Size | 714.9MB |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 1335e72ce95e270629c53b82529fb20a |
SHA1 | bc1ff081797b2b21040a82c069c6ad44b29710ac |
SHA256 | e8f0cdf21a55fc27f4149390a1db90491c3ab38aaa827afb541e1716df8886c4 |
SHA512 |
f64aafa56930ef713bab37e8535134b3f27be2cec9c453dd3ac73720763e982f8534a4ed3dca02981520e0ac79c04a2cccdcfc85bece6f8a27ee93d526648d1f
|
CRC32 | 52EA96AE |
ssdeep | None |
PDB Path | C:\CodeBases\isdev\redist\Language Independent\i386\setupPreReq.pdb |
Yara | None matched |
This file shows some signs of potential malicious behavior.
The score of this file is 1.1 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Sept. 9, 2025, 5:59 a.m. | Sept. 9, 2025, 6:03 a.m. | 278 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-09-09 05:59:12,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd 2025-09-09 05:59:12,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\ArtsAKZRHUWZdZwPjHQvNxbYfWhWyBw 2025-09-09 05:59:12,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\UGkEenmONhSpxgqUtWValTlImpNZxh 2025-09-09 05:59:12,890 [analyzer] DEBUG: Started auxiliary module Curtain 2025-09-09 05:59:12,890 [analyzer] DEBUG: Started auxiliary module DbgView 2025-09-09 05:59:13,296 [analyzer] DEBUG: Started auxiliary module Disguise 2025-09-09 05:59:13,500 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-09-09 05:59:13,500 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-09-09 05:59:13,500 [analyzer] DEBUG: Started auxiliary module Human 2025-09-09 05:59:13,500 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-09-09 05:59:13,515 [analyzer] DEBUG: Started auxiliary module Reboot 2025-09-09 05:59:13,592 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-09-09 05:59:13,592 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-09-09 05:59:13,592 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-09-09 05:59:13,592 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-09-09 05:59:19,000 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\Setup_Vector_Logger_Suite_4.5.6.exe' with arguments '' and pid 2312 2025-09-09 05:59:19,217 [analyzer] DEBUG: Loaded monitor into process with pid 2312 2025-09-09 05:59:20,467 [analyzer] INFO: Added new file to list with pid 2312 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\_ISMSIDEL.INI 2025-09-09 05:59:20,546 [analyzer] INFO: Added new file to list with pid 2312 and path C:\Users\Administrator\AppData\Local\Temp\~E3C9.tmp 2025-09-09 05:59:20,608 [analyzer] INFO: Added new file to list with pid 2312 and path C:\Users\Administrator\AppData\Local\Temp\~E408.tmp 2025-09-09 05:59:20,671 [analyzer] INFO: Added new file to list with pid 2312 and path C:\Users\Administrator\AppData\Local\Temp\~E457.tmp 2025-09-09 05:59:20,750 [analyzer] INFO: Added new file to list with pid 2312 and path C:\Users\Administrator\AppData\Local\Temp\~E497.tmp 2025-09-09 05:59:27,015 [analyzer] INFO: Injected into process with pid 1448 and name '' 2025-09-09 05:59:27,203 [analyzer] DEBUG: Loaded monitor into process with pid 1448 2025-09-09 05:59:27,280 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Setup.INI 2025-09-09 05:59:27,312 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\0x0409.ini 2025-09-09 05:59:27,421 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\~FEB3.tmp 2025-09-09 05:59:27,453 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\~FED4.tmp 2025-09-09 05:59:27,500 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Microsoft Visual C++ 2022 Redistributable Package (x64).prq 2025-09-09 05:59:27,530 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Microsoft Visual C++ 2022 Redistributable Package (x86).prq 2025-09-09 05:59:27,562 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Windows Installer 3.1 (x86).prq 2025-09-09 05:59:27,687 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Microsoft Visual C++ 2010 SP1 Redistributable Package (x86).prq 2025-09-09 05:59:27,733 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Windows Installer 3.1 for Windows Server 2003 SP1 (x64).prq 2025-09-09 05:59:27,828 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Windows Installer 3.1 for Windows XP (x64).prq 2025-09-09 05:59:27,921 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Microsoft Visual C++ 2010 SP1 Redistributable Package (x64).prq 2025-09-09 05:59:27,953 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Microsoft .NET Framework 4.8 Full.prq 2025-09-09 05:59:27,983 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Microsoft Visual C++ 2013 Redistributable Package (x86).prq 2025-09-09 05:59:28,015 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Microsoft Visual C++ 2013 Redistributable Package (x64).prq 2025-09-09 05:59:28,046 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Vector ShellExtension 64Bit.prq 2025-09-09 05:59:28,092 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Vector ShellExtension 32Bit.prq 2025-09-09 05:59:28,125 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Microsoft .NET Framework 4.7.1 Full.prq 2025-09-09 05:59:28,155 [analyzer] INFO: Added new file to list with pid 1448 and path C:\Users\Administrator\AppData\Local\Temp\{087D6D34-1C13-4AA1-B9B1-5B07858B9451}\Vector Support Assistant 64Bit.prq 2025-09-09 05:03:40,039 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-09-09 05:03:40,275 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2312. 2025-09-09 05:03:40,368 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1448. 2025-09-09 05:03:40,618 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-09-09 05:03:40,618 [lib.api.process] INFO: Successfully terminated process with pid 2312. 2025-09-09 05:03:40,634 [lib.api.process] INFO: Successfully terminated process with pid 1448. 2025-09-09 05:03:40,697 [analyzer] INFO: Analysis completed.
2025-09-09 05:59:30,413 [cuckoo.core.scheduler] INFO: Task #6962670: acquired machine win7x6412 (label=win7x6412) 2025-09-09 05:59:30,414 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.212 for task #6962670 2025-09-09 05:59:30,922 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1185595 (interface=vboxnet0, host=192.168.168.212) 2025-09-09 06:02:13,216 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6412 2025-09-09 06:02:14,144 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6412 to vmcloak 2025-09-09 06:02:24,236 [cuckoo.core.guest] INFO: Starting analysis #6962670 on guest (id=win7x6412, ip=192.168.168.212) 2025-09-09 06:02:25,242 [cuckoo.core.guest] DEBUG: win7x6412: not ready yet 2025-09-09 06:02:30,280 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6412, ip=192.168.168.212) 2025-09-09 06:02:30,360 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6412, ip=192.168.168.212, monitor=latest, size=6660546) 2025-09-09 06:03:04,016 [cuckoo.core.resultserver] DEBUG: Task #6962670: live log analysis.log initialized. 2025-09-09 06:03:05,481 [cuckoo.core.resultserver] DEBUG: Task #6962670 is sending a BSON stream 2025-09-09 06:03:06,819 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'shots/0001.jpg' 2025-09-09 06:03:06,869 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 133462 2025-09-09 06:03:11,184 [cuckoo.core.resultserver] DEBUG: Task #6962670 is sending a BSON stream 2025-09-09 06:03:12,622 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/c949ff7cb4005482_~E3C9.tmp' 2025-09-09 06:03:12,625 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 7604 2025-09-09 06:03:18,435 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6962670 still processing 2025-09-09 06:03:19,152 [cuckoo.core.resultserver] DEBUG: Task #6962670 is sending a BSON stream 2025-09-09 06:03:19,318 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/e3b0c44298fc1c14__MSI5166._IS' 2025-09-09 06:03:19,321 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 0 2025-09-09 06:03:19,701 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/6428ad0bd3732a20__isFF52..dll' 2025-09-09 06:03:19,725 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 2341376 2025-09-09 06:03:21,381 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'shots/0002.jpg' 2025-09-09 06:03:21,397 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 141293 2025-09-09 06:03:33,539 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6962670 still processing 2025-09-09 06:03:40,539 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'curtain/1757387020.53.curtain.log' 2025-09-09 06:03:40,542 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 36 2025-09-09 06:03:40,629 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'sysmon/1757387020.62.sysmon.xml' 2025-09-09 06:03:40,634 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 145478 2025-09-09 06:03:40,641 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/a885b7b4e07de7c1_microsoft .net framework 4.7.1 full.prq' 2025-09-09 06:03:40,645 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1529 2025-09-09 06:03:40,649 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/d5a15daf97ad83fc_windows installer 3.1 for windows xp (x64).prq' 2025-09-09 06:03:40,651 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1180 2025-09-09 06:03:40,653 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/1807b72ee8fdbf0e_windows installer 3.1 for windows server 2003 sp1 (x64).prq' 2025-09-09 06:03:40,655 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1220 2025-09-09 06:03:40,658 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/bc5e411a20417464_microsoft visual c++ 2013 redistributable package (x86).prq' 2025-09-09 06:03:40,659 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1859 2025-09-09 06:03:40,662 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/bd9f091c0dc6cbbc_windows installer 3.1 (x86).prq' 2025-09-09 06:03:40,664 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1572 2025-09-09 06:03:40,667 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/10515a7b58c2c1a1_microsoft .net framework 4.8 full.prq' 2025-09-09 06:03:40,668 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1588 2025-09-09 06:03:40,671 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/545e3c368f91e23d_microsoft visual c++ 2010 sp1 redistributable package (x86).prq' 2025-09-09 06:03:40,672 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 2416 2025-09-09 06:03:40,675 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/eccb9037ee039153_microsoft visual c++ 2022 redistributable package (x64).prq' 2025-09-09 06:03:40,676 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1247 2025-09-09 06:03:40,678 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/3a929161725c22f5__ismsidel.ini' 2025-09-09 06:03:40,680 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 5804 2025-09-09 06:03:40,683 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/ef88c06fdf8f50d0_vector support assistant 64bit.prq' 2025-09-09 06:03:40,685 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1016 2025-09-09 06:03:40,687 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/96bbec6f94ccffdf_microsoft visual c++ 2022 redistributable package (x86).prq' 2025-09-09 06:03:40,689 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1353 2025-09-09 06:03:40,692 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/8b76df0ffc9a226b_0x0409.ini' 2025-09-09 06:03:40,694 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 22480 2025-09-09 06:03:40,695 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/682f6a4a60c485d4_vector shellextension 32bit.prq' 2025-09-09 06:03:40,697 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 650 2025-09-09 06:03:40,698 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/24ccb7f678f67fa0_vector shellextension 64bit.prq' 2025-09-09 06:03:40,700 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 638 2025-09-09 06:03:40,702 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/c2e342bbe9a14e2e_microsoft visual c++ 2013 redistributable package (x64).prq' 2025-09-09 06:03:40,703 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 1648 2025-09-09 06:03:40,705 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'files/c1e1a0a0c3fc2ad7_microsoft visual c++ 2010 sp1 redistributable package (x64).prq' 2025-09-09 06:03:40,706 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 2019 2025-09-09 06:03:41,060 [cuckoo.core.resultserver] DEBUG: Task #6962670: File upload for 'shots/0003.jpg' 2025-09-09 06:03:41,076 [cuckoo.core.resultserver] DEBUG: Task #6962670 uploaded file length: 133455 2025-09-09 06:03:41,091 [cuckoo.core.resultserver] DEBUG: Task #6962670 had connection reset for <Context for LOG> 2025-09-09 06:03:42,591 [cuckoo.core.guest] INFO: win7x6412: analysis completed successfully 2025-09-09 06:03:42,604 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-09-09 06:03:42,628 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-09-09 06:03:43,959 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6412 to path /srv/cuckoo/cwd/storage/analyses/6962670/memory.dmp 2025-09-09 06:03:43,961 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6412 2025-09-09 06:03:52,534 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.212 for task #6962670 2025-09-09 06:03:52,849 [cuckoo.core.scheduler] DEBUG: Released database task #6962670 2025-09-09 06:03:52,865 [cuckoo.core.scheduler] INFO: Task #6962670: analysis procedure completed
pdb_path | C:\CodeBases\isdev\redist\Language Independent\i386\setupPreReq.pdb |
resource name | GIF |
resource name | PNG |
file | C:\Users\Administrator\AppData\Local\Temp\_isFF52..dll |