Size | 340.9KB |
---|---|
Type | HTML document, ASCII text, with very long lines (65361), with CRLF, LF line terminators |
MD5 | 706ff2f3376dc3bad230d047e41b7e90 |
SHA1 | 4663a387324b673154e49b8a5d3c1e6796bcfd96 |
SHA256 | 69f0f65fddfb82202010ef525b9746a26c91e7ff7ab6bc9a97aaa290ae6ce916 |
SHA512 |
678536b7815f89b09f23ede00b333693915ca745906170077269ca6b0a7696e03311e895bcc01ef7d71442e41aacf42ce08b2f2a89bf4916d04925022210dc74
|
CRC32 | 5D5535E9 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 8.0 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Sept. 25, 2025, 6:53 a.m. | Sept. 25, 2025, 7:02 a.m. | 511 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-09-22 21:04:34,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp564etj 2025-09-22 21:04:34,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\aWaprKGsLOpATQAHhJHKSeUC 2025-09-22 21:04:34,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\lalTcKxZRXKTwBVlmycnkboaVjaR 2025-09-22 21:04:34,265 [analyzer] DEBUG: Started auxiliary module Curtain 2025-09-22 21:04:34,265 [analyzer] DEBUG: Started auxiliary module DbgView 2025-09-22 21:04:34,765 [analyzer] DEBUG: Started auxiliary module Disguise 2025-09-22 21:04:35,000 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-09-22 21:04:35,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-09-22 21:04:35,000 [analyzer] DEBUG: Started auxiliary module Human 2025-09-22 21:04:35,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-09-22 21:04:35,000 [analyzer] DEBUG: Started auxiliary module Reboot 2025-09-22 21:04:35,062 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-09-22 21:04:35,062 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-09-22 21:04:35,062 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-09-22 21:04:35,062 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-09-22 21:04:35,078 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-09-22 21:04:35,140 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\69f0f65fddfb82202010ef525b9746a26c91e7ff7ab6bc9a97aaa290ae6ce916.js'] and pid 1516 2025-09-22 21:04:35,358 [analyzer] DEBUG: Loaded monitor into process with pid 1516 2025-09-22 21:04:35,828 [analyzer] INFO: io=NULL 2025-09-22 21:04:35,828 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-09-22 21:04:35,828 [analyzer] INFO: io=NULL 2025-09-22 21:04:35,828 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-09-22 21:04:35,828 [analyzer] INFO: io=NULL 2025-09-22 21:04:35,828 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-09-22 21:04:35,890 [analyzer] INFO: io=NULL 2025-09-22 21:04:35,890 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-09-22 21:04:35,890 [analyzer] INFO: io=NULL 2025-09-22 21:04:35,890 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-09-22 21:04:35,905 [analyzer] INFO: io=NULL 2025-09-22 21:04:35,905 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-09-22 21:05:04,217 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-09-22 21:05:04,655 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-09-22 21:05:04,655 [lib.api.process] INFO: Successfully terminated process with pid 1516. 2025-09-22 21:05:04,671 [analyzer] INFO: Analysis completed.
2025-09-25 06:53:52,750 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:53:53,787 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:53:54,826 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:53:55,861 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:53:56,885 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:53:57,911 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:53:58,937 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:53:59,962 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:00,995 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:02,637 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:03,734 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:04,783 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:05,808 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:06,830 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:07,882 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:09,179 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:10,286 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:12,152 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:13,216 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:14,291 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:15,349 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:16,459 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:17,545 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:18,659 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:19,775 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:20,865 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:22,456 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:23,527 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:24,583 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:25,610 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:26,631 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:27,652 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:28,672 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:29,698 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:30,732 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:31,765 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:32,913 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:33,983 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:35,030 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:36,079 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:37,143 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:38,219 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:39,289 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:40,356 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:41,425 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:43,228 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:44,351 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:45,460 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:46,516 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:47,621 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:48,707 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:49,768 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:50,879 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:51,940 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:53,225 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:54,340 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:55,577 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:56,689 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:57,807 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:58,905 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:54:59,986 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:01,253 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:02,397 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:03,524 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:04,673 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:05,782 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:06,881 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:07,995 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:09,111 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:11,061 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:12,150 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:13,250 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:14,324 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:15,408 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:16,496 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:17,744 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:18,910 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:20,055 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:21,146 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:22,250 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:23,347 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:24,438 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:25,563 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:26,734 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:28,318 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:29,368 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:30,405 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:31,443 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:32,478 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:33,511 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:34,547 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:35,868 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:36,976 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:38,373 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:39,909 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:41,537 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:42,869 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:45,677 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:46,889 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:47,959 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:49,803 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:50,948 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:52,042 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:53,381 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:54,479 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:55,672 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:56,799 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:57,905 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:55:59,883 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:00,976 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:02,387 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:03,517 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:04,639 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:05,729 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:06,856 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:07,964 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:09,438 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:10,968 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:12,076 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:13,152 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:14,455 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:15,565 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:16,652 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:18,322 [cuckoo.core.scheduler] DEBUG: Task #6999797: no machine available yet 2025-09-25 06:56:19,708 [cuckoo.core.scheduler] INFO: Task #6999797: acquired machine win7x6419 (label=win7x6419) 2025-09-25 06:56:19,713 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.219 for task #6999797 2025-09-25 06:56:21,022 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1397075 (interface=vboxnet0, host=192.168.168.219) 2025-09-25 06:56:22,007 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6419 2025-09-25 06:56:30,099 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6419 to vmcloak 2025-09-25 06:57:59,967 [cuckoo.core.guest] INFO: Starting analysis #6999797 on guest (id=win7x6419, ip=192.168.168.219) 2025-09-25 06:58:00,982 [cuckoo.core.guest] DEBUG: win7x6419: not ready yet 2025-09-25 06:58:06,676 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6419, ip=192.168.168.219) 2025-09-25 06:58:10,395 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6419, ip=192.168.168.219, monitor=latest, size=6660546) 2025-09-25 06:58:14,857 [cuckoo.core.resultserver] DEBUG: Task #6999797: live log analysis.log initialized. 2025-09-25 06:58:14,859 [cuckoo.core.resultserver] DEBUG: Task #6999797 is sending a BSON stream 2025-09-25 06:58:14,900 [cuckoo.core.resultserver] DEBUG: Task #6999797 is sending a BSON stream 2025-09-25 06:58:14,922 [cuckoo.core.resultserver] DEBUG: Task #6999797: File upload for 'shots/0001.jpg' 2025-09-25 06:58:16,120 [cuckoo.core.resultserver] DEBUG: Task #6999797 uploaded file length: 133578 2025-09-25 06:58:16,622 [cuckoo.core.resultserver] DEBUG: Task #6999797: File upload for 'shots/0002.jpg' 2025-09-25 06:58:17,281 [cuckoo.core.resultserver] DEBUG: Task #6999797 uploaded file length: 136624 2025-09-25 06:58:28,232 [cuckoo.core.guest] DEBUG: win7x6419: analysis #6999797 still processing 2025-09-25 06:58:42,261 [cuckoo.core.resultserver] DEBUG: Task #6999797: File upload for 'curtain/1758567904.42.curtain.log' 2025-09-25 06:58:42,264 [cuckoo.core.resultserver] DEBUG: Task #6999797 uploaded file length: 36 2025-09-25 06:58:42,497 [cuckoo.core.resultserver] DEBUG: Task #6999797: File upload for 'sysmon/1758567904.66.sysmon.xml' 2025-09-25 06:58:42,530 [cuckoo.core.resultserver] DEBUG: Task #6999797 uploaded file length: 747482 2025-09-25 06:58:42,535 [cuckoo.core.resultserver] DEBUG: Task #6999797 had connection reset for <Context for LOG> 2025-09-25 06:58:43,336 [cuckoo.core.guest] INFO: win7x6419: analysis completed successfully 2025-09-25 06:58:43,353 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-09-25 06:58:43,384 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-09-25 06:58:45,579 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6419 to path /srv/cuckoo/cwd/storage/analyses/6999797/memory.dmp 2025-09-25 06:58:45,581 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6419 2025-09-25 07:02:12,219 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.219 for task #6999797 2025-09-25 07:02:14,270 [cuckoo.core.scheduler] DEBUG: Released database task #6999797 2025-09-25 07:02:24,464 [cuckoo.core.scheduler] INFO: Task #6999797: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
G Data Antivirus (Windows) | Virus: Trojan.Script.GenericKDZ.27055 (Engine A) |
Avast Core Security (Linux) | Script:SNH-gen [Trj] |
eScan Antivirus (Linux) | Trojan.Script.GenericKDZ.27055(DB) |
ESET Security (Windows) | HTML/ScrInject.B trojan |
Bitdefender Antivirus (Linux) | Trojan.Script.GenericKDZ.27055 |
Emsisoft Commandline Scanner (Windows) | Trojan.Script.GenericKDZ.27055 (B) |