File 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe

Size 1.2MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4aa7c1931eef81b2b8930e18de269d43
SHA1 be740789322ef7b8f15cec420cf0d8368f0a97c7
SHA256 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42
SHA512
96aa8716b79c570f4aa9fee1d43fcfeb0956f4796a11c7069772a0020d2e82b7eaf6255030d53d39d841d6a66cb1802749d52bc82e2f6a180d6310be922a5b0d
CRC32 9524D8DD
ssdeep None
Yara
  • DebuggerException__SetConsoleCtrl - (no description)
  • win_mutex - Create or check mutex
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

7269372

7269373

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Dec. 27, 2025, 10:10 a.m. Dec. 27, 2025, 10:19 a.m. 521 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-12-27 09:03:39,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpt1gcja
2025-12-27 09:03:39,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\VQpYnkxOqKzXbpzkkPyBtcbabNDcQfZe
2025-12-27 09:03:39,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\znjJfBgzUYPOPcZUi
2025-12-27 09:03:39,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-12-27 09:03:39,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-12-27 09:03:39,796 [analyzer] DEBUG: Started auxiliary module Disguise
2025-12-27 09:03:40,030 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-12-27 09:03:40,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-12-27 09:03:40,030 [analyzer] DEBUG: Started auxiliary module Human
2025-12-27 09:03:40,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-12-27 09:03:40,030 [analyzer] DEBUG: Started auxiliary module Reboot
2025-12-27 09:03:40,092 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-12-27 09:03:40,092 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-12-27 09:03:40,092 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-12-27 09:03:40,092 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-12-27 09:03:40,265 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe' with arguments '' and pid 1084
2025-12-27 09:03:40,437 [analyzer] DEBUG: Loaded monitor into process with pid 1084
2025-12-27 09:03:40,796 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Windows\mssrv.exe
2025-12-27 09:03:40,858 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Program Files\Common Files\Microsoft Shared\swedish cumshot bukkake [milf]  (Janette).avi.exe
2025-12-27 09:03:41,390 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Program Files\Microsoft Office\Templates\french xxx uncut .zip.exe
2025-12-27 09:03:41,421 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\american cum horse girls balls  (Ashley,Melissa).mpg.exe
2025-12-27 09:03:41,530 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Program Files\Windows Journal\Templates\beast uncut cock penetration .mpeg.exe
2025-12-27 09:03:41,655 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Program Files\Windows Sidebar\Shared Gadgets\russian animal lesbian catfight gorgeoushorny .mpg.exe
2025-12-27 09:03:41,687 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\russian horse fucking full movie girly  (Gina,Curtney).zip.exe
2025-12-27 09:03:41,812 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Program Files (x86)\Common Files\microsoft shared\horse hot (!) cock .avi.exe
2025-12-27 09:03:42,140 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\american porn lesbian full movie 50+ .rar.exe
2025-12-27 09:03:42,217 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\Network\Downloader\horse voyeur feet 40+ .avi.exe
2025-12-27 09:03:42,250 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\RAC\Temp\tyrkish action xxx catfight hole shoes .avi.exe
2025-12-27 09:03:42,280 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\Search\Data\Temp\swedish animal fucking hidden  (Liz).zip.exe
2025-12-27 09:03:42,342 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\Windows\Templates\sperm uncut penetration .zip.exe
2025-12-27 09:03:42,405 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\Windows\Templates\black kicking bukkake sleeping gorgeoushorny .mpg.exe
2025-12-27 09:03:42,687 [analyzer] INFO: Injected into process with pid 2196 and name ''
2025-12-27 09:03:42,842 [analyzer] DEBUG: Loaded monitor into process with pid 2196
2025-12-27 09:03:42,967 [analyzer] INFO: Added new file to list with pid 1084 and path C:\tmpt1gcja\trambling [milf] femdom  (Gina,Jade).zip.exe
2025-12-27 09:03:43,078 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\black cum fucking lesbian hole .mpg.exe
2025-12-27 09:03:43,155 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\AppData\Local\Temp\danish handjob bukkake [free] lady .avi.exe
2025-12-27 09:03:43,187 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\beast big upskirt .zip.exe
2025-12-27 09:03:43,203 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\lingerie licking titts .rar.exe
2025-12-27 09:03:43,405 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\blowjob hot (!) .mpg.exe
2025-12-27 09:03:43,483 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\russian handjob horse full movie .mpg.exe
2025-12-27 09:03:43,546 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\black cum lingerie hidden 50+ .zip.exe
2025-12-27 09:03:43,608 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\Downloads\beast hot (!) upskirt  (Britney,Curtney).avi.exe
2025-12-27 09:03:43,655 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\american fetish fucking big hotel  (Sonja,Sylvia).rar.exe
2025-12-27 09:03:43,733 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\RAC\Temp\chinese sperm several models .mpg.exe
2025-12-27 09:03:43,765 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\Search\Data\Temp\japanese cumshot gay lesbian .mpeg.exe
2025-12-27 09:03:43,875 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\Windows\Templates\fucking sleeping .avi.exe
2025-12-27 09:03:43,921 [analyzer] INFO: Added new file to list with pid 1084 and path C:\ProgramData\Microsoft\Windows\Templates\japanese nude sperm voyeur cock traffic .mpg.exe
2025-12-27 09:03:43,967 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\bukkake uncut titts .mpg.exe
2025-12-27 09:03:43,983 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Default\AppData\Local\Temp\lesbian hidden .mpg.exe
2025-12-27 09:03:44,000 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\lesbian hot (!) high heels .zip.exe
2025-12-27 09:03:44,030 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\blowjob [free] bedroom .avi.exe
2025-12-27 09:03:44,062 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Default\Downloads\horse [bangbus] swallow .rar.exe
2025-12-27 09:03:44,108 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\indian beastiality trambling [milf] cock gorgeoushorny  (Sylvia).mpeg.exe
2025-12-27 09:03:44,125 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Users\Public\Downloads\horse girls feet bondage .rar.exe
2025-12-27 09:03:44,217 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\lingerie full movie boots .mpg.exe
2025-12-27 09:03:44,233 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\bukkake voyeur femdom .avi.exe
2025-12-27 09:03:44,312 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor\brasilian nude gay [milf] sm .zip.exe
2025-12-27 09:03:44,328 [analyzer] INFO: Added new file to list with pid 1084 and path C:\Windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor.Resources\tyrkish horse bukkake [milf] .zip.exe
2025-12-27 09:16:25,365 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-12-27 09:16:25,520 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1084.
2025-12-27 09:16:25,582 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2196.
2025-12-27 09:16:26,036 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-12-27 09:16:26,036 [lib.api.process] INFO: Successfully terminated process with pid 1084.
2025-12-27 09:16:26,036 [lib.api.process] INFO: Successfully terminated process with pid 2196.
2025-12-27 09:16:27,052 [analyzer] WARNING: Too many files: c:\programdata\microsoft\windows\templates\fucking sleeping .avi.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\microsoft\windows\temporary internet files\lingerie licking titts .rar.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\programdata\microsoft\windows\templates\japanese nude sperm voyeur cock traffic .mpg.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\programdata\microsoft\windows\templates\black kicking bukkake sleeping gorgeoushorny .mpg.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\programdata\microsoft\windows\templates\sperm uncut penetration .zip.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\users\default\appdata\local\temp\lesbian hidden .mpg.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\programdata\microsoft\network\downloader\horse voyeur feet 40+ .avi.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\microsoft\windows\temporary internet files\black cum fucking lesbian hole .mpg.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\users\public\downloads\horse girls feet bondage .rar.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\roaming\microsoft\windows\templates\american fetish fucking big hotel  (sonja,sylvia).rar.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\program files\windows sidebar\shared gadgets\russian animal lesbian catfight gorgeoushorny .mpg.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\programdata\microsoft\search\data\temp\japanese cumshot gay lesbian .mpeg.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\windows\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\lingerie full movie boots .mpg.exe
2025-12-27 09:16:27,068 [analyzer] WARNING: Too many files: c:\program files\microsoft office\templates\french xxx uncut .zip.exe
2025-12-27 09:16:27,068 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-12-27 10:10:22,616 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:23,658 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:24,689 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:25,709 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:26,724 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:27,764 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:28,796 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:29,843 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:30,873 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:32,023 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:33,060 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:34,129 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:35,173 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:36,317 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:37,423 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:38,706 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:39,751 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:40,778 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:41,835 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:42,871 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:43,902 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:44,922 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:45,945 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:46,969 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:47,990 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:49,006 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:50,035 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:51,062 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:52,085 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:53,120 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:54,579 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:55,630 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:56,668 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:57,709 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:58,736 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:10:59,757 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:00,779 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:01,808 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:02,830 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:03,862 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:04,887 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:05,909 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:06,930 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:07,990 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:09,018 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:10,037 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:11,060 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:12,081 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:13,104 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:14,125 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:15,146 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:16,167 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:17,190 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:18,212 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:19,234 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:20,263 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:21,362 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:22,387 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:23,416 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:24,446 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:25,473 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:26,501 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:27,520 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:28,542 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:29,562 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:30,578 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:31,595 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:32,619 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:33,662 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:34,717 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:35,774 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:36,816 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:37,877 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:39,044 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:40,167 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:41,244 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:42,318 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:43,385 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:44,445 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:45,484 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:46,640 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:47,688 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:48,742 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:49,840 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:50,879 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:51,928 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:53,212 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:54,237 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:55,258 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:56,277 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:57,297 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:58,322 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:11:59,341 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:00,362 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:01,378 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:02,400 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:03,427 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:04,449 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:05,472 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:06,495 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:07,517 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:08,537 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:09,558 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:10,580 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:11,597 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:12,730 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:13,808 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:14,841 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:15,874 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:16,914 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:17,954 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:19,022 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:20,080 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:21,160 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:22,246 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:23,312 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:24,396 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:25,457 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:26,527 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:27,599 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:28,669 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:29,844 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:30,986 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:32,178 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:33,276 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:34,347 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:35,441 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:36,656 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:37,877 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:38,949 [cuckoo.core.scheduler] DEBUG: Task #7269181: no machine available yet
2025-12-27 10:12:40,036 [cuckoo.core.scheduler] INFO: Task #7269181: acquired machine win7x642 (label=win7x642)
2025-12-27 10:12:40,038 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.202 for task #7269181
2025-12-27 10:12:40,465 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2601197 (interface=vboxnet0, host=192.168.168.202)
2025-12-27 10:12:48,858 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x642
2025-12-27 10:12:49,920 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x642 to vmcloak
2025-12-27 10:15:47,486 [cuckoo.core.guest] INFO: Starting analysis #7269181 on guest (id=win7x642, ip=192.168.168.202)
2025-12-27 10:15:48,492 [cuckoo.core.guest] DEBUG: win7x642: not ready yet
2025-12-27 10:15:53,515 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x642, ip=192.168.168.202)
2025-12-27 10:15:53,620 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x642, ip=192.168.168.202, monitor=latest, size=6660546)
2025-12-27 10:15:55,089 [cuckoo.core.resultserver] DEBUG: Task #7269181: live log analysis.log initialized.
2025-12-27 10:15:56,070 [cuckoo.core.resultserver] DEBUG: Task #7269181 is sending a BSON stream
2025-12-27 10:15:56,460 [cuckoo.core.resultserver] DEBUG: Task #7269181 is sending a BSON stream
2025-12-27 10:15:57,305 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'shots/0001.jpg'
2025-12-27 10:15:57,326 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 133603
2025-12-27 10:15:58,868 [cuckoo.core.resultserver] DEBUG: Task #7269181 is sending a BSON stream
2025-12-27 10:16:09,760 [cuckoo.core.guest] DEBUG: win7x642: analysis #7269181 still processing
2025-12-27 10:16:24,904 [cuckoo.core.guest] DEBUG: win7x642: analysis #7269181 still processing
2025-12-27 10:16:25,744 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'curtain/1766823385.74.curtain.log'
2025-12-27 10:16:25,752 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 36
2025-12-27 10:16:25,966 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'sysmon/1766823385.96.sysmon.xml'
2025-12-27 10:16:26,049 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 2282100
2025-12-27 10:16:26,063 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/ae4ad33b74ca7e07_black cum lingerie hidden 50+ .zip.exe'
2025-12-27 10:16:26,098 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 891882
2025-12-27 10:16:26,111 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/06e211ae2e71eb2a_blowjob [free] bedroom .avi.exe'
2025-12-27 10:16:26,158 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 2131580
2025-12-27 10:16:26,169 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/9930b0f7d496337f_trambling [milf] femdom  (gina,jade).zip.exe'
2025-12-27 10:16:26,210 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 890263
2025-12-27 10:16:26,217 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/48d6e61040304430_tyrkish horse bukkake [milf] .zip.exe'
2025-12-27 10:16:26,250 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1670921
2025-12-27 10:16:26,260 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/1e515763de0c2cf6_swedish animal fucking hidden  (liz).zip.exe'
2025-12-27 10:16:26,289 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1007883
2025-12-27 10:16:26,295 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/6689c4ad04b00635_horse [bangbus] swallow .rar.exe'
2025-12-27 10:16:26,332 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 744522
2025-12-27 10:16:26,341 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/7766ca1de9784426_chinese sperm several models .mpg.exe'
2025-12-27 10:16:26,373 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1013339
2025-12-27 10:16:26,382 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/7248b03300f9e0dd_beast hot (!) upskirt  (britney,curtney).avi.exe'
2025-12-27 10:16:26,410 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 756199
2025-12-27 10:16:26,416 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/18bc385118b86c56_brasilian nude gay [milf] sm .zip.exe'
2025-12-27 10:16:26,426 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 129730
2025-12-27 10:16:26,428 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/487cd06d9def73ac_lesbian hot (!) high heels .zip.exe'
2025-12-27 10:16:26,435 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 97322
2025-12-27 10:16:26,440 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/7e887bb43d3f2ded_swedish cumshot bukkake [milf]  (janette).avi.exe'
2025-12-27 10:16:26,471 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1128911
2025-12-27 10:16:26,494 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/c38ff94651b442ed_tyrkish action xxx catfight hole shoes .avi.exe'
2025-12-27 10:16:26,518 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 623169
2025-12-27 10:16:26,523 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/c6784a33cab71d01_indian beastiality trambling [milf] cock gorgeoushorny  (sylvia).mpeg.exe'
2025-12-27 10:16:26,539 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 317905
2025-12-27 10:16:26,542 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/ed8d2d58705996ab_danish handjob bukkake [free] lady .avi.exe'
2025-12-27 10:16:26,572 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1006490
2025-12-27 10:16:26,578 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/cd69746c420b9a3e_mssrv.exe'
2025-12-27 10:16:26,590 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 363560
2025-12-27 10:16:26,598 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/d885acfe4848891a_russian handjob horse full movie .mpg.exe'
2025-12-27 10:16:26,684 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1777519
2025-12-27 10:16:26,697 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/e184c4940554b13f_beast uncut cock penetration .mpeg.exe'
2025-12-27 10:16:26,735 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1160679
2025-12-27 10:16:26,745 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/a8bd0dd07aae2d76_bukkake voyeur femdom .avi.exe'
2025-12-27 10:16:26,750 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 137520
2025-12-27 10:16:26,753 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/d1e7b38c8d6c101c_beast big upskirt .zip.exe'
2025-12-27 10:16:26,798 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 792002
2025-12-27 10:16:26,811 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/d5f8af25d1a31903_american porn lesbian full movie 50+ .rar.exe'
2025-12-27 10:16:26,850 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 892338
2025-12-27 10:16:26,859 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/b634438bbc10783e_horse hot (!) cock .avi.exe'
2025-12-27 10:16:26,867 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/408ea9ffeb391e7c_bukkake uncut titts .mpg.exe'
2025-12-27 10:16:26,874 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/96011d5356a936fd_american cum horse girls balls  (ashley,melissa).mpg.exe'
2025-12-27 10:16:26,925 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1132787
2025-12-27 10:16:26,949 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 652756
2025-12-27 10:16:26,982 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 775948
2025-12-27 10:16:26,992 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/0e3f8b08abc1d0c6_russian horse fucking full movie girly  (gina,curtney).zip.exe'
2025-12-27 10:16:27,034 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1474501
2025-12-27 10:16:27,044 [cuckoo.core.resultserver] DEBUG: Task #7269181: File upload for 'files/18b0d3338be8c508_blowjob hot (!) .mpg.exe'
2025-12-27 10:16:27,089 [cuckoo.core.resultserver] DEBUG: Task #7269181 uploaded file length: 1182827
2025-12-27 10:16:27,106 [cuckoo.core.resultserver] DEBUG: Task #7269181 had connection reset for <Context for LOG>
2025-12-27 10:16:27,924 [cuckoo.core.guest] INFO: win7x642: analysis completed successfully
2025-12-27 10:16:28,043 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-12-27 10:16:28,075 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-12-27 10:16:29,320 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x642 to path /srv/cuckoo/cwd/storage/analyses/7269181/memory.dmp
2025-12-27 10:16:29,329 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x642
2025-12-27 10:19:03,076 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.202 for task #7269181
2025-12-27 10:19:03,959 [cuckoo.core.scheduler] DEBUG: Released database task #7269181
2025-12-27 10:19:04,007 [cuckoo.core.scheduler] INFO: Task #7269181: analysis procedure completed

Signatures

Yara rules detected for file (4 events)
description (no description) rule DebuggerException__SetConsoleCtrl
description Create or check mutex rule win_mutex
description Affect system registries rule win_registry
description Affect private profile rule win_files_operation
The executable uses a known packer (1 event)
packer Pelles C 3.00, 4.00, 4.50 EXE (X86 CRT-LIB)
A process attempted to delay the analysis task. (1 event)
description 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe tried to sleep 150 seconds, actually delayed analysis time by 150 seconds
Creates executable files on the filesystem (39 events)
file C:\Users\All Users\Microsoft\Search\Data\Temp\japanese cumshot gay lesbian .mpeg.exe
file C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\blowjob [free] bedroom .avi.exe
file C:\Users\Default\AppData\Local\Temp\lesbian hidden .mpg.exe
file C:\Users\Administrator\Templates\american fetish fucking big hotel (Sonja,Sylvia).rar.exe
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\black cum fucking lesbian hole .mpg.exe
file C:\Program Files\Windows Sidebar\Shared Gadgets\russian animal lesbian catfight gorgeoushorny .mpg.exe
file C:\Users\All Users\Templates\japanese nude sperm voyeur cock traffic .mpg.exe
file C:\Windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor.Resources\tyrkish horse bukkake [milf] .zip.exe
file C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\russian horse fucking full movie girly (Gina,Curtney).zip.exe
file C:\ProgramData\Microsoft\Search\Data\Temp\swedish animal fucking hidden (Liz).zip.exe
file C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\lingerie full movie boots .mpg.exe
file C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\beast big upskirt .zip.exe
file C:\Users\Administrator\Downloads\beast hot (!) upskirt (Britney,Curtney).avi.exe
file C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\american porn lesbian full movie 50+ .rar.exe
file C:\Program Files (x86)\Common Files\microsoft shared\horse hot (!) cock .avi.exe
file C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\bukkake uncut titts .mpg.exe
file C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\american cum horse girls balls (Ashley,Melissa).mpg.exe
file C:\Program Files\Common Files\Microsoft Shared\swedish cumshot bukkake [milf] (Janette).avi.exe
file C:\tmpt1gcja\trambling [milf] femdom (Gina,Jade).zip.exe
file C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\blowjob hot (!) .mpg.exe
file C:\Users\Default\AppData\Local\Temporary Internet Files\lesbian hot (!) high heels .zip.exe
file C:\Users\Public\Downloads\horse girls feet bondage .rar.exe
file C:\ProgramData\Microsoft\RAC\Temp\tyrkish action xxx catfight hole shoes .avi.exe
file C:\Users\Administrator\AppData\Local\Temporary Internet Files\lingerie licking titts .rar.exe
file C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\russian handjob horse full movie .mpg.exe
file C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\bukkake voyeur femdom .avi.exe
file C:\Users\All Users\Microsoft\Windows\Templates\fucking sleeping .avi.exe
file C:\Users\Default\Templates\indian beastiality trambling [milf] cock gorgeoushorny (Sylvia).mpeg.exe
file C:\Windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor\brasilian nude gay [milf] sm .zip.exe
file C:\Windows\mssrv.exe
file C:\Users\Administrator\AppData\Local\Temp\danish handjob bukkake [free] lady .avi.exe
file C:\Users\Default\Downloads\horse [bangbus] swallow .rar.exe
file C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\black cum lingerie hidden 50+ .zip.exe
file C:\ProgramData\Microsoft\Network\Downloader\horse voyeur feet 40+ .avi.exe
file C:\Users\All Users\Microsoft\RAC\Temp\chinese sperm several models .mpg.exe
file C:\ProgramData\Microsoft\Windows\Templates\sperm uncut penetration .zip.exe
file C:\Program Files\Windows Journal\Templates\beast uncut cock penetration .mpeg.exe
file C:\Program Files\Microsoft Office\Templates\french xxx uncut .zip.exe
file C:\ProgramData\Templates\black kicking bukkake sleeping gorgeoushorny .mpg.exe
Drops an executable to the user AppData folder (2 events)
file C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\black cum lingerie hidden 50+ .zip.exe
file C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\blowjob [free] bedroom .avi.exe
Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping (3 events)
Repeatedly searches for a not-found process, you may want to run a web browser during analysis (15 events)
Time & API Arguments Status Return Repeated

Process32NextW

snapshot_handle: 0x00000124
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 1084
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2196
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x00000280
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2080
0 0

Process32NextW

snapshot_handle: 0x0000011c
process_name: 1fd5e053b439c0dbced070cb1dde5d2b99678e835007782f6205da60e1a76e42.exe
process_identifier: 2196
0 0
Enumerates services, possibly for anti-virtualization (1 event)
Time & API Arguments Status Return Repeated

EnumServicesStatusA

service_handle: 0x0028caf8
service_type: 48
service_status: 1
0 0
Installs itself for autorun at Windows startup (1 event)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\mssrv32 reg_value C:\Windows\mssrv.exeÿY)ÿ @ß(ÿÜ ˜:&@ß(Êl§w[)Ä&n˜:&Y)Ä&èúÛõqø;ª8ûxÿõq«wUMþÿÿÿª8§w¢4§wY)noY)0ü7.(v&Y)Ã@\ýÜÞY)Øþâ@
Creates known WinSxsBot/Sfone Worm files, registry keys and/or mutexes (1 event)
mutex mutex666
File has been identified by 12 AntiVirus engine on IRMA as malicious (12 events)
G Data Antivirus (Windows) Virus: Gen:Variant.Application.Fragtor.4684 (Engine A), Win32.Worm.Sfone.B (Engine B)
Avast Core Security (Linux) Win32:Agent-URR [Trj]
C4S ClamAV (Linux) Win.Malware.Eclz-9953021-0
Trellix (Linux) W32/Generic.worm.f virus
WithSecure (Linux) Trojan.TR/Spy.Gen
eScan Antivirus (Linux) Gen:Variant.Application.Fragtor.4684(DB)
ESET Security (Windows) Win32/Agent.CP worm
Sophos Anti-Virus (Linux) W32/Sfone-A
DrWeb Antivirus (Linux) Win32.HLLW.Siggen.1607
ClamAV (Linux) Win.Malware.Eclz-9953021-0
Bitdefender Antivirus (Linux) Gen:Variant.Application.Fragtor.4684
Kaspersky Standard (Windows) Worm.Win32.Agent.cp
File has been identified by 68 AntiVirus engines on VirusTotal as malicious (50 out of 68 events)
Bkav W32.AIDetectMalware
Lionic Worm.Win32.Agent.tn3v
Elastic Windows.Generic.Threat
Cynet Malicious (score: 100)
CAT-QuickHeal Worm.Sfone.A3
Skyhigh BehavesLike.Win32.Dropper.tc
ALYac Trojan.GenericKDZ.94847
Cylance unsafe
VIPRE Trojan.GenericKDZ.94847
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00008f2e1 )
BitDefender Trojan.GenericKDZ.94847
K7GW Trojan ( 00008f2e1 )
Cybereason malicious.31eef8
Arcabit Trojan.Generic.D1727F
Baidu Win32.Worm.Agent.fj
VirIT Worm.Win32.Agent.CP
Symantec W32.SillyWNSE
tehtris Generic.Malware
ESET-NOD32 Win32/Agent.CP
APEX Malicious
McAfee W32/Generic.worm.f
Avast Win32:Agent-URR [Trj]
ClamAV Win.Malware.Eclz-9953021-0
Kaspersky Worm.Win32.Agent.cp
Alibaba Worm:Win32/Sfone.343
NANO-Antivirus Trojan.Win32.Agent.hakuu
SUPERAntiSpyware Worm.Sform/Variant
MicroWorld-eScan Trojan.GenericKDZ.94847
Rising Worm.Agent!1.CEBD (CLASSIC)
Emsisoft Trojan.GenericKDZ.94847 (B)
F-Secure Trojan.TR/Spy.Gen
DrWeb Win32.HLLW.Siggen.1607
Zillya Worm.Agent.Win32.9
TrendMicro WORM_AGENT.JM
Trapmine malicious.high.ml.score
FireEye Generic.mg.4aa7c1931eef81b2
Sophos W32/Sfone-A
Ikarus Trojan.Crypt
Jiangmin Worm/Agent.te
Google Detected
Avira TR/Spy.Gen
MAX malware (ai score=81)
Antiy-AVL Worm/Win32.Agent.cp
Gridinsoft Worm.Win32.Agent.ka!s1
Xcitium Worm.Win32.Agent.CP@42tt
Microsoft Worm:Win32/Sfone!pz
ViRobot Worm.Win32.A.Agent.61440
ZoneAlarm Worm.Win32.Agent.cp
GData Win32.Worm.Sfone.B
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.