Analyzer Log
2025-11-11 09:55:59,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4
2025-11-11 09:55:59,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\KhyoCsnVmOBUCCSqQILEFNpT
2025-11-11 09:55:59,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\uqmUyzJgmARLaQRszKPHZOdEjGL
2025-11-11 09:55:59,342 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-11 09:55:59,342 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-11 09:56:00,015 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-11 09:56:00,217 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-11-11 09:56:00,250 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-11 09:56:00,250 [analyzer] DEBUG: Started auxiliary module Human
2025-11-11 09:56:00,250 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-11 09:56:00,250 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-11 09:56:00,405 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-11 09:56:00,405 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-11 09:56:00,405 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-11 09:56:00,405 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-11 09:56:00,858 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\6252e9f1addf8d9b83f7777fdd29624e90b70c96dbf29645a913c7f9348a0c64.exe' with arguments '' and pid 2848
2025-11-11 09:56:01,140 [analyzer] DEBUG: Loaded monitor into process with pid 2848
2025-11-11 09:56:23,556 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Windows\System32\czIAPVJm.exe
2025-11-11 09:56:23,749 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL
2025-11-11 09:56:23,871 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\DESIGNER\MSADDNDR.DLL.exe
2025-11-11 09:56:24,033 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\DW\DBGHELP.DLL
2025-11-11 09:56:24,125 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\DW\DBGHELP.DLL.exe
2025-11-11 09:56:24,253 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE
2025-11-11 09:56:24,454 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE.exe
2025-11-11 09:56:24,608 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE
2025-11-11 09:56:24,733 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE.exe
2025-11-11 09:56:24,895 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\EQUATION\1033\EEINTL.DLL
2025-11-11 09:56:25,009 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\EQUATION\1033\EEINTL.DLL.exe
2025-11-11 09:56:25,158 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT
2025-11-11 09:56:25,286 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.CNT.exe
2025-11-11 09:56:25,431 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
2025-11-11 09:56:25,605 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE.exe
2025-11-11 09:56:25,904 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.HLP
2025-11-11 09:56:26,029 [analyzer] INFO: Added new file to list with pid 2848 and path C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.HLP.exe
2025-11-11 09:56:26,890 [analyzer] INFO: Process with pid 2848 has terminated
2025-11-11 09:56:26,890 [analyzer] INFO: Process list is empty, terminating analysis.
2025-11-11 09:56:28,250 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-11 09:56:32,467 [analyzer] WARNING: File at path u'c:\\windows\\system32\\cziapvjm.exe' does not exist, skip.
2025-11-11 09:56:34,421 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-11-22 00:37:50,290 [cuckoo.core.scheduler] INFO: Task #7168471: acquired machine win7x644 (label=win7x644)
2025-11-22 00:37:50,291 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #7168471
2025-11-22 00:37:50,635 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 544720 (interface=vboxnet0, host=192.168.168.204)
2025-11-22 00:38:07,237 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644
2025-11-22 00:38:08,176 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak
2025-11-22 00:41:19,147 [cuckoo.core.guest] INFO: Starting analysis #7168471 on guest (id=win7x644, ip=192.168.168.204)
2025-11-22 00:41:20,168 [cuckoo.core.guest] DEBUG: win7x644: not ready yet
2025-11-22 00:41:25,201 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204)
2025-11-22 00:41:25,296 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546)
2025-11-22 00:41:29,351 [cuckoo.core.resultserver] DEBUG: Task #7168471: live log analysis.log initialized.
2025-11-22 00:41:30,510 [cuckoo.core.resultserver] DEBUG: Task #7168471 is sending a BSON stream
2025-11-22 00:41:31,353 [cuckoo.core.resultserver] DEBUG: Task #7168471 is sending a BSON stream
2025-11-22 00:41:31,921 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'shots/0001.jpg'
2025-11-22 00:41:31,945 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 117981
2025-11-22 00:41:33,083 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'shots/0002.jpg'
2025-11-22 00:41:33,096 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 132742
2025-11-22 00:41:44,023 [cuckoo.core.guest] DEBUG: win7x644: analysis #7168471 still processing
2025-11-22 00:41:54,755 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'shots/0003.jpg'
2025-11-22 00:41:54,769 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 142087
2025-11-22 00:41:55,868 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'shots/0004.jpg'
2025-11-22 00:41:55,893 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 156191
2025-11-22 00:41:57,014 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'shots/0005.jpg'
2025-11-22 00:41:57,082 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 133528
2025-11-22 00:41:58,298 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'curtain/1762851388.05.curtain.log'
2025-11-22 00:41:58,301 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 36
2025-11-22 00:41:58,493 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'sysmon/1762851388.23.sysmon.xml'
2025-11-22 00:41:58,503 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 1435792
2025-11-22 00:41:58,715 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/642c4f1bd3ff5114_eeintl.dll'
2025-11-22 00:41:58,862 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28490415
2025-11-22 00:41:59,216 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/ff185ec81d19e900_dw20.exe'
2025-11-22 00:41:59,274 [cuckoo.core.guest] DEBUG: win7x644: analysis #7168471 still processing
2025-11-22 00:41:59,368 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28412591
2025-11-22 00:41:59,624 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/d97b60add2ce065d_eqnedt32.cnt'
2025-11-22 00:41:59,762 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28457647
2025-11-22 00:42:00,017 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/f68e588785c5f488_msaddndr.dll'
2025-11-22 00:42:00,176 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28405423
2025-11-22 00:42:00,380 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/cbe0adb0e376794d_dw20.exe.exe'
2025-11-22 00:42:00,536 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28502711
2025-11-22 00:42:00,742 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/835ba2a7e2ba3523_dwtrig20.exe.exe'
2025-11-22 00:42:00,899 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28539575
2025-11-22 00:42:01,115 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/d50c3f56300580c3_eeintl.dll.exe'
2025-11-22 00:42:01,235 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28550839
2025-11-22 00:42:01,455 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/de2257ef06a72b6d_msaddndr.dll.exe'
2025-11-22 00:42:01,575 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28409527
2025-11-22 00:42:01,808 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/845f894bd84a4bb0_eqnedt32.cnt.exe'
2025-11-22 00:42:01,980 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28506807
2025-11-22 00:42:02,220 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/44bd4dcffddf2f62_dwtrig20.exe'
2025-11-22 00:42:02,371 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28447407
2025-11-22 00:42:02,578 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/10bdde46866c04bc_eqnedt32.exe'
2025-11-22 00:42:02,712 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28473007
2025-11-22 00:42:02,950 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/ce7690c7da377ebc_dbghelp.dll.exe'
2025-11-22 00:42:03,080 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28464823
2025-11-22 00:42:03,299 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/0dba8f6fa66915a1_eqnedt32.exe.exe'
2025-11-22 00:42:03,416 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28509879
2025-11-22 00:42:03,608 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/e7ff66c358aa722d_dbghelp.dll'
2025-11-22 00:42:03,745 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28433071
2025-11-22 00:42:04,082 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/08858be15c73afc9_eqnedt32.hlp.exe'
2025-11-22 00:42:04,204 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28489399
2025-11-22 00:42:04,535 [cuckoo.core.resultserver] DEBUG: Task #7168471: File upload for 'files/ed28db55a7f306c9_eqnedt32.hlp'
2025-11-22 00:42:04,669 [cuckoo.core.resultserver] DEBUG: Task #7168471 uploaded file length: 28433071
2025-11-22 00:42:04,740 [cuckoo.core.resultserver] DEBUG: Task #7168471 had connection reset for <Context for LOG>
2025-11-22 00:42:05,316 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully
2025-11-22 00:42:05,337 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-22 00:42:05,367 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-22 00:42:06,587 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/7168471/memory.dmp
2025-11-22 00:42:06,589 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644
2025-11-22 00:44:39,217 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #7168471
2025-11-22 00:44:39,964 [cuckoo.core.scheduler] DEBUG: Released database task #7168471
2025-11-22 00:44:39,989 [cuckoo.core.scheduler] INFO: Task #7168471: analysis procedure completed