| Size | 172.0KB |
|---|---|
| Type | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5 | 1c0a1c4e35003d2a89e07b9d74601717 |
| SHA1 | 10b321cd9f1abeaf2a9cc56fea73b7e5316bce41 |
| SHA256 | 452c93f41c2f3613f8995d85c0cb8fcb926dd689b128801338918c788ca53cf6 |
| SHA512 |
9424fdf0d3bb208da279b4a0196ddc3cb14c2797065556142f99355b5399bf0c34b6ec1d2fc314461f0d602999cb3daf7d39a7f5b5baf4f04754538cc2c8e29f
|
| CRC32 | F4712857 |
| ssdeep | None |
| PDB Path | BootstrapPackagedGame-Win64-Shipping.pdb |
| Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| ARCHIVE | March 13, 2026, 10:02 a.m. | March 13, 2026, 10:03 a.m. | 65 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-03-13 09:02:29,062 [analyzer] DEBUG: Starting analyzer from: C:\tmptisd8w 2026-03-13 09:02:29,078 [analyzer] DEBUG: Pipe server name: \??\PIPE\tPlrohrZzuCJEZvwmiRBdIP 2026-03-13 09:02:29,078 [analyzer] DEBUG: Log pipe server name: \??\PIPE\xIlFZUrONvwxDUmFcKNDs 2026-03-13 09:02:29,250 [analyzer] DEBUG: Started auxiliary module Curtain 2026-03-13 09:02:29,265 [analyzer] DEBUG: Started auxiliary module DbgView 2026-03-13 09:02:29,655 [analyzer] DEBUG: Started auxiliary module Disguise 2026-03-13 09:02:29,858 [analyzer] DEBUG: Loaded monitor into process with pid 508 2026-03-13 09:02:29,875 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-03-13 09:02:29,875 [analyzer] DEBUG: Started auxiliary module Human 2026-03-13 09:02:29,875 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-03-13 09:02:29,890 [analyzer] DEBUG: Started auxiliary module Reboot 2026-03-13 09:02:30,000 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-03-13 09:02:30,000 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-03-13 09:02:30,000 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-03-13 09:02:30,000 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-03-13 09:02:30,078 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\Windows/SPERAP.exe' with arguments '' and pid 1276 2026-03-13 09:02:30,312 [analyzer] DEBUG: Loaded monitor into process with pid 1276 2026-03-13 09:03:24,910 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2026-03-13 09:03:25,174 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1276. 2026-03-13 09:03:25,424 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-03-13 09:03:25,424 [lib.api.process] INFO: Successfully terminated process with pid 1276. 2026-03-13 09:03:25,424 [analyzer] INFO: Analysis completed.
2026-03-13 10:02:31,090 [cuckoo.core.scheduler] INFO: Task #7484552: acquired machine win7x647 (label=win7x647) 2026-03-13 10:02:31,090 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.207 for task #7484552 2026-03-13 10:02:31,451 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3468603 (interface=vboxnet0, host=192.168.168.207) 2026-03-13 10:02:31,474 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x647 2026-03-13 10:02:32,219 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x647 to vmcloak 2026-03-13 10:02:47,271 [cuckoo.core.guest] INFO: Starting analysis #7484552 on guest (id=win7x647, ip=192.168.168.207) 2026-03-13 10:02:48,277 [cuckoo.core.guest] DEBUG: win7x647: not ready yet 2026-03-13 10:02:53,304 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x647, ip=192.168.168.207) 2026-03-13 10:02:53,400 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x647, ip=192.168.168.207, monitor=latest, size=6660546) 2026-03-13 10:02:54,786 [cuckoo.core.resultserver] DEBUG: Task #7484552: live log analysis.log initialized. 2026-03-13 10:02:55,583 [cuckoo.core.resultserver] DEBUG: Task #7484552 is sending a BSON stream 2026-03-13 10:02:55,944 [cuckoo.core.resultserver] DEBUG: Task #7484552 is sending a BSON stream 2026-03-13 10:02:56,926 [cuckoo.core.resultserver] DEBUG: Task #7484552: File upload for 'shots/0001.jpg' 2026-03-13 10:02:57,052 [cuckoo.core.resultserver] DEBUG: Task #7484552 uploaded file length: 136141 2026-03-13 10:03:09,371 [cuckoo.core.guest] DEBUG: win7x647: analysis #7484552 still processing 2026-03-13 10:03:24,458 [cuckoo.core.guest] DEBUG: win7x647: analysis #7484552 still processing 2026-03-13 10:03:25,324 [cuckoo.core.resultserver] DEBUG: Task #7484552: File upload for 'curtain/1773389005.32.curtain.log' 2026-03-13 10:03:25,328 [cuckoo.core.resultserver] DEBUG: Task #7484552 uploaded file length: 36 2026-03-13 10:03:25,428 [cuckoo.core.resultserver] DEBUG: Task #7484552: File upload for 'sysmon/1773389005.42.sysmon.xml' 2026-03-13 10:03:25,435 [cuckoo.core.resultserver] DEBUG: Task #7484552 uploaded file length: 156454 2026-03-13 10:03:26,015 [cuckoo.core.resultserver] DEBUG: Task #7484552: File upload for 'shots/0002.jpg' 2026-03-13 10:03:26,043 [cuckoo.core.resultserver] DEBUG: Task #7484552 uploaded file length: 133487 2026-03-13 10:03:26,060 [cuckoo.core.resultserver] DEBUG: Task #7484552 had connection reset for <Context for LOG> 2026-03-13 10:03:27,471 [cuckoo.core.guest] INFO: win7x647: analysis completed successfully 2026-03-13 10:03:27,485 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-03-13 10:03:27,513 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-03-13 10:03:28,373 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x647 to path /srv/cuckoo/cwd/storage/analyses/7484552/memory.dmp 2026-03-13 10:03:28,378 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x647 2026-03-13 10:03:36,033 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.207 for task #7484552 2026-03-13 10:03:36,383 [cuckoo.core.scheduler] DEBUG: Released database task #7484552 2026-03-13 10:03:36,401 [cuckoo.core.scheduler] INFO: Task #7484552: analysis procedure completed
| description | Checks if being debugged | rule | anti_dbg | ||||||
| description | Affect system registries | rule | win_registry | ||||||
| description | Affect private profile | rule | win_files_operation | ||||||
| pdb_path | BootstrapPackagedGame-Win64-Shipping.pdb |
| section | _RDATA |