Size | 83.2KB |
---|---|
Type | PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
MD5 | d8f35e18cb3b23dbe64bedcab0d3aa7c |
SHA1 | 4e72fc55ace9cee51a33a9a7e7a6b05fb32a3519 |
SHA256 | 31f061943c09beb8c0b119b48a53bc9141004aceb7faf0a2caf12eed90d6dbbd |
SHA512 |
5e3881a35662ac61daa313dcf387c430672b3ca9c548ba0862f0747d01c821ac0efb08b860922248b7da15f06669d00b1506a6746362185ec06f8b9e17f6a737
|
CRC32 | D521DA2D |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | March 12, 2025, 10:28 a.m. | March 12, 2025, 10:36 a.m. | 491 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-03-10 20:36:09,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt 2025-03-10 20:36:09,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\IxByxHlyabVxwpCPBhLS 2025-03-10 20:36:09,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\BlYSPvQbkgKAcipEEuEtiCTRtjghRJn 2025-03-10 20:36:09,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-03-10 20:36:09,015 [analyzer] INFO: Automatically selected analysis package "exe" 2025-03-10 20:36:09,312 [analyzer] DEBUG: Started auxiliary module Curtain 2025-03-10 20:36:09,312 [analyzer] DEBUG: Started auxiliary module DbgView 2025-03-10 20:36:09,765 [analyzer] DEBUG: Started auxiliary module Disguise 2025-03-10 20:36:09,967 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-03-10 20:36:09,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-03-10 20:36:09,967 [analyzer] DEBUG: Started auxiliary module Human 2025-03-10 20:36:09,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-03-10 20:36:09,967 [analyzer] DEBUG: Started auxiliary module Reboot 2025-03-10 20:36:10,030 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-03-10 20:36:10,030 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-03-10 20:36:10,030 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-03-10 20:36:10,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-03-10 20:36:10,171 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\31f061943c09beb8_rifaien2-v8ctmBUkiiRMFO7u.exe' with arguments '' and pid 2596 2025-03-10 20:36:10,390 [analyzer] DEBUG: Loaded monitor into process with pid 2596 2025-03-10 20:36:10,405 [analyzer] INFO: Added new file to list with pid 2596 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-vpjaURH2dLAvYlMu.exe 2025-03-10 20:36:40,812 [analyzer] INFO: Added new file to list with pid 2596 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-wA8GuZwPiabnu60I.exe 2025-03-10 20:37:11,000 [analyzer] INFO: Added new file to list with pid 2596 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-fKF7gmupCP9dAzg8.exe 2025-03-10 20:37:41,203 [analyzer] INFO: Added new file to list with pid 2596 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-Mymrng72gXD3opCw.exe 2025-03-10 20:38:11,453 [analyzer] INFO: Added new file to list with pid 2596 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-e8iY84CzbLF8KFFI.exe 2025-03-10 20:38:41,780 [analyzer] INFO: Added new file to list with pid 2596 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-Pn2yzBBoXo2fVDPL.exe 2025-03-10 20:39:11,967 [analyzer] INFO: Added new file to list with pid 2596 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-7uU2lXn1wkQbGwK6.exe 2025-03-10 20:39:29,250 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-03-10 20:39:30,280 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-03-10 20:39:30,280 [lib.api.process] INFO: Successfully terminated process with pid 2596. 2025-03-10 20:39:30,280 [analyzer] INFO: Analysis completed.
2025-03-12 10:28:39,413 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:40,501 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:41,623 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:42,706 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:43,772 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:44,828 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:45,883 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:46,935 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:47,996 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:49,040 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:50,414 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:51,470 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:52,548 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:53,600 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:54,679 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:55,735 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:56,783 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:57,830 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:58,890 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:28:59,951 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:01,000 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:02,054 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:03,133 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:04,187 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:05,233 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:06,267 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:07,351 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:08,414 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:09,457 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:10,499 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:11,551 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:12,638 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:13,707 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:14,822 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:15,930 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:17,037 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:18,572 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:19,688 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:20,831 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:21,905 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:22,978 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:24,044 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:25,162 [cuckoo.core.scheduler] DEBUG: Task #6082791: no machine available yet 2025-03-12 10:29:26,249 [cuckoo.core.scheduler] INFO: Task #6082791: acquired machine win7x6423 (label=win7x6423) 2025-03-12 10:29:26,252 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6082791 2025-03-12 10:29:26,860 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3356250 (interface=vboxnet0, host=192.168.168.223) 2025-03-12 10:29:27,139 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423 2025-03-12 10:29:27,986 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak 2025-03-12 10:31:13,463 [cuckoo.core.guest] INFO: Starting analysis #6082791 on guest (id=win7x6423, ip=192.168.168.223) 2025-03-12 10:31:14,470 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet 2025-03-12 10:31:19,494 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223) 2025-03-12 10:31:19,593 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546) 2025-03-12 10:31:20,884 [cuckoo.core.resultserver] DEBUG: Task #6082791: live log analysis.log initialized. 2025-03-12 10:31:21,729 [cuckoo.core.resultserver] DEBUG: Task #6082791 is sending a BSON stream 2025-03-12 10:31:22,135 [cuckoo.core.resultserver] DEBUG: Task #6082791 is sending a BSON stream 2025-03-12 10:31:22,646 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'files/87513c99d6b60ee0_rifaien2-vpjaURH2dLAvYlMu.exe' 2025-03-12 10:31:22,690 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 85151 2025-03-12 10:31:22,962 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0001.jpg' 2025-03-12 10:31:22,979 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 160648 2025-03-12 10:31:35,557 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:31:50,835 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:31:52,919 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'files/fd3a731adef2267b_rifaien2-wA8GuZwPiabnu60I.exe' 2025-03-12 10:31:52,965 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 85151 2025-03-12 10:31:54,059 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0002.jpg' 2025-03-12 10:31:54,150 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 160859 2025-03-12 10:32:06,050 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:32:21,977 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:32:23,216 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'files/5ecda33476a06bcc_rifaien2-fKF7gmupCP9dAzg8.exe' 2025-03-12 10:32:23,221 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 85151 2025-03-12 10:32:23,795 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0003.jpg' 2025-03-12 10:32:23,812 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 160909 2025-03-12 10:32:42,197 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:32:53,288 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'files/ed40c6aeb591d800_rifaien2-Mymrng72gXD3opCw.exe' 2025-03-12 10:32:53,290 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 85151 2025-03-12 10:32:53,630 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0004.jpg' 2025-03-12 10:32:53,877 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 160530 2025-03-12 10:32:57,696 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:33:12,857 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:33:23,583 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0005.jpg' 2025-03-12 10:33:23,601 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'files/b1b12e74a56ace52_rifaien2-e8iY84CzbLF8KFFI.exe' 2025-03-12 10:33:23,612 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 85151 2025-03-12 10:33:23,664 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 150794 2025-03-12 10:33:24,758 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0006.jpg' 2025-03-12 10:33:24,776 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 160556 2025-03-12 10:33:27,992 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:33:43,196 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:33:53,794 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'files/5f41c0688aac0fad_rifaien2-Pn2yzBBoXo2fVDPL.exe' 2025-03-12 10:33:53,803 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 85151 2025-03-12 10:33:54,475 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0007.jpg' 2025-03-12 10:33:54,490 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 160856 2025-03-12 10:33:58,638 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:34:13,819 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:34:24,029 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'files/a17c7765d422f672_rifaien2-7uU2lXn1wkQbGwK6.exe' 2025-03-12 10:34:24,086 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 85151 2025-03-12 10:34:24,088 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0008.jpg' 2025-03-12 10:34:24,102 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 162940 2025-03-12 10:34:25,365 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'shots/0009.jpg' 2025-03-12 10:34:25,418 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 160666 2025-03-12 10:34:29,146 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6082791 still processing 2025-03-12 10:34:41,255 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'curtain/1741635569.42.curtain.log' 2025-03-12 10:34:41,269 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 36 2025-03-12 10:34:42,012 [cuckoo.core.resultserver] DEBUG: Task #6082791: File upload for 'sysmon/1741635570.19.sysmon.xml' 2025-03-12 10:34:42,104 [cuckoo.core.resultserver] DEBUG: Task #6082791 uploaded file length: 10415404 2025-03-12 10:34:42,129 [cuckoo.core.resultserver] DEBUG: Task #6082791 had connection reset for <Context for LOG> 2025-03-12 10:34:44,333 [cuckoo.core.guest] INFO: win7x6423: analysis completed successfully 2025-03-12 10:34:44,370 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-03-12 10:34:44,459 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-03-12 10:34:45,740 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6082791/memory.dmp 2025-03-12 10:34:45,742 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423 2025-03-12 10:36:29,304 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6082791 2025-03-12 10:36:30,130 [cuckoo.core.scheduler] DEBUG: Released database task #6082791 2025-03-12 10:36:40,333 [cuckoo.core.scheduler] INFO: Task #6082791: analysis procedure completed
description | (no description) | rule | UPX | ||||||
description | The packer/protector section names/keywords | rule | suspicious_packer_section | ||||||
description | Communications over RAW socket | rule | network_tcp_socket |
packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
description | 31f061943c09beb8_rifaien2-v8ctmBUkiiRMFO7u.exe tried to sleep 210 seconds, actually delayed analysis time by 180 seconds |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-Mymrng72gXD3opCw.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-vpjaURH2dLAvYlMu.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-e8iY84CzbLF8KFFI.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-7uU2lXn1wkQbGwK6.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-Pn2yzBBoXo2fVDPL.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-wA8GuZwPiabnu60I.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-fKF7gmupCP9dAzg8.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-vpjaURH2dLAvYlMu.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-wA8GuZwPiabnu60I.exe |
section | {u'size_of_data': u'0x00014800', u'virtual_address': u'0x00014000', u'entropy': 7.711103975782718, u'name': u'UPX1', u'virtual_size': u'0x00015000'} | entropy | 7.71110397578 | description | A section with a high entropy has been found | |||||||||
entropy | 0.993939393939 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX | ||||||
section | UPX2 | description | Section name indicates UPX |
buffer | Buffer with sha1: 97653fe98384b5bef285a95b60548b73adae825a |
suricata | ETPRO MALWARE Win32/Snojan Variant Uploading EXE |
suricata | ET INFO Generic HTTP EXE Upload Outbound |
G Data Antivirus (Windows) | Virus: Trojan.Agent.CYZT (Engine A), Win32.Application.Snojan.A (Engine B) |
Avast Core Security (Linux) | Win32:TrojanX-gen [Trj] |
C4S ClamAV (Linux) | YARA.UPX.UNOFFICIAL |
F-Secure Antivirus (Linux) | Trojan.TR/Crypt.ULPM.Gen2 [Aquarius] |
Sophos Anti-Virus (Linux) | Troj/Bdoor-BHD |
eScan Antivirus (Linux) | Trojan.Agent.CYZT(DB) |
ESET Security (Windows) | a variant of Win32/Agent.AAEF trojan |
WithSecure (Linux) | Trojan.TR/Crypt.ULPM.Gen2 |
ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
Bitdefender Antivirus (Linux) | Trojan.Agent.CYZT |
Kaspersky Standard (Windows) | HEUR:Flooder.Win32.CoreWarrior.a |
Emsisoft Commandline Scanner (Windows) | Trojan.Agent.CYZT (B) |