Size | 643.5KB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 40c3f00df6d71c80b512a0fda6090f09 |
SHA1 | 7402f293dc6df4049eb373eff0ce634e43465cda |
SHA256 | 10f17b5bd68e71d637b20f2d8a4e2bda3e4a929a61d13f5a2423d8a4d6910f40 |
SHA512 |
e9228b68c995f061767bce98305f63ec045117005693a1519fc48d7b4ad48f960612da11a3d779e902341bb4de59f6151a9307813de5b76c3a5ec1c91314845e
|
CRC32 | 28114F8A |
ssdeep | None |
PDB Path | C:\Development\Utilities\CDMUninstaller\CDMUninstaller\DriverUninstallerGUI\Release\ctl_one.pdb |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
ARCHIVE | June 15, 2025, 1:04 p.m. | June 15, 2025, 1:07 p.m. | 162 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-15 13:04:27,062 [analyzer] DEBUG: Starting analyzer from: C:\tmpt1gcja 2025-06-15 13:04:27,062 [analyzer] DEBUG: Pipe server name: \??\PIPE\nOCqyKeAaLHvVfwbViAFKhAlbJf 2025-06-15 13:04:27,062 [analyzer] DEBUG: Log pipe server name: \??\PIPE\YGGpuHXSspiLeDFck 2025-06-15 13:04:27,296 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-15 13:04:27,296 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-15 13:04:27,703 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-15 13:04:27,905 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-06-15 13:04:27,905 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-15 13:04:27,905 [analyzer] DEBUG: Started auxiliary module Human 2025-06-15 13:04:27,905 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-15 13:04:27,905 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-15 13:04:28,015 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-15 13:04:28,015 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-15 13:04:28,030 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-15 13:04:28,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-15 13:04:28,171 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\FDTI CDM v2.12.36.4 WHQL Certified/CDMUninstaller.exe' with arguments '' and pid 556 2025-06-15 13:04:28,405 [analyzer] DEBUG: Loaded monitor into process with pid 556 2025-06-15 12:05:21,684 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-15 12:05:21,950 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 556. 2025-06-15 12:05:22,230 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-15 12:05:22,246 [lib.api.process] INFO: Successfully terminated process with pid 556. 2025-06-15 12:05:22,246 [analyzer] INFO: Analysis completed.
2025-06-15 13:04:27,668 [cuckoo.core.scheduler] INFO: Task #6556659: acquired machine win7x642 (label=win7x642) 2025-06-15 13:04:27,669 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.202 for task #6556659 2025-06-15 13:04:27,902 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1400651 (interface=vboxnet0, host=192.168.168.202) 2025-06-15 13:04:27,924 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x642 2025-06-15 13:04:28,339 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x642 to vmcloak 2025-06-15 13:04:43,846 [cuckoo.core.guest] INFO: Starting analysis #6556659 on guest (id=win7x642, ip=192.168.168.202) 2025-06-15 13:04:44,897 [cuckoo.core.guest] DEBUG: win7x642: not ready yet 2025-06-15 13:04:49,942 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x642, ip=192.168.168.202) 2025-06-15 13:04:50,010 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x642, ip=192.168.168.202, monitor=latest, size=6660546) 2025-06-15 13:04:51,498 [cuckoo.core.resultserver] DEBUG: Task #6556659: live log analysis.log initialized. 2025-06-15 13:04:52,350 [cuckoo.core.resultserver] DEBUG: Task #6556659 is sending a BSON stream 2025-06-15 13:04:52,834 [cuckoo.core.resultserver] DEBUG: Task #6556659 is sending a BSON stream 2025-06-15 13:04:53,739 [cuckoo.core.resultserver] DEBUG: Task #6556659: File upload for 'shots/0001.jpg' 2025-06-15 13:04:53,751 [cuckoo.core.resultserver] DEBUG: Task #6556659 uploaded file length: 136010 2025-06-15 13:05:06,343 [cuckoo.core.guest] DEBUG: win7x642: analysis #6556659 still processing 2025-06-15 13:05:21,459 [cuckoo.core.guest] DEBUG: win7x642: analysis #6556659 still processing 2025-06-15 13:05:22,129 [cuckoo.core.resultserver] DEBUG: Task #6556659: File upload for 'curtain/1749981922.12.curtain.log' 2025-06-15 13:05:22,132 [cuckoo.core.resultserver] DEBUG: Task #6556659 uploaded file length: 36 2025-06-15 13:05:22,236 [cuckoo.core.resultserver] DEBUG: Task #6556659: File upload for 'sysmon/1749981922.23.sysmon.xml' 2025-06-15 13:05:22,242 [cuckoo.core.resultserver] DEBUG: Task #6556659 uploaded file length: 358288 2025-06-15 13:05:22,734 [cuckoo.core.resultserver] DEBUG: Task #6556659: File upload for 'shots/0002.jpg' 2025-06-15 13:05:22,745 [cuckoo.core.resultserver] DEBUG: Task #6556659 uploaded file length: 133606 2025-06-15 13:05:22,764 [cuckoo.core.resultserver] DEBUG: Task #6556659 had connection reset for <Context for LOG> 2025-06-15 13:05:24,475 [cuckoo.core.guest] INFO: win7x642: analysis completed successfully 2025-06-15 13:05:24,489 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-15 13:05:24,518 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-15 13:05:25,125 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x642 to path /srv/cuckoo/cwd/storage/analyses/6556659/memory.dmp 2025-06-15 13:05:25,126 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x642 2025-06-15 13:07:08,033 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.202 for task #6556659 2025-06-15 13:07:09,446 [cuckoo.core.scheduler] DEBUG: Released database task #6556659 2025-06-15 13:07:09,466 [cuckoo.core.scheduler] INFO: Task #6556659: analysis procedure completed
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Escalade priviledges | rule | escalate_priv | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect system token | rule | win_token | ||||||
description | Affect private profile | rule | win_files_operation |
pdb_path | C:\Development\Utilities\CDMUninstaller\CDMUninstaller\DriverUninstallerGUI\Release\ctl_one.pdb |
MaxSecure | Trojan.Malware.11973.susgen |