| Size | 6.3KB |
|---|---|
| Type | HTML document, Unicode text, UTF-8 text |
| MD5 | c8011c7962e3eedfbe8d3d48685d9dc5 |
| SHA1 | fbc1d310813bd548fa5b9295ae7911ddfd66151d |
| SHA256 | 65d97d50c13598a32d8caa06fc8a73c102925221b3511fe7059f0202bcd4361b |
| SHA512 |
d4288f143456fcd9542824ea50a0fd2d334a0bf0f48724ed0a397db89f43c9f94dbf7796009bfc09e46a724291bc19db54d05ba96d9066d35c604c211f87f841
|
| CRC32 | 0BDDA691 |
| ssdeep | None |
| Yara | None matched |
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Jan. 12, 2026, 2:03 a.m. | Jan. 12, 2026, 2:10 a.m. | 419 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-01-11 08:51:19,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpj6atou
2026-01-11 08:51:19,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\FGuwMRseazcMNyUAfpfABmneyZRusAJ
2026-01-11 08:51:19,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\JEGTXAPCXckeRRljPZDoLq
2026-01-11 08:51:19,046 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2026-01-11 08:51:19,046 [analyzer] INFO: Automatically selected analysis package "ie"
2026-01-11 08:51:19,312 [analyzer] DEBUG: Started auxiliary module Curtain
2026-01-11 08:51:19,312 [analyzer] DEBUG: Started auxiliary module DbgView
2026-01-11 08:51:20,030 [analyzer] DEBUG: Started auxiliary module Disguise
2026-01-11 08:51:20,233 [analyzer] DEBUG: Loaded monitor into process with pid 504
2026-01-11 08:51:20,233 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2026-01-11 08:51:20,233 [analyzer] DEBUG: Started auxiliary module Human
2026-01-11 08:51:20,233 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2026-01-11 08:51:20,233 [analyzer] DEBUG: Started auxiliary module Reboot
2026-01-11 08:51:20,328 [analyzer] DEBUG: Started auxiliary module RecentFiles
2026-01-11 08:51:20,328 [analyzer] DEBUG: Started auxiliary module Screenshots
2026-01-11 08:51:20,328 [analyzer] DEBUG: Started auxiliary module Sysmon
2026-01-11 08:51:20,328 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2026-01-11 08:51:20,328 [modules.packages.ie] INFO: Submitted file is missing extension, adding .html
2026-01-11 08:51:20,453 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\65d97d50c13598a32d8caa06fc8a73c102925221b3511fe7059f0202bcd4361b.html'] and pid 2244
2026-01-11 08:51:20,608 [analyzer] DEBUG: Loaded monitor into process with pid 2244
2026-01-11 08:51:22,265 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2244 CREDAT:275457 /prefetch:2!
2026-01-11 08:51:22,328 [analyzer] INFO: Injected into process with pid 2192 and name u'iexplore.exe'
2026-01-11 08:51:22,405 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2192.
2026-01-11 08:51:22,515 [analyzer] INFO: Added new file to list with pid 2244 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{50EBE1AD-EEC2-11F0-B0F9-4ECB35129F8C}.dat
2026-01-11 08:51:22,578 [analyzer] INFO: Added new file to list with pid 2244 and path C:\Users\Administrator\AppData\Local\Temp\~DF3770488B901B6DBF.TMP
2026-01-11 08:51:22,608 [analyzer] DEBUG: Loaded monitor into process with pid 2192
2026-01-11 08:51:22,828 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-01-11 08:51:22,828 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-01-11 08:51:22,828 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-01-11 08:51:22,828 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-01-11 08:51:22,828 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-01-11 08:51:22,842 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-01-11 08:51:22,842 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-01-11 08:51:22,842 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-01-11 08:51:22,842 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-01-11 08:51:22,842 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-01-11 08:51:22,842 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-01-11 08:51:22,858 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-01-11 08:51:22,858 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-01-11 08:51:22,858 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-01-11 08:51:23,171 [analyzer] INFO: Added new file to list with pid 2244 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{50EBE1AF-EEC2-11F0-B0F9-4ECB35129F8C}.dat
2026-01-11 08:51:23,187 [analyzer] INFO: Added new file to list with pid 2244 and path C:\Users\Administrator\AppData\Local\Temp\~DFE38FD98EB3C89FC4.TMP
2026-01-11 08:51:23,233 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-01-11 08:51:23,233 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-01-11 08:51:23,233 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-01-11 08:51:23,233 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-01-11 08:51:23,233 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-01-11 08:51:23,233 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-01-11 08:51:23,233 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-01-11 08:51:28,717 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2026-01-11 08:51:28,717 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2026-01-11 08:51:28,733 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab3162.tmp
2026-01-11 08:51:28,750 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar3163.tmp
2026-01-11 08:51:28,750 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab3173.tmp
2026-01-11 08:51:28,750 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar3184.tmp
2026-01-11 08:51:28,890 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2026-01-11 08:51:28,890 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2026-01-11 08:51:28,905 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab3221.tmp
2026-01-11 08:51:28,921 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar3222.tmp
2026-01-11 08:51:28,937 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab3242.tmp
2026-01-11 08:51:28,937 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar3243.tmp
2026-01-11 08:51:29,108 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2026-01-11 08:51:29,108 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2026-01-11 08:51:29,187 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2026-01-11 08:51:29,187 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2026-01-11 08:51:29,203 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Cab334E.tmp
2026-01-11 08:51:29,217 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Tar334F.tmp
2026-01-11 08:51:49,453 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2026-01-11 08:51:49,796 [analyzer] INFO: Terminating remaining processes before shutdown.
2026-01-11 08:51:49,796 [lib.api.process] INFO: Successfully terminated process with pid 2244.
2026-01-11 08:51:49,812 [lib.api.process] INFO: Successfully terminated process with pid 2192.
2026-01-11 08:51:49,812 [analyzer] INFO: Error dumping file from path "c:\users\administrator\appdata\local\temp\~df3770488b901b6dbf.tmp": [Errno 13] Permission denied: u'c:\\users\\administrator\\appdata\\local\\temp\\~df3770488b901b6dbf.tmp'
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar3163.tmp' does not exist, skip.
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab3162.tmp' does not exist, skip.
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab3173.tmp' does not exist, skip.
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar334f.tmp' does not exist, skip.
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab3242.tmp' does not exist, skip.
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar3243.tmp' does not exist, skip.
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar3222.tmp' does not exist, skip.
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab334e.tmp' does not exist, skip.
2026-01-11 08:51:49,842 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab3221.tmp' does not exist, skip.
2026-01-11 08:51:49,858 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dfe38fd98eb3c89fc4.tmp' does not exist, skip.
2026-01-11 08:51:49,875 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar3184.tmp' does not exist, skip.
2026-01-11 08:51:49,875 [analyzer] INFO: Analysis completed.
2026-01-12 02:03:45,164 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:46,211 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:47,227 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:48,251 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:49,301 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:50,367 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:51,431 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:52,632 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:53,802 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:54,826 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:55,851 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:56,871 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:57,893 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:58,919 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:03:59,942 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:00,963 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:02,001 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:03,048 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:04,092 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:05,381 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:06,487 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:07,563 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:08,582 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:09,607 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:10,633 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:11,675 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:12,699 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:13,711 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:14,730 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:16,054 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:17,108 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:18,150 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:19,186 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:20,229 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:21,267 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:22,309 [cuckoo.core.scheduler] DEBUG: Task #7289636: no machine available yet
2026-01-12 02:04:23,358 [cuckoo.core.scheduler] INFO: Task #7289636: acquired machine win7x6416 (label=win7x6416)
2026-01-12 02:04:23,359 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.216 for task #7289636
2026-01-12 02:04:23,741 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 1080638 (interface=vboxnet0, host=192.168.168.216)
2026-01-12 02:04:23,773 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6416
2026-01-12 02:04:24,826 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6416 to vmcloak
2026-01-12 02:07:24,022 [cuckoo.core.guest] INFO: Starting analysis #7289636 on guest (id=win7x6416, ip=192.168.168.216)
2026-01-12 02:07:25,030 [cuckoo.core.guest] DEBUG: win7x6416: not ready yet
2026-01-12 02:07:30,138 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6416, ip=192.168.168.216)
2026-01-12 02:07:30,233 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6416, ip=192.168.168.216, monitor=latest, size=6660546)
2026-01-12 02:07:31,668 [cuckoo.core.resultserver] DEBUG: Task #7289636: live log analysis.log initialized.
2026-01-12 02:07:33,018 [cuckoo.core.resultserver] DEBUG: Task #7289636 is sending a BSON stream
2026-01-12 02:07:33,222 [cuckoo.core.resultserver] DEBUG: Task #7289636 is sending a BSON stream
2026-01-12 02:07:34,244 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'shots/0001.jpg'
2026-01-12 02:07:34,274 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 133564
2026-01-12 02:07:35,374 [cuckoo.core.resultserver] DEBUG: Task #7289636 is sending a BSON stream
2026-01-12 02:07:36,377 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'shots/0002.jpg'
2026-01-12 02:07:36,380 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 24345
2026-01-12 02:07:37,469 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'shots/0003.jpg'
2026-01-12 02:07:37,472 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 31731
2026-01-12 02:07:46,365 [cuckoo.core.guest] DEBUG: win7x6416: analysis #7289636 still processing
2026-01-12 02:07:59,051 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'shots/0004.jpg'
2026-01-12 02:07:59,054 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 36416
2026-01-12 02:08:01,915 [cuckoo.core.guest] DEBUG: win7x6416: analysis #7289636 still processing
2026-01-12 02:08:02,260 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'curtain/1768117909.58.curtain.log'
2026-01-12 02:08:02,263 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 36
2026-01-12 02:08:02,465 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'sysmon/1768117909.78.sysmon.xml'
2026-01-12 02:08:02,486 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 1710452
2026-01-12 02:08:02,493 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/cd3fa1e7d7dbc904_{50ebe1af-eec2-11f0-b0f9-4ecb35129f8c}.dat'
2026-01-12 02:08:02,497 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 5120
2026-01-12 02:08:02,504 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/ebd41040e4bb3ec7_14232b434cf29d4c4fb335a86d7fffe3'
2026-01-12 02:08:02,506 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 889
2026-01-12 02:08:02,510 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/6f076a8e5a032534_14232b434cf29d4c4fb335a86d7fffe3'
2026-01-12 02:08:02,511 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 170
2026-01-12 02:08:02,514 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/48c3f02e8ea2f726_b46811c17859ffb409cf0e904a4aa8f8'
2026-01-12 02:08:02,517 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 170
2026-01-12 02:08:02,682 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/70361fc5bd4a7fbf_8b2b9a00839eed1dfdccc3bfc2f5df12'
2026-01-12 02:08:02,689 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 1739
2026-01-12 02:08:02,691 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/8eb9de813ab7bd23_8b2b9a00839eed1dfdccc3bfc2f5df12'
2026-01-12 02:08:02,718 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 174
2026-01-12 02:08:02,721 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/33ba8221ff3f5211_94308059b57b3142e455b38a6eb92015'
2026-01-12 02:08:02,730 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 73211
2026-01-12 02:08:02,732 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/cf5ff9138614a429_recoverystore.{50ebe1ad-eec2-11f0-b0f9-4ecb35129f8c}.dat'
2026-01-12 02:08:02,736 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 5632
2026-01-12 02:08:02,737 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/6fb1b8e593cb0388_b46811c17859ffb409cf0e904a4aa8f8'
2026-01-12 02:08:02,739 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 530
2026-01-12 02:08:02,740 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'files/2800477c5ed727d2_94308059b57b3142e455b38a6eb92015'
2026-01-12 02:08:02,741 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 344
2026-01-12 02:08:03,274 [cuckoo.core.resultserver] DEBUG: Task #7289636: File upload for 'shots/0005.jpg'
2026-01-12 02:08:03,302 [cuckoo.core.resultserver] DEBUG: Task #7289636 uploaded file length: 133564
2026-01-12 02:08:03,315 [cuckoo.core.resultserver] DEBUG: Task #7289636 had connection reset for <Context for LOG>
2026-01-12 02:08:04,938 [cuckoo.core.guest] INFO: win7x6416: analysis completed successfully
2026-01-12 02:08:04,952 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2026-01-12 02:08:04,977 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2026-01-12 02:08:06,132 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6416 to path /srv/cuckoo/cwd/storage/analyses/7289636/memory.dmp
2026-01-12 02:08:06,133 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6416
2026-01-12 02:10:34,285 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.216 for task #7289636
2026-01-12 02:10:34,821 [cuckoo.core.scheduler] DEBUG: Released database task #7289636
2026-01-12 02:10:44,983 [cuckoo.core.scheduler] INFO: Task #7289636: analysis procedure completed
| cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2244 CREDAT:275457 /prefetch:2 |
| G Data Antivirus (Windows) | Virus: Trojan.GenericKD.78270303 (Engine A) |
| Avast Core Security (Linux) | HTML:DatingScam-D [Scam] |
| eScan Antivirus (Linux) | Trojan.GenericKD.78270303(DB) |
| Bitdefender Antivirus (Linux) | Trojan.GenericKD.78270303 |
| Emsisoft Commandline Scanner (Windows) | Trojan.GenericKD.78270303 (B) |
| Avast | HTML:DatingScam-D [Scam] |
| Cynet | Malicious (score: 99) |
| Rising | Trojan.Redirector/HTML!8.1290C (TOPIS:E0:XimDfE7CQkU) |
| Ikarus | Trojan.JS.Redirector |
| Detected | |
| Microsoft | Trojan:JS/Redirector.ABOB!MTB |
| Varist | JS/Phish.AYV!Eldorado |
| Fortinet | JS/Agent.AYV!tr |
| AVG | HTML:DatingScam-D [Scam] |