Size | 6.8KB |
---|---|
Type | Unicode text, UTF-8 text, with very long lines (640), with CRLF line terminators |
MD5 | 09153f9e9d1ac71dc7a310ff619165f7 |
SHA1 | 2065042a7f671006b7dd6e9b70f351b4cb6adfaf |
SHA256 | 4b66cf48bcb8c6036303bcd90597d6dc423209aca96ec1bcee621bfffc886ca8 |
SHA512 |
16dfc47674c407d10e4a801894b451326daced392c48f9fd67f0f104457ad15c156d94e7e745b6675648c4c2c0e6564cc02d3eb8b15c4f3b4f8629b17cc4f215
|
CRC32 | AAAECCF8 |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 14, 2025, 12:10 a.m. | May 14, 2025, 12:15 a.m. | 321 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-06 05:10:14,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp2pjrvv 2025-05-06 05:10:14,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\EpgYIvYKSoWPVtNSbInztLzUNwPUwffW 2025-05-06 05:10:14,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\uNPQMMrWqLrLWwGXBTzJa 2025-05-06 05:10:14,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-05-06 05:10:14,046 [analyzer] INFO: Automatically selected analysis package "generic" 2025-05-06 05:10:14,375 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-06 05:10:14,390 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-06 05:10:14,796 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-06 05:10:15,000 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-05-06 05:10:15,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-06 05:10:15,000 [analyzer] DEBUG: Started auxiliary module Human 2025-05-06 05:10:15,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-06 05:10:15,000 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-06 05:10:15,108 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-06 05:10:15,108 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-06 05:10:15,108 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-06 05:10:15,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-06 05:10:15,203 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"PrLvLvm"', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\KnVzAxrz.mp4'] and pid 2212 2025-05-06 05:10:15,483 [analyzer] DEBUG: Loaded monitor into process with pid 2212 2025-05-06 05:10:15,875 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 05:10:15,921 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:15,937 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:15,937 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:15,937 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 05:10:15,953 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:15,953 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:15,967 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:15,967 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,000 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,000 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 05:10:16,030 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 05:10:16,030 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,030 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,046 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,046 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 05:10:16,046 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,046 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,046 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,046 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,046 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,062 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 05:10:16,530 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 05:10:16,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,546 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,546 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 05:10:16,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,562 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,578 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,578 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 05:10:16,703 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 05:10:16,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,703 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,717 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 05:10:16,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,717 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,733 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:16,733 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 05:10:22,265 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 05:10:22,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,280 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 05:10:22,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,296 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,296 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,296 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,296 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,312 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 05:10:22,608 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 05:10:22,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,625 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 05:10:22,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 05:10:22,640 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 05:10:26,220 [analyzer] INFO: Process with pid 2212 has terminated 2025-05-06 05:10:26,220 [analyzer] INFO: Process list is empty, terminating analysis. 2025-05-06 05:10:27,602 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-06 05:10:27,602 [analyzer] INFO: Analysis completed.
2025-05-14 00:10:19,289 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:20,317 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:21,335 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:22,357 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:23,382 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:24,424 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:25,445 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:26,622 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:27,642 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:28,663 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:29,811 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:30,854 [cuckoo.core.scheduler] DEBUG: Task #6454302: no machine available yet 2025-05-14 00:10:31,888 [cuckoo.core.scheduler] INFO: Task #6454302: acquired machine win7x648 (label=win7x648) 2025-05-14 00:10:31,889 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.208 for task #6454302 2025-05-14 00:10:32,171 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1320992 (interface=vboxnet0, host=192.168.168.208) 2025-05-14 00:10:32,233 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x648 2025-05-14 00:10:32,791 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x648 to vmcloak 2025-05-14 00:12:53,631 [cuckoo.core.guest] INFO: Starting analysis #6454302 on guest (id=win7x648, ip=192.168.168.208) 2025-05-14 00:12:54,641 [cuckoo.core.guest] DEBUG: win7x648: not ready yet 2025-05-14 00:12:59,717 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x648, ip=192.168.168.208) 2025-05-14 00:12:59,882 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x648, ip=192.168.168.208, monitor=latest, size=6660546) 2025-05-14 00:13:01,570 [cuckoo.core.resultserver] DEBUG: Task #6454302: live log analysis.log initialized. 2025-05-14 00:13:02,516 [cuckoo.core.resultserver] DEBUG: Task #6454302 is sending a BSON stream 2025-05-14 00:13:02,913 [cuckoo.core.resultserver] DEBUG: Task #6454302 is sending a BSON stream 2025-05-14 00:13:03,814 [cuckoo.core.resultserver] DEBUG: Task #6454302: File upload for 'shots/0001.jpg' 2025-05-14 00:13:03,843 [cuckoo.core.resultserver] DEBUG: Task #6454302 uploaded file length: 110708 2025-05-14 00:13:14,196 [cuckoo.core.resultserver] DEBUG: Task #6454302: File upload for 'shots/0002.jpg' 2025-05-14 00:13:14,216 [cuckoo.core.resultserver] DEBUG: Task #6454302 uploaded file length: 134121 2025-05-14 00:13:15,010 [cuckoo.core.resultserver] DEBUG: Task #6454302: File upload for 'curtain/1746501027.43.curtain.log' 2025-05-14 00:13:15,013 [cuckoo.core.resultserver] DEBUG: Task #6454302 uploaded file length: 36 2025-05-14 00:13:15,175 [cuckoo.core.resultserver] DEBUG: Task #6454302: File upload for 'sysmon/1746501027.6.sysmon.xml' 2025-05-14 00:13:15,195 [cuckoo.core.resultserver] DEBUG: Task #6454302 uploaded file length: 976818 2025-05-14 00:13:15,256 [cuckoo.core.resultserver] DEBUG: Task #6454302 had connection reset for <Context for LOG> 2025-05-14 00:13:16,187 [cuckoo.core.guest] INFO: win7x648: analysis completed successfully 2025-05-14 00:13:16,198 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-14 00:13:16,219 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-14 00:13:16,935 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x648 to path /srv/cuckoo/cwd/storage/analyses/6454302/memory.dmp 2025-05-14 00:13:16,959 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x648 2025-05-14 00:15:38,434 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.208 for task #6454302 2025-05-14 00:15:40,146 [cuckoo.core.scheduler] DEBUG: Released database task #6454302 2025-05-14 00:15:40,170 [cuckoo.core.scheduler] INFO: Task #6454302: analysis procedure completed
No signatures