| Size | 12.7KB |
|---|---|
| Type | ASCII text, with very long lines (4127), with CRLF line terminators |
| MD5 | 1499c42dac1638b8fe44e9f7e6020c06 |
| SHA1 | 8467e55a871521f2a6b494c7a632900a42f9bf91 |
| SHA256 | c63541eeb8a0614ddbc9eecee085ba43dca6ca2882645237d319f58b48f9a4a4 |
| SHA512 |
631dcd891a8bc5184ac449916274b83d050a6fba71d16520e47c14eecce80d7c83cf62cd0f37b09305c4211ab36b3019384ac922fc66c58600e332bc5c5bc3e2
|
| CRC32 | 14109FF0 |
| ssdeep | None |
| Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Oct. 11, 2025, 11:24 a.m. | Oct. 11, 2025, 11:25 a.m. | 59 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-10-11 11:24:18,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpht3fil 2025-10-11 11:24:18,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\JFQCxWYQexGwQEKjtwLMhMvSwiZ 2025-10-11 11:24:18,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\NGEhJHIqGzqcDZEJjBoQL 2025-10-11 11:24:18,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-10-11 11:24:18,015 [analyzer] INFO: Automatically selected analysis package "generic" 2025-10-11 11:24:18,265 [analyzer] DEBUG: Started auxiliary module Curtain 2025-10-11 11:24:18,265 [analyzer] DEBUG: Started auxiliary module DbgView 2025-10-11 11:24:18,687 [analyzer] DEBUG: Started auxiliary module Disguise 2025-10-11 11:24:18,890 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-10-11 11:24:18,890 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-10-11 11:24:18,890 [analyzer] DEBUG: Started auxiliary module Human 2025-10-11 11:24:18,890 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-10-11 11:24:18,890 [analyzer] DEBUG: Started auxiliary module Reboot 2025-10-11 11:24:18,983 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-10-11 11:24:18,983 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-10-11 11:24:18,983 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-10-11 11:24:19,000 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-10-11 11:24:19,078 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"qypSNgWpbnmVTON"', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\WinSCP.ini'] and pid 216 2025-10-11 11:24:19,358 [analyzer] DEBUG: Loaded monitor into process with pid 216 2025-10-11 11:24:26,562 [analyzer] INFO: Injected into process with pid 2240 and name u'notepad.exe' 2025-10-11 11:24:26,812 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2240. 2025-10-11 11:24:27,030 [analyzer] DEBUG: Loaded monitor into process with pid 2240 2025-10-11 10:25:07,132 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-10-11 10:25:07,460 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 216. 2025-10-11 10:25:07,553 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2240. 2025-10-11 10:25:07,835 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-10-11 10:25:07,835 [lib.api.process] INFO: Successfully terminated process with pid 216. 2025-10-11 10:25:07,835 [lib.api.process] INFO: Successfully terminated process with pid 2240. 2025-10-11 10:25:07,835 [analyzer] INFO: Analysis completed.
2025-10-11 11:24:19,434 [cuckoo.core.scheduler] INFO: Task #7028600: acquired machine win7x6411 (label=win7x6411) 2025-10-11 11:24:19,435 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.211 for task #7028600 2025-10-11 11:24:19,853 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3007440 (interface=vboxnet0, host=192.168.168.211) 2025-10-11 11:24:19,954 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6411 2025-10-11 11:24:20,522 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6411 to vmcloak 2025-10-11 11:24:29,361 [cuckoo.core.guest] INFO: Starting analysis #7028600 on guest (id=win7x6411, ip=192.168.168.211) 2025-10-11 11:24:30,392 [cuckoo.core.guest] DEBUG: win7x6411: not ready yet 2025-10-11 11:24:35,420 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6411, ip=192.168.168.211) 2025-10-11 11:24:35,498 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6411, ip=192.168.168.211, monitor=latest, size=6660546) 2025-10-11 11:24:37,020 [cuckoo.core.resultserver] DEBUG: Task #7028600: live log analysis.log initialized. 2025-10-11 11:24:37,870 [cuckoo.core.resultserver] DEBUG: Task #7028600 is sending a BSON stream 2025-10-11 11:24:38,262 [cuckoo.core.resultserver] DEBUG: Task #7028600 is sending a BSON stream 2025-10-11 11:24:39,129 [cuckoo.core.resultserver] DEBUG: Task #7028600: File upload for 'shots/0001.jpg' 2025-10-11 11:24:39,141 [cuckoo.core.resultserver] DEBUG: Task #7028600 uploaded file length: 113175 2025-10-11 11:24:45,948 [cuckoo.core.resultserver] DEBUG: Task #7028600 is sending a BSON stream 2025-10-11 11:24:47,460 [cuckoo.core.resultserver] DEBUG: Task #7028600: File upload for 'shots/0002.jpg' 2025-10-11 11:24:47,472 [cuckoo.core.resultserver] DEBUG: Task #7028600 uploaded file length: 86921 2025-10-11 11:24:48,570 [cuckoo.core.resultserver] DEBUG: Task #7028600: File upload for 'shots/0003.jpg' 2025-10-11 11:24:48,583 [cuckoo.core.resultserver] DEBUG: Task #7028600 uploaded file length: 141188 2025-10-11 11:24:51,590 [cuckoo.core.guest] DEBUG: win7x6411: analysis #7028600 still processing 2025-10-11 11:25:06,871 [cuckoo.core.guest] DEBUG: win7x6411: analysis #7028600 still processing 2025-10-11 11:25:07,694 [cuckoo.core.resultserver] DEBUG: Task #7028600: File upload for 'curtain/1760171107.68.curtain.log' 2025-10-11 11:25:07,698 [cuckoo.core.resultserver] DEBUG: Task #7028600 uploaded file length: 36 2025-10-11 11:25:07,834 [cuckoo.core.resultserver] DEBUG: Task #7028600: File upload for 'sysmon/1760171107.82.sysmon.xml' 2025-10-11 11:25:07,840 [cuckoo.core.resultserver] DEBUG: Task #7028600 uploaded file length: 285282 2025-10-11 11:25:08,256 [cuckoo.core.resultserver] DEBUG: Task #7028600: File upload for 'shots/0004.jpg' 2025-10-11 11:25:08,277 [cuckoo.core.resultserver] DEBUG: Task #7028600 uploaded file length: 133541 2025-10-11 11:25:08,293 [cuckoo.core.resultserver] DEBUG: Task #7028600 had connection reset for <Context for LOG> 2025-10-11 11:25:09,889 [cuckoo.core.guest] INFO: win7x6411: analysis completed successfully 2025-10-11 11:25:09,901 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-10-11 11:25:09,919 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-10-11 11:25:10,965 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6411 to path /srv/cuckoo/cwd/storage/analyses/7028600/memory.dmp 2025-10-11 11:25:10,966 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6411 2025-10-11 11:25:18,694 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.211 for task #7028600 2025-10-11 11:25:19,006 [cuckoo.core.scheduler] DEBUG: Released database task #7028600 2025-10-11 11:25:19,023 [cuckoo.core.scheduler] INFO: Task #7028600: analysis procedure completed