Size | 2.1KB |
---|---|
Type | compiled Java class data, version 51.0 (Java 1.7) |
MD5 | 8afb7623f3634d2ccececb610b7c0df7 |
SHA1 | 0285ed7c3143f756483cfc6eb0e815b8981a7e3e |
SHA256 | b82f3f5518ea1088e7b0ea6981b153f335aab713ee3e1de2afe4544cacddaa0e |
SHA512 |
64beb80851bdd6f964d99595ac0b643603a53e3e3fcd738c27df5de1537593f991ffd1493c5e8cf40d6fae83aac9eb56b043805b11078cefff97fe785d7152eb
|
CRC32 | DA25869C |
ssdeep | None |
Yara | None matched |
This archive shows some signs of potential malicious behavior.
The score of this archive is 1.1 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
ARCHIVE | Sept. 3, 2025, 12:24 p.m. | Sept. 3, 2025, 12:25 p.m. | 68 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-09-03 12:24:04,046 [analyzer] DEBUG: Starting analyzer from: C:\tmpblqbwr 2025-09-03 12:24:04,078 [analyzer] DEBUG: Pipe server name: \??\PIPE\BBgjlrSWGyDBepwtsaPgQSmwrpTpTrD 2025-09-03 12:24:04,078 [analyzer] DEBUG: Log pipe server name: \??\PIPE\pubeIvpNwVSwOoEmxWQWxqTWmklNUqn 2025-09-03 12:24:04,328 [analyzer] DEBUG: Started auxiliary module Curtain 2025-09-03 12:24:04,328 [analyzer] DEBUG: Started auxiliary module DbgView 2025-09-03 12:24:04,780 [analyzer] DEBUG: Started auxiliary module Disguise 2025-09-03 12:24:04,983 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-09-03 12:24:04,983 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-09-03 12:24:04,983 [analyzer] DEBUG: Started auxiliary module Human 2025-09-03 12:24:04,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-09-03 12:24:04,983 [analyzer] DEBUG: Started auxiliary module Reboot 2025-09-03 12:24:05,092 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-09-03 12:24:05,092 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-09-03 12:24:05,092 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-09-03 12:24:05,092 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-09-03 12:24:05,203 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\com/mxgraph/reader/package.html'] and pid 1952 2025-09-03 12:24:05,358 [analyzer] DEBUG: Loaded monitor into process with pid 1952 2025-09-03 12:24:07,092 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1952 CREDAT:275457 /prefetch:2! 2025-09-03 12:24:07,155 [analyzer] INFO: Injected into process with pid 1276 and name u'iexplore.exe' 2025-09-03 12:24:07,250 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1276. 2025-09-03 12:24:07,375 [analyzer] INFO: Added new file to list with pid 1952 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{1DE22C4F-88B0-11F0-A5CD-D8386987CDBA}.dat 2025-09-03 12:24:07,421 [analyzer] INFO: Added new file to list with pid 1952 and path C:\Users\Administrator\AppData\Local\Temp\~DFA121F98502C92DF2.TMP 2025-09-03 12:24:07,453 [analyzer] DEBUG: Loaded monitor into process with pid 1276 2025-09-03 12:24:07,640 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-03 12:24:07,640 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-03 12:24:07,640 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-03 12:24:07,655 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-03 12:24:07,671 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-03 12:24:07,890 [analyzer] INFO: Added new file to list with pid 1952 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1DE22C51-88B0-11F0-A5CD-D8386987CDBA}.dat 2025-09-03 12:24:07,905 [analyzer] INFO: Added new file to list with pid 1952 and path C:\Users\Administrator\AppData\Local\Temp\~DFE78F461C371630BA.TMP 2025-09-03 12:24:07,937 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-03 12:24:07,937 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-03 12:24:07,937 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-03 12:24:07,937 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-03 12:24:07,937 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-03 12:24:07,937 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-03 12:24:07,937 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-03 11:24:59,404 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-09-03 11:24:59,717 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1952. 2025-09-03 11:24:59,888 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1276. 2025-09-03 11:25:00,201 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-09-03 11:25:00,201 [lib.api.process] INFO: Successfully terminated process with pid 1952. 2025-09-03 11:25:00,201 [lib.api.process] INFO: Successfully terminated process with pid 1276. 2025-09-03 11:25:00,201 [analyzer] INFO: Error dumping file from path "c:\users\administrator\appdata\local\temp\~dfa121f98502c92df2.tmp": [Errno 13] Permission denied: u'c:\\users\\administrator\\appdata\\local\\temp\\~dfa121f98502c92df2.tmp' 2025-09-03 11:25:00,233 [analyzer] INFO: Error dumping file from path "c:\users\administrator\appdata\local\temp\~dfe78f461c371630ba.tmp": [Errno 13] Permission denied: u'c:\\users\\administrator\\appdata\\local\\temp\\~dfe78f461c371630ba.tmp' 2025-09-03 11:25:00,233 [analyzer] INFO: Analysis completed.
2025-09-03 12:24:11,023 [cuckoo.core.scheduler] INFO: Task #6957388: acquired machine win7x6418 (label=win7x6418) 2025-09-03 12:24:11,024 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.218 for task #6957388 2025-09-03 12:24:11,455 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 4039097 (interface=vboxnet0, host=192.168.168.218) 2025-09-03 12:24:11,479 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6418 2025-09-03 12:24:12,249 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6418 to vmcloak 2025-09-03 12:24:21,809 [cuckoo.core.guest] INFO: Starting analysis #6957388 on guest (id=win7x6418, ip=192.168.168.218) 2025-09-03 12:24:22,814 [cuckoo.core.guest] DEBUG: win7x6418: not ready yet 2025-09-03 12:24:27,847 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6418, ip=192.168.168.218) 2025-09-03 12:24:27,942 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6418, ip=192.168.168.218, monitor=latest, size=6660546) 2025-09-03 12:24:29,170 [cuckoo.core.resultserver] DEBUG: Task #6957388: live log analysis.log initialized. 2025-09-03 12:24:30,142 [cuckoo.core.resultserver] DEBUG: Task #6957388 is sending a BSON stream 2025-09-03 12:24:30,478 [cuckoo.core.resultserver] DEBUG: Task #6957388 is sending a BSON stream 2025-09-03 12:24:31,401 [cuckoo.core.resultserver] DEBUG: Task #6957388: File upload for 'shots/0001.jpg' 2025-09-03 12:24:31,416 [cuckoo.core.resultserver] DEBUG: Task #6957388 uploaded file length: 133497 2025-09-03 12:24:32,574 [cuckoo.core.resultserver] DEBUG: Task #6957388 is sending a BSON stream 2025-09-03 12:24:33,512 [cuckoo.core.resultserver] DEBUG: Task #6957388: File upload for 'shots/0002.jpg' 2025-09-03 12:24:33,514 [cuckoo.core.resultserver] DEBUG: Task #6957388 uploaded file length: 24547 2025-09-03 12:24:34,639 [cuckoo.core.resultserver] DEBUG: Task #6957388: File upload for 'shots/0003.jpg' 2025-09-03 12:24:34,642 [cuckoo.core.resultserver] DEBUG: Task #6957388 uploaded file length: 28863 2025-09-03 12:24:43,843 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6957388 still processing 2025-09-03 12:24:59,070 [cuckoo.core.guest] DEBUG: win7x6418: analysis #6957388 still processing 2025-09-03 12:25:00,043 [cuckoo.core.resultserver] DEBUG: Task #6957388: File upload for 'curtain/1756891500.03.curtain.log' 2025-09-03 12:25:00,047 [cuckoo.core.resultserver] DEBUG: Task #6957388 uploaded file length: 36 2025-09-03 12:25:00,199 [cuckoo.core.resultserver] DEBUG: Task #6957388: File upload for 'sysmon/1756891500.19.sysmon.xml' 2025-09-03 12:25:00,206 [cuckoo.core.resultserver] DEBUG: Task #6957388 uploaded file length: 366908 2025-09-03 12:25:00,212 [cuckoo.core.resultserver] DEBUG: Task #6957388: File upload for 'files/5c8ff9aa46e34447_recoverystore.{1de22c4f-88b0-11f0-a5cd-d8386987cdba}.dat' 2025-09-03 12:25:00,215 [cuckoo.core.resultserver] DEBUG: Task #6957388 uploaded file length: 5632 2025-09-03 12:25:00,229 [cuckoo.core.resultserver] DEBUG: Task #6957388: File upload for 'files/81094aa6c9efe069_{1de22c51-88b0-11f0-a5cd-d8386987cdba}.dat' 2025-09-03 12:25:00,236 [cuckoo.core.resultserver] DEBUG: Task #6957388 uploaded file length: 3584 2025-09-03 12:25:00,484 [cuckoo.core.resultserver] DEBUG: Task #6957388: File upload for 'shots/0004.jpg' 2025-09-03 12:25:00,499 [cuckoo.core.resultserver] DEBUG: Task #6957388 uploaded file length: 133706 2025-09-03 12:25:00,513 [cuckoo.core.resultserver] DEBUG: Task #6957388 had connection reset for <Context for LOG> 2025-09-03 12:25:02,181 [cuckoo.core.guest] INFO: win7x6418: analysis completed successfully 2025-09-03 12:25:02,201 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-09-03 12:25:02,229 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-09-03 12:25:03,307 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6418 to path /srv/cuckoo/cwd/storage/analyses/6957388/memory.dmp 2025-09-03 12:25:03,311 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6418 2025-09-03 12:25:18,715 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.218 for task #6957388 2025-09-03 12:25:19,082 [cuckoo.core.scheduler] DEBUG: Released database task #6957388 2025-09-03 12:25:19,101 [cuckoo.core.scheduler] INFO: Task #6957388: analysis procedure completed
cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1952 CREDAT:275457 /prefetch:2 |