Analyzer Log
2025-07-09 03:09:38,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp564etj
2025-07-09 03:09:38,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\kvWyksIFMkIhbSAifIlORqvpNhwOylJ
2025-07-09 03:09:38,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\PDvIBZisBmNsubiyWkvkjS
2025-07-09 03:09:38,405 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-09 03:09:38,405 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-09 03:09:39,046 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-09 03:09:39,296 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-07-09 03:09:39,296 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-09 03:09:39,296 [analyzer] DEBUG: Started auxiliary module Human
2025-07-09 03:09:39,296 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-09 03:09:39,296 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-09 03:09:39,421 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-09 03:09:39,421 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-09 03:09:39,421 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-09 03:09:39,421 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-09 03:09:39,608 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d0c7cb65ad04f1db0307045c461ea2b64c0af7bd2c4ed38a72091d053672b3e1.exe' with arguments '' and pid 1560
2025-07-09 03:09:39,858 [analyzer] DEBUG: Loaded monitor into process with pid 1560
2025-07-09 03:09:39,937 [analyzer] INFO: Added new file to list with pid 1560 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-07-09 03:09:39,967 [analyzer] INFO: Added new file to list with pid 1560 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-07-09 03:09:40,078 [analyzer] INFO: Injected into process with pid 2988 and name ''
2025-07-09 03:09:40,250 [analyzer] DEBUG: Loaded monitor into process with pid 2988
2025-07-09 03:09:40,328 [analyzer] INFO: Added new file to list with pid 1560 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-07-09 03:09:40,467 [analyzer] INFO: Added new file to list with pid 1560 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-07-09 03:09:41,296 [analyzer] INFO: Added new file to list with pid 2988 and path C:\backup.exe
2025-07-09 03:10:08,625 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-09 03:10:09,078 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-09 03:10:09,078 [lib.api.process] INFO: Successfully terminated process with pid 1560.
2025-07-09 03:10:09,078 [lib.api.process] INFO: Successfully terminated process with pid 2988.
2025-07-09 03:10:09,108 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-13 19:34:17,894 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:18,922 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:19,948 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:20,979 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:22,012 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:23,050 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:24,078 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:25,109 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:26,148 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:27,187 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:28,213 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:29,229 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:30,255 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:31,286 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:32,312 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:33,364 [cuckoo.core.scheduler] DEBUG: Task #6700426: no machine available yet
2025-07-13 19:34:34,512 [cuckoo.core.scheduler] INFO: Task #6700426: acquired machine win7x6419 (label=win7x6419)
2025-07-13 19:34:34,514 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.219 for task #6700426
2025-07-13 19:34:34,915 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 40322 (interface=vboxnet0, host=192.168.168.219)
2025-07-13 19:34:35,064 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6419
2025-07-13 19:34:36,027 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6419 to vmcloak
2025-07-13 19:37:42,358 [cuckoo.core.guest] INFO: Starting analysis #6700426 on guest (id=win7x6419, ip=192.168.168.219)
2025-07-13 19:37:43,363 [cuckoo.core.guest] DEBUG: win7x6419: not ready yet
2025-07-13 19:37:48,412 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6419, ip=192.168.168.219)
2025-07-13 19:37:48,509 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6419, ip=192.168.168.219, monitor=latest, size=6660546)
2025-07-13 19:37:50,677 [cuckoo.core.resultserver] DEBUG: Task #6700426: live log analysis.log initialized.
2025-07-13 19:37:51,933 [cuckoo.core.resultserver] DEBUG: Task #6700426 is sending a BSON stream
2025-07-13 19:37:52,480 [cuckoo.core.resultserver] DEBUG: Task #6700426 is sending a BSON stream
2025-07-13 19:37:52,874 [cuckoo.core.resultserver] DEBUG: Task #6700426 is sending a BSON stream
2025-07-13 19:37:53,259 [cuckoo.core.resultserver] DEBUG: Task #6700426: File upload for 'shots/0001.jpg'
2025-07-13 19:37:53,271 [cuckoo.core.resultserver] DEBUG: Task #6700426 uploaded file length: 133545
2025-07-13 19:38:05,344 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6700426 still processing
2025-07-13 19:38:20,448 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6700426 still processing
2025-07-13 19:38:21,516 [cuckoo.core.resultserver] DEBUG: Task #6700426: File upload for 'curtain/1752023408.81.curtain.log'
2025-07-13 19:38:21,520 [cuckoo.core.resultserver] DEBUG: Task #6700426 uploaded file length: 36
2025-07-13 19:38:21,757 [cuckoo.core.resultserver] DEBUG: Task #6700426: File upload for 'sysmon/1752023409.05.sysmon.xml'
2025-07-13 19:38:21,783 [cuckoo.core.resultserver] DEBUG: Task #6700426 uploaded file length: 1544642
2025-07-13 19:38:21,790 [cuckoo.core.resultserver] DEBUG: Task #6700426: File upload for 'files/7638af64bd647a9c_backup.exe'
2025-07-13 19:38:21,794 [cuckoo.core.resultserver] DEBUG: Task #6700426 uploaded file length: 125680
2025-07-13 19:38:21,796 [cuckoo.core.resultserver] DEBUG: Task #6700426: File upload for 'files/9c202ace598ff41a_backup.exe'
2025-07-13 19:38:21,799 [cuckoo.core.resultserver] DEBUG: Task #6700426 uploaded file length: 125682
2025-07-13 19:38:21,801 [cuckoo.core.resultserver] DEBUG: Task #6700426: File upload for 'files/101db55863c633b5_backup.exe'
2025-07-13 19:38:21,805 [cuckoo.core.resultserver] DEBUG: Task #6700426 uploaded file length: 125680
2025-07-13 19:38:22,145 [cuckoo.core.resultserver] DEBUG: Task #6700426 had connection reset for <Context for LOG>
2025-07-13 19:38:23,464 [cuckoo.core.guest] INFO: win7x6419: analysis completed successfully
2025-07-13 19:38:23,490 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-13 19:38:23,520 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-13 19:38:24,682 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6419 to path /srv/cuckoo/cwd/storage/analyses/6700426/memory.dmp
2025-07-13 19:38:24,684 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6419
2025-07-13 19:41:30,458 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.219 for task #6700426
2025-07-13 19:41:30,903 [cuckoo.core.scheduler] DEBUG: Released database task #6700426
2025-07-13 19:41:30,950 [cuckoo.core.scheduler] INFO: Task #6700426: analysis procedure completed