Size | 390.2KB |
---|---|
Type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
MD5 | fe733a5a5fd798da95d860a500efaf29 |
SHA1 | 4ada519d9742769984fe46b6a510e323b5e51d08 |
SHA256 | 310bfc37fbb8f2b76ad1708612bc0280222de30a1cd0114614404d69ccbf704e |
SHA512 |
56d7655e614a70ae23069fd2f73949b0ff6a85d0c03f72da842d7b2b942eea77df71e39e94b1a6642b6543bc92e1cf670432e46562cfbbff8316989da49b1cc1
|
CRC32 | E91CD678 |
ssdeep | None |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 18, 2025, 6:18 a.m. | June 18, 2025, 6:24 a.m. | 397 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-18 06:13:37,015 [analyzer] DEBUG: Starting analyzer from: C:\tmppw5mq4 2025-06-18 06:13:37,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\foqsBIbZtTdvAhonpXmqVyyd 2025-06-18 06:13:37,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\CBdLWWaBTYIjOzPUmGotnOyPLA 2025-06-18 06:13:37,358 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-18 06:13:37,358 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-18 06:13:37,967 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-18 06:13:38,187 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-06-18 06:13:38,187 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-18 06:13:38,187 [analyzer] DEBUG: Started auxiliary module Human 2025-06-18 06:13:38,187 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-18 06:13:38,187 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-18 06:13:38,296 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-18 06:13:38,296 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-18 06:13:38,296 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-18 06:13:38,312 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-18 06:13:38,390 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\rundll32.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\WxWorkApis.dll,DllMain'] and pid 2740 2025-06-18 06:13:38,608 [analyzer] DEBUG: Loaded monitor into process with pid 2740 2025-06-18 06:13:38,765 [analyzer] INFO: Injected into process with pid 1464 and name u'rundll32.exe' 2025-06-18 06:13:39,000 [analyzer] DEBUG: Loaded monitor into process with pid 1464 2025-06-18 05:21:34,862 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-18 05:21:35,394 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-18 05:21:35,394 [lib.api.process] INFO: Successfully terminated process with pid 2740. 2025-06-18 05:21:35,410 [lib.api.process] INFO: Successfully terminated process with pid 1464. 2025-06-18 05:21:35,410 [analyzer] INFO: Analysis completed.
2025-06-18 06:18:13,725 [cuckoo.core.scheduler] DEBUG: Task #6559715: no machine available yet 2025-06-18 06:18:15,340 [cuckoo.core.scheduler] DEBUG: Task #6559715: no machine available yet 2025-06-18 06:18:17,613 [cuckoo.core.scheduler] DEBUG: Task #6559715: no machine available yet 2025-06-18 06:18:19,067 [cuckoo.core.scheduler] DEBUG: Task #6559715: no machine available yet 2025-06-18 06:18:20,147 [cuckoo.core.scheduler] DEBUG: Task #6559715: no machine available yet 2025-06-18 06:18:21,241 [cuckoo.core.scheduler] DEBUG: Task #6559715: no machine available yet 2025-06-18 06:18:22,330 [cuckoo.core.scheduler] INFO: Task #6559715: acquired machine win7x646 (label=win7x646) 2025-06-18 06:18:22,340 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.206 for task #6559715 2025-06-18 06:18:23,049 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3603407 (interface=vboxnet0, host=192.168.168.206) 2025-06-18 06:18:26,577 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x646 2025-06-18 06:18:34,990 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x646 to vmcloak 2025-06-18 06:20:56,749 [cuckoo.core.guest] INFO: Starting analysis #6559715 on guest (id=win7x646, ip=192.168.168.206) 2025-06-18 06:20:57,789 [cuckoo.core.guest] DEBUG: win7x646: not ready yet 2025-06-18 06:21:02,821 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x646, ip=192.168.168.206) 2025-06-18 06:21:02,979 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x646, ip=192.168.168.206, monitor=latest, size=6660546) 2025-06-18 06:21:05,930 [cuckoo.core.resultserver] DEBUG: Task #6559715: live log analysis.log initialized. 2025-06-18 06:21:05,932 [cuckoo.core.resultserver] DEBUG: Task #6559715 is sending a BSON stream 2025-06-18 06:21:05,933 [cuckoo.core.resultserver] DEBUG: Task #6559715 is sending a BSON stream 2025-06-18 06:21:06,349 [cuckoo.core.resultserver] DEBUG: Task #6559715 is sending a BSON stream 2025-06-18 06:21:07,083 [cuckoo.core.resultserver] DEBUG: Task #6559715: File upload for 'shots/0001.jpg' 2025-06-18 06:21:07,094 [cuckoo.core.resultserver] DEBUG: Task #6559715 uploaded file length: 137889 2025-06-18 06:21:20,861 [cuckoo.core.guest] DEBUG: win7x646: analysis #6559715 still processing 2025-06-18 06:21:35,358 [cuckoo.core.resultserver] DEBUG: Task #6559715: File upload for 'curtain/1750216895.1.curtain.log' 2025-06-18 06:21:35,362 [cuckoo.core.resultserver] DEBUG: Task #6559715 uploaded file length: 36 2025-06-18 06:21:35,376 [cuckoo.core.resultserver] DEBUG: Task #6559715: File upload for 'sysmon/1750216895.36.sysmon.xml' 2025-06-18 06:21:35,406 [cuckoo.core.resultserver] DEBUG: Task #6559715 uploaded file length: 1688078 2025-06-18 06:21:35,959 [cuckoo.core.guest] INFO: win7x646: analysis completed successfully 2025-06-18 06:21:35,973 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-18 06:21:36,003 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-18 06:21:36,345 [cuckoo.core.resultserver] DEBUG: Task #6559715: File upload for 'shots/0002.jpg' 2025-06-18 06:21:36,353 [cuckoo.core.resultserver] DEBUG: Task #6559715 uploaded file length: 133469 2025-06-18 06:21:36,372 [cuckoo.core.resultserver] DEBUG: Task #6559715 had connection reset for <Context for LOG> 2025-06-18 06:21:37,355 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x646 to path /srv/cuckoo/cwd/storage/analyses/6559715/memory.dmp 2025-06-18 06:21:37,356 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x646 2025-06-18 06:24:37,603 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.206 for task #6559715 2025-06-18 06:24:37,995 [cuckoo.core.scheduler] DEBUG: Released database task #6559715 2025-06-18 06:24:38,011 [cuckoo.core.scheduler] INFO: Task #6559715: analysis procedure completed
description | The packer/protector section names/keywords | rule | suspicious_packer_section |
section | .vmp0 |
section | .vmp1 |
section | {u'size_of_data': u'0x006ee000', u'virtual_address': u'0x006e1000', u'entropy': 7.901884832446314, u'name': u'.vmp1', u'virtual_size': u'0x006edf80'} | entropy | 7.90188483245 | description | A section with a high entropy has been found | |||||||||
entropy | 0.999718230487 | description | Overall entropy of this PE file is high |
section | .vmp0 | description | Section name indicates VMProtect | ||||||
section | .vmp1 | description | Section name indicates VMProtect |
DrWeb Antivirus (Linux) | Trojan.Packed2.46866 |