Size | 13.6KB |
---|---|
Type | MS-DOS executable |
MD5 | 9d42bbca7ec220ad75f669f29686643e |
SHA1 | 8cd4d1064dc69abe769f1e14bb21b0aa0eeacfdd |
SHA256 | dd3eb0ab0a32006470b924fdcac582cd4908f6b266ecf11e5ae5516664a4efaa |
SHA512 |
b226bf41f61923890c3430dab482928a17e1912821fcda3f7f2a6cd700aff90e2e51dbe5bb82ddb022e8dd5b9f1c62a0a1cf946167bec66741521f2893422822
|
CRC32 | D7C13139 |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 18, 2025, 3:59 p.m. | April 18, 2025, 4 p.m. | 63 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-18 15:59:11,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpzepe2z 2025-04-18 15:59:11,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\xIRoYgCJyNAaFbrjAxAm 2025-04-18 15:59:11,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\nluwRodTxUyelgGRkkPvMGWA 2025-04-18 15:59:11,280 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-18 15:59:11,280 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-18 15:59:11,717 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-18 15:59:11,967 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-04-18 15:59:11,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-18 15:59:11,967 [analyzer] DEBUG: Started auxiliary module Human 2025-04-18 15:59:11,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-18 15:59:11,967 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-18 15:59:12,046 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-18 15:59:12,046 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-18 15:59:12,046 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-18 15:59:12,046 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-18 15:59:12,092 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\append.exe' with arguments ['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\append.exe', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\append.exe', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
2025-04-18 15:59:27,872 [cuckoo.core.scheduler] INFO: Task #6298265: acquired machine win7x6417 (label=win7x6417) 2025-04-18 15:59:27,873 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.217 for task #6298265 2025-04-18 15:59:28,327 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3266248 (interface=vboxnet0, host=192.168.168.217) 2025-04-18 15:59:28,341 [cuckoo.common.objects] WARNING: Error enumerating exported functions: 'Invalid NT Headers signature.' 2025-04-18 15:59:28,374 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6417 2025-04-18 15:59:28,979 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6417 to vmcloak 2025-04-18 16:00:07,872 [cuckoo.core.guest] INFO: Starting analysis #6298265 on guest (id=win7x6417, ip=192.168.168.217) 2025-04-18 16:00:08,880 [cuckoo.core.guest] DEBUG: win7x6417: not ready yet 2025-04-18 16:00:13,916 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6417, ip=192.168.168.217) 2025-04-18 16:00:14,036 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6417, ip=192.168.168.217, monitor=latest, size=6660546) 2025-04-18 16:00:15,415 [cuckoo.core.resultserver] DEBUG: Task #6298265: live log analysis.log initialized. 2025-04-18 16:00:16,338 [cuckoo.core.resultserver] DEBUG: Task #6298265 is sending a BSON stream 2025-04-18 16:00:17,601 [cuckoo.core.resultserver] DEBUG: Task #6298265: File upload for 'shots/0001.jpg' 2025-04-18 16:00:17,614 [cuckoo.core.resultserver] DEBUG: Task #6298265 uploaded file length: 133476 2025-04-18 16:00:17,969 [cuckoo.core.guest] WARNING: win7x6417: analysis #6298265 caught an exception Traceback (most recent call last): File "C:/tmpzepe2z/analyzer.py", line 824, in <module> success = analyzer.run() File "C:/tmpzepe2z/analyzer.py", line 673, in run pids = self.package.start(self.target) File "C:\tmpzepe2z\modules\packages\exe.py", line 34, in start return self.execute(path, args=shlex.split(args)) File "C:\tmpzepe2z\lib\common\abstracts.py", line 205, in execute "Unable to execute the initial process, analysis aborted." CuckooPackageError: Unable to execute the initial process, analysis aborted. 2025-04-18 16:00:17,981 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-18 16:00:18,013 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-18 16:00:18,993 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6417 to path /srv/cuckoo/cwd/storage/analyses/6298265/memory.dmp 2025-04-18 16:00:18,994 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6417 2025-04-18 16:00:28,793 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.217 for task #6298265 2025-04-18 16:00:28,794 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6298265 2025-04-18 16:00:31,352 [cuckoo.core.scheduler] DEBUG: Released database task #6298265 2025-04-18 16:00:31,387 [cuckoo.core.scheduler] INFO: Task #6298265: analysis procedure completed
No signatures