Analyzer Log
2025-06-30 17:50:29,015 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht
2025-06-30 17:50:29,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\oiIKvNRBLgejSqxAhbLHcKEQHgpGuO
2025-06-30 17:50:29,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\RzwwJpmwQuuaDAUMVzsSaxWy
2025-06-30 17:50:29,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-30 17:50:29,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-30 17:50:29,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-30 17:50:29,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-30 17:50:29,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-30 17:50:29,983 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-06-30 17:50:29,983 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-30 17:50:29,983 [analyzer] DEBUG: Started auxiliary module Human
2025-06-30 17:50:29,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-30 17:50:29,983 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-30 17:50:30,046 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-30 17:50:30,046 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-30 17:50:30,046 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-30 17:50:30,046 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-30 17:50:30,171 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\c60abe071eb0a2ed_ahnsvc.exe' with arguments '' and pid 1876
2025-06-30 17:50:30,342 [analyzer] DEBUG: Loaded monitor into process with pid 1876
2025-06-30 17:50:30,375 [analyzer] INFO: Added new file to list with pid 1876 and path C:\ProgramData\AhnLab\AhnSvc.exe
2025-06-30 17:50:30,437 [analyzer] INFO: Injected into process with pid 3064 and name u'AhnSvc.exe'
2025-06-30 17:50:30,578 [analyzer] DEBUG: Loaded monitor into process with pid 3064
2025-06-30 17:50:30,608 [analyzer] INFO: Added pid 3064 for u'C:\\ProgramData\\AhnLab\\AhnSvc.exe'
2025-06-30 17:50:30,608 [analyzer] INFO: Added new file to list with pid 3064 and path C:\ProgramData\AhnLab\AhnSvc.exe
2025-06-30 17:51:01,187 [analyzer] INFO: Injected into process with pid 316 and name u'cmd.exe'
2025-06-30 17:51:01,421 [analyzer] DEBUG: Loaded monitor into process with pid 316
2025-06-30 17:51:02,171 [analyzer] INFO: Process with pid 1876 has terminated
2025-06-30 17:51:02,171 [analyzer] INFO: Process with pid 316 has terminated
2025-06-30 17:53:49,171 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-30 17:53:50,562 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-30 17:53:50,562 [lib.api.process] INFO: Successfully terminated process with pid 3064.
2025-06-30 17:53:50,578 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-05 10:32:15,753 [cuckoo.core.scheduler] DEBUG: Task #6650062: no machine available yet
2025-07-05 10:32:16,797 [cuckoo.core.scheduler] DEBUG: Task #6650062: no machine available yet
2025-07-05 10:32:17,820 [cuckoo.core.scheduler] DEBUG: Task #6650062: no machine available yet
2025-07-05 10:32:18,844 [cuckoo.core.scheduler] DEBUG: Task #6650062: no machine available yet
2025-07-05 10:32:19,863 [cuckoo.core.scheduler] DEBUG: Task #6650062: no machine available yet
2025-07-05 10:32:20,881 [cuckoo.core.scheduler] DEBUG: Task #6650062: no machine available yet
2025-07-05 10:32:21,904 [cuckoo.core.scheduler] DEBUG: Task #6650062: no machine available yet
2025-07-05 10:32:22,936 [cuckoo.core.scheduler] INFO: Task #6650062: acquired machine win7x641 (label=win7x641)
2025-07-05 10:32:22,936 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #6650062
2025-07-05 10:32:23,321 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3363794 (interface=vboxnet0, host=192.168.168.201)
2025-07-05 10:32:23,413 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641
2025-07-05 10:32:24,083 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak
2025-07-05 10:34:49,278 [cuckoo.core.guest] INFO: Starting analysis #6650062 on guest (id=win7x641, ip=192.168.168.201)
2025-07-05 10:34:50,282 [cuckoo.core.guest] DEBUG: win7x641: not ready yet
2025-07-05 10:34:55,323 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201)
2025-07-05 10:34:55,528 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546)
2025-07-05 10:34:56,804 [cuckoo.core.resultserver] DEBUG: Task #6650062: live log analysis.log initialized.
2025-07-05 10:34:57,661 [cuckoo.core.resultserver] DEBUG: Task #6650062 is sending a BSON stream
2025-07-05 10:34:58,005 [cuckoo.core.resultserver] DEBUG: Task #6650062 is sending a BSON stream
2025-07-05 10:34:58,413 [cuckoo.core.resultserver] DEBUG: Task #6650062 is sending a BSON stream
2025-07-05 10:34:58,967 [cuckoo.core.resultserver] DEBUG: Task #6650062: File upload for 'shots/0001.jpg'
2025-07-05 10:34:58,980 [cuckoo.core.resultserver] DEBUG: Task #6650062 uploaded file length: 133473
2025-07-05 10:35:11,573 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:35:26,684 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:35:29,098 [cuckoo.core.resultserver] DEBUG: Task #6650062 is sending a BSON stream
2025-07-05 10:35:29,179 [cuckoo.core.resultserver] DEBUG: Task #6650062: File upload for 'files/c60abe071eb0a2ed_c60abe071eb0a2ed_ahnsvc.exe'
2025-07-05 10:35:29,186 [cuckoo.core.resultserver] DEBUG: Task #6650062 uploaded file length: 61554
2025-07-05 10:35:41,936 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:35:57,144 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:36:12,311 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:36:27,454 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:36:42,602 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:36:57,957 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:37:13,234 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:37:28,505 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:37:43,665 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:37:58,800 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:38:14,036 [cuckoo.core.guest] DEBUG: win7x641: analysis #6650062 still processing
2025-07-05 10:38:17,117 [cuckoo.core.resultserver] DEBUG: Task #6650062: File upload for 'curtain/1751298829.36.curtain.log'
2025-07-05 10:38:17,135 [cuckoo.core.resultserver] DEBUG: Task #6650062 uploaded file length: 36
2025-07-05 10:38:18,150 [cuckoo.core.resultserver] DEBUG: Task #6650062: File upload for 'sysmon/1751298830.41.sysmon.xml'
2025-07-05 10:38:18,307 [cuckoo.core.resultserver] DEBUG: Task #6650062 uploaded file length: 15247012
2025-07-05 10:38:18,335 [cuckoo.core.resultserver] DEBUG: Task #6650062: File upload for 'files/a32795e46448b062_ahnsvc.exe_'
2025-07-05 10:38:18,338 [cuckoo.core.resultserver] DEBUG: Task #6650062: File upload for 'files/41d1ac567d28d812_ahnsvc.exe'
2025-07-05 10:38:18,340 [cuckoo.core.resultserver] DEBUG: Task #6650062 uploaded file length: 61559
2025-07-05 10:38:18,341 [cuckoo.core.resultserver] DEBUG: Task #6650062 uploaded file length: 61558
2025-07-05 10:38:18,345 [cuckoo.core.resultserver] DEBUG: Task #6650062 had connection reset for <Context for LOG>
2025-07-05 10:38:20,156 [cuckoo.core.guest] INFO: win7x641: analysis completed successfully
2025-07-05 10:38:20,170 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-05 10:38:20,195 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-05 10:38:21,082 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/6650062/memory.dmp
2025-07-05 10:38:21,083 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641
2025-07-05 10:40:08,477 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #6650062
2025-07-05 10:40:08,836 [cuckoo.core.scheduler] DEBUG: Released database task #6650062
2025-07-05 10:40:08,856 [cuckoo.core.scheduler] INFO: Task #6650062: analysis procedure completed