Size | 23.2KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text |
MD5 | d087b3e634e10c3db981de703c11635a |
SHA1 | 135b9ed14eff9452d1f691d89c21dd833d18dd04 |
SHA256 | bea6b3c66da6d735b5788f1f94a9d30cbee45e2b50036d6e3286479c57ab3bff |
SHA512 |
8ea52d2661d22692b0f122146634f122fec94ff1bbe73c8ef1750c5cecc29af6f5ddaab79917e2e9954bd1792907138a346698cbd6d5f708d566316fdea9dee6
|
CRC32 | 678316B3 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 29, 2025, 9:32 p.m. | April 29, 2025, 9:39 p.m. | 404 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-29 16:28:09,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt 2025-04-29 16:28:09,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\JeMadtCQOMlMukoMwU 2025-04-29 16:28:09,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\NtAYiXEUiWYeVODDJEvIRabEIqFiOO 2025-04-29 16:28:09,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-04-29 16:28:09,030 [analyzer] INFO: Automatically selected analysis package "ie" 2025-04-29 16:28:09,358 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-29 16:28:09,358 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-29 16:28:09,937 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-29 16:28:10,171 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-04-29 16:28:10,203 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-29 16:28:10,203 [analyzer] DEBUG: Started auxiliary module Human 2025-04-29 16:28:10,203 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-29 16:28:10,203 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-29 16:28:10,296 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-29 16:28:10,296 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-29 16:28:10,296 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-29 16:28:10,296 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-29 16:28:10,296 [modules.packages.ie] INFO: Submitted file is missing extension, adding .html 2025-04-29 16:28:10,437 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\bea6b3c66da6d735b5788f1f94a9d30cbee45e2b50036d6e3286479c57ab3bff.html'] and pid 1420 2025-04-29 16:28:10,592 [analyzer] DEBUG: Loaded monitor into process with pid 1420 2025-04-29 16:28:12,608 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1420 CREDAT:275457 /prefetch:2! 2025-04-29 16:28:12,671 [analyzer] INFO: Injected into process with pid 1820 and name u'iexplore.exe' 2025-04-29 16:28:12,733 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1820. 2025-04-29 16:28:12,875 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{2CB2E17D-2506-11F0-99EB-0CEAD772813F}.dat 2025-04-29 16:28:12,921 [analyzer] DEBUG: Loaded monitor into process with pid 1820 2025-04-29 16:28:12,983 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\~DF865EE390878D2807.TMP 2025-04-29 16:28:13,217 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-04-29 16:28:13,217 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-04-29 16:28:13,217 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-04-29 16:28:13,217 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-04-29 16:28:13,217 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-04-29 16:28:13,217 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-04-29 16:28:13,217 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-04-29 16:28:13,233 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-04-29 16:28:13,233 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-04-29 16:28:13,233 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-04-29 16:28:13,233 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-04-29 16:28:13,233 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-04-29 16:28:13,233 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-04-29 16:28:13,233 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-04-29 16:28:13,562 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2CB2E17F-2506-11F0-99EB-0CEAD772813F}.dat 2025-04-29 16:28:13,592 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\~DF7B27EC4DE8007F3D.TMP 2025-04-29 16:28:13,640 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-04-29 16:28:13,640 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-04-29 16:28:13,640 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-04-29 16:28:13,640 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-04-29 16:28:13,640 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-04-29 16:28:13,640 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-04-29 16:28:13,640 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-04-29 16:28:16,530 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3 2025-04-29 16:28:16,530 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3 2025-04-29 16:28:16,546 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\CabAA76.tmp 2025-04-29 16:28:16,578 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\TarAA77.tmp 2025-04-29 16:28:16,578 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\CabAA97.tmp 2025-04-29 16:28:16,592 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\TarAA98.tmp 2025-04-29 16:28:16,703 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 2025-04-29 16:28:16,703 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 2025-04-29 16:28:16,750 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\CabAB36.tmp 2025-04-29 16:28:16,750 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\TarAB37.tmp 2025-04-29 16:28:16,858 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\CabABA5.tmp 2025-04-29 16:28:16,858 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\TarABB6.tmp 2025-04-29 16:28:16,937 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-04-29 16:28:16,937 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-04-29 16:28:17,000 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 2025-04-29 16:28:17,000 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 2025-04-29 16:28:17,030 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\CabAC53.tmp 2025-04-29 16:28:17,046 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\TarAC64.tmp 2025-04-29 20:35:57,835 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C60C0C29522E01E6A22BD2717F20782E_891CA9AA028995B36234B797075B2660 2025-04-29 20:35:57,835 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C60C0C29522E01E6A22BD2717F20782E_891CA9AA028995B36234B797075B2660 2025-04-29 20:35:57,867 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\CabF739.tmp 2025-04-29 20:35:57,867 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\Local\Temp\TarF73A.tmp 2025-04-29 20:35:57,992 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F0ACCF77CDCBFF39F6191887F6D2D357 2025-04-29 20:35:58,007 [analyzer] INFO: Added new file to list with pid 1820 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F0ACCF77CDCBFF39F6191887F6D2D357 2025-04-29 20:36:01,117 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-29 20:36:01,555 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-29 20:36:01,555 [lib.api.process] INFO: Successfully terminated process with pid 1420. 2025-04-29 20:36:01,555 [lib.api.process] INFO: Successfully terminated process with pid 1820. 2025-04-29 20:36:01,555 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cababa5.tmp' does not exist, skip. 2025-04-29 20:36:01,585 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarac64.tmp' does not exist, skip. 2025-04-29 20:36:01,585 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\taraa98.tmp' does not exist, skip. 2025-04-29 20:36:01,585 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\taraa77.tmp' does not exist, skip. 2025-04-29 20:36:01,585 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarabb6.tmp' does not exist, skip. 2025-04-29 20:36:01,585 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df7b27ec4de8007f3d.tmp' does not exist, skip. 2025-04-29 20:36:01,585 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarab37.tmp' does not exist, skip. 2025-04-29 20:36:01,585 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabf739.tmp' does not exist, skip. 2025-04-29 20:36:01,617 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabaa97.tmp' does not exist, skip. 2025-04-29 20:36:01,617 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabac53.tmp' does not exist, skip. 2025-04-29 20:36:01,617 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabaa76.tmp' does not exist, skip. 2025-04-29 20:36:01,617 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabab36.tmp' does not exist, skip. 2025-04-29 20:36:01,617 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df865ee390878d2807.tmp' does not exist, skip. 2025-04-29 20:36:01,617 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarf73a.tmp' does not exist, skip. 2025-04-29 20:36:01,648 [analyzer] INFO: Analysis completed.
2025-04-29 21:32:24,758 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:25,795 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:26,961 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:28,046 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:29,082 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:30,106 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:31,135 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:32,151 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:33,181 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:34,200 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:35,248 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:36,419 [cuckoo.core.scheduler] DEBUG: Task #6358672: no machine available yet 2025-04-29 21:32:37,502 [cuckoo.core.scheduler] INFO: Task #6358672: acquired machine win7x6423 (label=win7x6423) 2025-04-29 21:32:37,504 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6358672 2025-04-29 21:32:37,981 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2845279 (interface=vboxnet0, host=192.168.168.223) 2025-04-29 21:32:38,041 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423 2025-04-29 21:32:38,565 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak 2025-04-29 21:35:23,166 [cuckoo.core.guest] INFO: Starting analysis #6358672 on guest (id=win7x6423, ip=192.168.168.223) 2025-04-29 21:35:24,170 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet 2025-04-29 21:35:29,205 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223) 2025-04-29 21:35:29,318 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546) 2025-04-29 21:35:30,657 [cuckoo.core.resultserver] DEBUG: Task #6358672: live log analysis.log initialized. 2025-04-29 21:35:31,797 [cuckoo.core.resultserver] DEBUG: Task #6358672 is sending a BSON stream 2025-04-29 21:35:32,198 [cuckoo.core.resultserver] DEBUG: Task #6358672 is sending a BSON stream 2025-04-29 21:35:33,090 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'shots/0001.jpg' 2025-04-29 21:35:33,112 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 133466 2025-04-29 21:35:34,527 [cuckoo.core.resultserver] DEBUG: Task #6358672 is sending a BSON stream 2025-04-29 21:35:35,248 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'shots/0002.jpg' 2025-04-29 21:35:35,253 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 66976 2025-04-29 21:35:36,347 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'shots/0003.jpg' 2025-04-29 21:35:36,350 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 32030 2025-04-29 21:35:45,311 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6358672 still processing 2025-04-29 21:35:57,996 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'shots/0004.jpg' 2025-04-29 21:35:57,998 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 31245 2025-04-29 21:35:59,189 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'shots/0005.jpg' 2025-04-29 21:35:59,820 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 47086 2025-04-29 21:36:00,549 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6358672 still processing 2025-04-29 21:36:01,276 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'curtain/1745951761.26.curtain.log' 2025-04-29 21:36:01,288 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 36 2025-04-29 21:36:01,489 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'sysmon/1745951761.48.sysmon.xml' 2025-04-29 21:36:01,561 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 2084240 2025-04-29 21:36:01,574 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3' 2025-04-29 21:36:01,579 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 889 2025-04-29 21:36:01,584 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/2499aafe95061ffa_c60c0c29522e01e6a22bd2717f20782e_891ca9aa028995b36234b797075b2660' 2025-04-29 21:36:01,595 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 394 2025-04-29 21:36:01,602 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/3ed7064af1ec8cf9_14232b434cf29d4c4fb335a86d7fffe3' 2025-04-29 21:36:01,605 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 170 2025-04-29 21:36:01,608 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/393323a1c06c9a71_{2cb2e17f-2506-11f0-99eb-0cead772813f}.dat' 2025-04-29 21:36:01,613 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 5120 2025-04-29 21:36:01,617 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/fb6a7c3edcd7b97f_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-04-29 21:36:01,625 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 1739 2025-04-29 21:36:01,631 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/04b5a3f7f96987d6_f0accf77cdcbff39f6191887f6d2d357' 2025-04-29 21:36:01,638 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 242 2025-04-29 21:36:01,642 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/5a4d87d40ae3afa6_b46811c17859ffb409cf0e904a4aa8f8' 2025-04-29 21:36:01,646 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 170 2025-04-29 21:36:01,649 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/d90b8f3b368599a9_c60c0c29522e01e6a22bd2717f20782e_891ca9aa028995b36234b797075b2660' 2025-04-29 21:36:01,657 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 279 2025-04-29 21:36:01,659 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/df545bf919a2439c_f0accf77cdcbff39f6191887f6d2d357' 2025-04-29 21:36:01,662 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 1521 2025-04-29 21:36:01,664 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/d06511276dbce4c5_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-04-29 21:36:01,667 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 174 2025-04-29 21:36:01,684 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/d72761e1a334a754_94308059b57b3142e455b38a6eb92015' 2025-04-29 21:36:01,688 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 73305 2025-04-29 21:36:01,691 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8' 2025-04-29 21:36:01,694 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 530 2025-04-29 21:36:01,696 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/89d237dd87600ddb_recoverystore.{2cb2e17d-2506-11f0-99eb-0cead772813f}.dat' 2025-04-29 21:36:01,699 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 5632 2025-04-29 21:36:01,702 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'files/cfd76b293792f5a6_94308059b57b3142e455b38a6eb92015' 2025-04-29 21:36:01,714 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 344 2025-04-29 21:36:02,308 [cuckoo.core.resultserver] DEBUG: Task #6358672: File upload for 'shots/0006.jpg' 2025-04-29 21:36:02,360 [cuckoo.core.resultserver] DEBUG: Task #6358672 uploaded file length: 133467 2025-04-29 21:36:02,371 [cuckoo.core.resultserver] DEBUG: Task #6358672 had connection reset for <Context for LOG> 2025-04-29 21:36:03,598 [cuckoo.core.guest] INFO: win7x6423: analysis completed successfully 2025-04-29 21:36:03,617 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-29 21:36:03,949 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-29 21:36:04,874 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6358672/memory.dmp 2025-04-29 21:36:04,877 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423 2025-04-29 21:38:58,585 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6358672 2025-04-29 21:38:59,051 [cuckoo.core.scheduler] DEBUG: Released database task #6358672 2025-04-29 21:39:09,161 [cuckoo.core.scheduler] INFO: Task #6358672: analysis procedure completed
cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1420 CREDAT:275457 /prefetch:2 |
Avast Core Security (Linux) | HTML:DatingScam-D [Scam] |
WithSecure (Linux) | Malware.HTML/Phish.PDTD |
Avast | HTML:DatingScam-D [Scam] |
Cynet | Malicious (score: 99) |
F-Secure | Malware.HTML/Phish.PDTD |
Detected | |
Avira | HTML/Phish.PDTD |
Varist | JS/Phish.AYV!Eldorado |
Tencent | Html.Win32.Script.506025 |
Fortinet | HTML/DatingScam.D!tr |
AVG | HTML:DatingScam-D [Scam] |