| Size | 1.4MB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | f47ed8630cebbeda8ff96e9f661dde1b |
| SHA1 | 059ef8ea9212df004ff3e81a480777a962f43b1c |
| SHA256 | e92a49a792121b4cca1410b81e54b8f0c4347ad93e52ec446b88fc3e13199c2c |
| SHA512 |
07d486e4e97f897ec831c1a2845a7e0f497a898ab274bd366acb5519a6ff284aa54ac29fd8e39ae25c160e5ffe35592a87d54d483a80f8653e9991231dffa82c
|
| CRC32 | CC049489 |
| ssdeep | None |
| Yara |
|
This file is very suspicious, with a score of 7.7 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Dec. 13, 2025, 4:21 p.m. | Dec. 13, 2025, 4:22 p.m. | 64 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-12-13 15:21:16,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpzepe2z 2025-12-13 15:21:16,000 [analyzer] DEBUG: Pipe server name: \??\PIPE\vvxCXQRHmESwjXGBUKJHLNUXIi 2025-12-13 15:21:16,000 [analyzer] DEBUG: Log pipe server name: \??\PIPE\JSsoFBokRiTjOmWlDKpqBlZWfkbtKS 2025-12-13 15:21:16,250 [analyzer] DEBUG: Started auxiliary module Curtain 2025-12-13 15:21:16,250 [analyzer] DEBUG: Started auxiliary module DbgView 2025-12-13 15:21:16,640 [analyzer] DEBUG: Started auxiliary module Disguise 2025-12-13 15:21:16,828 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-12-13 15:21:16,828 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-12-13 15:21:16,828 [analyzer] DEBUG: Started auxiliary module Human 2025-12-13 15:21:16,828 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-12-13 15:21:16,842 [analyzer] DEBUG: Started auxiliary module Reboot 2025-12-13 15:21:16,905 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-12-13 15:21:16,905 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-12-13 15:21:16,905 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-12-13 15:21:16,905 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-12-13 15:21:17,078 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\av.scr' with arguments '' and pid 2096 2025-12-13 15:21:17,250 [analyzer] DEBUG: Loaded monitor into process with pid 2096 2025-12-13 15:22:18,303 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-12-13 15:22:18,601 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-12-13 15:22:18,601 [lib.api.process] INFO: Successfully terminated process with pid 2096. 2025-12-13 15:22:18,601 [analyzer] INFO: Analysis completed.
2025-12-13 16:21:27,292 [cuckoo.core.scheduler] INFO: Task #7222229: acquired machine win7x6417 (label=win7x6417) 2025-12-13 16:21:27,292 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.217 for task #7222229 2025-12-13 16:21:27,739 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1123031 (interface=vboxnet0, host=192.168.168.217) 2025-12-13 16:21:28,513 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6417 2025-12-13 16:21:30,032 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6417 to vmcloak 2025-12-13 16:21:40,844 [cuckoo.core.guest] INFO: Starting analysis #7222229 on guest (id=win7x6417, ip=192.168.168.217) 2025-12-13 16:21:41,862 [cuckoo.core.guest] DEBUG: win7x6417: not ready yet 2025-12-13 16:21:46,892 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6417, ip=192.168.168.217) 2025-12-13 16:21:46,959 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6417, ip=192.168.168.217, monitor=latest, size=6660546) 2025-12-13 16:21:48,208 [cuckoo.core.resultserver] DEBUG: Task #7222229: live log analysis.log initialized. 2025-12-13 16:21:48,988 [cuckoo.core.resultserver] DEBUG: Task #7222229 is sending a BSON stream 2025-12-13 16:21:49,393 [cuckoo.core.resultserver] DEBUG: Task #7222229 is sending a BSON stream 2025-12-13 16:21:50,306 [cuckoo.core.resultserver] DEBUG: Task #7222229: File upload for 'shots/0001.jpg' 2025-12-13 16:21:50,324 [cuckoo.core.resultserver] DEBUG: Task #7222229 uploaded file length: 137746 2025-12-13 16:22:02,918 [cuckoo.core.guest] DEBUG: win7x6417: analysis #7222229 still processing 2025-12-13 16:22:18,108 [cuckoo.core.guest] DEBUG: win7x6417: analysis #7222229 still processing 2025-12-13 16:22:18,491 [cuckoo.core.resultserver] DEBUG: Task #7222229: File upload for 'curtain/1765635738.49.curtain.log' 2025-12-13 16:22:18,494 [cuckoo.core.resultserver] DEBUG: Task #7222229 uploaded file length: 36 2025-12-13 16:22:18,598 [cuckoo.core.resultserver] DEBUG: Task #7222229: File upload for 'sysmon/1765635738.6.sysmon.xml' 2025-12-13 16:22:18,605 [cuckoo.core.resultserver] DEBUG: Task #7222229 uploaded file length: 178208 2025-12-13 16:22:19,288 [cuckoo.core.resultserver] DEBUG: Task #7222229: File upload for 'shots/0002.jpg' 2025-12-13 16:22:19,313 [cuckoo.core.resultserver] DEBUG: Task #7222229 uploaded file length: 133513 2025-12-13 16:22:19,331 [cuckoo.core.resultserver] DEBUG: Task #7222229 had connection reset for <Context for LOG> 2025-12-13 16:22:21,122 [cuckoo.core.guest] INFO: win7x6417: analysis completed successfully 2025-12-13 16:22:21,133 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-12-13 16:22:21,165 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-12-13 16:22:22,406 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6417 to path /srv/cuckoo/cwd/storage/analyses/7222229/memory.dmp 2025-12-13 16:22:22,407 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6417 2025-12-13 16:22:31,489 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.217 for task #7222229 2025-12-13 16:22:31,886 [cuckoo.core.scheduler] DEBUG: Released database task #7222229 2025-12-13 16:22:31,905 [cuckoo.core.scheduler] INFO: Task #7222229: analysis procedure completed
| description | (no description) | rule | APT32_KerrDown | ||||||
| description | Detect PE file produced by pyinstaller | rule | PE_File_pyinstaller | ||||||
| description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
| description | Checks if being debugged | rule | anti_dbg | ||||||
| description | Affect private profile | rule | win_files_operation | ||||||
| section | .gfids |
| section | {u'size_of_data': u'0x00010800', u'virtual_address': u'0x0003c000', u'entropy': 7.255045319856109, u'name': u'.rsrc', u'virtual_size': u'0x00010608'} | entropy | 7.25504531986 | description | A section with a high entropy has been found | |||||||||
| entropy | 0.272164948454 | description | Overall entropy of this PE file is high | |||||||||||
| G Data Antivirus (Windows) | Virus: Win32.Trojan.PSE.1U72U99 (Engine B) |
| Avast Core Security (Linux) | Win32:Malware-gen |
| C4S ClamAV (Linux) | Win.Malware.F857af-9782719-0 |
| DrWeb Antivirus (Linux) | Python.BtcMine.5 |
| ClamAV (Linux) | Win.Malware.F857af-9782719-0 |