Analyzer Log
2025-06-20 18:41:00,000 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht
2025-06-20 18:41:00,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\WhavjXqWNScumysahe
2025-06-20 18:41:00,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\ydYycQeexAWIscVLYUiJyxjURSLIme
2025-06-20 18:41:00,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-20 18:41:00,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-20 18:41:00,812 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-20 18:41:01,030 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-06-20 18:41:01,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-20 18:41:01,030 [analyzer] DEBUG: Started auxiliary module Human
2025-06-20 18:41:01,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-20 18:41:01,046 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-20 18:41:01,140 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-20 18:41:01,140 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-20 18:41:01,140 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-20 18:41:01,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-20 18:41:01,342 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\b6957464fb9871684276bfbd256fbf9ee5517498b051a42daa675000fee0d37d.exe' with arguments '' and pid 2228
2025-06-20 18:41:01,578 [analyzer] DEBUG: Loaded monitor into process with pid 2228
2025-06-20 18:41:01,733 [analyzer] INFO: Added new file to list with pid 2228 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-06-20 18:41:01,750 [analyzer] INFO: Added new file to list with pid 2228 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-06-20 18:41:01,842 [analyzer] INFO: Injected into process with pid 2424 and name ''
2025-06-20 18:41:02,030 [analyzer] DEBUG: Loaded monitor into process with pid 2424
2025-06-20 18:41:02,155 [analyzer] INFO: Added new file to list with pid 2228 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-06-20 18:41:02,280 [analyzer] INFO: Added new file to list with pid 2228 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-06-20 18:41:03,125 [analyzer] INFO: Added new file to list with pid 2424 and path C:\backup.exe
2025-06-20 18:41:30,342 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-20 18:41:30,921 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-20 18:41:30,921 [lib.api.process] INFO: Successfully terminated process with pid 2228.
2025-06-20 18:41:30,921 [lib.api.process] INFO: Successfully terminated process with pid 2424.
2025-06-20 18:41:30,967 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-22 02:07:42,546 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:43,648 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:45,112 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:46,293 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:47,411 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:48,518 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:49,628 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:50,710 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:51,801 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:52,915 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:54,207 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:55,314 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:56,392 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:57,486 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:58,559 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:07:59,631 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:00,769 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:01,819 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:03,055 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:04,101 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:05,136 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:06,188 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:07,222 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:08,293 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:09,319 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:10,433 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:11,855 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:13,481 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:14,596 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:15,687 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:16,760 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:17,868 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:18,955 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:20,071 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:21,836 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:22,910 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:24,541 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:25,636 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:26,720 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:27,845 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:28,928 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:30,038 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:31,333 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:32,436 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:33,970 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:35,007 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:36,040 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:37,067 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:38,103 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:39,127 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:40,147 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:41,165 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:42,186 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:43,419 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:44,703 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:45,721 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:46,855 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:47,877 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:48,901 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:49,951 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:51,263 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:52,361 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:53,776 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:54,872 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:56,010 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:57,440 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:58,479 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:08:59,521 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:00,750 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:02,397 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:03,478 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:04,526 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:05,622 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:06,743 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:07,831 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:08,875 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:09,937 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:10,976 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:12,032 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:13,407 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:14,819 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:16,161 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:17,191 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:18,217 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:19,250 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:20,280 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:21,654 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:22,711 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:24,155 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:25,205 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:26,557 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:27,628 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:28,697 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:29,767 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:30,855 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:31,928 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:33,058 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:34,093 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:35,134 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:36,162 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:37,195 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:38,230 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:39,262 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:41,486 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:42,589 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:43,628 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:44,658 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:45,691 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:46,723 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:47,758 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:48,793 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:49,833 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:50,865 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:51,900 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:52,939 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:54,447 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:55,468 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:56,486 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:57,507 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:58,528 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:09:59,559 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:10:01,171 [cuckoo.core.scheduler] DEBUG: Task #6574203: no machine available yet
2025-06-22 02:10:02,230 [cuckoo.core.scheduler] INFO: Task #6574203: acquired machine win7x641 (label=win7x641)
2025-06-22 02:10:02,232 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #6574203
2025-06-22 02:10:02,885 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1593859 (interface=vboxnet0, host=192.168.168.201)
2025-06-22 02:10:02,993 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641
2025-06-22 02:10:10,670 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak
2025-06-22 02:11:55,776 [cuckoo.core.guest] INFO: Starting analysis #6574203 on guest (id=win7x641, ip=192.168.168.201)
2025-06-22 02:11:56,784 [cuckoo.core.guest] DEBUG: win7x641: not ready yet
2025-06-22 02:12:01,814 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201)
2025-06-22 02:12:01,914 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546)
2025-06-22 02:12:03,504 [cuckoo.core.resultserver] DEBUG: Task #6574203: live log analysis.log initialized.
2025-06-22 02:12:04,486 [cuckoo.core.resultserver] DEBUG: Task #6574203 is sending a BSON stream
2025-06-22 02:12:05,000 [cuckoo.core.resultserver] DEBUG: Task #6574203 is sending a BSON stream
2025-06-22 02:12:05,469 [cuckoo.core.resultserver] DEBUG: Task #6574203 is sending a BSON stream
2025-06-22 02:12:05,806 [cuckoo.core.resultserver] DEBUG: Task #6574203: File upload for 'shots/0001.jpg'
2025-06-22 02:12:05,826 [cuckoo.core.resultserver] DEBUG: Task #6574203 uploaded file length: 133474
2025-06-22 02:12:18,421 [cuckoo.core.guest] DEBUG: win7x641: analysis #6574203 still processing
2025-06-22 02:12:34,182 [cuckoo.core.resultserver] DEBUG: Task #6574203: File upload for 'curtain/1750437690.66.curtain.log'
2025-06-22 02:12:34,185 [cuckoo.core.guest] DEBUG: win7x641: analysis #6574203 still processing
2025-06-22 02:12:34,185 [cuckoo.core.resultserver] DEBUG: Task #6574203 uploaded file length: 36
2025-06-22 02:12:34,426 [cuckoo.core.resultserver] DEBUG: Task #6574203: File upload for 'sysmon/1750437690.91.sysmon.xml'
2025-06-22 02:12:34,445 [cuckoo.core.resultserver] DEBUG: Task #6574203 uploaded file length: 1224646
2025-06-22 02:12:34,459 [cuckoo.core.resultserver] DEBUG: Task #6574203: File upload for 'files/9120f299cf62f62d_backup.exe'
2025-06-22 02:12:34,462 [cuckoo.core.resultserver] DEBUG: Task #6574203 uploaded file length: 104068
2025-06-22 02:12:34,468 [cuckoo.core.resultserver] DEBUG: Task #6574203: File upload for 'files/5011280a9fb8547c_backup.exe'
2025-06-22 02:12:34,472 [cuckoo.core.resultserver] DEBUG: Task #6574203 uploaded file length: 104070
2025-06-22 02:12:34,479 [cuckoo.core.resultserver] DEBUG: Task #6574203: File upload for 'files/ed026bd1bc853217_backup.exe'
2025-06-22 02:12:34,482 [cuckoo.core.resultserver] DEBUG: Task #6574203 uploaded file length: 104068
2025-06-22 02:12:34,718 [cuckoo.core.resultserver] DEBUG: Task #6574203 had connection reset for <Context for LOG>
2025-06-22 02:12:37,198 [cuckoo.core.guest] INFO: win7x641: analysis completed successfully
2025-06-22 02:12:37,214 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-22 02:12:37,247 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-22 02:12:38,882 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/6574203/memory.dmp
2025-06-22 02:12:38,898 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641
2025-06-22 02:15:51,194 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #6574203
2025-06-22 02:15:51,602 [cuckoo.core.scheduler] DEBUG: Released database task #6574203
2025-06-22 02:15:51,667 [cuckoo.core.scheduler] INFO: Task #6574203: analysis procedure completed