URL |
---|
https://metahagrandview12.top/two_stepz_verytfications/authenstication?encrypted_context=mouCvCDl-qc9rUfat_U_4pwg9N6Ucjm7TaJi2uZ5gZamPKvlNqI1CNvxSaIHTbsUvCz55uIvXuKFL34IWuSi-GGZBojRWBCuHfNqOUOKTqbjsNFRdSHpKvryRmlL_S16vGRVtGISApb3yG0c40yt8wJLDQUBKI3eEymcKHrvGxLcogaIrcty1BXvn_RqfxAvGW5YHZofCHHS0l3r8rWkoL6UqqEZCvKqJhYCnAjGDlqWoy-iwUIYcqbu7PXW_BzYOLM_IgETbGtxb-5ezn7TdyDEuPmI3k489LNda-MuoE3bGKJ41pKqdNjHGulbySASYHmY4ceJ6DQZNKBZfK2NK1Hpp8e7hSy_4lOCJjBSsV16ZusSw1y7KeBRiiDxmVaX3ClPfOQ7U-69HURJJb3fum5sWXBwe0Klq-nKe2Gdoc1Ol23Lg_eK8zT13neIrw9zh3rvZUyhPaz8HrJxefTdCePX4g6EPnDnGPH3LB-zgMhQzNZdMSxo0Nsr9XbWDvSRVft1OuvQF6LxtTC7Jx73is6IoP9eH4-_X4eftBbFT5FdpEMIKhXUz5oLieS-SvOX5iQRv3-W0z5Kc3rLrhh90pRZrwC15911Fd_-OlkYlzqh_fDA1KEIaiPZZFiD5tXE0Mmipc7JlTjDtqnwghqGQMf1_6b7gfp1BrCuUPOXk6aRX5h0zJ2POMU8DLA_VpMjwWSl3TpWdkuq8uXcXH-UbNq1f1YeOEAfDROzKqTitu3_oxp_bDBEgGsZuFDmbInXiw5Sik9A6ch7ZGtgdInUhVRm93iHvSn6mEP2pY5cH4OKfn3QAFzmg5U0zOu4n5sMkL4FZaHZZbujbAjBwZJ0IWRso4pHYyO6ejciWEwbXmaoA_EECZB6TX79C01fxOrArvksnMJKWdXCesUI6bCJnc860UlWXXFixwSjrdwXjI0ECX9WnSKbOSvbwezqUGzPJOwh5F8&flow=pre_authentication&next?pageId=default |
This url shows some signs of potential malicious behavior.
The score of this url is 1.9 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
URL | Sept. 9, 2025, 5:46 a.m. | Sept. 9, 2025, 5:47 a.m. | 62 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-09-09 05:46:03,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd 2025-09-09 05:46:03,000 [analyzer] DEBUG: Pipe server name: \??\PIPE\WqEEivOOGuvOKHSYMIrrMxmcAOPtVL 2025-09-09 05:46:03,000 [analyzer] DEBUG: Log pipe server name: \??\PIPE\iluOWxdXmcbOJuGQzgaDBHR 2025-09-09 05:46:03,250 [analyzer] DEBUG: Started auxiliary module Curtain 2025-09-09 05:46:03,250 [analyzer] DEBUG: Started auxiliary module DbgView 2025-09-09 05:46:03,780 [analyzer] DEBUG: Started auxiliary module Disguise 2025-09-09 05:46:03,967 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-09-09 05:46:03,967 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-09-09 05:46:03,967 [analyzer] DEBUG: Started auxiliary module Human 2025-09-09 05:46:03,967 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-09-09 05:46:03,967 [analyzer] DEBUG: Started auxiliary module Reboot 2025-09-09 05:46:04,030 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-09-09 05:46:04,046 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-09-09 05:46:04,046 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-09-09 05:46:04,046 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-09-09 05:46:04,140 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://metahagrandview12.top/two_stepz_verytfications/authenstication?encrypted_context=mouCvCDl-qc9rUfat_U_4pwg9N6Ucjm7TaJi2uZ5gZamPKvlNqI1CNvxSaIHTbsUvCz55uIvXuKFL34IWuSi-GGZBojRWBCuHfNqOUOKTqbjsNFRdSHpKvryRmlL_S16vGRVtGISApb3yG0c40yt8wJLDQUBKI3eEymcKHrvGxLcogaIrcty1BXvn_RqfxAvGW5YHZofCHHS0l3r8rWkoL6UqqEZCvKqJhYCnAjGDlqWoy-iwUIYcqbu7PXW_BzYOLM_IgETbGtxb-5ezn7TdyDEuPmI3k489LNda-MuoE3bGKJ41pKqdNjHGulbySASYHmY4ceJ6DQZNKBZfK2NK1Hpp8e7hSy_4lOCJjBSsV16ZusSw1y7KeBRiiDxmVaX3ClPfOQ7U-69HURJJb3fum5sWXBwe0Klq-nKe2Gdoc1Ol23Lg_eK8zT13neIrw9zh3rvZUyhPaz8HrJxefTdCePX4g6EPnDnGPH3LB-zgMhQzNZdMSxo0Nsr9XbWDvSRVft1OuvQF6LxtTC7Jx73is6IoP9eH4-_X4eftBbFT5FdpEMIKhXUz5oLieS-SvOX5iQRv3-W0z5Kc3rLrhh90pRZrwC15911Fd_-OlkYlzqh_fDA1KEIaiPZZFiD5tXE0Mmipc7JlTjDtqnwghqGQMf1_6b7gfp1BrCuUPOXk6aRX5h0zJ2POMU8DLA_VpMjwWSl3TpWdkuq8uXcXH-UbNq1f1YeOEAfDROzKqTitu3_oxp_bDBEgGsZuFDmbInXiw5Sik9A6ch7ZGtgdInUhVRm93iHvSn6mEP2pY5cH4OKfn3QAFzmg5U0zOu4n5sMkL4FZaHZZbujbAjBwZJ0IWRso4pHYyO6ejciWEwbXmaoA_EECZB6TX79C01fxOrArvksnMJKWdXCesUI6bCJnc860UlWXXFixwSjrdwXjI0ECX9WnSKbOSvbwezqUGzPJOwh5F8&flow=pre_authentication&next?pageId=default'] and pid 2128 2025-09-09 05:46:04,296 [analyzer] DEBUG: Loaded monitor into process with pid 2128 2025-09-09 05:46:05,796 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2128 CREDAT:275457 /prefetch:2! 2025-09-09 05:46:05,875 [analyzer] INFO: Injected into process with pid 1420 and name u'iexplore.exe' 2025-09-09 05:46:05,983 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1420. 2025-09-09 05:46:06,125 [analyzer] INFO: Added new file to list with pid 2128 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{8217CCA5-8D2F-11F0-A9D1-30E4028CEEC5}.dat 2025-09-09 05:46:06,171 [analyzer] DEBUG: Loaded monitor into process with pid 1420 2025-09-09 05:46:06,280 [analyzer] INFO: Added new file to list with pid 2128 and path C:\Users\Administrator\AppData\Local\Temp\~DF0A8BCC88DA80BAA0.TMP 2025-09-09 05:46:06,421 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-09 05:46:06,421 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-09 05:46:06,421 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-09 05:46:06,421 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-09 05:46:06,421 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-09 05:46:06,421 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-09 05:46:06,421 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-09 05:46:06,437 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-09 05:46:06,437 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-09 05:46:06,437 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-09 05:46:06,437 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-09 05:46:06,437 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-09 05:46:06,437 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-09 05:46:06,437 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-09 05:46:06,733 [analyzer] INFO: Added new file to list with pid 2128 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{8217CCA7-8D2F-11F0-A9D1-30E4028CEEC5}.dat 2025-09-09 05:46:06,750 [analyzer] INFO: Added new file to list with pid 2128 and path C:\Users\Administrator\AppData\Local\Temp\~DFF2A57E5000BC4C4C.TMP 2025-09-09 05:46:09,812 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3 2025-09-09 05:46:09,812 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3 2025-09-09 05:46:09,828 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab5EE9.tmp 2025-09-09 05:46:09,842 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar5EEA.tmp 2025-09-09 05:46:09,842 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab5EFB.tmp 2025-09-09 05:46:09,858 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar5EFC.tmp 2025-09-09 05:46:10,000 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 2025-09-09 05:46:10,015 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 2025-09-09 05:46:10,046 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab5FB8.tmp 2025-09-09 05:46:10,046 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab5FCA.tmp 2025-09-09 05:46:10,062 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar5FB9.tmp 2025-09-09 05:46:10,062 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar5FCB.tmp 2025-09-09 05:46:10,233 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-09-09 05:46:10,233 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-09-09 05:46:10,312 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 2025-09-09 05:46:10,328 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 2025-09-09 05:46:10,358 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab60F5.tmp 2025-09-09 05:46:10,358 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar60F6.tmp 2025-09-09 05:46:11,280 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z9GTCWIE\authenstication[1].htm 2025-09-09 05:46:11,280 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-09 05:46:11,280 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-09 05:46:11,280 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-09 05:46:11,280 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-09 05:46:11,296 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-09 05:46:11,296 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-09 05:46:11,296 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-09 05:46:11,453 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIRKR6QC\I7MPNWSM 2025-09-09 05:46:11,483 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNU644SE\3.4[1].js 2025-09-09 05:46:11,562 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 2025-09-09 05:46:11,562 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 2025-09-09 05:46:11,671 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DABA17F5E36CBE65640DD2FE24F104E7 2025-09-09 05:46:11,671 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3513D73A177A2707D910183759B389B_EC627A057A38303C672CFD0B9DD2E54C 2025-09-09 05:46:11,671 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DABA17F5E36CBE65640DD2FE24F104E7 2025-09-09 05:46:11,687 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3513D73A177A2707D910183759B389B_EC627A057A38303C672CFD0B9DD2E54C 2025-09-09 05:46:11,842 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\070E0202839D9D67350CD2613E78E416 2025-09-09 05:46:11,842 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\070E0202839D9D67350CD2613E78E416 2025-09-09 05:46:11,858 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab66D3.tmp 2025-09-09 05:46:11,858 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar66E3.tmp 2025-09-09 05:46:11,875 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab66F4.tmp 2025-09-09 05:46:11,890 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4FA45AE1010E09657982D8D28B3BD38E_283E80E4304E0CE6924AD58602F06764 2025-09-09 05:46:11,890 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar66F5.tmp 2025-09-09 05:46:11,890 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4FA45AE1010E09657982D8D28B3BD38E_283E80E4304E0CE6924AD58602F06764 2025-09-09 05:46:11,921 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z9GTCWIE\KFOMCnqEu92Fr1ME7kSn66aGLdTylUAMQXC89YmC2DPNWubEbWmQ[1].woff 2025-09-09 05:46:11,921 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z9GTCWIE\soeuNpXL37G[1].png 2025-09-09 05:46:11,937 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIRKR6QC\KFOMCnqEu92Fr1ME7kSn66aGLdTylUAMQXC89YmC2DPNWuYjammQ[1].woff 2025-09-09 05:46:11,937 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab6735.tmp 2025-09-09 05:46:11,953 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIRKR6QC\KFOMCnqEu92Fr1ME7kSn66aGLdTylUAMQXC89YmC2DPNWub2bWmQ[1].woff 2025-09-09 05:46:11,967 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIRKR6QC\logo_48[1].png 2025-09-09 05:46:11,967 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar6736.tmp 2025-09-09 05:46:11,983 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab6765.tmp 2025-09-09 05:46:12,000 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar6766.tmp 2025-09-09 05:46:12,015 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab6777.tmp 2025-09-09 05:46:12,015 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar6778.tmp 2025-09-09 05:46:12,046 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab67A8.tmp 2025-09-09 05:46:12,062 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar67A9.tmp 2025-09-09 05:46:12,078 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab67C9.tmp 2025-09-09 05:46:12,092 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar67CA.tmp 2025-09-09 05:46:12,108 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab67EA.tmp 2025-09-09 05:46:12,125 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar67EB.tmp 2025-09-09 05:46:12,125 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab67FC.tmp 2025-09-09 05:46:12,125 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar67FD.tmp 2025-09-09 05:46:12,155 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab681D.tmp 2025-09-09 05:46:12,171 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9IPFD2J7\ACP-UnifiedDelta-AuthenticationApp-Mobile_light-3x[1].png 2025-09-09 05:46:12,171 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar681E.tmp 2025-09-09 05:46:12,171 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab682F.tmp 2025-09-09 05:46:12,187 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar6830.tmp 2025-09-09 05:46:12,250 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab686F.tmp 2025-09-09 05:46:12,250 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab6871.tmp 2025-09-09 05:46:12,250 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar6872.tmp 2025-09-09 05:46:12,250 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar6870.tmp 2025-09-09 05:46:12,280 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab68A2.tmp 2025-09-09 05:46:12,296 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab68A4.tmp 2025-09-09 05:46:12,296 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar68A3.tmp 2025-09-09 05:46:12,296 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar68A5.tmp 2025-09-09 05:46:12,358 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab68F4.tmp 2025-09-09 05:46:12,358 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar68F5.tmp 2025-09-09 05:46:12,375 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab6906.tmp 2025-09-09 05:46:12,375 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar6907.tmp 2025-09-09 05:46:12,405 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab6918.tmp 2025-09-09 05:46:12,405 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar6928.tmp 2025-09-09 05:46:12,421 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab6929.tmp 2025-09-09 05:46:12,421 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar693A.tmp 2025-09-09 05:46:12,467 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab696A.tmp 2025-09-09 05:46:12,467 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar696B.tmp 2025-09-09 05:46:12,483 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Cab697B.tmp 2025-09-09 05:46:12,500 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Temp\Tar697C.tmp 2025-09-09 05:46:12,655 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62 2025-09-09 05:46:12,655 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62 2025-09-09 05:46:12,796 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 2025-09-09 05:46:12,812 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 2025-09-09 05:46:12,921 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517 2025-09-09 05:46:12,921 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517 2025-09-09 05:46:12,937 [analyzer] INFO: Added new file to list with pid 1420 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNU644SE\socket.io.min[1].js 2025-09-09 04:46:56,997 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-09-09 04:46:57,122 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2128. 2025-09-09 04:46:57,232 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1420. 2025-09-09 04:46:57,482 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-09-09 04:46:57,482 [lib.api.process] INFO: Successfully terminated process with pid 2128. 2025-09-09 04:46:57,482 [lib.api.process] INFO: Successfully terminated process with pid 1420. 2025-09-09 04:46:57,497 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar66f5.tmp' does not exist, skip. 2025-09-09 04:46:57,497 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6928.tmp' does not exist, skip. 2025-09-09 04:46:57,513 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6778.tmp' does not exist, skip. 2025-09-09 04:46:57,513 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6871.tmp' does not exist, skip. 2025-09-09 04:46:57,513 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar67fd.tmp' does not exist, skip. 2025-09-09 04:46:57,529 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6735.tmp' does not exist, skip. 2025-09-09 04:46:57,529 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5fcb.tmp' does not exist, skip. 2025-09-09 04:46:57,529 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar68f5.tmp' does not exist, skip. 2025-09-09 04:46:57,529 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar693a.tmp' does not exist, skip. 2025-09-09 04:46:57,529 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar697c.tmp' does not exist, skip. 2025-09-09 04:46:57,529 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab682f.tmp' does not exist, skip. 2025-09-09 04:46:57,545 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab68a4.tmp' does not exist, skip. 2025-09-09 04:46:57,545 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6872.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5eea.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab60f5.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar696b.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6830.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6765.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5fca.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5efb.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab68a2.tmp' does not exist, skip. 2025-09-09 04:46:57,559 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dff2a57e5000bc4c4c.tmp' does not exist, skip. 2025-09-09 04:46:57,575 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5fb8.tmp' does not exist, skip. 2025-09-09 04:46:57,575 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab697b.tmp' does not exist, skip. 2025-09-09 04:46:57,575 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab681d.tmp' does not exist, skip. 2025-09-09 04:46:57,575 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5fb9.tmp' does not exist, skip. 2025-09-09 04:46:57,591 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab67a8.tmp' does not exist, skip. 2025-09-09 04:46:57,591 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab67fc.tmp' does not exist, skip. 2025-09-09 04:46:57,591 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6906.tmp' does not exist, skip. 2025-09-09 04:46:57,591 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar66e3.tmp' does not exist, skip. 2025-09-09 04:46:57,591 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6918.tmp' does not exist, skip. 2025-09-09 04:46:57,607 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar67eb.tmp' does not exist, skip. 2025-09-09 04:46:57,622 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab66d3.tmp' does not exist, skip. 2025-09-09 04:46:57,622 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df0a8bcc88da80baa0.tmp' does not exist, skip. 2025-09-09 04:46:57,622 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6929.tmp' does not exist, skip. 2025-09-09 04:46:57,622 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar60f6.tmp' does not exist, skip. 2025-09-09 04:46:57,622 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab66f4.tmp' does not exist, skip. 2025-09-09 04:46:57,622 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5ee9.tmp' does not exist, skip. 2025-09-09 04:46:57,638 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6736.tmp' does not exist, skip. 2025-09-09 04:46:57,638 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar68a3.tmp' does not exist, skip. 2025-09-09 04:46:57,638 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6766.tmp' does not exist, skip. 2025-09-09 04:46:57,638 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab67c9.tmp' does not exist, skip. 2025-09-09 04:46:57,638 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar681e.tmp' does not exist, skip. 2025-09-09 04:46:57,638 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6777.tmp' does not exist, skip. 2025-09-09 04:46:57,638 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar67a9.tmp' does not exist, skip. 2025-09-09 04:46:57,654 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar67ca.tmp' does not exist, skip. 2025-09-09 04:46:57,654 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab68f4.tmp' does not exist, skip. 2025-09-09 04:46:57,654 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5efc.tmp' does not exist, skip. 2025-09-09 04:46:57,654 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar68a5.tmp' does not exist, skip. 2025-09-09 04:46:57,654 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab686f.tmp' does not exist, skip. 2025-09-09 04:46:57,654 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab67ea.tmp' does not exist, skip. 2025-09-09 04:46:57,670 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab696a.tmp' does not exist, skip. 2025-09-09 04:46:57,670 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6907.tmp' does not exist, skip. 2025-09-09 04:46:57,670 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6870.tmp' does not exist, skip. 2025-09-09 04:46:57,684 [analyzer] INFO: Analysis completed.
2025-09-09 05:46:07,719 [cuckoo.core.scheduler] INFO: Task #6962666: acquired machine win7x6412 (label=win7x6412) 2025-09-09 05:46:07,720 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.212 for task #6962666 2025-09-09 05:46:08,251 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1179175 (interface=vboxnet0, host=192.168.168.212) 2025-09-09 05:46:08,273 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6412 2025-09-09 05:46:09,064 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6412 to vmcloak 2025-09-09 05:46:19,275 [cuckoo.core.guest] INFO: Starting analysis #6962666 on guest (id=win7x6412, ip=192.168.168.212) 2025-09-09 05:46:20,282 [cuckoo.core.guest] DEBUG: win7x6412: not ready yet 2025-09-09 05:46:25,313 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6412, ip=192.168.168.212) 2025-09-09 05:46:25,390 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6412, ip=192.168.168.212, monitor=latest, size=6660546) 2025-09-09 05:46:26,679 [cuckoo.core.resultserver] DEBUG: Task #6962666: live log analysis.log initialized. 2025-09-09 05:46:27,603 [cuckoo.core.resultserver] DEBUG: Task #6962666 is sending a BSON stream 2025-09-09 05:46:27,931 [cuckoo.core.resultserver] DEBUG: Task #6962666 is sending a BSON stream 2025-09-09 05:46:28,886 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'shots/0001.jpg' 2025-09-09 05:46:28,903 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 133453 2025-09-09 05:46:29,823 [cuckoo.core.resultserver] DEBUG: Task #6962666 is sending a BSON stream 2025-09-09 05:46:31,071 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'shots/0002.jpg' 2025-09-09 05:46:31,074 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 24436 2025-09-09 05:46:32,160 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'shots/0003.jpg' 2025-09-09 05:46:32,173 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 31255 2025-09-09 05:46:33,276 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'shots/0004.jpg' 2025-09-09 05:46:33,279 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 31379 2025-09-09 05:46:35,381 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'shots/0005.jpg' 2025-09-09 05:46:35,417 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 31353 2025-09-09 05:46:36,511 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'shots/0006.jpg' 2025-09-09 05:46:36,524 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 61243 2025-09-09 05:46:41,308 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6962666 still processing 2025-09-09 05:46:56,396 [cuckoo.core.guest] DEBUG: win7x6412: analysis #6962666 still processing 2025-09-09 05:46:57,353 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'curtain/1757386017.36.curtain.log' 2025-09-09 05:46:57,356 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 36 2025-09-09 05:46:57,483 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'sysmon/1757386017.48.sysmon.xml' 2025-09-09 05:46:57,489 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 257826 2025-09-09 05:46:57,494 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/0443f2fb70ecda9f_recoverystore.{8217cca5-8d2f-11f0-a9d1-30e4028ceec5}.dat' 2025-09-09 05:46:57,496 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 5632 2025-09-09 05:46:57,505 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/6b234180f3b3bde5_14232b434cf29d4c4fb335a86d7fffe3' 2025-09-09 05:46:57,509 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 170 2025-09-09 05:46:57,523 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/a214a6b6fc63a9b4_kfomcnqeu92fr1me7ksn66agldtyluamqxc89ymc2dpnwubebwmq[1].woff' 2025-09-09 05:46:57,526 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 64396 2025-09-09 05:46:57,534 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/dad4edffeb8ececc_daba17f5e36cbe65640dd2fe24f104e7' 2025-09-09 05:46:57,536 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 276 2025-09-09 05:46:57,542 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/33ba8221ff3f5211_94308059b57b3142e455b38a6eb92015' 2025-09-09 05:46:57,547 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 73211 2025-09-09 05:46:57,548 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8' 2025-09-09 05:46:57,550 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 530 2025-09-09 05:46:57,552 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/83df4abc7eec941f_socket.io.min[1].js' 2025-09-09 05:46:57,555 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 49732 2025-09-09 05:46:57,558 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/5989487b6d179d77_b66240b0f6c84bd4857aba60cf5ce4a0_5043e0f5df723415c9eecc201c838a62' 2025-09-09 05:46:57,560 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 2064 2025-09-09 05:46:57,563 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/d6099404c851852d_bad725c80f9e10846f35d039a996e4a8_88b6ae015495c1ecc395d19c1dd02894' 2025-09-09 05:46:57,565 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 1560 2025-09-09 05:46:57,570 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/359c287c5f936413_{8217cca7-8d2f-11f0-a9d1-30e4028ceec5}.dat' 2025-09-09 05:46:57,572 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 20480 2025-09-09 05:46:57,575 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/bb08512164b4994d_4fa45ae1010e09657982d8d28b3bd38e_283e80e4304e0ce6924ad58602f06764' 2025-09-09 05:46:57,577 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 471 2025-09-09 05:46:57,582 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/176e894661aa9cdc_3.4[1].js' 2025-09-09 05:46:57,587 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 407279 2025-09-09 05:46:57,590 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/994e4623e4c809a2_b3513d73a177a2707d910183759b389b_ec627a057a38303c672cfd0b9dd2e54c' 2025-09-09 05:46:57,592 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 472 2025-09-09 05:46:57,594 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/e44921235c395bb5_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-09-09 05:46:57,596 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 174 2025-09-09 05:46:57,601 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/6627e74dd59a232b_acp-unifieddelta-authenticationapp-mobile_light-3x[1].png' 2025-09-09 05:46:57,606 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/eafd0e1a2f0e0b98_kfomcnqeu92fr1me7ksn66agldtyluamqxc89ymc2dpnwuyjammq[1].woff' 2025-09-09 05:46:57,609 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 451984 2025-09-09 05:46:57,612 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 65844 2025-09-09 05:46:57,614 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/e9b2133ea6a2b89c_070e0202839d9d67350cd2613e78e416' 2025-09-09 05:46:57,616 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 230 2025-09-09 05:46:57,618 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/d8efa4ff60778c69_authenstication[1].htm' 2025-09-09 05:46:57,620 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3' 2025-09-09 05:46:57,640 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 889 2025-09-09 05:46:57,641 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 61526 2025-09-09 05:46:57,643 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/1b9efb22c9385009_logo_48[1].png' 2025-09-09 05:46:57,645 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 2228 2025-09-09 05:46:57,646 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/5a7495842cb6f4d0_b46811c17859ffb409cf0e904a4aa8f8' 2025-09-09 05:46:57,648 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 170 2025-09-09 05:46:57,649 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/81b7fa53b692b4d2_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-09-09 05:46:57,665 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 1739 2025-09-09 05:46:57,666 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/933b971c6388d594_i7mpnwsm' 2025-09-09 05:46:57,668 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 5 2025-09-09 05:46:57,669 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/7a426609b5fba435_soeunpxl37g[1].png' 2025-09-09 05:46:57,670 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 2965 2025-09-09 05:46:57,671 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/aaa90e7527286438_05ddc6aa91765aacacdb0a5f96df8199' 2025-09-09 05:46:57,673 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 170 2025-09-09 05:46:57,674 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/ff1afcc6a2544c35_94308059b57b3142e455b38a6eb92015' 2025-09-09 05:46:57,676 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 344 2025-09-09 05:46:57,677 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/d73494e3446b0216_070e0202839d9d67350cd2613e78e416' 2025-09-09 05:46:57,678 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 1302 2025-09-09 05:46:57,679 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/28689b30e4c306aa_daba17f5e36cbe65640dd2fe24f104e7' 2025-09-09 05:46:57,681 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 1145 2025-09-09 05:46:57,682 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/06070c57d9614319_75ca58072b9926f763a91f0cc2798706_645bc4a49dcdc40fe5917fa45c6d4517' 2025-09-09 05:46:57,683 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 1438 2025-09-09 05:46:57,684 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/b6340ff2cb1be5dd_75ca58072b9926f763a91f0cc2798706_645bc4a49dcdc40fe5917fa45c6d4517' 2025-09-09 05:46:57,686 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 434 2025-09-09 05:46:57,686 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/b5748a01b8878597_b66240b0f6c84bd4857aba60cf5ce4a0_5043e0f5df723415c9eecc201c838a62' 2025-09-09 05:46:57,688 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 458 2025-09-09 05:46:57,689 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/0296242769966d8e_b3513d73a177a2707d910183759b389b_ec627a057a38303c672cfd0b9dd2e54c' 2025-09-09 05:46:57,690 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 398 2025-09-09 05:46:57,691 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/6ec5402b9bdf4617_4fa45ae1010e09657982d8d28b3bd38e_283e80e4304e0ce6924ad58602f06764' 2025-09-09 05:46:57,693 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 402 2025-09-09 05:46:57,694 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/400e38b7c27364b7_kfomcnqeu92fr1me7ksn66agldtyluamqxc89ymc2dpnwub2bwmq[1].woff' 2025-09-09 05:46:57,698 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/eac173f6aa2de93a_05ddc6aa91765aacacdb0a5f96df8199' 2025-09-09 05:46:57,699 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 993 2025-09-09 05:46:57,700 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'files/7be35ae2b0c921e0_bad725c80f9e10846f35d039a996e4a8_88b6ae015495c1ecc395d19c1dd02894' 2025-09-09 05:46:57,702 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 432 2025-09-09 05:46:57,703 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 65664 2025-09-09 05:46:58,307 [cuckoo.core.resultserver] DEBUG: Task #6962666: File upload for 'shots/0007.jpg' 2025-09-09 05:46:58,318 [cuckoo.core.resultserver] DEBUG: Task #6962666 uploaded file length: 133454 2025-09-09 05:46:58,333 [cuckoo.core.resultserver] DEBUG: Task #6962666 had connection reset for <Context for LOG> 2025-09-09 05:46:59,408 [cuckoo.core.guest] INFO: win7x6412: analysis completed successfully 2025-09-09 05:46:59,420 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-09-09 05:46:59,447 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-09-09 05:47:00,856 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6412 to path /srv/cuckoo/cwd/storage/analyses/6962666/memory.dmp 2025-09-09 05:47:00,858 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6412 2025-09-09 05:47:09,382 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.212 for task #6962666 2025-09-09 05:47:09,688 [cuckoo.core.scheduler] DEBUG: Released database task #6962666 2025-09-09 05:47:09,705 [cuckoo.core.scheduler] INFO: Task #6962666: analysis procedure completed
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNU644SE\3.4[1].js |
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNU644SE\socket.io.min[1].js |
cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2128 CREDAT:275457 /prefetch:2 |
snort | ET DNS Query to a *.top domain - Likely Hostile |