File 04ad19ec4cca36d9a6684ea1e7f34a8a53599a27f2c8417c509464bc39b00f88

Size 137.4KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 590efac89c065e127ca7b4e131bd5177
SHA1 588ba161886dc57c903ea99a154051b0c7e9941b
SHA256 04ad19ec4cca36d9a6684ea1e7f34a8a53599a27f2c8417c509464bc39b00f88
SHA512
efd2205789c1bc4be23fa6dcb3f78b7861ee0a52d025a058a289a7f8ad6a524d906e817ead091e06118b296039d8594d4d0b59b13089f3048b73f79a141a1287
CRC32 2480B4FC
ssdeep None
Yara
  • SEH__vba - (no description)

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

6588613

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE June 21, 2025, 12:31 p.m. June 21, 2025, 12:38 p.m. 467 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-06-20 15:40:55,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt
2025-06-20 15:40:55,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\EnjpNwNmofhgaJueBi
2025-06-20 15:40:55,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\CPDAECmatSxpyoxfDemt
2025-06-20 15:40:55,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-20 15:40:55,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-20 15:40:55,796 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-20 15:40:56,015 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-20 15:40:56,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-20 15:40:56,015 [analyzer] DEBUG: Started auxiliary module Human
2025-06-20 15:40:56,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-20 15:40:56,015 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-20 15:40:56,108 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-20 15:40:56,108 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-20 15:40:56,108 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-20 15:40:56,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-20 15:40:56,250 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\04ad19ec4cca36d9a6684ea1e7f34a8a53599a27f2c8417c509464bc39b00f88.exe' with arguments '' and pid 2740
2025-06-20 15:40:56,453 [analyzer] DEBUG: Loaded monitor into process with pid 2740
2025-06-20 15:40:56,592 [analyzer] INFO: Injected into process with pid 1292 and name u'taskkill.exe'
2025-06-20 15:40:56,592 [analyzer] INFO: Added new file to list with pid 2740 and path C:\sys.exe
2025-06-20 15:40:56,608 [analyzer] INFO: Added new file to list with pid 2740 and path C:\Windows\sys.exe
2025-06-20 15:40:56,765 [analyzer] INFO: Injected into process with pid 2308 and name u'sys.exe'
2025-06-20 15:40:56,812 [analyzer] DEBUG: Loaded monitor into process with pid 1292
2025-06-20 15:40:56,828 [analyzer] INFO: Injected into process with pid 2944 and name u'cmd.exe'
2025-06-20 15:40:56,921 [analyzer] DEBUG: Loaded monitor into process with pid 2308
2025-06-20 15:41:25,250 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-20 15:41:25,703 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-20 15:41:25,717 [lib.api.process] INFO: Successfully terminated process with pid 2308.
2025-06-20 15:41:25,717 [lib.api.process] INFO: Successfully terminated process with pid 2944.
2025-06-20 15:41:25,733 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-06-21 12:31:07,067 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:08,112 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:09,235 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:10,275 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:11,303 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:12,764 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:14,149 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:15,204 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:16,255 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:17,281 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:18,312 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:19,356 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:20,453 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:21,489 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:22,534 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:23,584 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:24,653 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:25,736 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:26,796 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:27,901 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:28,980 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:30,086 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:31,212 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:32,473 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:33,583 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:34,674 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:35,748 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:36,782 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:38,148 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:39,486 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:40,571 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:41,878 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:42,918 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:43,955 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:44,999 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:46,569 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:47,604 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:48,644 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:49,672 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:50,699 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:51,722 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:52,749 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:53,789 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:55,125 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:56,297 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:57,381 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:58,430 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:31:59,476 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:00,513 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:01,563 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:02,599 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:03,661 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:04,862 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:06,014 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:07,120 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:08,190 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:09,262 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:10,337 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:11,408 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:12,462 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:14,078 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:15,195 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:16,310 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:17,381 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:18,443 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:19,504 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:20,567 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:21,643 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:22,708 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:23,799 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:24,862 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:25,921 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:26,958 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:27,986 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:29,020 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:30,039 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:31,633 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:33,036 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:34,161 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:35,320 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:36,444 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:37,554 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:38,638 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:39,726 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:40,798 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:41,860 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:43,237 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:44,336 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:45,389 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:46,510 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:47,812 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:48,891 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:49,976 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:51,034 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:52,102 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:53,168 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:54,212 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:55,257 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:56,705 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:57,847 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:32:58,954 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:00,064 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:01,179 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:02,270 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:03,619 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:04,715 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:06,107 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:07,185 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:08,271 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:09,902 [cuckoo.core.scheduler] DEBUG: Task #6570726: no machine available yet
2025-06-21 12:33:10,949 [cuckoo.core.scheduler] INFO: Task #6570726: acquired machine win7x6423 (label=win7x6423)
2025-06-21 12:33:10,950 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6570726
2025-06-21 12:33:11,564 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 279834 (interface=vboxnet0, host=192.168.168.223)
2025-06-21 12:33:11,681 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423
2025-06-21 12:33:12,801 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak
2025-06-21 12:35:43,173 [cuckoo.core.guest] INFO: Starting analysis #6570726 on guest (id=win7x6423, ip=192.168.168.223)
2025-06-21 12:35:44,210 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet
2025-06-21 12:35:49,505 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223)
2025-06-21 12:35:49,645 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546)
2025-06-21 12:35:51,062 [cuckoo.core.resultserver] DEBUG: Task #6570726: live log analysis.log initialized.
2025-06-21 12:35:51,947 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:52,387 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:52,728 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:53,099 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:53,104 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'files/933be721c6bede96_~DF1412389143A8AD22.TMP'
2025-06-21 12:35:53,109 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 25686
2025-06-21 12:35:53,112 [cuckoo.core.resultserver] DEBUG: Task #6570726 is sending a BSON stream
2025-06-21 12:35:53,221 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'shots/0001.jpg'
2025-06-21 12:35:53,236 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 133465
2025-06-21 12:36:05,822 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6570726 still processing
2025-06-21 12:36:21,518 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'curtain/1750426885.52.curtain.log'
2025-06-21 12:36:21,532 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 36
2025-06-21 12:36:21,605 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6570726 still processing
2025-06-21 12:36:21,695 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'sysmon/1750426885.69.sysmon.xml'
2025-06-21 12:36:21,709 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 1199586
2025-06-21 12:36:21,721 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'files/2aa2960252e67e3b_sys.exe'
2025-06-21 12:36:21,725 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 140723
2025-06-21 12:36:21,728 [cuckoo.core.resultserver] DEBUG: Task #6570726: File upload for 'files/b8cfc6343ca9f9b1_sys.exe'
2025-06-21 12:36:22,082 [cuckoo.core.resultserver] DEBUG: Task #6570726 uploaded file length: 140723
2025-06-21 12:36:22,104 [cuckoo.core.resultserver] DEBUG: Task #6570726 had connection reset for <Context for LOG>
2025-06-21 12:36:24,631 [cuckoo.core.guest] INFO: win7x6423: analysis completed successfully
2025-06-21 12:36:24,647 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-06-21 12:36:24,687 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-06-21 12:36:25,949 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6570726/memory.dmp
2025-06-21 12:36:25,952 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423
2025-06-21 12:38:54,393 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6570726
2025-06-21 12:38:54,808 [cuckoo.core.scheduler] DEBUG: Released database task #6570726
2025-06-21 12:38:54,831 [cuckoo.core.scheduler] INFO: Task #6570726: analysis procedure completed

Signatures

Yara rule detected for file (1 event)
description (no description) rule SEH__vba
Command line console output was observed (1 event)
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: ERROR: The process "KSafeTray.exe" not found.
console_handle: 0x0000000b
1 1 0
One or more processes crashed (3 events)
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1635416
registers.edi: 6033520
registers.eax: 1635416
registers.ebp: 1635496
registers.edx: 0
registers.ebx: 6033520
registers.esi: 6033520
registers.ecx: 2
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634856
registers.edi: 5981240
registers.eax: 1634856
registers.ebp: 1634936
registers.edx: 0
registers.ebx: 5981240
registers.esi: 5981240
registers.ecx: 2
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1635072
registers.edi: 5981240
registers.eax: 1635072
registers.ebp: 1635152
registers.edx: 0
registers.ebx: 5981240
registers.esi: 5981240
registers.ecx: 2
1 0 0
Foreign language identified in PE resource (1 event)
name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0001b1e0 size 0x00000220
Creates executable files on the filesystem (2 events)
file c:\sys.exe
file C:\Windows\sys.exe
Executes one or more WMI queries (1 event)
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "KSafeTray.exe")
Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping (22 events)
Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time) (1 event)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2740
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x003e0000
process_handle: 0xffffffff
1 0 0
Checks for the Locally Unique Identifier on the system for a suspicious privilege (1 event)
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
Uses Windows utilities for basic Windows functionality (2 events)
cmdline taskkill.exe /im KSafeTray.exe /f
cmdline cmd /c del 04ad19ec4cca36d9a6684ea1e7f34a8a53599a27f2c8417c509464bc39b00f88.exe
File has been identified by 12 AntiVirus engine on IRMA as malicious (12 events)
G Data Antivirus (Windows) Virus: Generic.Dacic.76A3436A.A.0CD67633 (Engine A), Win32.Trojan.PSE.12470O7 (Engine B)
Avast Core Security (Linux) Win32:MalwareX-gen [Drp]
C4S ClamAV (Linux) Win.Malware.Cyns-7782618-0
Trellix (Linux) GenericRXAE-GJ
WithSecure (Linux) Trojan.TR/Dropper.Gen
eScan Antivirus (Linux) Generic.Dacic.76A3436A.A.0CD67633(DB)
ESET Security (Windows) Win32/VB.PRB trojan
Sophos Anti-Virus (Linux) Mal/VB-WA
DrWeb Antivirus (Linux) Trojan.Click1.60752
ClamAV (Linux) Win.Malware.Cyns-7782618-0
Bitdefender Antivirus (Linux) Generic.Dacic.76A3436A.A.0CD67633
Emsisoft Commandline Scanner (Windows) Generic.Dacic.76A3436A.A.0CD67633 (B)
File has been identified by 63 AntiVirus engines on VirusTotal as malicious (50 out of 63 events)
Bkav W32.AIDetectMalware
tehtris Generic.Malware
Cynet Malicious (score: 100)
CAT-QuickHeal Trojan.CynsVMF.S28095021
Skyhigh BehavesLike.Win32.Generic.cm
ALYac Generic.Dacic.76A3436A.A.0CD67633
Cylance Unsafe
VIPRE Generic.Dacic.76A3436A.A.0CD67633
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Generic.Dacic.76A3436A.A.0CD67633
K7GW Trojan ( 0058d34b1 )
K7AntiVirus Trojan ( 0058d34b1 )
Arcabit Generic.Dacic.76A3436A.A.0CD67633
Baidu Win32.Trojan.VB.fb
VirIT Trojan.Win32.Click1.DLWQ
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Win32/VB.PRB
APEX Malicious
Avast Win32:MalwareX-gen [Drp]
ClamAV Win.Malware.Cyns-7782618-0
Kaspersky Trojan-Dropper.Win32.Cyns.a
NANO-Antivirus Trojan.Win32.Cyns.hivwdd
SUPERAntiSpyware Trojan.Agent/Gen-Dropper
MicroWorld-eScan Generic.Dacic.76A3436A.A.0CD67633
Rising Trojan.DL.Win32.VBcode.ary (CLASSIC)
Emsisoft Generic.Dacic.76A3436A.A.0CD67633 (B)
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.Click1.60752
Zillya Trojan.Agent.Win32.131109
McAfeeD ti!04AD19EC4CCA
Trapmine suspicious.low.ml.score
CTX exe.unknown.dacic
Sophos Mal/VB-WA
SentinelOne Static AI - Malicious PE
Jiangmin TrojanDropper.Cyns.b
Google Detected
Avira TR/Dropper.Gen
Antiy-AVL Trojan/Win32.VB.prb
Kingsoft malware.kb.a.986
Gridinsoft Trojan.Win32.Wacatac.dd!n
Xcitium TrojWare.Win32.Agent.hqvl@4j9rf1
Microsoft Trojan:Win32/Sisproc!pz
ViRobot Trojan.Win32.A.Agent.140804
ZoneAlarm Mal/VB-WA
GData Win32.Trojan.StartPage.AL
Varist W32/StartPage.BD.gen!Eldorado
AhnLab-V3 Trojan/Win32.StartPage.R19634
Acronis suspicious
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.