Size | 487.9KB Resubmit sample |
---|---|
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 3f486bafb28ecccf2e30e66be03cd67a |
SHA1 | 26d551235412ea166c31b01fe39b4bd30cff2a13 |
SHA256 | d37d4bfb11505ee9c23c9b8efe92dd4428f7b51d75ff911fd38f682a2259d05e |
SHA512 |
19b7dac17f89f8bffdae59232fbcbb257262ab12f1f04a8be4e7ed5e812199cf41b466da2164ca4c20e3a28cb76c2ba8b00800c15a91c8f6bc978f2c01926801
|
CRC32 | E332C6F8 |
ssdeep | 12288:nhxp3lZnT9bDuaI3bqMaOVu5L3Lya0QuwcMV:nJlh9bDuaIrHqLNPDb |
PDB Path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
Yara |
|
This file shows some signs of potential malicious behavior.
The score of this file is 1.2 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Category | Started | Completed | Duration | Logs |
---|---|---|---|---|
FILE | Nov. 18, 2018, 6:54 a.m. | Nov. 18, 2018, 6:58 a.m. | 240 seconds |
Name | Label | Started On | Shutdown On |
---|---|---|---|
win7x64 | win7x64 | 2018-11-18 06:54:45 | 2018-11-18 06:58:45 |
2018-11-17 22:54:44,030 [analyzer] DEBUG: Starting analyzer from: C:\tsakcqnpjc 2018-11-17 22:54:44,124 [analyzer] DEBUG: Pipe server name: \\.\PIPE\ahwgKzQzWMqaOKxiYsSnYBc 2018-11-17 22:54:44,124 [analyzer] DEBUG: Log pipe server name: \\.\PIPE\KliMPhipzktIBhuEiPBl 2018-11-17 22:54:44,124 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2018-11-17 22:54:44,124 [analyzer] INFO: Automatically selected analysis package "exe" 2018-11-17 22:54:45,887 [analyzer] DEBUG: Started auxiliary module Disguise 2018-11-17 22:54:46,401 [analyzer] DEBUG: Loaded monitor into process with pid 508 2018-11-17 22:54:46,448 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2018-11-17 22:54:46,448 [analyzer] DEBUG: Started auxiliary module Human 2018-11-17 22:54:46,448 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2018-11-17 22:54:46,448 [analyzer] DEBUG: Started auxiliary module Reboot 2018-11-17 22:54:46,635 [analyzer] DEBUG: Started auxiliary module RecentFiles 2018-11-17 22:54:46,651 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2018-11-17 22:54:46,651 [analyzer] DEBUG: Started auxiliary module Screenshots 2018-11-17 22:54:47,088 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\zamen\\AppData\\Local\\Temp\\Winzip.exe' with arguments '' and pid 2300 2018-11-17 22:54:47,650 [analyzer] DEBUG: Loaded monitor into process with pid 2300 2018-11-17 22:54:47,711 [analyzer] DEBUG: Received request to inject pid=2300, but we are already injected there. 2018-11-17 22:54:49,506 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,506 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2018-11-17 22:54:49,506 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,506 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2018-11-17 22:54:49,506 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,506 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2018-11-17 22:54:49,506 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,506 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2018-11-17 22:54:49,506 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,506 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2018-11-17 22:54:49,506 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,506 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2018-11-17 22:54:49,506 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,522 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2018-11-17 22:54:49,631 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,631 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2018-11-17 22:54:49,631 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,631 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2018-11-17 22:54:49,631 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,631 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2018-11-17 22:54:49,647 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,647 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2018-11-17 22:54:49,647 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,647 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2018-11-17 22:54:49,647 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,647 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2018-11-17 22:54:49,647 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:49,647 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2018-11-17 22:54:50,036 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:50,036 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2018-11-17 22:54:50,036 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:50,036 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2018-11-17 22:54:50,036 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:50,036 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2018-11-17 22:54:50,036 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:50,036 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2018-11-17 22:54:50,052 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:50,052 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2018-11-17 22:54:50,052 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:50,052 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2018-11-17 22:54:50,052 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit mshtml.dll (with timestamp 0x4ce7b8f3) 2018-11-17 22:54:50,052 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2018-11-17 22:54:50,832 [modules.auxiliary.human] INFO: Found button "Install", clicking it 2018-11-17 22:58:12,430 [analyzer] INFO: Added new file to list with pid 2300 and path C:\Windows\reg\registery.reg 2018-11-17 22:58:12,463 [analyzer] INFO: Added new file to list with pid 2300 and path C:\Windows\reg\Registry.exe 2018-11-17 22:58:35,253 [analyzer] INFO: Process with pid 2300 has terminated 2018-11-17 22:58:35,253 [analyzer] INFO: Process list is empty, terminating analysis. 2018-11-17 22:58:36,267 [analyzer] INFO: Terminating remaining processes before shutdown. 2018-11-17 22:58:36,267 [analyzer] INFO: Analysis completed.
2018-11-18 06:54:45,244 [lib.cuckoo.core.scheduler] INFO: Task #68: acquired machine win7x64 (label=win7x64) 2018-11-18 06:54:45,273 [modules.auxiliary.sniffer] INFO: Started sniffer with PID 5033 (interface=eth2, host=192.168.128.109, pcap=/opt/cuckoo/storage/analyses/68/dump.pcap) 2018-11-18 06:54:52,685 [lib.cuckoo.core.guest] INFO: Starting analysis on guest (id=win7x64, ip=192.168.128.109) 2018-11-18 06:58:45,096 [lib.cuckoo.core.guest] INFO: win7x64: analysis completed successfully 2018-11-18 06:58:48,375 [lib.cuckoo.core.plugins] WARNING: The processing module "Suricata" returned the following error: Unable to locate Suricata binary 2018-11-18 06:59:05,590 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7fe64e4029d0>: Failed to establish a new connection: [Errno 111] Connection refused 2018-11-18 06:59:05,650 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.001s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7fe64e402310>: Failed to establish a new connection: [Errno 111] Connection refused 2018-11-18 06:59:05,652 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7fe64e4020d0>: Failed to establish a new connection: [Errno 111] Connection refused 2018-11-18 06:59:05,652 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7fe64e402c90>: Failed to establish a new connection: [Errno 111] Connection refused 2018-11-18 06:59:05,653 [lib.cuckoo.core.plugins] ERROR: Failed to run the reporting module "ElasticSearch": Traceback (most recent call last): File "/opt/cuckoo/lib/cuckoo/core/plugins.py", line 533, in process current.run(self.results) File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 196, in run self.connect() File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 79, in connect if not self.es.indices.exists_template("cuckoo_template"): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/utils.py", line 69, in _wrapped return func(*args, params=params, **kwargs) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/indices.py", line 491, in exists_template name), params=params) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/transport.py", line 327, in perform_request status, headers, data = connection.perform_request(method, url, params, body, ignore=ignore, timeout=timeout) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 105, in perform_request raise ConnectionError('N/A', str(e), e) ConnectionError: ConnectionError(<urllib3.connection.HTTPConnection object at 0x7fe64e402c90>: Failed to establish a new connection: [Errno 111] Connection refused) caused by: NewConnectionError(<urllib3.connection.HTTPConnection object at 0x7fe64e402c90>: Failed to establish a new connection: [Errno 111] Connection refused)
pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
section | .gfids |
file | C:\Windows\reg\registery.reg |
file | C:\Windows\reg\Registry.exe |
Invincea | heuristic |
McAfee-GW-Edition | BehavesLike.Win32.Backdoor.gc |
CrowdStrike | malicious_confidence_60% (D) |
No domains contacted.
No hosts contacted.
Opened files
Written files
Files Read
Registry keys opened
Registry keys written
Registry keys read
Mutexes accessed
Directories created
Directories enumerated
DLLs Loaded
Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
---|---|---|---|---|
.text | 0x00001000 | 0x0002dfe8 | 0x0002e000 | 6.71024514176 |
.rdata | 0x0002f000 | 0x000099d0 | 0x00009a00 | 5.15286519013 |
.data | 0x00039000 | 0x0001f8b8 | 0x00000c00 | 3.29546719393 |
.gfids | 0x00059000 | 0x000000f0 | 0x00000200 | 2.12366990435 |
.rsrc | 0x0005a000 | 0x00004680 | 0x00004800 | 4.63811395267 |
.reloc | 0x0005f000 | 0x00001f8c | 0x00002000 | 6.62985537968 |
Antivirus | Signature |
---|---|
Bkav | Clean |
MicroWorld-eScan | Clean |
CMC | Clean |
CAT-QuickHeal | Clean |
McAfee | Clean |
Cylance | Clean |
TheHacker | Clean |
BitDefender | Clean |
K7GW | Clean |
K7AntiVirus | Clean |
TrendMicro | Clean |
Baidu | Clean |
Babable | Clean |
Cyren | Clean |
Symantec | Clean |
ESET-NOD32 | Clean |
TrendMicro-HouseCall | Clean |
Paloalto | Clean |
ClamAV | Clean |
Kaspersky | Clean |
Alibaba | Clean |
NANO-Antivirus | Clean |
ViRobot | Clean |
SUPERAntiSpyware | Clean |
Tencent | Clean |
Ad-Aware | Clean |
Trustlook | Clean |
Sophos | Clean |
F-Secure | Clean |
DrWeb | Clean |
Zillya | Clean |
Invincea | heuristic |
McAfee-GW-Edition | BehavesLike.Win32.Backdoor.gc |
Emsisoft | Clean |
Ikarus | Clean |
F-Prot | Clean |
Jiangmin | Clean |
Webroot | Clean |
Avira | Clean |
Fortinet | Clean |
Antiy-AVL | Clean |
Kingsoft | Clean |
Endgame | Clean |
Arcabit | Clean |
AegisLab | Clean |
ZoneAlarm | Clean |
Avast-Mobile | Clean |
Microsoft | Clean |
TACHYON | Clean |
AhnLab-V3 | Clean |
VBA32 | Clean |
ALYac | Clean |
MAX | Clean |
Malwarebytes | Clean |
Panda | Clean |
Zoner | Clean |
Rising | Clean |
Yandex | Clean |
SentinelOne | Clean |
eGambit | Clean |
GData | Clean |
AVG | Clean |
Cybereason | Clean |
Avast | Clean |
CrowdStrike | malicious_confidence_60% (D) |
Qihoo-360 | Clean |
No hosts contacted.
No domains contacted.
No TCP connections recorded.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.128.109 | 138 | 192.168.128.255 | 138 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts
Name | e3b0c44298fc1c14___tmp_rar_sfx_access_check_25265894 |
---|---|
Size | 0.0B |
Type | empty |
MD5 | d41d8cd98f00b204e9800998ecf8427e |
SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 |
SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
CRC32 | 00000000 |
ssdeep | 3:: |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 8c468122a647e4d6_Registry.exe |
---|---|
Filepath | C:\Windows\reg\Registry.exe |
Size | 360.5KB |
Processes | 2300 (Winzip.exe) |
Type | data |
MD5 | b66874c9d84e3bd10ba753f1cdc18bd3 |
SHA1 | 2a9e9dc8b0a4c96b278dd500d9a67bde05512f38 |
SHA256 | 8c468122a647e4d6c39d23847565957705d56fc08aa7363652dcd43a178016f8 |
CRC32 | 61BBF941 |
ssdeep | 3:F4IAKTWs4iv9lJF0s7Eq70G/l:XvTkilHj7GG/ |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 4332b157d5081340_registery.reg |
---|---|
Filepath | C:\Windows\reg\registery.reg |
Size | 388.0B |
Processes | 2300 (Winzip.exe) |
Type | 8086 relocatable (Microsoft) |
MD5 | 576f5aa6715baaad6c2a8846ec1a5fae |
SHA1 | 7d3b8b95602668cde3960ded1c4157204ab47f4e |
SHA256 | 4332b157d5081340fc526469e40729826109a6213612a72159bc5b2f45204dcb |
CRC32 | C15DE1C9 |
ssdeep | 6:vrToLE4MhZ/+wv3iWDGi4DBOF72dm7deBe/3dWpuLwCFf0Xl:vrTowZvS95dy0IdlNBFfsl |
Yara | None matched |
VirusTotal | Search for analysis |
Task ID | 68 |
---|---|
Mongo ID | 5bf1540b11d3080b6a1c5c70 |
Cuckoo release | 2.0-dev |