Size | 291.1KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (3137) |
MD5 | 4c2c3df11d01d59c2aaf897367105565 |
SHA1 | 57f03f6197ea5ec765eb603e01ee3395efb9590c |
SHA256 | 07c9c4387d79228caa7936319c36d9d91dc56b69f08dad2bf018905fa5425a84 |
SHA512 |
619294d700cc750511a25a9ef8d35acd6c4ee6ae53eceda79d880ce299a90e672fef3d77af8b526294760cf24fed73e9f9820334d3d47c51483e677ebb191c06
|
CRC32 | 9BC21F0C |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | June 21, 2025, 12:22 p.m. | June 21, 2025, 12:29 p.m. | 394 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-06-20 15:40:39,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp1xmcit 2025-06-20 15:40:39,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\MJgAOLOAETeKZPJdcZqd 2025-06-20 15:40:39,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\LrtrqFZAgrsvZSYQiIBYCYgIGfFWJuVH 2025-06-20 15:40:39,280 [analyzer] DEBUG: Started auxiliary module Curtain 2025-06-20 15:40:39,280 [analyzer] DEBUG: Started auxiliary module DbgView 2025-06-20 15:40:39,765 [analyzer] DEBUG: Started auxiliary module Disguise 2025-06-20 15:40:39,967 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-06-20 15:40:39,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-06-20 15:40:39,967 [analyzer] DEBUG: Started auxiliary module Human 2025-06-20 15:40:39,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-06-20 15:40:39,967 [analyzer] DEBUG: Started auxiliary module Reboot 2025-06-20 15:40:40,108 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-06-20 15:40:40,108 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-06-20 15:40:40,108 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-06-20 15:40:40,108 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-06-20 15:40:40,108 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-06-20 15:40:40,171 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\07c9c4387d79228caa7936319c36d9d91dc56b69f08dad2bf018905fa5425a84.js'] and pid 2124 2025-06-20 15:40:40,405 [analyzer] DEBUG: Loaded monitor into process with pid 2124 2025-06-20 15:40:40,765 [analyzer] INFO: io=NULL 2025-06-20 15:40:40,765 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-06-20 15:40:40,765 [analyzer] INFO: io=NULL 2025-06-20 15:40:40,765 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-06-20 15:40:40,765 [analyzer] INFO: io=NULL 2025-06-20 15:40:40,765 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-06-20 15:40:40,812 [analyzer] INFO: io=NULL 2025-06-20 15:40:40,812 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-06-20 15:40:40,828 [analyzer] INFO: io=NULL 2025-06-20 15:40:40,828 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-06-20 15:40:40,828 [analyzer] INFO: io=NULL 2025-06-20 15:40:40,828 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-06-20 15:41:09,233 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-06-20 15:41:10,030 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-06-20 15:41:10,030 [lib.api.process] INFO: Successfully terminated process with pid 2124. 2025-06-20 15:41:10,030 [analyzer] INFO: Analysis completed.
2025-06-21 12:22:42,957 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:43,975 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:45,005 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:46,031 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:47,051 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:48,070 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:49,416 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:50,477 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:51,525 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:52,564 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:53,614 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:54,651 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:55,701 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:56,761 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:57,806 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:58,852 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:22:59,892 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:00,948 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:02,335 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:03,399 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:04,475 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:06,268 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:07,511 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:08,532 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:09,553 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:10,574 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:11,595 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:12,747 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:14,481 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:15,656 [cuckoo.core.scheduler] DEBUG: Task #6570680: no machine available yet 2025-06-21 12:23:16,910 [cuckoo.core.scheduler] INFO: Task #6570680: acquired machine win7x6414 (label=win7x6414) 2025-06-21 12:23:16,913 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.214 for task #6570680 2025-06-21 12:23:17,664 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 267290 (interface=vboxnet0, host=192.168.168.214) 2025-06-21 12:23:17,743 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6414 2025-06-21 12:23:19,276 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6414 to vmcloak 2025-06-21 12:25:01,042 [cuckoo.core.guest] INFO: Starting analysis #6570680 on guest (id=win7x6414, ip=192.168.168.214) 2025-06-21 12:25:02,282 [cuckoo.core.guest] DEBUG: win7x6414: not ready yet 2025-06-21 12:25:07,336 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6414, ip=192.168.168.214) 2025-06-21 12:25:07,499 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6414, ip=192.168.168.214, monitor=latest, size=6660546) 2025-06-21 12:25:09,147 [cuckoo.core.resultserver] DEBUG: Task #6570680: live log analysis.log initialized. 2025-06-21 12:25:10,060 [cuckoo.core.resultserver] DEBUG: Task #6570680 is sending a BSON stream 2025-06-21 12:25:10,403 [cuckoo.core.resultserver] DEBUG: Task #6570680 is sending a BSON stream 2025-06-21 12:25:11,379 [cuckoo.core.resultserver] DEBUG: Task #6570680: File upload for 'shots/0001.jpg' 2025-06-21 12:25:11,392 [cuckoo.core.resultserver] DEBUG: Task #6570680 uploaded file length: 133465 2025-06-21 12:25:12,525 [cuckoo.core.resultserver] DEBUG: Task #6570680: File upload for 'shots/0002.jpg' 2025-06-21 12:25:12,545 [cuckoo.core.resultserver] DEBUG: Task #6570680 uploaded file length: 137092 2025-06-21 12:25:23,751 [cuckoo.core.guest] DEBUG: win7x6414: analysis #6570680 still processing 2025-06-21 12:25:39,571 [cuckoo.core.guest] DEBUG: win7x6414: analysis #6570680 still processing 2025-06-21 12:25:39,686 [cuckoo.core.resultserver] DEBUG: Task #6570680: File upload for 'curtain/1750426869.52.curtain.log' 2025-06-21 12:25:39,707 [cuckoo.core.resultserver] DEBUG: Task #6570680 uploaded file length: 36 2025-06-21 12:25:40,153 [cuckoo.core.resultserver] DEBUG: Task #6570680: File upload for 'sysmon/1750426869.69.sysmon.xml' 2025-06-21 12:25:40,213 [cuckoo.core.resultserver] DEBUG: Task #6570680 uploaded file length: 1115038 2025-06-21 12:25:40,621 [cuckoo.core.resultserver] DEBUG: Task #6570680: File upload for 'shots/0003.jpg' 2025-06-21 12:25:40,647 [cuckoo.core.resultserver] DEBUG: Task #6570680 uploaded file length: 133462 2025-06-21 12:25:40,662 [cuckoo.core.resultserver] DEBUG: Task #6570680 had connection reset for <Context for LOG> 2025-06-21 12:25:42,872 [cuckoo.core.guest] INFO: win7x6414: analysis completed successfully 2025-06-21 12:25:42,962 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-06-21 12:25:43,000 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-06-21 12:25:44,657 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6414 to path /srv/cuckoo/cwd/storage/analyses/6570680/memory.dmp 2025-06-21 12:25:44,658 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6414 2025-06-21 12:29:06,261 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.214 for task #6570680 2025-06-21 12:29:07,002 [cuckoo.core.scheduler] DEBUG: Released database task #6570680 2025-06-21 12:29:07,023 [cuckoo.core.scheduler] INFO: Task #6570680: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Avast Core Security (Linux) | HTML:Phishing-EAF [Phish] |
ESET Security (Windows) | HTML/ScrInject.B trojan |
DrWeb Antivirus (Linux) | JS.Inject.178 |