Size | 1.7MB |
---|---|
Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | d463e5b74daae385d73b8c8216cd0c24 |
SHA1 | 4ae596e1532f3a3d107cac282eb4e879edf346ae |
SHA256 | f7601bcff3284a4d077e98bfcb16c9d0434a827e80055db60ab016cfb4ad9324 |
SHA512 |
882297b4eabb97a1eb95c2218207b617fba3680496dfd253f575bf127711d5ac199703826fbe03c6ca63c1e6074b6edabfabc907ee1e7b77fc575999008bd04f
|
CRC32 | 334DA1BE |
ssdeep | None |
PDB Path | z:\task_1579288126\build\src\obj-firefox\toolkit\components\maintenanceservice\maintenanceservice.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 5, 2025, 12:03 p.m. | May 5, 2025, 12:10 p.m. | 385 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-05 10:41:05,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpwoh6zt 2025-05-05 10:41:05,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\smLOddzqzwIIypOJBF 2025-05-05 10:41:05,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\FwGXoUPcGwyvuOisWVKlz 2025-05-05 10:41:05,358 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-05 10:41:05,358 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-05 10:41:06,062 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-05 10:41:06,265 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-05-05 10:41:06,265 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-05 10:41:06,265 [analyzer] DEBUG: Started auxiliary module Human 2025-05-05 10:41:06,265 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-05 10:41:06,280 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-05 10:41:06,375 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-05 10:41:06,375 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-05 10:41:06,375 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-05 10:41:06,375 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-05 10:41:06,530 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d463e5b74daae385d73b8c8216cd0c2.exe' with arguments '' and pid 2164 2025-05-05 10:41:06,750 [analyzer] DEBUG: Loaded monitor into process with pid 2164 2025-05-05 10:41:07,233 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 2025-05-05 10:41:09,296 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\alg.exe 2025-05-05 10:41:10,453 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 2025-05-05 10:41:11,405 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 2025-05-05 10:41:12,671 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 2025-05-05 10:41:13,842 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\dllhost.exe 2025-05-05 10:41:15,030 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\ehome\ehrecvr.exe 2025-05-05 10:41:15,983 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\ehome\ehsched.exe 2025-05-05 10:41:17,125 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\FXSSVC.exe 2025-05-05 10:41:18,000 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\ieetwcollector.exe 2025-05-05 10:41:19,328 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 2025-05-05 10:41:20,483 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\msdtc.exe 2025-05-05 10:41:21,703 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\msiexec.exe 2025-05-05 11:07:23,522 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 2025-05-05 11:07:24,647 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\SysWOW64\perfhost.exe 2025-05-05 11:07:25,647 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\Locator.exe 2025-05-05 11:07:26,631 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\snmptrap.exe 2025-05-05 11:07:27,584 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\vds.exe 2025-05-05 11:07:28,974 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\VSSVC.exe 2025-05-05 11:07:30,427 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\wbengine.exe 2025-05-05 11:07:31,740 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Windows\System32\wbem\WmiApSrv.exe 2025-05-05 11:07:32,911 [analyzer] INFO: Added new file to list with pid 2164 and path C:\Program Files\Windows Media Player\wmpnetwk.exe 2025-05-05 11:07:34,272 [analyzer] INFO: Added new file to list with pid 2164 and path C:\MSOCache\All Users\{90140000-0012-0000-1000-0000000FF1CE}-C\ose.exe 2025-05-05 11:07:35,459 [analyzer] INFO: Added new file to list with pid 2164 and path C:\MSOCache\All Users\{90140000-0012-0000-1000-0000000FF1CE}-C\setup.exe 2025-05-05 11:07:35,927 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-05 11:07:36,068 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2164. 2025-05-05 11:07:36,443 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-05 11:07:36,443 [lib.api.process] INFO: Successfully terminated process with pid 2164. 2025-05-05 11:07:36,474 [analyzer] WARNING: File at path u'c:\\windows\\system32\\fxssvc.exe' does not exist, skip. 2025-05-05 11:07:36,474 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbem\\wmiapsrv.exe' does not exist, skip. 2025-05-05 11:07:36,522 [analyzer] WARNING: File at path u'c:\\windows\\system32\\snmptrap.exe' does not exist, skip. 2025-05-05 11:07:36,615 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vds.exe' does not exist, skip. 2025-05-05 11:07:36,647 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbengine.exe' does not exist, skip. 2025-05-05 11:07:36,772 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vssvc.exe' does not exist, skip. 2025-05-05 11:07:36,772 [analyzer] WARNING: File at path u'c:\\windows\\system32\\ieetwcollector.exe' does not exist, skip. 2025-05-05 11:07:36,772 [analyzer] WARNING: File at path u'c:\\windows\\system32\\msdtc.exe' does not exist, skip. 2025-05-05 11:07:36,802 [analyzer] WARNING: File at path u'c:\\windows\\system32\\locator.exe' does not exist, skip. 2025-05-05 11:07:36,865 [analyzer] WARNING: File at path u'c:\\windows\\system32\\alg.exe' does not exist, skip. 2025-05-05 11:07:36,865 [analyzer] INFO: Analysis completed.
2025-05-05 12:03:46,651 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:47,706 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:48,754 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:49,815 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:50,894 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:51,923 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:52,959 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:53,982 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:55,007 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:56,034 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:57,065 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:58,092 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:03:59,116 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:00,141 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:01,163 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:02,190 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:03,216 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:04,244 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:05,268 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:06,295 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:07,322 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:08,349 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:09,411 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:10,460 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:11,491 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:12,521 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:13,700 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:14,750 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:15,797 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:16,883 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:18,022 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:19,149 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:20,356 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:21,465 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:22,551 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:23,613 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:24,900 [cuckoo.core.scheduler] DEBUG: Task #6433152: no machine available yet 2025-05-05 12:04:26,016 [cuckoo.core.scheduler] INFO: Task #6433152: acquired machine win7x643 (label=win7x643) 2025-05-05 12:04:26,017 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.203 for task #6433152 2025-05-05 12:04:26,278 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3088528 (interface=vboxnet0, host=192.168.168.203) 2025-05-05 12:04:31,534 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x643 2025-05-05 12:04:32,034 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x643 to vmcloak 2025-05-05 12:06:56,957 [cuckoo.core.guest] INFO: Starting analysis #6433152 on guest (id=win7x643, ip=192.168.168.203) 2025-05-05 12:06:57,970 [cuckoo.core.guest] DEBUG: win7x643: not ready yet 2025-05-05 12:07:03,012 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x643, ip=192.168.168.203) 2025-05-05 12:07:03,108 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x643, ip=192.168.168.203, monitor=latest, size=6660546) 2025-05-05 12:07:05,376 [cuckoo.core.resultserver] DEBUG: Task #6433152: live log analysis.log initialized. 2025-05-05 12:07:06,602 [cuckoo.core.resultserver] DEBUG: Task #6433152 is sending a BSON stream 2025-05-05 12:07:07,007 [cuckoo.core.resultserver] DEBUG: Task #6433152 is sending a BSON stream 2025-05-05 12:07:07,885 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'shots/0001.jpg' 2025-05-05 12:07:07,923 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 133477 2025-05-05 12:07:19,822 [cuckoo.core.guest] DEBUG: win7x643: analysis #6433152 still processing 2025-05-05 12:07:34,898 [cuckoo.core.guest] DEBUG: win7x643: analysis #6433152 still processing 2025-05-05 12:07:36,180 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'curtain/1746436056.16.curtain.log' 2025-05-05 12:07:36,183 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 36 2025-05-05 12:07:36,430 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'sysmon/1746436056.43.sysmon.xml' 2025-05-05 12:07:36,452 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1685426 2025-05-05 12:07:36,474 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/8af5959bd5f30ebe_perfhost.exe' 2025-05-05 12:07:36,487 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1519104 2025-05-05 12:07:36,504 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/e535649aa2e3deff_aspnet_state.exe' 2025-05-05 12:07:36,526 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1533952 2025-05-05 12:07:36,542 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/c19c9d97e3f00eb8_mscorsvw.exe' 2025-05-05 12:07:36,556 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1561600 2025-05-05 12:07:36,595 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/d444fb499a5970e0_wmpnetwk.exe' 2025-05-05 12:07:36,620 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 2106368 2025-05-05 12:07:36,636 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/3bba4be14f87ee56_ose.exe' 2025-05-05 12:07:36,650 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1670144 2025-05-05 12:07:36,666 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/7142f2b0b4a4dc43_flashplayerupdateservice.exe' 2025-05-05 12:07:36,681 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1762816 2025-05-05 12:07:36,698 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/cec22460384bd5dd_setup.exe' 2025-05-05 12:07:36,714 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1953280 2025-05-05 12:07:36,729 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/5faeb225851f104d_ehsched.exe' 2025-05-05 12:07:36,740 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1625600 2025-05-05 12:07:36,746 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/f7ad4b09afb301ce_dllhost.exe' 2025-05-05 12:07:36,747 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 7168 2025-05-05 12:07:36,760 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/397de648ed472da4_mscorsvw.exe' 2025-05-05 12:07:36,773 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1585152 2025-05-05 12:07:36,779 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/78617ddf9a0067a3_msiexec.exe' 2025-05-05 12:07:36,781 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 73216 2025-05-05 12:07:36,801 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/296d56e4c2d5c357_ose.exe' 2025-05-05 12:07:36,817 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1670144 2025-05-05 12:07:36,834 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/ca0cd3a9c5175735_maintenanceservice.exe' 2025-05-05 12:07:36,848 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1640960 2025-05-05 12:07:36,864 [cuckoo.core.resultserver] DEBUG: Task #6433152: File upload for 'files/97c204b17e8d09a5_ehrecvr.exe' 2025-05-05 12:07:36,878 [cuckoo.core.resultserver] DEBUG: Task #6433152 uploaded file length: 1276416 2025-05-05 12:07:36,898 [cuckoo.core.resultserver] DEBUG: Task #6433152 had connection reset for <Context for LOG> 2025-05-05 12:07:37,917 [cuckoo.core.guest] INFO: win7x643: analysis completed successfully 2025-05-05 12:07:37,933 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-05 12:07:37,954 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-05 12:07:38,706 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x643 to path /srv/cuckoo/cwd/storage/analyses/6433152/memory.dmp 2025-05-05 12:07:38,707 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x643 2025-05-05 12:10:08,811 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.203 for task #6433152 2025-05-05 12:10:10,970 [cuckoo.core.scheduler] DEBUG: Released database task #6433152 2025-05-05 12:10:10,997 [cuckoo.core.scheduler] INFO: Task #6433152: analysis procedure completed
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Create a windows service | rule | create_service | ||||||
description | Escalade priviledges | rule | escalate_priv | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect system token | rule | win_token | ||||||
description | Affect private profile | rule | win_files_operation |