Size | 419.1MB |
---|---|
Type | Zip archive data, at least v1.0 to extract, compression method=store |
MD5 | 8c6263bc7dca4e4f1390e06913b84574 |
SHA1 | 2f8930ec7f4371f18c531eeaa81ec72066b0d516 |
SHA256 | fe6285f3bc4fd69bcaa90b5fe58e9e93a8946f7384771c1ddc1137f81ac82ad0 |
SHA512 |
2d356bdc76884abe21e360db18e2773c95c60500e2681c01fdcdb7a0a28f5d8c07c8f2653888290b653aab35597c8f7dbcb7ab4aabdc1c7494a507cd34733ccb
|
CRC32 | 5C965F1C |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | March 1, 2025, 1:27 a.m. | March 1, 2025, 1:29 a.m. | 97 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-03-01 00:27:38,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpwoh6zt 2025-03-01 00:27:38,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\VilYJAGgEgrHXhlAFkLTYwlqeRmELsD 2025-03-01 00:27:38,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\CIjyQAhgfTtIwOHId 2025-03-01 00:27:38,280 [analyzer] DEBUG: Started auxiliary module Curtain 2025-03-01 00:27:38,280 [analyzer] DEBUG: Started auxiliary module DbgView 2025-03-01 00:27:38,671 [analyzer] DEBUG: Started auxiliary module Disguise 2025-03-01 00:27:38,842 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-03-01 00:27:38,842 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-03-01 00:27:38,842 [analyzer] DEBUG: Started auxiliary module Human 2025-03-01 00:27:38,842 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-03-01 00:27:38,842 [analyzer] DEBUG: Started auxiliary module Reboot 2025-03-01 00:27:38,905 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-03-01 00:27:38,905 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-03-01 00:27:38,905 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-03-01 00:27:38,905 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-03-01 00:27:39,062 [lib.api.process] INFO: Successfully executed process from path 'bin/7za.exe' with arguments ['x', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\Disk2.zip', '-pinfected'] and pid 1688 2025-03-01 00:29:02,848 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\ose00000.exe' with arguments '' and pid 2628 2025-03-01 00:29:03,066 [analyzer] DEBUG: Loaded monitor into process with pid 2628 2025-03-01 00:29:03,207 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2628. 2025-03-01 00:29:03,848 [analyzer] INFO: Process with pid 2628 has terminated 2025-03-01 00:29:03,848 [analyzer] INFO: Process list is empty, terminating analysis. 2025-03-01 00:29:05,130 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-03-01 00:29:05,130 [analyzer] INFO: Analysis completed.
2025-03-01 01:27:49,369 [cuckoo.core.scheduler] INFO: Task #6030080: acquired machine win7x643 (label=win7x643) 2025-03-01 01:27:49,370 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.203 for task #6030080 2025-03-01 01:27:49,763 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 124769 (interface=vboxnet0, host=192.168.168.203) 2025-03-01 01:27:50,912 [androguard.apk] WARNING: Missing AndroidManifest.xml. Is this an APK file? 2025-03-01 01:27:50,970 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x643 2025-03-01 01:27:51,629 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x643 to vmcloak 2025-03-01 01:28:08,223 [cuckoo.core.guest] INFO: Starting analysis #6030080 on guest (id=win7x643, ip=192.168.168.203) 2025-03-01 01:28:11,035 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x643, ip=192.168.168.203) 2025-03-01 01:28:13,709 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x643, ip=192.168.168.203, monitor=latest, size=6660546) 2025-03-01 01:28:31,498 [cuckoo.core.resultserver] DEBUG: Task #6030080: live log analysis.log initialized. 2025-03-01 01:28:33,746 [cuckoo.core.resultserver] DEBUG: Task #6030080 is sending a BSON stream 2025-03-01 01:28:33,751 [cuckoo.core.resultserver] DEBUG: Task #6030080: File upload for 'shots/0001.jpg' 2025-03-01 01:28:33,776 [cuckoo.core.resultserver] DEBUG: Task #6030080 uploaded file length: 130854 2025-03-01 01:28:34,875 [cuckoo.core.resultserver] DEBUG: Task #6030080: File upload for 'shots/0002.jpg' 2025-03-01 01:28:34,889 [cuckoo.core.resultserver] DEBUG: Task #6030080 uploaded file length: 131812 2025-03-01 01:28:36,024 [cuckoo.core.resultserver] DEBUG: Task #6030080: File upload for 'shots/0003.jpg' 2025-03-01 01:28:36,034 [cuckoo.core.resultserver] DEBUG: Task #6030080 uploaded file length: 130976 2025-03-01 01:28:46,105 [cuckoo.core.guest] DEBUG: win7x643: analysis #6030080 still processing 2025-03-01 01:28:46,414 [cuckoo.core.resultserver] DEBUG: Task #6030080: File upload for 'shots/0004.jpg' 2025-03-01 01:28:46,425 [cuckoo.core.resultserver] DEBUG: Task #6030080 uploaded file length: 133666 2025-03-01 01:29:01,189 [cuckoo.core.guest] DEBUG: win7x643: analysis #6030080 still processing 2025-03-01 01:29:02,952 [cuckoo.core.resultserver] DEBUG: Task #6030080 is sending a BSON stream 2025-03-01 01:29:05,016 [cuckoo.core.resultserver] DEBUG: Task #6030080: File upload for 'curtain/1740785345.01.curtain.log' 2025-03-01 01:29:05,020 [cuckoo.core.resultserver] DEBUG: Task #6030080 uploaded file length: 36 2025-03-01 01:29:05,142 [cuckoo.core.resultserver] DEBUG: Task #6030080: File upload for 'sysmon/1740785345.13.sysmon.xml' 2025-03-01 01:29:05,147 [cuckoo.core.resultserver] DEBUG: Task #6030080 uploaded file length: 116172 2025-03-01 01:29:06,066 [cuckoo.core.resultserver] DEBUG: Task #6030080 had connection reset for <Context for LOG> 2025-03-01 01:29:07,241 [cuckoo.core.guest] INFO: win7x643: analysis completed successfully 2025-03-01 01:29:07,254 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-03-01 01:29:07,279 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-03-01 01:29:08,432 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x643 to path /srv/cuckoo/cwd/storage/analyses/6030080/memory.dmp 2025-03-01 01:29:08,434 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x643 2025-03-01 01:29:16,508 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.203 for task #6030080 2025-03-01 01:29:16,823 [cuckoo.core.scheduler] DEBUG: Released database task #6030080 2025-03-01 01:29:16,844 [cuckoo.core.scheduler] INFO: Task #6030080: analysis procedure completed
No signatures