Size | 60.0KB |
---|---|
Type | POSIX tar archive |
MD5 | 914397b84a86ffce8c44cc7d2187439b |
SHA1 | 7b0bbb5e36357369ccf8054d348563c71f2b272e |
SHA256 | 9d3b5fa5e09d4bae297d88c83ec8ddc3919fa27ae19fade29319c5ddf18a7555 |
SHA512 |
37c1ce2b6cc635ef3dc7a5acf368b05ed218f7c46569d90c16840489e2eff654d9329c16dcd743967409940b803ad7b080698bd905a41a9144194333daeaf894
|
CRC32 | 256C5716 |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
ARCHIVE | Aug. 3, 2025, 9:35 a.m. | Aug. 3, 2025, 9:36 a.m. | 66 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-03 09:35:11,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpqqrt4a 2025-08-03 09:35:11,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\vZirZqYGetMPeyxwkNj 2025-08-03 09:35:11,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\iYCjUcQcjQqUSkUhEA 2025-08-03 09:35:11,296 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-03 09:35:11,296 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-03 09:35:11,796 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-03 09:35:12,015 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-08-03 09:35:12,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-03 09:35:12,015 [analyzer] DEBUG: Started auxiliary module Human 2025-08-03 09:35:12,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-03 09:35:12,015 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-03 09:35:12,108 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-03 09:35:12,125 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-03 09:35:12,125 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-03 09:35:12,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-03 09:35:12,250 [lib.api.process] INFO: Successfully executed process from path 'bin/7za.exe' with arguments ['x', 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\output', '-pinfected'] and pid 2792 2025-08-03 08:36:05,855 [lib.api.process] INFO: Successfully executed process from path 'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\ose00000.exe' with arguments '' and pid 2744 2025-08-03 08:36:06,089 [analyzer] DEBUG: Loaded monitor into process with pid 2744 2025-08-03 08:36:06,184 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2744. 2025-08-03 08:36:06,855 [analyzer] INFO: Process with pid 2744 has terminated 2025-08-03 08:36:06,855 [analyzer] INFO: Process list is empty, terminating analysis. 2025-08-03 08:36:08,105 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-03 08:36:08,105 [analyzer] INFO: Analysis completed.
2025-08-03 09:35:12,395 [cuckoo.core.scheduler] INFO: Task #6816680: acquired machine win7x6428 (label=win7x6428) 2025-08-03 09:35:12,396 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.228 for task #6816680 2025-08-03 09:35:12,717 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1141424 (interface=vboxnet0, host=192.168.168.228) 2025-08-03 09:35:12,739 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6428 2025-08-03 09:35:13,255 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6428 to vmcloak 2025-08-03 09:35:26,612 [cuckoo.core.guest] INFO: Starting analysis #6816680 on guest (id=win7x6428, ip=192.168.168.228) 2025-08-03 09:35:27,618 [cuckoo.core.guest] DEBUG: win7x6428: not ready yet 2025-08-03 09:35:32,647 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6428, ip=192.168.168.228) 2025-08-03 09:35:32,859 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6428, ip=192.168.168.228, monitor=latest, size=6660546) 2025-08-03 09:35:34,364 [cuckoo.core.resultserver] DEBUG: Task #6816680: live log analysis.log initialized. 2025-08-03 09:35:35,235 [cuckoo.core.resultserver] DEBUG: Task #6816680 is sending a BSON stream 2025-08-03 09:35:36,541 [cuckoo.core.resultserver] DEBUG: Task #6816680: File upload for 'shots/0001.jpg' 2025-08-03 09:35:36,562 [cuckoo.core.resultserver] DEBUG: Task #6816680 uploaded file length: 140767 2025-08-03 09:35:48,847 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6816680 still processing 2025-08-03 09:36:03,937 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6816680 still processing 2025-08-03 09:36:05,953 [cuckoo.core.resultserver] DEBUG: Task #6816680 is sending a BSON stream 2025-08-03 09:36:08,005 [cuckoo.core.resultserver] DEBUG: Task #6816680: File upload for 'curtain/1754202968.0.curtain.log' 2025-08-03 09:36:08,009 [cuckoo.core.resultserver] DEBUG: Task #6816680 uploaded file length: 36 2025-08-03 09:36:08,117 [cuckoo.core.resultserver] DEBUG: Task #6816680: File upload for 'sysmon/1754202968.11.sysmon.xml' 2025-08-03 09:36:08,124 [cuckoo.core.resultserver] DEBUG: Task #6816680 uploaded file length: 200828 2025-08-03 09:36:08,549 [cuckoo.core.resultserver] DEBUG: Task #6816680 had connection reset for <Context for LOG> 2025-08-03 09:36:09,966 [cuckoo.core.guest] INFO: win7x6428: analysis completed successfully 2025-08-03 09:36:09,977 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-03 09:36:09,995 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-03 09:36:10,827 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6428 to path /srv/cuckoo/cwd/storage/analyses/6816680/memory.dmp 2025-08-03 09:36:10,828 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6428 2025-08-03 09:36:18,334 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.228 for task #6816680 2025-08-03 09:36:18,670 [cuckoo.core.scheduler] DEBUG: Released database task #6816680 2025-08-03 09:36:18,692 [cuckoo.core.scheduler] INFO: Task #6816680: analysis procedure completed
No signatures