Analyzer Log
2025-06-22 02:16:24,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4
2025-06-22 02:16:24,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\TSLeTuytAFKOlGmS
2025-06-22 02:16:24,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\UFMkJgtpFYpFVAhBoWGvHZt
2025-06-22 02:16:24,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-22 02:16:24,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-22 02:16:24,358 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-22 02:16:24,358 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-22 02:16:24,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-22 02:16:25,046 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-06-22 02:16:25,046 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-22 02:16:25,046 [analyzer] DEBUG: Started auxiliary module Human
2025-06-22 02:16:25,046 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-22 02:16:25,046 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-22 02:16:25,140 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-22 02:16:25,140 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-22 02:16:25,140 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-22 02:16:25,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-22 02:16:25,296 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\5011280a9fb8547c_backup.exe' with arguments '' and pid 1476
2025-06-22 02:16:25,483 [analyzer] DEBUG: Loaded monitor into process with pid 1476
2025-06-22 02:16:25,546 [analyzer] INFO: Added new file to list with pid 1476 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-06-22 02:16:25,562 [analyzer] INFO: Added new file to list with pid 1476 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-06-22 02:16:25,625 [analyzer] INFO: Injected into process with pid 1460 and name ''
2025-06-22 02:16:25,780 [analyzer] DEBUG: Loaded monitor into process with pid 1460
2025-06-22 02:16:25,842 [analyzer] INFO: Added new file to list with pid 1476 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-06-22 02:16:25,921 [analyzer] INFO: Added new file to list with pid 1476 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-06-22 02:16:26,842 [analyzer] INFO: Added new file to list with pid 1460 and path C:\backup.exe
2025-06-22 02:19:44,296 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-22 02:19:45,858 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-22 02:19:45,858 [lib.api.process] INFO: Successfully terminated process with pid 1476.
2025-06-22 02:19:45,858 [lib.api.process] INFO: Successfully terminated process with pid 1460.
2025-06-22 02:19:45,890 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-06-27 12:09:36,499 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:37,518 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:38,554 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:39,604 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:40,708 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:41,839 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:42,933 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:43,977 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:45,027 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:46,084 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:47,135 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:48,191 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:49,242 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:50,425 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:51,499 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:52,571 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:53,629 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:54,676 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:55,722 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:56,777 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:57,830 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:09:58,872 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:00,104 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:01,150 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:02,182 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:03,509 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:04,610 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:05,630 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:06,654 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:07,675 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:08,701 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:09,724 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:10,744 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:11,775 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:13,146 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:14,252 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:15,308 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:16,581 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:17,669 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:18,751 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:19,841 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:20,909 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:21,971 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:23,072 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:24,176 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:25,361 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:26,440 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:27,508 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:28,829 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:30,214 [cuckoo.core.scheduler] DEBUG: Task #6600850: no machine available yet
2025-06-27 12:10:31,442 [cuckoo.core.scheduler] INFO: Task #6600850: acquired machine win7x644 (label=win7x644)
2025-06-27 12:10:31,449 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #6600850
2025-06-27 12:10:32,055 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 251458 (interface=vboxnet0, host=192.168.168.204)
2025-06-27 12:10:32,244 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644
2025-06-27 12:10:39,726 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak
2025-06-27 12:12:38,291 [cuckoo.core.guest] INFO: Starting analysis #6600850 on guest (id=win7x644, ip=192.168.168.204)
2025-06-27 12:12:39,297 [cuckoo.core.guest] DEBUG: win7x644: not ready yet
2025-06-27 12:12:44,319 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204)
2025-06-27 12:12:44,389 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546)
2025-06-27 12:12:46,159 [cuckoo.core.resultserver] DEBUG: Task #6600850: live log analysis.log initialized.
2025-06-27 12:12:47,473 [cuckoo.core.resultserver] DEBUG: Task #6600850 is sending a BSON stream
2025-06-27 12:12:47,476 [cuckoo.core.resultserver] DEBUG: Task #6600850 is sending a BSON stream
2025-06-27 12:12:47,664 [cuckoo.core.resultserver] DEBUG: Task #6600850 is sending a BSON stream
2025-06-27 12:12:48,223 [cuckoo.core.resultserver] DEBUG: Task #6600850: File upload for 'shots/0001.jpg'
2025-06-27 12:12:48,343 [cuckoo.core.resultserver] DEBUG: Task #6600850 uploaded file length: 133498
2025-06-27 12:13:00,649 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:13:15,756 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:13:31,280 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:13:46,846 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:14:02,292 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:14:17,914 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:14:33,206 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:14:49,416 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:15:04,611 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:15:20,196 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:15:35,497 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:15:50,842 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:16:06,030 [cuckoo.core.guest] DEBUG: win7x644: analysis #6600850 still processing
2025-06-27 12:16:06,508 [cuckoo.core.resultserver] DEBUG: Task #6600850: File upload for 'curtain/1750551584.52.curtain.log'
2025-06-27 12:16:06,512 [cuckoo.core.resultserver] DEBUG: Task #6600850 uploaded file length: 36
2025-06-27 12:16:07,726 [cuckoo.core.resultserver] DEBUG: Task #6600850: File upload for 'sysmon/1750551585.73.sysmon.xml'
2025-06-27 12:16:07,846 [cuckoo.core.resultserver] DEBUG: Task #6600850 uploaded file length: 12261838
2025-06-27 12:16:07,875 [cuckoo.core.resultserver] DEBUG: Task #6600850: File upload for 'files/e91f0ccf96f85ee6_backup.exe'
2025-06-27 12:16:07,880 [cuckoo.core.resultserver] DEBUG: Task #6600850: File upload for 'files/055fd5c2ab4dc1e5_backup.exe'
2025-06-27 12:16:07,889 [cuckoo.core.resultserver] DEBUG: Task #6600850 uploaded file length: 104074
2025-06-27 12:16:07,892 [cuckoo.core.resultserver] DEBUG: Task #6600850 uploaded file length: 104072
2025-06-27 12:16:07,905 [cuckoo.core.resultserver] DEBUG: Task #6600850 had connection reset for <Context for LOG>
2025-06-27 12:16:09,089 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully
2025-06-27 12:16:09,118 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-27 12:16:09,148 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-27 12:16:10,484 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/6600850/memory.dmp
2025-06-27 12:16:10,486 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644
2025-06-27 12:19:05,712 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #6600850
2025-06-27 12:19:06,684 [cuckoo.core.scheduler] DEBUG: Released database task #6600850
2025-06-27 12:19:13,329 [cuckoo.core.scheduler] INFO: Task #6600850: analysis procedure completed