Category | Package | Started | Completed | Duration | Options | Log |
---|---|---|---|---|---|---|
FILE | doc | 2025-07-11 08:59:40 | 2025-07-11 09:02:48 | 188 seconds | Show Options | Show Log |
procdump=1
amsidump=1
2024-04-29 04:35:24,562 [root] INFO: Date set to: 20250711T01:59:40, timeout set to: 150 2025-07-11 01:59:40,015 [root] DEBUG: Starting analyzer from: C:\tmpkf7o2il2 2025-07-11 01:59:40,015 [root] DEBUG: Storing results at: C:\jXBlvUtF 2025-07-11 01:59:40,015 [root] DEBUG: Pipe server name: \\.\PIPE\yVHBwzeaF 2025-07-11 01:59:40,015 [root] DEBUG: Python path: C:\olddocs 2025-07-11 01:59:40,015 [root] INFO: Analysis package "doc" has been specified 2025-07-11 01:59:40,015 [root] DEBUG: Importing analysis package "doc"... 2025-07-11 01:59:40,031 [root] DEBUG: Initializing analysis package "doc"... 2025-07-11 01:59:40,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL option 2025-07-11 01:59:40,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL_64 option 2025-07-11 01:59:40,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader option 2025-07-11 01:59:40,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader_64 option 2025-07-11 01:59:40,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2025-07-11 01:59:40,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2025-07-11 01:59:40,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2025-07-11 01:59:40,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2025-07-11 01:59:40,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2025-07-11 01:59:40,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2025-07-11 01:59:40,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2025-07-11 01:59:40,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2025-07-11 01:59:40,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2025-07-11 01:59:40,109 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2025-07-11 01:59:40,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2025-07-11 01:59:40,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2025-07-11 01:59:40,187 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2025-07-11 01:59:40,187 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2025-07-11 01:59:40,187 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2025-07-11 01:59:40,187 [root] DEBUG: Initializing auxiliary module "Browser"... 2025-07-11 01:59:40,187 [root] DEBUG: Started auxiliary module Browser 2025-07-11 01:59:40,187 [root] DEBUG: Initializing auxiliary module "Curtain"... 2025-07-11 01:59:40,187 [root] DEBUG: Started auxiliary module Curtain 2025-07-11 01:59:40,187 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2025-07-11 01:59:40,218 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2025-07-11 01:59:40,218 [root] DEBUG: Started auxiliary module DefaultApps 2025-07-11 01:59:40,218 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2025-07-11 01:59:40,218 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2025-07-11 01:59:40,218 [modules.auxiliary.digisig] INFO: doc 2025-07-11 01:59:40,218 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2025-07-11 01:59:40,218 [root] DEBUG: Started auxiliary module DigiSig 2025-07-11 01:59:40,218 [root] DEBUG: Initializing auxiliary module "Disguise"... 2025-07-11 01:59:40,515 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2025-07-11 01:59:40,515 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2025-07-11 01:59:40,515 [root] DEBUG: Initializing auxiliary module "Evtx"... 2025-07-11 01:59:40,515 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpkf7o2il2\bin\auditpol.csv 2025-07-11 01:59:41,015 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 01:59:41,578 [root] DEBUG: Started auxiliary module Evtx 2025-07-11 01:59:41,578 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2025-07-11 01:59:41,578 [modules.auxiliary.fiddler] INFO: fiddler package: doc 2025-07-11 01:59:41,578 [root] DEBUG: Started auxiliary module Fiddler 2025-07-11 01:59:41,578 [root] DEBUG: Initializing auxiliary module "Human"... 2025-07-11 01:59:41,593 [root] DEBUG: Started auxiliary module Human 2025-07-11 01:59:41,593 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2025-07-11 01:59:41,593 [root] DEBUG: Started auxiliary module Screenshots 2025-07-11 01:59:41,593 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2025-07-11 01:59:41,593 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2025-07-11 01:59:41,593 [root] DEBUG: Started auxiliary module Sysmon 2025-07-11 01:59:41,593 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2025-07-11 01:59:41,593 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2025-07-11 01:59:41,593 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2025-07-11 01:59:41,593 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 556 2025-07-11 01:59:41,593 [lib.api.process] INFO: Monitor config for process 556: C:\tmpkf7o2il2\dll\556.ini 2025-07-11 01:59:41,593 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-11 01:59:41,593 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-11 01:59:41,593 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-11 01:59:41,593 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2025-07-11 01:59:41,593 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2025-07-11 01:59:41,593 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2025-07-11 01:59:41,593 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2025-07-11 01:59:41,593 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpkf7o2il2\dll\NeTFOUu.dll, loader C:\tmpkf7o2il2\bin\SvxOJKJc.exe 2025-07-11 01:59:41,625 [root] DEBUG: Loader: IAT patching disabled. 2025-07-11 01:59:41,625 [root] DEBUG: Loader: Injecting process 556 with C:\tmpkf7o2il2\dll\NeTFOUu.dll. 2025-07-11 01:59:41,656 [root] DEBUG: 556: Python path set to 'C:\olddocs'. 2025-07-11 01:59:41,671 [root] DEBUG: 556: Disabling sleep skipping. 2025-07-11 01:59:41,671 [root] DEBUG: 556: Process dumps enabled. 2025-07-11 01:59:41,671 [root] DEBUG: 556: AMSI dumping enabled. 2025-07-11 01:59:41,687 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEF6060000, thread 2488, image base 0x00000000FF340000, stack from 0x00000000016F3000-0x0000000001700000 2025-07-11 01:59:41,687 [root] DEBUG: 556: Commandline: C:\Windows\system32\lsass.exe 2025-07-11 01:59:41,703 [root] DEBUG: 556: Hooked 5 out of 5 functions 2025-07-11 01:59:41,703 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2025-07-11 01:59:41,703 [root] DEBUG: Successfully injected DLL C:\tmpkf7o2il2\dll\NeTFOUu.dll. 2025-07-11 01:59:41,703 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 556 2025-07-11 01:59:41,703 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2025-07-11 01:59:41,703 [root] DEBUG: Initializing auxiliary module "Usage"... 2025-07-11 01:59:41,703 [root] DEBUG: Started auxiliary module Usage 2025-07-11 01:59:43,734 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2025-07-11 01:59:44,343 [root] INFO: Restarting WMI Service 2025-07-11 01:59:53,437 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" with arguments ""C:\Users\pgabriel\AppData\Local\Temp\Invoice.docx" /q" with pid 1180 2025-07-11 01:59:53,437 [lib.api.process] INFO: Monitor config for process 1180: C:\tmpkf7o2il2\dll\1180.ini 2025-07-11 01:59:53,453 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-11 01:59:53,453 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-11 01:59:53,453 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-11 01:59:53,453 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2025-07-11 01:59:53,453 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2025-07-11 01:59:53,453 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2025-07-11 01:59:53,453 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpkf7o2il2\dll\dDldptMi.dll, loader C:\tmpkf7o2il2\bin\ZYVYomS.exe 2025-07-11 01:59:53,484 [root] DEBUG: Loader: IAT patching disabled. 2025-07-11 01:59:53,484 [root] DEBUG: Loader: Injecting process 1180 (thread 2852) with C:\tmpkf7o2il2\dll\dDldptMi.dll. 2025-07-11 01:59:53,484 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued. 2025-07-11 01:59:53,484 [root] DEBUG: Successfully injected DLL C:\tmpkf7o2il2\dll\dDldptMi.dll. 2025-07-11 01:59:53,484 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 1180 2025-07-11 01:59:53,734 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 01:59:55,484 [lib.api.process] INFO: Successfully resumed process with pid 1180 2025-07-11 01:59:55,531 [root] DEBUG: 1180: Python path set to 'C:\olddocs'. 2025-07-11 01:59:55,531 [root] DEBUG: 1180: Disabling sleep skipping. 2025-07-11 01:59:55,531 [root] DEBUG: 1180: Process dumps enabled. 2025-07-11 01:59:55,546 [root] DEBUG: 1180: AMSI dumping enabled. 2025-07-11 01:59:55,546 [root] DEBUG: 1180: Monitor config - unrecognised key office. 2025-07-11 01:59:55,546 [root] DEBUG: 1180: In-monitor YARA scans disabled. 2025-07-11 01:59:55,546 [root] DEBUG: 1180: Dropped file limit defaulting to 100. 2025-07-11 01:59:55,546 [root] DEBUG: 1180: Microsoft Office settings enabled. 2025-07-11 01:59:55,546 [root] DEBUG: 1180: Monitor initialised: 32-bit capemon loaded in process 1180 at 0x745c0000, thread 2852, image base 0x13e0000, stack from 0x1b3000-0x1c0000 2025-07-11 01:59:55,546 [root] DEBUG: 1180: Commandline: "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" "C:\Users\pgabriel\AppData\Local\Temp\Invoice.docx" /q 2025-07-11 01:59:55,578 [root] DEBUG: 1180: Hooked 455 out of 455 functions 2025-07-11 01:59:55,578 [root] DEBUG: 1180: WoW64 detected: 64-bit ntdll base: 0x77ae0000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x77b4b5f0, Wow64PrepareForException: 0x0 2025-07-11 01:59:55,578 [root] DEBUG: 1180: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0xa0000 2025-07-11 01:59:55,578 [root] INFO: Loaded monitor into process with pid 1180 2025-07-11 01:59:55,812 [root] DEBUG: 1180: DLL loaded at 0x704A0000: C:\Program Files (x86)\Microsoft Office\Office15\wwlib (0x14bc000 bytes). 2025-07-11 01:59:55,843 [root] DEBUG: 1180: DLL loaded at 0x74430000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus (0x190000 bytes). 2025-07-11 01:59:55,843 [root] DEBUG: 1180: DLL loaded at 0x777C0000: C:\Windows\syswow64\OLEAUT32 (0x8f000 bytes). 2025-07-11 01:59:56,000 [root] DEBUG: 1180: DLL loaded at 0x6F6F0000: C:\Program Files (x86)\Microsoft Office\Office15\oart (0xda8000 bytes). 2025-07-11 01:59:56,000 [root] DEBUG: 1180: DLL loaded at 0x74C10000: C:\Windows\system32\MSVCP100 (0x69000 bytes). 2025-07-11 01:59:56,046 [root] DEBUG: 1180: DLL loaded at 0x72AD0000: C:\Windows\system32\d2d1 (0x347000 bytes). 2025-07-11 01:59:56,328 [root] DEBUG: 1180: DLL loaded at 0x6DE00000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso (0x18e4000 bytes). 2025-07-11 01:59:56,328 [root] DEBUG: 1180: DLL loaded at 0x738D0000: C:\Windows\system32\MSIMG32 (0x5000 bytes). 2025-07-11 01:59:56,343 [root] DEBUG: 1180: DLL loaded at 0x73AC0000: C:\Windows\system32\uxtheme (0x80000 bytes). 2025-07-11 01:59:56,359 [root] DEBUG: 1180: DLL loaded at 0x739E0000: C:\Windows\system32\WTSAPI32 (0xd000 bytes). 2025-07-11 01:59:56,359 [root] DEBUG: 1180: DLL loaded at 0x74BE0000: C:\Windows\system32\WINSTA (0x29000 bytes). 2025-07-11 01:59:56,359 [root] DEBUG: 1180: DLL loaded at 0x74B70000: C:\Windows\system32\dxgi (0x4c000 bytes). 2025-07-11 01:59:56,375 [root] DEBUG: 1180: DLL loaded at 0x73A00000: C:\Windows\system32\VERSION (0x9000 bytes). 2025-07-11 01:59:56,375 [root] DEBUG: 1180: DLL loaded at 0x74D40000: C:\Windows\system32\dwmapi (0x13000 bytes). 2025-07-11 01:59:56,375 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:56,375 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:56,375 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:56,390 [root] DEBUG: 1180: DLL loaded at 0x75B40000: C:\Windows\syswow64\WINTRUST (0x2f000 bytes). 2025-07-11 01:59:56,406 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:56,406 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:56,406 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:56,406 [root] DEBUG: 1180: DLL loaded at 0x72890000: C:\Windows\system32\msi (0x240000 bytes). 2025-07-11 01:59:56,531 [root] DEBUG: 1180: api-rate-cap: NtQueryValueKey hook disabled due to rate 2025-07-11 01:59:56,531 [root] DEBUG: 1180: api-rate-cap: NtClose hook disabled due to rate 2025-07-11 01:59:56,531 [root] DEBUG: 1180: api-rate-cap: NtOpenKey hook disabled due to rate 2025-07-11 01:59:56,562 [root] DEBUG: 1180: api-rate-cap: RegCloseKey hook disabled due to rate 2025-07-11 01:59:56,578 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 01:59:56,625 [root] DEBUG: 1180: DLL loaded at 0x72270000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSPTLS (0x116000 bytes). 2025-07-11 01:59:56,781 [root] DEBUG: 1180: DLL loaded at 0x769D0000: C:\Windows\syswow64\SHELL32 (0xc4a000 bytes). 2025-07-11 01:59:56,796 [root] DEBUG: 1180: DLL loaded at 0x75D70000: C:\Windows\syswow64\profapi (0xb000 bytes). 2025-07-11 01:59:56,875 [root] DEBUG: 1180: DLL loaded at 0x73B50000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32 (0x19e000 bytes). 2025-07-11 01:59:56,890 [root] DEBUG: 1180: DLL loaded at 0x74340000: C:\Windows\system32\d3d10_1 (0x2c000 bytes). 2025-07-11 01:59:56,890 [lib.common.results] INFO: File 1752224396812500000.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 01:59:56,890 [root] DEBUG: 1180: DLL loaded at 0x742F0000: C:\Windows\system32\d3d10_1core (0x41000 bytes). 2025-07-11 01:59:56,906 [lib.common.results] INFO: File 1752224396781250000.Application.evtx.gz size is 6783, Max size: 100000000 2025-07-11 01:59:56,906 [lib.common.results] INFO: File 1752224396812500000.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 01:59:56,906 [root] DEBUG: 1180: DLL loaded at 0x71D70000: C:\Windows\system32\d3d11 (0x175000 bytes). 2025-07-11 01:59:56,937 [root] DEBUG: 1180: DLL loaded at 0x71B80000: C:\Windows\system32\D3D10Warp (0x1e9000 bytes). 2025-07-11 01:59:56,937 [lib.common.results] INFO: File 1752224396890625000.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 01:59:56,937 [lib.common.results] INFO: File 1752224396875000000.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 01:59:56,953 [lib.common.results] INFO: File 1752224396890625000.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 01:59:56,953 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:56,968 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:56,968 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:56,968 [lib.common.results] INFO: File 1752224396890625000.Security.evtx.gz size is 15680, Max size: 100000000 2025-07-11 01:59:56,968 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:56,968 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:56,968 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:56,984 [lib.common.results] INFO: File 1752224396937500000.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 01:59:56,984 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:56,984 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:56,984 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:57,000 [lib.common.results] INFO: File 1752224396937500000.System.evtx.gz size is 8754, Max size: 100000000 2025-07-11 01:59:57,000 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:57,000 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:57,000 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:57,031 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:57,031 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:57,031 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:57,062 [root] DEBUG: 1180: DLL loaded at 0x71A50000: C:\Windows\system32\WindowsCodecs (0x130000 bytes). 2025-07-11 01:59:57,062 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:57,078 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:57,078 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:57,078 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-11 01:59:57,078 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:57,093 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:57,125 [root] DEBUG: 1180: DLL loaded at 0x6DCC0000: C:\Windows\system32\DWrite (0x135000 bytes). 2025-07-11 01:59:57,140 [root] DEBUG: 1180: DLL loaded at 0x742A0000: C:\Windows\system32\mscoree (0x4a000 bytes). 2025-07-11 01:59:57,156 [root] DEBUG: 1180: DLL loaded at 0x719C0000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes). 2025-07-11 01:59:57,265 [root] DEBUG: 1180: DLL loaded at 0x6DC00000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\adal (0xb5000 bytes). 2025-07-11 01:59:57,265 [root] DEBUG: 1180: DLL loaded at 0x71960000: C:\Windows\system32\WINHTTP (0x58000 bytes). 2025-07-11 01:59:57,281 [root] DEBUG: 1180: DLL loaded at 0x731F0000: C:\Windows\system32\webio (0x50000 bytes). 2025-07-11 01:59:57,296 [root] DEBUG: 1180: DLL loaded at 0x76350000: C:\Windows\syswow64\WININET (0x1e4000 bytes). 2025-07-11 01:59:57,296 [root] DEBUG: 1180: DLL loaded at 0x75BE0000: C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes). 2025-07-11 01:59:57,296 [root] DEBUG: 1180: DLL loaded at 0x75D80000: C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes). 2025-07-11 01:59:57,312 [root] DEBUG: 1180: DLL loaded at 0x76910000: C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes). 2025-07-11 01:59:57,312 [root] DEBUG: 1180: DLL loaded at 0x76550000: C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes). 2025-07-11 01:59:57,312 [root] DEBUG: 1180: DLL loaded at 0x77850000: C:\Windows\syswow64\normaliz (0x3000 bytes). 2025-07-11 01:59:57,328 [root] DEBUG: 1180: DLL loaded at 0x76590000: C:\Windows\syswow64\iertutil (0x232000 bytes). 2025-07-11 01:59:57,328 [root] DEBUG: 1180: DLL loaded at 0x75710000: C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes). 2025-07-11 01:59:57,343 [root] DEBUG: 1180: DLL loaded at 0x75CB0000: C:\Windows\syswow64\USERENV (0x17000 bytes). 2025-07-11 01:59:57,343 [root] DEBUG: 1180: DLL loaded at 0x75180000: C:\Windows\system32\Secur32 (0x8000 bytes). 2025-07-11 01:59:57,359 [root] DEBUG: 1180: DLL loaded at 0x76830000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes). 2025-07-11 01:59:57,375 [root] DEBUG: 1180: DLL loaded at 0x6DBA0000: C:\Windows\System32\netprofm (0x5a000 bytes). 2025-07-11 01:59:57,375 [root] DEBUG: 1180: DLL loaded at 0x74D00000: C:\Windows\System32\nlaapi (0x10000 bytes). 2025-07-11 01:59:57,390 [root] DEBUG: 1180: DLL loaded at 0x73240000: C:\Windows\system32\CRYPTSP (0x17000 bytes). 2025-07-11 01:59:57,390 [root] DEBUG: 1180: DLL loaded at 0x731B0000: C:\Windows\system32\rsaenh (0x3b000 bytes). 2025-07-11 01:59:57,406 [root] DEBUG: 1180: DLL loaded at 0x741A0000: C:\Windows\system32\RpcRtRemote (0xe000 bytes). 2025-07-11 01:59:57,406 [root] DEBUG: 1180: DLL loaded at 0x74CF0000: C:\Windows\System32\npmproxy (0x8000 bytes). 2025-07-11 01:59:57,437 [root] DEBUG: 1180: DLL loaded at 0x6DA10000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20 (0x18e000 bytes). 2025-07-11 01:59:58,453 [root] DEBUG: 1180: DLL loaded at 0x741D0000: C:\Windows\system32\IPHLPAPI (0x1c000 bytes). 2025-07-11 01:59:58,453 [root] DEBUG: 1180: DLL loaded at 0x741C0000: C:\Windows\system32\WINNSI (0x7000 bytes). 2025-07-11 01:59:58,453 [root] DEBUG: 1180: DLL loaded at 0x74BD0000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes). 2025-07-11 01:59:58,468 [root] DEBUG: 1180: DLL loaded at 0x68CF0000: C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppc (0x2d000 bytes). 2025-07-11 01:59:58,468 [root] DEBUG: 1180: DLL loaded at 0x73260000: C:\Windows\system32\dhcpcsvc (0x12000 bytes). 2025-07-11 01:59:58,484 [root] DEBUG: 1180: DLL loaded at 0x738E0000: C:\Windows\system32\credssp (0x8000 bytes). 2025-07-11 01:59:58,484 [root] DEBUG: 1180: DLL loaded at 0x74160000: C:\Windows\system32\mswsock (0x3c000 bytes). 2025-07-11 01:59:58,484 [root] DEBUG: 1180: DLL loaded at 0x74150000: C:\Windows\System32\wshtcpip (0x5000 bytes). 2025-07-11 01:59:58,500 [root] DEBUG: 1180: DLL loaded at 0x74140000: C:\Windows\System32\wship6 (0x6000 bytes). 2025-07-11 01:59:58,500 [root] DEBUG: 1180: DLL loaded at 0x68CA0000: C:\Windows\system32\DNSAPI (0x44000 bytes). 2025-07-11 01:59:58,515 [root] DEBUG: 1180: DLL loaded at 0x68C40000: C:\Windows\system32\WINSPOOL.DRV (0x51000 bytes). 2025-07-11 01:59:58,546 [root] DEBUG: 1180: DLL loaded at 0x68BF0000: C:\Windows\SysWOW64\schannel (0x41000 bytes). 2025-07-11 01:59:59,062 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224399.0468748.sysmon.evtx.gz to host 2025-07-11 01:59:59,062 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 8760, Max size: 100000000 2025-07-11 01:59:59,249 [root] DEBUG: 1180: DLL loaded at 0x76170000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes). 2025-07-11 01:59:59,249 [root] DEBUG: 1180: DLL loaded at 0x76560000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-11 01:59:59,249 [root] DEBUG: 1180: DLL loaded at 0x75770000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-11 01:59:59,265 [root] DEBUG: 1180: DLL loaded at 0x68AF0000: C:\Windows\system32\propsys (0xf5000 bytes). 2025-07-11 01:59:59,265 [root] DEBUG: 1180: DLL loaded at 0x73A90000: C:\Windows\system32\ntmarta (0x21000 bytes). 2025-07-11 01:59:59,281 [root] DEBUG: 1180: DLL loaded at 0x75720000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes). 2025-07-11 01:59:59,375 [root] DEBUG: 1180: DLL loaded at 0x68990000: C:\Windows\System32\msxml6 (0x158000 bytes). 2025-07-11 01:59:59,500 [root] DEBUG: 1180: DLL loaded at 0x68960000: C:\Windows\system32\XmlLite (0x2f000 bytes). 2025-07-11 01:59:59,515 [root] DEBUG: 556: DLL loaded at 0x000007FEF9300000: C:\Windows\system32\keyiso (0xb000 bytes). 2025-07-11 01:59:59,609 [root] DEBUG: 1180: DLL loaded at 0x76020000: C:\Windows\SysWOW64\urlmon (0x14a000 bytes). 2025-07-11 01:59:59,625 [root] DEBUG: 1180: DLL loaded at 0x75F80000: C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes). 2025-07-11 01:59:59,656 [root] DEBUG: 1180: DLL loaded at 0x68950000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes). 2025-07-11 01:59:59,906 [root] DEBUG: 1180: DLL loaded at 0x688F0000: C:\Windows\system32\SXS (0x5f000 bytes). 2025-07-11 02:00:00,187 [root] DEBUG: 556: TLS 1.2 secrets logged to: C:\jXBlvUtF\tlsdump\tlsdump.log 2025-07-11 02:00:00,281 [root] DEBUG: 556: DLL loaded at 0x000007FEFAB60000: C:\Windows\system32\cryptnet (0x27000 bytes). 2025-07-11 02:00:00,296 [root] DEBUG: 556: DLL loaded at 0x000007FEFDCF0000: C:\Windows\system32\WLDAP32 (0x52000 bytes). 2025-07-11 02:00:00,343 [root] DEBUG: 1180: DLL loaded at 0x688A0000: C:\Windows\system32\ncrypt (0x39000 bytes). 2025-07-11 02:00:00,343 [root] DEBUG: 1180: DLL loaded at 0x68860000: C:\Windows\SysWOW64\bcryptprimitives (0x3d000 bytes). 2025-07-11 02:00:00,907 [root] DEBUG: 1180: DLL loaded at 0x68840000: C:\Windows\system32\GPAPI (0x16000 bytes). 2025-07-11 02:00:01,024 [root] DEBUG: 1180: DLL loaded at 0x68770000: C:\Windows\system32\webservices (0xc2000 bytes). 2025-07-11 02:00:01,071 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma00546271.png0 size is 119666, Max size: 100000000 2025-07-11 02:00:01,102 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02786999.png0 size is 8127, Max size: 100000000 2025-07-11 02:00:01,133 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900771.png0 size is 10213, Max size: 100000000 2025-07-11 02:00:01,157 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382936.png0 size is 37573, Max size: 100000000 2025-07-11 02:00:01,188 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382941.png0 size is 96333, Max size: 100000000 2025-07-11 02:00:01,211 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02835058.png0 size is 186365, Max size: 100000000 2025-07-11 02:00:01,243 [root] DEBUG: 1180: DLL loaded at 0x68750000: C:\Windows\system32\cryptnet (0x1d000 bytes). 2025-07-11 02:00:01,243 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03978815.png0 size is 711398, Max size: 100000000 2025-07-11 02:00:01,243 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78018332.png0 size is 26105, Max size: 100000000 2025-07-11 02:00:01,258 [root] DEBUG: 1180: DLL loaded at 0x68740000: C:\Windows\system32\SensApi (0x6000 bytes). 2025-07-11 02:00:01,274 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392850.png0 size is 280509, Max size: 100000000 2025-07-11 02:00:01,274 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45325165.png0 size is 9149, Max size: 100000000 2025-07-11 02:00:01,290 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03982351.png0 size is 12860, Max size: 100000000 2025-07-11 02:00:01,336 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392877.png0 size is 86215, Max size: 100000000 2025-07-11 02:00:01,352 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16402488.png0 size is 114584, Max size: 100000000 2025-07-11 02:00:01,368 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16412178.png0 size is 283253, Max size: 100000000 2025-07-11 02:00:01,392 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma56348247.png0 size is 55049, Max size: 100000000 2025-07-11 02:00:01,416 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900720.png0 size is 22877, Max size: 100000000 2025-07-11 02:00:01,439 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma88924273.png0 size is 103770, Max size: 100000000 2025-07-11 02:00:01,470 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02836342.png0 size is 26220, Max size: 100000000 2025-07-11 02:00:01,494 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02892315.png0 size is 20776, Max size: 100000000 2025-07-11 02:00:01,517 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002124.png0 size is 11329, Max size: 100000000 2025-07-11 02:00:01,533 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78500733.png0 size is 10169, Max size: 100000000 2025-07-11 02:00:01,556 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900688.png0 size is 8561, Max size: 100000000 2025-07-11 02:00:01,587 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900722.png0 size is 19188, Max size: 100000000 2025-07-11 02:00:01,595 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900743.png0 size is 33070, Max size: 100000000 2025-07-11 02:00:01,619 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02923944.png0 size is 4886, Max size: 100000000 2025-07-11 02:00:01,650 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002117.png0 size is 4962, Max size: 100000000 2025-07-11 02:00:01,681 [root] DEBUG: 1180: api-cap: RegOpenKeyExW hook disabled due to count: 5000 2025-07-11 02:00:01,689 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt16402400.png0 size is 33856, Max size: 100000000 2025-07-11 02:00:01,712 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt22746018.png0 size is 18469, Max size: 100000000 2025-07-11 02:00:01,736 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45088960.png0 size is 40992, Max size: 100000000 2025-07-11 02:00:01,759 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45420242.png0 size is 13339, Max size: 100000000 2025-07-11 02:00:02,451 [root] DEBUG: 1180: DLL loaded at 0x68710000: C:\Windows\system32\POWRPROF (0x25000 bytes). 2025-07-11 02:00:04,683 [lib.common.results] INFO: File c:\olddocs\1752224399671.saz size is 6637, Max size: 100000000 2025-07-11 02:00:04,699 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:00:12,033 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:00:12,322 [lib.common.results] INFO: File 1752224412259765600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:00:12,330 [lib.common.results] INFO: File 1752224412259765600.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:00:12,330 [lib.common.results] INFO: File 1752224412259765600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:00:12,353 [lib.common.results] INFO: File 1752224412259765600.Application.evtx.gz size is 6708, Max size: 100000000 2025-07-11 02:00:12,369 [lib.common.results] INFO: File 1752224412322265600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:00:12,384 [lib.common.results] INFO: File 1752224412330078100.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:00:12,384 [lib.common.results] INFO: File 1752224412330078100.Security.evtx.gz size is 7531, Max size: 100000000 2025-07-11 02:00:12,392 [lib.common.results] INFO: File 1752224412330078100.System.evtx.gz size is 8498, Max size: 100000000 2025-07-11 02:00:12,423 [lib.common.results] INFO: File 1752224412369140600.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:00:14,097 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 02:00:19,224 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224419.2246094.sysmon.evtx.gz to host 2025-07-11 02:00:19,224 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 80106, Max size: 100000000 2025-07-11 02:00:24,798 [lib.common.results] INFO: File c:\olddocs\1752224419779.saz size is 11998, Max size: 100000000 2025-07-11 02:00:24,814 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:00:27,470 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:00:27,715 [lib.common.results] INFO: File 1752224427658203100.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:00:27,731 [lib.common.results] INFO: File 1752224427658203100.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:00:27,731 [lib.common.results] INFO: File 1752224427658203100.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:00:27,731 [lib.common.results] INFO: File 1752224427658203100.Application.evtx.gz size is 6708, Max size: 100000000 2025-07-11 02:00:27,770 [lib.common.results] INFO: File 1752224427723632800.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:00:27,778 [lib.common.results] INFO: File 1752224427715820300.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:00:27,778 [lib.common.results] INFO: File 1752224427715820300.Security.evtx.gz size is 7260, Max size: 100000000 2025-07-11 02:00:27,786 [lib.common.results] INFO: File 1752224427723632800.System.evtx.gz size is 8145, Max size: 100000000 2025-07-11 02:00:27,809 [lib.common.results] INFO: File 1752224427770507800.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:00:34,243 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 02:00:39,324 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224439.3242185.sysmon.evtx.gz to host 2025-07-11 02:00:39,324 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6444, Max size: 100000000 2025-07-11 02:00:42,855 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:00:43,113 [lib.common.results] INFO: File 1752224443042968700.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:00:43,113 [lib.common.results] INFO: File 1752224443050781200.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:00:43,113 [lib.common.results] INFO: File 1752224443042968700.Application.evtx.gz size is 6708, Max size: 100000000 2025-07-11 02:00:43,128 [lib.common.results] INFO: File 1752224443050781200.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:00:43,160 [lib.common.results] INFO: File 1752224443113281200.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:00:43,160 [lib.common.results] INFO: File 1752224443113281200.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:00:43,175 [lib.common.results] INFO: File 1752224443113281200.Security.evtx.gz size is 7126, Max size: 100000000 2025-07-11 02:00:43,191 [lib.common.results] INFO: File 1752224443128906200.System.evtx.gz size is 8153, Max size: 100000000 2025-07-11 02:00:43,207 [lib.common.results] INFO: File 1752224443160156200.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:00:44,904 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:00:54,344 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 02:00:58,238 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:00:58,446 [lib.common.results] INFO: File 1752224458407226500.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:00:58,461 [lib.common.results] INFO: File 1752224458422851500.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:00:58,469 [lib.common.results] INFO: File 1752224458407226500.Application.evtx.gz size is 6969, Max size: 100000000 2025-07-11 02:00:58,508 [lib.common.results] INFO: File 1752224458461914000.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:00:58,516 [lib.common.results] INFO: File 1752224458469726500.Security.evtx.gz size is 7315, Max size: 100000000 2025-07-11 02:00:58,532 [lib.common.results] INFO: File 1752224458446289000.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:00:58,532 [lib.common.results] INFO: File 1752224458477539000.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:00:58,547 [lib.common.results] INFO: File 1752224458516601500.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:00:58,571 [lib.common.results] INFO: File 1752224458508789000.System.evtx.gz size is 8173, Max size: 100000000 2025-07-11 02:00:59,431 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224459.4316406.sysmon.evtx.gz to host 2025-07-11 02:00:59,431 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6657, Max size: 100000000 2025-07-11 02:01:04,990 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:01:13,611 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:01:13,830 [lib.common.results] INFO: File 1752224473798828100.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:01:13,845 [lib.common.results] INFO: File 1752224473798828100.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:01:13,861 [lib.common.results] INFO: File 1752224473798828100.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:01:13,861 [lib.common.results] INFO: File 1752224473798828100.Application.evtx.gz size is 6908, Max size: 100000000 2025-07-11 02:01:13,900 [lib.common.results] INFO: File 1752224473830078100.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:01:13,916 [lib.common.results] INFO: File 1752224473861328100.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:01:13,924 [lib.common.results] INFO: File 1752224473845703100.Security.evtx.gz size is 7253, Max size: 100000000 2025-07-11 02:01:13,924 [lib.common.results] INFO: File 1752224473861328100.System.evtx.gz size is 8127, Max size: 100000000 2025-07-11 02:01:13,948 [lib.common.results] INFO: File 1752224473900390600.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:01:14,448 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 02:01:19,531 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224479.53125.sysmon.evtx.gz to host 2025-07-11 02:01:19,531 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5634, Max size: 100000000 2025-07-11 02:01:25,056 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:01:28,982 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:01:29,201 [lib.common.results] INFO: File 1752224489154296800.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:01:29,224 [lib.common.results] INFO: File 1752224489154296800.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:01:29,224 [lib.common.results] INFO: File 1752224489162109300.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:01:29,232 [lib.common.results] INFO: File 1752224489154296800.Application.evtx.gz size is 6908, Max size: 100000000 2025-07-11 02:01:29,248 [lib.common.results] INFO: File 1752224489201171800.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:01:29,255 [lib.common.results] INFO: File 1752224489208984300.Security.evtx.gz size is 7240, Max size: 100000000 2025-07-11 02:01:29,263 [lib.common.results] INFO: File 1752224489216796800.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:01:29,279 [lib.common.results] INFO: File 1752224489216796800.System.evtx.gz size is 8164, Max size: 100000000 2025-07-11 02:01:29,294 [lib.common.results] INFO: File 1752224489248046800.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:01:34,560 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 02:01:39,635 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224499.6357422.sysmon.evtx.gz to host 2025-07-11 02:01:39,635 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5770, Max size: 100000000 2025-07-11 02:01:44,310 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:01:44,539 [lib.common.results] INFO: File 1752224504492187500.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:01:44,554 [lib.common.results] INFO: File 1752224504492187500.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:01:44,570 [lib.common.results] INFO: File 1752224504492187500.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:01:44,570 [lib.common.results] INFO: File 1752224504492187500.Application.evtx.gz size is 6908, Max size: 100000000 2025-07-11 02:01:44,593 [lib.common.results] INFO: File 1752224504539062500.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:01:44,593 [lib.common.results] INFO: File 1752224504554687500.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:01:44,617 [lib.common.results] INFO: File 1752224504546875000.Security.evtx.gz size is 7306, Max size: 100000000 2025-07-11 02:01:44,632 [lib.common.results] INFO: File 1752224504554687500.System.evtx.gz size is 8158, Max size: 100000000 2025-07-11 02:01:44,632 [lib.common.results] INFO: File 1752224504585937500.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:01:45,148 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:01:54,656 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 02:01:59,674 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:01:59,706 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224519.7060547.sysmon.evtx.gz to host 2025-07-11 02:01:59,706 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5811, Max size: 100000000 2025-07-11 02:01:59,877 [lib.common.results] INFO: File 1752224519846679600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:01:59,909 [lib.common.results] INFO: File 1752224519846679600.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:01:59,909 [lib.common.results] INFO: File 1752224519831054600.Application.evtx.gz size is 6908, Max size: 100000000 2025-07-11 02:01:59,909 [lib.common.results] INFO: File 1752224519846679600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:01:59,924 [lib.common.results] INFO: File 1752224519877929600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:01:59,940 [lib.common.results] INFO: File 1752224519893554600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:01:59,956 [lib.common.results] INFO: File 1752224519877929600.Security.evtx.gz size is 7274, Max size: 100000000 2025-07-11 02:01:59,971 [lib.common.results] INFO: File 1752224519893554600.System.evtx.gz size is 8170, Max size: 100000000 2025-07-11 02:01:59,987 [lib.common.results] INFO: File 1752224519924804600.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:02:05,239 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:02:14,713 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 02:02:15,026 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:02:15,245 [lib.common.results] INFO: File 1752224535198242100.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:02:15,245 [lib.common.results] INFO: File 1752224535198242100.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:02:15,260 [lib.common.results] INFO: File 1752224535198242100.Application.evtx.gz size is 6908, Max size: 100000000 2025-07-11 02:02:15,276 [lib.common.results] INFO: File 1752224535213867100.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:02:15,291 [lib.common.results] INFO: File 1752224535245117100.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:02:15,307 [lib.common.results] INFO: File 1752224535245117100.Security.evtx.gz size is 7188, Max size: 100000000 2025-07-11 02:02:15,323 [lib.common.results] INFO: File 1752224535260742100.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:02:15,323 [lib.common.results] INFO: File 1752224535276367100.System.evtx.gz size is 8176, Max size: 100000000 2025-07-11 02:02:15,338 [lib.common.results] INFO: File 1752224535291992100.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:02:19,772 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224539.7724607.sysmon.evtx.gz to host 2025-07-11 02:02:19,772 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5677, Max size: 100000000 2025-07-11 02:02:25,328 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:02:25,781 [root] INFO: Analysis timeout hit, terminating analysis 2025-07-11 02:02:25,781 [lib.api.process] INFO: Terminate event set for process 1180 2025-07-11 02:02:25,781 [root] DEBUG: 1180: Terminate Event: Attempting to dump process 1180 2025-07-11 02:02:25,781 [root] DEBUG: 1180: VerifyCodeSection: Executable code does not match, 0x64c of 0x154f matching 2025-07-11 02:02:25,781 [root] DEBUG: 1180: DoProcessDump: Code modification detected, dumping Imagebase at 0x013E0000. 2025-07-11 02:02:25,781 [root] DEBUG: 1180: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2025-07-11 02:02:25,781 [root] DEBUG: 1180: DumpProcess: Instantiating PeParser with address: 0x013E0000. 2025-07-11 02:02:25,781 [root] DEBUG: 1180: DumpProcess: Module entry point VA is 0x000010D4. 2025-07-11 02:02:25,812 [lib.common.results] INFO: File C:\jXBlvUtF\CAPE\1180_32636252911572025 size is 1915904, Max size: 100000000 2025-07-11 02:02:25,843 [root] DEBUG: 1180: DumpProcess: Module image dump success - dump size 0x1d3c00. 2025-07-11 02:02:25,859 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10 2025-07-11 02:02:25,859 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\~$nvoice.docx 2025-07-11 02:02:25,875 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\Invoice.docx 2025-07-11 02:02:25,875 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Office\Word15.customUI 2025-07-11 02:02:25,875 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B29334E3-54D5-43A5-B2AA-340DDC8C96E5}.tmp 2025-07-11 02:02:25,875 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm 2025-07-11 02:02:25,875 [lib.api.process] INFO: Termination confirmed for process 1180 2025-07-11 02:02:25,875 [root] DEBUG: 1180: Terminate Event: monitor shutdown complete for process 1180 2025-07-11 02:02:25,875 [root] INFO: Terminate event set for process 1180 2025-07-11 02:02:25,875 [root] INFO: Created shutdown mutex 2025-07-11 02:02:26,875 [root] INFO: Shutting down package 2025-07-11 02:02:26,875 [root] INFO: Stopping auxiliary modules 2025-07-11 02:02:26,875 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2025-07-11 02:02:26,875 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2025-07-11 02:02:26,899 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:02:27,150 [lib.common.results] INFO: File 1752224547103515600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:02:27,150 [lib.common.results] INFO: File 1752224547103515600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:02:27,150 [lib.common.results] INFO: File 1752224547087890600.Application.evtx.gz size is 6908, Max size: 100000000 2025-07-11 02:02:27,166 [lib.common.results] INFO: File 1752224547119140600.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:02:27,181 [lib.common.results] INFO: File 1752224547150390600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:02:27,197 [lib.common.results] INFO: File 1752224547150390600.Security.evtx.gz size is 7230, Max size: 100000000 2025-07-11 02:02:27,197 [lib.common.results] INFO: File 1752224547150390600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:02:27,212 [lib.common.results] INFO: File 1752224547166015600.System.evtx.gz size is 8183, Max size: 100000000 2025-07-11 02:02:27,228 [lib.common.results] INFO: File 1752224547181640600.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:02:30,374 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-11 02:02:30,589 [lib.common.results] INFO: File 1752224550530273400.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-11 02:02:30,609 [lib.common.results] INFO: File 1752224550545898400.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-11 02:02:30,609 [lib.common.results] INFO: File 1752224550530273400.Application.evtx.gz size is 6908, Max size: 100000000 2025-07-11 02:02:30,625 [lib.common.results] INFO: File 1752224550582031200.KeyManagementService.evtx.gz size is 2783, Max size: 100000000 2025-07-11 02:02:30,632 [lib.common.results] INFO: File 1752224550588867100.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:02:30,640 [lib.common.results] INFO: File 1752224550592773400.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-11 02:02:30,648 [lib.common.results] INFO: File 1752224550592773400.Security.evtx.gz size is 7227, Max size: 100000000 2025-07-11 02:02:30,679 [lib.common.results] INFO: File 1752224550632812500.WindowsPowerShell.evtx.gz size is 222, Max size: 100000000 2025-07-11 02:02:30,695 [lib.common.results] INFO: File 1752224550625000000.System.evtx.gz size is 8188, Max size: 100000000 2025-07-11 02:02:32,351 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-11 02:02:32,351 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2025-07-11 02:02:34,789 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-11 02:02:37,445 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752224557.4453125.sysmon.evtx.gz to host 2025-07-11 02:02:37,445 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 11554, Max size: 100000000 2025-07-11 02:02:37,460 [root] INFO: Finishing auxiliary modules 2025-07-11 02:02:37,460 [root] INFO: Shutting down pipe server and dumping dropped files 2025-07-11 02:02:37,460 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10 size is 23382, Max size: 100000000 2025-07-11 02:02:37,476 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\~$nvoice.docx size is 162, Max size: 100000000 2025-07-11 02:02:37,492 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\Invoice.docx size is 12435, Max size: 100000000 2025-07-11 02:02:37,507 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\Word15.customUI size is 3514, Max size: 100000000 2025-07-11 02:02:37,523 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B29334E3-54D5-43A5-B2AA-340DDC8C96E5}.tmp size is 1024, Max size: 100000000 2025-07-11 02:02:37,539 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm size is 17789, Max size: 100000000 2025-07-11 02:02:37,539 [root] WARNING: Folder at path "C:\jXBlvUtF\debugger" does not exist, skipping 2025-07-11 02:02:37,539 [root] INFO: Uploading files at path "C:\jXBlvUtF\tlsdump" 2025-07-11 02:02:37,539 [lib.common.results] INFO: File C:\jXBlvUtF\tlsdump\tlsdump.log size is 1644, Max size: 100000000 2025-07-11 02:02:37,554 [root] INFO: Analysis completed
Name | Label | Manager | Started On | Shutdown On | Route |
---|---|---|---|---|---|
win7office2k3flash2800137TWN3H107 | win7office2k3flash2800137TWN3H107 | KVM | 2025-07-11 08:59:40 | 2025-07-11 09:02:48 | internet |
File Name | Invoice.docx |
---|---|
File Size | 12435 bytes |
File Type | Microsoft Word 2007+ |
MD5 | 4ea3c0cd625321583007fb2d3c677d6d |
SHA1 | adeb93bf624b1f058ce139b6368f760e43b06cc5 |
SHA256 | ac3916391bef2bf456c77a692662a182f9c5315270e4551bca2d89951af47cef |
SHA512 | 78b63c8d8355faa96b727c96146ac8612dd2f982c88aa9f0909976159ec9b26626de67c99585769b97b147bb082d4111c6357197835d9538be4face0a98e310c |
SHA3-384 | 24c62480c3b0c4dec3d584d93d42304d018fcae0843a9363211a60714299bdaa092012bc60a6f608ef259309d6841986 |
CRC32 | 3CC4904D |
TLSH | T14542AF3DF94DF461C065067DF81C26EFF56495C25217D8FD3489B69B81842CB434F946 |
Ssdeep | 192:CtAuGCK1vh6NxtpgoZ22NNb4CZ4vrs0VbYVa/mwMWbOFrFwjdZueCTfk:aAuG9J6Nxt/ZtNNAs0SVDW/dZEfk |
File
|
Direct | IP | Country Name |
---|---|---|
Y | 8.8.8.8 [VT] | United States |
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP