Analyzer Log
2025-03-24 20:15:29,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpk4d6bl
2025-03-24 20:15:29,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\DvBdELOvVJFRRquOVmMhkM
2025-03-24 20:15:29,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\haOZHWqDojLaiIKsyaQT
2025-03-24 20:15:29,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-03-24 20:15:29,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-03-24 20:15:29,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-03-24 20:15:29,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-03-24 20:15:29,750 [analyzer] DEBUG: Started auxiliary module Disguise
2025-03-24 20:15:29,967 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-03-24 20:15:29,983 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-03-24 20:15:29,983 [analyzer] DEBUG: Started auxiliary module Human
2025-03-24 20:15:29,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-03-24 20:15:30,000 [analyzer] DEBUG: Started auxiliary module Reboot
2025-03-24 20:15:30,092 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-03-24 20:15:30,092 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-03-24 20:15:30,092 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-03-24 20:15:30,092 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-03-24 20:15:30,233 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\9dfc02225dd9e28b_bkgrnd.exe' with arguments '' and pid 844
2025-03-24 20:15:30,405 [analyzer] DEBUG: Loaded monitor into process with pid 844
2025-03-24 20:15:30,453 [analyzer] INFO: Added new file to list with pid 844 and path C:\Users\Administrator\AppData\Local\Temp\bkgrnd.exe
2025-03-24 20:15:30,578 [analyzer] INFO: Injected into process with pid 2000 and name u'bkgrnd.exe'
2025-03-24 20:15:30,733 [analyzer] DEBUG: Loaded monitor into process with pid 2000
2025-03-24 20:15:31,233 [analyzer] INFO: Process with pid 844 has terminated
2025-03-24 20:15:48,546 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
2025-03-24 20:15:48,562 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
2025-03-24 20:15:48,703 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-03-24 20:15:48,703 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-03-24 20:15:49,905 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2025-03-24 20:15:49,905 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2025-03-24 20:15:49,921 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\Local\Temp\Tar8F22.tmp
2025-03-24 20:15:50,015 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\Local\Temp\Tar8F82.tmp
2025-03-24 20:15:50,171 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-03-24 20:15:50,187 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-03-24 20:15:50,233 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2025-03-24 20:15:50,233 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2025-03-24 20:17:54,875 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F0ACCF77CDCBFF39F6191887F6D2D357
2025-03-24 20:17:54,875 [analyzer] INFO: Added new file to list with pid 2000 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F0ACCF77CDCBFF39F6191887F6D2D357
2025-03-24 20:18:49,250 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-03-24 20:18:51,125 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-03-24 20:18:51,125 [lib.api.process] INFO: Successfully terminated process with pid 2000.
2025-03-24 20:18:51,140 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8f22.tmp' does not exist, skip.
2025-03-24 20:18:51,140 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8f82.tmp' does not exist, skip.
2025-03-24 20:18:51,187 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-03-26 00:32:39,074 [cuckoo.core.scheduler] INFO: Task #6157412: acquired machine win7x6422 (label=win7x6422)
2025-03-26 00:32:39,075 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.222 for task #6157412
2025-03-26 00:32:39,649 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3098669 (interface=vboxnet0, host=192.168.168.222)
2025-03-26 00:32:39,705 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6422
2025-03-26 00:32:40,432 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6422 to vmcloak
2025-03-26 00:36:00,174 [cuckoo.core.guest] INFO: Starting analysis #6157412 on guest (id=win7x6422, ip=192.168.168.222)
2025-03-26 00:36:01,179 [cuckoo.core.guest] DEBUG: win7x6422: not ready yet
2025-03-26 00:36:06,207 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6422, ip=192.168.168.222)
2025-03-26 00:36:06,279 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6422, ip=192.168.168.222, monitor=latest, size=6660546)
2025-03-26 00:36:07,695 [cuckoo.core.resultserver] DEBUG: Task #6157412: live log analysis.log initialized.
2025-03-26 00:36:08,610 [cuckoo.core.resultserver] DEBUG: Task #6157412 is sending a BSON stream
2025-03-26 00:36:09,213 [cuckoo.core.resultserver] DEBUG: Task #6157412 is sending a BSON stream
2025-03-26 00:36:09,360 [cuckoo.core.resultserver] DEBUG: Task #6157412 is sending a BSON stream
2025-03-26 00:36:10,061 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'shots/0001.jpg'
2025-03-26 00:36:10,102 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 133470
2025-03-26 00:36:22,984 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:36:38,893 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:36:54,312 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:37:10,491 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:37:25,593 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:37:40,738 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:37:56,065 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:38:11,318 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:38:26,619 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:38:42,344 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:38:57,493 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:39:12,794 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:39:28,163 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6157412 still processing
2025-03-26 00:39:28,229 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'curtain/1742843929.52.curtain.log'
2025-03-26 00:39:28,232 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 36
2025-03-26 00:39:29,670 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'sysmon/1742843930.95.sysmon.xml'
2025-03-26 00:39:29,838 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 17528182
2025-03-26 00:39:29,868 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/df545bf919a2439c_f0accf77cdcbff39f6191887f6d2d357'
2025-03-26 00:39:29,871 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 1521
2025-03-26 00:39:29,872 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/d72761e1a334a754_94308059b57b3142e455b38a6eb92015'
2025-03-26 00:39:29,874 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/f157ed17fcaf8837_b46811c17859ffb409cf0e904a4aa8f8'
2025-03-26 00:39:29,877 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 436
2025-03-26 00:39:29,878 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/d86bbbb92ecd5e48_8b2b9a00839eed1dfdccc3bfc2f5df12'
2025-03-26 00:39:29,880 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 174
2025-03-26 00:39:29,881 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3'
2025-03-26 00:39:29,883 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 889
2025-03-26 00:39:29,884 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 73305
2025-03-26 00:39:29,886 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/96bcec06264976f3_2d85f72862b55c4eadd9e66e06947f3d'
2025-03-26 00:39:29,887 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 1391
2025-03-26 00:39:29,889 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/3b8abf93b8accb28_94308059b57b3142e455b38a6eb92015'
2025-03-26 00:39:29,890 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 344
2025-03-26 00:39:29,892 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/5243e0b7703bfd19_bkgrnd.exe'
2025-03-26 00:39:29,894 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 47674
2025-03-26 00:39:29,896 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/c13e8d22800c2009_8b2b9a00839eed1dfdccc3bfc2f5df12'
2025-03-26 00:39:29,897 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 1739
2025-03-26 00:39:29,899 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/1e94e1bbd203c01d_f0accf77cdcbff39f6191887f6d2d357'
2025-03-26 00:39:29,901 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 242
2025-03-26 00:39:29,902 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/dad288998df978e8_2d85f72862b55c4eadd9e66e06947f3d'
2025-03-26 00:39:29,904 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 192
2025-03-26 00:39:29,905 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/724a9ab64cdc0c0d_14232b434cf29d4c4fb335a86d7fffe3'
2025-03-26 00:39:29,907 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 170
2025-03-26 00:39:29,909 [cuckoo.core.resultserver] DEBUG: Task #6157412: File upload for 'files/a2c8f0aed5286351_b46811c17859ffb409cf0e904a4aa8f8'
2025-03-26 00:39:29,911 [cuckoo.core.resultserver] DEBUG: Task #6157412 uploaded file length: 170
2025-03-26 00:39:29,915 [cuckoo.core.resultserver] DEBUG: Task #6157412 had connection reset for <Context for LOG>
2025-03-26 00:39:31,186 [cuckoo.core.guest] INFO: win7x6422: analysis completed successfully
2025-03-26 00:39:31,198 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-03-26 00:39:31,227 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-03-26 00:39:32,678 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6422 to path /srv/cuckoo/cwd/storage/analyses/6157412/memory.dmp
2025-03-26 00:39:32,697 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6422
2025-03-26 00:41:59,863 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.222 for task #6157412
2025-03-26 00:42:00,574 [cuckoo.core.scheduler] DEBUG: Released database task #6157412
2025-03-26 00:42:07,269 [cuckoo.core.scheduler] INFO: Task #6157412: analysis procedure completed