Size | 83.1KB |
---|---|
Type | PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
MD5 | aba191b844cd3c33f0943858d5e6a356 |
SHA1 | b49cdca4afc116f96839a846439b2de14c0f6eef |
SHA256 | 3b2d94c9d490d015f33585360ba59b32336055ee23ea3c39bbe3cbdb9dd6de8e |
SHA512 |
d15eb96f28ef4a2d289e513953468b209eef2301e587b058b90883c146c2414a461c869828300e4afab08748a70db58dcfd2fd77c1ce7ef28cb0dda00e00f809
|
CRC32 | 469ED496 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Jan. 17, 2025, 7:37 p.m. | Jan. 17, 2025, 7:45 p.m. | 463 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-01-13 08:14:12,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd 2025-01-13 08:14:12,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\WTpNgexPfitXwnEAckhMMWwAIh 2025-01-13 08:14:12,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\TLeHKOclwojXHcnELcDXnODWy 2025-01-13 08:14:12,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-01-13 08:14:12,030 [analyzer] INFO: Automatically selected analysis package "exe" 2025-01-13 08:14:12,265 [analyzer] DEBUG: Started auxiliary module Curtain 2025-01-13 08:14:12,265 [analyzer] DEBUG: Started auxiliary module DbgView 2025-01-13 08:14:12,717 [analyzer] DEBUG: Started auxiliary module Disguise 2025-01-13 08:14:12,937 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-01-13 08:14:12,937 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-01-13 08:14:12,937 [analyzer] DEBUG: Started auxiliary module Human 2025-01-13 08:14:12,937 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-01-13 08:14:12,937 [analyzer] DEBUG: Started auxiliary module Reboot 2025-01-13 08:14:13,030 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-01-13 08:14:13,030 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-01-13 08:14:13,030 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-01-13 08:14:13,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-01-13 08:14:13,171 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\3b2d94c9d490d015_rifaien2-6GaomstaRV2SNTZY.exe' with arguments '' and pid 2132 2025-01-13 08:14:13,375 [analyzer] DEBUG: Loaded monitor into process with pid 2132 2025-01-13 08:14:13,390 [analyzer] INFO: Added new file to list with pid 2132 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-qC5nlAMbp0JxtgA1.exe 2025-01-13 08:14:43,592 [analyzer] INFO: Added new file to list with pid 2132 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-1CYCHqQrJ48sLwOO.exe 2025-01-13 08:15:13,828 [analyzer] INFO: Added new file to list with pid 2132 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-kjCtbU46Dvz9gDN2.exe 2025-01-13 08:15:44,000 [analyzer] INFO: Added new file to list with pid 2132 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-Q4gzucvshGsSZNXm.exe 2025-01-13 08:16:14,203 [analyzer] INFO: Added new file to list with pid 2132 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-sST8eq5hT6IomTjh.exe 2025-01-13 08:16:44,405 [analyzer] INFO: Added new file to list with pid 2132 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-pmrt2dErptqZuL7c.exe 2025-01-13 08:17:14,578 [analyzer] INFO: Added new file to list with pid 2132 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-u2I7CLP3b79Z4IGw.exe 2025-01-13 08:17:32,171 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-01-13 08:17:33,328 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-01-13 08:17:33,328 [lib.api.process] INFO: Successfully terminated process with pid 2132. 2025-01-13 08:17:33,328 [analyzer] INFO: Analysis completed.
2025-01-17 19:37:33,956 [cuckoo.core.scheduler] INFO: Task #5771570: acquired machine win7x6412 (label=win7x6412) 2025-01-17 19:37:33,956 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.212 for task #5771570 2025-01-17 19:37:34,323 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1150844 (interface=vboxnet0, host=192.168.168.212) 2025-01-17 19:37:34,451 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6412 2025-01-17 19:37:35,099 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6412 to vmcloak 2025-01-17 19:40:08,937 [cuckoo.core.guest] INFO: Starting analysis #5771570 on guest (id=win7x6412, ip=192.168.168.212) 2025-01-17 19:40:09,942 [cuckoo.core.guest] DEBUG: win7x6412: not ready yet 2025-01-17 19:40:14,969 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6412, ip=192.168.168.212) 2025-01-17 19:40:15,068 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6412, ip=192.168.168.212, monitor=latest, size=6660546) 2025-01-17 19:40:16,145 [cuckoo.core.resultserver] DEBUG: Task #5771570: live log analysis.log initialized. 2025-01-17 19:40:17,022 [cuckoo.core.resultserver] DEBUG: Task #5771570 is sending a BSON stream 2025-01-17 19:40:17,444 [cuckoo.core.resultserver] DEBUG: Task #5771570 is sending a BSON stream 2025-01-17 19:40:17,742 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'files/cb79e77db6507f07_rifaien2-qC5nlAMbp0JxtgA1.exe' 2025-01-17 19:40:17,746 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 85069 2025-01-17 19:40:18,284 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'shots/0001.jpg' 2025-01-17 19:40:18,303 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 155393 2025-01-17 19:40:30,903 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:40:46,059 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:40:47,860 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'shots/0002.jpg' 2025-01-17 19:40:47,873 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 152506 2025-01-17 19:40:47,985 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'files/6ff0c617b6bf8056_rifaien2-1CYCHqQrJ48sLwOO.exe' 2025-01-17 19:40:47,989 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 85069 2025-01-17 19:40:49,052 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'shots/0003.jpg' 2025-01-17 19:40:49,084 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 155862 2025-01-17 19:41:01,352 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:41:16,532 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:41:18,154 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'files/d165f7f97712a20a_rifaien2-kjCtbU46Dvz9gDN2.exe' 2025-01-17 19:41:18,157 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 85069 2025-01-17 19:41:18,857 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'shots/0004.jpg' 2025-01-17 19:41:18,872 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 155978 2025-01-17 19:41:31,713 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:41:46,954 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:41:48,435 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'files/e59e5d7da06963b2_rifaien2-Q4gzucvshGsSZNXm.exe' 2025-01-17 19:41:48,440 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 85069 2025-01-17 19:41:48,625 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'shots/0005.jpg' 2025-01-17 19:41:48,639 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 155479 2025-01-17 19:42:02,149 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:42:17,347 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:42:18,567 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'files/b97f2d44c92f26ee_rifaien2-sST8eq5hT6IomTjh.exe' 2025-01-17 19:42:18,572 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 85069 2025-01-17 19:42:19,278 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'shots/0006.jpg' 2025-01-17 19:42:19,292 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 155523 2025-01-17 19:42:32,463 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:42:47,702 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:42:48,728 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'files/443df4d3019d0235_rifaien2-pmrt2dErptqZuL7c.exe' 2025-01-17 19:42:48,731 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 85069 2025-01-17 19:42:48,874 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'shots/0007.jpg' 2025-01-17 19:42:48,894 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 155783 2025-01-17 19:43:02,975 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:43:18,301 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:43:18,891 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'files/33f9fd2d3defb8c0_rifaien2-u2I7CLP3b79Z4IGw.exe' 2025-01-17 19:43:18,898 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 85069 2025-01-17 19:43:19,466 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'shots/0008.jpg' 2025-01-17 19:43:19,480 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 155711 2025-01-17 19:43:33,392 [cuckoo.core.guest] DEBUG: win7x6412: analysis #5771570 still processing 2025-01-17 19:43:36,510 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'curtain/1736752652.34.curtain.log' 2025-01-17 19:43:36,542 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 36 2025-01-17 19:43:37,385 [cuckoo.core.resultserver] DEBUG: Task #5771570: File upload for 'sysmon/1736752653.23.sysmon.xml' 2025-01-17 19:43:37,615 [cuckoo.core.resultserver] DEBUG: Task #5771570 uploaded file length: 13695238 2025-01-17 19:43:37,631 [cuckoo.core.resultserver] DEBUG: Task #5771570 had connection reset for <Context for LOG> 2025-01-17 19:43:39,425 [cuckoo.core.guest] INFO: win7x6412: analysis completed successfully 2025-01-17 19:43:39,437 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-01-17 19:43:39,465 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-01-17 19:43:40,337 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6412 to path /srv/cuckoo/cwd/storage/analyses/5771570/memory.dmp 2025-01-17 19:43:40,339 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6412 2025-01-17 19:45:16,135 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.212 for task #5771570 2025-01-17 19:45:16,920 [cuckoo.core.scheduler] DEBUG: Released database task #5771570 2025-01-17 19:45:16,975 [cuckoo.core.scheduler] INFO: Task #5771570: analysis procedure completed
description | (no description) | rule | UPX | ||||||
description | The packer/protector section names/keywords | rule | suspicious_packer_section | ||||||
description | Communications over RAW socket | rule | network_tcp_socket |
packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
description | 3b2d94c9d490d015_rifaien2-6GaomstaRV2SNTZY.exe tried to sleep 210 seconds, actually delayed analysis time by 180 seconds |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-1CYCHqQrJ48sLwOO.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-kjCtbU46Dvz9gDN2.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-sST8eq5hT6IomTjh.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-Q4gzucvshGsSZNXm.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-qC5nlAMbp0JxtgA1.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-pmrt2dErptqZuL7c.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-u2I7CLP3b79Z4IGw.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-qC5nlAMbp0JxtgA1.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-1CYCHqQrJ48sLwOO.exe |
section | {u'size_of_data': u'0x00014800', u'virtual_address': u'0x00014000', u'entropy': 7.7110687744535955, u'name': u'UPX1', u'virtual_size': u'0x00015000'} | entropy | 7.71106877445 | description | A section with a high entropy has been found | |||||||||
entropy | 0.993939393939 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX | ||||||
section | UPX2 | description | Section name indicates UPX |
buffer | Buffer with sha1: 97653fe98384b5bef285a95b60548b73adae825a |
suricata | ETPRO MALWARE Win32/Snojan Variant Uploading EXE |
suricata | ET INFO Generic HTTP EXE Upload Outbound |
G Data Antivirus (Windows) | Virus: Trojan.Agent.CYZT (Engine A), Win32.Application.Snojan.A (Engine B) |
Avast Core Security (Linux) | Win32:TrojanX-gen [Trj] |
C4S ClamAV (Linux) | YARA.UPX.UNOFFICIAL |
F-Secure Antivirus (Linux) | Trojan.TR/Crypt.ULPM.Gen2 [Aquarius] |
Windows Defender (Windows) | Trojan:Win32/CoreWarrior.DA!MTB |
Forticlient (Linux) | W32/Agent.CYMT!tr |
Sophos Anti-Virus (Linux) | Troj/Bdoor-BHD |
eScan Antivirus (Linux) | Trojan.Agent.CYZT(DB) |
ESET Security (Windows) | a variant of Win32/Agent.AAEF trojan |
ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
Bitdefender Antivirus (Linux) | Trojan.Agent.CYZT |
Kaspersky Standard (Windows) | HEUR:Flooder.Win32.CoreWarrior.a |
Emsisoft Commandline Scanner (Windows) | Trojan.Agent.CYZT (B) |