File d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe

Size 689.2KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 21692d5eecf0d91e172116501d9fe245
SHA1 be1bb1e6a24cc6ae7eb579f3dfb8239f0b3b9530
SHA256 d764e1aff665cb8b94ff88c461888239fea5604a35b915a67481afc58be07896
SHA512
38c27a3bd451d271dfff3f94c051da81dba2ae75622ad3e7fe7157b71161b052db8b196acc6184da482df5427061bebf1b403b650197e00e7684fc551b50efb9
CRC32 CE9B4D65
ssdeep None
Yara
  • DebuggerException__SetConsoleCtrl - (no description)
  • win_mutex - Create or check mutex
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

Parent_Task_ID:6620477

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE July 5, 2025, 10:42 a.m. July 5, 2025, 10:50 a.m. 463 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-06-30 18:02:30,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpd0os1j
2025-06-30 18:02:30,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\MkSosmwNXOkVqEqtCKamGN
2025-06-30 18:02:30,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\VwmOSqKLHlMUAWOyEpqldtXUlMAlv
2025-06-30 18:02:30,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-30 18:02:30,108 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-30 18:02:30,390 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-30 18:02:30,390 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-30 18:02:30,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-30 18:02:31,000 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-06-30 18:02:31,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-30 18:02:31,000 [analyzer] DEBUG: Started auxiliary module Human
2025-06-30 18:02:31,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-30 18:02:31,000 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-30 18:02:31,062 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-30 18:02:31,062 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-30 18:02:31,062 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-30 18:02:31,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-30 18:02:31,250 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe' with arguments '' and pid 1628
2025-06-30 18:02:31,421 [analyzer] DEBUG: Loaded monitor into process with pid 1628
2025-06-30 18:02:31,562 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Windowsd50l2bvpd8
2025-06-30 18:02:31,640 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Common Files\Microsoft Shared\black qtcr1re ni0p0dq8 9w4xilz6j2 .mpg.exe
2025-06-30 18:02:31,890 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\DVD Maker\Shared\h3ps6tmu mkx87b [bangbus] titts v14bqy5ueys  (Jade,Karin).mpg.exe
2025-06-30 18:02:32,265 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Microsoft Office\Templates\jspx4i 76qp9o6j jbp79p wifey .rar.exe
2025-06-30 18:02:32,296 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\t1apup6 hot (!) latex .zip.exe
2025-06-30 18:02:32,390 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Windows Journal\Templates\3lhg1q chkaba9s0 g28gx7w6vur32j .rar.exe
2025-06-30 18:02:32,530 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files\Windows Sidebar\Shared Gadgets\u8ywwbo t1apup6 uncut ct48q6s .zip.exe
2025-06-30 18:02:32,562 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\3lhg1q q0vgw72 g28gx7w6vur32j .avi.exe
2025-06-30 18:02:32,671 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files (x86)\Common Files\microsoft shared\r2bdcnb q0vgw72 2e032zbb avhkl4osfi1b1  (l0p693,l0p693).zip.exe
2025-06-30 18:02:32,983 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\chkaba9s0 sperm 2e032zbb avhkl4osfi1b1 .mpg.exe
2025-06-30 18:02:33,078 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\RAC\Temp\wiya6rsl beast 2eoamoy big .avi.exe
2025-06-30 18:02:33,125 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Search\Data\Temp\black 76qp9o6j 2e032zbb hotel  (Sonja).rar.exe
2025-06-30 18:02:33,187 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Windows\Templates\0ymg8tq 2eoamoy nk2tll hole .mpg.exe
2025-06-30 18:02:33,265 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Windows\Templates\0ymg8tq horse jspx4i nugdmg18bgxp .mpg.exe
2025-06-30 18:02:33,655 [analyzer] INFO: Injected into process with pid 2108 and name ''
2025-06-30 18:02:33,796 [analyzer] INFO: Added new file to list with pid 1628 and path C:\tmpd0os1j\2wr8ay1 cum jbp79p .zip.exe
2025-06-30 18:02:33,828 [analyzer] DEBUG: Loaded monitor into process with pid 2108
2025-06-30 18:02:33,905 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\0ymg8tq porn hot (!) ash  (Jenna).mpg.exe
2025-06-30 18:02:34,000 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Local\Temp\chkaba9s0 nugdmg18bgxp boobs 55svezg .rar.exe
2025-06-30 18:02:34,046 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\qtcr1re uncut  (Sonja).zip.exe
2025-06-30 18:02:34,078 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\ibxj3s2 ibxj3s2 hot (!) p834ynn  (Sonja,Liz).mpeg.exe
2025-06-30 18:02:34,296 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\0516z8ivf q0vgw72 girls legs .avi.exe
2025-06-30 18:02:34,405 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\3o9e0ag1 horse l6ppef ibxj3s2 ct48q6s .zip.exe
2025-06-30 18:02:34,500 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\asian porn hot (!) cock wifey  (wrtdiha,Sonja).avi.exe
2025-06-30 18:02:34,592 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\RAC\Temp\0516z8ivf horse xxx 2e032zbb balls .mpg.exe
2025-06-30 18:02:34,640 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Search\Data\Temp\horse c4ou4r0 ni0p0dq8 50+ .rar.exe
2025-06-30 18:02:34,717 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Windows\Templates\wiya6rsl ibxj3s2 i4caruo hole u3nxpdd .zip.exe
2025-06-30 18:02:34,765 [analyzer] INFO: Added new file to list with pid 1628 and path C:\ProgramData\Microsoft\Windows\Templates\0516z8ivf t1apup6 i4caruo ofok9a 63k9qbq9xg  (1bcw83k).mpeg.exe
2025-06-30 18:02:34,796 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\y3hndyq mkx87b [free] ct48q6s .mpeg.exe
2025-06-30 18:02:34,812 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\u8ywwbo v8jedw8 big  (Jade,e6rl5yo1).zip.exe
2025-06-30 18:02:34,858 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\mkx87b jspx4i i4caruo hairy  (x8z5ka).mpeg.exe
2025-06-30 18:02:34,890 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\ar164nb horse [milf] avhkl4osfi1b1  (Karin).avi.exe
2025-06-30 18:02:35,000 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\98edvx c4ou4r0 t1apup6 2e032zbb wifey  (ihcwxtl,ydezx1cz6).mpeg.exe
2025-06-30 18:02:35,030 [analyzer] INFO: Added new file to list with pid 1628 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\nude mgdo94z3fb2 ibxj3s2  (Sandy).zip.exe
2025-06-30 18:05:50,250 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-30 18:05:51,421 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-30 18:05:51,421 [lib.api.process] INFO: Successfully terminated process with pid 1628.
2025-06-30 18:05:51,421 [lib.api.process] INFO: Successfully terminated process with pid 2108.
2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\roaming\microsoft\windows\templates\asian porn hot (!) cock wifey  (wrtdiha,sonja).avi.exe
2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\programdata\microsoft\windows\templates\0516z8ivf t1apup6 i4caruo ofok9a 63k9qbq9xg  (1bcw83k).mpeg.exe
2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\users\default\appdata\local\microsoft\windows\temporary internet files\y3hndyq mkx87b [free] ct48q6s .mpeg.exe
2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\chkaba9s0 nugdmg18bgxp boobs 55svezg .rar.exe
2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\program files (x86)\windows sidebar\shared gadgets\chkaba9s0 sperm 2e032zbb avhkl4osfi1b1 .mpg.exe
2025-06-30 18:05:52,046 [analyzer] WARNING: Too many files: c:\windows\assembly\gac_32\microsoft.grouppolicy.admtmpleditor.resources\nude mgdo94z3fb2 ibxj3s2  (sandy).zip.exe
2025-06-30 18:05:52,046 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-07-05 10:42:39,782 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:40,798 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:41,850 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:43,117 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:44,147 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:45,273 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:46,316 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:47,504 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:48,525 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:49,580 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:50,613 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:51,635 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:52,654 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:53,671 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:54,802 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:55,819 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:56,842 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:57,863 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:58,880 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:42:59,907 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:43:00,933 [cuckoo.core.scheduler] DEBUG: Task #6650108: no machine available yet
2025-07-05 10:43:01,961 [cuckoo.core.scheduler] INFO: Task #6650108: acquired machine win7x6429 (label=win7x6429)
2025-07-05 10:43:01,962 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.229 for task #6650108
2025-07-05 10:43:02,412 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3377853 (interface=vboxnet0, host=192.168.168.229)
2025-07-05 10:43:06,949 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6429
2025-07-05 10:43:14,366 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6429 to vmcloak
2025-07-05 10:44:59,682 [cuckoo.core.guest] INFO: Starting analysis #6650108 on guest (id=win7x6429, ip=192.168.168.229)
2025-07-05 10:45:00,688 [cuckoo.core.guest] DEBUG: win7x6429: not ready yet
2025-07-05 10:45:05,711 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6429, ip=192.168.168.229)
2025-07-05 10:45:05,913 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6429, ip=192.168.168.229, monitor=latest, size=6660546)
2025-07-05 10:45:07,154 [cuckoo.core.resultserver] DEBUG: Task #6650108: live log analysis.log initialized.
2025-07-05 10:45:08,102 [cuckoo.core.resultserver] DEBUG: Task #6650108 is sending a BSON stream
2025-07-05 10:45:08,509 [cuckoo.core.resultserver] DEBUG: Task #6650108 is sending a BSON stream
2025-07-05 10:45:09,331 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'shots/0001.jpg'
2025-07-05 10:45:09,467 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 133401
2025-07-05 10:45:10,959 [cuckoo.core.resultserver] DEBUG: Task #6650108 is sending a BSON stream
2025-07-05 10:45:21,870 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:45:36,986 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:45:52,207 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:46:07,583 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:46:22,972 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:46:38,341 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:46:53,542 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:47:08,969 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:47:24,174 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:47:39,411 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:47:54,760 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:48:09,932 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:48:25,320 [cuckoo.core.guest] DEBUG: win7x6429: analysis #6650108 still processing
2025-07-05 10:48:27,606 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'curtain/1751299550.44.curtain.log'
2025-07-05 10:48:27,610 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 36
2025-07-05 10:48:28,513 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'sysmon/1751299551.34.sysmon.xml'
2025-07-05 10:48:28,592 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 12936968
2025-07-05 10:48:28,614 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/0470d82bc8bfdeb6_3o9e0ag1 horse l6ppef ibxj3s2 ct48q6s .zip.exe'
2025-07-05 10:48:28,622 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1200197
2025-07-05 10:48:28,643 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/8d0837074c3cda08_0516z8ivf horse xxx 2e032zbb balls .mpg.exe'
2025-07-05 10:48:28,675 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 2161613
2025-07-05 10:48:28,698 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/ba2f0b2e24150172_ar164nb horse [milf] avhkl4osfi1b1  (karin).avi.exe'
2025-07-05 10:48:28,715 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 2065662
2025-07-05 10:48:28,721 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/398058dfdc2f399b_2wr8ay1 cum jbp79p .zip.exe'
2025-07-05 10:48:28,726 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 440062
2025-07-05 10:48:28,729 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/89b6a8091b66206e_t1apup6 hot (!) latex .zip.exe'
2025-07-05 10:48:28,733 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 296556
2025-07-05 10:48:28,737 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/c1fe38bec2fb59ed_ibxj3s2 ibxj3s2 hot (!) p834ynn  (sonja,liz).mpeg.exe'
2025-07-05 10:48:28,742 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 550858
2025-07-05 10:48:28,754 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/3499ee92f7dc109a_3lhg1q chkaba9s0 g28gx7w6vur32j .rar.exe'
2025-07-05 10:48:28,770 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1845360
2025-07-05 10:48:28,777 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/e9cf85ed13c0d0e1_3lhg1q q0vgw72 g28gx7w6vur32j .avi.exe'
2025-07-05 10:48:28,782 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 556596
2025-07-05 10:48:28,793 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/c7afa6a34a3b1435_black 76qp9o6j 2e032zbb hotel  (sonja).rar.exe'
2025-07-05 10:48:28,804 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1335572
2025-07-05 10:48:28,818 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/21ea0bb50765f6ac_h3ps6tmu mkx87b [bangbus] titts v14bqy5ueys  (jade,karin).mpg.exe'
2025-07-05 10:48:28,834 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1672256
2025-07-05 10:48:28,857 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/fd8096f9788a7831_wiya6rsl beast 2eoamoy big .avi.exe'
2025-07-05 10:48:28,878 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 2149659
2025-07-05 10:48:28,895 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/fbc2007d389e94ed_u8ywwbo t1apup6 uncut ct48q6s .zip.exe'
2025-07-05 10:48:28,905 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1355426
2025-07-05 10:48:28,921 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/e886e825d6c2bd4b_windowsd50l2bvpd8'
2025-07-05 10:48:28,929 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1207847
2025-07-05 10:48:28,935 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/5dbab55a98953219_u8ywwbo v8jedw8 big  (jade,e6rl5yo1).zip.exe'
2025-07-05 10:48:28,938 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 223384
2025-07-05 10:48:28,960 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/175bdc430c6ff2de_qtcr1re uncut  (sonja).zip.exe'
2025-07-05 10:48:28,981 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 2081017
2025-07-05 10:48:28,997 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/969b3801f0e01481_98edvx c4ou4r0 t1apup6 2e032zbb wifey  (ihcwxtl,ydezx1cz6).mpeg.exe'
2025-07-05 10:48:29,045 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1388542
2025-07-05 10:48:29,053 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/b72820f0e3708312_wiya6rsl ibxj3s2 i4caruo hole u3nxpdd .zip.exe'
2025-07-05 10:48:29,062 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 474674
2025-07-05 10:48:29,065 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/b55bca2f1227d91e_0ymg8tq horse jspx4i nugdmg18bgxp .mpg.exe'
2025-07-05 10:48:29,069 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 384746
2025-07-05 10:48:29,071 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/f1ea393f1bb057c4_0ymg8tq porn hot (!) ash  (jenna).mpg.exe'
2025-07-05 10:48:29,080 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/238714fa6800ce16_horse c4ou4r0 ni0p0dq8 50+ .rar.exe'
2025-07-05 10:48:29,083 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 863240
2025-07-05 10:48:29,099 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/fd0dda8b07a1b83f_black qtcr1re ni0p0dq8 9w4xilz6j2 .mpg.exe'
2025-07-05 10:48:29,102 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 275547
2025-07-05 10:48:29,120 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1925020
2025-07-05 10:48:29,127 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/0489ace2f44d993c_0516z8ivf q0vgw72 girls legs .avi.exe'
2025-07-05 10:48:29,131 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 400376
2025-07-05 10:48:29,140 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/9778db61c723f20f_r2bdcnb q0vgw72 2e032zbb avhkl4osfi1b1  (l0p693,l0p693).zip.exe'
2025-07-05 10:48:29,148 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1097375
2025-07-05 10:48:29,167 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/bf564d941eb5bd0e_0ymg8tq 2eoamoy nk2tll hole .mpg.exe'
2025-07-05 10:48:29,183 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 1853943
2025-07-05 10:48:29,193 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/c99fd37a8caec7c5_jspx4i 76qp9o6j jbp79p wifey .rar.exe'
2025-07-05 10:48:29,203 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 917115
2025-07-05 10:48:29,207 [cuckoo.core.resultserver] DEBUG: Task #6650108: File upload for 'files/91766c571209cb7c_mkx87b jspx4i i4caruo hairy  (x8z5ka).mpeg.exe'
2025-07-05 10:48:29,217 [cuckoo.core.resultserver] DEBUG: Task #6650108 uploaded file length: 778201
2025-07-05 10:48:29,232 [cuckoo.core.resultserver] DEBUG: Task #6650108 had connection reset for <Context for LOG>
2025-07-05 10:48:31,380 [cuckoo.core.guest] INFO: win7x6429: analysis completed successfully
2025-07-05 10:48:31,397 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-05 10:48:31,425 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-05 10:48:32,533 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6429 to path /srv/cuckoo/cwd/storage/analyses/6650108/memory.dmp
2025-07-05 10:48:32,534 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6429
2025-07-05 10:50:22,727 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.229 for task #6650108
2025-07-05 10:50:23,090 [cuckoo.core.scheduler] DEBUG: Released database task #6650108
2025-07-05 10:50:23,112 [cuckoo.core.scheduler] INFO: Task #6650108: analysis procedure completed

Signatures

Yara rules detected for file (4 events)
description (no description) rule DebuggerException__SetConsoleCtrl
description Create or check mutex rule win_mutex
description Affect system registries rule win_registry
description Affect private profile rule win_files_operation
The executable uses a known packer (1 event)
packer Pelles C 3.00, 4.00, 4.50 EXE (X86 CRT-LIB)
Creates executable files on the filesystem (31 events)
file C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\chkaba9s0 sperm 2e032zbb avhkl4osfi1b1 .mpg.exe
file C:\Users\All Users\Templates\0516z8ivf t1apup6 i4caruo ofok9a 63k9qbq9xg (1bcw83k).mpeg.exe
file C:\Users\Administrator\AppData\Local\Temp\chkaba9s0 nugdmg18bgxp boobs 55svezg .rar.exe
file C:\Program Files\DVD Maker\Shared\h3ps6tmu mkx87b [bangbus] titts v14bqy5ueys (Jade,Karin).mpg.exe
file C:\ProgramData\Microsoft\Search\Data\Temp\black 76qp9o6j 2e032zbb hotel (Sonja).rar.exe
file C:\Users\Administrator\Templates\asian porn hot (!) cock wifey (wrtdiha,Sonja).avi.exe
file C:\ProgramData\Templates\0ymg8tq horse jspx4i nugdmg18bgxp .mpg.exe
file C:\ProgramData\Microsoft\RAC\Temp\wiya6rsl beast 2eoamoy big .avi.exe
file C:\Users\All Users\Microsoft\RAC\Temp\0516z8ivf horse xxx 2e032zbb balls .mpg.exe
file C:\tmpd0os1j\2wr8ay1 cum jbp79p .zip.exe
file C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\t1apup6 hot (!) latex .zip.exe
file C:\Program Files\Common Files\Microsoft Shared\black qtcr1re ni0p0dq8 9w4xilz6j2 .mpg.exe
file C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\0516z8ivf q0vgw72 girls legs .avi.exe
file C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\qtcr1re uncut (Sonja).zip.exe
file C:\Users\Default\AppData\Local\Temporary Internet Files\u8ywwbo v8jedw8 big (Jade,e6rl5yo1).zip.exe
file C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\98edvx c4ou4r0 t1apup6 2e032zbb wifey (ihcwxtl,ydezx1cz6).mpeg.exe
file C:\Users\Administrator\AppData\Local\Temporary Internet Files\ibxj3s2 ibxj3s2 hot (!) p834ynn (Sonja,Liz).mpeg.exe
file C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\mkx87b jspx4i i4caruo hairy (x8z5ka).mpeg.exe
file C:\Program Files\Windows Sidebar\Shared Gadgets\u8ywwbo t1apup6 uncut ct48q6s .zip.exe
file C:\ProgramData\Microsoft\Windows\Templates\0ymg8tq 2eoamoy nk2tll hole .mpg.exe
file C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\y3hndyq mkx87b [free] ct48q6s .mpeg.exe
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\0ymg8tq porn hot (!) ash (Jenna).mpg.exe
file C:\Program Files\Windows Journal\Templates\3lhg1q chkaba9s0 g28gx7w6vur32j .rar.exe
file C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\nude mgdo94z3fb2 ibxj3s2 (Sandy).zip.exe
file C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\3lhg1q q0vgw72 g28gx7w6vur32j .avi.exe
file C:\Users\All Users\Microsoft\Search\Data\Temp\horse c4ou4r0 ni0p0dq8 50+ .rar.exe
file C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\3o9e0ag1 horse l6ppef ibxj3s2 ct48q6s .zip.exe
file C:\Program Files\Microsoft Office\Templates\jspx4i 76qp9o6j jbp79p wifey .rar.exe
file C:\Users\All Users\Microsoft\Windows\Templates\wiya6rsl ibxj3s2 i4caruo hole u3nxpdd .zip.exe
file C:\Users\Default\Templates\ar164nb horse [milf] avhkl4osfi1b1 (Karin).avi.exe
file C:\Program Files (x86)\Common Files\microsoft shared\r2bdcnb q0vgw72 2e032zbb avhkl4osfi1b1 (l0p693,l0p693).zip.exe
Drops an executable to the user AppData folder (1 event)
file C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\3o9e0ag1 horse l6ppef ibxj3s2 ct48q6s .zip.exe
Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping (18 events)
Repeatedly searches for a not-found process, you may want to run a web browser during analysis (50 out of 197 events)
Time & API Arguments Status Return Repeated

Process32NextW

snapshot_handle: 0x00000138
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1628
0 0

Process32NextW

snapshot_handle: 0x0000025c
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 2108
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000268
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000260
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x000002c0
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0

Process32NextW

snapshot_handle: 0x00000278
process_name: d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe
process_identifier: 1828
0 0
A process attempted to delay the analysis task. (1 event)
description d764e1aff665cb8b_wiya6rsl porn q0vgw72 mtn66856s5 titts .zip.exe tried to sleep 1346 seconds, actually delayed analysis time by 1346 seconds
Enumerates services, possibly for anti-virtualization (1 event)
Time & API Arguments Status Return Repeated

EnumServicesStatusA

service_handle: 0x0084ccb0
service_type: 48
service_status: 1
0 0
File has been identified by 10 AntiVirus engine on IRMA as malicious (10 events)
G Data Antivirus (Windows) Virus: Dropped:Generic.Malware.PVPk!!prn!.A4E7F61A (Engine A)
Avast Core Security (Linux) Win32:MalwareX-gen [Misc]
Trellix (Linux) GenericRXMK-QV
WithSecure (Linux) Trojan.TR/Spy.Gen
eScan Antivirus (Linux) Dropped:Generic.Malware.PVPk!!prn!.A4E7F61A(DB)
ESET Security (Windows) a variant of Win32/Agent.CP worm
Sophos Anti-Virus (Linux) Troj/Agent-AJFK
DrWeb Antivirus (Linux) Win32.HLLW.Siggen.1607
Bitdefender Antivirus (Linux) Dropped:Generic.Malware.PVPk!!prn!.A4E7F61A
Emsisoft Commandline Scanner (Windows) Dropped:Generic.Malware.PVPk!!prn!.A4E7F61A (B)
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.