Size | 134.3KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (11895), with CRLF, LF line terminators |
MD5 | 9d172461a66311e408ccfed1dbbbd257 |
SHA1 | 05b6208e8e125c07130de528671afdbd087d60c2 |
SHA256 | d459be044faed50614f2f47932675d366a56a5b22546dac27296375b560602d8 |
SHA512 |
b823f91f9963f5de9ef93aa29ddce2724452bcc5516e07cd06132d17ed494a32df2d4790b13ebde03b7bb6a062779617ad25d95ffb141a259a1785a0bf4eaf94
|
CRC32 | 5AF9A4DB |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 20, 2025, 12:32 a.m. | April 20, 2025, 12:41 a.m. | 535 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-19 16:05:05,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpj6atou 2025-04-19 16:05:05,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\XRCPyImMNOjZkTsGqGzzgpymiY 2025-04-19 16:05:05,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\UAFUQwVtmRqAXdWzq 2025-04-19 16:05:05,312 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-19 16:05:05,312 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-19 16:05:05,842 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-19 16:05:06,062 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-04-19 16:05:06,062 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-19 16:05:06,062 [analyzer] DEBUG: Started auxiliary module Human 2025-04-19 16:05:06,078 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-19 16:05:06,078 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-19 16:05:06,155 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-19 16:05:06,155 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-19 16:05:06,155 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-19 16:05:06,155 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-19 16:05:06,155 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-04-19 16:05:06,233 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\d459be044faed50614f2f47932675d366a56a5b22546dac27296375b560602d8.js'] and pid 1248 2025-04-19 16:05:06,453 [analyzer] DEBUG: Loaded monitor into process with pid 1248 2025-04-19 16:05:06,858 [analyzer] INFO: io=NULL 2025-04-19 16:05:06,858 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-19 16:05:06,858 [analyzer] INFO: io=NULL 2025-04-19 16:05:06,875 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-19 16:05:06,875 [analyzer] INFO: io=NULL 2025-04-19 16:05:06,875 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-19 16:05:06,921 [analyzer] INFO: io=NULL 2025-04-19 16:05:06,921 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-19 16:05:06,921 [analyzer] INFO: io=NULL 2025-04-19 16:05:06,921 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-19 16:05:06,921 [analyzer] INFO: io=NULL 2025-04-19 16:05:06,921 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-19 23:38:39,680 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-19 23:38:40,180 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-19 23:38:40,194 [lib.api.process] INFO: Successfully terminated process with pid 1248. 2025-04-19 23:38:40,194 [analyzer] INFO: Analysis completed.
2025-04-20 00:33:05,101 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:06,378 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:07,453 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:08,493 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:09,539 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:10,583 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:11,616 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:12,656 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:13,691 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:14,750 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:15,931 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:17,009 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:18,083 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:19,148 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:20,216 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:21,275 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:22,347 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:23,411 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:24,463 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:25,548 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:26,604 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:27,644 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:28,684 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:29,715 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:30,754 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:31,817 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:33,059 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:34,117 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:35,454 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:36,505 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:37,548 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:38,598 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:39,621 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:40,643 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:41,662 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:42,679 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:43,698 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:44,718 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:45,803 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:46,856 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:47,899 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:48,954 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:50,015 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:51,588 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:52,668 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:54,190 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:55,244 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:56,346 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:57,365 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:58,389 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:33:59,409 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:00,446 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:01,474 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:02,516 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:03,535 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:04,572 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:05,644 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:06,710 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:07,988 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:09,044 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:10,127 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:11,199 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:12,265 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:13,351 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:14,871 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:15,948 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:17,010 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:18,055 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:19,133 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:20,192 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:21,260 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:22,317 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:23,390 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:24,645 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:25,735 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:26,804 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:27,890 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:28,964 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:30,234 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:31,296 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:32,375 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:33,445 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:34,519 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:35,563 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:36,885 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:37,954 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:39,016 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:40,070 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:41,170 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:42,357 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:43,401 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:44,493 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:45,545 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:46,588 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:47,627 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:48,819 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:49,899 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:51,151 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:52,417 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:53,475 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:54,544 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:55,612 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:56,661 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:57,699 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:34:59,022 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:00,329 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:01,805 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:03,003 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:04,030 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:05,052 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:06,080 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:07,288 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:08,433 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:09,681 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:10,822 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:11,875 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:13,021 [cuckoo.core.scheduler] DEBUG: Task #6302218: no machine available yet 2025-04-20 00:35:14,325 [cuckoo.core.scheduler] INFO: Task #6302218: acquired machine win7x6416 (label=win7x6416) 2025-04-20 00:35:14,337 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.216 for task #6302218 2025-04-20 00:35:15,038 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 861144 (interface=vboxnet0, host=192.168.168.216) 2025-04-20 00:35:15,588 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6416 2025-04-20 00:35:16,510 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6416 to vmcloak 2025-04-20 00:38:01,450 [cuckoo.core.guest] INFO: Starting analysis #6302218 on guest (id=win7x6416, ip=192.168.168.216) 2025-04-20 00:38:02,454 [cuckoo.core.guest] DEBUG: win7x6416: not ready yet 2025-04-20 00:38:07,739 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6416, ip=192.168.168.216) 2025-04-20 00:38:07,867 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6416, ip=192.168.168.216, monitor=latest, size=6660546) 2025-04-20 00:38:09,366 [cuckoo.core.resultserver] DEBUG: Task #6302218: live log analysis.log initialized. 2025-04-20 00:38:10,383 [cuckoo.core.resultserver] DEBUG: Task #6302218 is sending a BSON stream 2025-04-20 00:38:10,697 [cuckoo.core.resultserver] DEBUG: Task #6302218 is sending a BSON stream 2025-04-20 00:38:11,680 [cuckoo.core.resultserver] DEBUG: Task #6302218: File upload for 'shots/0001.jpg' 2025-04-20 00:38:11,699 [cuckoo.core.resultserver] DEBUG: Task #6302218 uploaded file length: 133567 2025-04-20 00:38:12,822 [cuckoo.core.resultserver] DEBUG: Task #6302218: File upload for 'shots/0002.jpg' 2025-04-20 00:38:12,837 [cuckoo.core.resultserver] DEBUG: Task #6302218 uploaded file length: 137014 2025-04-20 00:38:24,118 [cuckoo.core.guest] DEBUG: win7x6416: analysis #6302218 still processing 2025-04-20 00:38:39,208 [cuckoo.core.guest] DEBUG: win7x6416: analysis #6302218 still processing 2025-04-20 00:38:39,962 [cuckoo.core.resultserver] DEBUG: Task #6302218: File upload for 'curtain/1745098719.94.curtain.log' 2025-04-20 00:38:39,978 [cuckoo.core.resultserver] DEBUG: Task #6302218 uploaded file length: 36 2025-04-20 00:38:40,181 [cuckoo.core.resultserver] DEBUG: Task #6302218: File upload for 'sysmon/1745098720.18.sysmon.xml' 2025-04-20 00:38:40,192 [cuckoo.core.resultserver] DEBUG: Task #6302218 uploaded file length: 1120568 2025-04-20 00:38:40,815 [cuckoo.core.resultserver] DEBUG: Task #6302218: File upload for 'shots/0003.jpg' 2025-04-20 00:38:40,830 [cuckoo.core.resultserver] DEBUG: Task #6302218 uploaded file length: 133593 2025-04-20 00:38:40,843 [cuckoo.core.resultserver] DEBUG: Task #6302218 had connection reset for <Context for LOG> 2025-04-20 00:38:42,225 [cuckoo.core.guest] INFO: win7x6416: analysis completed successfully 2025-04-20 00:38:42,240 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-20 00:38:42,263 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-20 00:38:43,397 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6416 to path /srv/cuckoo/cwd/storage/analyses/6302218/memory.dmp 2025-04-20 00:38:43,399 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6416 2025-04-20 00:41:49,518 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.216 for task #6302218 2025-04-20 00:41:50,497 [cuckoo.core.scheduler] DEBUG: Released database task #6302218 2025-04-20 00:41:50,548 [cuckoo.core.scheduler] INFO: Task #6302218: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
G Data Antivirus (Windows) | Virus: Trojan.GenericKD.76254891 (Engine A) |
eScan Antivirus (Linux) | Trojan.GenericKD.76254891(DB) |
ESET Security (Windows) | JS/Agent.RCS trojan |
Sophos Anti-Virus (Linux) | Troj/JSInject-V |
Bitdefender Antivirus (Linux) | Trojan.GenericKD.76254891 |
ESET-NOD32 | JS/Agent.RCS |
Zillya | Trojan.Agent.JS.55 |
Sophos | Troj/JSInject-V |
Detected | |
ZoneAlarm | Troj/JSInject-V |
Tencent | Trojan.JS.Agent.500715h |
Fortinet | JS/Agent.RCW!tr |