Size | 30.8KB |
---|---|
Type | HTML document, ASCII text, with very long lines (1639), with CRLF, LF line terminators |
MD5 | 23064e1e4c590cfe396c3605494c53b8 |
SHA1 | 950b47314ec473f7287dea30806043e0a77bc449 |
SHA256 | 503dca3cbbd6955dc5ecc1c35a8b3f66d63f6a10756166b6c828605b23a84842 |
SHA512 |
ff64b88630abc5071195ec6182b54159e9189c0828f97cbc8de652a8f64e1900621f19f7c8f0ae93469356747c5bca5979a6537204dae063ed4298e53649d2fe
|
CRC32 | 3701851D |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Jan. 26, 2025, 3:12 p.m. | Jan. 26, 2025, 3:15 p.m. | 163 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-01-21 14:54:06,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpblqbwr 2025-01-21 14:54:06,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\anfPeYqHjWCtHIrTTCwmVVFwgZq 2025-01-21 14:54:06,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\VEkqwDeECWcyNLWlyNfFwrvLUuQa 2025-01-21 14:54:06,342 [analyzer] DEBUG: Started auxiliary module Curtain 2025-01-21 14:54:06,342 [analyzer] DEBUG: Started auxiliary module DbgView 2025-01-21 14:54:06,812 [analyzer] DEBUG: Started auxiliary module Disguise 2025-01-21 14:54:07,015 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-01-21 14:54:07,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-01-21 14:54:07,015 [analyzer] DEBUG: Started auxiliary module Human 2025-01-21 14:54:07,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-01-21 14:54:07,015 [analyzer] DEBUG: Started auxiliary module Reboot 2025-01-21 14:54:07,155 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-01-21 14:54:07,155 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-01-21 14:54:07,155 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-01-21 14:54:07,155 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-01-21 14:54:07,155 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-01-21 14:54:07,265 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\503dca3cbbd6955dc5ecc1c35a8b3f66d63f6a10756166b6c828605b23a84842.js'] and pid 2040 2025-01-21 14:54:07,515 [analyzer] DEBUG: Loaded monitor into process with pid 2040 2025-01-21 14:54:07,921 [analyzer] INFO: io=NULL 2025-01-21 14:54:07,921 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-01-21 14:54:07,921 [analyzer] INFO: io=NULL 2025-01-21 14:54:07,921 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-01-21 14:54:07,921 [analyzer] INFO: io=NULL 2025-01-21 14:54:07,921 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-01-21 14:54:07,967 [analyzer] INFO: io=NULL 2025-01-21 14:54:07,967 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-01-21 14:54:07,967 [analyzer] INFO: io=NULL 2025-01-21 14:54:07,983 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-01-21 14:54:07,983 [analyzer] INFO: io=NULL 2025-01-21 14:54:07,983 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-01-21 14:54:36,328 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-01-21 14:54:36,858 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-01-21 14:54:36,875 [lib.api.process] INFO: Successfully terminated process with pid 2040. 2025-01-21 14:54:36,875 [analyzer] INFO: Analysis completed.
2025-01-26 15:12:52,689 [cuckoo.core.scheduler] INFO: Task #5831276: acquired machine win7x6418 (label=win7x6418) 2025-01-26 15:12:52,690 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.218 for task #5831276 2025-01-26 15:12:52,909 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 4143456 (interface=vboxnet0, host=192.168.168.218) 2025-01-26 15:12:52,947 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6418 2025-01-26 15:12:53,725 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6418 to vmcloak 2025-01-26 15:13:55,039 [cuckoo.core.guest] INFO: Starting analysis #5831276 on guest (id=win7x6418, ip=192.168.168.218) 2025-01-26 15:13:56,045 [cuckoo.core.guest] DEBUG: win7x6418: not ready yet 2025-01-26 15:14:01,087 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6418, ip=192.168.168.218) 2025-01-26 15:14:01,181 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6418, ip=192.168.168.218, monitor=latest, size=6660546) 2025-01-26 15:14:02,407 [cuckoo.core.resultserver] DEBUG: Task #5831276: live log analysis.log initialized. 2025-01-26 15:14:03,368 [cuckoo.core.resultserver] DEBUG: Task #5831276 is sending a BSON stream 2025-01-26 15:14:03,808 [cuckoo.core.resultserver] DEBUG: Task #5831276 is sending a BSON stream 2025-01-26 15:14:04,747 [cuckoo.core.resultserver] DEBUG: Task #5831276: File upload for 'shots/0001.jpg' 2025-01-26 15:14:04,770 [cuckoo.core.resultserver] DEBUG: Task #5831276 uploaded file length: 133465 2025-01-26 15:14:05,886 [cuckoo.core.resultserver] DEBUG: Task #5831276: File upload for 'shots/0002.jpg' 2025-01-26 15:14:05,911 [cuckoo.core.resultserver] DEBUG: Task #5831276 uploaded file length: 136724 2025-01-26 15:14:17,047 [cuckoo.core.guest] DEBUG: win7x6418: analysis #5831276 still processing 2025-01-26 15:14:32,564 [cuckoo.core.guest] DEBUG: win7x6418: analysis #5831276 still processing 2025-01-26 15:14:33,037 [cuckoo.core.resultserver] DEBUG: Task #5831276: File upload for 'curtain/1737467676.61.curtain.log' 2025-01-26 15:14:33,041 [cuckoo.core.resultserver] DEBUG: Task #5831276 uploaded file length: 36 2025-01-26 15:14:33,285 [cuckoo.core.resultserver] DEBUG: Task #5831276: File upload for 'sysmon/1737467676.86.sysmon.xml' 2025-01-26 15:14:33,304 [cuckoo.core.resultserver] DEBUG: Task #5831276 uploaded file length: 959350 2025-01-26 15:14:33,884 [cuckoo.core.resultserver] DEBUG: Task #5831276: File upload for 'shots/0003.jpg' 2025-01-26 15:14:33,900 [cuckoo.core.resultserver] DEBUG: Task #5831276 uploaded file length: 133465 2025-01-26 15:14:33,916 [cuckoo.core.resultserver] DEBUG: Task #5831276 had connection reset for <Context for LOG> 2025-01-26 15:14:35,596 [cuckoo.core.guest] INFO: win7x6418: analysis completed successfully 2025-01-26 15:14:35,622 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-01-26 15:14:35,650 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-01-26 15:14:36,479 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6418 to path /srv/cuckoo/cwd/storage/analyses/5831276/memory.dmp 2025-01-26 15:14:36,483 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6418 2025-01-26 15:15:34,608 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.218 for task #5831276 2025-01-26 15:15:35,612 [cuckoo.core.scheduler] DEBUG: Released database task #5831276 2025-01-26 15:15:35,632 [cuckoo.core.scheduler] INFO: Task #5831276: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Windows Defender (Windows) | Trojan:HTML/Phish.DG!MTB |
Microsoft Defender ATP (Linux) | Trojan:Win64/CoinMiner |
Forticlient (Linux) | HTML/Agent.363C!tr |
Ikarus | Phishing.HTML.Doc |
Detected | |
Microsoft | Trojan:HTML/Phish.DG!MTB |
Varist | HTML/Phish.HDZ |
MaxSecure | Trojan.WIN32.cryxos.5913 |
Fortinet | HTML/Agent.363C!tr |