Analyzer Log
2025-04-11 16:36:47,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpqnr2dk
2025-04-11 16:36:47,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\HCHXWBZCEeezEnotPfbVJKiavtiu
2025-04-11 16:36:47,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\ckzWHAqOOBplSnPSprJNDLTD
2025-04-11 16:36:47,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-11 16:36:47,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-11 16:36:47,765 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-11 16:36:47,967 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-04-11 16:36:47,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-11 16:36:47,967 [analyzer] DEBUG: Started auxiliary module Human
2025-04-11 16:36:47,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-11 16:36:47,967 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-11 16:36:48,046 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-11 16:36:48,046 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-11 16:36:48,046 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-11 16:36:48,046 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-11 16:36:48,358 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\08285351f13299aab15669c55edf9df75d374947d6f9fa5e15d5aba9c12b1b92.exe' with arguments '' and pid 124
2025-04-11 16:36:48,546 [analyzer] DEBUG: Loaded monitor into process with pid 124
2025-04-11 16:36:48,640 [analyzer] INFO: Added new file to list with pid 124 and path C:\Users\Administrator\AppData\Local\Temp\is-7P0U9.tmp\08285351f13299aab15669c55edf9df75d374947d6f9fa5e15d5aba9c12b1b92.tmp
2025-04-11 16:36:48,765 [analyzer] INFO: Injected into process with pid 328 and name ''
2025-04-11 16:36:48,953 [analyzer] DEBUG: Loaded monitor into process with pid 328
2025-04-11 16:36:49,046 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Temp\is-UNDS4.tmp\_isetup\_RegDLL.tmp
2025-04-11 16:36:49,062 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Temp\is-UNDS4.tmp\_isetup\_setup64.tmp
2025-04-11 16:36:49,078 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Temp\is-UNDS4.tmp\_isetup\_shfoldr.dll
2025-04-11 16:36:49,155 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Temp\is-UNDS4.tmp\_isetup\_iscrypt.dll
2025-04-11 16:36:50,405 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\uninstall\is-991LH.tmp
2025-04-11 16:36:50,437 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-IPQ0R.tmp
2025-04-11 16:36:50,578 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-FT6MJ.tmp
2025-04-11 16:36:50,703 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-91CLL.tmp
2025-04-11 16:36:50,717 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-9GJC5.tmp
2025-04-11 16:36:50,812 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-I394T.tmp
2025-04-11 16:36:50,842 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-SI39T.tmp
2025-04-11 16:36:50,937 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-P4GH6.tmp
2025-04-11 16:36:51,000 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-E0ESR.tmp
2025-04-11 16:36:51,015 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-BQRRB.tmp
2025-04-11 16:36:51,405 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-9KE95.tmp
2025-04-11 16:36:51,671 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-4TAOF.tmp
2025-04-11 16:36:51,703 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\is-R92OB.tmp
2025-04-11 16:36:52,483 [analyzer] INFO: Added new file to list with pid 328 and path C:\Users\Administrator\AppData\Local\Eraser Free 3.1.2.773\uninstall\unins000.dat
2025-04-11 16:37:17,358 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-04-11 16:37:18,000 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-04-11 16:37:18,000 [lib.api.process] INFO: Successfully terminated process with pid 124.
2025-04-11 16:37:18,000 [lib.api.process] INFO: Successfully terminated process with pid 328.
2025-04-11 16:37:18,608 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-04-14 10:54:12,676 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:13,719 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:14,751 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:15,784 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:16,832 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:17,854 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:19,001 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:20,040 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:21,070 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:22,098 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:23,432 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:24,458 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:25,477 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:26,499 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:27,527 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:28,555 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:29,586 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:30,626 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:31,660 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:32,902 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:33,944 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:34,980 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:36,017 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:37,056 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:38,465 [cuckoo.core.scheduler] DEBUG: Task #6279663: no machine available yet
2025-04-14 10:54:39,540 [cuckoo.core.scheduler] INFO: Task #6279663: acquired machine win7x6415 (label=win7x6415)
2025-04-14 10:54:39,544 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.215 for task #6279663
2025-04-14 10:54:40,005 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1052177 (interface=vboxnet0, host=192.168.168.215)
2025-04-14 10:54:57,351 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6415
2025-04-14 10:54:58,012 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6415 to vmcloak
2025-04-14 10:57:53,996 [cuckoo.core.guest] INFO: Starting analysis #6279663 on guest (id=win7x6415, ip=192.168.168.215)
2025-04-14 10:57:55,011 [cuckoo.core.guest] DEBUG: win7x6415: not ready yet
2025-04-14 10:58:00,071 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6415, ip=192.168.168.215)
2025-04-14 10:58:00,572 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6415, ip=192.168.168.215, monitor=latest, size=6660546)
2025-04-14 10:58:02,519 [cuckoo.core.resultserver] DEBUG: Task #6279663: live log analysis.log initialized.
2025-04-14 10:58:03,406 [cuckoo.core.resultserver] DEBUG: Task #6279663 is sending a BSON stream
2025-04-14 10:58:03,968 [cuckoo.core.resultserver] DEBUG: Task #6279663 is sending a BSON stream
2025-04-14 10:58:04,375 [cuckoo.core.resultserver] DEBUG: Task #6279663 is sending a BSON stream
2025-04-14 10:58:04,718 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'shots/0001.jpg'
2025-04-14 10:58:04,757 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 134017
2025-04-14 10:58:15,189 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'shots/0002.jpg'
2025-04-14 10:58:15,206 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 89604
2025-04-14 10:58:16,310 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'shots/0003.jpg'
2025-04-14 10:58:16,323 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 90048
2025-04-14 10:58:17,307 [cuckoo.core.guest] DEBUG: win7x6415: analysis #6279663 still processing
2025-04-14 10:58:17,418 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'shots/0004.jpg'
2025-04-14 10:58:17,428 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 90502
2025-04-14 10:58:18,524 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'shots/0005.jpg'
2025-04-14 10:58:18,533 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 90898
2025-04-14 10:58:32,611 [cuckoo.core.guest] DEBUG: win7x6415: analysis #6279663 still processing
2025-04-14 10:58:33,300 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'curtain/1744382237.62.curtain.log'
2025-04-14 10:58:33,305 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 36
2025-04-14 10:58:33,474 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'sysmon/1744382237.97.sysmon.xml'
2025-04-14 10:58:33,508 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 1772414
2025-04-14 10:58:33,535 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/173092c4e256958b_icuin51.dll'
2025-04-14 10:58:33,557 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 1767424
2025-04-14 10:58:33,565 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/d769fafa2b3232de_msvcp100.dll'
2025-04-14 10:58:33,569 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 421200
2025-04-14 10:58:33,614 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/142ace346cce444f_eraserfree773.exe'
2025-04-14 10:58:33,810 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 4274596
2025-04-14 10:58:33,823 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/16574f51785b0e2f_sqlite3.dll'
2025-04-14 10:58:33,829 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 645592
2025-04-14 10:58:33,847 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/2357806ca24c9d31_icuuc51.dll'
2025-04-14 10:58:33,861 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 1295872
2025-04-14 10:58:33,875 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/60c06e0fa4449314_msvcr100.dll'
2025-04-14 10:58:33,881 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 773968
2025-04-14 10:58:33,912 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/102ff5ae82519ef1_qt5gui.dll'
2025-04-14 10:58:33,933 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 2924032
2025-04-14 10:58:33,941 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/2f6294f9aa09f59a__iscrypt.dll'
2025-04-14 10:58:33,943 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 2560
2025-04-14 10:58:33,944 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/32b0acdf551507b4_qt5concurrent.dll'
2025-04-14 10:58:33,945 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 18432
2025-04-14 10:58:33,948 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/4dc09bac0613590f__regdll.tmp'
2025-04-14 10:58:33,949 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 4096
2025-04-14 10:58:33,987 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/b262e859ce82479e_qt5core.dll'
2025-04-14 10:58:34,036 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 3853824
2025-04-14 10:58:34,046 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/a4c86fc4836ac728__setup64.tmp'
2025-04-14 10:58:34,047 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 6144
2025-04-14 10:58:34,058 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/06bbe605d7b0ef04_libglesv2.dll'
2025-04-14 10:58:34,065 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/ded70e77dd752ae3_unins000.dat'
2025-04-14 10:58:34,066 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 6334
2025-04-14 10:58:34,068 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 728576
2025-04-14 10:58:34,071 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/ee1d7d8f396d627f_libegl.dll'
2025-04-14 10:58:34,073 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 48128
2025-04-14 10:58:34,084 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/ca6f64a587941fd3_08285351f13299aab15669c55edf9df75d374947d6f9fa5e15d5aba9c12b1b92.tmp'
2025-04-14 10:58:34,091 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 693760
2025-04-14 10:58:34,094 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/ff6507a53076a9c3_qt5printsupport.dll'
2025-04-14 10:58:34,097 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 226304
2025-04-14 10:58:34,099 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/9884e9d1b4f8a873__shfoldr.dll'
2025-04-14 10:58:34,100 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 23312
2025-04-14 10:58:34,111 [cuckoo.core.resultserver] DEBUG: Task #6279663: File upload for 'files/0f1fde1b1a2e86f3_unins000.exe'
2025-04-14 10:58:34,119 [cuckoo.core.resultserver] DEBUG: Task #6279663 uploaded file length: 704282
2025-04-14 10:58:34,137 [cuckoo.core.resultserver] DEBUG: Task #6279663 had connection reset for <Context for LOG>
2025-04-14 10:58:35,627 [cuckoo.core.guest] INFO: win7x6415: analysis completed successfully
2025-04-14 10:58:35,641 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-04-14 10:58:35,670 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-04-14 10:58:36,725 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6415 to path /srv/cuckoo/cwd/storage/analyses/6279663/memory.dmp
2025-04-14 10:58:36,726 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6415
2025-04-14 11:01:59,211 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.215 for task #6279663
2025-04-14 11:02:00,349 [cuckoo.core.scheduler] DEBUG: Released database task #6279663
2025-04-14 11:02:10,858 [cuckoo.core.scheduler] INFO: Task #6279663: analysis procedure completed