CUCKOO.DROPPAGES.COM SERVER
We discovered that the main page on cuckoo.droppages.com took three thousand six hundred and forty milliseconds to download. We could not discover a SSL certificate, so in conclusion our web crawlers consider this site not secure.
Internet Protocol
77.73.0.52
SERVER OS
We detected that this website is weilding the Microsoft-IIS/7.0 server.HTML TITLE
Cuckoo SandboxDESCRIPTION
PE32 executable GUI Intel 80386, for MS Windows. File not found on VirusTotal. Connect to a remote server winsock. Creates MS CTF mutex as seen in zeusramnit samples. Performs some HTTP requests. The binary likely contains encrypted or compressed data. Steals private information from local Internet browsers. Installs itself for autorun at Windows startup. 20010413 srv03 rtm.030324-2048. Microsoft xae Windows xae Operating System. Active Accessibility text support. Size of Raw Data. VersionIndepe.PARSED CONTENT
The site cuckoo.droppages.com had the following on the homepage, "PE32 executable GUI Intel 80386, for MS Windows." We noticed that the website said " File not found on VirusTotal." It also stated " Connect to a remote server winsock. Creates MS CTF mutex as seen in zeusramnit samples. The binary likely contains encrypted or compressed data. Steals private information from local Internet browsers. Installs itself for autorun at Windows startup. Microsoft xae Windows xae Operating System."