URL Details

URL
http://dwvbdibcriuf.com/

Score

This url appears fairly benign with a score of 0.0 out of 10.

Please notice: The scoring system is currently still in development and should be considered an alpha feature.

Information on Execution

Category Started Completed Duration Logs
URL Nov. 5, 2018, 5:15 p.m. Nov. 5, 2018, 5:15 p.m. 35 seconds

Machine

Name Label Started On Shutdown On
win7x64 win7x64 2018-11-05 17:15:12 2018-11-05 17:15:45

Analyzer Log

2018-11-05 09:15:12,015 [analyzer] DEBUG: Starting analyzer from: C:\pqwubq
2018-11-05 09:15:12,030 [analyzer] DEBUG: Pipe server name: \\.\PIPE\VLtDnlfluskbFkZeDLukK
2018-11-05 09:15:12,030 [analyzer] DEBUG: Log pipe server name: \\.\PIPE\cAYIxYOIGIgHkCgXXYCYyxtOaEbLp
2018-11-05 09:15:14,042 [analyzer] DEBUG: Started auxiliary module Disguise
2018-11-05 09:15:14,558 [analyzer] DEBUG: Loaded monitor into process with pid 508
2018-11-05 09:15:14,573 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2018-11-05 09:15:14,573 [analyzer] DEBUG: Started auxiliary module Human
2018-11-05 09:15:14,573 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2018-11-05 09:15:14,573 [analyzer] DEBUG: Started auxiliary module Reboot
2018-11-05 09:15:14,808 [analyzer] DEBUG: Started auxiliary module RecentFiles
2018-11-05 09:15:14,808 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2018-11-05 09:15:14,808 [analyzer] DEBUG: Started auxiliary module Screenshots
2018-11-05 09:15:14,885 [lib.api.process] INFO: Successfully executed process from path 'C:\\Windows\\System32\\control.exe' with arguments ['http://dwvbdibcriuf.com/'] and pid 2312
2018-11-05 09:15:15,618 [analyzer] DEBUG: Loaded monitor into process with pid 2312
2018-11-05 09:15:28,910 [analyzer] INFO: Injected into process with pid 2420 and name u'rundll32.exe'
2018-11-05 09:15:29,581 [analyzer] DEBUG: Loaded monitor into process with pid 2420
2018-11-05 09:15:29,658 [analyzer] DEBUG: Received request to inject pid=2420, but we are already injected there.
2018-11-05 09:15:31,390 [lib.api.process] INFO: Memory dump of process with pid 2420 completed
2018-11-05 09:15:32,170 [analyzer] INFO: Process with pid 2420 has terminated
2018-11-05 09:15:34,385 [lib.api.process] INFO: Memory dump of process with pid 2312 completed
2018-11-05 09:15:35,211 [analyzer] INFO: Process with pid 2312 has terminated
2018-11-05 09:15:35,211 [analyzer] INFO: Process list is empty, terminating analysis.
2018-11-05 09:15:36,226 [analyzer] INFO: Terminating remaining processes before shutdown.
2018-11-05 09:15:36,226 [analyzer] INFO: Analysis completed.

Cuckoo Log

2018-11-05 17:15:12,814 [lib.cuckoo.core.scheduler] INFO: Task #65: acquired machine win7x64 (label=win7x64)
2018-11-05 17:15:12,841 [modules.auxiliary.sniffer] INFO: Started sniffer with PID 7367 (interface=eth2, host=192.168.128.109, pcap=/opt/cuckoo/storage/analyses/65/dump.pcap)
2018-11-05 17:15:18,113 [lib.cuckoo.core.guest] INFO: Starting analysis on guest (id=win7x64, ip=192.168.128.109)
2018-11-05 17:15:44,715 [lib.cuckoo.core.guest] INFO: win7x64: analysis completed successfully
2018-11-05 17:15:49,618 [lib.cuckoo.core.plugins] WARNING: The processing module "Suricata" returned the following error: Unable to locate Suricata binary
2018-11-05 17:16:09,645 [modules.processing.virustotal] WARNING: Error fetching results from VirusTotal for "http://dwvbdibcriuf.com/": Unable to fetch VirusTotal results: MaxRetryError("HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /vtapi/v2/url/report (Caused by NewConnectionError('<urllib3.connection.VerifiedHTTPSConnection object at 0x7f728c3d3e90>: Failed to establish a new connection: [Errno -2] Name or service not known',))",)
2018-11-05 17:16:09,980 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.001s]
Traceback (most recent call last):
  File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request
    response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen
    _stacktrace=sys.exc_info()[2])
  File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment
    raise six.reraise(type(error), error, _stacktrace)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen
    chunked=chunked)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request
    conn.request(method, url, **httplib_request_kw)
  File "/usr/lib/python2.7/httplib.py", line 1017, in request
    self._send_request(method, url, body, headers)
  File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request
    self.endheaders(body)
  File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders
    self._send_output(message_body)
  File "/usr/lib/python2.7/httplib.py", line 864, in _send_output
    self.send(msg)
  File "/usr/lib/python2.7/httplib.py", line 826, in send
    self.connect()
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect
    conn = self._new_conn()
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn
    self, "Failed to establish a new connection: %s" % e)
NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f728c711a90>: Failed to establish a new connection: [Errno 111] Connection refused
2018-11-05 17:16:09,981 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s]
Traceback (most recent call last):
  File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request
    response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen
    _stacktrace=sys.exc_info()[2])
  File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment
    raise six.reraise(type(error), error, _stacktrace)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen
    chunked=chunked)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request
    conn.request(method, url, **httplib_request_kw)
  File "/usr/lib/python2.7/httplib.py", line 1017, in request
    self._send_request(method, url, body, headers)
  File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request
    self.endheaders(body)
  File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders
    self._send_output(message_body)
  File "/usr/lib/python2.7/httplib.py", line 864, in _send_output
    self.send(msg)
  File "/usr/lib/python2.7/httplib.py", line 826, in send
    self.connect()
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect
    conn = self._new_conn()
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn
    self, "Failed to establish a new connection: %s" % e)
NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f728c711350>: Failed to establish a new connection: [Errno 111] Connection refused
2018-11-05 17:16:09,982 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s]
Traceback (most recent call last):
  File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request
    response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen
    _stacktrace=sys.exc_info()[2])
  File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment
    raise six.reraise(type(error), error, _stacktrace)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen
    chunked=chunked)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request
    conn.request(method, url, **httplib_request_kw)
  File "/usr/lib/python2.7/httplib.py", line 1017, in request
    self._send_request(method, url, body, headers)
  File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request
    self.endheaders(body)
  File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders
    self._send_output(message_body)
  File "/usr/lib/python2.7/httplib.py", line 864, in _send_output
    self.send(msg)
  File "/usr/lib/python2.7/httplib.py", line 826, in send
    self.connect()
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect
    conn = self._new_conn()
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn
    self, "Failed to establish a new connection: %s" % e)
NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f728c711110>: Failed to establish a new connection: [Errno 111] Connection refused
2018-11-05 17:16:09,982 [elasticsearch] WARNING: HEAD http://127.0.0.1:9200/_template/cuckoo_template [status:N/A request:0.000s]
Traceback (most recent call last):
  File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 94, in perform_request
    response = self.pool.urlopen(method, url, body, retries=False, headers=self.headers, **kw)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 643, in urlopen
    _stacktrace=sys.exc_info()[2])
  File "/usr/local/lib/python2.7/dist-packages/urllib3/util/retry.py", line 251, in increment
    raise six.reraise(type(error), error, _stacktrace)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 594, in urlopen
    chunked=chunked)
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connectionpool.py", line 361, in _make_request
    conn.request(method, url, **httplib_request_kw)
  File "/usr/lib/python2.7/httplib.py", line 1017, in request
    self._send_request(method, url, body, headers)
  File "/usr/lib/python2.7/httplib.py", line 1051, in _send_request
    self.endheaders(body)
  File "/usr/lib/python2.7/httplib.py", line 1013, in endheaders
    self._send_output(message_body)
  File "/usr/lib/python2.7/httplib.py", line 864, in _send_output
    self.send(msg)
  File "/usr/lib/python2.7/httplib.py", line 826, in send
    self.connect()
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 163, in connect
    conn = self._new_conn()
  File "/usr/local/lib/python2.7/dist-packages/urllib3/connection.py", line 147, in _new_conn
    self, "Failed to establish a new connection: %s" % e)
NewConnectionError: <urllib3.connection.HTTPConnection object at 0x7f728c711290>: Failed to establish a new connection: [Errno 111] Connection refused
2018-11-05 17:16:09,983 [lib.cuckoo.core.plugins] ERROR: Failed to run the reporting module "ElasticSearch":
Traceback (most recent call last):
  File "/opt/cuckoo/lib/cuckoo/core/plugins.py", line 533, in process
    current.run(self.results)
  File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 196, in run
    self.connect()
  File "/opt/cuckoo/modules/reporting/elasticsearch.py", line 79, in connect
    if not self.es.indices.exists_template("cuckoo_template"):
  File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/utils.py", line 69, in _wrapped
    return func(*args, params=params, **kwargs)
  File "/usr/local/lib/python2.7/dist-packages/elasticsearch/client/indices.py", line 491, in exists_template
    name), params=params)
  File "/usr/local/lib/python2.7/dist-packages/elasticsearch/transport.py", line 327, in perform_request
    status, headers, data = connection.perform_request(method, url, params, body, ignore=ignore, timeout=timeout)
  File "/usr/local/lib/python2.7/dist-packages/elasticsearch/connection/http_urllib3.py", line 105, in perform_request
    raise ConnectionError('N/A', str(e), e)
ConnectionError: ConnectionError(<urllib3.connection.HTTPConnection object at 0x7f728c711290>: Failed to establish a new connection: [Errno 111] Connection refused) caused by: NewConnectionError(<urllib3.connection.HTTPConnection object at 0x7f728c711290>: Failed to establish a new connection: [Errno 111] Connection refused)

Signatures

No signatures

Screenshots

No screenshots available.

Network

DNS

No domains contacted.

Hosts

No hosts contacted.

Summary

Process control.exe (2312)

Process rundll32.exe (2420)

Process control.exe (2312)

  • Registry keys opened

    • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls
  • Registry keys read

    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{23c7429a-63cf-11e6-844a-0050569395d7}\Generation
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d292a6b8-63cb-11e6-bd5e-806e6f6e6963}\Data
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d292a6b5-63cb-11e6-bd5e-806e6f6e6963}\Data
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d292a6b8-63cb-11e6-bd5e-806e6f6e6963}\Generation
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d292a6b5-63cb-11e6-bd5e-806e6f6e6963}\Generation
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d292a6b9-63cb-11e6-bd5e-806e6f6e6963}\Generation
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d292a6b4-63cb-11e6-bd5e-806e6f6e6963}\Data
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{23c7429a-63cf-11e6-844a-0050569395d7}\Data
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d292a6b4-63cb-11e6-bd5e-806e6f6e6963}\Generation
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d292a6b9-63cb-11e6-bd5e-806e6f6e6963}\Data

Process rundll32.exe (2420)

  • Registry keys read

    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\PageAllocatorUseSystemHeap
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\PageAllocatorSystemHeapIsPrivate

Process control.exe (2312)

Process rundll32.exe (2420)

Process control.exe (2312)

Process rundll32.exe (2420)

Process control.exe (2312)

  • Processes created

    • %SystemRoot%\system32\rundll32.exe Shell32.dll,Control_RunDLL http://dwvbdibcriuf.com/
    • "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL http://dwvbdibcriuf.com/
  • DLLs Loaded

    • API-MS-Win-Core-LocalRegistry-L1-1-0.dll
    • SETUPAPI.dll

Process rundll32.exe (2420)

  • DLLs Loaded

    • Shell32.dll
    • dwmapi.dll
    • ole32.dll
    • C:\Windows\system32\uxtheme.dll
No static analysis available.
No antivirus signatures available.

Process Tree


control.exe, PID: 2312, Parent PID: 2288

default registry file network process services synchronisation iexplore office pdf

rundll32.exe, PID: 2420, Parent PID: 2312

default registry file network process services synchronisation iexplore office pdf

Deprecation note: While processing this analysis you did not have the httpreplay Python library installed. Installing this library (i.e., pip install httpreplay) will allow Cuckoo to do more proper PCAP analysis including but not limited to showing full HTTP and HTTPS (!) requests and responses. It is recommended that you install this library and possibly reprocess any interesting analysis tasks.

Hosts

No hosts contacted.

DNS

No domains contacted.

TCP

No TCP connections recorded.

UDP

No UDP connections recorded.

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.
Task ID 65
Mongo ID 5be0c12a11d30814d163e017
Cuckoo release 2.0-dev