Size | 17.3KB |
---|---|
Type | ASCII text, with very long lines (17665), with no line terminators |
MD5 | b3d4494a551a4bc845d0a8b78a080c99 |
SHA1 | 7e5a83c20b655be06291a6a82d123e2e0ca9237b |
SHA256 | b942343e5cdcb999ac902bfdafa8a8bb2da3aeeb99c28c8e7b33c05bdd852123 |
SHA512 |
42cdd7764de789b38489028f6583415924acd5258297f593fb8fe51b992cfcf45dc462a22243ad67fdd4a4cfe914ccb8a6aa2b1aefae30e0e99996492faa94e1
|
CRC32 | 8F9C5124 |
ssdeep | None |
Yara | None matched |
This file is very suspicious, with a score of 5.9 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | Aug. 30, 2025, 10:48 a.m. | Aug. 30, 2025, 10:49 a.m. | 62 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-08-26 21:01:45,000 [analyzer] DEBUG: Starting analyzer from: C:\tmppw5mq4 2025-08-26 21:01:45,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\trKhwiCAVrQHJdKxxLROsc 2025-08-26 21:01:45,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\OpjBtfLfizMmHnOEbRIn 2025-08-26 21:01:45,375 [analyzer] DEBUG: Started auxiliary module Curtain 2025-08-26 21:01:45,375 [analyzer] DEBUG: Started auxiliary module DbgView 2025-08-26 21:01:45,858 [analyzer] DEBUG: Started auxiliary module Disguise 2025-08-26 21:01:46,046 [analyzer] DEBUG: Loaded monitor into process with pid 504 2025-08-26 21:01:46,046 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-08-26 21:01:46,046 [analyzer] DEBUG: Started auxiliary module Human 2025-08-26 21:01:46,046 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-08-26 21:01:46,046 [analyzer] DEBUG: Started auxiliary module Reboot 2025-08-26 21:01:46,140 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-08-26 21:01:46,140 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-08-26 21:01:46,140 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-08-26 21:01:46,140 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-08-26 21:01:46,140 [modules.packages.js] INFO: Submitted file is missing extension, added .js 2025-08-26 21:01:46,203 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\wscript.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\b942343e5cdcb999ac902bfdafa8a8bb2da3aeeb99c28c8e7b33c05bdd852123.js'] and pid 2304 2025-08-26 21:01:46,453 [analyzer] DEBUG: Loaded monitor into process with pid 2304 2025-08-26 21:01:46,796 [analyzer] INFO: io=NULL 2025-08-26 21:01:46,796 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-08-26 21:01:46,796 [analyzer] INFO: io=NULL 2025-08-26 21:01:46,796 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-08-26 21:01:46,796 [analyzer] INFO: io=NULL 2025-08-26 21:01:46,796 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-08-26 21:01:46,842 [analyzer] INFO: io=NULL 2025-08-26 21:01:46,842 [analyzer] DEBUG: Error resolving function jscript!ActiveXObjectFncObj_Construct through our custom callback. 2025-08-26 21:01:46,842 [analyzer] INFO: io=NULL 2025-08-26 21:01:46,842 [analyzer] DEBUG: Error resolving function jscript!COleScript_Compile through our custom callback. 2025-08-26 21:01:46,842 [analyzer] INFO: io=NULL 2025-08-26 21:01:46,842 [analyzer] DEBUG: Error resolving function jscript!Math_random through our custom callback. 2025-08-26 21:02:15,265 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-08-26 21:02:15,687 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-08-26 21:02:15,703 [lib.api.process] INFO: Successfully terminated process with pid 2304. 2025-08-26 21:02:15,703 [analyzer] INFO: Analysis completed.
2025-08-30 10:48:17,895 [cuckoo.core.scheduler] INFO: Task #6931149: acquired machine win7x646 (label=win7x646) 2025-08-30 10:48:17,897 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.206 for task #6931149 2025-08-30 10:48:18,437 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2647886 (interface=vboxnet0, host=192.168.168.206) 2025-08-30 10:48:18,509 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x646 2025-08-30 10:48:19,339 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x646 to vmcloak 2025-08-30 10:48:29,568 [cuckoo.core.guest] INFO: Starting analysis #6931149 on guest (id=win7x646, ip=192.168.168.206) 2025-08-30 10:48:30,574 [cuckoo.core.guest] DEBUG: win7x646: not ready yet 2025-08-30 10:48:35,754 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x646, ip=192.168.168.206) 2025-08-30 10:48:35,831 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x646, ip=192.168.168.206, monitor=latest, size=6660546) 2025-08-30 10:48:37,137 [cuckoo.core.resultserver] DEBUG: Task #6931149: live log analysis.log initialized. 2025-08-30 10:48:38,143 [cuckoo.core.resultserver] DEBUG: Task #6931149 is sending a BSON stream 2025-08-30 10:48:38,438 [cuckoo.core.resultserver] DEBUG: Task #6931149 is sending a BSON stream 2025-08-30 10:48:39,756 [cuckoo.core.resultserver] DEBUG: Task #6931149: File upload for 'shots/0001.jpg' 2025-08-30 10:48:39,784 [cuckoo.core.resultserver] DEBUG: Task #6931149 uploaded file length: 133477 2025-08-30 10:48:40,893 [cuckoo.core.resultserver] DEBUG: Task #6931149: File upload for 'shots/0002.jpg' 2025-08-30 10:48:40,932 [cuckoo.core.resultserver] DEBUG: Task #6931149 uploaded file length: 138644 2025-08-30 10:48:52,048 [cuckoo.core.guest] DEBUG: win7x646: analysis #6931149 still processing 2025-08-30 10:49:07,259 [cuckoo.core.guest] DEBUG: win7x646: analysis #6931149 still processing 2025-08-30 10:49:07,683 [cuckoo.core.resultserver] DEBUG: Task #6931149: File upload for 'curtain/1756234935.52.curtain.log' 2025-08-30 10:49:07,704 [cuckoo.core.resultserver] DEBUG: Task #6931149 uploaded file length: 36 2025-08-30 10:49:07,853 [cuckoo.core.resultserver] DEBUG: Task #6931149: File upload for 'sysmon/1756234935.69.sysmon.xml' 2025-08-30 10:49:07,862 [cuckoo.core.resultserver] DEBUG: Task #6931149 uploaded file length: 508942 2025-08-30 10:49:07,895 [cuckoo.core.resultserver] DEBUG: Task #6931149 had connection reset for <Context for LOG> 2025-08-30 10:49:10,275 [cuckoo.core.guest] INFO: win7x646: analysis completed successfully 2025-08-30 10:49:10,287 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-08-30 10:49:10,314 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-08-30 10:49:11,537 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x646 to path /srv/cuckoo/cwd/storage/analyses/6931149/memory.dmp 2025-08-30 10:49:11,538 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x646 2025-08-30 10:49:19,494 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.206 for task #6931149 2025-08-30 10:49:19,797 [cuckoo.core.scheduler] DEBUG: Released database task #6931149 2025-08-30 10:49:19,815 [cuckoo.core.scheduler] INFO: Task #6931149: analysis procedure completed
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
Avast Core Security (Linux) | Script:SNH-gen [Trj] |
Symantec | JS.Malscript!g1 |
Ikarus | Trojan.JS.Redirector |