Analyzer Log
2025-05-19 10:50:48,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpzepe2z
2025-05-19 10:50:48,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\ZTPirWknfyfAutey
2025-05-19 10:50:48,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\gLBuSvPcTLoUMHuUev
2025-05-19 10:50:48,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-05-19 10:50:48,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-05-19 10:50:48,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-05-19 10:50:49,078 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-05-19 10:50:49,078 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-05-19 10:50:49,078 [analyzer] DEBUG: Started auxiliary module Human
2025-05-19 10:50:49,078 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-05-19 10:50:49,078 [analyzer] DEBUG: Started auxiliary module Reboot
2025-05-19 10:50:49,171 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-05-19 10:50:49,171 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-05-19 10:50:49,171 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-05-19 10:50:49,171 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-05-19 10:50:49,342 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\a02d1825d2d8bf63254cdf58f84bf8bc18e08a17dcacd4a1b4e260c55adafa7a.exe' with arguments '' and pid 1436
2025-05-19 10:50:49,546 [analyzer] DEBUG: Loaded monitor into process with pid 1436
2025-05-19 10:50:49,562 [analyzer] INFO: Added new file to list with pid 1436 and path C:\Users\Administrator\AppData\Local\Temp\MicroMedia\MediaCenter.exe
2025-05-19 10:50:49,625 [analyzer] INFO: Injected into process with pid 1000 and name u'MediaCenter.exe'
2025-05-19 10:50:49,812 [analyzer] DEBUG: Loaded monitor into process with pid 1000
2025-05-19 10:51:18,342 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-05-19 10:51:18,875 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-05-19 10:51:18,875 [lib.api.process] INFO: Successfully terminated process with pid 1436.
2025-05-19 10:51:18,875 [lib.api.process] INFO: Successfully terminated process with pid 1000.
2025-05-19 10:51:18,875 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-05-20 13:59:01,243 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:02,275 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:03,465 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:04,490 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:05,527 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:06,553 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:07,575 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:08,641 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:09,702 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:10,839 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:11,926 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:13,077 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:14,119 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:15,165 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:16,228 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:17,293 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:18,365 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:19,449 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:20,546 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:21,623 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:22,691 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:23,736 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:24,771 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:25,839 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:26,893 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:27,959 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:29,008 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:30,060 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:31,117 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:32,170 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:33,229 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:34,277 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:35,326 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:36,378 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:37,440 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:38,495 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:39,567 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:40,656 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:41,684 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:42,711 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:43,737 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:44,760 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:45,785 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:46,835 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:47,865 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:48,894 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:50,020 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:51,038 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:52,060 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:53,083 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:54,112 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:55,188 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:56,269 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:57,371 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:58,479 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 13:59:59,587 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:00,688 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:01,810 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:02,903 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:04,076 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:05,153 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:06,242 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:07,313 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:08,398 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:09,462 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:10,537 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:11,615 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:12,683 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:13,734 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:14,785 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:15,841 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:16,901 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:17,956 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:18,995 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:20,253 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:21,552 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:22,758 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:24,303 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:25,403 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:26,526 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:27,737 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:28,852 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:29,931 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:31,031 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:32,093 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:33,339 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:34,398 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:35,465 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:36,513 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:37,575 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:38,691 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:39,744 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:40,956 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:42,036 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:43,096 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:44,147 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:45,415 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:46,497 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:47,552 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:48,616 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:49,669 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:50,727 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:51,814 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:52,877 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:53,931 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:54,989 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:56,060 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:57,106 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:58,162 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:00:59,212 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:00,252 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:01,285 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:02,311 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:03,334 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:04,360 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:05,381 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:06,412 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:07,507 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:08,534 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:09,558 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:10,575 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:11,597 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:12,644 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:13,798 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:15,131 [cuckoo.core.scheduler] DEBUG: Task #6496903: no machine available yet
2025-05-20 14:01:16,539 [cuckoo.core.scheduler] INFO: Task #6496903: acquired machine win7x6417 (label=win7x6417)
2025-05-20 14:01:16,705 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.217 for task #6496903
2025-05-20 14:01:17,094 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1509735 (interface=vboxnet0, host=192.168.168.217)
2025-05-20 14:01:17,465 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6417
2025-05-20 14:01:18,091 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6417 to vmcloak
2025-05-20 14:04:21,644 [cuckoo.core.guest] INFO: Starting analysis #6496903 on guest (id=win7x6417, ip=192.168.168.217)
2025-05-20 14:04:22,649 [cuckoo.core.guest] DEBUG: win7x6417: not ready yet
2025-05-20 14:04:27,686 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6417, ip=192.168.168.217)
2025-05-20 14:04:27,775 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6417, ip=192.168.168.217, monitor=latest, size=6660546)
2025-05-20 14:04:29,027 [cuckoo.core.resultserver] DEBUG: Task #6496903: live log analysis.log initialized.
2025-05-20 14:04:30,049 [cuckoo.core.resultserver] DEBUG: Task #6496903 is sending a BSON stream
2025-05-20 14:04:30,471 [cuckoo.core.resultserver] DEBUG: Task #6496903 is sending a BSON stream
2025-05-20 14:04:30,747 [cuckoo.core.resultserver] DEBUG: Task #6496903 is sending a BSON stream
2025-05-20 14:04:31,342 [cuckoo.core.resultserver] DEBUG: Task #6496903: File upload for 'shots/0001.jpg'
2025-05-20 14:04:31,356 [cuckoo.core.resultserver] DEBUG: Task #6496903 uploaded file length: 133516
2025-05-20 14:04:43,877 [cuckoo.core.guest] DEBUG: win7x6417: analysis #6496903 still processing
2025-05-20 14:04:59,042 [cuckoo.core.guest] DEBUG: win7x6417: analysis #6496903 still processing
2025-05-20 14:04:59,639 [cuckoo.core.resultserver] DEBUG: Task #6496903: File upload for 'curtain/1747644678.59.curtain.log'
2025-05-20 14:04:59,646 [cuckoo.core.resultserver] DEBUG: Task #6496903 uploaded file length: 36
2025-05-20 14:04:59,870 [cuckoo.core.resultserver] DEBUG: Task #6496903: File upload for 'sysmon/1747644678.83.sysmon.xml'
2025-05-20 14:04:59,904 [cuckoo.core.resultserver] DEBUG: Task #6496903 uploaded file length: 1712230
2025-05-20 14:04:59,915 [cuckoo.core.resultserver] DEBUG: Task #6496903: File upload for 'files/a35a1007490e73a1_mediacenter.exe'
2025-05-20 14:04:59,917 [cuckoo.core.resultserver] DEBUG: Task #6496903 uploaded file length: 59392
2025-05-20 14:05:00,227 [cuckoo.core.resultserver] DEBUG: Task #6496903 had connection reset for <Context for LOG>
2025-05-20 14:05:02,056 [cuckoo.core.guest] INFO: win7x6417: analysis completed successfully
2025-05-20 14:05:02,081 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-05-20 14:05:02,109 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-05-20 14:05:03,105 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6417 to path /srv/cuckoo/cwd/storage/analyses/6496903/memory.dmp
2025-05-20 14:05:03,106 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6417
2025-05-20 14:08:11,540 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.217 for task #6496903
2025-05-20 14:08:11,933 [cuckoo.core.scheduler] DEBUG: Released database task #6496903
2025-05-20 14:08:11,965 [cuckoo.core.scheduler] INFO: Task #6496903: analysis procedure completed