Analyzer Log
2025-07-11 09:00:10,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpf7a_02
2025-07-11 09:00:10,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\snldsbeTmMLfUmPs
2025-07-11 09:00:10,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\bremnVRxIAtlsbLjmUnDjjfo
2025-07-11 09:00:10,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-11 09:00:10,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-11 09:00:10,750 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-11 09:00:10,953 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-07-11 09:00:10,953 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-11 09:00:10,953 [analyzer] DEBUG: Started auxiliary module Human
2025-07-11 09:00:10,953 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-11 09:00:10,953 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-11 09:00:11,046 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-11 09:00:11,046 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-11 09:00:11,062 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-11 09:00:11,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-11 09:00:11,155 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\\u9752\u5c9b\u56fd\u9645\u673a\u573a\u96c6\u56e2\u6709\u9650\u516c\u53f8\u300a\u805a\u4f17\u946b\uff08\u5317\u4eac\uff09\u79d1\u6280\u6709\u9650\u516c\u53f8\u300b\u8bc4\u5ba1\u5f02\u8bae\u6750\u6599\u8868.docx.exe' with arguments '' and pid 2480
2025-07-11 09:00:12,187 [analyzer] INFO: Process with pid 2480 has terminated
2025-07-11 09:00:12,187 [analyzer] INFO: Process list is empty, terminating analysis.
2025-07-11 09:00:13,390 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-11 09:00:13,390 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-11 09:00:32,509 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:33,539 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:34,572 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:35,666 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:36,960 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:38,247 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:39,788 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:41,352 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:42,436 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:43,501 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:44,561 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:45,871 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:46,926 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:47,991 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:49,042 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:50,091 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:51,335 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:52,409 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:53,476 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:54,568 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:55,639 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:56,701 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:58,043 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:00:59,117 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:00,235 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:01,321 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:02,399 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:03,464 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:04,551 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:05,705 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:06,967 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:08,096 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:09,223 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:10,333 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:11,494 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:12,594 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:13,880 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:14,963 [cuckoo.core.scheduler] DEBUG: Task #6719614: no machine available yet
2025-07-11 09:01:16,052 [cuckoo.core.scheduler] INFO: Task #6719614: acquired machine win7x6427 (label=win7x6427)
2025-07-11 09:01:16,055 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.227 for task #6719614
2025-07-11 09:01:16,527 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2765736 (interface=vboxnet0, host=192.168.168.227)
2025-07-11 09:01:18,101 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6427
2025-07-11 09:01:19,096 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6427 to vmcloak
2025-07-11 09:03:54,600 [cuckoo.core.guest] INFO: Starting analysis #6719614 on guest (id=win7x6427, ip=192.168.168.227)
2025-07-11 09:03:55,608 [cuckoo.core.guest] DEBUG: win7x6427: not ready yet
2025-07-11 09:04:00,649 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6427, ip=192.168.168.227)
2025-07-11 09:04:00,768 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6427, ip=192.168.168.227, monitor=latest, size=6660546)
2025-07-11 09:04:02,384 [cuckoo.core.resultserver] DEBUG: Task #6719614: live log analysis.log initialized.
2025-07-11 09:04:03,287 [cuckoo.core.resultserver] DEBUG: Task #6719614 is sending a BSON stream
2025-07-11 09:04:04,739 [cuckoo.core.resultserver] DEBUG: Task #6719614: File upload for 'shots/0001.jpg'
2025-07-11 09:04:04,753 [cuckoo.core.resultserver] DEBUG: Task #6719614 uploaded file length: 133452
2025-07-11 09:04:05,673 [cuckoo.core.resultserver] DEBUG: Task #6719614: File upload for 'curtain/1752217213.27.curtain.log'
2025-07-11 09:04:05,675 [cuckoo.core.resultserver] DEBUG: Task #6719614 uploaded file length: 36
2025-07-11 09:04:05,787 [cuckoo.core.resultserver] DEBUG: Task #6719614: File upload for 'sysmon/1752217213.38.sysmon.xml'
2025-07-11 09:04:05,793 [cuckoo.core.resultserver] DEBUG: Task #6719614 uploaded file length: 443822
2025-07-11 09:04:05,806 [cuckoo.core.resultserver] DEBUG: Task #6719614 had connection reset for <Context for LOG>
2025-07-11 09:04:07,897 [cuckoo.core.guest] INFO: win7x6427: analysis completed successfully
2025-07-11 09:04:07,906 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-11 09:04:07,941 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-11 09:04:09,091 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6427 to path /srv/cuckoo/cwd/storage/analyses/6719614/memory.dmp
2025-07-11 09:04:09,092 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6427
2025-07-11 09:07:21,207 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.227 for task #6719614
2025-07-11 09:07:21,667 [cuckoo.core.scheduler] DEBUG: Released database task #6719614
2025-07-11 09:07:35,020 [cuckoo.core.scheduler] INFO: Task #6719614: analysis procedure completed