Analyzer Log
2025-07-14 13:00:05,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp564etj
2025-07-14 13:00:05,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\kebAHLEMRuUpYkBYKPn
2025-07-14 13:00:05,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\qQgoEJIUufaYeaMGYznSKYPiAKFRf
2025-07-14 13:00:05,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-14 13:00:05,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-14 13:00:05,405 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-14 13:00:05,405 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-14 13:00:05,937 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-14 13:00:06,155 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-07-14 13:00:06,155 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-14 13:00:06,155 [analyzer] DEBUG: Started auxiliary module Human
2025-07-14 13:00:06,155 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-14 13:00:06,171 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-14 13:00:06,233 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-14 13:00:06,233 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-14 13:00:06,233 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-14 13:00:06,233 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-14 13:00:06,358 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\afa29518deb31dfa_umcuwp8de.exe' with arguments '' and pid 2924
2025-07-14 13:00:06,562 [analyzer] DEBUG: Loaded monitor into process with pid 2924
2025-07-14 13:00:06,562 [analyzer] INFO: Added new file to list with pid 2924 and path C:\Users\Administrator\AppData\Roaming\v9g0134h.exe
2025-07-14 13:00:06,640 [analyzer] INFO: Injected into process with pid 392 and name u'v9g0134h.exe'
2025-07-14 13:00:06,812 [analyzer] DEBUG: Loaded monitor into process with pid 392
2025-07-14 13:00:06,812 [analyzer] INFO: Added new file to list with pid 392 and path C:\Users\Administrator\AppData\Roaming\2hepw.exe
2025-07-14 13:00:06,890 [analyzer] INFO: Injected into process with pid 2900 and name u'2hepw.exe'
2025-07-14 13:00:07,062 [analyzer] DEBUG: Loaded monitor into process with pid 2900
2025-07-14 13:00:52,453 [analyzer] INFO: Added new file to list with pid 2900 and path C:\Users\Administrator\AppData\Roaming2nw0
2025-07-14 13:01:07,375 [analyzer] INFO: Process with pid 2924 has terminated
2025-07-14 13:01:08,375 [analyzer] INFO: Process with pid 392 has terminated
2025-07-14 13:03:25,375 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-14 13:03:27,625 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-14 13:03:27,640 [lib.api.process] INFO: Successfully terminated process with pid 2900.
2025-07-14 13:03:27,671 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-18 15:21:54,239 [cuckoo.core.scheduler] INFO: Task #6732359: acquired machine win7x6419 (label=win7x6419)
2025-07-18 15:21:54,240 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.219 for task #6732359
2025-07-18 15:21:54,607 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2759702 (interface=vboxnet0, host=192.168.168.219)
2025-07-18 15:21:54,768 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6419
2025-07-18 15:21:55,723 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6419 to vmcloak
2025-07-18 15:23:51,572 [cuckoo.core.guest] INFO: Starting analysis #6732359 on guest (id=win7x6419, ip=192.168.168.219)
2025-07-18 15:23:52,577 [cuckoo.core.guest] DEBUG: win7x6419: not ready yet
2025-07-18 15:23:57,600 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6419, ip=192.168.168.219)
2025-07-18 15:23:57,714 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6419, ip=192.168.168.219, monitor=latest, size=6660546)
2025-07-18 15:23:59,224 [cuckoo.core.resultserver] DEBUG: Task #6732359: live log analysis.log initialized.
2025-07-18 15:24:00,332 [cuckoo.core.resultserver] DEBUG: Task #6732359 is sending a BSON stream
2025-07-18 15:24:00,722 [cuckoo.core.resultserver] DEBUG: Task #6732359 is sending a BSON stream
2025-07-18 15:24:00,974 [cuckoo.core.resultserver] DEBUG: Task #6732359 is sending a BSON stream
2025-07-18 15:24:01,222 [cuckoo.core.resultserver] DEBUG: Task #6732359 is sending a BSON stream
2025-07-18 15:24:01,586 [cuckoo.core.resultserver] DEBUG: Task #6732359: File upload for 'shots/0001.jpg'
2025-07-18 15:24:01,603 [cuckoo.core.resultserver] DEBUG: Task #6732359 uploaded file length: 133548
2025-07-18 15:24:14,048 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:24:29,146 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:24:44,230 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:24:59,318 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:25:14,517 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:25:29,645 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:25:44,769 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:25:59,988 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:26:15,210 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:26:30,391 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:26:45,620 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:27:00,842 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:27:16,200 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6732359 still processing
2025-07-18 15:27:19,858 [cuckoo.core.resultserver] DEBUG: Task #6732359: File upload for 'curtain/1752491005.61.curtain.log'
2025-07-18 15:27:19,865 [cuckoo.core.resultserver] DEBUG: Task #6732359 uploaded file length: 36
2025-07-18 15:27:21,557 [cuckoo.core.resultserver] DEBUG: Task #6732359: File upload for 'sysmon/1752491007.16.sysmon.xml'
2025-07-18 15:27:21,872 [cuckoo.core.resultserver] DEBUG: Task #6732359 uploaded file length: 14557466
2025-07-18 15:27:21,907 [cuckoo.core.resultserver] DEBUG: Task #6732359: File upload for 'files/bf8e008adec34932_2hepw.exe'
2025-07-18 15:27:21,911 [cuckoo.core.resultserver] DEBUG: Task #6732359: File upload for 'files/0b05c32f3872c0e5_v9g0134h.exe'
2025-07-18 15:27:21,927 [cuckoo.core.resultserver] DEBUG: Task #6732359 uploaded file length: 62976
2025-07-18 15:27:21,929 [cuckoo.core.resultserver] DEBUG: Task #6732359 uploaded file length: 62976
2025-07-18 15:27:21,938 [cuckoo.core.resultserver] DEBUG: Task #6732359: File upload for 'files/bffee5d05218adc1_roaming2nw0'
2025-07-18 15:27:21,940 [cuckoo.core.resultserver] DEBUG: Task #6732359 uploaded file length: 100
2025-07-18 15:27:21,942 [cuckoo.core.resultserver] DEBUG: Task #6732359 had connection reset for <Context for LOG>
2025-07-18 15:27:22,243 [cuckoo.core.guest] INFO: win7x6419: analysis completed successfully
2025-07-18 15:27:22,260 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-18 15:27:22,291 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-18 15:27:23,419 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6419 to path /srv/cuckoo/cwd/storage/analyses/6732359/memory.dmp
2025-07-18 15:27:23,422 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6419
2025-07-18 15:28:34,853 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.219 for task #6732359
2025-07-18 15:28:35,289 [cuckoo.core.scheduler] DEBUG: Released database task #6732359
2025-07-18 15:28:35,310 [cuckoo.core.scheduler] INFO: Task #6732359: analysis procedure completed