| Size | 1.8MB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | 883f1c7beb7d290e92f9c0758773a2df |
| SHA1 | 0b128f76a7714bb125ebce78f732148dc7fd45a3 |
| SHA256 | 68b2cebfb7ea1ba712ed5663fc3460d767dd6fc4ca6bbf9e5a62a9db44d6b213 |
| SHA512 |
4e3bec8c5feecb287924d88601575ba8b9c97f8fe40f9733a5aa755e21ce1cd5e719ee6397fa0ec649ca795049375859a55393ceda596823c1b970f9b1dcdbea
|
| CRC32 | 220359A4 |
| ssdeep | None |
| Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Dec. 20, 2025, 9:33 p.m. | Dec. 20, 2025, 9:34 p.m. | 65 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-12-19 10:16:19,015 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht 2025-12-19 10:16:19,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\gYBtENmNwwOyqheWXzyAI 2025-12-19 10:16:19,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\SRwUEDfjnBwLhaSzqGrExzRFqPoqcHSL 2025-12-19 10:16:19,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-12-19 10:16:19,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-12-19 10:16:19,750 [analyzer] DEBUG: Started auxiliary module Disguise 2025-12-19 10:16:19,967 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-12-19 10:16:19,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-12-19 10:16:19,967 [analyzer] DEBUG: Started auxiliary module Human 2025-12-19 10:16:19,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-12-19 10:16:19,983 [analyzer] DEBUG: Started auxiliary module Reboot 2025-12-19 10:16:20,062 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-12-19 10:16:20,078 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-12-19 10:16:20,078 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-12-19 10:16:20,078 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-12-19 10:16:20,233 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\68b2cebfb7ea1ba712ed5663fc3460d767dd6fc4ca6bbf9e5a62a9db44d6b213.exe' with arguments '' and pid 2280 2025-12-19 10:16:20,421 [analyzer] DEBUG: Loaded monitor into process with pid 2280 2025-12-19 10:16:49,250 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-12-19 10:16:49,625 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-12-19 10:16:49,640 [lib.api.process] INFO: Successfully terminated process with pid 2280. 2025-12-19 10:16:49,640 [analyzer] INFO: Analysis completed.
2025-12-20 21:33:14,827 [cuckoo.core.scheduler] INFO: Task #7242844: acquired machine win7x641 (label=win7x641) 2025-12-20 21:33:14,828 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #7242844 2025-12-20 21:33:15,054 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 207535 (interface=vboxnet0, host=192.168.168.201) 2025-12-20 21:33:15,659 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641 2025-12-20 21:33:16,232 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak 2025-12-20 21:33:26,510 [cuckoo.core.guest] INFO: Starting analysis #7242844 on guest (id=win7x641, ip=192.168.168.201) 2025-12-20 21:33:27,516 [cuckoo.core.guest] DEBUG: win7x641: not ready yet 2025-12-20 21:33:32,544 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201) 2025-12-20 21:33:32,614 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546) 2025-12-20 21:33:33,963 [cuckoo.core.resultserver] DEBUG: Task #7242844: live log analysis.log initialized. 2025-12-20 21:33:34,903 [cuckoo.core.resultserver] DEBUG: Task #7242844 is sending a BSON stream 2025-12-20 21:33:35,320 [cuckoo.core.resultserver] DEBUG: Task #7242844 is sending a BSON stream 2025-12-20 21:33:36,187 [cuckoo.core.resultserver] DEBUG: Task #7242844: File upload for 'shots/0001.jpg' 2025-12-20 21:33:36,218 [cuckoo.core.resultserver] DEBUG: Task #7242844 uploaded file length: 133546 2025-12-20 21:33:36,274 [cuckoo.core.resultserver] DEBUG: Task #7242844: File upload for 'files/e3b0c44298fc1c14_nsfCEDE.tmp' 2025-12-20 21:33:36,277 [cuckoo.core.resultserver] DEBUG: Task #7242844 uploaded file length: 0 2025-12-20 21:33:37,350 [cuckoo.core.resultserver] DEBUG: Task #7242844: File upload for 'shots/0002.jpg' 2025-12-20 21:33:37,365 [cuckoo.core.resultserver] DEBUG: Task #7242844 uploaded file length: 139223 2025-12-20 21:33:48,546 [cuckoo.core.guest] DEBUG: win7x641: analysis #7242844 still processing 2025-12-20 21:34:03,653 [cuckoo.core.guest] DEBUG: win7x641: analysis #7242844 still processing 2025-12-20 21:34:04,494 [cuckoo.core.resultserver] DEBUG: Task #7242844: File upload for 'curtain/1766135809.52.curtain.log' 2025-12-20 21:34:04,500 [cuckoo.core.resultserver] DEBUG: Task #7242844 uploaded file length: 36 2025-12-20 21:34:04,613 [cuckoo.core.resultserver] DEBUG: Task #7242844: File upload for 'sysmon/1766135809.62.sysmon.xml' 2025-12-20 21:34:04,624 [cuckoo.core.resultserver] DEBUG: Task #7242844 uploaded file length: 259916 2025-12-20 21:34:05,310 [cuckoo.core.resultserver] DEBUG: Task #7242844: File upload for 'shots/0003.jpg' 2025-12-20 21:34:05,322 [cuckoo.core.resultserver] DEBUG: Task #7242844 uploaded file length: 133546 2025-12-20 21:34:05,337 [cuckoo.core.resultserver] DEBUG: Task #7242844 had connection reset for <Context for LOG> 2025-12-20 21:34:06,663 [cuckoo.core.guest] INFO: win7x641: analysis completed successfully 2025-12-20 21:34:06,674 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-12-20 21:34:06,706 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-12-20 21:34:07,446 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/7242844/memory.dmp 2025-12-20 21:34:07,448 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641 2025-12-20 21:34:20,170 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #7242844 2025-12-20 21:34:20,503 [cuckoo.core.scheduler] DEBUG: Released database task #7242844 2025-12-20 21:34:20,521 [cuckoo.core.scheduler] INFO: Task #7242844: analysis procedure completed
| description | Escalade priviledges | rule | escalate_priv | ||||||
| description | Take screenshot | rule | screenshot | ||||||
| description | Affect system registries | rule | win_registry | ||||||
| description | Affect system token | rule | win_token | ||||||
| description | Affect private profile | rule | win_files_operation | ||||||
| section | .ndata |
| WithSecure (Linux) | Trojan.TR/Crypt.XPACK.Gen |
| CrowdStrike | win/malicious_confidence_70% (W) |
| F-Secure | Trojan.TR/Crypt.XPACK.Gen |
| McAfeeD | ti!68B2CEBFB7EA |
| Detected | |
| Avira | TR/Crypt.XPACK.Gen |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| GData | Win32.Trojan.Agent.126Z0R |
| DeepInstinct | MALICIOUS |
| Ikarus | Trojan.Crypt |
| Tencent | Malware.Win32.Gencirc.11e2e900 |