URL |
---|
http://yjnsyjulbvpo.com/ |
This url shows some signs of potential malicious behavior.
The score of this url is 1.8 out of 10.
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Category | Started | Completed | Duration | Logs |
---|---|---|---|---|
URL | Jan. 20, 2019, 2:45 p.m. | Jan. 20, 2019, 2:49 p.m. | 256 seconds |
Name | Label | Started On | Shutdown On |
---|---|---|---|
winxpsp3x86 | winxpsp3x86 | 2019-01-20 14:45:36 | 2019-01-20 14:49:52 |
2019-01-20 22:45:35,000 [analyzer] DEBUG: Starting analyzer from: C:\wmnfl 2019-01-20 22:45:35,062 [analyzer] DEBUG: Pipe server name: \\.\PIPE\JdMnIsVwoPHdhscrDnNxRrLOb 2019-01-20 22:45:35,062 [analyzer] DEBUG: Log pipe server name: \\.\PIPE\bcWUdBbdpDesNOCyZ 2019-01-20 22:45:37,625 [analyzer] DEBUG: Started auxiliary module Disguise 2019-01-20 22:45:37,765 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit kernel32.dll (with timestamp 0x4802a12c) 2019-01-20 22:45:37,765 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit kernel32.dll (with timestamp 0x4802a12c) 2019-01-20 22:45:37,828 [analyzer] DEBUG: Loaded monitor into process with pid 700 2019-01-20 22:45:37,828 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2019-01-20 22:45:37,828 [analyzer] DEBUG: Started auxiliary module Human 2019-01-20 22:45:37,828 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2019-01-20 22:45:37,828 [analyzer] DEBUG: Started auxiliary module Reboot 2019-01-20 22:45:38,062 [analyzer] DEBUG: Started auxiliary module RecentFiles 2019-01-20 22:45:38,062 [analyzer] DEBUG: Started auxiliary module Screenshots 2019-01-20 22:45:38,233 [lib.api.process] INFO: Successfully executed process from path 'C:\\WINDOWS\\System32\\cmd.exe' with arguments ['/c', 'start', '/wait', '"LjsoIkmjLHOgdY"', 'http://yjnsyjulbvpo.com/'] and pid 1492 2019-01-20 22:45:38,405 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit kernel32.dll (with timestamp 0x4802a12c) 2019-01-20 22:45:38,405 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit kernel32.dll (with timestamp 0x4802a12c) 2019-01-20 22:45:38,515 [analyzer] DEBUG: Loaded monitor into process with pid 1492 2019-01-20 22:45:38,858 [analyzer] INFO: Injected into process with pid 1728 and name u'firefox.exe' 2019-01-20 22:45:38,953 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit kernel32.dll (with timestamp 0x4802a12c) 2019-01-20 22:45:38,953 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit kernel32.dll (with timestamp 0x4802a12c) 2019-01-20 22:45:39,046 [analyzer] DEBUG: Loaded monitor into process with pid 1728 2019-01-20 22:45:39,437 [analyzer] INFO: Added new file to list with pid 1728 and path C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\Crash Reports\UserID 2019-01-20 22:45:39,437 [analyzer] INFO: Added new file to list with pid 1728 and path C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2008052906 2019-01-20 22:45:39,640 [analyzer] INFO: Added new file to list with pid 1728 and path C:\Program Files\Mozilla Firefox\components\xpti.dat.tmp 2019-01-20 22:45:40,687 [analyzer] DEBUG: Received request to inject pid=1728, but we are already injected there. 2019-01-20 22:45:41,171 [analyzer] INFO: Added new file to list with pid 1728 and path C:\Program Files\Mozilla Firefox\components\compreg.dat.tmp 2019-01-20 22:45:42,467 [analyzer] INFO: Added new file to list with pid 1728 and path C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\profiles.ini 2019-01-20 22:45:42,546 [analyzer] INFO: Injected into process with pid 1996 and name u'firefox.exe' 2019-01-20 22:45:42,655 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit kernel32.dll (with timestamp 0x4802a12c) 2019-01-20 22:45:42,655 [analyzer] WARNING: Unable to find the correct offsets for functions of: 32-bit kernel32.dll (with timestamp 0x4802a12c) 2019-01-20 22:45:42,750 [analyzer] DEBUG: Loaded monitor into process with pid 1996 2019-01-20 22:45:42,983 [analyzer] INFO: Added new file to list with pid 1996 and path C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\Profiles\dvnj3pro.default\compatibility.ini 2019-01-20 22:45:43,062 [analyzer] INFO: Added new file to list with pid 1996 and path C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\Profiles\dvnj3pro.default\xpti.dat.tmp 2019-01-20 22:45:43,203 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:45:44,921 [analyzer] DEBUG: Received request to inject pid=1996, but we are already injected there. 2019-01-20 22:45:44,953 [analyzer] INFO: Added new file to list with pid 1996 and path C:\Documents and Settings\zamen\Local Settings\Application Data\Mozilla\Firefox\Profiles\dvnj3pro.default\XPC.mfl 2019-01-20 22:45:45,265 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:45:45,358 [analyzer] INFO: Added new file to list with pid 1996 and path C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\Profiles\dvnj3pro.default\compreg.dat.tmp 2019-01-20 22:45:46,483 [lib.api.process] INFO: Memory dump of process with pid 1728 completed 2019-01-20 22:45:47,250 [analyzer] INFO: Process with pid 1728 has terminated 2019-01-20 22:45:47,405 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:45:49,467 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:45:49,640 [analyzer] INFO: Added new file to list with pid 1996 and path C:\Documents and Settings\zamen\Local Settings\Application Data\Mozilla\Firefox\Profiles\dvnj3pro.default\XUL.mfl 2019-01-20 22:45:51,530 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:45:53,592 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:45:55,655 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:45:57,750 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:45:59,812 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:01,875 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:03,937 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:06,000 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:08,062 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:10,125 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:12,187 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:14,250 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:16,312 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:18,375 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:20,437 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:22,500 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:24,562 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:26,625 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:28,687 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:30,750 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:32,812 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:34,875 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:36,937 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:39,030 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:41,092 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:43,187 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:45,250 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:47,342 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:49,405 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:51,500 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:53,562 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:55,655 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:57,717 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:46:59,812 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:01,875 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:03,967 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:06,030 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:08,125 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:10,187 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:12,280 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:14,342 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:16,437 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:18,500 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:20,592 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:22,655 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:24,750 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:26,812 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:28,905 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:30,967 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:33,062 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:35,125 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:37,217 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:39,280 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:41,375 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:43,437 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:45,530 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:47,592 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:49,671 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:51,750 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:53,828 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:55,905 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:47:57,983 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:00,062 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:02,155 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:04,250 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:06,342 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:08,405 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:10,467 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:12,578 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:14,655 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:16,717 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:18,796 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:20,875 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:22,967 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:25,046 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:27,140 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:29,203 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:31,265 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:33,358 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:35,421 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:37,515 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:39,578 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:41,671 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:43,733 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:45,828 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:47,890 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:49,983 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:52,046 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:54,125 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:56,203 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:48:58,296 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:00,358 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:02,453 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:04,515 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:06,608 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:08,671 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:10,765 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:12,828 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:14,921 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:16,983 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:19,078 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:21,140 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:23,233 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:25,296 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:27,390 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:29,453 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:31,546 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:33,608 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:35,703 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:37,390 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2019-01-20 22:49:37,765 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:39,890 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:40,375 [lib.api.process] INFO: Memory dump of process with pid 1492 completed 2019-01-20 22:49:42,000 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-20 22:49:43,796 [lib.api.process] INFO: Memory dump of process with pid 1996 completed 2019-01-20 22:49:43,796 [analyzer] INFO: Terminating remaining processes before shutdown. 2019-01-20 22:49:43,796 [lib.api.process] INFO: Successfully terminated process with pid 1492. 2019-01-20 22:49:43,812 [lib.api.process] INFO: Successfully terminated process with pid 1996. 2019-01-20 22:49:43,828 [analyzer] WARNING: File at path "u'c:\\documents and settings\\zamen\\application data\\mozilla\\firefox\\profiles\\dvnj3pro.default\\xpti.dat.tmp'" does not exist, skip. 2019-01-20 22:49:43,921 [analyzer] WARNING: File at path "u'c:\\documents and settings\\zamen\\application data\\mozilla\\firefox\\profiles\\dvnj3pro.default\\compreg.dat.tmp'" does not exist, skip. 2019-01-20 22:49:43,937 [analyzer] INFO: Analysis completed.
2019-01-20 14:45:36,004 [lib.cuckoo.core.scheduler] INFO: Task #1180: acquired machine winxpsp3x86 (label=winxpsp3x86) 2019-01-20 14:45:36,025 [modules.auxiliary.sniffer] INFO: Started sniffer with PID 5274 (interface=eth2, host=192.168.128.101, pcap=/opt/cuckoo/storage/analyses/1180/dump.pcap) 2019-01-20 14:45:38,899 [lib.cuckoo.core.guest] INFO: Starting analysis on guest (id=winxpsp3x86, ip=192.168.128.101) 2019-01-20 14:49:51,383 [lib.cuckoo.core.guest] INFO: winxpsp3x86: analysis completed successfully 2019-01-20 14:53:44,974 [lib.cuckoo.core.plugins] WARNING: The processing module "Suricata" returned the following error: Unable to locate Suricata binary 2019-01-20 14:53:47,107 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937c19a990>: Failed to establish a new connection: [Errno 111] Connection refused 2019-01-20 14:53:47,108 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937c19af90>: Failed to establish a new connection: [Errno 111] Connection refused 2019-01-20 14:53:47,109 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937c19ae10>: Failed to establish a new connection: [Errno 111] Connection refused 2019-01-20 14:53:47,110 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937c19af50>: Failed to establish a new connection: [Errno 111] Connection refused 2019-01-20 14:53:47,110 [lib.cuckoo.core.plugins] ERROR: Failed to run the reporting module "ElasticSearch": Traceback (most recent call last): File "/opt/cuckoo/lib/cuckoo/core/plugins.py", line 533, in process current.run(self.results) File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 196, in run self.connect() File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 79, in connect if not self.es.indices.exists_template("cuckoo_template"): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/utils.py", line 69, in _wrapped return func(*args, params=params, **kwargs) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/indices.py", line 491, in exists_template name), params=params) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/transport.py", line 327, in perform_request status, headers, data = connection.perform_request(method, url, params, body, ignore=ignore, timeout=timeout) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 105, in perform_request raise ConnectionError('N/A', str(e), e) ConnectionError: ConnectionError(<urllib3.connection.HTTPConnection object at 0x7f937c19af50>: Failed to establish a new connection: [Errno 111] Connection refused) caused by: NewConnectionError(<urllib3.connection.HTTPConnection object at 0x7f937c19af50>: Failed to establish a new connection: [Errno 111] Connection refused)
file | C:\Program Files\Mozilla Firefox\chrome\classic.manifest |
dead_host | 192.158.197.132:3460 |
Name | Response | Post-Analysis Lookup |
---|---|---|
time.windows.com |
IP |
---|
192.158.197.132 |
Opened files
Written files
Files Read
Opened files
Written files
Files Read
Registry keys opened
Registry keys read
Registry keys opened
Registry keys read
Registry keys opened
Registry keys read
Mutexes accessed
Mutexes accessed
Directories created
Directories enumerated
Directories enumerated
Directories created
Directories enumerated
Processes created
DLLs Loaded
Processes created
DLLs Loaded
DLLs Loaded
IP |
---|
192.158.197.132 |
Name | Response | Post-Analysis Lookup |
---|---|---|
time.windows.com |
No TCP connections recorded.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.128.101 | 1025 | 192.168.128.111 | 53 |
192.168.128.101 | 137 | 192.168.128.255 | 137 |
192.168.128.101 | 138 | 192.168.128.255 | 138 |
192.168.128.101 | 1037 | 239.255.255.250 | 1900 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts
Name | 49480b1dceb1467b_compreg.dat |
---|---|
Filepath | c:\program files\mozilla firefox\components\compreg.dat |
Size | 139.3KB |
Processes | 1728 (firefox.exe) |
Type | ASCII text |
MD5 | 2e8de2e5c2f36010c70c6a4a47b4d72d |
SHA1 | 08b82460f59e79bf55b5e41d2c1138821e664947 |
SHA256 | 49480b1dceb1467b87c829762d0f2c81e67932da51c771ac1b22d3f084af6719 |
CRC32 | 9B0DF1E2 |
ssdeep | 3072:o47eS5VbguPWp2PuoHUzmUiHGZTj26cONiBahlVZeE:x7MmWNjvV9 |
Yara |
|
VirusTotal | Search for analysis |
Name | bbff096f00cd6b60_installtime2008052906 |
---|---|
Filepath | C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2008052906 |
Size | 10.0B |
Processes | 1728 (firefox.exe) |
Type | ASCII text, with no line terminators |
MD5 | feb0a62bfe5190a505979950c58ba57a |
SHA1 | 60dc0166947b2d32a80d4ede608851fac2945f30 |
SHA256 | bbff096f00cd6b60def770166c5b6cf14927506800dba0df1d4b9bccd4589f8d |
CRC32 | 0E32BD1B |
ssdeep | 3:JGz:sz |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 922947a67d0550f5_userid |
---|---|
Filepath | C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\Crash Reports\UserID |
Size | 36.0B |
Processes | 1728 (firefox.exe) |
Type | ASCII text, with no line terminators |
MD5 | 55ba6d7d894b4f4d22046b38b28c8a84 |
SHA1 | 7dca413b9be180a6cd38c46a4a7b561ec8b94fce |
SHA256 | 922947a67d0550f5ca45fd03f77ff2c3f30f1cdb69ea54db7c48d6ddcd4236ab |
CRC32 | 923CA02F |
ssdeep | 3:zVz2Ic9ASIuEUn:zVz2j9ASIu9 |
Yara |
|
VirusTotal | Search for analysis |
Name | e86b118de4857b52_profiles.ini |
---|---|
Filepath | C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\profiles.ini |
Size | 111.0B |
Processes | 1728 (firefox.exe) 1996 (firefox.exe) |
Type | ASCII text, with CRLF line terminators |
MD5 | 3c91867cdd51119f2f59bc93c853ebc0 |
SHA1 | d479ac977708eb30269c90dc2d7c835e11a8ed4f |
SHA256 | e86b118de4857b52eeb2288550815b7fcaa4222cbed53e61d1270af64f729e7b |
CRC32 | EAADE76F |
ssdeep | 3:1EmuRzTIIXov++IN4EI89fyHAKMj+uI8Xfyyn:1ETgv3IG8uAKMdI8XD |
Yara |
|
VirusTotal | Search for analysis |
Name | 2bdd80bf77860c97_xpti.dat |
---|---|
Filepath | c:\program files\mozilla firefox\components\xpti.dat |
Size | 93.7KB |
Processes | 1728 (firefox.exe) |
Type | ASCII text |
MD5 | 21ea86340d5037257b5eec0ae6b79c3f |
SHA1 | ce6952256f12146b5242c4b12d7eb0443ae94c91 |
SHA256 | 2bdd80bf77860c97c2aeb97c78075d0d449e0c8a9e975c0c1a650fb1ef1687b7 |
CRC32 | 48093FBC |
ssdeep | 1536:XrZ4orMucoti+EeYRgO8sdvqs030yhLu9+trwrdQdlAz0BJX4kIPIxok3p:XrZ4orMuccxYRgObCs0kyhLugt+dQdln |
Yara |
|
VirusTotal | Search for analysis |
Name | 103acd070b56360c_xpc.mfl |
---|---|
Filepath | C:\Documents and Settings\zamen\Local Settings\Application Data\Mozilla\Firefox\Profiles\dvnj3pro.default\XPC.mfl |
Size | 1.8MB |
Processes | 1996 (firefox.exe) |
Type | Mozilla XUL fastload data |
MD5 | 6cb02890ac239e0e6cb55a4275b57093 |
SHA1 | e54f745721fafd122abc37482199185b06789bd5 |
SHA256 | 103acd070b56360c3f5d788ce8a3d7d2b48e55aa7aa921b64380531e449d891e |
CRC32 | 7E86430A |
ssdeep | 12288:hLh0ne0JGAv3iJnhgycZRwXf5K+Esn76Aaea+3uKZgJGCm0T+FQ6MPGgk4cw+J5+:UifRuLG/9JshvTkq |
Yara |
|
VirusTotal | Search for analysis |
Name | 505e6c3196aeb9b1_compatibility.ini |
---|---|
Filepath | C:\Documents and Settings\zamen\Application Data\Mozilla\Firefox\Profiles\dvnj3pro.default\compatibility.ini |
Size | 177.0B |
Processes | 1996 (firefox.exe) |
Type | ASCII text, with CRLF line terminators |
MD5 | 59bd03f23354b0173407878ac9fef4f2 |
SHA1 | dfe4384b7f086070af24abec45c3df0fb0e8e7f0 |
SHA256 | 505e6c3196aeb9b1e73bd21e0634660793f9ca39a8138c586441185ec0a81777 |
CRC32 | DFA788D9 |
ssdeep | 3:tZAQW2V36TVADj2NEhWT/P4WX1rDZjrEFwHQ3ZjrEFw6:VKTVADimqN1rDVEFycVEFf |
Yara |
|
VirusTotal | Search for analysis |
Name | f15b0b996c57fdea_xul.mfl |
---|---|
Filepath | C:\Documents and Settings\zamen\Local Settings\Application Data\Mozilla\Firefox\Profiles\dvnj3pro.default\XUL.mfl |
Size | 29.0KB |
Processes | 1996 (firefox.exe) |
Type | Mozilla XUL fastload data |
MD5 | 4df725f7c12960a0c736952d93660c21 |
SHA1 | f033084294c7986c0e56fc033faf051cfb742c65 |
SHA256 | f15b0b996c57fdea97d345fd1cddceeffa15759573f1e73404cbdc835dd06283 |
CRC32 | 1BC0942A |
ssdeep | 768:RXcMalINlt7B15tyP/PaiSKTtXBMQPnNRO1KVs2vjQRWEL:RXc7INlt7B15tyniiSKTtXBMQlRO1KVW |
Yara |
|
VirusTotal | Search for analysis |
Task ID | 1180 |
---|---|
Mongo ID | 5c44d1d111d30812ab71ec37 |
Cuckoo release | 2.0-dev |