Analyzer Log
2025-06-24 21:29:14,030 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt
2025-06-24 21:29:14,062 [analyzer] DEBUG: Pipe server name: \??\PIPE\rnRGzHVPkwzKHGLtTaBVfwJwgUt
2025-06-24 21:29:14,062 [analyzer] DEBUG: Log pipe server name: \??\PIPE\eAViAtWxngGJdHpSGUjOlLpBzPlh
2025-06-24 21:29:14,062 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-24 21:29:14,078 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-24 21:29:14,733 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-24 21:29:14,733 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-24 21:29:15,328 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-24 21:29:15,592 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-24 21:29:15,608 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-24 21:29:15,608 [analyzer] DEBUG: Started auxiliary module Human
2025-06-24 21:29:15,625 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-24 21:29:15,625 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-24 21:29:15,717 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-24 21:29:15,717 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-24 21:29:15,717 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-24 21:29:15,717 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-24 21:29:15,983 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\3edb27daf6f653f5_unicorn-24005.exe' with arguments '' and pid 216
2025-06-24 21:29:16,250 [analyzer] DEBUG: Loaded monitor into process with pid 216
2025-06-24 21:29:19,342 [analyzer] INFO: Added new file to list with pid 216 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28488.exe
2025-06-24 21:29:19,467 [analyzer] INFO: Injected into process with pid 2288 and name u'Unicorn-28488.exe'
2025-06-24 21:29:19,671 [analyzer] DEBUG: Loaded monitor into process with pid 2288
2025-06-24 21:32:35,000 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-24 21:32:35,967 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-24 21:32:35,967 [lib.api.process] INFO: Successfully terminated process with pid 216.
2025-06-24 21:32:35,967 [lib.api.process] INFO: Successfully terminated process with pid 2288.
2025-06-24 21:32:35,983 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-02 12:12:50,473 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:51,493 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:52,525 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:53,597 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:54,633 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:55,662 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:56,688 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:57,713 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:58,744 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:12:59,776 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:00,832 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:03,733 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:04,810 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:05,900 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:07,006 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:08,077 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:09,164 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:10,251 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:11,305 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:12,575 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:13,661 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:14,743 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:15,805 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:16,881 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:17,952 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:19,251 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:20,324 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:21,380 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:22,846 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:23,881 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:24,936 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:25,966 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:26,995 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:28,029 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:29,288 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:30,393 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:31,636 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:32,849 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:33,916 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:34,979 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:36,219 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:37,283 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:38,326 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:39,363 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:40,397 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:41,779 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:42,830 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:44,150 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:45,197 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:46,241 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:47,272 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:48,309 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:49,347 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:50,379 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:51,424 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:52,517 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:53,555 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:54,610 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:55,656 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:56,701 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:57,737 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:13:58,887 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:00,195 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:01,251 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:02,297 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:03,359 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:04,536 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:05,626 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:06,761 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:07,857 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:09,195 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:10,311 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:11,407 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:12,512 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:13,573 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:14,681 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:15,768 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:16,868 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:17,959 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:19,061 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:20,154 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:21,217 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:22,273 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:23,365 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:24,426 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:25,812 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:26,837 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:28,042 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:29,523 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:30,982 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:32,047 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:33,112 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:34,168 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:35,213 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:36,267 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:37,325 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:38,399 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:39,583 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:40,609 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:41,681 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:42,720 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:43,760 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:44,822 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:46,027 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:47,072 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:48,096 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:49,136 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:50,178 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:51,232 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:52,319 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:53,377 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:54,564 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:55,772 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:57,271 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:58,371 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:14:59,439 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:15:00,481 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:15:01,775 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:15:02,831 [cuckoo.core.scheduler] DEBUG: Task #6631139: no machine available yet
2025-07-02 12:15:03,875 [cuckoo.core.scheduler] INFO: Task #6631139: acquired machine win7x6423 (label=win7x6423)
2025-07-02 12:15:03,881 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6631139
2025-07-02 12:15:04,346 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2754213 (interface=vboxnet0, host=192.168.168.223)
2025-07-02 12:15:06,430 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423
2025-07-02 12:15:13,695 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak
2025-07-02 12:17:04,604 [cuckoo.core.guest] INFO: Starting analysis #6631139 on guest (id=win7x6423, ip=192.168.168.223)
2025-07-02 12:17:05,611 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet
2025-07-02 12:17:10,654 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223)
2025-07-02 12:17:10,738 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546)
2025-07-02 12:17:12,351 [cuckoo.core.resultserver] DEBUG: Task #6631139: live log analysis.log initialized.
2025-07-02 12:17:14,058 [cuckoo.core.resultserver] DEBUG: Task #6631139 is sending a BSON stream
2025-07-02 12:17:14,511 [cuckoo.core.resultserver] DEBUG: Task #6631139 is sending a BSON stream
2025-07-02 12:17:15,544 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'shots/0001.jpg'
2025-07-02 12:17:15,595 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 133483
2025-07-02 12:17:17,941 [cuckoo.core.resultserver] DEBUG: Task #6631139 is sending a BSON stream
2025-07-02 12:17:19,843 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'shots/0002.jpg'
2025-07-02 12:17:19,858 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 137663
2025-07-02 12:17:24,078 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'shots/0003.jpg'
2025-07-02 12:17:24,119 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 127062
2025-07-02 12:17:27,087 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:17:27,505 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'shots/0004.jpg'
2025-07-02 12:17:27,600 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 126224
2025-07-02 12:17:29,701 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'shots/0005.jpg'
2025-07-02 12:17:29,713 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 110199
2025-07-02 12:17:37,148 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'shots/0006.jpg'
2025-07-02 12:17:37,325 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 109547
2025-07-02 12:17:42,287 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:17:57,474 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:18:12,801 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:18:28,179 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:18:43,322 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:18:58,746 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:19:14,073 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:19:29,202 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:19:44,613 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:20:00,000 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:20:15,531 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:20:30,689 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631139 still processing
2025-07-02 12:20:33,579 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'curtain/1750793555.19.curtain.log'
2025-07-02 12:20:33,582 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 36
2025-07-02 12:20:34,280 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'sysmon/1750793555.89.sysmon.xml'
2025-07-02 12:20:34,355 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 8629882
2025-07-02 12:20:34,377 [cuckoo.core.resultserver] DEBUG: Task #6631139: File upload for 'files/b6c012b09a95105c_unicorn-28488.exe'
2025-07-02 12:20:34,389 [cuckoo.core.resultserver] DEBUG: Task #6631139 uploaded file length: 479243
2025-07-02 12:20:34,402 [cuckoo.core.resultserver] DEBUG: Task #6631139 had connection reset for <Context for LOG>
2025-07-02 12:20:36,737 [cuckoo.core.guest] INFO: win7x6423: analysis completed successfully
2025-07-02 12:20:36,777 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-02 12:20:36,810 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-02 12:20:37,826 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6631139/memory.dmp
2025-07-02 12:20:37,833 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423
2025-07-02 12:22:26,970 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6631139
2025-07-02 12:22:27,719 [cuckoo.core.scheduler] DEBUG: Released database task #6631139
2025-07-02 12:22:27,744 [cuckoo.core.scheduler] INFO: Task #6631139: analysis procedure completed