Category | Package | Started | Completed | Duration | Options | Log | MalScore |
---|---|---|---|---|---|---|---|
FILE | doc | 2025-07-10 20:04:11 | 2025-07-10 20:06:13 | 122 seconds | Show Options | Show Log | 0.5 |
procdump=1
amsidump=1
2024-04-29 04:31:22,750 [root] INFO: Date set to: 20250710T13:04:11, timeout set to: 150 2025-07-10 13:04:11,000 [root] DEBUG: Starting analyzer from: C:\tmp9sa_k9cw 2025-07-10 13:04:11,000 [root] DEBUG: Storing results at: C:\tzISHwtwg 2025-07-10 13:04:11,000 [root] DEBUG: Pipe server name: \\.\PIPE\uiAUqSwPhr 2025-07-10 13:04:11,000 [root] DEBUG: Python path: C:\olddocs 2025-07-10 13:04:11,000 [root] INFO: Analysis package "doc" has been specified 2025-07-10 13:04:11,000 [root] DEBUG: Importing analysis package "doc"... 2025-07-10 13:04:11,015 [root] DEBUG: Initializing analysis package "doc"... 2025-07-10 13:04:11,015 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL option 2025-07-10 13:04:11,015 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL_64 option 2025-07-10 13:04:11,015 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader option 2025-07-10 13:04:11,015 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader_64 option 2025-07-10 13:04:11,046 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2025-07-10 13:04:11,046 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2025-07-10 13:04:11,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2025-07-10 13:04:11,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2025-07-10 13:04:11,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2025-07-10 13:04:11,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2025-07-10 13:04:11,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2025-07-10 13:04:11,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2025-07-10 13:04:11,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2025-07-10 13:04:11,109 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2025-07-10 13:04:11,156 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2025-07-10 13:04:11,156 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2025-07-10 13:04:11,156 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2025-07-10 13:04:11,171 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2025-07-10 13:04:11,171 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2025-07-10 13:04:11,171 [root] DEBUG: Initializing auxiliary module "Browser"... 2025-07-10 13:04:11,171 [root] DEBUG: Started auxiliary module Browser 2025-07-10 13:04:11,171 [root] DEBUG: Initializing auxiliary module "Curtain"... 2025-07-10 13:04:11,171 [root] DEBUG: Started auxiliary module Curtain 2025-07-10 13:04:11,171 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2025-07-10 13:04:11,203 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2025-07-10 13:04:11,203 [root] DEBUG: Started auxiliary module DefaultApps 2025-07-10 13:04:11,203 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2025-07-10 13:04:11,203 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2025-07-10 13:04:11,203 [modules.auxiliary.digisig] INFO: doc 2025-07-10 13:04:11,203 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2025-07-10 13:04:11,203 [root] DEBUG: Started auxiliary module DigiSig 2025-07-10 13:04:11,203 [root] DEBUG: Initializing auxiliary module "Disguise"... 2025-07-10 13:04:11,468 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2025-07-10 13:04:11,468 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2025-07-10 13:04:11,468 [root] DEBUG: Initializing auxiliary module "Evtx"... 2025-07-10 13:04:11,468 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmp9sa_k9cw\bin\auditpol.csv 2025-07-10 13:04:11,859 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:04:12,468 [root] DEBUG: Started auxiliary module Evtx 2025-07-10 13:04:12,468 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2025-07-10 13:04:12,468 [modules.auxiliary.fiddler] INFO: fiddler package: doc 2025-07-10 13:04:12,468 [root] DEBUG: Started auxiliary module Fiddler 2025-07-10 13:04:12,468 [root] DEBUG: Initializing auxiliary module "Human"... 2025-07-10 13:04:12,468 [root] DEBUG: Started auxiliary module Human 2025-07-10 13:04:12,468 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2025-07-10 13:04:12,468 [root] DEBUG: Started auxiliary module Screenshots 2025-07-10 13:04:12,468 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2025-07-10 13:04:12,468 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2025-07-10 13:04:12,468 [root] DEBUG: Started auxiliary module Sysmon 2025-07-10 13:04:12,468 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2025-07-10 13:04:12,468 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2025-07-10 13:04:12,484 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2025-07-10 13:04:12,484 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 556 2025-07-10 13:04:12,484 [lib.api.process] INFO: Monitor config for process 556: C:\tmp9sa_k9cw\dll\556.ini 2025-07-10 13:04:14,562 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2025-07-10 13:04:15,484 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-10 13:04:15,484 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-10 13:04:15,484 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-10 13:04:15,484 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2025-07-10 13:04:15,484 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2025-07-10 13:04:15,484 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2025-07-10 13:04:15,484 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2025-07-10 13:04:15,484 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp9sa_k9cw\dll\erOwIY.dll, loader C:\tmp9sa_k9cw\bin\OZeMqWOC.exe 2025-07-10 13:04:15,500 [root] DEBUG: Loader: IAT patching disabled. 2025-07-10 13:04:15,500 [root] DEBUG: Loader: Injecting process 556 with C:\tmp9sa_k9cw\dll\erOwIY.dll. 2025-07-10 13:04:15,562 [root] DEBUG: 556: Python path set to 'C:\olddocs'. 2025-07-10 13:04:15,562 [root] DEBUG: 556: Disabling sleep skipping. 2025-07-10 13:04:15,562 [root] DEBUG: 556: Process dumps enabled. 2025-07-10 13:04:15,562 [root] DEBUG: 556: AMSI dumping enabled. 2025-07-10 13:04:15,562 [root] DEBUG: 556: Monitor config - unrecognised key office. 2025-07-10 13:04:15,562 [root] DEBUG: 556: In-monitor YARA scans disabled. 2025-07-10 13:04:15,562 [root] DEBUG: 556: TLS secret dump mode enabled. 2025-07-10 13:04:15,562 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEECC50000, thread 2276, image base 0x00000000FF8A0000, stack from 0x00000000019F3000-0x0000000001A00000 2025-07-10 13:04:15,562 [root] DEBUG: 556: Commandline: C:\Windows\system32\lsass.exe 2025-07-10 13:04:15,578 [root] DEBUG: 556: Hooked 5 out of 5 functions 2025-07-10 13:04:15,578 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2025-07-10 13:04:15,578 [root] DEBUG: Successfully injected DLL C:\tmp9sa_k9cw\dll\erOwIY.dll. 2025-07-10 13:04:15,578 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 556 2025-07-10 13:04:15,578 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2025-07-10 13:04:15,578 [root] DEBUG: Initializing auxiliary module "Usage"... 2025-07-10 13:04:15,578 [root] DEBUG: Started auxiliary module Usage 2025-07-10 13:04:18,187 [root] INFO: Restarting WMI Service 2025-07-10 13:04:24,593 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-10 13:04:27,296 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" with arguments ""C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx" /q" with pid 2520 2025-07-10 13:04:27,296 [lib.api.process] INFO: Monitor config for process 2520: C:\tmp9sa_k9cw\dll\2520.ini 2025-07-10 13:04:27,296 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-10 13:04:27,296 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-10 13:04:27,296 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-10 13:04:27,296 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2025-07-10 13:04:27,296 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2025-07-10 13:04:27,296 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2025-07-10 13:04:27,296 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp9sa_k9cw\dll\eBTOXl.dll, loader C:\tmp9sa_k9cw\bin\dolTEvv.exe 2025-07-10 13:04:27,328 [root] DEBUG: Loader: IAT patching disabled. 2025-07-10 13:04:27,328 [root] DEBUG: Loader: Injecting process 2520 (thread 3044) with C:\tmp9sa_k9cw\dll\eBTOXl.dll. 2025-07-10 13:04:27,328 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued. 2025-07-10 13:04:27,328 [root] DEBUG: Successfully injected DLL C:\tmp9sa_k9cw\dll\eBTOXl.dll. 2025-07-10 13:04:27,328 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2520 2025-07-10 13:04:27,468 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:04:27,734 [lib.common.results] INFO: File 1752177867687500000.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-10 13:04:27,750 [lib.common.results] INFO: File 1752177867687500000.InternetExplorer.evtx.gz size is 252, Max size: 100000000 2025-07-10 13:04:27,765 [lib.common.results] INFO: File 1752177867687500000.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2025-07-10 13:04:27,781 [lib.common.results] INFO: File 1752177867687500000.Application.evtx.gz size is 6733, Max size: 100000000 2025-07-10 13:04:27,812 [lib.common.results] INFO: File 1752177867734375000.OAlerts.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:04:27,828 [lib.common.results] INFO: File 1752177867750000000.Setup.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:04:27,843 [lib.common.results] INFO: File 1752177867750000000.System.evtx.gz size is 8821, Max size: 100000000 2025-07-10 13:04:27,843 [lib.common.results] INFO: File 1752177867750000000.Security.evtx.gz size is 15168, Max size: 100000000 2025-07-10 13:04:27,843 [lib.common.results] INFO: File 1752177867812500000.WindowsPowerShell.evtx.gz size is 625, Max size: 100000000 2025-07-10 13:04:29,328 [lib.api.process] INFO: Successfully resumed process with pid 2520 2025-07-10 13:04:29,375 [root] DEBUG: 2520: Python path set to 'C:\olddocs'. 2025-07-10 13:04:29,390 [root] DEBUG: 2520: Disabling sleep skipping. 2025-07-10 13:04:29,390 [root] DEBUG: 2520: Process dumps enabled. 2025-07-10 13:04:29,390 [root] DEBUG: 2520: AMSI dumping enabled. 2025-07-10 13:04:29,390 [root] DEBUG: 2520: Monitor config - unrecognised key office. 2025-07-10 13:04:29,390 [root] DEBUG: 2520: In-monitor YARA scans disabled. 2025-07-10 13:04:29,390 [root] DEBUG: 2520: Dropped file limit defaulting to 100. 2025-07-10 13:04:29,390 [root] DEBUG: 2520: Microsoft Office settings enabled. 2025-07-10 13:04:29,390 [root] DEBUG: 2520: Monitor initialised: 32-bit capemon loaded in process 2520 at 0x739c0000, thread 3044, image base 0x360000, stack from 0x313000-0x320000 2025-07-10 13:04:29,390 [root] DEBUG: 2520: Commandline: "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" "C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx" /q 2025-07-10 13:04:29,421 [root] DEBUG: 2520: Hooked 455 out of 455 functions 2025-07-10 13:04:29,421 [root] DEBUG: 2520: WoW64 detected: 64-bit ntdll base: 0x76e60000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x76ecb5f0, Wow64PrepareForException: 0x0 2025-07-10 13:04:29,421 [root] DEBUG: 2520: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0xa0000 2025-07-10 13:04:29,421 [root] INFO: Loaded monitor into process with pid 2520 2025-07-10 13:04:29,656 [root] DEBUG: 2520: DLL loaded at 0x6F880000: C:\Program Files (x86)\Microsoft Office\Office15\wwlib (0x14bc000 bytes). 2025-07-10 13:04:29,671 [root] DEBUG: 2520: DLL loaded at 0x73830000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus (0x190000 bytes). 2025-07-10 13:04:29,687 [root] DEBUG: 2520: DLL loaded at 0x755B0000: C:\Windows\syswow64\OLEAUT32 (0x8f000 bytes). 2025-07-10 13:04:29,781 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752177869.78125.sysmon.evtx.gz to host 2025-07-10 13:04:29,796 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 9408, Max size: 100000000 2025-07-10 13:04:29,843 [root] DEBUG: 2520: DLL loaded at 0x6EAD0000: C:\Program Files (x86)\Microsoft Office\Office15\oart (0xda8000 bytes). 2025-07-10 13:04:29,843 [root] DEBUG: 2520: DLL loaded at 0x73FD0000: C:\Windows\system32\MSVCP100 (0x69000 bytes). 2025-07-10 13:04:29,890 [root] DEBUG: 2520: DLL loaded at 0x71EB0000: C:\Windows\system32\d2d1 (0x347000 bytes). 2025-07-10 13:04:30,187 [root] DEBUG: 2520: DLL loaded at 0x6D1E0000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso (0x18e4000 bytes). 2025-07-10 13:04:30,203 [root] DEBUG: 2520: DLL loaded at 0x72C50000: C:\Windows\system32\MSIMG32 (0x5000 bytes). 2025-07-10 13:04:30,218 [root] DEBUG: 2520: DLL loaded at 0x72E40000: C:\Windows\system32\uxtheme (0x80000 bytes). 2025-07-10 13:04:30,218 [root] DEBUG: 2520: DLL loaded at 0x72D60000: C:\Windows\system32\WTSAPI32 (0xd000 bytes). 2025-07-10 13:04:30,218 [root] DEBUG: 2520: DLL loaded at 0x73800000: C:\Windows\system32\WINSTA (0x29000 bytes). 2025-07-10 13:04:30,234 [root] DEBUG: 2520: DLL loaded at 0x737B0000: C:\Windows\system32\dxgi (0x4c000 bytes). 2025-07-10 13:04:30,234 [root] DEBUG: 2520: DLL loaded at 0x72D70000: C:\Windows\system32\VERSION (0x9000 bytes). 2025-07-10 13:04:30,234 [root] DEBUG: 2520: DLL loaded at 0x73FB0000: C:\Windows\system32\dwmapi (0x13000 bytes). 2025-07-10 13:04:30,249 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-10 13:04:30,249 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:30,249 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:30,265 [root] DEBUG: 2520: DLL loaded at 0x75B00000: C:\Windows\syswow64\WINTRUST (0x2f000 bytes). 2025-07-10 13:04:30,281 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-10 13:04:30,281 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:30,281 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:30,296 [root] DEBUG: 2520: DLL loaded at 0x71C70000: C:\Windows\system32\msi (0x240000 bytes). 2025-07-10 13:04:30,406 [root] DEBUG: 2520: api-rate-cap: NtOpenKey hook disabled due to rate 2025-07-10 13:04:30,421 [root] DEBUG: 2520: api-rate-cap: NtQueryValueKey hook disabled due to rate 2025-07-10 13:04:30,421 [root] DEBUG: 2520: api-rate-cap: NtClose hook disabled due to rate 2025-07-10 13:04:30,468 [root] DEBUG: 2520: api-rate-cap: RegQueryValueExW hook disabled due to rate 2025-07-10 13:04:30,500 [root] DEBUG: 2520: DLL loaded at 0x71650000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSPTLS (0x116000 bytes). 2025-07-10 13:04:30,640 [root] DEBUG: 2520: DLL loaded at 0x75E80000: C:\Windows\syswow64\SHELL32 (0xc4a000 bytes). 2025-07-10 13:04:30,640 [root] DEBUG: 2520: DLL loaded at 0x74B70000: C:\Windows\syswow64\profapi (0xb000 bytes). 2025-07-10 13:04:30,718 [root] DEBUG: 2520: DLL loaded at 0x72ED0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32 (0x19e000 bytes). 2025-07-10 13:04:30,734 [root] DEBUG: 2520: DLL loaded at 0x736C0000: C:\Windows\system32\d3d10_1 (0x2c000 bytes). 2025-07-10 13:04:30,750 [root] DEBUG: 2520: DLL loaded at 0x73670000: C:\Windows\system32\d3d10_1core (0x41000 bytes). 2025-07-10 13:04:30,765 [root] DEBUG: 2520: DLL loaded at 0x71150000: C:\Windows\system32\d3d11 (0x175000 bytes). 2025-07-10 13:04:30,796 [root] DEBUG: 2520: DLL loaded at 0x70F60000: C:\Windows\system32\D3D10Warp (0x1e9000 bytes). 2025-07-10 13:04:30,812 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-10 13:04:30,828 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:30,828 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:30,828 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-10 13:04:30,843 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:30,843 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:30,859 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-10 13:04:30,859 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:30,859 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:30,875 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-10 13:04:30,875 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:30,875 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:30,906 [root] DEBUG: 2520: DLL loaded at 0x70E30000: C:\Windows\system32\WindowsCodecs (0x130000 bytes). 2025-07-10 13:04:30,906 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-10 13:04:30,906 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:30,906 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:30,921 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-10 13:04:30,921 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:30,921 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:30,953 [root] DEBUG: 2520: DLL loaded at 0x6D0A0000: C:\Windows\system32\DWrite (0x135000 bytes). 2025-07-10 13:04:30,968 [root] DEBUG: 2520: DLL loaded at 0x73620000: C:\Windows\system32\mscoree (0x4a000 bytes). 2025-07-10 13:04:30,984 [root] DEBUG: 2520: DLL loaded at 0x70DA0000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes). 2025-07-10 13:04:31,078 [root] DEBUG: 2520: DLL loaded at 0x6CFE0000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\adal (0xb5000 bytes). 2025-07-10 13:04:31,093 [root] DEBUG: 2520: DLL loaded at 0x70D40000: C:\Windows\system32\WINHTTP (0x58000 bytes). 2025-07-10 13:04:31,109 [root] DEBUG: 2520: DLL loaded at 0x6CF90000: C:\Windows\system32\webio (0x50000 bytes). 2025-07-10 13:04:31,140 [root] DEBUG: 2520: DLL loaded at 0x74BA0000: C:\Windows\syswow64\WININET (0x1e4000 bytes). 2025-07-10 13:04:31,140 [root] DEBUG: 2520: DLL loaded at 0x755A0000: C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes). 2025-07-10 13:04:31,140 [root] DEBUG: 2520: DLL loaded at 0x75E70000: C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes). 2025-07-10 13:04:31,140 [root] DEBUG: 2520: DLL loaded at 0x74B90000: C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes). 2025-07-10 13:04:31,140 [root] DEBUG: 2520: DLL loaded at 0x75C10000: C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes). 2025-07-10 13:04:31,140 [root] DEBUG: 2520: DLL loaded at 0x74A00000: C:\Windows\syswow64\normaliz (0x3000 bytes). 2025-07-10 13:04:31,171 [root] DEBUG: 2520: DLL loaded at 0x75170000: C:\Windows\syswow64\iertutil (0x232000 bytes). 2025-07-10 13:04:31,171 [root] DEBUG: 2520: DLL loaded at 0x74F20000: C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes). 2025-07-10 13:04:31,171 [root] DEBUG: 2520: DLL loaded at 0x74E50000: C:\Windows\syswow64\USERENV (0x17000 bytes). 2025-07-10 13:04:31,171 [root] DEBUG: 2520: DLL loaded at 0x741E0000: C:\Windows\system32\Secur32 (0x8000 bytes). 2025-07-10 13:04:31,187 [root] DEBUG: 2520: DLL loaded at 0x74D90000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes). 2025-07-10 13:04:31,203 [root] DEBUG: 2520: DLL loaded at 0x6CF30000: C:\Windows\System32\netprofm (0x5a000 bytes). 2025-07-10 13:04:31,203 [root] DEBUG: 2520: DLL loaded at 0x73FA0000: C:\Windows\System32\nlaapi (0x10000 bytes). 2025-07-10 13:04:31,203 [root] DEBUG: 2520: DLL loaded at 0x72D40000: C:\Windows\system32\CRYPTSP (0x17000 bytes). 2025-07-10 13:04:31,218 [root] DEBUG: 2520: DLL loaded at 0x72D00000: C:\Windows\system32\rsaenh (0x3b000 bytes). 2025-07-10 13:04:31,218 [root] DEBUG: 2520: DLL loaded at 0x73520000: C:\Windows\system32\RpcRtRemote (0xe000 bytes). 2025-07-10 13:04:31,234 [root] DEBUG: 2520: DLL loaded at 0x73F90000: C:\Windows\System32\npmproxy (0x8000 bytes). 2025-07-10 13:04:31,265 [root] DEBUG: 2520: DLL loaded at 0x6CDA0000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20 (0x18e000 bytes). 2025-07-10 13:04:32,109 [root] DEBUG: 2520: DLL loaded at 0x68080000: C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppc (0x2d000 bytes). 2025-07-10 13:04:32,109 [root] DEBUG: 2520: DLL loaded at 0x73550000: C:\Windows\system32\IPHLPAPI (0x1c000 bytes). 2025-07-10 13:04:32,109 [root] DEBUG: 2520: DLL loaded at 0x73540000: C:\Windows\system32\WINNSI (0x7000 bytes). 2025-07-10 13:04:32,109 [root] DEBUG: 2520: DLL loaded at 0x73D90000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes). 2025-07-10 13:04:32,125 [root] DEBUG: 2520: DLL loaded at 0x68060000: C:\Windows\system32\dhcpcsvc (0x12000 bytes). 2025-07-10 13:04:32,125 [root] DEBUG: 2520: DLL loaded at 0x68000000: C:\Windows\system32\WINSPOOL.DRV (0x51000 bytes). 2025-07-10 13:04:32,125 [root] DEBUG: 2520: DLL loaded at 0x72660000: C:\Windows\system32\credssp (0x8000 bytes). 2025-07-10 13:04:32,140 [root] DEBUG: 2520: DLL loaded at 0x734E0000: C:\Windows\system32\mswsock (0x3c000 bytes). 2025-07-10 13:04:32,140 [root] DEBUG: 2520: DLL loaded at 0x734D0000: C:\Windows\System32\wshtcpip (0x5000 bytes). 2025-07-10 13:04:32,140 [root] DEBUG: 2520: DLL loaded at 0x734C0000: C:\Windows\System32\wship6 (0x6000 bytes). 2025-07-10 13:04:32,156 [root] DEBUG: 2520: DLL loaded at 0x67FB0000: C:\Windows\system32\DNSAPI (0x44000 bytes). 2025-07-10 13:04:32,171 [root] DEBUG: 2520: DLL loaded at 0x67F60000: C:\Windows\SysWOW64\schannel (0x41000 bytes). 2025-07-10 13:04:32,187 [root] DEBUG: 2520: DLL loaded at 0x75C20000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes). 2025-07-10 13:04:32,187 [root] DEBUG: 2520: DLL loaded at 0x753B0000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-10 13:04:32,187 [root] DEBUG: 2520: DLL loaded at 0x76B30000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-10 13:04:32,203 [root] DEBUG: 2520: DLL loaded at 0x67E60000: C:\Windows\system32\propsys (0xf5000 bytes). 2025-07-10 13:04:32,218 [root] DEBUG: 2520: DLL loaded at 0x72E10000: C:\Windows\system32\ntmarta (0x21000 bytes). 2025-07-10 13:04:32,218 [root] DEBUG: 2520: DLL loaded at 0x753E0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes). 2025-07-10 13:04:32,312 [root] DEBUG: 2520: DLL loaded at 0x67D00000: C:\Windows\System32\msxml6 (0x158000 bytes). 2025-07-10 13:04:32,406 [root] DEBUG: 2520: DLL loaded at 0x67CD0000: C:\Windows\system32\XmlLite (0x2f000 bytes). 2025-07-10 13:04:32,406 [root] DEBUG: 556: DLL loaded at 0x000007FEF99F0000: C:\Windows\system32\keyiso (0xb000 bytes). 2025-07-10 13:04:32,546 [root] DEBUG: 2520: DLL loaded at 0x74A10000: C:\Windows\SysWOW64\urlmon (0x14a000 bytes). 2025-07-10 13:04:32,546 [root] DEBUG: 2520: DLL loaded at 0x75AF0000: C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes). 2025-07-10 13:04:32,562 [root] DEBUG: 2520: DLL loaded at 0x72630000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes). 2025-07-10 13:04:32,687 [root] DEBUG: 2520: DLL loaded at 0x67C90000: C:\Windows\system32\windowscodecsext (0x37000 bytes). 2025-07-10 13:04:32,703 [root] DEBUG: 2520: DLL loaded at 0x67C10000: C:\Windows\system32\mscms (0x79000 bytes). 2025-07-10 13:04:32,718 [root] DEBUG: 2520: DLL loaded at 0x67BD0000: C:\Windows\system32\icm32 (0x38000 bytes). 2025-07-10 13:04:32,750 [root] DEBUG: 2520: api-rate-cap: RegOpenKeyExW hook disabled due to rate 2025-07-10 13:04:32,765 [root] DEBUG: 2520: api-rate-cap: NtOpenKeyEx hook disabled due to rate 2025-07-10 13:04:32,796 [root] DEBUG: 2520: DLL loaded at 0x67B90000: C:\Windows\SysWOW64\bcryptprimitives (0x3d000 bytes). 2025-07-10 13:04:32,828 [root] DEBUG: 2520: api-rate-cap: RtlSetCurrentTransaction hook disabled due to rate 2025-07-10 13:04:32,906 [root] DEBUG: 2520: DLL loaded at 0x67B50000: C:\Windows\system32\WINMM (0x32000 bytes). 2025-07-10 13:04:33,031 [root] DEBUG: 556: TLS 1.2 secrets logged to: C:\tzISHwtwg\tlsdump\tlsdump.log 2025-07-10 13:04:33,125 [root] DEBUG: 556: DLL loaded at 0x000007FEF9E90000: C:\Windows\system32\cryptnet (0x27000 bytes). 2025-07-10 13:04:33,125 [root] DEBUG: 556: DLL loaded at 0x000007FEFD560000: C:\Windows\system32\WLDAP32 (0x52000 bytes). 2025-07-10 13:04:33,140 [root] DEBUG: 2520: api-rate-cap: RegCloseKey hook disabled due to rate 2025-07-10 13:04:33,171 [root] DEBUG: 2520: DLL loaded at 0x67B10000: C:\Windows\system32\ncrypt (0x39000 bytes). 2025-07-10 13:04:33,203 [root] DEBUG: 2520: DLL loaded at 0x67AD0000: C:\Program Files (x86)\Microsoft Office\Office15\msproof7 (0x37000 bytes). 2025-07-10 13:04:33,265 [root] DEBUG: 2520: DLL loaded at 0x67AB0000: C:\Windows\system32\GPAPI (0x16000 bytes). 2025-07-10 13:04:33,296 [root] DEBUG: 2520: DLL loaded at 0x679E0000: C:\Windows\system32\webservices (0xc2000 bytes). 2025-07-10 13:04:33,328 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma00546271.png0 size is 119666, Max size: 100000000 2025-07-10 13:04:33,343 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02786999.png0 size is 8127, Max size: 100000000 2025-07-10 13:04:33,359 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900771.png0 size is 10213, Max size: 100000000 2025-07-10 13:04:33,375 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382936.png0 size is 37573, Max size: 100000000 2025-07-10 13:04:33,390 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382941.png0 size is 96333, Max size: 100000000 2025-07-10 13:04:33,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02835058.png0 size is 186365, Max size: 100000000 2025-07-10 13:04:33,437 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03978815.png0 size is 711398, Max size: 100000000 2025-07-10 13:04:33,468 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78018332.png0 size is 26105, Max size: 100000000 2025-07-10 13:04:33,468 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392850.png0 size is 280509, Max size: 100000000 2025-07-10 13:04:33,484 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45325165.png0 size is 9149, Max size: 100000000 2025-07-10 13:04:33,500 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03982351.png0 size is 12860, Max size: 100000000 2025-07-10 13:04:33,500 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392877.png0 size is 86215, Max size: 100000000 2025-07-10 13:04:33,515 [root] DEBUG: 2520: DLL loaded at 0x679C0000: C:\Windows\system32\cryptnet (0x1d000 bytes). 2025-07-10 13:04:33,531 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16402488.png0 size is 114584, Max size: 100000000 2025-07-10 13:04:33,531 [root] DEBUG: 2520: DLL loaded at 0x679B0000: C:\Windows\system32\SensApi (0x6000 bytes). 2025-07-10 13:04:33,546 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16412178.png0 size is 283253, Max size: 100000000 2025-07-10 13:04:33,562 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma56348247.png0 size is 55049, Max size: 100000000 2025-07-10 13:04:33,578 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900720.png0 size is 22877, Max size: 100000000 2025-07-10 13:04:33,593 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma88924273.png0 size is 103770, Max size: 100000000 2025-07-10 13:04:33,609 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02836342.png0 size is 26220, Max size: 100000000 2025-07-10 13:04:33,625 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02892315.png0 size is 20776, Max size: 100000000 2025-07-10 13:04:33,640 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002124.png0 size is 11329, Max size: 100000000 2025-07-10 13:04:33,656 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78500733.png0 size is 10169, Max size: 100000000 2025-07-10 13:04:33,671 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900688.png0 size is 8561, Max size: 100000000 2025-07-10 13:04:33,687 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900722.png0 size is 19188, Max size: 100000000 2025-07-10 13:04:33,703 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900743.png0 size is 33070, Max size: 100000000 2025-07-10 13:04:33,718 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02923944.png0 size is 4886, Max size: 100000000 2025-07-10 13:04:33,734 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002117.png0 size is 4962, Max size: 100000000 2025-07-10 13:04:33,750 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt16402400.png0 size is 33856, Max size: 100000000 2025-07-10 13:04:33,765 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt22746018.png0 size is 18469, Max size: 100000000 2025-07-10 13:04:33,781 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45088960.png0 size is 40992, Max size: 100000000 2025-07-10 13:04:33,812 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45420242.png0 size is 13339, Max size: 100000000 2025-07-10 13:04:33,843 [root] DEBUG: 2520: DLL loaded at 0x67810000: C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppcext (0x194000 bytes). 2025-07-10 13:04:33,859 [root] DEBUG: 2520: DLL loaded at 0x677E0000: C:\Windows\system32\WinSCard (0x23000 bytes). 2025-07-10 13:04:34,015 [modules.auxiliary.human] INFO: Issuing keypress on Office dialog 2025-07-10 13:04:35,641 [lib.common.results] INFO: File c:\olddocs\1752177870546.saz size is 4598, Max size: 100000000 2025-07-10 13:04:35,657 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-10 13:04:35,938 [root] DEBUG: 2520: DLL loaded at 0x67740000: C:\Program Files (x86)\Microsoft Office\Office15\PROOF\msspell7 (0x8a000 bytes). 2025-07-10 13:04:36,032 [root] DEBUG: 2520: DLL loaded at 0x67580000: C:\Program Files (x86)\Microsoft Office\OFFICE15\mscss7en (0x61000 bytes). 2025-07-10 13:04:36,047 [root] DEBUG: 2520: DLL loaded at 0x67500000: C:\Program Files (x86)\Microsoft Office\OFFICE15\css7Data0009 (0x7f000 bytes). 2025-07-10 13:04:36,235 [root] DEBUG: 2520: api-rate-cap: LdrGetProcedureAddress hook disabled due to rate 2025-07-10 13:04:36,313 [root] DEBUG: 2520: DLL loaded at 0x66AB0000: C:\Program Files (x86)\Microsoft Office\OFFICE15\PROOF\1033\MSGR3EN (0x486000 bytes). 2025-07-10 13:04:36,329 [root] DEBUG: 2520: DLL loaded at 0x66A80000: C:\Windows\system32\POWRPROF (0x25000 bytes). 2025-07-10 13:04:36,407 [root] DEBUG: 2520: api-rate-cap: LoadResource hook disabled due to rate 2025-07-10 13:04:36,407 [root] DEBUG: 2520: api-rate-cap: LockResource hook disabled due to rate 2025-07-10 13:04:36,407 [root] DEBUG: 2520: api-rate-cap: FindResourceExA hook disabled due to rate 2025-07-10 13:04:39,407 [root] DEBUG: 2520: DLL loaded at 0x66A50000: C:\Windows\system32\SXS (0x5f000 bytes). 2025-07-10 13:04:42,875 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:04:43,125 [lib.common.results] INFO: File 1752177883079101500.InternetExplorer.evtx.gz size is 252, Max size: 100000000 2025-07-10 13:04:43,141 [lib.common.results] INFO: File 1752177883079101500.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-10 13:04:43,141 [lib.common.results] INFO: File 1752177883079101500.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2025-07-10 13:04:43,157 [lib.common.results] INFO: File 1752177883079101500.Application.evtx.gz size is 6663, Max size: 100000000 2025-07-10 13:04:43,172 [lib.common.results] INFO: File 1752177883125976500.OAlerts.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:04:43,188 [lib.common.results] INFO: File 1752177883125976500.Setup.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:04:43,204 [lib.common.results] INFO: File 1752177883125976500.Security.evtx.gz size is 7734, Max size: 100000000 2025-07-10 13:04:43,219 [lib.common.results] INFO: File 1752177883125976500.System.evtx.gz size is 8874, Max size: 100000000 2025-07-10 13:04:43,235 [lib.common.results] INFO: File 1752177883172851500.WindowsPowerShell.evtx.gz size is 625, Max size: 100000000 2025-07-10 13:04:44,813 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-10 13:04:49,954 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752177889.9541016.sysmon.evtx.gz to host 2025-07-10 13:04:49,954 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 107882, Max size: 100000000 2025-07-10 13:04:55,750 [lib.common.results] INFO: File c:\olddocs\1752177890719.saz size is 20583, Max size: 100000000 2025-07-10 13:04:55,766 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-10 13:04:58,266 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:04:58,500 [lib.common.results] INFO: File 1752177898454101500.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2025-07-10 13:04:58,516 [lib.common.results] INFO: File 1752177898454101500.InternetExplorer.evtx.gz size is 252, Max size: 100000000 2025-07-10 13:04:58,516 [lib.common.results] INFO: File 1752177898454101500.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-10 13:04:58,532 [lib.common.results] INFO: File 1752177898454101500.Application.evtx.gz size is 6609, Max size: 100000000 2025-07-10 13:04:58,547 [lib.common.results] INFO: File 1752177898500976500.OAlerts.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:04:58,563 [lib.common.results] INFO: File 1752177898500976500.Security.evtx.gz size is 7135, Max size: 100000000 2025-07-10 13:04:58,563 [lib.common.results] INFO: File 1752177898516601500.Setup.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:04:58,579 [lib.common.results] INFO: File 1752177898516601500.System.evtx.gz size is 8873, Max size: 100000000 2025-07-10 13:04:58,594 [lib.common.results] INFO: File 1752177898547851500.WindowsPowerShell.evtx.gz size is 625, Max size: 100000000 2025-07-10 13:05:04,969 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-10 13:05:10,047 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752177910.0322266.sysmon.evtx.gz to host 2025-07-10 13:05:10,047 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 8280, Max size: 100000000 2025-07-10 13:05:13,625 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:05:13,860 [lib.common.results] INFO: File 1752177913813476500.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2025-07-10 13:05:13,875 [lib.common.results] INFO: File 1752177913813476500.InternetExplorer.evtx.gz size is 252, Max size: 100000000 2025-07-10 13:05:13,891 [lib.common.results] INFO: File 1752177913813476500.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-10 13:05:13,907 [lib.common.results] INFO: File 1752177913813476500.Application.evtx.gz size is 6609, Max size: 100000000 2025-07-10 13:05:13,922 [lib.common.results] INFO: File 1752177913860351500.OAlerts.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:05:13,938 [lib.common.results] INFO: File 1752177913860351500.Setup.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:05:13,954 [lib.common.results] INFO: File 1752177913860351500.Security.evtx.gz size is 7173, Max size: 100000000 2025-07-10 13:05:13,969 [lib.common.results] INFO: File 1752177913875976500.System.evtx.gz size is 8575, Max size: 100000000 2025-07-10 13:05:13,985 [lib.common.results] INFO: File 1752177913922851500.WindowsPowerShell.evtx.gz size is 625, Max size: 100000000 2025-07-10 13:05:15,875 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-10 13:05:16,188 [modules.auxiliary.human] INFO: Doing office click around. 2025-07-10 13:05:16,500 [root] DEBUG: 2520: DLL loaded at 0x661B0000: C:\Program Files (x86)\Microsoft Office\Office15\igx (0x893000 bytes). 2025-07-10 13:05:16,563 [root] DEBUG: 2520: DLL loaded at 0x66120000: C:\Windows\system32\UIAutomationCore (0x8c000 bytes). 2025-07-10 13:05:16,579 [root] DEBUG: 2520: DLL loaded at 0x75E00000: C:\Windows\syswow64\PSAPI (0x5000 bytes). 2025-07-10 13:05:16,579 [root] DEBUG: 2520: DLL loaded at 0x660E0000: C:\Windows\system32\OLEACC (0x3c000 bytes). 2025-07-10 13:05:25,063 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-10 13:05:25,922 [root] DEBUG: 2520: DLL loaded at 0x67790000: C:\Program Files (x86)\Microsoft Office\Office15\IEAWSDC (0x31000 bytes). 2025-07-10 13:05:26,672 [root] DEBUG: 2520: api-rate-cap: RegQueryInfoKeyW hook disabled due to rate 2025-07-10 13:05:26,672 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD7069.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,672 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD706B.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,688 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD706D.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,688 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD706C.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,688 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD706A.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,704 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD7070.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,704 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD706E.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,704 [root] DEBUG: 2520: DLL loaded at 0x67770000: C:\Windows\system32\Cabinet (0x15000 bytes). 2025-07-10 13:05:26,704 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD706F.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,719 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD7090.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,719 [root] DEBUG: 2520: DLL loaded at 0x67760000: C:\Windows\system32\DEVRTL (0xe000 bytes). 2025-07-10 13:05:26,813 [root] DEBUG: 2520: api-rate-cap: NtReadFile hook disabled due to rate 2025-07-10 13:05:26,813 [root] DEBUG: 2520: api-rate-cap: NtReadFile hook disabled due to rate 2025-07-10 13:05:26,813 [root] DEBUG: 2520: api-rate-cap: NtReadFile hook disabled due to rate 2025-07-10 13:05:26,813 [root] DEBUG: 2520: api-rate-cap: NtReadFile hook disabled due to rate 2025-07-10 13:05:26,829 [root] DEBUG: 2520: api-rate-cap: NtReadFile hook disabled due to rate 2025-07-10 13:05:26,829 [root] DEBUG: 2520: api-rate-cap: NtReadFile hook disabled due to rate 2025-07-10 13:05:26,829 [root] DEBUG: 2520: api-rate-cap: NtReadFile hook disabled due to rate 2025-07-10 13:05:26,829 [root] DEBUG: 2520: api-rate-cap: NtReadFile hook disabled due to rate 2025-07-10 13:05:26,829 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E3A.tmp size is 222992, Max size: 100000000 2025-07-10 13:05:26,844 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E4B.tmp size is 271273, Max size: 100000000 2025-07-10 13:05:26,860 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E27.tmp size is 276650, Max size: 100000000 2025-07-10 13:05:26,860 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD711E.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,875 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E4C.tmp size is 698244, Max size: 100000000 2025-07-10 13:05:26,875 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E39.tmp size is 261258, Max size: 100000000 2025-07-10 13:05:26,891 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E28.tmp size is 550906, Max size: 100000000 2025-07-10 13:05:26,891 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E26.tmp size is 295527, Max size: 100000000 2025-07-10 13:05:26,907 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E5D.tmp size is 1097591, Max size: 100000000 2025-07-10 13:05:26,922 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E38.tmp size is 307348, Max size: 100000000 2025-07-10 13:05:26,922 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD716D.tmp size is 0, Max size: 100000000 2025-07-10 13:05:26,954 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD717E.tmp size is 0, Max size: 100000000 2025-07-10 13:05:27,032 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6E6D.tmp size is 723359, Max size: 100000000 2025-07-10 13:05:27,063 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6F4A.tmp size is 1310275, Max size: 100000000 2025-07-10 13:05:27,079 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD720C.tmp size is 0, Max size: 100000000 2025-07-10 13:05:27,079 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD720B.tmp size is 0, Max size: 100000000 2025-07-10 13:05:27,110 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6F5B.tmp size is 1065873, Max size: 100000000 2025-07-10 13:05:27,125 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD722D.tmp size is 0, Max size: 100000000 2025-07-10 13:05:27,125 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD723E.tmp size is 0, Max size: 100000000 2025-07-10 13:05:27,125 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD723D.tmp size is 0, Max size: 100000000 2025-07-10 13:05:27,219 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6FAD.tmp size is 2527736, Max size: 100000000 2025-07-10 13:05:27,219 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6F9C.tmp size is 1766185, Max size: 100000000 2025-07-10 13:05:27,219 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6F8B.tmp size is 3256855, Max size: 100000000 2025-07-10 13:05:27,235 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab6EEB.tmp size is 2591108, Max size: 100000000 2025-07-10 13:05:29,016 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:05:29,250 [lib.common.results] INFO: File 1752177929204101500.InternetExplorer.evtx.gz size is 252, Max size: 100000000 2025-07-10 13:05:29,250 [lib.common.results] INFO: File 1752177929219726500.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-10 13:05:29,266 [lib.common.results] INFO: File 1752177929204101500.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2025-07-10 13:05:29,282 [lib.common.results] INFO: File 1752177929188476500.Application.evtx.gz size is 6827, Max size: 100000000 2025-07-10 13:05:29,297 [lib.common.results] INFO: File 1752177929250976500.OAlerts.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:05:29,313 [lib.common.results] INFO: File 1752177929250976500.Security.evtx.gz size is 7138, Max size: 100000000 2025-07-10 13:05:29,313 [lib.common.results] INFO: File 1752177929266601500.Setup.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:05:29,329 [lib.common.results] INFO: File 1752177929266601500.System.evtx.gz size is 8586, Max size: 100000000 2025-07-10 13:05:29,344 [lib.common.results] INFO: File 1752177929297851500.WindowsPowerShell.evtx.gz size is 625, Max size: 100000000 2025-07-10 13:05:30,125 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752177930.1259766.sysmon.evtx.gz to host 2025-07-10 13:05:30,125 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 8348, Max size: 100000000 2025-07-10 13:05:36,000 [lib.common.results] INFO: File c:\olddocs\1752177930954.saz size is 19087617, Max size: 100000000 2025-07-10 13:05:36,157 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-10 13:05:43,375 [modules.auxiliary.human] INFO: Closing Office window 2025-07-10 13:05:43,422 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\~$34_as_password_ha.docx size is 162, Max size: 100000000 2025-07-10 13:05:43,438 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{DC4F3E9F-60FD-4158-8572-4A9DEA59662C}.tmp size is 1688, Max size: 100000000 2025-07-10 13:05:43,547 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{999C8BA6-D70F-4537-8F31-AC1DA58EEA3E}.tmp size is 1024, Max size: 100000000 2025-07-10 13:05:43,610 [root] DEBUG: 2520: DLL loaded at 0x67AE0000: C:\Windows\system32\POWRPROF (0x25000 bytes). 2025-07-10 13:05:43,782 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\CVR93C2.tmp.cvr size is 0, Max size: 100000000 2025-07-10 13:05:43,797 [root] DEBUG: 2520: Dropped file limit reached. 2025-07-10 13:05:43,797 [root] DEBUG: 2520: NtTerminateProcess hook: Attempting to dump process 2520 2025-07-10 13:05:43,797 [root] DEBUG: 2520: VerifyCodeSection: Executable code does not match, 0x64c of 0x154f matching 2025-07-10 13:05:43,797 [root] DEBUG: 2520: DoProcessDump: Code modification detected, dumping Imagebase at 0x00360000. 2025-07-10 13:05:43,797 [root] DEBUG: 2520: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2025-07-10 13:05:43,813 [root] DEBUG: 2520: DumpProcess: Instantiating PeParser with address: 0x00360000. 2025-07-10 13:05:43,813 [root] DEBUG: 2520: DumpProcess: Module entry point VA is 0x000010D4. 2025-07-10 13:05:43,844 [lib.common.results] INFO: File C:\tzISHwtwg\CAPE\2520_209973514352010472025 size is 1915904, Max size: 100000000 2025-07-10 13:05:43,875 [root] DEBUG: 2520: DumpProcess: Module image dump success - dump size 0x1d3c00. 2025-07-10 13:05:43,907 [root] INFO: Process with pid 2520 has terminated 2025-07-10 13:05:44,375 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:05:44,641 [lib.common.results] INFO: File 1752177944594726500.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-10 13:05:44,657 [lib.common.results] INFO: File 1752177944594726500.InternetExplorer.evtx.gz size is 252, Max size: 100000000 2025-07-10 13:05:44,672 [lib.common.results] INFO: File 1752177944579101500.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2025-07-10 13:05:44,688 [lib.common.results] INFO: File 1752177944579101500.Application.evtx.gz size is 6757, Max size: 100000000 2025-07-10 13:05:44,704 [lib.common.results] INFO: File 1752177944641601500.OAlerts.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:05:44,704 [lib.common.results] INFO: File 1752177944641601500.System.evtx.gz size is 8558, Max size: 100000000 2025-07-10 13:05:44,719 [lib.common.results] INFO: File 1752177944641601500.Setup.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:05:44,719 [lib.common.results] INFO: File 1752177944641601500.Security.evtx.gz size is 6827, Max size: 100000000 2025-07-10 13:05:44,750 [lib.common.results] INFO: File 1752177944688476500.WindowsPowerShell.evtx.gz size is 625, Max size: 100000000 2025-07-10 13:05:45,141 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-10 13:05:50,266 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752177950.2666016.sysmon.evtx.gz to host 2025-07-10 13:05:50,266 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 64868, Max size: 100000000 2025-07-10 13:05:50,485 [root] INFO: Process list is empty, terminating analysis 2025-07-10 13:05:51,485 [root] INFO: Created shutdown mutex 2025-07-10 13:05:52,485 [root] INFO: Shutting down package 2025-07-10 13:05:52,485 [root] INFO: Stopping auxiliary modules 2025-07-10 13:05:52,485 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2025-07-10 13:05:52,485 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2025-07-10 13:05:52,500 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:05:52,750 [lib.common.results] INFO: File 1752177952704101500.InternetExplorer.evtx.gz size is 252, Max size: 100000000 2025-07-10 13:05:52,750 [lib.common.results] INFO: File 1752177952704101500.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-10 13:05:52,766 [lib.common.results] INFO: File 1752177952704101500.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2025-07-10 13:05:52,766 [lib.common.results] INFO: File 1752177952688476500.Application.evtx.gz size is 6757, Max size: 100000000 2025-07-10 13:05:52,797 [lib.common.results] INFO: File 1752177952750976500.Setup.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:05:52,813 [lib.common.results] INFO: File 1752177952750976500.Security.evtx.gz size is 6812, Max size: 100000000 2025-07-10 13:05:52,829 [lib.common.results] INFO: File 1752177952766601500.System.evtx.gz size is 8587, Max size: 100000000 2025-07-10 13:05:52,844 [lib.common.results] INFO: File 1752177952750976500.OAlerts.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:05:52,844 [lib.common.results] INFO: File 1752177952797851500.WindowsPowerShell.evtx.gz size is 625, Max size: 100000000 2025-07-10 13:05:56,219 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-10 13:05:57,938 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-10 13:05:57,938 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2025-07-10 13:05:59,797 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-10 13:06:00,047 [lib.common.results] INFO: File 1752177960000976500.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2025-07-10 13:06:00,079 [lib.common.results] INFO: File 1752177960000976500.Application.evtx.gz size is 6757, Max size: 100000000 2025-07-10 13:06:00,094 [lib.common.results] INFO: File 1752177960032226500.InternetExplorer.evtx.gz size is 252, Max size: 100000000 2025-07-10 13:06:00,110 [lib.common.results] INFO: File 1752177960047851500.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-10 13:06:00,125 [lib.common.results] INFO: File 1752177960063476500.OAlerts.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:06:00,141 [lib.common.results] INFO: File 1752177960094726500.Setup.evtx.gz size is 247, Max size: 100000000 2025-07-10 13:06:00,157 [lib.common.results] INFO: File 1752177960079101500.Security.evtx.gz size is 6915, Max size: 100000000 2025-07-10 13:06:00,172 [lib.common.results] INFO: File 1752177960110351500.System.evtx.gz size is 8614, Max size: 100000000 2025-07-10 13:06:00,172 [lib.common.results] INFO: File 1752177960125976500.WindowsPowerShell.evtx.gz size is 625, Max size: 100000000 2025-07-10 13:06:02,985 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752177962.9853513.sysmon.evtx.gz to host 2025-07-10 13:06:02,985 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6293, Max size: 100000000 2025-07-10 13:06:03,000 [root] INFO: Finishing auxiliary modules 2025-07-10 13:06:03,000 [root] INFO: Shutting down pipe server and dumping dropped files 2025-07-10 13:06:03,000 [root] WARNING: Folder at path "C:\tzISHwtwg\debugger" does not exist, skipping 2025-07-10 13:06:03,000 [root] INFO: Uploading files at path "C:\tzISHwtwg\tlsdump" 2025-07-10 13:06:03,000 [lib.common.results] INFO: File C:\tzISHwtwg\tlsdump\tlsdump.log size is 21646, Max size: 100000000 2025-07-10 13:06:03,016 [root] INFO: Analysis completed
Name | Label | Manager | Started On | Shutdown On | Route |
---|---|---|---|---|---|
win7office2k3flash2800137TWN3H102 | win7office2k3flash2800137TWN3H102 | KVM | 2025-07-10 20:04:11 | 2025-07-10 20:06:13 | internet |
File Name | 1234_as_password_ha.docx |
---|---|
File Size | 103867 bytes |
File Type | Microsoft Word 2007+ |
MD5 | 572312c9ea3f6515036ba67dbf94612e |
SHA1 | 39de356d1245c84d34380e801e271557dc8f6844 |
SHA256 | c4bcd28cc650de8bd7546643786316f8a36aa6086c046094a24867e606d2e28e |
SHA512 | adeb1c901a67a83a1c31efca5b6dc73406bd85e69330395670829f6d05e4dfaf732959f05425a577d81c0fb798009a5a13133c47bcf1aaed29f5d6d3d3508f52 |
SHA3-384 | b09e1caaadb85d3c8c57bfc7ee82998dedeae9e36f4ebda2b68a55e6c51a969e8e2c93d02ef75e2044a8f6384a1b3cf9 |
CRC32 | 5086EBBD |
TLSH | T153A3126FDAF5CA7AFE051C79F85B8162F0066405430E26B114018D6ACB42BA42FF36FE |
Ssdeep | 3072:pnnEtyfyKvDdpmn1Xi8BRaVpeT3wQRT3IB3:hEty6KvDe1XnRag3VRT3IJ |
File
|
|
Direct | IP | Country Name |
---|---|---|
N | 2.19.252.143 [VT] | Europe |
N | 2.18.63.31 [VT] | Europe |
Y | 8.8.8.8 [VT] | United States |
Name | Response | Post-Analysis Lookup |
---|---|---|
metadata.templates.cdn.office.net [VT] |
CNAME templatesmetadata.office.net.edgekey.net
[VT]
A 2.18.63.31 [VT] CNAME templatesmetadata.office.net [VT] A 2.18.63.57 [VT] CNAME e26769.dscb.akamaiedge.net [VT] |
96.17.193.45 [VT] |
binaries.templates.cdn.office.net [VT] |
CNAME binaries.templates.cdn.office.net.edgesuite.net
[VT]
A 2.19.252.136 [VT] CNAME a1847.dscg2.akamai.net [VT] A 2.19.252.143 [VT] |
23.33.90.71 [VT] |
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP