Size | 82.1KB |
---|---|
Type | HTML document, ASCII text, with very long lines (62728) |
MD5 | 04283245b802caeee044c928583fbaf8 |
SHA1 | 4fa3297bcff0cb32c8dff5332158ec06e1c26571 |
SHA256 | 599385e23139a73c256f20623974057d70ccdab477cdabba044c95ab9e2cfd93 |
SHA512 |
fa5b4977a3e0638facdb788d16a126663333b0f1fee0a85568263e79cd6448af3b06c0853dba8f6de52718399fec24644f71f120b68a5a4767f9c4df73507201
|
CRC32 | C84A64F0 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Aug. 18, 2025, 8:09 a.m. | Aug. 18, 2025, 8:15 a.m. | 357 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-15 21:43:55,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpl4240h 2025-08-15 21:43:55,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\yVpkQstMrFGUjzpvfHCm 2025-08-15 21:43:55,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\BxjyjHNyzGjqCrNqjZhWdJ 2025-08-15 21:43:55,342 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-15 21:43:55,342 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-15 21:43:55,828 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-15 21:43:56,046 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-08-15 21:43:56,046 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-15 21:43:56,046 [analyzer] DEBUG: Started auxiliary module Human 2025-08-15 21:43:56,046 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-15 21:43:56,046 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-15 21:43:56,140 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-15 21:43:56,140 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-15 21:43:56,140 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-15 21:43:56,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-15 21:43:56,155 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-08-15 21:43:56,203 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\599385e23139a73c256f20623974057d70ccdab477cdabba044c95ab9e2cfd93.js'] and pid 596 2025-08-15 21:43:56,421 [analyzer] DEBUG: Loaded monitor into process with pid 596 2025-08-15 21:43:56,780 [analyzer] INFO: io=NULL 2025-08-15 21:43:56,780 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-08-15 21:43:56,780 [analyzer] INFO: io=NULL 2025-08-15 21:43:56,780 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-08-15 21:43:56,796 [analyzer] INFO: io=NULL 2025-08-15 21:43:56,796 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-08-15 21:43:56,828 [analyzer] INFO: io=NULL 2025-08-15 21:43:56,828 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-08-15 21:43:56,828 [analyzer] INFO: io=NULL 2025-08-15 21:43:56,828 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-08-15 21:43:56,828 [analyzer] INFO: io=NULL 2025-08-15 21:43:56,842 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-08-15 21:44:25,233 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-08-15 21:44:25,703 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-15 21:44:25,703 [lib.api.process] INFO: Successfully terminated process with pid 596. 2025-08-15 21:44:25,703 [analyzer] INFO: Analysis completed.
2025-08-18 08:09:44,691 [cuckoo.core.scheduler] INFO: Task #6848752: acquired machine win7x649 (label=win7x649) 2025-08-18 08:09:44,692 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.209 for task #6848752 2025-08-18 08:09:45,203 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 4031612 (interface=vboxnet0, host=192.168.168.209) 2025-08-18 08:09:45,239 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x649 2025-08-18 08:09:46,081 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x649 to vmcloak 2025-08-18 08:12:25,366 [cuckoo.core.guest] INFO: Starting analysis #6848752 on guest (id=win7x649, ip=192.168.168.209) 2025-08-18 08:12:26,372 [cuckoo.core.guest] DEBUG: win7x649: not ready yet 2025-08-18 08:12:31,397 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x649, ip=192.168.168.209) 2025-08-18 08:12:31,763 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x649, ip=192.168.168.209, monitor=latest, size=6660546) 2025-08-18 08:12:33,422 [cuckoo.core.resultserver] DEBUG: Task #6848752: live log analysis.log initialized. 2025-08-18 08:12:34,457 [cuckoo.core.resultserver] DEBUG: Task #6848752 is sending a BSON stream 2025-08-18 08:12:34,690 [cuckoo.core.resultserver] DEBUG: Task #6848752 is sending a BSON stream 2025-08-18 08:12:35,602 [cuckoo.core.resultserver] DEBUG: Task #6848752: File upload for 'shots/0001.jpg' 2025-08-18 08:12:35,615 [cuckoo.core.resultserver] DEBUG: Task #6848752 uploaded file length: 133484 2025-08-18 08:12:36,756 [cuckoo.core.resultserver] DEBUG: Task #6848752: File upload for 'shots/0002.jpg' 2025-08-18 08:12:36,770 [cuckoo.core.resultserver] DEBUG: Task #6848752 uploaded file length: 137197 2025-08-18 08:12:48,079 [cuckoo.core.guest] DEBUG: win7x649: analysis #6848752 still processing 2025-08-18 08:13:03,178 [cuckoo.core.guest] DEBUG: win7x649: analysis #6848752 still processing 2025-08-18 08:13:03,822 [cuckoo.core.resultserver] DEBUG: Task #6848752: File upload for 'curtain/1755287065.45.curtain.log' 2025-08-18 08:13:03,825 [cuckoo.core.resultserver] DEBUG: Task #6848752 uploaded file length: 36 2025-08-18 08:13:04,035 [cuckoo.core.resultserver] DEBUG: Task #6848752: File upload for 'sysmon/1755287065.67.sysmon.xml' 2025-08-18 08:13:04,068 [cuckoo.core.resultserver] DEBUG: Task #6848752 uploaded file length: 1614468 2025-08-18 08:13:04,667 [cuckoo.core.resultserver] DEBUG: Task #6848752: File upload for 'shots/0003.jpg' 2025-08-18 08:13:04,685 [cuckoo.core.resultserver] DEBUG: Task #6848752 uploaded file length: 133484 2025-08-18 08:13:04,699 [cuckoo.core.resultserver] DEBUG: Task #6848752 had connection reset for <Context for LOG> 2025-08-18 08:13:06,194 [cuckoo.core.guest] INFO: win7x649: analysis completed successfully 2025-08-18 08:13:06,214 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-18 08:13:06,241 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-18 08:13:07,574 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x649 to path /srv/cuckoo/cwd/storage/analyses/6848752/memory.dmp 2025-08-18 08:13:07,579 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x649 2025-08-18 08:15:42,109 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.209 for task #6848752 2025-08-18 08:15:42,464 [cuckoo.core.scheduler] DEBUG: Released database task #6848752 2025-08-18 08:15:42,484 [cuckoo.core.scheduler] INFO: Task #6848752: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Avast Core Security (Linux) | HTML:Malware-gen |
Avast | HTML:Malware-gen |
NANO-Antivirus | Trojan.Script.Downloader.kslcdq |
Ikarus | Trojan.HTML.Agent |
Detected | |
GData | HTML.Trojan.Agent.GIFUPJ |
Fortinet | JS/Agent.53074!tr |
AVG | HTML:Malware-gen |