Analyzer Log
2025-07-11 09:19:13,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpblqbwr
2025-07-11 09:19:13,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\YDziYSXeXVeoxlKpRVyoZeHzeIP
2025-07-11 09:19:13,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\qJdhNdJKpvjeexWmOCy
2025-07-11 09:19:13,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-11 09:19:13,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-11 09:19:13,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-11 09:19:13,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-11 09:19:13,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-11 09:19:13,983 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-07-11 09:19:13,983 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-11 09:19:13,983 [analyzer] DEBUG: Started auxiliary module Human
2025-07-11 09:19:13,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-11 09:19:14,000 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-11 09:19:14,078 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-11 09:19:14,078 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-11 09:19:14,078 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-11 09:19:14,092 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-11 09:19:14,203 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\c1192ea13eb46357_half-life 2 nocd.exe' with arguments '' and pid 2380
2025-07-11 09:19:14,421 [analyzer] DEBUG: Loaded monitor into process with pid 2380
2025-07-11 09:19:14,437 [analyzer] INFO: Added new file to list with pid 2380 and path C:\Windows\win32dc\BattleField 1942 hack.exe
2025-07-11 09:19:14,437 [analyzer] INFO: Added new file to list with pid 2380 and path C:\Windows\win32dc\Quake3 + fix.exe
2025-07-11 09:19:14,453 [analyzer] INFO: Added new file to list with pid 2380 and path C:\Windows\win32dc\Doom 3_hack.exe
2025-07-11 09:19:14,483 [analyzer] INFO: Added new file to list with pid 2380 and path C:\Windows\win32dc\Half-Life 2_nocd.exe
2025-07-11 09:19:14,500 [analyzer] INFO: Added new file to list with pid 2380 and path C:\Windows\win32dc\Half-Life 2 hack.exe
2025-07-11 09:19:14,515 [analyzer] INFO: Added new file to list with pid 2380 and path C:\Windows\win32dc\Silent Hill 4 + serial.exe
2025-07-11 09:19:14,530 [analyzer] INFO: Added new file to list with pid 2380 and path C:\Windows\win32dc\FlatOut(cheat).exe
2025-07-11 09:22:33,203 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-11 09:22:34,203 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-11 09:22:34,203 [lib.api.process] INFO: Successfully terminated process with pid 2380.
2025-07-11 09:22:34,233 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-16 15:47:18,662 [cuckoo.core.scheduler] DEBUG: Task #6719676: no machine available yet
2025-07-16 15:47:19,724 [cuckoo.core.scheduler] INFO: Task #6719676: acquired machine win7x6418 (label=win7x6418)
2025-07-16 15:47:19,728 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.218 for task #6719676
2025-07-16 15:47:20,327 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2446245 (interface=vboxnet0, host=192.168.168.218)
2025-07-16 15:47:20,604 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6418
2025-07-16 15:47:22,044 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6418 to vmcloak
2025-07-16 15:49:47,017 [cuckoo.core.guest] INFO: Starting analysis #6719676 on guest (id=win7x6418, ip=192.168.168.218)
2025-07-16 15:49:48,024 [cuckoo.core.guest] DEBUG: win7x6418: not ready yet
2025-07-16 15:49:53,051 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6418, ip=192.168.168.218)
2025-07-16 15:49:53,137 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6418, ip=192.168.168.218, monitor=latest, size=6660546)
2025-07-16 15:49:54,327 [cuckoo.core.resultserver] DEBUG: Task #6719676: live log analysis.log initialized.
2025-07-16 15:49:55,260 [cuckoo.core.resultserver] DEBUG: Task #6719676 is sending a BSON stream
2025-07-16 15:49:55,888 [cuckoo.core.resultserver] DEBUG: Task #6719676 is sending a BSON stream
2025-07-16 15:49:56,515 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'shots/0001.jpg'
2025-07-16 15:49:56,532 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 136535
2025-07-16 15:50:09,326 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:50:24,989 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:50:40,134 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:50:55,262 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:51:10,848 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:51:26,245 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:51:41,606 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:51:56,741 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:52:11,854 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:52:27,167 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:52:42,328 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:52:57,570 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:53:12,666 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6719676 still processing
2025-07-16 15:53:14,738 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'curtain/1752218553.39.curtain.log'
2025-07-16 15:53:14,741 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 36
2025-07-16 15:53:15,448 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'sysmon/1752218554.06.sysmon.xml'
2025-07-16 15:53:15,545 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 10022566
2025-07-16 15:53:15,562 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'files/e99658d3a452710e_battlefield 1942 hack.exe'
2025-07-16 15:53:15,566 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'files/b2aad6b5e6035463_half-life 2 hack.exe'
2025-07-16 15:53:15,569 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 106583
2025-07-16 15:53:15,571 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'files/76f1304bf343b3d0_doom 3_hack.exe'
2025-07-16 15:53:15,574 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'files/960649628cadc85d_silent hill 4 + serial.exe'
2025-07-16 15:53:15,577 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 107607
2025-07-16 15:53:15,579 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 108631
2025-07-16 15:53:15,580 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 107607
2025-07-16 15:53:15,582 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'files/8273f88a22875c9c_half-life 2_nocd.exe'
2025-07-16 15:53:15,585 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'files/d0109359c6b064be_quake3 + fix.exe'
2025-07-16 15:53:15,588 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 107607
2025-07-16 15:53:15,590 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 109655
2025-07-16 15:53:15,595 [cuckoo.core.resultserver] DEBUG: Task #6719676: File upload for 'files/249a997e577d3fcb_flatout(cheat).exe'
2025-07-16 15:53:15,600 [cuckoo.core.resultserver] DEBUG: Task #6719676 uploaded file length: 106583
2025-07-16 15:53:15,604 [cuckoo.core.resultserver] DEBUG: Task #6719676 had connection reset for <Context for LOG>
2025-07-16 15:53:15,684 [cuckoo.core.guest] INFO: win7x6418: analysis completed successfully
2025-07-16 15:53:15,705 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-16 15:53:15,739 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-16 15:53:17,359 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6418 to path /srv/cuckoo/cwd/storage/analyses/6719676/memory.dmp
2025-07-16 15:53:17,370 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6418
2025-07-16 15:55:10,114 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.218 for task #6719676
2025-07-16 15:55:10,496 [cuckoo.core.scheduler] DEBUG: Released database task #6719676
2025-07-16 15:55:10,513 [cuckoo.core.scheduler] INFO: Task #6719676: analysis procedure completed