Analyzer Log
2025-07-16 22:16:27,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpd0os1j
2025-07-16 22:16:27,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\QcGFnhPeGWCyNjtiEpPPgHrNeFXBs
2025-07-16 22:16:27,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\WMuSdPQRShgxowVSVMffI
2025-07-16 22:16:27,358 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-16 22:16:27,358 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-16 22:16:27,905 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-16 22:16:28,108 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-07-16 22:16:28,108 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-16 22:16:28,108 [analyzer] DEBUG: Started auxiliary module Human
2025-07-16 22:16:28,108 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-16 22:16:28,108 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-16 22:16:28,203 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-16 22:16:28,203 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-16 22:16:28,203 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-16 22:16:28,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-16 22:16:28,390 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://cozy-cranachan-8d1152.netlify.app/?sNRJdxHxX1rG4T6xI0hytJwM2h=school124@bou.omskportal.ru'] and pid 2652
2025-07-16 22:16:28,530 [analyzer] DEBUG: Loaded monitor into process with pid 2652
2025-07-16 22:16:29,953 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2652 CREDAT:275457 /prefetch:2!
2025-07-16 22:16:30,015 [analyzer] INFO: Injected into process with pid 2192 and name u'iexplore.exe'
2025-07-16 22:16:30,078 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2192.
2025-07-16 22:16:30,217 [analyzer] INFO: Added new file to list with pid 2652 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{C10146F9-6281-11F0-BF07-40DD39EC8A9F}.dat
2025-07-16 22:16:30,250 [analyzer] DEBUG: Loaded monitor into process with pid 2192
2025-07-16 22:16:30,280 [analyzer] INFO: Added new file to list with pid 2652 and path C:\Users\Administrator\AppData\Local\Temp\~DF8861E4ED8EDD0008.TMP
2025-07-16 22:16:30,530 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-16 22:16:30,546 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-16 22:16:30,546 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-16 22:16:30,546 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-16 22:16:30,546 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-16 22:16:30,546 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-16 22:16:30,546 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-16 22:16:30,546 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-16 22:16:30,562 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-16 22:16:30,562 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-16 22:16:30,562 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-16 22:16:30,562 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-16 22:16:30,562 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-16 22:16:30,562 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-16 22:16:30,905 [analyzer] INFO: Added new file to list with pid 2652 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C10146FB-6281-11F0-BF07-40DD39EC8A9F}.dat
2025-07-16 22:16:30,937 [analyzer] INFO: Added new file to list with pid 2652 and path C:\Users\Administrator\AppData\Local\Temp\~DF13B832F0A2521BD9.TMP
2025-07-16 22:16:36,467 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\3C428B1A3E5F57D887EC4B864FAC5DCC
2025-07-16 22:16:36,467 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3C428B1A3E5F57D887EC4B864FAC5DCC
2025-07-16 22:16:36,483 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6B87.tmp
2025-07-16 22:16:36,500 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6B88.tmp
2025-07-16 22:16:36,500 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6B98.tmp
2025-07-16 22:16:36,515 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6B99.tmp
2025-07-16 22:16:36,655 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-07-16 22:16:36,655 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-07-16 22:16:36,671 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6C37.tmp
2025-07-16 22:16:36,671 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6C38.tmp
2025-07-16 22:16:36,687 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6C48.tmp
2025-07-16 22:16:36,687 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6C59.tmp
2025-07-16 22:16:36,717 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6C79.tmp
2025-07-16 22:16:36,733 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6C7A.tmp
2025-07-16 22:16:36,733 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6C8B.tmp
2025-07-16 22:16:36,750 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6C8C.tmp
2025-07-16 22:16:36,812 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6CDB.tmp
2025-07-16 22:16:36,812 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6CDD.tmp
2025-07-16 22:16:36,828 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6CDC.tmp
2025-07-16 22:16:36,828 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6CDE.tmp
2025-07-16 22:16:36,858 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6D0E.tmp
2025-07-16 22:16:36,875 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6D10.tmp
2025-07-16 22:16:36,890 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6D0F.tmp
2025-07-16 22:16:36,890 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6D20.tmp
2025-07-16 22:16:36,967 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6D7F.tmp
2025-07-16 22:16:36,983 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6D80.tmp
2025-07-16 22:16:36,983 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6D91.tmp
2025-07-16 22:16:37,000 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6D92.tmp
2025-07-16 22:16:37,030 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6DB2.tmp
2025-07-16 22:16:37,030 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6DB3.tmp
2025-07-16 22:16:37,046 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6DC4.tmp
2025-07-16 22:16:37,046 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6DC5.tmp
2025-07-16 22:16:37,108 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6E14.tmp
2025-07-16 22:16:37,125 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6E25.tmp
2025-07-16 22:16:37,125 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6E15.tmp
2025-07-16 22:16:37,125 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6E26.tmp
2025-07-16 22:16:37,171 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6E56.tmp
2025-07-16 22:16:37,171 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6E58.tmp
2025-07-16 22:16:37,187 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6E57.tmp
2025-07-16 22:16:37,187 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6E59.tmp
2025-07-16 22:16:37,296 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6ED7.tmp
2025-07-16 22:16:37,296 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6ED8.tmp
2025-07-16 22:16:37,312 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6EE9.tmp
2025-07-16 22:16:37,328 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6EEA.tmp
2025-07-16 22:16:37,342 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6F0A.tmp
2025-07-16 22:16:37,358 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6F0B.tmp
2025-07-16 22:16:37,358 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6F1C.tmp
2025-07-16 22:16:37,375 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6F1D.tmp
2025-07-16 22:16:37,421 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6F5C.tmp
2025-07-16 22:16:37,437 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6F5D.tmp
2025-07-16 22:16:37,453 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6F6E.tmp
2025-07-16 22:16:37,453 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6F6F.tmp
2025-07-16 22:16:37,500 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6FAE.tmp
2025-07-16 22:16:37,515 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab6FB0.tmp
2025-07-16 22:16:37,515 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6FAF.tmp
2025-07-16 22:16:37,515 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar6FB1.tmp
2025-07-16 22:16:37,592 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab7001.tmp
2025-07-16 22:16:37,592 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab7012.tmp
2025-07-16 22:16:37,592 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar7002.tmp
2025-07-16 22:16:37,592 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar7013.tmp
2025-07-16 22:16:37,640 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab7043.tmp
2025-07-16 22:16:37,640 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab7045.tmp
2025-07-16 22:16:37,655 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar7046.tmp
2025-07-16 22:16:37,655 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar7044.tmp
2025-07-16 22:16:37,733 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab70A5.tmp
2025-07-16 22:16:37,750 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar70A6.tmp
2025-07-16 22:16:37,750 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab70B6.tmp
2025-07-16 22:16:37,765 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar70B7.tmp
2025-07-16 22:16:37,780 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab70D8.tmp
2025-07-16 22:16:37,780 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar70D9.tmp
2025-07-16 22:16:37,796 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab70E9.tmp
2025-07-16 22:16:37,812 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar70EA.tmp
2025-07-16 22:16:37,858 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab712A.tmp
2025-07-16 22:16:37,875 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar712B.tmp
2025-07-16 22:16:37,905 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab714B.tmp
2025-07-16 22:16:37,921 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar715C.tmp
2025-07-16 22:16:38,015 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab71CA.tmp
2025-07-16 22:16:38,030 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar71CB.tmp
2025-07-16 22:16:38,092 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab721A.tmp
2025-07-16 22:16:38,108 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar721B.tmp
2025-07-16 22:16:38,140 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab724B.tmp
2025-07-16 22:16:38,155 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar724C.tmp
2025-07-16 22:16:38,217 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab729B.tmp
2025-07-16 22:16:38,233 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar729C.tmp
2025-07-16 22:16:38,265 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab72CC.tmp
2025-07-16 22:16:38,280 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar72CD.tmp
2025-07-16 22:16:38,342 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab730D.tmp
2025-07-16 22:16:38,342 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar731D.tmp
2025-07-16 22:16:38,405 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab734D.tmp
2025-07-16 22:16:38,405 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar735E.tmp
2025-07-16 22:16:38,483 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab73AD.tmp
2025-07-16 22:16:38,500 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar73AE.tmp
2025-07-16 22:16:38,530 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab73DE.tmp
2025-07-16 22:16:38,562 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar73DF.tmp
2025-07-16 22:16:38,655 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab744D.tmp
2025-07-16 22:16:38,671 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar744E.tmp
2025-07-16 22:16:38,703 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab748E.tmp
2025-07-16 22:16:38,717 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar748F.tmp
2025-07-16 22:16:38,780 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab74DE.tmp
2025-07-16 22:16:38,796 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar74DF.tmp
2025-07-16 22:16:38,842 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-16 22:16:38,842 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-16 22:16:38,842 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-16 22:16:38,842 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-16 22:16:38,842 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-16 22:16:38,842 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-16 22:16:38,858 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-16 22:16:38,858 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q0RFWJU9\invalidcert[1]
2025-07-16 22:16:38,921 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\12L6LJXC\ErrorPageTemplate[1]
2025-07-16 22:16:38,937 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MT360LSE\errorPageStrings[1]
2025-07-16 22:16:39,000 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q0RFWJU9\httpErrorPagesScripts[1]
2025-07-16 22:16:39,015 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\12L6LJXC\invalidcert[1]
2025-07-16 22:16:39,015 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AK24VCBO\red_shield_48[1]
2025-07-16 22:16:39,030 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MT360LSE\green_shield[1]
2025-07-16 22:16:39,046 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q0RFWJU9\red_shield[1]
2025-07-16 22:16:39,046 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\12L6LJXC\down[1]
2025-07-16 22:16:39,125 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AK24VCBO\background_gradient_red[1]
2025-07-16 21:22:32,584 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-16 21:22:32,818 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2652.
2025-07-16 21:22:32,881 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2192.
2025-07-16 21:22:33,193 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-16 21:22:33,193 [lib.api.process] INFO: Successfully terminated process with pid 2652.
2025-07-16 21:22:33,193 [lib.api.process] INFO: Successfully terminated process with pid 2192.
2025-07-16 21:22:33,193 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab73de.tmp' does not exist, skip.
2025-07-16 21:22:33,193 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar7002.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6fae.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar712b.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6e26.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6f6e.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab70d8.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6f1c.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6e15.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6e14.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab73ad.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6cdd.tmp' does not exist, skip.
2025-07-16 21:22:33,209 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6f0a.tmp' does not exist, skip.
2025-07-16 21:22:33,224 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6fb1.tmp' does not exist, skip.
2025-07-16 21:22:33,224 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6c48.tmp' does not exist, skip.
2025-07-16 21:22:33,224 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6c79.tmp' does not exist, skip.
2025-07-16 21:22:33,224 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6db2.tmp' does not exist, skip.
2025-07-16 21:22:33,224 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6dc4.tmp' does not exist, skip.
2025-07-16 21:22:33,224 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6f5d.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6faf.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab744d.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab7043.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar735e.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6c59.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6f0b.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6dc5.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6c7a.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6d92.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6ee9.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6c37.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar721b.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6c38.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar729c.tmp' does not exist, skip.
2025-07-16 21:22:33,240 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar7046.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6cde.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar73ae.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar70d9.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab721a.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6fb0.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab712a.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab70b6.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6b87.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6d80.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6c8c.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6ed8.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar70b7.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6e59.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab730d.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6d10.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar748f.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar71cb.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab729b.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab74de.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6cdb.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar7044.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6c8b.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6d7f.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab7045.tmp' does not exist, skip.
2025-07-16 21:22:33,256 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6b88.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6f5c.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab724b.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab70a5.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar70ea.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar724c.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6b99.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6db3.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6d0f.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6e58.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6e57.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar70a6.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6eea.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar715c.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6cdc.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df13b832f0a2521bd9.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6ed7.tmp' does not exist, skip.
2025-07-16 21:22:33,270 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6f6f.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6e56.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6d20.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6b98.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6e25.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab734d.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df8861e4ed8edd0008.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab7001.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar731d.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab714b.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6f1d.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar73df.tmp' does not exist, skip.
2025-07-16 21:22:33,286 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar74df.tmp' does not exist, skip.
2025-07-16 21:22:33,302 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab71ca.tmp' does not exist, skip.
2025-07-16 21:22:33,302 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar7013.tmp' does not exist, skip.
2025-07-16 21:22:33,302 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab70e9.tmp' does not exist, skip.
2025-07-16 21:22:33,302 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6d91.tmp' does not exist, skip.
2025-07-16 21:22:33,302 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab748e.tmp' does not exist, skip.
2025-07-16 21:22:33,302 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar744e.tmp' does not exist, skip.
2025-07-16 21:22:33,302 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab7012.tmp' does not exist, skip.
2025-07-16 21:22:33,318 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar72cd.tmp' does not exist, skip.
2025-07-16 21:22:33,318 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab72cc.tmp' does not exist, skip.
2025-07-16 21:22:33,318 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6d0e.tmp' does not exist, skip.
2025-07-16 21:22:33,318 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-16 22:17:07,252 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:08,277 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:09,301 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:10,321 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:11,342 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:12,363 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:13,388 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:14,439 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:15,507 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:16,526 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:17,545 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:18,566 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:19,692 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:20,715 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:21,735 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:22,754 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:23,779 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:24,802 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:25,821 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:26,850 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:27,909 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:28,970 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:30,025 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:31,091 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:32,135 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:33,228 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:34,317 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:35,451 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:36,512 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:37,570 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:38,620 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:39,681 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:40,737 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:41,806 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:42,906 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:44,007 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:45,049 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:46,092 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:47,139 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:48,190 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:49,240 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:50,467 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:51,540 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:52,589 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:53,615 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:54,638 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:55,661 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:56,688 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:57,743 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:58,799 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:17:59,978 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:01,019 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:02,061 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:03,095 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:04,122 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:05,165 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:06,202 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:07,284 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:08,332 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:09,364 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:10,422 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:11,517 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:12,572 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:13,608 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:14,861 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:15,902 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:16,941 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:17,986 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:19,028 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:20,056 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:21,096 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:22,133 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:23,167 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:24,206 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:25,239 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:26,286 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:27,320 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:28,356 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:29,415 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:30,448 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:31,480 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:32,536 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:33,662 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:34,716 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:35,810 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:36,849 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:37,887 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:39,042 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:40,111 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:41,553 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:42,588 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:43,627 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:44,729 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:45,757 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:46,777 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:47,796 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:48,817 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:49,838 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:50,861 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:51,886 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:52,921 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:53,942 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:54,968 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:55,984 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:57,001 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:58,021 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:18:59,043 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:00,071 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:01,091 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:02,113 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:03,130 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:04,157 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:05,179 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:06,235 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:07,408 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:08,539 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:09,768 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:10,815 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:11,893 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:12,915 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:14,073 [cuckoo.core.scheduler] DEBUG: Task #6736640: no machine available yet
2025-07-16 22:19:15,224 [cuckoo.core.scheduler] INFO: Task #6736640: acquired machine win7x6429 (label=win7x6429)
2025-07-16 22:19:15,226 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.229 for task #6736640
2025-07-16 22:19:15,562 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3015814 (interface=vboxnet0, host=192.168.168.229)
2025-07-16 22:19:15,597 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6429
2025-07-16 22:19:16,579 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6429 to vmcloak
2025-07-16 22:21:54,105 [cuckoo.core.guest] INFO: Starting analysis #6736640 on guest (id=win7x6429, ip=192.168.168.229)
2025-07-16 22:21:55,110 [cuckoo.core.guest] DEBUG: win7x6429: not ready yet
2025-07-16 22:22:00,163 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6429, ip=192.168.168.229)
2025-07-16 22:22:00,570 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6429, ip=192.168.168.229, monitor=latest, size=6660546)
2025-07-16 22:22:02,191 [cuckoo.core.resultserver] DEBUG: Task #6736640: live log analysis.log initialized.
2025-07-16 22:22:03,328 [cuckoo.core.resultserver] DEBUG: Task #6736640 is sending a BSON stream
2025-07-16 22:22:03,667 [cuckoo.core.resultserver] DEBUG: Task #6736640 is sending a BSON stream
2025-07-16 22:22:04,641 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'shots/0001.jpg'
2025-07-16 22:22:04,711 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 133409
2025-07-16 22:22:05,385 [cuckoo.core.resultserver] DEBUG: Task #6736640 is sending a BSON stream
2025-07-16 22:22:06,823 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'shots/0002.jpg'
2025-07-16 22:22:06,826 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 24519
2025-07-16 22:22:07,899 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'shots/0003.jpg'
2025-07-16 22:22:07,912 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 31356
2025-07-16 22:22:09,011 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'shots/0004.jpg'
2025-07-16 22:22:09,014 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 31331
2025-07-16 22:22:14,205 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'shots/0005.jpg'
2025-07-16 22:22:14,208 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 31363
2025-07-16 22:22:15,280 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'shots/0006.jpg'
2025-07-16 22:22:15,291 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 54717
2025-07-16 22:22:16,894 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6736640 still processing
2025-07-16 22:22:31,983 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6736640 still processing
2025-07-16 22:22:33,019 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'curtain/1752693753.01.curtain.log'
2025-07-16 22:22:33,021 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 36
2025-07-16 22:22:33,182 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'sysmon/1752693753.18.sysmon.xml'
2025-07-16 22:22:33,196 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 1430194
2025-07-16 22:22:33,203 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/5e2cd0990d6d3b0b_red_shield_48[1]'
2025-07-16 22:22:33,206 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 4127
2025-07-16 22:22:33,223 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/4c847e0c28733ed3_94308059b57b3142e455b38a6eb92015'
2025-07-16 22:22:33,230 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 73513
2025-07-16 22:22:33,235 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/59e53005e12d5c20_invalidcert[1]'
2025-07-16 22:22:33,237 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 5038
2025-07-16 22:22:33,242 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/1ba122f4b39a3333_green_shield[1]'
2025-07-16 22:22:33,244 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 810
2025-07-16 22:22:33,254 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/fa1261ad90a3f7b3_recoverystore.{c10146f9-6281-11f0-bf07-40dd39ec8a9f}.dat'
2025-07-16 22:22:33,256 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 5632
2025-07-16 22:22:33,269 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/a6d464183dfd8008_{c10146fb-6281-11f0-bf07-40dd39ec8a9f}.dat'
2025-07-16 22:22:33,271 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 3584
2025-07-16 22:22:33,279 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/39e7de847c9f731e_down[1]'
2025-07-16 22:22:33,281 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 748
2025-07-16 22:22:33,284 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/9466d620dc57835a_errorpagestrings[1]'
2025-07-16 22:22:33,286 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 2949
2025-07-16 22:22:33,289 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/e437c41302f69c89_94308059b57b3142e455b38a6eb92015'
2025-07-16 22:22:33,291 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 344
2025-07-16 22:22:33,293 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/46e019fa34465f4e_httperrorpagesscripts[1]'
2025-07-16 22:22:33,294 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 8714
2025-07-16 22:22:33,296 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/fbc23311fb5eb53c_background_gradient_red[1]'
2025-07-16 22:22:33,298 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 868
2025-07-16 22:22:33,303 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/cb3ccbb76031e5e0_3c428b1a3e5f57d887ec4b864fac5dcc'
2025-07-16 22:22:33,305 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 914
2025-07-16 22:22:33,307 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/bc4213155fa8f4b2_3c428b1a3e5f57d887ec4b864fac5dcc'
2025-07-16 22:22:33,309 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 252
2025-07-16 22:22:33,310 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/8d018639281b33da_errorpagetemplate[1]'
2025-07-16 22:22:33,312 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 2168
2025-07-16 22:22:33,315 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/f18e9671426708c6_invalidcert[1]'
2025-07-16 22:22:33,317 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 2588
2025-07-16 22:22:33,320 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'files/4bd9f96d6971c7d3_red_shield[1]'
2025-07-16 22:22:33,322 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 810
2025-07-16 22:22:33,688 [cuckoo.core.resultserver] DEBUG: Task #6736640: File upload for 'shots/0007.jpg'
2025-07-16 22:22:33,708 [cuckoo.core.resultserver] DEBUG: Task #6736640 uploaded file length: 133386
2025-07-16 22:22:33,722 [cuckoo.core.resultserver] DEBUG: Task #6736640 had connection reset for <Context for LOG>
2025-07-16 22:22:35,013 [cuckoo.core.guest] INFO: win7x6429: analysis completed successfully
2025-07-16 22:22:35,038 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-16 22:22:35,063 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-16 22:22:36,129 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6429 to path /srv/cuckoo/cwd/storage/analyses/6736640/memory.dmp
2025-07-16 22:22:36,132 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6429
2025-07-16 22:24:52,643 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.229 for task #6736640
2025-07-16 22:24:53,233 [cuckoo.core.scheduler] DEBUG: Released database task #6736640
2025-07-16 22:24:53,278 [cuckoo.core.scheduler] INFO: Task #6736640: analysis procedure completed