| Size | 20.1MB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | 5537c708edb9a2c21f88e34e8a0f1744 |
| SHA1 | 86233a285363c2a6863bf642deab7e20f062b8eb |
| SHA256 | 26d5748ffe6bd95e3fee6ce184d388a1a681006dc23a0f08d53c083c593c193b |
| SHA512 |
35f44c0df4635a1020f52743d7cf3e4346d1bdf9010161326e572250ac93e0285b202532a07d2db8dbc67f6f0ced864083769e904bd5d82611244339ca8d31a1
|
| CRC32 | 75ACB8AB |
| ssdeep | None |
| Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Dec. 18, 2025, 12:01 p.m. | Dec. 18, 2025, 12:03 p.m. | 127 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-12-18 11:01:45,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpht3fil 2025-12-18 11:01:45,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\RrOEhVUvfMJKlcdeRHbbFcnHBCaXSL 2025-12-18 11:01:45,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\FNsWXsLjvHHAfHAhEMK 2025-12-18 11:01:45,250 [analyzer] DEBUG: Started auxiliary module Curtain 2025-12-18 11:01:45,250 [analyzer] DEBUG: Started auxiliary module DbgView 2025-12-18 11:01:45,640 [analyzer] DEBUG: Started auxiliary module Disguise 2025-12-18 11:01:45,842 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-12-18 11:01:45,842 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-12-18 11:01:45,842 [analyzer] DEBUG: Started auxiliary module Human 2025-12-18 11:01:45,842 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-12-18 11:01:45,842 [analyzer] DEBUG: Started auxiliary module Reboot 2025-12-18 11:01:45,905 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-12-18 11:01:45,905 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-12-18 11:01:45,905 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-12-18 11:01:45,905 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-12-18 11:01:46,296 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\Advanced_IP_Scanner_2.5.4594.1 (1).exe' with arguments '' and pid 1036 2025-12-18 11:01:46,483 [analyzer] DEBUG: Loaded monitor into process with pid 1036 2025-12-18 11:01:46,750 [analyzer] INFO: Added new file to list with pid 1036 and path C:\Users\Administrator\AppData\Local\Temp\is-KSIDM.tmp\Advanced_IP_Scanner_2.5.4594.1 (1).tmp 2025-12-18 11:01:46,858 [analyzer] INFO: Injected into process with pid 320 and name '' 2025-12-18 11:01:47,046 [analyzer] DEBUG: Loaded monitor into process with pid 320 2025-12-18 11:03:20,125 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-12-18 11:03:20,345 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1036. 2025-12-18 11:03:20,437 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 320. 2025-12-18 11:03:20,812 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-12-18 11:03:20,812 [lib.api.process] INFO: Successfully terminated process with pid 1036. 2025-12-18 11:03:20,812 [lib.api.process] INFO: Successfully terminated process with pid 320. 2025-12-18 11:03:20,859 [analyzer] INFO: Analysis completed.
2025-12-18 12:01:51,048 [cuckoo.core.scheduler] INFO: Task #7227602: acquired machine win7x6411 (label=win7x6411) 2025-12-18 12:01:51,052 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.211 for task #7227602 2025-12-18 12:01:51,341 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2888249 (interface=vboxnet0, host=192.168.168.211) 2025-12-18 12:02:21,082 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6411 2025-12-18 12:02:21,674 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6411 to vmcloak 2025-12-18 12:02:41,134 [cuckoo.core.guest] INFO: Starting analysis #7227602 on guest (id=win7x6411, ip=192.168.168.211) 2025-12-18 12:02:42,140 [cuckoo.core.guest] DEBUG: win7x6411: not ready yet 2025-12-18 12:02:47,196 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6411, ip=192.168.168.211) 2025-12-18 12:02:47,545 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6411, ip=192.168.168.211, monitor=latest, size=6660546) 2025-12-18 12:02:49,822 [cuckoo.core.resultserver] DEBUG: Task #7227602: live log analysis.log initialized. 2025-12-18 12:02:50,613 [cuckoo.core.resultserver] DEBUG: Task #7227602 is sending a BSON stream 2025-12-18 12:02:51,238 [cuckoo.core.resultserver] DEBUG: Task #7227602 is sending a BSON stream 2025-12-18 12:02:51,912 [cuckoo.core.resultserver] DEBUG: Task #7227602 is sending a BSON stream 2025-12-18 12:02:51,927 [cuckoo.core.resultserver] DEBUG: Task #7227602: File upload for 'shots/0001.jpg' 2025-12-18 12:02:52,416 [cuckoo.core.resultserver] DEBUG: Task #7227602 uploaded file length: 133544 2025-12-18 12:02:53,101 [cuckoo.core.resultserver] DEBUG: Task #7227602: File upload for 'shots/0002.jpg' 2025-12-18 12:02:53,124 [cuckoo.core.resultserver] DEBUG: Task #7227602 uploaded file length: 138620 2025-12-18 12:03:04,597 [cuckoo.core.guest] DEBUG: win7x6411: analysis #7227602 still processing 2025-12-18 12:03:20,129 [cuckoo.core.guest] DEBUG: win7x6411: analysis #7227602 still processing 2025-12-18 12:03:20,623 [cuckoo.core.resultserver] DEBUG: Task #7227602: File upload for 'curtain/1766052200.61.curtain.log' 2025-12-18 12:03:20,626 [cuckoo.core.resultserver] DEBUG: Task #7227602 uploaded file length: 36 2025-12-18 12:03:20,812 [cuckoo.core.resultserver] DEBUG: Task #7227602: File upload for 'sysmon/1766052200.8.sysmon.xml' 2025-12-18 12:03:20,823 [cuckoo.core.resultserver] DEBUG: Task #7227602 uploaded file length: 818872 2025-12-18 12:03:20,848 [cuckoo.core.resultserver] DEBUG: Task #7227602: File upload for 'files/ec8252a333f68865_advanced_ip_scanner_2.5.4594.1 (1).tmp' 2025-12-18 12:03:20,865 [cuckoo.core.resultserver] DEBUG: Task #7227602 uploaded file length: 1190912 2025-12-18 12:03:21,050 [cuckoo.core.resultserver] DEBUG: Task #7227602: File upload for 'shots/0003.jpg' 2025-12-18 12:03:21,065 [cuckoo.core.resultserver] DEBUG: Task #7227602 uploaded file length: 133982 2025-12-18 12:03:21,084 [cuckoo.core.resultserver] DEBUG: Task #7227602 had connection reset for <Context for LOG> 2025-12-18 12:03:23,144 [cuckoo.core.guest] INFO: win7x6411: analysis completed successfully 2025-12-18 12:03:23,157 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-12-18 12:03:23,193 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-12-18 12:03:23,992 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6411 to path /srv/cuckoo/cwd/storage/analyses/7227602/memory.dmp 2025-12-18 12:03:23,994 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6411 2025-12-18 12:03:57,474 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.211 for task #7227602 2025-12-18 12:03:57,794 [cuckoo.core.scheduler] DEBUG: Released database task #7227602 2025-12-18 12:03:57,812 [cuckoo.core.scheduler] INFO: Task #7227602: analysis procedure completed
| description | Checks if being debugged | rule | anti_dbg | ||||||
| description | Bypass DEP | rule | disable_dep | ||||||
| description | Communications over SSL | rule | network_ssl | ||||||
| description | Escalade priviledges | rule | escalate_priv | ||||||
| description | Run a keylogger | rule | keylogger | ||||||
| description | Affect system registries | rule | win_registry | ||||||
| description | Affect system token | rule | win_token | ||||||
| description | Affect private profile | rule | win_files_operation | ||||||
| section | .itext |
| Rising | Hacktool.NetScan!8.17E0F (CLOUD) |
| DrWeb | Tool.Scanner.26 |