Analyzer Log
2025-06-24 21:29:14,030 [analyzer] DEBUG: Starting analyzer from: C:\tmptisd8w
2025-06-24 21:29:14,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\rjEndPtdjtQrLfokLQesZwFWfD
2025-06-24 21:29:14,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\QGJaLdfFBxufwNNIpOiKQnroSR
2025-06-24 21:29:14,046 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-24 21:29:14,062 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-24 21:29:14,421 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-24 21:29:14,421 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-24 21:29:14,890 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-24 21:29:15,171 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-24 21:29:15,171 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-24 21:29:15,187 [analyzer] DEBUG: Started auxiliary module Human
2025-06-24 21:29:15,187 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-24 21:29:15,187 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-24 21:29:15,250 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-24 21:29:15,250 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-24 21:29:15,250 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-24 21:29:15,250 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-24 21:29:15,500 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\de8c69e6b0eda4a7_unicorn-6744.exe' with arguments '' and pid 2796
2025-06-24 21:29:15,733 [analyzer] DEBUG: Loaded monitor into process with pid 2796
2025-06-24 21:29:18,812 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11841.exe
2025-06-24 21:29:18,937 [analyzer] INFO: Injected into process with pid 1484 and name u'Unicorn-11841.exe'
2025-06-24 21:29:19,140 [analyzer] DEBUG: Loaded monitor into process with pid 1484
2025-06-24 21:29:22,217 [analyzer] INFO: Added new file to list with pid 1484 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55090.exe
2025-06-24 21:29:22,312 [analyzer] INFO: Injected into process with pid 3040 and name u'Unicorn-55090.exe'
2025-06-24 21:29:22,467 [analyzer] DEBUG: Loaded monitor into process with pid 3040
2025-06-24 21:29:25,546 [analyzer] INFO: Added new file to list with pid 3040 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5801.exe
2025-06-24 21:29:25,655 [analyzer] INFO: Injected into process with pid 1488 and name u'Unicorn-5801.exe'
2025-06-24 21:29:25,828 [analyzer] DEBUG: Loaded monitor into process with pid 1488
2025-06-24 21:29:28,921 [analyzer] INFO: Added new file to list with pid 1488 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6481.exe
2025-06-24 21:29:29,265 [analyzer] INFO: Injected into process with pid 2304 and name u'Unicorn-6481.exe'
2025-06-24 21:29:29,437 [analyzer] DEBUG: Loaded monitor into process with pid 2304
2025-06-24 21:29:32,530 [analyzer] INFO: Added new file to list with pid 2304 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-145.exe
2025-06-24 21:29:32,717 [analyzer] INFO: Injected into process with pid 2368 and name u'Unicorn-145.exe'
2025-06-24 21:29:32,905 [analyzer] DEBUG: Loaded monitor into process with pid 2368
2025-06-24 21:29:36,046 [analyzer] INFO: Added new file to list with pid 2368 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-20247.exe
2025-06-24 21:29:36,155 [analyzer] INFO: Injected into process with pid 2920 and name u'Unicorn-20247.exe'
2025-06-24 21:29:36,328 [analyzer] DEBUG: Loaded monitor into process with pid 2920
2025-06-24 21:29:39,390 [analyzer] INFO: Added new file to list with pid 2920 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-9094.exe
2025-06-24 21:29:39,578 [analyzer] INFO: Injected into process with pid 1564 and name u'Unicorn-9094.exe'
2025-06-24 21:29:39,750 [analyzer] DEBUG: Loaded monitor into process with pid 1564
2025-06-24 21:29:42,890 [analyzer] INFO: Added new file to list with pid 1564 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-646.exe
2025-06-24 21:29:43,030 [analyzer] INFO: Injected into process with pid 3060 and name u'Unicorn-646.exe'
2025-06-24 21:29:43,217 [analyzer] DEBUG: Loaded monitor into process with pid 3060
2025-06-24 21:29:46,328 [analyzer] INFO: Added new file to list with pid 3060 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27751.exe
2025-06-24 21:29:46,467 [analyzer] INFO: Injected into process with pid 2952 and name u'Unicorn-27751.exe'
2025-06-24 21:29:46,640 [analyzer] DEBUG: Loaded monitor into process with pid 2952
2025-06-24 21:29:49,717 [analyzer] INFO: Added new file to list with pid 2952 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27279.exe
2025-06-24 21:29:49,875 [analyzer] INFO: Injected into process with pid 2332 and name u'Unicorn-27279.exe'
2025-06-24 21:29:50,046 [analyzer] DEBUG: Loaded monitor into process with pid 2332
2025-06-24 21:29:53,125 [analyzer] INFO: Added new file to list with pid 2332 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38431.exe
2025-06-24 21:29:53,265 [analyzer] INFO: Injected into process with pid 2476 and name u'Unicorn-38431.exe'
2025-06-24 21:29:53,437 [analyzer] DEBUG: Loaded monitor into process with pid 2476
2025-06-24 21:29:56,546 [analyzer] INFO: Added new file to list with pid 2476 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46127.exe
2025-06-24 21:29:56,780 [analyzer] INFO: Injected into process with pid 2652 and name u'Unicorn-46127.exe'
2025-06-24 21:29:56,953 [analyzer] DEBUG: Loaded monitor into process with pid 2652
2025-06-24 21:30:00,078 [analyzer] INFO: Added new file to list with pid 2652 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65255.exe
2025-06-24 21:30:00,203 [analyzer] INFO: Injected into process with pid 3120 and name u'Unicorn-65255.exe'
2025-06-24 21:30:00,358 [analyzer] DEBUG: Loaded monitor into process with pid 3120
2025-06-24 21:30:03,437 [analyzer] INFO: Added new file to list with pid 3120 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62271.exe
2025-06-24 21:30:03,578 [analyzer] INFO: Injected into process with pid 3212 and name u'Unicorn-62271.exe'
2025-06-24 21:30:03,750 [analyzer] DEBUG: Loaded monitor into process with pid 3212
2025-06-24 21:30:06,842 [analyzer] INFO: Added new file to list with pid 3212 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61799.exe
2025-06-24 21:30:06,953 [analyzer] INFO: Injected into process with pid 3300 and name u'Unicorn-61799.exe'
2025-06-24 21:30:07,125 [analyzer] DEBUG: Loaded monitor into process with pid 3300
2025-06-24 21:30:10,217 [analyzer] INFO: Added new file to list with pid 3300 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31631.exe
2025-06-24 21:30:10,358 [analyzer] INFO: Injected into process with pid 3380 and name u'Unicorn-31631.exe'
2025-06-24 21:30:10,530 [analyzer] DEBUG: Loaded monitor into process with pid 3380
2025-06-24 21:30:13,625 [analyzer] INFO: Added new file to list with pid 3380 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39711.exe
2025-06-24 21:30:13,765 [analyzer] INFO: Injected into process with pid 3476 and name u'Unicorn-39711.exe'
2025-06-24 21:30:13,937 [analyzer] DEBUG: Loaded monitor into process with pid 3476
2025-06-24 21:30:17,015 [analyzer] INFO: Added new file to list with pid 3476 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42311.exe
2025-06-24 21:30:17,125 [analyzer] INFO: Injected into process with pid 3560 and name u'Unicorn-42311.exe'
2025-06-24 21:30:17,296 [analyzer] DEBUG: Loaded monitor into process with pid 3560
2025-06-24 21:30:20,375 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27039.exe
2025-06-24 21:30:20,546 [analyzer] INFO: Injected into process with pid 3640 and name u'Unicorn-27039.exe'
2025-06-24 21:30:20,717 [analyzer] DEBUG: Loaded monitor into process with pid 3640
2025-06-24 21:30:23,812 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-63359.exe
2025-06-24 21:30:23,937 [analyzer] INFO: Injected into process with pid 3744 and name u'Unicorn-63359.exe'
2025-06-24 21:30:24,171 [analyzer] DEBUG: Loaded monitor into process with pid 3744
2025-06-24 21:30:27,265 [analyzer] INFO: Added new file to list with pid 3744 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33479.exe
2025-06-24 21:30:27,437 [analyzer] INFO: Injected into process with pid 3832 and name u'Unicorn-33479.exe'
2025-06-24 21:30:27,592 [analyzer] DEBUG: Loaded monitor into process with pid 3832
2025-06-24 21:30:30,671 [analyzer] INFO: Added new file to list with pid 3832 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41175.exe
2025-06-24 21:30:30,953 [analyzer] INFO: Injected into process with pid 3916 and name u'Unicorn-41175.exe'
2025-06-24 21:30:31,155 [analyzer] DEBUG: Loaded monitor into process with pid 3916
2025-06-24 21:30:34,233 [analyzer] INFO: Added new file to list with pid 3916 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-2934.exe
2025-06-24 21:30:34,467 [analyzer] INFO: Injected into process with pid 4016 and name u'Unicorn-2934.exe'
2025-06-24 21:30:34,625 [analyzer] DEBUG: Loaded monitor into process with pid 4016
2025-06-24 21:30:37,703 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43687.exe
2025-06-24 21:30:37,828 [analyzer] INFO: Injected into process with pid 3076 and name u'Unicorn-43687.exe'
2025-06-24 21:30:38,000 [analyzer] DEBUG: Loaded monitor into process with pid 3076
2025-06-24 21:30:41,092 [analyzer] INFO: Added new file to list with pid 3076 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13518.exe
2025-06-24 21:30:41,233 [analyzer] INFO: Injected into process with pid 3240 and name u'Unicorn-13518.exe'
2025-06-24 21:30:41,437 [analyzer] DEBUG: Loaded monitor into process with pid 3240
2025-06-24 21:30:44,546 [analyzer] INFO: Added new file to list with pid 3240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46103.exe
2025-06-24 21:30:44,655 [analyzer] INFO: Injected into process with pid 3456 and name u'Unicorn-46103.exe'
2025-06-24 21:30:44,828 [analyzer] DEBUG: Loaded monitor into process with pid 3456
2025-06-24 21:30:47,890 [analyzer] INFO: Added new file to list with pid 3456 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34951.exe
2025-06-24 21:30:48,046 [analyzer] INFO: Injected into process with pid 3576 and name u'Unicorn-34951.exe'
2025-06-24 21:30:48,217 [analyzer] DEBUG: Loaded monitor into process with pid 3576
2025-06-24 21:30:51,328 [analyzer] INFO: Added new file to list with pid 3576 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-45719.exe
2025-06-24 21:30:51,500 [analyzer] INFO: Injected into process with pid 3656 and name u'Unicorn-45719.exe'
2025-06-24 21:30:51,671 [analyzer] DEBUG: Loaded monitor into process with pid 3656
2025-06-24 21:30:54,750 [analyzer] INFO: Added new file to list with pid 3656 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-12766.exe
2025-06-24 21:30:54,890 [analyzer] INFO: Injected into process with pid 840 and name u'Unicorn-12766.exe'
2025-06-24 21:30:55,062 [analyzer] DEBUG: Loaded monitor into process with pid 840
2025-06-24 21:30:58,155 [analyzer] INFO: Added new file to list with pid 840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-23535.exe
2025-06-24 21:30:58,250 [analyzer] INFO: Injected into process with pid 3728 and name u'Unicorn-23535.exe'
2025-06-24 21:30:58,390 [analyzer] DEBUG: Loaded monitor into process with pid 3728
2025-06-24 21:31:01,467 [analyzer] INFO: Added new file to list with pid 3728 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48911.exe
2025-06-24 21:31:01,578 [analyzer] INFO: Injected into process with pid 2192 and name u'Unicorn-48911.exe'
2025-06-24 21:31:01,733 [analyzer] DEBUG: Loaded monitor into process with pid 2192
2025-06-24 21:31:04,842 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-32103.exe
2025-06-24 21:31:05,092 [analyzer] INFO: Injected into process with pid 1540 and name u'Unicorn-32103.exe'
2025-06-24 21:31:05,265 [analyzer] DEBUG: Loaded monitor into process with pid 1540
2025-06-24 21:31:08,358 [analyzer] INFO: Added new file to list with pid 1540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43063.exe
2025-06-24 21:31:08,453 [analyzer] INFO: Injected into process with pid 2316 and name u'Unicorn-43063.exe'
2025-06-24 21:31:08,608 [analyzer] DEBUG: Loaded monitor into process with pid 2316
2025-06-24 21:31:11,765 [analyzer] INFO: Added new file to list with pid 2316 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-63431.exe
2025-06-24 21:31:11,890 [analyzer] INFO: Injected into process with pid 2120 and name u'Unicorn-63431.exe'
2025-06-24 21:31:12,046 [analyzer] DEBUG: Loaded monitor into process with pid 2120
2025-06-24 21:31:15,140 [analyzer] INFO: Added new file to list with pid 2120 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25095.exe
2025-06-24 21:31:15,233 [analyzer] INFO: Injected into process with pid 2588 and name u'Unicorn-25095.exe'
2025-06-24 21:31:15,405 [analyzer] DEBUG: Loaded monitor into process with pid 2588
2025-06-24 21:31:18,483 [analyzer] INFO: Added new file to list with pid 2588 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1270.exe
2025-06-24 21:31:18,640 [analyzer] INFO: Injected into process with pid 3104 and name u'Unicorn-1270.exe'
2025-06-24 21:31:18,828 [analyzer] DEBUG: Loaded monitor into process with pid 3104
2025-06-24 21:31:21,921 [analyzer] INFO: Added new file to list with pid 3104 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25687.exe
2025-06-24 21:31:22,000 [analyzer] INFO: Injected into process with pid 3280 and name u'Unicorn-25687.exe'
2025-06-24 21:31:22,155 [analyzer] DEBUG: Loaded monitor into process with pid 3280
2025-06-24 21:31:25,233 [analyzer] INFO: Added new file to list with pid 3280 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52599.exe
2025-06-24 21:31:25,328 [analyzer] INFO: Injected into process with pid 3988 and name u'Unicorn-52599.exe'
2025-06-24 21:31:25,483 [analyzer] DEBUG: Loaded monitor into process with pid 3988
2025-06-24 21:31:28,578 [analyzer] INFO: Added new file to list with pid 3988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27623.exe
2025-06-24 21:31:28,655 [analyzer] INFO: Injected into process with pid 1300 and name u'Unicorn-27623.exe'
2025-06-24 21:31:28,828 [analyzer] DEBUG: Loaded monitor into process with pid 1300
2025-06-24 21:31:31,937 [analyzer] INFO: Added new file to list with pid 1300 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24639.exe
2025-06-24 21:31:32,030 [analyzer] INFO: Injected into process with pid 3632 and name u'Unicorn-24639.exe'
2025-06-24 21:31:32,203 [analyzer] DEBUG: Loaded monitor into process with pid 3632
2025-06-24 21:31:35,328 [analyzer] INFO: Added new file to list with pid 3632 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27239.exe
2025-06-24 21:31:35,421 [analyzer] INFO: Injected into process with pid 4120 and name u'Unicorn-27239.exe'
2025-06-24 21:31:35,562 [analyzer] DEBUG: Loaded monitor into process with pid 4120
2025-06-24 21:31:38,655 [analyzer] INFO: Added new file to list with pid 4120 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59631.exe
2025-06-24 21:31:38,733 [analyzer] INFO: Injected into process with pid 4200 and name u'Unicorn-59631.exe'
2025-06-24 21:31:38,890 [analyzer] DEBUG: Loaded monitor into process with pid 4200
2025-06-24 21:31:41,983 [analyzer] INFO: Added new file to list with pid 4200 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27639.exe
2025-06-24 21:31:42,062 [analyzer] INFO: Injected into process with pid 4280 and name u'Unicorn-27639.exe'
2025-06-24 21:31:42,233 [analyzer] DEBUG: Loaded monitor into process with pid 4280
2025-06-24 21:31:45,328 [analyzer] INFO: Added new file to list with pid 4280 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55908.exe
2025-06-24 21:31:45,390 [analyzer] INFO: Injected into process with pid 4360 and name u'Unicorn-55908.exe'
2025-06-24 21:31:45,562 [analyzer] DEBUG: Loaded monitor into process with pid 4360
2025-06-24 21:31:48,655 [analyzer] INFO: Added new file to list with pid 4360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-22764.exe
2025-06-24 21:31:48,733 [analyzer] INFO: Injected into process with pid 4440 and name u'Unicorn-22764.exe'
2025-06-24 21:31:48,890 [analyzer] DEBUG: Loaded monitor into process with pid 4440
2025-06-24 21:31:52,000 [analyzer] INFO: Added new file to list with pid 4440 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-859.exe
2025-06-24 21:31:52,062 [analyzer] INFO: Injected into process with pid 4524 and name u'Unicorn-859.exe'
2025-06-24 21:31:52,233 [analyzer] DEBUG: Loaded monitor into process with pid 4524
2025-06-24 21:31:55,342 [analyzer] INFO: Added new file to list with pid 4524 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46692.exe
2025-06-24 21:31:55,467 [analyzer] INFO: Injected into process with pid 4604 and name u'Unicorn-46692.exe'
2025-06-24 21:31:55,640 [analyzer] DEBUG: Loaded monitor into process with pid 4604
2025-06-24 21:31:58,750 [analyzer] INFO: Added new file to list with pid 4604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62940.exe
2025-06-24 21:31:58,842 [analyzer] INFO: Injected into process with pid 4684 and name u'Unicorn-62940.exe'
2025-06-24 21:31:59,000 [analyzer] DEBUG: Loaded monitor into process with pid 4684
2025-06-24 21:32:02,125 [analyzer] INFO: Added new file to list with pid 4684 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57372.exe
2025-06-24 21:32:02,203 [analyzer] INFO: Injected into process with pid 4764 and name u'Unicorn-57372.exe'
2025-06-24 21:32:02,375 [analyzer] DEBUG: Loaded monitor into process with pid 4764
2025-06-24 21:32:05,515 [analyzer] INFO: Added new file to list with pid 4764 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56900.exe
2025-06-24 21:32:05,592 [analyzer] INFO: Injected into process with pid 4848 and name u'Unicorn-56900.exe'
2025-06-24 21:32:05,780 [analyzer] DEBUG: Loaded monitor into process with pid 4848
2025-06-24 21:32:08,937 [analyzer] INFO: Added new file to list with pid 4848 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-8763.exe
2025-06-24 21:32:09,030 [analyzer] INFO: Injected into process with pid 4936 and name u'Unicorn-8763.exe'
2025-06-24 21:32:09,203 [analyzer] DEBUG: Loaded monitor into process with pid 4936
2025-06-24 21:32:12,358 [analyzer] INFO: Added new file to list with pid 4936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27700.exe
2025-06-24 21:32:12,467 [analyzer] INFO: Injected into process with pid 5020 and name u'Unicorn-27700.exe'
2025-06-24 21:32:12,625 [analyzer] DEBUG: Loaded monitor into process with pid 5020
2025-06-24 21:32:15,765 [analyzer] INFO: Added new file to list with pid 5020 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48068.exe
2025-06-24 21:32:15,842 [analyzer] INFO: Injected into process with pid 5112 and name u'Unicorn-48068.exe'
2025-06-24 21:32:16,000 [analyzer] DEBUG: Loaded monitor into process with pid 5112
2025-06-24 21:32:19,140 [analyzer] INFO: Added new file to list with pid 5112 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-9731.exe
2025-06-24 21:32:19,217 [analyzer] INFO: Injected into process with pid 4012 and name u'Unicorn-9731.exe'
2025-06-24 21:32:19,390 [analyzer] DEBUG: Loaded monitor into process with pid 4012
2025-06-24 21:32:22,562 [analyzer] INFO: Added new file to list with pid 4012 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25596.exe
2025-06-24 21:32:22,640 [analyzer] INFO: Injected into process with pid 4456 and name u'Unicorn-25596.exe'
2025-06-24 21:32:22,812 [analyzer] DEBUG: Loaded monitor into process with pid 4456
2025-06-24 21:32:25,953 [analyzer] INFO: Added new file to list with pid 4456 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26660.exe
2025-06-24 21:32:26,030 [analyzer] INFO: Injected into process with pid 4624 and name u'Unicorn-26660.exe'
2025-06-24 21:32:26,171 [analyzer] DEBUG: Loaded monitor into process with pid 4624
2025-06-24 21:32:29,328 [analyzer] INFO: Added new file to list with pid 4624 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21092.exe
2025-06-24 21:32:29,421 [analyzer] INFO: Injected into process with pid 4832 and name u'Unicorn-21092.exe'
2025-06-24 21:32:29,592 [analyzer] DEBUG: Loaded monitor into process with pid 4832
2025-06-24 21:32:32,796 [analyzer] INFO: Added new file to list with pid 4832 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61844.exe
2025-06-24 21:32:32,858 [analyzer] INFO: Injected into process with pid 3984 and name u'Unicorn-61844.exe'
2025-06-24 21:32:33,015 [analyzer] DEBUG: Loaded monitor into process with pid 3984
2025-06-24 21:32:34,687 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-24 21:32:35,671 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-24 21:32:35,671 [lib.api.process] INFO: Successfully terminated process with pid 2796.
2025-06-24 21:32:35,671 [lib.api.process] INFO: Successfully terminated process with pid 1484.
2025-06-24 21:32:35,671 [lib.api.process] INFO: Successfully terminated process with pid 3040.
2025-06-24 21:32:35,671 [lib.api.process] INFO: Successfully terminated process with pid 1488.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2304.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2368.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2920.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 1564.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3060.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2952.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2332.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2476.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2652.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3120.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3212.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3300.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3380.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3476.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3560.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3640.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3744.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3832.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3916.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 4016.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3076.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3240.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3456.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 3576.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 3656.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 840.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 3728.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 2192.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 1540.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 2316.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 2120.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 2588.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 3104.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 3280.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 3988.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 1300.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 3632.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4120.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4200.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4280.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4360.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4440.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4524.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4604.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4684.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4764.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4848.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4936.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 5020.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 5112.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 4012.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 4456.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 4624.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 4832.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 3984.
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-20247.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34951.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13518.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-65255.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11841.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59631.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24639.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27279.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42311.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62940.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41175.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-9094.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-61799.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46127.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27039.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56900.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-25095.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-63359.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-32103.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26660.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-5801.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27751.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-23535.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43687.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-38431.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46103.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6481.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-25687.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62271.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57372.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-48068.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43063.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-22764.exe
2025-06-24 21:32:35,967 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-02 12:12:59,276 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:00,296 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:03,691 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:04,759 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:05,850 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:06,899 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:07,934 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:08,965 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:09,989 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:11,017 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:12,051 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:13,215 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:14,248 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:15,288 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:16,319 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:17,348 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:18,379 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:19,409 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:20,567 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:21,750 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:22,877 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:23,955 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:25,050 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:26,112 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:27,175 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:28,245 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:29,320 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:30,413 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:31,630 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:32,823 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:33,913 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:34,980 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:36,221 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:37,294 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:38,367 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:39,413 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:40,458 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:41,779 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:42,837 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:44,200 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:45,264 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:46,325 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:47,381 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:48,449 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:49,533 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:50,604 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:51,669 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:52,910 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:54,234 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:55,319 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:56,372 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:57,596 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:58,840 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:59,942 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:01,084 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:02,170 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:03,280 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:04,511 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:05,621 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:06,770 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:07,862 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:09,193 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:10,286 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:11,324 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:12,413 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:13,454 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:14,566 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:15,604 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:16,633 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:17,666 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:18,765 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:19,810 [cuckoo.core.scheduler] INFO: Task #6631140: acquired machine win7x647 (label=win7x647)
2025-07-02 12:14:19,817 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.207 for task #6631140
2025-07-02 12:14:20,219 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2753377 (interface=vboxnet0, host=192.168.168.207)
2025-07-02 12:14:20,941 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x647
2025-07-02 12:14:21,635 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x647 to vmcloak
2025-07-02 12:15:37,409 [cuckoo.core.guest] INFO: Starting analysis #6631140 on guest (id=win7x647, ip=192.168.168.207)
2025-07-02 12:15:38,415 [cuckoo.core.guest] DEBUG: win7x647: not ready yet
2025-07-02 12:15:43,453 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x647, ip=192.168.168.207)
2025-07-02 12:15:43,528 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x647, ip=192.168.168.207, monitor=latest, size=6660546)
2025-07-02 12:15:44,984 [cuckoo.core.resultserver] DEBUG: Task #6631140: live log analysis.log initialized.
2025-07-02 12:15:46,139 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:46,669 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:47,381 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0001.jpg'
2025-07-02 12:15:47,400 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133483
2025-07-02 12:15:50,057 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:52,686 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0002.jpg'
2025-07-02 12:15:52,709 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 136753
2025-07-02 12:15:53,488 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:54,844 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0003.jpg'
2025-07-02 12:15:54,861 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 138055
2025-07-02 12:15:55,947 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0004.jpg'
2025-07-02 12:15:55,982 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 127189
2025-07-02 12:15:56,751 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:58,271 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0005.jpg'
2025-07-02 12:15:58,291 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 127254
2025-07-02 12:15:59,973 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:16:00,804 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:03,830 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:05,581 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0006.jpg'
2025-07-02 12:16:05,601 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 128810
2025-07-02 12:16:08,594 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:08,744 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0007.jpg'
2025-07-02 12:16:08,772 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 129882
2025-07-02 12:16:10,779 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:14,143 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:14,979 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0008.jpg'
2025-07-02 12:16:15,006 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 131149
2025-07-02 12:16:15,152 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:16:17,572 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:19,154 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0009.jpg'
2025-07-02 12:16:19,169 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 131644
2025-07-02 12:16:20,261 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0010.jpg'
2025-07-02 12:16:20,282 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 132821
2025-07-02 12:16:20,984 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:22,807 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0011.jpg'
2025-07-02 12:16:22,851 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 132447
2025-07-02 12:16:24,363 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:25,975 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0012.jpg'
2025-07-02 12:16:25,991 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 132954
2025-07-02 12:16:27,909 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:29,159 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0013.jpg'
2025-07-02 12:16:29,186 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133111
2025-07-02 12:16:30,380 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:16:31,280 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:34,693 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:38,104 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:41,465 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:44,876 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:45,498 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:16:48,222 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:51,648 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:55,105 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:58,519 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:00,650 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:17:02,088 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:05,562 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:08,935 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:12,365 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:15,927 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:17:15,948 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:19,150 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:22,612 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:25,983 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:29,412 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:31,086 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:17:32,654 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:36,188 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:39,667 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:42,969 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:46,337 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:46,661 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:17:49,752 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:53,076 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:56,413 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:59,921 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:01,875 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:18:03,122 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:06,498 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:09,810 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:13,154 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:16,635 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:17,252 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:18:19,810 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:23,393 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:26,560 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:29,920 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:32,366 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:18:33,457 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:36,701 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:40,122 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:43,544 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:45,540 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0014.jpg'
2025-07-02 12:18:45,555 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133554
2025-07-02 12:18:46,935 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:47,666 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0015.jpg'
2025-07-02 12:18:47,686 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:18:47,686 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 132852
2025-07-02 12:18:48,780 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0016.jpg'
2025-07-02 12:18:48,793 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133806
2025-07-02 12:18:50,311 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:50,922 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0017.jpg'
2025-07-02 12:18:50,937 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133662
2025-07-02 12:18:52,025 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0018.jpg'
2025-07-02 12:18:52,038 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 124644
2025-07-02 12:18:53,732 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:54,214 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0019.jpg'
2025-07-02 12:18:54,226 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 124847
2025-07-02 12:18:55,335 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0020.jpg'
2025-07-02 12:18:55,361 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 124040
2025-07-02 12:18:56,440 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0021.jpg'
2025-07-02 12:18:56,464 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 125351
2025-07-02 12:18:57,107 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:57,576 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0022.jpg'
2025-07-02 12:18:57,583 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 92327
2025-07-02 12:18:58,832 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0023.jpg'
2025-07-02 12:18:58,870 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 124469
2025-07-02 12:18:59,942 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0024.jpg'
2025-07-02 12:18:59,953 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 125992
2025-07-02 12:19:00,513 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:19:01,149 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0025.jpg'
2025-07-02 12:19:01,180 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 125762
2025-07-02 12:19:02,764 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:19:03,301 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0026.jpg'
2025-07-02 12:19:03,317 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 126640
2025-07-02 12:19:03,935 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:19:04,536 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0027.jpg'
2025-07-02 12:19:04,549 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 126800
2025-07-02 12:19:05,840 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'curtain/1750793554.83.curtain.log'
2025-07-02 12:19:05,843 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 36
2025-07-02 12:19:06,527 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'sysmon/1750793555.52.sysmon.xml'
2025-07-02 12:19:06,672 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0028.jpg'
2025-07-02 12:19:06,677 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 9354364
2025-07-02 12:19:06,719 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 127232
2025-07-02 12:19:06,739 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/3fb579a3150b0fb1_unicorn-646.exe'
2025-07-02 12:19:06,744 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479245
2025-07-02 12:19:06,749 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/41592e0c9b023724_unicorn-27623.exe'
2025-07-02 12:19:06,754 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479276
2025-07-02 12:19:06,759 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/8d388a3adb265e5a_unicorn-39711.exe'
2025-07-02 12:19:06,764 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479254
2025-07-02 12:19:06,768 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/fca5068e03e4a636_unicorn-9731.exe'
2025-07-02 12:19:06,772 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479291
2025-07-02 12:19:06,777 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/a244b4420809d82a_unicorn-12766.exe'
2025-07-02 12:19:06,782 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479266
2025-07-02 12:19:06,786 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/76d3386ec8564ce7_unicorn-145.exe'
2025-07-02 12:19:06,790 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479242
2025-07-02 12:19:06,795 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/a5a8ed9ae857c8b6_unicorn-8763.exe'
2025-07-02 12:19:06,800 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479288
2025-07-02 12:19:06,803 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/6e11cc09d250ff41_unicorn-859.exe'
2025-07-02 12:19:06,809 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479283
2025-07-02 12:19:06,814 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/a86168d486a97f14_unicorn-46692.exe'
2025-07-02 12:19:06,820 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479284
2025-07-02 12:19:06,823 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/ba07bca256966a1c_unicorn-27239.exe'
2025-07-02 12:19:06,828 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479278
2025-07-02 12:19:06,832 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/22d4191a6bb228ef_unicorn-31631.exe'
2025-07-02 12:19:06,838 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/2fd4fee88ee1b74e_unicorn-55908.exe'
2025-07-02 12:19:06,841 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479253
2025-07-02 12:19:06,849 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/3f76be1ba467f6c7_unicorn-33479.exe'
2025-07-02 12:19:06,852 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479281
2025-07-02 12:19:06,856 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479258
2025-07-02 12:19:06,862 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/df7cfb7f129b11c7_unicorn-27639.exe'
2025-07-02 12:19:07,036 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479280
2025-07-02 12:19:07,139 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/eaac0a84dfb9bd67_unicorn-27700.exe'
2025-07-02 12:19:07,146 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/6e78164cf2b6fdc3_unicorn-52599.exe'
2025-07-02 12:19:07,149 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/80e66f551336849a_unicorn-25596.exe'
2025-07-02 12:19:07,152 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/91d004345507f5a3_unicorn-1270.exe'
2025-07-02 12:19:07,155 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/d8c0d18bbfab302a_unicorn-55090.exe'
2025-07-02 12:19:08,790 [cuckoo.core.guest] INFO: win7x647: analysis completed successfully
2025-07-02 12:19:08,801 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-02 12:19:08,823 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-02 12:19:09,073 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479239
2025-07-02 12:19:09,076 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/aede924038d73542_unicorn-45719.exe'
2025-07-02 12:19:09,117 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479265
2025-07-02 12:19:09,120 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/f4bdcf6f7a87879e_unicorn-63431.exe'
2025-07-02 12:19:09,122 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/df9dac50c3004bdc_unicorn-21092.exe'
2025-07-02 12:19:09,125 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/59110235b40a937c_unicorn-61844.exe'
2025-07-02 12:19:09,127 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/ad9957567e061ca5_unicorn-48911.exe'
2025-07-02 12:19:09,130 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/68019cd3410e6de1_unicorn-2934.exe'
2025-07-02 12:19:09,179 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479260
2025-07-02 12:19:09,200 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479295
2025-07-02 12:19:09,203 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479271
2025-07-02 12:19:09,210 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479268
2025-07-02 12:19:09,213 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479294
2025-07-02 12:19:09,244 [cuckoo.core.resultserver] DEBUG: Task #6631140 had connection reset for <Context for LOG>
2025-07-02 12:19:09,362 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479273
2025-07-02 12:19:09,364 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479292
2025-07-02 12:19:09,366 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479275
2025-07-02 12:19:09,368 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479289
2025-07-02 12:19:10,003 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x647 to path /srv/cuckoo/cwd/storage/analyses/6631140/memory.dmp
2025-07-02 12:19:10,004 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x647
2025-07-02 12:21:45,231 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.207 for task #6631140
2025-07-02 12:21:46,281 [cuckoo.core.scheduler] DEBUG: Released database task #6631140
2025-07-02 12:21:46,300 [cuckoo.core.scheduler] INFO: Task #6631140: analysis procedure completed