Size | 826.1KB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 51a4486b194d50fe9a2a3cf3c116e2dd |
SHA1 | 719e2e3ad9d3c9cd60ff42f30e04bf975b4f07c2 |
SHA256 | 0839397e7d3d28227cb9279124840785b73c647032c95984c31e63f3d5489acf |
SHA512 |
17a3c69b81d50f55314613469897039ad763f382859000b1324296ae917b363f9703d20d33ab96b921b965e2d0eaaff272327e5950e9238e2125b6c6babe718c
|
CRC32 | EE50B4AE |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 30, 2025, 5:48 p.m. | June 30, 2025, 5:50 p.m. | 106 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-23 02:28:59,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpd0os1j 2025-06-23 02:28:59,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\qyTtcUZxeOYWSXzUsjrxyRAbp 2025-06-23 02:28:59,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\FAGSPuogOUWygjjrgfoZcHtIqkEecJ 2025-06-23 02:28:59,390 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-23 02:28:59,390 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-23 02:28:59,937 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-23 02:29:00,140 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-06-23 02:29:00,140 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-23 02:29:00,140 [analyzer] DEBUG: Started auxiliary module Human 2025-06-23 02:29:00,140 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-23 02:29:00,155 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-23 02:29:00,265 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-23 02:29:00,265 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-23 02:29:00,265 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-23 02:29:00,265 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-23 02:29:00,421 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\0839397e7d3d28227cb9279124840785b73c647032c95984c31e63f3d5489acf.exe' with arguments '' and pid 1448 2025-06-23 02:29:00,608 [analyzer] DEBUG: Loaded monitor into process with pid 1448 2025-06-23 02:29:04,608 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 2025-06-23 02:29:04,608 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 2025-06-23 02:29:04,687 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\Tar59D9.tmp 2025-06-23 02:29:04,780 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\Tar5A38.tmp 2025-06-23 02:29:04,937 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81B 2025-06-23 02:29:04,937 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81B 2025-06-23 02:29:05,062 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3 2025-06-23 02:29:05,078 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3 2025-06-23 02:29:05,155 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\349D186F1CB5682FA0194D4F3754EF36_320C97D80B18D9AAD99710A56CE7FDB7 2025-06-23 02:29:05,155 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\349D186F1CB5682FA0194D4F3754EF36_320C97D80B18D9AAD99710A56CE7FDB7 2025-06-23 02:29:29,453 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-23 02:29:29,858 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-23 02:29:29,875 [lib.api.process] INFO: Successfully terminated process with pid 1448. 2025-06-23 02:29:29,890 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5a38.tmp' does not exist, skip. 2025-06-23 02:29:29,905 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar59d9.tmp' does not exist, skip. 2025-06-23 02:29:29,905 [analyzer] INFO: Analysis completed.
2025-06-30 17:48:51,493 [cuckoo.core.scheduler] INFO: Task #6620418: acquired machine win7x6429 (label=win7x6429) 2025-06-30 17:48:51,495 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.229 for task #6620418 2025-06-30 17:48:51,774 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3223274 (interface=vboxnet0, host=192.168.168.229) 2025-06-30 17:48:52,331 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6429 2025-06-30 17:48:52,891 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6429 to vmcloak 2025-06-30 17:49:23,001 [cuckoo.core.guest] INFO: Starting analysis #6620418 on guest (id=win7x6429, ip=192.168.168.229) 2025-06-30 17:49:24,008 [cuckoo.core.guest] DEBUG: win7x6429: not ready yet 2025-06-30 17:49:29,042 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6429, ip=192.168.168.229) 2025-06-30 17:49:29,127 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6429, ip=192.168.168.229, monitor=latest, size=6660546) 2025-06-30 17:49:30,793 [cuckoo.core.resultserver] DEBUG: Task #6620418: live log analysis.log initialized. 2025-06-30 17:49:31,848 [cuckoo.core.resultserver] DEBUG: Task #6620418 is sending a BSON stream 2025-06-30 17:49:32,420 [cuckoo.core.resultserver] DEBUG: Task #6620418 is sending a BSON stream 2025-06-30 17:49:33,307 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'shots/0001.jpg' 2025-06-30 17:49:33,369 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 133392 2025-06-30 17:49:45,468 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6620418 still processing 2025-06-30 17:50:00,585 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6620418 still processing 2025-06-30 17:50:01,498 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'curtain/1750638569.72.curtain.log' 2025-06-30 17:50:01,500 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 36 2025-06-30 17:50:01,637 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'sysmon/1750638569.86.sysmon.xml' 2025-06-30 17:50:01,647 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'files/de3674e478dcc9d4_349d186f1cb5682fa0194d4f3754ef36_320c97d80b18d9aad99710a56ce7fdb7' 2025-06-30 17:50:01,651 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 532 2025-06-30 17:50:01,653 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 660218 2025-06-30 17:50:01,659 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'files/4c847e0c28733ed3_94308059b57b3142e455b38a6eb92015' 2025-06-30 17:50:01,662 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'files/7dc3fde8ec643b5f_0da515f703bb9b49479e8697adb0b955_4136d3715888e22d65ebe484b233d81b' 2025-06-30 17:50:01,664 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 1443 2025-06-30 17:50:01,665 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 73513 2025-06-30 17:50:01,667 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'files/23746e9a168f8423_b039fea45cb4cc4bbacfc013c7c55604_50d7940d5d3fedd8634d83074c7a46a3' 2025-06-30 17:50:01,670 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 1432 2025-06-30 17:50:01,671 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'files/9fdbb879db48be3c_94308059b57b3142e455b38a6eb92015' 2025-06-30 17:50:01,673 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 344 2025-06-30 17:50:01,675 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'files/949b7ef3743f9d41_349d186f1cb5682fa0194d4f3754ef36_320c97d80b18d9aad99710a56ce7fdb7' 2025-06-30 17:50:01,677 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 1432 2025-06-30 17:50:01,679 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'files/1cee9341a4af959c_0da515f703bb9b49479e8697adb0b955_4136d3715888e22d65ebe484b233d81b' 2025-06-30 17:50:01,681 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 508 2025-06-30 17:50:01,684 [cuckoo.core.resultserver] DEBUG: Task #6620418: File upload for 'files/e935e742d2e42471_b039fea45cb4cc4bbacfc013c7c55604_50d7940d5d3fedd8634d83074c7a46a3' 2025-06-30 17:50:01,685 [cuckoo.core.resultserver] DEBUG: Task #6620418 uploaded file length: 506 2025-06-30 17:50:02,271 [cuckoo.core.resultserver] DEBUG: Task #6620418 had connection reset for <Context for LOG> 2025-06-30 17:50:03,600 [cuckoo.core.guest] INFO: win7x6429: analysis completed successfully 2025-06-30 17:50:03,615 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-30 17:50:03,656 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-30 17:50:04,425 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6429 to path /srv/cuckoo/cwd/storage/analyses/6620418/memory.dmp 2025-06-30 17:50:04,426 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6429 2025-06-30 17:50:37,798 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.229 for task #6620418 2025-06-30 17:50:38,127 [cuckoo.core.scheduler] DEBUG: Released database task #6620418 2025-06-30 17:50:38,150 [cuckoo.core.scheduler] INFO: Task #6620418: analysis procedure completed
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Create or check mutex | rule | win_mutex | ||||||
description | Affect system registries | rule | win_registry |
section | .bak |
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0000d000', u'entropy': 7.041146031576513, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.04114603158 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0000f000', u'entropy': 7.08476838328402, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.08476838328 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00011000', u'entropy': 7.1116902099360315, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.11169020994 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00013000', u'entropy': 7.0615292398348775, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.06152923983 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00015000', u'entropy': 6.967131128970679, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 6.96713112897 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00017000', u'entropy': 6.8710090098653795, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 6.87100900987 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00019000', u'entropy': 7.015041780638179, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.01504178064 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0001b000', u'entropy': 7.003312252540721, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.00331225254 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0001d000', u'entropy': 7.092246050156893, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.09224605016 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0001f000', u'entropy': 6.956515834401943, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 6.9565158344 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00021000', u'entropy': 7.040209218888911, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.04020921889 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00023000', u'entropy': 7.087318420003481, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.08731842 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00025000', u'entropy': 7.11318831816698, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.11318831817 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00027000', u'entropy': 6.994113705957831, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 6.99411370596 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00029000', u'entropy': 7.099994086003486, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.099994086 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0002b000', u'entropy': 7.116428142428323, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.11642814243 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0002d000', u'entropy': 6.923338258779091, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 6.92333825878 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0002f000', u'entropy': 7.127283217928167, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.12728321793 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00031000', u'entropy': 7.092532313257827, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.09253231326 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00033000', u'entropy': 7.129403122603969, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.1294031226 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00035000', u'entropy': 7.094896789350792, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.09489678935 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00037000', u'entropy': 7.078469988047547, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.07846998805 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00039000', u'entropy': 7.046347836768366, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.04634783677 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0003b000', u'entropy': 7.0196141363385, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.01961413634 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0003d000', u'entropy': 7.0381196923042015, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.0381196923 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0003f000', u'entropy': 7.007460769440625, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.00746076944 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00041000', u'entropy': 6.829688418309309, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 6.82968841831 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00043000', u'entropy': 7.152740029355966, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.15274002936 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00045000', u'entropy': 7.131984766479759, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.13198476648 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00047000', u'entropy': 7.040222001908318, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.04022200191 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00049000', u'entropy': 6.9414176380176285, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 6.94141763802 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0004b000', u'entropy': 7.124103152273211, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.12410315227 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0004d000', u'entropy': 7.072179055323193, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.07217905532 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0004f000', u'entropy': 7.11120527138718, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.11120527139 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00051000', u'entropy': 7.1031682053047955, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.1031682053 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00053000', u'entropy': 7.075511878698271, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.0755118787 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00055000', u'entropy': 7.0925191844918904, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.09251918449 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00057000', u'entropy': 7.04055479143368, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.04055479143 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00059000', u'entropy': 7.08000563424642, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.08000563425 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0005b000', u'entropy': 7.126016363095404, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.1260163631 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0005d000', u'entropy': 7.030526800802326, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.0305268008 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0005f000', u'entropy': 7.062705280595525, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.0627052806 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00061000', u'entropy': 7.103509951846473, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.10350995185 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00063000', u'entropy': 7.117401841622544, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.11740184162 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00065000', u'entropy': 7.110940090339388, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.11094009034 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00067000', u'entropy': 7.116454477979576, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.11645447798 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00069000', u'entropy': 7.136620836368478, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.13662083637 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0006b000', u'entropy': 7.12147160674209, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.12147160674 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0006d000', u'entropy': 7.092232891823498, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.09223289182 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x0006f000', u'entropy': 7.071516006068809, u'name': u'.bak', u'virtual_size': u'0x00001903'} | entropy | 7.07151600607 | description | A section with a high entropy has been found |
Process injection | Process 1448 manipulating memory of non-child process 1448 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\B1BC968BD4F49D622AA89A81F2150152A41D829C\Blob |
G Data Antivirus (Windows) | Virus: Gen:Trojan.ProcessHijack.Z81@aqItpcki (Engine A), Win32.Trojan.PSE.16KWR3G (Engine B) |
C4S ClamAV (Linux) | Win.Dropper.C7c49bf-6974351-1 |
Trellix (Linux) | Packed-FAQ |
WithSecure (Linux) | Trojan.TR/Patched.Gen |
eScan Antivirus (Linux) | Gen:Trojan.ProcessHijack.Z81@aqItpcki(DB) |
ESET Security (Windows) | a variant of Win32/Patched.IW trojan |
Sophos Anti-Virus (Linux) | Troj/Patched-BS |
DrWeb Antivirus (Linux) | Win32.HLLP.Siggen.54 |
ClamAV (Linux) | Win.Dropper.C7c49bf-6974351-1 |
Bitdefender Antivirus (Linux) | Gen:Trojan.ProcessHijack.Z81@aqItpcki |
Kaspersky Standard (Windows) | HEUR:Exploit.Win32.Shellcode.gen |
Emsisoft Commandline Scanner (Windows) | Gen:Trojan.ProcessHijack.Z81@aqItpcki (B) |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Diple.3!c |
tehtris | Generic.Malware |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Trojan.Ghanarava.175061689916e2dd |
Skyhigh | BehavesLike.Win32.Generic.cc |
ALYac | Gen:Trojan.ProcessHijack.Z81@aqItpcki |
Cylance | Unsafe |
VIPRE | Gen:Trojan.ProcessHijack.Z81@aqItpcki |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_100% (W) |
BitDefender | Gen:Trojan.ProcessHijack.Z81@aqItpcki |
K7GW | Trojan ( 0015dce31 ) |
K7AntiVirus | Trojan ( 0015dce31 ) |
Arcabit | Trojan.ProcessHijack.EBDB77 |
VirIT | Win32.Diple.AA |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/Patched.IW |
APEX | Malicious |
ClamAV | Win.Dropper.C7c49bf-6974351-1 |
Kaspersky | HEUR:Exploit.Win32.Shellcode.gen |
Alibaba | Virus:Win32/Obfuscated.1050 |
MicroWorld-eScan | Gen:Trojan.ProcessHijack.Z81@aqItpcki |
Rising | Trojan.Patch!1.B0CA (CLASSIC) |
Emsisoft | Gen:Trojan.ProcessHijack.Z81@aqItpcki (B) |
F-Secure | Trojan.TR/Patched.Gen |
DrWeb | Win32.HLLP.Siggen.54 |
Zillya | Dropper.Injector.Win32.84073 |
McAfeeD | Real Protect-LS!51A4486B194D |
Trapmine | malicious.high.ml.score |
CTX | exe.trojan.patched |
Sophos | Troj/Patched-BS |
SentinelOne | Static AI - Malicious PE |
Detected | |
Avira | TR/Patched.Gen |
Gridinsoft | Trojan.U.Downloader.sa |
Microsoft | Trojan:Win32/Diple.GMA!MTB |
ZoneAlarm | Troj/Patched-BS |
GData | Gen:Trojan.ProcessHijack.Z81@aqItpcki |
Varist | W32/S-c7c49bf4!Eldorado |
VBA32 | Trojan.Diple |
DeepInstinct | MALICIOUS |
Malwarebytes | Generic.Malware.AI.DDS |
Ikarus | Trojan.Win32.Patched |
Panda | Trj/Genetic.gen |
TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9Z |
Tencent | Virus.Win32.Diple.ka |
TrellixENS | Packed-FAQ!51A4486B194D |
huorong | Virus/Injwndproc.a |