| URL |
|---|
| https://r.beetween-software.com/tr/cl/EDjrqmg3oDAyDKRbQ9pjaeB676Sa8TQi85cSy72sDDDk0rjhOoprXZlgrOMIXoE8A0MBp7Nwvl8wCwahvOi5PMu2nXSFlpVJBi7ua6VjO9TWmjrUjmnKLA9qbL2XIvhY_fcgRIDi-2J8qwVuQJtIjylKwOiTVCPMf_foDUEIT_YXNSLqBau6quGkeT5t4HAWdiasu97g8E8pvbHRTofNQmOiNx-O9umn2CKAk5-d4I3a09k3tf2NyfCcteGN8oTBYbSW7Q1N2pTQ5Mcd23YFBodZzjLTgIpaNAdLggaR4L7vDVTAqU1IRO4k8iGMyflVYBu0gAtEHR0Bv42UaYqPF3a0A7oT1P8Ru19zxIF7iPT61WRLUCWgrEDh_1GTOQSc-alcyA0cqT7ABWUNa8q0CqFtVQuLla3L28shzt9Y-FivIKK2 |
This url shows some signs of potential malicious behavior.
The score of this url is 1.1 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| URL | April 2, 2026, 4:20 a.m. | April 2, 2026, 4:21 a.m. | 61 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-04-02 04:20:56,000 [analyzer] DEBUG: Starting analyzer from: C:\tmphzbxu3
2026-04-02 04:20:56,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\CRowJXfXWWaLlFmFhI
2026-04-02 04:20:56,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\ZWZTrsZHMfnAqgQNQQXwvabmudDZk
2026-04-02 04:20:56,265 [analyzer] DEBUG: Started auxiliary module Curtain
2026-04-02 04:20:56,265 [analyzer] DEBUG: Started auxiliary module DbgView
2026-04-02 04:20:56,655 [analyzer] DEBUG: Started auxiliary module Disguise
2026-04-02 04:20:56,858 [analyzer] DEBUG: Loaded monitor into process with pid 500
2026-04-02 04:20:56,858 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2026-04-02 04:20:56,858 [analyzer] DEBUG: Started auxiliary module Human
2026-04-02 04:20:56,858 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2026-04-02 04:20:56,858 [analyzer] DEBUG: Started auxiliary module Reboot
2026-04-02 04:20:56,953 [analyzer] DEBUG: Started auxiliary module RecentFiles
2026-04-02 04:20:56,953 [analyzer] DEBUG: Started auxiliary module Screenshots
2026-04-02 04:20:56,953 [analyzer] DEBUG: Started auxiliary module Sysmon
2026-04-02 04:20:56,953 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2026-04-02 04:20:57,062 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://r.beetween-software.com/tr/cl/EDjrqmg3oDAyDKRbQ9pjaeB676Sa8TQi85cSy72sDDDk0rjhOoprXZlgrOMIXoE8A0MBp7Nwvl8wCwahvOi5PMu2nXSFlpVJBi7ua6VjO9TWmjrUjmnKLA9qbL2XIvhY_fcgRIDi-2J8qwVuQJtIjylKwOiTVCPMf_foDUEIT_YXNSLqBau6quGkeT5t4HAWdiasu97g8E8pvbHRTofNQmOiNx-O9umn2CKAk5-d4I3a09k3tf2NyfCcteGN8oTBYbSW7Q1N2pTQ5Mcd23YFBodZzjLTgIpaNAdLggaR4L7vDVTAqU1IRO4k8iGMyflVYBu0gAtEHR0Bv42UaYqPF3a0A7oT1P8Ru19zxIF7iPT61WRLUCWgrEDh_1GTOQSc-alcyA0cqT7ABWUNa8q0CqFtVQuLla3L28shzt9Y-FivIKK2'] and pid 1292
2026-04-02 04:20:57,203 [analyzer] DEBUG: Loaded monitor into process with pid 1292
2026-04-02 04:20:58,578 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1292 CREDAT:275457 /prefetch:2!
2026-04-02 04:20:58,640 [analyzer] INFO: Injected into process with pid 352 and name u'iexplore.exe'
2026-04-02 04:20:58,750 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 352.
2026-04-02 04:20:58,890 [analyzer] INFO: Added new file to list with pid 1292 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{94B5E309-2E3A-11F1-AD26-C68B0C3313EF}.dat
2026-04-02 04:20:58,937 [analyzer] DEBUG: Loaded monitor into process with pid 352
2026-04-02 04:20:58,967 [analyzer] INFO: Added new file to list with pid 1292 and path C:\Users\Administrator\AppData\Local\Temp\~DF27D7B103B23EF9D7.TMP
2026-04-02 04:20:59,233 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-04-02 04:20:59,250 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-04-02 04:20:59,265 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-04-02 04:20:59,265 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-04-02 04:20:59,265 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-04-02 04:20:59,265 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-04-02 04:20:59,453 [analyzer] INFO: Added new file to list with pid 1292 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{94B5E30B-2E3A-11F1-AD26-C68B0C3313EF}.dat
2026-04-02 04:20:59,453 [analyzer] INFO: Added new file to list with pid 1292 and path C:\Users\Administrator\AppData\Local\Temp\~DFC0492CFD7B91D7C5.TMP
2026-04-02 04:21:02,546 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
2026-04-02 04:21:02,546 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
2026-04-02 04:21:02,562 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8476.tmp
2026-04-02 04:21:02,578 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8477.tmp
2026-04-02 04:21:02,687 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab84E5.tmp
2026-04-02 04:21:02,687 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar84E6.tmp
2026-04-02 04:21:02,733 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2026-04-02 04:21:02,733 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2026-04-02 04:21:02,765 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8545.tmp
2026-04-02 04:21:02,780 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8546.tmp
2026-04-02 04:21:02,796 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8566.tmp
2026-04-02 04:21:02,812 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8567.tmp
2026-04-02 04:21:02,842 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8588.tmp
2026-04-02 04:21:02,842 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8589.tmp
2026-04-02 04:21:02,858 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8599.tmp
2026-04-02 04:21:02,858 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar85AA.tmp
2026-04-02 04:21:02,921 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab85E9.tmp
2026-04-02 04:21:02,937 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar85EA.tmp
2026-04-02 04:21:02,937 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab85FB.tmp
2026-04-02 04:21:02,937 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar85FC.tmp
2026-04-02 04:21:02,967 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab861C.tmp
2026-04-02 04:21:02,983 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar861D.tmp
2026-04-02 04:21:02,983 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab862E.tmp
2026-04-02 04:21:02,983 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar862F.tmp
2026-04-02 04:21:03,046 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab866E.tmp
2026-04-02 04:21:03,062 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar866F.tmp
2026-04-02 04:21:03,062 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8680.tmp
2026-04-02 04:21:03,078 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8681.tmp
2026-04-02 04:21:03,092 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab86A1.tmp
2026-04-02 04:21:03,108 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar86A2.tmp
2026-04-02 04:21:03,108 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab86B3.tmp
2026-04-02 04:21:03,125 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar86B4.tmp
2026-04-02 04:21:03,187 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab86F3.tmp
2026-04-02 04:21:03,187 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8705.tmp
2026-04-02 04:21:03,187 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8706.tmp
2026-04-02 04:21:03,187 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8704.tmp
2026-04-02 04:21:03,233 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8726.tmp
2026-04-02 04:21:03,233 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8738.tmp
2026-04-02 04:21:03,233 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8727.tmp
2026-04-02 04:21:03,233 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8739.tmp
2026-04-02 04:21:03,312 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8778.tmp
2026-04-02 04:21:03,312 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab878A.tmp
2026-04-02 04:21:03,312 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8779.tmp
2026-04-02 04:21:03,312 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar878B.tmp
2026-04-02 04:21:03,358 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab87AB.tmp
2026-04-02 04:21:03,358 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab87AC.tmp
2026-04-02 04:21:03,358 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar87AE.tmp
2026-04-02 04:21:03,358 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar87AD.tmp
2026-04-02 04:21:03,421 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab87FD.tmp
2026-04-02 04:21:03,437 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab87FF.tmp
2026-04-02 04:21:03,437 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar87FE.tmp
2026-04-02 04:21:03,437 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8800.tmp
2026-04-02 04:21:03,467 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8830.tmp
2026-04-02 04:21:03,483 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8832.tmp
2026-04-02 04:21:03,483 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8831.tmp
2026-04-02 04:21:03,483 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8833.tmp
2026-04-02 04:21:03,546 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8882.tmp
2026-04-02 04:21:03,546 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8884.tmp
2026-04-02 04:21:03,562 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8883.tmp
2026-04-02 04:21:03,562 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8885.tmp
2026-04-02 04:21:03,592 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab88B5.tmp
2026-04-02 04:21:03,592 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab88B7.tmp
2026-04-02 04:21:03,592 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar88B8.tmp
2026-04-02 04:21:03,608 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar88B6.tmp
2026-04-02 04:21:03,671 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab88F8.tmp
2026-04-02 04:21:03,671 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8909.tmp
2026-04-02 04:21:03,671 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8908.tmp
2026-04-02 04:21:03,671 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar890A.tmp
2026-04-02 04:21:03,703 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab892B.tmp
2026-04-02 04:21:03,717 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab892D.tmp
2026-04-02 04:21:03,717 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar892C.tmp
2026-04-02 04:21:03,717 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar892E.tmp
2026-04-02 04:21:03,780 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab897D.tmp
2026-04-02 04:21:03,780 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab897F.tmp
2026-04-02 04:21:03,796 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar897E.tmp
2026-04-02 04:21:03,796 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8980.tmp
2026-04-02 04:21:03,983 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8A3C.tmp
2026-04-02 04:21:03,983 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8A3D.tmp
2026-04-02 04:21:04,078 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8A9C.tmp
2026-04-02 04:21:04,078 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8AAD.tmp
2026-04-02 04:21:04,140 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8ADC.tmp
2026-04-02 04:21:04,140 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8AED.tmp
2026-04-02 04:21:04,250 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8B4C.tmp
2026-04-02 04:21:04,250 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8B4D.tmp
2026-04-02 04:21:04,296 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8B8C.tmp
2026-04-02 04:21:04,328 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8B8D.tmp
2026-04-02 04:21:04,421 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8C0B.tmp
2026-04-02 04:21:04,437 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8C0C.tmp
2026-04-02 04:21:04,483 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8C4C.tmp
2026-04-02 04:21:04,500 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8C4D.tmp
2026-04-02 04:21:04,592 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8CAC.tmp
2026-04-02 04:21:04,592 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8CAD.tmp
2026-04-02 04:21:04,640 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8CEC.tmp
2026-04-02 04:21:04,655 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8CED.tmp
2026-04-02 04:21:04,733 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8D4C.tmp
2026-04-02 04:21:04,750 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8D4D.tmp
2026-04-02 04:21:04,796 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8D7D.tmp
2026-04-02 04:21:04,796 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8D7E.tmp
2026-04-02 04:21:04,905 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Cab8DEC.tmp
2026-04-02 04:21:04,905 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Temp\Tar8DED.tmp
2026-04-02 04:21:04,983 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2026-04-02 04:21:04,983 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2026-04-02 04:21:04,983 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2026-04-02 04:21:04,983 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2026-04-02 04:21:04,983 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2026-04-02 04:21:04,983 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2026-04-02 04:21:04,983 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2026-04-02 04:21:05,000 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F9CGS68Y\invalidcert[1]
2026-04-02 04:21:05,078 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W861N6F0\ErrorPageTemplate[1]
2026-04-02 04:21:05,092 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YKXY50FX\errorPageStrings[1]
2026-04-02 04:21:05,125 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F9CGS68Y\httpErrorPagesScripts[1]
2026-04-02 04:21:05,125 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W861N6F0\invalidcert[1]
2026-04-02 04:21:05,140 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1WKJNSC4\red_shield_48[1]
2026-04-02 04:21:05,171 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YKXY50FX\green_shield[1]
2026-04-02 04:21:05,171 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F9CGS68Y\red_shield[1]
2026-04-02 04:21:05,187 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W861N6F0\down[1]
2026-04-02 04:21:05,265 [analyzer] INFO: Added new file to list with pid 352 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1WKJNSC4\background_gradient_red[1]
2026-04-02 03:21:45,908 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2026-04-02 03:21:46,127 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1292.
2026-04-02 03:21:46,204 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 352.
2026-04-02 03:21:46,440 [analyzer] INFO: Terminating remaining processes before shutdown.
2026-04-02 03:21:46,440 [lib.api.process] INFO: Successfully terminated process with pid 1292.
2026-04-02 03:21:46,440 [lib.api.process] INFO: Successfully terminated process with pid 352.
2026-04-02 03:21:46,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8830.tmp' does not exist, skip.
2026-04-02 03:21:46,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab87ac.tmp' does not exist, skip.
2026-04-02 03:21:46,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8b4c.tmp' does not exist, skip.
2026-04-02 03:21:46,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab892b.tmp' does not exist, skip.
2026-04-02 03:21:46,440 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab861c.tmp' does not exist, skip.
2026-04-02 03:21:46,454 [analyzer] INFO: Error dumping file from path "c:\users\administrator\appdata\local\temp\~dfc0492cfd7b91d7c5.tmp": [Errno 13] Permission denied: u'c:\\users\\administrator\\appdata\\local\\temp\\~dfc0492cfd7b91d7c5.tmp'
2026-04-02 03:21:46,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8d4c.tmp' does not exist, skip.
2026-04-02 03:21:46,454 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar85aa.tmp' does not exist, skip.
2026-04-02 03:21:46,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar87fe.tmp' does not exist, skip.
2026-04-02 03:21:46,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8dec.tmp' does not exist, skip.
2026-04-02 03:21:46,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8832.tmp' does not exist, skip.
2026-04-02 03:21:46,470 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8b8c.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8706.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8567.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar86a2.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8adc.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab86b3.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar892e.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8b8d.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab892d.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8779.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab85fb.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab878a.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8705.tmp' does not exist, skip.
2026-04-02 03:21:46,486 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab88b5.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8908.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8a9c.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8727.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8cac.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8909.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8882.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar892c.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab862e.tmp' does not exist, skip.
2026-04-02 03:21:46,502 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8800.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar87ae.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8831.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab87ff.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar861d.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar866f.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8884.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar88b6.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df27d7b103b23ef9d7.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8566.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8885.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar85ea.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8680.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar88b8.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8589.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8ded.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8476.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar890a.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab897d.tmp' does not exist, skip.
2026-04-02 03:21:46,517 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8588.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8599.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab86a1.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8d7e.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8a3c.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8738.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab87ab.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar84e6.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab84e5.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8778.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8546.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8980.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar87ad.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8aad.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8aed.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8c4d.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8833.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8b4d.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8cad.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8545.tmp' does not exist, skip.
2026-04-02 03:21:46,533 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab88b7.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8a3d.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab86f3.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab897f.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8c0b.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8477.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8ced.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8d7d.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8739.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8883.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar897e.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar862f.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab88f8.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar85fc.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8681.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar878b.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8726.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8cec.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab866e.tmp' does not exist, skip.
2026-04-02 03:21:46,549 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar86b4.tmp' does not exist, skip.
2026-04-02 03:21:46,565 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab8c4c.tmp' does not exist, skip.
2026-04-02 03:21:46,565 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab87fd.tmp' does not exist, skip.
2026-04-02 03:21:46,565 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8c0c.tmp' does not exist, skip.
2026-04-02 03:21:46,565 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8d4d.tmp' does not exist, skip.
2026-04-02 03:21:46,565 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar8704.tmp' does not exist, skip.
2026-04-02 03:21:46,565 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab85e9.tmp' does not exist, skip.
2026-04-02 03:21:46,565 [analyzer] INFO: Analysis completed.
2026-04-02 04:20:57,809 [cuckoo.core.scheduler] INFO: Task #7505927: acquired machine win7x6425 (label=win7x6425)
2026-04-02 04:20:57,810 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.225 for task #7505927
2026-04-02 04:20:58,352 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 787485 (interface=vboxnet0, host=192.168.168.225)
2026-04-02 04:20:58,388 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6425
2026-04-02 04:20:59,119 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6425 to vmcloak
2026-04-02 04:21:08,413 [cuckoo.core.guest] INFO: Starting analysis #7505927 on guest (id=win7x6425, ip=192.168.168.225)
2026-04-02 04:21:09,418 [cuckoo.core.guest] DEBUG: win7x6425: not ready yet
2026-04-02 04:21:14,444 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6425, ip=192.168.168.225)
2026-04-02 04:21:14,519 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6425, ip=192.168.168.225, monitor=latest, size=6660546)
2026-04-02 04:21:15,793 [cuckoo.core.resultserver] DEBUG: Task #7505927: live log analysis.log initialized.
2026-04-02 04:21:16,718 [cuckoo.core.resultserver] DEBUG: Task #7505927 is sending a BSON stream
2026-04-02 04:21:16,954 [cuckoo.core.resultserver] DEBUG: Task #7505927 is sending a BSON stream
2026-04-02 04:21:17,873 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'shots/0001.jpg'
2026-04-02 04:21:17,887 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 133472
2026-04-02 04:21:18,689 [cuckoo.core.resultserver] DEBUG: Task #7505927 is sending a BSON stream
2026-04-02 04:21:19,990 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'shots/0002.jpg'
2026-04-02 04:21:19,995 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 24449
2026-04-02 04:21:21,078 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'shots/0003.jpg'
2026-04-02 04:21:21,081 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 31043
2026-04-02 04:21:25,265 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'shots/0004.jpg'
2026-04-02 04:21:25,269 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 54539
2026-04-02 04:21:30,317 [cuckoo.core.guest] DEBUG: win7x6425: analysis #7505927 still processing
2026-04-02 04:21:45,853 [cuckoo.core.guest] DEBUG: win7x6425: analysis #7505927 still processing
2026-04-02 04:21:46,340 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'curtain/1775092906.33.curtain.log'
2026-04-02 04:21:46,351 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 36
2026-04-02 04:21:46,440 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'sysmon/1775092906.44.sysmon.xml'
2026-04-02 04:21:46,445 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 248674
2026-04-02 04:21:46,453 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/39e7de847c9f731e_down[1]'
2026-04-02 04:21:46,457 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 748
2026-04-02 04:21:46,478 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/46e019fa34465f4e_httperrorpagesscripts[1]'
2026-04-02 04:21:46,481 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 8714
2026-04-02 04:21:46,498 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/33ba8221ff3f5211_94308059b57b3142e455b38a6eb92015'
2026-04-02 04:21:46,501 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 73211
2026-04-02 04:21:46,505 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/f18e9671426708c6_invalidcert[1]'
2026-04-02 04:21:46,518 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 2588
2026-04-02 04:21:46,519 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/96bcec06264976f3_2d85f72862b55c4eadd9e66e06947f3d'
2026-04-02 04:21:46,521 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 1391
2026-04-02 04:21:46,523 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/59e53005e12d5c20_invalidcert[1]'
2026-04-02 04:21:46,524 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 5038
2026-04-02 04:21:46,526 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/8d018639281b33da_errorpagetemplate[1]'
2026-04-02 04:21:46,528 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 2168
2026-04-02 04:21:46,529 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/d970f834d7e343f6_{94b5e30b-2e3a-11f1-ad26-c68b0c3313ef}.dat'
2026-04-02 04:21:46,531 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 4608
2026-04-02 04:21:46,534 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/1ba122f4b39a3333_green_shield[1]'
2026-04-02 04:21:46,536 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 810
2026-04-02 04:21:46,537 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/fbc23311fb5eb53c_background_gradient_red[1]'
2026-04-02 04:21:46,539 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 868
2026-04-02 04:21:46,545 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/c82ccc590c62bf73_recoverystore.{94b5e309-2e3a-11f1-ad26-c68b0c3313ef}.dat'
2026-04-02 04:21:46,547 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 5632
2026-04-02 04:21:46,549 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/9466d620dc57835a_errorpagestrings[1]'
2026-04-02 04:21:46,564 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 2949
2026-04-02 04:21:46,565 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/5e2cd0990d6d3b0b_red_shield_48[1]'
2026-04-02 04:21:46,567 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 4127
2026-04-02 04:21:46,569 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/e22e21b8757a6cd7_94308059b57b3142e455b38a6eb92015'
2026-04-02 04:21:46,570 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 344
2026-04-02 04:21:46,572 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/4bd9f96d6971c7d3_red_shield[1]'
2026-04-02 04:21:46,574 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 810
2026-04-02 04:21:46,577 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'files/6f1be0dd04e51859_2d85f72862b55c4eadd9e66e06947f3d'
2026-04-02 04:21:46,579 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 192
2026-04-02 04:21:46,989 [cuckoo.core.resultserver] DEBUG: Task #7505927: File upload for 'shots/0005.jpg'
2026-04-02 04:21:47,002 [cuckoo.core.resultserver] DEBUG: Task #7505927 uploaded file length: 133462
2026-04-02 04:21:47,019 [cuckoo.core.resultserver] DEBUG: Task #7505927 had connection reset for <Context for LOG>
2026-04-02 04:21:48,866 [cuckoo.core.guest] INFO: win7x6425: analysis completed successfully
2026-04-02 04:21:48,878 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2026-04-02 04:21:48,904 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2026-04-02 04:21:50,216 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6425 to path /srv/cuckoo/cwd/storage/analyses/7505927/memory.dmp
2026-04-02 04:21:50,218 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6425
2026-04-02 04:21:58,425 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.225 for task #7505927
2026-04-02 04:21:58,785 [cuckoo.core.scheduler] DEBUG: Released database task #7505927
2026-04-02 04:21:58,819 [cuckoo.core.scheduler] INFO: Task #7505927: analysis procedure completed
| cmdline | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1292 CREDAT:275457 /prefetch:2 |