Size | 39.9KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (1923), with CRLF, LF line terminators |
MD5 | d2552d56c8a44985012aab5ecb02f6ea |
SHA1 | 9cc49d6c2a7b08faaa1a230e13723010701c4f84 |
SHA256 | bf3b85a720af16dc1d20aca7eb52228b810d88539e7fd0415ccdc9d116f04d36 |
SHA512 |
7fe9d7bf7db0403600cbdf0d6eee30574e7767636241610e6c065a57f835567fef83862af952a37c44ffd22d24861b1af99a72a3a0f6fa52afcf06a3c28ade24
|
CRC32 | 464DE2D1 |
ssdeep | None |
Yara | None matched |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 14, 2025, 10:57 a.m. | April 14, 2025, 11:05 a.m. | 435 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-11 16:37:04,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpsgyfoe 2025-04-11 16:37:04,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\CBFqSBWrgxxuSASvEvEuPwF 2025-04-11 16:37:04,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\FbrXqpONyKSXLtuiDNiUfisC 2025-04-11 16:37:04,421 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-11 16:37:04,421 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-11 16:37:04,983 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-11 16:37:05,203 [analyzer] DEBUG: Loaded monitor into process with pid 516 2025-04-11 16:37:05,203 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-11 16:37:05,203 [analyzer] DEBUG: Started auxiliary module Human 2025-04-11 16:37:05,203 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-11 16:37:05,203 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-11 16:37:05,296 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-11 16:37:05,296 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-11 16:37:05,296 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-11 16:37:05,312 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-11 16:37:05,312 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-04-11 16:37:05,390 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\bf3b85a720af16dc1d20aca7eb52228b810d88539e7fd0415ccdc9d116f04d36.js'] and pid 2996 2025-04-11 16:37:05,625 [analyzer] DEBUG: Loaded monitor into process with pid 2996 2025-04-11 16:37:05,967 [analyzer] INFO: io=NULL 2025-04-11 16:37:05,967 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-11 16:37:05,967 [analyzer] INFO: io=NULL 2025-04-11 16:37:05,967 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-11 16:37:05,967 [analyzer] INFO: io=NULL 2025-04-11 16:37:05,967 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-11 16:37:06,015 [analyzer] INFO: io=NULL 2025-04-11 16:37:06,015 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-11 16:37:06,015 [analyzer] INFO: io=NULL 2025-04-11 16:37:06,015 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-11 16:37:06,015 [analyzer] INFO: io=NULL 2025-04-11 16:37:06,015 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-11 16:37:34,405 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-11 16:37:34,842 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-11 16:37:34,842 [lib.api.process] INFO: Successfully terminated process with pid 2996. 2025-04-11 16:37:34,842 [analyzer] INFO: Analysis completed.
2025-04-14 10:57:56,442 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:57:57,684 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:57:58,964 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:00,017 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:01,321 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:02,585 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:03,659 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:04,730 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:05,802 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:06,857 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:07,931 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:09,024 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:10,113 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:11,282 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:12,337 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:13,402 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:14,464 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:15,544 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:16,600 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:17,657 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:18,723 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:19,834 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:20,888 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:21,927 [cuckoo.core.scheduler] DEBUG: Task #6279679: no machine available yet 2025-04-14 10:58:23,211 [cuckoo.core.scheduler] INFO: Task #6279679: acquired machine win7x6413 (label=win7x6413) 2025-04-14 10:58:23,217 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.213 for task #6279679 2025-04-14 10:58:23,636 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1056640 (interface=vboxnet0, host=192.168.168.213) 2025-04-14 10:58:23,978 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6413 2025-04-14 10:58:24,777 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6413 to vmcloak 2025-04-14 11:01:34,586 [cuckoo.core.guest] INFO: Starting analysis #6279679 on guest (id=win7x6413, ip=192.168.168.213) 2025-04-14 11:01:35,600 [cuckoo.core.guest] DEBUG: win7x6413: not ready yet 2025-04-14 11:01:40,659 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6413, ip=192.168.168.213) 2025-04-14 11:01:40,730 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6413, ip=192.168.168.213, monitor=latest, size=6660546) 2025-04-14 11:01:42,073 [cuckoo.core.resultserver] DEBUG: Task #6279679: live log analysis.log initialized. 2025-04-14 11:01:43,402 [cuckoo.core.resultserver] DEBUG: Task #6279679 is sending a BSON stream 2025-04-14 11:01:43,541 [cuckoo.core.resultserver] DEBUG: Task #6279679 is sending a BSON stream 2025-04-14 11:01:44,551 [cuckoo.core.resultserver] DEBUG: Task #6279679: File upload for 'shots/0001.jpg' 2025-04-14 11:01:44,633 [cuckoo.core.resultserver] DEBUG: Task #6279679 uploaded file length: 133563 2025-04-14 11:01:45,722 [cuckoo.core.resultserver] DEBUG: Task #6279679: File upload for 'shots/0002.jpg' 2025-04-14 11:01:45,740 [cuckoo.core.resultserver] DEBUG: Task #6279679 uploaded file length: 136982 2025-04-14 11:01:56,815 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6279679 still processing 2025-04-14 11:02:12,657 [cuckoo.core.guest] DEBUG: win7x6413: analysis #6279679 still processing 2025-04-14 11:02:12,671 [cuckoo.core.resultserver] DEBUG: Task #6279679: File upload for 'curtain/1744382254.59.curtain.log' 2025-04-14 11:02:12,673 [cuckoo.core.resultserver] DEBUG: Task #6279679 uploaded file length: 36 2025-04-14 11:02:12,904 [cuckoo.core.resultserver] DEBUG: Task #6279679: File upload for 'sysmon/1744382254.83.sysmon.xml' 2025-04-14 11:02:12,925 [cuckoo.core.resultserver] DEBUG: Task #6279679 uploaded file length: 2235588 2025-04-14 11:02:13,468 [cuckoo.core.resultserver] DEBUG: Task #6279679: File upload for 'shots/0003.jpg' 2025-04-14 11:02:13,487 [cuckoo.core.resultserver] DEBUG: Task #6279679 uploaded file length: 133563 2025-04-14 11:02:13,499 [cuckoo.core.resultserver] DEBUG: Task #6279679 had connection reset for <Context for LOG> 2025-04-14 11:02:15,683 [cuckoo.core.guest] INFO: win7x6413: analysis completed successfully 2025-04-14 11:02:15,698 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-14 11:02:15,724 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-14 11:02:17,216 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6413 to path /srv/cuckoo/cwd/storage/analyses/6279679/memory.dmp 2025-04-14 11:02:17,221 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6413 2025-04-14 11:05:11,118 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.213 for task #6279679 2025-04-14 11:05:11,638 [cuckoo.core.scheduler] DEBUG: Released database task #6279679 2025-04-14 11:05:11,661 [cuckoo.core.scheduler] INFO: Task #6279679: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
G Data Antivirus (Windows) | Virus: HTML:Beluga.8535 (Engine A) |
eScan Antivirus (Linux) | HTML:Beluga.8535(DB) |
Bitdefender Antivirus (Linux) | HTML:Beluga.8535 |
Emsisoft Commandline Scanner (Windows) | HTML:Beluga.8535 (B) |