Analyzer Log
2025-01-25 08:13:43,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpl4240h
2025-01-25 08:13:43,000 [analyzer] DEBUG: Pipe server name: \??\PIPE\doQEOOeGelfNzylmzFkdSffBCy
2025-01-25 08:13:43,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\OnnjejpHxRZVHxJRZJhToIbjdFYmyqUr
2025-01-25 08:13:43,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-01-25 08:13:43,015 [analyzer] INFO: Automatically selected analysis package "zip"
2025-01-25 08:13:43,342 [analyzer] DEBUG: Started auxiliary module Curtain
2025-01-25 08:13:43,342 [analyzer] DEBUG: Started auxiliary module DbgView
2025-01-25 08:13:43,750 [analyzer] DEBUG: Started auxiliary module Disguise
2025-01-25 08:13:43,967 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-01-25 08:13:43,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-01-25 08:13:43,967 [analyzer] DEBUG: Started auxiliary module Human
2025-01-25 08:13:43,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-01-25 08:13:43,967 [analyzer] DEBUG: Started auxiliary module Reboot
2025-01-25 08:13:44,046 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-01-25 08:13:44,046 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-01-25 08:13:44,062 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-01-25 08:13:44,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-01-25 08:13:44,062 [modules.packages.zip] DEBUG: Missing file option, auto executing: Readme.exe
2025-01-25 08:13:44,187 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\Readme.exe' with arguments '' and pid 2488
2025-01-25 08:13:44,390 [analyzer] DEBUG: Loaded monitor into process with pid 2488
2025-01-25 08:13:44,390 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\SysWOW64\ctfmen.exe
2025-01-25 08:13:44,437 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\SysWOW64\shervans.dll
2025-01-25 08:13:44,453 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\SysWOW64\grcopy.dll
2025-01-25 08:13:44,530 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\SysWOW64\satornas.dll
2025-01-25 08:13:48,592 [analyzer] INFO: Injected into process with pid 1316 and name u'ctfmen.exe'
2025-01-25 08:13:48,733 [analyzer] DEBUG: Loaded monitor into process with pid 1316
2025-01-25 08:13:48,796 [analyzer] INFO: Injected into process with pid 2276 and name u'smnss.exe'
2025-01-25 08:13:48,967 [analyzer] DEBUG: Loaded monitor into process with pid 2276
2025-01-25 08:13:48,967 [analyzer] INFO: Added new file to list with pid 2276 and path C:\Windows\SysWOW64\zipfi.dll
2025-01-25 08:13:49,062 [analyzer] INFO: Added new file to list with pid 2276 and path C:\Windows\SysWOW64\zipfiaq.dll
2025-01-25 08:13:49,187 [analyzer] INFO: Process with pid 2488 has terminated
2025-01-25 08:13:50,187 [analyzer] INFO: Process with pid 1316 has terminated
2025-01-25 08:14:06,187 [analyzer] INFO: Process with pid 2276 has terminated
2025-01-25 08:14:06,187 [analyzer] INFO: Process list is empty, terminating analysis.
2025-01-25 08:14:07,578 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-01-25 08:14:07,608 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-01-29 12:32:38,134 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:39,194 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:40,240 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:41,310 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:42,370 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:43,403 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:44,438 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:45,465 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:46,491 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:47,533 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:48,567 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:49,601 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:50,638 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:51,667 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:52,705 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:53,737 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:54,770 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:55,953 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:57,001 [cuckoo.core.scheduler] DEBUG: Task #5848427: no machine available yet
2025-01-29 12:32:58,093 [cuckoo.core.scheduler] INFO: Task #5848427: acquired machine win7x649 (label=win7x649)
2025-01-29 12:32:58,208 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.209 for task #5848427
2025-01-29 12:32:58,584 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1436026 (interface=vboxnet0, host=192.168.168.209)
2025-01-29 12:32:58,609 [androguard.apk] WARNING: Missing AndroidManifest.xml. Is this an APK file?
2025-01-29 12:32:58,670 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x649
2025-01-29 12:32:59,653 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x649 to vmcloak
2025-01-29 12:35:24,131 [cuckoo.core.guest] INFO: Starting analysis #5848427 on guest (id=win7x649, ip=192.168.168.209)
2025-01-29 12:35:25,136 [cuckoo.core.guest] DEBUG: win7x649: not ready yet
2025-01-29 12:35:30,159 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x649, ip=192.168.168.209)
2025-01-29 12:35:30,284 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x649, ip=192.168.168.209, monitor=latest, size=6660546)
2025-01-29 12:35:31,488 [cuckoo.core.resultserver] DEBUG: Task #5848427: live log analysis.log initialized.
2025-01-29 12:35:32,487 [cuckoo.core.resultserver] DEBUG: Task #5848427 is sending a BSON stream
2025-01-29 12:35:32,819 [cuckoo.core.resultserver] DEBUG: Task #5848427 is sending a BSON stream
2025-01-29 12:35:33,661 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'shots/0001.jpg'
2025-01-29 12:35:33,672 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 133465
2025-01-29 12:35:37,173 [cuckoo.core.resultserver] DEBUG: Task #5848427 is sending a BSON stream
2025-01-29 12:35:37,391 [cuckoo.core.resultserver] DEBUG: Task #5848427 is sending a BSON stream
2025-01-29 12:35:46,943 [cuckoo.core.guest] DEBUG: win7x649: analysis #5848427 still processing
2025-01-29 12:35:55,888 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'curtain/1737789247.38.curtain.log'
2025-01-29 12:35:55,893 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 36
2025-01-29 12:35:56,067 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'sysmon/1737789247.53.sysmon.xml'
2025-01-29 12:35:56,201 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 1555094
2025-01-29 12:35:56,223 [cuckoo.core.resultserver] DEBUG: Task #5848427 had connection reset for <Context for LOG>
2025-01-29 12:35:56,234 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'files/de28df3e89f794d4_grcopy.dll'
2025-01-29 12:35:56,240 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 77445
2025-01-29 12:35:56,248 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'files/ba207b4a26b4f41e_zipfi.dll'
2025-01-29 12:35:56,256 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 77563
2025-01-29 12:35:56,266 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'files/183a2d03a872891c_ctfmen.exe'
2025-01-29 12:35:56,280 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 4160
2025-01-29 12:35:56,283 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'files/96bc0520373ce88b_zipfiaq.dll'
2025-01-29 12:35:56,288 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 77559
2025-01-29 12:35:56,290 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'files/f87c062af889854e_satornas.dll'
2025-01-29 12:35:56,294 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 183
2025-01-29 12:35:56,297 [cuckoo.core.resultserver] DEBUG: Task #5848427: File upload for 'files/7a3d3de3f670f4bf_shervans.dll'
2025-01-29 12:35:56,302 [cuckoo.core.resultserver] DEBUG: Task #5848427 uploaded file length: 8704
2025-01-29 12:35:59,093 [cuckoo.core.guest] INFO: win7x649: analysis completed successfully
2025-01-29 12:35:59,129 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-01-29 12:35:59,158 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-01-29 12:36:00,120 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x649 to path /srv/cuckoo/cwd/storage/analyses/5848427/memory.dmp
2025-01-29 12:36:00,123 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x649
2025-01-29 12:37:32,859 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.209 for task #5848427
2025-01-29 12:37:33,816 [cuckoo.core.scheduler] DEBUG: Released database task #5848427
2025-01-29 12:37:33,849 [cuckoo.core.scheduler] INFO: Task #5848427: analysis procedure completed