| Size | 585.7MB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | 9382ce31bafcb4a94b68dfcaae208f64 |
| SHA1 | 9d846c64716f4ac4b5c5ec48d8582da61b199460 |
| SHA256 | 2fba14e48c22e00503426c9adfb812f3e8262120d27e9948bde7d997adbe55c8 |
| SHA512 |
e461f05c4fa93b7a7e4502d9d83575c113c2563369147f1159145f4bed039f60f23a78f11789febdc629bc407ca570cf9bd583236404bc95505c3f72eb66f318
|
| CRC32 | A0127F35 |
| ssdeep | None |
| Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| ARCHIVE | Feb. 20, 2026, 8:27 a.m. | Feb. 20, 2026, 8:29 a.m. | 122 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-02-20 07:27:15,453 [analyzer] DEBUG: Starting analyzer from: C:\tmpwwr_kc 2026-02-20 07:27:15,467 [analyzer] DEBUG: Pipe server name: \??\PIPE\rhDSZwBZdBnawpskKBoROgrbelQicq 2026-02-20 07:27:15,467 [analyzer] DEBUG: Log pipe server name: \??\PIPE\CjAKyISeArcfMiHyIpoIUJBVjLQS 2026-02-20 07:27:16,983 [analyzer] DEBUG: Started auxiliary module Curtain 2026-02-20 07:27:16,983 [analyzer] DEBUG: Started auxiliary module DbgView 2026-02-20 07:27:17,405 [analyzer] DEBUG: Started auxiliary module Disguise 2026-02-20 07:27:17,608 [analyzer] DEBUG: Loaded monitor into process with pid 504 2026-02-20 07:27:17,608 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-02-20 07:27:17,608 [analyzer] DEBUG: Started auxiliary module Human 2026-02-20 07:27:17,608 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-02-20 07:27:17,625 [analyzer] DEBUG: Started auxiliary module Reboot 2026-02-20 07:27:17,703 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-02-20 07:27:17,703 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-02-20 07:27:17,703 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-02-20 07:27:17,703 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-02-20 07:27:22,078 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\GTA - San Andreas - Hot Coffee [mysamp.do.am].exe' with arguments '' and pid 1312 2026-02-20 07:27:22,375 [analyzer] DEBUG: Loaded monitor into process with pid 1312 2026-02-20 07:27:22,780 [analyzer] INFO: Added new file to list with pid 1312 and path C:\Users\Administrator\AppData\Local\Temp\is-1JUJU.tmp\is-OD2BC.tmp 2026-02-20 07:27:22,890 [analyzer] INFO: Injected into process with pid 2964 and name u'is-OD2BC.tmp' 2026-02-20 07:27:23,125 [analyzer] DEBUG: Loaded monitor into process with pid 2964 2026-02-20 07:27:23,233 [analyzer] INFO: Added new file to list with pid 2964 and path C:\Users\Administrator\AppData\Local\Temp\is-1U045.tmp\_isetup\_setup64.tmp 2026-02-20 07:27:23,250 [analyzer] INFO: Added new file to list with pid 2964 and path C:\Users\Administrator\AppData\Local\Temp\is-1U045.tmp\_isetup\_shfoldr.dll 2026-02-20 07:28:58,056 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2026-02-20 07:28:58,290 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1312. 2026-02-20 07:28:58,384 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2964. 2026-02-20 07:28:58,681 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-02-20 07:28:58,697 [lib.api.process] INFO: Successfully terminated process with pid 1312. 2026-02-20 07:28:58,697 [lib.api.process] INFO: Successfully terminated process with pid 2964. 2026-02-20 07:28:58,713 [analyzer] INFO: Analysis completed.
2026-02-20 08:27:27,351 [cuckoo.core.scheduler] INFO: Task #7458802: acquired machine win7x645 (label=win7x645) 2026-02-20 08:27:27,352 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.205 for task #7458802 2026-02-20 08:27:27,926 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2425411 (interface=vboxnet0, host=192.168.168.205) 2026-02-20 08:27:27,944 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x645 2026-02-20 08:27:28,783 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x645 to vmcloak 2026-02-20 08:27:48,262 [cuckoo.core.guest] INFO: Starting analysis #7458802 on guest (id=win7x645, ip=192.168.168.205) 2026-02-20 08:27:50,438 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x645, ip=192.168.168.205) 2026-02-20 08:27:50,550 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x645, ip=192.168.168.205, monitor=latest, size=6660546) 2026-02-20 08:28:18,926 [cuckoo.core.resultserver] DEBUG: Task #7458802: live log analysis.log initialized. 2026-02-20 08:28:25,902 [cuckoo.core.resultserver] DEBUG: Task #7458802 is sending a BSON stream 2026-02-20 08:28:26,937 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'shots/0001.jpg' 2026-02-20 08:28:28,994 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 133483 2026-02-20 08:28:29,337 [cuckoo.core.resultserver] DEBUG: Task #7458802 is sending a BSON stream 2026-02-20 08:28:30,030 [cuckoo.core.resultserver] DEBUG: Task #7458802 is sending a BSON stream 2026-02-20 08:28:34,392 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'shots/0002.jpg' 2026-02-20 08:28:34,395 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 39519 2026-02-20 08:28:34,397 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'shots/0003.jpg' 2026-02-20 08:28:34,399 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 69628 2026-02-20 08:28:40,622 [cuckoo.core.guest] DEBUG: win7x645: analysis #7458802 still processing 2026-02-20 08:28:59,526 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'curtain/1771568938.57.curtain.log' 2026-02-20 08:28:59,563 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 36 2026-02-20 08:28:59,587 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'sysmon/1771568938.68.sysmon.xml' 2026-02-20 08:28:59,591 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 154998 2026-02-20 08:28:59,593 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'files/71b487f0523f2130_is-od2bc.tmp' 2026-02-20 08:28:59,931 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'files/e8a502e80fbeea31__setup64.tmp' 2026-02-20 08:28:59,933 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 4608 2026-02-20 08:28:59,934 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'files/9884e9d1b4f8a873__shfoldr.dll' 2026-02-20 08:28:59,935 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 23312 2026-02-20 08:28:59,936 [cuckoo.core.resultserver] DEBUG: Task #7458802: File upload for 'shots/0004.jpg' 2026-02-20 08:28:59,940 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 658432 2026-02-20 08:28:59,943 [cuckoo.core.resultserver] DEBUG: Task #7458802 uploaded file length: 133498 2026-02-20 08:28:59,958 [cuckoo.core.resultserver] DEBUG: Task #7458802 had connection reset for <Context for LOG> 2026-02-20 08:29:00,030 [cuckoo.core.guest] INFO: win7x645: analysis completed successfully 2026-02-20 08:29:00,042 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-02-20 08:29:00,071 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-02-20 08:29:01,673 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x645 to path /srv/cuckoo/cwd/storage/analyses/7458802/memory.dmp 2026-02-20 08:29:01,675 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x645 2026-02-20 08:29:15,054 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.205 for task #7458802 2026-02-20 08:29:15,379 [cuckoo.core.scheduler] DEBUG: Released database task #7458802 2026-02-20 08:29:15,399 [cuckoo.core.scheduler] INFO: Task #7458802: analysis procedure completed
| section | CODE |
| section | DATA |
| section | BSS |
| file | C:\Users\Administrator\AppData\Local\Temp\is-1U045.tmp\_isetup\_shfoldr.dll |
| Bkav | W32.AIDetectMalware |
| Detected |