Size | 49.9KB |
---|---|
Type | MS-DOS executable PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows, MZ for MS-DOS |
MD5 | 0d557f7ff8f404264023d22a2ec50184 |
SHA1 | 7d683fad3fecaef3208badaa33627a94eba7604f |
SHA256 | ed7e7bbb460ee49bbad099e110f4d90d6b31e1bfeaf37337e6a49dd6c185e9e2 |
SHA512 |
4f6d2e175d0e909c7155d6251f9846b79db6c8adbbd4144bba3bd16f4cea0b3f20426bdb1eb5ca8a7711b4b6172c24944af0d33df070eee248f8d23b444b956c
|
CRC32 | F55C26D4 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 9.1 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 16, 2025, 6:18 p.m. | July 16, 2025, 6:19 p.m. | 73 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-16 18:18:19,078 [analyzer] DEBUG: Starting analyzer from: C:\tmpht3fil 2025-07-16 18:18:19,078 [analyzer] DEBUG: Pipe server name: \??\PIPE\ldgxqyXdfuAdZzRTPrScUQDOon 2025-07-16 18:18:19,078 [analyzer] DEBUG: Log pipe server name: \??\PIPE\RAmydIWKPBpkIXIXxgJpZhMHQBbCj 2025-07-16 18:18:19,390 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-16 18:18:19,390 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-16 18:18:19,890 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-16 18:18:20,125 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-07-16 18:18:20,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-16 18:18:20,125 [analyzer] DEBUG: Started auxiliary module Human 2025-07-16 18:18:20,125 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-16 18:18:20,125 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-16 18:18:20,233 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-16 18:18:20,233 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-16 18:18:20,233 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-16 18:18:20,233 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-16 18:18:20,375 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\Us.exe' with arguments '' and pid 2156 2025-07-16 18:18:20,655 [analyzer] DEBUG: Loaded monitor into process with pid 2156 2025-07-16 17:19:26,209 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-07-16 17:19:26,522 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2156. 2025-07-16 17:19:26,802 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-16 17:19:26,802 [lib.api.process] INFO: Successfully terminated process with pid 2156. 2025-07-16 17:19:26,802 [analyzer] INFO: Analysis completed.
2025-07-16 18:18:35,194 [cuckoo.core.scheduler] INFO: Task #6736543: acquired machine win7x6411 (label=win7x6411) 2025-07-16 18:18:35,195 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.211 for task #6736543 2025-07-16 18:18:35,807 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2677421 (interface=vboxnet0, host=192.168.168.211) 2025-07-16 18:18:35,881 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6411 2025-07-16 18:18:37,098 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6411 to vmcloak 2025-07-16 18:18:48,288 [cuckoo.core.guest] INFO: Starting analysis #6736543 on guest (id=win7x6411, ip=192.168.168.211) 2025-07-16 18:18:49,295 [cuckoo.core.guest] DEBUG: win7x6411: not ready yet 2025-07-16 18:18:54,329 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6411, ip=192.168.168.211) 2025-07-16 18:18:54,405 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6411, ip=192.168.168.211, monitor=latest, size=6660546) 2025-07-16 18:18:55,827 [cuckoo.core.resultserver] DEBUG: Task #6736543: live log analysis.log initialized. 2025-07-16 18:18:56,901 [cuckoo.core.resultserver] DEBUG: Task #6736543 is sending a BSON stream 2025-07-16 18:18:57,338 [cuckoo.core.resultserver] DEBUG: Task #6736543 is sending a BSON stream 2025-07-16 18:18:58,175 [cuckoo.core.resultserver] DEBUG: Task #6736543: File upload for 'shots/0001.jpg' 2025-07-16 18:18:58,188 [cuckoo.core.resultserver] DEBUG: Task #6736543 uploaded file length: 113769 2025-07-16 18:19:06,525 [cuckoo.core.resultserver] DEBUG: Task #6736543: File upload for 'shots/0002.jpg' 2025-07-16 18:19:06,540 [cuckoo.core.resultserver] DEBUG: Task #6736543 uploaded file length: 133479 2025-07-16 18:19:10,825 [cuckoo.core.guest] DEBUG: win7x6411: analysis #6736543 still processing 2025-07-16 18:19:25,938 [cuckoo.core.guest] DEBUG: win7x6411: analysis #6736543 still processing 2025-07-16 18:19:26,830 [cuckoo.core.resultserver] DEBUG: Task #6736543: File upload for 'curtain/1752679166.66.curtain.log' 2025-07-16 18:19:26,833 [cuckoo.core.resultserver] DEBUG: Task #6736543 uploaded file length: 36 2025-07-16 18:19:26,835 [cuckoo.core.resultserver] DEBUG: Task #6736543: File upload for 'sysmon/1752679166.8.sysmon.xml' 2025-07-16 18:19:26,841 [cuckoo.core.resultserver] DEBUG: Task #6736543 uploaded file length: 654880 2025-07-16 18:19:27,217 [cuckoo.core.resultserver] DEBUG: Task #6736543 had connection reset for <Context for LOG> 2025-07-16 18:19:28,963 [cuckoo.core.guest] INFO: win7x6411: analysis completed successfully 2025-07-16 18:19:28,986 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-16 18:19:29,020 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-16 18:19:30,454 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6411 to path /srv/cuckoo/cwd/storage/analyses/6736543/memory.dmp 2025-07-16 18:19:30,455 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6411 2025-07-16 18:19:47,873 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.211 for task #6736543 2025-07-16 18:19:48,270 [cuckoo.core.scheduler] DEBUG: Released database task #6736543 2025-07-16 18:19:48,287 [cuckoo.core.scheduler] INFO: Task #6736543: analysis procedure completed
G Data Antivirus (Windows) | Virus: IL:Trojan.MSILZilla.5023 (Engine A) |
Avast Core Security (Linux) | Win32:UnwantedX-gen [PUP] |
WithSecure (Linux) | Trojan.TR/Dropper.Gen |
eScan Antivirus (Linux) | IL:Trojan.MSILZilla.5023(DB) |
ESET Security (Windows) | a variant of MSIL/Injector.VVX trojan |
DrWeb Antivirus (Linux) | Trojan.PWS.Stealer.32288 |
Bitdefender Antivirus (Linux) | IL:Trojan.MSILZilla.5023 |
Kaspersky Standard (Windows) | Trojan-PSW.MSIL.Reline.ldt |
Emsisoft Commandline Scanner (Windows) | IL:Trojan.MSILZilla.5023 (B) |