Size | 1.5MB |
---|---|
Type | PE32 executable (DLL) (console) Intel 80386, for MS Windows |
MD5 | 1e586ea1d4544d3429ca0c49b33ff67e |
SHA1 | 4c96d2bce0e12f8591999d4e00498bcdb8a116de |
SHA256 | 80eb5b91bdeeaea456de77e716942bc666ed4c152f5274c4317cd6740dcda8e8 |
SHA512 |
8c41bbb50243f3ede95b1bd906b48ceb6faa1dc34dc3076c7744317a0d70616066d83bd1e94dd27028db4edeaae87ed6c7288ea849262ce517fa0d2940826d2f
|
CRC32 | 64058097 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Feb. 4, 2025, 9:04 a.m. | Feb. 4, 2025, 9:10 a.m. | 362 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-02-02 12:40:12,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpzepe2z 2025-02-02 12:40:12,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\oAoFwGjNjedLyIcRnUgyvUtbsjj 2025-02-02 12:40:12,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\ObsXTptOuddaAsCTQOinzRpSBGvE 2025-02-02 12:40:12,421 [analyzer] DEBUG: Started auxiliary module Curtain 2025-02-02 12:40:12,421 [analyzer] DEBUG: Started auxiliary module DbgView 2025-02-02 12:40:12,905 [analyzer] DEBUG: Started auxiliary module Disguise 2025-02-02 12:40:13,125 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-02-02 12:40:13,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-02-02 12:40:13,125 [analyzer] DEBUG: Started auxiliary module Human 2025-02-02 12:40:13,125 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-02-02 12:40:13,125 [analyzer] DEBUG: Started auxiliary module Reboot 2025-02-02 12:40:13,203 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-02-02 12:40:13,203 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-02-02 12:40:13,203 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-02-02 12:40:13,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-02-02 12:40:13,280 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\80eb5b91bdeeaea456de77e716942bc666ed4c152f5274c4317cd6740dcda8e8.exe' with arguments ['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\80eb5b91bdeeaea456de77e716942bc666ed4c152f5274c4317cd6740dcda8e8.exe', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\80eb5b91bdeeaea456de77e716942bc666ed4c152f5274c4317cd6740dcda8e8.exe', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
2025-02-04 09:04:02,331 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:03,355 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:04,599 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:05,759 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:06,817 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:07,876 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:09,014 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:10,078 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:11,173 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:12,247 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:13,341 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:14,448 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:15,730 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:16,821 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:17,897 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:19,132 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:20,282 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:21,376 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:22,672 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:23,815 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:24,891 [cuckoo.core.scheduler] DEBUG: Task #5896095: no machine available yet 2025-02-04 09:04:26,106 [cuckoo.core.scheduler] INFO: Task #5896095: acquired machine win7x6417 (label=win7x6417) 2025-02-04 09:04:26,119 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.217 for task #5896095 2025-02-04 09:04:26,545 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1858022 (interface=vboxnet0, host=192.168.168.217) 2025-02-04 09:04:33,364 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6417 2025-02-04 09:04:34,611 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6417 to vmcloak 2025-02-04 09:07:31,332 [cuckoo.core.guest] INFO: Starting analysis #5896095 on guest (id=win7x6417, ip=192.168.168.217) 2025-02-04 09:07:32,340 [cuckoo.core.guest] DEBUG: win7x6417: not ready yet 2025-02-04 09:07:37,370 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6417, ip=192.168.168.217) 2025-02-04 09:07:37,514 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6417, ip=192.168.168.217, monitor=latest, size=6660546) 2025-02-04 09:07:38,979 [cuckoo.core.resultserver] DEBUG: Task #5896095: live log analysis.log initialized. 2025-02-04 09:07:40,047 [cuckoo.core.resultserver] DEBUG: Task #5896095 is sending a BSON stream 2025-02-04 09:07:41,310 [cuckoo.core.resultserver] DEBUG: Task #5896095: File upload for 'shots/0001.jpg' 2025-02-04 09:07:41,659 [cuckoo.core.resultserver] DEBUG: Task #5896095 uploaded file length: 133471 2025-02-04 09:07:41,727 [cuckoo.core.guest] WARNING: win7x6417: analysis #5896095 caught an exception Traceback (most recent call last): File "C:/tmpzepe2z/analyzer.py", line 824, in <module> success = analyzer.run() File "C:/tmpzepe2z/analyzer.py", line 673, in run pids = self.package.start(self.target) File "C:\tmpzepe2z\modules\packages\exe.py", line 34, in start return self.execute(path, args=shlex.split(args)) File "C:\tmpzepe2z\lib\common\abstracts.py", line 205, in execute "Unable to execute the initial process, analysis aborted." CuckooPackageError: Unable to execute the initial process, analysis aborted. 2025-02-04 09:07:41,792 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-02-04 09:07:41,833 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-02-04 09:07:43,191 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6417 to path /srv/cuckoo/cwd/storage/analyses/5896095/memory.dmp 2025-02-04 09:07:43,194 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6417 2025-02-04 09:10:00,822 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.217 for task #5896095 2025-02-04 09:10:00,825 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 5896095 2025-02-04 09:10:04,359 [cuckoo.core.scheduler] DEBUG: Released database task #5896095 2025-02-04 09:10:04,452 [cuckoo.core.scheduler] INFO: Task #5896095: analysis procedure completed
description | (no description) | rule | GenerateTLSClientHelloPacket_Test | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Communications over UDP network | rule | network_udp_sock | ||||||
description | Listen for incoming communication | rule | network_tcp_listen | ||||||
description | Communications smtp | rule | network_smtp_raw | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Communications use DNS | rule | network_dns | ||||||
description | Create or check mutex | rule | win_mutex | ||||||
description | Affect private profile | rule | win_files_operation |
G Data Antivirus (Windows) | Virus: Gen:Variant.Doina.62815 (Engine A) |
F-Secure Antivirus (Linux) | Trojan.TR/Proxy.bthor [Aquarius] |
Sophos Anti-Virus (Linux) | Mal/Generic-S |
eScan Antivirus (Linux) | Gen:Variant.Doina.62815(DB) |
ESET Security (Windows) | a variant of Win32/TrojanProxy.Agent.OBC trojan |
McAfee CLI scanner (Linux) | Trojan-FRNX |
DrWeb Antivirus (Linux) | BackDoor.Qbot.542 |
Bitdefender Antivirus (Linux) | Gen:Variant.Doina.62815 |
Kaspersky Standard (Windows) | HEUR:Trojan.Win32.Generic |
Emsisoft Commandline Scanner (Windows) | Gen:Variant.Doina.62815 (B) |
Lionic | Trojan.Win32.Qbot.11!c |
Cynet | Malicious (score: 99) |
CAT-QuickHeal | Trojan.Ghanarava.17276019333ff67e |
Skyhigh | Trojan-FRNX!1E586EA1D454 |
ALYac | Trojan.Proxy.Agent |
Cylance | Unsafe |
VIPRE | Gen:Variant.Doina.62815 |
Sangfor | Hacktool.Win32.Qbot.Vh34 |
CrowdStrike | win/malicious_confidence_100% (W) |
BitDefender | Gen:Variant.Doina.62815 |
K7GW | Proxy-Program ( 00516d9d1 ) |
K7AntiVirus | Proxy-Program ( 00516d9d1 ) |
Arcabit | Trojan.Doina.DF55F |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/TrojanProxy.Agent.OBC |
Avast | Win32:Trojan-gen |
Kaspersky | Trojan-Proxy.Win32.Qbot.a |
Alibaba | Trojan:Win32/Proxy.5ce9a4f2 |
NANO-Antivirus | Trojan.Win32.Mlw.fzipav |
MicroWorld-eScan | Gen:Variant.Doina.62815 |
Rising | Trojan.Masson!8.11118 (TFE:6:qnvK73MJ91J) |
Emsisoft | Gen:Variant.Doina.62815 (B) |
F-Secure | Trojan.TR/Proxy.bthor |
DrWeb | BackDoor.Qbot.542 |
Zillya | Trojan.Agent.Win32.1134052 |
McAfeeD | ti!80EB5B91BDEE |
CTX | dll.trojan.proxy |
Sophos | Mal/Generic-S |
FireEye | Gen:Variant.Doina.62815 |
Detected | |
Avira | TR/Proxy.bthor |
Antiy-AVL | Trojan[Proxy]/Win32.Agent |
Xcitium | Malware@#2k9yr88ac3g8i |
Microsoft | Trojan:Win32/QBot!MSR |
ViRobot | Trojan.Win32.S.Agent.1530880.L |
GData | Gen:Variant.Doina.62815 |
Varist | W32/Agent.DYW.gen!Eldorado |
AhnLab-V3 | Backdoor/Win32.QBot.C2284413 |
McAfee | Trojan-FRNX!1E586EA1D454 |
TACHYON | Backdoor/W32.QBot.1530880 |
DeepInstinct | MALICIOUS |
VBA32 | TrojanProxy.Qbot |
Malwarebytes | Proxy.Trojan.Agent.DDS |
Ikarus | Trojan-Proxy.Agent |
Panda | Trj/GdSda.A |
Tencent | Malware.Win32.Gencirc.13b3f6ca |
Yandex | Trojan.GenAsa!RDmrw5NIooA |
huorong | Trojan/Generic!3ADBB7CA97758DA0 |
MaxSecure | Trojan.Malware.74514755.susgen |