Analyzer Log
2025-07-13 07:14:25,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpqqrt4a
2025-07-13 07:14:25,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\RnyrmiQYwMaPKhBnYEOmNfkpNF
2025-07-13 07:14:25,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\hbDuOuDDCOuxpbcoszgcSuMQXEFbkhLi
2025-07-13 07:14:25,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-13 07:14:25,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-13 07:14:25,467 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-13 07:14:25,467 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-13 07:14:26,078 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-13 07:14:26,280 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-07-13 07:14:26,280 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-13 07:14:26,280 [analyzer] DEBUG: Started auxiliary module Human
2025-07-13 07:14:26,280 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-13 07:14:26,280 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-13 07:14:26,342 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-13 07:14:26,342 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-13 07:14:26,358 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-13 07:14:26,358 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-13 07:14:26,562 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dbab8a968bbd02f4_counter-strike serial.exe' with arguments '' and pid 944
2025-07-13 07:14:26,796 [analyzer] DEBUG: Loaded monitor into process with pid 944
2025-07-13 07:14:26,812 [analyzer] INFO: Added new file to list with pid 944 and path C:\Windows\win32dc\UT2004 hack.exe
2025-07-13 07:14:26,828 [analyzer] INFO: Added new file to list with pid 944 and path C:\Windows\win32dc\FlatOut_codes.exe
2025-07-13 07:14:26,858 [analyzer] INFO: Added new file to list with pid 944 and path C:\Windows\win32dc\Quake3(fix).exe
2025-07-13 07:14:26,875 [analyzer] INFO: Added new file to list with pid 944 and path C:\Windows\win32dc\Doom 3(serial).exe
2025-07-13 07:14:26,875 [analyzer] INFO: Added new file to list with pid 944 and path C:\Windows\win32dc\DAoC(serial).exe
2025-07-13 07:14:26,905 [analyzer] INFO: Added new file to list with pid 944 and path C:\Windows\win32dc\Silent Hill 4 trainer.exe
2025-07-13 07:14:26,937 [analyzer] INFO: Added new file to list with pid 944 and path C:\Windows\win32dc\FlatOut(cheat).exe
2025-07-13 07:14:26,953 [analyzer] INFO: Added new file to list with pid 944 and path C:\Windows\win32dc\Half-Life 2 + cdfix.exe
2025-07-13 07:17:45,562 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-13 07:17:47,280 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-13 07:17:47,280 [lib.api.process] INFO: Successfully terminated process with pid 944.
2025-07-13 07:17:47,328 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-17 09:54:58,464 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:54:59,487 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:00,724 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:01,784 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:02,822 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:03,860 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:04,890 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:05,923 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:06,972 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:08,151 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:09,181 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:10,218 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:11,249 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:12,281 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:13,308 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:14,342 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:15,496 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:16,527 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:17,545 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:18,560 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:19,576 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:20,595 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:21,621 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:22,839 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:23,891 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:24,941 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:26,571 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:28,037 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:29,069 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:30,097 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:31,287 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:32,324 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:33,359 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:34,624 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:35,723 [cuckoo.core.scheduler] DEBUG: Task #6725444: no machine available yet
2025-07-17 09:55:36,802 [cuckoo.core.scheduler] INFO: Task #6725444: acquired machine win7x6428 (label=win7x6428)
2025-07-17 09:55:36,803 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.228 for task #6725444
2025-07-17 09:55:37,356 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 12233 (interface=vboxnet0, host=192.168.168.228)
2025-07-17 09:55:38,043 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6428
2025-07-17 09:55:39,336 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6428 to vmcloak
2025-07-17 09:57:57,708 [cuckoo.core.guest] INFO: Starting analysis #6725444 on guest (id=win7x6428, ip=192.168.168.228)
2025-07-17 09:57:58,713 [cuckoo.core.guest] DEBUG: win7x6428: not ready yet
2025-07-17 09:58:03,732 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6428, ip=192.168.168.228)
2025-07-17 09:58:03,817 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6428, ip=192.168.168.228, monitor=latest, size=6660546)
2025-07-17 09:58:05,229 [cuckoo.core.resultserver] DEBUG: Task #6725444: live log analysis.log initialized.
2025-07-17 09:58:06,463 [cuckoo.core.resultserver] DEBUG: Task #6725444 is sending a BSON stream
2025-07-17 09:58:06,946 [cuckoo.core.resultserver] DEBUG: Task #6725444 is sending a BSON stream
2025-07-17 09:58:07,708 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'shots/0001.jpg'
2025-07-17 09:58:07,720 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 133457
2025-07-17 09:58:20,156 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 09:58:35,267 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 09:58:51,024 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 09:59:06,455 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 09:59:21,789 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 09:59:37,300 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 09:59:52,503 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 10:00:07,592 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 10:00:22,712 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 10:00:38,016 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 10:00:53,206 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 10:01:08,539 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 10:01:24,031 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6725444 still processing
2025-07-17 10:01:26,020 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'curtain/1752383865.77.curtain.log'
2025-07-17 10:01:26,023 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 36
2025-07-17 10:01:27,182 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'sysmon/1752383866.94.sysmon.xml'
2025-07-17 10:01:27,532 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 16038618
2025-07-17 10:01:27,546 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'files/28feb200ae78bc8d_daoc(serial).exe'
2025-07-17 10:01:27,549 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'files/eb4cf9fb6ff41635_doom 3(serial).exe'
2025-07-17 10:01:27,552 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'files/5e8dbe54cfc80d24_half-life 2 + cdfix.exe'
2025-07-17 10:01:27,554 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 212292
2025-07-17 10:01:27,555 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 210244
2025-07-17 10:01:27,558 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'files/13d534a948bf75cd_flatout(cheat).exe'
2025-07-17 10:01:27,560 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 213316
2025-07-17 10:01:27,562 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'files/b3e17dd95b28aeb3_quake3(fix).exe'
2025-07-17 10:01:27,564 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 212292
2025-07-17 10:01:27,567 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 211268
2025-07-17 10:01:27,569 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'files/736606064a270e7e_ut2004 hack.exe'
2025-07-17 10:01:27,572 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 211268
2025-07-17 10:01:27,573 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'files/eee49079475184d4_flatout_codes.exe'
2025-07-17 10:01:27,576 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 211268
2025-07-17 10:01:27,578 [cuckoo.core.resultserver] DEBUG: Task #6725444: File upload for 'files/f1fcea75d7fd92f3_silent hill 4 trainer.exe'
2025-07-17 10:01:27,583 [cuckoo.core.resultserver] DEBUG: Task #6725444 uploaded file length: 213316
2025-07-17 10:01:27,598 [cuckoo.core.resultserver] DEBUG: Task #6725444 had connection reset for <Context for LOG>
2025-07-17 10:01:30,102 [cuckoo.core.guest] INFO: win7x6428: analysis completed successfully
2025-07-17 10:01:30,126 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-17 10:01:30,166 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-17 10:01:31,609 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6428 to path /srv/cuckoo/cwd/storage/analyses/6725444/memory.dmp
2025-07-17 10:01:31,610 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6428
2025-07-17 10:02:57,632 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.228 for task #6725444
2025-07-17 10:02:58,175 [cuckoo.core.scheduler] DEBUG: Released database task #6725444
2025-07-17 10:02:58,236 [cuckoo.core.scheduler] INFO: Task #6725444: analysis procedure completed