File 7dca3dbf4a0d99e7c86edafb83698994e9f89d2ec51de988f0f8c7ec54e4f81b.exe

Size 667.3KB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 0519c157d2d7450690a1cef20ea51e8f
SHA1 bfe39774f356f799bd74649330ab7baecb95c052
SHA256 7dca3dbf4a0d99e7c86edafb83698994e9f89d2ec51de988f0f8c7ec54e4f81b
SHA512
a0632a5bfc725e6e2ac323f58980f1a8889712c9f02381a094d0b64495b5dc9a78563c9e953ce2233e6c11fcf437f79ea8dba4fdf976c24df4e5da59ac771d5f
CRC32 2881B177
ssdeep None
Yara
  • escalate_priv - Escalade priviledges
  • screenshot - Take screenshot
  • win_registry - Affect system registries
  • win_token - Affect system token
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Aug. 18, 2025, 1:45 p.m. Aug. 18, 2025, 1:51 p.m. 368 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-08-18 13:22:09,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpblqbwr
2025-08-18 13:22:09,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\AuzrPTlVuLuUTrlqTagpMTinh
2025-08-18 13:22:09,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\UQkrHmHABUxOmiXiHqZUNkl
2025-08-18 13:22:09,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-08-18 13:22:09,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-08-18 13:22:09,858 [analyzer] DEBUG: Started auxiliary module Disguise
2025-08-18 13:22:10,078 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-08-18 13:22:10,078 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-08-18 13:22:10,078 [analyzer] DEBUG: Started auxiliary module Human
2025-08-18 13:22:10,078 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-08-18 13:22:10,078 [analyzer] DEBUG: Started auxiliary module Reboot
2025-08-18 13:22:10,187 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-08-18 13:22:10,187 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-08-18 13:22:10,187 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-08-18 13:22:10,187 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-08-18 13:22:10,342 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\7dca3dbf4a0d99e7c86edafb83698994e9f89d2ec51de988f0f8c7ec54e4f81b.exe' with arguments '' and pid 596
2025-08-18 13:22:10,530 [analyzer] DEBUG: Loaded monitor into process with pid 596
2025-08-18 13:22:11,312 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Local\Temp\nsi64EF.tmp
2025-08-18 12:49:08,283 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\Machicolation.Vit
2025-08-18 12:49:08,408 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\Negrillo162.nov
2025-08-18 12:49:08,503 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\anticipatively.ini
2025-08-18 12:49:08,533 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\folketingsformand.txt
2025-08-18 12:49:08,581 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\levnedsmiddelets.sva
2025-08-18 12:49:08,706 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\pray.kry
2025-08-18 12:49:08,720 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Roaming\Rigsantikvarernes\supersupreme\respirationsstoppene.txt
2025-08-18 12:49:09,690 [analyzer] INFO: Added new file to list with pid 596 and path C:\Users\Administrator\AppData\Local\Temp\nsaCF72.tmp\System.dll
2025-08-18 12:49:10,456 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-08-18 12:49:10,628 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 596.
2025-08-18 12:49:11,283 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-08-18 12:49:11,283 [lib.api.process] INFO: Successfully terminated process with pid 596.
2025-08-18 12:49:11,315 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\nsi64ef.tmp' does not exist, skip.
2025-08-18 12:49:11,331 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-08-18 13:45:38,733 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:39,811 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:40,884 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:42,054 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:43,106 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:44,172 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:45,234 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:46,301 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:47,393 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:48,449 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:49,506 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:50,989 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:52,055 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:53,119 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:54,180 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:55,428 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:56,511 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:57,591 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:58,684 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:45:59,760 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:00,853 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:01,923 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:02,984 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:04,026 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:05,078 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:06,404 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:07,698 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:08,909 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:10,052 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:11,438 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:12,560 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:13,653 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:14,877 [cuckoo.core.scheduler] DEBUG: Task #6893623: no machine available yet
2025-08-18 13:46:16,086 [cuckoo.core.scheduler] INFO: Task #6893623: acquired machine win7x6418 (label=win7x6418)
2025-08-18 13:46:16,119 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.218 for task #6893623
2025-08-18 13:46:16,737 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 387991 (interface=vboxnet0, host=192.168.168.218)
2025-08-18 13:46:24,474 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6418
2025-08-18 13:46:25,287 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6418 to vmcloak
2025-08-18 13:48:31,575 [cuckoo.core.guest] INFO: Starting analysis #6893623 on guest (id=win7x6418, ip=192.168.168.218)
2025-08-18 13:48:32,600 [cuckoo.core.guest] DEBUG: win7x6418: not ready yet
2025-08-18 13:48:37,659 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6418, ip=192.168.168.218)
2025-08-18 13:48:38,519 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6418, ip=192.168.168.218, monitor=latest, size=6660546)
2025-08-18 13:48:40,116 [cuckoo.core.resultserver] DEBUG: Task #6893623: live log analysis.log initialized.
2025-08-18 13:48:41,188 [cuckoo.core.resultserver] DEBUG: Task #6893623 is sending a BSON stream
2025-08-18 13:48:41,837 [cuckoo.core.resultserver] DEBUG: Task #6893623 is sending a BSON stream
2025-08-18 13:48:42,449 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/e3b0c44298fc1c14_nsn6471.tmp'
2025-08-18 13:48:42,460 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 0
2025-08-18 13:48:42,466 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'shots/0001.jpg'
2025-08-18 13:48:42,505 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 133486
2025-08-18 13:48:43,651 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'shots/0002.jpg'
2025-08-18 13:48:43,678 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 127530
2025-08-18 13:48:44,950 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'shots/0003.jpg'
2025-08-18 13:48:44,995 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 133502
2025-08-18 13:48:54,856 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6893623 still processing
2025-08-18 13:49:10,227 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6893623 still processing
2025-08-18 13:49:10,878 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'curtain/1755514150.77.curtain.log'
2025-08-18 13:49:10,887 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 36
2025-08-18 13:49:11,179 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'sysmon/1755514150.96.sysmon.xml'
2025-08-18 13:49:11,326 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 1775874
2025-08-18 13:49:11,398 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/f742c0f0f0b306bb_negrillo162.nov'
2025-08-18 13:49:11,430 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 284577
2025-08-18 13:49:11,434 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/d34cc96d389edfac_pray.kry'
2025-08-18 13:49:11,442 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 70351
2025-08-18 13:49:11,451 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/1a953dc54649b2e6_anticipatively.ini'
2025-08-18 13:49:11,463 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 667
2025-08-18 13:49:11,478 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/7c448a6c8e8de646_folketingsformand.txt'
2025-08-18 13:49:11,489 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 530
2025-08-18 13:49:11,495 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/5a1c20a3e2e2eb18_system.dll'
2025-08-18 13:49:11,502 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 11264
2025-08-18 13:49:11,510 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/02daff0d6bafda6d_machicolation.vit'
2025-08-18 13:49:11,529 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 279146
2025-08-18 13:49:11,536 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/e7d5c4a66ead0a69_levnedsmiddelets.sva'
2025-08-18 13:49:11,564 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 473258
2025-08-18 13:49:11,574 [cuckoo.core.resultserver] DEBUG: Task #6893623: File upload for 'files/1b746c6a7d78152e_respirationsstoppene.txt'
2025-08-18 13:49:11,589 [cuckoo.core.resultserver] DEBUG: Task #6893623 uploaded file length: 661
2025-08-18 13:49:11,663 [cuckoo.core.resultserver] DEBUG: Task #6893623 had connection reset for <Context for LOG>
2025-08-18 13:49:13,247 [cuckoo.core.guest] INFO: win7x6418: analysis completed successfully
2025-08-18 13:49:13,266 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-08-18 13:49:13,297 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-08-18 13:49:14,674 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6418 to path /srv/cuckoo/cwd/storage/analyses/6893623/memory.dmp
2025-08-18 13:49:14,684 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6418
2025-08-18 13:51:46,260 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.218 for task #6893623
2025-08-18 13:51:46,619 [cuckoo.core.scheduler] DEBUG: Released database task #6893623
2025-08-18 13:51:46,637 [cuckoo.core.scheduler] INFO: Task #6893623: analysis procedure completed

Signatures

Yara rules detected for file (5 events)
description Escalade priviledges rule escalate_priv
description Take screenshot rule screenshot
description Affect system registries rule win_registry
description Affect system token rule win_token
description Affect private profile rule win_files_operation
Allocates read-write-execute memory (usually to unpack itself) (2 events)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 596
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x10004000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 596
region_size: 21553152
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06170000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffff
1 0 0
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available (1 event)
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
The executable contains unknown PE section names indicative of a packer (could be a false positive) (1 event)
section .ndata
Creates executable files on the filesystem (1 event)
file C:\Users\Administrator\AppData\Local\Temp\nsaCF72.tmp\System.dll
Creates hidden or system file (4 events)
Time & API Arguments Status Return Repeated

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Program Files (x86)\intreasure.sul
filepath: C:\Program Files (x86)\intreasure.sul
0 0

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Program Files (x86)\intreasure.sul
filepath: C:\Program Files (x86)\intreasure.sul
0 0

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Program Files (x86)\intreasure.sul
filepath: C:\Program Files (x86)\intreasure.sul
0 0

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\Program Files (x86)\intreasure.sul
filepath: C:\Program Files (x86)\intreasure.sul
0 0
File has been identified by 10 AntiVirus engine on IRMA as malicious (10 events)
G Data Antivirus (Windows) Virus: Trojan.GenericKD.75932461 (Engine A)
Avast Core Security (Linux) NSIS:MalwareX-gen [Inj]
WithSecure (Linux) Heuristic.HEUR/AGEN.1381105
eScan Antivirus (Linux) Trojan.GenericKD.75932461(DB)
ESET Security (Windows) NSIS/Injector.DNH trojan
Sophos Anti-Virus (Linux) Troj/Inject-JYK
DrWeb Antivirus (Linux) Trojan.Inject5.17805
Bitdefender Antivirus (Linux) Trojan.GenericKD.75932461
Kaspersky Standard (Windows) HEUR:Trojan.Win32.Agent.gen
Emsisoft Commandline Scanner (Windows) Trojan.GenericKD.75932461 (B)
File has been identified by 53 AntiVirus engines on VirusTotal as malicious (50 out of 53 events)
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.GuLoader.4!c
Cynet Malicious (score: 100)
CAT-QuickHeal Trojan.Genericml
Skyhigh BehavesLike.Win32.Dropper.jc
ALYac Trojan.GenericKD.75932461
Cylance Unsafe
VIPRE Trojan.GenericKD.75932461
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.75932461
K7GW Trojan ( 005c2c201 )
K7AntiVirus Trojan ( 005c2c201 )
Arcabit Trojan.Generic.D486A32D
VirIT Trojan.Win32.GenusT.EREZ
Symantec Trojan.Gen.MBT
Elastic malicious (high confidence)
ESET-NOD32 NSIS/Injector.DNH
APEX Malicious
Avast NSIS:InjectorX-gen [Trj]
Kaspersky HEUR:Trojan.Win32.Agent.gen
SUPERAntiSpyware Adware.Linkury/Variant
MicroWorld-eScan Trojan.GenericKD.75932461
Emsisoft Trojan.GenericKD.75932461 (B)
F-Secure Trojan.TR/Injector.bpooo
DrWeb Trojan.Inject5.17805
TrendMicro Backdoor.Win32.REMCOS.YXFCDZ
McAfeeD ti!7DCA3DBF4A0D
CTX exe.trojan.guloader
Sophos Mal/Generic-S
FireEye Trojan.GenericKD.75932461
Google Detected
Avira TR/Injector.bpooo
Antiy-AVL Trojan/Win32.GenericML.xnet
Kingsoft Win32.Trojan.GenericML.xnet
Xcitium Malware@#2eo9bpbd93847
Microsoft Trojan:Win32/Sabsik.FL.A!ml
GData Trojan.GenericKD.75932461
Varist W32/Trojan.DWOU-1399
AhnLab-V3 Downloader/Win.GuLoader.C5736681
McAfee Artemis!0519C157D2D7
DeepInstinct MALICIOUS
VBA32 Trojan.GuLoader
Malwarebytes Trojan.GuLoader
Ikarus Trojan.NSIS.Agent
TrendMicro-HouseCall Backdoor.Win32.REMCOS.YXFCDZ
Tencent Win32.Trojan.Agent.Aujl
Yandex Trojan.Igent.b3ZEnl.11
huorong HEUR:Trojan/Injector.ba
MaxSecure Trojan.Malware.336863331.susgen
Fortinet NSIS/Injector.CKR1!tr
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.