Analyzer Log
2024-12-15 08:45:56,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4
2024-12-15 08:45:56,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\ggqsLmEUNSdBrBhec
2024-12-15 08:45:56,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\SIriQuIRTxRQoLTPKoSEwCWTZArTFr
2024-12-15 08:45:56,375 [analyzer] DEBUG: Started auxiliary module Curtain
2024-12-15 08:45:56,375 [analyzer] DEBUG: Started auxiliary module DbgView
2024-12-15 08:45:56,890 [analyzer] DEBUG: Started auxiliary module Disguise
2024-12-15 08:45:57,125 [analyzer] DEBUG: Loaded monitor into process with pid 504
2024-12-15 08:45:57,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2024-12-15 08:45:57,125 [analyzer] DEBUG: Started auxiliary module Human
2024-12-15 08:45:57,125 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2024-12-15 08:45:57,125 [analyzer] DEBUG: Started auxiliary module Reboot
2024-12-15 08:45:57,203 [analyzer] DEBUG: Started auxiliary module RecentFiles
2024-12-15 08:45:57,217 [analyzer] DEBUG: Started auxiliary module Screenshots
2024-12-15 08:45:57,217 [analyzer] DEBUG: Started auxiliary module Sysmon
2024-12-15 08:45:57,217 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2024-12-15 08:45:57,328 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\update.exe' with arguments '' and pid 1808
2024-12-15 08:45:57,562 [analyzer] DEBUG: Loaded monitor into process with pid 1808
2024-12-15 08:45:57,592 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:57,733 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,062 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,062 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,108 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,187 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,203 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,203 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,203 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,203 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,328 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 7 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,375 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 9 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,375 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,375 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)!
2024-12-15 08:45:58,375 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc0000045)!
2024-12-15 08:46:54,408 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2024-12-15 08:46:54,815 [analyzer] INFO: Terminating remaining processes before shutdown.
2024-12-15 08:46:54,815 [lib.api.process] INFO: Successfully terminated process with pid 1808.
2024-12-15 08:46:54,815 [analyzer] INFO: Analysis completed.
Cuckoo Log
2024-12-15 09:46:03,092 [cuckoo.core.scheduler] INFO: Task #5661820: acquired machine win7x644 (label=win7x644)
2024-12-15 09:46:03,093 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #5661820
2024-12-15 09:46:03,546 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1433847 (interface=vboxnet0, host=192.168.168.204)
2024-12-15 09:46:03,674 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644
2024-12-15 09:46:04,388 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak
2024-12-15 09:46:16,555 [cuckoo.core.guest] INFO: Starting analysis #5661820 on guest (id=win7x644, ip=192.168.168.204)
2024-12-15 09:46:17,560 [cuckoo.core.guest] DEBUG: win7x644: not ready yet
2024-12-15 09:46:22,584 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204)
2024-12-15 09:46:22,669 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546)
2024-12-15 09:46:24,052 [cuckoo.core.resultserver] DEBUG: Task #5661820: live log analysis.log initialized.
2024-12-15 09:46:25,127 [cuckoo.core.resultserver] DEBUG: Task #5661820 is sending a BSON stream
2024-12-15 09:46:25,455 [cuckoo.core.resultserver] DEBUG: Task #5661820 is sending a BSON stream
2024-12-15 09:46:26,411 [cuckoo.core.resultserver] DEBUG: Task #5661820: File upload for 'shots/0001.jpg'
2024-12-15 09:46:26,433 [cuckoo.core.resultserver] DEBUG: Task #5661820 uploaded file length: 133525
2024-12-15 09:46:38,645 [cuckoo.core.guest] DEBUG: win7x644: analysis #5661820 still processing
2024-12-15 09:46:53,754 [cuckoo.core.guest] DEBUG: win7x644: analysis #5661820 still processing
2024-12-15 09:46:54,695 [cuckoo.core.resultserver] DEBUG: Task #5661820: File upload for 'curtain/1734248814.69.curtain.log'
2024-12-15 09:46:54,697 [cuckoo.core.resultserver] DEBUG: Task #5661820 uploaded file length: 36
2024-12-15 09:46:54,815 [cuckoo.core.resultserver] DEBUG: Task #5661820: File upload for 'sysmon/1734248814.82.sysmon.xml'
2024-12-15 09:46:54,819 [cuckoo.core.resultserver] DEBUG: Task #5661820 uploaded file length: 175502
2024-12-15 09:46:55,322 [cuckoo.core.resultserver] DEBUG: Task #5661820 had connection reset for <Context for LOG>
2024-12-15 09:46:56,770 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully
2024-12-15 09:46:56,790 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2024-12-15 09:46:56,819 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2024-12-15 09:46:58,072 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/5661820/memory.dmp
2024-12-15 09:46:58,073 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644
2024-12-15 09:47:06,154 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #5661820
2024-12-15 09:47:06,459 [cuckoo.core.scheduler] DEBUG: Released database task #5661820
2024-12-15 09:47:06,478 [cuckoo.core.scheduler] INFO: Task #5661820: analysis procedure completed