Size | 46.7KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (30858) |
MD5 | c9966db505a5d0eec45dff241614ec33 |
SHA1 | f8922c68c077f97a24691712c5e3fc63bd536ef4 |
SHA256 | 661bc5b37ed7aad3396fb7b89f127a4b708e78b7d3a72b41845f541b8a1abbc9 |
SHA512 |
473f3924499d9b359bcb2ce2e21cf00254207b820259caa8acbe5cfe43d3a26f96d629203048b48e7e019a425b500d1b7136358bb566ce6955b045b1da99be1d
|
CRC32 | 4DE54E6A |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 22, 2025, 11:01 a.m. | April 22, 2025, 11:05 a.m. | 273 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-21 01:12:08,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpl4240h 2025-04-21 01:12:08,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\TsCRJXGUwAEmTfbMInjxGnuhYzVkUcMU 2025-04-21 01:12:08,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\yNoWpHMirzmgkpFVrl 2025-04-21 01:12:08,453 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-21 01:12:08,453 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-21 01:12:08,875 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-21 01:12:09,078 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-04-21 01:12:09,078 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-21 01:12:09,078 [analyzer] DEBUG: Started auxiliary module Human 2025-04-21 01:12:09,078 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-21 01:12:09,078 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-21 01:12:09,203 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-21 01:12:09,203 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-21 01:12:09,203 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-21 01:12:09,203 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-21 01:12:09,203 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-04-21 01:12:09,280 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\661bc5b37ed7aad3396fb7b89f127a4b708e78b7d3a72b41845f541b8a1abbc9.js'] and pid 1788 2025-04-21 01:12:09,500 [analyzer] DEBUG: Loaded monitor into process with pid 1788 2025-04-21 01:12:09,842 [analyzer] INFO: io=NULL 2025-04-21 01:12:09,842 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-21 01:12:09,842 [analyzer] INFO: io=NULL 2025-04-21 01:12:09,842 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-21 01:12:09,842 [analyzer] INFO: io=NULL 2025-04-21 01:12:09,842 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-21 01:12:09,890 [analyzer] INFO: io=NULL 2025-04-21 01:12:09,890 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-04-21 01:12:09,890 [analyzer] INFO: io=NULL 2025-04-21 01:12:09,890 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-04-21 01:12:09,890 [analyzer] INFO: io=NULL 2025-04-21 01:12:09,890 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-04-21 01:12:38,312 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-21 01:12:38,765 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-21 01:12:38,765 [lib.api.process] INFO: Successfully terminated process with pid 1788. 2025-04-21 01:12:38,765 [analyzer] INFO: Analysis completed.
2025-04-22 11:01:35,631 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:36,654 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:37,675 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:38,796 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:39,818 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:40,838 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:41,863 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:42,884 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:43,911 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:44,947 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:45,968 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:47,003 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:48,056 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:49,101 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:50,160 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:51,211 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:52,262 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:53,312 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:54,351 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:55,584 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:56,638 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:57,690 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:01:59,294 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:00,370 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:01,428 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:02,475 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:03,517 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:04,559 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:05,627 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:06,717 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:07,881 [cuckoo.core.scheduler] DEBUG: Task #6318935: no machine available yet 2025-04-22 11:02:09,063 [cuckoo.core.scheduler] INFO: Task #6318935: acquired machine win7x649 (label=win7x649) 2025-04-22 11:02:09,064 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.209 for task #6318935 2025-04-22 11:02:09,491 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2031774 (interface=vboxnet0, host=192.168.168.209) 2025-04-22 11:02:09,591 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x649 2025-04-22 11:02:10,706 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x649 to vmcloak 2025-04-22 11:03:23,352 [cuckoo.core.guest] INFO: Starting analysis #6318935 on guest (id=win7x649, ip=192.168.168.209) 2025-04-22 11:03:24,359 [cuckoo.core.guest] DEBUG: win7x649: not ready yet 2025-04-22 11:03:29,384 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x649, ip=192.168.168.209) 2025-04-22 11:03:29,451 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x649, ip=192.168.168.209, monitor=latest, size=6660546) 2025-04-22 11:03:30,890 [cuckoo.core.resultserver] DEBUG: Task #6318935: live log analysis.log initialized. 2025-04-22 11:03:31,876 [cuckoo.core.resultserver] DEBUG: Task #6318935 is sending a BSON stream 2025-04-22 11:03:32,217 [cuckoo.core.resultserver] DEBUG: Task #6318935 is sending a BSON stream 2025-04-22 11:03:33,183 [cuckoo.core.resultserver] DEBUG: Task #6318935: File upload for 'shots/0001.jpg' 2025-04-22 11:03:33,204 [cuckoo.core.resultserver] DEBUG: Task #6318935 uploaded file length: 133445 2025-04-22 11:03:34,331 [cuckoo.core.resultserver] DEBUG: Task #6318935: File upload for 'shots/0002.jpg' 2025-04-22 11:03:34,348 [cuckoo.core.resultserver] DEBUG: Task #6318935 uploaded file length: 137172 2025-04-22 11:03:45,673 [cuckoo.core.guest] DEBUG: win7x649: analysis #6318935 still processing 2025-04-22 11:04:01,155 [cuckoo.core.guest] DEBUG: win7x649: analysis #6318935 still processing 2025-04-22 11:04:01,419 [cuckoo.core.resultserver] DEBUG: Task #6318935: File upload for 'curtain/1745190758.55.curtain.log' 2025-04-22 11:04:01,422 [cuckoo.core.resultserver] DEBUG: Task #6318935 uploaded file length: 36 2025-04-22 11:04:01,628 [cuckoo.core.resultserver] DEBUG: Task #6318935: File upload for 'sysmon/1745190758.77.sysmon.xml' 2025-04-22 11:04:01,643 [cuckoo.core.resultserver] DEBUG: Task #6318935 uploaded file length: 953952 2025-04-22 11:04:02,531 [cuckoo.core.resultserver] DEBUG: Task #6318935: File upload for 'shots/0003.jpg' 2025-04-22 11:04:02,549 [cuckoo.core.resultserver] DEBUG: Task #6318935 uploaded file length: 133445 2025-04-22 11:04:02,561 [cuckoo.core.resultserver] DEBUG: Task #6318935 had connection reset for <Context for LOG> 2025-04-22 11:04:04,191 [cuckoo.core.guest] INFO: win7x649: analysis completed successfully 2025-04-22 11:04:04,206 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-22 11:04:04,238 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-22 11:04:05,197 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x649 to path /srv/cuckoo/cwd/storage/analyses/6318935/memory.dmp 2025-04-22 11:04:05,199 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x649 2025-04-22 11:05:51,426 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.209 for task #6318935 2025-04-22 11:05:52,084 [cuckoo.core.scheduler] DEBUG: Released database task #6318935 2025-04-22 11:05:52,100 [cuckoo.core.scheduler] INFO: Task #6318935: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
WithSecure (Linux) | Malware.HTML/Redirect.PSDT |
Cynet | Malicious (score: 99) |
F-Secure | Malware.HTML/Redirect.PSDT |
Ikarus | HTML.Redirect |
Detected | |
Avira | HTML/Redirect.PSDT |
Microsoft | Trojan:Win32/SuspExecRep.A!cl |
GData | HTML.Trojan.Agent.BNJR83 |
Fortinet | JS/Kryptik.CFD!tr |