File e50e5ee8ea82a77c0ed5023f6d0e6c3bb1ff6ceecb2285d930bb0c3b86af8671

Size 88.4KB
Type HTML document, Unicode text, UTF-8 text, with very long lines (8950), with CRLF, LF line terminators
MD5 3eed069b7ab8c4659d4c9909dd418a04
SHA1 46038e40d20e830415b7a45a4f53508a8b9a9d60
SHA256 e50e5ee8ea82a77c0ed5023f6d0e6c3bb1ff6ceecb2285d930bb0c3b86af8671
SHA512
078f952933d18c2ae5ccb929575c88a26466a8b50d6846d6ff60386ba4c0f7bdb071786e6aec990a6e65b3aa8af2127e7e05ca8fd39755e88a68de351cba091e
CRC32 3E1CC195
ssdeep None
Yara None matched

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE April 20, 2025, 12:36 a.m. April 20, 2025, 12:42 a.m. 355 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-04-19 16:18:40,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpdyrg_l
2025-04-19 16:18:40,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\pNdJomBABlWZkYwKhy
2025-04-19 16:18:40,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\cdkjeGBglBonRjDXjjBAZdFMQB
2025-04-19 16:18:40,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-04-19 16:18:40,030 [analyzer] INFO: Automatically selected analysis package "ie"
2025-04-19 16:18:40,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-19 16:18:40,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-19 16:18:40,812 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-19 16:18:41,015 [analyzer] DEBUG: Loaded monitor into process with pid 500
2025-04-19 16:18:41,015 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-19 16:18:41,015 [analyzer] DEBUG: Started auxiliary module Human
2025-04-19 16:18:41,015 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-19 16:18:41,015 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-19 16:18:41,125 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-19 16:18:41,125 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-19 16:18:41,125 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-19 16:18:41,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-19 16:18:41,125 [modules.packages.ie] INFO: Submitted file is missing extension, adding .html
2025-04-19 16:18:41,233 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\e50e5ee8ea82a77c0ed5023f6d0e6c3bb1ff6ceecb2285d930bb0c3b86af8671.html'] and pid 2744
2025-04-19 16:18:41,375 [analyzer] DEBUG: Loaded monitor into process with pid 2744
2025-04-19 16:18:43,078 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2744 CREDAT:275457 /prefetch:2!
2025-04-19 16:18:43,140 [analyzer] INFO: Injected into process with pid 1888 and name u'iexplore.exe'
2025-04-19 16:18:43,203 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1888.
2025-04-19 16:18:43,328 [analyzer] INFO: Added new file to list with pid 2744 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{3131A68D-1D29-11F0-9AEA-829888585948}.dat
2025-04-19 16:18:43,375 [analyzer] INFO: Added new file to list with pid 2744 and path C:\Users\Administrator\AppData\Local\Temp\~DF12B6F68C8A8F6B05.TMP
2025-04-19 16:18:43,390 [analyzer] DEBUG: Loaded monitor into process with pid 1888
2025-04-19 16:18:43,655 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-19 16:18:43,655 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-19 16:18:43,655 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-19 16:18:43,655 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-19 16:18:43,655 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-19 16:18:43,655 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-19 16:18:43,655 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-19 16:18:43,671 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-19 16:18:43,671 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-19 16:18:43,687 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-19 16:18:43,687 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-19 16:18:43,687 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-19 16:18:43,687 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-19 16:18:43,687 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-19 16:18:44,015 [analyzer] INFO: Added new file to list with pid 2744 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3131A68F-1D29-11F0-9AEA-829888585948}.dat
2025-04-19 16:18:44,046 [analyzer] INFO: Added new file to list with pid 2744 and path C:\Users\Administrator\AppData\Local\Temp\~DF0CC7FE64DEEC1E58.TMP
2025-04-19 16:18:44,108 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-19 16:18:44,108 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-19 16:18:44,108 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-19 16:18:44,108 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-19 16:18:44,108 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-19 16:18:44,108 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-19 16:18:44,108 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-19 16:18:47,108 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4A9377E7E528F7E56B69A81C500ABC24
2025-04-19 16:18:47,108 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4A9377E7E528F7E56B69A81C500ABC24
2025-04-19 16:18:47,108 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCA6D.tmp
2025-04-19 16:18:47,125 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCA6E.tmp
2025-04-19 16:18:47,140 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCA7F.tmp
2025-04-19 16:18:47,140 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCA80.tmp
2025-04-19 16:18:47,280 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2025-04-19 16:18:47,280 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2025-04-19 16:18:47,296 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-04-19 16:18:47,296 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-04-19 16:18:47,312 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCB2C.tmp
2025-04-19 16:18:47,312 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCB3E.tmp
2025-04-19 16:18:47,312 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCB2D.tmp
2025-04-19 16:18:47,328 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCB3F.tmp
2025-04-19 16:18:47,328 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCB40.tmp
2025-04-19 16:18:47,328 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCB41.tmp
2025-04-19 16:18:47,328 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCB52.tmp
2025-04-19 16:18:47,342 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCB53.tmp
2025-04-19 16:18:47,358 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCB73.tmp
2025-04-19 16:18:47,375 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCB74.tmp
2025-04-19 16:18:47,375 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCB85.tmp
2025-04-19 16:18:47,375 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCB86.tmp
2025-04-19 16:18:47,592 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-04-19 16:18:47,592 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-04-19 16:18:47,608 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA
2025-04-19 16:18:47,608 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA
2025-04-19 16:18:47,717 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2025-04-19 16:18:47,733 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2025-04-19 16:18:47,733 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199
2025-04-19 16:18:47,733 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199
2025-04-19 16:18:47,875 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DDE8B1B7E253A9758EC380BD648952AF_1EEB81C4C021C918ADA067594911DA5D
2025-04-19 16:18:47,875 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DDE8B1B7E253A9758EC380BD648952AF_1EEB81C4C021C918ADA067594911DA5D
2025-04-19 16:18:47,890 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabCD8A.tmp
2025-04-19 16:18:47,905 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarCD8B.tmp
2025-04-19 16:18:48,108 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7E9E4F80D795A1B09D2046925025024D_6BDB025B09873FBFF4B7B9839C876D78
2025-04-19 16:18:48,125 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7E9E4F80D795A1B09D2046925025024D_6BDB025B09873FBFF4B7B9839C876D78
2025-04-19 16:18:48,467 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\helpers-wpb-elem.min[1].css
2025-04-19 16:18:48,483 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\base.min[1].css
2025-04-19 16:18:48,483 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\woo-widget-slider-price-filter.min[1].css
2025-04-19 16:18:48,530 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\woo-widget-product-list.min[1].css
2025-04-19 16:18:48,546 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\woo-widget-product-cat.min[1].css
2025-04-19 16:18:48,592 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\widget-wd-recent-posts.min[1].css
2025-04-19 16:18:48,608 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\js_composer.min[1].css
2025-04-19 16:18:48,750 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\mod-star-rating.min[1].css
2025-04-19 16:18:48,780 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\style.min[1].css
2025-04-19 16:18:48,796 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\int-rev-slider.min[1].css
2025-04-19 16:18:48,812 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\mp-plugins-components.min[1].css
2025-04-19 16:18:48,842 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\int-wpb-base.min[1].css
2025-04-19 16:18:48,875 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\int-wpb-base-deprecated.min[1].css
2025-04-19 16:18:48,905 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\woocommerce-base.min[1].css
2025-04-19 16:18:48,983 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\style.min[1].css
2025-04-19 16:18:48,983 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\int-wpcf7.min[1].css
2025-04-19 16:18:49,015 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\header-base.min[1].css
2025-04-19 16:18:49,092 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\widget-nav.min[1].css
2025-04-19 16:18:49,092 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\mod-tools.min[1].css
2025-04-19 16:18:49,108 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\header-el-base.min[1].css
2025-04-19 16:18:49,108 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\woo-el-track-order.min[1].css
2025-04-19 16:18:49,108 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\woo-page-compare.min[1].css
2025-04-19 16:18:49,125 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\woo-mod-block-notices.min[1].css
2025-04-19 16:18:49,125 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\woo-mod-stock-status.min[1].css
2025-04-19 16:18:49,171 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\wp-blocks.min[1].css
2025-04-19 16:18:49,217 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\header-el-my-account-dropdown.min[1].css
2025-04-19 16:18:49,217 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\header-el-search.min[1].css
2025-04-19 16:18:49,233 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\header-el-cart-side.min[1].css
2025-04-19 16:18:49,233 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\woo-widget-shopping-cart.min[1].css
2025-04-19 16:18:49,342 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\woo-page-empty-page.min[1].css
2025-04-19 16:18:49,342 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\el-social-icons.min[1].css
2025-04-19 16:18:49,342 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\footer-base.min[1].css
2025-04-19 16:18:49,358 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\opt-scrolltotop.min[1].css
2025-04-19 16:18:49,421 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\woo-mod-login-form.min[1].css
2025-04-19 16:18:49,453 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\wd-search-results.min[1].css
2025-04-19 16:18:49,453 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\wd-search-form.min[1].css
2025-04-19 16:18:49,467 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\header-el-my-account.min[1].css
2025-04-19 16:18:49,483 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\header-el-cart.min[1].css
2025-04-19 16:18:49,483 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\header-el-mobile-nav-dropdown.min[1].css
2025-04-19 16:18:49,546 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\page-title.min[1].css
2025-04-19 16:18:49,608 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\jquery.min[1].js
2025-04-19 16:18:49,608 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\wc-blocks[1].css
2025-04-19 16:18:49,655 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\jquery-migrate.min[1].js
2025-04-19 16:18:49,671 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\lib-magnific-popup.min[1].css
2025-04-19 16:18:49,687 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\el-section-title.min[1].css
2025-04-19 16:18:49,733 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\mod-highlighted-text.min[1].css
2025-04-19 16:18:49,765 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\opt-cookies.min[1].css
2025-04-19 16:18:49,780 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\woocommerce.min[1].js
2025-04-19 16:18:49,780 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\js.cookie.min[1].js
2025-04-19 16:18:49,780 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\header-el-search-fullscreen-1.min[1].css
2025-04-19 16:18:49,812 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\header-el-search-fullscreen-general.min[1].css
2025-04-19 16:18:49,858 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\device.min[1].js
2025-04-19 16:18:49,905 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\wood-logo-dark[1].svg
2025-04-19 16:18:49,937 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\jquery.blockUI.min[1].js
2025-04-19 16:18:49,937 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\add-to-cart.min[1].js
2025-04-19 16:18:50,000 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\woocommerce-add-to-cart[1].js
2025-04-19 16:18:50,092 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\logo[1].png
2025-04-19 16:18:50,125 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\scrollBar.min[1].js
2025-04-19 16:18:50,342 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\footer-background-ctcrio[1].jpg
2025-04-19 16:18:50,530 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
2025-04-19 16:18:50,530 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
2025-04-19 16:18:50,546 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD7DD.tmp
2025-04-19 16:18:50,546 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD7ED.tmp
2025-04-19 16:18:50,625 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD82D.tmp
2025-04-19 16:18:50,625 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD82E.tmp
2025-04-19 16:18:50,640 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD83F.tmp
2025-04-19 16:18:50,640 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD840.tmp
2025-04-19 16:18:50,671 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD86F.tmp
2025-04-19 16:18:50,671 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD870.tmp
2025-04-19 16:18:50,717 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD891.tmp
2025-04-19 16:18:50,717 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD892.tmp
2025-04-19 16:18:50,750 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD8C2.tmp
2025-04-19 16:18:50,750 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD8C3.tmp
2025-04-19 16:18:50,765 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD8D3.tmp
2025-04-19 16:18:50,765 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD8D4.tmp
2025-04-19 16:18:50,796 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD8F4.tmp
2025-04-19 16:18:50,812 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD8F5.tmp
2025-04-19 16:18:50,842 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD916.tmp
2025-04-19 16:18:50,842 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD917.tmp
2025-04-19 16:18:50,875 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD947.tmp
2025-04-19 16:18:50,890 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD948.tmp
2025-04-19 16:18:50,905 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD958.tmp
2025-04-19 16:18:50,905 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD959.tmp
2025-04-19 16:18:50,953 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD989.tmp
2025-04-19 16:18:50,953 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD98A.tmp
2025-04-19 16:18:51,015 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabD9D9.tmp
2025-04-19 16:18:51,030 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarD9DA.tmp
2025-04-19 16:18:51,078 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDA1A.tmp
2025-04-19 16:18:51,078 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDA1B.tmp
2025-04-19 16:18:51,092 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDA2B.tmp
2025-04-19 16:18:51,108 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDA2C.tmp
2025-04-19 16:18:51,155 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDA5C.tmp
2025-04-19 16:18:51,155 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDA5D.tmp
2025-04-19 16:18:51,155 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDA6E.tmp
2025-04-19 16:18:51,155 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDA6F.tmp
2025-04-19 16:18:51,203 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDA8F.tmp
2025-04-19 16:18:51,203 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDA90.tmp
2025-04-19 16:18:51,217 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDAB0.tmp
2025-04-19 16:18:51,217 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDAB1.tmp
2025-04-19 16:18:51,265 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDAE1.tmp
2025-04-19 16:18:51,265 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDAE3.tmp
2025-04-19 16:18:51,280 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDAE2.tmp
2025-04-19 16:18:51,280 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDAE4.tmp
2025-04-19 16:18:51,328 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDB24.tmp
2025-04-19 16:18:51,342 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDB25.tmp
2025-04-19 16:18:51,358 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDB35.tmp
2025-04-19 16:18:51,358 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDB46.tmp
2025-04-19 16:18:51,405 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDB66.tmp
2025-04-19 16:18:51,405 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDB67.tmp
2025-04-19 16:18:51,405 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDB78.tmp
2025-04-19 16:18:51,405 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDB79.tmp
2025-04-19 16:18:51,453 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDBA9.tmp
2025-04-19 16:18:51,467 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDBAA.tmp
2025-04-19 16:18:51,500 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDBDA.tmp
2025-04-19 16:18:51,500 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDBDB.tmp
2025-04-19 16:18:51,530 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDBFB.tmp
2025-04-19 16:18:51,546 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDBFC.tmp
2025-04-19 16:18:51,546 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDC0C.tmp
2025-04-19 16:18:51,546 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDC0D.tmp
2025-04-19 16:18:51,592 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDC2E.tmp
2025-04-19 16:18:51,592 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDC2F.tmp
2025-04-19 16:18:51,625 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDC5F.tmp
2025-04-19 16:18:51,625 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDC60.tmp
2025-04-19 16:18:51,671 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDC80.tmp
2025-04-19 16:18:51,671 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDC81.tmp
2025-04-19 16:18:51,687 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDC91.tmp
2025-04-19 16:18:51,687 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDC92.tmp
2025-04-19 16:18:51,717 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDCC2.tmp
2025-04-19 16:18:51,717 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDCC3.tmp
2025-04-19 16:18:51,765 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDCF3.tmp
2025-04-19 16:18:51,765 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDCF4.tmp
2025-04-19 16:18:51,796 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDD14.tmp
2025-04-19 16:18:51,812 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDD15.tmp
2025-04-19 16:18:51,812 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDD26.tmp
2025-04-19 16:18:51,828 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDD27.tmp
2025-04-19 16:18:51,858 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDD57.tmp
2025-04-19 16:18:51,858 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDD58.tmp
2025-04-19 16:18:51,890 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDD78.tmp
2025-04-19 16:18:51,905 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDD79.tmp
2025-04-19 16:18:51,937 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDDA9.tmp
2025-04-19 16:18:51,937 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDDAA.tmp
2025-04-19 16:18:51,937 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDDAB.tmp
2025-04-19 16:18:51,953 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDDAC.tmp
2025-04-19 16:18:51,983 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDDDC.tmp
2025-04-19 16:18:52,000 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDDDD.tmp
2025-04-19 16:18:52,030 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDE0D.tmp
2025-04-19 16:18:52,062 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDE0E.tmp
2025-04-19 16:18:52,078 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDE3E.tmp
2025-04-19 16:18:52,078 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDE3F.tmp
2025-04-19 16:18:52,125 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDE5F.tmp
2025-04-19 16:18:52,125 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDE60.tmp
2025-04-19 16:18:52,140 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDE71.tmp
2025-04-19 16:18:52,140 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDE72.tmp
2025-04-19 16:18:52,203 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDEC1.tmp
2025-04-19 16:18:52,203 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDEC2.tmp
2025-04-19 16:18:52,233 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDED2.tmp
2025-04-19 16:18:52,233 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDED3.tmp
2025-04-19 16:18:52,375 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDF71.tmp
2025-04-19 16:18:52,390 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDF72.tmp
2025-04-19 16:18:52,453 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDFC1.tmp
2025-04-19 16:18:52,467 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDFC2.tmp
2025-04-19 16:18:52,500 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabDFF2.tmp
2025-04-19 16:18:52,500 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarDFF3.tmp
2025-04-19 16:18:52,578 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE042.tmp
2025-04-19 16:18:52,578 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE043.tmp
2025-04-19 16:18:52,625 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE073.tmp
2025-04-19 16:18:52,625 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE074.tmp
2025-04-19 16:18:52,703 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE0B3.tmp
2025-04-19 16:18:52,703 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE0B4.tmp
2025-04-19 16:18:52,750 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE0E4.tmp
2025-04-19 16:18:52,750 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE0F5.tmp
2025-04-19 16:18:52,812 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE134.tmp
2025-04-19 16:18:52,828 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE135.tmp
2025-04-19 16:18:52,858 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE165.tmp
2025-04-19 16:18:52,875 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE166.tmp
2025-04-19 16:18:52,937 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE1B5.tmp
2025-04-19 16:18:52,937 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE1B6.tmp
2025-04-19 16:18:52,983 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE1E6.tmp
2025-04-19 16:18:52,983 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE1E7.tmp
2025-04-19 16:18:53,092 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE255.tmp
2025-04-19 16:18:53,092 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE256.tmp
2025-04-19 16:18:53,140 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE277.tmp
2025-04-19 16:18:53,140 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE287.tmp
2025-04-19 16:18:53,203 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE2C7.tmp
2025-04-19 16:18:53,217 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE2C8.tmp
2025-04-19 16:18:53,250 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE2F8.tmp
2025-04-19 16:18:53,250 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE2F9.tmp
2025-04-19 16:18:53,312 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE338.tmp
2025-04-19 16:18:53,312 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE339.tmp
2025-04-19 16:18:53,375 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE369.tmp
2025-04-19 16:18:53,375 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE36A.tmp
2025-04-19 16:18:53,437 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\CabE3B9.tmp
2025-04-19 16:18:53,437 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\TarE3BA.tmp
2025-04-19 23:40:43,102 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Cab17CB.tmp
2025-04-19 23:40:43,102 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Tar17DC.tmp
2025-04-19 23:40:43,211 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1801A0BFF52C676E5F51CA71C5350277
2025-04-19 23:40:43,227 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1801A0BFF52C676E5F51CA71C5350277
2025-04-19 23:40:43,227 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F0ACCF77CDCBFF39F6191887F6D2D357
2025-04-19 23:40:43,227 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F0ACCF77CDCBFF39F6191887F6D2D357
2025-04-19 23:40:43,227 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Cab185A.tmp
2025-04-19 23:40:43,243 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Tar185B.tmp
2025-04-19 23:40:43,259 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Cab186B.tmp
2025-04-19 23:40:43,259 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Tar187C.tmp
2025-04-19 23:40:43,321 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Cab18BC.tmp
2025-04-19 23:40:43,321 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Tar18BD.tmp
2025-04-19 23:40:43,336 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Cab18CD.tmp
2025-04-19 23:40:43,336 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Temp\Tar18CE.tmp
2025-04-19 23:40:43,352 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\updateCartFragmentsFix[1].js
2025-04-19 23:40:43,352 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\hooks.min[1].js
2025-04-19 23:40:43,368 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\index[2].js
2025-04-19 23:40:43,368 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\index[1].js
2025-04-19 23:40:43,430 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\mp-plugins-components.min[1].js
2025-04-19 23:40:43,461 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04
2025-04-19 23:40:43,461 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04
2025-04-19 23:40:43,571 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\i18n.min[1].js
2025-04-19 23:40:43,586 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\v2[1].js
2025-04-19 23:40:43,664 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\headerBuilder.min[1].js
2025-04-19 23:40:43,680 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\loginDropdown.min[1].js
2025-04-19 23:40:43,696 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\wishlist.min[1].js
2025-04-19 23:40:43,711 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\mp-checkout-update.min[1].js
2025-04-19 23:40:43,743 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\menuOffsets.min[1].js
2025-04-19 23:40:43,805 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\autocomplete.min[1].js
2025-04-19 23:40:43,821 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\sourcebuster.min[1].js
2025-04-19 23:40:43,930 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\js_composer_front.min[1].js
2025-04-19 23:40:43,946 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\menuSetUp.min[1].js
2025-04-19 23:40:43,993 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\scrollTop.min[1].js
2025-04-19 23:40:43,993 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\mobileNavigation.min[1].js
2025-04-19 23:40:44,055 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\order-attribution.min[1].js
2025-04-19 23:40:44,118 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\promoPopup.min[1].js
2025-04-19 23:40:44,150 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\ajaxSearch.min[1].js
2025-04-19 23:40:44,243 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\cartWidget.min[1].js
2025-04-19 23:40:44,243 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\cart-fragments.min[1].js
2025-04-19 23:40:44,305 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\magnific-popup.min[1].js
2025-04-19 23:40:44,368 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\onRemoveFromCart.min[1].js
2025-04-19 23:40:44,384 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\cookiesPopup.min[1].js
2025-04-19 23:40:44,430 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\helpers.min[1].js
2025-04-19 23:40:44,461 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\searchFullScreen.min[1].js
2025-04-19 23:40:44,555 [analyzer] INFO: Added new file to list with pid 1888 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\woocommerceNotices.min[1].js
2025-04-19 23:40:46,563 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-04-19 23:40:46,984 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-04-19 23:40:46,984 [lib.api.process] INFO: Successfully terminated process with pid 2744.
2025-04-19 23:40:46,984 [lib.api.process] INFO: Successfully terminated process with pid 1888.
2025-04-19 23:40:46,984 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcb3f.tmp' does not exist, skip.
2025-04-19 23:40:47,000 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdae1.tmp' does not exist, skip.
2025-04-19 23:40:47,000 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcb2d.tmp' does not exist, skip.
2025-04-19 23:40:47,016 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardb46.tmp' does not exist, skip.
2025-04-19 23:40:47,032 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar187c.tmp' does not exist, skip.
2025-04-19 23:40:47,032 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab18cd.tmp' does not exist, skip.
2025-04-19 23:40:47,032 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabde0d.tmp' does not exist, skip.
2025-04-19 23:40:47,032 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardd58.tmp' does not exist, skip.
2025-04-19 23:40:47,032 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcb40.tmp' does not exist, skip.
2025-04-19 23:40:47,048 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcd8a.tmp' does not exist, skip.
2025-04-19 23:40:47,048 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdae3.tmp' does not exist, skip.
2025-04-19 23:40:47,063 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdff2.tmp' does not exist, skip.
2025-04-19 23:40:47,063 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd83f.tmp' does not exist, skip.
2025-04-19 23:40:47,063 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe0e4.tmp' does not exist, skip.
2025-04-19 23:40:47,063 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdab0.tmp' does not exist, skip.
2025-04-19 23:40:47,063 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabde5f.tmp' does not exist, skip.
2025-04-19 23:40:47,078 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarde72.tmp' does not exist, skip.
2025-04-19 23:40:47,078 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarca6e.tmp' does not exist, skip.
2025-04-19 23:40:47,078 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabddab.tmp' does not exist, skip.
2025-04-19 23:40:47,078 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardd79.tmp' does not exist, skip.
2025-04-19 23:40:47,078 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdcf3.tmp' does not exist, skip.
2025-04-19 23:40:47,078 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd82d.tmp' does not exist, skip.
2025-04-19 23:40:47,078 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab17cb.tmp' does not exist, skip.
2025-04-19 23:40:47,078 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe277.tmp' does not exist, skip.
2025-04-19 23:40:47,095 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd86f.tmp' does not exist, skip.
2025-04-19 23:40:47,095 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardb78.tmp' does not exist, skip.
2025-04-19 23:40:47,095 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcb85.tmp' does not exist, skip.
2025-04-19 23:40:47,095 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcb86.tmp' does not exist, skip.
2025-04-19 23:40:47,095 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardddd.tmp' does not exist, skip.
2025-04-19 23:40:47,095 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdc91.tmp' does not exist, skip.
2025-04-19 23:40:47,109 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe3b9.tmp' does not exist, skip.
2025-04-19 23:40:47,109 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare3ba.tmp' does not exist, skip.
2025-04-19 23:40:47,109 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare2f9.tmp' does not exist, skip.
2025-04-19 23:40:47,109 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe255.tmp' does not exist, skip.
2025-04-19 23:40:47,109 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar18ce.tmp' does not exist, skip.
2025-04-19 23:40:47,109 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardec2.tmp' does not exist, skip.
2025-04-19 23:40:47,109 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardbdb.tmp' does not exist, skip.
2025-04-19 23:40:47,125 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardd27.tmp' does not exist, skip.
2025-04-19 23:40:47,125 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe042.tmp' does not exist, skip.
2025-04-19 23:40:47,125 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe1e6.tmp' does not exist, skip.
2025-04-19 23:40:47,141 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare256.tmp' does not exist, skip.
2025-04-19 23:40:47,141 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard7ed.tmp' does not exist, skip.
2025-04-19 23:40:47,141 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdc0c.tmp' does not exist, skip.
2025-04-19 23:40:47,141 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard917.tmp' does not exist, skip.
2025-04-19 23:40:47,141 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab18bc.tmp' does not exist, skip.
2025-04-19 23:40:47,141 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd8d3.tmp' does not exist, skip.
2025-04-19 23:40:47,157 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe0b3.tmp' does not exist, skip.
2025-04-19 23:40:47,157 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarda90.tmp' does not exist, skip.
2025-04-19 23:40:47,157 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdec1.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardbfc.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarde3f.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdcc2.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardc92.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar18bd.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard892.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabda8f.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd9d9.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdd78.tmp' does not exist, skip.
2025-04-19 23:40:47,173 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df0cc7fe64deec1e58.tmp' does not exist, skip.
2025-04-19 23:40:47,188 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare0f5.tmp' does not exist, skip.
2025-04-19 23:40:47,188 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarda1b.tmp' does not exist, skip.
2025-04-19 23:40:47,188 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd989.tmp' does not exist, skip.
2025-04-19 23:40:47,188 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd958.tmp' does not exist, skip.
2025-04-19 23:40:47,203 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard870.tmp' does not exist, skip.
2025-04-19 23:40:47,203 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardc2f.tmp' does not exist, skip.
2025-04-19 23:40:47,203 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe165.tmp' does not exist, skip.
2025-04-19 23:40:47,203 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarda6f.tmp' does not exist, skip.
2025-04-19 23:40:47,220 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardb25.tmp' does not exist, skip.
2025-04-19 23:40:47,220 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df12b6f68c8a8f6b05.tmp' does not exist, skip.
2025-04-19 23:40:47,220 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar17dc.tmp' does not exist, skip.
2025-04-19 23:40:47,220 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcb2c.tmp' does not exist, skip.
2025-04-19 23:40:47,234 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe369.tmp' does not exist, skip.
2025-04-19 23:40:47,234 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarddac.tmp' does not exist, skip.
2025-04-19 23:40:47,250 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare1b6.tmp' does not exist, skip.
2025-04-19 23:40:47,250 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdb35.tmp' does not exist, skip.
2025-04-19 23:40:47,266 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdbda.tmp' does not exist, skip.
2025-04-19 23:40:47,266 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardc0d.tmp' does not exist, skip.
2025-04-19 23:40:47,266 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare287.tmp' does not exist, skip.
2025-04-19 23:40:47,266 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardae4.tmp' does not exist, skip.
2025-04-19 23:40:47,266 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabded2.tmp' does not exist, skip.
2025-04-19 23:40:47,266 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe338.tmp' does not exist, skip.
2025-04-19 23:40:47,282 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare166.tmp' does not exist, skip.
2025-04-19 23:40:47,282 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabca6d.tmp' does not exist, skip.
2025-04-19 23:40:47,282 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabda1a.tmp' does not exist, skip.
2025-04-19 23:40:47,282 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdb24.tmp' does not exist, skip.
2025-04-19 23:40:47,282 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare074.tmp' does not exist, skip.
2025-04-19 23:40:47,282 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarda2c.tmp' does not exist, skip.
2025-04-19 23:40:47,282 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe1b5.tmp' does not exist, skip.
2025-04-19 23:40:47,282 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare0b4.tmp' does not exist, skip.
2025-04-19 23:40:47,298 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard959.tmp' does not exist, skip.
2025-04-19 23:40:47,298 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard82e.tmp' does not exist, skip.
2025-04-19 23:40:47,298 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardc60.tmp' does not exist, skip.
2025-04-19 23:40:47,298 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarde0e.tmp' does not exist, skip.
2025-04-19 23:40:47,298 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcb73.tmp' does not exist, skip.
2025-04-19 23:40:47,298 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabde71.tmp' does not exist, skip.
2025-04-19 23:40:47,328 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd8f4.tmp' does not exist, skip.
2025-04-19 23:40:47,328 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdc2e.tmp' does not exist, skip.
2025-04-19 23:40:47,345 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdb66.tmp' does not exist, skip.
2025-04-19 23:40:47,345 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarda5d.tmp' does not exist, skip.
2025-04-19 23:40:47,345 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdbfb.tmp' does not exist, skip.
2025-04-19 23:40:47,345 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab186b.tmp' does not exist, skip.
2025-04-19 23:40:47,345 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarde60.tmp' does not exist, skip.
2025-04-19 23:40:47,359 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardb79.tmp' does not exist, skip.
2025-04-19 23:40:47,359 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard98a.tmp' does not exist, skip.
2025-04-19 23:40:47,359 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar185b.tmp' does not exist, skip.
2025-04-19 23:40:47,359 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdc5f.tmp' does not exist, skip.
2025-04-19 23:40:47,359 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdc80.tmp' does not exist, skip.
2025-04-19 23:40:47,359 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardab1.tmp' does not exist, skip.
2025-04-19 23:40:47,359 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare1e7.tmp' does not exist, skip.
2025-04-19 23:40:47,375 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcb74.tmp' does not exist, skip.
2025-04-19 23:40:47,375 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd947.tmp' does not exist, skip.
2025-04-19 23:40:47,375 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardcf4.tmp' does not exist, skip.
2025-04-19 23:40:47,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardae2.tmp' does not exist, skip.
2025-04-19 23:40:47,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardff3.tmp' does not exist, skip.
2025-04-19 23:40:47,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd7dd.tmp' does not exist, skip.
2025-04-19 23:40:47,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard948.tmp' does not exist, skip.
2025-04-19 23:40:47,407 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd8c2.tmp' does not exist, skip.
2025-04-19 23:40:47,423 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardcc3.tmp' does not exist, skip.
2025-04-19 23:40:47,423 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdd14.tmp' does not exist, skip.
2025-04-19 23:40:47,438 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd891.tmp' does not exist, skip.
2025-04-19 23:40:47,453 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard9da.tmp' does not exist, skip.
2025-04-19 23:40:47,453 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard8c3.tmp' does not exist, skip.
2025-04-19 23:40:47,453 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdd26.tmp' does not exist, skip.
2025-04-19 23:40:47,453 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardd15.tmp' does not exist, skip.
2025-04-19 23:40:47,453 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd916.tmp' does not exist, skip.
2025-04-19 23:40:47,453 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarca80.tmp' does not exist, skip.
2025-04-19 23:40:47,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdddc.tmp' does not exist, skip.
2025-04-19 23:40:47,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab185a.tmp' does not exist, skip.
2025-04-19 23:40:47,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe2f8.tmp' does not exist, skip.
2025-04-19 23:40:47,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdba9.tmp' does not exist, skip.
2025-04-19 23:40:47,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardbaa.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabda6e.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcb3e.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdfc1.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard840.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcd8b.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare135.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardfc2.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard8d4.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardf72.tmp' does not exist, skip.
2025-04-19 23:40:47,484 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdb67.tmp' does not exist, skip.
2025-04-19 23:40:47,500 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabda2b.tmp' does not exist, skip.
2025-04-19 23:40:47,516 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdf71.tmp' does not exist, skip.
2025-04-19 23:40:47,516 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcb52.tmp' does not exist, skip.
2025-04-19 23:40:47,516 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe134.tmp' does not exist, skip.
2025-04-19 23:40:47,532 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdd57.tmp' does not exist, skip.
2025-04-19 23:40:47,532 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare36a.tmp' does not exist, skip.
2025-04-19 23:40:47,548 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe2c7.tmp' does not exist, skip.
2025-04-19 23:40:47,548 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tardc81.tmp' does not exist, skip.
2025-04-19 23:40:47,563 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare043.tmp' does not exist, skip.
2025-04-19 23:40:47,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcb53.tmp' does not exist, skip.
2025-04-19 23:40:47,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarded3.tmp' does not exist, skip.
2025-04-19 23:40:47,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare2c8.tmp' does not exist, skip.
2025-04-19 23:40:47,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabdda9.tmp' does not exist, skip.
2025-04-19 23:40:47,578 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabde3e.tmp' does not exist, skip.
2025-04-19 23:40:47,595 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarddaa.tmp' does not exist, skip.
2025-04-19 23:40:47,595 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabca7f.tmp' does not exist, skip.
2025-04-19 23:40:47,595 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard8f5.tmp' does not exist, skip.
2025-04-19 23:40:47,609 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcb41.tmp' does not exist, skip.
2025-04-19 23:40:47,609 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabe073.tmp' does not exist, skip.
2025-04-19 23:40:47,609 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tare339.tmp' does not exist, skip.
2025-04-19 23:40:47,609 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabda5c.tmp' does not exist, skip.
2025-04-19 23:40:47,609 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-04-20 00:36:45,943 [cuckoo.core.scheduler] INFO: Task #6302234: acquired machine win7x6430 (label=win7x6430)
2025-04-20 00:36:45,943 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.230 for task #6302234
2025-04-20 00:36:46,311 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 863395 (interface=vboxnet0, host=192.168.168.230)
2025-04-20 00:36:46,358 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6430
2025-04-20 00:36:47,049 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6430 to vmcloak
2025-04-20 00:40:08,808 [cuckoo.core.guest] INFO: Starting analysis #6302234 on guest (id=win7x6430, ip=192.168.168.230)
2025-04-20 00:40:09,814 [cuckoo.core.guest] DEBUG: win7x6430: not ready yet
2025-04-20 00:40:14,838 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6430, ip=192.168.168.230)
2025-04-20 00:40:14,923 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6430, ip=192.168.168.230, monitor=latest, size=6660546)
2025-04-20 00:40:16,323 [cuckoo.core.resultserver] DEBUG: Task #6302234: live log analysis.log initialized.
2025-04-20 00:40:17,283 [cuckoo.core.resultserver] DEBUG: Task #6302234 is sending a BSON stream
2025-04-20 00:40:17,987 [cuckoo.core.resultserver] DEBUG: Task #6302234 is sending a BSON stream
2025-04-20 00:40:18,735 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'shots/0001.jpg'
2025-04-20 00:40:18,988 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 133466
2025-04-20 00:40:19,657 [cuckoo.core.resultserver] DEBUG: Task #6302234 is sending a BSON stream
2025-04-20 00:40:21,272 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'shots/0002.jpg'
2025-04-20 00:40:21,289 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 24448
2025-04-20 00:40:22,341 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'shots/0003.jpg'
2025-04-20 00:40:22,367 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 31483
2025-04-20 00:40:27,357 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'shots/0004.jpg'
2025-04-20 00:40:27,366 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 68937
2025-04-20 00:40:31,657 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6302234 still processing
2025-04-20 00:40:46,700 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'curtain/1745098846.69.curtain.log'
2025-04-20 00:40:46,710 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 36
2025-04-20 00:40:46,784 [cuckoo.core.guest] DEBUG: win7x6430: analysis #6302234 still processing
2025-04-20 00:40:46,945 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'sysmon/1745098846.94.sysmon.xml'
2025-04-20 00:40:46,984 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2467096
2025-04-20 00:40:46,992 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/99423b8557114769_mp-checkout-update.min[1].js'
2025-04-20 00:40:46,994 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 164
2025-04-20 00:40:47,003 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/1aef1a47c1badadf_opt-cookies.min[1].css'
2025-04-20 00:40:47,004 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1908
2025-04-20 00:40:47,009 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/0988f1f43f828522_page-title.min[1].css'
2025-04-20 00:40:47,011 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 579
2025-04-20 00:40:47,015 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/25700a62843e0327_scrolltop.min[1].js'
2025-04-20 00:40:47,024 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 362
2025-04-20 00:40:47,028 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/b3f9dcaaed06d38b_woo-widget-shopping-cart.min[1].css'
2025-04-20 00:40:47,030 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 5672
2025-04-20 00:40:47,035 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/ff7d0c19f57f883c_4a9377e7e528f7e56b69a81c500abc24'
2025-04-20 00:40:47,037 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 176
2025-04-20 00:40:47,044 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/2d0040598ff55025_14232b434cf29d4c4fb335a86d7fffe3'
2025-04-20 00:40:47,046 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 170
2025-04-20 00:40:47,052 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/ddfd1641f7eecd60_js_composer.min[1].css'
2025-04-20 00:40:47,057 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 459497
2025-04-20 00:40:47,060 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/3e86c706b5116829_woo-mod-login-form.min[1].css'
2025-04-20 00:40:47,062 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2149
2025-04-20 00:40:47,063 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/a75340aed408a293_7e9e4f80d795a1b09d2046925025024d_6bdb025b09873fbff4b7b9839c876d78'
2025-04-20 00:40:47,064 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 279
2025-04-20 00:40:47,067 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/7e7624ea30707c29_woo-mod-block-notices.min[1].css'
2025-04-20 00:40:47,068 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2205
2025-04-20 00:40:47,073 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/f37b67a87ef0ce7f_scrollbar.min[1].js'
2025-04-20 00:40:47,075 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 356
2025-04-20 00:40:47,079 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/711283e412042fac_updatecartfragmentsfix[1].js'
2025-04-20 00:40:47,081 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1666
2025-04-20 00:40:47,085 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/f313d12ea6124bd2_i18n.min[1].js'
2025-04-20 00:40:47,086 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 9141
2025-04-20 00:40:47,091 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/4735f01842a85cd8_woo-mod-stock-status.min[1].css'
2025-04-20 00:40:47,093 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1135
2025-04-20 00:40:47,095 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/ed502f7005cf5876_logo[1].png'
2025-04-20 00:40:47,097 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2899
2025-04-20 00:40:47,101 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/40aba23929929fa2_header-el-my-account.min[1].css'
2025-04-20 00:40:47,103 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 353
2025-04-20 00:40:47,106 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/4e01d6cde5573fb8_header-el-mobile-nav-dropdown.min[1].css'
2025-04-20 00:40:47,108 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 90
2025-04-20 00:40:47,113 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/010b826875c43f2e_el-section-title.min[1].css'
2025-04-20 00:40:47,120 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1776
2025-04-20 00:40:47,130 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/927307a33c1232cc_wd-search-results.min[1].css'
2025-04-20 00:40:47,134 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2084
2025-04-20 00:40:47,138 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/8c2aa323961e3283_autocomplete.min[1].js'
2025-04-20 00:40:47,140 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 12660
2025-04-20 00:40:47,141 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/d72761e1a334a754_94308059b57b3142e455b38a6eb92015'
2025-04-20 00:40:47,143 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 73305
2025-04-20 00:40:47,145 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8'
2025-04-20 00:40:47,147 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 530
2025-04-20 00:40:47,148 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/a436e5b1270ce42c_dde8b1b7e253a9758ec380bd648952af_1eeb81c4c021c918ada067594911da5d'
2025-04-20 00:40:47,149 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 472
2025-04-20 00:40:47,150 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/1a1680511b1fe630_int-wpb-base.min[1].css'
2025-04-20 00:40:47,152 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 16225
2025-04-20 00:40:47,153 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/8a765e13504ce126_woocommerce-base.min[1].css'
2025-04-20 00:40:47,154 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 6570
2025-04-20 00:40:47,155 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/c336ebfe57741d8b_logindropdown.min[1].js'
2025-04-20 00:40:47,164 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1114
2025-04-20 00:40:47,170 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/0143671edb29a7d8_searchfullscreen.min[1].js'
2025-04-20 00:40:47,175 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2612
2025-04-20 00:40:47,182 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/ebd41040e4bb3ec7_4a9377e7e528f7e56b69a81c500abc24'
2025-04-20 00:40:47,190 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 889
2025-04-20 00:40:47,191 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/87fe27a424c9f0c5_promopopup.min[1].js'
2025-04-20 00:40:47,193 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1573
2025-04-20 00:40:47,194 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/b01f0da07cfd2024_mod-star-rating.min[1].css'
2025-04-20 00:40:47,195 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 535
2025-04-20 00:40:47,196 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/8b083f64f2e9e8ac_js.cookie.min[1].js'
2025-04-20 00:40:47,198 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1720
2025-04-20 00:40:47,199 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/c94d23045c0c0712_recoverystore.{3131a68d-1d29-11f0-9aea-829888585948}.dat'
2025-04-20 00:40:47,200 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 5632
2025-04-20 00:40:47,202 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/96bcec06264976f3_2d85f72862b55c4eadd9e66e06947f3d'
2025-04-20 00:40:47,203 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1391
2025-04-20 00:40:47,204 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/2535b4827f26fbad_b398b80134f72209547439db21ab308d_a4cf52cca82d7458083f7280801a3a04'
2025-04-20 00:40:47,206 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 471
2025-04-20 00:40:47,207 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/b4b5118b8e534140_wp-blocks.min[1].css'
2025-04-20 00:40:47,208 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 3502
2025-04-20 00:40:47,217 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/e3b94721c842cd85_v2[1].js'
2025-04-20 00:40:47,222 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 611410
2025-04-20 00:40:47,226 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/8d008c707f146a2b_cookiespopup.min[1].js'
2025-04-20 00:40:47,228 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 592
2025-04-20 00:40:47,230 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/7a496efb662af9b8_wc-blocks[1].css'
2025-04-20 00:40:47,232 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 12942
2025-04-20 00:40:47,235 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/69ec81afaf644f87_header-el-cart-side.min[1].css'
2025-04-20 00:40:47,236 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1008
2025-04-20 00:40:47,239 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/5c50e60fc1d0a1ee_header-el-my-account-dropdown.min[1].css'
2025-04-20 00:40:47,241 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 553
2025-04-20 00:40:47,244 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/3ca4aeb912cc8451_ajaxsearch.min[1].js'
2025-04-20 00:40:47,245 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 3564
2025-04-20 00:40:47,249 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/df6e8d31918cf772_header-el-base.min[1].css'
2025-04-20 00:40:47,250 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 897
2025-04-20 00:40:47,253 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/c0d8ca7980a5b270_el-social-icons.min[1].css'
2025-04-20 00:40:47,255 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 3694
2025-04-20 00:40:47,258 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/957b9e6561c0aa86_8b2b9a00839eed1dfdccc3bfc2f5df12'
2025-04-20 00:40:47,260 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 174
2025-04-20 00:40:47,263 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/3ebef99dcb63471d_device.min[1].js'
2025-04-20 00:40:47,265 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 3171
2025-04-20 00:40:47,268 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/13a52ef4cc07f13b_cartwidget.min[1].js'
2025-04-20 00:40:47,269 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 920
2025-04-20 00:40:47,274 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/d0bc90be93f01166_onremovefromcart.min[1].js'
2025-04-20 00:40:47,276 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 348
2025-04-20 00:40:47,279 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/a9fcac6ac02016e6_mod-highlighted-text.min[1].css'
2025-04-20 00:40:47,281 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 296
2025-04-20 00:40:47,286 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/d3cb49a53580cc25_widget-nav.min[1].css'
2025-04-20 00:40:47,289 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 503
2025-04-20 00:40:47,291 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/6d60e3b25e56d351_index[2].js'
2025-04-20 00:40:47,293 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 12512
2025-04-20 00:40:47,297 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/24c65e42aec85dc9_{3131a68f-1d29-11f0-9aea-829888585948}.dat'
2025-04-20 00:40:47,299 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 7680
2025-04-20 00:40:47,303 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/efe748f8f159a393_7e9e4f80d795a1b09d2046925025024d_6bdb025b09873fbff4b7b9839c876d78'
2025-04-20 00:40:47,305 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 418
2025-04-20 00:40:47,311 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/4782a37d58ea2c85_int-wpb-base-deprecated.min[1].css'
2025-04-20 00:40:47,313 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 810
2025-04-20 00:40:47,316 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/363aa2d4106f0f66_order-attribution.min[1].js'
2025-04-20 00:40:47,318 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2356
2025-04-20 00:40:47,321 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/f0af4010327a0229_b46811c17859ffb409cf0e904a4aa8f8'
2025-04-20 00:40:47,323 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 170
2025-04-20 00:40:47,325 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/b637a5e2ece25869_menusetup.min[1].js'
2025-04-20 00:40:47,327 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1537
2025-04-20 00:40:47,331 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/cb6f2d32c49d1c2b_jquery.min[1].js'
2025-04-20 00:40:47,334 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 87553
2025-04-20 00:40:47,336 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/3d52ba78eedc40ef_wd-search-form.min[1].css'
2025-04-20 00:40:47,338 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1532
2025-04-20 00:40:47,341 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/4ac01387c1f69d94_header-base.min[1].css'
2025-04-20 00:40:47,342 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 12716
2025-04-20 00:40:47,346 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/8c511dc6d00f6fa2_1801a0bff52c676e5f51ca71c5350277'
2025-04-20 00:40:47,348 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 252
2025-04-20 00:40:47,354 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/c50a0b33030ba0ec_sourcebuster.min[1].js'
2025-04-20 00:40:47,375 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 15315
2025-04-20 00:40:47,383 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/d2b998baf01f8f9a_mp-plugins-components.min[1].css'
2025-04-20 00:40:47,385 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 51396
2025-04-20 00:40:47,386 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/fb6a7c3edcd7b97f_8b2b9a00839eed1dfdccc3bfc2f5df12'
2025-04-20 00:40:47,388 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1739
2025-04-20 00:40:47,389 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/3a3c5ff18295a15c_woo-el-track-order.min[1].css'
2025-04-20 00:40:47,390 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1183
2025-04-20 00:40:47,391 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/60c732ff0e6a89a5_headerbuilder.min[1].js'
2025-04-20 00:40:47,393 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2439
2025-04-20 00:40:47,394 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/2196d9f8b32a0eda_js_composer_front.min[1].js'
2025-04-20 00:40:47,396 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 17471
2025-04-20 00:40:47,397 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/98a4253238053009_mobilenavigation.min[1].js'
2025-04-20 00:40:47,399 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 6710
2025-04-20 00:40:47,400 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/1f00e7386753e699_add-to-cart.min[1].js'
2025-04-20 00:40:47,401 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 4035
2025-04-20 00:40:47,402 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/10c2cbc4a606f3e3_header-el-search-fullscreen-1.min[1].css'
2025-04-20 00:40:47,404 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 4258
2025-04-20 00:40:47,405 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/d151f8c0b2659cfb_jquery.blockui.min[1].js'
2025-04-20 00:40:47,406 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 9636
2025-04-20 00:40:47,407 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/0775dbecb62fc060_style.min[1].css'
2025-04-20 00:40:47,409 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1266
2025-04-20 00:40:47,410 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/e9a7ae4968ec3a4c_woo-widget-product-cat.min[1].css'
2025-04-20 00:40:47,412 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2408
2025-04-20 00:40:47,415 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/6558d47fc26e471b_lib-magnific-popup.min[1].css'
2025-04-20 00:40:47,416 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2141
2025-04-20 00:40:47,420 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/cb1b131dd415c3bf_05ddc6aa91765aacacdb0a5f96df8199'
2025-04-20 00:40:47,422 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 170
2025-04-20 00:40:47,425 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/8ae581c1ea366de3_menuoffsets.min[1].js'
2025-04-20 00:40:47,427 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2778
2025-04-20 00:40:47,430 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/f0f76f30f4cb4442_b398b80134f72209547439db21ab308d_a4cf52cca82d7458083f7280801a3a04'
2025-04-20 00:40:47,432 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 400
2025-04-20 00:40:47,434 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/93efdfa2733eb60e_wishlist.min[1].js'
2025-04-20 00:40:47,436 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 7923
2025-04-20 00:40:47,439 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/732e5ef20e9409ae_int-wpcf7.min[1].css'
2025-04-20 00:40:47,441 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2498
2025-04-20 00:40:47,445 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/ba3c42a8c49d2682_header-el-search-fullscreen-general.min[1].css'
2025-04-20 00:40:47,447 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2032
2025-04-20 00:40:47,452 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/660fc6616e3ba910_woocommerce-add-to-cart[1].js'
2025-04-20 00:40:47,454 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 986
2025-04-20 00:40:47,455 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/b0c149d01e321d6e_footer-base.min[1].css'
2025-04-20 00:40:47,457 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 736
2025-04-20 00:40:47,458 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/4d445c4ad15c198c_wood-logo-dark[1].svg'
2025-04-20 00:40:47,459 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2977
2025-04-20 00:40:47,460 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/f79c4bf8047040ea_94308059b57b3142e455b38a6eb92015'
2025-04-20 00:40:47,462 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 344
2025-04-20 00:40:47,466 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/08eb212125b68c0e_opt-scrolltotop.min[1].css'
2025-04-20 00:40:47,467 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 740
2025-04-20 00:40:47,471 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/abbaf5ef8d625db1_woo-widget-slider-price-filter.min[1].css'
2025-04-20 00:40:47,473 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2652
2025-04-20 00:40:47,477 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/31f04d825c33067d_int-rev-slider.min[1].css'
2025-04-20 00:40:47,478 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 649
2025-04-20 00:40:47,481 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/f3b01ac231a5375b_woo-widget-product-list.min[1].css'
2025-04-20 00:40:47,482 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1034
2025-04-20 00:40:47,490 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/ddcce687729cb358_index[1].js'
2025-04-20 00:40:47,492 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 13452
2025-04-20 00:40:47,495 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/1c11e2f8aa9be285_footer-background-ctcrio[1].jpg'
2025-04-20 00:40:47,499 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 56280
2025-04-20 00:40:47,503 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/5274f11e6fb32ae0_jquery-migrate.min[1].js'
2025-04-20 00:40:47,504 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 13577
2025-04-20 00:40:47,508 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/4c95e1abdcc4b748_header-el-search.min[1].css'
2025-04-20 00:40:47,510 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1002
2025-04-20 00:40:47,512 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/abf38811e3bbab8c_24bd96d5497f70b3f510a6b53cd43f3e_3a89246fb90c5ee6620004f1ae0eb0ea'
2025-04-20 00:40:47,514 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1446
2025-04-20 00:40:47,517 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/be50abaccce74ebb_woo-page-compare.min[1].css'
2025-04-20 00:40:47,518 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 3485
2025-04-20 00:40:47,523 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/1f279bdbad4c37b2_f0accf77cdcbff39f6191887f6d2d357'
2025-04-20 00:40:47,525 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 242
2025-04-20 00:40:47,527 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/b3241e8eedad3697_woocommerce.min[1].js'
2025-04-20 00:40:47,529 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 3178
2025-04-20 00:40:47,532 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/487a7cb3e1600338_dde8b1b7e253a9758ec380bd648952af_1eeb81c4c021c918ada067594911da5d'
2025-04-20 00:40:47,534 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 398
2025-04-20 00:40:47,536 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/55fabf674756ad3b_widget-wd-recent-posts.min[1].css'
2025-04-20 00:40:47,538 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 746
2025-04-20 00:40:47,542 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/324133a15942496a_mod-tools.min[1].css'
2025-04-20 00:40:47,543 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 4797
2025-04-20 00:40:47,547 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/fd8e00796776c1fe_base.min[1].css'
2025-04-20 00:40:47,549 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 41297
2025-04-20 00:40:47,553 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/70eaa450b54185d7_helpers-wpb-elem.min[1].css'
2025-04-20 00:40:47,555 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 957
2025-04-20 00:40:47,558 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/1306a79dbda14891_header-el-cart.min[1].css'
2025-04-20 00:40:47,560 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2095
2025-04-20 00:40:47,562 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/9a1e0d38b691f1d2_hooks.min[1].js'
2025-04-20 00:40:47,563 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 4776
2025-04-20 00:40:47,566 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/f8d594e7b81f6e1d_woocommercenotices.min[1].js'
2025-04-20 00:40:47,568 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 485
2025-04-20 00:40:47,570 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/e54172bff4f17769_magnific-popup.min[1].js'
2025-04-20 00:40:47,572 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 20638
2025-04-20 00:40:47,575 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/597ddfdee7171750_style.min[1].css'
2025-04-20 00:40:47,577 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 116363
2025-04-20 00:40:47,582 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/60849543ba665c4d_2d85f72862b55c4eadd9e66e06947f3d'
2025-04-20 00:40:47,583 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 192
2025-04-20 00:40:47,586 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/35693106f408c209_woo-page-empty-page.min[1].css'
2025-04-20 00:40:47,587 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1910
2025-04-20 00:40:47,591 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/df545bf919a2439c_f0accf77cdcbff39f6191887f6d2d357'
2025-04-20 00:40:47,593 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 1521
2025-04-20 00:40:47,595 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/4a2b601fab32c5df_mp-plugins-components.min[1].js'
2025-04-20 00:40:47,597 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 43224
2025-04-20 00:40:47,600 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/eac173f6aa2de93a_05ddc6aa91765aacacdb0a5f96df8199'
2025-04-20 00:40:47,602 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 993
2025-04-20 00:40:47,604 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/6d8c91da07f208f6_helpers.min[1].js'
2025-04-20 00:40:47,605 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 9493
2025-04-20 00:40:47,611 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/592acc60b8eea94f_cart-fragments.min[1].js'
2025-04-20 00:40:47,616 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 2939
2025-04-20 00:40:47,618 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/4348a0e9444c78cb_1801a0bff52c676e5f51ca71c5350277'
2025-04-20 00:40:47,620 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 947
2025-04-20 00:40:47,621 [cuckoo.core.resultserver] DEBUG: Task #6302234: File upload for 'files/9fd09eb32cb41570_24bd96d5497f70b3f510a6b53cd43f3e_3a89246fb90c5ee6620004f1ae0eb0ea'
2025-04-20 00:40:47,623 [cuckoo.core.resultserver] DEBUG: Task #6302234 uploaded file length: 410
2025-04-20 00:40:47,638 [cuckoo.core.resultserver] DEBUG: Task #6302234 had connection reset for <Context for LOG>
2025-04-20 00:40:49,826 [cuckoo.core.guest] INFO: win7x6430: analysis completed successfully
2025-04-20 00:40:49,854 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-04-20 00:40:49,882 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-04-20 00:40:51,045 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6430 to path /srv/cuckoo/cwd/storage/analyses/6302234/memory.dmp
2025-04-20 00:40:51,069 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6430
2025-04-20 00:42:36,774 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.230 for task #6302234
2025-04-20 00:42:40,941 [cuckoo.core.scheduler] DEBUG: Released database task #6302234
2025-04-20 00:42:41,011 [cuckoo.core.scheduler] INFO: Task #6302234: analysis procedure completed

Signatures

Allocates read-write-execute memory (usually to unpack itself) (50 out of 319 events)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefda18000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefda18000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefda18000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefe35f000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefe336000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefe336000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefe336000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefb04b000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3e34000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefce94000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef9f4c000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef9f64000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef9ecb000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3f64000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefac5a000
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2744
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000003590000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefdc7b000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefdc7b000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefdc7b000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefdc7b000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefd5a1000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef1742000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2744
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3aee000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x002b6000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76e91000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x752dc000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x752dc000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x752dc000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x752d7000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x752d7000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x752d7000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x74e01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76f40000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76f40000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76f40000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75fd0000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x75f71000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76051000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76d01000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76e20000
process_handle: 0xffffffff
1 0 0
Creates executable files on the filesystem (38 events)
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\promoPopup.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\cookiesPopup.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\autocomplete.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\loginDropdown.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\device.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\ajaxSearch.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\helpers.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\headerBuilder.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\mp-checkout-update.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\js_composer_front.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\menuOffsets.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\i18n.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\index[2].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\woocommerce-add-to-cart[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\updateCartFragmentsFix[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\cart-fragments.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\onRemoveFromCart.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\index[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\js.cookie.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\cartWidget.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\v2[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\menuSetUp.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\mp-plugins-components.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\jquery-migrate.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\jquery.blockUI.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\mobileNavigation.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\sourcebuster.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\woocommerceNotices.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\scrollTop.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\woocommerce.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\wishlist.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\order-attribution.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\jquery.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OIYDJQ4H\scrollBar.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5F25PWQK\add-to-cart.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KMPXUNK1\hooks.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\magnific-popup.min[1].js
file C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHPDE3ET\searchFullScreen.min[1].js
Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time) (1 event)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1888
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 16 (PAGE_EXECUTE)
base_address: 0x07c90000
process_handle: 0xffffffff
1 0 0
Uses Windows utilities for basic Windows functionality (1 event)
cmdline "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2744 CREDAT:275457 /prefetch:2
Resumed a suspended thread in a remote process potentially indicative of process injection (2 events)
Process injection Process 2744 resumed a thread in remote process 1888
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x0000000000000370
suspend_count: 1
process_identifier: 1888
1 0 0
File has been identified by 5 AntiVirus engine on IRMA as malicious (5 events)
G Data Antivirus (Windows) Virus: Trojan.GenericKD.76253758 (Engine A)
Avast Core Security (Linux) Script:SNH-gen [Trj]
eScan Antivirus (Linux) Trojan.GenericKD.76253758(DB)
ESET Security (Windows) JS/Agent.RFB trojan
Bitdefender Antivirus (Linux) Trojan.GenericKD.76253758
File has been identified by 7 AntiVirus engines on VirusTotal as malicious (7 events)
ESET-NOD32 JS/Agent.RFB
Avast Script:SNH-gen [Trj]
Rising Trojan.Agent/JS!8.11351 (TOPIS:E0:chePuFYPjYL)
Google Detected
Varist JS/Agent.CNG
Fortinet JS/Agent.RFB!tr
AVG Script:SNH-gen [Trj]
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.