Size | 7.8KB |
---|---|
Type | Unicode text, UTF-8 text, with very long lines (1096), with CRLF line terminators |
MD5 | a78432dabc1a513040886fb094bdfcf7 |
SHA1 | aa479157681f02a0e63e8d38a89d5ee0ae1e2358 |
SHA256 | 25e48bbc083b29f3a539d83c9ae06d25459232b14952d892e4c289e82d2c5db0 |
SHA512 |
99276ac4fd8e81a9ebdef43ae0e6f9e2af9f30b38f20fb8d1b5e499794d1fe2b22f1a0f7a335df0b13ccaee0776a290a3d2379356790f1bb88625b218ab4ec50
|
CRC32 | C6117528 |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 13, 2025, 4:37 p.m. | May 13, 2025, 4:43 p.m. | 366 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-06 04:01:27,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpk4d6bl 2025-05-06 04:01:27,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\cPLOgtJTHIocPfeaEyJqGdqgJESATr 2025-05-06 04:01:27,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\occwJIAcYXuWeEFYqRFuvJRlkauVM 2025-05-06 04:01:27,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-05-06 04:01:27,030 [analyzer] INFO: Automatically selected analysis package "generic" 2025-05-06 04:01:27,390 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-06 04:01:27,390 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-06 04:01:27,967 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-06 04:01:28,187 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-05-06 04:01:28,187 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-06 04:01:28,187 [analyzer] DEBUG: Started auxiliary module Human 2025-05-06 04:01:28,187 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-06 04:01:28,203 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-06 04:01:28,328 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-06 04:01:28,328 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-06 04:01:28,328 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-06 04:01:28,328 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-06 04:01:28,515 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"robWFnd"', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\HlbyBanyTdeWvrnPdHJz.mp4'] and pid 2068 2025-05-06 04:01:28,875 [analyzer] DEBUG: Loaded monitor into process with pid 2068 2025-05-06 04:01:29,233 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 04:01:29,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,312 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,312 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,312 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 04:01:29,312 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,342 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,358 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,483 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,530 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,546 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 04:01:29,592 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 04:01:29,592 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,592 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,592 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,608 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 04:01:29,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,608 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,625 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:29,625 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 04:01:30,062 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 04:01:30,062 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,078 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,078 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 04:01:30,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,092 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,108 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 04:01:30,203 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 04:01:30,203 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,203 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,217 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,217 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 04:01:30,217 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,217 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,233 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,233 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,233 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:30,233 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 04:01:35,250 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 04:01:35,250 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,265 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 04:01:35,265 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,280 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,296 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,296 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 04:01:35,655 [analyzer] CRITICAL: Error creating function stub for advapi32!ControlService. 2025-05-06 04:01:35,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!DeleteService at 0x09f498 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,655 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerA at 0x09f336 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenSCManagerW at 0x09f4a8 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,671 [analyzer] CRITICAL: Error creating function stub for advapi32!OpenServiceA. 2025-05-06 04:01:35,671 [analyzer] CRITICAL: Unable to change memory protection of advapi32!OpenServiceW at 0x09f488 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegCloseKey at 0x09f6b4 5 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueA at 0x09f5ee 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!RegDeleteValueW at 0x09f5dc 10 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,687 [analyzer] CRITICAL: Unable to change memory protection of advapi32!StartServiceCtrlDispatcherW at 0x09f276 6 to RWX (error code 0xc0000045)! 2025-05-06 04:01:35,703 [analyzer] CRITICAL: Error creating function stub for advapi32!StartServiceW. 2025-05-06 04:01:39,546 [analyzer] INFO: Process with pid 2068 has terminated 2025-05-06 04:01:39,546 [analyzer] INFO: Process list is empty, terminating analysis. 2025-05-06 04:01:40,937 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-06 04:01:40,937 [analyzer] INFO: Analysis completed.
2025-05-13 16:37:02,089 [cuckoo.core.scheduler] INFO: Task #6452082: acquired machine win7x6422 (label=win7x6422) 2025-05-13 16:37:02,090 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.222 for task #6452082 2025-05-13 16:37:02,374 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 596490 (interface=vboxnet0, host=192.168.168.222) 2025-05-13 16:37:02,449 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6422 2025-05-13 16:37:03,022 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6422 to vmcloak 2025-05-13 16:39:27,849 [cuckoo.core.guest] INFO: Starting analysis #6452082 on guest (id=win7x6422, ip=192.168.168.222) 2025-05-13 16:39:28,862 [cuckoo.core.guest] DEBUG: win7x6422: not ready yet 2025-05-13 16:39:34,048 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6422, ip=192.168.168.222) 2025-05-13 16:39:34,266 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6422, ip=192.168.168.222, monitor=latest, size=6660546) 2025-05-13 16:39:35,825 [cuckoo.core.resultserver] DEBUG: Task #6452082: live log analysis.log initialized. 2025-05-13 16:39:36,969 [cuckoo.core.resultserver] DEBUG: Task #6452082 is sending a BSON stream 2025-05-13 16:39:37,562 [cuckoo.core.resultserver] DEBUG: Task #6452082 is sending a BSON stream 2025-05-13 16:39:38,337 [cuckoo.core.resultserver] DEBUG: Task #6452082: File upload for 'shots/0001.jpg' 2025-05-13 16:39:38,352 [cuckoo.core.resultserver] DEBUG: Task #6452082 uploaded file length: 114775 2025-05-13 16:39:45,602 [cuckoo.core.resultserver] DEBUG: Task #6452082: File upload for 'shots/0002.jpg' 2025-05-13 16:39:45,619 [cuckoo.core.resultserver] DEBUG: Task #6452082 uploaded file length: 111304 2025-05-13 16:39:46,715 [cuckoo.core.resultserver] DEBUG: Task #6452082: File upload for 'shots/0003.jpg' 2025-05-13 16:39:46,734 [cuckoo.core.resultserver] DEBUG: Task #6452082 uploaded file length: 111407 2025-05-13 16:39:47,836 [cuckoo.core.resultserver] DEBUG: Task #6452082: File upload for 'shots/0004.jpg' 2025-05-13 16:39:47,854 [cuckoo.core.resultserver] DEBUG: Task #6452082 uploaded file length: 129065 2025-05-13 16:39:48,959 [cuckoo.core.resultserver] DEBUG: Task #6452082: File upload for 'shots/0005.jpg' 2025-05-13 16:39:48,973 [cuckoo.core.resultserver] DEBUG: Task #6452082 uploaded file length: 134061 2025-05-13 16:39:49,629 [cuckoo.core.resultserver] DEBUG: Task #6452082: File upload for 'curtain/1746496900.78.curtain.log' 2025-05-13 16:39:49,632 [cuckoo.core.resultserver] DEBUG: Task #6452082 uploaded file length: 36 2025-05-13 16:39:49,780 [cuckoo.core.resultserver] DEBUG: Task #6452082: File upload for 'sysmon/1746496900.93.sysmon.xml' 2025-05-13 16:39:49,792 [cuckoo.core.resultserver] DEBUG: Task #6452082 uploaded file length: 553336 2025-05-13 16:39:50,016 [cuckoo.core.resultserver] DEBUG: Task #6452082 had connection reset for <Context for LOG> 2025-05-13 16:39:50,346 [cuckoo.core.guest] INFO: win7x6422: analysis completed successfully 2025-05-13 16:39:50,361 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-13 16:39:50,396 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-13 16:39:51,180 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6422 to path /srv/cuckoo/cwd/storage/analyses/6452082/memory.dmp 2025-05-13 16:39:51,181 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6422 2025-05-13 16:43:07,745 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.222 for task #6452082 2025-05-13 16:43:08,706 [cuckoo.core.scheduler] DEBUG: Released database task #6452082 2025-05-13 16:43:08,723 [cuckoo.core.scheduler] INFO: Task #6452082: analysis procedure completed
No signatures