Failed to run the processing module "Irma" for task #6168805: Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/cuckoo/core/plugins.py", line 250, in process data = current.run() File "/usr/local/lib/python2.7/dist-packages/cuckoo/processing/irma.py", line 201, in run result_id = self._scan_file(file_path, self.force) File "/usr/local/lib/python2.7/dist-packages/cuckoo/processing/irma.py", line 109, in _scan_file file_id = self._post_json(url, files=files,).get('result_id',None) File "/usr/local/lib/python2.7/dist-packages/cuckoo/processing/irma.py", line 82, in _post_json r = requests.post(url, timeout=self.timeout, **kwargs) File "/usr/local/lib/python2.7/dist-packages/requests/api.py", line 117, in post return request('post', url, data=data, json=json, **kwargs) File "/usr/local/lib/python2.7/dist-packages/requests/api.py", line 61, in request return session.request(method=method, url=url, **kwargs) File "/usr/local/lib/python2.7/dist-packages/requests/sessions.py", line 542, in request resp = self.send(prep, **send_kwargs) File "/usr/local/lib/python2.7/dist-packages/requests/sessions.py", line 655, in send r = adapter.send(request, **kwargs) File "/usr/local/lib/python2.7/dist-packages/requests/adapters.py", line 529, in send raise ReadTimeout(e, request=request) ReadTimeout: HTTPSConnectionPool(host='irma.cert.ee', port=443): Read timed out. (read timeout=300)
click to expand / collapse this errorFailed to run the processing module "NetworkAnalysis" for task #6168805: Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/cuckoo/core/plugins.py", line 250, in process data = current.run() File "/usr/local/lib/python2.7/dist-packages/cuckoo/processing/network.py", line 1026, in run results.update(Pcap(pcap_path, self.options).run()) File "/usr/local/lib/python2.7/dist-packages/cuckoo/processing/network.py", line 827, in run with geoip2.database.Reader(self.options.get("geoip_db")) as reader: File "/usr/local/lib/python2.7/dist-packages/geoip2/database.py", line 85, in __init__ self._db_reader = maxminddb.open_database(fileish, mode) File "/usr/local/lib/python2.7/dist-packages/maxminddb/__init__.py", line 46, in open_database return maxminddb.reader.Reader(database, mode) File "/usr/local/lib/python2.7/dist-packages/maxminddb/reader.py", line 52, in __init__ self._buffer = mmap.mmap(db_file.fileno(), 0, access=mmap.ACCESS_READ) ValueError: cannot mmap an empty file
click to expand / collapse this errorSize | 93.7MB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | ad90b30dc130b907d9f619dff3c7267c |
SHA1 | ad3a3d73f24787638c04ee13f7a2540dcce53859 |
SHA256 | 5f38b1b6ca20c4ffe1267e8b1f346659d59b0f33fb91f77e6813af8126d6347a |
SHA512 |
1fce225460193150c6471bd026633afc1540f864eb6e386e6387ac077fe728185c5a29940ad2ffc65767df342da3f4cb564aa959af2deb8cb8285936c215b850
|
CRC32 | 4445D17D |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | March 27, 2025, 8:03 p.m. | March 27, 2025, 8:47 p.m. | 2637 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-03-25 23:41:02,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpblqbwr 2025-03-25 23:41:02,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\FAOyhdMHhpyiySfTtVZBtIyM 2025-03-25 23:41:02,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\HdTohnoLGxJekIzy 2025-03-25 23:41:02,265 [analyzer] DEBUG: Started auxiliary module Curtain 2025-03-25 23:41:02,265 [analyzer] DEBUG: Started auxiliary module DbgView 2025-03-25 23:41:02,733 [analyzer] DEBUG: Started auxiliary module Disguise 2025-03-25 23:41:02,921 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-03-25 23:41:02,921 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-03-25 23:41:02,921 [analyzer] DEBUG: Started auxiliary module Human 2025-03-25 23:41:02,921 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-03-25 23:41:02,921 [analyzer] DEBUG: Started auxiliary module Reboot 2025-03-25 23:41:02,983 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-03-25 23:41:02,983 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-03-25 23:41:02,983 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-03-25 23:41:02,983 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-03-25 23:41:04,125 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\5f38b1b6ca20c4ffe1267e8b1f346659d59b0f33fb91f77e6813af8126d6347a.exe' with arguments '' and pid 2480 2025-03-25 23:41:04,312 [analyzer] DEBUG: Loaded monitor into process with pid 2480 2025-03-25 23:41:33,140 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-03-25 23:41:33,671 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-03-25 23:41:33,671 [lib.api.process] INFO: Successfully terminated process with pid 2480. 2025-03-25 23:41:33,687 [analyzer] INFO: Analysis completed.
2025-03-27 20:03:51,425 [cuckoo.core.scheduler] INFO: Task #6168805: acquired machine win7x6418 (label=win7x6418) 2025-03-27 20:03:51,430 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.218 for task #6168805 2025-03-27 20:03:52,320 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2834433 (interface=vboxnet0, host=192.168.168.218) 2025-03-27 20:41:43,903 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6418 2025-03-27 20:41:45,103 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6418 to vmcloak 2025-03-27 20:43:43,537 [cuckoo.core.guest] INFO: Starting analysis #6168805 on guest (id=win7x6418, ip=192.168.168.218) 2025-03-27 20:43:44,549 [cuckoo.core.guest] DEBUG: win7x6418: not ready yet 2025-03-27 20:43:49,583 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6418, ip=192.168.168.218) 2025-03-27 20:43:50,028 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6418, ip=192.168.168.218, monitor=latest, size=6660546) 2025-03-27 20:43:54,890 [cuckoo.core.resultserver] DEBUG: Task #6168805: live log analysis.log initialized. 2025-03-27 20:43:55,601 [cuckoo.core.resultserver] DEBUG: Task #6168805 is sending a BSON stream 2025-03-27 20:43:56,841 [cuckoo.core.resultserver] DEBUG: Task #6168805: File upload for 'shots/0001.jpg' 2025-03-27 20:43:56,855 [cuckoo.core.resultserver] DEBUG: Task #6168805 uploaded file length: 133494 2025-03-27 20:43:56,978 [cuckoo.core.resultserver] DEBUG: Task #6168805 is sending a BSON stream 2025-03-27 20:44:00,315 [cuckoo.core.resultserver] DEBUG: Task #6168805: File upload for 'shots/0002.jpg' 2025-03-27 20:44:00,340 [cuckoo.core.resultserver] DEBUG: Task #6168805 uploaded file length: 135718 2025-03-27 20:44:10,249 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6168805 still processing 2025-03-27 20:44:26,090 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6168805 still processing 2025-03-27 20:44:26,149 [cuckoo.core.resultserver] DEBUG: Task #6168805: File upload for 'curtain/1742942493.38.curtain.log' 2025-03-27 20:44:26,161 [cuckoo.core.resultserver] DEBUG: Task #6168805 uploaded file length: 36 2025-03-27 20:44:26,389 [cuckoo.core.resultserver] DEBUG: Task #6168805: File upload for 'sysmon/1742942493.61.sysmon.xml' 2025-03-27 20:44:26,518 [cuckoo.core.resultserver] DEBUG: Task #6168805 uploaded file length: 1782022 2025-03-27 20:44:27,308 [cuckoo.core.resultserver] DEBUG: Task #6168805: File upload for 'shots/0003.jpg' 2025-03-27 20:44:27,371 [cuckoo.core.resultserver] DEBUG: Task #6168805 uploaded file length: 133494 2025-03-27 20:44:27,381 [cuckoo.core.resultserver] DEBUG: Task #6168805 had connection reset for <Context for LOG> 2025-03-27 20:44:29,373 [cuckoo.core.guest] INFO: win7x6418: analysis completed successfully 2025-03-27 20:44:29,408 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-03-27 20:44:29,445 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-03-27 20:44:31,083 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6418 to path /srv/cuckoo/cwd/storage/analyses/6168805/memory.dmp 2025-03-27 20:44:31,084 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6418 2025-03-27 20:47:25,494 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.218 for task #6168805 2025-03-27 20:47:26,002 [cuckoo.core.scheduler] DEBUG: Released database task #6168805 2025-03-27 20:47:26,392 [cuckoo.core.scheduler] INFO: Task #6168805: analysis procedure completed
description | (no description) | rule | GenerateTLSClientHelloPacket_Test | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | inject_thread | ||||||
description | Communications over UDP network | rule | network_udp_sock | ||||||
description | Listen for incoming communication | rule | network_tcp_listen | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Communications use DNS | rule | network_dns | ||||||
description | Take screenshot | rule | screenshot | ||||||
description | Run a keylogger | rule | keylogger | ||||||
description | Create or check mutex | rule | win_mutex |
section | .itext |
section | .didata |
packer | BobSoft Mini Delphi -> BoB / BobSoft |
resource name | UNICODEDATA |
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c | ||||||||||||||||||
name | RT_BITMAP | language | LANG_PORTUGUESE | filetype | Device independent bitmap graphic, 2649 x 1479 x 24, image size 11755092, resolution 3778 x 3778 px/m | sublanguage | SUBLANG_PORTUGUESE_BRAZILIAN | offset | 0x0528e714 | size | 0x00b35e7c |
Skyhigh | Artemis |
Sangfor | Trojan.Win32.Save.a |
ESET-NOD32 | a variant of Win32/Spy.Grandoreiro.DS |
Kaspersky | HEUR:Trojan-Banker.Win32.Delf.gen |
Rising | Spyware.Grandoreiro!8.F2CC (CLOUD) |
McAfeeD | ti!5F38B1B6CA20 |
Detected | |
GData | Win32.Trojan.Agent.7ZOAON |
AhnLab-V3 | Malware/Win.Generic.C5647813 |
DeepInstinct | MALICIOUS |
Ikarus | Trojan-Spy.Win32.Grandoreiro |
Fortinet | W32/Grandoreiro.SS!tr.spy |