Size | 13.0KB |
---|---|
Type | Unicode text, UTF-8 text, with very long lines (1666), with CRLF line terminators |
MD5 | 325b7bcce70dc0d6eeab359346e13552 |
SHA1 | 9f0441640c24337966de4b6d56c100f167796ffc |
SHA256 | 67d86656a4dc4042233c79fc40f670ed47f1aef61f92b04cab33528dfa29ed63 |
SHA512 |
9b0947a9d21325711c7b471a835d1acce23b52ab70f6f100f160fe7359641b97e6ccc372da6f7d2f7f98eefaa6e7a764284370d78327583fd8a01f1dc1d76a39
|
CRC32 | B4361B90 |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 28, 2025, 9:14 p.m. | April 28, 2025, 9:21 p.m. | 414 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-28 11:34:05,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpk4d6bl 2025-04-28 11:34:05,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\fcYZPXrJgJOObFRbUNlIJszaWE 2025-04-28 11:34:05,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\WgWqCyZaSdooyFYMimWYjgYdpDiyzkBj 2025-04-28 11:34:05,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-04-28 11:34:05,046 [analyzer] INFO: Automatically selected analysis package "generic" 2025-04-28 11:34:05,437 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-28 11:34:05,437 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-28 11:34:06,108 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-28 11:34:06,328 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-04-28 11:34:06,328 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-28 11:34:06,328 [analyzer] DEBUG: Started auxiliary module Human 2025-04-28 11:34:06,328 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-28 11:34:06,342 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-28 11:34:06,453 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-28 11:34:06,453 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-28 11:34:06,467 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-28 11:34:06,467 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-28 11:34:06,562 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"jMhIDDunSoFUFamC"', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\gpuBBIGPGiGoJmTtrpL.mp3'] and pid 2176 2025-04-28 11:34:06,890 [analyzer] DEBUG: Loaded monitor into process with pid 2176 2025-04-28 11:34:07,265 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-28 11:34:07,296 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,312 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,312 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,328 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-28 11:34:07,328 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,328 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,390 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,405 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-28 11:34:07,453 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-28 11:34:07,467 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,500 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,592 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,608 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-28 11:34:07,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,640 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-28 11:34:07,953 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-28 11:34:07,967 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,967 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,967 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,967 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-28 11:34:07,967 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,967 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,983 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,983 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,983 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:07,983 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-28 11:34:08,125 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-28 11:34:08,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:08,125 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:08,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:08,140 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-28 11:34:08,140 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:08,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:08,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:08,155 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-28 11:34:08,171 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:08,171 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-28 11:34:13,250 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-28 11:34:13,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,265 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-28 11:34:13,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,296 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-28 11:34:13,625 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-04-28 11:34:13,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,640 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-04-28 11:34:13,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-04-28 11:34:13,655 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-04-28 11:34:17,595 [analyzer] INFO: Process with pid 2176 has terminated 2025-04-28 11:34:17,595 [analyzer] INFO: Process list is empty, terminating analysis. 2025-04-28 11:34:19,000 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-28 11:34:19,000 [analyzer] INFO: Analysis completed.
2025-04-28 21:14:56,177 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:14:57,208 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:14:58,231 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:14:59,250 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:00,277 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:01,307 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:02,368 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:03,397 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:04,421 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:05,523 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:06,551 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:07,588 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:08,648 [cuckoo.core.scheduler] DEBUG: Task #6354289: no machine available yet 2025-04-28 21:15:09,708 [cuckoo.core.scheduler] INFO: Task #6354289: acquired machine win7x6422 (label=win7x6422) 2025-04-28 21:15:09,708 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.222 for task #6354289 2025-04-28 21:15:09,980 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1203278 (interface=vboxnet0, host=192.168.168.222) 2025-04-28 21:15:10,080 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6422 2025-04-28 21:15:10,506 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6422 to vmcloak 2025-04-28 21:18:00,212 [cuckoo.core.guest] INFO: Starting analysis #6354289 on guest (id=win7x6422, ip=192.168.168.222) 2025-04-28 21:18:01,216 [cuckoo.core.guest] DEBUG: win7x6422: not ready yet 2025-04-28 21:18:06,246 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6422, ip=192.168.168.222) 2025-04-28 21:18:06,347 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6422, ip=192.168.168.222, monitor=latest, size=6660546) 2025-04-28 21:18:07,828 [cuckoo.core.resultserver] DEBUG: Task #6354289: live log analysis.log initialized. 2025-04-28 21:18:09,105 [cuckoo.core.resultserver] DEBUG: Task #6354289 is sending a BSON stream 2025-04-28 21:18:09,686 [cuckoo.core.resultserver] DEBUG: Task #6354289 is sending a BSON stream 2025-04-28 21:18:10,447 [cuckoo.core.resultserver] DEBUG: Task #6354289: File upload for 'shots/0001.jpg' 2025-04-28 21:18:10,466 [cuckoo.core.resultserver] DEBUG: Task #6354289 uploaded file length: 114851 2025-04-28 21:18:17,736 [cuckoo.core.resultserver] DEBUG: Task #6354289: File upload for 'shots/0002.jpg' 2025-04-28 21:18:17,761 [cuckoo.core.resultserver] DEBUG: Task #6354289 uploaded file length: 111874 2025-04-28 21:18:20,955 [cuckoo.core.resultserver] DEBUG: Task #6354289: File upload for 'shots/0003.jpg' 2025-04-28 21:18:20,978 [cuckoo.core.resultserver] DEBUG: Task #6354289 uploaded file length: 130339 2025-04-28 21:18:21,665 [cuckoo.core.resultserver] DEBUG: Task #6354289: File upload for 'curtain/1745832858.82.curtain.log' 2025-04-28 21:18:21,668 [cuckoo.core.resultserver] DEBUG: Task #6354289 uploaded file length: 36 2025-04-28 21:18:21,839 [cuckoo.core.resultserver] DEBUG: Task #6354289: File upload for 'sysmon/1745832858.99.sysmon.xml' 2025-04-28 21:18:21,851 [cuckoo.core.resultserver] DEBUG: Task #6354289 uploaded file length: 660134 2025-04-28 21:18:22,046 [cuckoo.core.resultserver] DEBUG: Task #6354289 had connection reset for <Context for LOG> 2025-04-28 21:18:22,626 [cuckoo.core.guest] INFO: win7x6422: analysis completed successfully 2025-04-28 21:18:22,642 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-28 21:18:22,671 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-28 21:18:23,318 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6422 to path /srv/cuckoo/cwd/storage/analyses/6354289/memory.dmp 2025-04-28 21:18:23,330 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6422 2025-04-28 21:21:48,926 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.222 for task #6354289 2025-04-28 21:21:50,384 [cuckoo.core.scheduler] DEBUG: Released database task #6354289 2025-04-28 21:21:50,415 [cuckoo.core.scheduler] INFO: Task #6354289: analysis procedure completed
No signatures