Category | Package | Started | Completed | Duration | Options | Log |
---|---|---|---|---|---|---|
FILE | bat | 2025-07-14 17:04:41 | 2025-07-14 17:07:46 | 185 seconds | Show Options | Show Log |
procdump=1
amsidump=1
2024-04-29 04:35:24,593 [root] INFO: Date set to: 20250714T10:04:41, timeout set to: 150 2025-07-14 10:04:41,015 [root] DEBUG: Starting analyzer from: C:\tmpkf7o2il2 2025-07-14 10:04:41,031 [root] DEBUG: Storing results at: C:\DYSXuawZG 2025-07-14 10:04:41,031 [root] DEBUG: Pipe server name: \\.\PIPE\jSGQlAxkwb 2025-07-14 10:04:41,031 [root] DEBUG: Python path: C:\olddocs 2025-07-14 10:04:41,031 [root] DEBUG: No analysis package specified, trying to detect it automagically 2025-07-14 10:04:41,031 [root] INFO: Automatically selected analysis package "bat" 2025-07-14 10:04:41,031 [root] DEBUG: Importing analysis package "bat"... 2025-07-14 10:04:41,031 [root] DEBUG: Initializing analysis package "bat"... 2025-07-14 10:04:41,031 [root] INFO: Analyzer: Package modules.packages.bat does not specify a DLL option 2025-07-14 10:04:41,031 [root] INFO: Analyzer: Package modules.packages.bat does not specify a DLL_64 option 2025-07-14 10:04:41,031 [root] INFO: Analyzer: Package modules.packages.bat does not specify a loader option 2025-07-14 10:04:41,031 [root] INFO: Analyzer: Package modules.packages.bat does not specify a loader_64 option 2025-07-14 10:04:41,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2025-07-14 10:04:41,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2025-07-14 10:04:41,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2025-07-14 10:04:41,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2025-07-14 10:04:41,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2025-07-14 10:04:41,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2025-07-14 10:04:41,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2025-07-14 10:04:41,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2025-07-14 10:04:41,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2025-07-14 10:04:41,109 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2025-07-14 10:04:41,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2025-07-14 10:04:41,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2025-07-14 10:04:41,171 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2025-07-14 10:04:41,187 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2025-07-14 10:04:41,187 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2025-07-14 10:04:41,187 [root] DEBUG: Initializing auxiliary module "Browser"... 2025-07-14 10:04:41,203 [root] DEBUG: Started auxiliary module Browser 2025-07-14 10:04:41,203 [root] DEBUG: Initializing auxiliary module "Curtain"... 2025-07-14 10:04:41,203 [root] DEBUG: Started auxiliary module Curtain 2025-07-14 10:04:41,203 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2025-07-14 10:04:41,234 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2025-07-14 10:04:41,234 [root] DEBUG: Started auxiliary module DefaultApps 2025-07-14 10:04:41,234 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2025-07-14 10:04:41,234 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2025-07-14 10:04:41,234 [modules.auxiliary.digisig] INFO: dummy 2025-07-14 10:04:41,234 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2025-07-14 10:04:41,234 [root] DEBUG: Started auxiliary module DigiSig 2025-07-14 10:04:41,234 [root] DEBUG: Initializing auxiliary module "Disguise"... 2025-07-14 10:04:41,593 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2025-07-14 10:04:41,593 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2025-07-14 10:04:41,593 [root] DEBUG: Initializing auxiliary module "Evtx"... 2025-07-14 10:04:41,593 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpkf7o2il2\bin\auditpol.csv 2025-07-14 10:04:41,890 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:04:42,515 [root] DEBUG: Started auxiliary module Evtx 2025-07-14 10:04:42,515 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2025-07-14 10:04:42,515 [modules.auxiliary.fiddler] INFO: fiddler package: dummy 2025-07-14 10:04:42,531 [root] DEBUG: Started auxiliary module Fiddler 2025-07-14 10:04:42,531 [root] DEBUG: Initializing auxiliary module "Human"... 2025-07-14 10:04:42,531 [root] DEBUG: Started auxiliary module Human 2025-07-14 10:04:42,531 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2025-07-14 10:04:42,531 [root] DEBUG: Started auxiliary module Screenshots 2025-07-14 10:04:42,531 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2025-07-14 10:04:42,531 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2025-07-14 10:04:42,531 [root] DEBUG: Started auxiliary module Sysmon 2025-07-14 10:04:42,531 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2025-07-14 10:04:42,531 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2025-07-14 10:04:42,531 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2025-07-14 10:04:42,546 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 556 2025-07-14 10:04:42,546 [lib.api.process] INFO: Monitor config for process 556: C:\tmpkf7o2il2\dll\556.ini 2025-07-14 10:04:44,640 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2025-07-14 10:04:45,546 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-14 10:04:45,546 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-14 10:04:45,546 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-14 10:04:45,546 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2025-07-14 10:04:45,546 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpkf7o2il2\dll\JZsJOXtk.dll, loader C:\tmpkf7o2il2\bin\ppYMpUsS.exe 2025-07-14 10:04:45,562 [root] DEBUG: Loader: Injecting process 556 with C:\tmpkf7o2il2\dll\JZsJOXtk.dll. 2025-07-14 10:04:45,593 [root] DEBUG: 556: Python path set to 'C:\olddocs'. 2025-07-14 10:04:45,593 [root] DEBUG: 556: Disabling sleep skipping. 2025-07-14 10:04:45,593 [root] DEBUG: 556: Process dumps enabled. 2025-07-14 10:04:45,593 [root] DEBUG: 556: AMSI dumping enabled. 2025-07-14 10:04:45,593 [root] DEBUG: 556: TLS secret dump mode enabled. 2025-07-14 10:04:45,609 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEEE180000, thread 2432, image base 0x00000000FF340000, stack from 0x00000000005C3000-0x00000000005D0000 2025-07-14 10:04:45,609 [root] DEBUG: 556: Commandline: C:\Windows\system32\lsass.exe 2025-07-14 10:04:45,609 [root] DEBUG: 556: Hooked 5 out of 5 functions 2025-07-14 10:04:45,609 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2025-07-14 10:04:45,625 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 556 2025-07-14 10:04:45,625 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2025-07-14 10:04:45,625 [root] DEBUG: Initializing auxiliary module "Usage"... 2025-07-14 10:04:45,625 [root] DEBUG: Started auxiliary module Usage 2025-07-14 10:04:48,249 [root] INFO: Restarting WMI Service 2025-07-14 10:04:52,312 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\pgabriel\AppData\Local\Temp\opencalc.bat"" with pid 1604 2025-07-14 10:04:52,328 [lib.api.process] INFO: Monitor config for process 1604: C:\tmpkf7o2il2\dll\1604.ini 2025-07-14 10:04:52,328 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-14 10:04:52,328 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-14 10:04:52,328 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-14 10:04:52,328 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpkf7o2il2\dll\GmaUQyD.dll, loader C:\tmpkf7o2il2\bin\oUMKrQE.exe 2025-07-14 10:04:52,359 [root] DEBUG: Loader: Injecting process 1604 (thread 2440) with C:\tmpkf7o2il2\dll\GmaUQyD.dll. 2025-07-14 10:04:52,359 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2025-07-14 10:04:52,359 [root] DEBUG: Successfully injected DLL C:\tmpkf7o2il2\dll\GmaUQyD.dll. 2025-07-14 10:04:52,359 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 1604 2025-07-14 10:04:54,359 [lib.api.process] INFO: Successfully resumed process with pid 1604 2025-07-14 10:04:54,406 [root] DEBUG: 1604: Python path set to 'C:\olddocs'. 2025-07-14 10:04:54,406 [root] DEBUG: 1604: Disabling sleep skipping. 2025-07-14 10:04:54,406 [root] DEBUG: 1604: Process dumps enabled. 2025-07-14 10:04:54,406 [root] DEBUG: 1604: AMSI dumping enabled. 2025-07-14 10:04:54,406 [root] DEBUG: 1604: Dropped file limit defaulting to 100. 2025-07-14 10:04:54,421 [root] DEBUG: 1604: YaraInit: Compiled 43 rule files 2025-07-14 10:04:54,421 [root] DEBUG: 1604: YaraInit: Compiled rules saved to file C:\tmpkf7o2il2\data\yara\capemon.yac 2025-07-14 10:04:54,421 [root] DEBUG: 1604: YaraScan: Scanning 0x4A890000, size 0x4bb2e 2025-07-14 10:04:54,437 [root] DEBUG: 1604: Monitor initialised: 32-bit capemon loaded in process 1604 at 0x74700000, thread 2440, image base 0x4a890000, stack from 0x243000-0x340000 2025-07-14 10:04:54,437 [root] DEBUG: 1604: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\pgabriel\AppData\Local\Temp\opencalc.bat" 2025-07-14 10:04:54,453 [root] WARNING: b'Unable to place hook on GetCommandLineA' 2025-07-14 10:04:54,453 [root] DEBUG: 1604: set_hooks: Unable to hook GetCommandLineA 2025-07-14 10:04:54,453 [root] WARNING: b'Unable to place hook on GetCommandLineW' 2025-07-14 10:04:54,453 [root] DEBUG: 1604: set_hooks: Unable to hook GetCommandLineW 2025-07-14 10:04:54,468 [root] DEBUG: 1604: Hooked 615 out of 617 functions 2025-07-14 10:04:54,468 [root] DEBUG: 1604: WoW64 detected: 64-bit ntdll base: 0x77ae0000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x77b4b5f0, Wow64PrepareForException: 0x0 2025-07-14 10:04:54,468 [root] DEBUG: 1604: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x150000 2025-07-14 10:04:54,484 [root] INFO: Loaded monitor into process with pid 1604 2025-07-14 10:04:54,484 [root] DEBUG: 1604: caller_dispatch: Added region at 0x4A890000 to tracked regions list (ntdll::NtOpenThread returns to 0x4A89732B, thread 2440). 2025-07-14 10:04:54,484 [root] DEBUG: 1604: YaraScan: Scanning 0x4A890000, size 0x4bb2e 2025-07-14 10:04:54,484 [root] DEBUG: 1604: ProcessImageBase: Main module image at 0x4A890000 unmodified (entropy change 0.000000e+00) 2025-07-14 10:04:54,500 [root] DEBUG: 1604: CreateProcessHandler: Injection info set for new process 3044: C:\Windows\system32\cmd.exe, ImageBase: 0x4A890000 2025-07-14 10:04:54,500 [root] INFO: Announced 32-bit process name: cmd.exe pid: 3044 2025-07-14 10:04:54,500 [lib.api.process] INFO: Monitor config for process 3044: C:\tmpkf7o2il2\dll\3044.ini 2025-07-14 10:04:54,500 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-14 10:04:54,500 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-14 10:04:54,500 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-14 10:04:54,500 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpkf7o2il2\dll\GmaUQyD.dll, loader C:\tmpkf7o2il2\bin\oUMKrQE.exe 2025-07-14 10:04:54,515 [root] DEBUG: Loader: Injecting process 3044 (thread 2020) with C:\tmpkf7o2il2\dll\GmaUQyD.dll. 2025-07-14 10:04:54,515 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2025-07-14 10:04:54,515 [root] DEBUG: Successfully injected DLL C:\tmpkf7o2il2\dll\GmaUQyD.dll. 2025-07-14 10:04:54,515 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 3044 2025-07-14 10:04:54,515 [root] DEBUG: 1604: DLL loaded at 0x72EA0000: C:\Windows\system32\apphelp (0x4c000 bytes). 2025-07-14 10:04:54,531 [root] WARNING: Received request to inject process with pid 3044, skipped alredy in inject list 2025-07-14 10:04:54,562 [root] DEBUG: 3044: Python path set to 'C:\olddocs'. 2025-07-14 10:04:54,562 [root] DEBUG: 3044: Disabling sleep skipping. 2025-07-14 10:04:54,562 [root] DEBUG: 3044: Process dumps enabled. 2025-07-14 10:04:54,562 [root] DEBUG: 3044: AMSI dumping enabled. 2025-07-14 10:04:54,562 [root] DEBUG: 3044: Dropped file limit defaulting to 100. 2025-07-14 10:04:54,578 [root] DEBUG: 3044: YaraInit: Compiled rules loaded from existing file C:\tmpkf7o2il2\data\yara\capemon.yac 2025-07-14 10:04:54,578 [root] DEBUG: 3044: YaraScan: Scanning 0x4A890000, size 0x4bb2e 2025-07-14 10:04:54,578 [root] DEBUG: 3044: Monitor initialised: 32-bit capemon loaded in process 3044 at 0x74700000, thread 2020, image base 0x4a890000, stack from 0x123000-0x220000 2025-07-14 10:04:54,578 [root] DEBUG: 3044: Commandline: C:\Windows\system32\cmd.exe /K "C:\Users\pgabriel\AppData\Local\Temp\opencalc.bat" 2025-07-14 10:04:54,593 [root] WARNING: b'Unable to place hook on GetCommandLineA' 2025-07-14 10:04:54,593 [root] DEBUG: 3044: set_hooks: Unable to hook GetCommandLineA 2025-07-14 10:04:54,593 [root] WARNING: b'Unable to place hook on GetCommandLineW' 2025-07-14 10:04:54,593 [root] DEBUG: 3044: set_hooks: Unable to hook GetCommandLineW 2025-07-14 10:04:54,609 [root] DEBUG: 3044: Hooked 615 out of 617 functions 2025-07-14 10:04:54,609 [root] DEBUG: 3044: WoW64 detected: 64-bit ntdll base: 0x77ae0000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x77b4b5f0, Wow64PrepareForException: 0x0 2025-07-14 10:04:54,609 [root] DEBUG: 3044: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x220000 2025-07-14 10:04:54,609 [root] INFO: Loaded monitor into process with pid 3044 2025-07-14 10:04:54,609 [root] DEBUG: 3044: caller_dispatch: Added region at 0x4A890000 to tracked regions list (ntdll::NtOpenThread returns to 0x4A89732B, thread 2020). 2025-07-14 10:04:54,609 [root] DEBUG: 3044: YaraScan: Scanning 0x4A890000, size 0x4bb2e 2025-07-14 10:04:54,625 [root] DEBUG: 3044: ProcessImageBase: Main module image at 0x4A890000 unmodified (entropy change 0.000000e+00) 2025-07-14 10:04:54,656 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:04:54,671 [root] DEBUG: 3044: CreateProcessHandler: Injection info set for new process 2872: C:\Windows\system32\calc.exe, ImageBase: 0x00420000 2025-07-14 10:04:54,671 [root] INFO: Announced 32-bit process name: calc.exe pid: 2872 2025-07-14 10:04:54,671 [lib.api.process] INFO: Monitor config for process 2872: C:\tmpkf7o2il2\dll\2872.ini 2025-07-14 10:04:54,671 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-14 10:04:54,671 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-14 10:04:54,671 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-14 10:04:54,671 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpkf7o2il2\dll\GmaUQyD.dll, loader C:\tmpkf7o2il2\bin\oUMKrQE.exe 2025-07-14 10:04:54,687 [root] DEBUG: Loader: Injecting process 2872 (thread 868) with C:\tmpkf7o2il2\dll\GmaUQyD.dll. 2025-07-14 10:04:54,687 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2025-07-14 10:04:54,687 [root] DEBUG: Successfully injected DLL C:\tmpkf7o2il2\dll\GmaUQyD.dll. 2025-07-14 10:04:54,687 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2872 2025-07-14 10:04:54,687 [root] DEBUG: 3044: DLL loaded at 0x72EA0000: C:\Windows\system32\apphelp (0x4c000 bytes). 2025-07-14 10:04:54,703 [root] WARNING: Received request to inject process with pid 2872, skipped alredy in inject list 2025-07-14 10:04:54,718 [root] DEBUG: 2872: Python path set to 'C:\olddocs'. 2025-07-14 10:04:54,718 [root] DEBUG: 2872: Process dumps enabled. 2025-07-14 10:04:54,718 [root] DEBUG: 2872: AMSI dumping enabled. 2025-07-14 10:04:54,718 [root] DEBUG: 2872: Dropped file limit defaulting to 100. 2025-07-14 10:04:54,718 [root] DEBUG: 2872: Disabling sleep skipping. 2025-07-14 10:04:54,718 [root] DEBUG: 2872: YaraInit: Compiled rules loaded from existing file C:\tmpkf7o2il2\data\yara\capemon.yac 2025-07-14 10:04:54,718 [root] DEBUG: 2872: YaraScan: Scanning 0x00420000, size 0xbfb3a 2025-07-14 10:04:54,734 [root] DEBUG: 2872: Monitor initialised: 32-bit capemon loaded in process 2872 at 0x74700000, thread 868, image base 0x420000, stack from 0x156000-0x160000 2025-07-14 10:04:54,734 [root] DEBUG: 2872: Commandline: calc.exe 2025-07-14 10:04:54,765 [root] WARNING: b'Unable to place hook on GetCommandLineA' 2025-07-14 10:04:54,765 [root] DEBUG: 2872: set_hooks: Unable to hook GetCommandLineA 2025-07-14 10:04:54,765 [root] WARNING: b'Unable to place hook on GetCommandLineW' 2025-07-14 10:04:54,765 [root] DEBUG: 2872: set_hooks: Unable to hook GetCommandLineW 2025-07-14 10:04:54,765 [root] DEBUG: 2872: Hooked 615 out of 617 functions 2025-07-14 10:04:54,765 [root] DEBUG: 2872: WoW64 detected: 64-bit ntdll base: 0x77ae0000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x77b4b5f0, Wow64PrepareForException: 0x0 2025-07-14 10:04:54,765 [root] DEBUG: 2872: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x360000 2025-07-14 10:04:54,781 [root] INFO: Loaded monitor into process with pid 2872 2025-07-14 10:04:54,781 [root] DEBUG: 2872: caller_dispatch: Added region at 0x00420000 to tracked regions list (ntdll::NtOpenKey returns to 0x00433433, thread 868). 2025-07-14 10:04:54,781 [root] DEBUG: 2872: YaraScan: Scanning 0x00420000, size 0xbfb3a 2025-07-14 10:04:54,781 [root] DEBUG: 2872: ProcessImageBase: Main module image at 0x00420000 unmodified (entropy change 0.000000e+00) 2025-07-14 10:04:54,781 [root] DEBUG: 2872: DLL loaded at 0x74440000: C:\Windows\SysWOW64\WindowsCodecs (0x130000 bytes). 2025-07-14 10:04:54,812 [root] DEBUG: 2872: DLL loaded at 0x74A90000: C:\Windows\SysWOW64\dwmapi (0x13000 bytes). 2025-07-14 10:04:54,843 [root] DEBUG: 2872: DLL loaded at 0x76830000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes). 2025-07-14 10:04:55,025 [root] DEBUG: 2872: DLL loaded at 0x74A50000: C:\Windows\SysWOW64\oleacc (0x3c000 bytes). 2025-07-14 10:04:57,525 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:04:57,869 [lib.common.results] INFO: File 1752512697791015600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:04:57,884 [lib.common.results] INFO: File 1752512697791015600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:04:57,900 [lib.common.results] INFO: File 1752512697791015600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:04:57,900 [lib.common.results] INFO: File 1752512697791015600.Application.evtx.gz size is 6799, Max size: 100000000 2025-07-14 10:04:57,994 [lib.common.results] INFO: File 1752512697869140600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:04:57,994 [lib.common.results] INFO: File 1752512697869140600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:04:58,009 [lib.common.results] INFO: File 1752512697869140600.System.evtx.gz size is 8843, Max size: 100000000 2025-07-14 10:04:58,009 [lib.common.results] INFO: File 1752512697869140600.Security.evtx.gz size is 16353, Max size: 100000000 2025-07-14 10:04:58,041 [lib.common.results] INFO: File 1752512697994140600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:04:59,712 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512699.7128906.sysmon.evtx.gz to host 2025-07-14 10:04:59,728 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 8460, Max size: 100000000 2025-07-14 10:05:05,650 [lib.common.results] INFO: File c:\olddocs\1752512700650.saz size is 4596, Max size: 100000000 2025-07-14 10:05:05,666 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:05:13,072 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:05:13,337 [lib.common.results] INFO: File 1752512713275390600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:05:13,337 [lib.common.results] INFO: File 1752512713275390600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:05:13,337 [lib.common.results] INFO: File 1752512713275390600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:05:13,353 [lib.common.results] INFO: File 1752512713275390600.Application.evtx.gz size is 6723, Max size: 100000000 2025-07-14 10:05:13,400 [lib.common.results] INFO: File 1752512713337890600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:05:13,416 [lib.common.results] INFO: File 1752512713337890600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:05:13,431 [lib.common.results] INFO: File 1752512713337890600.Security.evtx.gz size is 7909, Max size: 100000000 2025-07-14 10:05:13,447 [lib.common.results] INFO: File 1752512713353515600.System.evtx.gz size is 8315, Max size: 100000000 2025-07-14 10:05:13,462 [lib.common.results] INFO: File 1752512713400390600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:05:14,744 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:05:19,837 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512719.8378906.sysmon.evtx.gz to host 2025-07-14 10:05:19,853 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 17873, Max size: 100000000 2025-07-14 10:05:25,759 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:05:28,494 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:05:28,728 [lib.common.results] INFO: File 1752512728681640600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:05:28,744 [lib.common.results] INFO: File 1752512728681640600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:05:28,744 [lib.common.results] INFO: File 1752512728681640600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:05:28,744 [lib.common.results] INFO: File 1752512728681640600.Application.evtx.gz size is 6723, Max size: 100000000 2025-07-14 10:05:28,759 [lib.common.results] INFO: File 1752512728712890600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:05:28,775 [lib.common.results] INFO: File 1752512728712890600.Security.evtx.gz size is 7364, Max size: 100000000 2025-07-14 10:05:28,791 [lib.common.results] INFO: File 1752512728712890600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:05:28,806 [lib.common.results] INFO: File 1752512728728515600.System.evtx.gz size is 8253, Max size: 100000000 2025-07-14 10:05:28,822 [lib.common.results] INFO: File 1752512728759765600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:05:34,869 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:05:39,947 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512739.9472656.sysmon.evtx.gz to host 2025-07-14 10:05:39,947 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5658, Max size: 100000000 2025-07-14 10:05:43,853 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:05:44,087 [lib.common.results] INFO: File 1752512744041015600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:05:44,103 [lib.common.results] INFO: File 1752512744041015600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:05:44,103 [lib.common.results] INFO: File 1752512744041015600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:05:44,103 [lib.common.results] INFO: File 1752512744041015600.Application.evtx.gz size is 6723, Max size: 100000000 2025-07-14 10:05:44,150 [lib.common.results] INFO: File 1752512744087890600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:05:44,150 [lib.common.results] INFO: File 1752512744103515600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:05:44,166 [lib.common.results] INFO: File 1752512744103515600.Security.evtx.gz size is 7128, Max size: 100000000 2025-07-14 10:05:44,166 [lib.common.results] INFO: File 1752512744103515600.System.evtx.gz size is 8260, Max size: 100000000 2025-07-14 10:05:44,181 [lib.common.results] INFO: File 1752512744150390600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:05:45,837 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:05:54,962 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:05:59,212 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:05:59,416 [lib.common.results] INFO: File 1752512759384765600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:05:59,431 [lib.common.results] INFO: File 1752512759369140600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:05:59,431 [lib.common.results] INFO: File 1752512759369140600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:05:59,431 [lib.common.results] INFO: File 1752512759369140600.Application.evtx.gz size is 7010, Max size: 100000000 2025-07-14 10:05:59,462 [lib.common.results] INFO: File 1752512759416015600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:05:59,478 [lib.common.results] INFO: File 1752512759431640600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:05:59,478 [lib.common.results] INFO: File 1752512759431640600.Security.evtx.gz size is 7270, Max size: 100000000 2025-07-14 10:05:59,478 [lib.common.results] INFO: File 1752512759431640600.System.evtx.gz size is 8267, Max size: 100000000 2025-07-14 10:05:59,494 [lib.common.results] INFO: File 1752512759462890600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:06:00,041 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512760.0410156.sysmon.evtx.gz to host 2025-07-14 10:06:00,041 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5689, Max size: 100000000 2025-07-14 10:06:05,916 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:06:14,541 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:06:14,759 [lib.common.results] INFO: File 1752512774712890600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:06:14,791 [lib.common.results] INFO: File 1752512774712890600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:06:14,791 [lib.common.results] INFO: File 1752512774712890600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:06:14,791 [lib.common.results] INFO: File 1752512774712890600.Application.evtx.gz size is 6946, Max size: 100000000 2025-07-14 10:06:14,822 [lib.common.results] INFO: File 1752512774759765600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:06:14,837 [lib.common.results] INFO: File 1752512774775390600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:06:14,853 [lib.common.results] INFO: File 1752512774775390600.Security.evtx.gz size is 7100, Max size: 100000000 2025-07-14 10:06:14,869 [lib.common.results] INFO: File 1752512774775390600.System.evtx.gz size is 8253, Max size: 100000000 2025-07-14 10:06:14,884 [lib.common.results] INFO: File 1752512774822265600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:06:15,056 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:06:20,134 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512780.1347656.sysmon.evtx.gz to host 2025-07-14 10:06:20,134 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5595, Max size: 100000000 2025-07-14 10:06:25,994 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:06:29,916 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:06:30,197 [lib.common.results] INFO: File 1752512790150390600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:06:30,212 [lib.common.results] INFO: File 1752512790150390600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:06:30,228 [lib.common.results] INFO: File 1752512790150390600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:06:30,228 [lib.common.results] INFO: File 1752512790150390600.Application.evtx.gz size is 6946, Max size: 100000000 2025-07-14 10:06:30,244 [lib.common.results] INFO: File 1752512790197265600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:06:30,275 [lib.common.results] INFO: File 1752512790212890600.Security.evtx.gz size is 7104, Max size: 100000000 2025-07-14 10:06:30,275 [lib.common.results] INFO: File 1752512790228515600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:06:30,306 [lib.common.results] INFO: File 1752512790244140600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:06:30,322 [lib.common.results] INFO: File 1752512790228515600.System.evtx.gz size is 8271, Max size: 100000000 2025-07-14 10:06:35,150 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:06:40,212 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512800.2128906.sysmon.evtx.gz to host 2025-07-14 10:06:40,212 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5526, Max size: 100000000 2025-07-14 10:06:45,369 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:06:45,572 [lib.common.results] INFO: File 1752512805525390600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:06:45,572 [lib.common.results] INFO: File 1752512805525390600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:06:45,587 [lib.common.results] INFO: File 1752512805525390600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:06:45,587 [lib.common.results] INFO: File 1752512805525390600.Application.evtx.gz size is 6946, Max size: 100000000 2025-07-14 10:06:45,634 [lib.common.results] INFO: File 1752512805572265600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:06:45,650 [lib.common.results] INFO: File 1752512805572265600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:06:45,650 [lib.common.results] INFO: File 1752512805572265600.Security.evtx.gz size is 7258, Max size: 100000000 2025-07-14 10:06:45,666 [lib.common.results] INFO: File 1752512805587890600.System.evtx.gz size is 8268, Max size: 100000000 2025-07-14 10:06:45,681 [lib.common.results] INFO: File 1752512805634765600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:06:46,072 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:06:55,228 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:07:00,306 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512820.3066406.sysmon.evtx.gz to host 2025-07-14 10:07:00,306 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5881, Max size: 100000000 2025-07-14 10:07:00,712 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:07:00,916 [lib.common.results] INFO: File 1752512820869140600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:07:00,916 [lib.common.results] INFO: File 1752512820869140600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:07:00,916 [lib.common.results] INFO: File 1752512820869140600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:07:00,931 [lib.common.results] INFO: File 1752512820869140600.Application.evtx.gz size is 6946, Max size: 100000000 2025-07-14 10:07:00,962 [lib.common.results] INFO: File 1752512820916015600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:07:00,978 [lib.common.results] INFO: File 1752512820916015600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:07:00,978 [lib.common.results] INFO: File 1752512820916015600.Security.evtx.gz size is 7164, Max size: 100000000 2025-07-14 10:07:00,978 [lib.common.results] INFO: File 1752512820931640600.System.evtx.gz size is 8260, Max size: 100000000 2025-07-14 10:07:00,994 [lib.common.results] INFO: File 1752512820962890600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:07:06,134 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:07:15,322 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:07:16,025 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:07:16,228 [lib.common.results] INFO: File 1752512836181640600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:07:16,244 [lib.common.results] INFO: File 1752512836181640600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:07:16,244 [lib.common.results] INFO: File 1752512836181640600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:07:16,259 [lib.common.results] INFO: File 1752512836181640600.Application.evtx.gz size is 6946, Max size: 100000000 2025-07-14 10:07:16,306 [lib.common.results] INFO: File 1752512836228515600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:07:16,306 [lib.common.results] INFO: File 1752512836244140600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:07:16,306 [lib.common.results] INFO: File 1752512836244140600.Security.evtx.gz size is 7204, Max size: 100000000 2025-07-14 10:07:16,306 [lib.common.results] INFO: File 1752512836244140600.System.evtx.gz size is 8263, Max size: 100000000 2025-07-14 10:07:16,337 [lib.common.results] INFO: File 1752512836306640600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:07:20,384 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512840.3847656.sysmon.evtx.gz to host 2025-07-14 10:07:20,384 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5685, Max size: 100000000 2025-07-14 10:07:24,384 [root] INFO: Analysis timeout hit, terminating analysis 2025-07-14 10:07:24,384 [lib.api.process] INFO: Terminate event set for process 1604 2025-07-14 10:07:24,384 [root] DEBUG: 1604: Terminate Event: Attempting to dump process 1604 2025-07-14 10:07:24,384 [root] DEBUG: 1604: DoProcessDump: Skipping process dump as code is identical on disk. 2025-07-14 10:07:24,400 [lib.api.process] INFO: Termination confirmed for process 1604 2025-07-14 10:07:24,400 [root] INFO: Terminate event set for process 1604 2025-07-14 10:07:24,400 [root] DEBUG: 1604: Terminate Event: monitor shutdown complete for process 1604 2025-07-14 10:07:24,400 [lib.api.process] INFO: Terminate event set for process 3044 2025-07-14 10:07:24,400 [root] DEBUG: 3044: Terminate Event: Attempting to dump process 3044 2025-07-14 10:07:24,400 [root] DEBUG: 3044: DoProcessDump: Skipping process dump as code is identical on disk. 2025-07-14 10:07:24,400 [lib.api.process] INFO: Termination confirmed for process 3044 2025-07-14 10:07:24,400 [root] INFO: Terminate event set for process 3044 2025-07-14 10:07:24,400 [root] DEBUG: 3044: Terminate Event: monitor shutdown complete for process 3044 2025-07-14 10:07:24,400 [lib.api.process] INFO: Terminate event set for process 2872 2025-07-14 10:07:24,400 [root] DEBUG: 2872: Terminate Event: Attempting to dump process 2872 2025-07-14 10:07:24,416 [root] DEBUG: 2872: DoProcessDump: Skipping process dump as code is identical on disk. 2025-07-14 10:07:24,416 [lib.api.process] INFO: Termination confirmed for process 2872 2025-07-14 10:07:24,416 [root] INFO: Terminate event set for process 2872 2025-07-14 10:07:24,416 [root] DEBUG: 2872: Terminate Event: monitor shutdown complete for process 2872 2025-07-14 10:07:24,416 [root] INFO: Created shutdown mutex 2025-07-14 10:07:25,416 [root] INFO: Shutting down package 2025-07-14 10:07:25,416 [root] INFO: Stopping auxiliary modules 2025-07-14 10:07:25,416 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2025-07-14 10:07:25,416 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2025-07-14 10:07:25,431 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:07:25,650 [lib.common.results] INFO: File 1752512845603515600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:07:25,650 [lib.common.results] INFO: File 1752512845603515600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:07:25,650 [lib.common.results] INFO: File 1752512845603515600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:07:25,650 [lib.common.results] INFO: File 1752512845603515600.Application.evtx.gz size is 6946, Max size: 100000000 2025-07-14 10:07:25,697 [lib.common.results] INFO: File 1752512845650390600.Security.evtx.gz size is 7195, Max size: 100000000 2025-07-14 10:07:25,712 [lib.common.results] INFO: File 1752512845634765600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:07:25,712 [lib.common.results] INFO: File 1752512845650390600.System.evtx.gz size is 8236, Max size: 100000000 2025-07-14 10:07:25,728 [lib.common.results] INFO: File 1752512845650390600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:07:25,728 [lib.common.results] INFO: File 1752512845697265600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:07:26,212 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:07:30,822 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 10:07:30,822 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2025-07-14 10:07:31,369 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 10:07:31,587 [lib.common.results] INFO: File 1752512851541015600.HardwareEvents.evtx.gz size is 355, Max size: 100000000 2025-07-14 10:07:31,587 [lib.common.results] INFO: File 1752512851541015600.KeyManagementService.evtx.gz size is 227, Max size: 100000000 2025-07-14 10:07:31,587 [lib.common.results] INFO: File 1752512851541015600.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 10:07:31,603 [lib.common.results] INFO: File 1752512851541015600.Application.evtx.gz size is 6946, Max size: 100000000 2025-07-14 10:07:31,634 [lib.common.results] INFO: File 1752512851587890600.OAlerts.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:07:31,634 [lib.common.results] INFO: File 1752512851587890600.Setup.evtx.gz size is 241, Max size: 100000000 2025-07-14 10:07:31,650 [lib.common.results] INFO: File 1752512851587890600.Security.evtx.gz size is 7215, Max size: 100000000 2025-07-14 10:07:31,666 [lib.common.results] INFO: File 1752512851603515600.System.evtx.gz size is 8261, Max size: 100000000 2025-07-14 10:07:31,681 [lib.common.results] INFO: File 1752512851634765600.WindowsPowerShell.evtx.gz size is 256, Max size: 100000000 2025-07-14 10:07:35,400 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 10:07:35,900 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752512855.9003906.sysmon.evtx.gz to host 2025-07-14 10:07:35,900 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5171, Max size: 100000000 2025-07-14 10:07:35,916 [root] INFO: Finishing auxiliary modules 2025-07-14 10:07:35,916 [root] INFO: Shutting down pipe server and dumping dropped files 2025-07-14 10:07:35,916 [root] WARNING: Folder at path "C:\DYSXuawZG\debugger" does not exist, skipping 2025-07-14 10:07:35,916 [root] WARNING: Folder at path "C:\DYSXuawZG\tlsdump" does not exist, skipping 2025-07-14 10:07:35,916 [root] INFO: Analysis completed
Name | Label | Manager | Started On | Shutdown On | Route |
---|---|---|---|---|---|
win7office2k3flash2800137TWN3H107 | win7office2k3flash2800137TWN3H107 | KVM | 2025-07-14 17:04:41 | 2025-07-14 17:07:46 | internet |
File Name | opencalc.bat |
---|---|
File Size | 9 bytes |
File Type | ASCII text |
MD5 | c61463921d79e07e461fd0e731f72619 |
SHA1 | 4c70ac1680d2c4bdb145d5be5dad5230b20805f2 |
SHA256 | 7fdf626e0603f5bc2375a7bbc92c94a21088841c0a03cf3c5f12aa9c680ce4e6 |
SHA512 | 1a0ada808250064beaafad6095f6d12b0a26ddeb0aff616205986dc4db7c4e72686701945bfb948a141a5f6db0d0e6cec29cd2fddc59ba07a9279a93a7e3541e |
SHA3-384 | b61a7654e9f55c8d3f21ad0e18325fb9d987f7baece23caa7b5803b1ed18cc0603d1cc5a57f344355e3e08a0950fcd36 |
CRC32 | 8D648BCF |
Ssdeep | 3:FGLAdK:FbK |
File
|
|
calc.exe |
|
Direct | IP | Country Name |
---|---|---|
Y | 8.8.8.8 [VT] | United States |
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP