Size | 43.4KB |
---|---|
Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
MD5 | 617adecbeb0ae733664eca62f6946263 |
SHA1 | 3c4172023fe144c1e2a911a9b9a1a86ada1ecc37 |
SHA256 | 3adf00a86e3d0508ba6cd5621f7850f9807c8c085967f047bcf1ae09d13464e2 |
SHA512 |
a6c8c7c7d7184a47029d6d44af5c975969695e9fed4faa7c14ddbc3965d3e7dcb27856649f0b5ac078f90aefdf22d2467c457f34e7524f61d67e145f9dee3322
|
CRC32 | ED8E01A6 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 9.0 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 21, 2025, 12:27 p.m. | June 21, 2025, 12:34 p.m. | 416 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-20 15:40:50,015 [analyzer] DEBUG: Starting analyzer from: C:\tmphzbxu3 2025-06-20 15:40:50,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\enwbYQPeePRhJcOYKQmXoaarfqLsgQ 2025-06-20 15:40:50,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\sHatVLLDJSlHFipysCglQuhHLtBID 2025-06-20 15:40:50,390 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-20 15:40:50,390 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-20 15:40:51,092 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-20 15:40:51,296 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-06-20 15:40:51,296 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-20 15:40:51,296 [analyzer] DEBUG: Started auxiliary module Human 2025-06-20 15:40:51,296 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-20 15:40:51,312 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-20 15:40:51,405 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-20 15:40:51,405 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-20 15:40:51,405 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-20 15:40:51,405 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-20 15:40:51,546 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\3adf00a86e3d0508ba6cd5621f7850f9807c8c085967f047bcf1ae09d13464e2.exe' with arguments '' and pid 1824 2025-06-20 15:40:51,703 [analyzer] DEBUG: Loaded monitor into process with pid 1824 2025-06-20 15:41:20,562 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-20 15:41:21,046 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-20 15:41:21,046 [lib.api.process] INFO: Successfully terminated process with pid 1824. 2025-06-20 15:41:21,046 [analyzer] INFO: Analysis completed.
2025-06-21 12:28:05,022 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:06,711 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:07,782 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:08,871 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:09,967 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:11,023 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:12,067 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:13,417 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:14,465 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:15,519 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:16,584 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:17,632 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:18,707 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:19,760 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:20,791 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:21,813 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:22,835 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:23,950 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:25,015 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:26,072 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:27,133 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:28,263 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:29,296 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:30,540 [cuckoo.core.scheduler] DEBUG: Task #6570707: no machine available yet 2025-06-21 12:28:31,624 [cuckoo.core.scheduler] INFO: Task #6570707: acquired machine win7x6425 (label=win7x6425) 2025-06-21 12:28:31,632 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.225 for task #6570707 2025-06-21 12:28:32,212 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 273254 (interface=vboxnet0, host=192.168.168.225) 2025-06-21 12:28:32,267 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6425 2025-06-21 12:28:40,080 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6425 to vmcloak 2025-06-21 12:30:49,880 [cuckoo.core.guest] INFO: Starting analysis #6570707 on guest (id=win7x6425, ip=192.168.168.225) 2025-06-21 12:30:51,066 [cuckoo.core.guest] DEBUG: win7x6425: not ready yet 2025-06-21 12:30:56,109 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6425, ip=192.168.168.225) 2025-06-21 12:30:56,577 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6425, ip=192.168.168.225, monitor=latest, size=6660546) 2025-06-21 12:30:57,999 [cuckoo.core.resultserver] DEBUG: Task #6570707: live log analysis.log initialized. 2025-06-21 12:30:59,381 [cuckoo.core.resultserver] DEBUG: Task #6570707 is sending a BSON stream 2025-06-21 12:30:59,762 [cuckoo.core.resultserver] DEBUG: Task #6570707 is sending a BSON stream 2025-06-21 12:31:00,772 [cuckoo.core.resultserver] DEBUG: Task #6570707: File upload for 'shots/0001.jpg' 2025-06-21 12:31:01,053 [cuckoo.core.resultserver] DEBUG: Task #6570707 uploaded file length: 138609 2025-06-21 12:31:13,122 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6570707 still processing 2025-06-21 12:31:28,282 [cuckoo.core.guest] DEBUG: win7x6425: analysis #6570707 still processing 2025-06-21 12:31:28,841 [cuckoo.core.resultserver] DEBUG: Task #6570707: File upload for 'curtain/1750426880.83.curtain.log' 2025-06-21 12:31:28,849 [cuckoo.core.resultserver] DEBUG: Task #6570707 uploaded file length: 36 2025-06-21 12:31:29,035 [cuckoo.core.resultserver] DEBUG: Task #6570707: File upload for 'sysmon/1750426881.03.sysmon.xml' 2025-06-21 12:31:29,043 [cuckoo.core.resultserver] DEBUG: Task #6570707 uploaded file length: 1147182 2025-06-21 12:31:29,074 [cuckoo.core.resultserver] DEBUG: Task #6570707 had connection reset for <Context for LOG> 2025-06-21 12:31:31,297 [cuckoo.core.guest] INFO: win7x6425: analysis completed successfully 2025-06-21 12:31:31,316 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-21 12:31:31,359 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-21 12:31:32,754 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6425 to path /srv/cuckoo/cwd/storage/analyses/6570707/memory.dmp 2025-06-21 12:31:32,755 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6425 2025-06-21 12:34:45,998 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.225 for task #6570707 2025-06-21 12:34:47,222 [cuckoo.core.scheduler] DEBUG: Released database task #6570707 2025-06-21 12:34:54,518 [cuckoo.core.scheduler] INFO: Task #6570707: analysis procedure completed
section | .XPack0 |
section | .XPack |
section | {u'size_of_data': u'0x000014ab', u'virtual_address': u'0x00006000', u'entropy': 7.740807236057767, u'name': u'.XPack', u'virtual_size': u'0x000014ab'} | entropy | 7.74080723606 | description | A section with a high entropy has been found | |||||||||
entropy | 0.596169014085 | description | Overall entropy of this PE file is high |
G Data Antivirus (Windows) | Virus: Gen:Packer.Xpack.cmdoaKFarOf (Engine A) |
Avast Core Security (Linux) | Win32:MalwareX-gen [Misc] |
C4S ClamAV (Linux) | Win.Dropper.Zombie-10044469-0 |
Trellix (Linux) | GenericATG-FAF |
WithSecure (Linux) | Trojan.TR/Crypt.NSPM.Gen |
eScan Antivirus (Linux) | Gen:Packer.Xpack.cmdoaKFarOf(DB) |
ESET Security (Windows) | Win32/Agent.NBJ virus |
Sophos Anti-Virus (Linux) | Mal/EncPk-DM |
DrWeb Antivirus (Linux) | Trojan.Encoder.185 |
ClamAV (Linux) | Win.Dropper.Zombie-10044469-0 |
Bitdefender Antivirus (Linux) | Gen:Packer.Xpack.cmdoaKFarOf |
Emsisoft Commandline Scanner (Windows) | Gen:Packer.Xpack.cmdoaKFarOf (B) |