Analyzer Log
2025-03-27 00:56:22,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd
2025-03-27 00:56:22,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\gnAJcKKwtCvgPeQjzOwoeQcT
2025-03-27 00:56:22,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\uhkDDGcyLPAXLFAjhke
2025-03-27 00:56:22,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-03-27 00:56:22,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-03-27 00:56:22,375 [analyzer] DEBUG: Started auxiliary module Curtain
2025-03-27 00:56:22,375 [analyzer] DEBUG: Started auxiliary module DbgView
2025-03-27 00:56:23,187 [analyzer] DEBUG: Started auxiliary module Disguise
2025-03-27 00:56:23,421 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-03-27 00:56:23,421 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-03-27 00:56:23,421 [analyzer] DEBUG: Started auxiliary module Human
2025-03-27 00:56:23,421 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-03-27 00:56:23,421 [analyzer] DEBUG: Started auxiliary module Reboot
2025-03-27 00:56:23,530 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-03-27 00:56:23,530 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-03-27 00:56:23,530 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-03-27 00:56:23,530 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-03-27 00:56:23,687 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dac2188c436443ea_mainexe.exe' with arguments '' and pid 2700
2025-03-27 00:56:23,937 [analyzer] DEBUG: Loaded monitor into process with pid 2700
2025-03-27 00:56:23,937 [analyzer] INFO: Added new file to list with pid 2700 and path C:\Users\Administrator\AppData\Local\Temp\AddCer.exe
2025-03-27 00:56:24,108 [analyzer] INFO: Injected into process with pid 2456 and name u'AddCer.exe'
2025-03-27 00:56:24,312 [analyzer] DEBUG: Loaded monitor into process with pid 2456
2025-03-27 00:56:24,342 [analyzer] INFO: Added new file to list with pid 2456 and path C:\Users\Administrator\AppData\Local\Temp\z1yuny4n.cer
2025-03-27 00:56:24,640 [analyzer] INFO: Added new file to list with pid 2700 and path C:\Users\Administrator\AppData\Local\Temp\Z1rasadhlp.jpg
2025-03-27 00:56:24,703 [analyzer] INFO: Injected into process with pid 2544 and name u'rundll32.exe'
2025-03-27 00:56:24,828 [analyzer] INFO: Injected into process with pid 2076 and name u'cmd.exe'
2025-03-27 00:56:24,921 [analyzer] DEBUG: Loaded monitor into process with pid 2544
2025-03-27 00:56:25,046 [analyzer] DEBUG: Loaded monitor into process with pid 2076
2025-03-27 00:56:25,687 [analyzer] INFO: Process with pid 2700 has terminated
2025-03-27 00:56:25,687 [analyzer] INFO: Process with pid 2076 has terminated
2025-03-27 00:59:42,687 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-03-27 00:59:43,733 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-03-27 00:59:43,750 [lib.api.process] INFO: Successfully terminated process with pid 2544.
2025-03-27 00:59:43,750 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\addcer.exe' does not exist, skip.
2025-03-27 00:59:43,750 [analyzer] INFO: Analysis completed.
Cuckoo Log
2025-03-29 13:40:49,887 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:50,944 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:51,974 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:53,014 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:54,057 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:55,099 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:56,121 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:57,164 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:58,201 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:40:59,249 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:00,296 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:01,343 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:02,399 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:03,455 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:04,567 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:05,658 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:06,771 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:07,852 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:08,913 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:09,976 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:11,498 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:12,573 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:13,643 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:14,871 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:15,967 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:17,004 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:18,244 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:19,348 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:20,387 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:21,426 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:22,464 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:23,493 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:24,541 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:25,634 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:26,682 [cuckoo.core.scheduler] DEBUG: Task #6180506: no machine available yet
2025-03-29 13:41:27,725 [cuckoo.core.scheduler] INFO: Task #6180506: acquired machine win7x6412 (label=win7x6412)
2025-03-29 13:41:27,727 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.212 for task #6180506
2025-03-29 13:41:28,145 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2319833 (interface=vboxnet0, host=192.168.168.212)
2025-03-29 13:41:28,551 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6412
2025-03-29 13:41:29,234 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6412 to vmcloak
2025-03-29 13:44:17,158 [cuckoo.core.guest] INFO: Starting analysis #6180506 on guest (id=win7x6412, ip=192.168.168.212)
2025-03-29 13:44:18,165 [cuckoo.core.guest] DEBUG: win7x6412: not ready yet
2025-03-29 13:44:23,205 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6412, ip=192.168.168.212)
2025-03-29 13:44:23,410 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6412, ip=192.168.168.212, monitor=latest, size=6660546)
2025-03-29 13:44:25,516 [cuckoo.core.resultserver] DEBUG: Task #6180506: live log analysis.log initialized.
2025-03-29 13:44:26,883 [cuckoo.core.resultserver] DEBUG: Task #6180506 is sending a BSON stream
2025-03-29 13:44:27,383 [cuckoo.core.resultserver] DEBUG: Task #6180506 is sending a BSON stream
2025-03-29 13:44:27,758 [cuckoo.core.resultserver] DEBUG: Task #6180506 is sending a BSON stream
2025-03-29 13:44:28,188 [cuckoo.core.resultserver] DEBUG: Task #6180506: File upload for 'shots/0001.jpg'
2025-03-29 13:44:28,216 [cuckoo.core.resultserver] DEBUG: Task #6180506: File upload for 'files/556725558bfeae99_Z1rasadhlp.jpg'
2025-03-29 13:44:28,225 [cuckoo.core.resultserver] DEBUG: Task #6180506 uploaded file length: 28384
2025-03-29 13:44:28,232 [cuckoo.core.resultserver] DEBUG: Task #6180506 uploaded file length: 112146
2025-03-29 13:44:28,366 [cuckoo.core.resultserver] DEBUG: Task #6180506 is sending a BSON stream
2025-03-29 13:44:28,496 [cuckoo.core.resultserver] DEBUG: Task #6180506 is sending a BSON stream
2025-03-29 13:44:28,595 [cuckoo.core.resultserver] DEBUG: Task #6180506: File upload for 'files/dac2188c436443ea_dac2188c436443ea_mainexe.exe'
2025-03-29 13:44:28,601 [cuckoo.core.resultserver] DEBUG: Task #6180506 uploaded file length: 62976
2025-03-29 13:44:29,338 [cuckoo.core.resultserver] DEBUG: Task #6180506: File upload for 'shots/0002.jpg'
2025-03-29 13:44:29,348 [cuckoo.core.resultserver] DEBUG: Task #6180506 uploaded file length: 133504
2025-03-29 13:44:33,825 [cuckoo.core.resultserver] DEBUG: Task #6180506: File upload for 'files/8e4752179c57ee22_z1yuny4n.cer'
2025-03-29 13:44:33,828 [cuckoo.core.resultserver] DEBUG: Task #6180506 uploaded file length: 572
2025-03-29 13:44:40,217 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:44:55,635 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:45:10,847 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:45:25,954 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:45:41,084 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:45:56,405 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:46:11,521 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:46:26,654 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:46:41,928 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:46:57,067 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:47:12,310 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:47:27,448 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:47:42,593 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6180506 still processing
2025-03-29 13:47:46,421 [cuckoo.core.resultserver] DEBUG: Task #6180506: File upload for 'curtain/1743033582.89.curtain.log'
2025-03-29 13:47:46,425 [cuckoo.core.resultserver] DEBUG: Task #6180506 uploaded file length: 36
2025-03-29 13:47:47,172 [cuckoo.core.resultserver] DEBUG: Task #6180506: File upload for 'sysmon/1743033583.64.sysmon.xml'
2025-03-29 13:47:47,272 [cuckoo.core.resultserver] DEBUG: Task #6180506 uploaded file length: 10180026
2025-03-29 13:47:47,296 [cuckoo.core.resultserver] DEBUG: Task #6180506 had connection reset for <Context for LOG>
2025-03-29 13:47:48,630 [cuckoo.core.guest] INFO: win7x6412: analysis completed successfully
2025-03-29 13:47:48,650 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-03-29 13:47:48,671 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-03-29 13:47:49,798 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6412 to path /srv/cuckoo/cwd/storage/analyses/6180506/memory.dmp
2025-03-29 13:47:49,799 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6412
2025-03-29 13:49:29,118 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.212 for task #6180506
2025-03-29 13:49:29,735 [cuckoo.core.scheduler] DEBUG: Released database task #6180506
2025-03-29 13:49:29,753 [cuckoo.core.scheduler] INFO: Task #6180506: analysis procedure completed