| Size | 19.6KB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | ee1babde7f03e69fe695ff9b5251fb48 |
| SHA1 | b73e07221da80c4279f10bcff1aaf900057c56b3 |
| SHA256 | 9619dd2cab864ccb0efd2d0c8477f969ffb74701898fea358b7b6508273d5034 |
| SHA512 |
928fd66e9a661b6e080890773e2017bd290085ded151f36e1fcb5a50e64c4731dae216ae126ba6171c51974579ff962bcd8acda955ab2bffdf62c9babb168a38
|
| CRC32 | B0D48042 |
| ssdeep | None |
| Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Feb. 4, 2026, 5:55 a.m. | Feb. 4, 2026, 5:56 a.m. | 29 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-02-04 04:55:46,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpht3fil 2026-02-04 04:55:46,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\PKFrcyQLWNgjBmaoYLQZhEDXRZijshs 2026-02-04 04:55:46,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\LETuHhRazegMIGXTTWLEKEolN 2026-02-04 04:55:46,280 [analyzer] DEBUG: Started auxiliary module Curtain 2026-02-04 04:55:46,296 [analyzer] DEBUG: Started auxiliary module DbgView 2026-02-04 04:55:46,780 [analyzer] DEBUG: Started auxiliary module Disguise 2026-02-04 04:55:47,000 [analyzer] DEBUG: Loaded monitor into process with pid 504 2026-02-04 04:55:47,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-02-04 04:55:47,000 [analyzer] DEBUG: Started auxiliary module Human 2026-02-04 04:55:47,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-02-04 04:55:47,015 [analyzer] DEBUG: Started auxiliary module Reboot 2026-02-04 04:55:47,125 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-02-04 04:55:47,140 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-02-04 04:55:47,140 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-02-04 04:55:47,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-02-04 04:55:47,217 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\photo.scr' with arguments ['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\photo.scr', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\photo.scr', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
2026-02-04 05:55:47,715 [cuckoo.core.scheduler] INFO: Task #7449857: acquired machine win7x6411 (label=win7x6411)
2026-02-04 05:55:47,716 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.211 for task #7449857
2026-02-04 05:55:48,126 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1803787 (interface=vboxnet0, host=192.168.168.211)
2026-02-04 05:55:48,175 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6411
2026-02-04 05:55:48,682 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6411 to vmcloak
2026-02-04 05:55:57,774 [cuckoo.core.guest] INFO: Starting analysis #7449857 on guest (id=win7x6411, ip=192.168.168.211)
2026-02-04 05:55:58,781 [cuckoo.core.guest] DEBUG: win7x6411: not ready yet
2026-02-04 05:56:03,805 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6411, ip=192.168.168.211)
2026-02-04 05:56:03,892 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6411, ip=192.168.168.211, monitor=latest, size=6660546)
2026-02-04 05:56:05,229 [cuckoo.core.resultserver] DEBUG: Task #7449857: live log analysis.log initialized.
2026-02-04 05:56:06,179 [cuckoo.core.resultserver] DEBUG: Task #7449857 is sending a BSON stream
2026-02-04 05:56:07,502 [cuckoo.core.resultserver] DEBUG: Task #7449857: File upload for 'shots/0001.jpg'
2026-02-04 05:56:07,526 [cuckoo.core.resultserver] DEBUG: Task #7449857 uploaded file length: 133441
2026-02-04 05:56:07,779 [cuckoo.core.guest] WARNING: win7x6411: analysis #7449857 caught an exception
Traceback (most recent call last):
File "C:/tmpht3fil/analyzer.py", line 824, in <module>
success = analyzer.run()
File "C:/tmpht3fil/analyzer.py", line 673, in run
pids = self.package.start(self.target)
File "C:\tmpht3fil\modules\packages\exe.py", line 34, in start
return self.execute(path, args=shlex.split(args))
File "C:\tmpht3fil\lib\common\abstracts.py", line 205, in execute
"Unable to execute the initial process, analysis aborted."
CuckooPackageError: Unable to execute the initial process, analysis aborted.
2026-02-04 05:56:07,790 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2026-02-04 05:56:07,816 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2026-02-04 05:56:08,735 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6411 to path /srv/cuckoo/cwd/storage/analyses/7449857/memory.dmp
2026-02-04 05:56:08,736 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6411
2026-02-04 05:56:16,366 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.211 for task #7449857
2026-02-04 05:56:16,366 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 7449857
2026-02-04 05:56:16,696 [cuckoo.core.scheduler] DEBUG: Released database task #7449857
2026-02-04 05:56:16,713 [cuckoo.core.scheduler] INFO: Task #7449857: analysis procedure completed