Category | Package | Started | Completed | Duration | Options | Log |
---|---|---|---|---|---|---|
FILE | doc | 2025-07-14 20:03:29 | 2025-07-14 20:06:39 | 190 seconds | Show Options | Show Log |
procdump=1
amsidump=1
2024-04-29 04:32:59,093 [root] INFO: Date set to: 20250714T13:03:29, timeout set to: 150 2025-07-14 13:03:29,015 [root] DEBUG: Starting analyzer from: C:\tmpd65zellw 2025-07-14 13:03:29,015 [root] DEBUG: Storing results at: C:\ivhVKM 2025-07-14 13:03:29,015 [root] DEBUG: Pipe server name: \\.\PIPE\ANDvXiZE 2025-07-14 13:03:29,015 [root] DEBUG: Python path: C:\olddocs 2025-07-14 13:03:29,015 [root] INFO: Analysis package "doc" has been specified 2025-07-14 13:03:29,015 [root] DEBUG: Importing analysis package "doc"... 2025-07-14 13:03:29,031 [root] DEBUG: Initializing analysis package "doc"... 2025-07-14 13:03:29,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL option 2025-07-14 13:03:29,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL_64 option 2025-07-14 13:03:29,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader option 2025-07-14 13:03:29,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader_64 option 2025-07-14 13:03:29,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2025-07-14 13:03:29,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2025-07-14 13:03:29,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2025-07-14 13:03:29,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2025-07-14 13:03:29,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2025-07-14 13:03:29,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2025-07-14 13:03:29,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2025-07-14 13:03:29,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2025-07-14 13:03:29,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2025-07-14 13:03:29,109 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2025-07-14 13:03:29,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2025-07-14 13:03:29,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2025-07-14 13:03:29,171 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2025-07-14 13:03:29,171 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2025-07-14 13:03:29,171 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2025-07-14 13:03:29,171 [root] DEBUG: Initializing auxiliary module "Browser"... 2025-07-14 13:03:29,171 [root] DEBUG: Started auxiliary module Browser 2025-07-14 13:03:29,171 [root] DEBUG: Initializing auxiliary module "Curtain"... 2025-07-14 13:03:29,187 [root] DEBUG: Started auxiliary module Curtain 2025-07-14 13:03:29,187 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2025-07-14 13:03:29,234 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2025-07-14 13:03:29,234 [root] DEBUG: Started auxiliary module DefaultApps 2025-07-14 13:03:29,234 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2025-07-14 13:03:29,234 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2025-07-14 13:03:29,234 [modules.auxiliary.digisig] INFO: doc 2025-07-14 13:03:29,234 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2025-07-14 13:03:29,234 [root] DEBUG: Started auxiliary module DigiSig 2025-07-14 13:03:29,234 [root] DEBUG: Initializing auxiliary module "Disguise"... 2025-07-14 13:03:29,468 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2025-07-14 13:03:29,468 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2025-07-14 13:03:29,468 [root] DEBUG: Initializing auxiliary module "Evtx"... 2025-07-14 13:03:29,468 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpd65zellw\bin\auditpol.csv 2025-07-14 13:03:29,890 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:03:30,437 [root] DEBUG: Started auxiliary module Evtx 2025-07-14 13:03:30,437 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2025-07-14 13:03:30,437 [modules.auxiliary.fiddler] INFO: fiddler package: doc 2025-07-14 13:03:30,453 [root] DEBUG: Started auxiliary module Fiddler 2025-07-14 13:03:30,453 [root] DEBUG: Initializing auxiliary module "Human"... 2025-07-14 13:03:30,453 [root] DEBUG: Started auxiliary module Human 2025-07-14 13:03:30,453 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2025-07-14 13:03:30,453 [root] DEBUG: Started auxiliary module Screenshots 2025-07-14 13:03:30,453 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2025-07-14 13:03:30,453 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2025-07-14 13:03:30,453 [root] DEBUG: Started auxiliary module Sysmon 2025-07-14 13:03:30,453 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2025-07-14 13:03:30,453 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 556 2025-07-14 13:03:30,453 [lib.api.process] INFO: Monitor config for process 556: C:\tmpd65zellw\dll\556.ini 2025-07-14 13:03:30,453 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2025-07-14 13:03:30,453 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2025-07-14 13:03:32,531 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2025-07-14 13:03:33,468 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-14 13:03:33,468 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-14 13:03:33,468 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-14 13:03:33,468 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2025-07-14 13:03:33,468 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2025-07-14 13:03:33,468 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2025-07-14 13:03:33,468 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2025-07-14 13:03:33,468 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpd65zellw\dll\rkOPCQAn.dll, loader C:\tmpd65zellw\bin\DdEOhkus.exe 2025-07-14 13:03:33,484 [root] DEBUG: Loader: IAT patching disabled. 2025-07-14 13:03:33,500 [root] DEBUG: Loader: Injecting process 556 with C:\tmpd65zellw\dll\rkOPCQAn.dll. 2025-07-14 13:03:33,531 [root] DEBUG: 556: Python path set to 'C:\olddocs'. 2025-07-14 13:03:33,531 [root] DEBUG: 556: Disabling sleep skipping. 2025-07-14 13:03:33,531 [root] DEBUG: 556: Process dumps enabled. 2025-07-14 13:03:33,546 [root] DEBUG: 556: AMSI dumping enabled. 2025-07-14 13:03:33,546 [root] DEBUG: 556: Monitor config - unrecognised key office. 2025-07-14 13:03:33,546 [root] DEBUG: 556: In-monitor YARA scans disabled. 2025-07-14 13:03:33,546 [root] DEBUG: 556: TLS secret dump mode enabled. 2025-07-14 13:03:33,546 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEED310000, thread 2628, image base 0x00000000FFF80000, stack from 0x0000000001A32000-0x0000000001A40000 2025-07-14 13:03:33,546 [root] DEBUG: 556: Commandline: C:\Windows\system32\lsass.exe 2025-07-14 13:03:33,562 [root] DEBUG: 556: Hooked 5 out of 5 functions 2025-07-14 13:03:33,562 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2025-07-14 13:03:33,562 [root] DEBUG: Successfully injected DLL C:\tmpd65zellw\dll\rkOPCQAn.dll. 2025-07-14 13:03:33,562 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 556 2025-07-14 13:03:33,562 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2025-07-14 13:03:33,562 [root] DEBUG: Initializing auxiliary module "Usage"... 2025-07-14 13:03:33,562 [root] DEBUG: Started auxiliary module Usage 2025-07-14 13:03:36,218 [root] INFO: Restarting WMI Service 2025-07-14 13:03:42,531 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:03:45,328 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" with arguments ""C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx" /q" with pid 2596 2025-07-14 13:03:45,328 [lib.api.process] INFO: Monitor config for process 2596: C:\tmpd65zellw\dll\2596.ini 2025-07-14 13:03:45,328 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-14 13:03:45,328 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-14 13:03:45,328 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-14 13:03:45,328 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2025-07-14 13:03:45,328 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2025-07-14 13:03:45,328 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2025-07-14 13:03:45,328 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpd65zellw\dll\LLxIpUmT.dll, loader C:\tmpd65zellw\bin\AVBBtxK.exe 2025-07-14 13:03:45,343 [root] DEBUG: Loader: IAT patching disabled. 2025-07-14 13:03:45,359 [root] DEBUG: Loader: Injecting process 2596 (thread 2204) with C:\tmpd65zellw\dll\LLxIpUmT.dll. 2025-07-14 13:03:45,359 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued. 2025-07-14 13:03:45,359 [root] DEBUG: Successfully injected DLL C:\tmpd65zellw\dll\LLxIpUmT.dll. 2025-07-14 13:03:45,359 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2596 2025-07-14 13:03:45,437 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:03:45,718 [lib.common.results] INFO: File 1752523425640625000.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:03:45,718 [lib.common.results] INFO: File 1752523425640625000.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:03:45,734 [lib.common.results] INFO: File 1752523425640625000.Application.evtx.gz size is 6785, Max size: 100000000 2025-07-14 13:03:45,750 [lib.common.results] INFO: File 1752523425640625000.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:03:46,531 [lib.common.results] INFO: File 1752523425718750000.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:03:46,562 [lib.common.results] INFO: File 1752523425718750000.Security.evtx.gz size is 7853, Max size: 100000000 2025-07-14 13:03:46,609 [lib.common.results] INFO: File 1752523425718750000.System.evtx.gz size is 8805, Max size: 100000000 2025-07-14 13:03:46,640 [lib.common.results] INFO: File 1752523425718750000.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:03:47,078 [lib.common.results] INFO: File 1752523426359375000.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:03:47,359 [lib.api.process] INFO: Successfully resumed process with pid 2596 2025-07-14 13:03:47,437 [root] DEBUG: 2596: Python path set to 'C:\olddocs'. 2025-07-14 13:03:47,453 [root] DEBUG: 2596: Disabling sleep skipping. 2025-07-14 13:03:47,453 [root] DEBUG: 2596: Process dumps enabled. 2025-07-14 13:03:47,453 [root] DEBUG: 2596: AMSI dumping enabled. 2025-07-14 13:03:47,468 [root] DEBUG: 2596: Monitor config - unrecognised key office. 2025-07-14 13:03:47,468 [root] DEBUG: 2596: In-monitor YARA scans disabled. 2025-07-14 13:03:47,468 [root] DEBUG: 2596: Dropped file limit defaulting to 100. 2025-07-14 13:03:47,468 [root] DEBUG: 2596: Microsoft Office settings enabled. 2025-07-14 13:03:47,468 [root] DEBUG: 2596: Monitor initialised: 32-bit capemon loaded in process 2596 at 0x73f50000, thread 2204, image base 0x1270000, stack from 0x213000-0x220000 2025-07-14 13:03:47,468 [root] DEBUG: 2596: Commandline: "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" "C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx" /q 2025-07-14 13:03:47,500 [root] DEBUG: 2596: Hooked 455 out of 455 functions 2025-07-14 13:03:47,500 [root] DEBUG: 2596: WoW64 detected: 64-bit ntdll base: 0x773f0000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7745b5f0, Wow64PrepareForException: 0x0 2025-07-14 13:03:47,500 [root] DEBUG: 2596: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0xe0000 2025-07-14 13:03:47,500 [root] INFO: Loaded monitor into process with pid 2596 2025-07-14 13:03:47,640 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523427.640625.sysmon.evtx.gz to host 2025-07-14 13:03:47,640 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 8761, Max size: 100000000 2025-07-14 13:03:47,734 [root] DEBUG: 2596: DLL loaded at 0x6FE10000: C:\Program Files (x86)\Microsoft Office\Office15\wwlib (0x14bc000 bytes). 2025-07-14 13:03:47,765 [root] DEBUG: 2596: DLL loaded at 0x73DC0000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus (0x190000 bytes). 2025-07-14 13:03:47,765 [root] DEBUG: 2596: DLL loaded at 0x763B0000: C:\Windows\syswow64\OLEAUT32 (0x8f000 bytes). 2025-07-14 13:03:47,937 [root] DEBUG: 2596: DLL loaded at 0x6F060000: C:\Program Files (x86)\Microsoft Office\Office15\oart (0xda8000 bytes). 2025-07-14 13:03:47,953 [root] DEBUG: 2596: DLL loaded at 0x74560000: C:\Windows\system32\MSVCP100 (0x69000 bytes). 2025-07-14 13:03:48,000 [root] DEBUG: 2596: DLL loaded at 0x72440000: C:\Windows\system32\d2d1 (0x347000 bytes). 2025-07-14 13:03:48,281 [root] DEBUG: 2596: DLL loaded at 0x6D770000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso (0x18e4000 bytes). 2025-07-14 13:03:48,296 [root] DEBUG: 2596: DLL loaded at 0x731E0000: C:\Windows\system32\MSIMG32 (0x5000 bytes). 2025-07-14 13:03:48,312 [root] DEBUG: 2596: DLL loaded at 0x733D0000: C:\Windows\system32\uxtheme (0x80000 bytes). 2025-07-14 13:03:48,328 [root] DEBUG: 2596: DLL loaded at 0x732F0000: C:\Windows\system32\WTSAPI32 (0xd000 bytes). 2025-07-14 13:03:48,328 [root] DEBUG: 2596: DLL loaded at 0x74530000: C:\Windows\system32\WINSTA (0x29000 bytes). 2025-07-14 13:03:48,343 [root] DEBUG: 2596: DLL loaded at 0x73D70000: C:\Windows\system32\dxgi (0x4c000 bytes). 2025-07-14 13:03:48,343 [root] DEBUG: 2596: DLL loaded at 0x73300000: C:\Windows\system32\VERSION (0x9000 bytes). 2025-07-14 13:03:48,343 [root] DEBUG: 2596: DLL loaded at 0x73D50000: C:\Windows\system32\dwmapi (0x13000 bytes). 2025-07-14 13:03:48,375 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-14 13:03:48,375 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:48,375 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:48,390 [root] DEBUG: 2596: DLL loaded at 0x767B0000: C:\Windows\syswow64\WINTRUST (0x2f000 bytes). 2025-07-14 13:03:48,406 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-14 13:03:48,406 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:48,406 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:48,421 [root] DEBUG: 2596: DLL loaded at 0x72200000: C:\Windows\system32\msi (0x240000 bytes). 2025-07-14 13:03:48,546 [root] DEBUG: 2596: api-rate-cap: NtQueryValueKey hook disabled due to rate 2025-07-14 13:03:48,562 [root] DEBUG: 2596: api-rate-cap: NtClose hook disabled due to rate 2025-07-14 13:03:48,578 [root] DEBUG: 2596: api-rate-cap: NtOpenKey hook disabled due to rate 2025-07-14 13:03:48,609 [root] DEBUG: 2596: api-rate-cap: RegOpenKeyExW hook disabled due to rate 2025-07-14 13:03:48,609 [root] DEBUG: 2596: api-rate-cap: NtOpenKeyEx hook disabled due to rate 2025-07-14 13:03:48,640 [root] DEBUG: 2596: api-rate-cap: RegQueryValueExW hook disabled due to rate 2025-07-14 13:03:48,656 [root] DEBUG: 2596: DLL loaded at 0x71BE0000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSPTLS (0x116000 bytes). 2025-07-14 13:03:48,812 [root] DEBUG: 2596: DLL loaded at 0x75340000: C:\Windows\syswow64\SHELL32 (0xc4a000 bytes). 2025-07-14 13:03:48,812 [root] DEBUG: 2596: DLL loaded at 0x760A0000: C:\Windows\syswow64\profapi (0xb000 bytes). 2025-07-14 13:03:48,890 [root] DEBUG: 2596: DLL loaded at 0x73460000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32 (0x19e000 bytes). 2025-07-14 13:03:48,906 [root] DEBUG: 2596: DLL loaded at 0x73C60000: C:\Windows\system32\d3d10_1 (0x2c000 bytes). 2025-07-14 13:03:48,906 [root] DEBUG: 2596: DLL loaded at 0x73C10000: C:\Windows\system32\d3d10_1core (0x41000 bytes). 2025-07-14 13:03:48,921 [root] DEBUG: 2596: DLL loaded at 0x716E0000: C:\Windows\system32\d3d11 (0x175000 bytes). 2025-07-14 13:03:48,953 [root] DEBUG: 2596: DLL loaded at 0x714F0000: C:\Windows\system32\D3D10Warp (0x1e9000 bytes). 2025-07-14 13:03:48,968 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-14 13:03:48,968 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:48,968 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:48,968 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-14 13:03:48,984 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:48,984 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:49,000 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-14 13:03:49,000 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:49,000 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:49,015 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-14 13:03:49,015 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:49,015 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:49,046 [root] DEBUG: 2596: DLL loaded at 0x713C0000: C:\Windows\system32\WindowsCodecs (0x130000 bytes). 2025-07-14 13:03:49,046 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-14 13:03:49,046 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:49,062 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:49,078 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2025-07-14 13:03:49,078 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:49,078 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:49,125 [root] DEBUG: 2596: DLL loaded at 0x6D630000: C:\Windows\system32\DWrite (0x135000 bytes). 2025-07-14 13:03:49,140 [root] DEBUG: 2596: DLL loaded at 0x73BC0000: C:\Windows\system32\mscoree (0x4a000 bytes). 2025-07-14 13:03:49,140 [root] DEBUG: 2596: DLL loaded at 0x71330000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes). 2025-07-14 13:03:49,234 [root] DEBUG: 2596: DLL loaded at 0x6D570000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\adal (0xb5000 bytes). 2025-07-14 13:03:49,249 [root] DEBUG: 2596: DLL loaded at 0x712D0000: C:\Windows\system32\WINHTTP (0x58000 bytes). 2025-07-14 13:03:49,249 [root] DEBUG: 2596: DLL loaded at 0x6D520000: C:\Windows\system32\webio (0x50000 bytes). 2025-07-14 13:03:49,281 [root] DEBUG: 2596: DLL loaded at 0x76A20000: C:\Windows\syswow64\WININET (0x1e4000 bytes). 2025-07-14 13:03:49,281 [root] DEBUG: 2596: DLL loaded at 0x76980000: C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes). 2025-07-14 13:03:49,281 [root] DEBUG: 2596: DLL loaded at 0x77060000: C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes). 2025-07-14 13:03:49,281 [root] DEBUG: 2596: DLL loaded at 0x76520000: C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes). 2025-07-14 13:03:49,281 [root] DEBUG: 2596: DLL loaded at 0x76C10000: C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes). 2025-07-14 13:03:49,281 [root] DEBUG: 2596: DLL loaded at 0x76990000: C:\Windows\syswow64\normaliz (0x3000 bytes). 2025-07-14 13:03:49,312 [root] DEBUG: 2596: DLL loaded at 0x76D70000: C:\Windows\syswow64\iertutil (0x232000 bytes). 2025-07-14 13:03:49,312 [root] DEBUG: 2596: DLL loaded at 0x766A0000: C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes). 2025-07-14 13:03:49,312 [root] DEBUG: 2596: DLL loaded at 0x75090000: C:\Windows\syswow64\USERENV (0x17000 bytes). 2025-07-14 13:03:49,328 [root] DEBUG: 2596: DLL loaded at 0x74A90000: C:\Windows\system32\Secur32 (0x8000 bytes). 2025-07-14 13:03:49,343 [root] DEBUG: 2596: DLL loaded at 0x76610000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes). 2025-07-14 13:03:49,343 [root] DEBUG: 2596: DLL loaded at 0x6D4C0000: C:\Windows\System32\netprofm (0x5a000 bytes). 2025-07-14 13:03:49,343 [root] DEBUG: 2596: DLL loaded at 0x74520000: C:\Windows\System32\nlaapi (0x10000 bytes). 2025-07-14 13:03:49,359 [root] DEBUG: 2596: DLL loaded at 0x732D0000: C:\Windows\system32\CRYPTSP (0x17000 bytes). 2025-07-14 13:03:49,359 [root] DEBUG: 2596: DLL loaded at 0x73290000: C:\Windows\system32\rsaenh (0x3b000 bytes). 2025-07-14 13:03:49,375 [root] DEBUG: 2596: DLL loaded at 0x73AB0000: C:\Windows\system32\RpcRtRemote (0xe000 bytes). 2025-07-14 13:03:49,375 [root] DEBUG: 2596: DLL loaded at 0x74320000: C:\Windows\System32\npmproxy (0x8000 bytes). 2025-07-14 13:03:49,406 [root] DEBUG: 2596: DLL loaded at 0x6D330000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20 (0x18e000 bytes). 2025-07-14 13:03:50,234 [root] DEBUG: 2596: DLL loaded at 0x73AE0000: C:\Windows\system32\IPHLPAPI (0x1c000 bytes). 2025-07-14 13:03:50,234 [root] DEBUG: 2596: DLL loaded at 0x73AD0000: C:\Windows\system32\WINNSI (0x7000 bytes). 2025-07-14 13:03:50,234 [root] DEBUG: 2596: DLL loaded at 0x68610000: C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppc (0x2d000 bytes). 2025-07-14 13:03:50,234 [root] DEBUG: 2596: DLL loaded at 0x73BB0000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes). 2025-07-14 13:03:50,249 [root] DEBUG: 2596: DLL loaded at 0x72B70000: C:\Windows\system32\dhcpcsvc (0x12000 bytes). 2025-07-14 13:03:50,249 [root] DEBUG: 2596: DLL loaded at 0x68600000: C:\Windows\system32\credssp (0x8000 bytes). 2025-07-14 13:03:50,249 [root] DEBUG: 2596: DLL loaded at 0x73A70000: C:\Windows\system32\mswsock (0x3c000 bytes). 2025-07-14 13:03:50,249 [root] DEBUG: 2596: DLL loaded at 0x73A60000: C:\Windows\System32\wshtcpip (0x5000 bytes). 2025-07-14 13:03:50,265 [root] DEBUG: 2596: DLL loaded at 0x685A0000: C:\Windows\system32\WINSPOOL.DRV (0x51000 bytes). 2025-07-14 13:03:50,265 [root] DEBUG: 2596: DLL loaded at 0x73A50000: C:\Windows\System32\wship6 (0x6000 bytes). 2025-07-14 13:03:50,265 [root] DEBUG: 2596: DLL loaded at 0x68550000: C:\Windows\system32\DNSAPI (0x44000 bytes). 2025-07-14 13:03:50,296 [root] DEBUG: 2596: DLL loaded at 0x767E0000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes). 2025-07-14 13:03:50,296 [root] DEBUG: 2596: DLL loaded at 0x76110000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2025-07-14 13:03:50,296 [root] DEBUG: 2596: DLL loaded at 0x76A00000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2025-07-14 13:03:50,312 [root] DEBUG: 2596: DLL loaded at 0x68450000: C:\Windows\system32\propsys (0xf5000 bytes). 2025-07-14 13:03:50,312 [root] DEBUG: 2596: DLL loaded at 0x68400000: C:\Windows\SysWOW64\schannel (0x41000 bytes). 2025-07-14 13:03:50,328 [root] DEBUG: 2596: DLL loaded at 0x73350000: C:\Windows\system32\ntmarta (0x21000 bytes). 2025-07-14 13:03:50,328 [root] DEBUG: 2596: DLL loaded at 0x75040000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes). 2025-07-14 13:03:50,453 [root] DEBUG: 2596: DLL loaded at 0x682A0000: C:\Windows\System32\msxml6 (0x158000 bytes). 2025-07-14 13:03:50,562 [root] DEBUG: 2596: DLL loaded at 0x68270000: C:\Windows\system32\XmlLite (0x2f000 bytes). 2025-07-14 13:03:50,703 [root] DEBUG: 2596: DLL loaded at 0x76C20000: C:\Windows\SysWOW64\urlmon (0x14a000 bytes). 2025-07-14 13:03:50,703 [root] DEBUG: 2596: DLL loaded at 0x76530000: C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes). 2025-07-14 13:03:50,718 [root] DEBUG: 2596: DLL loaded at 0x68260000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes). 2025-07-14 13:03:50,765 [root] DEBUG: 556: DLL loaded at 0x000007FEF8F60000: C:\Windows\system32\keyiso (0xb000 bytes). 2025-07-14 13:03:50,890 [root] DEBUG: 2596: DLL loaded at 0x68200000: C:\Windows\system32\SXS (0x5f000 bytes). 2025-07-14 13:03:51,453 [root] DEBUG: 556: TLS 1.2 secrets logged to: C:\ivhVKM\tlsdump\tlsdump.log 2025-07-14 13:03:51,546 [root] DEBUG: 556: DLL loaded at 0x000007FEFA470000: C:\Windows\system32\cryptnet (0x27000 bytes). 2025-07-14 13:03:51,546 [root] DEBUG: 556: DLL loaded at 0x000007FEFEC30000: C:\Windows\system32\WLDAP32 (0x52000 bytes). 2025-07-14 13:03:51,593 [root] DEBUG: 2596: DLL loaded at 0x681C0000: C:\Windows\system32\ncrypt (0x39000 bytes). 2025-07-14 13:03:51,593 [root] DEBUG: 2596: DLL loaded at 0x68180000: C:\Windows\SysWOW64\bcryptprimitives (0x3d000 bytes). 2025-07-14 13:03:51,812 [root] DEBUG: 2596: DLL loaded at 0x68160000: C:\Windows\system32\GPAPI (0x16000 bytes). 2025-07-14 13:03:51,890 [root] DEBUG: 2596: DLL loaded at 0x68080000: C:\Windows\system32\webservices (0xc2000 bytes). 2025-07-14 13:03:51,921 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma00546271.png0 size is 119666, Max size: 100000000 2025-07-14 13:03:51,937 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02786999.png0 size is 8127, Max size: 100000000 2025-07-14 13:03:51,953 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900771.png0 size is 10213, Max size: 100000000 2025-07-14 13:03:51,968 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382936.png0 size is 37573, Max size: 100000000 2025-07-14 13:03:51,984 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382941.png0 size is 96333, Max size: 100000000 2025-07-14 13:03:52,000 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02835058.png0 size is 186365, Max size: 100000000 2025-07-14 13:03:52,032 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03978815.png0 size is 711398, Max size: 100000000 2025-07-14 13:03:52,063 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78018332.png0 size is 26105, Max size: 100000000 2025-07-14 13:03:52,086 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392850.png0 size is 280509, Max size: 100000000 2025-07-14 13:03:52,102 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45325165.png0 size is 9149, Max size: 100000000 2025-07-14 13:03:52,102 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03982351.png0 size is 12860, Max size: 100000000 2025-07-14 13:03:52,118 [root] DEBUG: 2596: DLL loaded at 0x68060000: C:\Windows\system32\cryptnet (0x1d000 bytes). 2025-07-14 13:03:52,125 [root] DEBUG: 2596: DLL loaded at 0x68050000: C:\Windows\system32\SensApi (0x6000 bytes). 2025-07-14 13:03:52,133 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392877.png0 size is 86215, Max size: 100000000 2025-07-14 13:03:52,141 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16402488.png0 size is 114584, Max size: 100000000 2025-07-14 13:03:52,165 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16412178.png0 size is 283253, Max size: 100000000 2025-07-14 13:03:52,196 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma56348247.png0 size is 55049, Max size: 100000000 2025-07-14 13:03:52,219 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900720.png0 size is 22877, Max size: 100000000 2025-07-14 13:03:52,250 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma88924273.png0 size is 103770, Max size: 100000000 2025-07-14 13:03:52,274 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02836342.png0 size is 26220, Max size: 100000000 2025-07-14 13:03:52,297 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02892315.png0 size is 20776, Max size: 100000000 2025-07-14 13:03:52,321 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002124.png0 size is 11329, Max size: 100000000 2025-07-14 13:03:52,344 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78500733.png0 size is 10169, Max size: 100000000 2025-07-14 13:03:52,375 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900688.png0 size is 8561, Max size: 100000000 2025-07-14 13:03:52,399 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900722.png0 size is 19188, Max size: 100000000 2025-07-14 13:03:52,422 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900743.png0 size is 33070, Max size: 100000000 2025-07-14 13:03:52,454 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02923944.png0 size is 4886, Max size: 100000000 2025-07-14 13:03:52,493 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002117.png0 size is 4962, Max size: 100000000 2025-07-14 13:03:52,524 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt16402400.png0 size is 33856, Max size: 100000000 2025-07-14 13:03:52,547 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt22746018.png0 size is 18469, Max size: 100000000 2025-07-14 13:03:52,571 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45088960.png0 size is 40992, Max size: 100000000 2025-07-14 13:03:52,594 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45420242.png0 size is 13339, Max size: 100000000 2025-07-14 13:03:53,548 [lib.common.results] INFO: File c:\olddocs\1752523428531.saz size is 4607, Max size: 100000000 2025-07-14 13:03:53,556 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:03:54,416 [root] DEBUG: 2596: DLL loaded at 0x68020000: C:\Windows\system32\POWRPROF (0x25000 bytes). 2025-07-14 13:04:02,140 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:04:02,390 [lib.common.results] INFO: File 1752523442343750000.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:04:02,406 [lib.common.results] INFO: File 1752523442343750000.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:04:02,421 [lib.common.results] INFO: File 1752523442343750000.Application.evtx.gz size is 6712, Max size: 100000000 2025-07-14 13:04:02,437 [lib.common.results] INFO: File 1752523442343750000.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:04:02,453 [lib.common.results] INFO: File 1752523442390625000.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:04:02,468 [lib.common.results] INFO: File 1752523442406250000.Security.evtx.gz size is 8061, Max size: 100000000 2025-07-14 13:04:02,484 [lib.common.results] INFO: File 1752523442406250000.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:04:02,500 [lib.common.results] INFO: File 1752523442421875000.System.evtx.gz size is 8635, Max size: 100000000 2025-07-14 13:04:02,515 [lib.common.results] INFO: File 1752523442453125000.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:04:02,640 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:04:07,763 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523447.7636719.sysmon.evtx.gz to host 2025-07-14 13:04:07,763 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 74416, Max size: 100000000 2025-07-14 13:04:13,674 [lib.common.results] INFO: File c:\olddocs\1752523448646.saz size is 14509, Max size: 100000000 2025-07-14 13:04:13,698 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:04:17,560 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:04:17,810 [lib.common.results] INFO: File 1752523457748046800.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:04:17,826 [lib.common.results] INFO: File 1752523457748046800.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:04:17,841 [lib.common.results] INFO: File 1752523457748046800.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:04:17,857 [lib.common.results] INFO: File 1752523457748046800.Application.evtx.gz size is 6712, Max size: 100000000 2025-07-14 13:04:17,873 [lib.common.results] INFO: File 1752523457794921800.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:04:17,888 [lib.common.results] INFO: File 1752523457810546800.Security.evtx.gz size is 7997, Max size: 100000000 2025-07-14 13:04:17,888 [lib.common.results] INFO: File 1752523457810546800.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:04:17,904 [lib.common.results] INFO: File 1752523457810546800.System.evtx.gz size is 8378, Max size: 100000000 2025-07-14 13:04:17,919 [lib.common.results] INFO: File 1752523457841796800.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:04:22,783 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:04:27,848 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523467.8486328.sysmon.evtx.gz to host 2025-07-14 13:04:27,848 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5269, Max size: 100000000 2025-07-14 13:04:32,954 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:04:33,171 [lib.common.results] INFO: File 1752523473125000000.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:04:33,187 [lib.common.results] INFO: File 1752523473125000000.Application.evtx.gz size is 6712, Max size: 100000000 2025-07-14 13:04:33,187 [lib.common.results] INFO: File 1752523473140625000.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:04:33,203 [lib.common.results] INFO: File 1752523473148437500.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:04:33,226 [lib.common.results] INFO: File 1752523473179687500.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:04:33,234 [lib.common.results] INFO: File 1752523473164062500.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:04:33,249 [lib.common.results] INFO: File 1752523473171875000.Security.evtx.gz size is 7861, Max size: 100000000 2025-07-14 13:04:33,257 [lib.common.results] INFO: File 1752523473187500000.System.evtx.gz size is 8386, Max size: 100000000 2025-07-14 13:04:33,273 [lib.common.results] INFO: File 1752523473226562500.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:04:33,804 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:04:42,864 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:04:47,938 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523487.9384766.sysmon.evtx.gz to host 2025-07-14 13:04:47,938 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5447, Max size: 100000000 2025-07-14 13:04:48,321 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:04:48,555 [lib.common.results] INFO: File 1752523488508789000.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:04:48,555 [lib.common.results] INFO: File 1752523488508789000.Application.evtx.gz size is 6918, Max size: 100000000 2025-07-14 13:04:48,555 [lib.common.results] INFO: File 1752523488508789000.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:04:48,602 [lib.common.results] INFO: File 1752523488555664000.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:04:48,618 [lib.common.results] INFO: File 1752523488555664000.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:04:48,633 [lib.common.results] INFO: File 1752523488540039000.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:04:48,633 [lib.common.results] INFO: File 1752523488555664000.Security.evtx.gz size is 7989, Max size: 100000000 2025-07-14 13:04:48,649 [lib.common.results] INFO: File 1752523488602539000.System.evtx.gz size is 8400, Max size: 100000000 2025-07-14 13:04:48,680 [lib.common.results] INFO: File 1752523488602539000.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:04:53,901 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:05:02,967 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:05:03,718 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:05:03,945 [lib.common.results] INFO: File 1752523503898437500.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:05:03,968 [lib.common.results] INFO: File 1752523503898437500.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:05:03,984 [lib.common.results] INFO: File 1752523503898437500.Application.evtx.gz size is 6848, Max size: 100000000 2025-07-14 13:05:03,984 [lib.common.results] INFO: File 1752523503898437500.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:05:04,000 [lib.common.results] INFO: File 1752523503945312500.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:05:04,015 [lib.common.results] INFO: File 1752523503945312500.Security.evtx.gz size is 7912, Max size: 100000000 2025-07-14 13:05:04,039 [lib.common.results] INFO: File 1752523503953125000.System.evtx.gz size is 8396, Max size: 100000000 2025-07-14 13:05:04,054 [lib.common.results] INFO: File 1752523503953125000.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:05:04,070 [lib.common.results] INFO: File 1752523504000000000.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:05:08,034 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523508.0341797.sysmon.evtx.gz to host 2025-07-14 13:05:08,034 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5626, Max size: 100000000 2025-07-14 13:05:13,986 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:05:19,121 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:05:19,355 [lib.common.results] INFO: File 1752523519300781200.Application.evtx.gz size is 6848, Max size: 100000000 2025-07-14 13:05:19,386 [lib.common.results] INFO: File 1752523519308593700.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:05:19,402 [lib.common.results] INFO: File 1752523519300781200.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:05:19,433 [lib.common.results] INFO: File 1752523519300781200.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:05:19,449 [lib.common.results] INFO: File 1752523519363281200.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:05:19,464 [lib.common.results] INFO: File 1752523519355468700.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:05:19,480 [lib.common.results] INFO: File 1752523519355468700.Security.evtx.gz size is 8011, Max size: 100000000 2025-07-14 13:05:19,496 [lib.common.results] INFO: File 1752523519371093700.System.evtx.gz size is 8406, Max size: 100000000 2025-07-14 13:05:19,511 [lib.common.results] INFO: File 1752523519410156200.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:05:23,053 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:05:28,134 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523528.1347656.sysmon.evtx.gz to host 2025-07-14 13:05:28,134 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5259, Max size: 100000000 2025-07-14 13:05:34,060 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:05:34,560 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:05:34,779 [lib.common.results] INFO: File 1752523534732421800.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:05:34,794 [lib.common.results] INFO: File 1752523534732421800.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:05:34,810 [lib.common.results] INFO: File 1752523534732421800.Application.evtx.gz size is 6848, Max size: 100000000 2025-07-14 13:05:34,826 [lib.common.results] INFO: File 1752523534732421800.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:05:34,841 [lib.common.results] INFO: File 1752523534779296800.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:05:34,873 [lib.common.results] INFO: File 1752523534779296800.Security.evtx.gz size is 7988, Max size: 100000000 2025-07-14 13:05:34,888 [lib.common.results] INFO: File 1752523534779296800.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:05:34,904 [lib.common.results] INFO: File 1752523534779296800.System.evtx.gz size is 8418, Max size: 100000000 2025-07-14 13:05:34,919 [lib.common.results] INFO: File 1752523534810546800.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:05:43,156 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:05:48,229 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523548.2294922.sysmon.evtx.gz to host 2025-07-14 13:05:48,229 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5470, Max size: 100000000 2025-07-14 13:05:49,964 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:05:50,190 [lib.common.results] INFO: File 1752523550136718700.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:05:50,210 [lib.common.results] INFO: File 1752523550136718700.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:05:50,226 [lib.common.results] INFO: File 1752523550136718700.Application.evtx.gz size is 6848, Max size: 100000000 2025-07-14 13:05:50,242 [lib.common.results] INFO: File 1752523550152343700.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:05:50,265 [lib.common.results] INFO: File 1752523550189453100.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:05:50,281 [lib.common.results] INFO: File 1752523550195312500.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:05:50,304 [lib.common.results] INFO: File 1752523550193359300.Security.evtx.gz size is 7909, Max size: 100000000 2025-07-14 13:05:50,328 [lib.common.results] INFO: File 1752523550203125000.System.evtx.gz size is 8434, Max size: 100000000 2025-07-14 13:05:50,343 [lib.common.results] INFO: File 1752523550226562500.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:05:54,159 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:06:03,250 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:06:05,384 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:06:05,595 [lib.common.results] INFO: File 1752523565564453100.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:06:05,611 [lib.common.results] INFO: File 1752523565564453100.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:06:05,626 [lib.common.results] INFO: File 1752523565564453100.Application.evtx.gz size is 6848, Max size: 100000000 2025-07-14 13:06:05,642 [lib.common.results] INFO: File 1752523565564453100.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:06:05,658 [lib.common.results] INFO: File 1752523565595703100.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:06:05,673 [lib.common.results] INFO: File 1752523565611328100.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:06:05,673 [lib.common.results] INFO: File 1752523565595703100.Security.evtx.gz size is 8105, Max size: 100000000 2025-07-14 13:06:05,689 [lib.common.results] INFO: File 1752523565626953100.System.evtx.gz size is 8410, Max size: 100000000 2025-07-14 13:06:05,705 [lib.common.results] INFO: File 1752523565642578100.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:06:08,333 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523568.3330078.sysmon.evtx.gz to host 2025-07-14 13:06:08,333 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5401, Max size: 100000000 2025-07-14 13:06:14,258 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:06:17,622 [root] INFO: Analysis timeout hit, terminating analysis 2025-07-14 13:06:17,622 [lib.api.process] INFO: Terminate event set for process 2596 2025-07-14 13:06:17,622 [root] DEBUG: 2596: Terminate Event: Attempting to dump process 2596 2025-07-14 13:06:17,622 [root] DEBUG: 2596: VerifyCodeSection: Executable code does not match, 0x64c of 0x154f matching 2025-07-14 13:06:17,622 [root] DEBUG: 2596: DoProcessDump: Code modification detected, dumping Imagebase at 0x01270000. 2025-07-14 13:06:17,629 [root] DEBUG: 2596: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2025-07-14 13:06:17,637 [root] DEBUG: 2596: DumpProcess: Instantiating PeParser with address: 0x01270000. 2025-07-14 13:06:17,637 [root] DEBUG: 2596: DumpProcess: Module entry point VA is 0x000010D4. 2025-07-14 13:06:17,676 [lib.common.results] INFO: File C:\ivhVKM\CAPE\2596_267731762014172025 size is 1915904, Max size: 100000000 2025-07-14 13:06:17,723 [root] DEBUG: 2596: DumpProcess: Module image dump success - dump size 0x1d3c00. 2025-07-14 13:06:17,739 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10 2025-07-14 13:06:17,747 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\~$34_as_password_ha.docx 2025-07-14 13:06:17,747 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx 2025-07-14 13:06:17,747 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Office\Word15.customUI 2025-07-14 13:06:17,747 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B47A855B-6F69-475E-A9E1-2864BACFCC77}.tmp 2025-07-14 13:06:17,747 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm 2025-07-14 13:06:17,747 [lib.api.process] INFO: Termination confirmed for process 2596 2025-07-14 13:06:17,754 [root] INFO: Terminate event set for process 2596 2025-07-14 13:06:17,754 [root] DEBUG: 2596: Terminate Event: monitor shutdown complete for process 2596 2025-07-14 13:06:17,754 [root] INFO: Created shutdown mutex 2025-07-14 13:06:18,756 [root] INFO: Shutting down package 2025-07-14 13:06:18,756 [root] INFO: Stopping auxiliary modules 2025-07-14 13:06:18,756 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2025-07-14 13:06:18,756 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2025-07-14 13:06:18,772 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:06:19,022 [lib.common.results] INFO: File 1752523578983398400.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:06:19,045 [lib.common.results] INFO: File 1752523578967773400.Application.evtx.gz size is 6848, Max size: 100000000 2025-07-14 13:06:19,061 [lib.common.results] INFO: File 1752523578983398400.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:06:19,077 [lib.common.results] INFO: File 1752523578999023400.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:06:19,092 [lib.common.results] INFO: File 1752523579022460900.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:06:19,108 [lib.common.results] INFO: File 1752523579030273400.Security.evtx.gz size is 8027, Max size: 100000000 2025-07-14 13:06:19,124 [lib.common.results] INFO: File 1752523579038085900.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:06:19,124 [lib.common.results] INFO: File 1752523579053710900.System.evtx.gz size is 8423, Max size: 100000000 2025-07-14 13:06:19,139 [lib.common.results] INFO: File 1752523579069335900.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:06:20,736 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-14 13:06:20,946 [lib.common.results] INFO: File 1752523580899414000.InternetExplorer.evtx.gz size is 251, Max size: 100000000 2025-07-14 13:06:20,977 [lib.common.results] INFO: File 1752523580899414000.HardwareEvents.evtx.gz size is 359, Max size: 100000000 2025-07-14 13:06:20,993 [lib.common.results] INFO: File 1752523580899414000.Application.evtx.gz size is 6848, Max size: 100000000 2025-07-14 13:06:21,008 [lib.common.results] INFO: File 1752523580946289000.OAlerts.evtx.gz size is 243, Max size: 100000000 2025-07-14 13:06:21,024 [lib.common.results] INFO: File 1752523580930664000.KeyManagementService.evtx.gz size is 7316, Max size: 100000000 2025-07-14 13:06:21,040 [lib.common.results] INFO: File 1752523580954101500.Setup.evtx.gz size is 240, Max size: 100000000 2025-07-14 13:06:21,055 [lib.common.results] INFO: File 1752523580954101500.Security.evtx.gz size is 8092, Max size: 100000000 2025-07-14 13:06:21,055 [lib.common.results] INFO: File 1752523580993164000.WindowsPowerShell.evtx.gz size is 8380, Max size: 100000000 2025-07-14 13:06:21,063 [lib.common.results] INFO: File 1752523580985351500.System.evtx.gz size is 8402, Max size: 100000000 2025-07-14 13:06:23,353 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-14 13:06:24,245 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-14 13:06:24,245 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2025-07-14 13:06:28,440 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752523588.4404294.sysmon.evtx.gz to host 2025-07-14 13:06:28,440 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 11826, Max size: 100000000 2025-07-14 13:06:29,315 [modules.auxiliary.sysmon] ERROR: Sysmon log file C:\Sysmon.evtx not found in guest machine 2025-07-14 13:06:29,315 [root] INFO: Finishing auxiliary modules 2025-07-14 13:06:29,315 [root] INFO: Shutting down pipe server and dumping dropped files 2025-07-14 13:06:29,315 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10 size is 23382, Max size: 100000000 2025-07-14 13:06:29,331 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\~$34_as_password_ha.docx size is 162, Max size: 100000000 2025-07-14 13:06:29,346 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx size is 107520, Max size: 100000000 2025-07-14 13:06:29,362 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\Word15.customUI size is 3514, Max size: 100000000 2025-07-14 13:06:29,377 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B47A855B-6F69-475E-A9E1-2864BACFCC77}.tmp size is 1024, Max size: 100000000 2025-07-14 13:06:29,393 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm size is 17789, Max size: 100000000 2025-07-14 13:06:29,409 [root] WARNING: Folder at path "C:\ivhVKM\debugger" does not exist, skipping 2025-07-14 13:06:29,409 [root] INFO: Uploading files at path "C:\ivhVKM\tlsdump" 2025-07-14 13:06:29,409 [lib.common.results] INFO: File C:\ivhVKM\tlsdump\tlsdump.log size is 1644, Max size: 100000000 2025-07-14 13:06:29,424 [root] INFO: Analysis completed
Name | Label | Manager | Started On | Shutdown On | Route |
---|---|---|---|---|---|
win7office2k3flash2800137TWN3H104 | win7office2k3flash2800137TWN3H104 | KVM | 2025-07-14 20:03:29 | 2025-07-14 20:06:39 | internet |
File Name | 1234_as_password_ha.docx |
---|---|
File Size | 107520 bytes |
File Type | CDFV2 Encrypted |
MD5 | 31ecd43e3606e0e4fe8ed3dc515e8b69 |
SHA1 | b5f7856b2a0ca9bce5355bfb6e81e5991183ebf4 |
SHA256 | af46d415f384795c00d2c08071848cf6c304e116b0db05e85a74ca3aeb783af0 |
SHA512 | 077abf6135aa0927ec816fab927a5665eb826b3620174749c954c5b3c950889cef2693d86a065aaf036591b9bc29e96275ce54663754a032146a9fc29dc65ec6 |
SHA3-384 | 5681b7a8afe9ce13719632b96a2cec0a09512fd2fa77d030f5077867fc5ea0e313c2e0a52c993a9359be977ce86776d2 |
CRC32 | 445C5EE7 |
TLSH | T1B5B31276C4A4CCDBE0222DB97247D40550236D8ED6813E663FAAB5050AF02B66FEC5FD |
Ssdeep | 3072:SKoFaUTc1xuMY8n2+IuyiVVZOTAduwe/N/:JoRT8k+ZwAkw4 |
File
|
|
Direct | IP | Country Name |
---|---|---|
Y | 8.8.8.8 [VT] | United States |
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP