Size | 236.0KB |
---|---|
Type | PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
MD5 | 3be7a3ba936d59e7c005ae6a45f60810 |
SHA1 | cb256f40ba2712ef4e0982ed5082c92eec2dd016 |
SHA256 | e2ab20947faaaa3b96236a4026db560be8aa6f47ce351be005dedad97da2c37f |
SHA512 |
fbde0d8eaf5362c0555eb6b939d198012cd1748f8045051add73bbaff979b25aa5b3f626d6d1c5c47ace08b0dc51c6177f47382debd5ec94723cd6112e2bee4f
|
CRC32 | E8E832F9 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 16, 2025, 8:03 p.m. | July 16, 2025, 8:08 p.m. | 261 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-11 20:00:44,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpt1gcja 2025-07-11 20:00:44,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\ovUoztEoASeRpomW 2025-07-11 20:00:44,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\MtQoLjVQzVJdScshTTVJCakrJrxy 2025-07-11 20:00:44,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-07-11 20:00:44,046 [analyzer] INFO: Automatically selected analysis package "exe" 2025-07-11 20:00:44,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-11 20:00:44,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-11 20:00:44,780 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-11 20:00:45,000 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-07-11 20:00:45,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-11 20:00:45,000 [analyzer] DEBUG: Started auxiliary module Human 2025-07-11 20:00:45,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-11 20:00:45,000 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-11 20:00:45,108 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-11 20:00:45,108 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-11 20:00:45,108 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-11 20:00:45,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-11 20:00:45,233 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\e2ab20947faaaa3b_rifaien2-8unazgumkyfkowoa.exe' with arguments '' and pid 2604 2025-07-11 20:00:45,453 [analyzer] DEBUG: Loaded monitor into process with pid 2604 2025-07-11 20:00:45,467 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-V6yelpXPUdfN8Luz.exe 2025-07-11 20:01:15,592 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-7WoX89291osCO45j.exe 2025-07-11 20:01:45,671 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-92MAENKJpMdS1guK.exe 2025-07-11 20:02:15,750 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-bFNv7iIS9yMxHemN.exe 2025-07-11 20:02:45,905 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-bFz1PUXFTHCrnY9d.exe 2025-07-11 20:03:16,000 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-2yySZqHMK5DgNI3o.exe 2025-07-11 20:03:46,092 [analyzer] INFO: Added new file to list with pid 2604 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-uhmGBoqpET8bz8k7.exe 2025-07-11 20:04:04,233 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-07-11 20:04:05,483 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-11 20:04:05,483 [lib.api.process] INFO: Successfully terminated process with pid 2604. 2025-07-11 20:04:05,483 [analyzer] INFO: Analysis completed.
2025-07-16 20:03:56,478 [cuckoo.core.scheduler] INFO: Task #6721070: acquired machine win7x642 (label=win7x642) 2025-07-16 20:03:56,479 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.202 for task #6721070 2025-07-16 20:03:56,766 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2806939 (interface=vboxnet0, host=192.168.168.202) 2025-07-16 20:03:56,929 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x642 2025-07-16 20:03:57,855 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x642 to vmcloak 2025-07-16 20:04:27,678 [cuckoo.core.guest] INFO: Starting analysis #6721070 on guest (id=win7x642, ip=192.168.168.202) 2025-07-16 20:04:28,733 [cuckoo.core.guest] DEBUG: win7x642: not ready yet 2025-07-16 20:04:33,757 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x642, ip=192.168.168.202) 2025-07-16 20:04:33,844 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x642, ip=192.168.168.202, monitor=latest, size=6660546) 2025-07-16 20:04:35,077 [cuckoo.core.resultserver] DEBUG: Task #6721070: live log analysis.log initialized. 2025-07-16 20:04:36,016 [cuckoo.core.resultserver] DEBUG: Task #6721070 is sending a BSON stream 2025-07-16 20:04:36,454 [cuckoo.core.resultserver] DEBUG: Task #6721070 is sending a BSON stream 2025-07-16 20:04:36,671 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'files/ae84270a19088c37_rifaien2-V6yelpXPUdfN8Luz.exe' 2025-07-16 20:04:36,675 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 241664 2025-07-16 20:04:37,309 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'shots/0001.jpg' 2025-07-16 20:04:37,322 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 160117 2025-07-16 20:04:49,891 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:05:05,076 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:05:06,761 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'files/631a9c29a4ca5ee7_rifaien2-7WoX89291osCO45j.exe' 2025-07-16 20:05:06,765 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 241664 2025-07-16 20:05:07,038 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'shots/0002.jpg' 2025-07-16 20:05:07,065 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 160144 2025-07-16 20:05:20,217 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:05:35,385 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:05:36,835 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'files/7a765992f02932b2_rifaien2-92MAENKJpMdS1guK.exe' 2025-07-16 20:05:36,844 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 241664 2025-07-16 20:05:37,839 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'shots/0003.jpg' 2025-07-16 20:05:37,853 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 160363 2025-07-16 20:05:50,510 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:06:05,699 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:06:06,994 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'files/f691214f14fa8408_rifaien2-bFNv7iIS9yMxHemN.exe' 2025-07-16 20:06:06,999 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 241664 2025-07-16 20:06:07,729 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'shots/0004.jpg' 2025-07-16 20:06:07,757 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 160133 2025-07-16 20:06:20,847 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:06:36,018 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:06:37,089 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'files/e61d331828244ce4_rifaien2-bFz1PUXFTHCrnY9d.exe' 2025-07-16 20:06:37,096 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 241664 2025-07-16 20:06:37,602 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'shots/0005.jpg' 2025-07-16 20:06:37,625 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 160500 2025-07-16 20:06:51,179 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:07:06,333 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:07:07,170 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'files/d07d16cce9b332d2_rifaien2-2yySZqHMK5DgNI3o.exe' 2025-07-16 20:07:07,174 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 241664 2025-07-16 20:07:07,591 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'shots/0006.jpg' 2025-07-16 20:07:07,738 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 160300 2025-07-16 20:07:21,488 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:07:36,608 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:07:37,291 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'files/e4794b35a1f936e7_rifaien2-uhmGBoqpET8bz8k7.exe' 2025-07-16 20:07:37,300 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 241664 2025-07-16 20:07:37,477 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'shots/0007.jpg' 2025-07-16 20:07:37,493 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 160289 2025-07-16 20:07:51,726 [cuckoo.core.guest] DEBUG: win7x642: analysis #6721070 still processing 2025-07-16 20:07:55,547 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'curtain/1752257044.45.curtain.log' 2025-07-16 20:07:55,549 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 36 2025-07-16 20:07:56,483 [cuckoo.core.resultserver] DEBUG: Task #6721070: File upload for 'sysmon/1752257045.39.sysmon.xml' 2025-07-16 20:07:56,566 [cuckoo.core.resultserver] DEBUG: Task #6721070 uploaded file length: 12203846 2025-07-16 20:07:56,591 [cuckoo.core.resultserver] DEBUG: Task #6721070 had connection reset for <Context for LOG> 2025-07-16 20:07:57,847 [cuckoo.core.guest] INFO: win7x642: analysis completed successfully 2025-07-16 20:07:57,860 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-16 20:07:57,887 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-16 20:07:58,779 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x642 to path /srv/cuckoo/cwd/storage/analyses/6721070/memory.dmp 2025-07-16 20:07:58,781 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x642 2025-07-16 20:08:17,125 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.202 for task #6721070 2025-07-16 20:08:17,519 [cuckoo.core.scheduler] DEBUG: Released database task #6721070 2025-07-16 20:08:17,535 [cuckoo.core.scheduler] INFO: Task #6721070: analysis procedure completed
description | (no description) | rule | UPX | ||||||
description | The packer/protector section names/keywords | rule | suspicious_packer_section | ||||||
description | Listen for incoming communication | rule | network_tcp_listen | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Communications use DNS | rule | network_dns |
description | e2ab20947faaaa3b_rifaien2-8unazgumkyfkowoa.exe tried to sleep 210 seconds, actually delayed analysis time by 180 seconds |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-bFz1PUXFTHCrnY9d.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-bFNv7iIS9yMxHemN.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-7WoX89291osCO45j.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-V6yelpXPUdfN8Luz.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-92MAENKJpMdS1guK.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-uhmGBoqpET8bz8k7.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-2yySZqHMK5DgNI3o.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-V6yelpXPUdfN8Luz.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-7WoX89291osCO45j.exe |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX | ||||||
section | UPX2 | description | Section name indicates UPX |
buffer | Buffer with sha1: 3147486f3393eaa0eb2b973dcb944b1b5ccfb026 |
suricata | ETPRO MALWARE Win32/Snojan Variant Uploading EXE |
suricata | ET INFO Generic HTTP EXE Upload Outbound |
G Data Antivirus (Windows) | Virus: Trojan.Agent.CYZT (Engine A) |
Avast Core Security (Linux) | Win32:Banker-LAA [Trj] |
C4S ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
WithSecure (Linux) | Trojan.TR/Agent.qasng |
eScan Antivirus (Linux) | Trojan.Agent.CYZT(DB) |
ESET Security (Windows) | a variant of Win32/Agent.AAEF trojan |
Sophos Anti-Virus (Linux) | Troj/Bdoor-BHD |
ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
Bitdefender Antivirus (Linux) | Trojan.Agent.CYZT |
Kaspersky Standard (Windows) | HEUR:Flooder.Win32.CoreWarrior.a |
Emsisoft Commandline Scanner (Windows) | Trojan.Agent.CYZT (B) |