Size | 15.6KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (5035) |
MD5 | 2a1c51ccc7ac9ef75c34da4cebc2829c |
SHA1 | 1c189b03b155d892403c07ae9fe83e1f008f3f06 |
SHA256 | cbb053eed68b1c5e5f65fcf605012d273405d5b24cae814db97d1b525f7a72c4 |
SHA512 |
d6c42177e8d9da9adfa1034bef1c16fa76fc65cecab1a62211062cddcc22c6de6bcc6e6f5fec2ee8c28deb446f7e09fa9c3324cabb1ea3234a677dccfe740403
|
CRC32 | AEDBCB3C |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 29, 2025, 9:29 p.m. | April 29, 2025, 9:36 p.m. | 433 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-29 16:28:06,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpwwr_kc 2025-04-29 16:28:06,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\iKVGkEyYyOelRBoWWfgRVnumust 2025-04-29 16:28:06,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\WMkcZNwIwyyQfOQEQuxfyts 2025-04-29 16:28:06,592 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-29 16:28:06,592 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-29 16:28:07,592 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-29 16:28:07,812 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-04-29 16:28:07,812 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-29 16:28:07,812 [analyzer] DEBUG: Started auxiliary module Human 2025-04-29 16:28:07,812 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-29 16:28:07,828 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-29 16:28:07,921 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-29 16:28:07,937 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-29 16:28:07,937 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-29 16:28:07,937 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-29 16:28:07,937 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-04-29 16:28:08,046 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\cbb053eed68b1c5e5f65fcf605012d273405d5b24cae814db97d1b525f7a72c4.js'] and pid 1028 2025-04-29 16:28:08,280 [analyzer] DEBUG: Loaded monitor into process with pid 1028 2025-04-29 16:28:08,687 [analyzer] INFO: io=NULL 2025-04-29 16:28:08,687 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-29 16:28:08,687 [analyzer] INFO: io=NULL 2025-04-29 16:28:08,687 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-29 16:28:08,687 [analyzer] INFO: io=NULL 2025-04-29 16:28:08,687 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-29 16:28:08,750 [analyzer] INFO: io=NULL 2025-04-29 16:28:08,750 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-29 16:28:08,750 [analyzer] INFO: io=NULL 2025-04-29 16:28:08,750 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-29 16:28:08,750 [analyzer] INFO: io=NULL 2025-04-29 16:28:08,750 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-29 20:33:39,266 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-29 20:33:40,095 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-29 20:33:40,095 [lib.api.process] INFO: Successfully terminated process with pid 1028. 2025-04-29 20:33:40,111 [analyzer] INFO: Analysis completed.
2025-04-29 21:29:18,487 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:19,530 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:20,568 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:21,586 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:22,611 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:23,640 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:24,664 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:25,686 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:26,850 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:27,880 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:28,915 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:29,944 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:30,971 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:31,995 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:33,015 [cuckoo.core.scheduler] DEBUG: Task #6358666: no machine available yet 2025-04-29 21:29:34,054 [cuckoo.core.scheduler] INFO: Task #6358666: acquired machine win7x645 (label=win7x645) 2025-04-29 21:29:34,055 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.205 for task #6358666 2025-04-29 21:29:34,423 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2840497 (interface=vboxnet0, host=192.168.168.205) 2025-04-29 21:29:34,477 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x645 2025-04-29 21:29:34,996 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x645 to vmcloak 2025-04-29 21:32:59,848 [cuckoo.core.guest] INFO: Starting analysis #6358666 on guest (id=win7x645, ip=192.168.168.205) 2025-04-29 21:33:00,855 [cuckoo.core.guest] DEBUG: win7x645: not ready yet 2025-04-29 21:33:05,890 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x645, ip=192.168.168.205) 2025-04-29 21:33:05,979 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x645, ip=192.168.168.205, monitor=latest, size=6660546) 2025-04-29 21:33:08,201 [cuckoo.core.resultserver] DEBUG: Task #6358666: live log analysis.log initialized. 2025-04-29 21:33:09,968 [cuckoo.core.resultserver] DEBUG: Task #6358666 is sending a BSON stream 2025-04-29 21:33:10,342 [cuckoo.core.resultserver] DEBUG: Task #6358666 is sending a BSON stream 2025-04-29 21:33:11,268 [cuckoo.core.resultserver] DEBUG: Task #6358666: File upload for 'shots/0001.jpg' 2025-04-29 21:33:11,493 [cuckoo.core.resultserver] DEBUG: Task #6358666 uploaded file length: 133485 2025-04-29 21:33:12,405 [cuckoo.core.resultserver] DEBUG: Task #6358666: File upload for 'shots/0002.jpg' 2025-04-29 21:33:12,415 [cuckoo.core.resultserver] DEBUG: Task #6358666 uploaded file length: 137199 2025-04-29 21:33:23,177 [cuckoo.core.guest] DEBUG: win7x645: analysis #6358666 still processing 2025-04-29 21:33:38,403 [cuckoo.core.guest] DEBUG: win7x645: analysis #6358666 still processing 2025-04-29 21:33:39,475 [cuckoo.core.resultserver] DEBUG: Task #6358666: File upload for 'curtain/1745951619.47.curtain.log' 2025-04-29 21:33:39,486 [cuckoo.core.resultserver] DEBUG: Task #6358666 uploaded file length: 36 2025-04-29 21:33:39,777 [cuckoo.core.resultserver] DEBUG: Task #6358666: File upload for 'sysmon/1745951619.64.sysmon.xml' 2025-04-29 21:33:40,142 [cuckoo.core.resultserver] DEBUG: Task #6358666 uploaded file length: 1329220 2025-04-29 21:33:40,255 [cuckoo.core.resultserver] DEBUG: Task #6358666: File upload for 'shots/0003.jpg' 2025-04-29 21:33:40,272 [cuckoo.core.resultserver] DEBUG: Task #6358666 uploaded file length: 134210 2025-04-29 21:33:40,288 [cuckoo.core.resultserver] DEBUG: Task #6358666 had connection reset for <Context for LOG> 2025-04-29 21:33:41,443 [cuckoo.core.guest] INFO: win7x645: analysis completed successfully 2025-04-29 21:33:41,457 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-29 21:33:41,633 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-29 21:33:42,725 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x645 to path /srv/cuckoo/cwd/storage/analyses/6358666/memory.dmp 2025-04-29 21:33:42,727 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x645 2025-04-29 21:36:31,350 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.205 for task #6358666 2025-04-29 21:36:31,876 [cuckoo.core.scheduler] DEBUG: Released database task #6358666 2025-04-29 21:36:31,890 [cuckoo.core.scheduler] INFO: Task #6358666: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Avast Core Security (Linux) | Script:SNH-gen [Trj] |
Avast | Script:SNH-gen [Trj] |
Rising | Trojan.Obfuse/JS!8.13444 (TOPIS:E0:4DQfWU1cVIK) |
Detected | |
Microsoft | Trojan:Script/Wacatac.B!ml |
Varist | JS/Agent.CMI1!Eldorado |
MaxSecure | Trojan.W32.cryxos.13240 |
Fortinet | JS/Cryxos.13371!tr |
AVG | Script:SNH-gen [Trj] |