Size | 1.9MB |
---|---|
Type | POSIX tar archive |
MD5 | 5b59bd2e0055dc1e0a5a5f7d022aeed6 |
SHA1 | 4aa0bccd0b2ee46c6f05ecf189d0761a6a26ddd6 |
SHA256 | 283cd537c8bb54454e4e81db742d0e546191fe63273e50745fea06c01f75a37d |
SHA512 |
ba1c4292c097d00ddc496ef1b6f2213c342bb67d984c63faa31f6f777fb132282c9c10502f6dbc9f74c43b748a248f38f5618d98330bc836b80656d5e9f5ec2c
|
CRC32 | AAD0F349 |
ssdeep | None |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
ARCHIVE | Aug. 2, 2025, 11:26 p.m. | Aug. 2, 2025, 11:27 p.m. | 65 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-02 23:26:14,046 [analyzer] DEBUG: Starting analyzer from: C:\tmpk4d6bl 2025-08-02 23:26:14,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\fnYTFsFpcsXxtiNakWGQO 2025-08-02 23:26:14,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\jqcrgSIWkgUbnOhImFZ 2025-08-02 23:26:14,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-02 23:26:14,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-02 23:26:14,780 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-02 23:26:14,983 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-08-02 23:26:14,983 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-02 23:26:14,983 [analyzer] DEBUG: Started auxiliary module Human 2025-08-02 23:26:14,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-02 23:26:15,000 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-02 23:26:15,108 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-02 23:26:15,108 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-02 23:26:15,108 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-02 23:26:15,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-02 23:26:15,265 [lib.api.process] INFO: Successfully executed process from path 'bin/7za.exe' with arguments ['x', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\output', '-pinfected'] and pid 2016 2025-08-02 22:27:07,385 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\ose00000.exe' with arguments '' and pid 1444 2025-08-02 22:27:07,605 [analyzer] DEBUG: Loaded monitor into process with pid 1444 2025-08-02 22:27:07,683 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1444. 2025-08-02 22:27:08,385 [analyzer] INFO: Process with pid 1444 has terminated 2025-08-02 22:27:08,385 [analyzer] INFO: Process list is empty, terminating analysis. 2025-08-02 22:27:09,667 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-02 22:27:09,667 [analyzer] INFO: Analysis completed.
2025-08-02 23:26:14,818 [cuckoo.core.scheduler] INFO: Task #6816197: acquired machine win7x6422 (label=win7x6422) 2025-08-02 23:26:14,819 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.222 for task #6816197 2025-08-02 23:26:15,120 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 676384 (interface=vboxnet0, host=192.168.168.222) 2025-08-02 23:26:15,141 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6422 2025-08-02 23:26:15,677 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6422 to vmcloak 2025-08-02 23:26:27,528 [cuckoo.core.guest] INFO: Starting analysis #6816197 on guest (id=win7x6422, ip=192.168.168.222) 2025-08-02 23:26:28,534 [cuckoo.core.guest] DEBUG: win7x6422: not ready yet 2025-08-02 23:26:33,568 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6422, ip=192.168.168.222) 2025-08-02 23:26:33,702 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6422, ip=192.168.168.222, monitor=latest, size=6660546) 2025-08-02 23:26:35,773 [cuckoo.core.resultserver] DEBUG: Task #6816197: live log analysis.log initialized. 2025-08-02 23:26:36,686 [cuckoo.core.resultserver] DEBUG: Task #6816197 is sending a BSON stream 2025-08-02 23:26:38,007 [cuckoo.core.resultserver] DEBUG: Task #6816197: File upload for 'shots/0001.jpg' 2025-08-02 23:26:38,028 [cuckoo.core.resultserver] DEBUG: Task #6816197 uploaded file length: 143650 2025-08-02 23:26:50,387 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6816197 still processing 2025-08-02 23:27:05,477 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6816197 still processing 2025-08-02 23:27:07,483 [cuckoo.core.resultserver] DEBUG: Task #6816197 is sending a BSON stream 2025-08-02 23:27:09,553 [cuckoo.core.resultserver] DEBUG: Task #6816197: File upload for 'curtain/1754166429.54.curtain.log' 2025-08-02 23:27:09,556 [cuckoo.core.resultserver] DEBUG: Task #6816197 uploaded file length: 36 2025-08-02 23:27:09,670 [cuckoo.core.resultserver] DEBUG: Task #6816197: File upload for 'sysmon/1754166429.65.sysmon.xml' 2025-08-02 23:27:09,677 [cuckoo.core.resultserver] DEBUG: Task #6816197 uploaded file length: 205540 2025-08-02 23:27:10,035 [cuckoo.core.resultserver] DEBUG: Task #6816197 had connection reset for <Context for LOG> 2025-08-02 23:27:11,510 [cuckoo.core.guest] INFO: win7x6422: analysis completed successfully 2025-08-02 23:27:11,522 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-02 23:27:11,550 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-02 23:27:12,394 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6422 to path /srv/cuckoo/cwd/storage/analyses/6816197/memory.dmp 2025-08-02 23:27:12,396 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6422 2025-08-02 23:27:19,771 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.222 for task #6816197 2025-08-02 23:27:20,237 [cuckoo.core.scheduler] DEBUG: Released database task #6816197 2025-08-02 23:27:20,256 [cuckoo.core.scheduler] INFO: Task #6816197: analysis procedure completed
description | (no description) | rule | APT1_WEBC2_Y21K |