Size | 157.9KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (8856), with CRLF, LF line terminators |
MD5 | 7c3f80bd9a5d26491422c35bea7098de |
SHA1 | b900f05d9ce507ff691977e59e14ebc19d19c8a7 |
SHA256 | 010c212a00e39c9e105e8e81c34b0450ba81b32276bae9af594513973c44252f |
SHA512 |
7a971d8bfdd9057257e34fcbdbb79d9e7b0c7d5b7aca2bc432e12e9835597c81eee70f137543612562b2f5288ebabe251230899d153c945169d08d86fcc8204d
|
CRC32 | 2F332C36 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 11, 2025, 2:08 p.m. | April 11, 2025, 2:14 p.m. | 392 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-10 13:22:32,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd 2025-04-10 13:22:32,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\BbawJQGXAoyytfmipTYADmtiS 2025-04-10 13:22:32,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\bxTvzalzXKiYzStC 2025-04-10 13:22:32,233 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-10 13:22:32,233 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-10 13:22:32,796 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-10 13:22:33,030 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-04-10 13:22:33,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-10 13:22:33,030 [analyzer] DEBUG: Started auxiliary module Human 2025-04-10 13:22:33,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-10 13:22:33,030 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-10 13:22:33,092 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-10 13:22:33,092 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-10 13:22:33,092 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-10 13:22:33,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-10 13:22:33,108 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-04-10 13:22:33,171 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\010c212a00e39c9e105e8e81c34b0450ba81b32276bae9af594513973c44252f.js'] and pid 196 2025-04-10 13:22:33,390 [analyzer] DEBUG: Loaded monitor into process with pid 196 2025-04-10 13:22:33,703 [analyzer] INFO: io=NULL 2025-04-10 13:22:33,703 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-10 13:22:33,703 [analyzer] INFO: io=NULL 2025-04-10 13:22:33,703 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-10 13:22:33,703 [analyzer] INFO: io=NULL 2025-04-10 13:22:33,703 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-10 13:22:33,750 [analyzer] INFO: io=NULL 2025-04-10 13:22:33,750 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-10 13:22:33,765 [analyzer] INFO: io=NULL 2025-04-10 13:22:33,765 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-10 13:22:33,780 [analyzer] INFO: io=NULL 2025-04-10 13:22:33,780 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-10 13:23:02,217 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-10 13:23:02,687 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-10 13:23:02,687 [lib.api.process] INFO: Successfully terminated process with pid 196. 2025-04-10 13:23:02,687 [analyzer] INFO: Analysis completed.
2025-04-11 14:08:11,875 [cuckoo.core.scheduler] INFO: Task #6259095: acquired machine win7x6412 (label=win7x6412) 2025-04-11 14:08:11,876 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.212 for task #6259095 2025-04-11 14:08:12,328 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3098511 (interface=vboxnet0, host=192.168.168.212) 2025-04-11 14:08:12,378 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6412 2025-04-11 14:08:13,084 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6412 to vmcloak 2025-04-11 14:10:45,946 [cuckoo.core.guest] INFO: Starting analysis #6259095 on guest (id=win7x6412, ip=192.168.168.212) 2025-04-11 14:10:46,954 [cuckoo.core.guest] DEBUG: win7x6412: not ready yet 2025-04-11 14:10:51,986 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6412, ip=192.168.168.212) 2025-04-11 14:10:52,075 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6412, ip=192.168.168.212, monitor=latest, size=6660546) 2025-04-11 14:10:53,596 [cuckoo.core.resultserver] DEBUG: Task #6259095: live log analysis.log initialized. 2025-04-11 14:10:54,581 [cuckoo.core.resultserver] DEBUG: Task #6259095 is sending a BSON stream 2025-04-11 14:10:54,688 [cuckoo.core.resultserver] DEBUG: Task #6259095 is sending a BSON stream 2025-04-11 14:10:55,688 [cuckoo.core.resultserver] DEBUG: Task #6259095: File upload for 'shots/0001.jpg' 2025-04-11 14:10:55,704 [cuckoo.core.resultserver] DEBUG: Task #6259095 uploaded file length: 133467 2025-04-11 14:10:56,818 [cuckoo.core.resultserver] DEBUG: Task #6259095: File upload for 'shots/0002.jpg' 2025-04-11 14:10:56,830 [cuckoo.core.resultserver] DEBUG: Task #6259095 uploaded file length: 136869 2025-04-11 14:11:08,146 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6259095 still processing 2025-04-11 14:11:23,358 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6259095 still processing 2025-04-11 14:11:23,926 [cuckoo.core.resultserver] DEBUG: Task #6259095: File upload for 'curtain/1744284182.47.curtain.log' 2025-04-11 14:11:23,929 [cuckoo.core.resultserver] DEBUG: Task #6259095 uploaded file length: 36 2025-04-11 14:11:24,131 [cuckoo.core.resultserver] DEBUG: Task #6259095: File upload for 'sysmon/1744284182.67.sysmon.xml' 2025-04-11 14:11:24,147 [cuckoo.core.resultserver] DEBUG: Task #6259095 uploaded file length: 1284540 2025-04-11 14:11:24,777 [cuckoo.core.resultserver] DEBUG: Task #6259095: File upload for 'shots/0003.jpg' 2025-04-11 14:11:24,790 [cuckoo.core.resultserver] DEBUG: Task #6259095 uploaded file length: 133459 2025-04-11 14:11:24,805 [cuckoo.core.resultserver] DEBUG: Task #6259095 had connection reset for <Context for LOG> 2025-04-11 14:11:26,377 [cuckoo.core.guest] INFO: win7x6412: analysis completed successfully 2025-04-11 14:11:26,394 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-11 14:11:26,421 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-11 14:11:27,531 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6412 to path /srv/cuckoo/cwd/storage/analyses/6259095/memory.dmp 2025-04-11 14:11:27,533 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6412 2025-04-11 14:14:43,256 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.212 for task #6259095 2025-04-11 14:14:43,645 [cuckoo.core.scheduler] DEBUG: Released database task #6259095 2025-04-11 14:14:43,661 [cuckoo.core.scheduler] INFO: Task #6259095: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Avast Core Security (Linux) | Other:SNH-gen [Phish] |
Sophos Anti-Virus (Linux) | Mal/JSInject-AC |
Avast | Other:SNH-gen [Phish] |
Sophos | Mal/JSInject-AC |
Detected | |
ZoneAlarm | Mal/JSInject-AC |
Varist | JS/Agent.COB |
Fortinet | JS/Agent.F5CF!tr |
AVG | Other:SNH-gen [Phish] |