Size | 5.9KB |
---|---|
Type | Unicode text, UTF-8 text, with very long lines (741), with CRLF line terminators |
MD5 | 368a907de9523d2a8b1a2a7c403c2de8 |
SHA1 | f7509e36f4de0809c8cb07332b4135def1ccb3c5 |
SHA256 | 00498eabf455cb1caf983e01645e59e4e601497f0e37bc105473ad82502dbc0f |
SHA512 |
50540bc22a8b6d13f6144a71f54acef5f1d50d4fd891d546e7ab4d584199ebdbafed702006b59560fe5c43b8e819d99891855082dfcd85c6a005696092ef3b60
|
CRC32 | 4E95D7D5 |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 16, 2025, 2:51 p.m. | May 16, 2025, 2:58 p.m. | 405 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-09 02:36:14,015 [analyzer] DEBUG: Starting analyzer from: C:\tmphzbxu3 2025-05-09 02:36:14,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\kQIAEGXZCuAagOcnlrFrzHWgBGF 2025-05-09 02:36:14,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\pEtrQQwmndEtMwoSHOPepa 2025-05-09 02:36:14,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-05-09 02:36:14,015 [analyzer] INFO: Automatically selected analysis package "xls" 2025-05-09 02:36:14,265 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-09 02:36:14,265 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-09 02:36:14,750 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-09 02:36:14,953 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-05-09 02:36:14,953 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-09 02:36:14,953 [analyzer] DEBUG: Started auxiliary module Human 2025-05-09 02:36:14,953 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-09 02:36:14,953 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-09 02:36:15,046 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-09 02:36:15,062 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-09 02:36:15,062 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-09 02:36:15,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-09 02:36:15,500 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\zrCxtiqGcDtEE.xls'] and pid 2684 2025-05-09 02:36:16,328 [analyzer] DEBUG: Loaded monitor into process with pid 2684 2025-05-09 02:36:44,515 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-09 02:36:44,905 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-09 02:36:44,905 [lib.api.process] INFO: Successfully terminated process with pid 2684. 2025-05-09 02:36:44,921 [analyzer] INFO: Analysis completed.
2025-05-16 14:51:15,742 [cuckoo.core.scheduler] INFO: Task #6473947: acquired machine win7x6425 (label=win7x6425) 2025-05-16 14:51:15,743 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.225 for task #6473947 2025-05-16 14:51:16,092 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2813366 (interface=vboxnet0, host=192.168.168.225) 2025-05-16 14:51:16,146 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6425 2025-05-16 14:51:16,743 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6425 to vmcloak 2025-05-16 14:54:26,130 [cuckoo.core.guest] INFO: Starting analysis #6473947 on guest (id=win7x6425, ip=192.168.168.225) 2025-05-16 14:54:27,268 [cuckoo.core.guest] DEBUG: win7x6425: not ready yet 2025-05-16 14:54:32,296 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6425, ip=192.168.168.225) 2025-05-16 14:54:32,377 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6425, ip=192.168.168.225, monitor=latest, size=6660546) 2025-05-16 14:54:33,718 [cuckoo.core.resultserver] DEBUG: Task #6473947: live log analysis.log initialized. 2025-05-16 14:54:34,638 [cuckoo.core.resultserver] DEBUG: Task #6473947 is sending a BSON stream 2025-05-16 14:54:35,961 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0001.jpg' 2025-05-16 14:54:35,981 [cuckoo.core.resultserver] DEBUG: Task #6473947 is sending a BSON stream 2025-05-16 14:54:35,990 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 133477 2025-05-16 14:54:39,234 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0002.jpg' 2025-05-16 14:54:39,248 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 124088 2025-05-16 14:54:40,364 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0003.jpg' 2025-05-16 14:54:40,373 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 123707 2025-05-16 14:54:41,491 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0004.jpg' 2025-05-16 14:54:41,502 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 123533 2025-05-16 14:54:42,593 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0005.jpg' 2025-05-16 14:54:42,602 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 130631 2025-05-16 14:54:43,706 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0006.jpg' 2025-05-16 14:54:43,727 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 178547 2025-05-16 14:54:44,826 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0007.jpg' 2025-05-16 14:54:44,840 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 196770 2025-05-16 14:54:45,929 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0008.jpg' 2025-05-16 14:54:45,938 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 119206 2025-05-16 14:54:48,406 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6473947 still processing 2025-05-16 14:55:03,613 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6473947 still processing 2025-05-16 14:55:04,411 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'curtain/1746751004.69.curtain.log' 2025-05-16 14:55:04,414 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 36 2025-05-16 14:55:04,604 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'sysmon/1746751004.89.sysmon.xml' 2025-05-16 14:55:04,628 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 1492714 2025-05-16 14:55:05,451 [cuckoo.core.resultserver] DEBUG: Task #6473947: File upload for 'shots/0009.jpg' 2025-05-16 14:55:05,461 [cuckoo.core.resultserver] DEBUG: Task #6473947 uploaded file length: 139284 2025-05-16 14:55:05,474 [cuckoo.core.resultserver] DEBUG: Task #6473947 had connection reset for <Context for LOG> 2025-05-16 14:55:06,628 [cuckoo.core.guest] INFO: win7x6425: analysis completed successfully 2025-05-16 14:55:06,644 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-16 14:55:06,693 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-16 14:55:07,536 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6425 to path /srv/cuckoo/cwd/storage/analyses/6473947/memory.dmp 2025-05-16 14:55:07,538 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6425 2025-05-16 14:58:00,280 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.225 for task #6473947 2025-05-16 14:58:00,984 [cuckoo.core.scheduler] DEBUG: Released database task #6473947 2025-05-16 14:58:01,029 [cuckoo.core.scheduler] INFO: Task #6473947: analysis procedure completed
Application Crash | Process EXCEL.EXE with pid 2684 crashed |