Category Started On Completed On Duration Cuckoo Version
FILE 2014-06-03 10:21:30 2014-06-03 10:22:53 83 seconds 1.3-dev
Machine Label Manager Started On Shutdown On
egg1 egg1 VirtualBox 2014-06-03 10:21:31 2014-06-03 10:22:50

File Details

File name ce51eaef8dab8d2f2c073456eca5adb6.bat
File size 196 bytes
File type ASCII text, with CRLF line terminators
CRC32 D30BC7DB
MD5 ce51eaef8dab8d2f2c073456eca5adb6
SHA1 b37e3c6c4bdd99b946924d0a844c08deb44a169b
SHA256 38c8dcde86be1122ae858a5bfa50d0d644b5a908d91210785b7f999c063a4871
SHA512 e9d02751264df744ee7511075e192f758bbff5566c97f3df71b0f7c21ede4cf5e52f7e0feab58bac58211f8c15c7dc7893049b3ab0109ee66e7ab9adb5d49d99
Ssdeep None
PEiD None matched
Yara None matched
VirusTotal VirusTotal lookup disabled, add your API key to the module

Signatures

No signatures matched

Screenshots

Static Analysis

Nothing to display.

Dropped Files

Nothing to display.

Network Analysis

Hosts Involved

DNS Requests

Behavior Summary

Files
  • C:\Users
  • C:\Users\ADMINI~1
  • C:\Users\ADMINI~1\AppData
  • C:\Users\ADMINI~1\AppData\Local
  • C:\Users\ADMINI~1\AppData\Local\Temp
  • C:\Users\ADMINI~1\AppData\Local\Temp\ce51eaef8dab8d2f2c073456eca5adb6.bat
  • C:\
  • C:\Users\ADMINI~1\AppData\Local\Temp\ce51eaef8dab8d2f2c073456eca5adb6.bat\
  • C:\Users\ADMINI~1\AppData\Local\Temp\
  • C:\Users\ADMINI~1\AppData\Local\
  • C:\Users\ADMINI~1\AppData\
  • C:\Users\ADMINI~1\
  • C:\Users\
  • C:
  • MountPointManager
  • C:\Users\ADMINI~1\AppData\Local\Temp\cmd.exe
  • C:\Users\ADMINI~1\AppData\Local\Temp\cmd.exe.*
  • C:\Windows\system32\cmd.exe
  • c:\flag1.txt
  • c:\Windows\flag2.txt
  • c:\Users\Administrator\Documents\flag3.txt
  • c:\Users\Administrator\AppData\Roaming\flag4.txt
Mutexes Nothing to display.
Registry Keys
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500
  • Software\Policies\Microsoft\Windows\System
  • Software\Microsoft\Command Processor
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\LevelObjects
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones
  • HKEY_USERS\S-1-5-21-1759130447-358110555-3069562910-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option

Processes

registry filesystem process services network synchronization

cmd.exe PID: 1924, Parent PID: 1852

cmd.exe PID: 2240, Parent PID: 1924

cmd.exe PID: 2280, Parent PID: 2240

cmd.exe PID: 2304, Parent PID: 2240

cmd.exe PID: 2328, Parent PID: 2240

cmd.exe PID: 2352, Parent PID: 2240

Volatility

Nothing to display.