Size | 6.1KB |
---|---|
Type | Unicode text, UTF-8 text, with very long lines (468), with CRLF line terminators |
MD5 | 575542ce890a14dfebeb5bc31c292a16 |
SHA1 | 18ede64becf756306ac576b9171daf3784d280a7 |
SHA256 | c8ecec07a75fb1f8f664d52958ffb9dc956b305d4a91f2692cf04cc7ee0740e2 |
SHA512 |
2937c717f9b23443063cb9f984f803228959289c632337fd363246e8bf1ac4cae8bc388e84ef11f675ab94b8177505c165441dc155ec1b4fae0831c42f25d61e
|
CRC32 | 217739C0 |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 15, 2025, 1:54 a.m. | May 15, 2025, 1:55 a.m. | 69 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-08 18:39:55,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp2zg5xi 2025-05-08 18:39:55,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ZVtLEarWFtRcufnEYxGYnAKoSfAX 2025-05-08 18:39:55,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\OWVpKZpabQVbhGzAIVIIYvxhemfk 2025-05-08 18:39:55,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-05-08 18:39:55,015 [analyzer] INFO: Automatically selected analysis package "xls" 2025-05-08 18:39:55,280 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-08 18:39:55,280 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-08 18:39:55,703 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-08 18:39:55,905 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-05-08 18:39:55,905 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-08 18:39:55,905 [analyzer] DEBUG: Started auxiliary module Human 2025-05-08 18:39:55,905 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-08 18:39:55,905 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-08 18:39:55,953 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-08 18:39:55,953 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-08 18:39:55,953 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-08 18:39:55,953 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-08 18:39:56,578 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Microsoft Office\\Office14\\EXCEL.EXE' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\MIGjuJiy.xls'] and pid 1788 2025-05-08 18:39:57,390 [analyzer] DEBUG: Loaded monitor into process with pid 1788 2025-05-08 18:40:02,030 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-05-08 18:40:02,078 [analyzer] CRITICAL: Unable to find closeby page for hooking! 2025-05-08 18:40:25,578 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-08 18:40:25,983 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-08 18:40:25,983 [lib.api.process] INFO: Successfully terminated process with pid 1788. 2025-05-08 18:40:25,983 [analyzer] INFO: Analysis completed.
2025-05-15 01:54:13,261 [cuckoo.core.scheduler] INFO: Task #6464958: acquired machine win7x6410 (label=win7x6410) 2025-05-15 01:54:13,262 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.210 for task #6464958 2025-05-15 01:54:13,505 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3821164 (interface=vboxnet0, host=192.168.168.210) 2025-05-15 01:54:13,577 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6410 2025-05-15 01:54:14,321 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6410 to vmcloak 2025-05-15 01:54:29,460 [cuckoo.core.guest] INFO: Starting analysis #6464958 on guest (id=win7x6410, ip=192.168.168.210) 2025-05-15 01:54:30,468 [cuckoo.core.guest] DEBUG: win7x6410: not ready yet 2025-05-15 01:54:35,508 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6410, ip=192.168.168.210) 2025-05-15 01:54:35,608 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6410, ip=192.168.168.210, monitor=latest, size=6660546) 2025-05-15 01:54:36,938 [cuckoo.core.resultserver] DEBUG: Task #6464958: live log analysis.log initialized. 2025-05-15 01:54:37,798 [cuckoo.core.resultserver] DEBUG: Task #6464958 is sending a BSON stream 2025-05-15 01:54:39,065 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'shots/0001.jpg' 2025-05-15 01:54:39,088 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 133460 2025-05-15 01:54:39,318 [cuckoo.core.resultserver] DEBUG: Task #6464958 is sending a BSON stream 2025-05-15 01:54:42,263 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'shots/0002.jpg' 2025-05-15 01:54:42,545 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 123010 2025-05-15 01:54:43,383 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'shots/0003.jpg' 2025-05-15 01:54:43,394 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 123551 2025-05-15 01:54:44,509 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'shots/0004.jpg' 2025-05-15 01:54:44,539 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 123486 2025-05-15 01:54:45,668 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'shots/0005.jpg' 2025-05-15 01:54:45,688 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 135499 2025-05-15 01:54:46,793 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'shots/0006.jpg' 2025-05-15 01:54:46,808 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 201753 2025-05-15 01:54:48,941 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'shots/0007.jpg' 2025-05-15 01:54:48,955 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 121970 2025-05-15 01:54:51,628 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6464958 still processing 2025-05-15 01:55:06,723 [cuckoo.core.guest] DEBUG: win7x6410: analysis #6464958 still processing 2025-05-15 01:55:07,834 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'curtain/1746722425.84.curtain.log' 2025-05-15 01:55:07,839 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 36 2025-05-15 01:55:07,941 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'sysmon/1746722425.98.sysmon.xml' 2025-05-15 01:55:07,948 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 499016 2025-05-15 01:55:08,581 [cuckoo.core.resultserver] DEBUG: Task #6464958: File upload for 'shots/0008.jpg' 2025-05-15 01:55:08,601 [cuckoo.core.resultserver] DEBUG: Task #6464958 uploaded file length: 139530 2025-05-15 01:55:08,615 [cuckoo.core.resultserver] DEBUG: Task #6464958 had connection reset for <Context for LOG> 2025-05-15 01:55:09,736 [cuckoo.core.guest] INFO: win7x6410: analysis completed successfully 2025-05-15 01:55:09,747 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-15 01:55:10,162 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-15 01:55:10,926 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6410 to path /srv/cuckoo/cwd/storage/analyses/6464958/memory.dmp 2025-05-15 01:55:10,927 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6410 2025-05-15 01:55:22,498 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.210 for task #6464958 2025-05-15 01:55:22,761 [cuckoo.core.scheduler] DEBUG: Released database task #6464958 2025-05-15 01:55:22,780 [cuckoo.core.scheduler] INFO: Task #6464958: analysis procedure completed
Application Crash | Process EXCEL.EXE with pid 1788 crashed |