Size | 83.4KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (4809), with CRLF, LF line terminators |
MD5 | b2b9033a07684f485d5386d55ead4a7b |
SHA1 | 261b32da0eda9968abcb99aed70e5a4d12ec18f4 |
SHA256 | 34bca5f54fb4530389822c8ea07f7672f37f927ef87a2df696a2753984188473 |
SHA512 |
2276788bfbcc5070b252e0511d2a79c58db3652b96931195c5527107aab87f60624f0d716563dfbf686a82114be1aff833de283bb78ef83dd8ee40a2e7cca972
|
CRC32 | 1917D5C9 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 2, 2025, 5:33 a.m. | April 2, 2025, 5:40 a.m. | 401 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-01 13:33:07,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpf7a_02 2025-04-01 13:33:07,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ShFPDSPiRyJtuBRqLb 2025-04-01 13:33:07,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\iNEYTXHXhZwnrWXvEGthDD 2025-04-01 13:33:07,296 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-01 13:33:07,296 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-01 13:33:07,765 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-01 13:33:07,967 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-04-01 13:33:07,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-01 13:33:07,967 [analyzer] DEBUG: Started auxiliary module Human 2025-04-01 13:33:07,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-01 13:33:07,967 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-01 13:33:08,046 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-01 13:33:08,046 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-01 13:33:08,046 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-01 13:33:08,046 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-01 13:33:08,046 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-04-01 13:33:08,140 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\34bca5f54fb4530389822c8ea07f7672f37f927ef87a2df696a2753984188473.js'] and pid 1380 2025-04-01 13:33:08,358 [analyzer] DEBUG: Loaded monitor into process with pid 1380 2025-04-01 13:33:08,703 [analyzer] INFO: io=NULL 2025-04-01 13:33:08,703 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-01 13:33:08,703 [analyzer] INFO: io=NULL 2025-04-01 13:33:08,703 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-01 13:33:08,703 [analyzer] INFO: io=NULL 2025-04-01 13:33:08,703 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-01 13:33:08,733 [analyzer] INFO: io=NULL 2025-04-01 13:33:08,733 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-01 13:33:08,733 [analyzer] INFO: io=NULL 2025-04-01 13:33:08,733 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-01 13:33:08,733 [analyzer] INFO: io=NULL 2025-04-01 13:33:08,750 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-01 13:33:37,155 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-01 13:33:37,655 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-01 13:33:37,655 [lib.api.process] INFO: Successfully terminated process with pid 1380. 2025-04-01 13:33:37,655 [analyzer] INFO: Analysis completed.
2025-04-02 05:33:20,385 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:21,448 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:22,471 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:23,623 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:24,678 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:25,710 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:26,918 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:27,950 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:28,974 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:30,002 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:31,048 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:32,079 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:33,119 [cuckoo.core.scheduler] DEBUG: Task #6205437: no machine available yet 2025-04-02 05:33:34,298 [cuckoo.core.scheduler] INFO: Task #6205437: acquired machine win7x6427 (label=win7x6427) 2025-04-02 05:33:34,316 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.227 for task #6205437 2025-04-02 05:33:34,665 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1563400 (interface=vboxnet0, host=192.168.168.227) 2025-04-02 05:33:34,701 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6427 2025-04-02 05:33:35,307 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6427 to vmcloak 2025-04-02 05:36:54,264 [cuckoo.core.guest] INFO: Starting analysis #6205437 on guest (id=win7x6427, ip=192.168.168.227) 2025-04-02 05:36:55,269 [cuckoo.core.guest] DEBUG: win7x6427: not ready yet 2025-04-02 05:37:00,293 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6427, ip=192.168.168.227) 2025-04-02 05:37:00,428 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6427, ip=192.168.168.227, monitor=latest, size=6660546) 2025-04-02 05:37:01,951 [cuckoo.core.resultserver] DEBUG: Task #6205437: live log analysis.log initialized. 2025-04-02 05:37:02,875 [cuckoo.core.resultserver] DEBUG: Task #6205437 is sending a BSON stream 2025-04-02 05:37:03,231 [cuckoo.core.resultserver] DEBUG: Task #6205437 is sending a BSON stream 2025-04-02 05:37:04,131 [cuckoo.core.resultserver] DEBUG: Task #6205437: File upload for 'shots/0001.jpg' 2025-04-02 05:37:04,156 [cuckoo.core.resultserver] DEBUG: Task #6205437 uploaded file length: 133433 2025-04-02 05:37:05,284 [cuckoo.core.resultserver] DEBUG: Task #6205437: File upload for 'shots/0002.jpg' 2025-04-02 05:37:05,299 [cuckoo.core.resultserver] DEBUG: Task #6205437 uploaded file length: 136922 2025-04-02 05:37:16,533 [cuckoo.core.guest] DEBUG: win7x6427: analysis #6205437 still processing 2025-04-02 05:37:31,797 [cuckoo.core.guest] DEBUG: win7x6427: analysis #6205437 still processing 2025-04-02 05:37:32,343 [cuckoo.core.resultserver] DEBUG: Task #6205437: File upload for 'curtain/1743507217.36.curtain.log' 2025-04-02 05:37:32,346 [cuckoo.core.resultserver] DEBUG: Task #6205437 uploaded file length: 36 2025-04-02 05:37:32,584 [cuckoo.core.resultserver] DEBUG: Task #6205437: File upload for 'sysmon/1743507217.61.sysmon.xml' 2025-04-02 05:37:32,632 [cuckoo.core.resultserver] DEBUG: Task #6205437 uploaded file length: 2326370 2025-04-02 05:37:32,891 [cuckoo.core.resultserver] DEBUG: Task #6205437: File upload for 'shots/0003.jpg' 2025-04-02 05:37:32,906 [cuckoo.core.resultserver] DEBUG: Task #6205437 uploaded file length: 133669 2025-04-02 05:37:32,919 [cuckoo.core.resultserver] DEBUG: Task #6205437 had connection reset for <Context for LOG> 2025-04-02 05:37:34,817 [cuckoo.core.guest] INFO: win7x6427: analysis completed successfully 2025-04-02 05:37:34,829 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-02 05:37:34,859 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-02 05:37:35,964 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6427 to path /srv/cuckoo/cwd/storage/analyses/6205437/memory.dmp 2025-04-02 05:37:35,966 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6427 2025-04-02 05:40:01,056 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.227 for task #6205437 2025-04-02 05:40:01,436 [cuckoo.core.scheduler] DEBUG: Released database task #6205437 2025-04-02 05:40:01,454 [cuckoo.core.scheduler] INFO: Task #6205437: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
G Data Antivirus (Windows) | Virus: HTML:Beluga.6361 (Engine A) |
eScan Antivirus (Linux) | HTML:Beluga.6361(DB) |
Bitdefender Antivirus (Linux) | HTML:Beluga.6361 |
Emsisoft Commandline Scanner (Windows) | HTML:Beluga.6361 (B) |
CTX | html.trojan.beluga |
ALYac | HTML:Beluga.6361 |
VIPRE | HTML:Beluga.6361 |
Arcabit | HTML:Beluga.D18D9 |
BitDefender | HTML:Beluga.6361 |
MicroWorld-eScan | HTML:Beluga.6361 |
Emsisoft | HTML:Beluga.6361 (B) |
FireEye | HTML:Beluga.6361 |
Microsoft | Trojan:HTML/Nemucod.PA!MTB |
GData | HTML:Beluga.6361 |
Tencent | OB:Trojan.Script.Phishing_l.506000 |
Fortinet | HTML/Agent.A2A7!tr |
alibabacloud | Trojan:Unknow/Nemucod.PM8PHU |