Size | 1.1MB |
---|---|
Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | 45689c7b1fa020b62a0c7a85660a4f12 |
SHA1 | 3a3ab50987ceaf26cf1e2739b84be35baef377e4 |
SHA256 | 1fbbe715d2748c45f8cbf8e78be2fa4df7e09a11947b6d6685a29af8032b5d79 |
SHA512 |
f05dbd054576511f2ac495b83771fc1c3773e494e0bafee5d1db094fef4c50a707557740366490a1b6f69481af27fe1ed8ecb014c4f39c07ba61cc100344cc7d
|
CRC32 | 08CDC0F0 |
ssdeep | None |
PDB Path | E:\CPython\cpython35\lib\distutils\command\wininst-14.0-amd64.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 5, 2025, 11:14 a.m. | May 5, 2025, 11:22 a.m. | 474 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-05 10:40:51,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdyrg_l 2025-05-05 10:40:51,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\bKuSkebWwbRsYlfGTUQJo 2025-05-05 10:40:51,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\HlklyjuduTvHdqVvvVuzFXlWZe 2025-05-05 10:40:51,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-05 10:40:51,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-05 10:40:51,780 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-05 10:40:51,983 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-05-05 10:40:51,983 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-05 10:40:51,983 [analyzer] DEBUG: Started auxiliary module Human 2025-05-05 10:40:51,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-05 10:40:52,000 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-05 10:40:52,125 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-05 10:40:52,140 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-05 10:40:52,140 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-05 10:40:52,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-05 10:40:52,265 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\45689c7b1fa020b62a0c7a85660a4f.exe' with arguments '' and pid 1696 2025-05-05 10:40:52,467 [analyzer] DEBUG: Loaded monitor into process with pid 1696 2025-05-05 10:40:53,092 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 2025-05-05 10:40:53,467 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\alg.exe 2025-05-05 10:40:53,875 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 2025-05-05 10:40:54,140 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 2025-05-05 10:40:54,592 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 2025-05-05 10:40:54,890 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\dllhost.exe 2025-05-05 10:40:55,203 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\ehome\ehrecvr.exe 2025-05-05 10:40:55,500 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\ehome\ehsched.exe 2025-05-05 10:40:55,717 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\FXSSVC.exe 2025-05-05 10:40:56,030 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\ieetwcollector.exe 2025-05-05 10:40:56,265 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 2025-05-05 10:40:56,562 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\msdtc.exe 2025-05-05 10:40:56,983 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\msiexec.exe 2025-05-05 10:40:57,358 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 2025-05-05 10:40:57,592 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\SysWOW64\perfhost.exe 2025-05-05 10:40:57,890 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\Locator.exe 2025-05-05 10:40:58,140 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\snmptrap.exe 2025-05-05 10:40:58,421 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\vds.exe 2025-05-05 10:40:58,812 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\VSSVC.exe 2025-05-05 10:40:59,358 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\wbengine.exe 2025-05-05 10:40:59,812 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Windows\System32\wbem\WmiApSrv.exe 2025-05-05 10:41:00,078 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Windows Media Player\wmpnetwk.exe 2025-05-05 10:41:00,530 [analyzer] INFO: Added new file to list with pid 1696 and path C:\MSOCache\All Users\{90140000-0012-0000-1000-0000000FF1CE}-C\ose.exe 2025-05-05 10:41:00,703 [analyzer] INFO: Added new file to list with pid 1696 and path C:\MSOCache\All Users\{90140000-0012-0000-1000-0000000FF1CE}-C\setup.exe 2025-05-05 10:41:01,030 [analyzer] INFO: Added new file to list with pid 1696 and path C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\DW20.EXE 2025-05-05 10:41:01,296 [analyzer] INFO: Added new file to list with pid 1696 and path C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\dwtrig20.exe 2025-05-05 10:41:02,140 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\jabswitch.exe 2025-05-05 10:41:02,280 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\java-rmi.exe 2025-05-05 10:41:02,483 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\java.exe 2025-05-05 10:41:02,687 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\javacpl.exe 2025-05-05 10:41:02,921 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\javaw.exe 2025-05-05 10:41:03,125 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\javaws.exe 2025-05-05 10:41:03,296 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\jp2launcher.exe 2025-05-05 10:41:03,467 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\keytool.exe 2025-05-05 10:41:03,671 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\kinit.exe 2025-05-05 10:41:03,875 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\klist.exe 2025-05-05 10:41:04,078 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\ktab.exe 2025-05-05 10:41:04,296 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\orbd.exe 2025-05-05 10:41:04,530 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\pack200.exe 2025-05-05 10:41:04,733 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\policytool.exe 2025-05-05 10:41:04,921 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\rmid.exe 2025-05-05 10:41:05,125 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\rmiregistry.exe 2025-05-05 10:41:05,390 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\servertool.exe 2025-05-05 10:41:05,625 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\ssvagent.exe 2025-05-05 10:41:05,858 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\tnameserv.exe 2025-05-05 10:41:06,062 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\Java\jre7\bin\unpack200.exe 2025-05-05 10:41:06,765 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\WinRAR\Ace32Loader.exe 2025-05-05 10:41:06,953 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\WinRAR\Rar.exe 2025-05-05 10:41:07,203 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\WinRAR\Uninstall.exe 2025-05-05 10:18:03,351 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\WinRAR\UnRAR.exe 2025-05-05 10:18:03,539 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files\WinRAR\WinRAR.exe 2025-05-05 10:18:03,898 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\A3DUtility.exe 2025-05-05 10:18:04,117 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroBroker.exe 2025-05-05 10:18:04,351 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe 2025-05-05 10:18:04,617 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32Info.exe 2025-05-05 10:18:04,851 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroTextExtractor.exe 2025-05-05 10:18:04,992 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AdobeCollabSync.exe 2025-05-05 10:18:05,289 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Eula.exe 2025-05-05 10:18:05,757 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe 2025-05-05 10:18:06,226 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Adobe\Reader 9.0\Setup Files\{AC76BA86-7AD7-1033-7B44-A90000000001}\Setup.exe 2025-05-05 10:18:06,539 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Common Files\Adobe\Updater6\AdobeUpdaterInstallMgr.exe 2025-05-05 10:18:06,678 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe 2025-05-05 10:18:07,039 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe 2025-05-05 10:18:07,178 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe 2025-05-05 10:18:07,351 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\airappinstaller.exe 2025-05-05 10:18:07,539 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\template.exe 2025-05-05 10:18:07,992 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Common Files\microsoft shared\TextConv\WksConv\Wkconv.exe 2025-05-05 10:18:08,414 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe 2025-05-05 10:18:08,694 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Globalscape\CuteFTP\cuteftppro.exe 2025-05-05 10:18:09,148 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Globalscape\CuteFTP\ftpte.exe 2025-05-05 10:18:09,492 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Globalscape\CuteFTP\Setup\Disk1\Setup.exe 2025-05-05 10:18:09,632 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\InstallShield Installation Information\{89B9E358-75C6-4C6B-BD38-803FF156CC4B}\Setup.exe 2025-05-05 10:18:09,819 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe 2025-05-05 10:18:09,992 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Firefox\firefox.exe 2025-05-05 10:18:10,178 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe 2025-05-05 10:18:10,351 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe 2025-05-05 10:18:10,539 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2025-05-05 10:18:10,694 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Firefox\updater.exe 2025-05-05 10:18:10,882 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe 2025-05-05 10:18:11,039 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Program Files (x86)\Mozilla Firefox\wow_helper.exe 2025-05-05 10:18:11,398 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\distutils\command\wininst-6.0.exe 2025-05-05 10:18:11,569 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\distutils\command\wininst-7.1.exe 2025-05-05 10:18:11,726 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\distutils\command\wininst-8.0.exe 2025-05-05 10:18:11,914 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\distutils\command\wininst-9.0-amd64.exe 2025-05-05 10:18:12,117 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\distutils\command\wininst-9.0.exe 2025-05-05 10:18:13,460 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\pip\_vendor\distlib\t32.exe 2025-05-05 10:18:13,773 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\pip\_vendor\distlib\t64.exe 2025-05-05 10:18:14,053 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\pip\_vendor\distlib\w32.exe 2025-05-05 10:18:14,319 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\pip\_vendor\distlib\w64.exe 2025-05-05 10:18:14,960 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\setuptools\cli-32.exe 2025-05-05 10:18:15,242 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\setuptools\cli-64.exe 2025-05-05 10:18:15,414 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\setuptools\cli.exe 2025-05-05 10:18:15,694 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\setuptools\gui-32.exe 2025-05-05 10:18:15,944 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\setuptools\gui-64.exe 2025-05-05 10:18:16,148 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\Lib\site-packages\setuptools\gui.exe 2025-05-05 10:18:17,178 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\python.exe 2025-05-05 10:18:17,242 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-05 10:18:17,335 [analyzer] INFO: Added new file to list with pid 1696 and path C:\Python27\RemovePillow.exe 2025-05-05 10:18:17,492 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1696. 2025-05-05 10:18:17,803 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-05 10:18:17,803 [lib.api.process] INFO: Successfully terminated process with pid 1696. 2025-05-05 10:18:17,819 [analyzer] WARNING: File at path u'c:\\windows\\system32\\fxssvc.exe' does not exist, skip. 2025-05-05 10:18:17,944 [analyzer] WARNING: File at path u'c:\\windows\\system32\\ieetwcollector.exe' does not exist, skip. 2025-05-05 10:18:18,023 [analyzer] WARNING: File at path u'c:\\windows\\system32\\locator.exe' does not exist, skip. 2025-05-05 10:18:18,178 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrord32info.exe 2025-05-05 10:18:18,178 [analyzer] WARNING: File at path u'c:\\windows\\system32\\snmptrap.exe' does not exist, skip. 2025-05-05 10:18:18,178 [analyzer] WARNING: Too many files: c:\program files\windows media player\wmpnetwk.exe 2025-05-05 10:18:18,178 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrotextextractor.exe 2025-05-05 10:18:18,178 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\adobe air application installer.exe 2025-05-05 10:18:18,178 [analyzer] WARNING: Too many files: c:\windows\ehome\ehrecvr.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0012-0000-1000-0000000ff1ce}-c\setup.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\microsoft shared\vsto\10.0\vstoinstaller.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\setuptools\gui-32.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\a3dutility.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\program files\winrar\winrar.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dwtrig20.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\servertool.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\program files (x86)\globalscape\cuteftp\setup\disk1\setup.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\program files (x86)\globalscape\cuteftp\ftpte.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: File at path u'c:\\windows\\system32\\msdtc.exe' does not exist, skip. 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\airappinstaller.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\setuptools\cli.exe 2025-05-05 10:18:18,194 [analyzer] WARNING: Too many files: c:\python27\lib\distutils\command\wininst-7.1.exe 2025-05-05 10:18:18,210 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbem\\wmiapsrv.exe' does not exist, skip. 2025-05-05 10:18:18,210 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\rmid.exe 2025-05-05 10:18:18,210 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe 2025-05-05 10:18:18,210 [analyzer] WARNING: Too many files: c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe 2025-05-05 10:18:18,210 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\adobe air updater.exe 2025-05-05 10:18:18,226 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vds.exe' does not exist, skip. 2025-05-05 10:18:18,226 [analyzer] WARNING: Too many files: c:\program files\common files\microsoft shared\source engine\ose.exe 2025-05-05 10:18:18,226 [analyzer] WARNING: Too many files: c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe 2025-05-05 10:18:18,226 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\javacpl.exe 2025-05-05 10:18:18,226 [analyzer] WARNING: Too many files: c:\python27\python.exe 2025-05-05 10:18:18,242 [analyzer] WARNING: Too many files: c:\program files\winrar\unrar.exe 2025-05-05 10:18:18,242 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vssvc.exe' does not exist, skip. 2025-05-05 10:18:18,242 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrobroker.exe 2025-05-05 10:18:18,242 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\setup files\{ac76ba86-7ad7-1033-7b44-a90000000001}\setup.exe 2025-05-05 10:18:18,242 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrord32.exe 2025-05-05 10:18:18,242 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\pip\_vendor\distlib\w32.exe 2025-05-05 10:18:18,242 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\orbd.exe 2025-05-05 10:18:18,242 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\webapprt-stub.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\klist.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\windows\system32\msiexec.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\plugin-container.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\pip\_vendor\distlib\t32.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe\updater6\adobe_updater.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: File at path u'c:\\windows\\system32\\alg.exe' does not exist, skip. 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\template.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\python27\lib\distutils\command\wininst-9.0-amd64.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\windows\microsoft.net\framework64\v4.0.30319\aspnet_state.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\maintenanceservice.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\ssvagent.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files (x86)\globalscape\cuteftp\cuteftppro.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\wow_helper.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbengine.exe' does not exist, skip. 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\python27\lib\distutils\command\wininst-6.0.exe 2025-05-05 10:18:18,257 [analyzer] WARNING: Too many files: c:\program files\winrar\uninstall.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\microsoft shared\textconv\wksconv\wkconv.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\program files\winrar\rar.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\windows\ehome\ehsched.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\windows\system32\dllhost.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\pack200.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\python27\lib\distutils\command\wininst-8.0.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\jp2launcher.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\setuptools\gui.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\jabswitch.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\tnameserv.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\eula.exe 2025-05-05 10:18:18,273 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\policytool.exe
2025-05-05 11:14:06,080 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:07,107 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:08,132 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:09,155 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:10,181 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:11,208 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:12,237 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:13,276 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:14,335 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:15,417 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:16,506 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:17,607 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:18,690 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:19,774 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:20,868 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:21,947 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:23,157 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:24,199 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:25,246 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:26,282 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:27,332 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:28,374 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:29,416 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:30,487 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:31,526 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:32,555 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:33,599 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:34,639 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:35,675 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:36,711 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:37,750 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:38,792 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:39,834 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:40,884 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:42,038 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:43,088 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:44,128 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:45,167 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:46,208 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:47,259 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:48,295 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:49,328 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:50,372 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:51,414 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:52,448 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:53,485 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:54,530 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:55,570 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:56,677 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:57,771 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:58,903 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:14:59,984 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:01,063 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:02,153 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:03,232 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:04,299 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:05,361 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:06,423 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:07,469 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:08,515 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:09,567 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:10,607 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:11,681 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:12,736 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:13,782 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:14,819 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:15,890 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:16,998 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:18,060 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:19,141 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:20,198 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:21,257 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:22,306 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:23,373 [cuckoo.core.scheduler] DEBUG: Task #6432908: no machine available yet 2025-05-05 11:15:24,455 [cuckoo.core.scheduler] INFO: Task #6432908: acquired machine win7x6430 (label=win7x6430) 2025-05-05 11:15:24,462 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.230 for task #6432908 2025-05-05 11:15:24,710 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3009645 (interface=vboxnet0, host=192.168.168.230) 2025-05-05 11:15:29,915 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6430 2025-05-05 11:15:30,437 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6430 to vmcloak 2025-05-05 11:17:39,347 [cuckoo.core.guest] INFO: Starting analysis #6432908 on guest (id=win7x6430, ip=192.168.168.230) 2025-05-05 11:17:40,357 [cuckoo.core.guest] DEBUG: win7x6430: not ready yet 2025-05-05 11:17:45,388 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6430, ip=192.168.168.230) 2025-05-05 11:17:45,499 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6430, ip=192.168.168.230, monitor=latest, size=6660546) 2025-05-05 11:17:46,966 [cuckoo.core.resultserver] DEBUG: Task #6432908: live log analysis.log initialized. 2025-05-05 11:17:47,894 [cuckoo.core.resultserver] DEBUG: Task #6432908 is sending a BSON stream 2025-05-05 11:17:48,315 [cuckoo.core.resultserver] DEBUG: Task #6432908 is sending a BSON stream 2025-05-05 11:17:49,215 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'shots/0001.jpg' 2025-05-05 11:17:49,239 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 135878 2025-05-05 11:18:01,641 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6432908 still processing 2025-05-05 11:18:16,767 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6432908 still processing 2025-05-05 11:18:17,602 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'curtain/1746433097.59.curtain.log' 2025-05-05 11:18:17,605 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 36 2025-05-05 11:18:17,783 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'sysmon/1746433097.77.sysmon.xml' 2025-05-05 11:18:17,802 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 1450616 2025-05-05 11:18:17,817 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/e1d23b680933e123_w64.exe' 2025-05-05 11:18:17,824 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 674816 2025-05-05 11:18:17,833 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/dab97f8f9636143a_javaws.exe' 2025-05-05 11:18:17,840 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 891904 2025-05-05 11:18:17,844 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/81278137a8f34e88_setup.exe' 2025-05-05 11:18:17,857 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 635392 2025-05-05 11:18:17,864 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/02353155e003482c_unpack200.exe' 2025-05-05 11:18:17,877 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/35cda3ca22258cf6_rmiregistry.exe' 2025-05-05 11:18:17,880 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/e28c143bcb4ad9cb_firefox.exe' 2025-05-05 11:18:17,884 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/c99f52eab49e7ef5_wininst-9.0.exe' 2025-05-05 11:18:17,892 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 754688 2025-05-05 11:18:17,896 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 590848 2025-05-05 11:18:17,899 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/b078793689d10a45_java-rmi.exe' 2025-05-05 11:18:17,901 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 949248 2025-05-05 11:18:17,908 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/7f9749cfaae1591a_reader_sl.exe' 2025-05-05 11:18:17,911 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 776704 2025-05-05 11:18:17,915 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 590848 2025-05-05 11:18:17,918 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/00e23dc7c821b5c5_ktab.exe' 2025-05-05 11:18:17,923 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 609280 2025-05-05 11:18:17,926 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 590848 2025-05-05 11:18:17,930 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/4aa063f23350eb07_javaw.exe' 2025-05-05 11:18:17,936 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/50fdd66df4f1355f_updater.exe' 2025-05-05 11:18:17,938 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 762880 2025-05-05 11:18:17,946 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/686336642ebf1e33_java.exe' 2025-05-05 11:18:17,949 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 870912 2025-05-05 11:18:17,955 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/4609809e06bb671d_plugin-hang-ui.exe' 2025-05-05 11:18:17,958 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 762880 2025-05-05 11:18:17,967 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/5fd5ee88da3f079e_kinit.exe' 2025-05-05 11:18:17,970 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 743424 2025-05-05 11:18:17,978 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 590848 2025-05-05 11:18:17,981 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/5a2fd220d8a07428_crashreporter.exe' 2025-05-05 11:18:17,989 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 855552 2025-05-05 11:18:17,993 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/9975ab0cacf5b877_ose.exe' 2025-05-05 11:18:17,998 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/9d562f2ada43ad58_ace32loader.exe' 2025-05-05 11:18:18,001 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 748544 2025-05-05 11:18:18,007 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 635904 2025-05-05 11:18:18,012 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/f84ff07f4da11d17_adobecollabsync.exe' 2025-05-05 11:18:18,023 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 1118208 2025-05-05 11:18:18,031 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/4f960ef94f44d6f5_keytool.exe' 2025-05-05 11:18:18,038 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 590848 2025-05-05 11:18:18,041 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/6bcb5b672a52a69d_t64.exe' 2025-05-05 11:18:18,047 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 678400 2025-05-05 11:18:18,051 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/a3c2eec11c24efdf_perfhost.exe' 2025-05-05 11:18:18,057 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 601600 2025-05-05 11:18:18,060 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/aae52bcf7f39193a_cli-64.exe' 2025-05-05 11:18:18,066 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 653824 2025-05-05 11:18:18,088 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/b1cf1c2bb1801776_removepillow.exe' 2025-05-05 11:18:18,113 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 776704 2025-05-05 11:18:18,177 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'files/b2a179e6ebad8995_adobeupdaterinstallmgr.exe' 2025-05-05 11:18:18,179 [cuckoo.core.resultserver] DEBUG: Task #6432908: File upload for 'shots/0002.jpg' 2025-05-05 11:18:18,202 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 667648 2025-05-05 11:18:18,246 [cuckoo.core.resultserver] DEBUG: Task #6432908 uploaded file length: 133485 2025-05-05 11:18:18,393 [cuckoo.core.resultserver] DEBUG: Task #6432908 had connection reset for <Context for LOG> 2025-05-05 11:18:19,787 [cuckoo.core.guest] INFO: win7x6430: analysis completed successfully 2025-05-05 11:18:19,810 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-05 11:18:19,845 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-05 11:18:20,526 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6430 to path /srv/cuckoo/cwd/storage/analyses/6432908/memory.dmp 2025-05-05 11:18:20,527 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6430 2025-05-05 11:21:59,544 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.230 for task #6432908 2025-05-05 11:22:00,252 [cuckoo.core.scheduler] DEBUG: Released database task #6432908 2025-05-05 11:22:00,316 [cuckoo.core.scheduler] INFO: Task #6432908: analysis procedure completed
description | (no description) | rule | APT32_KerrDown | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | (no description) | rule | Check_OutputDebugStringA_iat | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Take screenshot | rule | screenshot | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect private profile | rule | win_private_profile | ||||||
description | Affect private profile | rule | win_files_operation |