Size | 84.5KB |
---|---|
Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
MD5 | 120d18a69769add27031f647b521b569 |
SHA1 | 1d7cb78b43935f33d3dbbc97e8d90172c0ae7278 |
SHA256 | 26061aa44583771575bed8755660f338623bccbc6e734fcae02bfa8ebc43ed49 |
SHA512 |
73ab5753f837c72484928fd49f4a0978fc0c74f96697bf133f2857eeafdb822f354f08919dba0ffc5c4ef3b5ea1f370fe58b50bef6ddbda1e5d653a2c188effc
|
CRC32 | 20BC4492 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Aug. 26, 2025, 12:40 a.m. | Aug. 26, 2025, 12:49 a.m. | 527 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-23 18:52:57,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpsftntc 2025-08-23 18:52:57,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\glPsrTelrqfOcDqdvtS 2025-08-23 18:52:57,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\plMUwiTeDrDOdamOaM 2025-08-23 18:52:57,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-08-23 18:52:57,030 [analyzer] INFO: Automatically selected analysis package "exe" 2025-08-23 18:52:57,437 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-23 18:52:57,437 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-23 18:52:58,030 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-23 18:52:58,250 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-08-23 18:52:58,250 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-23 18:52:58,250 [analyzer] DEBUG: Started auxiliary module Human 2025-08-23 18:52:58,250 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-23 18:52:58,250 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-23 18:52:58,312 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-23 18:52:58,312 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-23 18:52:58,312 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-23 18:52:58,312 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-23 18:52:58,453 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\26061aa445837715_c4cd302acef1cc16abc10c84e86abbbab2c9133db00b20aa589d13c1af8db088.exe' with arguments '' and pid 1132 2025-08-23 18:52:58,640 [analyzer] DEBUG: Loaded monitor into process with pid 1132 2025-08-23 18:52:58,687 [analyzer] INFO: Injected into process with pid 1128 and name '' 2025-08-23 18:52:58,765 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1128. 2025-08-23 18:52:58,875 [analyzer] INFO: Added new file to list with pid 1132 and path C:\Users\Administrator\AppData\Local\Temp\RCXE05D.tmp 2025-08-23 18:56:17,453 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-08-23 18:56:18,608 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-23 18:56:18,608 [analyzer] INFO: Analysis completed.
2025-08-26 00:40:31,838 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:32,859 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:33,879 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:34,901 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:35,929 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:36,957 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:37,986 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:39,006 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:40,029 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:41,058 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:42,081 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:43,155 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:44,454 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:45,526 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:46,574 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:47,631 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:48,679 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:49,748 [cuckoo.core.scheduler] DEBUG: Task #6904226: no machine available yet 2025-08-26 00:40:51,049 [cuckoo.core.scheduler] INFO: Task #6904226: acquired machine win7x6421 (label=win7x6421) 2025-08-26 00:40:51,055 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.221 for task #6904226 2025-08-26 00:40:51,643 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1085515 (interface=vboxnet0, host=192.168.168.221) 2025-08-26 00:40:52,047 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6421 2025-08-26 00:40:52,918 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6421 to vmcloak 2025-08-26 00:43:31,217 [cuckoo.core.guest] INFO: Starting analysis #6904226 on guest (id=win7x6421, ip=192.168.168.221) 2025-08-26 00:43:32,224 [cuckoo.core.guest] DEBUG: win7x6421: not ready yet 2025-08-26 00:43:37,247 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6421, ip=192.168.168.221) 2025-08-26 00:43:37,388 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6421, ip=192.168.168.221, monitor=latest, size=6660546) 2025-08-26 00:43:38,698 [cuckoo.core.resultserver] DEBUG: Task #6904226: live log analysis.log initialized. 2025-08-26 00:43:39,988 [cuckoo.core.resultserver] DEBUG: Task #6904226 is sending a BSON stream 2025-08-26 00:43:40,257 [cuckoo.core.resultserver] DEBUG: Task #6904226 is sending a BSON stream 2025-08-26 00:43:41,127 [cuckoo.core.resultserver] DEBUG: Task #6904226: File upload for 'shots/0001.jpg' 2025-08-26 00:43:41,145 [cuckoo.core.resultserver] DEBUG: Task #6904226 uploaded file length: 133487 2025-08-26 00:43:53,301 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:44:08,390 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:44:23,475 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:44:38,547 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:44:53,794 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:45:09,197 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:45:24,484 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:45:39,643 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:45:54,895 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:46:10,226 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:46:25,342 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:46:40,465 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:46:55,877 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6904226 still processing 2025-08-26 00:46:59,322 [cuckoo.core.resultserver] DEBUG: Task #6904226: File upload for 'curtain/1755968177.62.curtain.log' 2025-08-26 00:46:59,325 [cuckoo.core.resultserver] DEBUG: Task #6904226 uploaded file length: 36 2025-08-26 00:47:00,225 [cuckoo.core.resultserver] DEBUG: Task #6904226: File upload for 'sysmon/1755968178.52.sysmon.xml' 2025-08-26 00:47:00,307 [cuckoo.core.resultserver] DEBUG: Task #6904226 uploaded file length: 13592180 2025-08-26 00:47:00,331 [cuckoo.core.resultserver] DEBUG: Task #6904226: File upload for 'files/9775ac2983e20662_26061aa445837715_c4cd302acef1cc16abc10c84e86abbbab2c9133db00b20aa589d13c1af8db088.exe' 2025-08-26 00:47:00,334 [cuckoo.core.resultserver] DEBUG: Task #6904226 uploaded file length: 86528 2025-08-26 00:47:00,335 [cuckoo.core.resultserver] DEBUG: Task #6904226 had connection reset for <Context for LOG> 2025-08-26 00:47:02,042 [cuckoo.core.guest] INFO: win7x6421: analysis completed successfully 2025-08-26 00:47:02,070 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-26 00:47:02,096 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-26 00:47:03,275 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6421 to path /srv/cuckoo/cwd/storage/analyses/6904226/memory.dmp 2025-08-26 00:47:03,279 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6421 2025-08-26 00:49:18,304 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.221 for task #6904226 2025-08-26 00:49:19,358 [cuckoo.core.scheduler] DEBUG: Released database task #6904226 2025-08-26 00:49:19,390 [cuckoo.core.scheduler] INFO: Task #6904226: analysis procedure completed
description | (no description) | rule | ThreadControl__Context | ||||||
description | Affect private profile | rule | win_files_operation |
section | {u'size_of_data': u'0x00006c00', u'virtual_address': u'0x00014000', u'entropy': 7.988872449590448, u'name': u'.rsrc', u'virtual_size': u'0x00006b80'} | entropy | 7.98887244959 | description | A section with a high entropy has been found | |||||||||
entropy | 0.323353293413 | description | Overall entropy of this PE file is high |
Process injection | Process 1132 manipulating memory of non-child process 1128 |