Category |
Started On |
Completed On |
Duration |
Cuckoo Version |
FILE |
2016-09-23 03:55:05.379671 |
2016-09-23 03:57:11.926338 |
126 seconds |
2.0-dev |
Machine |
Label |
Manager |
Started On |
Shutdown On |
win7cuckoo |
win7 Clone 1 |
VirtualBox |
2016-09-23 03:55:05 |
2016-09-23 03:57:11 |
File Details
File name |
a4b474214975a035e660e7d46eba54c73d40cbed.zip |
File size |
10565 bytes |
File type |
Zip archive data, at least v2.0 to extract |
CRC32 |
3A3C492F |
MD5 |
265b93bb5af98182618a6ed71b9b04d8 |
SHA1 |
a4b474214975a035e660e7d46eba54c73d40cbed |
SHA256 |
d28a9ca5d5657391153eed559f34408a8412c84a7e395cee4fd8c62d4c2ad3a8 |
SHA512 |
723bb0a1023af522cca2a5540c3a7d59579d05999b932d973e97ba30c14a979bc84728a0c5166f366fa046479959551252235eecc434ef84e0e172d5b57c0f1b |
Ssdeep |
192:6WlIQN/uXaZGkxUU9Qoy8pLnjXV1pa8271ZNpcvwYAooWfTZ5J:6WlIpcGNUTlp/V1K7/NpcLA/KTZ5J |
PEiD |
None matched
|
Yara |
|
VirusTotal |
File not found on VirusTotal
|
Signatures
recon_fingerprint details
Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate)
antivm_memory_available details
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available
dumped_buffer details
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
antivm_network_adapters details
Checks adapter addresses which can be used to detect virtual network interfaces
Windows_Proxy_Tinkering details
Accesses or modifies proxy settings
network_wscript_downloader details
Wscript.exe initiated network communications indicative of a script based payload download
malicious_document_urls details
Potentially malicious URL found in document
network_document_file details
Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe
Screenshots
No screenshots available.
Static Analysis
Nothing to display.
Dropped Files
File name |
a2fcb13fcd56ff76_4zkazhlqi |
File size |
207477 bytes |
File type |
Sendmail frozen configuration - version \202\006\003fF\0101\300\271\342\204'\023\234\341\020\205\265 |
MD5 |
a39f624ba61d83162cf5c064a7f81adb |
SHA1 |
8446bcdffdfcee7be6bff5f1048de62c719c051f |
SHA256 |
a2fcb13fcd56ff76b410d0ef46b17dbc9d5cfd217178e872dd0a0141e0c7e57f |
SHA512 |
66f77598504f3cb85043678e35358aa221accfd04e1e2de4df2d5b3ca1c7e0968175501cdf0599a1b0543c37e85c108007e2ebf6b0db816dbad8975b2cb81fa9 |
Ssdeep |
3072:3FWvoQYj+skchd0Mz/XnXQTNp6WTMXS1P7YnYa00IfRHgonZWhgD5EyTbKcwEemO:IailI0C/nXAnMgYsRHgRO5EyTbKt |
Yara |
None matched
|
File name |
delivery details scan 0BF35.js |
File size |
62774 bytes |
File type |
ASCII text, with very long lines |
MD5 |
d663e080f066bdb4ad05675884714c7a |
SHA1 |
4b9d5324d0306d12e4c89aa2dde4f11983f22b1b |
SHA256 |
773c49a1ea3e97135522fded7cd8125d8950a8b42c37fdc4c246f969ccba24e8 |
SHA512 |
ff37ca45abcfbeea3f80c10c73a3a2936553f3c1023ba0f696f68706e2912423c6ab2e44b9361ae262150c8ae3a15cd6d57b95d7b8f1da9b753f4ccf06307635 |
Ssdeep |
1536:GpTUWqGfkISaxnln4m28vSwrCtSmf/R2H0w70xvWKqPPidUzi3IJT2xH79J:GptqeRxidB2UUsWKqPP4Uzi3IF2xHj |
Yara |
None matched
|
Network Analysis
IP Address |
190.147.38.2 |
23.41.186.226 |
40.69.40.157 |
52.169.179.91 |
64.4.54.253 |
64.4.54.254 |
8.8.8.8 |
Domain |
IP Address |
crl.microsoft.com |
70.186.27.32 |
dns.msftncsi.com |
131.107.255.255 |
vortex-win.data.microsoft.com |
64.4.54.254 |
lesiyteco.com |
95.173.164.205 |
teredo.ipv6.microsoft.com |
67.195.61.46 |
www.microsoft.com |
104.75.131.184 |
settings-win.data.microsoft.com |
64.4.54.253 |
ctldl.windowsupdate.com |
70.186.27.9 |
ipv6.msftncsi.com |
|
URL |
Data |
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl |
GET /pkiops/crl/MicSecSerCA2011_2011-10-18.crl HTTP/1.1
Cache-Control: max-age = 572
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Thu, 12 May 2016 02:00:44 GMT
If-None-Match: "202c18f2abd11:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.microsoft.com
|
http://lesiyteco.com/1774s4 |
GET /1774s4 HTTP/1.1
Accept: */*
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: lesiyteco.com
Connection: Keep-Alive
|
Volatility
Nothing to display.