| Size | 231.2KB |
|---|---|
| Type | PDF document, version 1.4, 1 pages |
| MD5 | 6e6beef1af96e7df11842cd921e2b140 |
| SHA1 | 5c45cff77c1a51e4120df8d58f3137a8916dfe9c |
| SHA256 | 778f0897bdbb98ed2f553995b403716731dc470282e1b5f024fd6c8482db65ea |
| SHA512 |
1fbf597c0e326bc078bc73c17f077224e63cd9e9070f080950c4cb0514d7124393a0249c2f7577084c26c2492dee82d37ec73a42e85ebb1b56967101a3e8a766
|
| CRC32 | 317277E3 |
| ssdeep | None |
| Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Jan. 30, 2026, 11:49 a.m. | Jan. 30, 2026, 11:51 a.m. | 154 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-01-30 10:49:11,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpl4240h 2026-01-30 10:49:11,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\aQhwDAYQiZyPLDItvbbHNUG 2026-01-30 10:49:11,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\bnluVXBFnMiRdbMOB 2026-01-30 10:49:11,375 [analyzer] DEBUG: Started auxiliary module Curtain 2026-01-30 10:49:11,390 [analyzer] DEBUG: Started auxiliary module DbgView 2026-01-30 10:49:11,796 [analyzer] DEBUG: Started auxiliary module Disguise 2026-01-30 10:49:12,000 [analyzer] DEBUG: Loaded monitor into process with pid 508 2026-01-30 10:49:12,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-01-30 10:49:12,000 [analyzer] DEBUG: Started auxiliary module Human 2026-01-30 10:49:12,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-01-30 10:49:12,000 [analyzer] DEBUG: Started auxiliary module Reboot 2026-01-30 10:49:12,062 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-01-30 10:49:12,062 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-01-30 10:49:12,062 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-01-30 10:49:12,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-01-30 10:49:12,187 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AcroRd32.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\121.pdf'] and pid 2892 2026-01-30 10:49:12,342 [analyzer] DEBUG: Loaded monitor into process with pid 2892 2026-01-30 10:49:14,046 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin 2026-01-30 10:49:14,312 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wscRGB.icc 2026-01-30 10:49:14,342 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wsRGB.icc 2026-01-30 10:49:14,375 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Users\Administrator\AppData\Local\Adobe\Color\ACECache10.lst 2026-01-30 10:49:17,233 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents-journal 2026-01-30 10:49:17,250 [analyzer] INFO: Added new file to list with pid 2892 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents 2026-01-30 10:51:33,033 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2026-01-30 10:51:33,236 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2892. 2026-01-30 10:51:33,549 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-01-30 10:51:33,549 [lib.api.process] INFO: Successfully terminated process with pid 2892. 2026-01-30 10:51:33,581 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\roaming\\adobe\\acrobat\\9.0\\shareddataevents-journal' does not exist, skip. 2026-01-30 10:51:33,595 [analyzer] INFO: Analysis completed.
2026-01-30 11:49:12,510 [cuckoo.core.scheduler] INFO: Task #7348957: acquired machine win7x649 (label=win7x649) 2026-01-30 11:49:12,511 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.209 for task #7348957 2026-01-30 11:49:13,009 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 4036289 (interface=vboxnet0, host=192.168.168.209) 2026-01-30 11:49:13,040 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x649 2026-01-30 11:49:14,238 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x649 to vmcloak 2026-01-30 11:49:25,335 [cuckoo.core.guest] INFO: Starting analysis #7348957 on guest (id=win7x649, ip=192.168.168.209) 2026-01-30 11:49:26,340 [cuckoo.core.guest] DEBUG: win7x649: not ready yet 2026-01-30 11:49:31,365 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x649, ip=192.168.168.209) 2026-01-30 11:49:31,445 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x649, ip=192.168.168.209, monitor=latest, size=6660546) 2026-01-30 11:49:32,795 [cuckoo.core.resultserver] DEBUG: Task #7348957: live log analysis.log initialized. 2026-01-30 11:49:33,733 [cuckoo.core.resultserver] DEBUG: Task #7348957 is sending a BSON stream 2026-01-30 11:49:34,076 [cuckoo.core.resultserver] DEBUG: Task #7348957 is sending a BSON stream 2026-01-30 11:49:35,020 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'shots/0001.jpg' 2026-01-30 11:49:35,034 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 133507 2026-01-30 11:49:36,118 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'shots/0002.jpg' 2026-01-30 11:49:36,132 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 125324 2026-01-30 11:49:37,207 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'shots/0003.jpg' 2026-01-30 11:49:37,221 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 96027 2026-01-30 11:49:44,509 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'shots/0004.jpg' 2026-01-30 11:49:44,523 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 94355 2026-01-30 11:49:47,409 [cuckoo.core.guest] DEBUG: win7x649: analysis #7348957 still processing 2026-01-30 11:50:02,505 [cuckoo.core.guest] DEBUG: win7x649: analysis #7348957 still processing 2026-01-30 11:50:17,612 [cuckoo.core.guest] DEBUG: win7x649: analysis #7348957 still processing 2026-01-30 11:50:32,697 [cuckoo.core.guest] DEBUG: win7x649: analysis #7348957 still processing 2026-01-30 11:50:47,785 [cuckoo.core.guest] DEBUG: win7x649: analysis #7348957 still processing 2026-01-30 11:51:02,876 [cuckoo.core.guest] DEBUG: win7x649: analysis #7348957 still processing 2026-01-30 11:51:17,976 [cuckoo.core.guest] DEBUG: win7x649: analysis #7348957 still processing 2026-01-30 11:51:33,065 [cuckoo.core.guest] DEBUG: win7x649: analysis #7348957 still processing 2026-01-30 11:51:33,424 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'curtain/1769766693.42.curtain.log' 2026-01-30 11:51:33,428 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 36 2026-01-30 11:51:33,552 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'sysmon/1769766693.55.sysmon.xml' 2026-01-30 11:51:33,559 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 455124 2026-01-30 11:51:33,562 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'files/6dcbc76d87105b33_wscrgb.icc' 2026-01-30 11:51:33,565 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 66208 2026-01-30 11:51:33,571 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'files/53314556a8df5187_wsrgb.icc' 2026-01-30 11:51:33,573 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 2676 2026-01-30 11:51:33,597 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'files/cfed3f341c0ecf35_acecache10.lst' 2026-01-30 11:51:33,604 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 1946 2026-01-30 11:51:33,606 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'files/cb37b8d4fa82ed64_shareddataevents' 2026-01-30 11:51:33,623 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 3072 2026-01-30 11:51:33,625 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'files/2cbbfbe12768f624_usercache.bin' 2026-01-30 11:51:33,636 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 69063 2026-01-30 11:51:33,863 [cuckoo.core.resultserver] DEBUG: Task #7348957: File upload for 'shots/0005.jpg' 2026-01-30 11:51:33,880 [cuckoo.core.resultserver] DEBUG: Task #7348957 uploaded file length: 133503 2026-01-30 11:51:33,892 [cuckoo.core.resultserver] DEBUG: Task #7348957 had connection reset for <Context for LOG> 2026-01-30 11:51:36,076 [cuckoo.core.guest] INFO: win7x649: analysis completed successfully 2026-01-30 11:51:36,085 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-01-30 11:51:36,109 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-01-30 11:51:37,606 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x649 to path /srv/cuckoo/cwd/storage/analyses/7348957/memory.dmp 2026-01-30 11:51:37,607 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x649 2026-01-30 11:51:46,496 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.209 for task #7348957 2026-01-30 11:51:46,812 [cuckoo.core.scheduler] DEBUG: Released database task #7348957 2026-01-30 11:51:46,828 [cuckoo.core.scheduler] INFO: Task #7348957: analysis procedure completed
No signatures