| URL |
|---|
| http://caucwifi-bhb.pages.dev/ja/apps/ios |
This url shows some signs of potential malicious behavior.
The score of this url is 1.9 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| URL | Nov. 12, 2025, 7:54 a.m. | Nov. 12, 2025, 8:01 a.m. | 431 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-11-08 19:30:50,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpmdfut4
2025-11-08 19:30:50,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\IkIMcrRSIWJhNmcSfGUxrqFdnFppja
2025-11-08 19:30:50,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\AdfrIUoqNSYAiFNHWn
2025-11-08 19:30:50,328 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-08 19:30:50,328 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-08 19:30:51,062 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-08 19:30:51,296 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-11-08 19:30:51,296 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-08 19:30:51,296 [analyzer] DEBUG: Started auxiliary module Human
2025-11-08 19:30:51,296 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-08 19:30:51,312 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-08 19:30:51,405 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-08 19:30:51,405 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-08 19:30:51,405 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-08 19:30:51,405 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-08 19:30:51,530 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['http://caucwifi-bhb.pages.dev/ja/apps/ios'] and pid 2820
2025-11-08 19:30:51,687 [analyzer] DEBUG: Loaded monitor into process with pid 2820
2025-11-08 19:30:53,171 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2820 CREDAT:275457 /prefetch:2!
2025-11-08 19:30:53,265 [analyzer] INFO: Injected into process with pid 2764 and name u'iexplore.exe'
2025-11-08 19:30:53,358 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2764.
2025-11-08 19:30:53,546 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0D74E7FD-BCD1-11F0-9D7E-3020D62C6363}.dat
2025-11-08 19:30:53,562 [analyzer] DEBUG: Loaded monitor into process with pid 2764
2025-11-08 19:30:53,608 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\~DF5636E3C2275E65BB.TMP
2025-11-08 19:30:53,828 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-11-08 19:30:53,828 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-11-08 19:30:53,828 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-11-08 19:30:53,828 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-11-08 19:30:53,828 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-11-08 19:30:53,828 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-11-08 19:30:53,842 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-11-08 19:30:53,842 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-11-08 19:30:53,842 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-11-08 19:30:53,842 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-11-08 19:30:53,842 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-11-08 19:30:53,842 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-11-08 19:30:53,842 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-11-08 19:30:53,842 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-11-08 19:30:54,250 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0D74E7FF-BCD1-11F0-9D7E-3020D62C6363}.dat
2025-11-08 19:30:54,280 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\~DFA30D6DD771D35681.TMP
2025-11-08 19:30:57,546 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2025-11-08 19:30:57,562 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2025-11-08 19:30:57,578 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabCC0F.tmp
2025-11-08 19:30:57,592 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarCC10.tmp
2025-11-08 19:30:57,717 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-11-08 19:30:57,717 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-11-08 19:30:57,733 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabCCBD.tmp
2025-11-08 19:30:57,750 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarCCBE.tmp
2025-11-08 19:30:57,921 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-11-08 19:30:57,921 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-11-08 19:30:57,983 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2025-11-08 19:30:57,983 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2025-11-08 19:30:58,030 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabCDD9.tmp
2025-11-08 19:30:58,030 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarCDDA.tmp
2025-11-08 19:30:58,515 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\ios[1].htm
2025-11-08 19:30:58,530 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-11-08 19:30:58,530 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-11-08 19:30:58,530 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-11-08 19:30:58,530 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-11-08 19:30:58,530 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-11-08 19:30:58,530 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-11-08 19:30:58,530 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-11-08 19:30:58,750 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9ZBKLLKU\main[1].css
2025-11-08 19:30:58,780 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z08S974F\speedtest-app-promo-1x[1].png
2025-11-08 19:30:58,796 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabD0E8.tmp
2025-11-08 19:30:58,812 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabD0EA.tmp
2025-11-08 19:30:58,842 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AA516T8O\ios-app-qr[1].svg
2025-11-08 19:30:58,858 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AA516T8O\mobile-dd[1].svg
2025-11-08 19:30:58,858 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AA516T8O\Download_on_the_App_Store_Badge_JP_RGB_blk_100317[1].svg
2025-11-08 19:30:58,858 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarD0E9.tmp
2025-11-08 19:30:58,858 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarD0EB.tmp
2025-11-08 19:30:58,875 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AA516T8O\main[1].js
2025-11-08 19:30:58,890 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\masthead-app-promo-android-1x[1].png
2025-11-08 19:30:58,905 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\mobile-hero-1x-ja[1].png
2025-11-08 19:30:58,921 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\mobile-video[1].svg
2025-11-08 19:30:58,983 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9ZBKLLKU\mobile-maps[1].svg
2025-11-08 19:30:59,000 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabD1B7.tmp
2025-11-08 19:30:59,015 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarD1B8.tmp
2025-11-08 19:30:59,015 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z08S974F\Montserrat-Bold-kern-latin[1].woff
2025-11-08 19:30:59,062 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabD1E8.tmp
2025-11-08 19:30:59,062 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarD1E9.tmp
2025-11-08 19:30:59,092 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabD209.tmp
2025-11-08 19:30:59,092 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9ZBKLLKU\Montserrat-Regular-kern-latin[1].woff
2025-11-08 19:30:59,108 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarD20A.tmp
2025-11-08 19:30:59,131 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabD23A.tmp
2025-11-08 19:30:59,140 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarD23B.tmp
2025-11-08 19:30:59,198 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z08S974F\diffuser[1].js
2025-11-08 19:30:59,250 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabD2A9.tmp
2025-11-08 19:30:59,265 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\CabD2BB.tmp
2025-11-08 19:30:59,265 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarD2BA.tmp
2025-11-08 19:30:59,269 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Temp\TarD2BC.tmp
2025-11-08 19:30:59,471 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_2DBE917624E9880FE0C7C5570D56E691
2025-11-08 19:30:59,471 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_2DBE917624E9880FE0C7C5570D56E691
2025-11-08 19:30:59,549 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3328_2908F682DFC81A793BD240CF29711C77
2025-11-08 19:30:59,565 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5080DC7A65DB6A5960ECD874088F3328_2908F682DFC81A793BD240CF29711C77
2025-11-08 19:30:59,612 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\zdconsent_eu[1].js
2025-11-08 19:30:59,862 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9ZBKLLKU\favicon[2].ico
2025-11-08 19:30:59,878 [analyzer] INFO: Added new file to list with pid 2764 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\imagestore\uv2m46n\imagestore.dat
2025-11-08 19:31:20,535 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-08 19:31:20,737 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2820.
2025-11-08 19:31:20,815 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2764.
2025-11-08 19:31:21,299 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-08 19:31:21,299 [lib.api.process] INFO: Successfully terminated process with pid 2820.
2025-11-08 19:31:21,299 [lib.api.process] INFO: Successfully terminated process with pid 2764.
2025-11-08 19:31:21,315 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd0e8.tmp' does not exist, skip.
2025-11-08 19:31:21,346 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dfa30d6dd771d35681.tmp' does not exist, skip.
2025-11-08 19:31:21,362 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard1e9.tmp' does not exist, skip.
2025-11-08 19:31:21,362 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd1b7.tmp' does not exist, skip.
2025-11-08 19:31:21,362 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd1e8.tmp' does not exist, skip.
2025-11-08 19:31:21,362 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabccbd.tmp' does not exist, skip.
2025-11-08 19:31:21,378 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd23a.tmp' does not exist, skip.
2025-11-08 19:31:21,378 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcc0f.tmp' does not exist, skip.
2025-11-08 19:31:21,378 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard0e9.tmp' does not exist, skip.
2025-11-08 19:31:21,378 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd209.tmp' does not exist, skip.
2025-11-08 19:31:21,394 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd0ea.tmp' does not exist, skip.
2025-11-08 19:31:21,410 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard23b.tmp' does not exist, skip.
2025-11-08 19:31:21,410 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard1b8.tmp' does not exist, skip.
2025-11-08 19:31:21,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard2bc.tmp' does not exist, skip.
2025-11-08 19:31:21,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd2bb.tmp' does not exist, skip.
2025-11-08 19:31:21,424 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df5636e3c2275e65bb.tmp' does not exist, skip.
2025-11-08 19:31:21,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard0eb.tmp' does not exist, skip.
2025-11-08 19:31:21,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcc10.tmp' does not exist, skip.
2025-11-08 19:31:21,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcdd9.tmp' does not exist, skip.
2025-11-08 19:31:21,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcdda.tmp' does not exist, skip.
2025-11-08 19:31:21,471 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard20a.tmp' does not exist, skip.
2025-11-08 19:31:21,471 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard2ba.tmp' does not exist, skip.
2025-11-08 19:31:21,471 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd2a9.tmp' does not exist, skip.
2025-11-08 19:31:21,471 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarccbe.tmp' does not exist, skip.
2025-11-08 19:31:21,487 [analyzer] INFO: Analysis completed.
2025-11-12 07:54:08,997 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:10,039 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:11,087 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:12,134 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:13,188 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:14,240 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:15,288 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:16,393 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:17,440 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:18,505 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:19,578 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:20,643 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:21,704 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:22,771 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:23,843 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:24,914 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:26,022 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:27,109 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:28,216 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:29,312 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:30,413 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:31,534 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:32,785 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:33,964 [cuckoo.core.scheduler] DEBUG: Task #7120862: no machine available yet
2025-11-12 07:54:35,031 [cuckoo.core.scheduler] INFO: Task #7120862: acquired machine win7x644 (label=win7x644)
2025-11-12 07:54:35,032 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.204 for task #7120862
2025-11-12 07:54:35,221 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2942520 (interface=vboxnet0, host=192.168.168.204)
2025-11-12 07:54:35,553 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x644
2025-11-12 07:54:36,583 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x644 to vmcloak
2025-11-12 07:57:28,458 [cuckoo.core.guest] INFO: Starting analysis #7120862 on guest (id=win7x644, ip=192.168.168.204)
2025-11-12 07:57:29,463 [cuckoo.core.guest] DEBUG: win7x644: not ready yet
2025-11-12 07:57:34,495 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x644, ip=192.168.168.204)
2025-11-12 07:57:34,661 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x644, ip=192.168.168.204, monitor=latest, size=6660546)
2025-11-12 07:57:36,126 [cuckoo.core.resultserver] DEBUG: Task #7120862: live log analysis.log initialized.
2025-11-12 07:57:37,372 [cuckoo.core.resultserver] DEBUG: Task #7120862 is sending a BSON stream
2025-11-12 07:57:37,759 [cuckoo.core.resultserver] DEBUG: Task #7120862 is sending a BSON stream
2025-11-12 07:57:38,661 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'shots/0001.jpg'
2025-11-12 07:57:38,678 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 133492
2025-11-12 07:57:39,636 [cuckoo.core.resultserver] DEBUG: Task #7120862 is sending a BSON stream
2025-11-12 07:57:40,782 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'shots/0002.jpg'
2025-11-12 07:57:40,785 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 24534
2025-11-12 07:57:41,865 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'shots/0003.jpg'
2025-11-12 07:57:41,868 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 30319
2025-11-12 07:57:42,975 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'shots/0004.jpg'
2025-11-12 07:57:42,978 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 30426
2025-11-12 07:57:45,124 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'shots/0005.jpg'
2025-11-12 07:57:45,131 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 30492
2025-11-12 07:57:46,225 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'shots/0006.jpg'
2025-11-12 07:57:46,235 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 93798
2025-11-12 07:57:50,803 [cuckoo.core.guest] DEBUG: win7x644: analysis #7120862 still processing
2025-11-12 07:58:06,180 [cuckoo.core.guest] DEBUG: win7x644: analysis #7120862 still processing
2025-11-12 07:58:07,342 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'curtain/1762626680.94.curtain.log'
2025-11-12 07:58:07,376 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 36
2025-11-12 07:58:07,386 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'sysmon/1762626681.17.sysmon.xml'
2025-11-12 07:58:07,432 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 2222694
2025-11-12 07:58:07,440 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/835ed515deb70a3d_{0d74e7ff-bcd1-11f0-9d7e-3020d62c6363}.dat'
2025-11-12 07:58:07,442 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 5632
2025-11-12 07:58:07,450 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/e3b5bd8fa5ddaeae_montserrat-bold-kern-latin[1].woff'
2025-11-12 07:58:07,457 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 16016
2025-11-12 07:58:07,478 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/20de1196d25a39a5_zdconsent_eu[1].js'
2025-11-12 07:58:07,481 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 84242
2025-11-12 07:58:07,487 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3'
2025-11-12 07:58:07,489 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 889
2025-11-12 07:58:07,492 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/bd3bd35dd6f46aed_b2faf7692fd9ffbd64ede317e42334ba_2dbe917624e9880fe0c7c5570d56e691'
2025-11-12 07:58:07,494 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 1453
2025-11-12 07:58:07,496 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/c4d751dbb2f2842a_mobile-maps[1].svg'
2025-11-12 07:58:07,498 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 872
2025-11-12 07:58:07,500 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/18b3666e90e95477_14232b434cf29d4c4fb335a86d7fffe3'
2025-11-12 07:58:07,502 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 170
2025-11-12 07:58:07,504 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/5894798ec5249426_b46811c17859ffb409cf0e904a4aa8f8'
2025-11-12 07:58:07,506 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 170
2025-11-12 07:58:07,509 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/f8e33f36effeb0e1_speedtest-app-promo-1x[1].png'
2025-11-12 07:58:07,511 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 30167
2025-11-12 07:58:07,514 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/0f15b91fd0faab0e_5080dc7a65db6a5960ecd874088f3328_2908f682dfc81a793bd240cf29711c77'
2025-11-12 07:58:07,516 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 2232
2025-11-12 07:58:07,519 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/0f71708dbfee304a_8b2b9a00839eed1dfdccc3bfc2f5df12'
2025-11-12 07:58:07,521 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 1739
2025-11-12 07:58:07,523 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/6e824d6aedb0e42d_5080dc7a65db6a5960ecd874088f3328_2908f682dfc81a793bd240cf29711c77'
2025-11-12 07:58:07,525 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 490
2025-11-12 07:58:07,528 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/90c4a72bdf15f760_main[1].js'
2025-11-12 07:58:07,531 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 155344
2025-11-12 07:58:07,533 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/09d10d2bdc1f7f7e_montserrat-regular-kern-latin[1].woff'
2025-11-12 07:58:07,535 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 15916
2025-11-12 07:58:07,538 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/2896dffaaefcd6c5_mobile-dd[1].svg'
2025-11-12 07:58:07,540 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 2071
2025-11-12 07:58:07,542 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/864bbaab9db5147e_diffuser[1].js'
2025-11-12 07:58:07,544 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 33374
2025-11-12 07:58:07,548 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/450cfe56562dc717_ios-app-qr[1].svg'
2025-11-12 07:58:07,551 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 279790
2025-11-12 07:58:07,554 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/45c8513d4669fcf0_mobile-hero-1x-ja[1].png'
2025-11-12 07:58:07,555 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 40482
2025-11-12 07:58:07,559 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/a45589c7fa9402fa_main[1].css'
2025-11-12 07:58:07,562 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 257649
2025-11-12 07:58:07,564 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/864f89a86e00a6db_mobile-video[1].svg'
2025-11-12 07:58:07,587 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 585
2025-11-12 07:58:07,598 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/4a886ab353a90963_ios[1].htm'
2025-11-12 07:58:07,603 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 71698
2025-11-12 07:58:07,604 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/f55f5ec027eee793_8b2b9a00839eed1dfdccc3bfc2f5df12'
2025-11-12 07:58:07,605 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 174
2025-11-12 07:58:07,606 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/33ba8221ff3f5211_94308059b57b3142e455b38a6eb92015'
2025-11-12 07:58:07,608 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 73211
2025-11-12 07:58:07,609 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8'
2025-11-12 07:58:07,611 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 530
2025-11-12 07:58:07,612 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/8a49f1680c4b465f_imagestore.dat'
2025-11-12 07:58:07,613 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 1693
2025-11-12 07:58:07,614 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/c478356af85478f8_download_on_the_app_store_badge_jp_rgb_blk_100317[1].svg'
2025-11-12 07:58:07,616 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 6984
2025-11-12 07:58:07,617 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/92d45a8940b67251_b2faf7692fd9ffbd64ede317e42334ba_2dbe917624e9880fe0c7c5570d56e691'
2025-11-12 07:58:07,619 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 486
2025-11-12 07:58:07,620 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/a50ab7ec601cecfb_recoverystore.{0d74e7fd-bcd1-11f0-9d7e-3020d62c6363}.dat'
2025-11-12 07:58:07,622 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 5632
2025-11-12 07:58:07,627 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/260055fd6eda3dc6_94308059b57b3142e455b38a6eb92015'
2025-11-12 07:58:07,629 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 344
2025-11-12 07:58:07,630 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/f1a0f764c6440d24_favicon[2].ico'
2025-11-12 07:58:07,632 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 1150
2025-11-12 07:58:07,633 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'files/7b2669736565cf35_masthead-app-promo-android-1x[1].png'
2025-11-12 07:58:07,635 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 29513
2025-11-12 07:58:07,892 [cuckoo.core.resultserver] DEBUG: Task #7120862: File upload for 'shots/0007.jpg'
2025-11-12 07:58:07,903 [cuckoo.core.resultserver] DEBUG: Task #7120862 uploaded file length: 133483
2025-11-12 07:58:07,918 [cuckoo.core.resultserver] DEBUG: Task #7120862 had connection reset for <Context for LOG>
2025-11-12 07:58:09,206 [cuckoo.core.guest] INFO: win7x644: analysis completed successfully
2025-11-12 07:58:09,218 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-11-12 07:58:09,254 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-11-12 07:58:09,965 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x644 to path /srv/cuckoo/cwd/storage/analyses/7120862/memory.dmp
2025-11-12 07:58:09,967 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x644
2025-11-12 08:01:19,780 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.204 for task #7120862
2025-11-12 08:01:20,479 [cuckoo.core.scheduler] DEBUG: Released database task #7120862
2025-11-12 08:01:20,507 [cuckoo.core.scheduler] INFO: Task #7120862: analysis procedure completed
| file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z08S974F\diffuser[1].js |
| file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AA516T8O\main[1].js |
| file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BSBWJJLE\zdconsent_eu[1].js |
| cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2820 CREDAT:275457 /prefetch:2 |
| snort | ET INFO DNS Query to Cloudflare Page Developer Domain (pages .dev) |
| snort | ET INFO Observed Cloudflare Page Developer Domain (pages .dev in TLS SNI) |