Analyzer Log
2025-11-16 14:35:12,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4
2025-11-16 14:35:12,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\pIhXfuPrdOzXJAJY
2025-11-16 14:35:12,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\OBpiepKRTgziWnCu
2025-11-16 14:35:12,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-11-16 14:35:12,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-11-16 14:35:12,265 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-16 14:35:12,265 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-16 14:35:12,671 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-16 14:35:12,890 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-11-16 14:35:12,890 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-16 14:35:12,890 [analyzer] DEBUG: Started auxiliary module Human
2025-11-16 14:35:12,890 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-16 14:35:12,890 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-16 14:35:13,000 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-16 14:35:13,000 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-16 14:35:13,000 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-16 14:35:13,000 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-16 14:35:13,140 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\9d1cfc0f6513f75c_backup.exe' with arguments '' and pid 1392
2025-11-16 14:35:13,328 [analyzer] DEBUG: Loaded monitor into process with pid 1392
2025-11-16 14:35:13,390 [analyzer] INFO: Added new file to list with pid 1392 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-11-16 14:35:13,405 [analyzer] INFO: Added new file to list with pid 1392 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\update.exe
2025-11-16 14:35:13,453 [analyzer] INFO: Injected into process with pid 2924 and name ''
2025-11-16 14:35:13,703 [analyzer] DEBUG: Loaded monitor into process with pid 2924
2025-11-16 14:35:13,765 [analyzer] INFO: Added new file to list with pid 1392 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\update.exe
2025-11-16 14:35:13,858 [analyzer] INFO: Added new file to list with pid 1392 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-11-16 14:35:14,733 [analyzer] INFO: Added new file to list with pid 2924 and path C:\backup.exe
2025-11-16 14:38:32,155 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-16 14:38:33,203 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-16 14:38:33,203 [lib.api.process] INFO: Successfully terminated process with pid 1392.
2025-11-16 14:38:33,203 [lib.api.process] INFO: Successfully terminated process with pid 2924.
2025-11-16 14:38:33,217 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-11-23 12:12:57,884 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:12:58,926 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:12:59,951 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:00,990 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:02,015 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:03,036 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:04,060 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:05,086 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:06,104 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:07,197 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:08,217 [cuckoo.core.scheduler] DEBUG: Task #7184563: no machine available yet
2025-11-23 12:13:09,240 [cuckoo.core.scheduler] INFO: Task #7184563: acquired machine win7x644 (label=win7x644)
2025-11-23 12:13:09,241 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #7184563
2025-11-23 12:13:09,548 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3894332 (interface=vboxnet0, host=192.168.168.204)
2025-11-23 12:13:09,668 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644
2025-11-23 12:13:10,683 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak
2025-11-23 12:15:13,230 [cuckoo.core.guest] INFO: Starting analysis #7184563 on guest (id=win7x644, ip=192.168.168.204)
2025-11-23 12:15:14,233 [cuckoo.core.guest] DEBUG: win7x644: not ready yet
2025-11-23 12:15:19,253 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204)
2025-11-23 12:15:19,309 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546)
2025-11-23 12:15:20,423 [cuckoo.core.resultserver] DEBUG: Task #7184563: live log analysis.log initialized.
2025-11-23 12:15:21,255 [cuckoo.core.resultserver] DEBUG: Task #7184563 is sending a BSON stream
2025-11-23 12:15:21,763 [cuckoo.core.resultserver] DEBUG: Task #7184563 is sending a BSON stream
2025-11-23 12:15:22,050 [cuckoo.core.resultserver] DEBUG: Task #7184563 is sending a BSON stream
2025-11-23 12:15:22,632 [cuckoo.core.resultserver] DEBUG: Task #7184563: File upload for 'shots/0001.jpg'
2025-11-23 12:15:22,807 [cuckoo.core.resultserver] DEBUG: Task #7184563 uploaded file length: 133533
2025-11-23 12:15:35,370 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:15:50,967 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:16:06,208 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:16:21,328 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:16:36,468 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:16:51,563 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:17:06,659 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:17:21,735 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:17:36,856 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:17:51,928 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:18:07,004 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:18:22,082 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:18:37,161 [cuckoo.core.guest] DEBUG: win7x644: analysis #7184563 still processing
2025-11-23 12:18:40,774 [cuckoo.core.resultserver] DEBUG: Task #7184563: File upload for 'curtain/1763300312.34.curtain.log'
2025-11-23 12:18:40,777 [cuckoo.core.resultserver] DEBUG: Task #7184563 uploaded file length: 36
2025-11-23 12:18:41,543 [cuckoo.core.resultserver] DEBUG: Task #7184563: File upload for 'sysmon/1763300313.11.sysmon.xml'
2025-11-23 12:18:41,636 [cuckoo.core.resultserver] DEBUG: Task #7184563 uploaded file length: 10332660
2025-11-23 12:18:41,655 [cuckoo.core.resultserver] DEBUG: Task #7184563: File upload for 'files/a54395b461a0f279_backup.exe'
2025-11-23 12:18:41,658 [cuckoo.core.resultserver] DEBUG: Task #7184563: File upload for 'files/fb70ce4652a2509d_backup.exe'
2025-11-23 12:18:41,659 [cuckoo.core.resultserver] DEBUG: Task #7184563 uploaded file length: 91913
2025-11-23 12:18:41,663 [cuckoo.core.resultserver] DEBUG: Task #7184563 uploaded file length: 91915
2025-11-23 12:18:41,674 [cuckoo.core.resultserver] DEBUG: Task #7184563 had connection reset for <Context for LOG>
2025-11-23 12:18:43,192 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully
2025-11-23 12:18:43,201 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-23 12:18:43,229 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-23 12:18:44,163 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/7184563/memory.dmp
2025-11-23 12:18:44,164 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644
2025-11-23 12:19:58,152 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #7184563
2025-11-23 12:19:58,646 [cuckoo.core.scheduler] DEBUG: Released database task #7184563
2025-11-23 12:19:58,671 [cuckoo.core.scheduler] INFO: Task #7184563: analysis procedure completed