Size | 83.2KB |
---|---|
Type | PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
MD5 | 898d09a4f5aab7c44acd3b3fc757dc5d |
SHA1 | 92127dbbc0045e5a7ca03a9d7d262a85a2e480bc |
SHA256 | cd515bce6de7ac6bb3b2f513718da4ae3da4d3f7a6027e6409ba94291d75e6a3 |
SHA512 |
2039206d2d1f39a053025606f36446cb0ef1e2c0209b752d9db837f8d67c02d387d683f2a90081df2c70046a92751908cb8b24fc29a9e8cd6c765abc02fe0f0b
|
CRC32 | 9003B2D9 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 4, 2025, 12:20 a.m. | July 4, 2025, 12:25 a.m. | 348 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-28 15:58:12,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp564etj 2025-06-28 15:58:12,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\nCBxCtZYMtrHZcnYSuVtaQVN 2025-06-28 15:58:12,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\oYANDBoFuzaKCOMOxHvbQwqSmHLRAGXl 2025-06-28 15:58:12,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-06-28 15:58:12,030 [analyzer] INFO: Automatically selected analysis package "exe" 2025-06-28 15:58:12,296 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-28 15:58:12,296 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-28 15:58:12,842 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-28 15:58:13,078 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-06-28 15:58:13,078 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-28 15:58:13,078 [analyzer] DEBUG: Started auxiliary module Human 2025-06-28 15:58:13,078 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-28 15:58:13,078 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-28 15:58:13,140 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-28 15:58:13,140 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-28 15:58:13,140 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-28 15:58:13,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-28 15:58:13,280 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\cd515bce6de7ac6b_rifaien2-mmd9qzgfmdkalakq.exe' with arguments '' and pid 172 2025-06-28 15:58:13,562 [analyzer] DEBUG: Loaded monitor into process with pid 172 2025-06-28 15:58:13,592 [analyzer] INFO: Added new file to list with pid 172 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-MfWVkTMh3sVcOJbC.exe 2025-06-28 15:58:43,750 [analyzer] INFO: Added new file to list with pid 172 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-n9rlKNyQmKMa7rqI.exe 2025-06-28 15:59:13,812 [analyzer] INFO: Added new file to list with pid 172 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-hsf5OkWMvymCzL7S.exe 2025-06-28 15:59:43,890 [analyzer] INFO: Added new file to list with pid 172 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-UUWWupMbEdlWKyEF.exe 2025-06-28 16:00:13,953 [analyzer] INFO: Added new file to list with pid 172 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-lnw39cl6dYEHfPqS.exe 2025-06-28 16:00:44,015 [analyzer] INFO: Added new file to list with pid 172 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-zblsJ0UuJ4BNe6Xo.exe 2025-06-28 16:01:14,078 [analyzer] INFO: Added new file to list with pid 172 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-jP4VJ2NYPbFzPvhx.exe 2025-06-28 16:01:32,312 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-28 16:01:33,467 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-28 16:01:33,467 [lib.api.process] INFO: Successfully terminated process with pid 172. 2025-06-28 16:01:33,467 [analyzer] INFO: Analysis completed.
2025-07-04 00:20:08,470 [cuckoo.core.scheduler] INFO: Task #6641904: acquired machine win7x6419 (label=win7x6419) 2025-07-04 00:20:08,471 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.219 for task #6641904 2025-07-04 00:20:08,785 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 297765 (interface=vboxnet0, host=192.168.168.219) 2025-07-04 00:20:08,896 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6419 2025-07-04 00:20:09,464 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6419 to vmcloak 2025-07-04 00:20:54,998 [cuckoo.core.guest] INFO: Starting analysis #6641904 on guest (id=win7x6419, ip=192.168.168.219) 2025-07-04 00:20:56,004 [cuckoo.core.guest] DEBUG: win7x6419: not ready yet 2025-07-04 00:21:01,027 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6419, ip=192.168.168.219) 2025-07-04 00:21:01,121 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6419, ip=192.168.168.219, monitor=latest, size=6660546) 2025-07-04 00:21:02,389 [cuckoo.core.resultserver] DEBUG: Task #6641904: live log analysis.log initialized. 2025-07-04 00:21:03,445 [cuckoo.core.resultserver] DEBUG: Task #6641904 is sending a BSON stream 2025-07-04 00:21:03,878 [cuckoo.core.resultserver] DEBUG: Task #6641904 is sending a BSON stream 2025-07-04 00:21:04,149 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'files/8c563c9aec57f3d6_rifaien2-MfWVkTMh3sVcOJbC.exe' 2025-07-04 00:21:04,172 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 85156 2025-07-04 00:21:04,654 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'shots/0001.jpg' 2025-07-04 00:21:04,681 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 155125 2025-07-04 00:21:17,116 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:21:32,225 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:21:34,215 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'files/9578eeb316e26af6_rifaien2-n9rlKNyQmKMa7rqI.exe' 2025-07-04 00:21:34,217 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 85156 2025-07-04 00:21:34,340 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'shots/0002.jpg' 2025-07-04 00:21:34,381 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 155239 2025-07-04 00:21:47,387 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:22:02,547 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:22:04,281 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'files/c59b5add431a68cb_rifaien2-hsf5OkWMvymCzL7S.exe' 2025-07-04 00:22:04,285 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 85156 2025-07-04 00:22:05,041 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'shots/0003.jpg' 2025-07-04 00:22:05,058 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 155408 2025-07-04 00:22:17,776 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:22:32,938 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:22:34,350 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'files/14aae7355f746e95_rifaien2-UUWWupMbEdlWKyEF.exe' 2025-07-04 00:22:34,353 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 85156 2025-07-04 00:22:34,714 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'shots/0004.jpg' 2025-07-04 00:22:34,732 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 157519 2025-07-04 00:22:48,150 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:23:03,305 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:23:04,412 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'files/a78789d6d3fe297e_rifaien2-lnw39cl6dYEHfPqS.exe' 2025-07-04 00:23:04,415 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 85156 2025-07-04 00:23:05,386 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'shots/0005.jpg' 2025-07-04 00:23:05,400 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 157705 2025-07-04 00:23:18,617 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:23:33,709 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:23:34,548 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'files/16bd49d5f2befa28_rifaien2-zblsJ0UuJ4BNe6Xo.exe' 2025-07-04 00:23:34,552 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 85156 2025-07-04 00:23:40,644 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'shots/0006.jpg' 2025-07-04 00:23:40,800 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 157662 2025-07-04 00:23:55,781 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:24:04,566 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'files/ce6495574f3304c5_rifaien2-jP4VJ2NYPbFzPvhx.exe' 2025-07-04 00:24:04,571 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 85156 2025-07-04 00:24:05,349 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'shots/0007.jpg' 2025-07-04 00:24:05,369 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 155151 2025-07-04 00:24:11,071 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6641904 still processing 2025-07-04 00:24:22,885 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'curtain/1751119292.47.curtain.log' 2025-07-04 00:24:22,907 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 36 2025-07-04 00:24:23,573 [cuckoo.core.resultserver] DEBUG: Task #6641904: File upload for 'sysmon/1751119293.17.sysmon.xml' 2025-07-04 00:24:23,875 [cuckoo.core.resultserver] DEBUG: Task #6641904 uploaded file length: 10618368 2025-07-04 00:24:23,908 [cuckoo.core.resultserver] DEBUG: Task #6641904 had connection reset for <Context for LOG> 2025-07-04 00:24:26,351 [cuckoo.core.guest] INFO: win7x6419: analysis completed successfully 2025-07-04 00:24:26,369 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-04 00:24:26,397 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-04 00:24:27,191 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6419 to path /srv/cuckoo/cwd/storage/analyses/6641904/memory.dmp 2025-07-04 00:24:27,195 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6419 2025-07-04 00:25:56,205 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.219 for task #6641904 2025-07-04 00:25:56,878 [cuckoo.core.scheduler] DEBUG: Released database task #6641904 2025-07-04 00:25:56,921 [cuckoo.core.scheduler] INFO: Task #6641904: analysis procedure completed
description | (no description) | rule | UPX | ||||||
description | The packer/protector section names/keywords | rule | suspicious_packer_section | ||||||
description | Communications over RAW socket | rule | network_tcp_socket |
packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
description | cd515bce6de7ac6b_rifaien2-mmd9qzgfmdkalakq.exe tried to sleep 210 seconds, actually delayed analysis time by 180 seconds |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-jP4VJ2NYPbFzPvhx.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-zblsJ0UuJ4BNe6Xo.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-n9rlKNyQmKMa7rqI.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-MfWVkTMh3sVcOJbC.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-UUWWupMbEdlWKyEF.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-lnw39cl6dYEHfPqS.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-hsf5OkWMvymCzL7S.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-MfWVkTMh3sVcOJbC.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-n9rlKNyQmKMa7rqI.exe |
section | {u'size_of_data': u'0x00014800', u'virtual_address': u'0x00014000', u'entropy': 7.711094899099775, u'name': u'UPX1', u'virtual_size': u'0x00015000'} | entropy | 7.7110948991 | description | A section with a high entropy has been found | |||||||||
entropy | 0.993939393939 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX | ||||||
section | UPX2 | description | Section name indicates UPX |
buffer | Buffer with sha1: 97653fe98384b5bef285a95b60548b73adae825a |
suricata | ETPRO MALWARE Win32/Snojan Variant Uploading EXE |
suricata | ET INFO Generic HTTP EXE Upload Outbound |
G Data Antivirus (Windows) | Virus: Trojan.Agent.CYZT (Engine A), Win32.Application.Snojan.A (Engine B) |
Avast Core Security (Linux) | Win32:MalwareX-gen [Trj] |
C4S ClamAV (Linux) | YARA.UPX.UNOFFICIAL |
WithSecure (Linux) | Trojan.TR/Crypt.ULPM.Gen2 |
eScan Antivirus (Linux) | Trojan.Agent.CYZT(DB) |
ESET Security (Windows) | a variant of Win32/Agent.AAEF trojan |
Sophos Anti-Virus (Linux) | Troj/Bdoor-BHD |
ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
Bitdefender Antivirus (Linux) | Trojan.Agent.CYZT |
Kaspersky Standard (Windows) | HEUR:Flooder.Win32.CoreWarrior.a |
Emsisoft Commandline Scanner (Windows) | Trojan.Agent.CYZT (B) |