Size | 1.9MB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 1103fb0f2c64e0a486782967457c200d |
SHA1 | daeb04c5e22834c408ef866fd6dad8a9841cb846 |
SHA256 | 962989261e135f16576fd017c73b4dcc8a079410c99f2921e3557667fa492d7f |
SHA512 |
15923197dab67d4ea4ff4731f1e4d703f6d8be54b399bcee0ccf4fb53231477e89417850e2eba36842caaa066004057dfbc755d9ec9def3ae4e52957eefc1724
|
CRC32 | 5362023A |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Feb. 4, 2025, 8:48 a.m. | Feb. 4, 2025, 8:56 a.m. | 499 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-02-02 12:40:09,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpqqrt4a 2025-02-02 12:40:09,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\jfDQzSOtLwOVKjsYiMn 2025-02-02 12:40:09,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\zEpYCJKGhZAwcVymcsru 2025-02-02 12:40:09,390 [analyzer] DEBUG: Started auxiliary module Curtain 2025-02-02 12:40:09,390 [analyzer] DEBUG: Started auxiliary module DbgView 2025-02-02 12:40:10,092 [analyzer] DEBUG: Started auxiliary module Disguise 2025-02-02 12:40:10,280 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-02-02 12:40:10,280 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-02-02 12:40:10,280 [analyzer] DEBUG: Started auxiliary module Human 2025-02-02 12:40:10,280 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-02-02 12:40:10,280 [analyzer] DEBUG: Started auxiliary module Reboot 2025-02-02 12:40:10,358 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-02-02 12:40:10,358 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-02-02 12:40:10,358 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-02-02 12:40:10,375 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-02-02 12:40:10,515 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\962989261e135f16576fd017c73b4dcc8a079410c99f2921e3557667fa492d7f.exe' with arguments '' and pid 2628 2025-02-02 12:40:10,687 [analyzer] DEBUG: Loaded monitor into process with pid 2628 2025-02-02 12:40:22,000 [analyzer] INFO: Injected into process with pid 552 and name '' 2025-02-02 12:40:22,171 [analyzer] DEBUG: Loaded monitor into process with pid 552 2025-02-02 12:40:34,483 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 552. 2025-02-02 12:40:34,515 [analyzer] INFO: Added new file to list with pid 2628 and path \Device\NamedPipe\lsass 2025-02-02 12:40:34,546 [analyzer] INFO: Process with pid 552 has terminated 2025-02-02 12:40:34,750 [analyzer] INFO: Injected into process with pid 2136 and name u'cmd.exe' 2025-02-02 12:40:34,842 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2628. 2025-02-02 12:40:35,000 [analyzer] DEBUG: Loaded monitor into process with pid 2136 2025-02-02 12:40:35,125 [analyzer] INFO: Injected into process with pid 2560 and name u'PING.EXE' 2025-02-02 12:40:35,312 [analyzer] DEBUG: Loaded monitor into process with pid 2560 2025-02-02 12:40:35,546 [analyzer] INFO: Process with pid 2628 has terminated 2025-02-02 12:40:39,546 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-02-02 12:40:39,780 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2136. 2025-02-02 12:40:39,875 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2560. 2025-02-02 12:40:40,140 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-02-02 12:40:40,140 [lib.api.process] INFO: Successfully terminated process with pid 2136. 2025-02-02 12:40:40,140 [lib.api.process] INFO: Successfully terminated process with pid 2560. 2025-02-02 12:40:40,140 [analyzer] WARNING: File at path u'\\device\\namedpipe\\lsass' does not exist, skip. 2025-02-02 12:40:40,140 [analyzer] INFO: Analysis completed.
2025-02-04 08:48:21,547 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:22,573 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:23,594 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:24,618 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:25,642 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:26,672 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:27,694 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:28,715 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:29,741 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:30,770 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:31,969 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:33,165 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:34,207 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:35,247 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:36,286 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:37,356 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:38,397 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:39,430 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:40,650 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:41,934 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:43,020 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:44,096 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:45,119 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:46,136 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:47,178 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:48,299 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:49,321 [cuckoo.core.scheduler] DEBUG: Task #5896030: no machine available yet 2025-02-04 08:48:50,354 [cuckoo.core.scheduler] INFO: Task #5896030: acquired machine win7x6428 (label=win7x6428) 2025-02-04 08:48:50,355 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.228 for task #5896030 2025-02-04 08:48:50,922 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1834429 (interface=vboxnet0, host=192.168.168.228) 2025-02-04 08:48:54,122 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6428 2025-02-04 08:48:55,816 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6428 to vmcloak 2025-02-04 08:52:16,952 [cuckoo.core.guest] INFO: Starting analysis #5896030 on guest (id=win7x6428, ip=192.168.168.228) 2025-02-04 08:52:17,974 [cuckoo.core.guest] DEBUG: win7x6428: not ready yet 2025-02-04 08:52:23,027 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6428, ip=192.168.168.228) 2025-02-04 08:52:23,401 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6428, ip=192.168.168.228, monitor=latest, size=6660546) 2025-02-04 08:52:25,954 [cuckoo.core.resultserver] DEBUG: Task #5896030: live log analysis.log initialized. 2025-02-04 08:52:27,198 [cuckoo.core.resultserver] DEBUG: Task #5896030 is sending a BSON stream 2025-02-04 08:52:27,543 [cuckoo.core.resultserver] DEBUG: Task #5896030 is sending a BSON stream 2025-02-04 08:52:29,392 [cuckoo.core.resultserver] DEBUG: Task #5896030: File upload for 'shots/0001.jpg' 2025-02-04 08:52:29,440 [cuckoo.core.resultserver] DEBUG: Task #5896030 uploaded file length: 133471 2025-02-04 08:52:39,039 [cuckoo.core.resultserver] DEBUG: Task #5896030 is sending a BSON stream 2025-02-04 08:52:41,249 [cuckoo.core.guest] DEBUG: win7x6428: analysis #5896030 still processing 2025-02-04 08:52:51,862 [cuckoo.core.resultserver] DEBUG: Task #5896030 is sending a BSON stream 2025-02-04 08:52:52,159 [cuckoo.core.resultserver] DEBUG: Task #5896030 is sending a BSON stream 2025-02-04 08:52:56,529 [cuckoo.core.guest] DEBUG: win7x6428: analysis #5896030 still processing 2025-02-04 08:52:56,915 [cuckoo.core.resultserver] DEBUG: Task #5896030: File upload for 'curtain/1738496439.97.curtain.log' 2025-02-04 08:52:56,919 [cuckoo.core.resultserver] DEBUG: Task #5896030 uploaded file length: 36 2025-02-04 08:52:57,080 [cuckoo.core.resultserver] DEBUG: Task #5896030: File upload for 'sysmon/1738496440.12.sysmon.xml' 2025-02-04 08:52:57,094 [cuckoo.core.resultserver] DEBUG: Task #5896030 uploaded file length: 737834 2025-02-04 08:52:57,151 [cuckoo.core.resultserver] DEBUG: Task #5896030 had connection reset for <Context for LOG> 2025-02-04 08:52:59,561 [cuckoo.core.guest] INFO: win7x6428: analysis completed successfully 2025-02-04 08:52:59,581 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-02-04 08:52:59,663 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-02-04 08:53:00,847 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6428 to path /srv/cuckoo/cwd/storage/analyses/5896030/memory.dmp 2025-02-04 08:53:00,848 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6428 2025-02-04 08:56:40,355 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.228 for task #5896030 2025-02-04 08:56:41,160 [cuckoo.core.scheduler] DEBUG: Released database task #5896030 2025-02-04 08:56:41,180 [cuckoo.core.scheduler] INFO: Task #5896030: analysis procedure completed
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Take screenshot | rule | screenshot | ||||||
description | Run a keylogger | rule | keylogger | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect hook table | rule | win_hook |
cmdline | cmd.exe /c ping.exe -n 6 127.0.0.1 & type "C:\Windows\System32\calc.exe" > "C:\Users\Administrator\AppData\Local\Temp\962989261e135f16576fd017c73b4dcc8a079410c99f2921e3557667fa492d7f.exe" |
cmdline | "C:\Windows\System32\cmd.exe" /c ping.exe -n 6 127.0.0.1 & type "C:\Windows\System32\calc.exe" > "C:\Users\Administrator\AppData\Local\Temp\962989261e135f16576fd017c73b4dcc8a079410c99f2921e3557667fa492d7f.exe" |
section | {u'size_of_data': u'0x00056a00', u'virtual_address': u'0x00001000', u'entropy': 7.266393285552794, u'name': u'.text', u'virtual_size': u'0x00056965'} | entropy | 7.26639328555 | description | A section with a high entropy has been found |
cmdline | ping.exe -n 6 127.0.0.1 |
cmdline | cmd.exe /c ping.exe -n 6 127.0.0.1 & type "C:\Windows\System32\calc.exe" > "C:\Users\Administrator\AppData\Local\Temp\962989261e135f16576fd017c73b4dcc8a079410c99f2921e3557667fa492d7f.exe" |
cmdline | "C:\Windows\System32\cmd.exe" /c ping.exe -n 6 127.0.0.1 & type "C:\Windows\System32\calc.exe" > "C:\Users\Administrator\AppData\Local\Temp\962989261e135f16576fd017c73b4dcc8a079410c99f2921e3557667fa492d7f.exe" |
G Data Antivirus (Windows) | Virus: Gen:Variant.Ransom.Avaddon.57 (Engine A) |
Avast Core Security (Linux) | Win32:BankerX-gen [Trj] |
C4S ClamAV (Linux) | Win.Ransomware.Avaddon-10036887-0 |
F-Secure Antivirus (Linux) | Heuristic.HEUR/AGEN.1344382 [Aquarius] |
Sophos Anti-Virus (Linux) | Mal/EncPk-APV |
eScan Antivirus (Linux) | Gen:Variant.Ransom.Avaddon.57(DB) |
ESET Security (Windows) | a variant of Win32/Kryptik.HHNE trojan |
McAfee CLI scanner (Linux) | W32/PinkSbot-HG |
DrWeb Antivirus (Linux) | Trojan.Inject4.26829 |
ClamAV (Linux) | Win.Ransomware.Avaddon-10036887-0 |
Bitdefender Antivirus (Linux) | Gen:Variant.Ransom.Avaddon.57 |
Kaspersky Standard (Windows) | UDS:Trojan.Win32.Qshell.luu |
Emsisoft Commandline Scanner (Windows) | Gen:Variant.Ransom.Avaddon.57 (B) |
Bkav | W32.AIDetect.malware2 |
Lionic | Hacktool.Win32.Krap.lKMc |
Elastic | malicious (high confidence) |
ALYac | Gen:Variant.Razy.788722 |
Cylance | Unsafe |
Zillya | Trojan.Kryptik.Win32.3706197 |
Paloalto | generic.ml |
Sangfor | Trojan.Win32.Save.a |
K7AntiVirus | Trojan ( 0057342c1 ) |
BitDefender | Gen:Variant.Razy.788722 |
K7GW | Trojan ( 0057342c1 ) |
Cybereason | malicious.f2c64e |
Cyren | W32/Qbot.AL.gen!Eldorado |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/Kryptik.HHNE |
APEX | Malicious |
Avast | Win32:BankerX-gen [Trj] |
Cynet | Malicious (score: 100) |
Kaspersky | Trojan.Win32.Qshell.luu |
Alibaba | Trojan:Win32/Qshell.1bc1d788 |
NANO-Antivirus | Trojan.Win32.Qbot.icdqbb |
MicroWorld-eScan | Gen:Variant.Razy.788722 |
Rising | Trojan.Kryptik!1.CF1B (CLOUD) |
Ad-Aware | Gen:Variant.Razy.788722 |
Emsisoft | Gen:Variant.Razy.788722 (B) |
DrWeb | Trojan.Inject4.26829 |
BitDefenderTheta | Gen:NN.ZexaF.34638.6nX@aaiUwmi |
TrendMicro | TrojanSpy.Win32.QAKBOT.YXCCAZ |
McAfee-GW-Edition | W32/PinkSbot-HG!1103FB0F2C64 |
FireEye | Generic.mg.1103fb0f2c64e0a4 |
Sophos | Mal/Generic-S + Mal/EncPk-APV |
Ikarus | Trojan.Win32.Qakbot |
Jiangmin | Trojan.Banker.Qbot.ve |
Avira | HEUR/AGEN.1223588 |
MAX | malware (ai score=81) |
Microsoft | Trojan:Win32/Qakbot.GR!MTB |
ViRobot | Trojan.Win32.Z.Razy.1999952.B |
GData | Gen:Variant.Razy.788722 |
AhnLab-V3 | Trojan/Win32.RL_Generic.R358876 |
McAfee | W32/PinkSbot-HG!1103FB0F2C64 |
VBA32 | BScope.Trojan.Encoder |
Malwarebytes | MachineLearning/Anomalous.100% |
TrendMicro-HouseCall | TrojanSpy.Win32.QAKBOT.YXCCAZ |
Tencent | Malware.Win32.Gencirc.10d029c1 |
Yandex | Trojan.Qshell!8ajZJp7jcJQ |
SentinelOne | Static AI - Malicious PE |
MaxSecure | Trojan.Malware.121218.susgen |
Fortinet | W32/Kryptik.HJJV!tr |
AVG | Win32:BankerX-gen [Trj] |
Panda | Trj/Genetic.gen |