Analyzer Log
2025-07-07 10:05:23,030 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt
2025-07-07 10:05:23,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\QZtVHAcIyLzDAqtIrYtXqpmTxVB
2025-07-07 10:05:23,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\PLoobvDDWYhldFkXjIAEjTbGOFEV
2025-07-07 10:05:23,342 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-07 10:05:23,358 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-07 10:05:23,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-07 10:05:24,046 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-07-07 10:05:24,046 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-07 10:05:24,046 [analyzer] DEBUG: Started auxiliary module Human
2025-07-07 10:05:24,062 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-07 10:05:24,062 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-07 10:05:24,140 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-07 10:05:24,140 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-07 10:05:24,140 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-07 10:05:24,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-07 10:05:24,312 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\40390d043fe0131afcf00e297b2d350bd5d3d4bf6ead3efaef007aa635348fe7.exe' with arguments '' and pid 2360
2025-07-07 10:05:24,530 [analyzer] DEBUG: Loaded monitor into process with pid 2360
2025-07-07 10:05:24,625 [analyzer] INFO: io=NULL
2025-07-07 10:05:24,625 [analyzer] DEBUG: Error resolving function vbscript!COleScript_Compile through our custom callback.
2025-07-07 10:05:24,625 [analyzer] INFO: io=NULL
2025-07-07 10:05:24,640 [analyzer] DEBUG: Error resolving function vbscript!COleScript_Compile through our custom callback.
2025-07-07 10:05:24,858 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\lkdsu.txt
2025-07-07 10:05:25,171 [analyzer] INFO: Injected into process with pid 1716 and name u'cmd.exe'
2025-07-07 10:05:25,375 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1716.
2025-07-07 10:05:25,592 [analyzer] DEBUG: Loaded monitor into process with pid 1716
2025-07-07 10:05:25,703 [analyzer] INFO: Injected into process with pid 408 and name u'reg.exe'
2025-07-07 10:05:25,875 [analyzer] DEBUG: Loaded monitor into process with pid 408
2025-07-07 10:05:25,967 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Roaming\Directory\Windowsdef.txt
2025-07-07 10:05:26,312 [analyzer] INFO: Process with pid 1716 has terminated
2025-07-07 10:05:26,765 [analyzer] INFO: Injected into process with pid 1916 and name u'Windowsdef.exe'
2025-07-07 10:05:26,858 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1916.
2025-07-07 10:05:27,030 [analyzer] DEBUG: Loaded monitor into process with pid 1916
2025-07-07 10:05:27,108 [analyzer] INFO: io=NULL
2025-07-07 10:05:27,108 [analyzer] DEBUG: Error resolving function vbscript!COleScript_Compile through our custom callback.
2025-07-07 10:05:27,108 [analyzer] INFO: io=NULL
2025-07-07 10:05:27,108 [analyzer] DEBUG: Error resolving function vbscript!COleScript_Compile through our custom callback.
2025-07-07 13:58:30,263 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-07 13:58:30,686 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-07 13:58:30,686 [lib.api.process] INFO: Successfully terminated process with pid 1916.
2025-07-07 13:58:30,686 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-07 14:54:15,868 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:16,897 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:18,080 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:19,208 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:20,321 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:21,459 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:22,795 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:23,965 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:25,081 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:26,357 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:27,383 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:28,407 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:29,436 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:30,461 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:31,488 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:32,511 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:33,534 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:34,554 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:35,579 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:36,613 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:37,637 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:38,664 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:39,689 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:40,717 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:41,740 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:42,761 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:43,787 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:44,818 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:46,043 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:47,214 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:48,248 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:49,462 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:50,557 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:51,618 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:52,794 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:53,871 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:54,912 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:55,946 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:57,009 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:58,196 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:54:59,270 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:55:00,343 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:55:01,420 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:55:02,687 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:55:03,799 [cuckoo.core.scheduler] DEBUG: Task #6660507: no machine available yet
2025-07-07 14:55:04,841 [cuckoo.core.scheduler] INFO: Task #6660507: acquired machine win7x6423 (label=win7x6423)
2025-07-07 14:55:04,851 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6660507
2025-07-07 14:55:05,432 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2190439 (interface=vboxnet0, host=192.168.168.223)
2025-07-07 14:55:07,331 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423
2025-07-07 14:55:08,258 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak
2025-07-07 14:57:52,176 [cuckoo.core.guest] INFO: Starting analysis #6660507 on guest (id=win7x6423, ip=192.168.168.223)
2025-07-07 14:57:53,182 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet
2025-07-07 14:57:58,224 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223)
2025-07-07 14:57:58,322 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546)
2025-07-07 14:58:00,082 [cuckoo.core.resultserver] DEBUG: Task #6660507: live log analysis.log initialized.
2025-07-07 14:58:00,938 [cuckoo.core.resultserver] DEBUG: Task #6660507 is sending a BSON stream
2025-07-07 14:58:01,400 [cuckoo.core.resultserver] DEBUG: Task #6660507 is sending a BSON stream
2025-07-07 14:58:01,875 [cuckoo.core.resultserver] DEBUG: Task #6660507: File upload for 'files/c91b07a98f7d795d_lkdsu.txt'
2025-07-07 14:58:01,883 [cuckoo.core.resultserver] DEBUG: Task #6660507 uploaded file length: 160
2025-07-07 14:58:02,226 [cuckoo.core.resultserver] DEBUG: Task #6660507: File upload for 'shots/0001.jpg'
2025-07-07 14:58:02,250 [cuckoo.core.resultserver] DEBUG: Task #6660507 uploaded file length: 133464
2025-07-07 14:58:02,463 [cuckoo.core.resultserver] DEBUG: Task #6660507 is sending a BSON stream
2025-07-07 14:58:02,750 [cuckoo.core.resultserver] DEBUG: Task #6660507 is sending a BSON stream
2025-07-07 14:58:02,945 [cuckoo.core.resultserver] DEBUG: Task #6660507: File upload for 'files/be6b1d2c2d620cef_Windowsdef.txt'
2025-07-07 14:58:03,005 [cuckoo.core.resultserver] DEBUG: Task #6660507 uploaded file length: 2075010
2025-07-07 14:58:03,903 [cuckoo.core.resultserver] DEBUG: Task #6660507 is sending a BSON stream
2025-07-07 14:58:14,853 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6660507 still processing
2025-07-07 14:58:30,372 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6660507 still processing
2025-07-07 14:58:30,463 [cuckoo.core.resultserver] DEBUG: Task #6660507: File upload for 'curtain/1751889510.45.curtain.log'
2025-07-07 14:58:30,475 [cuckoo.core.resultserver] DEBUG: Task #6660507 uploaded file length: 36
2025-07-07 14:58:30,658 [cuckoo.core.resultserver] DEBUG: Task #6660507: File upload for 'sysmon/1751889510.65.sysmon.xml'
2025-07-07 14:58:30,684 [cuckoo.core.resultserver] DEBUG: Task #6660507 uploaded file length: 2168774
2025-07-07 14:58:31,018 [cuckoo.core.resultserver] DEBUG: Task #6660507 had connection reset for <Context for LOG>
2025-07-07 14:58:33,392 [cuckoo.core.guest] INFO: win7x6423: analysis completed successfully
2025-07-07 14:58:33,409 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-07 14:58:33,440 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-07 14:58:34,982 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6660507/memory.dmp
2025-07-07 14:58:34,983 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423
2025-07-07 15:00:48,510 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6660507
2025-07-07 15:00:49,158 [cuckoo.core.scheduler] DEBUG: Released database task #6660507
2025-07-07 15:00:49,206 [cuckoo.core.scheduler] INFO: Task #6660507: analysis procedure completed