Size | 38.6KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (8847), with CRLF, LF line terminators |
MD5 | 2566a82f0aa1b615ba6fcea3dbd174b7 |
SHA1 | f5f776e071bdec503571035bd932412e91ffa3da |
SHA256 | a36670a2b9b9e2353363ca010369d695e1932d9212eb5ec23695fb9508addbb6 |
SHA512 |
684e334e9e90c3286ada4c99424ec024f8811145da1ad327497c12775640f7b54c8c73dbc8dcbbe9903e11cc344c8e0339b372dfa96934e0cad8c210ecdbf92c
|
CRC32 | 3044A494 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Aug. 22, 2025, 10:30 p.m. | Aug. 22, 2025, 10:36 p.m. | 398 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-16 04:47:44,015 [analyzer] DEBUG: Starting analyzer from: C:\tmptpreht 2025-08-16 04:47:44,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\GYxLdKUTCJOZQPsKz 2025-08-16 04:47:44,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\phLvrNisRzqgTzssAHcsMeCHzIZyC 2025-08-16 04:47:44,342 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-16 04:47:44,342 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-16 04:47:44,921 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-16 04:47:45,125 [analyzer] DEBUG: Loaded monitor into process with pid 500 2025-08-16 04:47:45,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-16 04:47:45,125 [analyzer] DEBUG: Started auxiliary module Human 2025-08-16 04:47:45,125 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-16 04:47:45,125 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-16 04:47:45,187 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-16 04:47:45,187 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-16 04:47:45,187 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-16 04:47:45,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-16 04:47:45,203 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-08-16 04:47:45,296 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\a36670a2b9b9e2353363ca010369d695e1932d9212eb5ec23695fb9508addbb6.js'] and pid 400 2025-08-16 04:47:45,530 [analyzer] DEBUG: Loaded monitor into process with pid 400 2025-08-16 04:47:45,890 [analyzer] INFO: io=NULL 2025-08-16 04:47:45,890 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-08-16 04:47:45,890 [analyzer] INFO: io=NULL 2025-08-16 04:47:45,890 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-08-16 04:47:45,890 [analyzer] INFO: io=NULL 2025-08-16 04:47:45,890 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-08-16 04:47:45,937 [analyzer] INFO: io=NULL 2025-08-16 04:47:45,937 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-08-16 04:47:45,937 [analyzer] INFO: io=NULL 2025-08-16 04:47:45,937 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-08-16 04:47:45,937 [analyzer] INFO: io=NULL 2025-08-16 04:47:45,937 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-08-16 04:48:14,312 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-08-16 04:48:14,842 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-16 04:48:14,842 [lib.api.process] INFO: Successfully terminated process with pid 400. 2025-08-16 04:48:14,842 [analyzer] INFO: Analysis completed.
2025-08-22 22:30:06,185 [cuckoo.core.scheduler] INFO: Task #6873658: acquired machine win7x641 (label=win7x641) 2025-08-22 22:30:06,186 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.201 for task #6873658 2025-08-22 22:30:06,615 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2055418 (interface=vboxnet0, host=192.168.168.201) 2025-08-22 22:30:06,653 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x641 2025-08-22 22:30:07,531 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x641 to vmcloak 2025-08-22 22:33:11,614 [cuckoo.core.guest] INFO: Starting analysis #6873658 on guest (id=win7x641, ip=192.168.168.201) 2025-08-22 22:33:12,622 [cuckoo.core.guest] DEBUG: win7x641: not ready yet 2025-08-22 22:33:17,650 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x641, ip=192.168.168.201) 2025-08-22 22:33:17,766 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x641, ip=192.168.168.201, monitor=latest, size=6660546) 2025-08-22 22:33:19,180 [cuckoo.core.resultserver] DEBUG: Task #6873658: live log analysis.log initialized. 2025-08-22 22:33:20,303 [cuckoo.core.resultserver] DEBUG: Task #6873658 is sending a BSON stream 2025-08-22 22:33:20,690 [cuckoo.core.resultserver] DEBUG: Task #6873658 is sending a BSON stream 2025-08-22 22:33:21,542 [cuckoo.core.resultserver] DEBUG: Task #6873658: File upload for 'shots/0001.jpg' 2025-08-22 22:33:21,558 [cuckoo.core.resultserver] DEBUG: Task #6873658 uploaded file length: 133473 2025-08-22 22:33:22,679 [cuckoo.core.resultserver] DEBUG: Task #6873658: File upload for 'shots/0002.jpg' 2025-08-22 22:33:22,697 [cuckoo.core.resultserver] DEBUG: Task #6873658 uploaded file length: 137351 2025-08-22 22:33:34,152 [cuckoo.core.guest] DEBUG: win7x641: analysis #6873658 still processing 2025-08-22 22:33:49,276 [cuckoo.core.guest] DEBUG: win7x641: analysis #6873658 still processing 2025-08-22 22:33:49,747 [cuckoo.core.resultserver] DEBUG: Task #6873658: File upload for 'curtain/1755312494.55.curtain.log' 2025-08-22 22:33:49,750 [cuckoo.core.resultserver] DEBUG: Task #6873658 uploaded file length: 36 2025-08-22 22:33:49,979 [cuckoo.core.resultserver] DEBUG: Task #6873658: File upload for 'sysmon/1755312494.78.sysmon.xml' 2025-08-22 22:33:50,031 [cuckoo.core.resultserver] DEBUG: Task #6873658 uploaded file length: 1823682 2025-08-22 22:33:50,578 [cuckoo.core.resultserver] DEBUG: Task #6873658: File upload for 'shots/0003.jpg' 2025-08-22 22:33:50,594 [cuckoo.core.resultserver] DEBUG: Task #6873658 uploaded file length: 133480 2025-08-22 22:33:50,614 [cuckoo.core.resultserver] DEBUG: Task #6873658 had connection reset for <Context for LOG> 2025-08-22 22:33:52,292 [cuckoo.core.guest] INFO: win7x641: analysis completed successfully 2025-08-22 22:33:52,304 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-22 22:33:52,334 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-22 22:33:53,383 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x641 to path /srv/cuckoo/cwd/storage/analyses/6873658/memory.dmp 2025-08-22 22:33:53,385 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x641 2025-08-22 22:36:43,672 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.201 for task #6873658 2025-08-22 22:36:44,797 [cuckoo.core.scheduler] DEBUG: Released database task #6873658 2025-08-22 22:36:44,830 [cuckoo.core.scheduler] INFO: Task #6873658: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Avast Core Security (Linux) | HTML:Malware-gen |
DrWeb Antivirus (Linux) | Trojan.Siggen31.48459 |
Avast | HTML:Malware-gen |
NANO-Antivirus | Trojan.Script.Downloader.kslcdq |
DrWeb | Trojan.Siggen31.48459 |
Fortinet | JS/Agent.53074!tr |
AVG | HTML:Malware-gen |