Analyzer Log
2025-06-26 20:03:18,000 [analyzer] DEBUG: Starting analyzer from: C:\tmptisd8w
2025-06-26 20:03:18,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\HOybtJjemCxfSvtciLAY
2025-06-26 20:03:18,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\dojUNrmxFdbKfEHTiFXsgj
2025-06-26 20:03:18,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-26 20:03:18,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-26 20:03:18,265 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-26 20:03:18,265 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-26 20:03:18,655 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-26 20:03:18,858 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-26 20:03:18,858 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-26 20:03:18,858 [analyzer] DEBUG: Started auxiliary module Human
2025-06-26 20:03:18,858 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-26 20:03:18,858 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-26 20:03:18,937 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-26 20:03:18,937 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-26 20:03:18,937 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-26 20:03:18,937 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-26 20:03:19,078 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\f215b961c3e6cc08_backup.exe' with arguments '' and pid 2564
2025-06-26 20:03:19,265 [analyzer] DEBUG: Loaded monitor into process with pid 2564
2025-06-26 20:03:19,312 [analyzer] INFO: Added new file to list with pid 2564 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-06-26 20:03:19,328 [analyzer] INFO: Added new file to list with pid 2564 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-06-26 20:03:19,405 [analyzer] INFO: Injected into process with pid 1528 and name ''
2025-06-26 20:03:19,578 [analyzer] DEBUG: Loaded monitor into process with pid 1528
2025-06-26 20:03:19,640 [analyzer] INFO: Added new file to list with pid 2564 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\data.exe
2025-06-26 20:03:19,717 [analyzer] INFO: Added new file to list with pid 2564 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\data.exe
2025-06-26 20:03:20,640 [analyzer] INFO: Added new file to list with pid 1528 and path C:\backup.exe
2025-06-26 20:06:38,078 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-26 20:06:39,125 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-26 20:06:39,125 [lib.api.process] INFO: Successfully terminated process with pid 2564.
2025-06-26 20:06:39,140 [lib.api.process] INFO: Successfully terminated process with pid 1528.
2025-06-26 20:06:39,155 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-03 01:24:16,927 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:17,948 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:18,993 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:20,023 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:21,048 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:22,073 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:23,100 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:24,125 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:25,145 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:26,169 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:27,190 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:28,211 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:29,231 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:30,414 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:31,546 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:32,639 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:33,666 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:34,701 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:35,731 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:36,764 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:37,804 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:38,834 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:39,869 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:40,903 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:41,934 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:42,978 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:44,010 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:45,045 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:46,077 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:47,109 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:48,141 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:49,189 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:50,221 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:51,255 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:52,327 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:53,354 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:54,510 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:55,542 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:56,573 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:57,608 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:58,636 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:24:59,667 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:00,696 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:01,741 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:02,775 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:03,886 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:05,123 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:06,315 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:07,354 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:08,393 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:09,422 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:10,464 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:11,668 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:12,817 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:13,905 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:14,939 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:16,543 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:17,671 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:18,953 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:20,055 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:21,144 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:22,218 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:23,290 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:24,684 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:25,800 [cuckoo.core.scheduler] DEBUG: Task #6635967: no machine available yet
2025-07-03 01:25:26,928 [cuckoo.core.scheduler] INFO: Task #6635967: acquired machine win7x647 (label=win7x647)
2025-07-03 01:25:26,930 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.207 for task #6635967
2025-07-03 01:25:27,344 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3886916 (interface=vboxnet0, host=192.168.168.207)
2025-07-03 01:25:27,565 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x647
2025-07-03 01:25:28,197 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x647 to vmcloak
2025-07-03 01:27:32,110 [cuckoo.core.guest] INFO: Starting analysis #6635967 on guest (id=win7x647, ip=192.168.168.207)
2025-07-03 01:27:33,115 [cuckoo.core.guest] DEBUG: win7x647: not ready yet
2025-07-03 01:27:38,153 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x647, ip=192.168.168.207)
2025-07-03 01:27:38,213 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x647, ip=192.168.168.207, monitor=latest, size=6660546)
2025-07-03 01:27:39,383 [cuckoo.core.resultserver] DEBUG: Task #6635967: live log analysis.log initialized.
2025-07-03 01:27:40,110 [cuckoo.core.resultserver] DEBUG: Task #6635967 is sending a BSON stream
2025-07-03 01:27:40,504 [cuckoo.core.resultserver] DEBUG: Task #6635967 is sending a BSON stream
2025-07-03 01:27:40,897 [cuckoo.core.resultserver] DEBUG: Task #6635967 is sending a BSON stream
2025-07-03 01:27:41,355 [cuckoo.core.resultserver] DEBUG: Task #6635967: File upload for 'shots/0001.jpg'
2025-07-03 01:27:41,371 [cuckoo.core.resultserver] DEBUG: Task #6635967 uploaded file length: 133499
2025-07-03 01:27:54,398 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:28:09,546 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:28:24,780 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:28:40,266 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:28:55,506 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:29:11,194 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:29:26,325 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:29:41,430 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:29:56,599 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:30:11,951 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:30:27,133 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:30:42,308 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:30:57,517 [cuckoo.core.guest] DEBUG: win7x647: analysis #6635967 still processing
2025-07-03 01:30:59,592 [cuckoo.core.resultserver] DEBUG: Task #6635967: File upload for 'curtain/1750961198.25.curtain.log'
2025-07-03 01:30:59,602 [cuckoo.core.resultserver] DEBUG: Task #6635967 uploaded file length: 36
2025-07-03 01:31:00,364 [cuckoo.core.resultserver] DEBUG: Task #6635967: File upload for 'sysmon/1750961199.05.sysmon.xml'
2025-07-03 01:31:00,450 [cuckoo.core.resultserver] DEBUG: Task #6635967 uploaded file length: 11062288
2025-07-03 01:31:00,485 [cuckoo.core.resultserver] DEBUG: Task #6635967: File upload for 'files/64d4632c338de5c4_backup.exe'
2025-07-03 01:31:00,488 [cuckoo.core.resultserver] DEBUG: Task #6635967: File upload for 'files/81c73ba7fe05a165_backup.exe'
2025-07-03 01:31:00,493 [cuckoo.core.resultserver] DEBUG: Task #6635967 uploaded file length: 293302
2025-07-03 01:31:00,498 [cuckoo.core.resultserver] DEBUG: Task #6635967 uploaded file length: 293304
2025-07-03 01:31:00,500 [cuckoo.core.resultserver] DEBUG: Task #6635967 had connection reset for <Context for LOG>
2025-07-03 01:31:00,531 [cuckoo.core.guest] INFO: win7x647: analysis completed successfully
2025-07-03 01:31:00,543 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-03 01:31:00,564 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-03 01:31:01,511 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x647 to path /srv/cuckoo/cwd/storage/analyses/6635967/memory.dmp
2025-07-03 01:31:01,512 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x647
2025-07-03 01:32:19,466 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.207 for task #6635967
2025-07-03 01:32:20,275 [cuckoo.core.scheduler] DEBUG: Released database task #6635967
2025-07-03 01:32:20,301 [cuckoo.core.scheduler] INFO: Task #6635967: analysis procedure completed