Size | 361.0KB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 9700bbc1b3ce1afcd9e698603ec0cf72 |
SHA1 | 55edb6f0555d614966389f13b2a1984a73ab53fc |
SHA256 | dca205429af844e31f312f41ea6927d425b9ff921b8dfe89b3efa7234d74c890 |
SHA512 |
65b79813f9a3f2c9ca563e156b4b32f13eb2ab76d2f2df0bfa96460ffc6f4532f72ee8a74a8156b3605ebcfd953f156d48196cf72cbce1d6f56d5c2764de1702
|
CRC32 | 731CDB12 |
ssdeep | None |
PDB Path | f:\软件工ç¨\驱å¨ç¼ç¨\OK\KernelYK\bin\InstallSYS.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 11, 2025, 8:05 p.m. | July 11, 2025, 8:12 p.m. | 462 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-08 14:28:01,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpdyrg_l 2025-07-08 14:28:01,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ihjVWyhmVjHLqAYhjYawwrGkOapU 2025-07-08 14:28:01,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\gHlAGqUqiWRZXyiBpSLAJIrJrXnoGT 2025-07-08 14:28:01,437 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-08 14:28:01,437 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-08 14:28:02,155 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-08 14:28:02,358 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-07-08 14:28:02,358 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-08 14:28:02,358 [analyzer] DEBUG: Started auxiliary module Human 2025-07-08 14:28:02,358 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-08 14:28:02,358 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-08 14:28:02,483 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-08 14:28:02,483 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-08 14:28:02,483 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-08 14:28:02,483 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-08 14:28:02,655 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\dca205429af844e31f312f41ea6927d425b9ff921b8dfe89b3efa7234d74c890.exe' with arguments '' and pid 1508 2025-07-08 14:28:02,858 [analyzer] DEBUG: Loaded monitor into process with pid 1508 2025-07-08 14:28:03,405 [analyzer] INFO: Added new file to list with pid 1508 and path C:\Temp\CreateProcess.exe 2025-07-08 14:28:04,421 [analyzer] INFO: Added new file to list with pid 1508 and path C:\Temp\ytqlidbvtnlgdyvq.exe 2025-07-08 14:28:04,562 [analyzer] INFO: Injected into process with pid 2320 and name u'ytqlidbvtnlgdyvq.exe' 2025-07-08 14:28:04,671 [analyzer] INFO: Injected into process with pid 1660 and name u'iexplore.exe' 2025-07-08 14:28:04,703 [analyzer] DEBUG: Loaded monitor into process with pid 2320 2025-07-08 14:28:04,750 [analyzer] INFO: Added new file to list with pid 2320 and path \Device\NamedPipe\lsass 2025-07-08 14:28:04,905 [analyzer] DEBUG: Loaded monitor into process with pid 1660 2025-07-08 14:28:06,671 [analyzer] INFO: Added new file to list with pid 1508 and path C:\Temp\ytqlidbvtnlgdyvq.sys 2025-07-08 14:28:07,437 [analyzer] INFO: Added new file to list with pid 2320 and path C:\Temp\omhezwrpjh.exe 2025-07-08 14:28:07,483 [analyzer] INFO: Injected into process with pid 1500 and name u'CreateProcess.exe' 2025-07-08 14:28:07,640 [analyzer] DEBUG: Loaded monitor into process with pid 1500 2025-07-08 14:28:07,671 [analyzer] INFO: Process with pid 1508 has terminated 2025-07-08 14:28:08,671 [analyzer] INFO: Process with pid 1500 has terminated 2025-07-08 14:28:09,921 [analyzer] INFO: Added new file to list with pid 2320 and path C:\Temp\i_omhezwrpjh.exe 2025-07-08 14:28:15,296 [analyzer] INFO: Added new file to list with pid 2320 and path C:\Temp\jgbztrljeb.exe 2025-07-08 14:28:31,671 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-07-08 14:28:32,140 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-08 14:28:32,140 [lib.api.process] INFO: Successfully terminated process with pid 2320. 2025-07-08 14:28:32,140 [lib.api.process] INFO: Successfully terminated process with pid 1660. 2025-07-08 14:28:32,140 [analyzer] WARNING: File at path u'\\device\\namedpipe\\lsass' does not exist, skip. 2025-07-08 14:28:32,171 [analyzer] INFO: Analysis completed.
2025-07-11 20:05:14,433 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:15,464 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:16,493 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:17,526 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:18,563 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:19,590 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:20,617 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:21,652 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:22,675 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:23,702 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:24,723 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:25,749 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:26,781 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:27,810 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:28,834 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:29,857 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:30,887 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:31,919 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:32,942 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:33,964 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:35,021 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:36,054 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:37,083 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:38,107 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:39,137 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:40,165 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:41,190 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:42,222 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:43,251 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:44,345 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:45,410 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:46,508 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:47,557 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:48,615 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:49,687 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:50,773 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:51,824 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:52,877 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:54,080 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:55,294 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:56,336 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:57,405 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:58,439 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:05:59,491 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:00,527 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:01,579 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:02,598 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:03,632 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:04,660 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:05,686 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:06,720 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:07,943 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:08,987 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:10,024 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:11,054 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:12,082 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:13,112 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:14,137 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:15,157 [cuckoo.core.scheduler] DEBUG: Task #6687576: no machine available yet 2025-07-11 20:06:16,301 [cuckoo.core.scheduler] INFO: Task #6687576: acquired machine win7x6430 (label=win7x6430) 2025-07-11 20:06:16,302 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.230 for task #6687576 2025-07-11 20:06:16,769 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3853334 (interface=vboxnet0, host=192.168.168.230) 2025-07-11 20:06:17,064 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6430 2025-07-11 20:06:17,965 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6430 to vmcloak 2025-07-11 20:09:42,745 [cuckoo.core.guest] INFO: Starting analysis #6687576 on guest (id=win7x6430, ip=192.168.168.230) 2025-07-11 20:09:43,751 [cuckoo.core.guest] DEBUG: win7x6430: not ready yet 2025-07-11 20:09:48,792 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6430, ip=192.168.168.230) 2025-07-11 20:09:48,930 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6430, ip=192.168.168.230, monitor=latest, size=6660546) 2025-07-11 20:09:50,583 [cuckoo.core.resultserver] DEBUG: Task #6687576: live log analysis.log initialized. 2025-07-11 20:09:51,894 [cuckoo.core.resultserver] DEBUG: Task #6687576 is sending a BSON stream 2025-07-11 20:09:52,379 [cuckoo.core.resultserver] DEBUG: Task #6687576 is sending a BSON stream 2025-07-11 20:09:53,321 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'shots/0001.jpg' 2025-07-11 20:09:53,334 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 133445 2025-07-11 20:09:54,239 [cuckoo.core.resultserver] DEBUG: Task #6687576 is sending a BSON stream 2025-07-11 20:09:54,363 [cuckoo.core.resultserver] DEBUG: Task #6687576 is sending a BSON stream 2025-07-11 20:09:57,175 [cuckoo.core.resultserver] DEBUG: Task #6687576 is sending a BSON stream 2025-07-11 20:09:57,540 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'files/6b490819a7dd93fb_omhezwrpjh.exe' 2025-07-11 20:09:57,546 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 369664 2025-07-11 20:10:02,333 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'files/11ade02e3450116e_i_omhezwrpjh.exe' 2025-07-11 20:10:02,397 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 369664 2025-07-11 20:10:05,461 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6687576 still processing 2025-07-11 20:10:20,565 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6687576 still processing 2025-07-11 20:10:21,540 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'curtain/1751977711.92.curtain.log' 2025-07-11 20:10:21,544 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 36 2025-07-11 20:10:21,732 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'sysmon/1751977712.11.sysmon.xml' 2025-07-11 20:10:21,756 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 1534508 2025-07-11 20:10:21,767 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'files/1a9646f370251a0b_jgbztrljeb.exe' 2025-07-11 20:10:21,771 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 369664 2025-07-11 20:10:21,774 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'files/cb9d9ccd19610563_ytqlidbvtnlgdyvq.sys' 2025-07-11 20:10:21,779 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 300544 2025-07-11 20:10:21,782 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'files/568c842eedf355f0_ytqlidbvtnlgdyvq.exe' 2025-07-11 20:10:21,785 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 369664 2025-07-11 20:10:21,793 [cuckoo.core.resultserver] DEBUG: Task #6687576: File upload for 'files/6bb8614177548234_createprocess.exe' 2025-07-11 20:10:21,795 [cuckoo.core.resultserver] DEBUG: Task #6687576 uploaded file length: 3584 2025-07-11 20:10:22,200 [cuckoo.core.resultserver] DEBUG: Task #6687576 had connection reset for <Context for LOG> 2025-07-11 20:10:23,583 [cuckoo.core.guest] INFO: win7x6430: analysis completed successfully 2025-07-11 20:10:23,598 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-11 20:10:23,625 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-11 20:10:24,789 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6430 to path /srv/cuckoo/cwd/storage/analyses/6687576/memory.dmp 2025-07-11 20:10:24,790 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6430 2025-07-11 20:12:56,211 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.230 for task #6687576 2025-07-11 20:12:56,993 [cuckoo.core.scheduler] DEBUG: Released database task #6687576 2025-07-11 20:12:57,034 [cuckoo.core.scheduler] INFO: Task #6687576: analysis procedure completed
description | Possibly employs anti-virtualization techniques | rule | vmdetect | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | inject_thread | ||||||
description | Create a windows service | rule | create_service | ||||||
description | Communications over HTTP | rule | network_http | ||||||
description | File downloader/dropper | rule | network_dropper | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Escalade priviledges | rule | escalate_priv | ||||||
description | Take screenshot | rule | screenshot | ||||||
description | Run a keylogger | rule | keylogger |
pdb_path | f:\软件工ç¨\驱å¨ç¼ç¨\OK\KernelYK\bin\InstallSYS.pdb |
name | RT_ICON | language | LANG_CHINESE | filetype | Device independent bitmap graphic, 13 x 26 x 8, image size 208, 256 important colors | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005bec0 | size | 0x0000052c | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | Device independent bitmap graphic, 13 x 26 x 8, image size 208, 256 important colors | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005bec0 | size | 0x0000052c | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | Device independent bitmap graphic, 13 x 26 x 8, image size 208, 256 important colors | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005bec0 | size | 0x0000052c | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | Device independent bitmap graphic, 13 x 26 x 8, image size 208, 256 important colors | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005bec0 | size | 0x0000052c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005c3ec | size | 0x00000094 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005c480 | size | 0x0000003e | ||||||||||||||||||
name | RT_VERSION | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005c4c0 | size | 0x000002cc |
file | C:\Temp\omhezwrpjh.exe |
file | C:\Temp\ytqlidbvtnlgdyvq.exe |
file | C:\Temp\jgbztrljeb.exe |
file | C:\Temp\CreateProcess.exe |
file | C:\Temp\i_omhezwrpjh.exe |
cmdline | C:\Program Files\Internet Explorer\iexplore.exe http://xytets.com:2345/t.asp?os=home |
file | C:\Temp\i_omhezwrpjh.exe |
G Data Antivirus (Windows) | Virus: Trojan.Generic.7761207 (Engine A), Win32.Trojan.PSE1.YSVY3N (Engine B) |
Avast Core Security (Linux) | MBR:Backboot-D [Rtk] |
C4S ClamAV (Linux) | Win.Malware.Mikey-9949492-0 |
Trellix (Linux) | Generic Dropper.aoe trojan |
WithSecure (Linux) | Trojan.TR/Rogue.7909438 |
eScan Antivirus (Linux) | Trojan.Generic.7761207(DB) |
ESET Security (Windows) | Win32/Agent.PGA trojan |
Sophos Anti-Virus (Linux) | Troj/Drop-GZ |
DrWeb Antivirus (Linux) | Trojan.Click2.32800 |
ClamAV (Linux) | Win.Malware.Mikey-9949492-0 |
Bitdefender Antivirus (Linux) | Trojan.Generic.7761207 |
Kaspersky Standard (Windows) | Trojan.Win32.Tiny.cm |
Emsisoft Commandline Scanner (Windows) | Trojan.Generic.7761207 (B) |