Size | 83.1KB |
---|---|
Type | PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed |
MD5 | 05e5d1a83fe51ebd929b8950718768ed |
SHA1 | 4afdd420a4f3c671e70fd76e3973de2e24e6cd06 |
SHA256 | 22fdb4382d83052accb6be8165aaedaa3338c212392af8539efd4f8d378574c6 |
SHA512 |
5d1e1a34d49c7fa3f1efb9364322005e93e1c5213a3942ab8d9c218026e0a3d9cc26d0fcced4d568b2be70fe00a52ee1b72c6d7a627c1de16ec07b0e479b4aef
|
CRC32 | EC3528D4 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 19, 2025, 3:15 a.m. | May 19, 2025, 3:24 a.m. | 532 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-18 15:00:08,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpd0os1j 2025-05-18 15:00:08,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\jGAbqTEesgsgIiCNXBDNvScpXINGea 2025-05-18 15:00:08,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\kWqkYNusmwBZZPIRXq 2025-05-18 15:00:08,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-05-18 15:00:08,030 [analyzer] INFO: Automatically selected analysis package "exe" 2025-05-18 15:00:08,312 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-18 15:00:08,312 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-18 15:00:08,812 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-18 15:00:09,015 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-05-18 15:00:09,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-18 15:00:09,015 [analyzer] DEBUG: Started auxiliary module Human 2025-05-18 15:00:09,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-18 15:00:09,015 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-18 15:00:09,078 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-18 15:00:09,078 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-18 15:00:09,078 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-18 15:00:09,078 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-18 15:00:09,217 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\22fdb4382d83052a_rifaien2-jVjCCey0MJF6cpYv.exe' with arguments '' and pid 824 2025-05-18 15:00:09,453 [analyzer] DEBUG: Loaded monitor into process with pid 824 2025-05-18 15:00:09,467 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-iwD5RBQzK6FHHC0F.exe 2025-05-19 02:18:57,170 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-igbYEeAQF9ZwaHUq.exe 2025-05-19 02:19:27,513 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-8VZtnJPMnMYB50KS.exe 2025-05-19 02:19:57,857 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-PI9UNv8UagekCmSr.exe 2025-05-19 02:20:28,732 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-U8RaLITbyVxu6g7y.exe 2025-05-19 02:20:59,420 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-uOU3LhdKvj2RS24f.exe 2025-05-19 02:21:29,950 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\rifaien2-dHUh94zl8jFQTzAZ.exe 2025-05-19 02:21:45,529 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-19 02:21:46,545 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-19 02:21:46,545 [lib.api.process] INFO: Successfully terminated process with pid 824. 2025-05-19 02:21:46,545 [analyzer] INFO: Analysis completed.
2025-05-19 03:15:17,341 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:18,363 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:19,396 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:20,419 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:21,447 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:22,478 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:23,512 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:24,547 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:25,576 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:26,611 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:27,661 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:28,728 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:29,757 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:30,786 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:31,817 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:32,848 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:33,874 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:34,902 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:35,938 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:37,139 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:38,190 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:39,242 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:40,271 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:41,321 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:42,394 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:43,450 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:44,523 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:45,590 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:46,651 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:47,714 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:48,781 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:49,850 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:50,920 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:51,979 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:53,156 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:54,220 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:55,286 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:56,527 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:57,604 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:58,660 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:15:59,720 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:00,781 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:01,843 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:02,915 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:03,968 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:05,016 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:06,087 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:07,180 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:08,210 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:09,236 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:10,274 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:11,295 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:12,329 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:13,360 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:14,388 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:15,417 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:16,565 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:17,656 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:18,703 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:20,120 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:21,168 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:22,211 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:23,253 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:24,316 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:25,386 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:26,579 [cuckoo.core.scheduler] DEBUG: Task #6487585: no machine available yet 2025-05-19 03:16:27,646 [cuckoo.core.scheduler] INFO: Task #6487585: acquired machine win7x6429 (label=win7x6429) 2025-05-19 03:16:27,647 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.229 for task #6487585 2025-05-19 03:16:28,110 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2466685 (interface=vboxnet0, host=192.168.168.229) 2025-05-19 03:16:28,821 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6429 2025-05-19 03:16:36,142 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6429 to vmcloak 2025-05-19 03:18:17,802 [cuckoo.core.guest] INFO: Starting analysis #6487585 on guest (id=win7x6429, ip=192.168.168.229) 2025-05-19 03:18:18,806 [cuckoo.core.guest] DEBUG: win7x6429: not ready yet 2025-05-19 03:18:23,829 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6429, ip=192.168.168.229) 2025-05-19 03:18:23,892 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6429, ip=192.168.168.229, monitor=latest, size=6660546) 2025-05-19 03:18:25,180 [cuckoo.core.resultserver] DEBUG: Task #6487585: live log analysis.log initialized. 2025-05-19 03:18:26,149 [cuckoo.core.resultserver] DEBUG: Task #6487585 is sending a BSON stream 2025-05-19 03:18:26,571 [cuckoo.core.resultserver] DEBUG: Task #6487585 is sending a BSON stream 2025-05-19 03:18:27,169 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'files/2ddff0514b68687b_rifaien2-iwD5RBQzK6FHHC0F.exe' 2025-05-19 03:18:27,172 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 85057 2025-05-19 03:18:27,578 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0001.jpg' 2025-05-19 03:18:27,844 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 173956 2025-05-19 03:18:40,110 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:18:55,300 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:18:57,528 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0002.jpg' 2025-05-19 03:18:57,530 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'files/08b2010eb1cdebc5_rifaien2-igbYEeAQF9ZwaHUq.exe' 2025-05-19 03:18:57,533 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 85057 2025-05-19 03:18:57,541 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 164484 2025-05-19 03:18:59,093 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0003.jpg' 2025-05-19 03:18:59,107 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 173921 2025-05-19 03:19:10,640 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:19:25,761 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:19:27,710 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0004.jpg' 2025-05-19 03:19:27,721 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 164388 2025-05-19 03:19:27,853 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'files/373bc6b5ae37e68f_rifaien2-8VZtnJPMnMYB50KS.exe' 2025-05-19 03:19:27,855 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 85057 2025-05-19 03:19:28,815 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0005.jpg' 2025-05-19 03:19:29,039 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 173994 2025-05-19 03:19:41,134 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:19:56,251 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:19:58,420 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0006.jpg' 2025-05-19 03:19:58,436 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 164461 2025-05-19 03:19:58,735 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'files/35eaee86a71dd948_rifaien2-PI9UNv8UagekCmSr.exe' 2025-05-19 03:19:58,738 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 85057 2025-05-19 03:19:59,563 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0007.jpg' 2025-05-19 03:19:59,580 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 173889 2025-05-19 03:20:11,433 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:20:27,042 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:20:29,219 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0008.jpg' 2025-05-19 03:20:29,233 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 164376 2025-05-19 03:20:29,417 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'files/55f6cb8f6b01c348_rifaien2-U8RaLITbyVxu6g7y.exe' 2025-05-19 03:20:29,419 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 85057 2025-05-19 03:20:30,325 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0009.jpg' 2025-05-19 03:20:30,338 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 173960 2025-05-19 03:20:42,149 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:20:57,258 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:20:59,932 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0010.jpg' 2025-05-19 03:20:59,954 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'files/bc9f6adee958baf1_rifaien2-uOU3LhdKvj2RS24f.exe' 2025-05-19 03:20:59,961 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 85057 2025-05-19 03:20:59,977 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 164538 2025-05-19 03:21:01,079 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0011.jpg' 2025-05-19 03:21:01,093 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 174018 2025-05-19 03:21:12,666 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:21:28,621 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:21:30,358 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'files/e171b382f0377f58_rifaien2-dHUh94zl8jFQTzAZ.exe' 2025-05-19 03:21:30,362 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 85057 2025-05-19 03:21:30,657 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'shots/0012.jpg' 2025-05-19 03:21:30,676 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 173898 2025-05-19 03:21:43,870 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6487585 still processing 2025-05-19 03:21:45,734 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'curtain/1747614105.72.curtain.log' 2025-05-19 03:21:45,747 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 36 2025-05-19 03:21:46,483 [cuckoo.core.resultserver] DEBUG: Task #6487585: File upload for 'sysmon/1747614106.48.sysmon.xml' 2025-05-19 03:21:46,550 [cuckoo.core.resultserver] DEBUG: Task #6487585 uploaded file length: 9958590 2025-05-19 03:21:46,578 [cuckoo.core.resultserver] DEBUG: Task #6487585 had connection reset for <Context for LOG> 2025-05-19 03:21:46,895 [cuckoo.core.guest] INFO: win7x6429: analysis completed successfully 2025-05-19 03:21:46,911 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-19 03:21:46,933 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-19 03:21:48,034 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6429 to path /srv/cuckoo/cwd/storage/analyses/6487585/memory.dmp 2025-05-19 03:21:48,035 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6429 2025-05-19 03:24:09,609 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.229 for task #6487585 2025-05-19 03:24:10,005 [cuckoo.core.scheduler] DEBUG: Released database task #6487585 2025-05-19 03:24:10,022 [cuckoo.core.scheduler] INFO: Task #6487585: analysis procedure completed
description | (no description) | rule | UPX | ||||||
description | The packer/protector section names/keywords | rule | suspicious_packer_section | ||||||
description | Communications over RAW socket | rule | network_tcp_socket |
packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://wecan.hasthe.technology/upload |
request | POST http://wecan.hasthe.technology/upload |
request | POST http://wecan.hasthe.technology/upload |
description | 22fdb4382d83052a_rifaien2-jVjCCey0MJF6cpYv.exe tried to sleep 210 seconds, actually delayed analysis time by 180 seconds |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-uOU3LhdKvj2RS24f.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-igbYEeAQF9ZwaHUq.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-iwD5RBQzK6FHHC0F.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-PI9UNv8UagekCmSr.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-8VZtnJPMnMYB50KS.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-dHUh94zl8jFQTzAZ.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-U8RaLITbyVxu6g7y.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-iwD5RBQzK6FHHC0F.exe |
file | C:\Users\Administrator\AppData\Local\Temp\rifaien2-igbYEeAQF9ZwaHUq.exe |
section | {u'size_of_data': u'0x00014800', u'virtual_address': u'0x00014000', u'entropy': 7.71110853733008, u'name': u'UPX1', u'virtual_size': u'0x00015000'} | entropy | 7.71110853733 | description | A section with a high entropy has been found | |||||||||
entropy | 0.993939393939 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX | ||||||
section | UPX2 | description | Section name indicates UPX |
buffer | Buffer with sha1: 97653fe98384b5bef285a95b60548b73adae825a |
suricata | ETPRO MALWARE Win32/Snojan Variant Uploading EXE |
suricata | ET INFO Generic HTTP EXE Upload Outbound |
G Data Antivirus (Windows) | Virus: Trojan.Agent.CYZT (Engine A), Win32.Application.Snojan.A (Engine B) |
Avast Core Security (Linux) | Win32:MalwareX-gen [Trj] |
C4S ClamAV (Linux) | YARA.UPX.UNOFFICIAL |
WithSecure (Linux) | Trojan.TR/Crypt.ULPM.Gen2 |
eScan Antivirus (Linux) | Trojan.Agent.CYZT(DB) |
ESET Security (Windows) | a variant of Win32/Agent.AAEF trojan |
Sophos Anti-Virus (Linux) | Troj/Bdoor-BHD |
ClamAV (Linux) | Win.Malware.Cymt-10023133-0 |
Bitdefender Antivirus (Linux) | Trojan.Agent.CYZT |
Kaspersky Standard (Windows) | HEUR:Flooder.Win32.CoreWarrior.a |
Emsisoft Commandline Scanner (Windows) | Trojan.Agent.CYZT (B) |