Size | 361.0KB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 6f21790019ea95424659bb128810be12 |
SHA1 | 83308af5de614e9ec93e868c5ca9b490150cfe7e |
SHA256 | 5351201eb16a57ef515637da802759d9c78cf563e6d788731e106e80bd3c0d27 |
SHA512 |
b02061e9b370b71edef845f1ed106a1dce3ba0ce76484c92283acb7420b412a634566d3a42e8636283200a641de22998d68ace939f6093a571b7b4def238c561
|
CRC32 | 3C837632 |
ssdeep | None |
PDB Path | f:\软件工ç¨\驱å¨ç¼ç¨\OK\KernelYK\bin\InstallSYS.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 22, 2025, 1:52 a.m. | June 22, 2025, 1:59 a.m. | 435 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-20 18:40:37,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd 2025-06-20 18:40:37,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\NiHCzOKNuhHPYlxs 2025-06-20 18:40:37,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\jykvJuUPaZFcTzaKdGkjONuGsykZ 2025-06-20 18:40:37,358 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-20 18:40:37,358 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-20 18:40:38,030 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-20 18:40:38,250 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-06-20 18:40:38,250 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-20 18:40:38,250 [analyzer] DEBUG: Started auxiliary module Human 2025-06-20 18:40:38,250 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-20 18:40:38,250 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-20 18:40:38,375 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-20 18:40:38,375 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-20 18:40:38,390 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-20 18:40:38,390 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-20 18:40:38,515 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\5351201eb16a57ef515637da802759d9c78cf563e6d788731e106e80bd3c0d27.exe' with arguments '' and pid 2252 2025-06-20 18:40:38,750 [analyzer] DEBUG: Loaded monitor into process with pid 2252 2025-06-20 18:40:39,280 [analyzer] INFO: Added new file to list with pid 2252 and path C:\Temp\CreateProcess.exe 2025-06-20 18:40:40,280 [analyzer] INFO: Added new file to list with pid 2252 and path C:\Temp\wuomhezwrpjhbzur.exe 2025-06-20 18:40:40,375 [analyzer] INFO: Injected into process with pid 1924 and name u'wuomhezwrpjhbzur.exe' 2025-06-20 18:40:40,500 [analyzer] INFO: Injected into process with pid 2696 and name u'iexplore.exe' 2025-06-20 18:40:40,530 [analyzer] DEBUG: Loaded monitor into process with pid 1924 2025-06-20 18:40:40,578 [analyzer] INFO: Added new file to list with pid 1924 and path \Device\NamedPipe\lsass 2025-06-20 18:40:40,733 [analyzer] DEBUG: Loaded monitor into process with pid 2696 2025-06-20 18:40:42,500 [analyzer] INFO: Added new file to list with pid 2252 and path C:\Temp\wuomhezwrpjhbzur.sys 2025-06-20 18:40:43,233 [analyzer] INFO: Added new file to list with pid 1924 and path C:\Temp\aqkicausnk.exe 2025-06-20 18:40:43,296 [analyzer] INFO: Injected into process with pid 3056 and name u'CreateProcess.exe' 2025-06-20 18:40:43,453 [analyzer] DEBUG: Loaded monitor into process with pid 3056 2025-06-20 18:40:43,515 [analyzer] INFO: Process with pid 2252 has terminated 2025-06-20 18:40:44,515 [analyzer] INFO: Process with pid 3056 has terminated 2025-06-20 18:40:45,812 [analyzer] INFO: Added new file to list with pid 1924 and path C:\Temp\i_aqkicausnk.exe 2025-06-20 18:40:51,187 [analyzer] INFO: Added new file to list with pid 1924 and path C:\Temp\pnhfzxspki.exe 2025-06-20 18:41:07,515 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-20 18:41:08,000 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-20 18:41:08,000 [lib.api.process] INFO: Successfully terminated process with pid 1924. 2025-06-20 18:41:08,000 [lib.api.process] INFO: Successfully terminated process with pid 2696. 2025-06-20 18:41:08,000 [analyzer] WARNING: File at path u'\\device\\namedpipe\\lsass' does not exist, skip. 2025-06-20 18:41:08,046 [analyzer] INFO: Analysis completed.
2025-06-22 01:52:25,967 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:26,991 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:28,037 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:29,454 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:30,535 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:31,946 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:33,323 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:34,666 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:35,777 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:36,885 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:37,969 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:39,316 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:41,002 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:42,503 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:43,569 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:44,606 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:45,650 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:46,695 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:47,762 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:48,804 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:49,845 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:50,889 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:51,929 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:52,977 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:54,026 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:55,066 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:56,101 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:57,381 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:58,425 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:52:59,451 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:00,486 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:01,508 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:02,908 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:04,749 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:05,785 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:06,816 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:07,843 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:08,870 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:09,908 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:10,933 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:12,170 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:13,228 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:14,634 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:15,931 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:17,873 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:18,894 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:19,910 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:20,934 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:21,957 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:23,056 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:24,409 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:25,467 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:26,827 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:27,914 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:29,058 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:30,118 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:31,164 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:32,205 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:33,251 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:34,294 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:35,540 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:36,678 [cuckoo.core.scheduler] DEBUG: Task #6574125: no machine available yet 2025-06-22 01:53:37,992 [cuckoo.core.scheduler] INFO: Task #6574125: acquired machine win7x6412 (label=win7x6412) 2025-06-22 01:53:37,992 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.212 for task #6574125 2025-06-22 01:53:38,738 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1575140 (interface=vboxnet0, host=192.168.168.212) 2025-06-22 01:53:41,495 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6412 2025-06-22 01:53:42,490 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6412 to vmcloak 2025-06-22 01:56:27,897 [cuckoo.core.guest] INFO: Starting analysis #6574125 on guest (id=win7x6412, ip=192.168.168.212) 2025-06-22 01:56:28,904 [cuckoo.core.guest] DEBUG: win7x6412: not ready yet 2025-06-22 01:56:33,930 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6412, ip=192.168.168.212) 2025-06-22 01:56:34,010 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6412, ip=192.168.168.212, monitor=latest, size=6660546) 2025-06-22 01:56:35,439 [cuckoo.core.resultserver] DEBUG: Task #6574125: live log analysis.log initialized. 2025-06-22 01:56:36,632 [cuckoo.core.resultserver] DEBUG: Task #6574125 is sending a BSON stream 2025-06-22 01:56:37,298 [cuckoo.core.resultserver] DEBUG: Task #6574125 is sending a BSON stream 2025-06-22 01:56:37,958 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'shots/0001.jpg' 2025-06-22 01:56:37,988 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 133468 2025-06-22 01:56:38,893 [cuckoo.core.resultserver] DEBUG: Task #6574125 is sending a BSON stream 2025-06-22 01:56:39,035 [cuckoo.core.resultserver] DEBUG: Task #6574125 is sending a BSON stream 2025-06-22 01:56:41,854 [cuckoo.core.resultserver] DEBUG: Task #6574125 is sending a BSON stream 2025-06-22 01:56:42,270 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'files/8a6309173bdf0748_aqkicausnk.exe' 2025-06-22 01:56:42,316 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 369664 2025-06-22 01:56:47,019 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'files/dfba1aa1603aafc8_i_aqkicausnk.exe' 2025-06-22 01:56:47,029 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 369664 2025-06-22 01:56:50,468 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6574125 still processing 2025-06-22 01:57:05,903 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6574125 still processing 2025-06-22 01:57:06,162 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'curtain/1750437667.7.curtain.log' 2025-06-22 01:57:06,166 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 36 2025-06-22 01:57:06,429 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'sysmon/1750437667.97.sysmon.xml' 2025-06-22 01:57:06,460 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 1806494 2025-06-22 01:57:06,476 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'files/2b3ced484d8b6701_wuomhezwrpjhbzur.sys' 2025-06-22 01:57:06,481 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 300544 2025-06-22 01:57:06,488 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'files/8d6f04157f31ad86_wuomhezwrpjhbzur.exe' 2025-06-22 01:57:06,502 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'files/3cd1a3ed53b832a3_createprocess.exe' 2025-06-22 01:57:06,505 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 3584 2025-06-22 01:57:06,507 [cuckoo.core.resultserver] DEBUG: Task #6574125: File upload for 'files/3053dc3635dd2e63_pnhfzxspki.exe' 2025-06-22 01:57:06,516 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 369664 2025-06-22 01:57:06,521 [cuckoo.core.resultserver] DEBUG: Task #6574125 uploaded file length: 369664 2025-06-22 01:57:06,885 [cuckoo.core.resultserver] DEBUG: Task #6574125 had connection reset for <Context for LOG> 2025-06-22 01:57:08,917 [cuckoo.core.guest] INFO: win7x6412: analysis completed successfully 2025-06-22 01:57:08,934 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-22 01:57:08,966 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-22 01:57:10,692 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6412 to path /srv/cuckoo/cwd/storage/analyses/6574125/memory.dmp 2025-06-22 01:57:10,694 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6412 2025-06-22 01:59:32,269 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.212 for task #6574125 2025-06-22 01:59:34,662 [cuckoo.core.scheduler] DEBUG: Released database task #6574125 2025-06-22 01:59:34,690 [cuckoo.core.scheduler] INFO: Task #6574125: analysis procedure completed
description | Possibly employs anti-virtualization techniques | rule | vmdetect | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | inject_thread | ||||||
description | Create a windows service | rule | create_service | ||||||
description | Communications over HTTP | rule | network_http | ||||||
description | File downloader/dropper | rule | network_dropper | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Escalade priviledges | rule | escalate_priv | ||||||
description | Take screenshot | rule | screenshot | ||||||
description | Run a keylogger | rule | keylogger |
pdb_path | f:\软件工ç¨\驱å¨ç¼ç¨\OK\KernelYK\bin\InstallSYS.pdb |
name | RT_ICON | language | LANG_CHINESE | filetype | Device independent bitmap graphic, 13 x 26 x 8, image size 208, 256 important colors | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005bec0 | size | 0x0000052c | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | Device independent bitmap graphic, 13 x 26 x 8, image size 208, 256 important colors | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005bec0 | size | 0x0000052c | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | Device independent bitmap graphic, 13 x 26 x 8, image size 208, 256 important colors | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005bec0 | size | 0x0000052c | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | Device independent bitmap graphic, 13 x 26 x 8, image size 208, 256 important colors | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005bec0 | size | 0x0000052c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005c3ec | size | 0x00000094 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005c480 | size | 0x0000003e | ||||||||||||||||||
name | RT_VERSION | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005c4c0 | size | 0x000002cc |
file | C:\Temp\i_aqkicausnk.exe |
file | C:\Temp\pnhfzxspki.exe |
file | C:\Temp\aqkicausnk.exe |
file | C:\Temp\wuomhezwrpjhbzur.exe |
file | C:\Temp\CreateProcess.exe |
cmdline | C:\Program Files\Internet Explorer\iexplore.exe http://xytets.com:2345/t.asp?os=home |
G Data Antivirus (Windows) | Virus: Trojan.Generic.7761207 (Engine A), Win32.Trojan.PSE1.YSVY3N (Engine B) |
Avast Core Security (Linux) | MBR:Backboot-D [Rtk] |
C4S ClamAV (Linux) | Win.Malware.Mikey-9949492-0 |
Trellix (Linux) | Generic Dropper.aoe trojan |
WithSecure (Linux) | Trojan.TR/Rogue.7909438 |
eScan Antivirus (Linux) | Trojan.Generic.7761207(DB) |
ESET Security (Windows) | Win32/Agent.PGA trojan |
Sophos Anti-Virus (Linux) | Troj/Drop-GZ |
DrWeb Antivirus (Linux) | Trojan.Click2.32800 |
ClamAV (Linux) | Win.Malware.Mikey-9949492-0 |
Bitdefender Antivirus (Linux) | Trojan.Generic.7761207 |
Emsisoft Commandline Scanner (Windows) | Trojan.Generic.7761207 (B) |