URL |
---|
https://homlaa.com |
This url is very suspicious, with a score of 10.0 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
URL | July 6, 2025, 3:12 p.m. | July 6, 2025, 3:13 p.m. | 66 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-07-06 15:12:13,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpk4d6bl 2025-07-06 15:12:13,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\oqKfPyHxksQczdNpdEBfhhuPP 2025-07-06 15:12:13,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\KuJmHaTgNJxXBZhaVUKdNOOkRaD 2025-07-06 15:12:13,453 [analyzer] DEBUG: Started auxiliary module Curtain 2025-07-06 15:12:13,453 [analyzer] DEBUG: Started auxiliary module DbgView 2025-07-06 15:12:13,953 [analyzer] DEBUG: Started auxiliary module Disguise 2025-07-06 15:12:14,155 [analyzer] DEBUG: Loaded monitor into process with pid 512 2025-07-06 15:12:14,155 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-07-06 15:12:14,155 [analyzer] DEBUG: Started auxiliary module Human 2025-07-06 15:12:14,155 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-07-06 15:12:14,155 [analyzer] DEBUG: Started auxiliary module Reboot 2025-07-06 15:12:14,296 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-07-06 15:12:14,296 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-07-06 15:12:14,312 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-07-06 15:12:14,312 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-07-06 15:12:14,483 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://homlaa.com'] and pid 580 2025-07-06 15:12:14,625 [analyzer] DEBUG: Loaded monitor into process with pid 580 2025-07-06 15:12:16,030 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:580 CREDAT:275457 /prefetch:2! 2025-07-06 15:12:16,092 [analyzer] INFO: Injected into process with pid 1900 and name u'iexplore.exe' 2025-07-06 15:12:16,171 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1900. 2025-07-06 15:12:16,296 [analyzer] INFO: Added new file to list with pid 580 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{D529EA15-5A6A-11F0-8B03-6A4C24D117AF}.dat 2025-07-06 15:12:16,358 [analyzer] INFO: Added new file to list with pid 580 and path C:\Users\Administrator\AppData\Local\Temp\~DFF5D9221A9CB4E6F9.TMP 2025-07-06 15:12:16,358 [analyzer] DEBUG: Loaded monitor into process with pid 1900 2025-07-06 15:12:16,546 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-07-06 15:12:16,562 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-07-06 15:12:16,937 [analyzer] INFO: Added new file to list with pid 580 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D529EA17-5A6A-11F0-8B03-6A4C24D117AF}.dat 2025-07-06 15:12:16,953 [analyzer] INFO: Added new file to list with pid 580 and path C:\Users\Administrator\AppData\Local\Temp\~DFB379DA9ED57582C4.TMP 2025-07-06 15:12:20,046 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3 2025-07-06 15:12:20,062 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3 2025-07-06 15:12:20,078 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab56E2.tmp 2025-07-06 15:12:20,092 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar56E3.tmp 2025-07-06 15:12:20,108 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab5703.tmp 2025-07-06 15:12:20,108 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar5704.tmp 2025-07-06 15:12:20,280 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 2025-07-06 15:12:20,280 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 2025-07-06 15:12:20,296 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab57C1.tmp 2025-07-06 15:12:20,312 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar57D2.tmp 2025-07-06 15:12:20,328 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab57E2.tmp 2025-07-06 15:12:20,328 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar57E3.tmp 2025-07-06 15:12:20,483 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-07-06 15:12:20,483 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-07-06 15:12:20,546 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 2025-07-06 15:12:20,546 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 2025-07-06 15:12:20,578 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab58EE.tmp 2025-07-06 15:12:20,592 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar58EF.tmp 2025-07-06 15:12:21,405 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZWG09X8\6OT0WT1G.htm 2025-07-06 15:12:21,421 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-07-06 15:12:21,421 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-07-06 15:12:21,421 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-07-06 15:12:21,421 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-07-06 15:12:21,421 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-07-06 15:12:21,421 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-07-06 15:12:21,421 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-07-06 15:12:22,562 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\weui[1].css 2025-07-06 15:12:22,592 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1801A0BFF52C676E5F51CA71C5350277 2025-07-06 15:12:22,608 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1801A0BFF52C676E5F51CA71C5350277 2025-07-06 15:12:22,608 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\bootstrap.min[1].css 2025-07-06 15:12:22,625 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\layer[1].js 2025-07-06 15:12:22,640 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab60DF.tmp 2025-07-06 15:12:22,640 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab6100.tmp 2025-07-06 15:12:22,640 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar6101.tmp 2025-07-06 15:12:22,655 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab6102.tmp 2025-07-06 15:12:22,671 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar6103.tmp 2025-07-06 15:12:22,671 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar60F0.tmp 2025-07-06 15:12:22,671 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab6124.tmp 2025-07-06 15:12:22,687 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar6125.tmp 2025-07-06 15:12:22,717 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab6154.tmp 2025-07-06 15:12:22,733 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar6155.tmp 2025-07-06 15:12:22,750 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab6176.tmp 2025-07-06 15:12:22,750 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab6178.tmp 2025-07-06 15:12:22,765 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar6177.tmp 2025-07-06 15:12:22,765 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar6179.tmp 2025-07-06 15:12:22,765 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab6189.tmp 2025-07-06 15:12:22,765 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar618A.tmp 2025-07-06 15:12:22,812 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab61AB.tmp 2025-07-06 15:12:22,812 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab61AC.tmp 2025-07-06 15:12:22,812 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar61AD.tmp 2025-07-06 15:12:22,828 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar61BD.tmp 2025-07-06 15:12:22,842 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\jquery.min[1].js 2025-07-06 15:12:22,842 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Cab61DD.tmp 2025-07-06 15:12:22,858 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Temp\Tar61DE.tmp 2025-07-06 15:12:22,875 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\weui.min[1].js 2025-07-06 15:12:22,875 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\zepto.min[1].js 2025-07-06 15:12:22,921 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDCVLMVQ\swiper-3.4.2.min[1].js 2025-07-06 15:12:22,953 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_23FFFDCAABB8E63694AD1202ED02BF57 2025-07-06 15:12:22,967 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_23FFFDCAABB8E63694AD1202ED02BF57 2025-07-06 15:12:22,983 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDCVLMVQ\common[1].css 2025-07-06 15:12:23,155 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14561BF7422BB6F70A9CB14F5AA8A7DA_9CF321A24FA1B7BFFF66435FA3483EF9 2025-07-06 15:12:23,155 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14561BF7422BB6F70A9CB14F5AA8A7DA_9CF321A24FA1B7BFFF66435FA3483EF9 2025-07-06 15:12:23,265 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZWG09X8\iconfont[1].css 2025-07-06 15:12:23,467 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WYZU3NA0\common[1].js 2025-07-06 15:12:23,467 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WYZU3NA0\style[1].css 2025-07-06 15:12:23,530 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZWG09X8\swiper-3.4.2.min[1].css 2025-07-06 15:12:23,546 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDCVLMVQ\usdt1[1].jpg 2025-07-06 15:12:23,671 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDCVLMVQ\nav6[1].png 2025-07-06 15:12:23,828 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZWG09X8\usdt3[1].jpg 2025-07-06 15:12:23,983 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZWG09X8\202311141[1].png 2025-07-06 15:12:24,125 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZWG09X8\layer[1].css 2025-07-06 15:12:24,155 [analyzer] INFO: Added new file to list with pid 1900 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZWG09X8\usdt2[1].jpg 2025-07-06 14:13:07,082 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-07-06 14:13:07,207 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 580. 2025-07-06 14:13:07,286 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1900. 2025-07-06 14:13:07,551 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-07-06 14:13:07,551 [lib.api.process] INFO: Successfully terminated process with pid 580. 2025-07-06 14:13:07,551 [lib.api.process] INFO: Successfully terminated process with pid 1900. 2025-07-06 14:13:07,551 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar58ef.tmp' does not exist, skip. 2025-07-06 14:13:07,551 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab61ab.tmp' does not exist, skip. 2025-07-06 14:13:07,551 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6189.tmp' does not exist, skip. 2025-07-06 14:13:07,582 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab61dd.tmp' does not exist, skip. 2025-07-06 14:13:07,598 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dff5d9221a9cb4e6f9.tmp' does not exist, skip. 2025-07-06 14:13:07,598 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar57e3.tmp' does not exist, skip. 2025-07-06 14:13:07,614 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6176.tmp' does not exist, skip. 2025-07-06 14:13:11,066 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar57d2.tmp' does not exist, skip. 2025-07-06 14:13:11,082 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6100.tmp' does not exist, skip. 2025-07-06 14:13:11,082 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab61ac.tmp' does not exist, skip. 2025-07-06 14:13:11,098 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dfb379da9ed57582c4.tmp' does not exist, skip. 2025-07-06 14:13:11,098 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar56e3.tmp' does not exist, skip. 2025-07-06 14:13:11,098 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6124.tmp' does not exist, skip. 2025-07-06 14:13:11,114 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6103.tmp' does not exist, skip. 2025-07-06 14:13:11,114 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6154.tmp' does not exist, skip. 2025-07-06 14:13:11,130 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6155.tmp' does not exist, skip. 2025-07-06 14:13:11,130 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5703.tmp' does not exist, skip. 2025-07-06 14:13:11,144 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6101.tmp' does not exist, skip. 2025-07-06 14:13:11,161 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar61de.tmp' does not exist, skip. 2025-07-06 14:13:11,176 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab58ee.tmp' does not exist, skip. 2025-07-06 14:13:11,176 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6177.tmp' does not exist, skip. 2025-07-06 14:13:11,176 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab60df.tmp' does not exist, skip. 2025-07-06 14:13:11,191 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6102.tmp' does not exist, skip. 2025-07-06 14:13:11,191 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar60f0.tmp' does not exist, skip. 2025-07-06 14:13:11,191 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab57e2.tmp' does not exist, skip. 2025-07-06 14:13:11,191 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar61bd.tmp' does not exist, skip. 2025-07-06 14:13:11,207 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5704.tmp' does not exist, skip. 2025-07-06 14:13:11,207 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab57c1.tmp' does not exist, skip. 2025-07-06 14:13:11,207 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar618a.tmp' does not exist, skip. 2025-07-06 14:13:11,207 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar61ad.tmp' does not exist, skip. 2025-07-06 14:13:11,223 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab56e2.tmp' does not exist, skip. 2025-07-06 14:13:11,223 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6125.tmp' does not exist, skip. 2025-07-06 14:13:11,223 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6179.tmp' does not exist, skip. 2025-07-06 14:13:11,223 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6178.tmp' does not exist, skip. 2025-07-06 14:13:11,223 [analyzer] INFO: Analysis completed.
2025-07-06 15:12:15,481 [cuckoo.core.scheduler] INFO: Task #6659022: acquired machine win7x6422 (label=win7x6422) 2025-07-06 15:12:15,481 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.222 for task #6659022 2025-07-06 15:12:15,873 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1083651 (interface=vboxnet0, host=192.168.168.222) 2025-07-06 15:12:15,910 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6422 2025-07-06 15:12:16,563 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6422 to vmcloak 2025-07-06 15:12:29,137 [cuckoo.core.guest] INFO: Starting analysis #6659022 on guest (id=win7x6422, ip=192.168.168.222) 2025-07-06 15:12:30,144 [cuckoo.core.guest] DEBUG: win7x6422: not ready yet 2025-07-06 15:12:35,171 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6422, ip=192.168.168.222) 2025-07-06 15:12:35,250 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6422, ip=192.168.168.222, monitor=latest, size=6660546) 2025-07-06 15:12:36,557 [cuckoo.core.resultserver] DEBUG: Task #6659022: live log analysis.log initialized. 2025-07-06 15:12:37,665 [cuckoo.core.resultserver] DEBUG: Task #6659022 is sending a BSON stream 2025-07-06 15:12:38,133 [cuckoo.core.resultserver] DEBUG: Task #6659022 is sending a BSON stream 2025-07-06 15:12:38,977 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0001.jpg' 2025-07-06 15:12:38,996 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 133435 2025-07-06 15:12:39,866 [cuckoo.core.resultserver] DEBUG: Task #6659022 is sending a BSON stream 2025-07-06 15:12:41,090 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0002.jpg' 2025-07-06 15:12:41,093 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 24470 2025-07-06 15:12:42,177 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0003.jpg' 2025-07-06 15:12:42,180 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 28956 2025-07-06 15:12:49,441 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0004.jpg' 2025-07-06 15:12:49,449 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 61075 2025-07-06 15:12:51,072 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6659022 still processing 2025-07-06 15:12:51,583 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0005.jpg' 2025-07-06 15:12:51,595 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 100164 2025-07-06 15:12:53,729 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0006.jpg' 2025-07-06 15:12:53,746 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 86182 2025-07-06 15:12:54,833 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0007.jpg' 2025-07-06 15:12:54,968 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 72995 2025-07-06 15:12:57,092 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0008.jpg' 2025-07-06 15:12:57,106 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 87193 2025-07-06 15:13:00,247 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0009.jpg' 2025-07-06 15:13:00,252 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 61232 2025-07-06 15:13:02,373 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0010.jpg' 2025-07-06 15:13:02,382 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 80041 2025-07-06 15:13:03,474 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0011.jpg' 2025-07-06 15:13:03,481 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 85803 2025-07-06 15:13:05,606 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0012.jpg' 2025-07-06 15:13:05,615 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 72025 2025-07-06 15:13:06,158 [cuckoo.core.guest] DEBUG: win7x6422: analysis #6659022 still processing 2025-07-06 15:13:07,424 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'curtain/1751803987.41.curtain.log' 2025-07-06 15:13:11,001 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 36 2025-07-06 15:13:11,004 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'sysmon/1751803987.55.sysmon.xml' 2025-07-06 15:13:11,008 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 373580 2025-07-06 15:13:11,013 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/5f97c557476ec985_14561bf7422bb6f70a9cb14f5aa8a7da_9cf321a24fa1b7bfff66435fa3483ef9' 2025-07-06 15:13:11,015 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 412 2025-07-06 15:13:11,016 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/47b0e7129add982c_swiper-3.4.2.min[1].css' 2025-07-06 15:13:11,018 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 17759 2025-07-06 15:13:11,019 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3' 2025-07-06 15:13:11,020 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 889 2025-07-06 15:13:11,022 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/bfbd4401c20017b1_14561bf7422bb6f70a9cb14f5aa8a7da_9cf321a24fa1b7bfff66435fa3483ef9' 2025-07-06 15:13:11,023 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 727 2025-07-06 15:13:11,024 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/acc5ff4598c9f00a_14232b434cf29d4c4fb335a86d7fffe3' 2025-07-06 15:13:11,038 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 170 2025-07-06 15:13:11,040 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/82c310a2ec15e202_usdt3[1].jpg' 2025-07-06 15:13:11,044 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'shots/0013.jpg' 2025-07-06 15:13:11,050 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 1075956 2025-07-06 15:13:11,071 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 133662 2025-07-06 15:13:11,073 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/d1ef34a99014b14f_b46811c17859ffb409cf0e904a4aa8f8' 2025-07-06 15:13:11,076 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 170 2025-07-06 15:13:11,081 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/09f5d0abb59ff075_1801a0bff52c676e5f51ca71c5350277' 2025-07-06 15:13:11,085 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 252 2025-07-06 15:13:11,087 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/ce9f8f9bb4e5eef2_common[1].js' 2025-07-06 15:13:11,090 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 3807 2025-07-06 15:13:11,096 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/6d92dfc1700fd38c_bootstrap.min[1].css' 2025-07-06 15:13:11,099 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 121457 2025-07-06 15:13:11,104 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/fb6a7c3edcd7b97f_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-07-06 15:13:11,106 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 1739 2025-07-06 15:13:11,111 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/1ce6649d82d2db0f_layer[1].js' 2025-07-06 15:13:11,113 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 22116 2025-07-06 15:13:11,125 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/045622e58d664331_weui[1].css' 2025-07-06 15:13:11,133 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 807589 2025-07-06 15:13:11,137 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/29fd5016efe08849_zepto.min[1].js' 2025-07-06 15:13:11,199 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 29237 2025-07-06 15:13:11,201 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/eacab6919dee6aa4_202311141[1].png' 2025-07-06 15:13:11,203 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 41804 2025-07-06 15:13:11,205 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/624a077a5d6f5777_usdt1[1].jpg' 2025-07-06 15:13:11,207 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 59516 2025-07-06 15:13:11,208 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/4a10219bee747aad_swiper-3.4.2.min[1].js' 2025-07-06 15:13:11,210 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/e310e2ee66d791da_style[1].css' 2025-07-06 15:13:11,212 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 2641 2025-07-06 15:13:11,213 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/c12f6098e641aaca_jquery.min[1].js' 2025-07-06 15:13:11,215 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/882dd0c290d95072_b398b80134f72209547439db21ab308d_23fffdcaabb8e63694ad1202ed02bf57' 2025-07-06 15:13:11,217 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 471 2025-07-06 15:13:11,218 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/2e765eee6d6db0ab_recoverystore.{d529ea15-5a6a-11f0-8b03-6a4c24d117af}.dat' 2025-07-06 15:13:11,220 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 5632 2025-07-06 15:13:11,222 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/e5109363ade51573_{d529ea17-5a6a-11f0-8b03-6a4c24d117af}.dat' 2025-07-06 15:13:11,223 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 5120 2025-07-06 15:13:11,225 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/352d1d21f87dd1eb_nav6[1].png' 2025-07-06 15:13:11,226 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 4551 2025-07-06 15:13:11,227 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/ad818d92030a0ffa_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-07-06 15:13:11,229 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 174 2025-07-06 15:13:11,231 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/e292ce67ecbecc4f_weui.min[1].js' 2025-07-06 15:13:11,233 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 36806 2025-07-06 15:13:11,234 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/4c847e0c28733ed3_94308059b57b3142e455b38a6eb92015' 2025-07-06 15:13:11,237 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8' 2025-07-06 15:13:11,239 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 530 2025-07-06 15:13:11,240 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 73513 2025-07-06 15:13:11,241 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 92629 2025-07-06 15:13:11,243 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 96419 2025-07-06 15:13:11,247 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/7f1ca0c14288b531_b398b80134f72209547439db21ab308d_23fffdcaabb8e63694ad1202ed02bf57' 2025-07-06 15:13:11,248 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 400 2025-07-06 15:13:11,249 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/9fa256777e1db1a1_iconfont[1].css' 2025-07-06 15:13:11,250 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 25550 2025-07-06 15:13:11,251 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/ec87c3ba9266d0c3_94308059b57b3142e455b38a6eb92015' 2025-07-06 15:13:11,252 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 344 2025-07-06 15:13:11,253 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/4348a0e9444c78cb_1801a0bff52c676e5f51ca71c5350277' 2025-07-06 15:13:11,254 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 947 2025-07-06 15:13:11,255 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/e3144d018a6a24f7_layer[1].css' 2025-07-06 15:13:11,257 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 14367 2025-07-06 15:13:11,258 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/2c2c0c079430a4c3_6ot0wt1g.htm' 2025-07-06 15:13:11,259 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 27090 2025-07-06 15:13:11,260 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/0f400e84f7bd330c_usdt2[1].jpg' 2025-07-06 15:13:11,261 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 19371 2025-07-06 15:13:11,262 [cuckoo.core.resultserver] DEBUG: Task #6659022: File upload for 'files/7d020cfe0eeeaea8_common[1].css' 2025-07-06 15:13:11,264 [cuckoo.core.resultserver] DEBUG: Task #6659022 uploaded file length: 1173 2025-07-06 15:13:11,264 [cuckoo.core.resultserver] DEBUG: Task #6659022 had connection reset for <Context for LOG> 2025-07-06 15:13:12,192 [cuckoo.core.guest] INFO: win7x6422: analysis completed successfully 2025-07-06 15:13:12,205 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-07-06 15:13:12,237 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-07-06 15:13:13,510 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6422 to path /srv/cuckoo/cwd/storage/analyses/6659022/memory.dmp 2025-07-06 15:13:13,511 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6422 2025-07-06 15:13:21,399 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.222 for task #6659022 2025-07-06 15:13:21,751 [cuckoo.core.scheduler] DEBUG: Released database task #6659022 2025-07-06 15:13:21,772 [cuckoo.core.scheduler] INFO: Task #6659022: analysis procedure completed
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\zepto.min[1].js |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WYZU3NA0\common[1].js |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDCVLMVQ\swiper-3.4.2.min[1].js |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\jquery.min[1].js |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\weui.min[1].js |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PZWRF9A3\layer[1].js |
cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:580 CREDAT:275457 /prefetch:2 |
alphaMountain_ai | phishing site |
Fortinet | phishing site |
Seclookup | malicious site |
CRDF | malicious site |
CyRadar | malicious site |
Webroot | malicious site |
SOCRadar | phishing site |
Forcepoint ThreatSeeker | phishing site |
Gridinsoft | phishing site |