.168.221)
2025-06-24 21:30:12,647 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6421
2025-06-24 21:30:13,428 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6421 to vmcloak
2025-06-24 21:32:30,600 [cuckoo.core.guest] INFO: Starting analysis #6585880 on guest (id=win7x6421, ip=192.168.168.221)
2025-06-24 21:32:31,605 [cuckoo.core.guest] DEBUG: win7x6421: not ready yet
2025-06-24 21:32:36,633 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6421, ip=192.168.168.221)
2025-06-24 21:32:36,765 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6421, ip=192.168.168.221, monitor=latest, size=6660546)
2025-06-24 21:32:37,994 [cuckoo.core.resultserver] DEBUG: Task #6585880: live log analysis.log initialized.
2025-06-24 21:32:39,184 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:32:39,590 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:32:40,460 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0001.jpg'
2025-06-24 21:32:40,477 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 133473
2025-06-24 21:32:43,235 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:32:45,727 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0002.jpg'
2025-06-24 21:32:45,739 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 136446
2025-06-24 21:32:46,323 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:32:46,835 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0003.jpg'
2025-06-24 21:32:46,855 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 137569
2025-06-24 21:32:48,971 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0004.jpg'
2025-06-24 21:32:48,983 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 127345
2025-06-24 21:32:49,635 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:32:51,131 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0005.jpg'
2025-06-24 21:32:51,145 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 127343
2025-06-24 21:32:52,948 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:32:53,222 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6585880 still processing
2025-06-24 21:32:54,331 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0006.jpg'
2025-06-24 21:32:54,345 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 128596
2025-06-24 21:32:56,479 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:32:57,537 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0007.jpg'
2025-06-24 21:32:57,563 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 129798
2025-06-24 21:32:59,651 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:33:03,195 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:33:03,828 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0008.jpg'
2025-06-24 21:33:03,841 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 130935
2025-06-24 21:33:05,046 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0009.jpg'
2025-06-24 21:33:05,081 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 131556
2025-06-24 21:33:06,496 [cuckoo.core.resultserver] DEBUG: Task #6585880 is sending a BSON stream
2025-06-24 21:33:07,513 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0010.jpg'
2025-06-24 21:33:07,553 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 131581
2025-06-24 21:33:08,699 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'curtain/1750491279.7.curtain.log'
2025-06-24 21:33:08,701 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 36
2025-06-24 21:33:08,745 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6585880 still processing
2025-06-24 21:33:08,881 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'sysmon/1750491279.88.sysmon.xml'
2025-06-24 21:33:08,897 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 1409082
2025-06-24 21:33:08,913 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'files/fcdd2f1d143465a8_unicorn-53585.exe'
2025-06-24 21:33:08,928 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 479234
2025-06-24 21:33:08,931 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'files/2cff557a384adc83_unicorn-34753.exe'
2025-06-24 21:33:08,944 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 479238
2025-06-24 21:33:08,962 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'files/64e55a3c2b9fbf16_unicorn-31193.exe'
2025-06-24 21:33:08,967 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 479235
2025-06-24 21:33:08,974 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'files/9a53b1a43a2f04fe_unicorn-36201.exe'
2025-06-24 21:33:08,977 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 479240
2025-06-24 21:33:08,986 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'files/fec38d592fe0dafb_unicorn-20669.exe'
2025-06-24 21:33:08,990 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'files/0ee2c1b420689149_unicorn-57145.exe'
2025-06-24 21:33:08,992 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 479236
2025-06-24 21:33:08,995 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 479237
2025-06-24 21:33:08,999 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'files/d91a5188c19c9061_unicorn-29361.exe'
2025-06-24 21:33:09,004 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 479233
2025-06-24 21:33:09,014 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'files/140c3b041fd97d0e_unicorn-61141.exe'
2025-06-24 21:33:09,017 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 479239
2025-06-24 21:33:09,860 [cuckoo.core.resultserver] DEBUG: Task #6585880: File upload for 'shots/0011.jpg'
2025-06-24 21:33:09,900 [cuckoo.core.resultserver] DEBUG: Task #6585880 uploaded file length: 143092
2025-06-24 21:33:09,911 [cuckoo.core.resultserver] DEBUG: Task #6585880 had connection reset for <Context for LOG>
2025-06-24 21:33:11,761 [cuckoo.core.guest] INFO: win7x6421: analysis completed successfully
2025-06-24 21:33:11,779 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-24 21:33:11,811 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-24 21:33:12,982 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6421 to path /srv/cuckoo/cwd/storage/analyses/6585880/memory.dmp
2025-06-24 21:33:12,983 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6421
2025-06-24 21:35:40,381 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.221 for task #6585880
2025-06-24 21:35:40,845 [cuckoo.core.scheduler] DEBUG: Released database task #6585880
2025-06-24 21:35:51,117 [cuckoo.core.scheduler] INFO: Task #6585880: analysis procedure completed