Analyzer Log
2025-11-08 12:44:05,015 [analyzer] DEBUG: Starting analyzer from: C:\tmppw5mq4
2025-11-08 12:44:05,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\XIpXavvuGtwmPtSdMNSum
2025-11-08 12:44:05,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\UzRgShwzXfTQHxpOGqnDb
2025-11-08 12:44:05,265 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-08 12:44:05,265 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-08 12:44:05,812 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-08 12:44:06,030 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-11-08 12:44:06,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-08 12:44:06,030 [analyzer] DEBUG: Started auxiliary module Human
2025-11-08 12:44:06,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-08 12:44:06,030 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-08 12:44:06,140 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-08 12:44:06,140 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-08 12:44:06,140 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-08 12:44:06,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-08 12:44:06,328 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d678cd78e60c1aa24eba80944c2160fc64f1bb7e6b1ae2c479952afc567fa9a7.exe' with arguments '' and pid 2492
2025-11-08 12:44:06,530 [analyzer] DEBUG: Loaded monitor into process with pid 2492
2025-11-08 12:44:06,625 [analyzer] INFO: Added new file to list with pid 2492 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-11-08 12:44:06,640 [analyzer] INFO: Added new file to list with pid 2492 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-11-08 12:44:06,733 [analyzer] INFO: Injected into process with pid 2184 and name ''
2025-11-08 12:44:06,905 [analyzer] DEBUG: Loaded monitor into process with pid 2184
2025-11-08 12:44:07,000 [analyzer] INFO: Added new file to list with pid 2492 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-11-08 12:44:07,125 [analyzer] INFO: Added new file to list with pid 2492 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\update.exe
2025-11-08 12:44:07,983 [analyzer] INFO: Added new file to list with pid 2184 and path C:\backup.exe
2025-11-08 12:44:35,328 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-08 12:44:35,703 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-08 12:44:35,717 [lib.api.process] INFO: Successfully terminated process with pid 2492.
2025-11-08 12:44:35,717 [lib.api.process] INFO: Successfully terminated process with pid 2184.
2025-11-08 12:44:35,733 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-11-16 15:25:44,438 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:45,498 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:46,535 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:47,562 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:48,584 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:49,621 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:50,673 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:51,699 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:52,716 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:53,742 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:54,764 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:55,805 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:56,825 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:57,854 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:25:59,006 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:00,041 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:01,066 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:02,085 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:03,111 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:04,135 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:05,162 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:06,187 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:07,224 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:08,253 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:09,279 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:10,305 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:11,322 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:12,343 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:13,390 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:14,439 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:15,501 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:16,576 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:17,881 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:18,922 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:19,947 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:20,975 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:22,010 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:23,030 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:24,380 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:25,412 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:26,516 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:27,544 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:28,908 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:29,947 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:30,975 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:32,001 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:33,034 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:34,069 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:35,098 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:36,123 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:37,148 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:38,176 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:39,196 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:40,390 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:41,432 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:42,478 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:43,552 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:44,616 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:45,707 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:46,784 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:47,972 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:49,050 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:50,084 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:51,109 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:52,135 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:53,168 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:54,190 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:55,209 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:56,228 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:57,254 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:58,296 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:26:59,475 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:00,505 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:01,524 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:02,545 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:04,188 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:05,209 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:06,235 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:07,253 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:08,446 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:09,482 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:10,538 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:11,589 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:12,629 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:13,663 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:14,704 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:15,734 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:16,765 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:18,027 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:19,109 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:20,213 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:21,272 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:22,307 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:23,327 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:24,396 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:25,504 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:26,564 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:27,633 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:28,703 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:29,750 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:30,805 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:31,873 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:32,924 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:33,975 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:35,036 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:36,099 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:37,156 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:38,219 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:39,263 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:40,317 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:41,380 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:42,431 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:43,467 [cuckoo.core.scheduler] DEBUG: Task #7095165: no machine available yet
2025-11-16 15:27:44,500 [cuckoo.core.scheduler] INFO: Task #7095165: acquired machine win7x646 (label=win7x646)
2025-11-16 15:27:44,501 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.206 for task #7095165
2025-11-16 15:27:44,832 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 989733 (interface=vboxnet0, host=192.168.168.206)
2025-11-16 15:27:44,926 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x646
2025-11-16 15:27:45,843 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x646 to vmcloak
2025-11-16 15:30:02,656 [cuckoo.core.guest] INFO: Starting analysis #7095165 on guest (id=win7x646, ip=192.168.168.206)
2025-11-16 15:30:03,672 [cuckoo.core.guest] DEBUG: win7x646: not ready yet
2025-11-16 15:30:08,755 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x646, ip=192.168.168.206)
2025-11-16 15:30:10,615 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x646, ip=192.168.168.206, monitor=latest, size=6660546)
2025-11-16 15:30:13,034 [cuckoo.core.resultserver] DEBUG: Task #7095165: live log analysis.log initialized.
2025-11-16 15:30:14,018 [cuckoo.core.resultserver] DEBUG: Task #7095165 is sending a BSON stream
2025-11-16 15:30:14,497 [cuckoo.core.resultserver] DEBUG: Task #7095165 is sending a BSON stream
2025-11-16 15:30:14,877 [cuckoo.core.resultserver] DEBUG: Task #7095165 is sending a BSON stream
2025-11-16 15:30:15,311 [cuckoo.core.resultserver] DEBUG: Task #7095165: File upload for 'shots/0001.jpg'
2025-11-16 15:30:15,328 [cuckoo.core.resultserver] DEBUG: Task #7095165 uploaded file length: 133502
2025-11-16 15:30:27,824 [cuckoo.core.guest] DEBUG: win7x646: analysis #7095165 still processing
2025-11-16 15:30:42,941 [cuckoo.core.guest] DEBUG: win7x646: analysis #7095165 still processing
2025-11-16 15:30:43,571 [cuckoo.core.resultserver] DEBUG: Task #7095165: File upload for 'curtain/1762602275.53.curtain.log'
2025-11-16 15:30:43,574 [cuckoo.core.resultserver] DEBUG: Task #7095165 uploaded file length: 36
2025-11-16 15:30:43,752 [cuckoo.core.resultserver] DEBUG: Task #7095165: File upload for 'sysmon/1762602275.7.sysmon.xml'
2025-11-16 15:30:43,761 [cuckoo.core.resultserver] DEBUG: Task #7095165 uploaded file length: 863176
2025-11-16 15:30:43,769 [cuckoo.core.resultserver] DEBUG: Task #7095165: File upload for 'files/9d1cfc0f6513f75c_backup.exe'
2025-11-16 15:30:43,774 [cuckoo.core.resultserver] DEBUG: Task #7095165: File upload for 'files/bbfcfbb07767c2be_backup.exe'
2025-11-16 15:30:43,781 [cuckoo.core.resultserver] DEBUG: Task #7095165 uploaded file length: 91911
2025-11-16 15:30:43,783 [cuckoo.core.resultserver] DEBUG: Task #7095165: File upload for 'files/344ee1c070334a28_update.exe'
2025-11-16 15:30:43,800 [cuckoo.core.resultserver] DEBUG: Task #7095165 uploaded file length: 91909
2025-11-16 15:30:43,837 [cuckoo.core.resultserver] DEBUG: Task #7095165 uploaded file length: 91909
2025-11-16 15:30:44,280 [cuckoo.core.resultserver] DEBUG: Task #7095165 had connection reset for <Context for LOG>
2025-11-16 15:30:45,961 [cuckoo.core.guest] INFO: win7x646: analysis completed successfully
2025-11-16 15:30:45,974 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-16 15:30:46,005 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-16 15:30:46,993 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x646 to path /srv/cuckoo/cwd/storage/analyses/7095165/memory.dmp
2025-11-16 15:30:46,997 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x646
2025-11-16 15:34:16,374 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.206 for task #7095165
2025-11-16 15:34:16,814 [cuckoo.core.scheduler] DEBUG: Released database task #7095165
2025-11-16 15:34:26,946 [cuckoo.core.scheduler] INFO: Task #7095165: analysis procedure completed