Analyzer Log
2023-12-14 05:37:57,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd
2023-12-14 05:37:57,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ZUqFTrGGBqURVtEMmLTFd
2023-12-14 05:37:57,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\DzVybjKLvucxpOHGbIwrWsQ
2023-12-14 05:37:57,203 [analyzer] DEBUG: Started auxiliary module Curtain
2023-12-14 05:37:57,203 [analyzer] DEBUG: Started auxiliary module DbgView
2023-12-14 05:37:57,733 [analyzer] DEBUG: Started auxiliary module Disguise
2023-12-14 05:37:57,937 [analyzer] DEBUG: Loaded monitor into process with pid 508
2023-12-14 05:37:57,937 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2023-12-14 05:37:57,937 [analyzer] DEBUG: Started auxiliary module Human
2023-12-14 05:37:57,937 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2023-12-14 05:37:57,937 [analyzer] DEBUG: Started auxiliary module Reboot
2023-12-14 05:37:58,000 [analyzer] DEBUG: Started auxiliary module RecentFiles
2023-12-14 05:37:58,000 [analyzer] DEBUG: Started auxiliary module Screenshots
2023-12-14 05:37:58,000 [analyzer] DEBUG: Started auxiliary module Sysmon
2023-12-14 05:37:58,000 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2023-12-14 05:37:58,108 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AcroRd32.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\pastebin-hack-robux-free.pdf'] and pid 1140
2023-12-14 05:37:58,265 [analyzer] DEBUG: Loaded monitor into process with pid 1140
2023-12-14 05:37:59,500 [analyzer] INFO: Added new file to list with pid 1140 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin
2023-12-14 05:37:59,655 [analyzer] INFO: Added new file to list with pid 1140 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wscRGB.icc
2023-12-14 05:37:59,671 [analyzer] INFO: Added new file to list with pid 1140 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wsRGB.icc
2023-12-14 05:37:59,687 [analyzer] INFO: Added new file to list with pid 1140 and path C:\Users\Administrator\AppData\Local\Adobe\Color\ACECache10.lst
2023-12-14 05:38:02,405 [analyzer] INFO: Added new file to list with pid 1140 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents-journal
2023-12-14 05:38:02,421 [analyzer] INFO: Added new file to list with pid 1140 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents
2023-12-14 05:38:57,108 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2023-12-14 05:38:57,421 [analyzer] INFO: Terminating remaining processes before shutdown.
2023-12-14 05:38:57,421 [lib.api.process] INFO: Successfully terminated process with pid 1140.
2023-12-14 05:38:57,453 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\roaming\\adobe\\acrobat\\9.0\\shareddataevents-journal' does not exist, skip.
2023-12-14 05:38:57,453 [analyzer] INFO: Analysis completed.
Cuckoo Log
2023-12-14 06:38:07,265 [cuckoo.core.scheduler] INFO: Task #4441312: acquired machine win7x6412 (label=win7x6412)
2023-12-14 06:38:07,265 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.212 for task #4441312
2023-12-14 06:38:07,422 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1293070 (interface=vboxnet0, host=192.168.168.212)
2023-12-14 06:38:07,615 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6412
2023-12-14 06:38:08,104 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6412 to vmcloak
2023-12-14 06:38:20,889 [cuckoo.core.guest] INFO: Starting analysis #4441312 on guest (id=win7x6412, ip=192.168.168.212)
2023-12-14 06:38:21,894 [cuckoo.core.guest] DEBUG: win7x6412: not ready yet
2023-12-14 06:38:26,924 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6412, ip=192.168.168.212)
2023-12-14 06:38:26,972 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6412, ip=192.168.168.212, monitor=latest, size=6659295)
2023-12-14 06:38:27,930 [cuckoo.core.resultserver] DEBUG: Task #4441312: live log analysis.log initialized.
2023-12-14 06:38:28,808 [cuckoo.core.resultserver] DEBUG: Task #4441312 is sending a BSON stream
2023-12-14 06:38:29,136 [cuckoo.core.resultserver] DEBUG: Task #4441312 is sending a BSON stream
2023-12-14 06:38:30,029 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'shots/0001.jpg'
2023-12-14 06:38:30,041 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 125318
2023-12-14 06:38:31,136 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'shots/0002.jpg'
2023-12-14 06:38:31,147 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 138991
2023-12-14 06:38:32,268 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'shots/0003.jpg'
2023-12-14 06:38:32,279 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 132422
2023-12-14 06:38:39,461 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'shots/0004.jpg'
2023-12-14 06:38:39,473 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 130591
2023-12-14 06:38:42,724 [cuckoo.core.guest] DEBUG: win7x6412: analysis #4441312 still processing
2023-12-14 06:38:57,826 [cuckoo.core.guest] DEBUG: win7x6412: analysis #4441312 still processing
2023-12-14 06:39:12,898 [cuckoo.core.guest] DEBUG: win7x6412: analysis #4441312 still processing
2023-12-14 06:39:27,978 [cuckoo.core.guest] DEBUG: win7x6412: analysis #4441312 still processing
2023-12-14 06:39:28,235 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'curtain/1702528737.3.curtain.log'
2023-12-14 06:39:28,239 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 36
2023-12-14 06:39:28,336 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'sysmon/1702528737.39.sysmon.xml'
2023-12-14 06:39:28,348 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 788400
2023-12-14 06:39:28,375 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'files/57a1b18473496132_wscrgb.icc'
2023-12-14 06:39:28,383 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 66208
2023-12-14 06:39:28,384 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'files/977a75b22eb6ae12_wsrgb.icc'
2023-12-14 06:39:28,387 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 2676
2023-12-14 06:39:28,388 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'files/f01f36a20e17d8d0_acecache10.lst'
2023-12-14 06:39:28,390 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 1946
2023-12-14 06:39:28,391 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'files/eac8db284af335fd_shareddataevents'
2023-12-14 06:39:28,393 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 3072
2023-12-14 06:39:28,394 [cuckoo.core.resultserver] DEBUG: Task #4441312: File upload for 'files/2cbbfbe12768f624_usercache.bin'
2023-12-14 06:39:28,397 [cuckoo.core.resultserver] DEBUG: Task #4441312 uploaded file length: 69063
2023-12-14 06:39:28,413 [cuckoo.core.resultserver] DEBUG: Task #4441312 had connection reset for <Context for LOG>
2023-12-14 06:39:31,052 [cuckoo.core.guest] INFO: win7x6412: analysis completed successfully
2023-12-14 06:39:31,066 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2023-12-14 06:39:31,117 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2023-12-14 06:39:31,804 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6412 to path /srv/cuckoo/cwd/storage/analyses/4441312/memory.dmp
2023-12-14 06:39:31,806 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6412
2023-12-14 06:39:39,007 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.212 for task #4441312
2023-12-14 06:39:39,133 [cuckoo.core.scheduler] DEBUG: Released database task #4441312
2023-12-14 06:39:39,149 [cuckoo.core.scheduler] INFO: Task #4441312: analysis procedure completed