Size | 397.0KB |
---|---|
Type | PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
MD5 | 5cf961052beffa7e12f57cdc5061fab2 |
SHA1 | 31d233b6fd6fc3b2faa2f856e1567e6baed88c43 |
SHA256 | 55f9efb5b812a168abf48e7e2d29ec7793211c3caf115668394ea8dff1fb0aae |
SHA512 |
eb04ac88b5235f527750eb839e517690e9ca1ef2d44d0b3f732ea5186608350ac8d456c5bb31a70168ed3f620e65bacea1850bdad79834522ae73660c8f1b9c5
|
CRC32 | 7BA3E78E |
ssdeep | None |
PDB Path | C:\Jenkins\workspace\RSDUWin-Clients\label\Windows7\build\Clients\Release\bin\CviGraphComponent.pdb |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 3, 2025, 12:20 p.m. | July 3, 2025, 12:26 p.m. | 408 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-03 12:15:20,015 [analyzer] DEBUG: Starting analyzer from: C:\tmptisd8w 2025-07-03 12:15:20,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\yZmxcjfweLZItcMWChFHQO 2025-07-03 12:15:20,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\jDyEyvJGExESoezrcMkDwvWQXArSG 2025-07-03 12:15:20,796 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-03 12:15:20,796 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-03 12:15:21,233 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-03 12:15:21,453 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-07-03 12:15:21,453 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-03 12:15:21,453 [analyzer] DEBUG: Started auxiliary module Human 2025-07-03 12:15:21,453 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-03 12:15:21,453 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-03 12:15:21,500 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-03 12:15:21,500 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-03 12:15:21,515 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-03 12:15:21,515 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-03 12:15:21,608 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\CviGraphComponent.dll' with arguments ['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\CviGraphComponent.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\CviGraphComponent.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
2025-07-03 12:20:00,714 [cuckoo.core.scheduler] DEBUG: Task #6655667: no machine available yet 2025-07-03 12:20:01,745 [cuckoo.core.scheduler] DEBUG: Task #6655667: no machine available yet 2025-07-03 12:20:02,772 [cuckoo.core.scheduler] DEBUG: Task #6655667: no machine available yet 2025-07-03 12:20:03,791 [cuckoo.core.scheduler] DEBUG: Task #6655667: no machine available yet 2025-07-03 12:20:04,829 [cuckoo.core.scheduler] INFO: Task #6655667: acquired machine win7x647 (label=win7x647) 2025-07-03 12:20:04,830 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.207 for task #6655667 2025-07-03 12:20:05,290 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 695204 (interface=vboxnet0, host=192.168.168.207) 2025-07-03 12:20:05,990 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x647 2025-07-03 12:20:06,609 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x647 to vmcloak 2025-07-03 12:23:10,011 [cuckoo.core.guest] INFO: Starting analysis #6655667 on guest (id=win7x647, ip=192.168.168.207) 2025-07-03 12:23:11,190 [cuckoo.core.guest] DEBUG: win7x647: not ready yet 2025-07-03 12:23:16,389 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x647, ip=192.168.168.207) 2025-07-03 12:23:16,509 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x647, ip=192.168.168.207, monitor=latest, size=6660546) 2025-07-03 12:23:18,961 [cuckoo.core.resultserver] DEBUG: Task #6655667: live log analysis.log initialized. 2025-07-03 12:23:20,365 [cuckoo.core.resultserver] DEBUG: Task #6655667 is sending a BSON stream 2025-07-03 12:23:21,306 [cuckoo.core.guest] WARNING: win7x647: analysis #6655667 caught an exception Traceback (most recent call last): File "C:/tmptisd8w/analyzer.py", line 824, in <module> success = analyzer.run() File "C:/tmptisd8w/analyzer.py", line 673, in run pids = self.package.start(self.target) File "C:\tmptisd8w\modules\packages\exe.py", line 34, in start return self.execute(path, args=shlex.split(args)) File "C:\tmptisd8w\lib\common\abstracts.py", line 205, in execute "Unable to execute the initial process, analysis aborted." CuckooPackageError: Unable to execute the initial process, analysis aborted. 2025-07-03 12:23:21,331 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-03 12:23:21,586 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-03 12:23:21,592 [cuckoo.core.resultserver] DEBUG: Task #6655667: File upload for 'shots/0001.jpg' 2025-07-03 12:23:21,857 [cuckoo.core.resultserver] DEBUG: Task #6655667 uploaded file length: 133495 2025-07-03 12:23:22,889 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x647 to path /srv/cuckoo/cwd/storage/analyses/6655667/memory.dmp 2025-07-03 12:23:22,905 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x647 2025-07-03 12:26:48,354 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.207 for task #6655667 2025-07-03 12:26:48,354 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6655667 2025-07-03 12:26:48,745 [cuckoo.core.scheduler] DEBUG: Released database task #6655667 2025-07-03 12:26:48,765 [cuckoo.core.scheduler] INFO: Task #6655667: analysis procedure completed
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Create or check mutex | rule | win_mutex |
pdb_path | C:\Jenkins\workspace\RSDUWin-Clients\label\Windows7\build\Clients\Release\bin\CviGraphComponent.pdb |