Analyzer Log
2025-06-24 21:32:24,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpl4240h
2025-06-24 21:32:24,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\iexojrjbwjSCBCbtwjHuquBPENj
2025-06-24 21:32:24,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\BMFROnVxBWJvPHxDGsrJobbRpaOB
2025-06-24 21:32:24,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-24 21:32:24,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-24 21:32:24,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-24 21:32:24,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-24 21:32:24,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-24 21:32:25,046 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-24 21:32:25,062 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-24 21:32:25,062 [analyzer] DEBUG: Started auxiliary module Human
2025-06-24 21:32:25,062 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-24 21:32:25,062 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-24 21:32:25,108 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-24 21:32:25,108 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-24 21:32:25,108 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-24 21:32:25,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-24 21:32:25,233 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\361b705e59617815_i_uomgeywroj.exe' with arguments '' and pid 216
2025-06-24 21:32:25,405 [analyzer] DEBUG: Loaded monitor into process with pid 216
2025-06-24 21:32:25,921 [analyzer] INFO: Added new file to list with pid 216 and path C:\Temp\CreateProcess.exe
2025-06-24 21:32:26,921 [analyzer] INFO: Added new file to list with pid 216 and path C:\Temp\zusmkecwupmhfzxr.exe
2025-06-24 21:32:26,983 [analyzer] INFO: Injected into process with pid 1068 and name u'zusmkecwupmhfzxr.exe'
2025-06-24 21:32:27,078 [analyzer] INFO: Injected into process with pid 1904 and name u'iexplore.exe'
2025-06-24 21:32:27,140 [analyzer] DEBUG: Loaded monitor into process with pid 1068
2025-06-24 21:32:27,171 [analyzer] INFO: Added new file to list with pid 1068 and path \Device\NamedPipe\lsass
2025-06-24 21:32:27,280 [analyzer] DEBUG: Loaded monitor into process with pid 1904
2025-06-24 21:32:29,078 [analyzer] INFO: Added new file to list with pid 216 and path C:\Temp\zusmkecwupmhfzxr.sys
2025-06-24 21:32:29,233 [analyzer] INFO: Process with pid 216 has terminated
2025-06-24 21:32:29,812 [analyzer] INFO: Added new file to list with pid 1068 and path C:\Temp\xvqnigaysq.exe
2025-06-24 21:32:29,858 [analyzer] INFO: Injected into process with pid 820 and name u'CreateProcess.exe'
2025-06-24 21:32:30,000 [analyzer] DEBUG: Loaded monitor into process with pid 820
2025-06-24 21:32:31,233 [analyzer] INFO: Process with pid 820 has terminated
2025-06-24 21:32:32,296 [analyzer] INFO: Added new file to list with pid 1068 and path C:\Temp\i_xvqnigaysq.exe
2025-06-24 21:32:37,671 [analyzer] INFO: Added new file to list with pid 1068 and path C:\Temp\vpnifaxsqk.exe
2025-06-24 21:35:44,250 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-24 21:35:50,140 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-24 21:35:50,140 [lib.api.process] INFO: Successfully terminated process with pid 1068.
2025-06-24 21:35:50,140 [lib.api.process] INFO: Successfully terminated process with pid 1904.
2025-06-24 21:35:50,140 [analyzer] WARNING: File at path u'\\device\\namedpipe\\lsass' does not exist, skip.
2025-06-24 21:35:50,171 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-02 12:16:12,283 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:13,328 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:14,354 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:15,378 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:16,403 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:17,429 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:18,456 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:19,477 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:20,499 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:21,523 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:22,768 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:23,937 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:25,036 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:26,136 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:27,217 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:28,422 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:29,568 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:30,677 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:31,753 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:32,799 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:33,871 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:34,928 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:35,969 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:37,006 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:38,099 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:39,170 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:40,232 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:41,270 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:42,321 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:43,944 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:44,984 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:46,057 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:47,095 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:48,124 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:49,149 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:50,207 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:51,262 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:52,302 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:53,331 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:54,366 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:55,389 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:56,500 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:57,624 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:58,671 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:16:59,872 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:00,967 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:02,077 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:03,123 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:04,204 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:05,456 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:06,661 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:07,766 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:08,917 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:10,000 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:11,093 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:12,200 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:13,679 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:14,730 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:15,977 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:17,030 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:18,084 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:19,148 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:20,208 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:21,436 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:22,513 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:23,615 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:24,661 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:25,709 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:26,830 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:28,056 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:29,110 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:30,730 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:31,761 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:32,820 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:34,098 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:35,160 [cuckoo.core.scheduler] DEBUG: Task #6631161: no machine available yet
2025-07-02 12:17:36,222 [cuckoo.core.scheduler] INFO: Task #6631161: acquired machine win7x649 (label=win7x649)
2025-07-02 12:17:36,224 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.209 for task #6631161
2025-07-02 12:17:36,640 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2757039 (interface=vboxnet0, host=192.168.168.209)
2025-07-02 12:17:37,900 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x649
2025-07-02 12:17:38,656 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x649 to vmcloak
2025-07-02 12:18:59,174 [cuckoo.core.guest] INFO: Starting analysis #6631161 on guest (id=win7x649, ip=192.168.168.209)
2025-07-02 12:19:00,179 [cuckoo.core.guest] DEBUG: win7x649: not ready yet
2025-07-02 12:19:05,202 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x649, ip=192.168.168.209)
2025-07-02 12:19:05,285 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x649, ip=192.168.168.209, monitor=latest, size=6660546)
2025-07-02 12:19:06,489 [cuckoo.core.resultserver] DEBUG: Task #6631161: live log analysis.log initialized.
2025-07-02 12:19:09,259 [cuckoo.core.resultserver] DEBUG: Task #6631161 is sending a BSON stream
2025-07-02 12:19:09,292 [cuckoo.core.resultserver] DEBUG: Task #6631161 is sending a BSON stream
2025-07-02 12:19:09,355 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'shots/0001.jpg'
2025-07-02 12:19:09,375 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 133484
2025-07-02 12:19:09,622 [cuckoo.core.resultserver] DEBUG: Task #6631161 is sending a BSON stream
2025-07-02 12:19:09,763 [cuckoo.core.resultserver] DEBUG: Task #6631161 is sending a BSON stream
2025-07-02 12:19:12,434 [cuckoo.core.resultserver] DEBUG: Task #6631161 is sending a BSON stream
2025-07-02 12:19:12,830 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'files/79bd55a41716675d_xvqnigaysq.exe'
2025-07-02 12:19:12,838 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 369664
2025-07-02 12:19:17,513 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'files/26aaac6694de50b2_i_xvqnigaysq.exe'
2025-07-02 12:19:17,521 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 369664
2025-07-02 12:19:21,210 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:19:36,328 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:19:51,528 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:20:06,869 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:20:22,239 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:20:37,639 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:20:52,789 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:21:07,967 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:21:23,349 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:21:38,829 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:21:54,174 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:22:09,290 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:22:24,470 [cuckoo.core.guest] DEBUG: win7x649: analysis #6631161 still processing
2025-07-02 12:22:27,044 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'curtain/1750793744.5.curtain.log'
2025-07-02 12:22:27,047 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 36
2025-07-02 12:22:32,440 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'sysmon/1750793745.69.sysmon.xml'
2025-07-02 12:22:32,663 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 13123530
2025-07-02 12:22:32,692 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'files/330e3562f2e690da_vpnifaxsqk.exe'
2025-07-02 12:22:32,694 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'files/65f3c47e9d6e350e_zusmkecwupmhfzxr.sys'
2025-07-02 12:22:32,696 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'files/8f2e33ea22315bdf_createprocess.exe'
2025-07-02 12:22:32,698 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 3584
2025-07-02 12:22:32,699 [cuckoo.core.resultserver] DEBUG: Task #6631161: File upload for 'files/7a6268c17ff4be16_zusmkecwupmhfzxr.exe'
2025-07-02 12:22:32,702 [cuckoo.core.resultserver] DEBUG: Task #6631161 had connection reset for <Context for LOG>
2025-07-02 12:22:32,705 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 300544
2025-07-02 12:22:32,708 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 369664
2025-07-02 12:22:32,712 [cuckoo.core.resultserver] DEBUG: Task #6631161 uploaded file length: 369664
2025-07-02 12:22:33,980 [cuckoo.core.guest] INFO: win7x649: analysis completed successfully
2025-07-02 12:22:34,007 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-02 12:22:34,050 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-02 12:22:34,975 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x649 to path /srv/cuckoo/cwd/storage/analyses/6631161/memory.dmp
2025-07-02 12:22:34,976 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x649
2025-07-02 12:23:53,024 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.209 for task #6631161
2025-07-02 12:23:53,428 [cuckoo.core.scheduler] DEBUG: Released database task #6631161
2025-07-02 12:24:03,538 [cuckoo.core.scheduler] INFO: Task #6631161: analysis procedure completed