Size | 1.2MB |
---|---|
Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | 8f910c60acc0e4ca98800858c8e545d2 |
SHA1 | 07e185936ddbd2cb25b556f03d0cae991352f6d4 |
SHA256 | 216c683717d220178b4f2ff178398080efec0abbd62ea7cf8012a9124a0c3c8f |
SHA512 |
958447d66e944dbce0adbf825d58689e64d65b36c970f907b1181e6b6d800dd88d2658f91d400a0a1a81c94149571372f0bbc9b1c8aa258634a3b27e7ee78a71
|
CRC32 | 152A54A8 |
ssdeep | None |
PDB Path | C:\Users\Vinay\Projects\simple_launcher\x64\Release\GUISimpleLauncher.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 23, 2025, 10:48 a.m. | July 23, 2025, 10:50 a.m. | 86 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-23 07:39:45,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp2pjrvv 2025-07-23 07:39:45,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\YRzxInYVxRXBHmMdBHHV 2025-07-23 07:39:45,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\fkoHkeJFtoTOcpjaNDgbbg 2025-07-23 07:39:45,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-07-23 07:39:45,030 [analyzer] INFO: Automatically selected analysis package "exe" 2025-07-23 07:39:45,421 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-23 07:39:45,421 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-23 07:39:45,890 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-23 07:39:46,092 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-07-23 07:39:46,092 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-23 07:39:46,092 [analyzer] DEBUG: Started auxiliary module Human 2025-07-23 07:39:46,092 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-23 07:39:46,092 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-23 07:39:46,155 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-23 07:39:46,155 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-23 07:39:46,171 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-23 07:39:46,171 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-23 07:39:46,296 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\216c683717d22017_w64.exe' with arguments '' and pid 856 2025-07-23 07:39:46,500 [analyzer] DEBUG: Loaded monitor into process with pid 856 2025-07-23 07:39:48,265 [analyzer] INFO: Added new file to list with pid 856 and path C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 2025-07-23 07:39:48,750 [analyzer] INFO: Added new file to list with pid 856 and path C:\Windows\System32\alg.exe 2025-07-23 07:39:49,405 [analyzer] INFO: Added new file to list with pid 856 and path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 2025-07-23 07:39:50,015 [analyzer] INFO: Added new file to list with pid 856 and path C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 2025-07-23 07:39:50,655 [analyzer] INFO: Added new file to list with pid 856 and path C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 2025-07-23 07:39:51,140 [analyzer] INFO: Added new file to list with pid 856 and path C:\Windows\System32\dllhost.exe 2025-07-23 07:39:51,296 [analyzer] INFO: Process with pid 856 has terminated 2025-07-23 07:39:51,296 [analyzer] INFO: Process list is empty, terminating analysis. 2025-07-23 07:39:52,562 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-23 07:39:54,796 [analyzer] WARNING: File at path u'c:\\windows\\system32\\alg.exe' does not exist, skip. 2025-07-23 07:39:54,796 [analyzer] INFO: Analysis completed.
2025-07-23 10:48:36,071 [cuckoo.core.scheduler] INFO: Task #6755768: acquired machine win7x648 (label=win7x648) 2025-07-23 10:48:36,072 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.208 for task #6755768 2025-07-23 10:48:36,628 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2430647 (interface=vboxnet0, host=192.168.168.208) 2025-07-23 10:48:37,525 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x648 2025-07-23 10:48:38,977 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x648 to vmcloak 2025-07-23 10:49:09,792 [cuckoo.core.guest] INFO: Starting analysis #6755768 on guest (id=win7x648, ip=192.168.168.208) 2025-07-23 10:49:10,796 [cuckoo.core.guest] DEBUG: win7x648: not ready yet 2025-07-23 10:49:15,820 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x648, ip=192.168.168.208) 2025-07-23 10:49:15,927 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x648, ip=192.168.168.208, monitor=latest, size=6660546) 2025-07-23 10:49:17,221 [cuckoo.core.resultserver] DEBUG: Task #6755768: live log analysis.log initialized. 2025-07-23 10:49:18,927 [cuckoo.core.resultserver] DEBUG: Task #6755768 is sending a BSON stream 2025-07-23 10:49:19,828 [cuckoo.core.resultserver] DEBUG: Task #6755768 is sending a BSON stream 2025-07-23 10:49:19,875 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'shots/0001.jpg' 2025-07-23 10:49:19,895 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 133471 2025-07-23 10:49:21,095 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'shots/0002.jpg' 2025-07-23 10:49:21,524 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 136498 2025-07-23 10:49:25,068 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'shots/0003.jpg' 2025-07-23 10:49:25,071 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'curtain/1753249192.44.curtain.log' 2025-07-23 10:49:25,074 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 36 2025-07-23 10:49:25,076 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'sysmon/1753249192.56.sysmon.xml' 2025-07-23 10:49:25,081 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 479692 2025-07-23 10:49:25,084 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'files/16acf92ce372dab9_mscorsvw.exe' 2025-07-23 10:49:25,098 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 1212416 2025-07-23 10:49:25,103 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 133471 2025-07-23 10:49:26,209 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'files/c18c9e55df3a33b8_flashplayerupdateservice.exe' 2025-07-23 10:49:26,579 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 1390080 2025-07-23 10:49:26,623 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'files/9582144bea4dbf68_aspnet_state.exe' 2025-07-23 10:49:27,009 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 1165312 2025-07-23 10:49:27,014 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'files/f7ad4b09afb301ce_dllhost.exe' 2025-07-23 10:49:27,016 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 7168 2025-07-23 10:49:27,018 [cuckoo.core.resultserver] DEBUG: Task #6755768: File upload for 'files/4474bb33c6207a38_mscorsvw.exe' 2025-07-23 10:49:27,029 [cuckoo.core.resultserver] DEBUG: Task #6755768 uploaded file length: 1188864 2025-07-23 10:49:27,051 [cuckoo.core.resultserver] DEBUG: Task #6755768 had connection reset for <Context for LOG> 2025-07-23 10:49:29,028 [cuckoo.core.guest] INFO: win7x648: analysis completed successfully 2025-07-23 10:49:29,040 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-23 10:49:29,063 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-23 10:49:30,741 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x648 to path /srv/cuckoo/cwd/storage/analyses/6755768/memory.dmp 2025-07-23 10:49:30,742 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x648 2025-07-23 10:50:02,167 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.208 for task #6755768 2025-07-23 10:50:02,663 [cuckoo.core.scheduler] DEBUG: Released database task #6755768 2025-07-23 10:50:02,678 [cuckoo.core.scheduler] INFO: Task #6755768: analysis procedure completed
description | (no description) | rule | DebuggerException__ConsoleCtrl | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Affect private profile | rule | win_files_operation |