| Size | 67.9KB |
|---|---|
| Type | PDF document, version 1.4, 2 pages |
| MD5 | 425b5df5915d8c8caddf9a9bfa6fe67d |
| SHA1 | 9541f4689f272bc0b1e1f095b11aa9aaa531f6c2 |
| SHA256 | 22ff21ea36f3064f4e0a02727fcec7ec2e0bfc21d6169d30475fb5323dbef261 |
| SHA512 |
f2207ff0c230fdbea5e625c9ae3bf9a81fcc84b55ee0a206205ed8829cb04f3785c86401c2e0e349d2f9640bdcd0785aa7b493fcaf6106dddcb1affcd1f21581
|
| CRC32 | E7B33873 |
| ssdeep | None |
| Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Jan. 10, 2026, 12:55 a.m. | Jan. 10, 2026, 12:56 a.m. | 62 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-01-09 23:55:16,000 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht 2026-01-09 23:55:16,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\HxOKBRlbpKYCvHuderv 2026-01-09 23:55:16,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\BGmPjnpMmUFYHchSNiCbndqXobaeDkCJ 2026-01-09 23:55:16,328 [analyzer] DEBUG: Started auxiliary module Curtain 2026-01-09 23:55:16,328 [analyzer] DEBUG: Started auxiliary module DbgView 2026-01-09 23:55:17,140 [analyzer] DEBUG: Started auxiliary module Disguise 2026-01-09 23:55:17,375 [analyzer] DEBUG: Loaded monitor into process with pid 500 2026-01-09 23:55:17,375 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-01-09 23:55:17,375 [analyzer] DEBUG: Started auxiliary module Human 2026-01-09 23:55:17,375 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-01-09 23:55:17,390 [analyzer] DEBUG: Started auxiliary module Reboot 2026-01-09 23:55:17,453 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-01-09 23:55:17,453 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-01-09 23:55:17,467 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-01-09 23:55:17,467 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-01-09 23:55:17,717 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AcroRd32.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\civil-engineering-resume-objective-examples.pdf'] and pid 2648 2026-01-09 23:55:17,905 [analyzer] DEBUG: Loaded monitor into process with pid 2648 2026-01-09 23:55:19,733 [analyzer] INFO: Added new file to list with pid 2648 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin 2026-01-09 23:55:19,983 [analyzer] INFO: Added new file to list with pid 2648 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wscRGB.icc 2026-01-09 23:55:20,015 [analyzer] INFO: Added new file to list with pid 2648 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wsRGB.icc 2026-01-09 23:55:20,046 [analyzer] INFO: Added new file to list with pid 2648 and path C:\Users\Administrator\AppData\Local\Adobe\Color\ACECache10.lst 2026-01-09 23:56:07,272 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2026-01-09 23:56:07,693 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-01-09 23:56:07,693 [lib.api.process] INFO: Successfully terminated process with pid 2648. 2026-01-09 23:56:07,740 [analyzer] INFO: Analysis completed.
2026-01-10 00:55:17,325 [cuckoo.core.scheduler] INFO: Task #7284396: acquired machine win7x641 (label=win7x641) 2026-01-10 00:55:17,326 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #7284396 2026-01-10 00:55:17,810 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2736093 (interface=vboxnet0, host=192.168.168.201) 2026-01-10 00:55:17,835 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641 2026-01-10 00:55:18,815 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak 2026-01-10 00:55:29,283 [cuckoo.core.guest] INFO: Starting analysis #7284396 on guest (id=win7x641, ip=192.168.168.201) 2026-01-10 00:55:30,290 [cuckoo.core.guest] DEBUG: win7x641: not ready yet 2026-01-10 00:55:35,316 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201) 2026-01-10 00:55:35,395 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546) 2026-01-10 00:55:36,525 [cuckoo.core.resultserver] DEBUG: Task #7284396: live log analysis.log initialized. 2026-01-10 00:55:37,833 [cuckoo.core.resultserver] DEBUG: Task #7284396 is sending a BSON stream 2026-01-10 00:55:38,364 [cuckoo.core.resultserver] DEBUG: Task #7284396 is sending a BSON stream 2026-01-10 00:55:39,122 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'shots/0001.jpg' 2026-01-10 00:55:39,147 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 133478 2026-01-10 00:55:40,271 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'shots/0002.jpg' 2026-01-10 00:55:40,303 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 125291 2026-01-10 00:55:41,429 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'shots/0003.jpg' 2026-01-10 00:55:41,451 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 133410 2026-01-10 00:55:42,525 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'shots/0004.jpg' 2026-01-10 00:55:42,529 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 40184 2026-01-10 00:55:51,176 [cuckoo.core.guest] DEBUG: win7x641: analysis #7284396 still processing 2026-01-10 00:56:06,268 [cuckoo.core.guest] DEBUG: win7x641: analysis #7284396 still processing 2026-01-10 00:56:07,563 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'curtain/1767999367.55.curtain.log' 2026-01-10 00:56:07,566 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 36 2026-01-10 00:56:07,699 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'sysmon/1767999367.69.sysmon.xml' 2026-01-10 00:56:07,704 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 230560 2026-01-10 00:56:07,712 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'files/75cbca9c3d8bbf1a_wscrgb.icc' 2026-01-10 00:56:07,715 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 66208 2026-01-10 00:56:07,720 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'files/a376f4112849aac6_wsrgb.icc' 2026-01-10 00:56:07,722 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 2676 2026-01-10 00:56:07,729 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'files/83cefe5bcd825820_acecache10.lst' 2026-01-10 00:56:07,731 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 1946 2026-01-10 00:56:07,737 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'files/2cbbfbe12768f624_usercache.bin' 2026-01-10 00:56:07,741 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 69063 2026-01-10 00:56:08,380 [cuckoo.core.resultserver] DEBUG: Task #7284396: File upload for 'shots/0005.jpg' 2026-01-10 00:56:08,396 [cuckoo.core.resultserver] DEBUG: Task #7284396 uploaded file length: 133478 2026-01-10 00:56:08,408 [cuckoo.core.resultserver] DEBUG: Task #7284396 had connection reset for <Context for LOG> 2026-01-10 00:56:09,281 [cuckoo.core.guest] INFO: win7x641: analysis completed successfully 2026-01-10 00:56:09,295 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-01-10 00:56:09,319 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-01-10 00:56:10,523 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/7284396/memory.dmp 2026-01-10 00:56:10,525 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641 2026-01-10 00:56:18,961 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #7284396 2026-01-10 00:56:19,378 [cuckoo.core.scheduler] DEBUG: Released database task #7284396 2026-01-10 00:56:19,396 [cuckoo.core.scheduler] INFO: Task #7284396: analysis procedure completed
| description | (no description) | rule | invalid_trailer_structure | ||||||
| description | The first entry in a cross-reference table is always free and has a generation number of 65,535 | rule | invalid_xref_numbers | ||||||