| Size | 176.4KB |
|---|---|
| Type | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5 | e61a851eb367a605ec25b9efa2f48931 |
| SHA1 | 0ebf62b274673640b947bc5ca1b90e0a2b62162a |
| SHA256 | eb5d7c439a65cc1677c19dd3656bfa9d883cf1f78789b37bf02f2b15422bb086 |
| SHA512 |
76d639b5c15cf1e9d14ea6abad3dee8f8c2eafae1903490b16b60904be92a587698cc37c7bc608c4fea36bc959ecbb29c467a9729d6c3300ccbe6fe362baeedf
|
| CRC32 | 99386E87 |
| ssdeep | None |
| Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Nov. 29, 2025, 10:56 p.m. | Nov. 29, 2025, 10:57 p.m. | 73 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-11-29 21:55:32,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpd0os1j 2025-11-29 21:55:32,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\LEgmVFgRjicwjgIULVMGH 2025-11-29 21:55:32,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\OlbBZMdwTIOgbCrDVX 2025-11-29 21:55:32,280 [analyzer] DEBUG: Started auxiliary module Curtain 2025-11-29 21:55:32,280 [analyzer] DEBUG: Started auxiliary module DbgView 2025-11-29 21:55:32,733 [analyzer] DEBUG: Started auxiliary module Disguise 2025-11-29 21:55:32,921 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-11-29 21:55:32,921 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-11-29 21:55:32,921 [analyzer] DEBUG: Started auxiliary module Human 2025-11-29 21:55:32,921 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-11-29 21:55:32,921 [analyzer] DEBUG: Started auxiliary module Reboot 2025-11-29 21:55:33,046 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-11-29 21:55:33,046 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-11-29 21:55:33,046 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-11-29 21:55:33,046 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-11-29 21:55:33,155 [lib.api.process] INFO: Successfully executed process from path 'bin/7za.exe' with arguments ['x', u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\XSyAlpha16.zip', '-pinfected'] and pid 2172 2025-11-29 21:57:05,232 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\ose00000.exe' with arguments '' and pid 1416 2025-11-29 21:57:05,466 [analyzer] DEBUG: Loaded monitor into process with pid 1416 2025-11-29 21:57:06,232 [analyzer] INFO: Process with pid 1416 has terminated 2025-11-29 21:57:06,232 [analyzer] INFO: Process list is empty, terminating analysis. 2025-11-29 21:57:07,513 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-11-29 21:57:07,513 [analyzer] INFO: Analysis completed.
2025-11-29 22:56:06,074 [cuckoo.core.scheduler] INFO: Task #7208335: acquired machine win7x6429 (label=win7x6429) 2025-11-29 22:56:06,075 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.229 for task #7208335 2025-11-29 22:56:06,490 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 640471 (interface=vboxnet0, host=192.168.168.229) 2025-11-29 22:56:06,501 [cuckoo.common.objects] WARNING: Error extracting package and main activity: File is not a zip file. 2025-11-29 22:56:06,542 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6429 2025-11-29 22:56:07,884 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6429 to vmcloak 2025-11-29 22:56:26,233 [cuckoo.core.guest] INFO: Starting analysis #7208335 on guest (id=win7x6429, ip=192.168.168.229) 2025-11-29 22:56:27,239 [cuckoo.core.guest] DEBUG: win7x6429: not ready yet 2025-11-29 22:56:32,272 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6429, ip=192.168.168.229) 2025-11-29 22:56:32,358 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6429, ip=192.168.168.229, monitor=latest, size=6660546) 2025-11-29 22:56:33,672 [cuckoo.core.resultserver] DEBUG: Task #7208335: live log analysis.log initialized. 2025-11-29 22:56:34,563 [cuckoo.core.resultserver] DEBUG: Task #7208335 is sending a BSON stream 2025-11-29 22:56:35,883 [cuckoo.core.resultserver] DEBUG: Task #7208335: File upload for 'shots/0001.jpg' 2025-11-29 22:56:35,900 [cuckoo.core.resultserver] DEBUG: Task #7208335 uploaded file length: 133421 2025-11-29 22:56:48,278 [cuckoo.core.guest] DEBUG: win7x6429: analysis #7208335 still processing 2025-11-29 22:57:03,380 [cuckoo.core.guest] DEBUG: win7x6429: analysis #7208335 still processing 2025-11-29 22:57:05,328 [cuckoo.core.resultserver] DEBUG: Task #7208335 is sending a BSON stream 2025-11-29 22:57:07,400 [cuckoo.core.resultserver] DEBUG: Task #7208335: File upload for 'curtain/1764449827.39.curtain.log' 2025-11-29 22:57:07,405 [cuckoo.core.resultserver] DEBUG: Task #7208335 uploaded file length: 36 2025-11-29 22:57:07,523 [cuckoo.core.resultserver] DEBUG: Task #7208335: File upload for 'sysmon/1764449827.51.sysmon.xml' 2025-11-29 22:57:07,529 [cuckoo.core.resultserver] DEBUG: Task #7208335 uploaded file length: 188708 2025-11-29 22:57:07,837 [cuckoo.core.resultserver] DEBUG: Task #7208335 had connection reset for <Context for LOG> 2025-11-29 22:57:09,416 [cuckoo.core.guest] INFO: win7x6429: analysis completed successfully 2025-11-29 22:57:09,431 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-11-29 22:57:09,461 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-11-29 22:57:10,634 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6429 to path /srv/cuckoo/cwd/storage/analyses/7208335/memory.dmp 2025-11-29 22:57:10,635 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6429 2025-11-29 22:57:18,820 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.229 for task #7208335 2025-11-29 22:57:19,130 [cuckoo.core.scheduler] DEBUG: Released database task #7208335 2025-11-29 22:57:19,149 [cuckoo.core.scheduler] INFO: Task #7208335: analysis procedure completed
No signatures