Size | 236.0KB |
---|---|
Type | PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
MD5 | b506339076d02ac6cede792b285c0bd2 |
SHA1 | 07071d6d2714b670f7f5310eee9152d858ea16fc |
SHA256 | d8f6c5fdaa8a0b7ac2c7a833a3de26b2c15938b5618302eb4fd8fcc8bf83d53b |
SHA512 |
86e84968e27cbb8269aeedfb311dd7538f70107fb34975c603c947755cc71e2f9276fa778acbe2c6c1a526ed1704fc6b1aee4f0fcc6717169ad3bc31185e076f
|
CRC32 | 662D74BA |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 23, 2025, 10:48 a.m. | July 23, 2025, 10:52 a.m. | 289 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-23 07:39:42,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpwoh6zt 2025-07-23 07:39:42,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\kpUkKAcGHDXzLPTBHuCLmIyQLXfBFna 2025-07-23 07:39:42,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\QyjTKGdTRmSzzvfeQJpJKtzdCbe 2025-07-23 07:39:42,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-07-23 07:39:42,015 [analyzer] INFO: Automatically selected analysis package "exe" 2025-07-23 07:39:42,375 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-23 07:39:42,375 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-23 07:39:42,890 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-23 07:39:43,108 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-07-23 07:39:43,108 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-23 07:39:43,108 [analyzer] DEBUG: Started auxiliary module Human 2025-07-23 07:39:43,108 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-23 07:39:43,108 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-23 07:39:43,203 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-23 07:39:43,203 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-23 07:39:43,203 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-23 07:39:43,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-23 07:39:43,375 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d8f6c5fdaa8a0b7a_rifaien2-e5p7yFEGH5xCVMgX.exe' with arguments '' and pid 1940 2025-07-23 07:39:43,608 [analyzer] DEBUG: Loaded monitor into process with pid 1940 2025-07-23 07:39:43,625 [analyzer] INFO: Added new file to list with pid 1940 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-2rTUj1UapRERNS2F.exe 2025-07-23 09:49:14,904 [analyzer] INFO: Added new file to list with pid 1940 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-TcXmhRIsQkYZYqlH.exe 2025-07-23 09:49:45,184 [analyzer] INFO: Added new file to list with pid 1940 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-7SLy5U1l15U9YQCB.exe 2025-07-23 09:50:15,263 [analyzer] INFO: Added new file to list with pid 1940 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-H5dCk5pzORYyoR9s.exe 2025-07-23 09:50:45,357 [analyzer] INFO: Added new file to list with pid 1940 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-HlSiH6ulvLOt2oud.exe 2025-07-23 09:51:15,450 [analyzer] INFO: Added new file to list with pid 1940 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-aF1UVmoFxSrIBYP8.exe 2025-07-23 09:51:45,607 [analyzer] INFO: Added new file to list with pid 1940 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-IxfjZjwvfr13hYHD.exe 2025-07-23 09:52:03,466 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-07-23 09:52:04,575 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-23 09:52:04,575 [lib.api.process] INFO: Successfully terminated process with pid 1940. 2025-07-23 09:52:04,575 [analyzer] INFO: Analysis completed.
2025-07-23 10:48:01,922 [cuckoo.core.scheduler] INFO: Task #6755766: acquired machine win7x643 (label=win7x643) 2025-07-23 10:48:01,924 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.203 for task #6755766 2025-07-23 10:48:02,450 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2429185 (interface=vboxnet0, host=192.168.168.203) 2025-07-23 10:48:02,709 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x643 2025-07-23 10:48:04,002 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x643 to vmcloak 2025-07-23 10:48:35,590 [cuckoo.core.guest] INFO: Starting analysis #6755766 on guest (id=win7x643, ip=192.168.168.203) 2025-07-23 10:48:36,596 [cuckoo.core.guest] DEBUG: win7x643: not ready yet 2025-07-23 10:48:41,639 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x643, ip=192.168.168.203) 2025-07-23 10:48:41,745 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x643, ip=192.168.168.203, monitor=latest, size=6660546) 2025-07-23 10:48:43,245 [cuckoo.core.resultserver] DEBUG: Task #6755766: live log analysis.log initialized. 2025-07-23 10:48:44,978 [cuckoo.core.resultserver] DEBUG: Task #6755766 is sending a BSON stream 2025-07-23 10:48:45,223 [cuckoo.core.resultserver] DEBUG: Task #6755766 is sending a BSON stream 2025-07-23 10:48:45,224 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'files/6c08f99c1ad73100_rifaien2-2rTUj1UapRERNS2F.exe' 2025-07-23 10:48:45,257 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 241664 2025-07-23 10:48:45,504 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'shots/0001.jpg' 2025-07-23 10:48:45,579 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 158166 2025-07-23 10:48:57,890 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:49:13,037 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:49:15,714 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'files/125145fbac261ae1_rifaien2-TcXmhRIsQkYZYqlH.exe' 2025-07-23 10:49:15,752 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'shots/0002.jpg' 2025-07-23 10:49:15,797 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 241664 2025-07-23 10:49:15,910 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 158882 2025-07-23 10:49:28,783 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:49:44,096 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:49:45,264 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'files/30ec0d1b4efa4b2b_rifaien2-7SLy5U1l15U9YQCB.exe' 2025-07-23 10:49:45,463 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 241664 2025-07-23 10:49:45,668 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'shots/0003.jpg' 2025-07-23 10:49:45,695 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 158213 2025-07-23 10:49:59,361 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:50:14,508 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:50:15,360 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'files/1ec7abad929875fd_rifaien2-H5dCk5pzORYyoR9s.exe' 2025-07-23 10:50:15,365 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 241664 2025-07-23 10:50:15,675 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'shots/0004.jpg' 2025-07-23 10:50:15,690 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 158835 2025-07-23 10:50:29,649 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:50:44,886 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:50:45,461 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'files/8ceb7905617a8d49_rifaien2-HlSiH6ulvLOt2oud.exe' 2025-07-23 10:50:45,466 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 241664 2025-07-23 10:50:45,646 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'shots/0005.jpg' 2025-07-23 10:50:45,676 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 158122 2025-07-23 10:50:59,988 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:51:15,416 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:51:15,603 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'shots/0006.jpg' 2025-07-23 10:51:15,612 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'files/820e47e1ba5f65b9_rifaien2-aF1UVmoFxSrIBYP8.exe' 2025-07-23 10:51:15,626 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 241664 2025-07-23 10:51:15,640 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 158970 2025-07-23 10:51:16,948 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'shots/0007.jpg' 2025-07-23 10:51:17,391 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 158870 2025-07-23 10:51:30,575 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:51:45,684 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'files/583d3210dbc47fbf_rifaien2-IxfjZjwvfr13hYHD.exe' 2025-07-23 10:51:45,701 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 241664 2025-07-23 10:51:45,703 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:51:45,851 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'shots/0008.jpg' 2025-07-23 10:51:45,869 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 158033 2025-07-23 10:52:01,016 [cuckoo.core.guest] DEBUG: win7x643: analysis #6755766 still processing 2025-07-23 10:52:03,672 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'curtain/1753257123.65.curtain.log' 2025-07-23 10:52:03,778 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 36 2025-07-23 10:52:04,454 [cuckoo.core.resultserver] DEBUG: Task #6755766: File upload for 'sysmon/1753257124.36.sysmon.xml' 2025-07-23 10:52:04,580 [cuckoo.core.resultserver] DEBUG: Task #6755766 uploaded file length: 8782086 2025-07-23 10:52:04,615 [cuckoo.core.resultserver] DEBUG: Task #6755766 had connection reset for <Context for LOG> 2025-07-23 10:52:07,046 [cuckoo.core.guest] INFO: win7x643: analysis completed successfully 2025-07-23 10:52:07,266 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-23 10:52:07,294 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-23 10:52:09,153 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x643 to path /srv/cuckoo/cwd/storage/analyses/6755766/memory.dmp 2025-07-23 10:52:09,155 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x643 2025-07-23 10:52:50,499 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.203 for task #6755766 2025-07-23 10:52:50,934 [cuckoo.core.scheduler] DEBUG: Released database task #6755766 2025-07-23 10:52:50,952 [cuckoo.core.scheduler] INFO: Task #6755766: analysis procedure completed
description | (no description) | rule | UPX | ||||||
description | The packer/protector section names/keywords | rule | suspicious_packer_section | ||||||
description | Listen for incoming communication | rule | network_tcp_listen | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Communications use DNS | rule | network_dns |
description | d8f6c5fdaa8a0b7a_rifaien2-e5p7yFEGH5xCVMgX.exe tried to sleep 210 seconds, actually delayed analysis time by 180 seconds |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-TcXmhRIsQkYZYqlH.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-IxfjZjwvfr13hYHD.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-H5dCk5pzORYyoR9s.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-HlSiH6ulvLOt2oud.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-2rTUj1UapRERNS2F.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-7SLy5U1l15U9YQCB.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-aF1UVmoFxSrIBYP8.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-2rTUj1UapRERNS2F.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-TcXmhRIsQkYZYqlH.exe |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX | ||||||
section | UPX2 | description | Section name indicates UPX |
buffer | Buffer with sha1: 60e98cc8f1d32de70b4207208d06f95d5329fca8 |
suricata | ETPRO MALWARE Win32/Snojan Variant Uploading EXE |
suricata | ET INFO Generic HTTP EXE Upload Outbound |
G Data Antivirus (Windows) | Virus: Trojan.Agent.CYZT (Engine A) |
Avast Core Security (Linux) | Win32:Banker-LAA [Trj] |
C4S ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
WithSecure (Linux) | Trojan.TR/Agent.qasng |
eScan Antivirus (Linux) | Trojan.Agent.CYZT(DB) |
ESET Security (Windows) | a variant of Win32/Agent.AAEF trojan |
Sophos Anti-Virus (Linux) | Troj/Bdoor-BHD |
ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
Bitdefender Antivirus (Linux) | Trojan.Agent.CYZT |
Kaspersky Standard (Windows) | HEUR:Flooder.Win32.CoreWarrior.a |
Emsisoft Commandline Scanner (Windows) | Trojan.Agent.CYZT (B) |