Size | 136.3KB |
---|---|
Type | Zip archive data, at least v2.0 to extract, compression method=deflate |
MD5 | c8d43d264f8e60153ee4f2c4a9786559 |
SHA1 | 1ccd7fa53ae1bf7af80b9b47d2fff002c4d6ef26 |
SHA256 | 8d4f0f6d81029c4dd37983bb263035bdecda4dbb3b79ac8612b3471f1b2e3ca6 |
SHA512 |
c795ed32ba1a45423feb7980eae9a887c2c54891214481d7ba68f3989ad374135ef923fb62e53a51b08f8b5c43caa080cd0ac5e317f8079313d4b9dcecbcd4fa
|
CRC32 | 922B773A |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 16, 2025, 10:45 p.m. | June 16, 2025, 10:46 p.m. | 85 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-16 22:45:16,015 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht 2025-06-16 22:45:16,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ngfSSFPPVacAVLvSOpDOgdRVFNr 2025-06-16 22:45:16,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\YjApEezJsrjMoAXzKiuEZG 2025-06-16 22:45:16,375 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-16 22:45:16,375 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-16 22:45:16,828 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-16 22:45:17,030 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-06-16 22:45:17,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-16 22:45:17,030 [analyzer] DEBUG: Started auxiliary module Human 2025-06-16 22:45:17,046 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-16 22:45:17,046 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-16 22:45:17,171 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-16 22:45:17,171 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-16 22:45:17,171 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-16 22:45:17,187 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-16 22:45:17,342 [lib.api.process] INFO: Successfully executed process from path 'bin/7za.exe' with arguments ['x', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\drbw.zip', '-pinfected'] and pid 2116 2025-06-16 21:46:07,352 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\system32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"KQCGataTQKLTW"', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\hl.bat'] and pid 2652 2025-06-16 21:46:07,696 [analyzer] DEBUG: Loaded monitor into process with pid 2652 2025-06-16 21:46:07,836 [analyzer] INFO: Injected into process with pid 2988 and name u'cmd.exe' 2025-06-16 21:46:07,946 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2988. 2025-06-16 21:46:08,164 [analyzer] DEBUG: Loaded monitor into process with pid 2988 2025-06-16 21:46:08,243 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,243 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,243 [analyzer] CRITICAL: Error creating function stub for advapi32!DeleteService. 2025-06-16 21:46:08,259 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,259 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,259 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,259 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 10 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,259 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,259 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,259 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,259 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,275 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,275 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,275 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,275 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,275 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 7 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,275 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,289 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,289 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,305 [analyzer] CRITICAL: Unable to change memory protection of advapi32!ControlService at 0x09f2f0 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,305 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,305 [analyzer] CRITICAL: Error creating function stub for advapi32!DeleteService. 2025-06-16 21:46:08,305 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,305 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,305 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,305 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceA at 0x09f43e 10 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 5 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 7 to RWX (error code 0xc000004e)! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Conditional jumps in 64-bit are considered unstable! 2025-06-16 21:46:08,321 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceW at 0x09f4cc 6 to RWX (error code 0xc000004e)! 2025-06-16 21:46:36,352 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-16 21:46:36,634 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-16 21:46:36,634 [lib.api.process] INFO: Successfully terminated process with pid 2652. 2025-06-16 21:46:36,634 [lib.api.process] INFO: Successfully terminated process with pid 2988. 2025-06-16 21:46:36,650 [analyzer] INFO: Analysis completed.
2025-06-16 22:45:18,019 [cuckoo.core.scheduler] INFO: Task #6557545: acquired machine win7x641 (label=win7x641) 2025-06-16 22:45:18,020 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #6557545 2025-06-16 22:45:18,260 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2346971 (interface=vboxnet0, host=192.168.168.201) 2025-06-16 22:45:18,266 [cuckoo.common.objects] WARNING: Error extracting package and main activity: File is not a zip file. 2025-06-16 22:45:18,300 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641 2025-06-16 22:45:18,764 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak 2025-06-16 22:45:27,892 [cuckoo.core.guest] INFO: Starting analysis #6557545 on guest (id=win7x641, ip=192.168.168.201) 2025-06-16 22:45:28,898 [cuckoo.core.guest] DEBUG: win7x641: not ready yet 2025-06-16 22:45:33,927 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201) 2025-06-16 22:45:34,005 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546) 2025-06-16 22:45:35,621 [cuckoo.core.resultserver] DEBUG: Task #6557545: live log analysis.log initialized. 2025-06-16 22:45:36,616 [cuckoo.core.resultserver] DEBUG: Task #6557545 is sending a BSON stream 2025-06-16 22:45:37,958 [cuckoo.core.resultserver] DEBUG: Task #6557545: File upload for 'shots/0001.jpg' 2025-06-16 22:45:37,979 [cuckoo.core.resultserver] DEBUG: Task #6557545 uploaded file length: 133508 2025-06-16 22:45:49,974 [cuckoo.core.guest] DEBUG: win7x641: analysis #6557545 still processing 2025-06-16 22:46:05,063 [cuckoo.core.guest] DEBUG: win7x641: analysis #6557545 still processing 2025-06-16 22:46:07,543 [cuckoo.core.resultserver] DEBUG: Task #6557545 is sending a BSON stream 2025-06-16 22:46:08,013 [cuckoo.core.resultserver] DEBUG: Task #6557545 is sending a BSON stream 2025-06-16 22:46:08,083 [cuckoo.core.resultserver] DEBUG: Task #6557545: File upload for 'shots/0002.jpg' 2025-06-16 22:46:08,111 [cuckoo.core.resultserver] DEBUG: Task #6557545 uploaded file length: 115243 2025-06-16 22:46:09,217 [cuckoo.core.resultserver] DEBUG: Task #6557545: File upload for 'shots/0003.jpg' 2025-06-16 22:46:09,357 [cuckoo.core.resultserver] DEBUG: Task #6557545 uploaded file length: 118340 2025-06-16 22:46:20,173 [cuckoo.core.guest] DEBUG: win7x641: analysis #6557545 still processing 2025-06-16 22:46:35,244 [cuckoo.core.guest] INFO: win7x641: end of analysis reached! 2025-06-16 22:46:35,271 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-16 22:46:35,301 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-16 22:46:36,028 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/6557545/memory.dmp 2025-06-16 22:46:36,029 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641 2025-06-16 22:46:36,569 [cuckoo.core.resultserver] DEBUG: Task #6557545: File upload for 'curtain/1750103196.49.curtain.log' 2025-06-16 22:46:36,573 [cuckoo.core.resultserver] DEBUG: Task #6557545 uploaded file length: 36 2025-06-16 22:46:36,635 [cuckoo.core.resultserver] DEBUG: Task #6557545: File upload for 'sysmon/1750103196.62.sysmon.xml' 2025-06-16 22:46:36,642 [cuckoo.core.resultserver] DEBUG: Task #6557545 uploaded file length: 279422 2025-06-16 22:46:43,224 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #6557545 2025-06-16 22:46:43,225 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6557545 2025-06-16 22:46:43,526 [cuckoo.core.scheduler] DEBUG: Released database task #6557545 2025-06-16 22:46:43,546 [cuckoo.core.scheduler] INFO: Task #6557545: analysis procedure completed