Size | 908.4KB |
---|---|
Type | news or mail, ASCII text, with CRLF line terminators |
MD5 | b254d02e77a4226c9461c5a44d7de59d |
SHA1 | a57c8f71978e68bfa86bbcf62161cfa454441db4 |
SHA256 | 33a0a4fd2895d8118443fb8fae4ac9ca93b3a3cb1c10791d983e16644940411d |
SHA512 |
40e2d786259e41b0fc520807b53740c625a590ab488ed709f7c7c397c26a0bc388591ed089e05ec21cc1749439016fefb9ba41b0069b55d987e1599622400a8e
|
CRC32 | 6E707B6D |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 12, 2025, 3:29 p.m. | April 12, 2025, 3:36 p.m. | 420 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-11 00:45:04,015 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht 2025-04-11 00:45:04,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\UDjJppIRMAHjXpuJsjpXrukenAj 2025-04-11 00:45:04,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\vTZzoDOkRTnnkGIocTEqaiAKH 2025-04-11 00:45:04,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-04-11 00:45:04,265 [analyzer] INFO: Automatically selected analysis package "generic" 2025-04-11 00:45:04,875 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-11 00:45:04,875 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-11 00:45:06,046 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-11 00:45:06,312 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-04-11 00:45:06,312 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-11 00:45:06,312 [analyzer] DEBUG: Started auxiliary module Human 2025-04-11 00:45:06,312 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-11 00:45:06,328 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-11 00:45:06,483 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-11 00:45:06,483 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-11 00:45:06,483 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-11 00:45:06,483 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-11 00:45:06,640 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"bRWLJrDhHWjTgELV"', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\33a0a4fd2895d8118443fb8fae4ac9ca93b3a3cb1c10791d983e16644940411d'] and pid 2560 2025-04-11 00:45:07,030 [analyzer] DEBUG: Loaded monitor into process with pid 2560 2025-04-11 00:45:07,717 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,750 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,765 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,765 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,765 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,780 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,780 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,796 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,796 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,842 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,842 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,905 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,905 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,921 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,921 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,921 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,921 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,937 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,937 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,953 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,953 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:07,953 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,483 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,483 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,483 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,483 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,500 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,500 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,500 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,500 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,515 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,515 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,515 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,625 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,625 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,625 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,625 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,640 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,640 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,640 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,655 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,655 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,671 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:08,671 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,640 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,655 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,655 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,671 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,671 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,687 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,687 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,703 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,703 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,717 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:14,733 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-04-11 00:45:19,296 [analyzer] INFO: Injected into process with pid 1304 and name u'rundll32.exe' 2025-04-11 00:45:19,592 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1304. 2025-04-11 00:45:19,828 [analyzer] DEBUG: Loaded monitor into process with pid 1304 2025-04-11 00:45:20,217 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-11 00:45:20,250 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,265 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-11 00:45:20,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,296 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,296 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-11 00:45:20,328 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-11 00:45:20,328 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,328 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,328 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,342 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-11 00:45:20,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:20,342 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-11 00:45:21,342 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-11 00:45:21,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,358 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-11 00:45:21,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,375 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,375 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,375 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,390 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,390 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-11 00:45:21,530 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-11 00:45:21,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,562 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-11 00:45:21,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,578 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,578 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,578 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,592 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:21,592 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-11 00:45:23,467 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-11 00:45:23,467 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:23,467 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:23,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:23,483 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-11 00:45:23,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:23,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-11 00:45:23,500 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:23,500 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-11 00:45:23,500 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-11 00:45:23,500 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-11 00:45:35,717 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-11 00:45:36,000 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-11 00:45:36,000 [lib.api.process] INFO: Successfully terminated process with pid 2560. 2025-04-11 00:45:36,000 [lib.api.process] INFO: Successfully terminated process with pid 1304. 2025-04-11 00:45:36,000 [analyzer] INFO: Analysis completed.
2025-04-12 15:29:52,231 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:29:53,268 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:29:54,298 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:29:55,322 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:29:56,342 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:29:57,369 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:29:58,388 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:29:59,413 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:00,439 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:01,466 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:02,486 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:03,510 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:04,532 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:05,550 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:06,575 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:07,600 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:08,686 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:09,733 [cuckoo.core.scheduler] DEBUG: Task #6267124: no machine available yet 2025-04-12 15:30:10,788 [cuckoo.core.scheduler] INFO: Task #6267124: acquired machine win7x641 (label=win7x641) 2025-04-12 15:30:10,789 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #6267124 2025-04-12 15:30:11,035 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1346386 (interface=vboxnet0, host=192.168.168.201) 2025-04-12 15:30:11,070 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641 2025-04-12 15:30:11,532 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak 2025-04-12 15:33:19,506 [cuckoo.core.guest] INFO: Starting analysis #6267124 on guest (id=win7x641, ip=192.168.168.201) 2025-04-12 15:33:20,513 [cuckoo.core.guest] DEBUG: win7x641: not ready yet 2025-04-12 15:33:25,661 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201) 2025-04-12 15:33:25,929 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546) 2025-04-12 15:33:29,021 [cuckoo.core.resultserver] DEBUG: Task #6267124: live log analysis.log initialized. 2025-04-12 15:33:31,201 [cuckoo.core.resultserver] DEBUG: Task #6267124 is sending a BSON stream 2025-04-12 15:33:31,810 [cuckoo.core.resultserver] DEBUG: Task #6267124 is sending a BSON stream 2025-04-12 15:33:32,638 [cuckoo.core.resultserver] DEBUG: Task #6267124: File upload for 'shots/0001.jpg' 2025-04-12 15:33:32,650 [cuckoo.core.resultserver] DEBUG: Task #6267124 uploaded file length: 115341 2025-04-12 15:33:43,393 [cuckoo.core.guest] DEBUG: win7x641: analysis #6267124 still processing 2025-04-12 15:33:44,637 [cuckoo.core.resultserver] DEBUG: Task #6267124 is sending a BSON stream 2025-04-12 15:33:58,550 [cuckoo.core.guest] DEBUG: win7x641: analysis #6267124 still processing 2025-04-12 15:34:00,846 [cuckoo.core.resultserver] DEBUG: Task #6267124: File upload for 'curtain/1744325135.88.curtain.log' 2025-04-12 15:34:00,849 [cuckoo.core.resultserver] DEBUG: Task #6267124 uploaded file length: 36 2025-04-12 15:34:00,973 [cuckoo.core.resultserver] DEBUG: Task #6267124: File upload for 'sysmon/1744325136.0.sysmon.xml' 2025-04-12 15:34:00,985 [cuckoo.core.resultserver] DEBUG: Task #6267124 uploaded file length: 950590 2025-04-12 15:34:01,565 [cuckoo.core.guest] INFO: win7x641: analysis completed successfully 2025-04-12 15:34:01,581 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-12 15:34:01,616 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-12 15:34:01,751 [cuckoo.core.resultserver] DEBUG: Task #6267124: File upload for 'shots/0002.jpg' 2025-04-12 15:34:01,812 [cuckoo.core.resultserver] DEBUG: Task #6267124 uploaded file length: 133507 2025-04-12 15:34:01,832 [cuckoo.core.resultserver] DEBUG: Task #6267124 had connection reset for <Context for LOG> 2025-04-12 15:34:02,317 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/6267124/memory.dmp 2025-04-12 15:34:02,318 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641 2025-04-12 15:36:51,767 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #6267124 2025-04-12 15:36:52,806 [cuckoo.core.scheduler] DEBUG: Released database task #6267124 2025-04-12 15:36:52,831 [cuckoo.core.scheduler] INFO: Task #6267124: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Microsoft Outlook\Capabilities\Hidden |
G Data Antivirus (Windows) | Virus: Trojan.GenericKD.76211561 (Engine A) |
C4S ClamAV (Linux) | C4S.MALWARE.SHA256.AUTOGEN.64000629.UNOFFICIAL |
eScan Antivirus (Linux) | Trojan.GenericKD.76211561(DB) |
DrWeb Antivirus (Linux) | Trojan.Inject4.29903 |
Bitdefender Antivirus (Linux) | Trojan.GenericKD.76211561 |
Emsisoft Commandline Scanner (Windows) | Trojan.GenericKD.76211561 (B) |
Cynet | Malicious (score: 99) |
Kaspersky | HEUR:Trojan-PSW.MSIL.Agensla.gen |
F-Secure | Heuristic.HEUR/AGEN.1353849 |
DrWeb | Trojan.Inject4.29903 |
Antiy-AVL | Trojan[PSW]/MSIL.Agensla |
GData | Script.Trojan.Agent.0Y9MDW |
Varist | W32/MSIL_Kryptik.GYS.gen!Eldorado |
McAfee | Suspect-FU |
Zoner | Trojan.Win32.133234 |
Yandex | Trojan.Igent.bXMmnC.3 |
Fortinet | MSIL/Kryptik.AEVP!tr |