Analyzer Log
2025-07-13 19:42:15,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpwoh6zt
2025-07-13 19:42:15,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\gCHfZjHilyUgqFZvAjhsDKJmWOPvOxT
2025-07-13 19:42:15,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\bErFevxgGKtQigzBBxOjpIeHR
2025-07-13 19:42:15,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-13 19:42:15,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-13 19:42:15,328 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-13 19:42:15,328 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-13 19:42:15,890 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-13 19:42:16,092 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-07-13 19:42:16,092 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-13 19:42:16,092 [analyzer] DEBUG: Started auxiliary module Human
2025-07-13 19:42:16,092 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-13 19:42:16,092 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-13 19:42:16,155 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-13 19:42:16,155 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-13 19:42:16,155 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-13 19:42:16,155 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-13 19:42:16,296 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\e358961abc559d88_backup.exe' with arguments '' and pid 1540
2025-07-13 19:42:16,500 [analyzer] DEBUG: Loaded monitor into process with pid 1540
2025-07-13 19:42:16,562 [analyzer] INFO: Added new file to list with pid 1540 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-07-13 19:42:16,578 [analyzer] INFO: Added new file to list with pid 1540 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-07-13 19:42:16,655 [analyzer] INFO: Injected into process with pid 2768 and name ''
2025-07-13 19:42:16,828 [analyzer] DEBUG: Loaded monitor into process with pid 2768
2025-07-13 19:42:16,890 [analyzer] INFO: Added new file to list with pid 1540 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-07-13 19:42:16,967 [analyzer] INFO: Added new file to list with pid 1540 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-07-13 19:42:17,890 [analyzer] INFO: Added new file to list with pid 2768 and path C:\backup.exe
2025-07-13 19:45:35,296 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-13 19:45:37,358 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-13 19:45:37,358 [lib.api.process] INFO: Successfully terminated process with pid 1540.
2025-07-13 19:45:37,358 [lib.api.process] INFO: Successfully terminated process with pid 2768.
2025-07-13 19:45:37,375 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-17 16:20:40,148 [cuckoo.core.scheduler] INFO: Task #6727561: acquired machine win7x643 (label=win7x643)
2025-07-17 16:20:40,149 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.203 for task #6727561
2025-07-17 16:20:40,866 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 591903 (interface=vboxnet0, host=192.168.168.203)
2025-07-17 16:20:41,367 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x643
2025-07-17 16:20:42,606 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x643 to vmcloak
2025-07-17 16:23:39,467 [cuckoo.core.guest] INFO: Starting analysis #6727561 on guest (id=win7x643, ip=192.168.168.203)
2025-07-17 16:23:40,474 [cuckoo.core.guest] DEBUG: win7x643: not ready yet
2025-07-17 16:23:45,495 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x643, ip=192.168.168.203)
2025-07-17 16:23:45,577 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x643, ip=192.168.168.203, monitor=latest, size=6660546)
2025-07-17 16:23:46,839 [cuckoo.core.resultserver] DEBUG: Task #6727561: live log analysis.log initialized.
2025-07-17 16:23:47,880 [cuckoo.core.resultserver] DEBUG: Task #6727561 is sending a BSON stream
2025-07-17 16:23:48,284 [cuckoo.core.resultserver] DEBUG: Task #6727561 is sending a BSON stream
2025-07-17 16:23:48,598 [cuckoo.core.resultserver] DEBUG: Task #6727561 is sending a BSON stream
2025-07-17 16:23:49,118 [cuckoo.core.resultserver] DEBUG: Task #6727561: File upload for 'shots/0001.jpg'
2025-07-17 16:23:49,128 [cuckoo.core.resultserver] DEBUG: Task #6727561 uploaded file length: 133463
2025-07-17 16:24:01,469 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:24:16,729 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:24:32,175 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:24:47,452 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:25:02,735 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:25:17,869 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:25:33,144 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:25:48,301 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:26:03,462 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:26:18,717 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:26:34,313 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:26:50,104 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:27:05,344 [cuckoo.core.guest] DEBUG: win7x643: analysis #6727561 still processing
2025-07-17 16:27:07,373 [cuckoo.core.resultserver] DEBUG: Task #6727561: File upload for 'curtain/1752428735.52.curtain.log'
2025-07-17 16:27:07,376 [cuckoo.core.resultserver] DEBUG: Task #6727561 uploaded file length: 36
2025-07-17 16:27:08,542 [cuckoo.core.resultserver] DEBUG: Task #6727561: File upload for 'sysmon/1752428736.28.sysmon.xml'
2025-07-17 16:27:09,216 [cuckoo.core.resultserver] DEBUG: Task #6727561 uploaded file length: 9697474
2025-07-17 16:27:09,266 [cuckoo.core.resultserver] DEBUG: Task #6727561 had connection reset for <Context for LOG>
2025-07-17 16:27:09,267 [cuckoo.core.resultserver] DEBUG: Task #6727561: File upload for 'files/b42fd392ac226ddb_backup.exe'
2025-07-17 16:27:09,270 [cuckoo.core.resultserver] DEBUG: Task #6727561: File upload for 'files/f72fbd607fbfb6b2_backup.exe'
2025-07-17 16:27:09,272 [cuckoo.core.resultserver] DEBUG: Task #6727561 uploaded file length: 90372
2025-07-17 16:27:09,274 [cuckoo.core.resultserver] DEBUG: Task #6727561 uploaded file length: 90374
2025-07-17 16:27:11,862 [cuckoo.core.guest] INFO: win7x643: analysis completed successfully
2025-07-17 16:27:11,875 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-17 16:27:11,911 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-17 16:27:13,427 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x643 to path /srv/cuckoo/cwd/storage/analyses/6727561/memory.dmp
2025-07-17 16:27:13,429 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x643
2025-07-17 16:29:29,349 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.203 for task #6727561
2025-07-17 16:29:30,031 [cuckoo.core.scheduler] DEBUG: Released database task #6727561
2025-07-17 16:29:30,049 [cuckoo.core.scheduler] INFO: Task #6727561: analysis procedure completed