Size | 206.1KB |
---|---|
Type | data |
MD5 | 327ef4e63ddf05872f937753028257cd |
SHA1 | 19569c0a1f740152dc827e560e5ba1c00091d741 |
SHA256 | ec8594a98d3546f991947e2bb1c8ffc8ce1a3c9d0f6aa890639b4152d9b72d20 |
SHA512 |
a954741a7caf24482b57c87b3c836843d787a199d8c7e798691875908c67b070bd40520ab59ab5f1fd06a39197a3098a0c8dbfb3528499558efec4ea01400a3a
|
CRC32 | 28243455 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 18, 2025, 5:55 a.m. | April 18, 2025, 5:55 a.m. | 37 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-18 05:55:09,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpj6atou 2025-04-18 05:55:09,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\qRnprYfeyrCrdSZbkclpKNYUsSCgdQw 2025-04-18 05:55:09,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\uuKbHBLYARBDUVnAfaHaxBRSzURxmb 2025-04-18 05:55:09,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-04-18 05:55:09,062 [analyzer] INFO: Automatically selected analysis package "generic" 2025-04-18 05:55:09,280 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-18 05:55:09,280 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-18 05:55:09,733 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-18 05:55:09,921 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-04-18 05:55:09,921 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-18 05:55:09,921 [analyzer] DEBUG: Started auxiliary module Human 2025-04-18 05:55:09,921 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-18 05:55:09,921 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-18 05:55:10,015 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-18 05:55:10,015 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-18 05:55:10,015 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-18 05:55:10,015 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-18 05:55:10,140 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"xjKiTxHsvzMbHb"', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\02.08.2022.exe'] and pid 2624 2025-04-18 05:55:10,421 [analyzer] DEBUG: Loaded monitor into process with pid 2624 2025-04-18 05:55:10,530 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-18 05:55:10,530 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,546 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-18 05:55:10,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,578 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,625 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-18 05:55:10,671 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-18 05:55:11,140 [analyzer] INFO: Process with pid 2624 has terminated 2025-04-18 05:55:11,155 [analyzer] INFO: Process list is empty, terminating analysis. 2025-04-18 05:55:12,375 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-18 05:55:12,375 [analyzer] INFO: Analysis completed.
2025-04-18 05:55:14,353 [cuckoo.core.scheduler] INFO: Task #6298006: acquired machine win7x6416 (label=win7x6416) 2025-04-18 05:55:14,354 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.216 for task #6298006 2025-04-18 05:55:14,729 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2987325 (interface=vboxnet0, host=192.168.168.216) 2025-04-18 05:55:14,759 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6416 2025-04-18 05:55:15,440 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6416 to vmcloak 2025-04-18 05:55:29,654 [cuckoo.core.guest] INFO: Starting analysis #6298006 on guest (id=win7x6416, ip=192.168.168.216) 2025-04-18 05:55:30,658 [cuckoo.core.guest] DEBUG: win7x6416: not ready yet 2025-04-18 05:55:35,691 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6416, ip=192.168.168.216) 2025-04-18 05:55:35,773 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6416, ip=192.168.168.216, monitor=latest, size=6660546) 2025-04-18 05:55:37,211 [cuckoo.core.resultserver] DEBUG: Task #6298006: live log analysis.log initialized. 2025-04-18 05:55:38,081 [cuckoo.core.resultserver] DEBUG: Task #6298006 is sending a BSON stream 2025-04-18 05:55:38,503 [cuckoo.core.resultserver] DEBUG: Task #6298006 is sending a BSON stream 2025-04-18 05:55:39,381 [cuckoo.core.resultserver] DEBUG: Task #6298006: File upload for 'shots/0001.jpg' 2025-04-18 05:55:39,394 [cuckoo.core.resultserver] DEBUG: Task #6298006 uploaded file length: 133571 2025-04-18 05:55:40,487 [cuckoo.core.resultserver] DEBUG: Task #6298006: File upload for 'curtain/1744948512.25.curtain.log' 2025-04-18 05:55:40,489 [cuckoo.core.resultserver] DEBUG: Task #6298006 uploaded file length: 36 2025-04-18 05:55:40,598 [cuckoo.core.resultserver] DEBUG: Task #6298006: File upload for 'sysmon/1744948512.38.sysmon.xml' 2025-04-18 05:55:40,600 [cuckoo.core.resultserver] DEBUG: Task #6298006 uploaded file length: 24832 2025-04-18 05:55:41,494 [cuckoo.core.resultserver] DEBUG: Task #6298006 had connection reset for <Context for LOG> 2025-04-18 05:55:42,617 [cuckoo.core.guest] INFO: win7x6416: analysis completed successfully 2025-04-18 05:55:42,629 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-18 05:55:42,653 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-18 05:55:43,546 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6416 to path /srv/cuckoo/cwd/storage/analyses/6298006/memory.dmp 2025-04-18 05:55:43,547 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6416 2025-04-18 05:55:51,175 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.216 for task #6298006 2025-04-18 05:55:51,462 [cuckoo.core.scheduler] DEBUG: Released database task #6298006 2025-04-18 05:55:51,479 [cuckoo.core.scheduler] INFO: Task #6298006: analysis procedure completed
G Data Antivirus (Windows) | Virus: Trojan.Shellcode.21.Gen (Engine A) |
Trend Micro SProtect (Linux) | Trojan.Win32.COBALT.SMD.hp |
eScan Antivirus (Linux) | Trojan.Shellcode.21.Gen(DB) |
Sophos Anti-Virus (Linux) | ATK/Cobalt-D |
Bitdefender Antivirus (Linux) | Trojan.Shellcode.21.Gen |
Kaspersky Standard (Windows) | HEUR:Trojan.Win64.CobaltStrike.gen |
Emsisoft Commandline Scanner (Windows) | Trojan.Shellcode.21.Gen (B) |
CTX | mp3.trojan.shellcode |
VIPRE | Trojan.Shellcode.21.Gen |
Arcabit | Trojan.Shellcode.21.Gen |
TrendMicro-HouseCall | Trojan.Win32.COBALT.SMD.hp |
Kaspersky | HEUR:Trojan.Win64.CobaltStrike.gen |
BitDefender | Trojan.Shellcode.21.Gen |
MicroWorld-eScan | Trojan.Shellcode.21.Gen |
Emsisoft | Trojan.Shellcode.21.Gen (B) |
TrendMicro | Trojan.Win32.COBALT.SMD.hp |
Sophos | ATK/Cobalt-D |
Detected | |
ZoneAlarm | ATK/Cobalt-D |
GData | Trojan.Shellcode.21.Gen |