Size | 236.0KB |
---|---|
Type | PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
MD5 | 269f1113b0c981eba1f3116d2357f49a |
SHA1 | 384ae9fb417b6c3821e1323106e6c3e07edcc386 |
SHA256 | e65b04abcef7e4de05fb08dd9ce5e561724da50fa09066cb98f861a7b1b35e74 |
SHA512 |
678f289cabe706a3868057d62e0550cbc86bccdba9a5687784e70225a0d2e7ed07f7d0a7efd3f16dca004c66f46d7951811552d10c35cc25c25b53ee1c8debf7
|
CRC32 | 1CF91B15 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 16, 2025, 8:06 p.m. | July 16, 2025, 8:11 p.m. | 247 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-11 20:10:34,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpsgyfoe 2025-07-11 20:10:34,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\AEQjDwBxCmovAgjQ 2025-07-11 20:10:34,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\EEjvWwFYHPvKXkMjnKAmUNrGXAvmr 2025-07-11 20:10:34,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-07-11 20:10:34,015 [analyzer] INFO: Automatically selected analysis package "exe" 2025-07-11 20:10:34,375 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-11 20:10:34,375 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-11 20:10:34,890 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-11 20:10:35,108 [analyzer] DEBUG: Loaded monitor into process with pid 516 2025-07-11 20:10:35,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-11 20:10:35,125 [analyzer] DEBUG: Started auxiliary module Human 2025-07-11 20:10:35,140 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-11 20:10:35,140 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-11 20:10:35,217 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-11 20:10:35,217 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-11 20:10:35,217 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-11 20:10:35,217 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-11 20:10:35,358 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\e65b04abcef7e4de_rifaien2-fy5zfzbaqpik85ow.exe' with arguments '' and pid 1388 2025-07-11 20:10:35,592 [analyzer] DEBUG: Loaded monitor into process with pid 1388 2025-07-11 20:10:35,608 [analyzer] INFO: Added new file to list with pid 1388 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-OyiydJ6wQNncHaSm.exe 2025-07-11 20:11:05,796 [analyzer] INFO: Added new file to list with pid 1388 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-QYOlCl1523z9r0ox.exe 2025-07-11 20:11:35,890 [analyzer] INFO: Added new file to list with pid 1388 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-D5EclVeCATYOWg3d.exe 2025-07-11 20:12:05,967 [analyzer] INFO: Added new file to list with pid 1388 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-cmqPBj6hq53qnbLI.exe 2025-07-11 20:12:36,046 [analyzer] INFO: Added new file to list with pid 1388 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-ljODHrslzxvMSOD9.exe 2025-07-11 20:13:06,140 [analyzer] INFO: Added new file to list with pid 1388 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-0zjbpWhadreY1ZU2.exe 2025-07-11 20:13:36,233 [analyzer] INFO: Added new file to list with pid 1388 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-FCX6AkJ7NbGouZTL.exe 2025-07-11 20:13:54,437 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-07-11 20:13:56,375 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-11 20:13:56,375 [lib.api.process] INFO: Successfully terminated process with pid 1388. 2025-07-11 20:13:56,375 [analyzer] INFO: Analysis completed.
2025-07-16 20:06:56,485 [cuckoo.core.scheduler] INFO: Task #6721086: acquired machine win7x6413 (label=win7x6413) 2025-07-16 20:06:56,491 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.213 for task #6721086 2025-07-16 20:06:56,752 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2810685 (interface=vboxnet0, host=192.168.168.213) 2025-07-16 20:06:56,939 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6413 2025-07-16 20:06:57,964 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6413 to vmcloak 2025-07-16 20:07:23,647 [cuckoo.core.guest] INFO: Starting analysis #6721086 on guest (id=win7x6413, ip=192.168.168.213) 2025-07-16 20:07:24,652 [cuckoo.core.guest] DEBUG: win7x6413: not ready yet 2025-07-16 20:07:29,677 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6413, ip=192.168.168.213) 2025-07-16 20:07:29,779 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6413, ip=192.168.168.213, monitor=latest, size=6660546) 2025-07-16 20:07:31,178 [cuckoo.core.resultserver] DEBUG: Task #6721086: live log analysis.log initialized. 2025-07-16 20:07:32,218 [cuckoo.core.resultserver] DEBUG: Task #6721086 is sending a BSON stream 2025-07-16 20:07:32,684 [cuckoo.core.resultserver] DEBUG: Task #6721086 is sending a BSON stream 2025-07-16 20:07:32,973 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'files/a6d09f15df55558e_rifaien2-OyiydJ6wQNncHaSm.exe' 2025-07-16 20:07:32,978 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 241664 2025-07-16 20:07:33,514 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'shots/0001.jpg' 2025-07-16 20:07:33,530 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 159923 2025-07-16 20:07:45,823 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:08:00,962 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:08:03,057 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'files/235b19e17cf23710_rifaien2-QYOlCl1523z9r0ox.exe' 2025-07-16 20:08:03,062 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 241664 2025-07-16 20:08:03,359 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'shots/0002.jpg' 2025-07-16 20:08:03,383 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 159998 2025-07-16 20:08:16,148 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:08:31,423 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:08:33,146 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'files/e8fd07b7c3e751b6_rifaien2-D5EclVeCATYOWg3d.exe' 2025-07-16 20:08:33,150 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 241664 2025-07-16 20:08:34,020 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'shots/0003.jpg' 2025-07-16 20:08:34,039 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 159986 2025-07-16 20:08:46,603 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:09:08,238 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'files/adee5edac9ed203c_rifaien2-cmqPBj6hq53qnbLI.exe' 2025-07-16 20:09:08,265 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 241664 2025-07-16 20:09:08,284 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'shots/0004.jpg' 2025-07-16 20:09:08,944 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 159989 2025-07-16 20:09:10,528 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:09:25,717 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:09:34,767 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'files/a40119a0a06639bb_rifaien2-ljODHrslzxvMSOD9.exe' 2025-07-16 20:09:34,778 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 241664 2025-07-16 20:09:34,909 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'shots/0005.jpg' 2025-07-16 20:09:35,850 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 160202 2025-07-16 20:09:41,056 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:09:56,315 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:10:05,435 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'files/2af4e911d8f61324_rifaien2-0zjbpWhadreY1ZU2.exe' 2025-07-16 20:10:05,477 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 241664 2025-07-16 20:10:05,580 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'shots/0006.jpg' 2025-07-16 20:10:06,757 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 160185 2025-07-16 20:10:11,578 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:10:26,865 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:10:34,628 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'files/d10f091942d2da3b_rifaien2-FCX6AkJ7NbGouZTL.exe' 2025-07-16 20:10:34,678 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 241664 2025-07-16 20:10:34,828 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'shots/0007.jpg' 2025-07-16 20:10:35,962 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 160068 2025-07-16 20:10:42,002 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6721086 still processing 2025-07-16 20:10:51,884 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'curtain/1752257634.7.curtain.log' 2025-07-16 20:10:51,890 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 36 2025-07-16 20:10:53,081 [cuckoo.core.resultserver] DEBUG: Task #6721086: File upload for 'sysmon/1752257635.91.sysmon.xml' 2025-07-16 20:10:53,556 [cuckoo.core.resultserver] DEBUG: Task #6721086 uploaded file length: 13023888 2025-07-16 20:10:53,586 [cuckoo.core.resultserver] DEBUG: Task #6721086 had connection reset for <Context for LOG> 2025-07-16 20:10:54,118 [cuckoo.core.guest] INFO: win7x6413: analysis completed successfully 2025-07-16 20:10:54,156 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-16 20:10:54,193 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-16 20:10:55,127 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6413 to path /srv/cuckoo/cwd/storage/analyses/6721086/memory.dmp 2025-07-16 20:10:55,136 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6413 2025-07-16 20:11:03,251 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.213 for task #6721086 2025-07-16 20:11:03,763 [cuckoo.core.scheduler] DEBUG: Released database task #6721086 2025-07-16 20:11:03,816 [cuckoo.core.scheduler] INFO: Task #6721086: analysis procedure completed
description | (no description) | rule | UPX | ||||||
description | The packer/protector section names/keywords | rule | suspicious_packer_section | ||||||
description | Listen for incoming communication | rule | network_tcp_listen | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Communications use DNS | rule | network_dns |
description | e65b04abcef7e4de_rifaien2-fy5zfzbaqpik85ow.exe tried to sleep 210 seconds, actually delayed analysis time by 180 seconds |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-ljODHrslzxvMSOD9.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-OyiydJ6wQNncHaSm.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-QYOlCl1523z9r0ox.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-cmqPBj6hq53qnbLI.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-0zjbpWhadreY1ZU2.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-FCX6AkJ7NbGouZTL.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-D5EclVeCATYOWg3d.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-OyiydJ6wQNncHaSm.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-QYOlCl1523z9r0ox.exe |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX | ||||||
section | UPX2 | description | Section name indicates UPX |
buffer | Buffer with sha1: 510752f9e9dc633503e4ad7c744e9ce5c1cb6655 |
suricata | ETPRO MALWARE Win32/Snojan Variant Uploading EXE |
suricata | ET INFO Generic HTTP EXE Upload Outbound |
G Data Antivirus (Windows) | Virus: Trojan.Agent.CYZT (Engine A) |
Avast Core Security (Linux) | Win32:Banker-LAA [Trj] |
C4S ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
WithSecure (Linux) | Trojan.TR/Agent.qasng |
eScan Antivirus (Linux) | Trojan.Agent.CYZT(DB) |
ESET Security (Windows) | a variant of Win32/Agent.AAEF trojan |
Sophos Anti-Virus (Linux) | Troj/Bdoor-BHD |
ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
Bitdefender Antivirus (Linux) | Trojan.Agent.CYZT |
Kaspersky Standard (Windows) | HEUR:Flooder.Win32.CoreWarrior.a |
Emsisoft Commandline Scanner (Windows) | Trojan.Agent.CYZT (B) |