Size | 1.1MB |
---|---|
Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | c99b9146add9d90f6be456c28c48ef10 |
SHA1 | 7f3a6d8cfc4cbff8c6d3704dc8ca252708b419f2 |
SHA256 | 7cd3fe862d7e8657731fd28f23c884340b812ec50b1489142f2fd4e479359462 |
SHA512 |
b2656ec6cda0491de8255c3b5314edcf0d3aad1ca95895cb4938752f5520d6c08563c0bbda89e4c33eee7efa39f2cce9e144f474d822fb8845c2c48255e92ac6
|
CRC32 | 695BBDE0 |
ssdeep | None |
PDB Path | E:\CPython\cpython35\lib\distutils\command\wininst-14.0-amd64.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 5, 2025, 12:04 p.m. | May 5, 2025, 12:10 p.m. | 358 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-05 10:41:05,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp2pjrvv 2025-05-05 10:41:05,000 [analyzer] DEBUG: Pipe server name: \??\PIPE\kcIlvRqtUyQCNZKPVtDeCZWfsMPM 2025-05-05 10:41:05,000 [analyzer] DEBUG: Log pipe server name: \??\PIPE\fznCHXnWnBZutWLZRxCTzrvNCNVBsbqE 2025-05-05 10:41:05,296 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-05 10:41:05,296 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-05 10:41:05,733 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-05 10:41:05,937 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-05-05 10:41:05,937 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-05 10:41:05,937 [analyzer] DEBUG: Started auxiliary module Human 2025-05-05 10:41:05,937 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-05 10:41:05,937 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-05 10:41:06,015 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-05 10:41:06,015 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-05 10:41:06,015 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-05 10:41:06,015 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-05 10:41:06,125 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\c99b9146add9d90f6be456c28c48ef.exe' with arguments '' and pid 2116 2025-05-05 10:41:06,342 [analyzer] DEBUG: Loaded monitor into process with pid 2116 2025-05-05 10:41:06,812 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 2025-05-05 10:41:07,312 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\alg.exe 2025-05-05 10:41:07,858 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 2025-05-05 10:41:08,233 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 2025-05-05 10:41:08,671 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 2025-05-05 10:41:09,062 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\dllhost.exe 2025-05-05 10:41:09,515 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\ehome\ehrecvr.exe 2025-05-05 10:41:09,953 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\ehome\ehsched.exe 2025-05-05 10:41:10,312 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\FXSSVC.exe 2025-05-05 10:41:10,703 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\ieetwcollector.exe 2025-05-05 10:41:11,078 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 2025-05-05 10:41:11,515 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\msdtc.exe 2025-05-05 10:41:11,983 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\msiexec.exe 2025-05-05 10:41:12,328 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 2025-05-05 10:41:12,625 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\SysWOW64\perfhost.exe 2025-05-05 10:41:12,967 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\Locator.exe 2025-05-05 10:41:13,453 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\snmptrap.exe 2025-05-05 10:41:13,858 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\vds.exe 2025-05-05 10:41:14,265 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\VSSVC.exe 2025-05-05 10:41:14,780 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\wbengine.exe 2025-05-05 10:41:15,171 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Windows\System32\wbem\WmiApSrv.exe 2025-05-05 10:41:15,608 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Windows Media Player\wmpnetwk.exe 2025-05-05 10:41:16,030 [analyzer] INFO: Added new file to list with pid 2116 and path C:\MSOCache\All Users\{90140000-0012-0000-1000-0000000FF1CE}-C\ose.exe 2025-05-05 10:41:16,342 [analyzer] INFO: Added new file to list with pid 2116 and path C:\MSOCache\All Users\{90140000-0012-0000-1000-0000000FF1CE}-C\setup.exe 2025-05-05 10:41:16,812 [analyzer] INFO: Added new file to list with pid 2116 and path C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\DW20.EXE 2025-05-05 10:41:17,030 [analyzer] INFO: Added new file to list with pid 2116 and path C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\dwtrig20.exe 2025-05-05 10:41:18,062 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\jabswitch.exe 2025-05-05 10:41:18,375 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\java-rmi.exe 2025-05-05 10:41:18,717 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\java.exe 2025-05-05 10:41:19,030 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\javacpl.exe 2025-05-05 10:41:19,375 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\javaw.exe 2025-05-05 10:41:19,765 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\javaws.exe 2025-05-05 10:41:20,030 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\jp2launcher.exe 2025-05-05 10:41:20,312 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\keytool.exe 2025-05-05 10:41:20,640 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\kinit.exe 2025-05-05 10:41:21,046 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\klist.exe 2025-05-05 10:41:21,390 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\ktab.exe 2025-05-05 11:07:34,752 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\orbd.exe 2025-05-05 11:07:35,142 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\pack200.exe 2025-05-05 11:07:35,454 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\policytool.exe 2025-05-05 11:07:35,767 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\rmid.exe 2025-05-05 11:07:36,065 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\rmiregistry.exe 2025-05-05 11:07:36,345 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\servertool.exe 2025-05-05 11:07:36,642 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\ssvagent.exe 2025-05-05 11:07:36,940 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\tnameserv.exe 2025-05-05 11:07:37,252 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\Java\jre7\bin\unpack200.exe 2025-05-05 11:07:38,079 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\WinRAR\Ace32Loader.exe 2025-05-05 11:07:38,361 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\WinRAR\Rar.exe 2025-05-05 11:07:38,815 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\WinRAR\Uninstall.exe 2025-05-05 11:07:39,111 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\WinRAR\UnRAR.exe 2025-05-05 11:07:39,392 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files\WinRAR\WinRAR.exe 2025-05-05 11:07:39,704 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\A3DUtility.exe 2025-05-05 11:07:40,033 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroBroker.exe 2025-05-05 11:07:40,345 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe 2025-05-05 11:07:40,690 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32Info.exe 2025-05-05 11:07:40,986 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroTextExtractor.exe 2025-05-05 11:07:41,236 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AdobeCollabSync.exe 2025-05-05 11:07:41,658 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Eula.exe 2025-05-05 11:07:42,190 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe 2025-05-05 11:07:42,799 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Adobe\Reader 9.0\Setup Files\{AC76BA86-7AD7-1033-7B44-A90000000001}\Setup.exe 2025-05-05 11:07:43,190 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Common Files\Adobe\Updater6\AdobeUpdaterInstallMgr.exe 2025-05-05 11:07:43,533 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe 2025-05-05 11:07:44,033 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe 2025-05-05 11:07:44,315 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe 2025-05-05 11:07:44,658 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\airappinstaller.exe 2025-05-05 11:07:44,940 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\template.exe 2025-05-05 11:07:45,517 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Common Files\microsoft shared\TextConv\WksConv\Wkconv.exe 2025-05-05 11:07:45,892 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe 2025-05-05 11:07:46,283 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Globalscape\CuteFTP\cuteftppro.exe 2025-05-05 11:07:46,799 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Globalscape\CuteFTP\ftpte.exe 2025-05-05 11:07:47,142 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Globalscape\CuteFTP\Setup\Disk1\Setup.exe 2025-05-05 11:07:47,424 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\InstallShield Installation Information\{89B9E358-75C6-4C6B-BD38-803FF156CC4B}\Setup.exe 2025-05-05 11:07:47,690 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe 2025-05-05 11:07:47,892 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Mozilla Firefox\firefox.exe 2025-05-05 11:07:48,142 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-05 11:07:48,204 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe 2025-05-05 11:07:48,392 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe 2025-05-05 11:07:48,424 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2116. 2025-05-05 11:07:48,595 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2025-05-05 11:07:48,799 [analyzer] INFO: Added new file to list with pid 2116 and path C:\Program Files (x86)\Mozilla Firefox\updater.exe 2025-05-05 11:07:48,940 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-05 11:07:48,940 [lib.api.process] INFO: Successfully terminated process with pid 2116. 2025-05-05 11:07:49,315 [analyzer] WARNING: File at path u'c:\\windows\\system32\\fxssvc.exe' does not exist, skip. 2025-05-05 11:07:49,392 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbem\\wmiapsrv.exe' does not exist, skip. 2025-05-05 11:07:49,627 [analyzer] WARNING: File at path u'c:\\windows\\system32\\snmptrap.exe' does not exist, skip. 2025-05-05 11:07:50,049 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vds.exe' does not exist, skip. 2025-05-05 11:07:50,065 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbengine.exe' does not exist, skip. 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\microsoft shared\vsto\10.0\vstoinstaller.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\program files\winrar\rar.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\windows\ehome\ehsched.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\windows\system32\dllhost.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\windows\system32\msiexec.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\maintenanceservice.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\a3dutility.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: Too many files: c:\program files\winrar\winrar.exe 2025-05-05 11:07:50,267 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vssvc.exe' does not exist, skip. 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\javaw.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dwtrig20.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\pack200.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\servertool.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\plugin-hang-ui.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\updater.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\java.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\globalscape\cuteftp\setup\disk1\setup.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrobroker.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\orbd.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: File at path u'c:\\windows\\system32\\ieetwcollector.exe' does not exist, skip. 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\winrar\ace32loader.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: File at path u'c:\\windows\\system32\\msdtc.exe' does not exist, skip. 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\kinit.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\adobe air application installer.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\jp2launcher.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrord32.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\crashreporter.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0012-0000-1000-0000000ff1ce}-c\ose.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\firefox.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\java-rmi.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: File at path u'c:\\windows\\system32\\locator.exe' does not exist, skip. 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\installshield installation information\{89b9e358-75c6-4c6b-bd38-803ff156cc4b}\setup.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\jabswitch.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\tnameserv.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\policytool.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\setup files\{ac76ba86-7ad7-1033-7b44-a90000000001}\setup.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\klist.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\eula.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\adobecollabsync.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: Too many files: c:\windows\ehome\ehrecvr.exe 2025-05-05 11:07:50,283 [analyzer] WARNING: File at path u'c:\\windows\\system32\\alg.exe' does not exist, skip. 2025-05-05 11:07:50,299 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\keytool.exe 2025-05-05 11:07:50,299 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\template.exe 2025-05-05 11:07:50,299 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\plugin-container.exe 2025-05-05 11:07:50,299 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrotextextractor.exe 2025-05-05 11:07:50,299 [analyzer] INFO: Analysis completed.
2025-05-05 12:04:12,821 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:13,844 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:14,865 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:15,884 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:16,905 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:18,037 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:19,149 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:20,356 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:21,455 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:22,558 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:23,688 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:25,099 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:26,194 [cuckoo.core.scheduler] DEBUG: Task #6433156: no machine available yet 2025-05-05 12:04:27,506 [cuckoo.core.scheduler] INFO: Task #6433156: acquired machine win7x648 (label=win7x648) 2025-05-05 12:04:27,522 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.208 for task #6433156 2025-05-05 12:04:27,769 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3088574 (interface=vboxnet0, host=192.168.168.208) 2025-05-05 12:04:37,319 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x648 2025-05-05 12:04:38,440 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x648 to vmcloak 2025-05-05 12:07:10,293 [cuckoo.core.guest] INFO: Starting analysis #6433156 on guest (id=win7x648, ip=192.168.168.208) 2025-05-05 12:07:11,299 [cuckoo.core.guest] DEBUG: win7x648: not ready yet 2025-05-05 12:07:16,321 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x648, ip=192.168.168.208) 2025-05-05 12:07:16,421 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x648, ip=192.168.168.208, monitor=latest, size=6660546) 2025-05-05 12:07:17,981 [cuckoo.core.resultserver] DEBUG: Task #6433156: live log analysis.log initialized. 2025-05-05 12:07:18,872 [cuckoo.core.resultserver] DEBUG: Task #6433156 is sending a BSON stream 2025-05-05 12:07:19,201 [cuckoo.core.resultserver] DEBUG: Task #6433156 is sending a BSON stream 2025-05-05 12:07:20,144 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'shots/0001.jpg' 2025-05-05 12:07:20,200 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 136167 2025-05-05 12:07:32,702 [cuckoo.core.guest] DEBUG: win7x648: analysis #6433156 still processing 2025-05-05 12:07:47,930 [cuckoo.core.guest] DEBUG: win7x648: analysis #6433156 still processing 2025-05-05 12:07:48,584 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'curtain/1746436068.58.curtain.log' 2025-05-05 12:07:48,586 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 36 2025-05-05 12:07:48,912 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'sysmon/1746436068.91.sysmon.xml' 2025-05-05 12:07:48,946 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 2164602 2025-05-05 12:07:49,062 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'shots/0002.jpg' 2025-05-05 12:07:49,075 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 134192 2025-05-05 12:07:49,190 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/604dc2651140b591_adobe_updater.exe' 2025-05-05 12:07:49,258 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 3089920 2025-05-05 12:07:49,290 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/bce8dabff7f6e783_perfhost.exe' 2025-05-05 12:07:49,326 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1519104 2025-05-05 12:07:49,337 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/171b09e571aa7452_javaws.exe' 2025-05-05 12:07:49,352 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1809408 2025-05-05 12:07:49,365 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/39e79a3b3edfdd50_unpack200.exe' 2025-05-05 12:07:49,447 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1672192 2025-05-05 12:07:49,452 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/5652671b0d908f7a_rmid.exe' 2025-05-05 12:07:49,464 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1508352 2025-05-05 12:07:49,482 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/56f09a92871e20e6_adobeupdaterinstallmgr.exe' 2025-05-05 12:07:49,493 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1585152 2025-05-05 12:07:49,609 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/428410e0eeaaad4a_aspnet_state.exe' 2025-05-05 12:07:49,622 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1533952 2025-05-05 12:07:49,637 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/c38c883f3f12c673_mscorsvw.exe' 2025-05-05 12:07:49,647 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1557504 2025-05-05 12:07:49,666 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/bcf0d554068c4ec9_ssvagent.exe' 2025-05-05 12:07:49,675 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1557504 2025-05-05 12:07:49,691 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/e6259c415f212635_acrord32info.exe' 2025-05-05 12:07:49,701 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1507840 2025-05-05 12:07:49,723 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/6228215b3154db8d_wmpnetwk.exe' 2025-05-05 12:07:49,738 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 2106368 2025-05-05 12:07:49,753 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/96254a723f0db9db_rmiregistry.exe' 2025-05-05 12:07:49,763 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1508352 2025-05-05 12:07:49,779 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/cc40e1caad74680b_ktab.exe' 2025-05-05 12:07:49,790 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1508352 2025-05-05 12:07:49,805 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/80277b3f18d6c96c_adobe air updater.exe' 2025-05-05 12:07:49,817 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1529344 2025-05-05 12:07:49,837 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/2b36cfb1b85abdc0_ftpte.exe' 2025-05-05 12:07:49,860 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 2463232 2025-05-05 12:07:49,892 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/61dd44ddb8ae9d2c_cuteftppro.exe' 2025-05-05 12:07:50,042 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 4133888 2025-05-05 12:07:50,057 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/8d0a5c52662cb905_ose.exe' 2025-05-05 12:07:50,065 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1666048 2025-05-05 12:07:50,080 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/551d2ebebe9427bc_reader_sl.exe' 2025-05-05 12:07:50,089 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1526784 2025-05-05 12:07:50,104 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/05adb9468c23c97f_unrar.exe' 2025-05-05 12:07:50,114 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1827328 2025-05-05 12:07:50,128 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/c5f6b86a83faa6ad_uninstall.exe' 2025-05-05 12:07:50,135 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1678848 2025-05-05 12:07:50,149 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/8410860ea5561357_airappinstaller.exe' 2025-05-05 12:07:50,158 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1526784 2025-05-05 12:07:50,173 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/81dccd8ed5ea1c6c_javacpl.exe' 2025-05-05 12:07:50,181 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1568256 2025-05-05 12:07:50,201 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/2ee29dc1fca3d5d1_wkconv.exe' 2025-05-05 12:07:50,210 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1774080 2025-05-05 12:07:50,225 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/912f0bf317a1be4d_flashplayerupdateservice.exe' 2025-05-05 12:07:50,236 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1758720 2025-05-05 12:07:50,252 [cuckoo.core.resultserver] DEBUG: Task #6433156: File upload for 'files/39a6e7a477f67fd4_setup.exe' 2025-05-05 12:07:50,274 [cuckoo.core.resultserver] DEBUG: Task #6433156 uploaded file length: 1953280 2025-05-05 12:07:50,312 [cuckoo.core.resultserver] DEBUG: Task #6433156 had connection reset for <Context for LOG> 2025-05-05 12:07:50,940 [cuckoo.core.guest] INFO: win7x648: analysis completed successfully 2025-05-05 12:07:50,951 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-05 12:07:50,974 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-05 12:07:51,652 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x648 to path /srv/cuckoo/cwd/storage/analyses/6433156/memory.dmp 2025-05-05 12:07:51,653 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x648 2025-05-05 12:10:08,847 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.208 for task #6433156 2025-05-05 12:10:11,035 [cuckoo.core.scheduler] DEBUG: Released database task #6433156 2025-05-05 12:10:11,077 [cuckoo.core.scheduler] INFO: Task #6433156: analysis procedure completed
description | (no description) | rule | APT32_KerrDown | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | (no description) | rule | Check_OutputDebugStringA_iat | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Take screenshot | rule | screenshot | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect private profile | rule | win_private_profile | ||||||
description | Affect private profile | rule | win_files_operation |