Size | 19.5MB |
---|---|
Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | 61d1987addfaf155bfb31363ca6edead |
SHA1 | e4990739e461247f8969811078ed140634fa0fd2 |
SHA256 | 2e95133ce32a15fc9daeb1c2ea30bca5998c2566278f0b5e3435a452461a7ce2 |
SHA512 |
ca82b64496fc18d1ce3ff4c7e7fd8e20c7c74c891a766b8e9c92f79fb30064e48e09efb7b5b48534a3e7ce22479c559e962d5d5ad6fb618805a3493bc5ca192c
|
CRC32 | B977A7A9 |
ssdeep | None |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | March 10, 2025, 1:02 a.m. | March 10, 2025, 1:10 a.m. | 480 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-03-08 12:14:21,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpk4d6bl 2025-03-08 12:14:21,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\QuetuEQTpsZCpOfzWjjSrgSaU 2025-03-08 12:14:21,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\afDhtuQhxgUWusUuwvDDOgw 2025-03-08 12:14:21,296 [analyzer] DEBUG: Started auxiliary module Curtain 2025-03-08 12:14:21,296 [analyzer] DEBUG: Started auxiliary module DbgView 2025-03-08 12:14:21,937 [analyzer] DEBUG: Started auxiliary module Disguise 2025-03-08 12:14:22,125 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-03-08 12:14:22,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-03-08 12:14:22,125 [analyzer] DEBUG: Started auxiliary module Human 2025-03-08 12:14:22,125 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-03-08 12:14:22,125 [analyzer] DEBUG: Started auxiliary module Reboot 2025-03-08 12:14:22,217 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-03-08 12:14:22,217 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-03-08 12:14:22,217 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-03-08 12:14:22,217 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-03-08 12:14:22,562 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2e95133ce32a15fc9daeb1c2ea30bca5998c2566278f0b5e3435a452461a7ce2.exe' with arguments '' and pid 2220 2025-03-08 12:14:23,578 [analyzer] INFO: Process with pid 2220 has terminated 2025-03-08 12:14:23,578 [analyzer] INFO: Process list is empty, terminating analysis. 2025-03-08 12:14:24,750 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-03-08 12:14:24,750 [analyzer] INFO: Analysis completed.
2025-03-10 01:02:39,092 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:40,537 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:41,693 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:43,878 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:45,347 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:46,502 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:47,584 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:48,650 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:49,709 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:51,304 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:52,597 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:53,957 [cuckoo.core.scheduler] DEBUG: Task #6066193: no machine available yet 2025-03-10 01:02:55,309 [cuckoo.core.scheduler] INFO: Task #6066193: acquired machine win7x6422 (label=win7x6422) 2025-03-10 01:02:55,336 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.222 for task #6066193 2025-03-10 01:02:55,818 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2372015 (interface=vboxnet0, host=192.168.168.222) 2025-03-10 01:04:04,582 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6422 2025-03-10 01:04:05,523 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6422 to vmcloak 2025-03-10 01:07:09,892 [cuckoo.core.guest] INFO: Starting analysis #6066193 on guest (id=win7x6422, ip=192.168.168.222) 2025-03-10 01:07:10,897 [cuckoo.core.guest] DEBUG: win7x6422: not ready yet 2025-03-10 01:07:15,920 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6422, ip=192.168.168.222) 2025-03-10 01:07:16,020 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6422, ip=192.168.168.222, monitor=latest, size=6660546) 2025-03-10 01:07:18,536 [cuckoo.core.resultserver] DEBUG: Task #6066193: live log analysis.log initialized. 2025-03-10 01:07:19,605 [cuckoo.core.resultserver] DEBUG: Task #6066193 is sending a BSON stream 2025-03-10 01:07:20,888 [cuckoo.core.resultserver] DEBUG: Task #6066193: File upload for 'shots/0001.jpg' 2025-03-10 01:07:20,902 [cuckoo.core.resultserver] DEBUG: Task #6066193 uploaded file length: 133484 2025-03-10 01:07:22,211 [cuckoo.core.resultserver] DEBUG: Task #6066193: File upload for 'curtain/1741432464.66.curtain.log' 2025-03-10 01:07:22,226 [cuckoo.core.resultserver] DEBUG: Task #6066193 uploaded file length: 36 2025-03-10 01:07:22,291 [cuckoo.core.resultserver] DEBUG: Task #6066193: File upload for 'sysmon/1741432464.73.sysmon.xml' 2025-03-10 01:07:22,294 [cuckoo.core.resultserver] DEBUG: Task #6066193 uploaded file length: 41948 2025-03-10 01:07:22,997 [cuckoo.core.resultserver] DEBUG: Task #6066193 had connection reset for <Context for LOG> 2025-03-10 01:07:24,162 [cuckoo.core.guest] INFO: win7x6422: analysis completed successfully 2025-03-10 01:07:24,174 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-03-10 01:07:24,199 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-03-10 01:07:25,497 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6422 to path /srv/cuckoo/cwd/storage/analyses/6066193/memory.dmp 2025-03-10 01:07:25,562 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6422 2025-03-10 01:10:05,300 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.222 for task #6066193 2025-03-10 01:10:05,809 [cuckoo.core.scheduler] DEBUG: Released database task #6066193 2025-03-10 01:10:12,470 [cuckoo.core.scheduler] INFO: Task #6066193: analysis procedure completed
description | Affect system registries | rule | win_registry |
section | .managed |
section | .WnV |
section | .lH) |
section | .jCA |
section | {u'size_of_data': u'0x01376a00', u'virtual_address': u'0x02d22000', u'entropy': 7.991891361865033, u'name': u'.jCA', u'virtual_size': u'0x0137692c'} | entropy | 7.99189136187 | description | A section with a high entropy has been found | |||||||||
entropy | 0.999849499586 | description | Overall entropy of this PE file is high |
ESET Security (Windows) | a variant of Generik.CMSKKON trojan |
Skyhigh | Artemis |
Elastic | malicious (moderate confidence) |
ESET-NOD32 | a variant of Generik.CMSKKON |
Rising | Trojan.Undefined!8.1327C (CLOUD) |
McAfeeD | ti!2E95133CE32A |
Detected | |
GData | Win64.Trojan.Agent.BXMWKQ |
McAfee | Artemis!61D1987ADDFA |
DeepInstinct | MALICIOUS |
Ikarus | Trojan.SuspectCRC |
Fortinet | Malicious_Behavior.SB |