Analyzer Log
2025-06-24 21:30:41,030 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht
2025-06-24 21:30:41,078 [analyzer] DEBUG: Pipe server name: \??\PIPE\uMkvkLlFlXrTUCGBeEdNyzZKWZS
2025-06-24 21:30:41,078 [analyzer] DEBUG: Log pipe server name: \??\PIPE\vOWtHiqYtILFqdOLVa
2025-06-24 21:30:41,078 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-24 21:30:41,078 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-24 21:30:41,546 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-24 21:30:41,546 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-24 21:30:42,437 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-24 21:30:42,687 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-06-24 21:30:42,687 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-24 21:30:42,687 [analyzer] DEBUG: Started auxiliary module Human
2025-06-24 21:30:42,687 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-24 21:30:42,687 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-24 21:30:42,750 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-24 21:30:42,750 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-24 21:30:42,765 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-24 21:30:42,765 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-24 21:30:43,015 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\5e1b71ed75943732_quake3 patch.exe' with arguments '' and pid 2892
2025-06-24 21:30:43,421 [analyzer] DEBUG: Loaded monitor into process with pid 2892
2025-06-24 21:30:43,453 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Windows\win32dc\Doom 3 nocd.exe
2025-06-24 21:30:43,562 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Windows\win32dc\UT2004 + serial.exe
2025-06-24 21:30:43,625 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Windows\win32dc\Silent Hill 4(nocd).exe
2025-06-24 21:30:43,687 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Windows\win32dc\Quake3 nocd.exe
2025-06-24 21:30:43,687 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Windows\win32dc\FlatOut + crack.exe
2025-06-24 21:30:43,703 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Windows\win32dc\UT2004_patch.exe
2025-06-24 21:34:02,030 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-24 21:34:03,187 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-24 21:34:03,187 [lib.api.process] INFO: Successfully terminated process with pid 2892.
2025-06-24 21:34:03,250 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-02 12:14:48,489 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:49,506 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:50,540 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:51,583 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:52,611 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:53,636 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:54,658 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:55,755 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:57,271 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:58,387 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:14:59,475 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:15:00,544 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:15:01,804 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:15:02,880 [cuckoo.core.scheduler] DEBUG: Task #6631152: no machine available yet
2025-07-02 12:15:04,342 [cuckoo.core.scheduler] INFO: Task #6631152: acquired machine win7x641 (label=win7x641)
2025-07-02 12:15:04,347 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #6631152
2025-07-02 12:15:04,919 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2754217 (interface=vboxnet0, host=192.168.168.201)
2025-07-02 12:15:05,888 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641
2025-07-02 12:15:13,518 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak
2025-07-02 12:16:54,862 [cuckoo.core.guest] INFO: Starting analysis #6631152 on guest (id=win7x641, ip=192.168.168.201)
2025-07-02 12:16:55,867 [cuckoo.core.guest] DEBUG: win7x641: not ready yet
2025-07-02 12:17:00,962 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201)
2025-07-02 12:17:01,042 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546)
2025-07-02 12:17:02,693 [cuckoo.core.resultserver] DEBUG: Task #6631152: live log analysis.log initialized.
2025-07-02 12:17:04,337 [cuckoo.core.resultserver] DEBUG: Task #6631152 is sending a BSON stream
2025-07-02 12:17:05,042 [cuckoo.core.resultserver] DEBUG: Task #6631152 is sending a BSON stream
2025-07-02 12:17:05,624 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'shots/0001.jpg'
2025-07-02 12:17:05,645 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 133471
2025-07-02 12:17:17,514 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:17:32,824 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:17:48,078 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:18:03,753 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:18:18,959 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:18:34,195 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:18:49,291 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:19:04,786 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:19:20,106 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:19:35,253 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:19:50,616 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:20:06,294 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:20:21,614 [cuckoo.core.guest] DEBUG: win7x641: analysis #6631152 still processing
2025-07-02 12:20:24,016 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'curtain/1750793642.25.curtain.log'
2025-07-02 12:20:24,019 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 36
2025-07-02 12:20:24,867 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'sysmon/1750793643.11.sysmon.xml'
2025-07-02 12:20:24,950 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 10405318
2025-07-02 12:20:24,970 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'files/73dc8d15284ea85b_flatout + crack.exe'
2025-07-02 12:20:24,974 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 204904
2025-07-02 12:20:24,976 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'files/4bf5cfdc99618811_silent hill 4(nocd).exe'
2025-07-02 12:20:24,980 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 207976
2025-07-02 12:20:24,983 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'files/1039c7ebf62139d2_ut2004_patch.exe'
2025-07-02 12:20:24,988 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 207976
2025-07-02 12:20:24,990 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'files/c8d60463aba446ff_doom 3 nocd.exe'
2025-07-02 12:20:24,996 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 207976
2025-07-02 12:20:24,998 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'files/f1931a2601dd9bca_quake3 nocd.exe'
2025-07-02 12:20:25,002 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 204904
2025-07-02 12:20:25,005 [cuckoo.core.resultserver] DEBUG: Task #6631152: File upload for 'files/43bdba5423bee625_ut2004 + serial.exe'
2025-07-02 12:20:25,011 [cuckoo.core.resultserver] DEBUG: Task #6631152 uploaded file length: 205928
2025-07-02 12:20:25,031 [cuckoo.core.resultserver] DEBUG: Task #6631152 had connection reset for <Context for LOG>
2025-07-02 12:20:27,692 [cuckoo.core.guest] INFO: win7x641: analysis completed successfully
2025-07-02 12:20:27,702 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-02 12:20:27,725 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-02 12:20:28,712 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/6631152/memory.dmp
2025-07-02 12:20:28,714 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641
2025-07-02 12:22:26,548 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #6631152
2025-07-02 12:22:27,128 [cuckoo.core.scheduler] DEBUG: Released database task #6631152
2025-07-02 12:22:27,148 [cuckoo.core.scheduler] INFO: Task #6631152: analysis procedure completed