File c21bb16736e6214f54fe1488e5bd50b000ec2fc0dde0f171b6ccbc4b20d2cacd

Size 162.1KB
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
MD5 a5f56b47a9d6877de3ac87f3ebc1ab10
SHA1 4cecf14862ba64584d3f251941906a24bbf3e399
SHA256 c21bb16736e6214f54fe1488e5bd50b000ec2fc0dde0f171b6ccbc4b20d2cacd
SHA512
50e7b5e5f88e76555b300cf4de52e43554d6af766be5d76aedaf82256f424e792ca1d3e9d7e741cd1717fc01db6ead62755981d23b47f2c61794608998488993
CRC32 21E5FFBD
ssdeep None
Yara
  • suspicious_packer_section - The packer/protector section names/keywords
  • keylogger - Run a keylogger
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 9.6 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

6600879

6600880

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE June 22, 2025, 2:17 a.m. June 22, 2025, 2:23 a.m. 343 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-06-20 18:41:14,030 [analyzer] DEBUG: Starting analyzer from: C:\tmppw5mq4
2025-06-20 18:41:14,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\pEhZDLVoQIOVqIMYcsQrcrLXAJALlhvL
2025-06-20 18:41:14,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\FlCTnJWjYHpVcYvCAawJjXNbVHTz
2025-06-20 18:41:14,592 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-20 18:41:14,592 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-20 18:41:15,437 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-20 18:41:15,671 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-06-20 18:41:15,671 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-20 18:41:15,671 [analyzer] DEBUG: Started auxiliary module Human
2025-06-20 18:41:15,671 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-20 18:41:15,671 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-20 18:41:15,750 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-20 18:41:15,750 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-20 18:41:15,750 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-20 18:41:15,750 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-20 18:41:15,937 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\c21bb16736e6214f54fe1488e5bd50b000ec2fc0dde0f171b6ccbc4b20d2cacd.exe' with arguments '' and pid 2464
2025-06-20 18:41:16,108 [analyzer] DEBUG: Loaded monitor into process with pid 2464
2025-06-20 18:41:16,203 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Star Wars Episode 2 - Attack Of The Clones Full Downloader.exe
2025-06-20 18:41:16,217 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Jenna Jameson - Built For Speed Downloader.exe
2025-06-20 18:41:16,217 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\[DiVX] Lord of The Rings Full Downloader.exe
2025-06-20 18:41:16,217 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\[DiVX] Harry Potter And The Sorcerors Stone Full Downloader.exe
2025-06-20 18:41:16,233 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\CKY3 - Bam Margera World Industries Alien Workshop Full Downloader.exe
2025-06-20 18:41:16,233 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Cat Attacks Child Full Downloader.exe
2025-06-20 18:41:16,233 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\PS1 Boot Disc Full Dwonloader.exe
2025-06-20 18:41:16,233 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Sony Play station boot disc - Downloader.exe
2025-06-20 18:41:16,250 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\How To Hack Websites.exe
2025-06-20 18:41:16,250 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\AIM Account Stealer Downloader.exe
2025-06-20 18:41:16,250 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\MSN Password Hacker and Stealer.exe
2025-06-20 18:41:16,250 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Hacking Tool Collection.exe
2025-06-20 18:41:16,250 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Windows XP Full Downloader.exe
2025-06-20 18:41:16,265 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Macromedia Flash 5.0 Full Downloader.exe
2025-06-20 18:41:16,265 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\DSL Modem Uncapper.exe
2025-06-20 18:41:16,265 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Internet and Computer Speed Booster.exe
2025-06-20 18:41:16,265 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\ZoneAlarm Firewall Full Downloader.exe
2025-06-20 18:41:16,265 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Borland Delphi 6 Key Generator.exe
2025-06-20 18:41:16,280 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\ScaryMovie 2 Full Downloader.exe
2025-06-20 18:41:16,280 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\StarWars2 - CloneAttack - FullDownloader.exe
2025-06-20 18:41:16,280 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Spiderman FullDownloader.exe
2025-06-20 18:41:16,280 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Shakira FullDownloader.exe
2025-06-20 18:41:16,296 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Gladiator FullDownloader.exe
2025-06-20 18:41:16,296 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\AikaQuest3Hentai FullDownloader.exe
2025-06-20 18:41:16,296 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\MoviezChannelsInstaler.exe
2025-06-20 18:41:16,312 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Zidane-ScreenInstaler.exe
2025-06-20 18:41:16,312 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\LordOfTheRings-FullDownloader.exe
2025-06-20 18:41:16,312 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\SIMS FullDownloader.exe
2025-06-20 18:41:16,312 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Britney spears nude.exe
2025-06-20 18:41:16,328 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Quake 4 BETA.exe
2025-06-20 18:41:16,328 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Windows XP key generator.exe
2025-06-20 18:41:16,328 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Windows XP serial generator.exe
2025-06-20 18:41:16,328 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Xbox.info.exe
2025-06-20 18:41:16,342 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\DivX.exe
2025-06-20 18:41:16,342 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\GTA3 crack.exe
2025-06-20 18:41:16,342 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Battle.net key generator (WORKS!!).exe
2025-06-20 18:41:16,342 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Warcraft 3 battle.net serial generator.exe
2025-06-20 18:41:16,358 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Half-life WON key generator.exe
2025-06-20 18:41:16,358 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Star wars episode 2 downloader.exe
2025-06-20 18:41:16,358 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Winzip 8.0 + serial.exe
2025-06-20 18:41:16,358 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Winrar + crack.exe
2025-06-20 18:41:16,358 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Key generator for all windows XP versions.exe
2025-06-20 18:41:16,375 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Warcraft 3 ONLINE key generator.exe
2025-06-20 18:41:16,375 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Half-life ONLINE key generator.exe
2025-06-20 18:41:16,375 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Grand theft auto 3 CD1 crack.exe
2025-06-20 18:41:16,375 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Macromedia key generator (all products).exe
2025-06-20 18:41:16,390 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\KaZaA media desktop v2.0 UNOFFICIAL.exe
2025-06-20 18:41:16,390 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Microsoft key generator, works for ALL microsoft products!!.exe
2025-06-20 18:41:16,390 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Microsoft Windows XP crack pack.exe
2025-06-20 18:41:16,390 [analyzer] INFO: Added new file to list with pid 2464 and path C:\Windows\Temp\Hack into any computer!!.exe
2025-06-20 18:41:16,937 [analyzer] INFO: Process with pid 2464 has terminated
2025-06-20 18:41:16,937 [analyzer] INFO: Process list is empty, terminating analysis.
2025-06-20 18:41:18,187 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-20 18:41:18,390 [analyzer] WARNING: Too many files: c:\windows\temp\half-life won key generator.exe
2025-06-20 18:41:18,390 [analyzer] WARNING: Too many files: c:\windows\temp\star wars episode 2 - attack of the clones full downloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\moviezchannelsinstaler.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\kazaa media desktop v2.0 unofficial.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\divx.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\borland delphi 6 key generator.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\jenna jameson - built for speed downloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\hack into any computer!!.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\[divx] harry potter and the sorcerors stone full downloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\sony play station boot disc - downloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\scarymovie 2 full downloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\star wars episode 2 downloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\starwars2 - cloneattack - fulldownloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\microsoft windows xp crack pack.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\grand theft auto 3 cd1 crack.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\zidane-screeninstaler.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\lordoftherings-fulldownloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\zonealarm firewall full downloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\microsoft key generator, works for all microsoft products!!.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\ps1 boot disc full dwonloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\half-life online key generator.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\dsl modem uncapper.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\spiderman fulldownloader.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\windows xp serial generator.exe
2025-06-20 18:41:18,405 [analyzer] WARNING: Too many files: c:\windows\temp\internet and computer speed booster.exe
2025-06-20 18:41:18,405 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-06-22 02:17:20,774 [cuckoo.core.scheduler] DEBUG: Task #6574249: no machine available yet
2025-06-22 02:17:21,809 [cuckoo.core.scheduler] DEBUG: Task #6574249: no machine available yet
2025-06-22 02:17:22,999 [cuckoo.core.scheduler] DEBUG: Task #6574249: no machine available yet
2025-06-22 02:17:24,040 [cuckoo.core.scheduler] INFO: Task #6574249: acquired machine win7x646 (label=win7x646)
2025-06-22 02:17:24,042 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.206 for task #6574249
2025-06-22 02:17:24,620 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1602683 (interface=vboxnet0, host=192.168.168.206)
2025-06-22 02:17:24,811 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x646
2025-06-22 02:17:25,567 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x646 to vmcloak
2025-06-22 02:20:58,340 [cuckoo.core.guest] INFO: Starting analysis #6574249 on guest (id=win7x646, ip=192.168.168.206)
2025-06-22 02:20:59,377 [cuckoo.core.guest] DEBUG: win7x646: not ready yet
2025-06-22 02:21:04,824 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x646, ip=192.168.168.206)
2025-06-22 02:21:04,951 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x646, ip=192.168.168.206, monitor=latest, size=6660546)
2025-06-22 02:21:08,383 [cuckoo.core.resultserver] DEBUG: Task #6574249: live log analysis.log initialized.
2025-06-22 02:21:10,000 [cuckoo.core.resultserver] DEBUG: Task #6574249 is sending a BSON stream
2025-06-22 02:21:10,116 [cuckoo.core.resultserver] DEBUG: Task #6574249 is sending a BSON stream
2025-06-22 02:21:11,026 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'shots/0001.jpg'
2025-06-22 02:21:11,061 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 133474
2025-06-22 02:21:12,184 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'curtain/1750437678.06.curtain.log'
2025-06-22 02:21:12,204 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 36
2025-06-22 02:21:12,286 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'sysmon/1750437678.17.sysmon.xml'
2025-06-22 02:21:12,294 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 267276
2025-06-22 02:21:12,299 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/2ee1b31f269c9e78_xbox.info.exe'
2025-06-22 02:21:12,303 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166121
2025-06-22 02:21:12,306 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/3f6ef1c596b02e79_winzip 8.0 + serial.exe'
2025-06-22 02:21:12,309 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166273
2025-06-22 02:21:12,313 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/f3a7ce2eafe07941_quake 4 beta.exe'
2025-06-22 02:21:12,316 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166283
2025-06-22 02:21:12,323 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/48b1ac756b81e2a5_macromedia flash 5.0 full downloader.exe'
2025-06-22 02:21:12,326 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166148
2025-06-22 02:21:12,330 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/81f9da4e38837f65_gladiator fulldownloader.exe'
2025-06-22 02:21:12,336 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166140
2025-06-22 02:21:12,343 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/84ff22072eb1dc73_cky3 - bam margera world industries alien workshop full downloader.exe'
2025-06-22 02:21:12,346 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166219
2025-06-22 02:21:12,348 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/0bc91aca60040471_warcraft 3 online key generator.exe'
2025-06-22 02:21:12,351 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166357
2025-06-22 02:21:12,354 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/222cbd4479e851fa_battle.net key generator (works!!).exe'
2025-06-22 02:21:12,357 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166041
2025-06-22 02:21:12,363 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/2c65a453716d6c9f_warcraft 3 battle.net serial generator.exe'
2025-06-22 02:21:12,365 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166156
2025-06-22 02:21:12,369 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/1e37407b52329370_how to hack websites.exe'
2025-06-22 02:21:12,372 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166423
2025-06-22 02:21:12,374 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/db2047a1de0c08a7_shakira fulldownloader.exe'
2025-06-22 02:21:12,376 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166489
2025-06-22 02:21:12,380 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/873c8b9edfc893bf_[divx] lord of the rings full downloader.exe'
2025-06-22 02:21:12,382 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166165
2025-06-22 02:21:12,386 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/e7949a451533fddb_windows xp full downloader.exe'
2025-06-22 02:21:12,389 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166015
2025-06-22 02:21:12,392 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/cdc904829d6d65fe_cat attacks child full downloader.exe'
2025-06-22 02:21:12,394 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166150
2025-06-22 02:21:12,399 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/2681c158ace189b9_macromedia key generator (all products).exe'
2025-06-22 02:21:12,412 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166387
2025-06-22 02:21:12,416 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/33a6700605c4c3d8_winrar + crack.exe'
2025-06-22 02:21:12,508 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/7a5cad5e7fe75511_aim account stealer downloader.exe'
2025-06-22 02:21:12,511 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/ae15e711f9f63edb_key generator for all windows xp versions.exe'
2025-06-22 02:21:12,513 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/79d49e66ebf6779b_gta3 crack.exe'
2025-06-22 02:21:12,515 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/29ccc3a3b08848e0_sims fulldownloader.exe'
2025-06-22 02:21:12,517 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/01e76ddabafd90eb_britney spears nude.exe'
2025-06-22 02:21:12,519 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/98112b83eedffd3d_windows xp key generator.exe'
2025-06-22 02:21:12,521 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/fa1db0f6dd31516d_msn password hacker and stealer.exe'
2025-06-22 02:21:12,523 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/f0b27fdaeb97817e_hacking tool collection.exe'
2025-06-22 02:21:12,525 [cuckoo.core.resultserver] DEBUG: Task #6574249: File upload for 'files/4f4a7bcf781a937b_aikaquest3hentai fulldownloader.exe'
2025-06-22 02:21:12,531 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166303
2025-06-22 02:21:12,532 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166083
2025-06-22 02:21:12,534 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166084
2025-06-22 02:21:12,535 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166465
2025-06-22 02:21:12,536 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166475
2025-06-22 02:21:12,538 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166252
2025-06-22 02:21:12,540 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166158
2025-06-22 02:21:12,541 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166448
2025-06-22 02:21:12,543 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166298
2025-06-22 02:21:12,545 [cuckoo.core.resultserver] DEBUG: Task #6574249 uploaded file length: 166449
2025-06-22 02:21:13,238 [cuckoo.core.resultserver] DEBUG: Task #6574249 had connection reset for <Context for LOG>
2025-06-22 02:21:13,554 [cuckoo.core.guest] INFO: win7x646: analysis completed successfully
2025-06-22 02:21:13,566 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-22 02:21:13,887 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-22 02:21:15,657 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x646 to path /srv/cuckoo/cwd/storage/analyses/6574249/memory.dmp
2025-06-22 02:21:15,694 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x646
2025-06-22 02:23:02,644 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.206 for task #6574249
2025-06-22 02:23:03,340 [cuckoo.core.scheduler] DEBUG: Released database task #6574249
2025-06-22 02:23:03,373 [cuckoo.core.scheduler] INFO: Task #6574249: analysis procedure completed

Signatures

Yara rules detected for file (4 events)
description The packer/protector section names/keywords rule suspicious_packer_section
description Run a keylogger rule keylogger
description Affect system registries rule win_registry
description Affect private profile rule win_files_operation
The executable contains unknown PE section names indicative of a packer (could be a false positive) (1 event)
section .imports
The executable uses a known packer (1 event)
packer BobSoft Mini Delphi -> BoB / BobSoft
Creates executable files on the filesystem (50 events)
file C:\Windows\Temp\StarWars2 - CloneAttack - FullDownloader.exe
file C:\Windows\Temp\Microsoft Windows XP crack pack.exe
file C:\Windows\Temp\Star Wars Episode 2 - Attack Of The Clones Full Downloader.exe
file C:\Windows\Temp\LordOfTheRings-FullDownloader.exe
file C:\Windows\Temp\Winzip 8.0 + serial.exe
file C:\Windows\Temp\KaZaA media desktop v2.0 UNOFFICIAL.exe
file C:\Windows\Temp\Microsoft key generator, works for ALL microsoft products!!.exe
file C:\Windows\Temp\Warcraft 3 battle.net serial generator.exe
file C:\Windows\Temp\Xbox.info.exe
file C:\Windows\Temp\Quake 4 BETA.exe
file C:\Windows\Temp\[DiVX] Harry Potter And The Sorcerors Stone Full Downloader.exe
file C:\Windows\Temp\AikaQuest3Hentai FullDownloader.exe
file C:\Windows\Temp\Half-life WON key generator.exe
file C:\Windows\Temp\Cat Attacks Child Full Downloader.exe
file C:\Windows\Temp\Macromedia key generator (all products).exe
file C:\Windows\Temp\Winrar + crack.exe
file C:\Windows\Temp\ZoneAlarm Firewall Full Downloader.exe
file C:\Windows\Temp\Key generator for all windows XP versions.exe
file C:\Windows\Temp\Macromedia Flash 5.0 Full Downloader.exe
file C:\Windows\Temp\Jenna Jameson - Built For Speed Downloader.exe
file C:\Windows\Temp\Britney spears nude.exe
file C:\Windows\Temp\Half-life ONLINE key generator.exe
file C:\Windows\Temp\Battle.net key generator (WORKS!!).exe
file C:\Windows\Temp\DSL Modem Uncapper.exe
file C:\Windows\Temp\Windows XP serial generator.exe
file C:\Windows\Temp\[DiVX] Lord of The Rings Full Downloader.exe
file C:\Windows\Temp\ScaryMovie 2 Full Downloader.exe
file C:\Windows\Temp\Grand theft auto 3 CD1 crack.exe
file C:\Windows\Temp\MoviezChannelsInstaler.exe
file C:\Windows\Temp\AIM Account Stealer Downloader.exe
file C:\Windows\Temp\PS1 Boot Disc Full Dwonloader.exe
file C:\Windows\Temp\Gladiator FullDownloader.exe
file C:\Windows\Temp\CKY3 - Bam Margera World Industries Alien Workshop Full Downloader.exe
file C:\Windows\Temp\SIMS FullDownloader.exe
file C:\Windows\Temp\MSN Password Hacker and Stealer.exe
file C:\Windows\Temp\Hack into any computer!!.exe
file C:\Windows\Temp\Shakira FullDownloader.exe
file C:\Windows\Temp\Sony Play station boot disc - Downloader.exe
file C:\Windows\Temp\Internet and Computer Speed Booster.exe
file C:\Windows\Temp\Windows XP Full Downloader.exe
file C:\Windows\Temp\Star wars episode 2 downloader.exe
file C:\Windows\Temp\Zidane-ScreenInstaler.exe
file C:\Windows\Temp\Warcraft 3 ONLINE key generator.exe
file C:\Windows\Temp\GTA3 crack.exe
file C:\Windows\Temp\DivX.exe
file C:\Windows\Temp\Borland Delphi 6 Key Generator.exe
file C:\Windows\Temp\Windows XP key generator.exe
file C:\Windows\Temp\How To Hack Websites.exe
file C:\Windows\Temp\Hacking Tool Collection.exe
file C:\Windows\Temp\Spiderman FullDownloader.exe
The executable is compressed using UPX (2 events)
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
File has been identified by 13 AntiVirus engine on IRMA as malicious (13 events)
G Data Antivirus (Windows) Virus: Gen:Trojan.P2P-Worm.kqY@ay@Oyrm (Engine A), Win32.Worm.Soltern.A (Engine B)
Avast Core Security (Linux) Win32:Delf-UDU [Trj]
C4S ClamAV (Linux) Win.Worm.Soltern-1
Trend Micro SProtect (Linux) Worm.Win32.SYTRO.SMJT
Trellix (Linux) W32/Sytro.worm.gen
WithSecure (Linux) Worm.WORM/Soltern.oald
eScan Antivirus (Linux) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm(DB)
ESET Security (Windows) a variant of Win32/Soltern.NAA worm
Sophos Anti-Virus (Linux) W32/Systro-J
DrWeb Antivirus (Linux) Win32.HLLW.Sytro
ClamAV (Linux) Win.Worm.Soltern-1
Bitdefender Antivirus (Linux) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm
Emsisoft Commandline Scanner (Windows) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm (B)
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.