| Category | Package | Started | Completed | Duration | Options | Log | MalScore |
|---|---|---|---|---|---|---|---|
| FILE | xls | 2026-04-14 09:23:00 | 2026-04-14 09:26:08 | 188 seconds | Show Options | Show Log | 0.5 |
procdump=1
amsidump=1
2025-12-02 01:31:19,062 [root] INFO: Date set to: 20260414T02:22:59, timeout set to: 150 2026-04-14 03:22:59,031 [root] DEBUG: Starting analyzer from: C:\tmpn7j73yx1 2026-04-14 03:22:59,031 [root] DEBUG: Storing results at: C:\bcBckJLx 2026-04-14 03:22:59,031 [root] DEBUG: Pipe server name: \\.\PIPE\XSkmScXT 2026-04-14 03:22:59,031 [root] DEBUG: Python path: C:\olddocs 2026-04-14 03:22:59,031 [root] INFO: Analysis package "xls" has been specified 2026-04-14 03:22:59,031 [root] DEBUG: Importing analysis package "xls"... 2026-04-14 03:22:59,046 [root] DEBUG: Initializing analysis package "xls"... 2026-04-14 03:22:59,046 [root] INFO: Analyzer: Package modules.packages.xls does not specify a DLL option 2026-04-14 03:22:59,046 [root] INFO: Analyzer: Package modules.packages.xls does not specify a DLL_64 option 2026-04-14 03:22:59,046 [root] INFO: Analyzer: Package modules.packages.xls does not specify a loader option 2026-04-14 03:22:59,046 [root] INFO: Analyzer: Package modules.packages.xls does not specify a loader_64 option 2026-04-14 03:22:59,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2026-04-14 03:22:59,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2026-04-14 03:22:59,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2026-04-14 03:22:59,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2026-04-14 03:22:59,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2026-04-14 03:22:59,140 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2026-04-14 03:22:59,156 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2026-04-14 03:22:59,156 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2026-04-14 03:22:59,171 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2026-04-14 03:22:59,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-04-14 03:22:59,265 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2026-04-14 03:22:59,281 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2026-04-14 03:22:59,281 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2026-04-14 03:22:59,281 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2026-04-14 03:22:59,281 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2026-04-14 03:22:59,281 [root] DEBUG: Initializing auxiliary module "Browser"... 2026-04-14 03:22:59,281 [root] DEBUG: Started auxiliary module Browser 2026-04-14 03:22:59,281 [root] DEBUG: Initializing auxiliary module "Curtain"... 2026-04-14 03:22:59,296 [root] DEBUG: Started auxiliary module Curtain 2026-04-14 03:22:59,296 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2026-04-14 03:22:59,359 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2026-04-14 03:22:59,359 [root] DEBUG: Started auxiliary module DefaultApps 2026-04-14 03:22:59,359 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2026-04-14 03:22:59,359 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2026-04-14 03:22:59,359 [modules.auxiliary.digisig] INFO: xls 2026-04-14 03:22:59,359 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2026-04-14 03:22:59,359 [root] DEBUG: Started auxiliary module DigiSig 2026-04-14 03:22:59,359 [root] DEBUG: Initializing auxiliary module "Disguise"... 2026-04-14 03:22:59,812 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2026-04-14 03:22:59,812 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2026-04-14 03:22:59,812 [root] DEBUG: Initializing auxiliary module "Evtx"... 2026-04-14 03:22:59,812 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpn7j73yx1\bin\auditpol.csv 2026-04-14 03:23:00,000 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:23:00,890 [root] DEBUG: Started auxiliary module Evtx 2026-04-14 03:23:00,890 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2026-04-14 03:23:00,906 [modules.auxiliary.fiddler] INFO: fiddler package: xls 2026-04-14 03:23:00,906 [root] DEBUG: Started auxiliary module Fiddler 2026-04-14 03:23:00,906 [root] DEBUG: Initializing auxiliary module "Human"... 2026-04-14 03:23:00,906 [root] DEBUG: Started auxiliary module Human 2026-04-14 03:23:00,906 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2026-04-14 03:23:00,906 [root] DEBUG: Started auxiliary module Screenshots 2026-04-14 03:23:00,906 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2026-04-14 03:23:00,906 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2026-04-14 03:23:00,906 [root] DEBUG: Started auxiliary module Sysmon 2026-04-14 03:23:00,906 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2026-04-14 03:23:00,906 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 560 2026-04-14 03:23:00,921 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2026-04-14 03:23:00,921 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2026-04-14 03:23:00,921 [lib.api.process] INFO: Monitor config for process 560: C:\tmpn7j73yx1\dll\560.ini 2026-04-14 03:23:03,046 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2026-04-14 03:23:03,937 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2026-04-14 03:23:03,937 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2026-04-14 03:23:03,937 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2026-04-14 03:23:03,937 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2026-04-14 03:23:03,937 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2026-04-14 03:23:03,937 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2026-04-14 03:23:03,937 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2026-04-14 03:23:03,937 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpn7j73yx1\dll\MmxrzX.dll, loader C:\tmpn7j73yx1\bin\QAnKRhcx.exe 2026-04-14 03:23:03,968 [root] DEBUG: Loader: IAT patching disabled. 2026-04-14 03:23:03,968 [root] DEBUG: Loader: Injecting process 560 with C:\tmpn7j73yx1\dll\MmxrzX.dll. 2026-04-14 03:23:04,015 [root] DEBUG: 560: Python path set to 'C:\olddocs'. 2026-04-14 03:23:04,015 [root] DEBUG: 560: Disabling sleep skipping. 2026-04-14 03:23:04,015 [root] DEBUG: 560: Process dumps enabled. 2026-04-14 03:23:04,015 [root] DEBUG: 560: AMSI dumping enabled. 2026-04-14 03:23:04,015 [root] DEBUG: 560: Monitor config - unrecognised key office. 2026-04-14 03:23:04,015 [root] DEBUG: 560: In-monitor YARA scans disabled. 2026-04-14 03:23:04,015 [root] DEBUG: 560: TLS secret dump mode enabled. 2026-04-14 03:23:04,031 [root] DEBUG: 560: Monitor initialised: 64-bit capemon loaded in process 560 at 0x000007FEEDC00000, thread 2464, image base 0x00000000FF510000, stack from 0x00000000014A2000-0x00000000014B0000 2026-04-14 03:23:04,031 [root] DEBUG: 560: Commandline: C:\Windows\system32\lsass.exe 2026-04-14 03:23:04,031 [root] DEBUG: 560: Hooked 5 out of 5 functions 2026-04-14 03:23:04,046 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-04-14 03:23:04,046 [root] DEBUG: Successfully injected DLL C:\tmpn7j73yx1\dll\MmxrzX.dll. 2026-04-14 03:23:04,046 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 560 2026-04-14 03:23:04,046 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2026-04-14 03:23:04,046 [root] DEBUG: Initializing auxiliary module "Usage"... 2026-04-14 03:23:04,046 [root] DEBUG: Started auxiliary module Usage 2026-04-14 03:23:06,703 [root] INFO: Restarting WMI Service 2026-04-14 03:23:13,062 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:23:13,828 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft Office\Office15\EXCEL.EXE" with arguments ""C:\Users\pgabriel\AppData\Local\Temp\Rothmans Table 3.xlsx" /dde" with pid 2868 2026-04-14 03:23:13,828 [lib.api.process] INFO: Monitor config for process 2868: C:\tmpn7j73yx1\dll\2868.ini 2026-04-14 03:23:13,828 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2026-04-14 03:23:13,828 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2026-04-14 03:23:13,828 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2026-04-14 03:23:13,828 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2026-04-14 03:23:13,828 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2026-04-14 03:23:13,828 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2026-04-14 03:23:13,828 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpn7j73yx1\dll\mJTGoC.dll, loader C:\tmpn7j73yx1\bin\kCZJmlx.exe 2026-04-14 03:23:13,843 [root] DEBUG: Loader: IAT patching disabled. 2026-04-14 03:23:13,843 [root] DEBUG: Loader: Injecting process 2868 (thread 956) with C:\tmpn7j73yx1\dll\mJTGoC.dll. 2026-04-14 03:23:13,843 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued. 2026-04-14 03:23:13,843 [root] DEBUG: Successfully injected DLL C:\tmpn7j73yx1\dll\mJTGoC.dll. 2026-04-14 03:23:13,859 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2868 2026-04-14 03:23:15,859 [lib.api.process] INFO: Successfully resumed process with pid 2868 2026-04-14 03:23:15,890 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:23:16,203 [lib.common.results] INFO: File 1776162196093750000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:23:16,203 [lib.common.results] INFO: File 1776162196093750000.Application.evtx.gz size is 6957, Max size: 100000000 2026-04-14 03:23:16,218 [root] DEBUG: 2868: Python path set to 'C:\olddocs'. 2026-04-14 03:23:16,218 [root] DEBUG: 2868: Disabling sleep skipping. 2026-04-14 03:23:16,218 [lib.common.results] INFO: File 1776162196125000000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:23:16,265 [lib.common.results] INFO: File 1776162196203125000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 03:23:16,281 [lib.common.results] INFO: File 1776162196171875000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:23:16,281 [lib.common.results] INFO: File 1776162196218750000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:23:16,296 [lib.common.results] INFO: File 1776162196203125000.Security.evtx.gz size is 15306, Max size: 100000000 2026-04-14 03:23:16,312 [root] DEBUG: 2868: Microsoft Office settings enabled. 2026-04-14 03:23:16,328 [root] DEBUG: 2868: Monitor initialised: 32-bit capemon loaded in process 2868 at 0x725f0000, thread 956, image base 0xbd0000, stack from 0x263000-0x270000 2026-04-14 03:23:16,328 [root] DEBUG: 2868: Commandline: "C:\Program Files (x86)\Microsoft Office\Office15\EXCEL.EXE" "C:\Users\pgabriel\AppData\Local\Temp\Rothmans Table 3.xlsx" /dde 2026-04-14 03:23:16,328 [root] DEBUG: 2868: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft Office\Office15\oart.dll 2026-04-14 03:23:16,328 [lib.common.results] INFO: File 1776162196265625000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:23:16,343 [lib.common.results] INFO: File 1776162196265625000.System.evtx.gz size is 8689, Max size: 100000000 2026-04-14 03:23:16,359 [root] DEBUG: 2868: Hooked 456 out of 456 functions 2026-04-14 03:23:16,484 [root] INFO: Loaded monitor into process with pid 2868 2026-04-14 03:23:16,500 [root] DEBUG: 2868: DLL loaded at 0x6F7B0000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso (0x18e4000 bytes). 2026-04-14 03:23:16,500 [root] DEBUG: 2868: DLL loaded at 0x73440000: C:\Windows\system32\MSIMG32 (0x5000 bytes). 2026-04-14 03:23:16,515 [root] DEBUG: 2868: DLL loaded at 0x73510000: C:\Windows\system32\uxtheme (0x80000 bytes). 2026-04-14 03:23:16,515 [root] DEBUG: 2868: DLL loaded at 0x73750000: C:\Windows\system32\WTSAPI32 (0xd000 bytes). 2026-04-14 03:23:16,515 [root] DEBUG: 2868: DLL loaded at 0x74110000: C:\Windows\system32\WINSTA (0x29000 bytes). 2026-04-14 03:23:16,531 [root] DEBUG: 2868: DLL loaded at 0x73DE0000: C:\Windows\system32\dxgi (0x4c000 bytes). 2026-04-14 03:23:16,531 [root] DEBUG: 2868: DLL loaded at 0x73760000: C:\Windows\system32\VERSION (0x9000 bytes). 2026-04-14 03:23:16,531 [root] DEBUG: 2868: DLL loaded at 0x73DC0000: C:\Windows\system32\dwmapi (0x13000 bytes). 2026-04-14 03:23:16,531 [root] DEBUG: 2868: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 03:23:16,546 [root] DEBUG: 2868: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 03:23:16,546 [root] DEBUG: 2868: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 03:23:16,546 [root] DEBUG: 2868: DLL loaded at 0x75730000: C:\Windows\syswow64\WINTRUST (0x2f000 bytes). 2026-04-14 03:23:16,562 [root] DEBUG: 2868: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 03:23:16,562 [root] DEBUG: 2868: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 03:23:16,562 [root] DEBUG: 2868: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 03:23:16,562 [root] DEBUG: 2868: DLL loaded at 0x723B0000: C:\Windows\system32\msi (0x240000 bytes). 2026-04-14 03:23:16,687 [root] DEBUG: 2868: DLL loaded at 0x73590000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32 (0x19e000 bytes). 2026-04-14 03:23:16,781 [root] DEBUG: 2868: DLL loaded at 0x73D90000: C:\Windows\system32\d3d10_1 (0x2c000 bytes). 2026-04-14 03:23:16,781 [root] DEBUG: 2868: DLL loaded at 0x73D40000: C:\Windows\system32\d3d10_1core (0x41000 bytes). 2026-04-14 03:23:16,781 [root] DEBUG: 2868: DLL loaded at 0x6F630000: C:\Windows\system32\d3d11 (0x175000 bytes). 2026-04-14 03:23:16,796 [root] DEBUG: 2868: DLL loaded at 0x6F440000: C:\Windows\system32\D3D10Warp (0x1e9000 bytes). 2026-04-14 03:23:16,796 [root] DEBUG: 2868: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 03:23:16,796 [root] DEBUG: 2868: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 03:23:16,796 [root] DEBUG: 2868: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 03:23:16,812 [root] DEBUG: 2868: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 03:23:16,812 [root] DEBUG: 2868: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 03:23:16,812 [root] DEBUG: 2868: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 03:23:16,828 [root] DEBUG: 2868: DLL loaded at 0x757C0000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 03:23:16,828 [root] DEBUG: 2868: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 03:23:16,828 [root] DEBUG: 2868: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 03:23:16,968 [root] DEBUG: 2868: DLL loaded at 0x731B0000: C:\Windows\system32\mscoree (0x4a000 bytes). 2026-04-14 03:23:16,968 [root] DEBUG: 2868: DLL loaded at 0x6F030000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes). 2026-04-14 03:23:16,984 [root] DEBUG: 2868: DLL loaded at 0x6EF70000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\adal (0xb5000 bytes). 2026-04-14 03:23:17,000 [root] DEBUG: 2868: DLL loaded at 0x71E50000: C:\Windows\system32\WINHTTP (0x58000 bytes). 2026-04-14 03:23:17,000 [root] DEBUG: 2868: DLL loaded at 0x73160000: C:\Windows\system32\webio (0x50000 bytes). 2026-04-14 03:23:17,015 [root] DEBUG: 2868: DLL loaded at 0x75C70000: C:\Windows\syswow64\WININET (0x1e4000 bytes). 2026-04-14 03:23:17,015 [root] DEBUG: 2868: DLL loaded at 0x75F70000: C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes). 2026-04-14 03:23:17,015 [root] DEBUG: 2868: DLL loaded at 0x75720000: C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes). 2026-04-14 03:23:17,015 [root] DEBUG: 2868: DLL loaded at 0x75A20000: C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes). 2026-04-14 03:23:17,015 [root] DEBUG: 2868: DLL loaded at 0x752B0000: C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes). 2026-04-14 03:23:17,015 [root] DEBUG: 2868: DLL loaded at 0x77020000: C:\Windows\syswow64\normaliz (0x3000 bytes). 2026-04-14 03:23:17,015 [root] DEBUG: 2868: DLL loaded at 0x753C0000: C:\Windows\syswow64\iertutil (0x232000 bytes). 2026-04-14 03:23:17,031 [root] DEBUG: 2868: DLL loaded at 0x77300000: C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes). 2026-04-14 03:23:17,031 [root] DEBUG: 2868: DLL loaded at 0x77310000: C:\Windows\syswow64\USERENV (0x17000 bytes). 2026-04-14 03:23:17,031 [root] DEBUG: 2868: DLL loaded at 0x753B0000: C:\Windows\syswow64\profapi (0xb000 bytes). 2026-04-14 03:23:17,031 [root] DEBUG: 2868: DLL loaded at 0x74750000: C:\Windows\system32\Secur32 (0x8000 bytes). 2026-04-14 03:23:17,109 [root] DEBUG: 2868: DLL loaded at 0x752D0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes). 2026-04-14 03:23:17,109 [root] DEBUG: 2868: DLL loaded at 0x6EF10000: C:\Windows\System32\netprofm (0x5a000 bytes). 2026-04-14 03:23:17,125 [root] DEBUG: 2868: DLL loaded at 0x74100000: C:\Windows\System32\nlaapi (0x10000 bytes). 2026-04-14 03:23:17,125 [root] DEBUG: 2868: DLL loaded at 0x73240000: C:\Windows\system32\CRYPTSP (0x17000 bytes). 2026-04-14 03:23:17,125 [root] DEBUG: 2868: DLL loaded at 0x73200000: C:\Windows\system32\rsaenh (0x3b000 bytes). 2026-04-14 03:23:17,140 [root] DEBUG: 2868: DLL loaded at 0x73C10000: C:\Windows\system32\RpcRtRemote (0xe000 bytes). 2026-04-14 03:23:17,140 [root] DEBUG: 2868: DLL loaded at 0x74090000: C:\Windows\System32\npmproxy (0x8000 bytes). 2026-04-14 03:23:17,312 [root] DEBUG: 2868: DLL loaded at 0x6ED80000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20 (0x18e000 bytes). 2026-04-14 03:23:17,390 [root] DEBUG: 2868: DLL loaded at 0x73D10000: C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppc (0x2d000 bytes). 2026-04-14 03:23:17,406 [root] DEBUG: 2868: DLL loaded at 0x69F50000: C:\Windows\system32\DWrite (0x135000 bytes). 2026-04-14 03:23:17,578 [root] DEBUG: 2868: DLL loaded at 0x760F0000: C:\Windows\syswow64\SHELL32 (0xc4a000 bytes). 2026-04-14 03:23:17,625 [root] DEBUG: 2868: DLL loaded at 0x69F20000: C:\Windows\system32\XmlLite (0x2f000 bytes). 2026-04-14 03:23:17,703 [root] DEBUG: 2868: DLL loaded at 0x757C0000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes). 2026-04-14 03:23:17,703 [root] DEBUG: 2868: DLL loaded at 0x75B40000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 03:23:17,703 [root] DEBUG: 2868: DLL loaded at 0x75B20000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 03:23:17,703 [root] DEBUG: 2868: DLL loaded at 0x69E20000: C:\Windows\system32\propsys (0xf5000 bytes). 2026-04-14 03:23:17,703 [root] DEBUG: 2868: DLL loaded at 0x73460000: C:\Windows\system32\ntmarta (0x21000 bytes). 2026-04-14 03:23:17,718 [root] DEBUG: 2868: DLL loaded at 0x751C0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes). 2026-04-14 03:23:17,765 [root] DEBUG: 2868: DLL loaded at 0x770E0000: C:\Windows\SysWOW64\urlmon (0x14a000 bytes). 2026-04-14 03:23:17,765 [root] DEBUG: 2868: DLL loaded at 0x772F0000: C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes). 2026-04-14 03:23:17,781 [root] DEBUG: 2868: DLL loaded at 0x73390000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes). 2026-04-14 03:23:17,828 [root] DEBUG: 2868: DLL loaded at 0x69E00000: C:\Windows\system32\MPR (0x12000 bytes). 2026-04-14 03:23:17,890 [root] DEBUG: 2868: DLL loaded at 0x69CA0000: C:\Windows\System32\msxml6 (0x158000 bytes). 2026-04-14 03:23:18,000 [root] DEBUG: 2868: DLL loaded at 0x69B70000: C:\Windows\system32\WindowsCodecs (0x130000 bytes). 2026-04-14 03:23:18,015 [root] DEBUG: 2868: DLL loaded at 0x69B30000: C:\Windows\system32\WINMM (0x32000 bytes). 2026-04-14 03:23:18,046 [root] DEBUG: 2868: DLL loaded at 0x69AD0000: C:\Windows\system32\WINSPOOL.DRV (0x51000 bytes). 2026-04-14 03:23:18,062 [root] DEBUG: 2868: CreateProcessHandler: Injection info set for new process 2908: C:\Windows\splwow64.exe, ImageBase: 0xFF870000 2026-04-14 03:23:18,062 [root] INFO: Announced 64-bit process name: splwow64.exe pid: 2908 2026-04-14 03:23:18,062 [root] DEBUG: 2868: DLL loaded at 0x733F0000: C:\Windows\system32\apphelp (0x4c000 bytes). 2026-04-14 03:23:18,078 [root] WARNING: Received request to inject process with pid 2908, skipped alredy in inject list 2026-04-14 03:23:18,156 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162198.15625.sysmon.evtx.gz to host 2026-04-14 03:23:18,156 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 8795, Max size: 100000000 2026-04-14 03:23:18,625 [root] DEBUG: 2868: DLL loaded at 0x69AC0000: C:\Windows\system32\msimtf (0xb000 bytes). 2026-04-14 03:23:18,625 [root] DEBUG: 2868: set_hooks_by_export_directory: Hooked 0 out of 456 functions 2026-04-14 03:23:18,625 [root] DEBUG: 2868: DLL loaded at 0x69AB0000: C:\Program Files (x86)\Microsoft Office\Office15\MSOSTYLE (0xa000 bytes). 2026-04-14 03:23:18,985 [modules.auxiliary.human] INFO: Found button "&Continue", clicking it 2026-04-14 03:23:22,258 [root] DEBUG: 2868: DLL loaded at 0x69A80000: C:\Windows\system32\POWRPROF (0x25000 bytes). 2026-04-14 03:23:24,024 [lib.common.results] INFO: File c:\olddocs\1776162199032.saz size is 4604, Max size: 100000000 2026-04-14 03:23:24,040 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:23:26,383 [root] DEBUG: 2868: DLL loaded at 0x69A50000: C:\Windows\system32\SXS (0x5f000 bytes). 2026-04-14 03:23:31,383 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:23:31,665 [lib.common.results] INFO: File 1776162211602539000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:23:31,680 [lib.common.results] INFO: File 1776162211602539000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:23:31,680 [lib.common.results] INFO: File 1776162211602539000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:23:31,680 [lib.common.results] INFO: File 1776162211586914000.Application.evtx.gz size is 6876, Max size: 100000000 2026-04-14 03:23:31,727 [lib.common.results] INFO: File 1776162211665039000.OAlerts.evtx.gz size is 1238, Max size: 100000000 2026-04-14 03:23:31,727 [lib.common.results] INFO: File 1776162211680664000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:23:31,743 [lib.common.results] INFO: File 1776162211680664000.System.evtx.gz size is 8405, Max size: 100000000 2026-04-14 03:23:31,743 [lib.common.results] INFO: File 1776162211665039000.Security.evtx.gz size is 7200, Max size: 100000000 2026-04-14 03:23:31,774 [lib.common.results] INFO: File 1776162211727539000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:23:33,180 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:23:38,305 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162218.305664.sysmon.evtx.gz to host 2026-04-14 03:23:38,305 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 69438, Max size: 100000000 2026-04-14 03:23:44,149 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:23:46,805 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:23:47,055 [lib.common.results] INFO: File 1776162226993164000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:23:47,055 [lib.common.results] INFO: File 1776162226993164000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:23:47,055 [lib.common.results] INFO: File 1776162226993164000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:23:47,071 [lib.common.results] INFO: File 1776162226993164000.Application.evtx.gz size is 6825, Max size: 100000000 2026-04-14 03:23:47,102 [lib.common.results] INFO: File 1776162227055664000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:23:47,118 [lib.common.results] INFO: File 1776162227055664000.OAlerts.evtx.gz size is 1180, Max size: 100000000 2026-04-14 03:23:47,118 [lib.common.results] INFO: File 1776162227055664000.System.evtx.gz size is 8039, Max size: 100000000 2026-04-14 03:23:47,133 [lib.common.results] INFO: File 1776162227055664000.Security.evtx.gz size is 7193, Max size: 100000000 2026-04-14 03:23:47,149 [lib.common.results] INFO: File 1776162227102539000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:23:53,321 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:23:58,415 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162238.415039.sysmon.evtx.gz to host 2026-04-14 03:23:58,415 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 7047, Max size: 100000000 2026-04-14 03:24:02,180 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:24:02,415 [lib.common.results] INFO: File 1776162242352539000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:24:02,415 [lib.common.results] INFO: File 1776162242368164000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:24:02,415 [lib.common.results] INFO: File 1776162242368164000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:24:02,415 [lib.common.results] INFO: File 1776162242352539000.Application.evtx.gz size is 6825, Max size: 100000000 2026-04-14 03:24:02,477 [lib.common.results] INFO: File 1776162242415039000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:24:02,477 [lib.common.results] INFO: File 1776162242415039000.Security.evtx.gz size is 7227, Max size: 100000000 2026-04-14 03:24:02,477 [lib.common.results] INFO: File 1776162242399414000.OAlerts.evtx.gz size is 1180, Max size: 100000000 2026-04-14 03:24:02,477 [lib.common.results] INFO: File 1776162242415039000.System.evtx.gz size is 8020, Max size: 100000000 2026-04-14 03:24:02,508 [lib.common.results] INFO: File 1776162242477539000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:24:04,243 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:24:05,149 [modules.auxiliary.human] INFO: Doing office click around. 2026-04-14 03:24:13,430 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:24:17,540 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:24:17,774 [lib.common.results] INFO: File 1776162257727539000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:24:17,790 [lib.common.results] INFO: File 1776162257727539000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:24:17,790 [lib.common.results] INFO: File 1776162257727539000.Application.evtx.gz size is 6953, Max size: 100000000 2026-04-14 03:24:17,790 [lib.common.results] INFO: File 1776162257727539000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:24:17,836 [lib.common.results] INFO: File 1776162257774414000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:24:17,836 [lib.common.results] INFO: File 1776162257774414000.OAlerts.evtx.gz size is 1180, Max size: 100000000 2026-04-14 03:24:17,836 [lib.common.results] INFO: File 1776162257774414000.Security.evtx.gz size is 7199, Max size: 100000000 2026-04-14 03:24:17,836 [lib.common.results] INFO: File 1776162257790039000.System.evtx.gz size is 8022, Max size: 100000000 2026-04-14 03:24:17,868 [lib.common.results] INFO: File 1776162257836914000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:24:18,540 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162258.5400388.sysmon.evtx.gz to host 2026-04-14 03:24:18,540 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 32815, Max size: 100000000 2026-04-14 03:24:24,336 [lib.common.results] INFO: File c:\olddocs\1776162259321.saz size is 2837, Max size: 100000000 2026-04-14 03:24:24,352 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:24:32,336 [modules.auxiliary.human] INFO: Closing Office window 2026-04-14 03:24:32,899 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:24:33,133 [lib.common.results] INFO: File 1776162273086914000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:24:33,149 [lib.common.results] INFO: File 1776162273071289000.Application.evtx.gz size is 6887, Max size: 100000000 2026-04-14 03:24:33,149 [lib.common.results] INFO: File 1776162273102539000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:24:33,149 [lib.common.results] INFO: File 1776162273102539000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:24:33,196 [lib.common.results] INFO: File 1776162273133789000.OAlerts.evtx.gz size is 1180, Max size: 100000000 2026-04-14 03:24:33,196 [lib.common.results] INFO: File 1776162273149414000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:24:33,196 [lib.common.results] INFO: File 1776162273133789000.Security.evtx.gz size is 7157, Max size: 100000000 2026-04-14 03:24:33,211 [lib.common.results] INFO: File 1776162273149414000.System.evtx.gz size is 8059, Max size: 100000000 2026-04-14 03:24:33,243 [lib.common.results] INFO: File 1776162273180664000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:24:33,336 [modules.auxiliary.human] INFO: Issuing keypress on Office dialog 2026-04-14 03:24:33,446 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\Rothmans Table 3.xlsx 2026-04-14 03:24:33,446 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\26151000 2026-04-14 03:24:33,461 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\3D74E48D.tmp size is 54017, Max size: 100000000 2026-04-14 03:24:33,555 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:24:33,680 [root] DEBUG: 2868: DLL loaded at 0x697D0000: C:\Windows\system32\POWRPROF (0x25000 bytes). 2026-04-14 03:24:33,868 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\CVREA05.tmp.cvr size is 0, Max size: 100000000 2026-04-14 03:24:33,915 [root] DEBUG: 2868: NtTerminateProcess hook: Attempting to dump process 2868 2026-04-14 03:24:33,946 [root] DEBUG: 2868: VerifyCodeSection: Executable code does not match, 0xa86f8 of 0x130f9ab matching 2026-04-14 03:24:33,961 [root] DEBUG: 2868: DoProcessDump: Code modification detected, dumping Imagebase at 0x00BD0000. 2026-04-14 03:24:33,977 [root] DEBUG: 2868: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2026-04-14 03:24:33,977 [root] DEBUG: 2868: DumpProcess: Instantiating PeParser with address: 0x00BD0000. 2026-04-14 03:24:33,977 [root] DEBUG: 2868: DumpProcess: Module entry point VA is 0x00003550. 2026-04-14 03:24:34,258 [lib.common.results] INFO: File C:\bcBckJLx\CAPE\2868_1991034241014242026 size is 25693184, Max size: 100000000 2026-04-14 03:24:34,430 [root] DEBUG: 2868: DumpProcess: Module image dump success - dump size 0x1880c00. 2026-04-14 03:24:34,477 [root] INFO: Process with pid 2868 has terminated 2026-04-14 03:24:38,649 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162278.6494138.sysmon.evtx.gz to host 2026-04-14 03:24:38,649 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 22974, Max size: 100000000 2026-04-14 03:24:44,415 [lib.common.results] INFO: File c:\olddocs\1776162279399.saz size is 2838, Max size: 100000000 2026-04-14 03:24:44,430 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:24:48,274 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:24:48,571 [lib.common.results] INFO: File 1776162288461914000.Application.evtx.gz size is 6887, Max size: 100000000 2026-04-14 03:24:48,586 [lib.common.results] INFO: File 1776162288508789000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:24:48,602 [lib.common.results] INFO: File 1776162288493164000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:24:48,602 [lib.common.results] INFO: File 1776162288524414000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:24:48,665 [lib.common.results] INFO: File 1776162288586914000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:24:48,665 [lib.common.results] INFO: File 1776162288571289000.OAlerts.evtx.gz size is 1235, Max size: 100000000 2026-04-14 03:24:48,680 [lib.common.results] INFO: File 1776162288586914000.Security.evtx.gz size is 7232, Max size: 100000000 2026-04-14 03:24:48,680 [lib.common.results] INFO: File 1776162288602539000.System.evtx.gz size is 8058, Max size: 100000000 2026-04-14 03:24:48,696 [lib.common.results] INFO: File 1776162288649414000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:24:53,649 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:24:58,727 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162298.727539.sysmon.evtx.gz to host 2026-04-14 03:24:58,743 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 26929, Max size: 100000000 2026-04-14 03:25:03,743 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:25:04,008 [lib.common.results] INFO: File 1776162303946289000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:04,008 [lib.common.results] INFO: File 1776162303915039000.Application.evtx.gz size is 6887, Max size: 100000000 2026-04-14 03:25:04,024 [lib.common.results] INFO: File 1776162303961914000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:04,071 [lib.common.results] INFO: File 1776162304008789000.OAlerts.evtx.gz size is 1176, Max size: 100000000 2026-04-14 03:25:04,071 [lib.common.results] INFO: File 1776162304008789000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:25:04,071 [lib.common.results] INFO: File 1776162303993164000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:25:04,086 [lib.common.results] INFO: File 1776162304008789000.Security.evtx.gz size is 7319, Max size: 100000000 2026-04-14 03:25:04,118 [lib.common.results] INFO: File 1776162304071289000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:25:04,133 [lib.common.results] INFO: File 1776162304071289000.System.evtx.gz size is 8058, Max size: 100000000 2026-04-14 03:25:04,493 [lib.common.results] INFO: File c:\olddocs\1776162299493.saz size is 6207, Max size: 100000000 2026-04-14 03:25:04,493 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:25:13,743 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:25:18,821 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162318.821289.sysmon.evtx.gz to host 2026-04-14 03:25:18,821 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 19589, Max size: 100000000 2026-04-14 03:25:19,165 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:25:19,446 [lib.common.results] INFO: File 1776162319383789000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:19,446 [lib.common.results] INFO: File 1776162319368164000.Application.evtx.gz size is 6887, Max size: 100000000 2026-04-14 03:25:19,461 [lib.common.results] INFO: File 1776162319383789000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:19,461 [lib.common.results] INFO: File 1776162319399414000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:25:19,508 [lib.common.results] INFO: File 1776162319446289000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:25:19,524 [lib.common.results] INFO: File 1776162319430664000.OAlerts.evtx.gz size is 1176, Max size: 100000000 2026-04-14 03:25:19,524 [lib.common.results] INFO: File 1776162319446289000.Security.evtx.gz size is 7282, Max size: 100000000 2026-04-14 03:25:19,555 [lib.common.results] INFO: File 1776162319461914000.System.evtx.gz size is 8044, Max size: 100000000 2026-04-14 03:25:19,571 [lib.common.results] INFO: File 1776162319508789000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:25:24,586 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:25:33,836 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:25:34,586 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:25:34,852 [lib.common.results] INFO: File 1776162334790039000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:34,852 [lib.common.results] INFO: File 1776162334805664000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:34,868 [lib.common.results] INFO: File 1776162334821289000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:25:34,883 [lib.common.results] INFO: File 1776162334790039000.Application.evtx.gz size is 6887, Max size: 100000000 2026-04-14 03:25:34,930 [lib.common.results] INFO: File 1776162334868164000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:25:34,930 [lib.common.results] INFO: File 1776162334868164000.Security.evtx.gz size is 7275, Max size: 100000000 2026-04-14 03:25:34,946 [lib.common.results] INFO: File 1776162334883789000.System.evtx.gz size is 8064, Max size: 100000000 2026-04-14 03:25:34,946 [lib.common.results] INFO: File 1776162334852539000.OAlerts.evtx.gz size is 1176, Max size: 100000000 2026-04-14 03:25:34,977 [lib.common.results] INFO: File 1776162334930664000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:25:38,930 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162338.9306638.sysmon.evtx.gz to host 2026-04-14 03:25:38,930 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 7745, Max size: 100000000 2026-04-14 03:25:44,649 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:25:45,899 [root] INFO: Analysis timeout hit, terminating analysis 2026-04-14 03:25:45,899 [root] INFO: Created shutdown mutex 2026-04-14 03:25:46,899 [root] INFO: Shutting down package 2026-04-14 03:25:46,899 [root] INFO: Stopping auxiliary modules 2026-04-14 03:25:46,899 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2026-04-14 03:25:46,899 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2026-04-14 03:25:46,915 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:25:47,149 [lib.common.results] INFO: File 1776162347086914000.Application.evtx.gz size is 6887, Max size: 100000000 2026-04-14 03:25:47,165 [lib.common.results] INFO: File 1776162347086914000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:47,165 [lib.common.results] INFO: File 1776162347118164000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:47,180 [lib.common.results] INFO: File 1776162347118164000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:25:47,211 [lib.common.results] INFO: File 1776162347149414000.OAlerts.evtx.gz size is 1176, Max size: 100000000 2026-04-14 03:25:47,227 [lib.common.results] INFO: File 1776162347149414000.Security.evtx.gz size is 7470, Max size: 100000000 2026-04-14 03:25:47,243 [lib.common.results] INFO: File 1776162347165039000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:25:47,258 [lib.common.results] INFO: File 1776162347180664000.System.evtx.gz size is 8062, Max size: 100000000 2026-04-14 03:25:47,258 [lib.common.results] INFO: File 1776162347211914000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:25:50,024 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 03:25:50,258 [lib.common.results] INFO: File 1776162350196289000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:50,258 [lib.common.results] INFO: File 1776162350196289000.Application.evtx.gz size is 6887, Max size: 100000000 2026-04-14 03:25:50,274 [lib.common.results] INFO: File 1776162350211914000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 03:25:50,305 [lib.common.results] INFO: File 1776162350243164000.KeyManagementService.evtx.gz size is 2070, Max size: 100000000 2026-04-14 03:25:50,321 [lib.common.results] INFO: File 1776162350258789000.OAlerts.evtx.gz size is 1176, Max size: 100000000 2026-04-14 03:25:50,336 [lib.common.results] INFO: File 1776162350258789000.Security.evtx.gz size is 7391, Max size: 100000000 2026-04-14 03:25:50,336 [lib.common.results] INFO: File 1776162350274414000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 03:25:50,352 [lib.common.results] INFO: File 1776162350305664000.System.evtx.gz size is 8058, Max size: 100000000 2026-04-14 03:25:50,368 [lib.common.results] INFO: File 1776162350321289000.WindowsPowerShell.evtx.gz size is 2223, Max size: 100000000 2026-04-14 03:25:52,336 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 03:25:52,336 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2026-04-14 03:25:53,946 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 03:25:57,399 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776162357.399414.sysmon.evtx.gz to host 2026-04-14 03:25:57,399 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 10932, Max size: 100000000 2026-04-14 03:25:57,399 [root] INFO: Finishing auxiliary modules 2026-04-14 03:25:57,399 [root] INFO: Shutting down pipe server and dumping dropped files 2026-04-14 03:25:57,399 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\Rothmans Table 3.xlsx size is 53434, Max size: 100000000 2026-04-14 03:25:57,415 [root] WARNING: Folder at path "C:\bcBckJLx\debugger" does not exist, skipping 2026-04-14 03:25:57,415 [root] WARNING: Folder at path "C:\bcBckJLx\tlsdump" does not exist, skipping 2026-04-14 03:25:57,415 [root] WARNING: Monitor injection attempted but failed for process 2908 2026-04-14 03:25:57,415 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win7office2k3flash2800137TWN3H105 | win7office2k3flash2800137TWN3H105 | KVM | 2026-04-14 09:23:00 | 2026-04-14 09:26:08 | internet |
| File Name | Rothmans Table 3.xlsx |
|---|---|
| File Size | 54017 bytes |
| File Type | Microsoft Excel 2007+ |
| MD5 | a1a7d70422565983e9197801e7845e5d |
| SHA1 | 4a5c4fa62fcbe057f9028f4a1ffff4a2b6ac6dcd |
| SHA256 | 19d13e58f8161a61821ccc549bb61b78f1a942d877282522d13a160569bb99e9 |
| SHA512 | ce6e1f6e8013226e574398a8d03deafc29f680a0697c2b58f8ec426bea1b31e04d420329c000cf87ff8a12637728d7dd7bd5ca062fa089b1eba92ec50f7e8f54 |
| SHA3-384 | d875800f0ad33ce73312d4a1005760ca0284ab88a83eb66dc3048de82bee0094a45f3701c74bb7ae894eaf9a9d3afda5 |
| CRC32 | C60809F8 |
| TLSH | T18833E05DA300B4ADCB2699FDC90803E0A9C55552C1CAFDBA2B94B61C674F5F713AE38C |
| Ssdeep | 768:tQoaNwb2jp/jCCd1hcioDHLCCVCnRF4egf1+7lnp95KZWQMpJGy85HHqDIgLK+0V:tQvwipxjZVF+f4SWQQGL5HHij6WC |
File
|
| Direct | IP | Country Name |
|---|---|---|
| Y | 8.8.8.8 [VT] | United States |
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP