Category | Package | Started | Completed | Duration | Options | Log |
---|---|---|---|---|---|---|
FILE | bat | 2025-07-16 14:05:05 | 2025-07-16 14:08:08 | 183 seconds | Show Options | Show Log |
procdump=1
amsidump=1
2024-04-29 04:34:35,515 [root] INFO: Date set to: 20250716T07:05:05, timeout set to: 150 2025-07-16 07:05:05,031 [root] DEBUG: Starting analyzer from: C:\tmp4xmvmnkr 2025-07-16 07:05:05,031 [root] DEBUG: Storing results at: C:\NNxDoWybNW 2025-07-16 07:05:05,031 [root] DEBUG: Pipe server name: \\.\PIPE\seZqhWb 2025-07-16 07:05:05,031 [root] DEBUG: Python path: C:\olddocs 2025-07-16 07:05:05,031 [root] DEBUG: No analysis package specified, trying to detect it automagically 2025-07-16 07:05:05,031 [root] INFO: Automatically selected analysis package "bat" 2025-07-16 07:05:05,031 [root] DEBUG: Importing analysis package "bat"... 2025-07-16 07:05:05,031 [root] DEBUG: Initializing analysis package "bat"... 2025-07-16 07:05:05,031 [root] INFO: Analyzer: Package modules.packages.bat does not specify a DLL option 2025-07-16 07:05:05,031 [root] INFO: Analyzer: Package modules.packages.bat does not specify a DLL_64 option 2025-07-16 07:05:05,031 [root] INFO: Analyzer: Package modules.packages.bat does not specify a loader option 2025-07-16 07:05:05,031 [root] INFO: Analyzer: Package modules.packages.bat does not specify a loader_64 option 2025-07-16 07:05:05,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2025-07-16 07:05:05,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2025-07-16 07:05:05,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2025-07-16 07:05:05,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2025-07-16 07:05:05,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2025-07-16 07:05:05,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2025-07-16 07:05:05,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2025-07-16 07:05:05,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2025-07-16 07:05:05,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2025-07-16 07:05:05,125 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2025-07-16 07:05:05,203 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2025-07-16 07:05:05,203 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2025-07-16 07:05:05,203 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2025-07-16 07:05:05,218 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2025-07-16 07:05:05,218 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2025-07-16 07:05:05,218 [root] DEBUG: Initializing auxiliary module "Browser"... 2025-07-16 07:05:05,218 [root] DEBUG: Started auxiliary module Browser 2025-07-16 07:05:05,218 [root] DEBUG: Initializing auxiliary module "Curtain"... 2025-07-16 07:05:05,218 [root] DEBUG: Started auxiliary module Curtain 2025-07-16 07:05:05,218 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2025-07-16 07:05:05,249 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2025-07-16 07:05:05,249 [root] DEBUG: Started auxiliary module DefaultApps 2025-07-16 07:05:05,249 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2025-07-16 07:05:05,249 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2025-07-16 07:05:05,249 [modules.auxiliary.digisig] INFO: dummy 2025-07-16 07:05:05,249 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2025-07-16 07:05:05,249 [root] DEBUG: Started auxiliary module DigiSig 2025-07-16 07:05:05,249 [root] DEBUG: Initializing auxiliary module "Disguise"... 2025-07-16 07:05:05,515 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2025-07-16 07:05:05,515 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2025-07-16 07:05:05,515 [root] DEBUG: Initializing auxiliary module "Evtx"... 2025-07-16 07:05:05,515 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmp4xmvmnkr\bin\auditpol.csv 2025-07-16 07:05:05,796 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:05:06,718 [root] DEBUG: Started auxiliary module Evtx 2025-07-16 07:05:06,718 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2025-07-16 07:05:06,718 [modules.auxiliary.fiddler] INFO: fiddler package: dummy 2025-07-16 07:05:06,734 [root] DEBUG: Started auxiliary module Fiddler 2025-07-16 07:05:06,734 [root] DEBUG: Initializing auxiliary module "Human"... 2025-07-16 07:05:06,734 [root] DEBUG: Started auxiliary module Human 2025-07-16 07:05:06,734 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2025-07-16 07:05:06,734 [root] DEBUG: Started auxiliary module Screenshots 2025-07-16 07:05:06,734 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2025-07-16 07:05:06,734 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2025-07-16 07:05:06,734 [root] DEBUG: Started auxiliary module Sysmon 2025-07-16 07:05:06,734 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2025-07-16 07:05:06,734 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 556 2025-07-16 07:05:06,734 [lib.api.process] INFO: Monitor config for process 556: C:\tmp4xmvmnkr\dll\556.ini 2025-07-16 07:05:06,750 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-16 07:05:06,750 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-16 07:05:06,750 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-16 07:05:06,750 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2025-07-16 07:05:06,750 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp4xmvmnkr\dll\hOOGGo.dll, loader C:\tmp4xmvmnkr\bin\SpVwShXB.exe 2025-07-16 07:05:06,750 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2025-07-16 07:05:06,750 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2025-07-16 07:05:06,781 [root] DEBUG: Loader: Injecting process 556 with C:\tmp4xmvmnkr\dll\hOOGGo.dll. 2025-07-16 07:05:06,828 [root] DEBUG: 556: Python path set to 'C:\olddocs'. 2025-07-16 07:05:06,828 [root] DEBUG: 556: Disabling sleep skipping. 2025-07-16 07:05:06,828 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEF5C30000, thread 2928, image base 0x00000000FF900000, stack from 0x00000000021B2000-0x00000000021C0000 2025-07-16 07:05:06,828 [root] DEBUG: 556: Hooked 5 out of 5 functions 2025-07-16 07:05:06,843 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2025-07-16 07:05:06,843 [root] DEBUG: Successfully injected DLL C:\tmp4xmvmnkr\dll\hOOGGo.dll. 2025-07-16 07:05:06,843 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 556 2025-07-16 07:05:06,843 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2025-07-16 07:05:06,843 [root] DEBUG: Initializing auxiliary module "Usage"... 2025-07-16 07:05:06,843 [root] DEBUG: Started auxiliary module Usage 2025-07-16 07:05:08,906 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2025-07-16 07:05:09,546 [root] INFO: Restarting WMI Service 2025-07-16 07:05:13,609 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\pgabriel\AppData\Local\Temp\opencalc.bat"" with pid 2708 2025-07-16 07:05:13,609 [lib.api.process] INFO: Monitor config for process 2708: C:\tmp4xmvmnkr\dll\2708.ini 2025-07-16 07:05:13,625 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-16 07:05:13,625 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-16 07:05:13,625 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-16 07:05:13,625 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp4xmvmnkr\dll\jvPRBN.dll, loader C:\tmp4xmvmnkr\bin\twUnfDj.exe 2025-07-16 07:05:13,640 [root] DEBUG: Loader: Injecting process 2708 (thread 2580) with C:\tmp4xmvmnkr\dll\jvPRBN.dll. 2025-07-16 07:05:13,640 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2025-07-16 07:05:13,640 [root] DEBUG: Successfully injected DLL C:\tmp4xmvmnkr\dll\jvPRBN.dll. 2025-07-16 07:05:13,656 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2708 2025-07-16 07:05:15,656 [lib.api.process] INFO: Successfully resumed process with pid 2708 2025-07-16 07:05:15,703 [root] DEBUG: 2708: Python path set to 'C:\olddocs'. 2025-07-16 07:05:15,703 [root] DEBUG: 2708: Disabling sleep skipping. 2025-07-16 07:05:15,703 [root] DEBUG: 2708: Process dumps enabled. 2025-07-16 07:05:15,703 [root] DEBUG: 2708: AMSI dumping enabled. 2025-07-16 07:05:15,703 [root] DEBUG: 2708: Dropped file limit defaulting to 100. 2025-07-16 07:05:15,703 [root] DEBUG: 2708: YaraInit: Compiled 43 rule files 2025-07-16 07:05:15,718 [root] DEBUG: 2708: YaraInit: Compiled rules saved to file C:\tmp4xmvmnkr\data\yara\capemon.yac 2025-07-16 07:05:15,718 [root] DEBUG: 2708: YaraScan: Scanning 0x4A7A0000, size 0x4bb2e 2025-07-16 07:05:15,718 [root] DEBUG: 2708: Monitor initialised: 32-bit capemon loaded in process 2708 at 0x74140000, thread 2580, image base 0x4a7a0000, stack from 0x253000-0x350000 2025-07-16 07:05:15,718 [root] DEBUG: 2708: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\pgabriel\AppData\Local\Temp\opencalc.bat" 2025-07-16 07:05:15,750 [root] WARNING: b'Unable to place hook on GetCommandLineA' 2025-07-16 07:05:15,750 [root] DEBUG: 2708: set_hooks: Unable to hook GetCommandLineA 2025-07-16 07:05:15,750 [root] WARNING: b'Unable to place hook on GetCommandLineW' 2025-07-16 07:05:15,750 [root] DEBUG: 2708: set_hooks: Unable to hook GetCommandLineW 2025-07-16 07:05:15,750 [root] DEBUG: 2708: Hooked 615 out of 617 functions 2025-07-16 07:05:15,750 [root] DEBUG: 2708: WoW64 detected: 64-bit ntdll base: 0x775a0000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7760b5f0, Wow64PrepareForException: 0x0 2025-07-16 07:05:15,750 [root] DEBUG: 2708: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x220000 2025-07-16 07:05:15,765 [root] INFO: Loaded monitor into process with pid 2708 2025-07-16 07:05:15,765 [root] DEBUG: 2708: caller_dispatch: Added region at 0x4A7A0000 to tracked regions list (ntdll::NtOpenThread returns to 0x4A7A732B, thread 2580). 2025-07-16 07:05:15,765 [root] DEBUG: 2708: YaraScan: Scanning 0x4A7A0000, size 0x4bb2e 2025-07-16 07:05:15,765 [root] DEBUG: 2708: ProcessImageBase: Main module image at 0x4A7A0000 unmodified (entropy change 0.000000e+00) 2025-07-16 07:05:15,765 [root] DEBUG: 2708: CreateProcessHandler: Injection info set for new process 1292: C:\Windows\system32\cmd.exe, ImageBase: 0x4A7A0000 2025-07-16 07:05:15,781 [root] INFO: Announced 32-bit process name: cmd.exe pid: 1292 2025-07-16 07:05:15,781 [lib.api.process] INFO: Monitor config for process 1292: C:\tmp4xmvmnkr\dll\1292.ini 2025-07-16 07:05:15,781 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-16 07:05:15,781 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-16 07:05:15,781 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-16 07:05:15,781 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp4xmvmnkr\dll\jvPRBN.dll, loader C:\tmp4xmvmnkr\bin\twUnfDj.exe 2025-07-16 07:05:15,796 [root] DEBUG: Loader: Injecting process 1292 (thread 648) with C:\tmp4xmvmnkr\dll\jvPRBN.dll. 2025-07-16 07:05:15,796 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2025-07-16 07:05:15,796 [root] DEBUG: Successfully injected DLL C:\tmp4xmvmnkr\dll\jvPRBN.dll. 2025-07-16 07:05:15,796 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 1292 2025-07-16 07:05:15,812 [root] DEBUG: 2708: DLL loaded at 0x733B0000: C:\Windows\system32\apphelp (0x4c000 bytes). 2025-07-16 07:05:15,812 [root] WARNING: Received request to inject process with pid 1292, skipped alredy in inject list 2025-07-16 07:05:15,843 [root] DEBUG: 1292: Python path set to 'C:\olddocs'. 2025-07-16 07:05:15,843 [root] DEBUG: 1292: Disabling sleep skipping. 2025-07-16 07:05:15,843 [root] DEBUG: 1292: Process dumps enabled. 2025-07-16 07:05:15,843 [root] DEBUG: 1292: AMSI dumping enabled. 2025-07-16 07:05:15,843 [root] DEBUG: 1292: Dropped file limit defaulting to 100. 2025-07-16 07:05:15,859 [root] DEBUG: 1292: YaraInit: Compiled rules loaded from existing file C:\tmp4xmvmnkr\data\yara\capemon.yac 2025-07-16 07:05:15,859 [root] DEBUG: 1292: YaraScan: Scanning 0x4A7A0000, size 0x4bb2e 2025-07-16 07:05:15,859 [root] DEBUG: 1292: Monitor initialised: 32-bit capemon loaded in process 1292 at 0x74140000, thread 648, image base 0x4a7a0000, stack from 0x1a3000-0x2a0000 2025-07-16 07:05:15,859 [root] DEBUG: 1292: Commandline: C:\Windows\system32\cmd.exe /K "C:\Users\pgabriel\AppData\Local\Temp\opencalc.bat" 2025-07-16 07:05:15,890 [root] WARNING: b'Unable to place hook on GetCommandLineA' 2025-07-16 07:05:15,906 [root] DEBUG: 1292: set_hooks: Unable to hook GetCommandLineA 2025-07-16 07:05:15,906 [root] WARNING: b'Unable to place hook on GetCommandLineW' 2025-07-16 07:05:15,906 [root] DEBUG: 1292: set_hooks: Unable to hook GetCommandLineW 2025-07-16 07:05:15,906 [root] DEBUG: 1292: Hooked 615 out of 617 functions 2025-07-16 07:05:15,906 [root] DEBUG: 1292: WoW64 detected: 64-bit ntdll base: 0x775a0000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7760b5f0, Wow64PrepareForException: 0x0 2025-07-16 07:05:15,906 [root] DEBUG: 1292: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x190000 2025-07-16 07:05:15,921 [root] INFO: Loaded monitor into process with pid 1292 2025-07-16 07:05:15,921 [root] DEBUG: 1292: caller_dispatch: Added region at 0x4A7A0000 to tracked regions list (ntdll::NtOpenThread returns to 0x4A7A732B, thread 648). 2025-07-16 07:05:15,921 [root] DEBUG: 1292: YaraScan: Scanning 0x4A7A0000, size 0x4bb2e 2025-07-16 07:05:15,921 [root] DEBUG: 1292: ProcessImageBase: Main module image at 0x4A7A0000 unmodified (entropy change 0.000000e+00) 2025-07-16 07:05:15,984 [root] DEBUG: 1292: CreateProcessHandler: Injection info set for new process 1148: C:\Windows\system32\calc.exe, ImageBase: 0x00F10000 2025-07-16 07:05:15,984 [root] INFO: Announced 32-bit process name: calc.exe pid: 1148 2025-07-16 07:05:15,984 [lib.api.process] INFO: Monitor config for process 1148: C:\tmp4xmvmnkr\dll\1148.ini 2025-07-16 07:05:16,000 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2025-07-16 07:05:16,000 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2025-07-16 07:05:16,000 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2025-07-16 07:05:16,000 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmp4xmvmnkr\dll\jvPRBN.dll, loader C:\tmp4xmvmnkr\bin\twUnfDj.exe 2025-07-16 07:05:16,000 [root] DEBUG: Loader: Injecting process 1148 (thread 2444) with C:\tmp4xmvmnkr\dll\jvPRBN.dll. 2025-07-16 07:05:16,000 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2025-07-16 07:05:16,000 [root] DEBUG: Successfully injected DLL C:\tmp4xmvmnkr\dll\jvPRBN.dll. 2025-07-16 07:05:16,031 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 1148 2025-07-16 07:05:16,031 [root] DEBUG: 1292: DLL loaded at 0x733B0000: C:\Windows\system32\apphelp (0x4c000 bytes). 2025-07-16 07:05:16,046 [root] WARNING: Received request to inject process with pid 1148, skipped alredy in inject list 2025-07-16 07:05:16,062 [root] DEBUG: 1148: Python path set to 'C:\olddocs'. 2025-07-16 07:05:16,062 [root] DEBUG: 1148: Process dumps enabled. 2025-07-16 07:05:16,062 [root] DEBUG: 1148: AMSI dumping enabled. 2025-07-16 07:05:16,062 [root] DEBUG: 1148: Dropped file limit defaulting to 100. 2025-07-16 07:05:16,078 [root] DEBUG: 1148: Disabling sleep skipping. 2025-07-16 07:05:16,078 [root] DEBUG: 1148: YaraInit: Compiled rules loaded from existing file C:\tmp4xmvmnkr\data\yara\capemon.yac 2025-07-16 07:05:16,078 [root] DEBUG: 1148: YaraScan: Scanning 0x00F10000, size 0xbfb3a 2025-07-16 07:05:16,078 [root] DEBUG: 1148: Monitor initialised: 32-bit capemon loaded in process 1148 at 0x74140000, thread 2444, image base 0xf10000, stack from 0x96000-0xa0000 2025-07-16 07:05:16,078 [root] DEBUG: 1148: Commandline: calc.exe 2025-07-16 07:05:16,093 [root] WARNING: b'Unable to place hook on GetCommandLineA' 2025-07-16 07:05:16,109 [root] DEBUG: 1148: set_hooks: Unable to hook GetCommandLineA 2025-07-16 07:05:16,109 [root] WARNING: b'Unable to place hook on GetCommandLineW' 2025-07-16 07:05:16,109 [root] DEBUG: 1148: set_hooks: Unable to hook GetCommandLineW 2025-07-16 07:05:16,109 [root] DEBUG: 1148: Hooked 615 out of 617 functions 2025-07-16 07:05:16,109 [root] DEBUG: 1148: WoW64 detected: 64-bit ntdll base: 0x775a0000, KiUserExceptionDispatcher: 0x0, NtSetContextThread: 0x7760b5f0, Wow64PrepareForException: 0x0 2025-07-16 07:05:16,109 [root] DEBUG: 1148: WoW64 workaround: KiUserExceptionDispatcher hook installed at: 0x1a0000 2025-07-16 07:05:16,125 [root] INFO: Loaded monitor into process with pid 1148 2025-07-16 07:05:16,125 [root] DEBUG: 1148: caller_dispatch: Added region at 0x00F10000 to tracked regions list (ntdll::NtOpenKey returns to 0x00F23433, thread 2444). 2025-07-16 07:05:16,125 [root] DEBUG: 1148: YaraScan: Scanning 0x00F10000, size 0xbfb3a 2025-07-16 07:05:16,125 [root] DEBUG: 1148: ProcessImageBase: Main module image at 0x00F10000 unmodified (entropy change 0.000000e+00) 2025-07-16 07:05:16,140 [root] DEBUG: 1148: DLL loaded at 0x73E80000: C:\Windows\SysWOW64\WindowsCodecs (0x130000 bytes). 2025-07-16 07:05:16,140 [root] DEBUG: 1148: DLL loaded at 0x74A70000: C:\Windows\SysWOW64\dwmapi (0x13000 bytes). 2025-07-16 07:05:16,187 [root] DEBUG: 1148: DLL loaded at 0x77240000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes). 2025-07-16 07:05:16,375 [root] DEBUG: 1148: DLL loaded at 0x74510000: C:\Windows\SysWOW64\oleacc (0x3c000 bytes). 2025-07-16 07:05:18,907 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-16 07:05:21,719 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:05:21,969 [lib.common.results] INFO: File 1752674721907226500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:05:21,969 [lib.common.results] INFO: File 1752674721907226500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:05:21,985 [lib.common.results] INFO: File 1752674721922851500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:05:21,985 [lib.common.results] INFO: File 1752674721907226500.Application.evtx.gz size is 6850, Max size: 100000000 2025-07-16 07:05:22,032 [lib.common.results] INFO: File 1752674721969726500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:05:22,032 [lib.common.results] INFO: File 1752674721969726500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:05:22,047 [lib.common.results] INFO: File 1752674721969726500.System.evtx.gz size is 8822, Max size: 100000000 2025-07-16 07:05:22,063 [lib.common.results] INFO: File 1752674721969726500.Security.evtx.gz size is 15348, Max size: 100000000 2025-07-16 07:05:22,079 [lib.common.results] INFO: File 1752674722032226500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:05:23,985 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674723.9853513.sysmon.evtx.gz to host 2025-07-16 07:05:23,985 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 14252, Max size: 100000000 2025-07-16 07:05:29,829 [lib.common.results] INFO: File c:\olddocs\1752674724829.saz size is 4604, Max size: 100000000 2025-07-16 07:05:29,844 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:05:37,110 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:05:37,329 [lib.common.results] INFO: File 1752674737282226500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:05:37,344 [lib.common.results] INFO: File 1752674737282226500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:05:37,344 [lib.common.results] INFO: File 1752674737282226500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:05:37,344 [lib.common.results] INFO: File 1752674737282226500.Application.evtx.gz size is 6784, Max size: 100000000 2025-07-16 07:05:37,391 [lib.common.results] INFO: File 1752674737329101500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:05:37,391 [lib.common.results] INFO: File 1752674737329101500.Security.evtx.gz size is 7066, Max size: 100000000 2025-07-16 07:05:37,407 [lib.common.results] INFO: File 1752674737329101500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:05:37,407 [lib.common.results] INFO: File 1752674737344726500.System.evtx.gz size is 8495, Max size: 100000000 2025-07-16 07:05:37,438 [lib.common.results] INFO: File 1752674737391601500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:05:39,000 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-16 07:05:44,063 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674744.0634766.sysmon.evtx.gz to host 2025-07-16 07:05:44,063 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5728, Max size: 100000000 2025-07-16 07:05:49,938 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:05:52,469 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:05:52,688 [lib.common.results] INFO: File 1752674752641601500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:05:52,688 [lib.common.results] INFO: File 1752674752641601500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:05:52,704 [lib.common.results] INFO: File 1752674752641601500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:05:52,704 [lib.common.results] INFO: File 1752674752641601500.Application.evtx.gz size is 6784, Max size: 100000000 2025-07-16 07:05:52,735 [lib.common.results] INFO: File 1752674752688476500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:05:52,735 [lib.common.results] INFO: File 1752674752688476500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:05:52,750 [lib.common.results] INFO: File 1752674752688476500.Security.evtx.gz size is 6851, Max size: 100000000 2025-07-16 07:05:52,750 [lib.common.results] INFO: File 1752674752704101500.System.evtx.gz size is 8386, Max size: 100000000 2025-07-16 07:05:52,782 [lib.common.results] INFO: File 1752674752735351500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:05:59,079 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-16 07:06:04,157 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674764.1572266.sysmon.evtx.gz to host 2025-07-16 07:06:04,157 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5881, Max size: 100000000 2025-07-16 07:06:07,813 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:06:08,032 [lib.common.results] INFO: File 1752674767985351500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:06:08,032 [lib.common.results] INFO: File 1752674767985351500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:06:08,032 [lib.common.results] INFO: File 1752674767985351500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:06:08,047 [lib.common.results] INFO: File 1752674767985351500.Application.evtx.gz size is 6784, Max size: 100000000 2025-07-16 07:06:08,079 [lib.common.results] INFO: File 1752674768032226500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:06:08,094 [lib.common.results] INFO: File 1752674768032226500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:06:08,094 [lib.common.results] INFO: File 1752674768032226500.Security.evtx.gz size is 6897, Max size: 100000000 2025-07-16 07:06:08,110 [lib.common.results] INFO: File 1752674768047851500.System.evtx.gz size is 8217, Max size: 100000000 2025-07-16 07:06:08,110 [lib.common.results] INFO: File 1752674768063476500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:06:10,016 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:06:19,157 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-16 07:06:23,125 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:06:23,360 [lib.common.results] INFO: File 1752674783313476500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:06:23,375 [lib.common.results] INFO: File 1752674783313476500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:06:23,375 [lib.common.results] INFO: File 1752674783313476500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:06:23,375 [lib.common.results] INFO: File 1752674783313476500.Application.evtx.gz size is 6893, Max size: 100000000 2025-07-16 07:06:23,407 [lib.common.results] INFO: File 1752674783360351500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:06:23,407 [lib.common.results] INFO: File 1752674783360351500.Security.evtx.gz size is 6925, Max size: 100000000 2025-07-16 07:06:23,422 [lib.common.results] INFO: File 1752674783360351500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:06:23,422 [lib.common.results] INFO: File 1752674783375976500.System.evtx.gz size is 8227, Max size: 100000000 2025-07-16 07:06:23,454 [lib.common.results] INFO: File 1752674783407226500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:06:24,235 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674784.2353516.sysmon.evtx.gz to host 2025-07-16 07:06:24,235 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5930, Max size: 100000000 2025-07-16 07:06:30,110 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:06:38,485 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:06:38,704 [lib.common.results] INFO: File 1752674798657226500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:06:38,719 [lib.common.results] INFO: File 1752674798657226500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:06:38,735 [lib.common.results] INFO: File 1752674798657226500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:06:38,735 [lib.common.results] INFO: File 1752674798657226500.Application.evtx.gz size is 6825, Max size: 100000000 2025-07-16 07:06:38,750 [lib.common.results] INFO: File 1752674798704101500.Security.evtx.gz size is 6896, Max size: 100000000 2025-07-16 07:06:38,766 [lib.common.results] INFO: File 1752674798704101500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:06:38,766 [lib.common.results] INFO: File 1752674798704101500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:06:38,766 [lib.common.results] INFO: File 1752674798704101500.System.evtx.gz size is 8217, Max size: 100000000 2025-07-16 07:06:38,782 [lib.common.results] INFO: File 1752674798750976500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:06:39,250 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-16 07:06:44,313 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674804.3134766.sysmon.evtx.gz to host 2025-07-16 07:06:44,313 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5357, Max size: 100000000 2025-07-16 07:06:50,219 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:06:53,829 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:06:54,063 [lib.common.results] INFO: File 1752674814032226500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:06:54,079 [lib.common.results] INFO: File 1752674814016601500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:06:54,079 [lib.common.results] INFO: File 1752674814016601500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:06:54,079 [lib.common.results] INFO: File 1752674814016601500.Application.evtx.gz size is 6825, Max size: 100000000 2025-07-16 07:06:54,125 [lib.common.results] INFO: File 1752674814063476500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:06:54,125 [lib.common.results] INFO: File 1752674814063476500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:06:54,125 [lib.common.results] INFO: File 1752674814063476500.Security.evtx.gz size is 6870, Max size: 100000000 2025-07-16 07:06:54,141 [lib.common.results] INFO: File 1752674814079101500.System.evtx.gz size is 8200, Max size: 100000000 2025-07-16 07:06:54,157 [lib.common.results] INFO: File 1752674814125976500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:06:59,344 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-16 07:07:04,407 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674824.4072266.sysmon.evtx.gz to host 2025-07-16 07:07:04,407 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5557, Max size: 100000000 2025-07-16 07:07:09,188 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:07:09,407 [lib.common.results] INFO: File 1752674829375976500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:07:09,422 [lib.common.results] INFO: File 1752674829360351500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:07:09,438 [lib.common.results] INFO: File 1752674829360351500.Application.evtx.gz size is 6825, Max size: 100000000 2025-07-16 07:07:09,438 [lib.common.results] INFO: File 1752674829375976500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:07:09,454 [lib.common.results] INFO: File 1752674829407226500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:07:09,469 [lib.common.results] INFO: File 1752674829422851500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:07:09,469 [lib.common.results] INFO: File 1752674829422851500.System.evtx.gz size is 8228, Max size: 100000000 2025-07-16 07:07:09,485 [lib.common.results] INFO: File 1752674829407226500.Security.evtx.gz size is 6883, Max size: 100000000 2025-07-16 07:07:09,500 [lib.common.results] INFO: File 1752674829454101500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:07:10,329 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:07:19,438 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-16 07:07:24,532 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:07:24,532 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674844.5322266.sysmon.evtx.gz to host 2025-07-16 07:07:24,547 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5744, Max size: 100000000 2025-07-16 07:07:24,766 [lib.common.results] INFO: File 1752674844719726500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:07:24,766 [lib.common.results] INFO: File 1752674844719726500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:07:24,766 [lib.common.results] INFO: File 1752674844719726500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:07:24,766 [lib.common.results] INFO: File 1752674844719726500.Application.evtx.gz size is 6825, Max size: 100000000 2025-07-16 07:07:24,829 [lib.common.results] INFO: File 1752674844766601500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:07:24,829 [lib.common.results] INFO: File 1752674844766601500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:07:24,829 [lib.common.results] INFO: File 1752674844766601500.Security.evtx.gz size is 6827, Max size: 100000000 2025-07-16 07:07:24,829 [lib.common.results] INFO: File 1752674844766601500.System.evtx.gz size is 8202, Max size: 100000000 2025-07-16 07:07:24,860 [lib.common.results] INFO: File 1752674844813476500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:07:30,422 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:07:39,563 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2025-07-16 07:07:39,891 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:07:40,125 [lib.common.results] INFO: File 1752674860079101500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:07:40,141 [lib.common.results] INFO: File 1752674860079101500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:07:40,141 [lib.common.results] INFO: File 1752674860079101500.Application.evtx.gz size is 6825, Max size: 100000000 2025-07-16 07:07:40,141 [lib.common.results] INFO: File 1752674860079101500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:07:40,157 [lib.common.results] INFO: File 1752674860110351500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:07:40,188 [lib.common.results] INFO: File 1752674860125976500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:07:40,188 [lib.common.results] INFO: File 1752674860125976500.Security.evtx.gz size is 6837, Max size: 100000000 2025-07-16 07:07:40,188 [lib.common.results] INFO: File 1752674860125976500.System.evtx.gz size is 8201, Max size: 100000000 2025-07-16 07:07:40,204 [lib.common.results] INFO: File 1752674860157226500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:07:44,657 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674864.6572266.sysmon.evtx.gz to host 2025-07-16 07:07:44,657 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5445, Max size: 100000000 2025-07-16 07:07:46,672 [root] INFO: Analysis timeout hit, terminating analysis 2025-07-16 07:07:46,672 [lib.api.process] INFO: Terminate event set for process 2708 2025-07-16 07:07:46,672 [root] DEBUG: 2708: Terminate Event: Attempting to dump process 2708 2025-07-16 07:07:46,672 [root] DEBUG: 2708: DoProcessDump: Skipping process dump as code is identical on disk. 2025-07-16 07:07:46,672 [lib.api.process] INFO: Termination confirmed for process 2708 2025-07-16 07:07:46,672 [root] INFO: Terminate event set for process 2708 2025-07-16 07:07:46,672 [root] DEBUG: 2708: Terminate Event: monitor shutdown complete for process 2708 2025-07-16 07:07:46,688 [lib.api.process] INFO: Terminate event set for process 1292 2025-07-16 07:07:46,688 [root] DEBUG: 1292: Terminate Event: Attempting to dump process 1292 2025-07-16 07:07:46,688 [root] DEBUG: 1292: DoProcessDump: Skipping process dump as code is identical on disk. 2025-07-16 07:07:46,688 [lib.api.process] INFO: Termination confirmed for process 1292 2025-07-16 07:07:46,688 [root] DEBUG: 1292: Terminate Event: monitor shutdown complete for process 1292 2025-07-16 07:07:46,688 [root] INFO: Terminate event set for process 1292 2025-07-16 07:07:46,688 [lib.api.process] INFO: Terminate event set for process 1148 2025-07-16 07:07:46,688 [root] DEBUG: 1148: Terminate Event: Attempting to dump process 1148 2025-07-16 07:07:46,688 [root] DEBUG: 1148: DoProcessDump: Skipping process dump as code is identical on disk. 2025-07-16 07:07:46,704 [lib.api.process] INFO: Termination confirmed for process 1148 2025-07-16 07:07:46,704 [root] DEBUG: 1148: Terminate Event: monitor shutdown complete for process 1148 2025-07-16 07:07:46,704 [root] INFO: Terminate event set for process 1148 2025-07-16 07:07:46,704 [root] INFO: Created shutdown mutex 2025-07-16 07:07:47,704 [root] INFO: Shutting down package 2025-07-16 07:07:47,704 [root] INFO: Stopping auxiliary modules 2025-07-16 07:07:47,704 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2025-07-16 07:07:47,704 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2025-07-16 07:07:47,719 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:07:47,922 [lib.common.results] INFO: File 1752674867875976500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:07:47,922 [lib.common.results] INFO: File 1752674867875976500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:07:47,922 [lib.common.results] INFO: File 1752674867875976500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:07:47,922 [lib.common.results] INFO: File 1752674867875976500.Application.evtx.gz size is 6825, Max size: 100000000 2025-07-16 07:07:47,954 [lib.common.results] INFO: File 1752674867922851500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:07:47,969 [lib.common.results] INFO: File 1752674867922851500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:07:47,985 [lib.common.results] INFO: File 1752674867922851500.Security.evtx.gz size is 6927, Max size: 100000000 2025-07-16 07:07:48,000 [lib.common.results] INFO: File 1752674867922851500.System.evtx.gz size is 8218, Max size: 100000000 2025-07-16 07:07:48,016 [lib.common.results] INFO: File 1752674867954101500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:07:50,516 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:07:53,110 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2025-07-16 07:07:53,110 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2025-07-16 07:07:55,235 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2025-07-16 07:07:55,454 [lib.common.results] INFO: File 1752674875407226500.HardwareEvents.evtx.gz size is 504, Max size: 100000000 2025-07-16 07:07:55,469 [lib.common.results] INFO: File 1752674875407226500.Application.evtx.gz size is 6825, Max size: 100000000 2025-07-16 07:07:55,469 [lib.common.results] INFO: File 1752674875422851500.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2025-07-16 07:07:55,500 [lib.common.results] INFO: File 1752674875438476500.KeyManagementService.evtx.gz size is 261, Max size: 100000000 2025-07-16 07:07:55,500 [lib.common.results] INFO: File 1752674875454101500.OAlerts.evtx.gz size is 246, Max size: 100000000 2025-07-16 07:07:55,516 [lib.common.results] INFO: File 1752674875454101500.Security.evtx.gz size is 6902, Max size: 100000000 2025-07-16 07:07:55,516 [lib.common.results] INFO: File 1752674875469726500.Setup.evtx.gz size is 248, Max size: 100000000 2025-07-16 07:07:55,547 [lib.common.results] INFO: File 1752674875500976500.WindowsPowerShell.evtx.gz size is 258, Max size: 100000000 2025-07-16 07:07:55,563 [lib.common.results] INFO: File 1752674875500976500.System.evtx.gz size is 8235, Max size: 100000000 2025-07-16 07:07:58,188 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1752674878.1884763.sysmon.evtx.gz to host 2025-07-16 07:07:58,188 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5346, Max size: 100000000 2025-07-16 07:07:58,204 [root] INFO: Finishing auxiliary modules 2025-07-16 07:07:58,204 [root] INFO: Shutting down pipe server and dumping dropped files 2025-07-16 07:07:58,204 [root] WARNING: Folder at path "C:\NNxDoWybNW\debugger" does not exist, skipping 2025-07-16 07:07:58,204 [root] WARNING: Folder at path "C:\NNxDoWybNW\tlsdump" does not exist, skipping 2025-07-16 07:07:58,204 [root] INFO: Analysis completed
Name | Label | Manager | Started On | Shutdown On | Route |
---|---|---|---|---|---|
win7office2k3flash2800137TWN3H106 | win7office2k3flash2800137TWN3H106 | KVM | 2025-07-16 14:05:05 | 2025-07-16 14:08:08 | internet |
File Name | opencalc.bat |
---|---|
File Size | 9 bytes |
File Type | ASCII text |
MD5 | c61463921d79e07e461fd0e731f72619 |
SHA1 | 4c70ac1680d2c4bdb145d5be5dad5230b20805f2 |
SHA256 | 7fdf626e0603f5bc2375a7bbc92c94a21088841c0a03cf3c5f12aa9c680ce4e6 |
SHA512 | 1a0ada808250064beaafad6095f6d12b0a26ddeb0aff616205986dc4db7c4e72686701945bfb948a141a5f6db0d0e6cec29cd2fddc59ba07a9279a93a7e3541e |
SHA3-384 | b61a7654e9f55c8d3f21ad0e18325fb9d987f7baece23caa7b5803b1ed18cc0603d1cc5a57f344355e3e08a0950fcd36 |
CRC32 | 8D648BCF |
Ssdeep | 3:FGLAdK:FbK |
File
|
|
calc.exe |
|
Direct | IP | Country Name |
---|---|---|
Y | 8.8.8.8 [VT] | United States |
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP