Analyzer Log
2025-07-26 05:40:32,030 [analyzer] DEBUG: Starting analyzer from: C:\tmp564etj
2025-07-26 05:40:32,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\pUEeRiqTiwvjWGAZXKcDDWkHfbQrwiH
2025-07-26 05:40:32,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\jXpcvqtjfptuEvvJAKjhGZ
2025-07-26 05:40:32,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-26 05:40:32,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-26 05:40:32,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-26 05:40:33,000 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-07-26 05:40:33,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-26 05:40:33,000 [analyzer] DEBUG: Started auxiliary module Human
2025-07-26 05:40:33,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-26 05:40:33,000 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-26 05:40:33,062 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-26 05:40:33,062 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-26 05:40:33,062 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-26 05:40:33,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-26 05:40:33,203 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\bb5d3ef04b0e277861abc750cc51351ac747a9f64842349d47e3cd694071f116.exe' with arguments '' and pid 1824
2025-07-26 05:40:33,375 [analyzer] DEBUG: Loaded monitor into process with pid 1824
2025-07-26 05:40:33,421 [analyzer] INFO: Added new file to list with pid 1824 and path C:\ProgramData\AhnLab\AhnSvc.exe
2025-07-26 05:40:33,515 [analyzer] INFO: Injected into process with pid 324 and name u'AhnSvc.exe'
2025-07-26 05:40:33,671 [analyzer] DEBUG: Loaded monitor into process with pid 324
2025-07-26 05:40:33,717 [analyzer] INFO: Added pid 324 for u'C:\\ProgramData\\AhnLab\\AhnSvc.exe'
2025-07-26 05:40:33,717 [analyzer] INFO: Added new file to list with pid 324 and path C:\ProgramData\AhnLab\AhnSvc.exe
2025-07-26 05:41:02,217 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-26 05:41:02,905 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-26 05:41:02,905 [lib.api.process] INFO: Successfully terminated process with pid 1824.
2025-07-26 05:41:02,937 [lib.api.process] INFO: Successfully terminated process with pid 324.
2025-07-26 05:41:02,967 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-27 15:53:46,673 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:47,805 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:48,946 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:50,089 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:51,249 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:52,362 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:53,469 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:54,588 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:55,719 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:57,158 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:58,287 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:53:59,377 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:00,446 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:01,551 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:02,674 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:03,784 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:05,200 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:06,338 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:07,465 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:08,580 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:09,679 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:10,785 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:11,861 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:12,978 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:14,275 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:15,662 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:16,867 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:18,332 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:19,524 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:20,691 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:22,007 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:23,330 [cuckoo.core.scheduler] DEBUG: Task #6772907: no machine available yet
2025-07-27 15:54:24,534 [cuckoo.core.scheduler] INFO: Task #6772907: acquired machine win7x6419 (label=win7x6419)
2025-07-27 15:54:24,548 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.219 for task #6772907
2025-07-27 15:54:25,089 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1303014 (interface=vboxnet0, host=192.168.168.219)
2025-07-27 15:54:26,717 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6419
2025-07-27 15:54:28,125 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6419 to vmcloak
2025-07-27 15:56:28,274 [cuckoo.core.guest] INFO: Starting analysis #6772907 on guest (id=win7x6419, ip=192.168.168.219)
2025-07-27 15:56:29,379 [cuckoo.core.guest] DEBUG: win7x6419: not ready yet
2025-07-27 15:56:34,426 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6419, ip=192.168.168.219)
2025-07-27 15:56:34,907 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6419, ip=192.168.168.219, monitor=latest, size=6660546)
2025-07-27 15:56:36,519 [cuckoo.core.resultserver] DEBUG: Task #6772907: live log analysis.log initialized.
2025-07-27 15:56:37,486 [cuckoo.core.resultserver] DEBUG: Task #6772907 is sending a BSON stream
2025-07-27 15:56:37,829 [cuckoo.core.resultserver] DEBUG: Task #6772907 is sending a BSON stream
2025-07-27 15:56:38,126 [cuckoo.core.resultserver] DEBUG: Task #6772907 is sending a BSON stream
2025-07-27 15:56:38,697 [cuckoo.core.resultserver] DEBUG: Task #6772907: File upload for 'shots/0001.jpg'
2025-07-27 15:56:38,713 [cuckoo.core.resultserver] DEBUG: Task #6772907 uploaded file length: 133566
2025-07-27 15:56:51,472 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6772907 still processing
2025-07-27 15:57:06,737 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6772907 still processing
2025-07-27 15:57:07,088 [cuckoo.core.resultserver] DEBUG: Task #6772907: File upload for 'curtain/1753501262.55.curtain.log'
2025-07-27 15:57:07,115 [cuckoo.core.resultserver] DEBUG: Task #6772907 uploaded file length: 36
2025-07-27 15:57:07,374 [cuckoo.core.resultserver] DEBUG: Task #6772907: File upload for 'sysmon/1753501262.83.sysmon.xml'
2025-07-27 15:57:07,477 [cuckoo.core.resultserver] DEBUG: Task #6772907 uploaded file length: 1621834
2025-07-27 15:57:07,521 [cuckoo.core.resultserver] DEBUG: Task #6772907: File upload for 'files/39c04065abccd35e_ahnsvc.exe_'
2025-07-27 15:57:07,524 [cuckoo.core.resultserver] DEBUG: Task #6772907 uploaded file length: 61600
2025-07-27 15:57:07,530 [cuckoo.core.resultserver] DEBUG: Task #6772907: File upload for 'files/fd4812987e1dc2a9_ahnsvc.exe'
2025-07-27 15:57:07,532 [cuckoo.core.resultserver] DEBUG: Task #6772907 uploaded file length: 61601
2025-07-27 15:57:07,560 [cuckoo.core.resultserver] DEBUG: Task #6772907 had connection reset for <Context for LOG>
2025-07-27 15:57:09,752 [cuckoo.core.guest] INFO: win7x6419: analysis completed successfully
2025-07-27 15:57:09,767 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-27 15:57:09,804 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-27 15:57:11,801 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6419 to path /srv/cuckoo/cwd/storage/analyses/6772907/memory.dmp
2025-07-27 15:57:11,818 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6419
2025-07-27 15:59:51,061 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.219 for task #6772907
2025-07-27 15:59:51,703 [cuckoo.core.scheduler] DEBUG: Released database task #6772907
2025-07-27 16:00:01,907 [cuckoo.core.scheduler] INFO: Task #6772907: analysis procedure completed