| Size | 23.0MB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | e39448dd752bbc91f01da82b67ac35ed |
| SHA1 | 20e165b7bcc90fc9f4834d7435f624e03f13e206 |
| SHA256 | 90fdf1060a847cca427a477620937e68944e1fd9862d953dadc834d94a025be1 |
| SHA512 |
2c1967af7007d43b3cdec75d8afa482c7a6e51661dabc0440b67037d5dfff85d3fd8d948e57394fc6156f73ff764b3dbb4e1fbe58dc2155cf626137e969c89be
|
| CRC32 | 735CE23B |
| ssdeep | None |
| Yara |
|
This archive is very suspicious, with a score of 7.9 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| ARCHIVE | Feb. 7, 2026, 3:59 p.m. | Feb. 7, 2026, 4 p.m. | 64 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-02-07 14:59:10,187 [analyzer] DEBUG: Starting analyzer from: C:\tmpwwr_kc 2026-02-07 14:59:10,187 [analyzer] DEBUG: Pipe server name: \??\PIPE\voDIcYnIPKBiGEaSFIJEMTZAhyplHikW 2026-02-07 14:59:10,187 [analyzer] DEBUG: Log pipe server name: \??\PIPE\fEHEihJmWGKIkoLriLCBZ 2026-02-07 14:59:10,515 [analyzer] DEBUG: Started auxiliary module Curtain 2026-02-07 14:59:10,530 [analyzer] DEBUG: Started auxiliary module DbgView 2026-02-07 14:59:10,953 [analyzer] DEBUG: Started auxiliary module Disguise 2026-02-07 14:59:11,140 [analyzer] DEBUG: Loaded monitor into process with pid 504 2026-02-07 14:59:11,140 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-02-07 14:59:11,140 [analyzer] DEBUG: Started auxiliary module Human 2026-02-07 14:59:11,140 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-02-07 14:59:11,140 [analyzer] DEBUG: Started auxiliary module Reboot 2026-02-07 14:59:11,203 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-02-07 14:59:11,203 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-02-07 14:59:11,203 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-02-07 14:59:11,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-02-07 14:59:11,687 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\cherome.exe' with arguments '' and pid 3004 2026-02-07 14:59:11,842 [analyzer] DEBUG: Loaded monitor into process with pid 3004 2026-02-07 15:00:04,174 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2026-02-07 15:00:04,394 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 3004. 2026-02-07 15:00:04,736 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-02-07 15:00:04,736 [lib.api.process] INFO: Successfully terminated process with pid 3004. 2026-02-07 15:00:04,736 [analyzer] INFO: Analysis completed.
2026-02-07 15:59:11,482 [cuckoo.core.scheduler] INFO: Task #7451946: acquired machine win7x645 (label=win7x645) 2026-02-07 15:59:11,483 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.205 for task #7451946 2026-02-07 15:59:11,888 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 462495 (interface=vboxnet0, host=192.168.168.205) 2026-02-07 15:59:11,904 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x645 2026-02-07 15:59:12,447 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x645 to vmcloak 2026-02-07 15:59:24,689 [cuckoo.core.guest] INFO: Starting analysis #7451946 on guest (id=win7x645, ip=192.168.168.205) 2026-02-07 15:59:25,693 [cuckoo.core.guest] DEBUG: win7x645: not ready yet 2026-02-07 15:59:30,744 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x645, ip=192.168.168.205) 2026-02-07 15:59:30,839 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x645, ip=192.168.168.205, monitor=latest, size=6660546) 2026-02-07 15:59:33,466 [cuckoo.core.resultserver] DEBUG: Task #7451946: live log analysis.log initialized. 2026-02-07 15:59:34,560 [cuckoo.core.resultserver] DEBUG: Task #7451946 is sending a BSON stream 2026-02-07 15:59:35,248 [cuckoo.core.resultserver] DEBUG: Task #7451946 is sending a BSON stream 2026-02-07 15:59:35,824 [cuckoo.core.resultserver] DEBUG: Task #7451946: File upload for 'shots/0001.jpg' 2026-02-07 15:59:35,855 [cuckoo.core.resultserver] DEBUG: Task #7451946 uploaded file length: 139150 2026-02-07 15:59:48,450 [cuckoo.core.guest] DEBUG: win7x645: analysis #7451946 still processing 2026-02-07 16:00:03,541 [cuckoo.core.guest] DEBUG: win7x645: analysis #7451946 still processing 2026-02-07 16:00:04,582 [cuckoo.core.resultserver] DEBUG: Task #7451946: File upload for 'curtain/1770472804.58.curtain.log' 2026-02-07 16:00:04,587 [cuckoo.core.resultserver] DEBUG: Task #7451946 uploaded file length: 36 2026-02-07 16:00:04,737 [cuckoo.core.resultserver] DEBUG: Task #7451946: File upload for 'sysmon/1770472804.74.sysmon.xml' 2026-02-07 16:00:04,744 [cuckoo.core.resultserver] DEBUG: Task #7451946 uploaded file length: 234178 2026-02-07 16:00:04,765 [cuckoo.core.resultserver] DEBUG: Task #7451946 had connection reset for <Context for LOG> 2026-02-07 16:00:06,553 [cuckoo.core.guest] INFO: win7x645: analysis completed successfully 2026-02-07 16:00:06,564 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-02-07 16:00:06,591 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-02-07 16:00:07,551 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x645 to path /srv/cuckoo/cwd/storage/analyses/7451946/memory.dmp 2026-02-07 16:00:07,552 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x645 2026-02-07 16:00:15,107 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.205 for task #7451946 2026-02-07 16:00:15,467 [cuckoo.core.scheduler] DEBUG: Released database task #7451946 2026-02-07 16:00:15,478 [cuckoo.core.scheduler] INFO: Task #7451946: analysis procedure completed
| description | Create or check mutex | rule | win_mutex | ||||||
| description | Affect private profile | rule | win_files_operation | ||||||
| section | .gentee |
| packer | Armadillo v1.71 |
| section | {u'size_of_data': u'0x0000e000', u'virtual_address': u'0x00004000', u'entropy': 7.813470970697603, u'name': u'.gentee', u'virtual_size': u'0x0000d20f'} | entropy | 7.8134709707 | description | A section with a high entropy has been found | |||||||||
| entropy | 0.636363636364 | description | Overall entropy of this PE file is high | |||||||||||
| G Data Antivirus (Windows) | Virus: Gen:Variant.Adware.Mikey.106715 (Engine A) |
| Avast Core Security (Linux) | Win32:Malware-gen |
| eScan Antivirus (Linux) | Gen:Variant.Adware.Mikey.106715(DB) |
| Bitdefender Antivirus (Linux) | Gen:Variant.Adware.Mikey.106715 |
| Emsisoft Commandline Scanner (Windows) | Gen:Variant.Adware.Mikey.106715 (B) |