Size | 1.4MB |
---|---|
Type | PE32 executable (console) Intel 80386, for MS Windows |
MD5 | bb1e4329368a37fd0fb86fc49c4c520b |
SHA1 | e3df7c1dd8adf32fd90c5b163d05987be5dc35ea |
SHA256 | 8af5959bd5f30ebee1d97726efcca5dca55a4d5f2c47e1b8c2bd498ac54d901d |
SHA512 |
09c6fc42829a813a075ecb7877ae20810b09ec8e5104b5e0a70fadf4d6aac3c1dbcb8658d741ed9940ecbdfd6de1940be098cea21f6299b247fd5f7c25596ac9
|
CRC32 | F48478F3 |
ssdeep | None |
PDB Path | PerfHost.pdb |
Yara | None matched |
This file is very suspicious, with a score of 9.4 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 11, 2025, 4:22 a.m. | May 11, 2025, 4:28 a.m. | 350 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-05 12:11:15,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpwoh6zt 2025-05-05 12:11:15,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\PiGUNQxDvALtcqaF 2025-05-05 12:11:15,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\wYdEmGcqteDLjbBOAABvElNQYBhDurYx 2025-05-05 12:11:15,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-05-05 12:11:15,046 [analyzer] INFO: Automatically selected analysis package "exe" 2025-05-05 12:11:15,530 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-05 12:11:15,530 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-05 12:11:16,967 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-05 12:11:17,187 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-05-05 12:11:17,187 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-05 12:11:17,187 [analyzer] DEBUG: Started auxiliary module Human 2025-05-05 12:11:17,187 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-05 12:11:17,187 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-05 12:11:17,296 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-05 12:11:17,296 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-05 12:11:17,296 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-05 12:11:17,296 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-05 12:11:17,578 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\8af5959bd5f30ebe_perfhost.exe' with arguments '' and pid 636 2025-05-05 12:11:17,812 [analyzer] DEBUG: Loaded monitor into process with pid 636 2025-05-05 12:11:18,578 [analyzer] INFO: Process with pid 636 has terminated 2025-05-05 12:11:18,578 [analyzer] INFO: Process list is empty, terminating analysis. 2025-05-05 12:11:19,796 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-05 12:11:19,796 [analyzer] INFO: Analysis completed.
2025-05-11 04:22:59,912 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:00,933 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:01,953 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:02,972 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:03,991 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:05,032 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:06,052 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:07,071 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:08,088 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:09,105 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:10,131 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:11,161 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:12,193 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:13,216 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:14,244 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:15,277 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:16,307 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:17,333 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:18,356 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:19,381 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:20,406 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:21,534 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:22,576 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:23,623 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:24,668 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:25,712 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:26,758 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:27,829 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:29,152 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:30,207 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:31,273 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:32,317 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:33,350 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:34,380 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:35,411 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:36,443 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:37,469 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:38,497 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:39,537 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:40,574 [cuckoo.core.scheduler] DEBUG: Task #6433788: no machine available yet 2025-05-11 04:23:41,724 [cuckoo.core.scheduler] INFO: Task #6433788: acquired machine win7x643 (label=win7x643) 2025-05-11 04:23:41,727 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.203 for task #6433788 2025-05-11 04:23:41,963 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3413582 (interface=vboxnet0, host=192.168.168.203) 2025-05-11 04:23:45,865 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x643 2025-05-11 04:23:46,490 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x643 to vmcloak 2025-05-11 04:26:12,223 [cuckoo.core.guest] INFO: Starting analysis #6433788 on guest (id=win7x643, ip=192.168.168.203) 2025-05-11 04:26:13,231 [cuckoo.core.guest] DEBUG: win7x643: not ready yet 2025-05-11 04:26:18,326 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x643, ip=192.168.168.203) 2025-05-11 04:26:18,590 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x643, ip=192.168.168.203, monitor=latest, size=6660546) 2025-05-11 04:26:21,046 [cuckoo.core.resultserver] DEBUG: Task #6433788: live log analysis.log initialized. 2025-05-11 04:26:23,206 [cuckoo.core.resultserver] DEBUG: Task #6433788 is sending a BSON stream 2025-05-11 04:26:23,809 [cuckoo.core.resultserver] DEBUG: Task #6433788 is sending a BSON stream 2025-05-11 04:26:24,533 [cuckoo.core.resultserver] DEBUG: Task #6433788: File upload for 'shots/0001.jpg' 2025-05-11 04:26:24,581 [cuckoo.core.resultserver] DEBUG: Task #6433788 uploaded file length: 133472 2025-05-11 04:26:25,717 [cuckoo.core.resultserver] DEBUG: Task #6433788: File upload for 'curtain/1746439879.64.curtain.log' 2025-05-11 04:26:25,746 [cuckoo.core.resultserver] DEBUG: Task #6433788 uploaded file length: 36 2025-05-11 04:26:25,889 [cuckoo.core.resultserver] DEBUG: Task #6433788: File upload for 'sysmon/1746439879.78.sysmon.xml' 2025-05-11 04:26:25,937 [cuckoo.core.resultserver] DEBUG: Task #6433788 uploaded file length: 354892 2025-05-11 04:26:26,202 [cuckoo.core.guest] INFO: win7x643: analysis completed successfully 2025-05-11 04:26:26,239 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-11 04:26:26,284 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-11 04:26:26,739 [cuckoo.core.resultserver] DEBUG: Task #6433788 had connection reset for <Context for LOG> 2025-05-11 04:26:27,005 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x643 to path /srv/cuckoo/cwd/storage/analyses/6433788/memory.dmp 2025-05-11 04:26:27,035 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x643 2025-05-11 04:28:49,543 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.203 for task #6433788 2025-05-11 04:28:50,194 [cuckoo.core.scheduler] DEBUG: Released database task #6433788 2025-05-11 04:28:50,230 [cuckoo.core.scheduler] INFO: Task #6433788: analysis procedure completed