Size | 1.1MB |
---|---|
Type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
MD5 | 35f0a01afb1ab74d2f1f1d2a2d0e4e57 |
SHA1 | dabc8db06c9111cc7f09d1a9f895a022a06c6493 |
SHA256 | 95b40dfb81ea97e28cefaf64bc65fb6f55e429b25a5e84b7e0bd022b9f312892 |
SHA512 |
5cbcb4b02687486c532f0fe903b7a3fc9791f2b427cb97e00bef8de7cce8c28e52fc59216d4bcfec9f945faa5917c0e44cd5254e5588fc900557676df3a55a4a
|
CRC32 | BD8BFDC7 |
ssdeep | None |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Aug. 11, 2025, 11:24 a.m. | Aug. 11, 2025, 11:24 a.m. | 36 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-11 10:20:34,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt 2025-08-11 10:20:34,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\avtXFnQkpVwDgPqsOtYVvKkyvjEJomMG 2025-08-11 10:20:34,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\plmoOOAGgKcNOdGNyhMDxxIApaVjau 2025-08-11 10:20:34,342 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-11 10:20:34,342 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-11 10:20:34,796 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-11 10:20:35,015 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-08-11 10:20:35,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-11 10:20:35,015 [analyzer] DEBUG: Started auxiliary module Human 2025-08-11 10:20:35,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-11 10:20:35,015 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-11 10:20:35,092 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-11 10:20:35,092 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-11 10:20:35,092 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-11 10:20:35,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-11 10:20:35,187 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\UnisDll32.dll' with arguments ['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\UnisDll32.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\UnisDll32.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
2025-08-11 11:24:08,942 [cuckoo.core.scheduler] INFO: Task #6829298: acquired machine win7x6423 (label=win7x6423) 2025-08-11 11:24:08,943 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6829298 2025-08-11 11:24:09,878 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1772595 (interface=vboxnet0, host=192.168.168.223) 2025-08-11 11:24:11,018 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423 2025-08-11 11:24:12,061 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak 2025-08-11 11:24:23,835 [cuckoo.core.guest] INFO: Starting analysis #6829298 on guest (id=win7x6423, ip=192.168.168.223) 2025-08-11 11:24:24,841 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet 2025-08-11 11:24:30,045 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223) 2025-08-11 11:24:30,159 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546) 2025-08-11 11:24:31,460 [cuckoo.core.resultserver] DEBUG: Task #6829298: live log analysis.log initialized. 2025-08-11 11:24:32,423 [cuckoo.core.resultserver] DEBUG: Task #6829298 is sending a BSON stream 2025-08-11 11:24:33,702 [cuckoo.core.resultserver] DEBUG: Task #6829298: File upload for 'shots/0001.jpg' 2025-08-11 11:24:33,716 [cuckoo.core.resultserver] DEBUG: Task #6829298 uploaded file length: 133511 2025-08-11 11:24:33,986 [cuckoo.core.guest] WARNING: win7x6423: analysis #6829298 caught an exception Traceback (most recent call last): File "C:/tmp4w2pkt/analyzer.py", line 824, in <module> success = analyzer.run() File "C:/tmp4w2pkt/analyzer.py", line 673, in run pids = self.package.start(self.target) File "C:\tmp4w2pkt\modules\packages\exe.py", line 34, in start return self.execute(path, args=shlex.split(args)) File "C:\tmp4w2pkt\lib\common\abstracts.py", line 205, in execute "Unable to execute the initial process, analysis aborted." CuckooPackageError: Unable to execute the initial process, analysis aborted. 2025-08-11 11:24:33,998 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-11 11:24:34,027 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-11 11:24:35,829 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6829298/memory.dmp 2025-08-11 11:24:35,830 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423 2025-08-11 11:24:44,709 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6829298 2025-08-11 11:24:44,709 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6829298 2025-08-11 11:24:45,040 [cuckoo.core.scheduler] DEBUG: Released database task #6829298 2025-08-11 11:24:45,058 [cuckoo.core.scheduler] INFO: Task #6829298: analysis procedure completed
description | (no description) | rule | GenerateTLSClientHelloPacket_Test | ||||||
description | Take screenshot | rule | screenshot |
packer | Armadillo v1.xx - v2.xx |
name | RT_VERSION | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00116060 | size | 0x000003b0 |