Archive NirSoft/x64/regfromapp.exe @ WinPE11_10_8_Sergei_Strelec_x86_x64_2024.08.21_English.iso

Size 94.6KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 5d6c01a906025220ad6fb565e3538016
SHA1 e6ec6fb1fa67702c8ca2c6dd879041550bc8d899
SHA256 a745831032340b3f68d3171c150e3f176a59cd6c633d90d843de8d205e426e71
SHA512
7894f4bfe8886a13ad39fa51b4347b7fe713b5e6da6d7a64cba1b3b7c5185f83da153ea78582e732913bc724d93113a00649baaa1f9cb39037046b59b6b7331e
CRC32 B666B568
ssdeep None
PDB Path c:\Projects\VS2005\RegFromApp\x64\Release\RegFromApp.pdb
Yara
  • inject_thread - Code injection with CreateRemoteThread in a remote process
  • screenshot - Take screenshot

Score

This archive appears fairly benign with a score of 0.9 out of 10.

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
ARCHIVE March 4, 2026, 9:46 p.m. March 4, 2026, 9:54 p.m. 479 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2026-03-04 20:45:13,937 [analyzer] DEBUG: Starting analyzer from: C:\tmp4hzt0l
2026-03-04 20:45:13,937 [analyzer] DEBUG: Pipe server name: \??\PIPE\bbmUAuyRWKRtJsBUJqDu
2026-03-04 20:45:13,937 [analyzer] DEBUG: Log pipe server name: \??\PIPE\IfyFyyFMHNJKbhlQRPSwNMpsewPOqr
2026-03-04 20:45:14,187 [analyzer] DEBUG: Started auxiliary module Curtain
2026-03-04 20:45:14,187 [analyzer] DEBUG: Started auxiliary module DbgView
2026-03-04 20:45:14,671 [analyzer] DEBUG: Started auxiliary module Disguise
2026-03-04 20:45:14,875 [analyzer] DEBUG: Loaded monitor into process with pid 504
2026-03-04 20:45:14,875 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2026-03-04 20:45:14,875 [analyzer] DEBUG: Started auxiliary module Human
2026-03-04 20:45:14,875 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2026-03-04 20:45:14,875 [analyzer] DEBUG: Started auxiliary module Reboot
2026-03-04 20:45:14,983 [analyzer] DEBUG: Started auxiliary module RecentFiles
2026-03-04 20:45:14,983 [analyzer] DEBUG: Started auxiliary module Screenshots
2026-03-04 20:45:14,983 [analyzer] DEBUG: Started auxiliary module Sysmon
2026-03-04 20:45:15,000 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2026-03-04 20:45:15,108 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\NirSoft/x64/regfromapp.exe' with arguments '' and pid 1520
2026-03-04 20:45:15,342 [analyzer] DEBUG: Loaded monitor into process with pid 1520
2026-03-04 20:52:05,490 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2026-03-04 20:52:05,740 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1520.
2026-03-04 20:52:06,069 [analyzer] INFO: Terminating remaining processes before shutdown.
2026-03-04 20:52:06,069 [lib.api.process] INFO: Successfully terminated process with pid 1520.
2026-03-04 20:52:06,069 [analyzer] INFO: Analysis completed.

Cuckoo Log

2026-03-04 21:46:56,822 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:46:57,846 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:00,210 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:01,249 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:04,128 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:06,649 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:07,886 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:08,970 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:10,069 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:11,512 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:12,594 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:13,704 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:14,792 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:16,077 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:17,273 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:18,381 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:19,432 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:20,469 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:22,980 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:24,040 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:26,991 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:28,321 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:29,354 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:30,413 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:31,467 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:32,490 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:33,514 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:34,640 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:35,925 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:37,012 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:38,079 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:39,128 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:40,171 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:41,211 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:44,350 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:45,988 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:47,264 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:48,353 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:49,447 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:50,501 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:51,551 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:54,568 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:55,693 [cuckoo.core.scheduler] DEBUG: Task #7475203: no machine available yet
2026-03-04 21:47:56,993 [cuckoo.core.scheduler] INFO: Task #7475203: acquired machine win7x6420 (label=win7x6420)
2026-03-04 21:47:57,018 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.220 for task #7475203
2026-03-04 21:47:57,659 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3335329 (interface=vboxnet0, host=192.168.168.220)
2026-03-04 21:47:57,711 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6420
2026-03-04 21:48:05,204 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6420 to vmcloak
2026-03-04 21:51:22,436 [cuckoo.core.guest] INFO: Starting analysis #7475203 on guest (id=win7x6420, ip=192.168.168.220)
2026-03-04 21:51:23,561 [cuckoo.core.guest] DEBUG: win7x6420: not ready yet
2026-03-04 21:51:28,596 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6420, ip=192.168.168.220)
2026-03-04 21:51:28,678 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6420, ip=192.168.168.220, monitor=latest, size=6660546)
2026-03-04 21:51:34,374 [cuckoo.core.resultserver] DEBUG: Task #7475203: live log analysis.log initialized.
2026-03-04 21:51:36,217 [cuckoo.core.resultserver] DEBUG: Task #7475203 is sending a BSON stream
2026-03-04 21:51:36,637 [cuckoo.core.resultserver] DEBUG: Task #7475203 is sending a BSON stream
2026-03-04 21:51:37,490 [cuckoo.core.resultserver] DEBUG: Task #7475203: File upload for 'shots/0001.jpg'
2026-03-04 21:51:37,524 [cuckoo.core.resultserver] DEBUG: Task #7475203 uploaded file length: 137529
2026-03-04 21:51:38,654 [cuckoo.core.resultserver] DEBUG: Task #7475203: File upload for 'shots/0002.jpg'
2026-03-04 21:51:38,683 [cuckoo.core.resultserver] DEBUG: Task #7475203 uploaded file length: 107570
2026-03-04 21:51:40,945 [cuckoo.core.resultserver] DEBUG: Task #7475203: File upload for 'shots/0003.jpg'
2026-03-04 21:51:40,958 [cuckoo.core.resultserver] DEBUG: Task #7475203 uploaded file length: 152112
2026-03-04 21:51:49,119 [cuckoo.core.guest] DEBUG: win7x6420: analysis #7475203 still processing
2026-03-04 21:52:05,860 [cuckoo.core.resultserver] DEBUG: Task #7475203: File upload for 'curtain/1772653925.85.curtain.log'
2026-03-04 21:52:05,863 [cuckoo.core.resultserver] DEBUG: Task #7475203 uploaded file length: 36
2026-03-04 21:52:05,988 [cuckoo.core.guest] DEBUG: win7x6420: analysis #7475203 still processing
2026-03-04 21:52:06,039 [cuckoo.core.resultserver] DEBUG: Task #7475203: File upload for 'sysmon/1772653926.04.sysmon.xml'
2026-03-04 21:52:06,069 [cuckoo.core.resultserver] DEBUG: Task #7475203 uploaded file length: 1699868
2026-03-04 21:52:06,643 [cuckoo.core.resultserver] DEBUG: Task #7475203: File upload for 'shots/0004.jpg'
2026-03-04 21:52:06,662 [cuckoo.core.resultserver] DEBUG: Task #7475203 uploaded file length: 133450
2026-03-04 21:52:06,674 [cuckoo.core.resultserver] DEBUG: Task #7475203 had connection reset for <Context for LOG>
2026-03-04 21:52:09,005 [cuckoo.core.guest] INFO: win7x6420: analysis completed successfully
2026-03-04 21:52:09,016 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2026-03-04 21:52:09,046 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2026-03-04 21:52:10,613 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6420 to path /srv/cuckoo/cwd/storage/analyses/7475203/memory.dmp
2026-03-04 21:52:10,614 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6420
2026-03-04 21:54:52,866 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.220 for task #7475203
2026-03-04 21:54:53,287 [cuckoo.core.scheduler] DEBUG: Released database task #7475203
2026-03-04 21:54:53,301 [cuckoo.core.scheduler] INFO: Task #7475203: analysis procedure completed

Signatures

Yara rules detected for file (2 events)
description Code injection with CreateRemoteThread in a remote process rule inject_thread
description Take screenshot rule screenshot
Checks if process is being debugged by a debugger (1 event)
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
This executable has a PDB path (1 event)
pdb_path c:\Projects\VS2005\RegFromApp\x64\Release\RegFromApp.pdb
The file contains an unknown PE resource name possibly indicative of a packer (1 event)
resource name BIN
Checks for the Locally Unique Identifier on the system for a suspicious privilege (1 event)
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.