Size | 162.9MB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 5b47f417c7a7852747989fcb43999ff8 |
SHA1 | aa0606d7fd7ac554063c7c96452f4e99d5a2c8be |
SHA256 | 8939ee7269967a56ce0082db3a26acee08da92c41f63652f0e8d61f813bd47c4 |
SHA512 |
8613c7edaba1239b5d031717fa9b4afac93ed82416b30883f542569cc502a30623276e0974e285544a91730bff90099634835174dee3a5f206c4abe756619139
|
CRC32 | A6584FA3 |
ssdeep | None |
PDB Path | D:\scljenkins-slv\workspace\ESD-current-CI\ESD\src\bin\Release\AdDLMgrSFX.pdb |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Dec. 25, 2024, 6:43 p.m. | Dec. 25, 2024, 6:45 p.m. | 109 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2024-12-25 17:43:40,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4 2024-12-25 17:43:40,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\QmtdswjESmQJyttCjNGkdOARIyXs 2024-12-25 17:43:40,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\kEUIUFMPmNMkprSEeejhzPaduCNwNq 2024-12-25 17:43:40,265 [analyzer] DEBUG: Started auxiliary module Curtain 2024-12-25 17:43:40,280 [analyzer] DEBUG: Started auxiliary module DbgView 2024-12-25 17:43:40,717 [analyzer] DEBUG: Started auxiliary module Disguise 2024-12-25 17:43:40,890 [analyzer] DEBUG: Loaded monitor into process with pid 504 2024-12-25 17:43:40,890 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2024-12-25 17:43:40,890 [analyzer] DEBUG: Started auxiliary module Human 2024-12-25 17:43:40,890 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2024-12-25 17:43:40,905 [analyzer] DEBUG: Started auxiliary module Reboot 2024-12-25 17:43:41,000 [analyzer] DEBUG: Started auxiliary module RecentFiles 2024-12-25 17:43:41,000 [analyzer] DEBUG: Started auxiliary module Screenshots 2024-12-25 17:43:41,000 [analyzer] DEBUG: Started auxiliary module Sysmon 2024-12-25 17:43:41,000 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2024-12-25 17:43:42,703 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\AutoCAD_2020_student.64.exe' with arguments '' and pid 1948 2024-12-25 17:43:42,905 [analyzer] DEBUG: Loaded monitor into process with pid 1948 2024-12-25 17:45:27,762 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2024-12-25 17:45:28,167 [analyzer] INFO: Terminating remaining processes before shutdown. 2024-12-25 17:45:28,167 [lib.api.process] INFO: Successfully terminated process with pid 1948. 2024-12-25 17:45:28,167 [analyzer] INFO: Analysis completed.
2024-12-25 18:43:51,300 [cuckoo.core.scheduler] INFO: Task #5695834: acquired machine win7x644 (label=win7x644) 2024-12-25 18:43:51,301 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #5695834 2024-12-25 18:43:51,532 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 219267 (interface=vboxnet0, host=192.168.168.204) 2024-12-25 18:44:31,861 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644 2024-12-25 18:44:32,291 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak 2024-12-25 18:44:41,849 [cuckoo.core.guest] INFO: Starting analysis #5695834 on guest (id=win7x644, ip=192.168.168.204) 2024-12-25 18:44:42,855 [cuckoo.core.guest] DEBUG: win7x644: not ready yet 2024-12-25 18:44:47,884 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204) 2024-12-25 18:44:47,965 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546) 2024-12-25 18:44:56,025 [cuckoo.core.resultserver] DEBUG: Task #5695834: live log analysis.log initialized. 2024-12-25 18:44:56,869 [cuckoo.core.resultserver] DEBUG: Task #5695834 is sending a BSON stream 2024-12-25 18:44:58,182 [cuckoo.core.resultserver] DEBUG: Task #5695834: File upload for 'shots/0001.jpg' 2024-12-25 18:44:58,193 [cuckoo.core.resultserver] DEBUG: Task #5695834 uploaded file length: 133529 2024-12-25 18:44:58,868 [cuckoo.core.resultserver] DEBUG: Task #5695834 is sending a BSON stream 2024-12-25 18:45:02,375 [cuckoo.core.resultserver] DEBUG: Task #5695834: File upload for 'shots/0002.jpg' 2024-12-25 18:45:02,395 [cuckoo.core.resultserver] DEBUG: Task #5695834 uploaded file length: 131187 2024-12-25 18:45:10,750 [cuckoo.core.guest] DEBUG: win7x644: analysis #5695834 still processing 2024-12-25 18:45:25,836 [cuckoo.core.guest] DEBUG: win7x644: analysis #5695834 still processing 2024-12-25 18:45:28,027 [cuckoo.core.resultserver] DEBUG: Task #5695834: File upload for 'curtain/1735145128.03.curtain.log' 2024-12-25 18:45:28,030 [cuckoo.core.resultserver] DEBUG: Task #5695834 uploaded file length: 36 2024-12-25 18:45:28,148 [cuckoo.core.resultserver] DEBUG: Task #5695834: File upload for 'sysmon/1735145128.14.sysmon.xml' 2024-12-25 18:45:28,171 [cuckoo.core.resultserver] DEBUG: Task #5695834 uploaded file length: 92184 2024-12-25 18:45:28,207 [cuckoo.core.resultserver] DEBUG: Task #5695834 had connection reset for <Context for LOG> 2024-12-25 18:45:28,849 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully 2024-12-25 18:45:28,861 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2024-12-25 18:45:28,883 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2024-12-25 18:45:29,614 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/5695834/memory.dmp 2024-12-25 18:45:29,616 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644 2024-12-25 18:45:36,936 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #5695834 2024-12-25 18:45:37,230 [cuckoo.core.scheduler] DEBUG: Released database task #5695834 2024-12-25 18:45:37,249 [cuckoo.core.scheduler] INFO: Task #5695834: analysis procedure completed
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Take screenshot | rule | screenshot | ||||||
description | Run a keylogger | rule | keylogger | ||||||
description | Create or check mutex | rule | win_mutex | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect private profile | rule | win_files_operation |
pdb_path | D:\scljenkins-slv\workspace\ESD-current-CI\ESD\src\bin\Release\AdDLMgrSFX.pdb |
resource name | PNG |