Size | 224.4KB |
---|---|
Type | PE32+ executable (DLL) (GUI) x86-64, for MS Windows |
MD5 | 1f2fc894c994682a6ed537961c20b475 |
SHA1 | 5b7434102cf842eeab0cc779c64341b696b0a6dd |
SHA256 | a328d12f9109c07294bdc1100f39dd36ed81bf7405769e8f2224d3c3995d3fa8 |
SHA512 |
c8ece2b18636b86c1441a6f4ef2c5603ca341398d69b27756a301e03d9bd112dc30c8ff4624dab91d8ff915edfd2bc818b070999fee3e7d7dcb85021342401a7
|
CRC32 | D7ED5E56 |
ssdeep | None |
PDB Path | jdwp.pdb |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 27, 2025, 1:45 p.m. | June 27, 2025, 1:51 p.m. | 362 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-27 13:42:51,000 [analyzer] DEBUG: Starting analyzer from: C:\tmptisd8w 2025-06-27 13:42:51,000 [analyzer] DEBUG: Pipe server name: \??\PIPE\wCNtTigojRcvYwEtUlvX 2025-06-27 13:42:51,000 [analyzer] DEBUG: Log pipe server name: \??\PIPE\dRhfhUYJSKxfrEYFJs 2025-06-27 13:42:51,265 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-27 13:42:51,265 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-27 13:42:51,733 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-27 13:42:51,937 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-06-27 13:42:51,937 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-27 13:42:51,937 [analyzer] DEBUG: Started auxiliary module Human 2025-06-27 13:42:51,937 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-27 13:42:51,937 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-27 13:42:52,000 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-27 13:42:52,000 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-27 13:42:52,000 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-27 13:42:52,000 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-27 13:42:52,046 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\jdwp.dll' with arguments ['bin\\inject-x64.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\jdwp.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x64.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\jdwp.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
2025-06-27 13:45:16,799 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:17,883 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:18,937 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:19,996 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:21,069 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:22,127 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:23,150 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:24,429 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:26,017 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:27,066 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:28,110 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:29,164 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:30,209 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:31,527 [cuckoo.core.scheduler] DEBUG: Task #6638162: no machine available yet 2025-06-27 13:45:32,629 [cuckoo.core.scheduler] INFO: Task #6638162: acquired machine win7x647 (label=win7x647) 2025-06-27 13:45:32,636 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.207 for task #6638162 2025-06-27 13:45:33,134 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 398457 (interface=vboxnet0, host=192.168.168.207) 2025-06-27 13:45:33,462 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x647 2025-06-27 13:45:34,245 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x647 to vmcloak 2025-06-27 13:49:14,315 [cuckoo.core.guest] INFO: Starting analysis #6638162 on guest (id=win7x647, ip=192.168.168.207) 2025-06-27 13:49:15,321 [cuckoo.core.guest] DEBUG: win7x647: not ready yet 2025-06-27 13:49:20,345 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x647, ip=192.168.168.207) 2025-06-27 13:49:20,529 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x647, ip=192.168.168.207, monitor=latest, size=6660546) 2025-06-27 13:49:21,710 [cuckoo.core.resultserver] DEBUG: Task #6638162: live log analysis.log initialized. 2025-06-27 13:49:22,607 [cuckoo.core.resultserver] DEBUG: Task #6638162 is sending a BSON stream 2025-06-27 13:49:23,854 [cuckoo.core.resultserver] DEBUG: Task #6638162: File upload for 'shots/0001.jpg' 2025-06-27 13:49:23,876 [cuckoo.core.resultserver] DEBUG: Task #6638162 uploaded file length: 133491 2025-06-27 13:49:24,352 [cuckoo.core.guest] WARNING: win7x647: analysis #6638162 caught an exception Traceback (most recent call last): File "C:/tmptisd8w/analyzer.py", line 824, in <module> success = analyzer.run() File "C:/tmptisd8w/analyzer.py", line 673, in run pids = self.package.start(self.target) File "C:\tmptisd8w\modules\packages\exe.py", line 34, in start return self.execute(path, args=shlex.split(args)) File "C:\tmptisd8w\lib\common\abstracts.py", line 205, in execute "Unable to execute the initial process, analysis aborted." CuckooPackageError: Unable to execute the initial process, analysis aborted. 2025-06-27 13:49:24,366 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-27 13:49:24,397 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-27 13:49:25,759 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x647 to path /srv/cuckoo/cwd/storage/analyses/6638162/memory.dmp 2025-06-27 13:49:25,760 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x647 2025-06-27 13:51:17,009 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.207 for task #6638162 2025-06-27 13:51:17,015 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6638162 2025-06-27 13:51:17,931 [cuckoo.core.scheduler] DEBUG: Released database task #6638162 2025-06-27 13:51:17,950 [cuckoo.core.scheduler] INFO: Task #6638162: analysis procedure completed
description | Checks if being debugged | rule | anti_dbg |
pdb_path | jdwp.pdb |