URL |
---|
https://sftpemea.west.com/pcs/uploads/jsc/5276729.zip |
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Category | Started | Completed | Duration | Logs |
---|---|---|---|---|
URL | Feb. 6, 2019, 6:15 a.m. | Feb. 6, 2019, 6:20 a.m. | 268 seconds |
Name | Label | Started On | Shutdown On |
---|---|---|---|
win7x64 | win7x64 | 2019-02-06 06:15:36 | 2019-02-06 06:20:03 |
2019-02-05 22:15:35,046 [analyzer] DEBUG: Starting analyzer from: C:\cljoweyer 2019-02-05 22:15:35,124 [analyzer] DEBUG: Pipe server name: \\.\PIPE\LsFtJwAeEutgbMBQaYRPitDhDa 2019-02-05 22:15:35,124 [analyzer] DEBUG: Log pipe server name: \\.\PIPE\qQZTQlPSJeJIGztcjhD 2019-02-05 22:15:35,124 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically. 2019-02-05 22:15:35,124 [analyzer] INFO: Automatically selected analysis package "ie" 2019-02-05 22:15:36,964 [analyzer] DEBUG: Started auxiliary module Disguise 2019-02-05 22:15:37,417 [analyzer] DEBUG: Loaded monitor into process with pid 508 2019-02-05 22:15:37,417 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2019-02-05 22:15:37,417 [analyzer] DEBUG: Started auxiliary module Human 2019-02-05 22:15:37,417 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2019-02-05 22:15:37,417 [analyzer] DEBUG: Started auxiliary module Reboot 2019-02-05 22:15:37,744 [analyzer] DEBUG: Started auxiliary module RecentFiles 2019-02-05 22:15:37,760 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2019-02-05 22:15:37,760 [analyzer] DEBUG: Started auxiliary module Screenshots 2019-02-05 22:15:37,931 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://sftpemea.west.com/pcs/uploads/jsc/5276729.zip'] and pid 2316 2019-02-05 22:15:38,431 [analyzer] DEBUG: Loaded monitor into process with pid 2316 2019-02-05 22:15:38,602 [analyzer] DEBUG: Ignoring process "C:\Windows\System32\ie4uinit.exe" -ShowQLIcon! 2019-02-05 22:15:43,190 [analyzer] DEBUG: Following legitimate iexplore process: "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2316 CREDAT:79873! 2019-02-05 22:15:43,236 [analyzer] INFO: Injected into process with pid 2460 and name u'iexplore.exe' 2019-02-05 22:15:43,377 [analyzer] DEBUG: Loaded monitor into process with pid 2460 2019-02-05 22:15:43,750 [analyzer] INFO: Added new file to list with pid 2316 and path C:\Users\zamen\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{9F79A3D5-29D6-11E9-B036-0050569395D7}.dat 2019-02-05 22:15:43,813 [analyzer] INFO: Added new file to list with pid 2316 and path C:\Users\zamen\AppData\Local\Temp\~DF78591C720D7F9597.TMP 2019-02-05 22:15:46,528 [analyzer] INFO: Added new file to list with pid 2316 and path C:\Users\zamen\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9F79A3D6-29D6-11E9-B036-0050569395D7}.dat 2019-02-05 22:15:46,575 [analyzer] INFO: Added new file to list with pid 2316 and path C:\Users\zamen\AppData\Local\Temp\~DF314E77333919DBF9.TMP 2019-02-05 22:19:40,325 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2019-02-05 22:19:44,460 [lib.api.process] INFO: Memory dump of process with pid 2316 completed 2019-02-05 22:19:53,132 [lib.api.process] INFO: Memory dump of process with pid 2460 completed 2019-02-05 22:19:53,132 [analyzer] INFO: Terminating remaining processes before shutdown. 2019-02-05 22:19:53,132 [lib.api.process] INFO: Successfully terminated process with pid 2316. 2019-02-05 22:19:53,132 [lib.api.process] INFO: Successfully terminated process with pid 2460. 2019-02-05 22:19:53,132 [analyzer] INFO: Error dumping file from path "c:\users\zamen\appdata\local\temp\~df78591c720d7f9597.tmp": [Errno 13] Permission denied: u'c:\\users\\zamen\\appdata\\local\\temp\\~df78591c720d7f9597.tmp' 2019-02-05 22:19:53,132 [analyzer] INFO: Error dumping file from path "c:\users\zamen\appdata\local\temp\~df314e77333919dbf9.tmp": [Errno 13] Permission denied: u'c:\\users\\zamen\\appdata\\local\\temp\\~df314e77333919dbf9.tmp' 2019-02-05 22:19:53,319 [analyzer] INFO: Analysis completed.
2019-02-06 06:15:36,367 [lib.cuckoo.core.scheduler] INFO: Task #1234: acquired machine win7x64 (label=win7x64) 2019-02-06 06:15:36,774 [modules.auxiliary.sniffer] INFO: Started sniffer with PID 4252 (interface=eth2, host=192.168.128.109, pcap=/opt/cuckoo/storage/analyses/1234/dump.pcap) 2019-02-06 06:15:44,074 [lib.cuckoo.core.guest] INFO: Starting analysis on guest (id=win7x64, ip=192.168.128.109) 2019-02-06 06:19:53,606 [lib.cuckoo.core.resultserver] WARNING: Uploaded file length larger than upload_max_size, stopping upload. 2019-02-06 06:20:02,370 [lib.cuckoo.core.resultserver] WARNING: Uploaded file length larger than upload_max_size, stopping upload. 2019-02-06 06:20:02,713 [lib.cuckoo.core.guest] INFO: win7x64: analysis completed successfully 2019-02-06 06:20:08,129 [lib.cuckoo.core.plugins] WARNING: The processing module "Suricata" returned the following error: Unable to locate Suricata binary 2019-02-06 06:20:09,634 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937f590f10>: Failed to establish a new connection: [Errno 111] Connection refused 2019-02-06 06:20:09,635 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937f590590>: Failed to establish a new connection: [Errno 111] Connection refused 2019-02-06 06:20:09,635 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937f590f50>: Failed to establish a new connection: [Errno 111] Connection refused 2019-02-06 06:20:09,636 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s] Traceback (most recent call last): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen _stacktrace=sys.exc_info()[2]) File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment raise six.reraise(type(error), error, _stacktrace) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen chunked=chunked) File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request conn.request(method, url, **httplib_request_kw) File "/usr/lib/python2.7/httplib.py", line 1017, in request self._send_request(method, url, body, headers) File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request self.endheaders(body) File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders self._send_output(message_body) File "/usr/lib/python2.7/httplib.py", line 864, in _send_output self.send(msg) File "/usr/lib/python2.7/httplib.py", line 826, in send self.connect() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect conn = self._new_conn() File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn self, "Failed to establish a new connection: %s" % e) NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f937f590f90>: Failed to establish a new connection: [Errno 111] Connection refused 2019-02-06 06:20:09,637 [lib.cuckoo.core.plugins] ERROR: Failed to run the reporting module "ElasticSearch": Traceback (most recent call last): File "/opt/cuckoo/lib/cuckoo/core/plugins.py", line 533, in process current.run(self.results) File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 196, in run self.connect() File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 79, in connect if not self.es.indices.exists_template("cuckoo_template"): File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/utils.py", line 69, in _wrapped return func(*args, params=params, **kwargs) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/indices.py", line 491, in exists_template name), params=params) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/transport.py", line 327, in perform_request status, headers, data = connection.perform_request(method, url, params, body, ignore=ignore, timeout=timeout) File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 105, in perform_request raise ConnectionError('N/A', str(e), e) ConnectionError: ConnectionError(<urllib3.connection.HTTPConnection object at 0x7f937f590f90>: Failed to establish a new connection: [Errno 111] Connection refused) caused by: NewConnectionError(<urllib3.connection.HTTPConnection object at 0x7f937f590f90>: Failed to establish a new connection: [Errno 111] Connection refused)
Name | Response | Post-Analysis Lookup |
---|---|---|
www.bing.com | 204.79.197.200 | |
sftpemea.west.com | 94.175.244.208 |
No hosts contacted.
Opened files
Written files
Processes created
DLLs Loaded
No hosts contacted.
Name | Response | Post-Analysis Lookup |
---|---|---|
www.bing.com | 204.79.197.200 | |
sftpemea.west.com | 94.175.244.208 |
No TCP connections recorded.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.128.109 | 52096 | 192.168.128.111 | 53 |
192.168.128.109 | 60112 | 192.168.128.111 | 53 |
192.168.128.109 | 64209 | 192.168.128.111 | 53 |
192.168.128.109 | 137 | 192.168.128.255 | 137 |
192.168.128.109 | 138 | 192.168.128.255 | 138 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts
Name | a4489c998d58ce68_{9f79a3d6-29d6-11e9-b036-0050569395d7}.dat |
---|---|
Filepath | C:\Users\zamen\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9F79A3D6-29D6-11E9-B036-0050569395D7}.dat |
Size | 4.5KB |
Processes | 2316 (iexplore.exe) |
Type | Composite Document File V2 Document, No summary info |
MD5 | 906fe226d1ede7adff98419c676eff80 |
SHA1 | d9a871b51fbe94806f02da6eb121a429031f6710 |
SHA256 | a4489c998d58ce68ed7afce286aafd64d8820ce4a3dc69e90f24ac599f20bade |
CRC32 | F5DA9B7D |
ssdeep | 12:rlfFXtrrEgmfR16FVbYrEgmfN1qjNlYfOD+/Nl089iDjoIu2A1qSh:r7hGUYGgNljsNl08iDcGAf |
Yara |
|
VirusTotal | Search for analysis |
Name | b079383c400a7c3d_recoverystore.{9f79a3d5-29d6-11e9-b036-0050569395d7}.dat |
---|---|
Filepath | C:\Users\zamen\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{9F79A3D5-29D6-11E9-B036-0050569395D7}.dat |
Size | 3.5KB |
Processes | 2316 (iexplore.exe) |
Type | Composite Document File V2 Document, No summary info |
MD5 | aa4289f170561f7027686601a7dbd6bd |
SHA1 | 396aba5009698bfc5f3c170f75639ea69bcc0212 |
SHA256 | b079383c400a7c3d63ec40a4dd3bdb56be5da467f7566180b9ae3c870f1e5c82 |
CRC32 | 64BE150A |
ssdeep | 12:rl0YmGF2hDOrEg5+IaCrI017+F0sDrEgmf+IaCy8qgQNlTqni:rI85/7YGv/TQNlWni |
Yara |
|
VirusTotal | Search for analysis |
Task ID | 1234 |
---|---|
Mongo ID | 5c5ac2ea11d30812ab71f47b |
Cuckoo release | 2.0-dev |