URL |
---|
https://t.ly/h6Qht |
This url shows some signs of potential malicious behavior.
The score of this url is 1.9 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
URL | Sept. 9, 2025, 6:02 a.m. | Sept. 9, 2025, 6:03 a.m. | 63 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-09-09 06:02:28,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4 2025-09-09 06:02:28,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\MjwjaDPTyCAHgNIoEe 2025-09-09 06:02:28,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\MSdTiBzzsewYwoGBUEETtroBcfvERan 2025-09-09 06:02:28,296 [analyzer] DEBUG: Started auxiliary module Curtain 2025-09-09 06:02:28,312 [analyzer] DEBUG: Started auxiliary module DbgView 2025-09-09 06:02:28,812 [analyzer] DEBUG: Started auxiliary module Disguise 2025-09-09 06:02:29,030 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-09-09 06:02:29,030 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-09-09 06:02:29,030 [analyzer] DEBUG: Started auxiliary module Human 2025-09-09 06:02:29,030 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-09-09 06:02:29,030 [analyzer] DEBUG: Started auxiliary module Reboot 2025-09-09 06:02:29,155 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-09-09 06:02:29,155 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-09-09 06:02:29,155 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-09-09 06:02:29,155 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-09-09 06:02:29,250 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://t.ly/h6Qht'] and pid 2272 2025-09-09 06:02:29,390 [analyzer] DEBUG: Loaded monitor into process with pid 2272 2025-09-09 06:02:30,858 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2272 CREDAT:275457 /prefetch:2! 2025-09-09 06:02:30,937 [analyzer] INFO: Injected into process with pid 340 and name u'iexplore.exe' 2025-09-09 06:02:31,030 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 340. 2025-09-09 06:02:31,217 [analyzer] INFO: Added new file to list with pid 2272 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{CD412D41-8D31-11F0-9D7E-3020D62C6363}.dat 2025-09-09 06:02:31,233 [analyzer] DEBUG: Loaded monitor into process with pid 340 2025-09-09 06:02:31,280 [analyzer] INFO: Added new file to list with pid 2272 and path C:\Users\Administrator\AppData\Local\Temp\~DFF66F31D4B689DBCF.TMP 2025-09-09 06:02:31,437 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-09 06:02:31,437 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-09 06:02:31,437 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-09 06:02:31,437 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-09 06:02:31,437 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-09 06:02:31,453 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-09 06:02:31,796 [analyzer] INFO: Added new file to list with pid 2272 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{CD412D43-8D31-11F0-9D7E-3020D62C6363}.dat 2025-09-09 06:02:31,812 [analyzer] INFO: Added new file to list with pid 2272 and path C:\Users\Administrator\AppData\Local\Temp\~DF61B9FE41B5430857.TMP 2025-09-09 06:02:37,203 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3 2025-09-09 06:02:37,203 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3 2025-09-09 06:02:37,217 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\CabD314.tmp 2025-09-09 06:02:37,233 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\CabD316.tmp 2025-09-09 06:02:37,250 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\TarD315.tmp 2025-09-09 06:02:37,250 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\TarD327.tmp 2025-09-09 06:02:37,405 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 2025-09-09 06:02:37,405 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 2025-09-09 06:02:37,405 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\CabD3D4.tmp 2025-09-09 06:02:37,421 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\TarD3D5.tmp 2025-09-09 06:02:37,578 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-09-09 06:02:37,578 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-09-09 06:02:37,671 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 2025-09-09 06:02:37,671 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 2025-09-09 06:02:37,687 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\CabD4EF.tmp 2025-09-09 06:02:37,703 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\TarD4F0.tmp 2025-09-09 06:02:37,717 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\CabD501.tmp 2025-09-09 06:02:37,717 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Temp\TarD511.tmp 2025-09-09 06:02:39,000 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F652AB2EFB7861D27E109EE07F4A4860_98EB09BB7594A10296F35472C1912155 2025-09-09 06:02:39,000 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F652AB2EFB7861D27E109EE07F4A4860_98EB09BB7594A10296F35472C1912155 2025-09-09 06:02:39,140 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AA516T8O\authentication[1].htm 2025-09-09 06:02:39,171 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-09-09 06:02:39,171 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-09-09 06:02:39,171 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-09-09 06:02:39,171 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-09-09 06:02:39,171 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-09-09 06:02:39,171 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-09-09 06:02:39,171 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-09-09 06:02:39,280 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\main.b44bf633[1].css 2025-09-09 06:02:39,296 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\main.d953633f[1].js 2025-09-09 06:02:39,375 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199 2025-09-09 06:02:39,390 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 2025-09-09 06:02:39,437 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3513D73A177A2707D910183759B389B_EC627A057A38303C672CFD0B9DD2E54C 2025-09-09 06:02:39,437 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3513D73A177A2707D910183759B389B_EC627A057A38303C672CFD0B9DD2E54C 2025-09-09 06:02:39,608 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9ZBKLLKU\favicon[2].ico 2025-09-09 06:02:39,640 [analyzer] INFO: Added new file to list with pid 340 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\imagestore\uv2m46n\imagestore.dat 2025-09-09 05:03:25,938 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-09-09 05:03:26,157 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2272. 2025-09-09 05:03:26,252 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 340. 2025-09-09 05:03:26,516 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-09-09 05:03:26,516 [lib.api.process] INFO: Successfully terminated process with pid 2272. 2025-09-09 05:03:26,516 [lib.api.process] INFO: Successfully terminated process with pid 340. 2025-09-09 05:03:26,516 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd4ef.tmp' does not exist, skip. 2025-09-09 05:03:26,548 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df61b9fe41b5430857.tmp' does not exist, skip. 2025-09-09 05:03:26,579 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard3d5.tmp' does not exist, skip. 2025-09-09 05:03:26,579 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd3d4.tmp' does not exist, skip. 2025-09-09 05:03:26,595 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard511.tmp' does not exist, skip. 2025-09-09 05:03:26,595 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd501.tmp' does not exist, skip. 2025-09-09 05:03:26,611 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard4f0.tmp' does not exist, skip. 2025-09-09 05:03:26,611 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd314.tmp' does not exist, skip. 2025-09-09 05:03:26,641 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dff66f31d4b689dbcf.tmp' does not exist, skip. 2025-09-09 05:03:26,641 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard327.tmp' does not exist, skip. 2025-09-09 05:03:26,657 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard315.tmp' does not exist, skip. 2025-09-09 05:03:26,657 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd316.tmp' does not exist, skip. 2025-09-09 05:03:26,657 [analyzer] INFO: Analysis completed.
2025-09-09 06:02:35,041 [cuckoo.core.scheduler] INFO: Task #6962671: acquired machine win7x644 (label=win7x644) 2025-09-09 06:02:35,042 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #6962671 2025-09-09 06:02:35,602 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1186156 (interface=vboxnet0, host=192.168.168.204) 2025-09-09 06:02:35,628 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644 2025-09-09 06:02:36,639 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak 2025-09-09 06:02:48,182 [cuckoo.core.guest] INFO: Starting analysis #6962671 on guest (id=win7x644, ip=192.168.168.204) 2025-09-09 06:02:49,189 [cuckoo.core.guest] DEBUG: win7x644: not ready yet 2025-09-09 06:02:54,209 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204) 2025-09-09 06:02:54,285 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546) 2025-09-09 06:02:55,659 [cuckoo.core.resultserver] DEBUG: Task #6962671: live log analysis.log initialized. 2025-09-09 06:02:56,645 [cuckoo.core.resultserver] DEBUG: Task #6962671 is sending a BSON stream 2025-09-09 06:02:57,005 [cuckoo.core.resultserver] DEBUG: Task #6962671 is sending a BSON stream 2025-09-09 06:02:57,950 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'shots/0001.jpg' 2025-09-09 06:02:57,962 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 133469 2025-09-09 06:02:58,848 [cuckoo.core.resultserver] DEBUG: Task #6962671 is sending a BSON stream 2025-09-09 06:03:00,077 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'shots/0002.jpg' 2025-09-09 06:03:00,080 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 24494 2025-09-09 06:03:01,160 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'shots/0003.jpg' 2025-09-09 06:03:01,187 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 28528 2025-09-09 06:03:07,416 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'shots/0004.jpg' 2025-09-09 06:03:07,419 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 31586 2025-09-09 06:03:10,147 [cuckoo.core.guest] DEBUG: win7x644: analysis #6962671 still processing 2025-09-09 06:03:25,233 [cuckoo.core.guest] DEBUG: win7x644: analysis #6962671 still processing 2025-09-09 06:03:26,392 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'curtain/1757387006.38.curtain.log' 2025-09-09 06:03:26,395 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 36 2025-09-09 06:03:26,522 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'sysmon/1757387006.52.sysmon.xml' 2025-09-09 06:03:26,529 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 248274 2025-09-09 06:03:26,536 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3' 2025-09-09 06:03:26,540 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 889 2025-09-09 06:03:26,556 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/61d0bdd8c36f450c_main.d953633f[1].js' 2025-09-09 06:03:26,577 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/5ed911c9cfd6832e_14232b434cf29d4c4fb335a86d7fffe3' 2025-09-09 06:03:26,580 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 170 2025-09-09 06:03:26,581 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/7835eb8ba444b0d4_b46811c17859ffb409cf0e904a4aa8f8' 2025-09-09 06:03:26,584 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 170 2025-09-09 06:03:26,586 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/ffd5705c82e29870_b3513d73a177a2707d910183759b389b_ec627a057a38303c672cfd0b9dd2e54c' 2025-09-09 06:03:26,588 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 398 2025-09-09 06:03:26,590 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 367287 2025-09-09 06:03:26,593 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/a26842c940f05dec_main.b44bf633[1].css' 2025-09-09 06:03:26,598 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/81b7fa53b692b4d2_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-09-09 06:03:26,601 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 506053 2025-09-09 06:03:26,603 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 1739 2025-09-09 06:03:26,607 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/994e4623e4c809a2_b3513d73a177a2707d910183759b389b_ec627a057a38303c672cfd0b9dd2e54c' 2025-09-09 06:03:26,609 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 472 2025-09-09 06:03:26,613 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/59e82f95601f80a4_authentication[1].htm' 2025-09-09 06:03:26,616 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 732 2025-09-09 06:03:26,617 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/549ae493b39d9546_f652ab2efb7861d27e109ee07f4a4860_98eb09bb7594a10296f35472c1912155' 2025-09-09 06:03:26,619 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 280 2025-09-09 06:03:26,624 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/004aa031465ff8cf_05ddc6aa91765aacacdb0a5f96df8199' 2025-09-09 06:03:26,626 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 170 2025-09-09 06:03:26,629 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/46bdb2730fec5772_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-09-09 06:03:26,631 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 174 2025-09-09 06:03:26,633 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/33ba8221ff3f5211_94308059b57b3142e455b38a6eb92015' 2025-09-09 06:03:26,636 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 73211 2025-09-09 06:03:26,638 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/b64a135a121f1233_recoverystore.{cd412d41-8d31-11f0-9d7e-3020d62c6363}.dat' 2025-09-09 06:03:26,640 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 5632 2025-09-09 06:03:26,642 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8' 2025-09-09 06:03:26,644 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 530 2025-09-09 06:03:26,646 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/e12e11e133250002_imagestore.dat' 2025-09-09 06:03:26,648 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 4789 2025-09-09 06:03:26,650 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/eac173f6aa2de93a_05ddc6aa91765aacacdb0a5f96df8199' 2025-09-09 06:03:26,670 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 993 2025-09-09 06:03:26,674 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/0bff9adbe14321a9_{cd412d43-8d31-11f0-9d7e-3020d62c6363}.dat' 2025-09-09 06:03:26,677 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 6656 2025-09-09 06:03:26,678 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/4f87ca8dd2e678b6_94308059b57b3142e455b38a6eb92015' 2025-09-09 06:03:26,680 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 344 2025-09-09 06:03:26,682 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/98eb116496dd329d_favicon[2].ico' 2025-09-09 06:03:26,684 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 4286 2025-09-09 06:03:26,685 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'files/9eae9bfc2213a56a_f652ab2efb7861d27e109ee07f4a4860_98eb09bb7594a10296f35472c1912155' 2025-09-09 06:03:26,687 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 410 2025-09-09 06:03:27,097 [cuckoo.core.resultserver] DEBUG: Task #6962671: File upload for 'shots/0005.jpg' 2025-09-09 06:03:27,112 [cuckoo.core.resultserver] DEBUG: Task #6962671 uploaded file length: 133470 2025-09-09 06:03:27,127 [cuckoo.core.resultserver] DEBUG: Task #6962671 had connection reset for <Context for LOG> 2025-09-09 06:03:28,246 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully 2025-09-09 06:03:28,256 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-09-09 06:03:28,281 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-09-09 06:03:29,584 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/6962671/memory.dmp 2025-09-09 06:03:29,586 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644 2025-09-09 06:03:38,162 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #6962671 2025-09-09 06:03:38,496 [cuckoo.core.scheduler] DEBUG: Released database task #6962671 2025-09-09 06:03:38,517 [cuckoo.core.scheduler] INFO: Task #6962671: analysis procedure completed
file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\main.d953633f[1].js |
cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2272 CREDAT:275457 /prefetch:2 |
snort | ET INFO URL Shortening Service Domain in DNS Lookup (t .ly) |
snort | ET INFO Observed URL Shortening Service Domain (t .ly in TLS SNI) |