File 2ee1b31f269c9e78_xbox.info.exe

Size 162.2KB
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
MD5 72a4c4c0c91258d5d4b0b407020a8bd8
SHA1 d1dadd9ddb8025d94ed5aca221597e583b0a53e9
SHA256 2ee1b31f269c9e7846a86efdf47e20ebd7c8f5e163a744e1a10d80be3bd3304a
SHA512
429aa44537ed821a6c56518325491f2e565a33fa8ceafb2694f9954cfcc369656b2e1af437e19967387abcabbd4f2b05c682ac482fa682f10489fa7ef5a3274b
CRC32 797E921A
ssdeep None
Yara
  • suspicious_packer_section - The packer/protector section names/keywords
  • keylogger - Run a keylogger
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 9.6 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

Parent_Task_ID:6574249

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE June 27, 2025, 12:16 p.m. June 27, 2025, 12:22 p.m. 368 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-06-22 02:23:30,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpl4240h
2025-06-22 02:23:30,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\qcTKFvpcXIgcoujWHeSK
2025-06-22 02:23:30,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\anqMkVUIOKfWeMjCOaCvYsjjxDx
2025-06-22 02:23:30,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-22 02:23:30,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-22 02:23:30,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-22 02:23:30,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-22 02:23:30,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-22 02:23:31,000 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-22 02:23:31,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-22 02:23:31,000 [analyzer] DEBUG: Started auxiliary module Human
2025-06-22 02:23:31,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-22 02:23:31,000 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-22 02:23:31,092 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-22 02:23:31,092 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-22 02:23:31,092 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-22 02:23:31,092 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-22 02:23:31,250 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2ee1b31f269c9e78_xbox.info.exe' with arguments '' and pid 1020
2025-06-22 02:23:31,421 [analyzer] DEBUG: Loaded monitor into process with pid 1020
2025-06-22 02:23:31,515 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Star Wars Episode 2 - Attack Of The Clones Full Downloader.exe
2025-06-22 02:23:31,515 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Jenna Jameson - Built For Speed Downloader.exe
2025-06-22 02:23:31,515 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\[DiVX] Lord of The Rings Full Downloader.exe
2025-06-22 02:23:31,515 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\[DiVX] Harry Potter And The Sorcerors Stone Full Downloader.exe
2025-06-22 02:23:31,515 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\CKY3 - Bam Margera World Industries Alien Workshop Full Downloader.exe
2025-06-22 02:23:31,515 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Cat Attacks Child Full Downloader.exe
2025-06-22 02:23:31,515 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\PS1 Boot Disc Full Dwonloader.exe
2025-06-22 02:23:31,530 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Sony Play station boot disc - Downloader.exe
2025-06-22 02:23:31,530 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\How To Hack Websites.exe
2025-06-22 02:23:31,530 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\AIM Account Stealer Downloader.exe
2025-06-22 02:23:31,530 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\MSN Password Hacker and Stealer.exe
2025-06-22 02:23:31,530 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Hacking Tool Collection.exe
2025-06-22 02:23:31,530 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Windows XP Full Downloader.exe
2025-06-22 02:23:31,530 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Macromedia Flash 5.0 Full Downloader.exe
2025-06-22 02:23:31,530 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\DSL Modem Uncapper.exe
2025-06-22 02:23:31,546 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Internet and Computer Speed Booster.exe
2025-06-22 02:23:31,546 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\ZoneAlarm Firewall Full Downloader.exe
2025-06-22 02:23:31,546 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Borland Delphi 6 Key Generator.exe
2025-06-22 02:23:31,546 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\ScaryMovie 2 Full Downloader.exe
2025-06-22 02:23:31,546 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\StarWars2 - CloneAttack - FullDownloader.exe
2025-06-22 02:23:31,546 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Spiderman FullDownloader.exe
2025-06-22 02:23:31,546 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Shakira FullDownloader.exe
2025-06-22 02:23:31,562 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Gladiator FullDownloader.exe
2025-06-22 02:23:31,562 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\AikaQuest3Hentai FullDownloader.exe
2025-06-22 02:23:31,562 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\MoviezChannelsInstaler.exe
2025-06-22 02:23:31,562 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Zidane-ScreenInstaler.exe
2025-06-22 02:23:31,562 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\LordOfTheRings-FullDownloader.exe
2025-06-22 02:23:31,562 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\SIMS FullDownloader.exe
2025-06-22 02:23:31,562 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Britney spears nude.exe
2025-06-22 02:23:31,562 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Quake 4 BETA.exe
2025-06-22 02:23:31,578 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Windows XP key generator.exe
2025-06-22 02:23:31,578 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Windows XP serial generator.exe
2025-06-22 02:23:31,578 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Xbox.info.exe
2025-06-22 02:23:31,578 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\DivX.exe
2025-06-22 02:23:31,578 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\GTA3 crack.exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Battle.net key generator (WORKS!!).exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Warcraft 3 battle.net serial generator.exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Half-life WON key generator.exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Star wars episode 2 downloader.exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Winzip 8.0 + serial.exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Winrar + crack.exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Key generator for all windows XP versions.exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Warcraft 3 ONLINE key generator.exe
2025-06-22 02:23:31,592 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Half-life ONLINE key generator.exe
2025-06-22 02:23:31,608 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Grand theft auto 3 CD1 crack.exe
2025-06-22 02:23:31,608 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Macromedia key generator (all products).exe
2025-06-22 02:23:31,608 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\KaZaA media desktop v2.0 UNOFFICIAL.exe
2025-06-22 02:23:31,608 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Microsoft key generator, works for ALL microsoft products!!.exe
2025-06-22 02:23:31,608 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Microsoft Windows XP crack pack.exe
2025-06-22 02:23:31,608 [analyzer] INFO: Added new file to list with pid 1020 and path C:\Windows\Temp\Hack into any computer!!.exe
2025-06-22 02:23:32,250 [analyzer] INFO: Process with pid 1020 has terminated
2025-06-22 02:23:32,250 [analyzer] INFO: Process list is empty, terminating analysis.
2025-06-22 02:23:33,453 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\half-life won key generator.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\star wars episode 2 - attack of the clones full downloader.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\moviezchannelsinstaler.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\kazaa media desktop v2.0 unofficial.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\divx.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\borland delphi 6 key generator.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\jenna jameson - built for speed downloader.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\hack into any computer!!.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\[divx] harry potter and the sorcerors stone full downloader.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\sony play station boot disc - downloader.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\scarymovie 2 full downloader.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\star wars episode 2 downloader.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\starwars2 - cloneattack - fulldownloader.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\microsoft windows xp crack pack.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\grand theft auto 3 cd1 crack.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\zidane-screeninstaler.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\lordoftherings-fulldownloader.exe
2025-06-22 02:23:33,592 [analyzer] WARNING: Too many files: c:\windows\temp\zonealarm firewall full downloader.exe
2025-06-22 02:23:33,608 [analyzer] WARNING: Too many files: c:\windows\temp\microsoft key generator, works for all microsoft products!!.exe
2025-06-22 02:23:33,608 [analyzer] WARNING: Too many files: c:\windows\temp\ps1 boot disc full dwonloader.exe
2025-06-22 02:23:33,608 [analyzer] WARNING: Too many files: c:\windows\temp\half-life online key generator.exe
2025-06-22 02:23:33,608 [analyzer] WARNING: Too many files: c:\windows\temp\dsl modem uncapper.exe
2025-06-22 02:23:33,608 [analyzer] WARNING: Too many files: c:\windows\temp\spiderman fulldownloader.exe
2025-06-22 02:23:33,608 [analyzer] WARNING: Too many files: c:\windows\temp\windows xp serial generator.exe
2025-06-22 02:23:33,608 [analyzer] WARNING: Too many files: c:\windows\temp\internet and computer speed booster.exe
2025-06-22 02:23:33,608 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-06-27 12:16:14,095 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:15,284 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:16,334 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:17,371 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:18,408 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:19,456 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:21,155 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:23,086 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:24,312 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:25,368 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:26,444 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:27,608 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:29,772 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:31,089 [cuckoo.core.scheduler] DEBUG: Task #6600880: no machine available yet
2025-06-27 12:16:32,235 [cuckoo.core.scheduler] INFO: Task #6600880: acquired machine win7x649 (label=win7x649)
2025-06-27 12:16:32,238 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.209 for task #6600880
2025-06-27 12:16:32,896 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 258944 (interface=vboxnet0, host=192.168.168.209)
2025-06-27 12:16:35,071 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x649
2025-06-27 12:16:36,155 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x649 to vmcloak
2025-06-27 12:19:51,870 [cuckoo.core.guest] INFO: Starting analysis #6600880 on guest (id=win7x649, ip=192.168.168.209)
2025-06-27 12:19:53,023 [cuckoo.core.guest] DEBUG: win7x649: not ready yet
2025-06-27 12:19:58,270 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x649, ip=192.168.168.209)
2025-06-27 12:19:58,787 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x649, ip=192.168.168.209, monitor=latest, size=6660546)
2025-06-27 12:20:02,248 [cuckoo.core.resultserver] DEBUG: Task #6600880: live log analysis.log initialized.
2025-06-27 12:20:02,254 [cuckoo.core.resultserver] DEBUG: Task #6600880 is sending a BSON stream
2025-06-27 12:20:02,258 [cuckoo.core.resultserver] DEBUG: Task #6600880 is sending a BSON stream
2025-06-27 12:20:02,357 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'shots/0001.jpg'
2025-06-27 12:20:02,370 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 133468
2025-06-27 12:20:03,482 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'curtain/1750551813.31.curtain.log'
2025-06-27 12:20:03,489 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 36
2025-06-27 12:20:03,607 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'sysmon/1750551813.44.sysmon.xml'
2025-06-27 12:20:03,621 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/0774e8ba0d8f7075_xbox.info.exe'
2025-06-27 12:20:03,636 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166355
2025-06-27 12:20:03,659 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 486354
2025-06-27 12:20:03,674 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/12b880f39f06cad3_winzip 8.0 + serial.exe'
2025-06-27 12:20:03,690 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166394
2025-06-27 12:20:03,700 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/984d184e860a341e_quake 4 beta.exe'
2025-06-27 12:20:03,714 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166147
2025-06-27 12:20:03,722 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/702ac55ca034c756_macromedia flash 5.0 full downloader.exe'
2025-06-27 12:20:03,730 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/b9f6ff8392c8039e_gladiator fulldownloader.exe'
2025-06-27 12:20:03,744 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166353
2025-06-27 12:20:03,747 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/b3ced4b674b50d91_cky3 - bam margera world industries alien workshop full downloader.exe'
2025-06-27 12:20:03,754 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166501
2025-06-27 12:20:03,758 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/c5453643f9b6cf93_warcraft 3 online key generator.exe'
2025-06-27 12:20:03,767 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166559
2025-06-27 12:20:03,772 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/949baf7350a6103a_battle.net key generator (works!!).exe'
2025-06-27 12:20:03,782 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166370
2025-06-27 12:20:03,787 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/842c50c176740d93_warcraft 3 battle.net serial generator.exe'
2025-06-27 12:20:03,806 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166362
2025-06-27 12:20:03,809 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/355dffaff75df5c3_how to hack websites.exe'
2025-06-27 12:20:03,823 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166271
2025-06-27 12:20:03,829 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166521
2025-06-27 12:20:03,895 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/e5ba083143c15083_shakira fulldownloader.exe'
2025-06-27 12:20:03,939 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166489
2025-06-27 12:20:03,955 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/b83ce83c49a6f26a_[divx] lord of the rings full downloader.exe'
2025-06-27 12:20:03,976 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166274
2025-06-27 12:20:03,980 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/e82015aae1027245_windows xp full downloader.exe'
2025-06-27 12:20:03,992 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166532
2025-06-27 12:20:03,996 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/456f44784325e557_cat attacks child full downloader.exe'
2025-06-27 12:20:04,009 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166428
2025-06-27 12:20:04,013 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/1a2ce496843bc029_macromedia key generator (all products).exe'
2025-06-27 12:20:04,026 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166376
2025-06-27 12:20:04,030 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/298eb4592a7cd8af_winrar + crack.exe'
2025-06-27 12:20:04,044 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/881f379cbf2651e3_key generator for all windows xp versions.exe'
2025-06-27 12:20:04,053 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166197
2025-06-27 12:20:04,057 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/ba43de39350a15b4_gta3 crack.exe'
2025-06-27 12:20:04,098 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166207
2025-06-27 12:20:04,108 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/7c314cabecca9e4b_sims fulldownloader.exe'
2025-06-27 12:20:04,193 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166487
2025-06-27 12:20:04,201 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/85de1fba3f930def_britney spears nude.exe'
2025-06-27 12:20:04,218 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166222
2025-06-27 12:20:04,228 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/3a9bf9d0e0595272_windows xp key generator.exe'
2025-06-27 12:20:04,247 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166216
2025-06-27 12:20:04,252 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/1038bce92f7d2662_msn password hacker and stealer.exe'
2025-06-27 12:20:04,273 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166469
2025-06-27 12:20:04,283 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/34797127a0519632_hacking tool collection.exe'
2025-06-27 12:20:04,292 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166164
2025-06-27 12:20:04,296 [cuckoo.core.resultserver] DEBUG: Task #6600880: File upload for 'files/a534bbcd3248d82a_aikaquest3hentai fulldownloader.exe'
2025-06-27 12:20:04,313 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166143
2025-06-27 12:20:04,321 [cuckoo.core.resultserver] DEBUG: Task #6600880 uploaded file length: 166587
2025-06-27 12:20:04,412 [cuckoo.core.resultserver] DEBUG: Task #6600880 had connection reset for <Context for LOG>
2025-06-27 12:20:05,793 [cuckoo.core.guest] INFO: win7x649: analysis completed successfully
2025-06-27 12:20:05,808 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-27 12:20:05,836 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-27 12:20:06,987 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x649 to path /srv/cuckoo/cwd/storage/analyses/6600880/memory.dmp
2025-06-27 12:20:07,001 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x649
2025-06-27 12:22:11,326 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.209 for task #6600880
2025-06-27 12:22:11,942 [cuckoo.core.scheduler] DEBUG: Released database task #6600880
2025-06-27 12:22:22,115 [cuckoo.core.scheduler] INFO: Task #6600880: analysis procedure completed

Signatures

Yara rules detected for file (4 events)
description The packer/protector section names/keywords rule suspicious_packer_section
description Run a keylogger rule keylogger
description Affect system registries rule win_registry
description Affect private profile rule win_files_operation
The executable contains unknown PE section names indicative of a packer (could be a false positive) (1 event)
section .imports
The executable uses a known packer (1 event)
packer BobSoft Mini Delphi -> BoB / BobSoft
Creates executable files on the filesystem (50 events)
file C:\Windows\Temp\StarWars2 - CloneAttack - FullDownloader.exe
file C:\Windows\Temp\Microsoft Windows XP crack pack.exe
file C:\Windows\Temp\Star Wars Episode 2 - Attack Of The Clones Full Downloader.exe
file C:\Windows\Temp\LordOfTheRings-FullDownloader.exe
file C:\Windows\Temp\Winzip 8.0 + serial.exe
file C:\Windows\Temp\KaZaA media desktop v2.0 UNOFFICIAL.exe
file C:\Windows\Temp\Microsoft key generator, works for ALL microsoft products!!.exe
file C:\Windows\Temp\Warcraft 3 battle.net serial generator.exe
file C:\Windows\Temp\Xbox.info.exe
file C:\Windows\Temp\Quake 4 BETA.exe
file C:\Windows\Temp\[DiVX] Harry Potter And The Sorcerors Stone Full Downloader.exe
file C:\Windows\Temp\AikaQuest3Hentai FullDownloader.exe
file C:\Windows\Temp\Half-life WON key generator.exe
file C:\Windows\Temp\Cat Attacks Child Full Downloader.exe
file C:\Windows\Temp\Macromedia key generator (all products).exe
file C:\Windows\Temp\Winrar + crack.exe
file C:\Windows\Temp\ZoneAlarm Firewall Full Downloader.exe
file C:\Windows\Temp\Key generator for all windows XP versions.exe
file C:\Windows\Temp\Macromedia Flash 5.0 Full Downloader.exe
file C:\Windows\Temp\Jenna Jameson - Built For Speed Downloader.exe
file C:\Windows\Temp\Britney spears nude.exe
file C:\Windows\Temp\Half-life ONLINE key generator.exe
file C:\Windows\Temp\Battle.net key generator (WORKS!!).exe
file C:\Windows\Temp\DSL Modem Uncapper.exe
file C:\Windows\Temp\Windows XP serial generator.exe
file C:\Windows\Temp\[DiVX] Lord of The Rings Full Downloader.exe
file C:\Windows\Temp\ScaryMovie 2 Full Downloader.exe
file C:\Windows\Temp\Grand theft auto 3 CD1 crack.exe
file C:\Windows\Temp\MoviezChannelsInstaler.exe
file C:\Windows\Temp\AIM Account Stealer Downloader.exe
file C:\Windows\Temp\PS1 Boot Disc Full Dwonloader.exe
file C:\Windows\Temp\Gladiator FullDownloader.exe
file C:\Windows\Temp\CKY3 - Bam Margera World Industries Alien Workshop Full Downloader.exe
file C:\Windows\Temp\SIMS FullDownloader.exe
file C:\Windows\Temp\MSN Password Hacker and Stealer.exe
file C:\Windows\Temp\Hack into any computer!!.exe
file C:\Windows\Temp\Shakira FullDownloader.exe
file C:\Windows\Temp\Sony Play station boot disc - Downloader.exe
file C:\Windows\Temp\Internet and Computer Speed Booster.exe
file C:\Windows\Temp\Windows XP Full Downloader.exe
file C:\Windows\Temp\Star wars episode 2 downloader.exe
file C:\Windows\Temp\Zidane-ScreenInstaler.exe
file C:\Windows\Temp\Warcraft 3 ONLINE key generator.exe
file C:\Windows\Temp\GTA3 crack.exe
file C:\Windows\Temp\DivX.exe
file C:\Windows\Temp\Borland Delphi 6 Key Generator.exe
file C:\Windows\Temp\Windows XP key generator.exe
file C:\Windows\Temp\How To Hack Websites.exe
file C:\Windows\Temp\Hacking Tool Collection.exe
file C:\Windows\Temp\Spiderman FullDownloader.exe
The executable is compressed using UPX (2 events)
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
File has been identified by 14 AntiVirus engine on IRMA as malicious (14 events)
G Data Antivirus (Windows) Virus: Gen:Trojan.P2P-Worm.kqY@ay@Oyrm (Engine A), Win32.Worm.Soltern.A (Engine B)
Avast Core Security (Linux) Win32:Delf-UDU [Trj]
C4S ClamAV (Linux) Win.Worm.Soltern-1
Trend Micro SProtect (Linux) Worm.Win32.SYTRO.SMJT
Trellix (Linux) W32/Sytro.worm.gen
WithSecure (Linux) Worm.WORM/Soltern.oald
eScan Antivirus (Linux) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm(DB)
ESET Security (Windows) a variant of Win32/Soltern.NAA worm
Sophos Anti-Virus (Linux) W32/Systro-J
DrWeb Antivirus (Linux) Win32.HLLW.Sytro
ClamAV (Linux) Win.Worm.Soltern-1
Bitdefender Antivirus (Linux) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm
Kaspersky Standard (Windows) P2P-Worm.Win32.Sytro.j
Emsisoft Commandline Scanner (Windows) Gen:Trojan.P2P-Worm.kqY@ay@Oyrm (B)
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.