URL |
---|
http://uyawyjoatdsx.com/ |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Category | Started | Completed | Duration | Logs |
---|---|---|---|---|
URL | Jan. 22, 2019, 7:59 a.m. | Jan. 22, 2019, 8 a.m. | 37 seconds |
Name | Label | Started On | Shutdown On |
---|---|---|---|
win7x64 | win7x64 | 2019-01-22 07:59:48 | 2019-01-22 08:00:23 |
2019-01-21 23:59:47,015 [analyzer] DEBUG: Starting analyzer from: C:\qbftpdjo 2019-01-21 23:59:47,078 [analyzer] DEBUG: Pipe server name: \\.\PIPE\DMeURgMaQpEUOGYb 2019-01-21 23:59:47,078 [analyzer] DEBUG: Log pipe server name: \\.\PIPE\QKsVwHTDtzyCRLayHrLsnMQAE 2019-01-21 23:59:48,746 [analyzer] DEBUG: Started auxiliary module Disguise 2019-01-21 23:59:49,308 [analyzer] DEBUG: Loaded monitor into process with pid 508 2019-01-21 23:59:49,323 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2019-01-21 23:59:49,323 [analyzer] DEBUG: Started auxiliary module Human 2019-01-21 23:59:49,323 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2019-01-21 23:59:49,323 [analyzer] DEBUG: Started auxiliary module Reboot 2019-01-21 23:59:49,526 [analyzer] DEBUG: Started auxiliary module RecentFiles 2019-01-21 23:59:49,526 [analyzer] DEBUG: Started auxiliary module Screenshots 2019-01-21 23:59:49,526 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2019-01-21 23:59:49,822 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\msiexec.exe' with arguments ['/I', 'http://uyawyjoatdsx.com/'] and pid 2280 2019-01-21 23:59:50,711 [analyzer] DEBUG: Loaded monitor into process with pid 2280 2019-01-21 23:59:50,789 [analyzer] DEBUG: Received request to inject pid=2280, but we are already injected there. 2019-01-22 00:00:09,838 [modules.auxiliary.human] INFO: Found button "OK", clicking it 2019-01-22 00:00:12,427 [lib.api.process] INFO: Memory dump of process with pid 2280 completed 2019-01-22 00:00:13,161 [analyzer] INFO: Process with pid 2280 has terminated 2019-01-22 00:00:13,161 [analyzer] INFO: Process list is empty, terminating analysis. 2019-01-22 00:00:14,174 [analyzer] INFO: Terminating remaining processes before shutdown. 2019-01-22 00:00:14,174 [analyzer] INFO: Analysis completed.
2019-01-22 07:59:47,504 [lib.cuckoo.core.scheduler] INFO: Task #1212: acquired machine win7x64 (label=win7x64) 2019-01-22 07:59:48,361 [modules.auxiliary.sniffer] INFO: Started sniffer with PID 13000 (interface=eth2, host=192.168.128.109, pcap=/opt/cuckoo/storage/analyses/1212/dump.pcap) 2019-01-22 07:59:52,190 [lib.cuckoo.core.guest] INFO: Starting analysis on guest (id=win7x64, ip=192.168.128.109) 2019-01-22 08:00:22,835 [lib.cuckoo.core.guest] INFO: win7x64: analysis completed successfully 2019-01-22 08:00:26,445 [lib.cuckoo.core.plugins] WARNING: The processing module "Suricata" returned the following error: Unable to locate Suricata binary 2019-01-22 08:00:28,014 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937f540490>: Failed to establish a new connection: [Errno 111] Connection refused 2019-01-22 08:00:28,015 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937f540350>: Failed to establish a new connection: [Errno 111] Connection refused 2019-01-22 08:00:28,015 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937f540410>: Failed to establish a new connection: [Errno 111] Connection refused 2019-01-22 08:00:28,016 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937f540cd0>: Failed to establish a new connection: [Errno 111] Connection refused 2019-01-22 08:00:28,016 [lib.cuckoo.core.plugins] ERROR: Failed to run the reporting module "ElasticSearch": Traceback (most recent call last): File "/opt/cuckoo/lib/cuckoo/core/plugins.py", line 533, in process current.run(self.results) File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 196, in run self.connect() File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 79, in connect if not self.es.indices.exists_template("cuckoo_template"): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/utils.py", line 69, in _wrapped return func(*args, params=params, **kwargs) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/indices.py", line 491, in exists_template name), params=params) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/transport.py", line 327, in perform_request status, headers, data = connection.perform_request(method, url, params, body, ignore=ignore, timeout=timeout) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 105, in perform_request raise ConnectionError('N/A', str(e), e) ConnectionError: ConnectionError(<urllib3.connection.HTTPConnection object at 0x7f937f540cd0>: Failed to establish a new connection: [Errno 111] Connection refused) caused by: NewConnectionError(<urllib3.connection.HTTPConnection object at 0x7f937f540cd0>: Failed to establish a new connection: [Errno 111] Connection refused)
Name | Response | Post-Analysis Lookup |
---|---|---|
uyawyjoatdsx.com |
No hosts contacted.
Opened files
Registry keys opened
Registry keys read
DLLs Loaded
No hosts contacted.
Name | Response | Post-Analysis Lookup |
---|---|---|
uyawyjoatdsx.com |
No TCP connections recorded.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.128.109 | 52096 | 192.168.128.111 | 53 |
192.168.128.109 | 137 | 192.168.128.255 | 137 |
192.168.128.109 | 64209 | 224.0.0.252 | 5355 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts
Task ID | 1212 |
---|---|
Mongo ID | 5c4713ec11d30812ab71f2e3 |
Cuckoo release | 2.0-dev |