Analyzer Log
2025-07-25 15:34:12,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp564etj
2025-07-25 15:34:12,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ouzxCWVgYAzxihNUl
2025-07-25 15:34:12,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\WLxYnLCjXXCgPFRKgzW
2025-07-25 15:34:12,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-25 15:34:12,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-25 15:34:12,750 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-25 15:34:12,937 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-07-25 15:34:12,937 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-25 15:34:12,937 [analyzer] DEBUG: Started auxiliary module Human
2025-07-25 15:34:12,937 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-25 15:34:12,953 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-25 15:34:13,015 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-25 15:34:13,015 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-25 15:34:13,015 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-25 15:34:13,015 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-25 15:34:13,140 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://gfw8w.l3t5d01tr19ht.xyz:443/'] and pid 1348
2025-07-25 15:34:13,280 [analyzer] DEBUG: Loaded monitor into process with pid 1348
2025-07-25 15:34:14,655 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1348 CREDAT:275457 /prefetch:2!
2025-07-25 15:34:14,717 [analyzer] INFO: Injected into process with pid 788 and name u'iexplore.exe'
2025-07-25 15:34:14,796 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 788.
2025-07-25 15:34:14,921 [analyzer] INFO: Added new file to list with pid 1348 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0CFBC17F-695C-11F0-A7EE-6A001A20C83C}.dat
2025-07-25 15:34:14,967 [analyzer] DEBUG: Loaded monitor into process with pid 788
2025-07-25 15:34:14,967 [analyzer] INFO: Added new file to list with pid 1348 and path C:\Users\Administrator\AppData\Local\Temp\~DF313E988F60D92ED2.TMP
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-25 15:34:15,265 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-25 15:34:15,280 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-25 15:34:15,280 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-25 15:34:15,280 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-25 15:34:15,280 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-25 15:34:15,546 [analyzer] INFO: Added new file to list with pid 1348 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0CFBC181-695C-11F0-A7EE-6A001A20C83C}.dat
2025-07-25 15:34:15,562 [analyzer] INFO: Added new file to list with pid 1348 and path C:\Users\Administrator\AppData\Local\Temp\~DF82B4B59CA4BC050F.TMP
2025-07-25 15:34:18,546 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
2025-07-25 15:34:18,546 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
2025-07-25 15:34:18,562 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4A96.tmp
2025-07-25 15:34:18,578 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4AA8.tmp
2025-07-25 15:34:18,578 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4A97.tmp
2025-07-25 15:34:18,592 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4AA9.tmp
2025-07-25 15:34:18,717 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-07-25 15:34:18,717 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-07-25 15:34:18,733 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4B36.tmp
2025-07-25 15:34:18,733 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4B37.tmp
2025-07-25 15:34:18,750 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4B48.tmp
2025-07-25 15:34:18,750 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4B49.tmp
2025-07-25 15:34:18,780 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4B79.tmp
2025-07-25 15:34:18,796 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4B8A.tmp
2025-07-25 15:34:18,796 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4B7A.tmp
2025-07-25 15:34:18,812 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4B8B.tmp
2025-07-25 15:34:18,890 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4BDB.tmp
2025-07-25 15:34:18,890 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4BEC.tmp
2025-07-25 15:34:18,890 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4BDC.tmp
2025-07-25 15:34:18,905 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4BED.tmp
2025-07-25 15:34:18,953 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4C1D.tmp
2025-07-25 15:34:18,953 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4C1E.tmp
2025-07-25 15:34:18,953 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4C2F.tmp
2025-07-25 15:34:18,967 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4C30.tmp
2025-07-25 15:34:19,046 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4C8E.tmp
2025-07-25 15:34:19,062 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4C8F.tmp
2025-07-25 15:34:19,062 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4CA0.tmp
2025-07-25 15:34:19,078 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4CA1.tmp
2025-07-25 15:34:19,108 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4CD1.tmp
2025-07-25 15:34:19,125 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4CD2.tmp
2025-07-25 15:34:19,125 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4CE3.tmp
2025-07-25 15:34:19,140 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4CE4.tmp
2025-07-25 15:34:19,203 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4D33.tmp
2025-07-25 15:34:19,217 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4D44.tmp
2025-07-25 15:34:19,217 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4D34.tmp
2025-07-25 15:34:19,233 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4D45.tmp
2025-07-25 15:34:19,265 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4D75.tmp
2025-07-25 15:34:19,265 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4D77.tmp
2025-07-25 15:34:19,280 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4D76.tmp
2025-07-25 15:34:19,280 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4D78.tmp
2025-07-25 15:34:19,358 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4DC7.tmp
2025-07-25 15:34:19,358 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4DD9.tmp
2025-07-25 15:34:19,358 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4DC8.tmp
2025-07-25 15:34:19,375 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4DDA.tmp
2025-07-25 15:34:19,421 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4E0A.tmp
2025-07-25 15:34:19,421 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4E1B.tmp
2025-07-25 15:34:19,421 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4E1A.tmp
2025-07-25 15:34:19,437 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4E1C.tmp
2025-07-25 15:34:19,515 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4E6C.tmp
2025-07-25 15:34:19,515 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4E7D.tmp
2025-07-25 15:34:19,530 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4E6D.tmp
2025-07-25 15:34:19,530 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4E7E.tmp
2025-07-25 15:34:19,578 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4EAE.tmp
2025-07-25 15:34:19,578 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4EC0.tmp
2025-07-25 15:34:19,592 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4EAF.tmp
2025-07-25 15:34:19,592 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4EC1.tmp
2025-07-25 15:34:19,671 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4F10.tmp
2025-07-25 15:34:19,671 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4F21.tmp
2025-07-25 15:34:19,687 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4F20.tmp
2025-07-25 15:34:19,687 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4F22.tmp
2025-07-25 15:34:19,733 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4F52.tmp
2025-07-25 15:34:19,733 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4F53.tmp
2025-07-25 15:34:19,733 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4F55.tmp
2025-07-25 15:34:19,750 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4F54.tmp
2025-07-25 15:34:19,828 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4FB5.tmp
2025-07-25 15:34:19,828 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4FB4.tmp
2025-07-25 15:34:19,828 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4FB7.tmp
2025-07-25 15:34:19,828 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4FB6.tmp
2025-07-25 15:34:19,875 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4FF7.tmp
2025-07-25 15:34:19,890 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab4FF9.tmp
2025-07-25 15:34:19,890 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4FF8.tmp
2025-07-25 15:34:19,890 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar4FFA.tmp
2025-07-25 15:34:19,967 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab5058.tmp
2025-07-25 15:34:19,983 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar5059.tmp
2025-07-25 15:34:19,983 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab506A.tmp
2025-07-25 15:34:19,983 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar506B.tmp
2025-07-25 15:34:20,108 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab50E9.tmp
2025-07-25 15:34:20,125 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar50EA.tmp
2025-07-25 15:34:20,203 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab5149.tmp
2025-07-25 15:34:20,217 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar514A.tmp
2025-07-25 15:34:20,250 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab517A.tmp
2025-07-25 15:34:20,265 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar517B.tmp
2025-07-25 15:34:20,328 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab51CA.tmp
2025-07-25 15:34:20,342 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar51CB.tmp
2025-07-25 15:34:20,390 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab520A.tmp
2025-07-25 15:34:20,390 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar520B.tmp
2025-07-25 15:34:20,453 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab524B.tmp
2025-07-25 15:34:20,467 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar524C.tmp
2025-07-25 15:34:20,515 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab528B.tmp
2025-07-25 15:34:20,530 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar528C.tmp
2025-07-25 15:34:20,592 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab52DB.tmp
2025-07-25 15:34:20,608 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar52DC.tmp
2025-07-25 15:34:20,655 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab530C.tmp
2025-07-25 15:34:20,655 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar531D.tmp
2025-07-25 15:34:20,733 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab536C.tmp
2025-07-25 15:34:20,750 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar536D.tmp
2025-07-25 15:34:20,796 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab53AC.tmp
2025-07-25 15:34:20,812 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar53AD.tmp
2025-07-25 15:34:20,875 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Cab53FD.tmp
2025-07-25 15:34:20,890 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Temp\Tar53FE.tmp
2025-07-25 15:34:20,937 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-07-25 15:34:20,953 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-07-25 15:34:20,953 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-07-25 15:34:20,953 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-07-25 15:34:20,953 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-07-25 15:34:20,953 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-07-25 15:34:20,953 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-07-25 15:34:20,967 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8TUN8DLS\invalidcert[1]
2025-07-25 15:34:21,015 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ESSUB5FZ\ErrorPageTemplate[1]
2025-07-25 15:34:21,030 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1KG60UM\errorPageStrings[1]
2025-07-25 15:34:21,046 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8TUN8DLS\httpErrorPagesScripts[1]
2025-07-25 15:34:21,062 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ESSUB5FZ\invalidcert[1]
2025-07-25 15:34:21,062 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1KG60UM\red_shield_48[1]
2025-07-25 15:34:21,092 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NTS6RXZ\green_shield[1]
2025-07-25 15:34:21,108 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8TUN8DLS\red_shield[1]
2025-07-25 15:34:21,108 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ESSUB5FZ\down[1]
2025-07-25 15:34:21,187 [analyzer] INFO: Added new file to list with pid 788 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1KG60UM\background_gradient_red[1]
2025-07-25 14:44:24,792 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-25 14:44:25,010 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1348.
2025-07-25 14:44:25,088 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 788.
2025-07-25 14:44:25,463 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-25 14:44:25,463 [lib.api.process] INFO: Successfully terminated process with pid 1348.
2025-07-25 14:44:25,463 [lib.api.process] INFO: Successfully terminated process with pid 788.
2025-07-25 14:44:25,463 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4e0a.tmp' does not exist, skip.
2025-07-25 14:44:25,479 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4cd1.tmp' does not exist, skip.
2025-07-25 14:44:25,479 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4d45.tmp' does not exist, skip.
2025-07-25 14:44:25,479 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar53fe.tmp' does not exist, skip.
2025-07-25 14:44:25,479 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4b36.tmp' does not exist, skip.
2025-07-25 14:44:25,479 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4d34.tmp' does not exist, skip.
2025-07-25 14:44:25,479 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4fb4.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab530c.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar50ea.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4b37.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5149.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab506a.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4dd9.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4aa8.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4b8b.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab53fd.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4eaf.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4e6c.tmp' does not exist, skip.
2025-07-25 14:44:25,494 [analyzer] INFO: Error dumping file from path "c:\users\administrator\appdata\local\temp\~df313e988f60d92ed2.tmp": [Errno 13] Permission denied: u'c:\\users\\administrator\\appdata\\local\\temp\\~df313e988f60d92ed2.tmp'
2025-07-25 14:44:25,494 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4fb6.tmp' does not exist, skip.
2025-07-25 14:44:25,510 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4b7a.tmp' does not exist, skip.
2025-07-25 14:44:25,510 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4d77.tmp' does not exist, skip.
2025-07-25 14:44:25,510 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4a96.tmp' does not exist, skip.
2025-07-25 14:44:25,526 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4e7e.tmp' does not exist, skip.
2025-07-25 14:44:25,526 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4f22.tmp' does not exist, skip.
2025-07-25 14:44:25,526 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4dda.tmp' does not exist, skip.
2025-07-25 14:44:25,526 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4b79.tmp' does not exist, skip.
2025-07-25 14:44:25,526 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4ff8.tmp' does not exist, skip.
2025-07-25 14:44:25,526 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4c30.tmp' does not exist, skip.
2025-07-25 14:44:25,526 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar514a.tmp' does not exist, skip.
2025-07-25 14:44:25,526 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5058.tmp' does not exist, skip.
2025-07-25 14:44:25,542 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4fb7.tmp' does not exist, skip.
2025-07-25 14:44:25,542 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4b8a.tmp' does not exist, skip.
2025-07-25 14:44:25,542 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4f55.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4c1e.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4e1b.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4f53.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4f10.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab536c.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab51ca.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar520b.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4bed.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4fb5.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4d76.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4c8e.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4eae.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4ff7.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4dc8.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4ce4.tmp' does not exist, skip.
2025-07-25 14:44:25,556 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4e6d.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4dc7.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4aa9.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab52db.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4bdc.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4f21.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4ffa.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4d44.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4e7d.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab517a.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab528b.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4d33.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4c8f.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab520a.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5059.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4f20.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar52dc.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4c2f.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar506b.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4ff9.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4bec.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab53ac.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4c1d.tmp' does not exist, skip.
2025-07-25 14:44:25,572 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar536d.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar531d.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar51cb.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar528c.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4d78.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4a97.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar524c.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab524b.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4b48.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4ca0.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar53ad.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4ce3.tmp' does not exist, skip.
2025-07-25 14:44:25,588 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4f52.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4ca1.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4f54.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4cd2.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4b49.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4ec0.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4e1a.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar517b.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df82b4b59ca4bc050f.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4bdb.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab50e9.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4ec1.tmp' does not exist, skip.
2025-07-25 14:44:25,604 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab4d75.tmp' does not exist, skip.
2025-07-25 14:44:25,619 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar4e1c.tmp' does not exist, skip.
2025-07-25 14:44:25,619 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-25 15:40:41,102 [cuckoo.core.scheduler] INFO: Task #6760463: acquired machine win7x6419 (label=win7x6419)
2025-07-25 15:40:41,104 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.219 for task #6760463
2025-07-25 15:40:41,440 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 620896 (interface=vboxnet0, host=192.168.168.219)
2025-07-25 15:40:41,491 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6419
2025-07-25 15:40:43,143 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6419 to vmcloak
2025-07-25 15:43:47,215 [cuckoo.core.guest] INFO: Starting analysis #6760463 on guest (id=win7x6419, ip=192.168.168.219)
2025-07-25 15:43:48,221 [cuckoo.core.guest] DEBUG: win7x6419: not ready yet
2025-07-25 15:43:53,243 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6419, ip=192.168.168.219)
2025-07-25 15:43:53,327 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6419, ip=192.168.168.219, monitor=latest, size=6660546)
2025-07-25 15:43:54,641 [cuckoo.core.resultserver] DEBUG: Task #6760463: live log analysis.log initialized.
2025-07-25 15:43:55,522 [cuckoo.core.resultserver] DEBUG: Task #6760463 is sending a BSON stream
2025-07-25 15:43:55,866 [cuckoo.core.resultserver] DEBUG: Task #6760463 is sending a BSON stream
2025-07-25 15:43:56,772 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'shots/0001.jpg'
2025-07-25 15:43:56,783 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 133567
2025-07-25 15:43:57,554 [cuckoo.core.resultserver] DEBUG: Task #6760463 is sending a BSON stream
2025-07-25 15:43:58,895 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'shots/0002.jpg'
2025-07-25 15:43:58,898 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 24486
2025-07-25 15:43:59,988 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'shots/0003.jpg'
2025-07-25 15:43:59,991 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 30000
2025-07-25 15:44:01,086 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'shots/0004.jpg'
2025-07-25 15:44:01,106 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 30189
2025-07-25 15:44:04,209 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'shots/0005.jpg'
2025-07-25 15:44:04,214 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 53417
2025-07-25 15:44:09,414 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6760463 still processing
2025-07-25 15:44:24,558 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6760463 still processing
2025-07-25 15:44:25,215 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'curtain/1753447465.21.curtain.log'
2025-07-25 15:44:25,218 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 36
2025-07-25 15:44:25,414 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'sysmon/1753447465.42.sysmon.xml'
2025-07-25 15:44:25,465 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 1811572
2025-07-25 15:44:25,474 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/3d49807888bca9ac_{0cfbc181-695c-11f0-a7ee-6a001a20c83c}.dat'
2025-07-25 15:44:25,476 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 3584
2025-07-25 15:44:25,484 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/9466d620dc57835a_errorpagestrings[1]'
2025-07-25 15:44:25,487 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 2949
2025-07-25 15:44:25,511 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/4c847e0c28733ed3_94308059b57b3142e455b38a6eb92015'
2025-07-25 15:44:25,518 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 73513
2025-07-25 15:44:25,539 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/39e7de847c9f731e_down[1]'
2025-07-25 15:44:25,551 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 748
2025-07-25 15:44:25,553 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/59e53005e12d5c20_invalidcert[1]'
2025-07-25 15:44:25,555 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 5038
2025-07-25 15:44:25,556 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/96bcec06264976f3_2d85f72862b55c4eadd9e66e06947f3d'
2025-07-25 15:44:25,558 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 1391
2025-07-25 15:44:25,559 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/5e2cd0990d6d3b0b_red_shield_48[1]'
2025-07-25 15:44:25,560 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 4127
2025-07-25 15:44:25,561 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/f18e9671426708c6_invalidcert[1]'
2025-07-25 15:44:25,563 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 2588
2025-07-25 15:44:25,564 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/f28dff338d9dc294_2d85f72862b55c4eadd9e66e06947f3d'
2025-07-25 15:44:25,565 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 192
2025-07-25 15:44:25,579 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/55401d73fe03599c_94308059b57b3142e455b38a6eb92015'
2025-07-25 15:44:25,582 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 344
2025-07-25 15:44:25,583 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/46e019fa34465f4e_httperrorpagesscripts[1]'
2025-07-25 15:44:25,586 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 8714
2025-07-25 15:44:25,588 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/fbc23311fb5eb53c_background_gradient_red[1]'
2025-07-25 15:44:25,589 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 868
2025-07-25 15:44:25,596 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/8d018639281b33da_errorpagetemplate[1]'
2025-07-25 15:44:25,598 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 2168
2025-07-25 15:44:25,600 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/4bd9f96d6971c7d3_red_shield[1]'
2025-07-25 15:44:25,602 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 810
2025-07-25 15:44:25,608 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/43a7419c0473f36e_recoverystore.{0cfbc17f-695c-11f0-a7ee-6a001a20c83c}.dat'
2025-07-25 15:44:25,610 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 5632
2025-07-25 15:44:25,612 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'files/1ba122f4b39a3333_green_shield[1]'
2025-07-25 15:44:25,614 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 810
2025-07-25 15:44:25,940 [cuckoo.core.resultserver] DEBUG: Task #6760463: File upload for 'shots/0006.jpg'
2025-07-25 15:44:25,954 [cuckoo.core.resultserver] DEBUG: Task #6760463 uploaded file length: 133564
2025-07-25 15:44:25,967 [cuckoo.core.resultserver] DEBUG: Task #6760463 had connection reset for <Context for LOG>
2025-07-25 15:44:27,590 [cuckoo.core.guest] INFO: win7x6419: analysis completed successfully
2025-07-25 15:44:27,612 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-25 15:44:27,704 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-25 15:44:29,282 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6419 to path /srv/cuckoo/cwd/storage/analyses/6760463/memory.dmp
2025-07-25 15:44:29,283 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6419
2025-07-25 15:47:51,234 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.219 for task #6760463
2025-07-25 15:47:51,600 [cuckoo.core.scheduler] DEBUG: Released database task #6760463
2025-07-25 15:47:51,619 [cuckoo.core.scheduler] INFO: Task #6760463: analysis procedure completed