Size | 56.8KB |
---|---|
Type | PDF document, version 1.4, 2 pages |
MD5 | f48436202153b98e8fb2547e8d36f63d |
SHA1 | 402cfd37c78b95ec4c491392092475df1732daaa |
SHA256 | ed2ae519d076858ab168dde6408bdd4c021a9afc510b43345baa75ea52701ff3 |
SHA512 |
21898ac9f6a4a983935811e7675a580b4a21681418f61146a15c31ad8433187df07abe32876bc1be665a00ad362ee6c5e3bc02436776ce4e82b9452b991a1121
|
CRC32 | A96EDFBA |
ssdeep | None |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 19, 2025, 3:31 a.m. | May 19, 2025, 3:38 a.m. | 451 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-18 15:01:53,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpqnr2dk 2025-05-18 15:01:53,000 [analyzer] DEBUG: Pipe server name: \??\PIPE\vrzCmIyPsOAoqQxxOxksxLqqBkdoaM 2025-05-18 15:01:53,000 [analyzer] DEBUG: Log pipe server name: \??\PIPE\qbBSlRwsOFAVUhBfixZOu 2025-05-18 15:01:53,250 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-18 15:01:53,250 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-18 15:01:53,687 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-18 15:01:53,890 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-05-18 15:01:53,921 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-18 15:01:53,921 [analyzer] DEBUG: Started auxiliary module Human 2025-05-18 15:01:53,921 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-18 15:01:53,921 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-18 15:01:54,030 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-18 15:01:54,030 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-18 15:01:54,030 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-18 15:01:54,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-18 15:01:54,030 [modules.packages.pdf] INFO: Submitted file is missing extension, added .pdf 2025-05-18 15:01:54,171 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AcroRd32.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\ed2ae519d076858ab168dde6408bdd4c021a9afc510b43345baa75ea52701ff3.pdf'] and pid 1424 2025-05-18 15:01:54,342 [analyzer] DEBUG: Loaded monitor into process with pid 1424 2025-05-18 15:01:55,687 [analyzer] INFO: Added new file to list with pid 1424 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\UserCache.bin 2025-05-18 15:01:55,905 [analyzer] INFO: Added new file to list with pid 1424 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wscRGB.icc 2025-05-18 15:01:55,937 [analyzer] INFO: Added new file to list with pid 1424 and path C:\Users\Administrator\AppData\Local\Adobe\Color\Profiles\wsRGB.icc 2025-05-18 15:01:55,953 [analyzer] INFO: Added new file to list with pid 1424 and path C:\Users\Administrator\AppData\Local\Adobe\Color\ACECache10.lst 2025-05-18 15:01:58,592 [analyzer] INFO: Added new file to list with pid 1424 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents-journal 2025-05-18 15:01:58,592 [analyzer] INFO: Added new file to list with pid 1424 and path C:\Users\Administrator\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents 2025-05-19 02:35:22,279 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-19 02:35:22,763 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-19 02:35:22,763 [lib.api.process] INFO: Successfully terminated process with pid 1424. 2025-05-19 02:35:22,795 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\roaming\\adobe\\acrobat\\9.0\\shareddataevents-journal' does not exist, skip. 2025-05-19 02:35:22,811 [analyzer] INFO: Analysis completed.
2025-05-19 03:31:22,048 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:23,078 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:24,114 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:25,139 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:26,170 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:27,203 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:28,233 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:29,261 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:30,532 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:31,578 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:32,619 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:33,658 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:34,688 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:35,752 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:36,785 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:37,878 [cuckoo.core.scheduler] DEBUG: Task #6487642: no machine available yet 2025-05-19 03:31:38,927 [cuckoo.core.scheduler] INFO: Task #6487642: acquired machine win7x6415 (label=win7x6415) 2025-05-19 03:31:38,927 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.215 for task #6487642 2025-05-19 03:31:39,368 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2488009 (interface=vboxnet0, host=192.168.168.215) 2025-05-19 03:31:39,389 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6415 2025-05-19 03:31:39,970 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6415 to vmcloak 2025-05-19 03:34:44,043 [cuckoo.core.guest] INFO: Starting analysis #6487642 on guest (id=win7x6415, ip=192.168.168.215) 2025-05-19 03:34:45,048 [cuckoo.core.guest] DEBUG: win7x6415: not ready yet 2025-05-19 03:34:50,457 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6415, ip=192.168.168.215) 2025-05-19 03:34:50,813 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6415, ip=192.168.168.215, monitor=latest, size=6660546) 2025-05-19 03:34:52,087 [cuckoo.core.resultserver] DEBUG: Task #6487642: live log analysis.log initialized. 2025-05-19 03:34:52,935 [cuckoo.core.resultserver] DEBUG: Task #6487642 is sending a BSON stream 2025-05-19 03:34:53,385 [cuckoo.core.resultserver] DEBUG: Task #6487642 is sending a BSON stream 2025-05-19 03:34:54,236 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'shots/0001.jpg' 2025-05-19 03:34:54,246 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 125286 2025-05-19 03:34:56,389 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'shots/0002.jpg' 2025-05-19 03:34:56,400 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 111975 2025-05-19 03:35:03,661 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'shots/0003.jpg' 2025-05-19 03:35:03,669 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 109825 2025-05-19 03:35:07,071 [cuckoo.core.guest] DEBUG: win7x6415: analysis #6487642 still processing 2025-05-19 03:35:22,449 [cuckoo.core.guest] DEBUG: win7x6415: analysis #6487642 still processing 2025-05-19 03:35:22,450 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'curtain/1747614922.45.curtain.log' 2025-05-19 03:35:22,453 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 36 2025-05-19 03:35:22,723 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'sysmon/1747614922.65.sysmon.xml' 2025-05-19 03:35:22,786 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 1788730 2025-05-19 03:35:22,794 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'files/818589d4d3447ee7_wscrgb.icc' 2025-05-19 03:35:22,798 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 66208 2025-05-19 03:35:22,800 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'files/a6a396b01f151ee6_wsrgb.icc' 2025-05-19 03:35:22,803 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 2676 2025-05-19 03:35:22,805 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'files/b8e09955b7016b78_acecache10.lst' 2025-05-19 03:35:22,807 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 1946 2025-05-19 03:35:22,808 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'files/00c469d01ed54bd3_shareddataevents' 2025-05-19 03:35:22,823 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 3072 2025-05-19 03:35:22,828 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'files/2cbbfbe12768f624_usercache.bin' 2025-05-19 03:35:22,830 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 69063 2025-05-19 03:35:23,402 [cuckoo.core.resultserver] DEBUG: Task #6487642: File upload for 'shots/0004.jpg' 2025-05-19 03:35:23,593 [cuckoo.core.resultserver] DEBUG: Task #6487642 uploaded file length: 133474 2025-05-19 03:35:23,610 [cuckoo.core.resultserver] DEBUG: Task #6487642 had connection reset for <Context for LOG> 2025-05-19 03:35:25,468 [cuckoo.core.guest] INFO: win7x6415: analysis completed successfully 2025-05-19 03:35:25,486 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-19 03:35:25,518 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-19 03:35:26,487 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6415 to path /srv/cuckoo/cwd/storage/analyses/6487642/memory.dmp 2025-05-19 03:35:26,488 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6415 2025-05-19 03:38:53,378 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.215 for task #6487642 2025-05-19 03:38:53,843 [cuckoo.core.scheduler] DEBUG: Released database task #6487642 2025-05-19 03:38:53,860 [cuckoo.core.scheduler] INFO: Task #6487642: analysis procedure completed
description | (no description) | rule | invalid_trailer_structure |
Avast Core Security (Linux) | PDF:MalwareX-gen [Scam] |
WithSecure (Linux) | Trojan.TR/AVI.MalwareX.wdpvn |