Size | 84.5KB |
---|---|
Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
MD5 | f853d251ee7e1d5aa2fc29310d6eaba1 |
SHA1 | 2f89fa8b670525df63c9d1b697bb45b344932d6f |
SHA256 | c4cd302acef1cc16abc10c84e86abbbab2c9133db00b20aa589d13c1af8db088 |
SHA512 |
173d2e7f0a8956d9c7d063a541f21160bc9b310b7ca8e6629b59f15d7b3bfd0fdd3fb82d939611b140223ccc9967b17de6a9bdae02a8c665212226292f518da9
|
CRC32 | 6239E572 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Aug. 23, 2025, 6:45 p.m. | Aug. 23, 2025, 6:52 p.m. | 387 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-16 07:45:06,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpsftntc 2025-08-16 07:45:06,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\rqABVGeWTjIOAWQtpr 2025-08-16 07:45:06,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\bylCKWEUitweUhnSUv 2025-08-16 07:45:06,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-16 07:45:06,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-16 07:45:06,828 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-16 07:45:07,062 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-08-16 07:45:07,062 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-16 07:45:07,062 [analyzer] DEBUG: Started auxiliary module Human 2025-08-16 07:45:07,062 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-16 07:45:07,062 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-16 07:45:07,108 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-16 07:45:07,108 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-16 07:45:07,125 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-16 07:45:07,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-16 07:45:07,280 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\c4cd302acef1cc16abc10c84e86abbbab2c9133db00b20aa589d13c1af8db088.exe' with arguments '' and pid 2668 2025-08-16 07:45:07,453 [analyzer] DEBUG: Loaded monitor into process with pid 2668 2025-08-16 07:45:07,515 [analyzer] INFO: Injected into process with pid 984 and name '' 2025-08-16 07:45:07,592 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 984. 2025-08-16 07:45:07,703 [analyzer] INFO: Added new file to list with pid 2668 and path C:\Users\Administrator\AppData\Local\Temp\RCXE649.tmp 2025-08-16 07:45:36,280 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-08-16 07:45:36,733 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-16 07:45:36,733 [analyzer] INFO: Analysis completed.
2025-08-23 18:45:57,287 [cuckoo.core.scheduler] DEBUG: Task #6879283: no machine available yet 2025-08-23 18:45:58,321 [cuckoo.core.scheduler] DEBUG: Task #6879283: no machine available yet 2025-08-23 18:45:59,342 [cuckoo.core.scheduler] DEBUG: Task #6879283: no machine available yet 2025-08-23 18:46:00,359 [cuckoo.core.scheduler] DEBUG: Task #6879283: no machine available yet 2025-08-23 18:46:01,397 [cuckoo.core.scheduler] INFO: Task #6879283: acquired machine win7x6421 (label=win7x6421) 2025-08-23 18:46:01,398 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.221 for task #6879283 2025-08-23 18:46:01,702 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3970730 (interface=vboxnet0, host=192.168.168.221) 2025-08-23 18:46:01,883 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6421 2025-08-23 18:46:02,422 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6421 to vmcloak 2025-08-23 18:48:53,204 [cuckoo.core.guest] INFO: Starting analysis #6879283 on guest (id=win7x6421, ip=192.168.168.221) 2025-08-23 18:48:54,210 [cuckoo.core.guest] DEBUG: win7x6421: not ready yet 2025-08-23 18:48:59,240 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6421, ip=192.168.168.221) 2025-08-23 18:48:59,408 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6421, ip=192.168.168.221, monitor=latest, size=6660546) 2025-08-23 18:49:01,223 [cuckoo.core.resultserver] DEBUG: Task #6879283: live log analysis.log initialized. 2025-08-23 18:49:02,222 [cuckoo.core.resultserver] DEBUG: Task #6879283 is sending a BSON stream 2025-08-23 18:49:02,598 [cuckoo.core.resultserver] DEBUG: Task #6879283 is sending a BSON stream 2025-08-23 18:49:03,452 [cuckoo.core.resultserver] DEBUG: Task #6879283: File upload for 'shots/0001.jpg' 2025-08-23 18:49:03,475 [cuckoo.core.resultserver] DEBUG: Task #6879283 uploaded file length: 133475 2025-08-23 18:49:15,956 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6879283 still processing 2025-08-23 18:49:31,052 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6879283 still processing 2025-08-23 18:49:31,737 [cuckoo.core.resultserver] DEBUG: Task #6879283: File upload for 'curtain/1755323136.52.curtain.log' 2025-08-23 18:49:31,740 [cuckoo.core.resultserver] DEBUG: Task #6879283 uploaded file length: 36 2025-08-23 18:49:31,934 [cuckoo.core.resultserver] DEBUG: Task #6879283: File upload for 'sysmon/1755323136.7.sysmon.xml' 2025-08-23 18:49:31,954 [cuckoo.core.resultserver] DEBUG: Task #6879283 uploaded file length: 1620834 2025-08-23 18:49:31,963 [cuckoo.core.resultserver] DEBUG: Task #6879283: File upload for 'files/26061aa445837715_c4cd302acef1cc16abc10c84e86abbbab2c9133db00b20aa589d13c1af8db088.exe' 2025-08-23 18:49:31,966 [cuckoo.core.resultserver] DEBUG: Task #6879283 uploaded file length: 86528 2025-08-23 18:49:32,181 [cuckoo.core.resultserver] DEBUG: Task #6879283 had connection reset for <Context for LOG> 2025-08-23 18:49:34,166 [cuckoo.core.guest] INFO: win7x6421: analysis completed successfully 2025-08-23 18:49:34,187 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-23 18:49:34,219 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-23 18:49:35,100 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6421 to path /srv/cuckoo/cwd/storage/analyses/6879283/memory.dmp 2025-08-23 18:49:35,102 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6421 2025-08-23 18:52:24,034 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.221 for task #6879283 2025-08-23 18:52:24,571 [cuckoo.core.scheduler] DEBUG: Released database task #6879283 2025-08-23 18:52:24,596 [cuckoo.core.scheduler] INFO: Task #6879283: analysis procedure completed
description | (no description) | rule | ThreadControl__Context | ||||||
description | Affect private profile | rule | win_files_operation |
section | {u'size_of_data': u'0x00006c00', u'virtual_address': u'0x00014000', u'entropy': 7.98419053084366, u'name': u'.rsrc', u'virtual_size': u'0x00006b80'} | entropy | 7.98419053084 | description | A section with a high entropy has been found | |||||||||
entropy | 0.323353293413 | description | Overall entropy of this PE file is high |
Process injection | Process 2668 manipulating memory of non-child process 984 |