Size | 12.1KB |
---|---|
Type | HTML document, ASCII text, with very long lines (8851), with CRLF, LF line terminators |
MD5 | bebf5858dbdef8fe79cbd27cac5812c5 |
SHA1 | ce3130cf9080f6624b8b55f3b78674710246ae9d |
SHA256 | cd8ea57aebb0ef07224c6cab1124c8c99e9ff70225f9512ded37fba7084c7984 |
SHA512 |
d4f9f6c1b43c7e280e24d6b27c3a74fc3885afc838c05860f029b4b0a621a91191e57799b1d3388dc4b983c15103fe404c7f4da28f8345e880b4e4170c29fef4
|
CRC32 | 4A306B4E |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 5.9 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 19, 2025, 3:29 a.m. | May 19, 2025, 3:36 a.m. | 413 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-18 15:01:48,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt 2025-05-18 15:01:48,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\OkkXPYBHxvZRGzvwBdLFerPFmwKmeH 2025-05-18 15:01:48,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\YaSMUpsgythowtzsTPTWARlHNgXqUKa 2025-05-18 15:01:48,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-18 15:01:48,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-18 15:01:48,828 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-18 15:01:49,030 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-05-18 15:01:49,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-18 15:01:49,030 [analyzer] DEBUG: Started auxiliary module Human 2025-05-18 15:01:49,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-18 15:01:49,030 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-18 15:01:49,078 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-18 15:01:49,078 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-18 15:01:49,078 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-18 15:01:49,078 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-18 15:01:49,078 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-05-18 15:01:49,155 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\cd8ea57aebb0ef07224c6cab1124c8c99e9ff70225f9512ded37fba7084c7984.js'] and pid 708 2025-05-18 15:01:49,500 [analyzer] DEBUG: Loaded monitor into process with pid 708 2025-05-18 15:01:49,937 [analyzer] INFO: io=NULL 2025-05-18 15:01:49,937 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-05-18 15:01:49,937 [analyzer] INFO: io=NULL 2025-05-18 15:01:49,937 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-05-18 15:01:49,937 [analyzer] INFO: io=NULL 2025-05-18 15:01:49,937 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-05-18 15:01:49,967 [analyzer] INFO: io=NULL 2025-05-18 15:01:49,967 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-05-18 15:01:49,967 [analyzer] INFO: io=NULL 2025-05-18 15:01:49,967 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-05-18 15:01:49,983 [analyzer] INFO: io=NULL 2025-05-18 15:01:49,983 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-05-19 02:33:25,532 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-19 02:33:25,907 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-19 02:33:25,907 [lib.api.process] INFO: Successfully terminated process with pid 708. 2025-05-19 02:33:25,907 [analyzer] INFO: Analysis completed.
2025-05-19 03:29:47,409 [cuckoo.core.scheduler] INFO: Task #6487634: acquired machine win7x6423 (label=win7x6423) 2025-05-19 03:29:47,409 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6487634 2025-05-19 03:29:47,835 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2483481 (interface=vboxnet0, host=192.168.168.223) 2025-05-19 03:29:47,871 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423 2025-05-19 03:29:48,508 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak 2025-05-19 03:32:47,872 [cuckoo.core.guest] INFO: Starting analysis #6487634 on guest (id=win7x6423, ip=192.168.168.223) 2025-05-19 03:32:48,877 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet 2025-05-19 03:32:53,900 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223) 2025-05-19 03:32:53,974 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546) 2025-05-19 03:32:55,314 [cuckoo.core.resultserver] DEBUG: Task #6487634: live log analysis.log initialized. 2025-05-19 03:32:56,300 [cuckoo.core.resultserver] DEBUG: Task #6487634 is sending a BSON stream 2025-05-19 03:32:56,566 [cuckoo.core.resultserver] DEBUG: Task #6487634 is sending a BSON stream 2025-05-19 03:32:57,546 [cuckoo.core.resultserver] DEBUG: Task #6487634: File upload for 'shots/0001.jpg' 2025-05-19 03:32:57,572 [cuckoo.core.resultserver] DEBUG: Task #6487634 uploaded file length: 133470 2025-05-19 03:32:58,676 [cuckoo.core.resultserver] DEBUG: Task #6487634: File upload for 'shots/0002.jpg' 2025-05-19 03:32:58,687 [cuckoo.core.resultserver] DEBUG: Task #6487634 uploaded file length: 137081 2025-05-19 03:33:10,035 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6487634 still processing 2025-05-19 03:33:25,412 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6487634 still processing 2025-05-19 03:33:25,689 [cuckoo.core.resultserver] DEBUG: Task #6487634: File upload for 'curtain/1747614805.67.curtain.log' 2025-05-19 03:33:25,691 [cuckoo.core.resultserver] DEBUG: Task #6487634 uploaded file length: 36 2025-05-19 03:33:25,885 [cuckoo.core.resultserver] DEBUG: Task #6487634: File upload for 'sysmon/1747614805.88.sysmon.xml' 2025-05-19 03:33:25,913 [cuckoo.core.resultserver] DEBUG: Task #6487634 uploaded file length: 1561858 2025-05-19 03:33:26,505 [cuckoo.core.resultserver] DEBUG: Task #6487634: File upload for 'shots/0003.jpg' 2025-05-19 03:33:26,529 [cuckoo.core.resultserver] DEBUG: Task #6487634 uploaded file length: 133474 2025-05-19 03:33:26,542 [cuckoo.core.resultserver] DEBUG: Task #6487634 had connection reset for <Context for LOG> 2025-05-19 03:33:28,429 [cuckoo.core.guest] INFO: win7x6423: analysis completed successfully 2025-05-19 03:33:28,440 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-19 03:33:28,630 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-19 03:33:29,586 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6487634/memory.dmp 2025-05-19 03:33:29,588 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423 2025-05-19 03:36:40,259 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6487634 2025-05-19 03:36:40,975 [cuckoo.core.scheduler] DEBUG: Released database task #6487634 2025-05-19 03:36:41,029 [cuckoo.core.scheduler] INFO: Task #6487634: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Avast Core Security (Linux) | Script:SNH-gen [Trj] |
Avast | Script:SNH-gen [Trj] |
NANO-Antivirus | Trojan.Script.Downloader.kslcdq |
AVG | Script:SNH-gen [Trj] |