Size | 1.4MB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 48641168e26a21f0d19d5bb66ddb9a8c |
SHA1 | 66bb7dcd3b2b4cb43a501e3b4a10627b1f893bd6 |
SHA256 | a61875f6d0d90c8f294084cd9deb949b97c24c838f64ccaadb322c49cd3f0fa6 |
SHA512 |
4cd48a5b51bc7e1b4dca5412fa33a4bfb4e7b063d6ca24b35cd58e3b4f0a41c9b206a4ef98ecaf6a8ab67bbb3da9cc5ec21910132768e7ce78147fc73bea9505
|
CRC32 | AAF2F3DD |
ssdeep | None |
PDB Path | c:\ade\jenkins\workspace\8-2-build-windows-i586-cygwin\jdk8u241\331\build\windows-i586\deploy\jre-image\bin\javaws.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 20, 2025, 11:24 a.m. | July 20, 2025, 11:31 a.m. | 424 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-18 10:00:08,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp2zg5xi 2025-07-18 10:00:08,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\YrzWGvXsJkPBHBKWeWRNOBHHa 2025-07-18 10:00:08,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\wvFFWahcOUdRxUxjlZobiSn 2025-07-18 10:00:08,296 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-18 10:00:08,296 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-18 10:00:08,750 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-18 10:00:08,967 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-07-18 10:00:08,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-18 10:00:08,967 [analyzer] DEBUG: Started auxiliary module Human 2025-07-18 10:00:08,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-18 10:00:08,967 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-18 10:00:09,046 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-18 10:00:09,046 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-18 10:00:09,046 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-18 10:00:09,046 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-18 10:00:09,187 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\a61875f6d0d90c8f294084cd9deb949b97c24c838f64ccaadb322c49cd3f0fa6.exe' with arguments '' and pid 2488 2025-07-18 10:00:09,358 [analyzer] DEBUG: Loaded monitor into process with pid 2488 2025-07-18 10:00:09,421 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Users\Administrator\AppData\Roaming\404f86c4da43eb3b.bin 2025-07-18 10:00:09,453 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 2025-07-18 10:00:09,671 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\alg.exe 2025-07-18 10:00:09,967 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 2025-07-18 10:00:10,375 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 2025-07-18 10:00:10,750 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 2025-07-18 10:00:11,000 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\dllhost.exe 2025-07-18 10:00:11,217 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\ehome\ehrecvr.exe 2025-07-18 10:00:11,562 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\ehome\ehsched.exe 2025-07-18 10:00:11,765 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\FXSSVC.exe 2025-07-18 10:00:12,000 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\ieetwcollector.exe 2025-07-18 10:00:12,203 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 2025-07-18 10:00:12,467 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\msdtc.exe 2025-07-18 10:00:12,937 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\msiexec.exe 2025-07-18 10:00:13,640 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 2025-07-18 10:00:13,875 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\SysWOW64\perfhost.exe 2025-07-18 10:00:14,250 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\Locator.exe 2025-07-18 10:00:14,453 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\snmptrap.exe 2025-07-18 10:00:14,703 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\vds.exe 2025-07-18 10:00:14,967 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\VSSVC.exe 2025-07-18 10:00:15,375 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\wbengine.exe 2025-07-18 10:00:15,640 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Windows\System32\wbem\WmiApSrv.exe 2025-07-18 10:00:15,890 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Windows Media Player\wmpnetwk.exe 2025-07-18 10:00:16,171 [analyzer] INFO: Added new file to list with pid 2488 and path C:\MSOCache\All Users\{90140000-0012-0000-1000-0000000FF1CE}-C\ose.exe 2025-07-18 10:00:16,312 [analyzer] INFO: Added new file to list with pid 2488 and path C:\MSOCache\All Users\{90140000-0012-0000-1000-0000000FF1CE}-C\setup.exe 2025-07-18 10:00:16,546 [analyzer] INFO: Added new file to list with pid 2488 and path C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\DW20.EXE 2025-07-18 10:00:16,671 [analyzer] INFO: Added new file to list with pid 2488 and path C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\dwtrig20.exe 2025-07-18 10:00:17,046 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\jabswitch.exe 2025-07-18 10:00:17,187 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\java-rmi.exe 2025-07-18 10:00:17,328 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\java.exe 2025-07-18 10:00:17,530 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\javacpl.exe 2025-07-18 10:00:17,687 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\javaw.exe 2025-07-18 10:00:17,828 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\javaws.exe 2025-07-18 10:00:18,030 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\jp2launcher.exe 2025-07-18 10:00:18,171 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\keytool.exe 2025-07-18 10:00:18,265 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\kinit.exe 2025-07-18 10:00:18,405 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\klist.exe 2025-07-18 10:00:18,530 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\ktab.exe 2025-07-18 10:00:18,671 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\orbd.exe 2025-07-18 10:00:18,796 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\pack200.exe 2025-07-18 10:00:18,921 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\policytool.exe 2025-07-18 10:00:19,046 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\rmid.exe 2025-07-18 10:00:19,171 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\rmiregistry.exe 2025-07-18 10:00:19,280 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\servertool.exe 2025-07-18 10:00:19,437 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\ssvagent.exe 2025-07-18 10:00:19,578 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\tnameserv.exe 2025-07-18 10:00:19,812 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\Java\jre7\bin\unpack200.exe 2025-07-18 10:00:20,233 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\WinRAR\Ace32Loader.exe 2025-07-18 10:00:20,390 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\WinRAR\Rar.exe 2025-07-18 10:00:20,625 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\WinRAR\Uninstall.exe 2025-07-18 10:00:20,890 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\WinRAR\UnRAR.exe 2025-07-18 10:00:21,030 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files\WinRAR\WinRAR.exe 2025-07-18 10:00:21,203 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\A3DUtility.exe 2025-07-18 10:00:21,342 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroBroker.exe 2025-07-18 10:00:21,515 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe 2025-07-18 10:00:21,717 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32Info.exe 2025-07-18 10:00:21,858 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroTextExtractor.exe 2025-07-18 10:00:21,983 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AdobeCollabSync.exe 2025-07-18 10:00:22,342 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Eula.exe 2025-07-18 10:00:22,687 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe 2025-07-18 10:00:22,937 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Adobe\Reader 9.0\Setup Files\{AC76BA86-7AD7-1033-7B44-A90000000001}\Setup.exe 2025-07-18 10:00:23,140 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Common Files\Adobe\Updater6\AdobeUpdaterInstallMgr.exe 2025-07-18 10:00:23,296 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe 2025-07-18 10:00:23,515 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe 2025-07-18 10:00:23,640 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe 2025-07-18 10:00:23,812 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\airappinstaller.exe 2025-07-18 10:00:23,953 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\template.exe 2025-07-18 10:00:24,187 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Common Files\microsoft shared\TextConv\WksConv\Wkconv.exe 2025-07-18 10:00:24,375 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe 2025-07-18 10:00:24,578 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Globalscape\CuteFTP\cuteftppro.exe 2025-07-18 10:00:24,953 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Globalscape\CuteFTP\ftpte.exe 2025-07-18 10:00:25,171 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Globalscape\CuteFTP\Setup\Disk1\Setup.exe 2025-07-18 10:00:25,312 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\InstallShield Installation Information\{89B9E358-75C6-4C6B-BD38-803FF156CC4B}\Setup.exe 2025-07-18 10:00:25,483 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe 2025-07-18 10:00:25,640 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Firefox\firefox.exe 2025-07-18 10:00:25,842 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe 2025-07-18 10:00:25,983 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe 2025-07-18 10:00:26,125 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2025-07-18 10:00:26,280 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Firefox\updater.exe 2025-07-18 10:00:26,405 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe 2025-07-18 10:00:26,530 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Program Files (x86)\Mozilla Firefox\wow_helper.exe 2025-07-18 10:00:26,812 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\distutils\command\wininst-6.0.exe 2025-07-18 10:00:27,000 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\distutils\command\wininst-7.1.exe 2025-07-18 10:00:27,140 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\distutils\command\wininst-8.0.exe 2025-07-18 10:00:27,296 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\distutils\command\wininst-9.0-amd64.exe 2025-07-18 10:00:27,437 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\distutils\command\wininst-9.0.exe 2025-07-18 10:00:28,078 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\pip\_vendor\distlib\t32.exe 2025-07-18 10:00:28,233 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\pip\_vendor\distlib\t64.exe 2025-07-18 10:00:28,405 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\pip\_vendor\distlib\w32.exe 2025-07-18 10:00:28,578 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\pip\_vendor\distlib\w64.exe 2025-07-18 10:00:29,000 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\setuptools\cli-32.exe 2025-07-18 10:00:29,187 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\setuptools\cli-64.exe 2025-07-18 10:00:29,328 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\setuptools\cli.exe 2025-07-18 10:00:29,515 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\setuptools\gui-32.exe 2025-07-18 10:00:29,655 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\setuptools\gui-64.exe 2025-07-18 10:00:29,796 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\Lib\site-packages\setuptools\gui.exe 2025-07-18 10:00:30,467 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\python.exe 2025-07-18 10:00:30,608 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\RemovePillow.exe 2025-07-18 10:00:31,233 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Python27\w9xpopen.exe 2025-07-18 10:00:31,375 [analyzer] INFO: Added new file to list with pid 2488 and path C:\tmp2zg5xi\bin\7za.exe 2025-07-18 10:00:31,483 [analyzer] INFO: Added new file to list with pid 2488 and path C:\tmp2zg5xi\bin\execsc.exe 2025-07-18 10:00:31,608 [analyzer] INFO: Added new file to list with pid 2488 and path C:\tmp2zg5xi\bin\inject-x64.exe 2025-07-18 10:00:31,796 [analyzer] INFO: Added new file to list with pid 2488 and path C:\tmp2zg5xi\bin\inject-x86.exe 2025-07-18 10:00:31,937 [analyzer] INFO: Added new file to list with pid 2488 and path C:\tmp2zg5xi\bin\is32bit.exe 2025-07-18 10:00:32,125 [analyzer] INFO: Added new file to list with pid 2488 and path C:\tmp2zg5xi\bin\Procmon.exe 2025-07-18 10:00:32,342 [analyzer] INFO: Added new file to list with pid 2488 and path C:\tmp2zg5xi\bin\UnRAR.exe 2025-07-18 10:00:33,078 [analyzer] INFO: Added new file to list with pid 2488 and path \Device\NamedPipe\wkssvc 2025-07-18 10:00:38,187 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-07-18 10:00:38,592 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-18 10:00:38,592 [lib.api.process] INFO: Successfully terminated process with pid 2488. 2025-07-18 10:00:38,608 [analyzer] WARNING: File at path u'c:\\windows\\system32\\fxssvc.exe' does not exist, skip. 2025-07-18 10:00:39,000 [analyzer] WARNING: File at path u'c:\\windows\\system32\\ieetwcollector.exe' does not exist, skip. 2025-07-18 10:00:39,140 [analyzer] WARNING: File at path u'c:\\windows\\system32\\locator.exe' does not exist, skip. 2025-07-18 10:00:39,655 [analyzer] WARNING: Too many files: c:\python27\removepillow.exe 2025-07-18 10:00:39,655 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe\updater6\adobeupdaterinstallmgr.exe 2025-07-18 10:00:39,655 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrord32info.exe 2025-07-18 10:00:39,655 [analyzer] WARNING: File at path u'c:\\windows\\system32\\snmptrap.exe' does not exist, skip. 2025-07-18 10:00:39,671 [analyzer] WARNING: File at path u'c:\\windows\\system32\\alg.exe' does not exist, skip. 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrotextextractor.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\adobe air application installer.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\windows\ehome\ehrecvr.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\tmp2zg5xi\bin\inject-x64.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0012-0000-1000-0000000ff1ce}-c\setup.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\microsoft shared\vsto\10.0\vstoinstaller.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\setuptools\gui-32.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\windows\system32\msiexec.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\a3dutility.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files\winrar\winrar.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dwtrig20.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\tmp2zg5xi\bin\procmon.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\servertool.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\globalscape\cuteftp\setup\disk1\setup.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\globalscape\cuteftp\ftpte.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: File at path u'c:\\windows\\system32\\msdtc.exe' does not exist, skip. 2025-07-18 10:00:39,671 [analyzer] WARNING: File at path u'\\device\\namedpipe\\wkssvc' does not exist, skip. 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\airappinstaller.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\setuptools\cli.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\tmp2zg5xi\bin\is32bit.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\python27\lib\distutils\command\wininst-7.1.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\python27\w9xpopen.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbem\\wmiapsrv.exe' does not exist, skip. 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\rmid.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\msocache\all users\{90140000-0115-0409-1000-0000000ff1ce}-c\dw20.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\roaming\404f86c4da43eb3b.bin 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\adobe air updater.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vds.exe' does not exist, skip. 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files\common files\microsoft shared\source engine\ose.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\javacpl.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\python27\python.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files\winrar\unrar.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vssvc.exe' does not exist, skip. 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe air\versions\1.0\template.exe 2025-07-18 10:00:39,671 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\setup files\{ac76ba86-7ad7-1033-7b44-a90000000001}\setup.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrord32.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\pip\_vendor\distlib\w32.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\orbd.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\webapprt-stub.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\klist.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\windows media player\wmpnetwk.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\plugin-container.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\pip\_vendor\distlib\t32.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\adobe\updater6\adobe_updater.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\python27\lib\distutils\command\wininst-9.0-amd64.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\windows\microsoft.net\framework64\v4.0.30319\aspnet_state.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\maintenanceservice.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\ssvagent.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\acrobroker.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\globalscape\cuteftp\cuteftppro.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\mozilla firefox\wow_helper.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbengine.exe' does not exist, skip. 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\python27\lib\distutils\command\wininst-6.0.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\winrar\uninstall.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files (x86)\common files\microsoft shared\textconv\wksconv\wkconv.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\winrar\rar.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\windows\ehome\ehsched.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\windows\system32\dllhost.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\pack200.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\python27\lib\distutils\command\wininst-8.0.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\jp2launcher.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\setuptools\gui.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\jabswitch.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\tnameserv.exe 2025-07-18 10:00:39,687 [analyzer] WARNING: Too many files: c:\tmp2zg5xi\bin\inject-x86.exe 2025-07-18 10:00:39,703 [analyzer] WARNING: Too many files: c:\program files (x86)\adobe\reader 9.0\reader\eula.exe 2025-07-18 10:00:39,703 [analyzer] WARNING: Too many files: c:\program files\java\jre7\bin\policytool.exe 2025-07-18 10:00:39,703 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\setuptools\cli-32.exe 2025-07-18 10:00:39,703 [analyzer] WARNING: Too many files: c:\tmp2zg5xi\bin\execsc.exe 2025-07-18 10:00:39,703 [analyzer] WARNING: Too many files: c:\python27\lib\site-packages\setuptools\gui-64.exe 2025-07-18 10:00:39,703 [analyzer] INFO: Analysis completed.
2025-07-20 11:24:31,990 [cuckoo.core.scheduler] INFO: Task #6746581: acquired machine win7x6410 (label=win7x6410) 2025-07-20 11:24:31,991 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.210 for task #6746581 2025-07-20 11:24:32,590 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2850583 (interface=vboxnet0, host=192.168.168.210) 2025-07-20 11:24:33,890 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6410 2025-07-20 11:24:35,061 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6410 to vmcloak 2025-07-20 11:28:03,417 [cuckoo.core.guest] INFO: Starting analysis #6746581 on guest (id=win7x6410, ip=192.168.168.210) 2025-07-20 11:28:04,422 [cuckoo.core.guest] DEBUG: win7x6410: not ready yet 2025-07-20 11:28:09,445 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6410, ip=192.168.168.210) 2025-07-20 11:28:09,592 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6410, ip=192.168.168.210, monitor=latest, size=6660546) 2025-07-20 11:28:11,034 [cuckoo.core.resultserver] DEBUG: Task #6746581: live log analysis.log initialized. 2025-07-20 11:28:11,952 [cuckoo.core.resultserver] DEBUG: Task #6746581 is sending a BSON stream 2025-07-20 11:28:12,327 [cuckoo.core.resultserver] DEBUG: Task #6746581 is sending a BSON stream 2025-07-20 11:28:13,216 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'shots/0001.jpg' 2025-07-20 11:28:13,270 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 135783 2025-07-20 11:28:25,978 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6746581 still processing 2025-07-20 11:28:41,069 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6746581 still processing 2025-07-20 11:28:41,413 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'curtain/1752825638.36.curtain.log' 2025-07-20 11:28:41,416 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 36 2025-07-20 11:28:41,625 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'sysmon/1752825638.58.sysmon.xml' 2025-07-20 11:28:41,637 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1720850 2025-07-20 11:28:41,648 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/216c683717d22017_w64.exe' 2025-07-20 11:28:41,659 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1223680 2025-07-20 11:28:41,674 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/fa5194f1baa0198b_javaws.exe' 2025-07-20 11:28:41,692 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1440768 2025-07-20 11:28:41,705 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/750bb023df665d75_setup.exe' 2025-07-20 11:28:41,715 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1184256 2025-07-20 11:28:41,728 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/4875c746942af3b2_unpack200.exe' 2025-07-20 11:28:41,752 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1303552 2025-07-20 11:28:41,774 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/15b737100752cea1_rmiregistry.exe' 2025-07-20 11:28:41,818 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1139712 2025-07-20 11:28:41,824 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/1a6fbafb774e4251_firefox.exe' 2025-07-20 11:28:41,839 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1498112 2025-07-20 11:28:41,854 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/70b58874173b7179_wininst-9.0.exe' 2025-07-20 11:28:41,865 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1325568 2025-07-20 11:28:41,877 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/2f076c54606600cf_java-rmi.exe' 2025-07-20 11:28:41,884 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1139712 2025-07-20 11:28:41,899 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/609825433eb12c21_unrar.exe' 2025-07-20 11:28:41,911 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1500672 2025-07-20 11:28:41,924 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/b9e4774c5166b408_reader_sl.exe' 2025-07-20 11:28:41,933 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1158144 2025-07-20 11:28:41,945 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/50faee883a1de595_ktab.exe' 2025-07-20 11:28:41,953 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1139712 2025-07-20 11:28:41,965 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/eb07ed4ec9186067_7za.exe' 2025-07-20 11:28:41,974 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1318912 2025-07-20 11:28:41,989 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/2271158bc7025416_javaw.exe' 2025-07-20 11:28:41,999 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1311744 2025-07-20 11:28:42,011 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/b0478637cb690e2f_updater.exe' 2025-07-20 11:28:42,023 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1419776 2025-07-20 11:28:42,035 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/172e7e5e3aefc042_java.exe' 2025-07-20 11:28:42,044 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1311744 2025-07-20 11:28:42,058 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/ddfd158bfec508d1_plugin-hang-ui.exe' 2025-07-20 11:28:42,066 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1292288 2025-07-20 11:28:42,076 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/5159631fc91cd2a8_kinit.exe' 2025-07-20 11:28:42,085 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1139712 2025-07-20 11:28:42,098 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/5735b2efaf0ec468_crashreporter.exe' 2025-07-20 11:28:42,113 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1404416 2025-07-20 11:28:42,125 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/0375be84175e106e_ose.exe' 2025-07-20 11:28:42,134 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1297408 2025-07-20 11:28:42,146 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/41e2177796a61d68_ace32loader.exe' 2025-07-20 11:28:42,155 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1184768 2025-07-20 11:28:42,176 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/2f0a9abbf7eeb748_adobecollabsync.exe' 2025-07-20 11:28:42,191 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1667072 2025-07-20 11:28:42,223 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/9a2fc55fdf462503_keytool.exe' 2025-07-20 11:28:42,234 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1139712 2025-07-20 11:28:42,410 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/cffb306ffdc48b54_t64.exe' 2025-07-20 11:28:42,649 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1227264 2025-07-20 11:28:42,663 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/40fc1257755d44a3_perfhost.exe' 2025-07-20 11:28:42,686 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1150464 2025-07-20 11:28:42,702 [cuckoo.core.resultserver] DEBUG: Task #6746581: File upload for 'files/b92090211aa0242d_cli-64.exe' 2025-07-20 11:28:42,711 [cuckoo.core.resultserver] DEBUG: Task #6746581 uploaded file length: 1202688 2025-07-20 11:28:42,768 [cuckoo.core.resultserver] DEBUG: Task #6746581 had connection reset for <Context for LOG> 2025-07-20 11:28:44,166 [cuckoo.core.guest] INFO: win7x6410: analysis completed successfully 2025-07-20 11:28:44,189 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-20 11:28:44,224 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-20 11:28:46,157 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6410 to path /srv/cuckoo/cwd/storage/analyses/6746581/memory.dmp 2025-07-20 11:28:46,163 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6410 2025-07-20 11:31:35,779 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.210 for task #6746581 2025-07-20 11:31:36,339 [cuckoo.core.scheduler] DEBUG: Released database task #6746581 2025-07-20 11:31:36,369 [cuckoo.core.scheduler] INFO: Task #6746581: analysis procedure completed
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Escalade priviledges | rule | escalate_priv | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect system token | rule | win_token | ||||||
description | Affect private profile | rule | win_files_operation |