Size | 72.9MB |
---|---|
Type | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {D11D1A01-F475-44D2-BE71-0120E9530948}, Number of Words: 10, Subject: Kroqoul Civil Tools, Author: Werqos Livina, Name of Creating Application: Kroqoul Civil Tools, Template: x64;1033, Comments: This installer database contains the logic and data required to install Kroqoul Civil Tools., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Sun Jun 22 22:28:53 2025, Last Saved Time/Date: Sun Jun 22 22:28:53 2025, Last Printed: Sun Jun 22 22:28:53 2025, Number of Pages: 450 |
MD5 | ec36175fdada97232b695634192dd62e |
SHA1 | 137b9deae5e7822353ce4a2c2d576063c4c69c23 |
SHA256 | 0ed50d27280d82fc40effa6c72ce38b2fae60476a242f95f379fd5c13d537ca2 |
SHA512 |
a0ba063768d92a48f203cf220e5aeda6200f8740af41f95dfff8fd7fa96c3b9a013c526da9f6476ff2fa149d142918f5081f77b3fe5ab4e9ba1b2a663ba0be72
|
CRC32 | 7571EDC0 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 6.0 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 23, 2025, 2:27 p.m. | June 23, 2025, 2:34 p.m. | 442 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-23 14:27:08,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpsgyfoe 2025-06-23 14:27:08,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\wIQwcHhMgJORrKjE 2025-06-23 14:27:08,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\PkDkkTNjSnfepcUnEZNYzwGxH 2025-06-23 14:27:08,233 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-23 14:27:08,233 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-23 14:27:08,655 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-23 14:27:08,937 [analyzer] DEBUG: Loaded monitor into process with pid 516 2025-06-23 14:27:08,937 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-23 14:27:08,937 [analyzer] DEBUG: Started auxiliary module Human 2025-06-23 14:27:08,937 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-23 14:27:08,937 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-23 14:27:09,015 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-23 14:27:09,015 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-23 14:27:09,030 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-23 14:27:09,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-23 14:27:09,030 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-06-23 14:27:09,108 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\setup.msi.js'] and pid 2472 2025-06-23 14:27:09,328 [analyzer] DEBUG: Loaded monitor into process with pid 2472 2025-06-23 14:27:09,687 [analyzer] INFO: io=NULL 2025-06-23 14:27:09,687 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-06-23 14:27:09,687 [analyzer] INFO: io=NULL 2025-06-23 14:27:09,687 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-06-23 14:27:09,687 [analyzer] INFO: io=NULL 2025-06-23 14:27:09,687 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-06-23 14:27:09,733 [analyzer] INFO: io=NULL 2025-06-23 14:27:09,733 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-06-23 14:27:09,733 [analyzer] INFO: io=NULL 2025-06-23 14:27:09,733 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-06-23 14:27:09,733 [analyzer] INFO: io=NULL 2025-06-23 14:27:09,733 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-06-23 13:31:14,674 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-23 13:31:14,878 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2472. 2025-06-23 13:31:15,206 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-23 13:31:15,206 [lib.api.process] INFO: Successfully terminated process with pid 2472. 2025-06-23 13:31:15,206 [analyzer] INFO: Analysis completed.
2025-06-23 14:27:26,894 [cuckoo.core.scheduler] INFO: Task #6626298: acquired machine win7x6413 (label=win7x6413) 2025-06-23 14:27:26,898 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.213 for task #6626298 2025-06-23 14:27:27,400 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3884875 (interface=vboxnet0, host=192.168.168.213) 2025-06-23 14:27:27,445 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6413 2025-06-23 14:27:28,075 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6413 to vmcloak 2025-06-23 14:30:32,205 [cuckoo.core.guest] INFO: Starting analysis #6626298 on guest (id=win7x6413, ip=192.168.168.213) 2025-06-23 14:30:33,211 [cuckoo.core.guest] DEBUG: win7x6413: not ready yet 2025-06-23 14:30:38,234 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6413, ip=192.168.168.213) 2025-06-23 14:30:38,358 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6413, ip=192.168.168.213, monitor=latest, size=6660546) 2025-06-23 14:30:44,542 [cuckoo.core.resultserver] DEBUG: Task #6626298: live log analysis.log initialized. 2025-06-23 14:30:45,426 [cuckoo.core.resultserver] DEBUG: Task #6626298 is sending a BSON stream 2025-06-23 14:30:45,739 [cuckoo.core.resultserver] DEBUG: Task #6626298 is sending a BSON stream 2025-06-23 14:30:46,688 [cuckoo.core.resultserver] DEBUG: Task #6626298: File upload for 'shots/0001.jpg' 2025-06-23 14:30:46,713 [cuckoo.core.resultserver] DEBUG: Task #6626298 uploaded file length: 133570 2025-06-23 14:30:47,815 [cuckoo.core.resultserver] DEBUG: Task #6626298: File upload for 'shots/0002.jpg' 2025-06-23 14:30:47,830 [cuckoo.core.resultserver] DEBUG: Task #6626298 uploaded file length: 136653 2025-06-23 14:31:00,183 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6626298 still processing 2025-06-23 14:31:14,997 [cuckoo.core.resultserver] DEBUG: Task #6626298: File upload for 'curtain/1750678274.99.curtain.log' 2025-06-23 14:31:15,001 [cuckoo.core.resultserver] DEBUG: Task #6626298 uploaded file length: 36 2025-06-23 14:31:15,196 [cuckoo.core.resultserver] DEBUG: Task #6626298: File upload for 'sysmon/1750678275.19.sysmon.xml' 2025-06-23 14:31:15,211 [cuckoo.core.resultserver] DEBUG: Task #6626298 uploaded file length: 1198374 2025-06-23 14:31:15,550 [cuckoo.core.guest] INFO: win7x6413: analysis completed successfully 2025-06-23 14:31:15,570 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-23 14:31:15,605 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-23 14:31:15,823 [cuckoo.core.resultserver] DEBUG: Task #6626298: File upload for 'shots/0003.jpg' 2025-06-23 14:31:15,839 [cuckoo.core.resultserver] DEBUG: Task #6626298 uploaded file length: 133562 2025-06-23 14:31:15,850 [cuckoo.core.resultserver] DEBUG: Task #6626298 had connection reset for <Context for LOG> 2025-06-23 14:31:16,758 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6413 to path /srv/cuckoo/cwd/storage/analyses/6626298/memory.dmp 2025-06-23 14:31:16,759 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6413 2025-06-23 14:34:45,898 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.213 for task #6626298 2025-06-23 14:34:46,305 [cuckoo.core.scheduler] DEBUG: Released database task #6626298 2025-06-23 14:34:46,319 [cuckoo.core.scheduler] INFO: Task #6626298: analysis procedure completed
description | Matched shellcode byte patterns | rule | shellcode | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Anti-Sandbox checks for ThreatExpert | rule | antisb_threatExpert | ||||||
description | Disable AntiVirus | rule | disable_antivirus | ||||||
description | Communications over HTTP | rule | network_http | ||||||
description | Communications over RAW socket | rule | network_tcp_socket | ||||||
description | Escalade priviledges | rule | escalate_priv | ||||||
description | Take screenshot | rule | screenshot |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Kaspersky Standard (Windows) | Trojan.BAT.Agent.cno |
Kaspersky | Trojan.BAT.Agent.cno |
Ikarus | Trojan-Spy.Rat |