Size | 689.2KB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 21692d5eecf0d91e172116501d9fe245 |
SHA1 | be1bb1e6a24cc6ae7eb579f3dfb8239f0b3b9530 |
SHA256 | d764e1aff665cb8b94ff88c461888239fea5604a35b915a67481afc58be07896 |
SHA512 |
38c27a3bd451d271dfff3f94c051da81dba2ae75622ad3e7fe7157b71161b052db8b196acc6184da482df5427061bebf1b403b650197e00e7684fc551b50efb9
|
CRC32 | CE9B4D65 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 5, 2025, 10:42 a.m. | July 5, 2025, 10:50 a.m. | 463 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-30 18:02:30,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpd0os1j 2025-06-30 18:02:30,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\MkSosmwNXOkVqEqtCKamGN 2025-06-30 18:02:30,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\VwmOSqKLHlMUAWOyEpqldtXUlMAlv 2025-06-30 18:02:30,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-06-30 18:02:30,108 [analyzer] INFO: Automatically selected analysis package "exe" 2025-06-30 18:02:30,390 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-30 18:02:30,390 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-30 18:02:30,780 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-30 18:02:31,000 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-06-30 18:02:31,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-30 18:02:31,000 [analyzer] DEBUG: Started auxiliary module Human 2025-06-30 18:02:31,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-30 18:02:31,000 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-30 18:02:31,062 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-30 18:02:31,062 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-30 18:02:31,062 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-30 18:02:31,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-30 18:02:31,250 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe' with arguments '' and pid 1628 2025-06-30 18:02:31,421 [analyzer] DEBUG: Loaded monitor into process with pid 1628 2025-06-30 18:02:31,562 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Windowsd50l2bvpd8 2025-06-30 18:02:31,640 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Common Files\Microsoft Shared\black qtcr1re ni0p0dq8 9w4xilz6j2 .mpg.exe 2025-06-30 18:02:31,890 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\DVD Maker\Shared\h3ps6tmu mkx87b [bangbus] titts v14bqy5ueys (Jade,Karin).mpg.exe 2025-06-30 18:02:32,265 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Microsoft Office\Templates\jspx4i 76qp9o6j jbp79p wifey .rar.exe 2025-06-30 18:02:32,296 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\t1apup6 hot (!) latex .zip.exe 2025-06-30 18:02:32,390 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Windows Journal\Templates\3lhg1q chkaba9s0 g28gx7w6vur32j .rar.exe 2025-06-30 18:02:32,530 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Windows Sidebar\Shared Gadgets\u8ywwbo t1apup6 uncut ct48q6s .zip.exe 2025-06-30 18:02:32,562 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\3lhg1q q0vgw72 g28gx7w6vur32j .avi.exe 2025-06-30 18:02:32,671 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files (x86)\Common Files\microsoft shared\r2bdcnb q0vgw72 2e032zbb avhkl4osfi1b1 (l0p693,l0p693).zip.exe 2025-06-30 18:02:32,983 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\chkaba9s0 sperm 2e032zbb avhkl4osfi1b1 .mpg.exe 2025-06-30 18:02:33,078 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\RAC\Temp\wiya6rsl beast 2eoamoy big .avi.exe 2025-06-30 18:02:33,125 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Search\Data\Temp\black 76qp9o6j 2e032zbb hotel (Sonja).rar.exe 2025-06-30 18:02:33,187 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Windows\Templates\0ymg8tq 2eoamoy nk2tll hole .mpg.exe 2025-06-30 18:02:33,265 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Windows\Templates\0ymg8tq horse jspx4i nugdmg18bgxp .mpg.exe 2025-06-30 18:02:33,655 [analyzer] INFO: Injected into process with pid 2108 and name '' 2025-06-30 18:02:33,796 [analyzer] INFO: Added new file to list with pid 1628 and path C:\tmpd0os1j\2wr8ay1 cum jbp79p .zip.exe 2025-06-30 18:02:33,828 [analyzer] DEBUG: Loaded monitor into process with pid 2108 2025-06-30 18:02:33,905 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\0ymg8tq porn hot (!) ash (Jenna).mpg.exe 2025-06-30 18:02:34,000 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Local\Temp\chkaba9s0 nugdmg18bgxp boobs 55svezg .rar.exe 2025-06-30 18:02:34,046 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\qtcr1re uncut (Sonja).zip.exe 2025-06-30 18:02:34,078 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\ibxj3s2 ibxj3s2 hot (!) p834ynn (Sonja,Liz).mpeg.exe 2025-06-30 18:02:34,296 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\0516z8ivf q0vgw72 girls legs .avi.exe 2025-06-30 18:02:34,405 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\3o9e0ag1 horse l6ppef ibxj3s2 ct48q6s .zip.exe 2025-06-30 18:02:34,500 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\asian porn hot (!) cock wifey (wrtdiha,Sonja).avi.exe 2025-06-30 18:02:34,592 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\RAC\Temp\0516z8ivf horse xxx 2e032zbb balls .mpg.exe 2025-06-30 18:02:34,640 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Search\Data\Temp\horse c4ou4r0 ni0p0dq8 50+ .rar.exe 2025-06-30 18:02:34,717 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Windows\Templates\wiya6rsl ibxj3s2 i4caruo hole u3nxpdd .zip.exe 2025-06-30 18:02:34,765 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Windows\Templates\0516z8ivf t1apup6 i4caruo ofok9a 63k9qbq9xg (1bcw83k).mpeg.exe 2025-06-30 18:02:34,796 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\y3hndyq mkx87b [free] ct48q6s .mpeg.exe 2025-06-30 18:02:34,812 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\u8ywwbo v8jedw8 big (Jade,e6rl5yo1).zip.exe 2025-06-30 18:02:34,858 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\mkx87b jspx4i i4caruo hairy (x8z5ka).mpeg.exe 2025-06-30 18:02:34,890 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\ar164nb horse [milf] avhkl4osfi1b1 (Karin).avi.exe 2025-06-30 18:02:35,000 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\98edvx c4ou4r0 t1apup6 2e032zbb wifey (ihcwxtl,ydezx1cz6).mpeg.exe 2025-06-30 18:02:35,030 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\nude mgdo94z3fb2 ibxj3s2 (Sandy).zip.exe 2025-06-30 18:05:50,250 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-30 18:05:51,421 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-30 18:05:51,421 [lib.api.process] INFO: Successfully terminated process with pid 1628. 2025-06-30 18:05:51,421 [lib.api.process] INFO: Successfully terminated process with pid 2108. 2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\roaming\microsoft\windows\templates\asian porn hot (!) cock wifey (wrtdiha,sonja).avi.exe 2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\programdata\microsoft\windows\templates\0516z8ivf t1apup6 i4caruo ofok9a 63k9qbq9xg (1bcw83k).mpeg.exe 2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\users\default\appdata\local\microsoft\windows\temporary internet files\y3hndyq mkx87b [free] ct48q6s .mpeg.exe 2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\chkaba9s0 nugdmg18bgxp boobs 55svezg .rar.exe 2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\program files (x86)\windows sidebar\shared gadgets\chkaba9s0 sperm 2e032zbb avhkl4osfi1b1 .mpg.exe 2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\windows\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\nude mgdo94z3fb2 ibxj3s2 (sandy).zip.exe 2025-06-30 18:05:52,046 [analyzer] INFO: Analysis completed.
2025-07-05 10:42:39,782 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:40,798 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:41,850 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:43,117 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:44,147 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:45,273 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:46,316 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:47,504 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:48,525 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:49,580 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:50,613 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:51,635 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:52,654 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:53,671 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:54,802 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:55,819 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:56,842 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:57,863 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:58,880 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:42:59,907 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:43:00,933 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet 2025-07-05 10:43:01,961 [cuckoo.core.scheduler] INFO: Task #6650108: acquired machine win7x6429 (label=win7x6429) 2025-07-05 10:43:01,962 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.229 for task #6650108 2025-07-05 10:43:02,412 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3377853 (interface=vboxnet0, host=192.168.168.229) 2025-07-05 10:43:06,949 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6429 2025-07-05 10:43:14,366 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6429 to vmcloak 2025-07-05 10:44:59,682 [cuckoo.core.guest] INFO: Starting analysis #6650108 on guest (id=win7x6429, ip=192.168.168.229) 2025-07-05 10:45:00,688 [cuckoo.core.guest] DEBUG: win7x6429: not ready yet 2025-07-05 10:45:05,711 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6429, ip=192.168.168.229) 2025-07-05 10:45:05,913 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6429, ip=192.168.168.229, monitor=latest, size=6660546) 2025-07-05 10:45:07,154 [cuckoo.core.resultserver] DEBUG: Task #6650108: live log analysis.log initialized. 2025-07-05 10:45:08,102 [cuckoo.core.resultserver] DEBUG: Task #6650108 is sending a BSON stream 2025-07-05 10:45:08,509 [cuckoo.core.resultserver] DEBUG: Task #6650108 is sending a BSON stream 2025-07-05 10:45:09,331 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'shots/0001.jpg' 2025-07-05 10:45:09,467 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 133401 2025-07-05 10:45:10,959 [cuckoo.core.resultserver] DEBUG: Task #6650108 is sending a BSON stream 2025-07-05 10:45:21,870 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:45:36,986 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:45:52,207 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:46:07,583 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:46:22,972 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:46:38,341 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:46:53,542 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:47:08,969 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:47:24,174 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:47:39,411 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:47:54,760 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:48:09,932 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:48:25,320 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing 2025-07-05 10:48:27,606 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'curtain/1751299550.44.curtain.log' 2025-07-05 10:48:27,610 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 36 2025-07-05 10:48:28,513 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'sysmon/1751299551.34.sysmon.xml' 2025-07-05 10:48:28,592 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 12936968 2025-07-05 10:48:28,614 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/0470d82bc8bfdeb6_3o9e0ag1 horse l6ppef ibxj3s2 ct48q6s .zip.exe' 2025-07-05 10:48:28,622 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1200197 2025-07-05 10:48:28,643 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/8d0837074c3cda08_0516z8ivf horse xxx 2e032zbb balls .mpg.exe' 2025-07-05 10:48:28,675 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 2161613 2025-07-05 10:48:28,698 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/ba2f0b2e24150172_ar164nb horse [milf] avhkl4osfi1b1 (karin).avi.exe' 2025-07-05 10:48:28,715 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 2065662 2025-07-05 10:48:28,721 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/398058dfdc2f399b_2wr8ay1 cum jbp79p .zip.exe' 2025-07-05 10:48:28,726 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 440062 2025-07-05 10:48:28,729 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/89b6a8091b66206e_t1apup6 hot (!) latex .zip.exe' 2025-07-05 10:48:28,733 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 296556 2025-07-05 10:48:28,737 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/c1fe38bec2fb59ed_ibxj3s2 ibxj3s2 hot (!) p834ynn (sonja,liz).mpeg.exe' 2025-07-05 10:48:28,742 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 550858 2025-07-05 10:48:28,754 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/3499ee92f7dc109a_3lhg1q chkaba9s0 g28gx7w6vur32j .rar.exe' 2025-07-05 10:48:28,770 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1845360 2025-07-05 10:48:28,777 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/e9cf85ed13c0d0e1_3lhg1q q0vgw72 g28gx7w6vur32j .avi.exe' 2025-07-05 10:48:28,782 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 556596 2025-07-05 10:48:28,793 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/c7afa6a34a3b1435_black 76qp9o6j 2e032zbb hotel (sonja).rar.exe' 2025-07-05 10:48:28,804 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1335572 2025-07-05 10:48:28,818 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/21ea0bb50765f6ac_h3ps6tmu mkx87b [bangbus] titts v14bqy5ueys (jade,karin).mpg.exe' 2025-07-05 10:48:28,834 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1672256 2025-07-05 10:48:28,857 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/fd8096f9788a7831_wiya6rsl beast 2eoamoy big .avi.exe' 2025-07-05 10:48:28,878 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 2149659 2025-07-05 10:48:28,895 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/fbc2007d389e94ed_u8ywwbo t1apup6 uncut ct48q6s .zip.exe' 2025-07-05 10:48:28,905 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1355426 2025-07-05 10:48:28,921 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/e886e825d6c2bd4b_windowsd50l2bvpd8' 2025-07-05 10:48:28,929 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1207847 2025-07-05 10:48:28,935 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/5dbab55a98953219_u8ywwbo v8jedw8 big (jade,e6rl5yo1).zip.exe' 2025-07-05 10:48:28,938 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 223384 2025-07-05 10:48:28,960 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/175bdc430c6ff2de_qtcr1re uncut (sonja).zip.exe' 2025-07-05 10:48:28,981 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 2081017 2025-07-05 10:48:28,997 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/969b3801f0e01481_98edvx c4ou4r0 t1apup6 2e032zbb wifey (ihcwxtl,ydezx1cz6).mpeg.exe' 2025-07-05 10:48:29,045 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1388542 2025-07-05 10:48:29,053 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/b72820f0e3708312_wiya6rsl ibxj3s2 i4caruo hole u3nxpdd .zip.exe' 2025-07-05 10:48:29,062 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 474674 2025-07-05 10:48:29,065 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/b55bca2f1227d91e_0ymg8tq horse jspx4i nugdmg18bgxp .mpg.exe' 2025-07-05 10:48:29,069 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 384746 2025-07-05 10:48:29,071 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/f1ea393f1bb057c4_0ymg8tq porn hot (!) ash (jenna).mpg.exe' 2025-07-05 10:48:29,080 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/238714fa6800ce16_horse c4ou4r0 ni0p0dq8 50+ .rar.exe' 2025-07-05 10:48:29,083 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 863240 2025-07-05 10:48:29,099 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/fd0dda8b07a1b83f_black qtcr1re ni0p0dq8 9w4xilz6j2 .mpg.exe' 2025-07-05 10:48:29,102 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 275547 2025-07-05 10:48:29,120 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1925020 2025-07-05 10:48:29,127 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/0489ace2f44d993c_0516z8ivf q0vgw72 girls legs .avi.exe' 2025-07-05 10:48:29,131 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 400376 2025-07-05 10:48:29,140 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/9778db61c723f20f_r2bdcnb q0vgw72 2e032zbb avhkl4osfi1b1 (l0p693,l0p693).zip.exe' 2025-07-05 10:48:29,148 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1097375 2025-07-05 10:48:29,167 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/bf564d941eb5bd0e_0ymg8tq 2eoamoy nk2tll hole .mpg.exe' 2025-07-05 10:48:29,183 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1853943 2025-07-05 10:48:29,193 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/c99fd37a8caec7c5_jspx4i 76qp9o6j jbp79p wifey .rar.exe' 2025-07-05 10:48:29,203 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 917115 2025-07-05 10:48:29,207 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/91766c571209cb7c_mkx87b jspx4i i4caruo hairy (x8z5ka).mpeg.exe' 2025-07-05 10:48:29,217 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 778201 2025-07-05 10:48:29,232 [cuckoo.core.resultserver] DEBUG: Task #6650108 had connection reset for <Context for LOG> 2025-07-05 10:48:31,380 [cuckoo.core.guest] INFO: win7x6429: analysis completed successfully 2025-07-05 10:48:31,397 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-05 10:48:31,425 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-05 10:48:32,533 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6429 to path /srv/cuckoo/cwd/storage/analyses/6650108/memory.dmp 2025-07-05 10:48:32,534 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6429 2025-07-05 10:50:22,727 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.229 for task #6650108 2025-07-05 10:50:23,090 [cuckoo.core.scheduler] DEBUG: Released database task #6650108 2025-07-05 10:50:23,112 [cuckoo.core.scheduler] INFO: Task #6650108: analysis procedure completed
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | Create or check mutex | rule | win_mutex | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect private profile | rule | win_files_operation |
packer | Pelles C 3.00, 4.00, 4.50 EXE (X86 CRT-LIB) |
file | C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\chkaba9s0 sperm 2e032zbb avhkl4osfi1b1 .mpg.exe |
file | C:\Users\All Users\Templates\0516z8ivf t1apup6 i4caruo ofok9a 63k9qbq9xg (1bcw83k).mpeg.exe |
file | C:\Users\Administrator\AppData\Local\Temp\chkaba9s0 nugdmg18bgxp boobs 55svezg .rar.exe |
file | C:\Program Files\DVD Maker\Shared\h3ps6tmu mkx87b [bangbus] titts v14bqy5ueys (Jade,Karin).mpg.exe |
file | C:\ProgramData\Microsoft\Search\Data\Temp\black 76qp9o6j 2e032zbb hotel (Sonja).rar.exe |
file | C:\Users\Administrator\Templates\asian porn hot (!) cock wifey (wrtdiha,Sonja).avi.exe |
file | C:\ProgramData\Templates\0ymg8tq horse jspx4i nugdmg18bgxp .mpg.exe |
file | C:\ProgramData\Microsoft\RAC\Temp\wiya6rsl beast 2eoamoy big .avi.exe |
file | C:\Users\All Users\Microsoft\RAC\Temp\0516z8ivf horse xxx 2e032zbb balls .mpg.exe |
file | C:\tmpd0os1j\2wr8ay1 cum jbp79p .zip.exe |
file | C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\t1apup6 hot (!) latex .zip.exe |
file | C:\Program Files\Common Files\Microsoft Shared\black qtcr1re ni0p0dq8 9w4xilz6j2 .mpg.exe |
file | C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\0516z8ivf q0vgw72 girls legs .avi.exe |
file | C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\qtcr1re uncut (Sonja).zip.exe |
file | C:\Users\Default\AppData\Local\Temporary Internet Files\u8ywwbo v8jedw8 big (Jade,e6rl5yo1).zip.exe |
file | C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\98edvx c4ou4r0 t1apup6 2e032zbb wifey (ihcwxtl,ydezx1cz6).mpeg.exe |
file | C:\Users\Administrator\AppData\Local\Temporary Internet Files\ibxj3s2 ibxj3s2 hot (!) p834ynn (Sonja,Liz).mpeg.exe |
file | C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\mkx87b jspx4i i4caruo hairy (x8z5ka).mpeg.exe |
file | C:\Program Files\Windows Sidebar\Shared Gadgets\u8ywwbo t1apup6 uncut ct48q6s .zip.exe |
file | C:\ProgramData\Microsoft\Windows\Templates\0ymg8tq 2eoamoy nk2tll hole .mpg.exe |
file | C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\y3hndyq mkx87b [free] ct48q6s .mpeg.exe |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\0ymg8tq porn hot (!) ash (Jenna).mpg.exe |
file | C:\Program Files\Windows Journal\Templates\3lhg1q chkaba9s0 g28gx7w6vur32j .rar.exe |
file | C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\nude mgdo94z3fb2 ibxj3s2 (Sandy).zip.exe |
file | C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\3lhg1q q0vgw72 g28gx7w6vur32j .avi.exe |
file | C:\Users\All Users\Microsoft\Search\Data\Temp\horse c4ou4r0 ni0p0dq8 50+ .rar.exe |
file | C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\3o9e0ag1 horse l6ppef ibxj3s2 ct48q6s .zip.exe |
file | C:\Program Files\Microsoft Office\Templates\jspx4i 76qp9o6j jbp79p wifey .rar.exe |
file | C:\Users\All Users\Microsoft\Windows\Templates\wiya6rsl ibxj3s2 i4caruo hole u3nxpdd .zip.exe |
file | C:\Users\Default\Templates\ar164nb horse [milf] avhkl4osfi1b1 (Karin).avi.exe |
file | C:\Program Files (x86)\Common Files\microsoft shared\r2bdcnb q0vgw72 2e032zbb avhkl4osfi1b1 (l0p693,l0p693).zip.exe |
file | C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\3o9e0ag1 horse l6ppef ibxj3s2 ct48q6s .zip.exe |
description | d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe tried to sleep 1346 seconds, actually delayed analysis time by 1346 seconds |
G Data Antivirus (Windows) | Virus: Dropped:Generic.Malware.PVPk!!prn!.A4E7F61A (Engine A) |
Avast Core Security (Linux) | Win32:MalwareX-gen [Misc] |
Trellix (Linux) | GenericRXMK-QV |
WithSecure (Linux) | Trojan.TR/Spy.Gen |
eScan Antivirus (Linux) | Dropped:Generic.Malware.PVPk!!prn!.A4E7F61A(DB) |
ESET Security (Windows) | a variant of Win32/Agent.CP worm |
Sophos Anti-Virus (Linux) | Troj/Agent-AJFK |
DrWeb Antivirus (Linux) | Win32.HLLW.Siggen.1607 |
Bitdefender Antivirus (Linux) | Dropped:Generic.Malware.PVPk!!prn!.A4E7F61A |
Emsisoft Commandline Scanner (Windows) | Dropped:Generic.Malware.PVPk!!prn!.A4E7F61A (B) |