Size | 1.1MB |
---|---|
Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | d0f4b601ec0028ab1dbde57d6b91c77a |
SHA1 | fa568618c0d1a7ba6965742d15f80378795e6df1 |
SHA256 | 91af8e1da6c110954d001e703c668eb799bd308a913ae34bd2ff4f6d07f97735 |
SHA512 |
1b3ee989ed1ced511274e3af40889ae34a8e4ac50757d179beb8b3db313dd0431de58390faffbaf8e369642b56d579793b2e4aedad2fc403265efdb3186f0078
|
CRC32 | D138CBAC |
ssdeep | None |
PDB Path | c:\srv\slave\workdir\repos\opera\chromium\src\out\Release\installer_helper\installer_helper.exe.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 5, 2025, 11:57 a.m. | May 5, 2025, 12:03 p.m. | 357 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-05 10:41:03,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpsftntc 2025-05-05 10:41:03,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\DvtzrUIeJhLBbVXoSJtZHjEDXS 2025-05-05 10:41:03,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\uAMLixnvvtrVVpbcZVYs 2025-05-05 10:41:03,342 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-05 10:41:03,342 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-05 10:41:03,937 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-05 10:41:04,203 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-05-05 10:41:04,203 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-05 10:41:04,203 [analyzer] DEBUG: Started auxiliary module Human 2025-05-05 10:41:04,203 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-05 10:41:04,217 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-05 10:41:04,280 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-05 10:41:04,280 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-05 10:41:04,296 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-05 10:41:04,296 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-05 10:41:04,421 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d0f4b601ec0028ab1dbde57d6b91c77.exe' with arguments '' and pid 1524 2025-05-05 10:41:04,671 [analyzer] DEBUG: Loaded monitor into process with pid 1524 2025-05-05 10:41:05,030 [analyzer] INFO: Added new file to list with pid 1524 and path C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 2025-05-05 10:41:05,467 [analyzer] INFO: Added new file to list with pid 1524 and path C:\Windows\System32\alg.exe 2025-05-05 10:41:05,750 [analyzer] INFO: Added new file to list with pid 1524 and path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 2025-05-05 10:41:06,171 [analyzer] INFO: Added new file to list with pid 1524 and path C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 2025-05-05 10:41:06,578 [analyzer] INFO: Added new file to list with pid 1524 and path C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 2025-05-05 10:41:06,890 [analyzer] INFO: Added new file to list with pid 1524 and path C:\Windows\System32\dllhost.exe 2025-05-05 11:00:23,405 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-05 11:00:23,719 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1524. 2025-05-05 11:00:24,094 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-05 11:00:24,094 [lib.api.process] INFO: Successfully terminated process with pid 1524. 2025-05-05 11:00:24,155 [analyzer] WARNING: File at path u'c:\\windows\\system32\\alg.exe' does not exist, skip. 2025-05-05 11:00:24,155 [analyzer] INFO: Analysis completed.
2025-05-05 11:57:22,978 [cuckoo.core.scheduler] DEBUG: Task #6433120: no machine available yet 2025-05-05 11:57:24,087 [cuckoo.core.scheduler] DEBUG: Task #6433120: no machine available yet 2025-05-05 11:57:25,209 [cuckoo.core.scheduler] DEBUG: Task #6433120: no machine available yet 2025-05-05 11:57:26,408 [cuckoo.core.scheduler] DEBUG: Task #6433120: no machine available yet 2025-05-05 11:57:27,688 [cuckoo.core.scheduler] INFO: Task #6433120: acquired machine win7x6421 (label=win7x6421) 2025-05-05 11:57:27,691 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.221 for task #6433120 2025-05-05 11:57:28,096 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3079562 (interface=vboxnet0, host=192.168.168.221) 2025-05-05 11:57:39,420 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6421 2025-05-05 11:57:40,184 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6421 to vmcloak 2025-05-05 11:59:45,351 [cuckoo.core.guest] INFO: Starting analysis #6433120 on guest (id=win7x6421, ip=192.168.168.221) 2025-05-05 11:59:46,357 [cuckoo.core.guest] DEBUG: win7x6421: not ready yet 2025-05-05 11:59:51,393 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6421, ip=192.168.168.221) 2025-05-05 11:59:51,505 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6421, ip=192.168.168.221, monitor=latest, size=6660546) 2025-05-05 11:59:52,981 [cuckoo.core.resultserver] DEBUG: Task #6433120: live log analysis.log initialized. 2025-05-05 11:59:54,110 [cuckoo.core.resultserver] DEBUG: Task #6433120 is sending a BSON stream 2025-05-05 11:59:54,469 [cuckoo.core.resultserver] DEBUG: Task #6433120 is sending a BSON stream 2025-05-05 11:59:55,417 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'shots/0001.jpg' 2025-05-05 11:59:55,447 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 133477 2025-05-05 11:59:57,591 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'shots/0002.jpg' 2025-05-05 11:59:57,613 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 141513 2025-05-05 12:00:04,934 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'shots/0003.jpg' 2025-05-05 12:00:04,955 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 141026 2025-05-05 12:00:07,518 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6433120 still processing 2025-05-05 12:00:22,632 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6433120 still processing 2025-05-05 12:00:23,853 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'curtain/1746435623.84.curtain.log' 2025-05-05 12:00:23,856 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 36 2025-05-05 12:00:24,079 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'sysmon/1746435624.06.sysmon.xml' 2025-05-05 12:00:24,101 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 1950820 2025-05-05 12:00:24,112 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'files/9738696ee3c747e7_mscorsvw.exe' 2025-05-05 12:00:24,118 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 663552 2025-05-05 12:00:24,122 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'files/48e4a8f565fbe359_flashplayerupdateservice.exe' 2025-05-05 12:00:24,128 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 841216 2025-05-05 12:00:24,134 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'files/53b2a2e24a4e82b0_aspnet_state.exe' 2025-05-05 12:00:24,141 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 616448 2025-05-05 12:00:24,145 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'files/f7ad4b09afb301ce_dllhost.exe' 2025-05-05 12:00:24,147 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 7168 2025-05-05 12:00:24,153 [cuckoo.core.resultserver] DEBUG: Task #6433120: File upload for 'files/a9144d8db6680c89_mscorsvw.exe' 2025-05-05 12:00:24,162 [cuckoo.core.resultserver] DEBUG: Task #6433120 uploaded file length: 640000 2025-05-05 12:00:24,608 [cuckoo.core.resultserver] DEBUG: Task #6433120 had connection reset for <Context for LOG> 2025-05-05 12:00:25,700 [cuckoo.core.guest] INFO: win7x6421: analysis completed successfully 2025-05-05 12:00:25,750 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-05 12:00:25,780 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-05 12:00:26,490 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6421 to path /srv/cuckoo/cwd/storage/analyses/6433120/memory.dmp 2025-05-05 12:00:26,491 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6421 2025-05-05 12:03:18,191 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.221 for task #6433120 2025-05-05 12:03:19,907 [cuckoo.core.scheduler] DEBUG: Released database task #6433120 2025-05-05 12:03:19,961 [cuckoo.core.scheduler] INFO: Task #6433120: analysis procedure completed
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Affect private profile | rule | win_files_operation |