File f381e338212079c3a03fbbb532cdec44b1d27db03e8cc4c47408ef038885d934.exe

Size 1.0MB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 411019bcb582ef6e3dab080d99925b4b
SHA1 38cfa080a7ab69fb6c5010f38e321272a39d5f19
SHA256 f381e338212079c3a03fbbb532cdec44b1d27db03e8cc4c47408ef038885d934
SHA512
8908321719d00323c5fac12e1c7ea3a11a79b534e11d9434743651630402369c32f33c5054fc31ddd34ca9fb3403e0cef6c72f5b2c242a4b1ed6283ce1040a80
CRC32 12F641B7
ssdeep None
Yara
  • keylogger - Run a keylogger

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE May 12, 2026, 2:12 p.m. May 12, 2026, 2:13 p.m. 59 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2026-05-12 14:12:46,015 [analyzer] DEBUG: Starting analyzer from: C:\tmppw5mq4
2026-05-12 14:12:46,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\McCXsECCWwKEgUKPoPRbKYiJOeyL
2026-05-12 14:12:46,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\XpxEesrrovylDMGGsCPZ
2026-05-12 14:12:46,280 [analyzer] DEBUG: Started auxiliary module Curtain
2026-05-12 14:12:46,280 [analyzer] DEBUG: Started auxiliary module DbgView
2026-05-12 14:12:46,796 [analyzer] DEBUG: Started auxiliary module Disguise
2026-05-12 14:12:47,000 [analyzer] DEBUG: Loaded monitor into process with pid 504
2026-05-12 14:12:47,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2026-05-12 14:12:47,000 [analyzer] DEBUG: Started auxiliary module Human
2026-05-12 14:12:47,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2026-05-12 14:12:47,000 [analyzer] DEBUG: Started auxiliary module Reboot
2026-05-12 14:12:47,030 [analyzer] DEBUG: Started auxiliary module RecentFiles
2026-05-12 14:12:47,030 [analyzer] DEBUG: Started auxiliary module Screenshots
2026-05-12 14:12:47,030 [analyzer] DEBUG: Started auxiliary module Sysmon
2026-05-12 14:12:47,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2026-05-12 14:12:47,155 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\f381e338212079c3a03fbbb532cdec44b1d27db03e8cc4c47408ef038885d934.exe' with arguments '' and pid 1524
2026-05-12 14:12:47,296 [analyzer] DEBUG: Loaded monitor into process with pid 1524
2026-05-12 13:13:34,786 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2026-05-12 13:13:35,005 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1524.
2026-05-12 13:13:35,316 [analyzer] INFO: Terminating remaining processes before shutdown.
2026-05-12 13:13:35,316 [lib.api.process] INFO: Successfully terminated process with pid 1524.
2026-05-12 13:13:35,316 [analyzer] INFO: Analysis completed.

Cuckoo Log

2026-05-12 14:12:46,583 [cuckoo.core.scheduler] INFO: Task #7552216: acquired machine win7x646 (label=win7x646)
2026-05-12 14:12:46,584 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.206 for task #7552216
2026-05-12 14:12:47,042 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1208613 (interface=vboxnet0, host=192.168.168.206)
2026-05-12 14:12:47,441 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x646
2026-05-12 14:12:48,114 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x646 to vmcloak
2026-05-12 14:12:57,184 [cuckoo.core.guest] INFO: Starting analysis #7552216 on guest (id=win7x646, ip=192.168.168.206)
2026-05-12 14:12:58,190 [cuckoo.core.guest] DEBUG: win7x646: not ready yet
2026-05-12 14:13:03,215 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x646, ip=192.168.168.206)
2026-05-12 14:13:03,292 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x646, ip=192.168.168.206, monitor=latest, size=6660546)
2026-05-12 14:13:04,619 [cuckoo.core.resultserver] DEBUG: Task #7552216: live log analysis.log initialized.
2026-05-12 14:13:05,564 [cuckoo.core.resultserver] DEBUG: Task #7552216 is sending a BSON stream
2026-05-12 14:13:05,861 [cuckoo.core.resultserver] DEBUG: Task #7552216 is sending a BSON stream
2026-05-12 14:13:06,791 [cuckoo.core.resultserver] DEBUG: Task #7552216: File upload for 'shots/0001.jpg'
2026-05-12 14:13:06,818 [cuckoo.core.resultserver] DEBUG: Task #7552216 uploaded file length: 133477
2026-05-12 14:13:19,232 [cuckoo.core.guest] DEBUG: win7x646: analysis #7552216 still processing
2026-05-12 14:13:34,314 [cuckoo.core.guest] DEBUG: win7x646: analysis #7552216 still processing
2026-05-12 14:13:35,200 [cuckoo.core.resultserver] DEBUG: Task #7552216: File upload for 'curtain/1778584415.19.curtain.log'
2026-05-12 14:13:35,203 [cuckoo.core.resultserver] DEBUG: Task #7552216 uploaded file length: 36
2026-05-12 14:13:35,310 [cuckoo.core.resultserver] DEBUG: Task #7552216: File upload for 'sysmon/1778584415.3.sysmon.xml'
2026-05-12 14:13:35,314 [cuckoo.core.resultserver] DEBUG: Task #7552216 uploaded file length: 148142
2026-05-12 14:13:35,673 [cuckoo.core.resultserver] DEBUG: Task #7552216 had connection reset for <Context for LOG>
2026-05-12 14:13:37,326 [cuckoo.core.guest] INFO: win7x646: analysis completed successfully
2026-05-12 14:13:37,337 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2026-05-12 14:13:37,366 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2026-05-12 14:13:38,267 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x646 to path /srv/cuckoo/cwd/storage/analyses/7552216/memory.dmp
2026-05-12 14:13:38,268 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x646
2026-05-12 14:13:45,872 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.206 for task #7552216
2026-05-12 14:13:46,228 [cuckoo.core.scheduler] DEBUG: Released database task #7552216
2026-05-12 14:13:46,245 [cuckoo.core.scheduler] INFO: Task #7552216: analysis procedure completed

Signatures

Yara rule detected for file (1 event)
description Run a keylogger rule keylogger
Allocates read-write-execute memory (usually to unpack itself) (23 events)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1524
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72a82000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1524
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72a82000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1524
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72a82000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x009d0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00aa0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00513000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00660000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00545000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0054b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00547000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0051d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0053a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00537000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 1310720
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x011c0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x012c0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0052d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00661000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 32768
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00662000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00536000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0066a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0053b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0066b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1524
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0066c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
Checks if process is being debugged by a debugger (2 events)
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available (1 event)
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
The binary likely contains encrypted or compressed data indicative of a packer (2 events)
section {u'size_of_data': u'0x000f4e00', u'virtual_address': u'0x00002000', u'entropy': 7.064783548776407, u'name': u'.text', u'virtual_size': u'0x000f4cd4'} entropy 7.06478354878 description A section with a high entropy has been found
entropy 0.918855534709 description Overall entropy of this PE file is high
File has been identified by 13 AntiVirus engine on IRMA as malicious (13 events)
G Data Antivirus (Windows) Virus: Trojan.Ransom.Loki.DBZ (Engine A), MSIL.Trojan-Spy.Snake.XMTIRX (Engine B)
Avast Core Security (Linux) Win32:MalwareX-gen [Pws]
C4S ClamAV (Linux) Sanesecurity.Rogue.0hr.20220510-1546.UNOFFICIAL
Trellix (Linux) GenericRXSW-EH
WithSecure (Linux) Trojan.TR/AD.SnakeStealer.mpbph
eScan Antivirus (Linux) Trojan.Ransom.Loki.DBZ(DB)
ESET Security (Windows) MSIL/Spy.Agent.AES trojan
Sophos Anti-Virus (Linux) Troj/Krypt-LX
DrWeb Antivirus (Linux) Trojan.PackedNET.331
ClamAV (Linux) Sanesecurity.Rogue.0hr.20220510-1546.UNOFFICIAL
Bitdefender Antivirus (Linux) Trojan.Ransom.Loki.DBZ
Kaspersky Standard (Windows) HEUR:Trojan.MSIL.Taskun.gen
Emsisoft Commandline Scanner (Windows) Trojan.Ransom.Loki.DBZ (B)
File has been identified by 61 AntiVirus engines on VirusTotal as malicious (50 out of 61 events)
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Loki.4!c
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
Skyhigh GenericRXSW-EH!411019BCB582
ALYac Trojan.Ransom.Loki.DBZ
Cylance Unsafe
Sangfor Spyware.Msil.Tnega.Vy2p
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.Ransom.Loki.DBZ
K7GW Trojan ( 00592bc01 )
K7AntiVirus Trojan ( 00592bc01 )
Arcabit Trojan.Ransom.Loki.DBZ
VirIT Trojan.Win32.MSIL.BUO
Symantec Trojan.Gen.MBT
Elastic malicious (high confidence)
ESET-NOD32 MSIL/Spy.Agent.AES trojan
Avast Win32:MalwareX-gen [Pws]
ClamAV Win.Dropper.LokiBot-10026309-0
Kaspersky HEUR:Trojan.MSIL.Taskun.gen
Alibaba Trojan:MSIL/Tnega.1403fd51
NANO-Antivirus Trojan.Win32.Taskun.jsflgf
SUPERAntiSpyware Trojan.Agent/GenericKDZ
MicroWorld-eScan Trojan.Ransom.Loki.DBZ
Rising Backdoor.Androm!8.113 (KTSE)
Emsisoft Trojan.Ransom.Loki.DBZ (B)
F-Secure Trojan.TR/AD.SnakeStealer.mpbph
DrWeb Trojan.PackedNET.331
VIPRE Trojan.Ransom.Loki.DBZ
TrendMicro TrojanSpy.MSIL.SNAKELOGGER.JPQ
McAfeeD ti!F381E3382120
Trapmine malicious.moderate.ml.score
CTX exe.trojan.msil
Sophos Troj/Krypt-LX
SentinelOne Static AI - Suspicious PE
Jiangmin Trojan.MSIL.amrha
Webroot W32.Trojan.Gen
Google Detected
Avira TR/AD.SnakeStealer.mpbph
Antiy-AVL Trojan/MSIL.Kryptik
Xcitium Malware@#1m1caykgusd8e
Microsoft Trojan:MSIL/Tnega.ST!MTB
ZoneAlarm Troj/Krypt-LX
GData MSIL.Trojan-Spy.Snake.XMTIRX
Varist W32/MSIL_Kryptik.HFI.gen!Eldorado
AhnLab-V3 Trojan/Win.Infostealer.R491212
VBA32 TScope.Trojan.MSIL
DeepInstinct MALICIOUS
Malwarebytes Neshta.Virus.FileInfector.DDS
Ikarus Trojan.MSIL.Crypt
Panda Trj/WLT.G
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.