Size | 9.3KB |
---|---|
Type | HTML document, Unicode text, UTF-8 text, with very long lines (358), with CRLF, LF line terminators |
MD5 | 7bd1b136ea21491f54c07400deb9ac76 |
SHA1 | a18e978d2ebe8a9de1aad684f5ad97d60a2d9296 |
SHA256 | 2369e07c244a0d9dc47cd9b4d4b147e1cf715a9280010d0aba9c85076e9abbf4 |
SHA512 |
09042313cb6d06f101f20689ecafc8891dd0b7c1938a00381285672adf356e94ca23c916f53a527ea78f36683e0b36aa77c40638b99bd3f41665c3db881bbd50
|
CRC32 | AE3F60C7 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | April 22, 2025, 11:04 a.m. | April 22, 2025, 11:08 a.m. | 272 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-04-21 01:23:58,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpqqrt4a 2025-04-21 01:23:58,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\JkANGeniztrvNBpVrtuLEMWSJdlIls 2025-04-21 01:23:58,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\VIgXXXlhONUzSCKeyY 2025-04-21 01:23:58,046 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2025-04-21 01:23:58,046 [analyzer] INFO: Automatically selected analysis package "ie" 2025-04-21 01:23:58,467 [analyzer] DEBUG: Started auxiliary module Curtain 2025-04-21 01:23:58,467 [analyzer] DEBUG: Started auxiliary module DbgView 2025-04-21 01:23:58,983 [analyzer] DEBUG: Started auxiliary module Disguise 2025-04-21 01:23:59,187 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-04-21 01:23:59,187 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-04-21 01:23:59,187 [analyzer] DEBUG: Started auxiliary module Human 2025-04-21 01:23:59,187 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-04-21 01:23:59,203 [analyzer] DEBUG: Started auxiliary module Reboot 2025-04-21 01:23:59,265 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-04-21 01:23:59,265 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-04-21 01:23:59,265 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-04-21 01:23:59,265 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-04-21 01:23:59,265 [modules.packages.ie] INFO: Submitted file is missing extension, adding .html 2025-04-21 01:23:59,375 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\2369e07c244a0d9dc47cd9b4d4b147e1cf715a9280010d0aba9c85076e9abbf4.html'] and pid 944 2025-04-21 01:23:59,515 [analyzer] DEBUG: Loaded monitor into process with pid 944 2025-04-21 01:24:01,342 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:944 CREDAT:275457 /prefetch:2! 2025-04-21 01:24:01,437 [analyzer] INFO: Injected into process with pid 2084 and name u'iexplore.exe' 2025-04-21 01:24:01,546 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2084. 2025-04-21 01:24:01,717 [analyzer] INFO: Added new file to list with pid 944 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{89283B6B-1E3E-11F0-853C-D01BC09EA8A1}.dat 2025-04-21 01:24:01,733 [analyzer] DEBUG: Loaded monitor into process with pid 2084 2025-04-21 01:24:01,780 [analyzer] INFO: Added new file to list with pid 944 and path C:\Users\Administrator\AppData\Local\Temp\~DF74A4EE58C2E4011D.TMP 2025-04-21 01:24:01,983 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-04-21 01:24:01,983 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-04-21 01:24:01,983 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-04-21 01:24:01,983 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-04-21 01:24:01,983 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-04-21 01:24:01,983 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-04-21 01:24:01,983 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-04-21 01:24:01,983 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-04-21 01:24:02,000 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-04-21 01:24:02,000 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-04-21 01:24:02,000 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-04-21 01:24:02,000 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-04-21 01:24:02,000 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-04-21 01:24:02,000 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-04-21 01:24:02,530 [analyzer] INFO: Added new file to list with pid 944 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{89283B6D-1E3E-11F0-853C-D01BC09EA8A1}.dat 2025-04-21 01:24:02,562 [analyzer] INFO: Added new file to list with pid 944 and path C:\Users\Administrator\AppData\Local\Temp\~DFF6CB1204496D6A51.TMP 2025-04-21 01:24:02,578 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback. 2025-04-21 01:24:02,578 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback. 2025-04-21 01:24:02,578 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback. 2025-04-21 01:24:02,578 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback. 2025-04-21 01:24:02,578 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback. 2025-04-21 01:24:02,578 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback. 2025-04-21 01:24:02,578 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback. 2025-04-21 01:24:05,733 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3 2025-04-21 01:24:05,750 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3 2025-04-21 01:24:05,750 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\CabCFF7.tmp 2025-04-21 01:24:05,765 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\TarCFF8.tmp 2025-04-21 01:24:05,780 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\CabD019.tmp 2025-04-21 01:24:05,796 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\TarD01A.tmp 2025-04-21 01:24:05,890 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 2025-04-21 01:24:05,905 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 2025-04-21 01:24:05,921 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\CabD098.tmp 2025-04-21 01:24:05,921 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\TarD099.tmp 2025-04-21 01:24:05,921 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\CabD0A9.tmp 2025-04-21 01:24:05,937 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\TarD0AA.tmp 2025-04-21 01:24:06,125 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-04-21 01:24:06,125 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 2025-04-21 01:24:06,171 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 2025-04-21 01:24:06,187 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8 2025-04-21 01:24:06,217 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\CabD1C5.tmp 2025-04-21 01:24:06,217 [analyzer] INFO: Added new file to list with pid 2084 and path C:\Users\Administrator\AppData\Local\Temp\TarD1C6.tmp 2025-04-21 01:24:28,390 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-04-21 01:24:28,875 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-04-21 01:24:28,875 [lib.api.process] INFO: Successfully terminated process with pid 944. 2025-04-21 01:24:28,875 [lib.api.process] INFO: Successfully terminated process with pid 2084. 2025-04-21 01:24:28,875 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd019.tmp' does not exist, skip. 2025-04-21 01:24:28,890 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd1c5.tmp' does not exist, skip. 2025-04-21 01:24:28,905 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd0a9.tmp' does not exist, skip. 2025-04-21 01:24:28,905 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard099.tmp' does not exist, skip. 2025-04-21 01:24:28,921 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard0aa.tmp' does not exist, skip. 2025-04-21 01:24:28,937 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tarcff8.tmp' does not exist, skip. 2025-04-21 01:24:28,937 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabcff7.tmp' does not exist, skip. 2025-04-21 01:24:28,953 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df74a4ee58c2e4011d.tmp' does not exist, skip. 2025-04-21 01:24:28,953 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dff6cb1204496d6a51.tmp' does not exist, skip. 2025-04-21 01:24:28,953 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard01a.tmp' does not exist, skip. 2025-04-21 01:24:28,967 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tard1c6.tmp' does not exist, skip. 2025-04-21 01:24:28,967 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cabd098.tmp' does not exist, skip. 2025-04-21 01:24:28,983 [analyzer] INFO: Analysis completed.
2025-04-22 11:04:02,671 [cuckoo.core.scheduler] INFO: Task #6318945: acquired machine win7x6428 (label=win7x6428) 2025-04-22 11:04:02,672 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.228 for task #6318945 2025-04-22 11:04:03,070 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2034799 (interface=vboxnet0, host=192.168.168.228) 2025-04-22 11:04:03,107 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6428 2025-04-22 11:04:03,775 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6428 to vmcloak 2025-04-22 11:05:45,427 [cuckoo.core.guest] INFO: Starting analysis #6318945 on guest (id=win7x6428, ip=192.168.168.228) 2025-04-22 11:05:46,433 [cuckoo.core.guest] DEBUG: win7x6428: not ready yet 2025-04-22 11:05:51,464 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6428, ip=192.168.168.228) 2025-04-22 11:05:51,572 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6428, ip=192.168.168.228, monitor=latest, size=6660546) 2025-04-22 11:05:53,032 [cuckoo.core.resultserver] DEBUG: Task #6318945: live log analysis.log initialized. 2025-04-22 11:05:54,328 [cuckoo.core.resultserver] DEBUG: Task #6318945 is sending a BSON stream 2025-04-22 11:05:54,493 [cuckoo.core.resultserver] DEBUG: Task #6318945 is sending a BSON stream 2025-04-22 11:05:55,433 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'shots/0001.jpg' 2025-04-22 11:05:55,450 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 133449 2025-04-22 11:05:56,711 [cuckoo.core.resultserver] DEBUG: Task #6318945 is sending a BSON stream 2025-04-22 11:05:57,581 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'shots/0002.jpg' 2025-04-22 11:05:57,584 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 24141 2025-04-22 11:05:58,680 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'shots/0003.jpg' 2025-04-22 11:05:58,683 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 31832 2025-04-22 11:06:01,848 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'shots/0004.jpg' 2025-04-22 11:06:01,859 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 56195 2025-04-22 11:06:07,986 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6318945 still processing 2025-04-22 11:06:23,188 [cuckoo.core.guest] DEBUG: win7x6428: analysis #6318945 still processing 2025-04-22 11:06:23,659 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'curtain/1745191468.61.curtain.log' 2025-04-22 11:06:23,678 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 36 2025-04-22 11:06:23,908 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'sysmon/1745191468.77.sysmon.xml' 2025-04-22 11:06:23,922 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 1152726 2025-04-22 11:06:23,938 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3' 2025-04-22 11:06:23,940 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 889 2025-04-22 11:06:23,951 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/e5c5d41ba1c1b429_{89283b6d-1e3e-11f0-853c-d01bc09ea8a1}.dat' 2025-04-22 11:06:23,953 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 7680 2025-04-22 11:06:23,959 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/ad7960fa74293b67_14232b434cf29d4c4fb335a86d7fffe3' 2025-04-22 11:06:23,962 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 170 2025-04-22 11:06:23,971 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/5c8cb58aa9f863da_b46811c17859ffb409cf0e904a4aa8f8' 2025-04-22 11:06:23,973 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 170 2025-04-22 11:06:23,986 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/fb6a7c3edcd7b97f_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-04-22 11:06:23,989 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 1739 2025-04-22 11:06:23,996 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/f933d22265850f7a_recoverystore.{89283b6b-1e3e-11f0-853c-d01bc09ea8a1}.dat' 2025-04-22 11:06:23,998 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 5632 2025-04-22 11:06:24,002 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/f4ffa983372e9f6e_8b2b9a00839eed1dfdccc3bfc2f5df12' 2025-04-22 11:06:24,004 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 174 2025-04-22 11:06:24,008 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/d72761e1a334a754_94308059b57b3142e455b38a6eb92015' 2025-04-22 11:06:24,010 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 73305 2025-04-22 11:06:24,012 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8' 2025-04-22 11:06:24,015 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 530 2025-04-22 11:06:24,022 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'files/0af59ec6df272f14_94308059b57b3142e455b38a6eb92015' 2025-04-22 11:06:24,024 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 344 2025-04-22 11:06:24,629 [cuckoo.core.resultserver] DEBUG: Task #6318945: File upload for 'shots/0005.jpg' 2025-04-22 11:06:24,645 [cuckoo.core.resultserver] DEBUG: Task #6318945 uploaded file length: 133449 2025-04-22 11:06:24,661 [cuckoo.core.resultserver] DEBUG: Task #6318945 had connection reset for <Context for LOG> 2025-04-22 11:06:26,398 [cuckoo.core.guest] INFO: win7x6428: analysis completed successfully 2025-04-22 11:06:26,618 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-04-22 11:06:26,648 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-04-22 11:06:27,742 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6428 to path /srv/cuckoo/cwd/storage/analyses/6318945/memory.dmp 2025-04-22 11:06:27,743 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6428 2025-04-22 11:08:34,407 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.228 for task #6318945 2025-04-22 11:08:34,837 [cuckoo.core.scheduler] DEBUG: Released database task #6318945 2025-04-22 11:08:34,873 [cuckoo.core.scheduler] INFO: Task #6318945: analysis procedure completed
cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:944 CREDAT:275457 /prefetch:2 |
G Data Antivirus (Windows) | Virus: Trojan.GenericKD.76262747 (Engine A) |
Avast Core Security (Linux) | HTML:Script-inf [Susp] |
eScan Antivirus (Linux) | Trojan.GenericKD.76262747(DB) |
ESET Security (Windows) | JS/Agent.RGI trojan |
DrWeb Antivirus (Linux) | Trojan.Siggen31.15179 |
Bitdefender Antivirus (Linux) | Trojan.GenericKD.76262747 |
Emsisoft Commandline Scanner (Windows) | Trojan.GenericKD.76262747 (B) |
ESET-NOD32 | JS/Agent.RGI |
Avast | HTML:Script-inf [Susp] |
Rising | Trojan.ScrInject/HTML!8.13176 (TOPIS:E1:iCVFM5cNTgI) |
Detected | |
Varist | URL/Agent.MJ.gen!Eldorado |
Fortinet | JS/Agent.RGI!tr |
AVG | HTML:Script-inf [Susp] |