File 21c78bf2a5e135c5f60409a9d196edf6531790196ccf1294e9073e622c57918

Size 728.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b918d3b0126e041f5dc691eee3356189
SHA1 6bd3a48ebbdac6f610c449fe2c2759fb4c5b265e
SHA256 21c78bf2a5e135c5f60409a9d196edf6531790196ccf1294e9073e622c579184
SHA512
0079163515c58fc56c6895e59cc820f18ef82e420aa2328edb56ffcdfc1f1e08a23a49a32be97d601af4c2c014f0f85ee37cddfd1cc235f5e7a42a34dd49c083
CRC32 73CB4C3D
ssdeep None
Yara
  • DebuggerException__SetConsoleCtrl - (no description)
  • screenshot - Take screenshot
  • keylogger - Run a keylogger
  • win_registry - Affect system registries
  • win_private_profile - Affect private profile
  • win_files_operation - Affect private profile
  • win_hook - Affect hook table

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Feb. 6, 2025, 6:42 a.m. Feb. 6, 2025, 6:52 a.m. 565 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-02-04 09:11:27,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpwoh6zt
2025-02-04 09:11:27,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\bfOgOJgXlCRUoavotzFfVj
2025-02-04 09:11:27,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\yCrAVuXnYsQKiJurIsWjBHJjWRlIM
2025-02-04 09:11:27,467 [analyzer] DEBUG: Started auxiliary module Curtain
2025-02-04 09:11:27,467 [analyzer] DEBUG: Started auxiliary module DbgView
2025-02-04 09:11:28,342 [analyzer] DEBUG: Started auxiliary module Disguise
2025-02-04 09:11:28,592 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-02-04 09:11:28,592 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-02-04 09:11:28,592 [analyzer] DEBUG: Started auxiliary module Human
2025-02-04 09:11:28,592 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-02-04 09:11:28,608 [analyzer] DEBUG: Started auxiliary module Reboot
2025-02-04 09:11:28,812 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-02-04 09:11:28,812 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-02-04 09:11:28,812 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-02-04 09:11:28,812 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-02-04 09:11:28,967 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\21c78bf2a5e135c5f60409a9d196edf6531790196ccf1294e9073e622c57918.exe' with arguments '' and pid 1032
2025-02-04 09:11:29,171 [analyzer] DEBUG: Loaded monitor into process with pid 1032
2025-02-04 09:11:57,967 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-02-04 09:11:58,203 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1032.
2025-02-04 09:11:58,717 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-02-04 09:11:58,717 [lib.api.process] INFO: Successfully terminated process with pid 1032.
2025-02-04 09:11:58,717 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-02-06 06:42:42,710 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:43,737 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:44,767 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:45,792 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:46,818 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:50,123 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:51,295 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:52,329 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:53,349 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:54,371 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:55,403 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:56,425 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:57,447 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:58,486 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:42:59,512 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:00,564 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:01,644 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:02,672 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:03,704 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:04,736 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:05,800 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:06,841 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:07,873 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:08,927 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:09,972 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:11,024 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:12,266 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:13,342 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:14,616 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:15,713 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:16,794 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:17,893 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:18,952 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:20,037 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:21,133 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:22,196 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:23,258 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:24,322 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:25,405 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:26,477 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:27,550 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:28,627 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:29,701 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:30,773 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:31,804 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:32,833 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:33,863 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:34,889 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:35,917 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:36,940 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:38,001 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:39,075 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:40,668 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:41,707 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:42,820 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:43,890 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:44,952 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:46,024 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:47,090 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:48,143 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:49,196 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:50,228 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:51,653 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:53,014 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:54,161 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:55,188 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:56,258 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:57,547 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:43:58,739 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:00,020 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:01,219 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:02,390 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:03,637 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:04,771 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:05,882 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:06,930 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:07,964 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:08,999 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:10,141 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:11,289 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:12,336 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:13,523 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:14,552 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:15,580 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:16,607 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:17,639 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:18,660 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:19,693 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:20,733 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:21,764 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:22,786 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:23,808 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:24,838 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:25,868 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:26,901 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:27,922 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:28,953 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:29,982 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:31,025 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:32,049 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:33,069 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:34,107 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:35,161 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:36,220 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:37,293 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:38,394 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:39,578 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:40,635 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:41,695 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:43,106 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:44,224 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:45,298 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:46,369 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:47,439 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:48,511 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:49,969 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:51,062 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:52,167 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:53,438 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:54,537 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:55,624 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:56,733 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:57,807 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:44:59,028 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:00,124 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:01,715 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:02,841 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:03,940 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:05,022 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:06,097 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:07,210 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:08,476 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:09,569 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:10,660 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:11,737 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:12,807 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:13,884 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:14,961 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:16,034 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:17,097 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:18,161 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:19,290 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:20,485 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:21,569 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:22,642 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:23,681 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:24,702 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:25,723 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:26,760 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:27,786 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:28,813 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:29,831 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:30,849 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:31,868 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:32,889 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:33,912 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:34,938 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:35,960 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:36,980 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:38,012 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:39,036 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:40,134 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:41,365 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:42,420 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:43,470 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:44,566 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:45,629 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:46,682 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:47,726 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:48,773 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:49,822 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:50,969 [cuckoo.core.scheduler] DEBUG: Task #5908043: no machine available yet
2025-02-06 06:45:52,040 [cuckoo.core.scheduler] INFO: Task #5908043: acquired machine win7x643 (label=win7x643)
2025-02-06 06:45:52,041 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.203 for task #5908043
2025-02-06 06:45:52,478 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1964610 (interface=vboxnet0, host=192.168.168.203)
2025-02-06 06:45:53,467 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x643
2025-02-06 06:45:54,231 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x643 to vmcloak
2025-02-06 06:48:02,993 [cuckoo.core.guest] INFO: Starting analysis #5908043 on guest (id=win7x643, ip=192.168.168.203)
2025-02-06 06:48:04,022 [cuckoo.core.guest] DEBUG: win7x643: not ready yet
2025-02-06 06:48:09,071 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x643, ip=192.168.168.203)
2025-02-06 06:48:09,177 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x643, ip=192.168.168.203, monitor=latest, size=6660546)
2025-02-06 06:48:11,274 [cuckoo.core.resultserver] DEBUG: Task #5908043: live log analysis.log initialized.
2025-02-06 06:48:12,842 [cuckoo.core.resultserver] DEBUG: Task #5908043 is sending a BSON stream
2025-02-06 06:48:13,396 [cuckoo.core.resultserver] DEBUG: Task #5908043 is sending a BSON stream
2025-02-06 06:48:14,262 [cuckoo.core.resultserver] DEBUG: Task #5908043: File upload for 'shots/0001.jpg'
2025-02-06 06:48:14,274 [cuckoo.core.resultserver] DEBUG: Task #5908043 uploaded file length: 133428
2025-02-06 06:48:25,496 [cuckoo.core.guest] DEBUG: win7x643: analysis #5908043 still processing
2025-02-06 06:48:40,753 [cuckoo.core.guest] DEBUG: win7x643: analysis #5908043 still processing
2025-02-06 06:48:42,681 [cuckoo.core.resultserver] DEBUG: Task #5908043: File upload for 'curtain/1738656718.36.curtain.log'
2025-02-06 06:48:42,703 [cuckoo.core.resultserver] DEBUG: Task #5908043 uploaded file length: 36
2025-02-06 06:48:43,011 [cuckoo.core.resultserver] DEBUG: Task #5908043: File upload for 'sysmon/1738656718.58.sysmon.xml'
2025-02-06 06:48:43,090 [cuckoo.core.resultserver] DEBUG: Task #5908043 uploaded file length: 1054008
2025-02-06 06:48:43,220 [cuckoo.core.resultserver] DEBUG: Task #5908043 had connection reset for <Context for LOG>
2025-02-06 06:48:43,794 [cuckoo.core.guest] INFO: win7x643: analysis completed successfully
2025-02-06 06:48:43,823 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-02-06 06:48:43,858 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-02-06 06:48:45,021 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x643 to path /srv/cuckoo/cwd/storage/analyses/5908043/memory.dmp
2025-02-06 06:48:45,028 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x643
2025-02-06 06:52:07,075 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.203 for task #5908043
2025-02-06 06:52:07,506 [cuckoo.core.scheduler] DEBUG: Released database task #5908043
2025-02-06 06:52:07,525 [cuckoo.core.scheduler] INFO: Task #5908043: analysis procedure completed

Signatures

Yara rules detected for file (7 events)
description (no description) rule DebuggerException__SetConsoleCtrl
description Take screenshot rule screenshot
description Run a keylogger rule keylogger
description Affect system registries rule win_registry
description Affect private profile rule win_private_profile
description Affect private profile rule win_files_operation
description Affect hook table rule win_hook
Allocates read-write-execute memory (usually to unpack itself) (4 events)
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 1032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00340000
allocation_type: 12289 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00350000
allocation_type: 12289 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1032
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x003e0000
allocation_type: 12289 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1032
region_size: 114688
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00540000
allocation_type: 4097 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
Queries for the computername (1 event)
Time & API Arguments Status Return Repeated

GetComputerNameA

computer_name: OYPUWMIKCDX
1 1 0
Uses Windows APIs to generate a cryptographic key (2 events)
Time & API Arguments Status Return Repeated

CryptGenKey

crypto_handle: 0x00737dd0
algorithm_identifier: 0x0000660e ()
flags: 1
key: fýòT³½Ë ¼~Aÿ
provider_handle: 0x00680988
1 1 0

CryptExportKey

buffer: f¤ïDz'6et/=,ÔºuŽáÌÛ¾p{Û[M;³ÙoðèOSy }G‘ËìžÌ@ªL¨º”Á)Ë-i^Õ¢¾LbN¨•]0g¨S¢Òå¿ò\ÞöÔn•êèÿ4]ý™
crypto_handle: 0x00737dd0
flags: 64
crypto_export_handle: 0x00680bd8
blob_type: 1
1 1 0
The executable contains unknown PE section names indicative of a packer (could be a false positive) (1 event)
section .didat
The file contains an unknown PE resource name possibly indicative of a packer (1 event)
resource name None
Foreign language identified in PE resource (4 events)
name RT_ICON language LANG_CHINESE filetype Device independent bitmap graphic, 16 x 32 x 4, image size 128 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000901f8 size 0x00000128
name RT_ICON language LANG_CHINESE filetype Device independent bitmap graphic, 16 x 32 x 4, image size 128 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000901f8 size 0x00000128
name RT_GROUP_ICON language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00090320 size 0x00000022
name None language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00090348 size 0x0001bb33
Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping (8 events)
Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time) (1 event)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1032
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 45056
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x00581000
process_handle: 0xffffffff
1 0 0
Checks adapter addresses which can be used to detect virtual network interfaces (1 event)
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 46
family: 0
1 0 0
Expresses interest in specific running processes (1 event)
process 21c78bf2a5e135c5f60409a9d196edf6531790196ccf1294e9073e622c57918.exe
Reads the systems User Agent and subsequently performs requests (1 event)
Time & API Arguments Status Return Repeated

InternetOpenW

proxy_name:
proxy_bypass:
flags: 0
user_agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
access_type: 0
1 13369348 0
Sets or modifies WPAD proxy autoconfiguration file for traffic interception (10 events)
Time & API Arguments Status Return Repeated

RegSetValueExW

key_handle: 0x000002f8
regkey_r: WpadDecisionReason
reg_type: 4 (REG_DWORD)
value: 1
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{092F0E6C-7874-4263-8D41-969F2B667EA2}\WpadDecisionReason
1 0 0

RegSetValueExW

key_handle: 0x000002f8
regkey_r: WpadDecisionTime
reg_type: 3 (REG_BINARY)
value: $¬ÐävÛ
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{092F0E6C-7874-4263-8D41-969F2B667EA2}\WpadDecisionTime
1 0 0

RegSetValueExW

key_handle: 0x000002f8
regkey_r: WpadDecision
reg_type: 4 (REG_DWORD)
value: 0
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{092F0E6C-7874-4263-8D41-969F2B667EA2}\WpadDecision
1 0 0

RegSetValueExW

key_handle: 0x000002f8
regkey_r: WpadNetworkName
reg_type: 1 (REG_SZ)
value: Network
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{092F0E6C-7874-4263-8D41-969F2B667EA2}\WpadNetworkName
1 0 0

RegSetValueExW

key_handle: 0x00000344
regkey_r: WpadDecisionReason
reg_type: 4 (REG_DWORD)
value: 1
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionReason
1 0 0

RegSetValueExW

key_handle: 0x00000344
regkey_r: WpadDecisionTime
reg_type: 3 (REG_BINARY)
value: $¬ÐävÛ
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionTime
1 0 0

RegSetValueExW

key_handle: 0x00000344
regkey_r: WpadDecision
reg_type: 4 (REG_DWORD)
value: 0
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecision
1 0 0

RegSetValueExW

key_handle: 0x00000344
regkey_r: WpadDecisionReason
reg_type: 4 (REG_DWORD)
value: 1
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionReason
1 0 0

RegSetValueExW

key_handle: 0x00000344
regkey_r: WpadDecisionTime
reg_type: 3 (REG_BINARY)
value: $¬ÐävÛ
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionTime
1 0 0

RegSetValueExW

key_handle: 0x00000344
regkey_r: WpadDecision
reg_type: 4 (REG_DWORD)
value: 0
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecision
1 0 0
File has been identified by 14 AntiVirus engine on IRMA as malicious (14 events)
G Data Antivirus (Windows) Virus: Trojan.Agent.EXRB (Engine A)
Avast Core Security (Linux) Win32:CrypterX-gen [Trj]
C4S ClamAV (Linux) Win.Malware.Emotet-9778573-0
F-Secure Antivirus (Linux) Trojan.TR/AD.Emotet.emt [Aquarius]
Sophos Anti-Virus (Linux) Troj/Emotet-CQO
eScan Antivirus (Linux) Trojan.Agent.EXRB(DB)
ESET Security (Windows) Win32/Emotet.CI trojan
McAfee CLI scanner (Linux) Emotet-FSF
DrWeb Antivirus (Linux) Trojan.DownLoader35.21714
Trend Micro SProtect (Linux) TrojanSpy.Win32.EMOTET.SMU.hp
ClamAV (Linux) Win.Malware.Emotet-9778573-0
Bitdefender Antivirus (Linux) Trojan.Agent.EXRB
Kaspersky Standard (Windows) UDS:Trojan-Banker.Win32.Emotet.gen
Emsisoft Commandline Scanner (Windows) Trojan.Emotet (A)
File has been identified by 66 AntiVirus engines on VirusTotal as malicious (50 out of 66 events)
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Cynet Malicious (score: 99)
Skyhigh Emotet-FSF!B918D3B0126E
ALYac Trojan.Agent.Emotet
Cylance Unsafe
VIPRE Trojan.Agent.EXRB
Sangfor Trojan.Win32.EmotetCrypt.SS
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.Agent.EXRB
K7GW Trojan ( 005605291 )
K7AntiVirus Trojan ( 005605291 )
Arcabit Trojan.Agent.EXRB
VirIT Trojan.Win32.Emotet.CMU
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Win32/Emotet.CI
APEX Malicious
Avast Win32:CrypterX-gen [Trj]
ClamAV Win.Malware.Emotet-9778573-0
Kaspersky HEUR:Trojan-Banker.Win32.Emotet.gen
Alibaba Trojan:Win32/EmotetCrypt.dfae99c9
NANO-Antivirus Trojan.Win32.Emotet.hzovsz
SUPERAntiSpyware Trojan.Agent/Gen-Emotet
MicroWorld-eScan Trojan.Agent.EXRB
Rising Trojan.Kryptik!1.CD18 (CLASSIC)
Emsisoft Trojan.Emotet (A)
F-Secure Trojan.TR/AD.Emotet.emt
DrWeb Trojan.DownLoader35.21714
Zillya Trojan.Emotet.Win32.43784
TrendMicro TrojanSpy.Win32.EMOTET.SMU.hp
McAfeeD ti!21C78BF2A5E1
Trapmine malicious.high.ml.score
CTX exe.trojan.emotet
Sophos Troj/Emotet-CQO
SentinelOne Static AI - Suspicious PE
FireEye Generic.mg.b918d3b0126e041f
Jiangmin Trojan.Banker.Emotet.oxh
Google Detected
Avira TR/AD.Emotet.emt
Antiy-AVL Trojan/Win32.Emotet
Kingsoft malware.kb.a.987
Gridinsoft Trojan.Win32.Emotet.oa!s1
Xcitium Malware@#3ux7q8n3zr97c
Microsoft Trojan:Win32/EmotetCrypt.SS!MTB
ViRobot Trojan.Win32.Emotet.745472.A
ZoneAlarm HEUR:Trojan-Banker.Win32.Emotet.gen
GData Trojan.Agent.EXRB
Varist W32/Emotet.AUY.gen!Eldorado
AhnLab-V3 Trojan/Win32.Emotet.C4206572
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.