Analyzer Log
2025-07-08 13:34:06,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpwwr_kc
2025-07-08 13:34:06,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\vEqFujjpAqdcBjsO
2025-07-08 13:34:06,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\tmQwvgEMxsmHMWLLzqQbWkZoclSDU
2025-07-08 13:34:06,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-08 13:34:06,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-08 13:34:06,828 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-08 13:34:07,030 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-07-08 13:34:07,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-08 13:34:07,030 [analyzer] DEBUG: Started auxiliary module Human
2025-07-08 13:34:07,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-08 13:34:07,030 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-08 13:34:07,108 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-08 13:34:07,108 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-08 13:34:07,108 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-08 13:34:07,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-08 13:34:07,265 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\301af6e674565a87e9d58d498e4014f97408cbf748036680c8c8761b6f4be155.exe' with arguments '' and pid 2708
2025-07-08 13:34:07,467 [analyzer] DEBUG: Loaded monitor into process with pid 2708
2025-07-08 13:34:07,530 [analyzer] INFO: Added new file to list with pid 2708 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-07-08 13:34:07,546 [analyzer] INFO: Added new file to list with pid 2708 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-07-08 13:34:07,608 [analyzer] INFO: Injected into process with pid 720 and name ''
2025-07-08 13:34:07,780 [analyzer] DEBUG: Loaded monitor into process with pid 720
2025-07-08 13:34:07,858 [analyzer] INFO: Added new file to list with pid 2708 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-07-08 13:34:07,937 [analyzer] INFO: Added new file to list with pid 2708 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-07-08 13:34:08,828 [analyzer] INFO: Added new file to list with pid 720 and path C:\backup.exe
2025-07-08 13:34:36,280 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-08 13:34:36,858 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-08 13:34:36,858 [lib.api.process] INFO: Successfully terminated process with pid 2708.
2025-07-08 13:34:36,858 [lib.api.process] INFO: Successfully terminated process with pid 720.
2025-07-08 13:34:36,905 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-11 18:01:02,862 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:03,888 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:04,920 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:05,956 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:06,991 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:08,007 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:09,060 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:10,188 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:11,321 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:12,348 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:13,372 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:14,410 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:15,450 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:16,502 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:17,564 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:18,622 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:19,683 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:20,729 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:21,922 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:23,070 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:24,123 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:25,181 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:26,232 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:27,465 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:28,506 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:29,569 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:30,746 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:31,821 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:33,031 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:34,064 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:35,156 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:36,445 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:37,481 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:38,508 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:40,096 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:41,118 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:42,141 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:43,467 [cuckoo.core.scheduler] DEBUG: Task #6687012: no machine available yet
2025-07-11 18:01:44,514 [cuckoo.core.scheduler] INFO: Task #6687012: acquired machine win7x645 (label=win7x645)
2025-07-11 18:01:44,516 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.205 for task #6687012
2025-07-11 18:01:44,904 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3657745 (interface=vboxnet0, host=192.168.168.205)
2025-07-11 18:01:45,012 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x645
2025-07-11 18:01:45,890 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x645 to vmcloak
2025-07-11 18:05:14,865 [cuckoo.core.guest] INFO: Starting analysis #6687012 on guest (id=win7x645, ip=192.168.168.205)
2025-07-11 18:05:15,872 [cuckoo.core.guest] DEBUG: win7x645: not ready yet
2025-07-11 18:05:20,900 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x645, ip=192.168.168.205)
2025-07-11 18:05:21,010 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x645, ip=192.168.168.205, monitor=latest, size=6660546)
2025-07-11 18:05:22,515 [cuckoo.core.resultserver] DEBUG: Task #6687012: live log analysis.log initialized.
2025-07-11 18:05:23,486 [cuckoo.core.resultserver] DEBUG: Task #6687012 is sending a BSON stream
2025-07-11 18:05:23,915 [cuckoo.core.resultserver] DEBUG: Task #6687012 is sending a BSON stream
2025-07-11 18:05:24,340 [cuckoo.core.resultserver] DEBUG: Task #6687012 is sending a BSON stream
2025-07-11 18:05:24,755 [cuckoo.core.resultserver] DEBUG: Task #6687012: File upload for 'shots/0001.jpg'
2025-07-11 18:05:24,768 [cuckoo.core.resultserver] DEBUG: Task #6687012 uploaded file length: 133466
2025-07-11 18:05:37,428 [cuckoo.core.guest] DEBUG: win7x645: analysis #6687012 still processing
2025-07-11 18:05:52,924 [cuckoo.core.guest] DEBUG: win7x645: analysis #6687012 still processing
2025-07-11 18:05:53,005 [cuckoo.core.resultserver] DEBUG: Task #6687012: File upload for 'curtain/1751974476.48.curtain.log'
2025-07-11 18:05:53,008 [cuckoo.core.resultserver] DEBUG: Task #6687012 uploaded file length: 36
2025-07-11 18:05:53,211 [cuckoo.core.resultserver] DEBUG: Task #6687012: File upload for 'sysmon/1751974476.69.sysmon.xml'
2025-07-11 18:05:53,394 [cuckoo.core.resultserver] DEBUG: Task #6687012 uploaded file length: 1785564
2025-07-11 18:05:53,404 [cuckoo.core.resultserver] DEBUG: Task #6687012: File upload for 'files/dad26f38bc8b6fad_backup.exe'
2025-07-11 18:05:53,408 [cuckoo.core.resultserver] DEBUG: Task #6687012 uploaded file length: 91636
2025-07-11 18:05:53,411 [cuckoo.core.resultserver] DEBUG: Task #6687012: File upload for 'files/61fb0e75e4f29248_backup.exe'
2025-07-11 18:05:53,436 [cuckoo.core.resultserver] DEBUG: Task #6687012 uploaded file length: 91638
2025-07-11 18:05:53,572 [cuckoo.core.resultserver] DEBUG: Task #6687012 had connection reset for <Context for LOG>
2025-07-11 18:05:55,939 [cuckoo.core.guest] INFO: win7x645: analysis completed successfully
2025-07-11 18:05:55,959 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-11 18:05:55,992 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-11 18:05:57,242 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x645 to path /srv/cuckoo/cwd/storage/analyses/6687012/memory.dmp
2025-07-11 18:05:57,245 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x645
2025-07-11 18:08:17,483 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.205 for task #6687012
2025-07-11 18:08:18,123 [cuckoo.core.scheduler] DEBUG: Released database task #6687012
2025-07-11 18:08:18,162 [cuckoo.core.scheduler] INFO: Task #6687012: analysis procedure completed