Size | 288.0B |
---|---|
Type | VAX-order 68k Blit mpx/mux executable |
MD5 | 2305f9607f3c0cbc94d584abc5a9be06 |
SHA1 | 70661870217bf70e2e6aa1b160a80837325cff14 |
SHA256 | 534e58da42d4089db1c50d776795273cb978e6f65a43dabe09e38e8ed88c28a3 |
SHA512 |
7bd5acd94585e15a2e8060d88c44578202b5223991cc32cf7f17fcdae3f660920b5e6c2b27e99a7a0e89e095e07162d8b25446d6365a98f4d6b067fc8e561510
|
CRC32 | 89804BEE |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Aug. 11, 2025, 12:14 p.m. | Aug. 11, 2025, 12:18 p.m. | 236 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-11 11:40:48,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpsftntc 2025-08-11 11:40:48,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\tGRueqSHlONbmtBlwjyTUagQ 2025-08-11 11:40:48,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\vRqVBagNpPaWZpbFloGZwhfxUKaTZJNw 2025-08-11 11:40:48,046 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-08-11 11:40:48,046 [analyzer] INFO: Automatically selected analysis package "generic" 2025-08-11 11:40:48,405 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-11 11:40:48,405 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-11 11:40:48,921 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-11 11:40:49,125 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-08-11 11:40:49,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-11 11:40:49,125 [analyzer] DEBUG: Started auxiliary module Human 2025-08-11 11:40:49,125 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-11 11:40:49,140 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-11 11:40:49,203 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-11 11:40:49,203 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-11 11:40:49,203 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-11 11:40:49,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-11 11:40:49,265 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"vZHNHTSjV"', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\534e58da42d4089d_skotes.job'] and pid 1160 2025-08-11 11:40:49,515 [analyzer] DEBUG: Loaded monitor into process with pid 1160 2025-08-11 11:40:49,858 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-08-11 11:40:49,890 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:49,905 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:49,905 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:49,905 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-08-11 11:40:49,905 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:49,921 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:49,921 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:49,921 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-08-11 11:40:49,967 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:49,983 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-08-11 11:40:50,015 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-08-11 11:40:50,015 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,015 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,030 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,030 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-08-11 11:40:50,030 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,030 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,030 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,046 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,046 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,046 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-08-11 11:40:50,467 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-08-11 11:40:50,467 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,467 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,467 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,483 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-08-11 11:40:50,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,500 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-08-11 11:40:50,608 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-08-11 11:40:50,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,625 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-08-11 11:40:50,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,640 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:50,655 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:54,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-08-11 11:40:54,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-08-11 11:40:54,092 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-08-11 11:17:58,713 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-08-11 11:17:59,480 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-11 11:17:59,480 [lib.api.process] INFO: Successfully terminated process with pid 1160. 2025-08-11 11:17:59,480 [analyzer] INFO: Analysis completed.
2025-08-11 12:14:16,656 [cuckoo.core.scheduler] INFO: Task #6829456: acquired machine win7x6421 (label=win7x6421) 2025-08-11 12:14:16,657 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.221 for task #6829456 2025-08-11 12:14:17,382 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1843674 (interface=vboxnet0, host=192.168.168.221) 2025-08-11 12:14:17,415 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6421 2025-08-11 12:14:18,428 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6421 to vmcloak 2025-08-11 12:14:30,691 [cuckoo.core.guest] INFO: Starting analysis #6829456 on guest (id=win7x6421, ip=192.168.168.221) 2025-08-11 12:14:31,697 [cuckoo.core.guest] DEBUG: win7x6421: not ready yet 2025-08-11 12:14:36,775 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6421, ip=192.168.168.221) 2025-08-11 12:14:36,903 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6421, ip=192.168.168.221, monitor=latest, size=6660546) 2025-08-11 12:14:38,345 [cuckoo.core.resultserver] DEBUG: Task #6829456: live log analysis.log initialized. 2025-08-11 12:14:39,419 [cuckoo.core.resultserver] DEBUG: Task #6829456 is sending a BSON stream 2025-08-11 12:14:39,747 [cuckoo.core.resultserver] DEBUG: Task #6829456 is sending a BSON stream 2025-08-11 12:14:40,683 [cuckoo.core.resultserver] DEBUG: Task #6829456: File upload for 'shots/0001.jpg' 2025-08-11 12:14:40,694 [cuckoo.core.resultserver] DEBUG: Task #6829456 uploaded file length: 110777 2025-08-11 12:14:44,879 [cuckoo.core.resultserver] DEBUG: Task #6829456: File upload for 'shots/0002.jpg' 2025-08-11 12:14:44,917 [cuckoo.core.resultserver] DEBUG: Task #6829456 uploaded file length: 109624 2025-08-11 12:14:46,032 [cuckoo.core.resultserver] DEBUG: Task #6829456: File upload for 'shots/0003.jpg' 2025-08-11 12:14:46,048 [cuckoo.core.resultserver] DEBUG: Task #6829456 uploaded file length: 121279 2025-08-11 12:14:52,888 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:15:08,562 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:15:23,927 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:15:39,303 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:15:54,405 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:16:09,917 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:16:25,528 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:16:41,151 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:16:57,248 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:17:12,370 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:17:27,762 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:17:43,224 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:17:58,896 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6829456 still processing 2025-08-11 12:17:59,330 [cuckoo.core.resultserver] DEBUG: Task #6829456: File upload for 'curtain/1754903879.01.curtain.log' 2025-08-11 12:17:59,352 [cuckoo.core.resultserver] DEBUG: Task #6829456 uploaded file length: 36 2025-08-11 12:17:59,419 [cuckoo.core.resultserver] DEBUG: Task #6829456: File upload for 'sysmon/1754903879.42.sysmon.xml' 2025-08-11 12:17:59,487 [cuckoo.core.resultserver] DEBUG: Task #6829456 uploaded file length: 2741184 2025-08-11 12:17:59,506 [cuckoo.core.resultserver] DEBUG: Task #6829456 had connection reset for <Context for LOG> 2025-08-11 12:18:01,923 [cuckoo.core.guest] INFO: win7x6421: analysis completed successfully 2025-08-11 12:18:01,963 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-11 12:18:02,008 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-11 12:18:04,023 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6421 to path /srv/cuckoo/cwd/storage/analyses/6829456/memory.dmp 2025-08-11 12:18:04,026 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6421 2025-08-11 12:18:13,088 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.221 for task #6829456 2025-08-11 12:18:13,444 [cuckoo.core.scheduler] DEBUG: Released database task #6829456 2025-08-11 12:18:13,463 [cuckoo.core.scheduler] INFO: Task #6829456: analysis procedure completed
No signatures