Size | 92.5KB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | e96c7486d3d6d2c5337b2d151901b1e6 |
SHA1 | 59188c23e05487e9668f7d3429b698d48ef75d73 |
SHA256 | 86525da3ee899345ee72bc542ba7f23b03a56a5100334510d76e190cc93fa1c7 |
SHA512 |
02f0ccee7556bdd538e6d0f13cbe8960a300ae0b7816ad1db43cd4bcc680a13dcb6c24192b30043db558d8b6dff2ae43dc93a8ce5d8a17c305792747d75b2163
|
CRC32 | DC72BE65 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Aug. 28, 2025, 5:03 p.m. | Aug. 28, 2025, 5:04 p.m. | 71 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-26 16:59:45,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpj6atou 2025-08-26 16:59:45,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\FRqXzMbKCyyBLLboK 2025-08-26 16:59:45,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\wNQkrKUJeMADtMSmLpKwVGihnnSXDqnO 2025-08-26 16:59:45,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-26 16:59:45,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-26 16:59:45,687 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-26 16:59:45,921 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-08-26 16:59:45,921 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-26 16:59:45,921 [analyzer] DEBUG: Started auxiliary module Human 2025-08-26 16:59:45,921 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-26 16:59:45,921 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-26 16:59:46,030 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-26 16:59:46,030 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-26 16:59:46,030 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-26 16:59:46,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-26 16:59:46,187 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\86525da3ee899345ee72bc542ba7f23b03a56a5100334510d76e190cc93fa1c7.exe' with arguments '' and pid 2776 2025-08-26 16:59:46,358 [analyzer] DEBUG: Loaded monitor into process with pid 2776 2025-08-26 16:59:46,578 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Windows6g2yf6t03h 2025-08-26 16:59:46,608 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files\Common Files\Microsoft Shared\yn0pxd horse xxx 6mjj01 50+ .mpg.exe 2025-08-26 16:59:46,828 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files\DVD Maker\Shared\r2qc46i jmmawhs 9k8bf2i [free] wzxubo .mpg.exe 2025-08-26 16:59:47,140 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files\Microsoft Office\Templates\sperm fs8utd .mpg.exe 2025-08-26 16:59:47,217 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\l8qccpyq [free] kpbv9mg7 .zip.exe 2025-08-26 16:59:47,342 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files\Windows Journal\Templates\cw4ymo3u nude xxx srpvkzygmcsw (Liz).zip.exe 2025-08-26 16:59:47,467 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files\Windows Sidebar\Shared Gadgets\z8dvsxk [milf] ttbp10m .zip.exe 2025-08-26 16:59:47,515 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\vftv0ou m5v129k gay big .mpeg.exe 2025-08-26 16:59:47,625 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files (x86)\Common Files\microsoft shared\xiwlzi0 9oypb8 a3xo5xtn [milf] aqp9g9a .mpeg.exe 2025-08-26 16:59:47,937 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\9k8bf2i uncut kpbv9mg7 .avi.exe 2025-08-26 16:59:48,000 [analyzer] INFO: Added new file to list with pid 2776 and path C:\ProgramData\Microsoft\RAC\Temp\yn0pxd ko6o6a sperm wk79oa4s2r04wd ngo69ybvy (q922zop0f,v89zo5).zip.exe 2025-08-26 16:59:48,015 [analyzer] INFO: Added new file to list with pid 2776 and path C:\ProgramData\Microsoft\Search\Data\Temp\l8qccpyq f6br2s2 .mpeg.exe 2025-08-26 16:59:48,078 [analyzer] INFO: Added new file to list with pid 2776 and path C:\ProgramData\Microsoft\Windows\Templates\l8qccpyq 6r3apw4 titts 6jug8f (Sarah).mpg.exe 2025-08-26 16:59:48,108 [analyzer] INFO: Added new file to list with pid 2776 and path C:\ProgramData\Microsoft\Windows\Templates\yn0pxd porn l8qccpyq kmozxo (ynve4mgf).zip.exe 2025-08-26 16:59:48,592 [analyzer] INFO: Injected into process with pid 1388 and name '' 2025-08-26 16:59:48,608 [analyzer] INFO: Added new file to list with pid 2776 and path C:\tmpj6atou\l8qccpyq big feet (sr0fncw4,ysxdgxr).zip.exe 2025-08-26 16:59:48,687 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\tvolgth jmmawhs beast [milf] (ysxdgxr).avi.exe 2025-08-26 16:59:48,750 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Administrator\AppData\Local\Temp\cw4ymo3u jmmawhs xxx fs8utd feet rqmct8k1i30 .mpeg.exe 2025-08-26 16:59:48,765 [analyzer] DEBUG: Loaded monitor into process with pid 1388 2025-08-26 16:59:48,780 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\rdoti90 6mjj01 latex .zip.exe 2025-08-26 16:59:48,796 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\rdoti90 6r3apw4 hole qcjxxhb .avi.exe 2025-08-26 16:59:48,953 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\xiwlzi0 m5v129k xxx uncut (v89zo5).mpg.exe 2025-08-26 16:59:49,046 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\gay f6br2s2 girly .rar.exe 2025-08-26 16:59:49,092 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\yn0pxd nude sperm srpvkzygmcsw feet 50+ .avi.exe 2025-08-26 16:59:49,203 [analyzer] INFO: Added new file to list with pid 2776 and path C:\ProgramData\Microsoft\RAC\Temp\xiwlzi0 nude horse 6r3apw4 .mpeg.exe 2025-08-26 16:59:49,250 [analyzer] INFO: Added new file to list with pid 2776 and path C:\ProgramData\Microsoft\Search\Data\Temp\horse kmozxo glans .mpg.exe 2025-08-26 16:59:49,342 [analyzer] INFO: Added new file to list with pid 2776 and path C:\ProgramData\Microsoft\Windows\Templates\yn0pxd y6go35p beast 6r3apw4 (ysxdgxr).mpeg.exe 2025-08-26 16:59:49,437 [analyzer] INFO: Added new file to list with pid 2776 and path C:\ProgramData\Microsoft\Windows\Templates\xxx wk79oa4s2r04wd sd7o90wnjx .mpeg.exe 2025-08-26 16:59:49,500 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\sperm wk79oa4s2r04wd girly .mpeg.exe 2025-08-26 16:59:49,530 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Default\AppData\Local\Temp\xiwlzi0 mtu2oyuh5 6r3apw4 uncut .rar.exe 2025-08-26 16:59:49,562 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\horse [free] feet kgh6zo8 .avi.exe 2025-08-26 16:59:49,640 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\sperm [free] 45ld689 .avi.exe 2025-08-26 16:59:49,687 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\xiwlzi0 m5v129k l8qccpyq 6mjj01 glans hairy (Karin).zip.exe 2025-08-26 16:59:49,796 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\gay [bangbus] wzxubo .rar.exe 2025-08-26 16:59:49,796 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\a3xo5xtn [milf] cock wifey (Jade).avi.exe 2025-08-26 16:59:49,875 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor\vftv0ou nude rdoti90 [free] shoes (q922zop0f,Karin).avi.exe 2025-08-26 16:59:49,890 [analyzer] INFO: Added new file to list with pid 2776 and path C:\Windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor.Resources\z8dvsxk 6r3apw4 wzxubo (q922zop0f,5qcarib).mpg.exe 2025-08-26 17:00:15,187 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-08-26 17:00:15,578 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-26 17:00:15,578 [lib.api.process] INFO: Successfully terminated process with pid 2776. 2025-08-26 17:00:15,578 [lib.api.process] INFO: Successfully terminated process with pid 1388. 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\windows\assembly\gac_32\microsoft.grouppolicy.admtmpleditor\gay [bangbus] wzxubo .rar.exe 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\users\default\appdata\local\microsoft\windows\temporary internet files\sperm wk79oa4s2r04wd girly .mpeg.exe 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\program files\microsoft office\templates\sperm fs8utd .mpg.exe 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\program files (x86)\windows sidebar\shared gadgets\9k8bf2i uncut kpbv9mg7 .avi.exe 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\roaming\macromedia\flash player\#sharedobjects\xiwlzi0 m5v129k xxx uncut (v89zo5).mpg.exe 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\users\default\appdata\local\temp\xiwlzi0 mtu2oyuh5 6r3apw4 uncut .rar.exe 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\windows\assembly\gac_64\microsoft.grouppolicy.admtmpleditor\vftv0ou nude rdoti90 [free] shoes (q922zop0f,karin).avi.exe 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\roaming\microsoft\windows\templates\gay f6br2s2 girly .rar.exe 2025-08-26 17:00:16,296 [analyzer] WARNING: Too many files: c:\program files\microsoft office\templates\1033\onenote\14\notebook templates\l8qccpyq [free] kpbv9mg7 .zip.exe 2025-08-26 17:00:16,296 [analyzer] INFO: Analysis completed.
2025-08-28 17:03:30,518 [cuckoo.core.scheduler] INFO: Task #6920144: acquired machine win7x6416 (label=win7x6416) 2025-08-28 17:03:30,519 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.216 for task #6920144 2025-08-28 17:03:30,737 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2718430 (interface=vboxnet0, host=192.168.168.216) 2025-08-28 17:03:30,800 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6416 2025-08-28 17:03:31,220 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6416 to vmcloak 2025-08-28 17:03:46,280 [cuckoo.core.guest] INFO: Starting analysis #6920144 on guest (id=win7x6416, ip=192.168.168.216) 2025-08-28 17:03:47,285 [cuckoo.core.guest] DEBUG: win7x6416: not ready yet 2025-08-28 17:03:52,313 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6416, ip=192.168.168.216) 2025-08-28 17:03:52,391 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6416, ip=192.168.168.216, monitor=latest, size=6660546) 2025-08-28 17:03:53,652 [cuckoo.core.resultserver] DEBUG: Task #6920144: live log analysis.log initialized. 2025-08-28 17:03:54,526 [cuckoo.core.resultserver] DEBUG: Task #6920144 is sending a BSON stream 2025-08-28 17:03:54,948 [cuckoo.core.resultserver] DEBUG: Task #6920144 is sending a BSON stream 2025-08-28 17:03:55,808 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'shots/0001.jpg' 2025-08-28 17:03:55,821 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 133577 2025-08-28 17:03:57,355 [cuckoo.core.resultserver] DEBUG: Task #6920144 is sending a BSON stream 2025-08-28 17:04:08,293 [cuckoo.core.guest] DEBUG: win7x6416: analysis #6920144 still processing 2025-08-28 17:04:23,433 [cuckoo.core.guest] DEBUG: win7x6416: analysis #6920144 still processing 2025-08-28 17:04:24,111 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'curtain/1756220415.44.curtain.log' 2025-08-28 17:04:24,127 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 36 2025-08-28 17:04:24,248 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'sysmon/1756220415.58.sysmon.xml' 2025-08-28 17:04:24,260 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 411090 2025-08-28 17:04:24,272 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/b3a09f7255edc789_rdoti90 6r3apw4 hole qcjxxhb .avi.exe' 2025-08-28 17:04:24,280 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 934857 2025-08-28 17:04:24,287 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/17891c4de2f6bba2_z8dvsxk 6r3apw4 wzxubo (q922zop0f,5qcarib).mpg.exe' 2025-08-28 17:04:24,296 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 931623 2025-08-28 17:04:24,301 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/196858beb2ca613b_yn0pxd porn l8qccpyq kmozxo (ynve4mgf).zip.exe' 2025-08-28 17:04:24,308 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 617419 2025-08-28 17:04:24,311 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/246f1f8b267855d3_yn0pxd ko6o6a sperm wk79oa4s2r04wd ngo69ybvy (q922zop0f,v89zo5).zip.exe' 2025-08-28 17:04:24,318 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 998815 2025-08-28 17:04:24,328 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/519da6203e5c30d0_yn0pxd y6go35p beast 6r3apw4 (ysxdgxr).mpeg.exe' 2025-08-28 17:04:24,345 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1817035 2025-08-28 17:04:24,358 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/da84f8eb1c5dcf0c_horse [free] feet kgh6zo8 .avi.exe' 2025-08-28 17:04:24,389 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1504401 2025-08-28 17:04:24,404 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/21ec912093d9d923_z8dvsxk [milf] ttbp10m .zip.exe' 2025-08-28 17:04:24,417 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1595296 2025-08-28 17:04:24,426 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/5e73cff23a23cbb0_cw4ymo3u nude xxx srpvkzygmcsw (liz).zip.exe' 2025-08-28 17:04:24,436 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/7585dd988b63b8f7_tvolgth jmmawhs beast [milf] (ysxdgxr).avi.exe' 2025-08-28 17:04:24,440 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 894709 2025-08-28 17:04:24,445 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 445713 2025-08-28 17:04:24,449 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/4331ab78219c811d_l8qccpyq f6br2s2 .mpeg.exe' 2025-08-28 17:04:24,457 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 598835 2025-08-28 17:04:24,461 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/7fe4bac984b55e0c_yn0pxd nude sperm srpvkzygmcsw feet 50+ .avi.exe' 2025-08-28 17:04:24,471 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 861107 2025-08-28 17:04:24,482 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/4330af93d9684ae9_r2qc46i jmmawhs 9k8bf2i [free] wzxubo .mpg.exe' 2025-08-28 17:04:24,488 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/ae072fb30ea9b6e1_windows6g2yf6t03h' 2025-08-28 17:04:24,498 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/59d0a16f47815543_rdoti90 6mjj01 latex .zip.exe' 2025-08-28 17:04:24,521 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 998400 2025-08-28 17:04:24,526 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/bd6b33826f36edf8_horse kmozxo glans .mpg.exe' 2025-08-28 17:04:24,537 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 923158 2025-08-28 17:04:24,545 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 554644 2025-08-28 17:04:24,556 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1560140 2025-08-28 17:04:24,579 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/e2ec00eb44689bc5_xxx wk79oa4s2r04wd sd7o90wnjx .mpeg.exe' 2025-08-28 17:04:24,657 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 2051220 2025-08-28 17:04:24,671 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/11671031327c36c8_a3xo5xtn [milf] cock wifey (jade).avi.exe' 2025-08-28 17:04:24,686 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/749f776cc3ecee0b_vftv0ou m5v129k gay big .mpeg.exe' 2025-08-28 17:04:24,707 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 348057 2025-08-28 17:04:24,710 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1078853 2025-08-28 17:04:24,720 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/94e0ecec38fdbc08_xiwlzi0 m5v129k l8qccpyq 6mjj01 glans hairy (karin).zip.exe' 2025-08-28 17:04:24,740 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1723087 2025-08-28 17:04:24,752 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/91f81751f46d272f_xiwlzi0 nude horse 6r3apw4 .mpeg.exe' 2025-08-28 17:04:24,759 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 771935 2025-08-28 17:04:24,763 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/8f4e21a1ba9887aa_l8qccpyq big feet (sr0fncw4,ysxdgxr).zip.exe' 2025-08-28 17:04:24,768 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 222263 2025-08-28 17:04:24,771 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/d714663e8df0d9af_cw4ymo3u jmmawhs xxx fs8utd feet rqmct8k1i30 .mpeg.exe' 2025-08-28 17:04:24,781 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1128025 2025-08-28 17:04:24,795 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/dd527dfa150b1d41_yn0pxd horse xxx 6mjj01 50+ .mpg.exe' 2025-08-28 17:04:24,817 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 2061160 2025-08-28 17:04:24,824 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/5d3b25abdbb7f18f_l8qccpyq 6r3apw4 titts 6jug8f (sarah).mpg.exe' 2025-08-28 17:04:24,842 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/3e7ec35bb901cb2f_xiwlzi0 9oypb8 a3xo5xtn [milf] aqp9g9a .mpeg.exe' 2025-08-28 17:04:24,904 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1634098 2025-08-28 17:04:24,911 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 88777 2025-08-28 17:04:24,914 [cuckoo.core.resultserver] DEBUG: Task #6920144: File upload for 'files/44b821b77a31318a_sperm [free] 45ld689 .avi.exe' 2025-08-28 17:04:24,977 [cuckoo.core.resultserver] DEBUG: Task #6920144 uploaded file length: 1106950 2025-08-28 17:04:24,994 [cuckoo.core.resultserver] DEBUG: Task #6920144 had connection reset for <Context for LOG> 2025-08-28 17:04:26,454 [cuckoo.core.guest] INFO: win7x6416: analysis completed successfully 2025-08-28 17:04:26,469 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-28 17:04:26,508 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-28 17:04:27,205 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6416 to path /srv/cuckoo/cwd/storage/analyses/6920144/memory.dmp 2025-08-28 17:04:27,207 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6416 2025-08-28 17:04:41,716 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.216 for task #6920144 2025-08-28 17:04:42,059 [cuckoo.core.scheduler] DEBUG: Released database task #6920144 2025-08-28 17:04:42,080 [cuckoo.core.scheduler] INFO: Task #6920144: analysis procedure completed
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | Create or check mutex | rule | win_mutex | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect private profile | rule | win_files_operation |
section | .text\x00\xe5\xfb |
section | .data\x00E\x86 |
packer | Pelles C 3.00, 4.00, 4.50 EXE (X86 CRT-LIB) |
description | 86525da3ee899345ee72bc542ba7f23b03a56a5100334510d76e190cc93fa1c7.exe tried to sleep 149 seconds, actually delayed analysis time by 149 seconds |
file | C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates\sperm [free] 45ld689 .avi.exe |
file | C:\Users\Administrator\AppData\Local\Temporary Internet Files\rdoti90 6r3apw4 hole qcjxxhb .avi.exe |
file | C:\Users\All Users\Microsoft\RAC\Temp\xiwlzi0 nude horse 6r3apw4 .mpeg.exe |
file | C:\Windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor.Resources\z8dvsxk 6r3apw4 wzxubo (q922zop0f,5qcarib).mpg.exe |
file | C:\Users\Administrator\Templates\yn0pxd nude sperm srpvkzygmcsw feet 50+ .avi.exe |
file | C:\Users\Administrator\AppData\Local\Temp\mozilla-temp-files\rdoti90 6mjj01 latex .zip.exe |
file | C:\Program Files (x86)\Windows Sidebar\Shared Gadgets\9k8bf2i uncut kpbv9mg7 .avi.exe |
file | C:\ProgramData\Microsoft\RAC\Temp\yn0pxd ko6o6a sperm wk79oa4s2r04wd ngo69ybvy (q922zop0f,v89zo5).zip.exe |
file | C:\Program Files\Common Files\Microsoft Shared\yn0pxd horse xxx 6mjj01 50+ .mpg.exe |
file | C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Templates\gay f6br2s2 girly .rar.exe |
file | C:\Program Files (x86)\Adobe\Reader 9.0\Reader\IDTemplates\vftv0ou m5v129k gay big .mpeg.exe |
file | C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\14\Notebook Templates\l8qccpyq [free] kpbv9mg7 .zip.exe |
file | C:\Users\Administrator\AppData\Local\Temp\cw4ymo3u jmmawhs xxx fs8utd feet rqmct8k1i30 .mpeg.exe |
file | C:\Program Files\DVD Maker\Shared\r2qc46i jmmawhs 9k8bf2i [free] wzxubo .mpg.exe |
file | C:\Users\All Users\Microsoft\Search\Data\Temp\horse kmozxo glans .mpg.exe |
file | C:\Windows\assembly\GAC_64\Microsoft.GroupPolicy.AdmTmplEditor\vftv0ou nude rdoti90 [free] shoes (q922zop0f,Karin).avi.exe |
file | C:\Program Files\Windows Sidebar\Shared Gadgets\z8dvsxk [milf] ttbp10m .zip.exe |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\tvolgth jmmawhs beast [milf] (ysxdgxr).avi.exe |
file | C:\ProgramData\Microsoft\Search\Data\Temp\l8qccpyq f6br2s2 .mpeg.exe |
file | C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\sperm wk79oa4s2r04wd girly .mpeg.exe |
file | C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor\gay [bangbus] wzxubo .rar.exe |
file | C:\Users\Default\Templates\xiwlzi0 m5v129k l8qccpyq 6mjj01 glans hairy (Karin).zip.exe |
file | C:\Users\Administrator\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\xiwlzi0 m5v129k xxx uncut (v89zo5).mpg.exe |
file | C:\Windows\assembly\GAC_32\Microsoft.GroupPolicy.AdmTmplEditor.Resources\a3xo5xtn [milf] cock wifey (Jade).avi.exe |
file | C:\Users\Default\AppData\Local\Temp\xiwlzi0 mtu2oyuh5 6r3apw4 uncut .rar.exe |
file | C:\Users\Default\AppData\Local\Temporary Internet Files\horse [free] feet kgh6zo8 .avi.exe |
file | C:\tmpj6atou\l8qccpyq big feet (sr0fncw4,ysxdgxr).zip.exe |
file | C:\ProgramData\Templates\yn0pxd porn l8qccpyq kmozxo (ynve4mgf).zip.exe |
file | C:\Users\All Users\Microsoft\Windows\Templates\yn0pxd y6go35p beast 6r3apw4 (ysxdgxr).mpeg.exe |
file | C:\Program Files\Windows Journal\Templates\cw4ymo3u nude xxx srpvkzygmcsw (Liz).zip.exe |
file | C:\Program Files\Microsoft Office\Templates\sperm fs8utd .mpg.exe |
file | C:\ProgramData\Microsoft\Windows\Templates\l8qccpyq 6r3apw4 titts 6jug8f (Sarah).mpg.exe |
file | C:\Users\All Users\Templates\xxx wk79oa4s2r04wd sd7o90wnjx .mpeg.exe |
file | C:\Program Files (x86)\Common Files\microsoft shared\xiwlzi0 9oypb8 a3xo5xtn [milf] aqp9g9a .mpeg.exe |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\rdoti90 6r3apw4 hole qcjxxhb .avi.exe |
G Data Antivirus (Windows) | Virus: Generic.Malware.PfVPk!1!prn!.FE0B916D (Engine A) |
Avast Core Security (Linux) | Win32:MalwareX-gen [Misc] |
C4S ClamAV (Linux) | Win.Malware.Pvpk-10056926-0 |
Trellix (Linux) | GenericRXMK-QV |
WithSecure (Linux) | Trojan.TR/Spy.Gen |
eScan Antivirus (Linux) | Generic.Malware.PfVPk!1!prn!.FE0B916D(DB) |
ESET Security (Windows) | a variant of Win32/Agent.CP worm |
Sophos Anti-Virus (Linux) | Mal/Generic-S |
DrWeb Antivirus (Linux) | Win32.HLLW.Siggen.1607 |
ClamAV (Linux) | Win.Malware.Pvpk-10056926-0 |
Bitdefender Antivirus (Linux) | Generic.Malware.PfVPk!1!prn!.FE0B916D |
Kaspersky Standard (Windows) | HEUR:Trojan.Win32.Generic |
Emsisoft Commandline Scanner (Windows) | Generic.Malware.PfVPk!1!prn!.FE0B916D (B) |
Bkav | W32.AIDetectMalware |
tehtris | Generic.Malware |
Cynet | Malicious (score: 100) |
Skyhigh | BehavesLike.Win32.Generic.nh |
ALYac | Generic.Malware.PfVPk!1!prn!.FE0B916D |
Cylance | Unsafe |
VIPRE | Generic.Malware.PfVPk!1!prn!.FE0B916D |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_100% (D) |
BitDefender | Generic.Malware.PfVPk!1!prn!.FE0B916D |
K7GW | Trojan ( 004ca8b71 ) |
K7AntiVirus | Trojan ( 004ca8b71 ) |
Arcabit | Generic.Malware.PfVPk!1!prn!.FE0B916D |
Baidu | Win32.Worm.Agent.fj |
VirIT | Worm.Win32.Agent.CP |
Symantec | ML.Attribute.HighConfidence |
Elastic | Windows.Generic.Threat |
ESET-NOD32 | a variant of Win32/Agent.CP |
APEX | Malicious |
Avast | Win32:MalwareX-gen [Misc] |
ClamAV | Win.Malware.Pvpk-10056926-0 |
Kaspersky | UDS:Trojan.Win32.Generic |
NANO-Antivirus | Trojan.Win32.Wofith.iariji |
MicroWorld-eScan | Generic.Malware.PfVPk!1!prn!.FE0B916D |
Rising | Worm.Agent!1.12BB7 (CLASSIC) |
Emsisoft | Generic.Malware.PfVPk!1!prn!.FE0B916D (B) |
F-Secure | Trojan.TR/Spy.Gen |
DrWeb | Win32.HLLW.Siggen.1607 |
Zillya | Worm.Agent.Win32.9 |
McAfeeD | Real Protect-LS!E96C7486D3D6 |
Trapmine | malicious.high.ml.score |
CTX | exe.unknown.pfvpk |
Sophos | ML/PE-A |
SentinelOne | Static AI - Malicious PE |
Jiangmin | Worm.Agent.yh |
Webroot | W32.Worm.Gen |
Detected | |
Avira | TR/Spy.Gen |
Antiy-AVL | Trojan/Win32.Vindor |
Kingsoft | malware.kb.a.1000 |
Gridinsoft | Ransom.Win32.Zbot.oa!s1 |
Microsoft | Worm:Win32/Sfone!pz |
GData | Win32.Trojan.PSE.1F2XTI5 |
Varist | W32/Agent.LDP.gen!Eldorado |
AhnLab-V3 | Worm/Win.Generic.R704852 |
Acronis | suspicious |
VBA32 | BScope.Worm.Convagent |
DeepInstinct | MALICIOUS |
Malwarebytes | Generic.Malware.AI.DDS |
Ikarus | Worm.Win32.Agent |