| Size | 308.6KB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | 42abc4a7fbdc5d9576375abbf9af7349 |
| SHA1 | 8f893586abd55a8a91ec18b1f9e92ca99dda04cf |
| SHA256 | 6bafeab61149af6a607d33c92b001b3798872bd2d6a37acfcd90226c980005f6 |
| SHA512 |
4f4b683c9aa9a04226f05b014f56ff4316afe0051a78d4275534a3d61b6ae460e7f6c5842588c5c757ff4e9167fabc20de3b45952b5d5ff304e548aeffc4ed1e
|
| CRC32 | 471D0C42 |
| ssdeep | None |
| PDB Path | c:\Projects\VS2005\SkypeContactsView\Release\SkypeContactsView.pdb |
| Yara |
|
This archive is very suspicious, with a score of 9.1 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| ARCHIVE | March 4, 2026, 9:05 p.m. | March 4, 2026, 9:06 p.m. | 80 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-03-04 20:05:03,905 [analyzer] DEBUG: Starting analyzer from: C:\tmpsftntc 2026-03-04 20:05:03,905 [analyzer] DEBUG: Pipe server name: \??\PIPE\isjbbiylzCfmWsiZ 2026-03-04 20:05:03,905 [analyzer] DEBUG: Log pipe server name: \??\PIPE\DhhuVrSGJUPzaHEuxVh 2026-03-04 20:05:04,203 [analyzer] DEBUG: Started auxiliary module Curtain 2026-03-04 20:05:04,203 [analyzer] DEBUG: Started auxiliary module DbgView 2026-03-04 20:05:04,655 [analyzer] DEBUG: Started auxiliary module Disguise 2026-03-04 20:05:04,842 [analyzer] DEBUG: Loaded monitor into process with pid 508 2026-03-04 20:05:04,842 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-03-04 20:05:04,842 [analyzer] DEBUG: Started auxiliary module Human 2026-03-04 20:05:04,842 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-03-04 20:05:04,842 [analyzer] DEBUG: Started auxiliary module Reboot 2026-03-04 20:05:04,953 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-03-04 20:05:04,953 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-03-04 20:05:04,953 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-03-04 20:05:04,953 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-03-04 20:05:05,092 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\NirSoft/skypecontactsview.exe' with arguments '' and pid 1916 2026-03-04 20:05:05,265 [analyzer] DEBUG: Loaded monitor into process with pid 1916 2026-03-04 20:06:04,188 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2026-03-04 20:06:04,375 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1916. 2026-03-04 20:06:04,673 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-03-04 20:06:04,673 [lib.api.process] INFO: Successfully terminated process with pid 1916. 2026-03-04 20:06:04,673 [analyzer] INFO: Analysis completed.
2026-03-04 21:05:06,530 [cuckoo.core.scheduler] INFO: Task #7474970: acquired machine win7x6421 (label=win7x6421) 2026-03-04 21:05:06,531 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.221 for task #7474970 2026-03-04 21:05:07,109 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3262926 (interface=vboxnet0, host=192.168.168.221) 2026-03-04 21:05:07,138 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6421 2026-03-04 21:05:07,927 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6421 to vmcloak 2026-03-04 21:05:21,460 [cuckoo.core.guest] INFO: Starting analysis #7474970 on guest (id=win7x6421, ip=192.168.168.221) 2026-03-04 21:05:22,466 [cuckoo.core.guest] DEBUG: win7x6421: not ready yet 2026-03-04 21:05:27,495 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6421, ip=192.168.168.221) 2026-03-04 21:05:27,581 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6421, ip=192.168.168.221, monitor=latest, size=6660546) 2026-03-04 21:05:33,059 [cuckoo.core.resultserver] DEBUG: Task #7474970: live log analysis.log initialized. 2026-03-04 21:05:34,826 [cuckoo.core.resultserver] DEBUG: Task #7474970 is sending a BSON stream 2026-03-04 21:05:35,234 [cuckoo.core.resultserver] DEBUG: Task #7474970 is sending a BSON stream 2026-03-04 21:05:36,187 [cuckoo.core.resultserver] DEBUG: Task #7474970: File upload for 'shots/0001.jpg' 2026-03-04 21:05:36,216 [cuckoo.core.resultserver] DEBUG: Task #7474970 uploaded file length: 110687 2026-03-04 21:05:47,872 [cuckoo.core.guest] DEBUG: win7x6421: analysis #7474970 still processing 2026-03-04 21:06:03,269 [cuckoo.core.guest] DEBUG: win7x6421: analysis #7474970 still processing 2026-03-04 21:06:04,530 [cuckoo.core.resultserver] DEBUG: Task #7474970: File upload for 'curtain/1772651164.53.curtain.log' 2026-03-04 21:06:04,533 [cuckoo.core.resultserver] DEBUG: Task #7474970 uploaded file length: 36 2026-03-04 21:06:04,673 [cuckoo.core.resultserver] DEBUG: Task #7474970: File upload for 'sysmon/1772651164.67.sysmon.xml' 2026-03-04 21:06:04,683 [cuckoo.core.resultserver] DEBUG: Task #7474970 uploaded file length: 629488 2026-03-04 21:06:05,244 [cuckoo.core.resultserver] DEBUG: Task #7474970: File upload for 'shots/0002.jpg' 2026-03-04 21:06:05,261 [cuckoo.core.resultserver] DEBUG: Task #7474970 uploaded file length: 133448 2026-03-04 21:06:05,282 [cuckoo.core.resultserver] DEBUG: Task #7474970 had connection reset for <Context for LOG> 2026-03-04 21:06:06,282 [cuckoo.core.guest] INFO: win7x6421: analysis completed successfully 2026-03-04 21:06:06,296 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-03-04 21:06:06,324 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-03-04 21:06:07,740 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6421 to path /srv/cuckoo/cwd/storage/analyses/7474970/memory.dmp 2026-03-04 21:06:07,741 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6421 2026-03-04 21:06:23,409 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.221 for task #7474970 2026-03-04 21:06:24,444 [cuckoo.core.scheduler] DEBUG: Released database task #7474970 2026-03-04 21:06:24,467 [cuckoo.core.scheduler] INFO: Task #7474970: analysis procedure completed
| description | Rule to detect the presence of SQLite data in raw image | rule | with_sqlite | ||||||
| description | Take screenshot | rule | screenshot | ||||||
| description | Affect system registries | rule | win_registry | ||||||
| description | Affect private profile | rule | win_files_operation | ||||||
| pdb_path | c:\Projects\VS2005\SkypeContactsView\Release\SkypeContactsView.pdb |
| resource name | BIN |
| Bkav | W32.AIDetectMalware |
| CrowdStrike | win/grayware_confidence_100% (W) |
| ESET-NOD32 | Win32/SkypeContactsView.A potentially unsafe application |
| Rising | Malware.Undefined!8.C (C64:YzY0Otn8jmjZo0a2Ur6vjf1fMGA) |
| Zillya | Trojan.SkypeContactsView.Win32.2 |
| Gridinsoft | Trojan.Win32.Gen.cl |
| VBA32 | TrojanBanker.Convagent |
| Malwarebytes | RiskWare.ContactsViewer |
| Yandex | Trojan.Igent.bT8fiK.54 |