Size | 68.3KB |
---|---|
Type | data |
MD5 | 60187112ed624571c5338b91ede7a560 |
SHA1 | 4810561bacc819e0c400ce1190bd99dd0561dc0e |
SHA256 | fefcc39b007faf2c3badcd72c0433a2ffe0f84eac0e980be5275b998adefd834 |
SHA512 |
6cf7931b3ca78e1abb777d624cc837cd4f3fcbacdee39728a72afc23618deaeadc3be7767c2b7f91bfeef0d84a89f3b4bcf2d91bdb308006549c95021949ad52
|
CRC32 | C946FA8C |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 24, 2025, 8:28 a.m. | May 24, 2025, 8:28 a.m. | 31 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-24 08:28:15,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp2zg5xi 2025-05-24 08:28:15,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\sUiGbPLGZYBZmkCtvdTFLswLBlpXW 2025-05-24 08:28:15,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\ufoPREFTeGWwkGkLbACVEDQNaAhHNFSc 2025-05-24 08:28:15,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-05-24 08:28:15,046 [analyzer] INFO: Automatically selected analysis package "generic" 2025-05-24 08:28:15,421 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-24 08:28:15,437 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-24 08:28:15,828 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-24 08:28:16,046 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-05-24 08:28:16,046 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-24 08:28:16,046 [analyzer] DEBUG: Started auxiliary module Human 2025-05-24 08:28:16,046 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-24 08:28:16,046 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-24 08:28:16,140 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-24 08:28:16,140 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-24 08:28:16,140 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-24 08:28:16,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-24 08:28:16,265 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"mQeABKzFe"', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\02.08.2022.exe'] and pid 896 2025-05-24 08:28:16,578 [analyzer] DEBUG: Loaded monitor into process with pid 896 2025-05-24 08:28:16,655 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-24 08:28:16,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,671 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-24 08:28:16,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,687 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,750 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-24 08:28:16,780 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-24 08:28:17,280 [analyzer] INFO: Process with pid 896 has terminated 2025-05-24 08:28:17,296 [analyzer] INFO: Process list is empty, terminating analysis. 2025-05-24 08:28:18,515 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-24 08:28:18,515 [analyzer] INFO: Analysis completed.
2025-05-24 08:28:22,652 [cuckoo.core.scheduler] INFO: Task #6512465: acquired machine win7x6410 (label=win7x6410) 2025-05-24 08:28:22,653 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.210 for task #6512465 2025-05-24 08:28:22,954 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2905718 (interface=vboxnet0, host=192.168.168.210) 2025-05-24 08:28:22,986 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6410 2025-05-24 08:28:23,676 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6410 to vmcloak 2025-05-24 08:28:32,423 [cuckoo.core.guest] INFO: Starting analysis #6512465 on guest (id=win7x6410, ip=192.168.168.210) 2025-05-24 08:28:33,428 [cuckoo.core.guest] DEBUG: win7x6410: not ready yet 2025-05-24 08:28:38,456 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6410, ip=192.168.168.210) 2025-05-24 08:28:38,527 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6410, ip=192.168.168.210, monitor=latest, size=6660546) 2025-05-24 08:28:39,922 [cuckoo.core.resultserver] DEBUG: Task #6512465: live log analysis.log initialized. 2025-05-24 08:28:40,917 [cuckoo.core.resultserver] DEBUG: Task #6512465 is sending a BSON stream 2025-05-24 08:28:41,339 [cuckoo.core.resultserver] DEBUG: Task #6512465 is sending a BSON stream 2025-05-24 08:28:42,232 [cuckoo.core.resultserver] DEBUG: Task #6512465: File upload for 'shots/0001.jpg' 2025-05-24 08:28:42,244 [cuckoo.core.resultserver] DEBUG: Task #6512465 uploaded file length: 133470 2025-05-24 08:28:43,335 [cuckoo.core.resultserver] DEBUG: Task #6512465: File upload for 'curtain/1748068098.39.curtain.log' 2025-05-24 08:28:43,340 [cuckoo.core.resultserver] DEBUG: Task #6512465 uploaded file length: 36 2025-05-24 08:28:43,453 [cuckoo.core.resultserver] DEBUG: Task #6512465: File upload for 'sysmon/1748068098.52.sysmon.xml' 2025-05-24 08:28:43,457 [cuckoo.core.resultserver] DEBUG: Task #6512465 uploaded file length: 55098 2025-05-24 08:28:44,330 [cuckoo.core.resultserver] DEBUG: Task #6512465 had connection reset for <Context for LOG> 2025-05-24 08:28:45,451 [cuckoo.core.guest] INFO: win7x6410: analysis completed successfully 2025-05-24 08:28:45,465 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-24 08:28:45,495 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-24 08:28:46,440 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6410 to path /srv/cuckoo/cwd/storage/analyses/6512465/memory.dmp 2025-05-24 08:28:46,442 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6410 2025-05-24 08:28:53,822 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.210 for task #6512465 2025-05-24 08:28:54,095 [cuckoo.core.scheduler] DEBUG: Released database task #6512465 2025-05-24 08:28:54,141 [cuckoo.core.scheduler] INFO: Task #6512465: analysis procedure completed
Trend Micro SProtect (Linux) | Trojan.Win32.COBALT.SMD.hp |
Sophos Anti-Virus (Linux) | ATK/Cobalt-D |
DrWeb Antivirus (Linux) | BackDoor.Meterpreter.152 |
Kaspersky Standard (Windows) | HEUR:Trojan.Win64.CobaltStrike.gen |