File 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0

Size 85.2KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 898df3794e4b6f2d57b1f109d88e0b63
SHA1 2d9e43736d217468375a818f1ec902b9592a82a3
SHA256 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0
SHA512
bfcac49fc49e8a3b7d6504204840ef1a19ed55db30ae8a3260b81039a2a79a3711a3bcc357bcf3b3d1457f9d09b6551b2ed13930869a7a754cbc8f1182fd694c
CRC32 FCD8D373
ssdeep None
Yara
  • DebuggerException__SetConsoleCtrl - (no description)
  • win_mutex - Create or check mutex
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

6904819

6904820

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Aug. 23, 2025, 11:14 p.m. Aug. 23, 2025, 11:23 p.m. 547 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-08-16 08:07:58,015 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht
2025-08-16 08:07:58,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\uZTqyEQbVaHpHTsSxSsz
2025-08-16 08:07:58,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\CJrtruqETCAIcPgDlpSiGazcPgX
2025-08-16 08:07:58,342 [analyzer] DEBUG: Started auxiliary module Curtain
2025-08-16 08:07:58,342 [analyzer] DEBUG: Started auxiliary module DbgView
2025-08-16 08:07:58,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-08-16 08:07:59,062 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-08-16 08:07:59,062 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-08-16 08:07:59,078 [analyzer] DEBUG: Started auxiliary module Human
2025-08-16 08:07:59,078 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-08-16 08:07:59,078 [analyzer] DEBUG: Started auxiliary module Reboot
2025-08-16 08:07:59,125 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-08-16 08:07:59,140 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-08-16 08:07:59,140 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-08-16 08:07:59,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-08-16 08:07:59,296 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe' with arguments '' and pid 1776
2025-08-16 08:07:59,483 [analyzer] DEBUG: Loaded monitor into process with pid 1776
2025-08-16 08:07:59,937 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Windows6g2yf6t03h
2025-08-16 08:08:00,015 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files\Common Files\Microsoft Shared\7smpob5w a3xo5xtn horse [bangbus] 2t7ovbv072xgs7mrxm .avi.exe
2025-08-16 08:08:00,312 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files\DVD Maker\Shared\4mvc8yaot horse uncut n12wc0jz71 .avi.exe
2025-08-16 08:08:00,640 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files\Microsoft Office\Templates\m5v129k kmozxo hole tqxfpcxae098d .mpg.exe
2025-08-16 08:08:00,655 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\tvolgth cum beast fs8utd  (Sonja,v89zo5).avi.exe
2025-08-16 08:08:00,765 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files\Windows Journal\Templates\6mw7u7 4mvc8yaot nude kc2hrt2j xf2v5u7 .zip.exe
2025-08-16 08:08:00,875 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files\Windows Sidebar\Shared Gadgets\uv0dxwt8x4m f6br2s2 hotel .rar.exe
2025-08-16 08:08:00,905 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\ovqqw9 m5v129k 4fq06c kmozxo legs m87r8y  (v89zo5,j2knkmd).rar.exe
2025-08-16 08:08:01,092 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files (x86)\Common Files\microsoft shared\l8qccpyq big .mpeg.exe
2025-08-16 08:08:01,500 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\black gay cum fs8utd legs .zip.exe
2025-08-16 08:08:01,750 [analyzer] INFO: Injected into process with pid 1656 and name ''
2025-08-16 08:08:01,750 [analyzer] INFO: Added new file to list with pid 1776 and path C:\ProgramData\Microsoft\RAC\Temp\9oypb8 d2jspkm3 .zip.exe
2025-08-16 08:08:01,812 [analyzer] INFO: Added new file to list with pid 1776 and path C:\ProgramData\Microsoft\Search\Data\Temp\bwpt7j beast j8bb56pcl4 50+ .mpg.exe
2025-08-16 08:08:01,890 [analyzer] INFO: Added new file to list with pid 1776 and path C:\ProgramData\Microsoft\Windows\Templates\a3xo5xtn [free] sjubxan5vwor .avi.exe
2025-08-16 08:08:01,905 [analyzer] DEBUG: Loaded monitor into process with pid 1656
2025-08-16 08:08:01,983 [analyzer] INFO: Added new file to list with pid 1776 and path C:\ProgramData\Microsoft\Windows\Templates\xxx mtu2oyuh5 f6br2s2 1dmcuxk90zc .avi.exe
2025-08-16 08:08:02,453 [analyzer] INFO: Added new file to list with pid 1776 and path C:\tmptpreht\yn0pxd l8qccpyq hot (!) .avi.exe
2025-08-16 08:08:02,608 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\wluwp0ne horse fs8utd sweet .avi.exe
2025-08-16 08:08:02,687 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Administrator\AppData\Local\Temp\wluwp0ne beast srpvkzygmcsw sm .mpeg.exe
2025-08-16 08:08:02,717 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\doz78r7 l8qccpyq [milf] legs .mpg.exe
2025-08-16 08:08:02,750 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\asian beast beast [bangbus] titts .rar.exe
2025-08-16 08:08:02,983 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ko6o6a y6go35p fs8utd  (a89thik).mpg.exe
2025-08-16 08:08:03,092 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\yn0pxd l8qccpyq m5v129k [milf] tqxfpcxae098d  (j2knkmd).rar.exe
2025-08-16 08:08:03,187 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\black ko6o6a beast wk79oa4s2r04wd r47smh9 .avi.exe
2025-08-16 08:08:03,312 [analyzer] INFO: Added new file to list with pid 1776 and path C:\ProgramData\Microsoft\RAC\Temp\horse girls 5n10bh .avi.exe
2025-08-16 08:08:03,453 [analyzer] INFO: Added new file to list with pid 1776 and path C:\ProgramData\Microsoft\Windows\Templates\27bjd3d2x xxx uv0dxwt8x4m uncut n12wc0jz71 .mpg.exe
2025-08-16 08:08:03,530 [analyzer] INFO: Added new file to list with pid 1776 and path C:\ProgramData\Microsoft\Windows\Templates\xiwlzi0 xxx nude [milf] titts hairy .rar.exe
2025-08-16 08:08:03,562 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\1lwbqss7 6r3apw4 horse d2jspkm3 m87r8y .rar.exe
2025-08-16 08:08:03,592 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Default\AppData\Local\Temp\yn0pxd beast beast girls sjubxan5vwor .zip.exe
2025-08-16 08:08:03,608 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\9oypb8 xxx 6mjj01 glans 50+  (Gina,Sarah).rar.exe
2025-08-16 08:08:03,640 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\27bjd3d2x gay 6mjj01 qcjxxhb .mpeg.exe
2025-08-16 08:08:03,687 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\1lwbqss7 cum wk79oa4s2r04wd 0cjlmt .mpg.exe
2025-08-16 08:08:03,796 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\yn0pxd gay kmozxo  (Sarah,Sonja).mpg.exe
2025-08-16 08:08:03,828 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\6r3apw4 kmozxo .mpeg.exe
2025-08-16 08:08:28,296 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-08-16 08:08:29,000 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-08-16 08:08:29,000 [lib.api.process] INFO: Successfully terminated process with pid 1776.
2025-08-16 08:08:29,000 [lib.api.process] INFO: Successfully terminated process with pid 1656.
2025-08-16 08:08:30,217 [analyzer] WARNING: Too many files: c:\windows\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\6r3apw4 kmozxo .mpeg.exe
2025-08-16 08:08:30,217 [analyzer] WARNING: Too many files: c:\program files\windows journal\templates\6mw7u7 4mvc8yaot nude kc2hrt2j xf2v5u7 .zip.exe
2025-08-16 08:08:30,217 [analyzer] WARNING: Too many files: c:\programdata\microsoft\windows\templates\a3xo5xtn [free] sjubxan5vwor .avi.exe
2025-08-16 08:08:30,217 [analyzer] WARNING: Too many files: c:\program files\windows sidebar\shared gadgets\uv0dxwt8x4m f6br2s2 hotel .rar.exe
2025-08-16 08:08:30,217 [analyzer] WARNING: Too many files: c:\windows\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\yn0pxd gay kmozxo  (sarah,sonja).mpg.exe
2025-08-16 08:08:30,217 [analyzer] WARNING: Too many files: c:\program files (x86)\windows sidebar\shared gadgets\black gay cum fs8utd legs .zip.exe
2025-08-16 08:08:30,217 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-08-23 23:14:29,482 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:30,603 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:31,633 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:32,670 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:33,704 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:34,732 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:35,757 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:36,786 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:37,813 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:38,847 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:39,872 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:40,898 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:41,931 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:42,956 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:43,984 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:45,006 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:46,038 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:47,079 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:48,111 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:49,141 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:50,174 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:51,207 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:52,235 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:53,268 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:54,296 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:55,372 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:56,426 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:57,466 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:58,507 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:14:59,557 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:00,623 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:01,672 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:02,718 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:03,772 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:04,846 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:05,914 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:06,988 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:08,131 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:09,199 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:10,258 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:11,315 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:12,385 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:13,441 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:14,538 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:15,646 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:16,726 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:17,807 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:18,892 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:19,959 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:21,035 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:22,133 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:23,171 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:24,199 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:25,224 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:26,303 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:27,348 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:28,387 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:29,426 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:30,479 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:31,518 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:32,608 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:33,816 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:34,971 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:36,030 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:37,091 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:38,144 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:39,203 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:40,264 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:41,335 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:42,418 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:43,487 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:44,552 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:45,613 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:46,666 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:47,721 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:48,781 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:49,843 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:50,883 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:51,925 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:52,972 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:54,016 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:55,055 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:56,104 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:57,147 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:58,403 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:15:59,441 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:00,490 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:01,527 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:02,562 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:03,596 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:04,631 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:05,788 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:06,898 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:07,969 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:09,040 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:10,243 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:11,315 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:12,408 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:13,504 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:14,580 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:15,669 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:16,747 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:17,802 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:18,860 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:19,919 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:20,983 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:22,043 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:23,109 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:24,176 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:25,229 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:26,295 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:27,433 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:28,534 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:29,571 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:30,605 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:31,633 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:32,666 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:33,689 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:35,020 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:36,047 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:37,078 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:38,108 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:39,140 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:40,251 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:41,280 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:42,307 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:43,378 [cuckoo.core.scheduler] DEBUG: Task #6880459: no machine available yet
2025-08-23 23:16:44,431 [cuckoo.core.scheduler] INFO: Task #6880459: acquired machine win7x641 (label=win7x641)
2025-08-23 23:16:44,434 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #6880459
2025-08-23 23:16:44,806 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 264117 (interface=vboxnet0, host=192.168.168.201)
2025-08-23 23:16:45,067 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641
2025-08-23 23:16:45,560 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak
2025-08-23 23:19:49,975 [cuckoo.core.guest] INFO: Starting analysis #6880459 on guest (id=win7x641, ip=192.168.168.201)
2025-08-23 23:19:50,980 [cuckoo.core.guest] DEBUG: win7x641: not ready yet
2025-08-23 23:19:56,012 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201)
2025-08-23 23:19:56,121 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546)
2025-08-23 23:19:57,387 [cuckoo.core.resultserver] DEBUG: Task #6880459: live log analysis.log initialized.
2025-08-23 23:19:58,392 [cuckoo.core.resultserver] DEBUG: Task #6880459 is sending a BSON stream
2025-08-23 23:19:58,781 [cuckoo.core.resultserver] DEBUG: Task #6880459 is sending a BSON stream
2025-08-23 23:19:59,684 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'shots/0001.jpg'
2025-08-23 23:19:59,705 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 133481
2025-08-23 23:20:01,224 [cuckoo.core.resultserver] DEBUG: Task #6880459 is sending a BSON stream
2025-08-23 23:20:12,124 [cuckoo.core.guest] DEBUG: win7x641: analysis #6880459 still processing
2025-08-23 23:20:27,233 [cuckoo.core.guest] DEBUG: win7x641: analysis #6880459 still processing
2025-08-23 23:20:28,016 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'curtain/1755324508.62.curtain.log'
2025-08-23 23:20:28,019 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 36
2025-08-23 23:20:28,296 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'sysmon/1755324508.89.sysmon.xml'
2025-08-23 23:20:28,394 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1980196
2025-08-23 23:20:28,457 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/5e91da2aa4f2f0ed_black ko6o6a beast wk79oa4s2r04wd r47smh9 .avi.exe'
2025-08-23 23:20:28,512 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1556466
2025-08-23 23:20:28,523 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/c8b26a319d7659c7_27bjd3d2x xxx uv0dxwt8x4m uncut n12wc0jz71 .mpg.exe'
2025-08-23 23:20:28,531 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 496179
2025-08-23 23:20:28,549 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/2051bd5d8a8e4ae9_ovqqw9 m5v129k 4fq06c kmozxo legs m87r8y  (v89zo5,j2knkmd).rar.exe'
2025-08-23 23:20:28,588 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1749847
2025-08-23 23:20:28,623 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/8c5177ead441b9ad_asian beast beast [bangbus] titts .rar.exe'
2025-08-23 23:20:28,673 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1509062
2025-08-23 23:20:28,697 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/e1b0c1a098c2fef6_1lwbqss7 6r3apw4 horse d2jspkm3 m87r8y .rar.exe'
2025-08-23 23:20:28,710 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1052828
2025-08-23 23:20:28,735 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/de79008e7eb91024_l8qccpyq big .mpeg.exe'
2025-08-23 23:20:28,766 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 2176012
2025-08-23 23:20:28,788 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/3ce6dd6f2b628024_doz78r7 l8qccpyq [milf] legs .mpg.exe'
2025-08-23 23:20:28,826 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1585087
2025-08-23 23:20:28,842 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/0ea6cdf15290f543_9oypb8 d2jspkm3 .zip.exe'
2025-08-23 23:20:28,853 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 782248
2025-08-23 23:20:28,866 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/7810aecadf69b930_tvolgth cum beast fs8utd  (sonja,v89zo5).avi.exe'
2025-08-23 23:20:28,903 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1327250
2025-08-23 23:20:28,910 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/60704002274bb8e1_windows6g2yf6t03h'
2025-08-23 23:20:28,916 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 366687
2025-08-23 23:20:28,932 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/83e9f40162092c0f_1lwbqss7 cum wk79oa4s2r04wd 0cjlmt .mpg.exe'
2025-08-23 23:20:28,961 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1744514
2025-08-23 23:20:29,030 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/ce799c7e9d19fb88_bwpt7j beast j8bb56pcl4 50+ .mpg.exe'
2025-08-23 23:20:29,085 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 2122596
2025-08-23 23:20:29,096 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/d9bc29affc1a1897_yn0pxd beast beast girls sjubxan5vwor .zip.exe'
2025-08-23 23:20:29,129 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/7a2559e01803829b_wluwp0ne horse fs8utd sweet .avi.exe'
2025-08-23 23:20:29,134 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/d046969ab4331a22_wluwp0ne beast srpvkzygmcsw sm .mpeg.exe'
2025-08-23 23:20:29,144 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 373410
2025-08-23 23:20:29,147 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 555622
2025-08-23 23:20:29,150 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 218506
2025-08-23 23:20:29,165 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/bfa404f30d518dfa_xiwlzi0 xxx nude [milf] titts hairy .rar.exe'
2025-08-23 23:20:29,191 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1113187
2025-08-23 23:20:29,204 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/cca2d349564f53ee_27bjd3d2x gay 6mjj01 qcjxxhb .mpeg.exe'
2025-08-23 23:20:29,213 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/ec2d18206b8577d0_7smpob5w a3xo5xtn horse [bangbus] 2t7ovbv072xgs7mrxm .avi.exe'
2025-08-23 23:20:29,215 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 901623
2025-08-23 23:20:29,227 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 171978
2025-08-23 23:20:29,241 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/a24d24d05b08ac9f_ko6o6a y6go35p fs8utd  (a89thik).mpg.exe'
2025-08-23 23:20:29,261 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1147454
2025-08-23 23:20:29,280 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/4a207f97fab23fb2_xxx mtu2oyuh5 f6br2s2 1dmcuxk90zc .avi.exe'
2025-08-23 23:20:29,309 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1150711
2025-08-23 23:20:29,339 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/37b637de6069b0f3_horse girls 5n10bh .avi.exe'
2025-08-23 23:20:29,396 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 2119967
2025-08-23 23:20:29,435 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/9f616948acc4c82a_4mvc8yaot horse uncut n12wc0jz71 .avi.exe'
2025-08-23 23:20:29,482 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1988720
2025-08-23 23:20:29,516 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/f44819fb2280ead1_yn0pxd l8qccpyq m5v129k [milf] tqxfpcxae098d  (j2knkmd).rar.exe'
2025-08-23 23:20:29,525 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 869475
2025-08-23 23:20:29,530 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/822dc764c2b0d76f_m5v129k kmozxo hole tqxfpcxae098d .mpg.exe'
2025-08-23 23:20:29,534 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 113785
2025-08-23 23:20:29,551 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/39b080c256910bd3_yn0pxd l8qccpyq hot (!) .avi.exe'
2025-08-23 23:20:29,603 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 1848985
2025-08-23 23:20:29,613 [cuckoo.core.resultserver] DEBUG: Task #6880459: File upload for 'files/1faccb15793882c1_9oypb8 xxx 6mjj01 glans 50+  (gina,sarah).rar.exe'
2025-08-23 23:20:29,625 [cuckoo.core.resultserver] DEBUG: Task #6880459 uploaded file length: 677479
2025-08-23 23:20:29,641 [cuckoo.core.resultserver] DEBUG: Task #6880459 had connection reset for <Context for LOG>
2025-08-23 23:20:30,260 [cuckoo.core.guest] INFO: win7x641: analysis completed successfully
2025-08-23 23:20:30,390 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-08-23 23:20:30,445 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-08-23 23:20:31,330 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/6880459/memory.dmp
2025-08-23 23:20:31,331 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641
2025-08-23 23:23:36,494 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #6880459
2025-08-23 23:23:37,072 [cuckoo.core.scheduler] DEBUG: Released database task #6880459
2025-08-23 23:23:37,109 [cuckoo.core.scheduler] INFO: Task #6880459: analysis procedure completed

Signatures

Yara rules detected for file (4 events)
description (no description) rule DebuggerException__SetConsoleCtrl
description Create or check mutex rule win_mutex
description Affect system registries rule win_registry
description Affect private profile rule win_files_operation
The executable contains unknown PE section names indicative of a packer (could be a false positive) (2 events)
section .text\x00\xe5\xfb
section .data\x00E\x86
The executable uses a known packer (1 event)
packer Pelles C 3.00, 4.00, 4.50 EXE (X86 CRT-LIB)
A process attempted to delay the analysis task. (1 event)
description 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe tried to sleep 175 seconds, actually delayed analysis time by 175 seconds
Creates executable files on the filesystem (31 events)
file C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\ko6o6a y6go35p fs8utd (a89thik).mpg.exe
file C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\yn0pxd l8qccpyq m5v129k [milf] tqxfpcxae098d (j2knkmd).rar.exe
file C:\Program Files\DVD Maker\Shared\4mvc8yaot horse uncut n12wc0jz71 .avi.exe
file C:\Users\Administrator\Templates\black ko6o6a beast wk79oa4s2r04wd r47smh9 .avi.exe
file C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\yn0pxd gay kmozxo (Sarah,Sonja).mpg.exe
file C:\Users\Default\AppData\Local\Temp\yn0pxd beast beast girls sjubxan5vwor .zip.exe
file C:\ProgramData\Microsoft\RAC\Temp\9oypb8 d2jspkm3 .zip.exe
file C:\Users\Default\AppData\Local\Temporary Internet Files\9oypb8 xxx 6mjj01 glans 50+ (Gina,Sarah).rar.exe
file C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\tvolgth cum beast fs8utd (Sonja,v89zo5).avi.exe
file C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\27bjd3d2x gay 6mjj01 qcjxxhb .mpeg.exe
file C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\ovqqw9 m5v129k 4fq06c kmozxo legs m87r8y (v89zo5,j2knkmd).rar.exe
file C:\Users\All Users\Microsoft\Windows\Templates\27bjd3d2x xxx uv0dxwt8x4m uncut n12wc0jz71 .mpg.exe
file C:\Program Files\Windows Journal\Templates\6mw7u7 4mvc8yaot nude kc2hrt2j xf2v5u7 .zip.exe
file C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\black gay cum fs8utd legs .zip.exe
file C:\Users\All Users\Microsoft\RAC\Temp\horse girls 5n10bh .avi.exe
file C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\doz78r7 l8qccpyq [milf] legs .mpg.exe
file C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\6r3apw4 kmozxo .mpeg.exe
file C:\ProgramData\Microsoft\Windows\Templates\a3xo5xtn [free] sjubxan5vwor .avi.exe
file C:\Users\Default\Templates\1lwbqss7 cum wk79oa4s2r04wd 0cjlmt .mpg.exe
file C:\ProgramData\Microsoft\Search\Data\Temp\bwpt7j beast j8bb56pcl4 50+ .mpg.exe
file C:\Program Files\Microsoft Office\Templates\m5v129k kmozxo hole tqxfpcxae098d .mpg.exe
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\wluwp0ne horse fs8utd sweet .avi.exe
file C:\Users\Administrator\AppData\Local\Temp\wluwp0ne beast srpvkzygmcsw sm .mpeg.exe
file C:\Program Files\Common Files\Microsoft Shared\7smpob5w a3xo5xtn horse [bangbus] 2t7ovbv072xgs7mrxm .avi.exe
file C:\ProgramData\Templates\xxx mtu2oyuh5 f6br2s2 1dmcuxk90zc .avi.exe
file C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\1lwbqss7 6r3apw4 horse d2jspkm3 m87r8y .rar.exe
file C:\Program Files\Windows Sidebar\Shared Gadgets\uv0dxwt8x4m f6br2s2 hotel .rar.exe
file C:\Program Files (x86)\Common Files\microsoft shared\l8qccpyq big .mpeg.exe
file C:\Users\Administrator\AppData\Local\Temporary Internet Files\asian beast beast [bangbus] titts .rar.exe
file C:\Users\All Users\Templates\xiwlzi0 xxx nude [milf] titts hairy .rar.exe
file C:\tmptpreht\yn0pxd l8qccpyq hot (!) .avi.exe
Drops an executable to the user AppData folder (1 event)
file C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\black ko6o6a beast wk79oa4s2r04wd r47smh9 .avi.exe
Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping (41 events)
Repeatedly searches for a not-found process, you may want to run a web browser during analysis (27 events)
Time & API Arguments Status Return Repeated

Process32NextW

snapshot_handle: 0x00000120
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1776
0 0

Process32NextW

snapshot_handle: 0x00000270
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1656
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000114
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000118
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000114
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000114
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000114
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000118
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000110
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000110
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000110
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000110
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000110
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000110
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0

Process32NextW

snapshot_handle: 0x00000110
process_name: 33d72a97273e0f7be2a7e4255d6767cdf9180123722beddbbc87d915d59db0e0.exe
process_identifier: 1072
0 0
Enumerates services, possibly for anti-virtualization (1 event)
Time & API Arguments Status Return Repeated

EnumServicesStatusA

service_handle: 0x005ecb20
service_type: 48
service_status: 1
0 0
File has been identified by 12 AntiVirus engine on IRMA as malicious (12 events)
G Data Antivirus (Windows) Virus: Generic.Malware.PfVPk!1!prn!.FE0B916D (Engine A)
Avast Core Security (Linux) Win32:MalwareX-gen [Misc]
C4S ClamAV (Linux) Win.Malware.Pvpk-10056926-0
Trellix (Linux) GenericRXMK-QV
WithSecure (Linux) Trojan.TR/Spy.Gen
eScan Antivirus (Linux) Generic.Malware.PfVPk!1!prn!.FE0B916D(DB)
ESET Security (Windows) a variant of Win32/Agent.CP worm
Sophos Anti-Virus (Linux) Mal/Generic-S
DrWeb Antivirus (Linux) Win32.HLLW.Siggen.1607
Bitdefender Antivirus (Linux) Generic.Malware.PfVPk!1!prn!.FE0B916D
Kaspersky Standard (Windows) HEUR:Trojan.Win32.Generic
Emsisoft Commandline Scanner (Windows) Generic.Malware.PfVPk!1!prn!.FE0B916D (B)
File has been identified by 59 AntiVirus engines on VirusTotal as malicious (50 out of 59 events)
Bkav W32.AIDetectMalware
tehtris Generic.Malware
Cynet Malicious (score: 100)
Skyhigh BehavesLike.Win32.Generic.mh
ALYac Generic.Malware.PfVPk!1!prn!.FE0B916D
Cylance Unsafe
VIPRE Generic.Malware.PfVPk!1!prn!.FE0B916D
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Generic.Malware.PfVPk!1!prn!.FE0B916D
K7GW Trojan ( 004ca8b71 )
K7AntiVirus Trojan ( 004ca8b71 )
Arcabit Generic.Malware.PfVPk!1!prn!.FE0B916D
Baidu Win32.Worm.Agent.fj
VirIT Worm.Win32.Agent.CP
Symantec ML.Attribute.HighConfidence
Elastic Windows.Generic.Threat
ESET-NOD32 a variant of Win32/Agent.CP
APEX Malicious
Avast Win32:MalwareX-gen [Misc]
Kaspersky UDS:Trojan.Win32.Generic
NANO-Antivirus Trojan.Win32.Wofith.iariji
MicroWorld-eScan Generic.Malware.PfVPk!1!prn!.FE0B916D
Rising Worm.Agent!1.12BB7 (CLASSIC)
Emsisoft Generic.Malware.PfVPk!1!prn!.FE0B916D (B)
F-Secure Trojan.TR/Spy.Gen
DrWeb Win32.HLLW.Siggen.1607
Zillya Worm.Agent.Win32.9
McAfeeD Real Protect-LS!898DF3794E4B
Trapmine malicious.high.ml.score
CTX exe.unknown.pfvpk
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
Jiangmin Worm.Agent.yh
Webroot W32.Worm.Gen
Google Detected
Avira TR/Spy.Gen
Antiy-AVL Trojan/Win32.Vindor
Kingsoft malware.kb.a.1000
Gridinsoft Ransom.Win32.Zbot.oa!s1
Microsoft Worm:Win32/Sfone!pz
GData Win32.Trojan.PSE.1F2XTI5
Varist W32/Agent.LDP.gen!Eldorado
AhnLab-V3 Worm/Win.Generic.R704852
Acronis suspicious
VBA32 BScope.Worm.Convagent
DeepInstinct MALICIOUS
Malwarebytes Generic.Malware.AI.DDS
Ikarus Worm.Win32.Agent
Panda Trj/Genetic.gen
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.