Size | 4.1MB |
---|---|
Type | PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows |
MD5 | 0fab860738586945e79a69e464adf624 |
SHA1 | fd2d8b38c36827c40dc0549e21b95cbe15b81d78 |
SHA256 | 5466af90e3d3ce893f3ce4ab6186bbd7b47cd4ef215c4996a4c2cf5a5ccb3aed |
SHA512 |
1b84851384566ef406ce702a2bff7c9cf1718c8688ea8795f5e815d929494259ff6af5a75f5bef434bb2aa6adde49b04d393f56023603167c2e7b621dbd67140
|
CRC32 | F316E6D7 |
ssdeep | None |
PDB Path | c:\Projects\18.1\BuildLabel\Temp\NetStudio.v18.1.2005\Win\DevExpress.XtraPrinting\DevExpress.Printing.Core\obj_netFW\Release\DevExpress.Printing.v18.1.Core.pdb |
Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | July 3, 2025, 12:33 p.m. | July 3, 2025, 12:40 p.m. | 433 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-03 12:15:26,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpriinqn 2025-07-03 12:15:26,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\hTrSFHytysxcpvjEjzWfRxxbTrwC 2025-07-03 12:15:26,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\YGjERQZUTNIdNNnILyAkKW 2025-07-03 12:15:26,421 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-03 12:15:26,421 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-03 12:15:26,842 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-03 12:15:27,046 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-07-03 12:15:27,046 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-03 12:15:27,046 [analyzer] DEBUG: Started auxiliary module Human 2025-07-03 12:15:27,046 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-03 12:15:27,046 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-03 12:15:27,092 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-03 12:15:27,092 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-03 12:15:27,108 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-03 12:15:27,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-03 12:15:27,203 [lib.api.process] ERROR: Failed to execute process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\DevExpress.Printing.v18.1.Core.dll' with arguments ['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\DevExpress.Printing.v18.1.Core.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp'] (Error: Command '['bin\\inject-x86.exe', '--app', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\DevExpress.Printing.v18.1.Core.dll', '--only-start', '--curdir', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp']' returned non-zero exit status 1)
2025-07-03 12:33:39,503 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:40,525 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:41,545 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:42,569 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:43,597 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:44,637 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:45,660 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:46,680 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:47,809 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:48,911 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:50,192 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:51,351 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:52,470 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:53,584 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:54,665 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:55,783 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:56,865 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:57,964 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:33:59,199 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:00,351 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:01,497 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:02,598 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:03,687 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:04,771 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:05,848 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:07,015 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:08,099 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:09,192 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:10,281 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:11,359 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:12,424 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:13,491 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:14,553 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:15,624 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:16,663 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:17,699 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:18,732 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:19,772 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:20,807 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:21,851 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:22,891 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:23,928 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:24,968 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:26,018 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:27,093 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:28,161 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:29,215 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:30,274 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:31,404 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:32,462 [cuckoo.core.scheduler] DEBUG: Task #6655734: no machine available yet 2025-07-03 12:34:33,543 [cuckoo.core.scheduler] INFO: Task #6655734: acquired machine win7x6426 (label=win7x6426) 2025-07-03 12:34:33,545 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.226 for task #6655734 2025-07-03 12:34:34,297 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 713214 (interface=vboxnet0, host=192.168.168.226) 2025-07-03 12:34:44,471 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6426 2025-07-03 12:34:45,437 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6426 to vmcloak 2025-07-03 12:38:00,243 [cuckoo.core.guest] INFO: Starting analysis #6655734 on guest (id=win7x6426, ip=192.168.168.226) 2025-07-03 12:38:01,248 [cuckoo.core.guest] DEBUG: win7x6426: not ready yet 2025-07-03 12:38:06,279 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6426, ip=192.168.168.226) 2025-07-03 12:38:06,492 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6426, ip=192.168.168.226, monitor=latest, size=6660546) 2025-07-03 12:38:08,729 [cuckoo.core.resultserver] DEBUG: Task #6655734: live log analysis.log initialized. 2025-07-03 12:38:10,045 [cuckoo.core.resultserver] DEBUG: Task #6655734 is sending a BSON stream 2025-07-03 12:38:10,959 [cuckoo.core.resultserver] DEBUG: Task #6655734: File upload for 'shots/0001.jpg' 2025-07-03 12:38:10,992 [cuckoo.core.resultserver] DEBUG: Task #6655734 uploaded file length: 133385 2025-07-03 12:38:11,292 [cuckoo.core.guest] WARNING: win7x6426: analysis #6655734 caught an exception Traceback (most recent call last): File "C:/tmpriinqn/analyzer.py", line 824, in <module> success = analyzer.run() File "C:/tmpriinqn/analyzer.py", line 673, in run pids = self.package.start(self.target) File "C:\tmpriinqn\modules\packages\exe.py", line 34, in start return self.execute(path, args=shlex.split(args)) File "C:\tmpriinqn\lib\common\abstracts.py", line 205, in execute "Unable to execute the initial process, analysis aborted." CuckooPackageError: Unable to execute the initial process, analysis aborted. 2025-07-03 12:38:11,306 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-03 12:38:11,338 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-03 12:38:12,525 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6426 to path /srv/cuckoo/cwd/storage/analyses/6655734/memory.dmp 2025-07-03 12:38:12,527 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6426 2025-07-03 12:40:50,878 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.226 for task #6655734 2025-07-03 12:40:50,880 [cuckoo.core.resultserver] DEBUG: Cancel <Context for LOG> for task 6655734 2025-07-03 12:40:52,030 [cuckoo.core.scheduler] DEBUG: Released database task #6655734 2025-07-03 12:40:52,068 [cuckoo.core.scheduler] INFO: Task #6655734: analysis procedure completed
description | Listen for incoming communication | rule | network_tcp_listen | ||||||
description | Affect private profile | rule | win_files_operation |
pdb_path | c:\Projects\18.1\BuildLabel\Temp\NetStudio.v18.1.2005\Win\DevExpress.XtraPrinting\DevExpress.Printing.Core\obj_netFW\Release\DevExpress.Printing.v18.1.Core.pdb |