Size | 57.2KB |
---|---|
Type | HTML document, ASCII text, with very long lines (9155), with CRLF, LF line terminators |
MD5 | e67affb0580f551352f7a6c2f1c37ee1 |
SHA1 | 3079a0055cbfdf56248fe2acff1e5ee0def17ab6 |
SHA256 | 0320125aef0c04340444b6f83193aed37ad58eedebbfa60001cff2fe0a8eb9b8 |
SHA512 |
5f2a663caea15d8f4e352681ca03ab9b52b682c37e1b2d46e056475359e1086dc24f23533a6d205a744f1209dfb4bf4c09c7851d31fbe91a99ec3910b872432e
|
CRC32 | 7627CDCE |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 2, 2025, 5:40 a.m. | April 2, 2025, 5:48 a.m. | 455 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-01 13:33:17,062 [analyzer] DEBUG: Starting analyzer from: C:\tmppw5mq4 2025-04-01 13:33:17,078 [analyzer] DEBUG: Pipe server name: \??\PIPE\xeHRxSAIiwDhLEiaVqbbZirascXHYEj 2025-04-01 13:33:17,078 [analyzer] DEBUG: Log pipe server name: \??\PIPE\GgPlHECDqDLQwmVIxC 2025-04-01 13:33:17,671 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-01 13:33:17,671 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-01 13:33:18,983 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-01 13:33:19,217 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-04-01 13:33:19,217 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-01 13:33:19,217 [analyzer] DEBUG: Started auxiliary module Human 2025-04-01 13:33:19,217 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-01 13:33:19,217 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-01 13:33:19,342 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-01 13:33:19,342 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-01 13:33:19,358 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-01 13:33:19,358 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-01 13:33:19,358 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-04-01 13:33:19,500 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\0320125aef0c04340444b6f83193aed37ad58eedebbfa60001cff2fe0a8eb9b8.js'] and pid 3008 2025-04-01 13:33:19,750 [analyzer] DEBUG: Loaded monitor into process with pid 3008 2025-04-01 13:33:20,125 [analyzer] INFO: io=NULL 2025-04-01 13:33:20,125 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-01 13:33:20,125 [analyzer] INFO: io=NULL 2025-04-01 13:33:20,125 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-01 13:33:20,140 [analyzer] INFO: io=NULL 2025-04-01 13:33:20,140 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-01 13:33:20,187 [analyzer] INFO: io=NULL 2025-04-01 13:33:20,187 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-01 13:33:20,187 [analyzer] INFO: io=NULL 2025-04-01 13:33:20,187 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-01 13:33:20,187 [analyzer] INFO: io=NULL 2025-04-01 13:33:20,187 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-01 13:33:48,500 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-01 13:33:49,015 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-01 13:33:49,015 [lib.api.process] INFO: Successfully terminated process with pid 3008. 2025-04-01 13:33:49,015 [analyzer] INFO: Analysis completed.
2025-04-02 05:40:44,945 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:46,082 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:47,114 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:48,141 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:49,165 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:50,201 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:51,233 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:52,269 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:53,298 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:54,322 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:55,343 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:56,366 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:57,399 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:58,436 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:40:59,460 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:00,490 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:01,585 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:02,627 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:03,645 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:04,670 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:05,703 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:06,733 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:07,763 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:08,783 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:09,818 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:10,841 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:11,865 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:12,890 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:13,909 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:14,985 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:16,028 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:17,081 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:18,132 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:19,187 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:20,234 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:21,458 [cuckoo.core.scheduler] DEBUG: Task #6205479: no machine available yet 2025-04-02 05:41:22,563 [cuckoo.core.scheduler] INFO: Task #6205479: acquired machine win7x646 (label=win7x646) 2025-04-02 05:41:22,568 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.206 for task #6205479 2025-04-02 05:41:22,996 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1575988 (interface=vboxnet0, host=192.168.168.206) 2025-04-02 05:41:23,079 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x646 2025-04-02 05:41:23,707 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x646 to vmcloak 2025-04-02 05:44:21,409 [cuckoo.core.guest] INFO: Starting analysis #6205479 on guest (id=win7x646, ip=192.168.168.206) 2025-04-02 05:44:22,415 [cuckoo.core.guest] DEBUG: win7x646: not ready yet 2025-04-02 05:44:27,456 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x646, ip=192.168.168.206) 2025-04-02 05:44:27,584 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x646, ip=192.168.168.206, monitor=latest, size=6660546) 2025-04-02 05:44:30,067 [cuckoo.core.resultserver] DEBUG: Task #6205479: live log analysis.log initialized. 2025-04-02 05:44:32,228 [cuckoo.core.resultserver] DEBUG: Task #6205479 is sending a BSON stream 2025-04-02 05:44:32,648 [cuckoo.core.resultserver] DEBUG: Task #6205479 is sending a BSON stream 2025-04-02 05:44:33,533 [cuckoo.core.resultserver] DEBUG: Task #6205479: File upload for 'shots/0001.jpg' 2025-04-02 05:44:33,547 [cuckoo.core.resultserver] DEBUG: Task #6205479 uploaded file length: 133433 2025-04-02 05:44:34,696 [cuckoo.core.resultserver] DEBUG: Task #6205479: File upload for 'shots/0002.jpg' 2025-04-02 05:44:34,711 [cuckoo.core.resultserver] DEBUG: Task #6205479 uploaded file length: 137183 2025-04-02 05:44:44,304 [cuckoo.core.guest] DEBUG: win7x646: analysis #6205479 still processing 2025-04-02 05:44:59,770 [cuckoo.core.guest] DEBUG: win7x646: analysis #6205479 still processing 2025-04-02 05:45:01,890 [cuckoo.core.resultserver] DEBUG: Task #6205479: File upload for 'curtain/1743507228.77.curtain.log' 2025-04-02 05:45:01,893 [cuckoo.core.resultserver] DEBUG: Task #6205479 uploaded file length: 36 2025-04-02 05:45:02,104 [cuckoo.core.resultserver] DEBUG: Task #6205479: File upload for 'sysmon/1743507228.98.sysmon.xml' 2025-04-02 05:45:02,138 [cuckoo.core.resultserver] DEBUG: Task #6205479 uploaded file length: 1517738 2025-04-02 05:45:02,767 [cuckoo.core.resultserver] DEBUG: Task #6205479: File upload for 'shots/0003.jpg' 2025-04-02 05:45:02,785 [cuckoo.core.guest] INFO: win7x646: analysis completed successfully 2025-04-02 05:45:02,792 [cuckoo.core.resultserver] DEBUG: Task #6205479 uploaded file length: 133433 2025-04-02 05:45:02,799 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-02 05:45:02,809 [cuckoo.core.resultserver] DEBUG: Task #6205479 had connection reset for <Context for LOG> 2025-04-02 05:45:02,832 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-02 05:45:03,812 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x646 to path /srv/cuckoo/cwd/storage/analyses/6205479/memory.dmp 2025-04-02 05:45:03,814 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x646 2025-04-02 05:48:20,094 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.206 for task #6205479 2025-04-02 05:48:20,522 [cuckoo.core.scheduler] DEBUG: Released database task #6205479 2025-04-02 05:48:20,544 [cuckoo.core.scheduler] INFO: Task #6205479: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
G Data Antivirus (Windows) | Virus: HTML:Beluga.9133 (Engine A) |
eScan Antivirus (Linux) | HTML:Beluga.9133(DB) |
Bitdefender Antivirus (Linux) | HTML:Beluga.9133 |
Emsisoft Commandline Scanner (Windows) | HTML:Beluga.9133 (B) |
MicroWorld-eScan | HTML:Beluga.9133 |
CTX | html.trojan.beluga |
ALYac | HTML:Beluga.9133 |
VIPRE | HTML:Beluga.9133 |
Arcabit | HTML:Beluga.D23AD |
BitDefender | HTML:Beluga.9133 |
Emsisoft | HTML:Beluga.9133 (B) |
Ikarus | HTML.Beluga |
FireEye | HTML:Beluga.9133 |
Detected | |
Microsoft | Trojan:HTML/Phish.DG!MTB |
GData | HTML:Beluga.9133 |
Tencent | OB:Trojan.Script.Phishing_l.506017 |
MaxSecure | Trojan.WIN32.cryxos.5913 |
Fortinet | HTML/Agent.EC!tr |
alibabacloud | Trojan:Unknow/Phish.DU8PHU |