Analyzer Log
2025-07-16 22:16:27,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp2zg5xi
2025-07-16 22:16:27,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\joylWkWAikusBUohFcbPDxCPzSQL
2025-07-16 22:16:27,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\epyhCuSnyWqJEsHnfarDK
2025-07-16 22:16:27,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-16 22:16:27,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-16 22:16:27,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-16 22:16:28,000 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-07-16 22:16:28,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-16 22:16:28,000 [analyzer] DEBUG: Started auxiliary module Human
2025-07-16 22:16:28,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-16 22:16:28,000 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-16 22:16:28,125 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-16 22:16:28,125 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-16 22:16:28,125 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-16 22:16:28,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-16 22:16:28,358 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://governmentlevityintroduction.com:443/'] and pid 680
2025-07-16 22:16:28,530 [analyzer] DEBUG: Loaded monitor into process with pid 680
2025-07-16 22:16:30,092 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:680 CREDAT:275457 /prefetch:2!
2025-07-16 22:16:30,203 [analyzer] INFO: Injected into process with pid 1512 and name u'iexplore.exe'
2025-07-16 22:16:30,358 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1512.
2025-07-16 22:16:30,546 [analyzer] INFO: Added new file to list with pid 680 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{C10146F9-6281-11F0-ABA3-F26623DBDEC8}.dat
2025-07-16 22:16:30,562 [analyzer] DEBUG: Loaded monitor into process with pid 1512
2025-07-16 22:16:30,671 [analyzer] INFO: Added new file to list with pid 680 and path C:\Users\Administrator\AppData\Local\Temp\~DFC8C4CEE58BC2974C.TMP
2025-07-16 22:16:31,030 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-16 22:16:31,030 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-16 22:16:31,030 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-16 22:16:31,030 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-16 22:16:31,030 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-16 22:16:31,030 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-16 22:16:31,046 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-16 22:16:31,062 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-16 22:16:31,062 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-16 22:16:31,062 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-16 22:16:31,062 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-16 22:16:31,078 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-16 22:16:31,078 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-16 22:16:31,078 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-16 22:16:31,546 [analyzer] INFO: Added new file to list with pid 680 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C10146FB-6281-11F0-ABA3-F26623DBDEC8}.dat
2025-07-16 22:16:31,562 [analyzer] INFO: Added new file to list with pid 680 and path C:\Users\Administrator\AppData\Local\Temp\~DFFAC0B532650568B8.TMP
2025-07-16 22:16:36,030 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
2025-07-16 22:16:36,030 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
2025-07-16 22:16:36,046 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\CabE8A.tmp
2025-07-16 22:16:36,062 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\TarE8B.tmp
2025-07-16 22:16:36,078 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\CabEAC.tmp
2025-07-16 22:16:36,092 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\TarEAD.tmp
2025-07-16 22:16:36,187 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-07-16 22:16:36,187 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-07-16 22:16:36,217 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\CabF2B.tmp
2025-07-16 22:16:36,217 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\CabF3C.tmp
2025-07-16 22:16:36,217 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\TarF2C.tmp
2025-07-16 22:16:36,233 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\TarF3D.tmp
2025-07-16 22:16:36,280 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\CabF7D.tmp
2025-07-16 22:16:36,280 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\CabF7E.tmp
2025-07-16 22:16:36,296 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\TarF80.tmp
2025-07-16 22:16:36,296 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\TarF7F.tmp
2025-07-16 22:16:36,375 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\CabFDF.tmp
2025-07-16 22:16:36,390 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\CabFF0.tmp
2025-07-16 22:16:36,390 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\TarFE0.tmp
2025-07-16 22:16:36,405 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\TarFF1.tmp
2025-07-16 22:16:36,467 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1032.tmp
2025-07-16 22:16:36,467 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1031.tmp
2025-07-16 22:16:36,467 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1033.tmp
2025-07-16 22:16:36,467 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1043.tmp
2025-07-16 22:16:36,578 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab10B2.tmp
2025-07-16 22:16:36,578 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab10B4.tmp
2025-07-16 22:16:36,592 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar10B3.tmp
2025-07-16 22:16:36,592 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar10B5.tmp
2025-07-16 22:16:36,655 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1104.tmp
2025-07-16 22:16:36,655 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1105.tmp
2025-07-16 22:16:36,671 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1107.tmp
2025-07-16 22:16:36,671 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1106.tmp
2025-07-16 22:16:36,780 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1185.tmp
2025-07-16 22:16:36,796 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1186.tmp
2025-07-16 22:16:36,796 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1196.tmp
2025-07-16 22:16:36,812 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1197.tmp
2025-07-16 22:16:36,858 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab11C8.tmp
2025-07-16 22:16:36,858 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab11C7.tmp
2025-07-16 22:16:36,875 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar11C9.tmp
2025-07-16 22:16:36,875 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar11CA.tmp
2025-07-16 22:16:37,000 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1258.tmp
2025-07-16 22:16:37,015 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab126A.tmp
2025-07-16 22:16:37,015 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1259.tmp
2025-07-16 22:16:37,015 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar126B.tmp
2025-07-16 22:16:37,078 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab12AA.tmp
2025-07-16 22:16:37,078 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab12AC.tmp
2025-07-16 22:16:37,078 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar12AB.tmp
2025-07-16 22:16:37,078 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar12AD.tmp
2025-07-16 22:16:37,171 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab130C.tmp
2025-07-16 22:16:37,171 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab131D.tmp
2025-07-16 22:16:37,171 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar130D.tmp
2025-07-16 22:16:37,187 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar131E.tmp
2025-07-16 22:16:37,217 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab134E.tmp
2025-07-16 22:16:37,233 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1350.tmp
2025-07-16 22:16:37,233 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar134F.tmp
2025-07-16 22:16:37,233 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1351.tmp
2025-07-16 22:16:37,342 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab13CF.tmp
2025-07-16 22:16:37,358 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar13D0.tmp
2025-07-16 22:16:37,358 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab13E1.tmp
2025-07-16 22:16:37,375 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar13E2.tmp
2025-07-16 22:16:37,421 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1412.tmp
2025-07-16 22:16:37,421 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1422.tmp
2025-07-16 22:16:37,437 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1423.tmp
2025-07-16 22:16:37,437 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1434.tmp
2025-07-16 22:16:37,515 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1484.tmp
2025-07-16 22:16:37,515 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1483.tmp
2025-07-16 22:16:37,530 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1485.tmp
2025-07-16 22:16:37,530 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1486.tmp
2025-07-16 22:16:37,578 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab14B6.tmp
2025-07-16 22:16:37,578 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab14C8.tmp
2025-07-16 22:16:37,592 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar14C9.tmp
2025-07-16 22:16:37,592 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar14C7.tmp
2025-07-16 22:16:37,671 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1527.tmp
2025-07-16 22:16:37,671 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1528.tmp
2025-07-16 22:16:37,687 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1529.tmp
2025-07-16 22:16:37,687 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar152A.tmp
2025-07-16 22:16:38,062 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab16B2.tmp
2025-07-16 22:16:38,078 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar16B3.tmp
2025-07-16 22:16:38,155 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1712.tmp
2025-07-16 22:16:38,171 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1713.tmp
2025-07-16 22:16:38,217 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1743.tmp
2025-07-16 22:16:38,217 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1744.tmp
2025-07-16 22:16:38,312 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab17B2.tmp
2025-07-16 22:16:38,328 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar17B3.tmp
2025-07-16 22:16:38,375 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab17F3.tmp
2025-07-16 22:16:38,390 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar17F4.tmp
2025-07-16 22:16:38,483 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1862.tmp
2025-07-16 22:16:38,500 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1863.tmp
2025-07-16 22:16:38,546 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab18A2.tmp
2025-07-16 22:16:38,562 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar18A3.tmp
2025-07-16 22:16:38,640 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1902.tmp
2025-07-16 22:16:38,671 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1903.tmp
2025-07-16 22:16:38,717 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1952.tmp
2025-07-16 22:16:38,733 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1953.tmp
2025-07-16 22:16:38,812 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab19A2.tmp
2025-07-16 22:16:38,812 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar19A3.tmp
2025-07-16 22:16:38,858 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab19E3.tmp
2025-07-16 22:16:38,858 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar19E4.tmp
2025-07-16 22:16:38,937 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Cab1A33.tmp
2025-07-16 22:16:38,953 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Temp\Tar1A34.tmp
2025-07-16 22:16:39,015 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-16 22:16:39,030 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-16 22:16:39,046 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-16 22:16:39,046 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-16 22:16:39,046 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-16 22:16:39,046 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-16 22:16:39,046 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-16 22:16:39,108 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PGE6LI4G\invalidcert[1]
2025-07-16 22:16:39,171 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\226LUPUX\ErrorPageTemplate[1]
2025-07-16 22:16:39,187 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\928VIF8D\errorPageStrings[1]
2025-07-16 22:16:39,203 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PGE6LI4G\httpErrorPagesScripts[1]
2025-07-16 22:16:39,203 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\226LUPUX\invalidcert[1]
2025-07-16 22:16:39,217 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\928VIF8D\red_shield_48[1]
2025-07-16 22:16:39,265 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DJVKKYGN\green_shield[1]
2025-07-16 22:16:39,265 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PGE6LI4G\red_shield[1]
2025-07-16 22:16:39,280 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\226LUPUX\down[1]
2025-07-16 22:16:39,342 [analyzer] INFO: Added new file to list with pid 1512 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\928VIF8D\background_gradient_red[1]
2025-07-16 21:27:13,627 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-16 21:27:13,907 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 680.
2025-07-16 21:27:13,986 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1512.
2025-07-16 21:27:14,345 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-16 21:27:14,345 [lib.api.process] INFO: Successfully terminated process with pid 680.
2025-07-16 21:27:14,345 [lib.api.process] INFO: Successfully terminated process with pid 1512.
2025-07-16 21:27:14,345 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1104.tmp' does not exist, skip.
2025-07-16 21:27:14,345 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1862.tmp' does not exist, skip.
2025-07-16 21:27:14,345 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1712.tmp' does not exist, skip.
2025-07-16 21:27:14,361 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab130c.tmp' does not exist, skip.
2025-07-16 21:27:14,361 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabeac.tmp' does not exist, skip.
2025-07-16 21:27:14,361 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1033.tmp' does not exist, skip.
2025-07-16 21:27:14,361 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1484.tmp' does not exist, skip.
2025-07-16 21:27:14,361 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar19e4.tmp' does not exist, skip.
2025-07-16 21:27:14,377 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1744.tmp' does not exist, skip.
2025-07-16 21:27:14,377 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1527.tmp' does not exist, skip.
2025-07-16 21:27:14,377 [analyzer] INFO: Error dumping file from path "c:\users\administrator\appdata\local\temp\~dfc8c4cee58bc2974c.tmp": [Errno 13] Permission denied: u'c:\\users\\administrator\\appdata\\local\\temp\\~dfc8c4cee58bc2974c.tmp'
2025-07-16 21:27:14,377 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1032.tmp' does not exist, skip.
2025-07-16 21:27:14,377 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1197.tmp' does not exist, skip.
2025-07-16 21:27:14,377 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab134e.tmp' does not exist, skip.
2025-07-16 21:27:14,377 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dffac0b532650568b8.tmp' does not exist, skip.
2025-07-16 21:27:14,377 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar10b5.tmp' does not exist, skip.
2025-07-16 21:27:14,392 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab10b2.tmp' does not exist, skip.
2025-07-16 21:27:14,392 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1185.tmp' does not exist, skip.
2025-07-16 21:27:14,392 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar14c9.tmp' does not exist, skip.
2025-07-16 21:27:14,392 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab131d.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar130d.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar17f4.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab11c8.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1485.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1528.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1486.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1953.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf7e.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1351.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab13cf.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar152a.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar11c9.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1902.tmp' does not exist, skip.
2025-07-16 21:27:14,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar16b3.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar134f.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab12aa.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1043.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf3d.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf7d.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab17b2.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1186.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\taread.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar17b3.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar13d0.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab14c8.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabff0.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab10b4.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab19a2.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfe0.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1422.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1258.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1106.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf3c.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab17f3.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab18a2.tmp' does not exist, skip.
2025-07-16 21:27:14,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab13e1.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar11ca.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf2b.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar131e.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1529.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar12ad.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1196.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab126a.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1863.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare8b.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1423.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1434.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf7f.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1105.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe8a.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf2c.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab11c7.tmp' does not exist, skip.
2025-07-16 21:27:14,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1713.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1a33.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab16b2.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar10b3.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1412.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1031.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1259.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab12ac.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf80.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar12ab.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfdf.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1903.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar14c7.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar13e2.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab14b6.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1743.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar126b.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar18a3.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab19e3.tmp' does not exist, skip.
2025-07-16 21:27:14,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1107.tmp' does not exist, skip.
2025-07-16 21:27:14,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar1a34.tmp' does not exist, skip.
2025-07-16 21:27:14,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarff1.tmp' does not exist, skip.
2025-07-16 21:27:14,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar19a3.tmp' does not exist, skip.
2025-07-16 21:27:14,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1952.tmp' does not exist, skip.
2025-07-16 21:27:14,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1483.tmp' does not exist, skip.
2025-07-16 21:27:14,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab1350.tmp' does not exist, skip.
2025-07-16 21:27:14,470 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-16 22:23:12,134 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:13,170 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:14,237 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:15,261 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:16,285 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:17,371 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:18,440 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:19,521 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:20,596 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:21,655 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:22,718 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:23,782 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:24,849 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:25,964 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:27,107 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:28,172 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:29,235 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:30,320 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:31,384 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:32,635 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:33,754 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:34,854 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:35,980 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:37,096 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:38,324 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:39,564 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:40,896 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:42,103 [cuckoo.core.scheduler] DEBUG: Task #6736670: no machine available yet
2025-07-16 22:23:43,257 [cuckoo.core.scheduler] INFO: Task #6736670: acquired machine win7x6410 (label=win7x6410)
2025-07-16 22:23:43,259 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.210 for task #6736670
2025-07-16 22:23:43,679 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3020701 (interface=vboxnet0, host=192.168.168.210)
2025-07-16 22:23:43,733 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6410
2025-07-16 22:23:44,689 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6410 to vmcloak
2025-07-16 22:26:35,762 [cuckoo.core.guest] INFO: Starting analysis #6736670 on guest (id=win7x6410, ip=192.168.168.210)
2025-07-16 22:26:36,770 [cuckoo.core.guest] DEBUG: win7x6410: not ready yet
2025-07-16 22:26:41,809 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6410, ip=192.168.168.210)
2025-07-16 22:26:41,912 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6410, ip=192.168.168.210, monitor=latest, size=6660546)
2025-07-16 22:26:43,252 [cuckoo.core.resultserver] DEBUG: Task #6736670: live log analysis.log initialized.
2025-07-16 22:26:44,208 [cuckoo.core.resultserver] DEBUG: Task #6736670 is sending a BSON stream
2025-07-16 22:26:44,739 [cuckoo.core.resultserver] DEBUG: Task #6736670 is sending a BSON stream
2025-07-16 22:26:45,553 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'shots/0001.jpg'
2025-07-16 22:26:45,574 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 133497
2025-07-16 22:26:46,770 [cuckoo.core.resultserver] DEBUG: Task #6736670 is sending a BSON stream
2025-07-16 22:26:47,803 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'shots/0002.jpg'
2025-07-16 22:26:47,810 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 66987
2025-07-16 22:26:48,963 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'shots/0003.jpg'
2025-07-16 22:26:48,968 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 24472
2025-07-16 22:26:50,059 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'shots/0004.jpg'
2025-07-16 22:26:50,064 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 30796
2025-07-16 22:26:55,402 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'shots/0005.jpg'
2025-07-16 22:26:55,405 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 30846
2025-07-16 22:26:56,506 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'shots/0006.jpg'
2025-07-16 22:26:56,535 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 54164
2025-07-16 22:26:57,959 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6736670 still processing
2025-07-16 22:27:13,053 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6736670 still processing
2025-07-16 22:27:14,138 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'curtain/1752694034.11.curtain.log'
2025-07-16 22:27:14,140 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 36
2025-07-16 22:27:14,338 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'sysmon/1752694034.31.sysmon.xml'
2025-07-16 22:27:14,365 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 1818442
2025-07-16 22:27:14,375 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/5e2cd0990d6d3b0b_red_shield_48[1]'
2025-07-16 22:27:14,377 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 4127
2025-07-16 22:27:14,388 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/4bd9f96d6971c7d3_red_shield[1]'
2025-07-16 22:27:14,391 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 810
2025-07-16 22:27:14,398 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/9466d620dc57835a_errorpagestrings[1]'
2025-07-16 22:27:14,400 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 2949
2025-07-16 22:27:14,404 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/8d018639281b33da_errorpagetemplate[1]'
2025-07-16 22:27:14,406 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 2168
2025-07-16 22:27:14,414 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/f18e9671426708c6_invalidcert[1]'
2025-07-16 22:27:14,416 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 2588
2025-07-16 22:27:14,419 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/4758458caa2628f1_recoverystore.{c10146f9-6281-11f0-aba3-f26623dbdec8}.dat'
2025-07-16 22:27:14,421 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 5632
2025-07-16 22:27:14,428 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/4c847e0c28733ed3_94308059b57b3142e455b38a6eb92015'
2025-07-16 22:27:14,430 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 73513
2025-07-16 22:27:14,435 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/39e7de847c9f731e_down[1]'
2025-07-16 22:27:14,437 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 748
2025-07-16 22:27:14,443 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/96bcec06264976f3_2d85f72862b55c4eadd9e66e06947f3d'
2025-07-16 22:27:14,445 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 1391
2025-07-16 22:27:14,451 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/1ba122f4b39a3333_green_shield[1]'
2025-07-16 22:27:14,452 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 810
2025-07-16 22:27:14,457 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/fbc23311fb5eb53c_background_gradient_red[1]'
2025-07-16 22:27:14,459 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 868
2025-07-16 22:27:14,462 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/46e019fa34465f4e_httperrorpagesscripts[1]'
2025-07-16 22:27:14,463 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 8714
2025-07-16 22:27:14,469 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/c55f4b6ef82c5122_94308059b57b3142e455b38a6eb92015'
2025-07-16 22:27:14,471 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 344
2025-07-16 22:27:14,479 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/0e655080b7695297_{c10146fb-6281-11f0-aba3-f26623dbdec8}.dat'
2025-07-16 22:27:14,480 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 4096
2025-07-16 22:27:14,484 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/59e53005e12d5c20_invalidcert[1]'
2025-07-16 22:27:14,486 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 5038
2025-07-16 22:27:14,488 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'files/2ff6ca5d5e413345_2d85f72862b55c4eadd9e66e06947f3d'
2025-07-16 22:27:14,490 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 192
2025-07-16 22:27:15,120 [cuckoo.core.resultserver] DEBUG: Task #6736670: File upload for 'shots/0007.jpg'
2025-07-16 22:27:15,135 [cuckoo.core.resultserver] DEBUG: Task #6736670 uploaded file length: 133469
2025-07-16 22:27:15,150 [cuckoo.core.resultserver] DEBUG: Task #6736670 had connection reset for <Context for LOG>
2025-07-16 22:27:16,067 [cuckoo.core.guest] INFO: win7x6410: analysis completed successfully
2025-07-16 22:27:16,080 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-16 22:27:16,105 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-16 22:27:17,128 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6410 to path /srv/cuckoo/cwd/storage/analyses/6736670/memory.dmp
2025-07-16 22:27:17,130 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6410
2025-07-16 22:30:02,137 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.210 for task #6736670
2025-07-16 22:30:02,803 [cuckoo.core.scheduler] DEBUG: Released database task #6736670
2025-07-16 22:30:02,829 [cuckoo.core.scheduler] INFO: Task #6736670: analysis procedure completed