| Size | 636.2KB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | dd5bbe32340fa539592ae9c4e039c33f |
| SHA1 | 9e2b19edcbb0813c504819261fb4c3f280fc4f8a |
| SHA256 | 1c709f565c10011a7958275be2f211d64b48c79c2522b48f2e20362357dff846 |
| SHA512 |
3505d925c3ce35a0a77cd77575caf930bb2f4cdcc834810f2a5eb9369b988da108977f171696d5d7be6bb61171473659bd2d7d5bc5ce1d9ff0a3efa42117a7e7
|
| CRC32 | 7B318744 |
| ssdeep | None |
| Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Jan. 9, 2026, 10:32 p.m. | Jan. 9, 2026, 10:33 p.m. | 61 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-01-09 21:32:34,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpf7a_02 2026-01-09 21:32:34,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\MPpbDsZkaFIobFczeXuNZVjxFinjn 2026-01-09 21:32:34,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\LXncPugLkkTEDpRoJNxYjRqBdY 2026-01-09 21:32:34,342 [analyzer] DEBUG: Started auxiliary module Curtain 2026-01-09 21:32:34,342 [analyzer] DEBUG: Started auxiliary module DbgView 2026-01-09 21:32:34,750 [analyzer] DEBUG: Started auxiliary module Disguise 2026-01-09 21:32:34,953 [analyzer] DEBUG: Loaded monitor into process with pid 504 2026-01-09 21:32:34,953 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-01-09 21:32:34,953 [analyzer] DEBUG: Started auxiliary module Human 2026-01-09 21:32:34,953 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-01-09 21:32:34,953 [analyzer] DEBUG: Started auxiliary module Reboot 2026-01-09 21:32:35,062 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-01-09 21:32:35,078 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-01-09 21:32:35,078 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-01-09 21:32:35,078 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-01-09 21:32:35,328 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\setup.exe' with arguments '' and pid 1924 2026-01-09 21:32:35,671 [analyzer] DEBUG: Loaded monitor into process with pid 1924 2026-01-09 21:32:35,796 [analyzer] INFO: Added new file to list with pid 1924 and path C:\Users\Administrator\AppData\Local\Temp\is-754L2.tmp\setup.tmp 2026-01-09 21:32:35,890 [analyzer] INFO: Injected into process with pid 2824 and name u'setup.tmp' 2026-01-09 21:32:36,078 [analyzer] DEBUG: Loaded monitor into process with pid 2824 2026-01-09 21:33:24,615 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2026-01-09 21:33:24,819 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1924. 2026-01-09 21:33:24,897 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2824. 2026-01-09 21:33:25,210 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-01-09 21:33:25,210 [lib.api.process] INFO: Successfully terminated process with pid 1924. 2026-01-09 21:33:25,210 [lib.api.process] INFO: Successfully terminated process with pid 2824. 2026-01-09 21:33:25,240 [analyzer] INFO: Analysis completed.
2026-01-09 22:32:35,011 [cuckoo.core.scheduler] INFO: Task #7284375: acquired machine win7x6427 (label=win7x6427) 2026-01-09 22:32:35,012 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.227 for task #7284375 2026-01-09 22:32:35,445 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2625752 (interface=vboxnet0, host=192.168.168.227) 2026-01-09 22:32:35,696 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6427 2026-01-09 22:32:36,645 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6427 to vmcloak 2026-01-09 22:32:46,623 [cuckoo.core.guest] INFO: Starting analysis #7284375 on guest (id=win7x6427, ip=192.168.168.227) 2026-01-09 22:32:47,629 [cuckoo.core.guest] DEBUG: win7x6427: not ready yet 2026-01-09 22:32:52,654 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6427, ip=192.168.168.227) 2026-01-09 22:32:52,793 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6427, ip=192.168.168.227, monitor=latest, size=6660546) 2026-01-09 22:32:54,239 [cuckoo.core.resultserver] DEBUG: Task #7284375: live log analysis.log initialized. 2026-01-09 22:32:55,161 [cuckoo.core.resultserver] DEBUG: Task #7284375 is sending a BSON stream 2026-01-09 22:32:55,852 [cuckoo.core.resultserver] DEBUG: Task #7284375 is sending a BSON stream 2026-01-09 22:32:56,269 [cuckoo.core.resultserver] DEBUG: Task #7284375 is sending a BSON stream 2026-01-09 22:32:56,465 [cuckoo.core.resultserver] DEBUG: Task #7284375: File upload for 'shots/0001.jpg' 2026-01-09 22:32:56,499 [cuckoo.core.resultserver] DEBUG: Task #7284375 uploaded file length: 133464 2026-01-09 22:32:57,618 [cuckoo.core.resultserver] DEBUG: Task #7284375: File upload for 'shots/0002.jpg' 2026-01-09 22:32:57,636 [cuckoo.core.resultserver] DEBUG: Task #7284375 uploaded file length: 138455 2026-01-09 22:33:08,729 [cuckoo.core.guest] DEBUG: win7x6427: analysis #7284375 still processing 2026-01-09 22:33:23,832 [cuckoo.core.guest] DEBUG: win7x6427: analysis #7284375 still processing 2026-01-09 22:33:25,090 [cuckoo.core.resultserver] DEBUG: Task #7284375: File upload for 'curtain/1767990805.09.curtain.log' 2026-01-09 22:33:25,094 [cuckoo.core.resultserver] DEBUG: Task #7284375 uploaded file length: 36 2026-01-09 22:33:25,209 [cuckoo.core.resultserver] DEBUG: Task #7284375: File upload for 'sysmon/1767990805.21.sysmon.xml' 2026-01-09 22:33:25,214 [cuckoo.core.resultserver] DEBUG: Task #7284375 uploaded file length: 161820 2026-01-09 22:33:25,234 [cuckoo.core.resultserver] DEBUG: Task #7284375: File upload for 'files/cf0018affdd0b792_setup.tmp' 2026-01-09 22:33:25,245 [cuckoo.core.resultserver] DEBUG: Task #7284375 uploaded file length: 1175040 2026-01-09 22:33:25,557 [cuckoo.core.resultserver] DEBUG: Task #7284375: File upload for 'shots/0003.jpg' 2026-01-09 22:33:25,571 [cuckoo.core.resultserver] DEBUG: Task #7284375 uploaded file length: 133454 2026-01-09 22:33:25,582 [cuckoo.core.resultserver] DEBUG: Task #7284375 had connection reset for <Context for LOG> 2026-01-09 22:33:26,845 [cuckoo.core.guest] INFO: win7x6427: analysis completed successfully 2026-01-09 22:33:26,857 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-01-09 22:33:26,885 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-01-09 22:33:28,108 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6427 to path /srv/cuckoo/cwd/storage/analyses/7284375/memory.dmp 2026-01-09 22:33:28,109 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6427 2026-01-09 22:33:36,192 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.227 for task #7284375 2026-01-09 22:33:36,525 [cuckoo.core.scheduler] DEBUG: Released database task #7284375 2026-01-09 22:33:36,544 [cuckoo.core.scheduler] INFO: Task #7284375: analysis procedure completed
| description | Bypass DEP | rule | disable_dep | ||||||
| description | Escalade priviledges | rule | escalate_priv | ||||||
| description | Run a keylogger | rule | keylogger | ||||||
| description | Affect system registries | rule | win_registry | ||||||
| description | Affect system token | rule | win_token | ||||||
| description | Affect private profile | rule | win_files_operation | ||||||
| section | .itext |
| APEX | Malicious |
| Trapmine | suspicious.low.ml.score |