Analyzer Log
2025-07-09 03:09:29,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpht3fil
2025-07-09 03:09:29,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\yTtyOufreRmUiBIezxLZhSuaklf
2025-07-09 03:09:29,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\cJmqfEalwSFxjmLtptgrh
2025-07-09 03:09:29,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-09 03:09:29,328 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-09 03:09:29,828 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-09 03:09:30,030 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-07-09 03:09:30,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-09 03:09:30,030 [analyzer] DEBUG: Started auxiliary module Human
2025-07-09 03:09:30,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-09 03:09:30,030 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-09 03:09:30,125 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-09 03:09:30,125 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-09 03:09:30,125 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-09 03:09:30,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-09 03:09:30,250 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\1754622fb1f8fac4eb509f473ba772b20ed3ec9c699eb535c258dd96e1f5e70c.exe' with arguments '' and pid 1628
2025-07-09 03:09:30,437 [analyzer] DEBUG: Loaded monitor into process with pid 1628
2025-07-09 03:09:31,250 [analyzer] INFO: Process with pid 1628 has terminated
2025-07-09 03:09:31,250 [analyzer] INFO: Process list is empty, terminating analysis.
2025-07-09 03:09:32,515 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-09 03:09:32,515 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-13 19:25:51,941 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:25:52,972 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:25:53,998 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:25:55,034 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:25:56,067 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:25:57,196 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:25:58,222 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:25:59,246 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:00,286 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:01,335 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:02,375 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:03,482 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:04,504 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:05,528 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:06,556 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:07,586 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:08,616 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:09,719 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:10,809 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:12,056 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:13,147 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:14,240 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:15,351 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:16,442 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:17,511 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:18,593 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:19,617 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:20,639 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:21,665 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:22,689 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:23,714 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:24,744 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:25,772 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:26,793 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:27,819 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:28,839 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:29,861 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:30,888 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:31,909 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:33,041 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:34,064 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:35,084 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:36,107 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:37,150 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:38,207 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:39,303 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:40,380 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:41,465 [cuckoo.core.scheduler] DEBUG: Task #6700392: no machine available yet
2025-07-13 19:26:42,538 [cuckoo.core.scheduler] INFO: Task #6700392: acquired machine win7x6411 (label=win7x6411)
2025-07-13 19:26:42,539 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.211 for task #6700392
2025-07-13 19:26:42,943 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 30139 (interface=vboxnet0, host=192.168.168.211)
2025-07-13 19:26:43,036 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6411
2025-07-13 19:26:44,132 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6411 to vmcloak
2025-07-13 19:29:19,926 [cuckoo.core.guest] INFO: Starting analysis #6700392 on guest (id=win7x6411, ip=192.168.168.211)
2025-07-13 19:29:20,933 [cuckoo.core.guest] DEBUG: win7x6411: not ready yet
2025-07-13 19:29:25,967 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6411, ip=192.168.168.211)
2025-07-13 19:29:26,077 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6411, ip=192.168.168.211, monitor=latest, size=6660546)
2025-07-13 19:29:27,688 [cuckoo.core.resultserver] DEBUG: Task #6700392: live log analysis.log initialized.
2025-07-13 19:29:28,664 [cuckoo.core.resultserver] DEBUG: Task #6700392 is sending a BSON stream
2025-07-13 19:29:29,053 [cuckoo.core.resultserver] DEBUG: Task #6700392 is sending a BSON stream
2025-07-13 19:29:29,947 [cuckoo.core.resultserver] DEBUG: Task #6700392: File upload for 'shots/0001.jpg'
2025-07-13 19:29:30,006 [cuckoo.core.resultserver] DEBUG: Task #6700392 uploaded file length: 133441
2025-07-13 19:29:31,074 [cuckoo.core.resultserver] DEBUG: Task #6700392: File upload for 'curtain/1752023372.38.curtain.log'
2025-07-13 19:29:31,079 [cuckoo.core.resultserver] DEBUG: Task #6700392 uploaded file length: 36
2025-07-13 19:29:31,207 [cuckoo.core.resultserver] DEBUG: Task #6700392: File upload for 'sysmon/1752023372.5.sysmon.xml'
2025-07-13 19:29:31,214 [cuckoo.core.resultserver] DEBUG: Task #6700392 uploaded file length: 191076
2025-07-13 19:29:32,095 [cuckoo.core.resultserver] DEBUG: Task #6700392 had connection reset for <Context for LOG>
2025-07-13 19:29:33,228 [cuckoo.core.guest] INFO: win7x6411: analysis completed successfully
2025-07-13 19:29:33,241 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-13 19:29:33,280 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-13 19:29:34,365 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6411 to path /srv/cuckoo/cwd/storage/analyses/6700392/memory.dmp
2025-07-13 19:29:34,367 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6411
2025-07-13 19:33:02,098 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.211 for task #6700392
2025-07-13 19:33:02,507 [cuckoo.core.scheduler] DEBUG: Released database task #6700392
2025-07-13 19:33:02,522 [cuckoo.core.scheduler] INFO: Task #6700392: analysis procedure completed