Analyzer Log
2025-09-13 05:59:02,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp2pjrvv
2025-09-13 05:59:02,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\nSchueoLcWPBKijWnUujtNarHaDYhW
2025-09-13 05:59:02,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\QddtUFUNlxNIbQzEqgIwVVPKiiXru
2025-09-13 05:59:02,342 [analyzer] DEBUG: Started auxiliary module Curtain
2025-09-13 05:59:02,342 [analyzer] DEBUG: Started auxiliary module DbgView
2025-09-13 05:59:02,796 [analyzer] DEBUG: Started auxiliary module Disguise
2025-09-13 05:59:03,015 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-09-13 05:59:03,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-09-13 05:59:03,015 [analyzer] DEBUG: Started auxiliary module Human
2025-09-13 05:59:03,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-09-13 05:59:03,015 [analyzer] DEBUG: Started auxiliary module Reboot
2025-09-13 05:59:03,125 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-09-13 05:59:03,125 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-09-13 05:59:03,125 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-09-13 05:59:03,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-09-13 05:59:03,265 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\4bcce0ecfacf141f7edf5873501fcbad8ed558a3b5f6fc005ac90342f4032a47_unsafe.exe' with arguments '' and pid 1416
2025-09-13 05:59:03,437 [analyzer] DEBUG: Loaded monitor into process with pid 1416
2025-09-13 05:59:08,000 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-09-13 05:59:08,000 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-09-13 05:59:08,000 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-09-13 05:59:08,000 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-09-13 05:59:08,015 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-09-13 05:59:08,015 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-09-13 05:59:08,015 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-09-13 05:59:08,046 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-09-13 05:59:08,046 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-09-13 05:59:08,046 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-09-13 05:59:08,046 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-09-13 05:59:08,062 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-09-13 05:59:08,062 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-09-13 05:59:08,062 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-09-13 05:59:09,421 [analyzer] INFO: Injected into process with pid 1832 and name ''
2025-09-13 05:59:09,592 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1832.
2025-09-13 05:59:09,687 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1416.
2025-09-13 05:59:09,750 [analyzer] DEBUG: Loaded monitor into process with pid 1832
2025-09-13 05:59:10,265 [analyzer] INFO: Process with pid 1416 has terminated
2025-09-13 05:59:13,500 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-09-13 05:59:13,500 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-09-13 05:59:13,500 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-09-13 05:59:13,500 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-09-13 05:59:13,500 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-09-13 05:59:13,500 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-09-13 05:59:13,500 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-09-13 05:59:13,515 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-09-13 05:59:13,515 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-09-13 05:59:13,530 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-09-13 05:59:13,530 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-09-13 05:59:13,530 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-09-13 05:59:13,530 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-09-13 05:59:13,530 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-09-13 05:00:00,289 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-09-13 05:00:00,477 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1832.
2025-09-13 05:00:00,743 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-09-13 05:00:00,743 [lib.api.process] INFO: Successfully terminated process with pid 1832.
2025-09-13 05:00:00,743 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-09-13 05:59:06,304 [cuckoo.core.scheduler] INFO: Task #6968165: acquired machine win7x648 (label=win7x648)
2025-09-13 05:59:06,305 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.208 for task #6968165
2025-09-13 05:59:07,582 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1284397 (interface=vboxnet0, host=192.168.168.208)
2025-09-13 05:59:07,814 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x648
2025-09-13 05:59:09,417 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x648 to vmcloak
2025-09-13 05:59:22,687 [cuckoo.core.guest] INFO: Starting analysis #6968165 on guest (id=win7x648, ip=192.168.168.208)
2025-09-13 05:59:23,692 [cuckoo.core.guest] DEBUG: win7x648: not ready yet
2025-09-13 05:59:28,714 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x648, ip=192.168.168.208)
2025-09-13 05:59:28,798 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x648, ip=192.168.168.208, monitor=latest, size=6660546)
2025-09-13 05:59:30,003 [cuckoo.core.resultserver] DEBUG: Task #6968165: live log analysis.log initialized.
2025-09-13 05:59:30,973 [cuckoo.core.resultserver] DEBUG: Task #6968165 is sending a BSON stream
2025-09-13 05:59:31,379 [cuckoo.core.resultserver] DEBUG: Task #6968165 is sending a BSON stream
2025-09-13 05:59:32,260 [cuckoo.core.resultserver] DEBUG: Task #6968165: File upload for 'shots/0001.jpg'
2025-09-13 05:59:32,273 [cuckoo.core.resultserver] DEBUG: Task #6968165 uploaded file length: 133481
2025-09-13 05:59:36,479 [cuckoo.core.resultserver] DEBUG: Task #6968165: File upload for 'shots/0002.jpg'
2025-09-13 05:59:36,491 [cuckoo.core.resultserver] DEBUG: Task #6968165 uploaded file length: 135645
2025-09-13 05:59:37,590 [cuckoo.core.resultserver] DEBUG: Task #6968165: File upload for 'shots/0003.jpg'
2025-09-13 05:59:37,611 [cuckoo.core.resultserver] DEBUG: Task #6968165 uploaded file length: 133481
2025-09-13 05:59:37,706 [cuckoo.core.resultserver] DEBUG: Task #6968165 is sending a BSON stream
2025-09-13 05:59:41,794 [cuckoo.core.resultserver] DEBUG: Task #6968165: File upload for 'shots/0004.jpg'
2025-09-13 05:59:41,811 [cuckoo.core.resultserver] DEBUG: Task #6968165 uploaded file length: 135645
2025-09-13 05:59:42,911 [cuckoo.core.resultserver] DEBUG: Task #6968165: File upload for 'shots/0005.jpg'
2025-09-13 05:59:42,922 [cuckoo.core.resultserver] DEBUG: Task #6968165 uploaded file length: 133481
2025-09-13 05:59:44,574 [cuckoo.core.guest] DEBUG: win7x648: analysis #6968165 still processing
2025-09-13 05:59:59,668 [cuckoo.core.guest] DEBUG: win7x648: analysis #6968165 still processing
2025-09-13 06:00:00,626 [cuckoo.core.resultserver] DEBUG: Task #6968165: File upload for 'curtain/1757732400.62.curtain.log'
2025-09-13 06:00:00,630 [cuckoo.core.resultserver] DEBUG: Task #6968165 uploaded file length: 36
2025-09-13 06:00:00,746 [cuckoo.core.resultserver] DEBUG: Task #6968165: File upload for 'sysmon/1757732400.74.sysmon.xml'
2025-09-13 06:00:00,755 [cuckoo.core.resultserver] DEBUG: Task #6968165 uploaded file length: 154188
2025-09-13 06:00:01,489 [cuckoo.core.resultserver] DEBUG: Task #6968165 had connection reset for <Context for LOG>
2025-09-13 06:00:02,681 [cuckoo.core.guest] INFO: win7x648: analysis completed successfully
2025-09-13 06:00:02,693 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-09-13 06:00:02,725 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-09-13 06:00:05,501 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x648 to path /srv/cuckoo/cwd/storage/analyses/6968165/memory.dmp
2025-09-13 06:00:05,502 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x648
2025-09-13 06:00:15,921 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.208 for task #6968165
2025-09-13 06:00:16,228 [cuckoo.core.scheduler] DEBUG: Released database task #6968165
2025-09-13 06:00:16,246 [cuckoo.core.scheduler] INFO: Task #6968165: analysis procedure completed