Analyzer Log
2025-06-22 01:47:26,000 [analyzer] DEBUG: Starting analyzer from: C:\tmphzbxu3
2025-06-22 01:47:26,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\eKAyVfiLWoroOBtvWmitOaAfs
2025-06-22 01:47:26,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\lTTQyrxbGwpzsPZQFn
2025-06-22 01:47:26,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-22 01:47:26,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-22 01:47:26,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-22 01:47:26,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-22 01:47:26,765 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-22 01:47:26,953 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-06-22 01:47:26,953 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-22 01:47:26,953 [analyzer] DEBUG: Started auxiliary module Human
2025-06-22 01:47:26,953 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-22 01:47:26,953 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-22 01:47:27,030 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-22 01:47:27,030 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-22 01:47:27,030 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-22 01:47:27,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-22 01:47:27,187 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d582d79b1c5e3855_sims 2 fix.exe' with arguments '' and pid 3028
2025-06-22 01:47:27,437 [analyzer] DEBUG: Loaded monitor into process with pid 3028
2025-06-22 01:47:27,483 [analyzer] INFO: Added new file to list with pid 3028 and path C:\Windows\win32dc\UT2004(cdfix).exe
2025-06-22 01:47:27,515 [analyzer] INFO: Added new file to list with pid 3028 and path C:\Windows\win32dc\Counter-Strike(serial).exe
2025-06-22 01:47:27,530 [analyzer] INFO: Added new file to list with pid 3028 and path C:\Windows\win32dc\Quake3(crack).exe
2025-06-22 01:47:27,546 [analyzer] INFO: Added new file to list with pid 3028 and path C:\Windows\win32dc\BattleField 1942 nocd.exe
2025-06-22 01:47:27,578 [analyzer] INFO: Added new file to list with pid 3028 and path C:\Windows\win32dc\Counter-Strike + fix.exe
2025-06-22 01:47:27,592 [analyzer] INFO: Added new file to list with pid 3028 and path C:\Windows\win32dc\Silent Hill 4(serial).exe
2025-06-22 01:50:46,187 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-22 01:50:47,421 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-22 01:50:47,421 [lib.api.process] INFO: Successfully terminated process with pid 3028.
2025-06-22 01:50:47,453 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-27 11:41:28,177 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:29,703 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:30,985 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:32,283 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:33,528 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:34,570 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:35,614 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:36,684 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:38,345 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:39,486 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:40,567 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:41,627 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:42,678 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:43,831 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:45,300 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:46,378 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:48,123 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:49,175 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:50,222 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:52,052 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:53,203 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:54,289 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:55,575 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:56,613 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:57,646 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:58,669 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:41:59,698 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:00,722 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:01,745 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:02,764 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:03,787 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:05,290 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:06,681 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:07,706 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:08,727 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:09,750 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:10,770 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:11,795 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:12,947 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:14,036 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:15,371 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:16,696 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:18,005 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:19,134 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:20,195 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:21,403 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:22,888 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:24,408 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:25,493 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:26,584 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:27,689 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:28,760 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:29,844 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:30,910 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:32,011 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:33,088 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:34,361 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:35,686 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:36,774 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:37,909 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:39,321 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:40,459 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:41,697 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:43,005 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:44,065 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:45,154 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:46,212 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:47,243 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:48,545 [cuckoo.core.scheduler] DEBUG: Task #6600728: no machine available yet
2025-06-27 11:42:49,613 [cuckoo.core.scheduler] INFO: Task #6600728: acquired machine win7x6425 (label=win7x6425)
2025-06-27 11:42:49,621 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.225 for task #6600728
2025-06-27 11:42:50,152 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 198685 (interface=vboxnet0, host=192.168.168.225)
2025-06-27 11:42:50,286 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6425
2025-06-27 11:42:57,710 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6425 to vmcloak
2025-06-27 11:45:23,622 [cuckoo.core.guest] INFO: Starting analysis #6600728 on guest (id=win7x6425, ip=192.168.168.225)
2025-06-27 11:45:24,630 [cuckoo.core.guest] DEBUG: win7x6425: not ready yet
2025-06-27 11:45:29,670 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6425, ip=192.168.168.225)
2025-06-27 11:45:29,764 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6425, ip=192.168.168.225, monitor=latest, size=6660546)
2025-06-27 11:45:31,158 [cuckoo.core.resultserver] DEBUG: Task #6600728: live log analysis.log initialized.
2025-06-27 11:45:32,058 [cuckoo.core.resultserver] DEBUG: Task #6600728 is sending a BSON stream
2025-06-27 11:45:32,788 [cuckoo.core.resultserver] DEBUG: Task #6600728 is sending a BSON stream
2025-06-27 11:45:33,494 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'shots/0001.jpg'
2025-06-27 11:45:33,773 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 133492
2025-06-27 11:45:46,199 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:46:01,959 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:46:17,302 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:46:32,677 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:46:47,849 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:47:03,218 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:47:18,354 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:47:33,936 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:47:49,124 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:48:04,469 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:48:19,634 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:48:34,782 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:48:50,081 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6600728 still processing
2025-06-27 11:48:51,563 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'curtain/1750549846.39.curtain.log'
2025-06-27 11:48:51,566 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 36
2025-06-27 11:48:52,492 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'sysmon/1750549847.31.sysmon.xml'
2025-06-27 11:48:52,600 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 12288612
2025-06-27 11:48:52,621 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'files/a95a0e43b9b495bf_quake3(crack).exe'
2025-06-27 11:48:52,625 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'files/dc89ab89e3e5e307_counter-strike(serial).exe'
2025-06-27 11:48:52,627 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'files/c1b8fe659a4e10b9_battlefield 1942 nocd.exe'
2025-06-27 11:48:52,629 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'files/a4ebac162647ecda_ut2004(cdfix).exe'
2025-06-27 11:48:52,631 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 113998
2025-06-27 11:48:52,633 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 113998
2025-06-27 11:48:52,634 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 112974
2025-06-27 11:48:52,635 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 111950
2025-06-27 11:48:52,639 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'files/4b105ebdb43b6237_counter-strike + fix.exe'
2025-06-27 11:48:52,641 [cuckoo.core.resultserver] DEBUG: Task #6600728: File upload for 'files/a6e4c491958ccc14_silent hill 4(serial).exe'
2025-06-27 11:48:52,643 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 111950
2025-06-27 11:48:52,645 [cuckoo.core.resultserver] DEBUG: Task #6600728 uploaded file length: 111950
2025-06-27 11:48:52,653 [cuckoo.core.resultserver] DEBUG: Task #6600728 had connection reset for <Context for LOG>
2025-06-27 11:48:53,124 [cuckoo.core.guest] INFO: win7x6425: analysis completed successfully
2025-06-27 11:48:53,140 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-27 11:48:53,160 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-27 11:48:54,450 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6425 to path /srv/cuckoo/cwd/storage/analyses/6600728/memory.dmp
2025-06-27 11:48:54,451 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6425
2025-06-27 11:50:45,180 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.225 for task #6600728
2025-06-27 11:50:51,910 [cuckoo.core.scheduler] DEBUG: Released database task #6600728
2025-06-27 11:51:02,104 [cuckoo.core.scheduler] INFO: Task #6600728: analysis procedure completed