| Size | 4.7KB |
|---|---|
| Type | HTML document, Unicode text, UTF-8 text, with very long lines (331) |
| MD5 | 1675783e6e2c5fca82b062dd6e83d82a |
| SHA1 | 21081992501dc64a2b72f1a252288697052bc9d9 |
| SHA256 | 2220cf703763d64e36bcc8a4fa082d8b6ed4c3ca7c6ecaccf8983ca4cc67d7ea |
| SHA512 |
b5fba163eda5f406f3abd6725cea18b2e5576fdcc7e3709f1f96f9073e1c82c025e9b772a9dccc865f80099c547ccfb47b66708151ec0acf4a91c79fd33f1f80
|
| CRC32 | 3E2A9073 |
| ssdeep | None |
| Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Jan. 12, 2026, 4:01 a.m. | Jan. 12, 2026, 4:07 a.m. | 361 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-01-11 08:56:28,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpsgyfoe
2026-01-11 08:56:28,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\cdMzvdAgVgCbyzHiboA
2026-01-11 08:56:28,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\KRECRWYKkNfSlIUEnoeFauXDZxKLX
2026-01-11 08:56:28,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2026-01-11 08:56:28,015 [analyzer] INFO: Automatically selected analysis package "ie"
2026-01-11 08:56:28,233 [analyzer] DEBUG: Started auxiliary module Curtain
2026-01-11 08:56:28,233 [analyzer] DEBUG: Started auxiliary module DbgView
2026-01-11 08:56:28,687 [analyzer] DEBUG: Started auxiliary module Disguise
2026-01-11 08:56:28,890 [analyzer] DEBUG: Loaded monitor into process with pid 516
2026-01-11 08:56:28,890 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2026-01-11 08:56:28,890 [analyzer] DEBUG: Started auxiliary module Human
2026-01-11 08:56:28,890 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2026-01-11 08:56:28,890 [analyzer] DEBUG: Started auxiliary module Reboot
2026-01-11 08:56:28,953 [analyzer] DEBUG: Started auxiliary module RecentFiles
2026-01-11 08:56:28,967 [analyzer] DEBUG: Started auxiliary module Screenshots
2026-01-11 08:56:28,967 [analyzer] DEBUG: Started auxiliary module Sysmon
2026-01-11 08:56:28,967 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2026-01-11 08:56:28,967 [modules.packages.ie] INFO: Submitted file is missing extension, adding .html
2026-01-11 08:56:29,078 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2220cf703763d64e36bcc8a4fa082d8b6ed4c3ca7c6ecaccf8983ca4cc67d7ea.html'] and pid 1768
2026-01-11 08:56:29,233 [analyzer] DEBUG: Loaded monitor into process with pid 1768
2026-01-11 08:56:30,858 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1768 CREDAT:275457 /prefetch:2!
2026-01-11 08:56:30,937 [analyzer] INFO: Injected into process with pid 604 and name u'iexplore.exe'
2026-01-11 08:56:31,015 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 604.
2026-01-11 08:56:31,125 [analyzer] INFO: Added new file to list with pid 1768 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{08DDEF63-EEC3-11F0-B6CB-E83752CEA8EC}.dat
2026-01-11 08:56:31,171 [analyzer] INFO: Added new file to list with pid 1768 and path C:\Users\Administrator\AppData\Local\Temp\~DFFFD24E8386F7B040.TMP
2026-01-11 08:56:31,187 [analyzer] DEBUG: Loaded monitor into process with pid 604
2026-01-11 08:56:31,405 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-01-11 08:56:31,421 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-01-11 08:56:31,421 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-01-11 08:56:31,421 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-01-11 08:56:31,421 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-01-11 08:56:31,421 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-01-11 08:56:31,421 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-01-11 08:56:31,421 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-01-11 08:56:31,437 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-01-11 08:56:31,437 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-01-11 08:56:31,437 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-01-11 08:56:31,437 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-01-11 08:56:31,437 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-01-11 08:56:31,437 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-01-11 08:56:31,780 [analyzer] INFO: Added new file to list with pid 1768 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{08DDEF65-EEC3-11F0-B6CB-E83752CEA8EC}.dat
2026-01-11 08:56:31,812 [analyzer] INFO: Added new file to list with pid 1768 and path C:\Users\Administrator\AppData\Local\Temp\~DF74F34DFBB96488BF.TMP
2026-01-11 08:56:31,875 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-01-11 08:56:31,875 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-01-11 08:56:31,875 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-01-11 08:56:31,875 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-01-11 08:56:31,875 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-01-11 08:56:31,875 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-01-11 08:56:31,875 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-01-11 08:56:34,905 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2026-01-11 08:56:34,905 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2026-01-11 08:56:34,937 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFDFF.tmp
2026-01-11 08:56:34,937 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFDFE.tmp
2026-01-11 08:56:34,937 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFE00.tmp
2026-01-11 08:56:34,953 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFE01.tmp
2026-01-11 08:56:34,953 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFE12.tmp
2026-01-11 08:56:34,953 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFE22.tmp
2026-01-11 08:56:34,967 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFE23.tmp
2026-01-11 08:56:34,967 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFE24.tmp
2026-01-11 08:56:35,062 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFE83.tmp
2026-01-11 08:56:35,062 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFE84.tmp
2026-01-11 08:56:35,108 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2026-01-11 08:56:35,108 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2026-01-11 08:56:35,125 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFED3.tmp
2026-01-11 08:56:35,140 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFED4.tmp
2026-01-11 08:56:35,140 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFEE5.tmp
2026-01-11 08:56:35,140 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFEE6.tmp
2026-01-11 08:56:35,171 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFEF6.tmp
2026-01-11 08:56:35,171 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\CabFF08.tmp
2026-01-11 08:56:35,171 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFF07.tmp
2026-01-11 08:56:35,171 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\TarFF09.tmp
2026-01-11 08:56:35,358 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2026-01-11 08:56:35,358 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2026-01-11 08:56:35,437 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2026-01-11 08:56:35,437 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2026-01-11 08:56:35,467 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\Cab33.tmp
2026-01-11 08:56:35,483 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Temp\Tar34.tmp
2026-01-11 08:56:35,780 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C68VKH1C\vendor[1].css
2026-01-11 08:56:35,858 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PCUP2C46\girl[1].jpg
2026-01-11 08:56:35,890 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PCUP2C46\vendor[1].js
2026-01-11 08:56:35,937 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PCUP2C46\fp.v3[1].js
2026-01-11 08:56:36,108 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199
2026-01-11 08:56:36,108 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199
2026-01-11 08:56:36,203 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3513D73A177A2707D910183759B389B_599209EAB8E3D2235736F827CC0ED73A
2026-01-11 08:56:36,203 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3513D73A177A2707D910183759B389B_599209EAB8E3D2235736F827CC0ED73A
2026-01-11 08:56:36,483 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6DA548C7E5915679F87E910D6581DEF1_99C0BCCB9531DB01BDAD6B285F1D8DF1
2026-01-11 08:56:36,500 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6DA548C7E5915679F87E910D6581DEF1_99C0BCCB9531DB01BDAD6B285F1D8DF1
2026-01-11 08:56:36,546 [analyzer] INFO: Added new file to list with pid 604 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1LK710WS\triangle[1].svg
2026-01-11 08:56:58,078 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2026-01-11 08:56:58,500 [analyzer] INFO: Terminating remaining processes before shutdown.
2026-01-11 08:56:58,500 [lib.api.process] INFO: Successfully terminated process with pid 1768.
2026-01-11 08:56:58,500 [lib.api.process] INFO: Successfully terminated process with pid 604.
2026-01-11 08:56:58,500 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfed3.tmp' does not exist, skip.
2026-01-11 08:56:58,515 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfe00.tmp' does not exist, skip.
2026-01-11 08:56:58,515 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfef6.tmp' does not exist, skip.
2026-01-11 08:56:58,515 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfe84.tmp' does not exist, skip.
2026-01-11 08:56:58,515 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfe83.tmp' does not exist, skip.
2026-01-11 08:56:58,530 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabff08.tmp' does not exist, skip.
2026-01-11 08:56:58,562 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarff09.tmp' does not exist, skip.
2026-01-11 08:56:58,562 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfe01.tmp' does not exist, skip.
2026-01-11 08:56:58,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfee6.tmp' does not exist, skip.
2026-01-11 08:56:58,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfdff.tmp' does not exist, skip.
2026-01-11 08:56:58,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dfffd24e8386f7b040.tmp' does not exist, skip.
2026-01-11 08:56:58,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfe22.tmp' does not exist, skip.
2026-01-11 08:56:58,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfe24.tmp' does not exist, skip.
2026-01-11 08:56:58,592 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df74f34dfbb96488bf.tmp' does not exist, skip.
2026-01-11 08:56:58,592 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarfed4.tmp' does not exist, skip.
2026-01-11 08:56:58,592 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab33.tmp' does not exist, skip.
2026-01-11 08:56:58,592 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfe12.tmp' does not exist, skip.
2026-01-11 08:56:58,592 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar34.tmp' does not exist, skip.
2026-01-11 08:56:58,608 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfe23.tmp' does not exist, skip.
2026-01-11 08:56:58,608 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarff07.tmp' does not exist, skip.
2026-01-11 08:56:58,625 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfdfe.tmp' does not exist, skip.
2026-01-11 08:56:58,640 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabfee5.tmp' does not exist, skip.
2026-01-11 08:56:58,640 [analyzer] INFO: Analysis completed.
2026-01-12 04:02:04,470 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:05,506 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:06,671 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:07,774 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:08,814 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:09,834 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:10,855 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:11,871 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:12,887 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:13,931 [cuckoo.core.scheduler] DEBUG: Task #7290196: no machine available yet
2026-01-12 04:02:14,990 [cuckoo.core.scheduler] INFO: Task #7290196: acquired machine win7x6413 (label=win7x6413)
2026-01-12 04:02:14,991 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.213 for task #7290196
2026-01-12 04:02:15,454 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1274148 (interface=vboxnet0, host=192.168.168.213)
2026-01-12 04:02:15,687 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6413
2026-01-12 04:02:16,764 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6413 to vmcloak
2026-01-12 04:04:29,566 [cuckoo.core.guest] INFO: Starting analysis #7290196 on guest (id=win7x6413, ip=192.168.168.213)
2026-01-12 04:04:30,575 [cuckoo.core.guest] DEBUG: win7x6413: not ready yet
2026-01-12 04:04:35,686 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6413, ip=192.168.168.213)
2026-01-12 04:04:35,896 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6413, ip=192.168.168.213, monitor=latest, size=6660546)
2026-01-12 04:04:37,202 [cuckoo.core.resultserver] DEBUG: Task #7290196: live log analysis.log initialized.
2026-01-12 04:04:38,082 [cuckoo.core.resultserver] DEBUG: Task #7290196 is sending a BSON stream
2026-01-12 04:04:38,414 [cuckoo.core.resultserver] DEBUG: Task #7290196 is sending a BSON stream
2026-01-12 04:04:39,319 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'shots/0001.jpg'
2026-01-12 04:04:39,335 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 133570
2026-01-12 04:04:40,365 [cuckoo.core.resultserver] DEBUG: Task #7290196 is sending a BSON stream
2026-01-12 04:04:41,470 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'shots/0002.jpg'
2026-01-12 04:04:41,477 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 24496
2026-01-12 04:04:42,555 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'shots/0003.jpg'
2026-01-12 04:04:42,557 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 31702
2026-01-12 04:04:45,716 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'shots/0004.jpg'
2026-01-12 04:04:45,751 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 34318
2026-01-12 04:04:46,942 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'shots/0005.jpg'
2026-01-12 04:04:46,952 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 99645
2026-01-12 04:04:52,153 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7290196 still processing
2026-01-12 04:05:07,421 [cuckoo.core.guest] DEBUG: win7x6413: analysis #7290196 still processing
2026-01-12 04:05:07,502 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'curtain/1768118218.25.curtain.log'
2026-01-12 04:05:07,505 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 36
2026-01-12 04:05:07,718 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'sysmon/1768118218.47.sysmon.xml'
2026-01-12 04:05:07,748 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 2072104
2026-01-12 04:05:07,759 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/a341c76c97d73331_girl[1].jpg'
2026-01-12 04:05:07,764 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 156612
2026-01-12 04:05:07,766 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3'
2026-01-12 04:05:07,768 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 889
2026-01-12 04:05:07,773 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/fd61e74b2e64ddf6_14232b434cf29d4c4fb335a86d7fffe3'
2026-01-12 04:05:07,775 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 170
2026-01-12 04:05:07,796 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/6d33fe768fc3c193_b46811c17859ffb409cf0e904a4aa8f8'
2026-01-12 04:05:07,798 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 170
2026-01-12 04:05:07,800 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/9aa12d141f3c4162_fp.v3[1].js'
2026-01-12 04:05:07,802 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 40104
2026-01-12 04:05:07,810 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/645778a1770b6a0b_b3513d73a177a2707d910183759b389b_599209eab8e3d2235736f827cc0ed73a'
2026-01-12 04:05:07,812 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 398
2026-01-12 04:05:07,815 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/f20283a1330933b9_05ddc6aa91765aacacdb0a5f96df8199'
2026-01-12 04:05:07,817 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 170
2026-01-12 04:05:07,820 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/364258e1672bcb94_vendor[1].js'
2026-01-12 04:05:07,822 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 100254
2026-01-12 04:05:07,826 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8'
2026-01-12 04:05:07,827 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 530
2026-01-12 04:05:07,830 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/8d4302df78db06e6_6da548c7e5915679f87e910d6581def1_99c0bccb9531db01bdad6b285f1d8df1'
2026-01-12 04:05:07,832 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 471
2026-01-12 04:05:07,835 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/70361fc5bd4a7fbf_8b2b9a00839eed1dfdccc3bfc2f5df12'
2026-01-12 04:05:07,837 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 1739
2026-01-12 04:05:07,839 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/e5c3bb7dd890070b_recoverystore.{08ddef63-eec3-11f0-b6cb-e83752cea8ec}.dat'
2026-01-12 04:05:07,840 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 5632
2026-01-12 04:05:07,844 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/4c7e62cb9ddf9262_triangle[1].svg'
2026-01-12 04:05:07,846 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 296
2026-01-12 04:05:07,850 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/d230813b83845840_8b2b9a00839eed1dfdccc3bfc2f5df12'
2026-01-12 04:05:07,852 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 174
2026-01-12 04:05:07,855 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/33ba8221ff3f5211_94308059b57b3142e455b38a6eb92015'
2026-01-12 04:05:07,858 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 73211
2026-01-12 04:05:07,862 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/eac173f6aa2de93a_05ddc6aa91765aacacdb0a5f96df8199'
2026-01-12 04:05:07,864 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 993
2026-01-12 04:05:07,866 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/404537bcb6ec82f2_{08ddef65-eec3-11f0-b6cb-e83752cea8ec}.dat'
2026-01-12 04:05:07,868 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 5120
2026-01-12 04:05:07,871 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/f0f791c727bc57c2_94308059b57b3142e455b38a6eb92015'
2026-01-12 04:05:07,873 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 344
2026-01-12 04:05:07,876 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/c1c471427cfe2bfe_vendor[1].css'
2026-01-12 04:05:07,878 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 9741
2026-01-12 04:05:07,881 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/f8f8a4a1c6c5fcb6_b3513d73a177a2707d910183759b389b_599209eab8e3d2235736f827cc0ed73a'
2026-01-12 04:05:07,883 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 472
2026-01-12 04:05:07,886 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'files/76e3b1892d52bf01_6da548c7e5915679f87e910d6581def1_99c0bccb9531db01bdad6b285f1d8df1'
2026-01-12 04:05:07,888 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 402
2026-01-12 04:05:08,462 [cuckoo.core.resultserver] DEBUG: Task #7290196: File upload for 'shots/0006.jpg'
2026-01-12 04:05:08,482 [cuckoo.core.resultserver] DEBUG: Task #7290196 uploaded file length: 133570
2026-01-12 04:05:08,498 [cuckoo.core.resultserver] DEBUG: Task #7290196 had connection reset for <Context for LOG>
2026-01-12 04:05:10,437 [cuckoo.core.guest] INFO: win7x6413: analysis completed successfully
2026-01-12 04:05:10,448 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2026-01-12 04:05:10,561 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2026-01-12 04:05:11,783 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6413 to path /srv/cuckoo/cwd/storage/analyses/7290196/memory.dmp
2026-01-12 04:05:11,790 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6413
2026-01-12 04:07:53,694 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.213 for task #7290196
2026-01-12 04:07:55,466 [cuckoo.core.scheduler] DEBUG: Released database task #7290196
2026-01-12 04:07:55,487 [cuckoo.core.scheduler] INFO: Task #7290196: analysis procedure completed
| file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PCUP2C46\fp.v3[1].js |
| file | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PCUP2C46\vendor[1].js |
| cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1768 CREDAT:275457 /prefetch:2 |
| G Data Antivirus (Windows) | Virus: Trojan.GenericKD.78268508 (Engine A) |
| Avast Core Security (Linux) | Script:SNH-gen [Trj] |
| eScan Antivirus (Linux) | Trojan.GenericKD.78268508(DB) |
| Bitdefender Antivirus (Linux) | Trojan.GenericKD.78268508 |
| Emsisoft Commandline Scanner (Windows) | Trojan.GenericKD.78268508 (B) |
| Avast | Script:SNH-gen [Trj] |
| Cynet | Malicious (score: 99) |
| Rising | Trojan.Redirector/HTML!8.1290C (TOPIS:E0:Cb2UtrRaglD) |
| Ikarus | Trojan.JS.Redirector |
| Detected | |
| Microsoft | Trojan:JS/Redirector.ABOB!MTB |
| Varist | JS/Phish.AYV!Eldorado |
| Fortinet | JS/Agent.AYV!tr |
| AVG | Script:SNH-gen [Trj] |