Analyzer Log
2025-06-21 12:41:38,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpqqrt4a
2025-06-21 12:41:38,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\UntddpXAmEJecdMeLgrvHwovJEf
2025-06-21 12:41:38,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\cMKMUfxULURzxcOSsLulMGUH
2025-06-21 12:41:38,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-21 12:41:38,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-21 12:41:38,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-21 12:41:38,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-21 12:41:38,921 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-21 12:41:39,155 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-06-21 12:41:39,155 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-21 12:41:39,155 [analyzer] DEBUG: Started auxiliary module Human
2025-06-21 12:41:39,155 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-21 12:41:39,155 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-21 12:41:39,203 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-21 12:41:39,203 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-21 12:41:39,217 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-21 12:41:39,217 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-21 12:41:39,467 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\35b131914173b444_7d57ad13e21.exe' with arguments '' and pid 1892
2025-06-21 12:41:39,625 [analyzer] DEBUG: Loaded monitor into process with pid 1892
2025-06-21 12:42:00,233 [analyzer] INFO: Added new file to list with pid 1892 and path C:\Users\Administrator\AppData\Roaming\7D57AD13E21.exe
2025-06-21 12:42:00,546 [analyzer] INFO: Injected into process with pid 2844 and name u'reg.exe'
2025-06-21 12:42:00,780 [analyzer] DEBUG: Loaded monitor into process with pid 2844
2025-06-21 12:42:00,780 [analyzer] INFO: Injected into process with pid 1064 and name u'7D57AD13E21.exe'
2025-06-21 12:42:01,000 [analyzer] DEBUG: Loaded monitor into process with pid 1064
2025-06-21 12:42:01,390 [analyzer] INFO: Added new file to list with pid 1892 and path C:\Users\Administrator\AppData\Roaming\Scegli_nome_allegato.exe
2025-06-21 12:42:01,467 [analyzer] INFO: Process with pid 2844 has terminated
2025-06-21 12:42:02,467 [analyzer] INFO: Process with pid 1892 has terminated
2025-06-21 12:44:58,467 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-21 12:44:59,733 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-21 12:44:59,733 [lib.api.process] INFO: Successfully terminated process with pid 1064.
2025-06-21 12:44:59,905 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-25 12:50:05,777 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:06,822 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:07,855 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:08,874 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:09,904 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:10,933 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:11,955 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:12,990 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:14,043 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:15,071 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:16,205 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:17,226 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:18,253 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:19,274 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:20,295 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:21,321 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:22,348 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:23,376 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:24,400 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:25,427 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:26,703 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:27,754 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:28,796 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:29,837 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:30,880 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:31,933 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:32,974 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:34,008 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:35,051 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:36,086 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:37,259 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:38,304 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:39,345 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:40,377 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:41,410 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:42,555 [cuckoo.core.scheduler] DEBUG: Task #6588615: no machine available yet
2025-06-25 12:50:43,615 [cuckoo.core.scheduler] INFO: Task #6588615: acquired machine win7x6428 (label=win7x6428)
2025-06-25 12:50:43,617 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.228 for task #6588615
2025-06-25 12:50:43,924 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3990858 (interface=vboxnet0, host=192.168.168.228)
2025-06-25 12:50:52,795 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6428
2025-06-25 12:50:53,342 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6428 to vmcloak
2025-06-25 12:54:04,521 [cuckoo.core.guest] INFO: Starting analysis #6588615 on guest (id=win7x6428, ip=192.168.168.228)
2025-06-25 12:54:05,527 [cuckoo.core.guest] DEBUG: win7x6428: not ready yet
2025-06-25 12:54:10,551 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6428, ip=192.168.168.228)
2025-06-25 12:54:10,660 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6428, ip=192.168.168.228, monitor=latest, size=6660546)
2025-06-25 12:54:12,322 [cuckoo.core.resultserver] DEBUG: Task #6588615: live log analysis.log initialized.
2025-06-25 12:54:13,411 [cuckoo.core.resultserver] DEBUG: Task #6588615 is sending a BSON stream
2025-06-25 12:54:13,864 [cuckoo.core.resultserver] DEBUG: Task #6588615 is sending a BSON stream
2025-06-25 12:54:14,645 [cuckoo.core.resultserver] DEBUG: Task #6588615: File upload for 'shots/0001.jpg'
2025-06-25 12:54:14,657 [cuckoo.core.resultserver] DEBUG: Task #6588615 uploaded file length: 133497
2025-06-25 12:54:27,136 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:54:35,021 [cuckoo.core.resultserver] DEBUG: Task #6588615 is sending a BSON stream
2025-06-25 12:54:35,257 [cuckoo.core.resultserver] DEBUG: Task #6588615 is sending a BSON stream
2025-06-25 12:54:42,276 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:54:57,374 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:55:12,803 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:55:27,909 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:55:43,450 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:55:58,672 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:56:13,790 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:56:28,950 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:56:44,047 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:56:59,145 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:57:14,273 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:57:29,484 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6588615 still processing
2025-06-25 12:57:32,990 [cuckoo.core.resultserver] DEBUG: Task #6588615: File upload for 'curtain/1750502698.66.curtain.log'
2025-06-25 12:57:32,993 [cuckoo.core.resultserver] DEBUG: Task #6588615 uploaded file length: 36
2025-06-25 12:57:33,951 [cuckoo.core.resultserver] DEBUG: Task #6588615: File upload for 'sysmon/1750502699.62.sysmon.xml'
2025-06-25 12:57:34,056 [cuckoo.core.resultserver] DEBUG: Task #6588615 uploaded file length: 13533612
2025-06-25 12:57:34,125 [cuckoo.core.resultserver] DEBUG: Task #6588615: File upload for 'files/9fea97e4b6379e4a_scegli_nome_allegato.exe'
2025-06-25 12:57:34,136 [cuckoo.core.resultserver] DEBUG: Task #6588615 uploaded file length: 1050871
2025-06-25 12:57:34,191 [cuckoo.core.resultserver] DEBUG: Task #6588615: File upload for 'files/5dd6f4535e7a2cea_7d57ad13e21.exe'
2025-06-25 12:57:34,234 [cuckoo.core.resultserver] DEBUG: Task #6588615 uploaded file length: 6014905
2025-06-25 12:57:34,247 [cuckoo.core.resultserver] DEBUG: Task #6588615 had connection reset for <Context for LOG>
2025-06-25 12:57:35,519 [cuckoo.core.guest] INFO: win7x6428: analysis completed successfully
2025-06-25 12:57:35,536 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-25 12:57:35,651 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-25 12:57:36,535 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6428 to path /srv/cuckoo/cwd/storage/analyses/6588615/memory.dmp
2025-06-25 12:57:36,536 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6428
2025-06-25 13:00:17,387 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.228 for task #6588615
2025-06-25 13:00:17,859 [cuckoo.core.scheduler] DEBUG: Released database task #6588615
2025-06-25 13:00:17,877 [cuckoo.core.scheduler] INFO: Task #6588615: analysis procedure completed