Size | 122.8KB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 217a2abd1327aff95ef9d28ab53924fd |
SHA1 | 93421c816acfc2e365aa7170538b299e07de826d |
SHA256 | a70b987be9a848c7d33001a4a9933642fbd47ed8626d55f83351f26bcd0f1389 |
SHA512 |
2d167aa377952a612c87f96d7bc96a973a565c55eff60342f938c06b13a9a94171a1ac94ab25b22c9227a60b684f22dafe7eb70d72e25eeb9639eec3f1464ea5
|
CRC32 | 49A574D5 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 7, 2025, 2:55 p.m. | July 7, 2025, 3:01 p.m. | 362 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-07 10:05:24,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpblqbwr 2025-07-07 10:05:24,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\sHQAISIliyLzJnFzTtxcUXSZrsRjpF 2025-07-07 10:05:24,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\fDhWwAGQNAOGxFpSROuJEzbQZeZU 2025-07-07 10:05:24,312 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-07 10:05:24,312 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-07 10:05:24,812 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-07 10:05:25,030 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-07-07 10:05:25,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-07 10:05:25,030 [analyzer] DEBUG: Started auxiliary module Human 2025-07-07 10:05:25,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-07 10:05:25,030 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-07 10:05:25,125 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-07 10:05:25,125 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-07 10:05:25,125 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-07 10:05:25,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-07 10:05:25,312 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\a70b987be9a848c7d33001a4a9933642fbd47ed8626d55f83351f26bcd0f1389.exe' with arguments '' and pid 2492 2025-07-07 10:05:25,500 [analyzer] DEBUG: Loaded monitor into process with pid 2492 2025-07-07 10:05:25,562 [analyzer] INFO: Added new file to list with pid 2492 and path C:\Users\Administrator\AppData\Local\Temp\backup.exe 2025-07-07 10:05:25,578 [analyzer] INFO: Added new file to list with pid 2492 and path C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe 2025-07-07 10:05:25,640 [analyzer] INFO: Injected into process with pid 2356 and name '' 2025-07-07 10:05:25,812 [analyzer] DEBUG: Loaded monitor into process with pid 2356 2025-07-07 10:05:25,890 [analyzer] INFO: Added new file to list with pid 2492 and path C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe 2025-07-07 10:05:25,967 [analyzer] INFO: Added new file to list with pid 2492 and path C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe 2025-07-07 10:05:26,858 [analyzer] INFO: Added new file to list with pid 2356 and path C:\backup.exe 2025-07-07 13:58:49,549 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-07-07 13:58:50,017 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-07 13:58:50,017 [lib.api.process] INFO: Successfully terminated process with pid 2492. 2025-07-07 13:58:50,017 [lib.api.process] INFO: Successfully terminated process with pid 2356. 2025-07-07 13:58:50,065 [analyzer] INFO: Analysis completed.
2025-07-07 14:55:24,732 [cuckoo.core.scheduler] DEBUG: Task #6660511: no machine available yet 2025-07-07 14:55:25,771 [cuckoo.core.scheduler] DEBUG: Task #6660511: no machine available yet 2025-07-07 14:55:27,007 [cuckoo.core.scheduler] DEBUG: Task #6660511: no machine available yet 2025-07-07 14:55:28,291 [cuckoo.core.scheduler] DEBUG: Task #6660511: no machine available yet 2025-07-07 14:55:29,553 [cuckoo.core.scheduler] INFO: Task #6660511: acquired machine win7x6418 (label=win7x6418) 2025-07-07 14:55:29,556 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.218 for task #6660511 2025-07-07 14:55:30,332 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2191685 (interface=vboxnet0, host=192.168.168.218) 2025-07-07 14:55:30,587 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6418 2025-07-07 14:55:31,609 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6418 to vmcloak 2025-07-07 14:58:11,813 [cuckoo.core.guest] INFO: Starting analysis #6660511 on guest (id=win7x6418, ip=192.168.168.218) 2025-07-07 14:58:12,819 [cuckoo.core.guest] DEBUG: win7x6418: not ready yet 2025-07-07 14:58:17,842 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6418, ip=192.168.168.218) 2025-07-07 14:58:17,924 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6418, ip=192.168.168.218, monitor=latest, size=6660546) 2025-07-07 14:58:19,233 [cuckoo.core.resultserver] DEBUG: Task #6660511: live log analysis.log initialized. 2025-07-07 14:58:20,461 [cuckoo.core.resultserver] DEBUG: Task #6660511 is sending a BSON stream 2025-07-07 14:58:20,736 [cuckoo.core.resultserver] DEBUG: Task #6660511 is sending a BSON stream 2025-07-07 14:58:20,974 [cuckoo.core.resultserver] DEBUG: Task #6660511 is sending a BSON stream 2025-07-07 14:58:21,480 [cuckoo.core.resultserver] DEBUG: Task #6660511: File upload for 'shots/0001.jpg' 2025-07-07 14:58:21,499 [cuckoo.core.resultserver] DEBUG: Task #6660511 uploaded file length: 133464 2025-07-07 14:58:34,078 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6660511 still processing 2025-07-07 14:58:49,765 [cuckoo.core.resultserver] DEBUG: Task #6660511: File upload for 'curtain/1751889529.75.curtain.log' 2025-07-07 14:58:49,767 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6660511 still processing 2025-07-07 14:58:49,769 [cuckoo.core.resultserver] DEBUG: Task #6660511 uploaded file length: 36 2025-07-07 14:58:49,982 [cuckoo.core.resultserver] DEBUG: Task #6660511: File upload for 'sysmon/1751889529.97.sysmon.xml' 2025-07-07 14:58:50,027 [cuckoo.core.resultserver] DEBUG: Task #6660511 uploaded file length: 2188720 2025-07-07 14:58:50,046 [cuckoo.core.resultserver] DEBUG: Task #6660511: File upload for 'files/7942290d8a21f653_backup.exe' 2025-07-07 14:58:50,062 [cuckoo.core.resultserver] DEBUG: Task #6660511 uploaded file length: 125752 2025-07-07 14:58:50,066 [cuckoo.core.resultserver] DEBUG: Task #6660511: File upload for 'files/b741e4a368b0db29_backup.exe' 2025-07-07 14:58:50,070 [cuckoo.core.resultserver] DEBUG: Task #6660511 uploaded file length: 125754 2025-07-07 14:58:50,096 [cuckoo.core.resultserver] DEBUG: Task #6660511 had connection reset for <Context for LOG> 2025-07-07 14:58:52,788 [cuckoo.core.guest] INFO: win7x6418: analysis completed successfully 2025-07-07 14:58:52,809 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-07 14:58:52,839 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-07 14:58:54,615 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6418 to path /srv/cuckoo/cwd/storage/analyses/6660511/memory.dmp 2025-07-07 14:58:54,625 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6418 2025-07-07 15:01:26,652 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.218 for task #6660511 2025-07-07 15:01:27,054 [cuckoo.core.scheduler] DEBUG: Released database task #6660511 2025-07-07 15:01:27,078 [cuckoo.core.scheduler] INFO: Task #6660511: analysis procedure completed
description | The packer/protector section names/keywords | rule | suspicious_packer_section |
file | C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe |
file | C:\backup.exe |
file | C:\Users\Administrator\AppData\Local\Temp\backup.exe |
file | C:\Users\Administrator\AppData\Local\Temp\9C7EA51D-B2B9-4ABB-A82F-1B32707A146E\backup.exe |
file | C:\Users\Administrator\AppData\Local\Temp\hsperfdata_Administrator\backup.exe |
file | C:\Users\Administrator\AppData\Local\Temp\0C7910BA-F902-421E-9E69-CF9AEE0DD4D7\backup.exe |
section | {u'size_of_data': u'0x00003e00', u'virtual_address': u'0x00011000', u'entropy': 7.804677160000422, u'name': u'.pdata', u'virtual_size': u'0x00004000'} | entropy | 7.80467716 | description | A section with a high entropy has been found | |||||||||
entropy | 0.260504201681 | description | Overall entropy of this PE file is high |
G Data Antivirus (Windows) | Virus: Trojan.GenericKD.76484443 (Engine A), Win32.Trojan.Vilsel.B (Engine B) |
Avast Core Security (Linux) | Win32:Evo-gen [Trj] |
C4S ClamAV (Linux) | Win.Malware.Genpack-6989317-0 |
Trellix (Linux) | Generic VB.z trojan |
WithSecure (Linux) | Trojan.TR/Crypt.ULPM.Gen |
eScan Antivirus (Linux) | Trojan.GenericKD.76484443(DB) |
ESET Security (Windows) | Win32/VB.OZA trojan |
Sophos Anti-Virus (Linux) | Troj/VB-LET |
DrWeb Antivirus (Linux) | Trojan.Copyself.102 |
ClamAV (Linux) | Win.Malware.Genpack-6989317-0 |
Bitdefender Antivirus (Linux) | Trojan.GenericKD.76484443 |
Kaspersky Standard (Windows) | Trojan.Win32.Vilsel.loy |
Emsisoft Commandline Scanner (Windows) | Trojan.GenericKD.76484443 (B) |