Analyzer Log
2025-08-18 13:22:09,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpblqbwr
2025-08-18 13:22:09,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\AuzrPTlVuLuUTrlqTagpMTinh
2025-08-18 13:22:09,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\UQkrHmHABUxOmiXiHqZUNkl
2025-08-18 13:22:09,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-08-18 13:22:09,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-08-18 13:22:09,858 [analyzer] DEBUG: Started auxiliary module Disguise
2025-08-18 13:22:10,078 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-08-18 13:22:10,078 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-08-18 13:22:10,078 [analyzer] DEBUG: Started auxiliary module Human
2025-08-18 13:22:10,078 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-08-18 13:22:10,078 [analyzer] DEBUG: Started auxiliary module Reboot
2025-08-18 13:22:10,187 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-08-18 13:22:10,187 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-08-18 13:22:10,187 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-08-18 13:22:10,187 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-08-18 13:22:10,342 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\7dca3dbf4a0d99e7c86edafb83698994e9f89d2ec51de988f0f8c7ec54e4f81b.exe' with arguments '' and pid 596
2025-08-18 13:22:10,530 [analyzer] DEBUG: Loaded monitor into process with pid 596
2025-08-18 13:22:11,312 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Local\Temp\nsi64EF.tmp
2025-08-18 12:49:08,283 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\Machicolation.Vit
2025-08-18 12:49:08,408 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\Negrillo162.nov
2025-08-18 12:49:08,503 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\anticipatively.ini
2025-08-18 12:49:08,533 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\folketingsformand.txt
2025-08-18 12:49:08,581 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\levnedsmiddelets.sva
2025-08-18 12:49:08,706 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\pray.kry
2025-08-18 12:49:08,720 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\supersupreme\respirationsstoppene.txt
2025-08-18 12:49:09,690 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Local\Temp\nsaCF72.tmp\System.dll
2025-08-18 12:49:10,456 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-08-18 12:49:10,628 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 596.
2025-08-18 12:49:11,283 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-08-18 12:49:11,283 [lib.api.process] INFO: Successfully terminated process with pid 596.
2025-08-18 12:49:11,315 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\nsi64ef.tmp' does not exist, skip.
2025-08-18 12:49:11,331 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-08-18 13:45:38,733 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:39,811 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:40,884 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:42,054 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:43,106 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:44,172 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:45,234 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:46,301 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:47,393 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:48,449 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:49,506 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:50,989 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:52,055 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:53,119 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:54,180 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:55,428 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:56,511 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:57,591 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:58,684 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:59,760 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:00,853 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:01,923 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:02,984 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:04,026 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:05,078 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:06,404 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:07,698 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:08,909 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:10,052 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:11,438 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:12,560 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:13,653 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:14,877 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:16,086 [cuckoo.core.scheduler] INFO: Task #6893623: acquired machine win7x6418 (label=win7x6418)
2025-08-18 13:46:16,119 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.218 for task #6893623
2025-08-18 13:46:16,737 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 387991 (interface=vboxnet0, host=192.168.168.218)
2025-08-18 13:46:24,474 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6418
2025-08-18 13:46:25,287 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6418 to vmcloak
2025-08-18 13:48:31,575 [cuckoo.core.guest] INFO: Starting analysis #6893623 on guest (id=win7x6418, ip=192.168.168.218)
2025-08-18 13:48:32,600 [cuckoo.core.guest] DEBUG: win7x6418: not ready yet
2025-08-18 13:48:37,659 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6418, ip=192.168.168.218)
2025-08-18 13:48:38,519 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6418, ip=192.168.168.218, monitor=latest, size=6660546)
2025-08-18 13:48:40,116 [cuckoo.core.resultserver] DEBUG: Task #6893623: live log analysis.log initialized.
2025-08-18 13:48:41,188 [cuckoo.core.resultserver] DEBUG: Task #6893623 is sending a BSON stream
2025-08-18 13:48:41,837 [cuckoo.core.resultserver] DEBUG: Task #6893623 is sending a BSON stream
2025-08-18 13:48:42,449 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/e3b0c44298fc1c14_nsn6471.tmp'
2025-08-18 13:48:42,460 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 0
2025-08-18 13:48:42,466 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'shots/0001.jpg'
2025-08-18 13:48:42,505 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 133486
2025-08-18 13:48:43,651 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'shots/0002.jpg'
2025-08-18 13:48:43,678 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 127530
2025-08-18 13:48:44,950 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'shots/0003.jpg'
2025-08-18 13:48:44,995 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 133502
2025-08-18 13:48:54,856 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6893623 still processing
2025-08-18 13:49:10,227 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6893623 still processing
2025-08-18 13:49:10,878 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'curtain/1755514150.77.curtain.log'
2025-08-18 13:49:10,887 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 36
2025-08-18 13:49:11,179 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'sysmon/1755514150.96.sysmon.xml'
2025-08-18 13:49:11,326 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 1775874
2025-08-18 13:49:11,398 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/f742c0f0f0b306bb_negrillo162.nov'
2025-08-18 13:49:11,430 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 284577
2025-08-18 13:49:11,434 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/d34cc96d389edfac_pray.kry'
2025-08-18 13:49:11,442 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 70351
2025-08-18 13:49:11,451 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/1a953dc54649b2e6_anticipatively.ini'
2025-08-18 13:49:11,463 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 667
2025-08-18 13:49:11,478 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/7c448a6c8e8de646_folketingsformand.txt'
2025-08-18 13:49:11,489 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 530
2025-08-18 13:49:11,495 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/5a1c20a3e2e2eb18_system.dll'
2025-08-18 13:49:11,502 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 11264
2025-08-18 13:49:11,510 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/02daff0d6bafda6d_machicolation.vit'
2025-08-18 13:49:11,529 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 279146
2025-08-18 13:49:11,536 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/e7d5c4a66ead0a69_levnedsmiddelets.sva'
2025-08-18 13:49:11,564 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 473258
2025-08-18 13:49:11,574 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/1b746c6a7d78152e_respirationsstoppene.txt'
2025-08-18 13:49:11,589 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 661
2025-08-18 13:49:11,663 [cuckoo.core.resultserver] DEBUG: Task #6893623 had connection reset for <Context for LOG>
2025-08-18 13:49:13,247 [cuckoo.core.guest] INFO: win7x6418: analysis completed successfully
2025-08-18 13:49:13,266 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-08-18 13:49:13,297 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-08-18 13:49:14,674 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6418 to path /srv/cuckoo/cwd/storage/analyses/6893623/memory.dmp
2025-08-18 13:49:14,684 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6418
2025-08-18 13:51:46,260 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.218 for task #6893623
2025-08-18 13:51:46,619 [cuckoo.core.scheduler] DEBUG: Released database task #6893623
2025-08-18 13:51:46,637 [cuckoo.core.scheduler] INFO: Task #6893623: analysis procedure completed