Analyzer Log
2025-06-30 17:46:39,030 [analyzer] DEBUG: Starting analyzer from: C:\tmp4nivwu
2025-06-30 17:46:39,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\JpmJZgPDPoDRfyAPaQKq
2025-06-30 17:46:39,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\uZDEsjXHjjNeFkMDpUtbpCjKpdkCnzb
2025-06-30 17:46:39,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-30 17:46:39,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-30 17:46:39,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-30 17:46:39,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-30 17:46:39,812 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-30 17:46:40,062 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-30 17:46:40,062 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-30 17:46:40,062 [analyzer] DEBUG: Started auxiliary module Human
2025-06-30 17:46:40,062 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-30 17:46:40,062 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-30 17:46:40,140 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-30 17:46:40,140 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-30 17:46:40,140 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-30 17:46:40,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-30 17:46:40,265 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2e6c171ac87d6ba5_windows.exe' with arguments '' and pid 2920
2025-06-30 17:46:40,453 [analyzer] DEBUG: Loaded monitor into process with pid 2920
2025-06-30 17:46:40,500 [analyzer] INFO: Added new file to list with pid 2920 and path C:\Windows\windows.exe
2025-06-30 17:46:40,500 [analyzer] INFO: Added new file to list with pid 2920 and path C:\system.exe
2025-06-30 17:46:40,578 [analyzer] INFO: Injected into process with pid 2008 and name u'iexplore.exe'
2025-06-30 17:46:40,796 [analyzer] DEBUG: Loaded monitor into process with pid 2008
2025-06-30 17:49:59,265 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-30 17:50:00,500 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-30 17:50:00,500 [lib.api.process] INFO: Successfully terminated process with pid 2920.
2025-06-30 17:50:00,500 [lib.api.process] INFO: Successfully terminated process with pid 2008.
2025-06-30 17:50:00,515 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-05 10:29:35,453 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:36,474 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:37,503 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:38,527 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:39,685 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:40,709 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:41,737 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:42,760 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:43,781 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:44,810 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:45,842 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:46,926 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:48,096 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:49,148 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:50,174 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:51,418 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:52,453 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:53,477 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:54,496 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:55,516 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:56,536 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:57,558 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:58,583 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:29:59,609 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:00,799 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:01,851 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:02,885 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:03,925 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:04,964 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:06,004 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:07,043 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:08,083 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:09,110 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:10,234 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:11,256 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:12,275 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:13,299 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:14,326 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:15,356 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:16,454 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:17,482 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:18,515 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:19,541 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:20,568 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:21,595 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:22,618 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:23,645 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:24,698 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:25,843 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:26,870 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:27,890 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:28,908 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:29,928 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:30,950 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:31,972 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:32,994 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:34,016 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:35,035 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:36,127 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:37,156 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:38,185 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:39,225 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:40,256 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:41,292 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:42,334 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:43,374 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:44,409 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:45,474 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:46,508 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:47,540 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:48,578 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:49,631 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:50,685 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:51,733 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:52,796 [cuckoo.core.scheduler] DEBUG: Task #6650041: no machine available yet
2025-07-05 10:30:53,856 [cuckoo.core.scheduler] INFO: Task #6650041: acquired machine win7x6424 (label=win7x6424)
2025-07-05 10:30:53,856 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.224 for task #6650041
2025-07-05 10:30:54,221 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3361374 (interface=vboxnet0, host=192.168.168.224)
2025-07-05 10:30:54,309 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6424
2025-07-05 10:30:54,970 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6424 to vmcloak
2025-07-05 10:32:06,577 [cuckoo.core.guest] INFO: Starting analysis #6650041 on guest (id=win7x6424, ip=192.168.168.224)
2025-07-05 10:32:07,583 [cuckoo.core.guest] DEBUG: win7x6424: not ready yet
2025-07-05 10:32:12,614 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6424, ip=192.168.168.224)
2025-07-05 10:32:12,721 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6424, ip=192.168.168.224, monitor=latest, size=6660546)
2025-07-05 10:32:13,951 [cuckoo.core.resultserver] DEBUG: Task #6650041: live log analysis.log initialized.
2025-07-05 10:32:15,130 [cuckoo.core.resultserver] DEBUG: Task #6650041 is sending a BSON stream
2025-07-05 10:32:15,344 [cuckoo.core.resultserver] DEBUG: Task #6650041 is sending a BSON stream
2025-07-05 10:32:15,644 [cuckoo.core.resultserver] DEBUG: Task #6650041 is sending a BSON stream
2025-07-05 10:32:16,216 [cuckoo.core.resultserver] DEBUG: Task #6650041: File upload for 'shots/0001.jpg'
2025-07-05 10:32:16,233 [cuckoo.core.resultserver] DEBUG: Task #6650041 uploaded file length: 133475
2025-07-05 10:32:26,508 [cuckoo.core.resultserver] DEBUG: Task #6650041: File upload for 'shots/0002.jpg'
2025-07-05 10:32:26,521 [cuckoo.core.resultserver] DEBUG: Task #6650041 uploaded file length: 138206
2025-07-05 10:32:28,661 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:32:34,727 [cuckoo.core.resultserver] DEBUG: Task #6650041: File upload for 'shots/0003.jpg'
2025-07-05 10:32:34,746 [cuckoo.core.resultserver] DEBUG: Task #6650041 uploaded file length: 138141
2025-07-05 10:32:43,746 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:32:58,862 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:33:14,040 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:33:29,175 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:33:44,361 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:33:59,483 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:34:14,663 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:34:29,991 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:34:45,252 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:35:00,486 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:35:15,858 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:35:31,085 [cuckoo.core.guest] DEBUG: win7x6424: analysis #6650041 still processing
2025-07-05 10:35:34,392 [cuckoo.core.resultserver] DEBUG: Task #6650041: File upload for 'curtain/1751298599.44.curtain.log'
2025-07-05 10:35:34,395 [cuckoo.core.resultserver] DEBUG: Task #6650041 uploaded file length: 36
2025-07-05 10:35:35,319 [cuckoo.core.resultserver] DEBUG: Task #6650041: File upload for 'sysmon/1751298600.34.sysmon.xml'
2025-07-05 10:35:35,465 [cuckoo.core.resultserver] DEBUG: Task #6650041 uploaded file length: 14761258
2025-07-05 10:35:35,491 [cuckoo.core.resultserver] DEBUG: Task #6650041: File upload for 'files/d17fc8d600e2cd9d_system.exe'
2025-07-05 10:35:35,493 [cuckoo.core.resultserver] DEBUG: Task #6650041 uploaded file length: 56948
2025-07-05 10:35:35,494 [cuckoo.core.resultserver] DEBUG: Task #6650041: File upload for 'files/9bf30de5dffc5a06_windows.exe'
2025-07-05 10:35:35,496 [cuckoo.core.resultserver] DEBUG: Task #6650041 uploaded file length: 56948
2025-07-05 10:35:35,501 [cuckoo.core.resultserver] DEBUG: Task #6650041 had connection reset for <Context for LOG>
2025-07-05 10:35:37,178 [cuckoo.core.guest] INFO: win7x6424: analysis completed successfully
2025-07-05 10:35:37,203 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-05 10:35:37,258 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-05 10:35:38,232 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6424 to path /srv/cuckoo/cwd/storage/analyses/6650041/memory.dmp
2025-07-05 10:35:38,249 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6424
2025-07-05 10:37:08,271 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.224 for task #6650041
2025-07-05 10:37:08,983 [cuckoo.core.scheduler] DEBUG: Released database task #6650041
2025-07-05 10:37:09,066 [cuckoo.core.scheduler] INFO: Task #6650041: analysis procedure completed