| Size | 1008.0KB |
|---|---|
| Type | PE32+ executable (console) x86-64, for MS Windows |
| MD5 | 1ce499174caa25f6264040fde201012f |
| SHA1 | 84f0f957e692fb10b150ce9c80918d2af55f1ce3 |
| SHA256 | 3b578f155219ec9622881ee5f8d2f3db99ed59f77ad36a1b140a24398c75585b |
| SHA512 |
d6aa7930cef9f2407d6547f817897a856db1b955226c32dce9309f8a19bd39319d486f4c18c119d162948f0b8dcb140e9530811541baeedbed323fe30b887b69
|
| CRC32 | 40F8C8C3 |
| ssdeep | None |
| Yara |
|
This file is very suspicious, with a score of 9.1 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Feb. 6, 2026, 12:21 a.m. | Feb. 6, 2026, 12:22 a.m. | 66 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-02-05 23:21:05,015 [analyzer] DEBUG: Starting analyzer from: C:\tmptisd8w 2026-02-05 23:21:05,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\oKFxqpMvYcqhyIUsyt 2026-02-05 23:21:05,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\CPqmzeTjOTTdGRIuxrhWTbC 2026-02-05 23:21:05,233 [analyzer] DEBUG: Started auxiliary module Curtain 2026-02-05 23:21:05,233 [analyzer] DEBUG: Started auxiliary module DbgView 2026-02-05 23:21:05,578 [analyzer] DEBUG: Started auxiliary module Disguise 2026-02-05 23:21:05,765 [analyzer] DEBUG: Loaded monitor into process with pid 508 2026-02-05 23:21:05,765 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-02-05 23:21:05,765 [analyzer] DEBUG: Started auxiliary module Human 2026-02-05 23:21:05,765 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-02-05 23:21:05,765 [analyzer] DEBUG: Started auxiliary module Reboot 2026-02-05 23:21:05,812 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-02-05 23:21:05,828 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-02-05 23:21:05,828 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-02-05 23:21:05,828 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-02-05 23:21:06,000 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dudidudida.exe' with arguments '' and pid 2008 2026-02-05 23:21:06,296 [analyzer] DEBUG: Loaded monitor into process with pid 2008 2026-02-05 23:22:00,654 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2026-02-05 23:22:00,951 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2008. 2026-02-05 23:22:01,217 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-02-05 23:22:01,217 [lib.api.process] INFO: Successfully terminated process with pid 2008. 2026-02-05 23:22:01,217 [analyzer] INFO: Analysis completed.
2026-02-06 00:21:05,734 [cuckoo.core.scheduler] INFO: Task #7450894: acquired machine win7x647 (label=win7x647) 2026-02-06 00:21:05,734 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.207 for task #7450894 2026-02-06 00:21:06,237 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3319918 (interface=vboxnet0, host=192.168.168.207) 2026-02-06 00:21:06,949 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x647 2026-02-06 00:21:07,577 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x647 to vmcloak 2026-02-06 00:21:23,109 [cuckoo.core.guest] INFO: Starting analysis #7450894 on guest (id=win7x647, ip=192.168.168.207) 2026-02-06 00:21:24,114 [cuckoo.core.guest] DEBUG: win7x647: not ready yet 2026-02-06 00:21:29,137 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x647, ip=192.168.168.207) 2026-02-06 00:21:29,218 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x647, ip=192.168.168.207, monitor=latest, size=6660546) 2026-02-06 00:21:30,630 [cuckoo.core.resultserver] DEBUG: Task #7450894: live log analysis.log initialized. 2026-02-06 00:21:31,339 [cuckoo.core.resultserver] DEBUG: Task #7450894 is sending a BSON stream 2026-02-06 00:21:31,776 [cuckoo.core.resultserver] DEBUG: Task #7450894 is sending a BSON stream 2026-02-06 00:21:32,601 [cuckoo.core.resultserver] DEBUG: Task #7450894: File upload for 'shots/0001.jpg' 2026-02-06 00:21:32,617 [cuckoo.core.resultserver] DEBUG: Task #7450894 uploaded file length: 111981 2026-02-06 00:21:45,300 [cuckoo.core.guest] DEBUG: win7x647: analysis #7450894 still processing 2026-02-06 00:22:00,393 [cuckoo.core.guest] DEBUG: win7x647: analysis #7450894 still processing 2026-02-06 00:22:01,108 [cuckoo.core.resultserver] DEBUG: Task #7450894: File upload for 'curtain/1770330121.09.curtain.log' 2026-02-06 00:22:01,117 [cuckoo.core.resultserver] DEBUG: Task #7450894 uploaded file length: 36 2026-02-06 00:22:01,211 [cuckoo.core.resultserver] DEBUG: Task #7450894: File upload for 'sysmon/1770330121.2.sysmon.xml' 2026-02-06 00:22:01,216 [cuckoo.core.resultserver] DEBUG: Task #7450894 uploaded file length: 156654 2026-02-06 00:22:01,557 [cuckoo.core.resultserver] DEBUG: Task #7450894: File upload for 'shots/0002.jpg' 2026-02-06 00:22:01,571 [cuckoo.core.resultserver] DEBUG: Task #7450894 uploaded file length: 133496 2026-02-06 00:22:01,586 [cuckoo.core.resultserver] DEBUG: Task #7450894 had connection reset for <Context for LOG> 2026-02-06 00:22:03,409 [cuckoo.core.guest] INFO: win7x647: analysis completed successfully 2026-02-06 00:22:03,424 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-02-06 00:22:03,455 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-02-06 00:22:04,520 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x647 to path /srv/cuckoo/cwd/storage/analyses/7450894/memory.dmp 2026-02-06 00:22:04,521 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x647 2026-02-06 00:22:12,222 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.207 for task #7450894 2026-02-06 00:22:12,543 [cuckoo.core.scheduler] DEBUG: Released database task #7450894 2026-02-06 00:22:12,565 [cuckoo.core.scheduler] INFO: Task #7450894: analysis procedure completed
| description | Checks if being debugged | rule | anti_dbg | ||||||
| description | Anti-Sandbox checks for ThreatExpert | rule | antisb_threatExpert | ||||||
| description | Affect private profile | rule | win_files_operation | ||||||
| section | ._deh |
| section | .minfo |
| section | .dp |
| section | .tp |
| section | .fptable |
| Bkav | W64.AIDetectMalware |
| CrowdStrike | win/malicious_confidence_60% (D) |
| APEX | Malicious |
| McAfeeD | ti!3B578F155219 |
| Detected | |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| DeepInstinct | MALICIOUS |
| Ikarus | Trojan.Win64.Spy |
| MaxSecure | Trojan.Malware.324995110.susgen |