Size | 17.4KB |
---|---|
Type | PE32+ executable (DLL) (console) x86-64, for MS Windows |
MD5 | 3b7f628a88c7fd51a3897f82261b06e7 |
SHA1 | 7a9a0117bf988c1d57ced7e4ff1280d699f765df |
SHA256 | 64dcc0aba701234350a873ed14c442274145e813f2c8ae334e40465cf3e7a800 |
SHA512 |
d6590078b21ed93a379dc5733e21c57e3cbba8bd7c6ef412f0541ee55473064380029a0510dff96f88dd47bfea51718e2f70ed0bc941082597ee1c883a612bd4
|
CRC32 | 909BCED4 |
ssdeep | None |
PDB Path | api-ms-win-crt-convert-l1-1-0.pdb |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 27, 2025, 1:55 p.m. | June 27, 2025, 2:02 p.m. | 423 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-27 13:42:52,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpwoh6zt 2025-06-27 13:42:52,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\RUjkSSIhUixlJTKIRIYTxTcvjUSLwQ 2025-06-27 13:42:52,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\GobTsSPSWzdzObdKqavvxhIAdd 2025-06-27 13:42:52,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-27 13:42:52,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-27 13:42:52,828 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-27 13:42:53,078 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-06-27 13:42:53,078 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-27 13:42:53,078 [analyzer] DEBUG: Started auxiliary module Human 2025-06-27 13:42:53,078 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-27 13:42:53,092 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-27 13:42:53,217 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-27 13:42:53,217 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-27 13:42:53,233 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-27 13:42:53,233 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-27 13:42:53,280 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\api-ms-win-crt-convert-l1-1-0.dll' with arguments ['bin\\inject-x64.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\api-ms-win-crt-convert-l1-1-0.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x64.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\api-ms-win-crt-convert-l1-1-0.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
2025-06-27 13:56:00,454 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:01,481 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:02,506 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:03,541 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:04,814 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:06,205 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:07,241 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:08,484 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:09,613 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:10,740 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:11,832 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:13,163 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:14,637 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:15,998 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:17,213 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:18,500 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:19,781 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:21,843 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:22,993 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:24,406 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:25,464 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:26,763 [cuckoo.core.scheduler] DEBUG: Task #6638211: no machine available yet 2025-06-27 13:56:27,813 [cuckoo.core.scheduler] INFO: Task #6638211: acquired machine win7x643 (label=win7x643) 2025-06-27 13:56:27,814 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.203 for task #6638211 2025-06-27 13:56:28,323 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 424342 (interface=vboxnet0, host=192.168.168.203) 2025-06-27 13:56:28,433 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x643 2025-06-27 13:56:29,248 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x643 to vmcloak 2025-06-27 13:59:07,303 [cuckoo.core.guest] INFO: Starting analysis #6638211 on guest (id=win7x643, ip=192.168.168.203) 2025-06-27 13:59:08,309 [cuckoo.core.guest] DEBUG: win7x643: not ready yet 2025-06-27 13:59:13,338 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x643, ip=192.168.168.203) 2025-06-27 13:59:13,441 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x643, ip=192.168.168.203, monitor=latest, size=6660546) 2025-06-27 13:59:14,809 [cuckoo.core.resultserver] DEBUG: Task #6638211: live log analysis.log initialized. 2025-06-27 13:59:15,827 [cuckoo.core.resultserver] DEBUG: Task #6638211 is sending a BSON stream 2025-06-27 13:59:17,184 [cuckoo.core.resultserver] DEBUG: Task #6638211: File upload for 'shots/0001.jpg' 2025-06-27 13:59:17,199 [cuckoo.core.resultserver] DEBUG: Task #6638211 uploaded file length: 133465 2025-06-27 13:59:17,260 [cuckoo.core.guest] WARNING: win7x643: analysis #6638211 caught an exception Traceback (most recent call last): File "C:/tmpwoh6zt/analyzer.py", line 824, in <module> success = analyzer.run() File "C:/tmpwoh6zt/analyzer.py", line 673, in run pids = self.package.start(self.target) File "C:\tmpwoh6zt\modules\packages\exe.py", line 34, in start return self.execute(path, args=shlex.split(args)) File "C:\tmpwoh6zt\lib\common\abstracts.py", line 205, in execute "Unable to execute the initial process, analysis aborted." CuckooPackageError: Unable to execute the initial process, analysis aborted. 2025-06-27 13:59:17,276 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-27 13:59:17,299 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-27 13:59:18,623 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x643 to path /srv/cuckoo/cwd/storage/analyses/6638211/memory.dmp 2025-06-27 13:59:18,625 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x643 2025-06-27 14:02:52,852 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.203 for task #6638211 2025-06-27 14:02:52,857 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6638211 2025-06-27 14:02:53,529 [cuckoo.core.scheduler] DEBUG: Released database task #6638211 2025-06-27 14:02:53,552 [cuckoo.core.scheduler] INFO: Task #6638211: analysis procedure completed
pdb_path | api-ms-win-crt-convert-l1-1-0.pdb |