Analyzer Log
2025-07-23 07:59:06,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4
2025-07-23 07:59:06,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\gQqQspBdDsJywooALqWRwHYigpe
2025-07-23 07:59:06,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\KhzwkeGpeMYdbtGLgQKbzk
2025-07-23 07:59:06,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-23 07:59:06,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-23 07:59:06,421 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-23 07:59:06,437 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-23 07:59:06,890 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-23 07:59:07,092 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-07-23 07:59:07,092 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-23 07:59:07,092 [analyzer] DEBUG: Started auxiliary module Human
2025-07-23 07:59:07,092 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-23 07:59:07,108 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-23 07:59:07,203 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-23 07:59:07,203 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-23 07:59:07,203 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-23 07:59:07,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-23 07:59:07,342 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\a8bb8d43053b171d_backup.exe' with arguments '' and pid 2552
2025-07-23 07:59:07,562 [analyzer] DEBUG: Loaded monitor into process with pid 2552
2025-07-23 07:59:07,640 [analyzer] INFO: Added new file to list with pid 2552 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe
2025-07-23 07:59:07,655 [analyzer] INFO: Added new file to list with pid 2552 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe
2025-07-23 07:59:07,750 [analyzer] INFO: Injected into process with pid 2032 and name ''
2025-07-23 07:59:07,921 [analyzer] DEBUG: Loaded monitor into process with pid 2032
2025-07-23 07:59:08,015 [analyzer] INFO: Added new file to list with pid 2552 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe
2025-07-23 07:59:08,125 [analyzer] INFO: Added new file to list with pid 2552 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe
2025-07-23 07:59:08,983 [analyzer] INFO: Added new file to list with pid 2032 and path C:\backup.exe
2025-07-23 10:06:38,605 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-07-23 10:06:39,762 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-23 10:06:39,762 [lib.api.process] INFO: Successfully terminated process with pid 2552.
2025-07-23 10:06:39,762 [lib.api.process] INFO: Successfully terminated process with pid 2032.
2025-07-23 10:06:39,778 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-07-23 11:02:21,535 [cuckoo.core.scheduler] INFO: Task #6755835: acquired machine win7x644 (label=win7x644)
2025-07-23 11:02:21,536 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #6755835
2025-07-23 11:02:22,002 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2460845 (interface=vboxnet0, host=192.168.168.204)
2025-07-23 11:02:22,079 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644
2025-07-23 11:02:23,299 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak
2025-07-23 11:03:10,408 [cuckoo.core.guest] INFO: Starting analysis #6755835 on guest (id=win7x644, ip=192.168.168.204)
2025-07-23 11:03:11,415 [cuckoo.core.guest] DEBUG: win7x644: not ready yet
2025-07-23 11:03:16,445 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204)
2025-07-23 11:03:16,547 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546)
2025-07-23 11:03:18,234 [cuckoo.core.resultserver] DEBUG: Task #6755835: live log analysis.log initialized.
2025-07-23 11:03:19,280 [cuckoo.core.resultserver] DEBUG: Task #6755835 is sending a BSON stream
2025-07-23 11:03:19,734 [cuckoo.core.resultserver] DEBUG: Task #6755835 is sending a BSON stream
2025-07-23 11:03:20,094 [cuckoo.core.resultserver] DEBUG: Task #6755835 is sending a BSON stream
2025-07-23 11:03:20,601 [cuckoo.core.resultserver] DEBUG: Task #6755835: File upload for 'shots/0001.jpg'
2025-07-23 11:03:20,619 [cuckoo.core.resultserver] DEBUG: Task #6755835 uploaded file length: 133495
2025-07-23 11:03:32,855 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:03:48,770 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:04:04,267 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:04:19,528 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:04:34,727 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:04:49,830 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:05:05,606 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:05:20,712 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:05:35,790 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:05:51,321 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:06:06,700 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:06:21,878 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:06:37,016 [cuckoo.core.guest] DEBUG: win7x644: analysis #6755835 still processing
2025-07-23 11:06:38,792 [cuckoo.core.resultserver] DEBUG: Task #6755835: File upload for 'curtain/1753257998.78.curtain.log'
2025-07-23 11:06:38,797 [cuckoo.core.resultserver] DEBUG: Task #6755835 uploaded file length: 36
2025-07-23 11:06:39,677 [cuckoo.core.resultserver] DEBUG: Task #6755835: File upload for 'sysmon/1753257999.67.sysmon.xml'
2025-07-23 11:06:39,765 [cuckoo.core.resultserver] DEBUG: Task #6755835 uploaded file length: 13406284
2025-07-23 11:06:39,792 [cuckoo.core.resultserver] DEBUG: Task #6755835: File upload for 'files/3cef0fa967599dfa_backup.exe'
2025-07-23 11:06:39,795 [cuckoo.core.resultserver] DEBUG: Task #6755835: File upload for 'files/1ff1865ea45bc411_backup.exe'
2025-07-23 11:06:39,797 [cuckoo.core.resultserver] DEBUG: Task #6755835: File upload for 'files/53b6b3f41051a31c_backup.exe'
2025-07-23 11:06:39,799 [cuckoo.core.resultserver] DEBUG: Task #6755835 uploaded file length: 84164
2025-07-23 11:06:39,800 [cuckoo.core.resultserver] DEBUG: Task #6755835 uploaded file length: 84162
2025-07-23 11:06:39,802 [cuckoo.core.resultserver] DEBUG: Task #6755835 uploaded file length: 84162
2025-07-23 11:06:39,812 [cuckoo.core.resultserver] DEBUG: Task #6755835 had connection reset for <Context for LOG>
2025-07-23 11:06:40,029 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully
2025-07-23 11:06:40,046 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-23 11:06:40,069 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-23 11:06:41,415 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/6755835/memory.dmp
2025-07-23 11:06:41,416 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644
2025-07-23 11:07:14,362 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #6755835
2025-07-23 11:07:14,961 [cuckoo.core.scheduler] DEBUG: Released database task #6755835
2025-07-23 11:07:14,975 [cuckoo.core.scheduler] INFO: Task #6755835: analysis procedure completed