File 3f6ef1c596b02e79_winzip 8.0 + serial.exe

Size 162.4KB
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
MD5 07b521880b10f60938b443f9964c77ef
SHA1 f4e6b7ea602d2d6f1ab0f88dad7b7943a9ed714c
SHA256 3f6ef1c596b02e7976f1be0d2299382a6f3fd2d34950489934a0daf6a825c0d9
SHA512
48fc04ff6684ae63c6fbda99e9959177ea583c59cf33d3243ba0e6b9497a9eddf199a610f4e0d8eb0c2ff8040193699b432b336d55ea14278f09c5556fd83f74
CRC32 73DA366A
ssdeep None
Yara
  • suspicious_packer_section - The packer/protector section names/keywords
  • keylogger - Run a keylogger
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 9.6 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

Parent_Task_ID:6574249

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE June 27, 2025, 12:15 p.m. June 27, 2025, 12:21 p.m. 353 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-06-22 02:23:30,000 [analyzer] DEBUG: Starting analyzer from: C:\tmphzbxu3
2025-06-22 02:23:30,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ekdhTLrWSZdmpWRDLSUtP
2025-06-22 02:23:30,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\tUOQrDwGQocyyjTJlk
2025-06-22 02:23:30,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-22 02:23:30,015 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-22 02:23:30,467 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-22 02:23:30,467 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-22 02:23:31,217 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-22 02:23:31,437 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-06-22 02:23:31,437 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-22 02:23:31,437 [analyzer] DEBUG: Started auxiliary module Human
2025-06-22 02:23:31,437 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-22 02:23:31,437 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-22 02:23:31,500 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-22 02:23:31,500 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-22 02:23:31,500 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-22 02:23:31,500 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-22 02:23:31,625 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\3f6ef1c596b02e79_winzip 8.0 + serial.exe' with arguments '' and pid 2344
2025-06-22 02:23:31,796 [analyzer] DEBUG: Loaded monitor into process with pid 2344
2025-06-22 02:23:31,905 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Star Wars Episode 2 - Attack Of The Clones Full Downloader.exe
2025-06-22 02:23:31,905 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Jenna Jameson - Built For Speed Downloader.exe
2025-06-22 02:23:31,905 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\[DiVX] Lord of The Rings Full Downloader.exe
2025-06-22 02:23:31,905 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\[DiVX] Harry Potter And The Sorcerors Stone Full Downloader.exe
2025-06-22 02:23:31,921 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\CKY3 - Bam Margera World Industries Alien Workshop Full Downloader.exe
2025-06-22 02:23:31,921 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Cat Attacks Child Full Downloader.exe
2025-06-22 02:23:31,921 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\PS1 Boot Disc Full Dwonloader.exe
2025-06-22 02:23:31,921 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Sony Play station boot disc - Downloader.exe
2025-06-22 02:23:31,921 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\How To Hack Websites.exe
2025-06-22 02:23:31,921 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\AIM Account Stealer Downloader.exe
2025-06-22 02:23:31,921 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\MSN Password Hacker and Stealer.exe
2025-06-22 02:23:31,921 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Hacking Tool Collection.exe
2025-06-22 02:23:31,937 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Windows XP Full Downloader.exe
2025-06-22 02:23:31,937 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Macromedia Flash 5.0 Full Downloader.exe
2025-06-22 02:23:31,937 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\DSL Modem Uncapper.exe
2025-06-22 02:23:31,937 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Internet and Computer Speed Booster.exe
2025-06-22 02:23:31,937 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\ZoneAlarm Firewall Full Downloader.exe
2025-06-22 02:23:31,953 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Borland Delphi 6 Key Generator.exe
2025-06-22 02:23:31,953 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\ScaryMovie 2 Full Downloader.exe
2025-06-22 02:23:31,953 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\StarWars2 - CloneAttack - FullDownloader.exe
2025-06-22 02:23:31,953 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Spiderman FullDownloader.exe
2025-06-22 02:23:31,967 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Shakira FullDownloader.exe
2025-06-22 02:23:31,967 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Gladiator FullDownloader.exe
2025-06-22 02:23:31,967 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\AikaQuest3Hentai FullDownloader.exe
2025-06-22 02:23:31,967 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\MoviezChannelsInstaler.exe
2025-06-22 02:23:31,967 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Zidane-ScreenInstaler.exe
2025-06-22 02:23:31,967 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\LordOfTheRings-FullDownloader.exe
2025-06-22 02:23:31,967 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\SIMS FullDownloader.exe
2025-06-22 02:23:31,983 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Britney spears nude.exe
2025-06-22 02:23:31,983 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Quake 4 BETA.exe
2025-06-22 02:23:31,983 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Windows XP key generator.exe
2025-06-22 02:23:31,983 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Windows XP serial generator.exe
2025-06-22 02:23:31,983 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Xbox.info.exe
2025-06-22 02:23:32,000 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\DivX.exe
2025-06-22 02:23:32,000 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\GTA3 crack.exe
2025-06-22 02:23:32,000 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Battle.net key generator (WORKS!!).exe
2025-06-22 02:23:32,000 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Warcraft 3 battle.net serial generator.exe
2025-06-22 02:23:32,000 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Half-life WON key generator.exe
2025-06-22 02:23:32,015 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Star wars episode 2 downloader.exe
2025-06-22 02:23:32,015 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Winzip 8.0 + serial.exe
2025-06-22 02:23:32,015 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Winrar + crack.exe
2025-06-22 02:23:32,015 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Key generator for all windows XP versions.exe
2025-06-22 02:23:32,015 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Warcraft 3 ONLINE key generator.exe
2025-06-22 02:23:32,015 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Half-life ONLINE key generator.exe
2025-06-22 02:23:32,030 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Grand theft auto 3 CD1 crack.exe
2025-06-22 02:23:32,030 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Macromedia key generator (all products).exe
2025-06-22 02:23:32,030 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\KaZaA media desktop v2.0 UNOFFICIAL.exe
2025-06-22 02:23:32,030 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Microsoft key generator, works for ALL microsoft products!!.exe
2025-06-22 02:23:32,030 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Microsoft Windows XP crack pack.exe
2025-06-22 02:23:32,030 [analyzer] INFO: Added new file to list with pid 2344 and path C:\Windows\Temp\Hack into any computer!!.exe
2025-06-22 02:23:32,625 [analyzer] INFO: Process with pid 2344 has terminated
2025-06-22 02:23:32,625 [analyzer] INFO: Process list is empty, terminating analysis.
2025-06-22 02:23:33,812 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\half-life won key generator.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\star wars episode 2 - attack of the clones full downloader.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\moviezchannelsinstaler.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\kazaa media desktop v2.0 unofficial.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\divx.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\borland delphi 6 key generator.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\jenna jameson - built for speed downloader.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\hack into any computer!!.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\[divx] harry potter and the sorcerors stone full downloader.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\sony play station boot disc - downloader.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\scarymovie 2 full downloader.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\star wars episode 2 downloader.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\starwars2 - cloneattack - fulldownloader.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\microsoft windows xp crack pack.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\grand theft auto 3 cd1 crack.exe
2025-06-22 02:23:33,937 [analyzer] WARNING: Too many files: c:\windows\temp\zidane-screeninstaler.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\lordoftherings-fulldownloader.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\zonealarm firewall full downloader.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\microsoft key generator, works for all microsoft products!!.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\ps1 boot disc full dwonloader.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\half-life online key generator.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\dsl modem uncapper.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\spiderman fulldownloader.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\windows xp serial generator.exe
2025-06-22 02:23:33,953 [analyzer] WARNING: Too many files: c:\windows\temp\internet and computer speed booster.exe
2025-06-22 02:23:33,953 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-06-27 12:15:52,474 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:15:53,740 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:15:54,767 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:15:55,810 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:15:56,960 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:15:58,311 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:15:59,346 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:00,419 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:01,460 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:02,520 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:03,576 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:04,631 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:05,860 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:06,966 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:08,030 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:09,102 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:10,307 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:11,705 [cuckoo.core.scheduler] DEBUG: Task #6600879: no machine available yet
2025-06-27 12:16:12,894 [cuckoo.core.scheduler] INFO: Task #6600879: acquired machine win7x6425 (label=win7x6425)
2025-06-27 12:16:12,912 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.225 for task #6600879
2025-06-27 12:16:13,479 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 258388 (interface=vboxnet0, host=192.168.168.225)
2025-06-27 12:16:14,168 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6425
2025-06-27 12:16:14,992 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6425 to vmcloak
2025-06-27 12:19:12,296 [cuckoo.core.guest] INFO: Starting analysis #6600879 on guest (id=win7x6425, ip=192.168.168.225)
2025-06-27 12:19:13,303 [cuckoo.core.guest] DEBUG: win7x6425: not ready yet
2025-06-27 12:19:18,326 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6425, ip=192.168.168.225)
2025-06-27 12:19:18,479 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6425, ip=192.168.168.225, monitor=latest, size=6660546)
2025-06-27 12:19:21,065 [cuckoo.core.resultserver] DEBUG: Task #6600879: live log analysis.log initialized.
2025-06-27 12:19:22,272 [cuckoo.core.resultserver] DEBUG: Task #6600879 is sending a BSON stream
2025-06-27 12:19:22,615 [cuckoo.core.resultserver] DEBUG: Task #6600879 is sending a BSON stream
2025-06-27 12:19:23,505 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'shots/0001.jpg'
2025-06-27 12:19:23,516 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 133497
2025-06-27 12:19:24,605 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'curtain/1750551813.7.curtain.log'
2025-06-27 12:19:24,607 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 36
2025-06-27 12:19:24,709 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'sysmon/1750551813.8.sysmon.xml'
2025-06-27 12:19:24,714 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 515320
2025-06-27 12:19:24,717 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/0dd6bad8837ad163_xbox.info.exe'
2025-06-27 12:19:24,720 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166465
2025-06-27 12:19:24,723 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/cb7e37891cd1ee66_winzip 8.0 + serial.exe'
2025-06-27 12:19:24,727 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166348
2025-06-27 12:19:24,729 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/f4af2de045f8bdd1_quake 4 beta.exe'
2025-06-27 12:19:24,732 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166283
2025-06-27 12:19:24,735 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/6f58768d9ac33016_macromedia flash 5.0 full downloader.exe'
2025-06-27 12:19:24,738 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166619
2025-06-27 12:19:24,741 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/2d006c19c275a04f_gladiator fulldownloader.exe'
2025-06-27 12:19:24,744 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/28e47cbbbcf6a4b2_cky3 - bam margera world industries alien workshop full downloader.exe'
2025-06-27 12:19:24,746 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166381
2025-06-27 12:19:24,748 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166523
2025-06-27 12:19:24,750 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/827b77227eec7f63_warcraft 3 online key generator.exe'
2025-06-27 12:19:24,754 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166714
2025-06-27 12:19:24,758 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/310d3bb883ffe1ed_battle.net key generator (works!!).exe'
2025-06-27 12:19:24,775 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166689
2025-06-27 12:19:24,781 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/bd98061fce4a59ef_warcraft 3 battle.net serial generator.exe'
2025-06-27 12:19:24,784 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/22cb2d7a1168df69_how to hack websites.exe'
2025-06-27 12:19:24,786 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/e22a36456d97c6c5_shakira fulldownloader.exe'
2025-06-27 12:19:24,788 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/8184a9b26891a034_[divx] lord of the rings full downloader.exe'
2025-06-27 12:19:24,792 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/bc71ed57bf27ec11_windows xp full downloader.exe'
2025-06-27 12:19:24,794 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/fa902bf244cfd0e4_cat attacks child full downloader.exe'
2025-06-27 12:19:24,796 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166304
2025-06-27 12:19:24,798 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166598
2025-06-27 12:19:24,799 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166369
2025-06-27 12:19:24,801 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/e59ca54c3a921a2d_macromedia key generator (all products).exe'
2025-06-27 12:19:24,803 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/d2e821ad7db57727_winrar + crack.exe'
2025-06-27 12:19:24,806 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166345
2025-06-27 12:19:24,807 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166368
2025-06-27 12:19:24,810 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/3f6ef1c596b02e79_aim account stealer downloader.exe'
2025-06-27 12:19:24,812 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166673
2025-06-27 12:19:24,813 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166398
2025-06-27 12:19:24,814 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166691
2025-06-27 12:19:24,816 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/2d2b75f8c03a3966_key generator for all windows xp versions.exe'
2025-06-27 12:19:24,818 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/81ff344a86bc70f0_gta3 crack.exe'
2025-06-27 12:19:24,821 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166371
2025-06-27 12:19:24,822 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166273
2025-06-27 12:19:24,824 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/0b783cb73d1b0064_sims fulldownloader.exe'
2025-06-27 12:19:24,826 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166740
2025-06-27 12:19:24,828 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/ab4345c2c4b7ca82_britney spears nude.exe'
2025-06-27 12:19:24,830 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/81f30673abed41d6_windows xp key generator.exe'
2025-06-27 12:19:24,832 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166440
2025-06-27 12:19:24,834 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/147655ceb383c9eb_msn password hacker and stealer.exe'
2025-06-27 12:19:24,837 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166505
2025-06-27 12:19:24,839 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166416
2025-06-27 12:19:24,841 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/0677efa9cbea6c7b_hacking tool collection.exe'
2025-06-27 12:19:24,843 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166601
2025-06-27 12:19:24,845 [cuckoo.core.resultserver] DEBUG: Task #6600879: File upload for 'files/693b8767329e86e4_aikaquest3hentai fulldownloader.exe'
2025-06-27 12:19:24,847 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166434
2025-06-27 12:19:24,849 [cuckoo.core.resultserver] DEBUG: Task #6600879 uploaded file length: 166475
2025-06-27 12:19:25,560 [cuckoo.core.resultserver] DEBUG: Task #6600879 had connection reset for <Context for LOG>
2025-06-27 12:19:26,370 [cuckoo.core.guest] INFO: win7x6425: analysis completed successfully
2025-06-27 12:19:26,384 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-27 12:19:26,408 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-27 12:19:27,724 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6425 to path /srv/cuckoo/cwd/storage/analyses/6600879/memory.dmp
2025-06-27 12:19:27,729 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6425
2025-06-27 12:21:45,189 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.225 for task #6600879
2025-06-27 12:21:45,552 [cuckoo.core.scheduler] DEBUG: Released database task #6600879
2025-06-27 12:21:45,565 [cuckoo.core.scheduler] INFO: Task #6600879: analysis procedure completed

Signatures

Yara rules detected for file (4 events)
description The packer/protector section names/keywords rule suspicious_packer_section
description Run a keylogger rule keylogger
description Affect system registries rule win_registry
description Affect private profile rule win_files_operation
The executable contains unknown PE section names indicative of a packer (could be a false positive) (1 event)
section .imports
The executable uses a known packer (1 event)
packer BobSoft Mini Delphi -> BoB / BobSoft
Creates executable files on the filesystem (50 events)
file C:\Windows\Temp\StarWars2 - CloneAttack - FullDownloader.exe
file C:\Windows\Temp\Microsoft Windows XP crack pack.exe
file C:\Windows\Temp\Star Wars Episode 2 - Attack Of The Clones Full Downloader.exe
file C:\Windows\Temp\LordOfTheRings-FullDownloader.exe
file C:\Windows\Temp\Winzip 8.0 + serial.exe
file C:\Windows\Temp\KaZaA media desktop v2.0 UNOFFICIAL.exe
file C:\Windows\Temp\Microsoft key generator, works for ALL microsoft products!!.exe
file C:\Windows\Temp\Warcraft 3 battle.net serial generator.exe
file C:\Windows\Temp\Xbox.info.exe
file C:\Windows\Temp\Quake 4 BETA.exe
file C:\Windows\Temp\[DiVX] Harry Potter And The Sorcerors Stone Full Downloader.exe
file C:\Windows\Temp\AikaQuest3Hentai FullDownloader.exe
file C:\Windows\Temp\Half-life WON key generator.exe
file C:\Windows\Temp\Cat Attacks Child Full Downloader.exe
file C:\Windows\Temp\Macromedia key generator (all products).exe
file C:\Windows\Temp\Winrar + crack.exe
file C:\Windows\Temp\ZoneAlarm Firewall Full Downloader.exe
file C:\Windows\Temp\Key generator for all windows XP versions.exe
file C:\Windows\Temp\Macromedia Flash 5.0 Full Downloader.exe
file C:\Windows\Temp\Jenna Jameson - Built For Speed Downloader.exe
file C:\Windows\Temp\Britney spears nude.exe
file C:\Windows\Temp\Half-life ONLINE key generator.exe
file C:\Windows\Temp\Battle.net key generator (WORKS!!).exe
file C:\Windows\Temp\DSL Modem Uncapper.exe
file C:\Windows\Temp\Windows XP serial generator.exe
file C:\Windows\Temp\[DiVX] Lord of The Rings Full Downloader.exe
file C:\Windows\Temp\ScaryMovie 2 Full Downloader.exe
file C:\Windows\Temp\Grand theft auto 3 CD1 crack.exe
file C:\Windows\Temp\MoviezChannelsInstaler.exe
file C:\Windows\Temp\AIM Account Stealer Downloader.exe
file C:\Windows\Temp\PS1 Boot Disc Full Dwonloader.exe
file C:\Windows\Temp\Gladiator FullDownloader.exe
file C:\Windows\Temp\CKY3 - Bam Margera World Industries Alien Workshop Full Downloader.exe
file C:\Windows\Temp\SIMS FullDownloader.exe
file C:\Windows\Temp\MSN Password Hacker and Stealer.exe
file C:\Windows\Temp\Hack into any computer!!.exe
file C:\Windows\Temp\Shakira FullDownloader.exe
file C:\Windows\Temp\Sony Play station boot disc - Downloader.exe
file C:\Windows\Temp\Internet and Computer Speed Booster.exe
file C:\Windows\Temp\Windows XP Full Downloader.exe
file C:\Windows\Temp\Star wars episode 2 downloader.exe
file C:\Windows\Temp\Zidane-ScreenInstaler.exe
file C:\Windows\Temp\Warcraft 3 ONLINE key generator.exe
file C:\Windows\Temp\GTA3 crack.exe
file C:\Windows\Temp\DivX.exe
file C:\Windows\Temp\Borland Delphi 6 Key Generator.exe
file C:\Windows\Temp\Windows XP key generator.exe
file C:\Windows\Temp\How To Hack Websites.exe
file C:\Windows\Temp\Hacking Tool Collection.exe
file C:\Windows\Temp\Spiderman FullDownloader.exe
The executable is compressed using UPX (2 events)
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
File has been identified by 14 AntiVirus engine on IRMA as malicious (14 events)
G Data Antivirus (Windows) Virus: Gen:Trojan.P2P-Worm.kqY@ay@Oyrm (Engine A), Win32.Worm.Soltern.A (Engine B)
Avast Core Security (Linux) Win32:Delf-UDU [Trj]
C4S ClamAV (Linux) Win.Worm.Soltern-1
Trend Micro SProtect (Linux) Worm.Win32.SYTRO.SMJT
Trellix (Linux) W32/Sytro.worm.gen
WithSecure (Linux) Worm.WORM/Soltern.oald
eScan Antivirus (Linux) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm(DB)
ESET Security (Windows) a variant of Win32/Soltern.NAA worm
Sophos Anti-Virus (Linux) W32/Systro-J
DrWeb Antivirus (Linux) Win32.HLLW.Sytro
ClamAV (Linux) Win.Worm.Soltern-1
Bitdefender Antivirus (Linux) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm
Kaspersky Standard (Windows) P2P-Worm.Win32.Sytro.j
Emsisoft Commandline Scanner (Windows) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm (B)
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.