Analyzer Log
2025-05-05 12:11:15,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdyrg_l
2025-05-05 12:11:15,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\wzdbtsSZVmoiAgdaI
2025-05-05 12:11:15,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\GkGDKuvVAAeZyTLOkiDeNQLyhSs
2025-05-05 12:11:15,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-05-05 12:11:15,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-05-05 12:11:15,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-05-05 12:11:15,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-05-05 12:11:15,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-05-05 12:11:16,015 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-05-05 12:11:16,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-05-05 12:11:16,015 [analyzer] DEBUG: Started auxiliary module Human
2025-05-05 12:11:16,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-05-05 12:11:16,015 [analyzer] DEBUG: Started auxiliary module Reboot
2025-05-05 12:11:16,078 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-05-05 12:11:16,078 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-05-05 12:11:16,078 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-05-05 12:11:16,078 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-05-05 12:11:16,265 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\604dc2651140b591_adobe_updater.exe' with arguments '' and pid 1372
2025-05-05 12:11:16,530 [analyzer] DEBUG: Loaded monitor into process with pid 1372
2025-05-05 12:11:16,655 [analyzer] INFO: Added new file to list with pid 1372 and path C:\Users\Administrator\AppData\Local\Adobe\Updater6\AdobeUpdaterPrefs.dat
2025-05-05 12:11:16,671 [analyzer] INFO: Added new file to list with pid 1372 and path C:\Users\Administrator\AppData\Local\Adobe\Updater6\aum.log
2025-05-05 12:11:17,015 [analyzer] INFO: Added new file to list with pid 1372 and path C:\Users\Administrator\AppData\Local\Adobe\Updater6\AUTrans.xml_
2025-05-05 12:11:17,046 [analyzer] INFO: Added new file to list with pid 1372 and path C:\Users\Administrator\AppData\Local\Adobe\Updater6\AUTrans.sig
2025-05-05 12:14:35,296 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-05-05 12:14:36,592 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-05-05 12:14:36,592 [lib.api.process] INFO: Successfully terminated process with pid 1372.
2025-05-05 12:14:36,625 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-05-11 04:23:10,130 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:11,162 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:12,195 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:13,217 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:14,244 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:15,281 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:16,306 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:17,332 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:18,358 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:19,385 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:20,409 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:21,533 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:22,575 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:23,619 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:24,670 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:25,714 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:26,757 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:27,833 [cuckoo.core.scheduler] DEBUG: Task #6433789: no machine available yet
2025-05-11 04:23:29,156 [cuckoo.core.scheduler] INFO: Task #6433789: acquired machine win7x6430 (label=win7x6430)
2025-05-11 04:23:29,160 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.230 for task #6433789
2025-05-11 04:23:29,418 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3413200 (interface=vboxnet0, host=192.168.168.230)
2025-05-11 04:23:32,532 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6430
2025-05-11 04:23:32,987 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6430 to vmcloak
2025-05-11 04:25:45,750 [cuckoo.core.guest] INFO: Starting analysis #6433789 on guest (id=win7x6430, ip=192.168.168.230)
2025-05-11 04:25:46,755 [cuckoo.core.guest] DEBUG: win7x6430: not ready yet
2025-05-11 04:25:51,779 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6430, ip=192.168.168.230)
2025-05-11 04:25:51,846 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6430, ip=192.168.168.230, monitor=latest, size=6660546)
2025-05-11 04:25:53,312 [cuckoo.core.resultserver] DEBUG: Task #6433789: live log analysis.log initialized.
2025-05-11 04:25:54,261 [cuckoo.core.resultserver] DEBUG: Task #6433789 is sending a BSON stream
2025-05-11 04:25:54,758 [cuckoo.core.resultserver] DEBUG: Task #6433789 is sending a BSON stream
2025-05-11 04:25:55,345 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'files/d7d1d900e0da4705_AUTrans.xml_'
2025-05-11 04:25:55,349 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 261
2025-05-11 04:25:55,361 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'files/e3b0c44298fc1c14_AdobeUpdater.aum'
2025-05-11 04:25:55,363 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 0
2025-05-11 04:25:55,493 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'shots/0001.jpg'
2025-05-11 04:25:55,508 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 133515
2025-05-11 04:25:56,606 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'shots/0002.jpg'
2025-05-11 04:25:56,623 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 138690
2025-05-11 04:26:07,926 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:26:23,096 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:26:38,414 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:26:53,514 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:27:08,652 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:27:23,734 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:27:38,851 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:27:54,007 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:28:09,121 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:28:24,211 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:28:39,554 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:28:54,699 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:29:09,812 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6433789 still processing
2025-05-11 04:29:14,177 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'curtain/1746440075.56.curtain.log'
2025-05-11 04:29:14,183 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 36
2025-05-11 04:29:15,028 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'sysmon/1746440076.48.sysmon.xml'
2025-05-11 04:29:15,134 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 11293810
2025-05-11 04:29:15,155 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'files/ac3fbfe71318488f_autrans.sig'
2025-05-11 04:29:15,157 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 32
2025-05-11 04:29:15,158 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'files/2a1bae790bbdc314_aum.log'
2025-05-11 04:29:15,159 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 779
2025-05-11 04:29:15,161 [cuckoo.core.resultserver] DEBUG: Task #6433789: File upload for 'files/33307967def22108_adobeupdaterprefs.dat'
2025-05-11 04:29:15,162 [cuckoo.core.resultserver] DEBUG: Task #6433789 uploaded file length: 384
2025-05-11 04:29:15,188 [cuckoo.core.resultserver] DEBUG: Task #6433789 had connection reset for <Context for LOG>
2025-05-11 04:29:15,843 [cuckoo.core.guest] INFO: win7x6430: analysis completed successfully
2025-05-11 04:29:15,857 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-05-11 04:29:15,889 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-05-11 04:29:16,538 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6430 to path /srv/cuckoo/cwd/storage/analyses/6433789/memory.dmp
2025-05-11 04:29:16,540 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6430
2025-05-11 04:32:01,298 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.230 for task #6433789
2025-05-11 04:32:02,626 [cuckoo.core.scheduler] DEBUG: Released database task #6433789
2025-05-11 04:32:02,663 [cuckoo.core.scheduler] INFO: Task #6433789: analysis procedure completed