Analyzer Log
2025-09-11 09:58:37,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpzepe2z
2025-09-11 09:58:37,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\YygWTGYxgOHAfCXjTJdz
2025-09-11 09:58:37,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\EVozSOSuiKDsLjUZYUBwbiGoDseC
2025-09-11 09:58:37,328 [analyzer] DEBUG: Started auxiliary module Curtain
2025-09-11 09:58:37,328 [analyzer] DEBUG: Started auxiliary module DbgView
2025-09-11 09:58:37,733 [analyzer] DEBUG: Started auxiliary module Disguise
2025-09-11 09:58:37,953 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-09-11 09:58:37,953 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-09-11 09:58:37,953 [analyzer] DEBUG: Started auxiliary module Human
2025-09-11 09:58:37,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-09-11 09:58:37,967 [analyzer] DEBUG: Started auxiliary module Reboot
2025-09-11 09:58:38,015 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-09-11 09:58:38,015 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-09-11 09:58:38,015 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-09-11 09:58:38,015 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-09-11 09:58:38,155 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\c96ebdb12684d0b47ebd0fa81aee556c8c981b942262d2169d9f63dc3b7e5a7c.exe' with arguments '' and pid 1708
2025-09-11 09:58:38,328 [analyzer] DEBUG: Loaded monitor into process with pid 1708
2025-09-11 09:07:59,697 [analyzer] INFO: Injected into process with pid 1724 and name ''
2025-09-11 09:07:59,808 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1724.
2025-09-11 09:07:59,885 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1708.
2025-09-11 09:07:59,947 [analyzer] INFO: Process with pid 1708 has terminated
2025-09-11 09:07:59,994 [analyzer] DEBUG: Loaded monitor into process with pid 1724
2025-09-11 09:08:02,917 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2025-09-11 09:08:02,917 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2025-09-11 09:08:02,933 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\Local\Temp\Cab4D6.tmp
2025-09-11 09:08:02,963 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\Local\Temp\Tar4D7.tmp
2025-09-11 09:08:03,119 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-09-11 09:08:03,119 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-09-11 09:08:03,135 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\Local\Temp\Cab5A3.tmp
2025-09-11 09:08:03,135 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\Local\Temp\Tar5A4.tmp
2025-09-11 09:08:03,322 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-09-11 09:08:03,338 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-09-11 09:08:03,401 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2025-09-11 09:08:03,417 [analyzer] INFO: Added new file to list with pid 1724 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2025-09-11 09:08:03,776 [analyzer] INFO: Injected into process with pid 664 and name u'icacls.exe'
2025-09-11 09:08:03,917 [analyzer] DEBUG: Loaded monitor into process with pid 664
2025-09-11 09:08:03,994 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 664.
2025-09-11 09:08:10,947 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-09-11 09:08:11,010 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1724.
2025-09-11 09:08:11,010 [lib.api.process] WARNING: The process with pid 664 is not alive, memory dump aborted
2025-09-11 09:08:11,322 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-09-11 09:08:11,322 [lib.api.process] INFO: Successfully terminated process with pid 1724.
2025-09-11 09:08:11,354 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-09-11 10:05:28,506 [cuckoo.core.scheduler] INFO: Task #6966063: acquired machine win7x6417 (label=win7x6417)
2025-09-11 10:05:28,506 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.217 for task #6966063
2025-09-11 10:05:29,121 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3585636 (interface=vboxnet0, host=192.168.168.217)
2025-09-11 10:05:29,798 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6417
2025-09-11 10:05:30,769 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6417 to vmcloak
2025-09-11 10:07:33,082 [cuckoo.core.guest] INFO: Starting analysis #6966063 on guest (id=win7x6417, ip=192.168.168.217)
2025-09-11 10:07:34,087 [cuckoo.core.guest] DEBUG: win7x6417: not ready yet
2025-09-11 10:07:39,317 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6417, ip=192.168.168.217)
2025-09-11 10:07:39,467 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6417, ip=192.168.168.217, monitor=latest, size=6660546)
2025-09-11 10:07:40,773 [cuckoo.core.resultserver] DEBUG: Task #6966063: live log analysis.log initialized.
2025-09-11 10:07:41,677 [cuckoo.core.resultserver] DEBUG: Task #6966063 is sending a BSON stream
2025-09-11 10:07:42,036 [cuckoo.core.resultserver] DEBUG: Task #6966063 is sending a BSON stream
2025-09-11 10:07:42,947 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'shots/0001.jpg'
2025-09-11 10:07:42,961 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 133468
2025-09-11 10:07:55,998 [cuckoo.core.guest] DEBUG: win7x6417: analysis #6966063 still processing
2025-09-11 10:07:59,917 [cuckoo.core.resultserver] DEBUG: Task #6966063 is sending a BSON stream
2025-09-11 10:08:03,245 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/d12dd18018f984aa_Cab4D6.tmp'
2025-09-11 10:08:03,262 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 58383
2025-09-11 10:08:03,264 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/78eeb661b72a34ca_Tar4D7.tmp'
2025-09-11 10:08:03,266 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/33ba8221ff3f5211_Cab5A3.tmp'
2025-09-11 10:08:03,269 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 73211
2025-09-11 10:08:03,270 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/4018ab25d7d15f77_Tar5A4.tmp'
2025-09-11 10:08:03,273 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 146584
2025-09-11 10:08:03,275 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 189652
2025-09-11 10:08:03,848 [cuckoo.core.resultserver] DEBUG: Task #6966063 is sending a BSON stream
2025-09-11 10:08:11,108 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'curtain/1757574491.1.curtain.log'
2025-09-11 10:08:11,110 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 36
2025-09-11 10:08:11,160 [cuckoo.core.guest] DEBUG: win7x6417: analysis #6966063 still processing
2025-09-11 10:08:11,293 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'sysmon/1757574491.29.sysmon.xml'
2025-09-11 10:08:11,315 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 1734346
2025-09-11 10:08:11,322 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/58a0a35e406f4a86_8b2b9a00839eed1dfdccc3bfc2f5df12'
2025-09-11 10:08:11,325 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 174
2025-09-11 10:08:11,331 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8'
2025-09-11 10:08:11,333 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 530
2025-09-11 10:08:11,334 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3'
2025-09-11 10:08:11,336 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 889
2025-09-11 10:08:11,338 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/2b4b975177c96ea7_94308059b57b3142e455b38a6eb92015'
2025-09-11 10:08:11,340 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 344
2025-09-11 10:08:11,342 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/81b7fa53b692b4d2_8b2b9a00839eed1dfdccc3bfc2f5df12'
2025-09-11 10:08:11,361 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 1739
2025-09-11 10:08:11,371 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/d9974a87c551c616_14232b434cf29d4c4fb335a86d7fffe3'
2025-09-11 10:08:11,382 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 170
2025-09-11 10:08:11,384 [cuckoo.core.resultserver] DEBUG: Task #6966063: File upload for 'files/ef93064d5a8fc039_b46811c17859ffb409cf0e904a4aa8f8'
2025-09-11 10:08:11,392 [cuckoo.core.resultserver] DEBUG: Task #6966063 uploaded file length: 170
2025-09-11 10:08:11,687 [cuckoo.core.resultserver] DEBUG: Task #6966063 had connection reset for <Context for LOG>
2025-09-11 10:08:14,173 [cuckoo.core.guest] INFO: win7x6417: analysis completed successfully
2025-09-11 10:08:14,186 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-09-11 10:08:14,210 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-09-11 10:08:15,724 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6417 to path /srv/cuckoo/cwd/storage/analyses/6966063/memory.dmp
2025-09-11 10:08:15,726 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6417
2025-09-11 10:09:56,516 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.217 for task #6966063
2025-09-11 10:09:56,921 [cuckoo.core.scheduler] DEBUG: Released database task #6966063
2025-09-11 10:09:56,943 [cuckoo.core.scheduler] INFO: Task #6966063: analysis procedure completed