Size | 659.0KB |
---|---|
Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | 605d20784c495adbb9769215ebed4500 |
SHA1 | 5382d2f06f455ae23e52519a658df95ea0925ad6 |
SHA256 | e1d23b680933e12331b7faddbbe8cf3406664c1a7723028667533d14987b92ad |
SHA512 |
73167e8c4ac106ea5ddf767d20e001f2fe4387fb68dea373dfded7ec99cf47339d383ef37dbc70b2e2f8eda37696c303a82e0d403fe38ec839917f29f4d5f340
|
CRC32 | 99CEB191 |
ssdeep | None |
PDB Path | C:\Users\Vinay\Projects\simple_launcher\x64\Release\GUISimpleLauncher.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 11, 2025, 4:04 a.m. | May 11, 2025, 4:11 a.m. | 370 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-05 11:22:43,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpblqbwr 2025-05-05 11:22:43,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\oDTffGJAwLkNyxdtpjfODzjHSt 2025-05-05 11:22:43,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\YiOqZpeCSHRdqbeT 2025-05-05 11:22:43,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-05-05 11:22:43,030 [analyzer] INFO: Automatically selected analysis package "exe" 2025-05-05 11:22:43,312 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-05 11:22:43,312 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-05 11:22:43,796 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-05 11:22:44,000 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-05-05 11:22:44,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-05 11:22:44,000 [analyzer] DEBUG: Started auxiliary module Human 2025-05-05 11:22:44,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-05 11:22:44,000 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-05 11:22:44,078 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-05 11:22:44,078 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-05 11:22:44,078 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-05 11:22:44,078 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-05 11:22:44,187 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\e1d23b680933e123_w64.exe' with arguments '' and pid 2392 2025-05-05 11:22:44,390 [analyzer] DEBUG: Loaded monitor into process with pid 2392 2025-05-05 11:22:44,953 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 2025-05-05 11:22:45,342 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\System32\alg.exe 2025-05-05 11:22:45,592 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 2025-05-05 11:22:46,000 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 2025-05-05 11:22:46,265 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 2025-05-05 11:22:46,530 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\System32\dllhost.exe 2025-05-05 11:22:46,796 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\ehome\ehrecvr.exe 2025-05-05 11:22:47,092 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\ehome\ehsched.exe 2025-05-05 11:22:47,342 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\System32\FXSSVC.exe 2025-05-05 11:22:47,703 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Windows\System32\ieetwcollector.exe 2025-05-05 11:22:47,921 [analyzer] INFO: Added new file to list with pid 2392 and path C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 2025-05-05 11:22:48,187 [analyzer] INFO: Process with pid 2392 has terminated 2025-05-05 11:22:48,187 [analyzer] INFO: Process list is empty, terminating analysis. 2025-05-05 11:22:49,780 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-05 11:22:49,828 [analyzer] WARNING: File at path u'c:\\windows\\system32\\fxssvc.exe' does not exist, skip. 2025-05-05 11:22:49,842 [analyzer] WARNING: File at path u'c:\\windows\\system32\\ieetwcollector.exe' does not exist, skip. 2025-05-05 11:22:49,937 [analyzer] WARNING: File at path u'c:\\windows\\system32\\alg.exe' does not exist, skip. 2025-05-05 11:22:49,967 [analyzer] INFO: Analysis completed.
2025-05-11 04:05:00,037 [cuckoo.core.scheduler] INFO: Task #6433570: acquired machine win7x6418 (label=win7x6418) 2025-05-11 04:05:00,038 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.218 for task #6433570 2025-05-11 04:05:00,281 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3392127 (interface=vboxnet0, host=192.168.168.218) 2025-05-11 04:05:00,813 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6418 2025-05-11 04:05:01,251 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6418 to vmcloak 2025-05-11 04:08:22,736 [cuckoo.core.guest] INFO: Starting analysis #6433570 on guest (id=win7x6418, ip=192.168.168.218) 2025-05-11 04:08:23,741 [cuckoo.core.guest] DEBUG: win7x6418: not ready yet 2025-05-11 04:08:28,765 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6418, ip=192.168.168.218) 2025-05-11 04:08:28,838 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6418, ip=192.168.168.218, monitor=latest, size=6660546) 2025-05-11 04:08:30,049 [cuckoo.core.resultserver] DEBUG: Task #6433570: live log analysis.log initialized. 2025-05-11 04:08:30,985 [cuckoo.core.resultserver] DEBUG: Task #6433570 is sending a BSON stream 2025-05-11 04:08:31,314 [cuckoo.core.resultserver] DEBUG: Task #6433570 is sending a BSON stream 2025-05-11 04:08:32,241 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'shots/0001.jpg' 2025-05-11 04:08:32,264 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 136368 2025-05-11 04:08:35,427 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'shots/0002.jpg' 2025-05-11 04:08:35,454 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 133486 2025-05-11 04:08:36,522 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'curtain/1746436969.47.curtain.log' 2025-05-11 04:08:36,529 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 36 2025-05-11 04:08:36,829 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'sysmon/1746436969.77.sysmon.xml' 2025-05-11 04:08:36,836 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 680850 2025-05-11 04:08:36,850 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'files/3e7a75056f3d7311_mscorsvw.exe' 2025-05-11 04:08:36,856 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 663552 2025-05-11 04:08:36,869 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'files/e05bddcd3859adf9_maintenanceservice.exe' 2025-05-11 04:08:36,888 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 1296896 2025-05-11 04:08:36,902 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'files/1583626fcd1f597b_flashplayerupdateservice.exe' 2025-05-11 04:08:36,913 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 841216 2025-05-11 04:08:36,932 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'files/c07341b8d5488add_aspnet_state.exe' 2025-05-11 04:08:36,938 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 616448 2025-05-11 04:08:36,950 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'files/8665de76a658da51_ehsched.exe' 2025-05-11 04:08:36,973 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 708096 2025-05-11 04:08:36,978 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'files/f7ad4b09afb301ce_dllhost.exe' 2025-05-11 04:08:36,980 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 7168 2025-05-11 04:08:36,986 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'files/f712b667506c7f92_mscorsvw.exe' 2025-05-11 04:08:36,993 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 640000 2025-05-11 04:08:37,003 [cuckoo.core.resultserver] DEBUG: Task #6433570: File upload for 'files/0e45c8297f9ecb7c_ehrecvr.exe' 2025-05-11 04:08:37,022 [cuckoo.core.resultserver] DEBUG: Task #6433570 uploaded file length: 1276416 2025-05-11 04:08:37,525 [cuckoo.core.resultserver] DEBUG: Task #6433570 had connection reset for <Context for LOG> 2025-05-11 04:08:38,701 [cuckoo.core.guest] INFO: win7x6418: analysis completed successfully 2025-05-11 04:08:38,716 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-11 04:08:38,737 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-11 04:08:39,368 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6418 to path /srv/cuckoo/cwd/storage/analyses/6433570/memory.dmp 2025-05-11 04:08:39,377 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6418 2025-05-11 04:11:09,681 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.218 for task #6433570 2025-05-11 04:11:10,269 [cuckoo.core.scheduler] DEBUG: Released database task #6433570 2025-05-11 04:11:10,286 [cuckoo.core.scheduler] INFO: Task #6433570: analysis procedure completed
description | (no description) | rule | DebuggerException__ConsoleCtrl | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Affect private profile | rule | win_files_operation |