Analyzer Log
2025-07-13 19:42:23,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp564etj
2025-07-13 19:42:23,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\CjUKvXdraogqOudCdgdlG
2025-07-13 19:42:23,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\lbgqjWcrFBdrXUbqvXhgoSBJoV
2025-07-13 19:42:23,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-13 19:42:23,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-13 19:42:23,328 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-13 19:42:23,328 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-13 19:42:23,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-13 19:42:24,046 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-07-13 19:42:24,046 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-13 19:42:24,046 [analyzer] DEBUG: Started auxiliary module Human
2025-07-13 19:42:24,046 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-13 19:42:24,046 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-13 19:42:24,108 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-13 19:42:24,108 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-13 19:42:24,108 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-13 19:42:24,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-13 19:42:24,265 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\7638af64bd647a9c_backup.exe' with arguments '' and pid 1560
2025-07-13 19:42:24,467 [analyzer] DEBUG: Loaded monitor into process with pid 1560
2025-07-13 19:42:24,562 [analyzer] INFO: Added new file to list with pid 1560 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-07-13 19:42:24,562 [analyzer] INFO: Added new file to list with pid 1560 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-07-13 19:42:24,625 [analyzer] INFO: Injected into process with pid 2368 and name ''
2025-07-13 19:42:24,796 [analyzer] DEBUG: Loaded monitor into process with pid 2368
2025-07-13 19:42:24,905 [analyzer] INFO: Added new file to list with pid 1560 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-07-13 19:42:24,967 [analyzer] INFO: Added new file to list with pid 1560 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-07-13 19:42:25,875 [analyzer] INFO: Added new file to list with pid 2368 and path C:\backup.exe
2025-07-13 19:45:43,265 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-13 19:45:44,530 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-13 19:45:44,530 [lib.api.process] INFO: Successfully terminated process with pid 1560.
2025-07-13 19:45:44,530 [lib.api.process] INFO: Successfully terminated process with pid 2368.
2025-07-13 19:45:44,546 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-17 16:21:22,867 [cuckoo.core.scheduler] INFO: Task #6727564: acquired machine win7x6419 (label=win7x6419)
2025-07-17 16:21:22,868 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.219 for task #6727564
2025-07-17 16:21:23,509 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 592783 (interface=vboxnet0, host=192.168.168.219)
2025-07-17 16:21:23,632 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6419
2025-07-17 16:21:24,900 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6419 to vmcloak
2025-07-17 16:24:31,323 [cuckoo.core.guest] INFO: Starting analysis #6727564 on guest (id=win7x6419, ip=192.168.168.219)
2025-07-17 16:24:32,330 [cuckoo.core.guest] DEBUG: win7x6419: not ready yet
2025-07-17 16:24:37,549 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6419, ip=192.168.168.219)
2025-07-17 16:24:37,648 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6419, ip=192.168.168.219, monitor=latest, size=6660546)
2025-07-17 16:24:39,301 [cuckoo.core.resultserver] DEBUG: Task #6727564: live log analysis.log initialized.
2025-07-17 16:24:40,264 [cuckoo.core.resultserver] DEBUG: Task #6727564 is sending a BSON stream
2025-07-17 16:24:40,687 [cuckoo.core.resultserver] DEBUG: Task #6727564 is sending a BSON stream
2025-07-17 16:24:40,995 [cuckoo.core.resultserver] DEBUG: Task #6727564 is sending a BSON stream
2025-07-17 16:24:41,480 [cuckoo.core.resultserver] DEBUG: Task #6727564: File upload for 'shots/0001.jpg'
2025-07-17 16:24:41,491 [cuckoo.core.resultserver] DEBUG: Task #6727564 uploaded file length: 133574
2025-07-17 16:24:54,065 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:25:09,359 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:25:24,547 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:25:39,828 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:25:55,325 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:26:11,039 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:26:26,203 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:26:41,480 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:26:56,695 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:27:12,144 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:27:27,596 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:27:42,906 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:27:58,095 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6727564 still processing
2025-07-17 16:27:59,739 [cuckoo.core.resultserver] DEBUG: Task #6727564: File upload for 'curtain/1752428743.45.curtain.log'
2025-07-17 16:27:59,743 [cuckoo.core.resultserver] DEBUG: Task #6727564 uploaded file length: 36
2025-07-17 16:28:00,472 [cuckoo.core.resultserver] DEBUG: Task #6727564: File upload for 'sysmon/1752428744.19.sysmon.xml'
2025-07-17 16:28:00,814 [cuckoo.core.resultserver] DEBUG: Task #6727564 uploaded file length: 10017452
2025-07-17 16:28:00,831 [cuckoo.core.resultserver] DEBUG: Task #6727564: File upload for 'files/a77345e1320c6fb5_backup.exe'
2025-07-17 16:28:00,841 [cuckoo.core.resultserver] DEBUG: Task #6727564: File upload for 'files/20377b6db8c4facc_backup.exe'
2025-07-17 16:28:00,843 [cuckoo.core.resultserver] DEBUG: Task #6727564 uploaded file length: 125682
2025-07-17 16:28:00,847 [cuckoo.core.resultserver] DEBUG: Task #6727564 uploaded file length: 125684
2025-07-17 16:28:00,857 [cuckoo.core.resultserver] DEBUG: Task #6727564 had connection reset for <Context for LOG>
2025-07-17 16:28:01,125 [cuckoo.core.guest] INFO: win7x6419: analysis completed successfully
2025-07-17 16:28:01,139 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-17 16:28:01,165 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-17 16:28:03,039 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6419 to path /srv/cuckoo/cwd/storage/analyses/6727564/memory.dmp
2025-07-17 16:28:03,041 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6419
2025-07-17 16:30:25,750 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.219 for task #6727564
2025-07-17 16:30:26,134 [cuckoo.core.scheduler] DEBUG: Released database task #6727564
2025-07-17 16:30:26,158 [cuckoo.core.scheduler] INFO: Task #6727564: analysis procedure completed