| Category | Package | Started | Completed | Duration | Options | Log |
|---|---|---|---|---|---|---|
| FILE | chrome | 2026-04-14 10:06:30 | 2026-04-14 10:09:33 | 183 seconds | Show Options | Show Log |
procdump=1
amsidump=1
2025-12-02 01:32:07,234 [root] INFO: Date set to: 20260414T03:06:29, timeout set to: 150 2026-04-14 04:06:29,015 [root] DEBUG: Starting analyzer from: C:\tmpvt__1blj 2026-04-14 04:06:29,015 [root] DEBUG: Storing results at: C:\wzMwqPEfuI 2026-04-14 04:06:29,015 [root] DEBUG: Pipe server name: \\.\PIPE\dSFVkfaeh 2026-04-14 04:06:29,015 [root] DEBUG: Python path: C:\olddocs 2026-04-14 04:06:29,015 [root] DEBUG: No analysis package specified, trying to detect it automagically 2026-04-14 04:06:29,015 [root] INFO: Automatically selected analysis package "chrome" 2026-04-14 04:06:29,015 [root] DEBUG: Importing analysis package "chrome"... 2026-04-14 04:06:29,031 [root] DEBUG: Initializing analysis package "chrome"... 2026-04-14 04:06:29,031 [root] INFO: Analyzer: Package modules.packages.chrome does not specify a DLL option 2026-04-14 04:06:29,031 [root] INFO: Analyzer: Package modules.packages.chrome does not specify a DLL_64 option 2026-04-14 04:06:29,031 [root] INFO: Analyzer: Package modules.packages.chrome does not specify a loader option 2026-04-14 04:06:29,031 [root] INFO: Analyzer: Package modules.packages.chrome does not specify a loader_64 option 2026-04-14 04:06:29,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2026-04-14 04:06:29,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2026-04-14 04:06:29,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2026-04-14 04:06:29,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2026-04-14 04:06:29,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2026-04-14 04:06:29,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2026-04-14 04:06:29,140 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2026-04-14 04:06:29,156 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2026-04-14 04:06:29,156 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2026-04-14 04:06:29,171 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-04-14 04:06:29,249 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2026-04-14 04:06:29,265 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2026-04-14 04:06:29,265 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2026-04-14 04:06:29,265 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2026-04-14 04:06:29,281 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2026-04-14 04:06:29,281 [root] DEBUG: Initializing auxiliary module "Browser"... 2026-04-14 04:06:29,281 [root] DEBUG: Started auxiliary module Browser 2026-04-14 04:06:29,281 [root] DEBUG: Initializing auxiliary module "Curtain"... 2026-04-14 04:06:29,281 [root] DEBUG: Started auxiliary module Curtain 2026-04-14 04:06:29,281 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2026-04-14 04:06:29,312 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2026-04-14 04:06:29,312 [root] DEBUG: Started auxiliary module DefaultApps 2026-04-14 04:06:29,312 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2026-04-14 04:06:29,312 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2026-04-14 04:06:29,312 [modules.auxiliary.digisig] INFO: dummy 2026-04-14 04:06:29,312 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2026-04-14 04:06:29,312 [root] DEBUG: Started auxiliary module DigiSig 2026-04-14 04:06:29,312 [root] DEBUG: Initializing auxiliary module "Disguise"... 2026-04-14 04:06:29,578 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2026-04-14 04:06:29,593 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2026-04-14 04:06:29,593 [root] DEBUG: Initializing auxiliary module "Evtx"... 2026-04-14 04:06:29,593 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpvt__1blj\bin\auditpol.csv 2026-04-14 04:06:29,953 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:06:30,750 [root] DEBUG: Started auxiliary module Evtx 2026-04-14 04:06:30,750 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2026-04-14 04:06:30,750 [modules.auxiliary.fiddler] INFO: fiddler package: dummy 2026-04-14 04:06:30,765 [root] DEBUG: Started auxiliary module Fiddler 2026-04-14 04:06:30,765 [root] DEBUG: Initializing auxiliary module "Human"... 2026-04-14 04:06:30,765 [root] DEBUG: Started auxiliary module Human 2026-04-14 04:06:30,765 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2026-04-14 04:06:30,765 [root] DEBUG: Started auxiliary module Screenshots 2026-04-14 04:06:30,781 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2026-04-14 04:06:30,781 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2026-04-14 04:06:30,781 [root] DEBUG: Started auxiliary module Sysmon 2026-04-14 04:06:30,781 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2026-04-14 04:06:30,781 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 556 2026-04-14 04:06:30,781 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2026-04-14 04:06:30,781 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2026-04-14 04:06:30,781 [lib.api.process] INFO: Monitor config for process 556: C:\tmpvt__1blj\dll\556.ini 2026-04-14 04:06:30,781 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2026-04-14 04:06:30,781 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2026-04-14 04:06:30,781 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2026-04-14 04:06:30,781 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpvt__1blj\dll\hlJvMkB.dll, loader C:\tmpvt__1blj\bin\QKHMoorA.exe 2026-04-14 04:06:30,812 [root] DEBUG: Loader: Injecting process 556 with C:\tmpvt__1blj\dll\hlJvMkB.dll. 2026-04-14 04:06:30,859 [root] DEBUG: 556: Python path set to 'C:\olddocs'. 2026-04-14 04:06:30,859 [root] DEBUG: 556: Disabling sleep skipping. 2026-04-14 04:06:30,859 [root] DEBUG: 556: Process dumps enabled. 2026-04-14 04:06:30,859 [root] DEBUG: 556: AMSI dumping enabled. 2026-04-14 04:06:30,859 [root] DEBUG: 556: TLS secret dump mode enabled. 2026-04-14 04:06:30,875 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEF5F80000, thread 2540, image base 0x00000000FF1A0000, stack from 0x0000000001F92000-0x0000000001FA0000 2026-04-14 04:06:30,875 [root] DEBUG: 556: Commandline: C:\Windows\system32\lsass.exe 2026-04-14 04:06:30,875 [root] DEBUG: 556: Hooked 5 out of 5 functions 2026-04-14 04:06:30,890 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-04-14 04:06:30,906 [root] DEBUG: Successfully injected DLL C:\tmpvt__1blj\dll\hlJvMkB.dll. 2026-04-14 04:06:30,906 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 556 2026-04-14 04:06:30,906 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2026-04-14 04:06:30,906 [root] DEBUG: Initializing auxiliary module "Usage"... 2026-04-14 04:06:30,906 [root] DEBUG: Started auxiliary module Usage 2026-04-14 04:06:32,984 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2026-04-14 04:06:33,640 [root] INFO: Restarting WMI Service 2026-04-14 04:06:37,796 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files\Google\Chrome\Application\chrome.exe" with arguments "--no-sandbox --test-type --ignore-ssl-errors "C:\Users\pgabriel\AppData\Local\Temp\Silver Birch _ 217_.html"" with pid 2416 2026-04-14 04:06:37,796 [lib.api.process] INFO: Monitor config for process 2416: C:\tmpvt__1blj\dll\2416.ini 2026-04-14 04:06:37,796 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2026-04-14 04:06:37,796 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2026-04-14 04:06:37,796 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpvt__1blj\dll\hlJvMkB.dll, loader C:\tmpvt__1blj\bin\QKHMoorA.exe 2026-04-14 04:06:37,812 [root] DEBUG: Loader: Injecting process 2416 (thread 2700) with C:\tmpvt__1blj\dll\hlJvMkB.dll. 2026-04-14 04:06:37,828 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-04-14 04:06:37,828 [root] DEBUG: Successfully injected DLL C:\tmpvt__1blj\dll\hlJvMkB.dll. 2026-04-14 04:06:37,828 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 2416 2026-04-14 04:06:39,828 [lib.api.process] INFO: Successfully resumed process with pid 2416 2026-04-14 04:06:39,875 [root] DEBUG: 2416: Python path set to 'C:\olddocs'. 2026-04-14 04:06:39,875 [root] DEBUG: 2416: Disabling sleep skipping. 2026-04-14 04:06:39,875 [root] DEBUG: 2416: Process dumps enabled. 2026-04-14 04:06:39,875 [root] DEBUG: 2416: AMSI dumping enabled. 2026-04-14 04:06:39,875 [root] DEBUG: 2416: Dropped file limit defaulting to 100. 2026-04-14 04:06:39,890 [root] DEBUG: 2416: Chrome-specific hook-set enabled. 2026-04-14 04:06:39,890 [root] DEBUG: 2416: Monitor initialised: 64-bit capemon loaded in process 2416 at 0x000007FEF5F80000, thread 2700, image base 0x000000013F290000, stack from 0x0000000000982000-0x0000000000990000 2026-04-14 04:06:39,890 [root] DEBUG: 2416: Commandline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-sandbox --test-type --ignore-ssl-errors "C:\Users\pgabriel\AppData\Local\Temp\Silver Birch _ 217_.html" 2026-04-14 04:06:39,906 [root] DEBUG: 2416: Hooked 16 out of 16 functions 2026-04-14 04:06:39,921 [root] DEBUG: 2416: RestoreHeaders: Restored original import table. 2026-04-14 04:06:39,921 [root] INFO: Loaded monitor into process with pid 2416 2026-04-14 04:06:39,921 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD5E0000: C:\Windows\system32\cryptbase (0xf000 bytes). 2026-04-14 04:06:39,937 [root] DEBUG: 2416: DLL loaded at 0x000007FEF9220000: C:\Windows\system32\WINMM (0x3b000 bytes). 2026-04-14 04:06:39,953 [root] DEBUG: 2416: caller_dispatch: Added region at 0x000000013F290000 to tracked regions list (ntdll::NtClose returns to 0x000000013F397089, thread 2700). 2026-04-14 04:06:39,953 [root] DEBUG: 2416: caller_dispatch: Scanning calling region at 0x000000013F290000... 2026-04-14 04:06:39,953 [root] DEBUG: 2416: ProcessImageBase: Main module image at 0x000000013F290000 unmodified (entropy change 0.000000e+00) 2026-04-14 04:06:39,953 [root] DEBUG: 2416: DLL loaded at 0x000007FEFC1B0000: C:\Windows\system32\ntmarta (0x2d000 bytes). 2026-04-14 04:06:39,953 [root] DEBUG: 2416: DLL loaded at 0x000007FEFE8D0000: C:\Windows\system32\WLDAP32 (0x52000 bytes). 2026-04-14 04:06:39,953 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 2320: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:39,968 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 2320 2026-04-14 04:06:39,968 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD580000: C:\Windows\system32\apphelp (0x57000 bytes). 2026-04-14 04:06:39,968 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 2320 2026-04-14 04:06:39,984 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat 2026-04-14 04:06:40,000 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1AD0000: C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0 (0x4000 bytes). 2026-04-14 04:06:40,000 [root] DEBUG: 2416: DLL loaded at 0x000007FEFDB40000: C:\Windows\system32\shell32 (0xd88000 bytes). 2026-04-14 04:06:42,984 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:06:44,453 [root] DEBUG: 2416: DLL loaded at 0x000007FEDF480000: C:\Program Files\Google\Chrome\Application\92.0.4515.131\chrome (0xa41f000 bytes). 2026-04-14 04:06:44,453 [root] DEBUG: 2416: DLL loaded at 0x000007FEEC750000: C:\Windows\system32\dbghelp (0x125000 bytes). 2026-04-14 04:06:44,468 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB3F0000: C:\Windows\system32\IPHLPAPI (0x27000 bytes). 2026-04-14 04:06:44,468 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB510000: C:\Windows\system32\WINNSI (0xb000 bytes). 2026-04-14 04:06:44,500 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1900000: C:\Windows\system32\UIAutomationCore (0xba000 bytes). 2026-04-14 04:06:44,500 [root] DEBUG: 2416: DLL loaded at 0x0000000077BA0000: C:\Windows\system32\PSAPI (0x7000 bytes). 2026-04-14 04:06:44,515 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1670000: C:\Windows\system32\OLEACC (0x54000 bytes). 2026-04-14 04:06:44,515 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD3A0000: C:\Windows\system32\Secur32 (0xb000 bytes). 2026-04-14 04:06:44,515 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD8D0000: C:\Windows\system32\USERENV (0x1e000 bytes). 2026-04-14 04:06:44,515 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD790000: C:\Windows\system32\profapi (0xf000 bytes). 2026-04-14 04:06:44,515 [root] DEBUG: 2416: DLL loaded at 0x000007FEFDB00000: C:\Windows\system32\WINTRUST (0x3b000 bytes). 2026-04-14 04:06:44,546 [root] DEBUG: 2416: DLL loaded at 0x000007FEED9E0000: C:\Windows\system32\DWrite (0x196000 bytes). 2026-04-14 04:06:44,562 [root] DEBUG: 2416: DLL loaded at 0x000007FEF9E80000: C:\Windows\system32\WINSPOOL.DRV (0x71000 bytes). 2026-04-14 04:06:44,578 [root] DEBUG: 2416: DLL loaded at 0x000007FEFA730000: C:\Windows\system32\WINHTTP (0x71000 bytes). 2026-04-14 04:06:44,578 [root] DEBUG: 2416: DLL loaded at 0x000007FEFA6C0000: C:\Windows\system32\webio (0x65000 bytes). 2026-04-14 04:06:44,593 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB200000: C:\Windows\system32\dhcpcsvc (0x18000 bytes). 2026-04-14 04:06:44,609 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1AD0000: C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0 (0x4000 bytes). 2026-04-14 04:06:44,609 [root] DEBUG: 2416: DLL loaded at 0x000007FEFDB40000: C:\Windows\system32\shell32 (0xd88000 bytes). 2026-04-14 04:06:44,625 [root] DEBUG: 2416: DLL loaded at 0x000007FEFBD40000: C:\Windows\system32\uxtheme (0x56000 bytes). 2026-04-14 04:06:44,640 [root] DEBUG: 2416: DLL loaded at 0x000007FEFCA30000: C:\Windows\system32\GPAPI (0x1b000 bytes). 2026-04-14 04:06:44,640 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB1E0000: C:\Windows\system32\wkscli (0x15000 bytes). 2026-04-14 04:06:44,640 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB220000: C:\Windows\system32\netutils (0xc000 bytes). 2026-04-14 04:06:44,734 [root] DEBUG: 2416: DLL loaded at 0x000007FEFC1E0000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\COMCTL32 (0x1f4000 bytes). 2026-04-14 04:06:44,796 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB820000: C:\Windows\system32\NLAapi (0x15000 bytes). 2026-04-14 04:06:44,812 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB230000: C:\Windows\system32\dhcpcsvc6 (0x11000 bytes). 2026-04-14 04:06:44,812 [root] DEBUG: 2416: DLL loaded at 0x000007FEFBA60000: C:\Windows\system32\dwmapi (0x18000 bytes). 2026-04-14 04:06:44,828 [root] DEBUG: 2416: DLL loaded at 0x000007FEFF0A0000: C:\Windows\system32\CLBCatQ (0x99000 bytes). 2026-04-14 04:06:44,828 [root] DEBUG: 2416: DLL loaded at 0x000007FEFDB40000: C:\Windows\system32\SHELL32 (0xd88000 bytes). 2026-04-14 04:06:44,843 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB4F0000: C:\Windows\system32\WTSAPI32 (0x11000 bytes). 2026-04-14 04:06:44,859 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD6B0000: C:\Windows\system32\WINSTA (0x3d000 bytes). 2026-04-14 04:06:44,875 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1530000: C:\Windows\system32\mscms (0x9c000 bytes). 2026-04-14 04:06:44,890 [root] DEBUG: 2416: DLL loaded at 0x000007FEFC080000: C:\Windows\System32\MMDevApi (0x4b000 bytes). 2026-04-14 04:06:44,906 [root] DEBUG: 2416: DLL loaded at 0x000007FEFBF20000: C:\Windows\System32\PROPSYS (0x12c000 bytes). 2026-04-14 04:06:44,906 [root] DEBUG: 2416: DLL loaded at 0x000007FEFEEC0000: C:\Windows\system32\SETUPAPI (0x1d7000 bytes). 2026-04-14 04:06:44,906 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 3004: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:44,906 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD8F0000: C:\Windows\system32\CFGMGR32 (0x36000 bytes). 2026-04-14 04:06:44,906 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3004 2026-04-14 04:06:44,906 [root] DEBUG: 2416: DLL loaded at 0x000007FEFDAD0000: C:\Windows\system32\DEVOBJ (0x1a000 bytes). 2026-04-14 04:06:44,906 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3004 2026-04-14 04:06:44,906 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index 2026-04-14 04:06:44,921 [root] DEBUG: 2416: DLL loaded at 0x000007FEF13C0000: C:\Windows\System32\Wpc (0x6f000 bytes). 2026-04-14 04:06:44,937 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD190000: C:\Windows\System32\wevtapi (0x6d000 bytes). 2026-04-14 04:06:44,937 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 1172 2026-04-14 04:06:44,953 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Last Version 2026-04-14 04:06:44,953 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB1C0000: C:\Windows\system32\samcli (0x14000 bytes). 2026-04-14 04:06:44,953 [root] DEBUG: 2416: DLL loaded at 0x000007FEFBF00000: C:\Windows\system32\SAMLIB (0x1d000 bytes). 2026-04-14 04:06:45,015 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 1204: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:45,015 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 1204 2026-04-14 04:06:45,015 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 1204 2026-04-14 04:06:45,046 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History 2026-04-14 04:06:45,109 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOCK 2026-04-14 04:06:45,109 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\MANIFEST-000001 2026-04-14 04:06:45,109 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\000003.log 2026-04-14 04:06:45,109 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG 2026-04-14 04:06:45,125 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\000003.log size is 0, Max size: 100000000 2026-04-14 04:06:45,140 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\CURRENT size is 16, Max size: 100000000 2026-04-14 04:06:45,171 [root] DEBUG: 2416: DLL loaded at 0x000007FEFC880000: C:\Windows\system32\FirewallAPI (0xbb000 bytes). 2026-04-14 04:06:45,171 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG size is 351, Max size: 100000000 2026-04-14 04:06:45,171 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF13b691.TMP size is 327, Max size: 100000000 2026-04-14 04:06:45,187 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old size is 311, Max size: 100000000 2026-04-14 04:06:45,187 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\MANIFEST-000001 size is 41, Max size: 100000000 2026-04-14 04:06:45,203 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOCK size is 0, Max size: 100000000 2026-04-14 04:06:45,234 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\MANIFEST-000001 2026-04-14 04:06:45,234 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\000001.dbtmp 2026-04-14 04:06:45,343 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1AD0000: C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0 (0x4000 bytes). 2026-04-14 04:06:45,343 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\7d32e619-f9a0-467f-ab1c-214f845e1f49.tmp 2026-04-14 04:06:45,359 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\7d32e619-f9a0-467f-ab1c-214f845e1f49.tmp size is 1, Max size: 100000000 2026-04-14 04:06:45,546 [root] DEBUG: 2416: DLL loaded at 0x000007FEFC0D0000: C:\Windows\system32\POWRPROF (0x2c000 bytes). 2026-04-14 04:06:45,753 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:06:45,816 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index 2026-04-14 04:06:46,035 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 2592: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:46,035 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 2592 2026-04-14 04:06:46,035 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 2592 2026-04-14 04:06:46,082 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 2152: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:46,316 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF13baf6.TMP size is 329, Max size: 100000000 2026-04-14 04:06:46,363 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001 2026-04-14 04:06:46,394 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log 2026-04-14 04:06:46,394 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\GrShaderCache\GPUCache\index 2026-04-14 04:06:46,433 [lib.common.results] INFO: File 1776164806253906200.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:06:46,468 [lib.common.results] INFO: File 1776164806253906200.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:06:46,485 [lib.common.results] INFO: File 1776164806238281200.Application.evtx.gz size is 6910, Max size: 100000000 2026-04-14 04:06:46,485 [lib.common.results] INFO: File 1776164806300781200.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:06:46,581 [lib.common.results] INFO: File 1776164806485351500.System.evtx.gz size is 8854, Max size: 100000000 2026-04-14 04:06:46,581 [root] DEBUG: 2416: DLL loaded at 0x000007FEF9C10000: C:\Windows\system32\explorerframe (0x1ca000 bytes). 2026-04-14 04:06:46,596 [lib.common.results] INFO: File 1776164806449218700.Security.evtx.gz size is 16866, Max size: 100000000 2026-04-14 04:06:46,596 [root] DEBUG: 2416: DLL loaded at 0x000007FEFBAD0000: C:\Windows\system32\DUser (0x43000 bytes). 2026-04-14 04:06:46,612 [lib.common.results] INFO: File 1776164806429687500.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:06:46,612 [lib.common.results] INFO: File 1776164806469726500.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:06:46,643 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB950000: C:\Windows\system32\DUI70 (0xf2000 bytes). 2026-04-14 04:06:46,643 [lib.common.results] INFO: File 1776164806581054600.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:06:46,643 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF13bc4e.TMP size is 317, Max size: 100000000 2026-04-14 04:06:46,690 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG 2026-04-14 04:06:46,690 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000001 2026-04-14 04:06:46,752 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 876: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:46,752 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 876 2026-04-14 04:06:46,752 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 876 2026-04-14 04:06:46,861 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1B10000: C:\Windows\system32\wlanapi (0x20000 bytes). 2026-04-14 04:06:46,866 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1B00000: C:\Windows\system32\wlanutil (0x7000 bytes). 2026-04-14 04:06:46,881 [root] DEBUG: 2416: DLL loaded at 0x000007FEFC0D0000: C:\Windows\system32\POWRPROF (0x2c000 bytes). 2026-04-14 04:06:46,883 [root] DEBUG: 2416: DLL loaded at 0x000007FEFC0D0000: C:\Windows\system32\POWRPROF (0x2c000 bytes). 2026-04-14 04:06:46,918 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 2164: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:46,920 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 2164 2026-04-14 04:06:46,929 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\bab46678-5e73-4523-9dd3-8bbcef6f3df0.tmp 2026-04-14 04:06:46,933 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\dc84d642-186b-45f8-b9c6-6e17e6feee3f.tmp 2026-04-14 04:06:46,958 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\6ff088e8-aaa2-4072-9649-feb065e97630.tmp 2026-04-14 04:06:46,979 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF13bd87.TMP size is 9213, Max size: 100000000 2026-04-14 04:06:46,994 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\7dadc225-9d11-47ef-aadc-71d10289ac30.tmp 2026-04-14 04:06:47,056 [root] DEBUG: 2416: DLL loaded at 0x000007FEFCED0000: C:\Windows\system32\mswsock (0x55000 bytes). 2026-04-14 04:06:47,072 [root] DEBUG: 2416: DLL loaded at 0x000007FEFC940000: C:\Windows\System32\wshtcpip (0x7000 bytes). 2026-04-14 04:06:47,101 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old~RF13be04.TMP size is 323, Max size: 100000000 2026-04-14 04:06:47,268 [root] DEBUG: 556: DLL loaded at 0x000007FEF8E90000: C:\Windows\system32\keyiso (0xb000 bytes). 2026-04-14 04:06:47,612 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\80b5107f-8821-4775-bc73-d3dff4e26f4e.tmp 2026-04-14 04:06:47,614 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\c12eca5d-579f-400c-ab85-2e06e51eec47.tmp 2026-04-14 04:06:47,786 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mpbjkejclgfgadiemmefgebjfooflfhl\LOG.old~RF13c0b3.TMP size is 405, Max size: 100000000 2026-04-14 04:06:47,852 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF13c101.TMP size is 405, Max size: 100000000 2026-04-14 04:06:47,955 [root] DEBUG: 556: DLL loaded at 0x000007FEF1630000: C:\Windows\system32\dssenh (0x32000 bytes). 2026-04-14 04:06:47,987 [root] DEBUG: 556: TLS 1.2 secrets logged to: C:\wzMwqPEfuI\tlsdump\tlsdump.log 2026-04-14 04:06:48,071 [root] DEBUG: 556: DLL loaded at 0x000007FEFAA70000: C:\Windows\system32\cryptnet (0x27000 bytes). 2026-04-14 04:06:48,072 [root] DEBUG: 556: DLL loaded at 0x000007FEFE8D0000: C:\Windows\system32\WLDAP32 (0x52000 bytes). 2026-04-14 04:06:48,112 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164808.1123047.sysmon.evtx.gz to host 2026-04-14 04:06:48,113 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 28406, Max size: 100000000 2026-04-14 04:06:48,135 [root] DEBUG: 2416: DLL loaded at 0x000007FEFCF30000: C:\Windows\system32\CRYPTSP (0x18000 bytes). 2026-04-14 04:06:48,141 [root] DEBUG: 2416: DLL loaded at 0x000007FEFCC30000: C:\Windows\system32\rsaenh (0x47000 bytes). 2026-04-14 04:06:48,157 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD100000: C:\Windows\system32\ncrypt (0x50000 bytes). 2026-04-14 04:06:48,167 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD040000: C:\Windows\system32\bcryptprimitives (0x4c000 bytes). 2026-04-14 04:06:48,283 [root] DEBUG: 2416: DLL loaded at 0x000007FEFAA70000: C:\Windows\system32\cryptnet (0x27000 bytes). 2026-04-14 04:06:49,717 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB2B0000: C:\Windows\system32\netapi32 (0x16000 bytes). 2026-04-14 04:06:49,717 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD2F0000: C:\Windows\system32\srvcli (0x23000 bytes). 2026-04-14 04:06:49,717 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1B10000: C:\Windows\system32\wlanapi (0x20000 bytes). 2026-04-14 04:06:49,735 [root] DEBUG: 2416: DLL loaded at 0x000007FEF1B00000: C:\Windows\system32\wlanutil (0x7000 bytes). 2026-04-14 04:06:49,783 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-66299726-990.pma size is 4194304, Max size: 100000000 2026-04-14 04:06:49,876 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-69DE1FC4-970.pma size is 4194304, Max size: 100000000 2026-04-14 04:06:49,939 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma size is 1048576, Max size: 100000000 2026-04-14 04:06:50,220 [root] DEBUG: 2416: DLL loaded at 0x000007FEDF080000: C:\Windows\system32\mf (0x3f1000 bytes). 2026-04-14 04:06:50,220 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB7C0000: C:\Windows\system32\ATL (0x19000 bytes). 2026-04-14 04:06:50,220 [root] DEBUG: 2416: DLL loaded at 0x000007FEED840000: C:\Windows\system32\MFPlat (0x6d000 bytes). 2026-04-14 04:06:50,220 [root] DEBUG: 2416: DLL loaded at 0x000007FEFBEF0000: C:\Windows\system32\AVRT (0x9000 bytes). 2026-04-14 04:06:50,236 [root] DEBUG: 2416: DLL loaded at 0x0000000074C30000: C:\Windows\system32\ksuser (0x6000 bytes). 2026-04-14 04:06:50,236 [root] DEBUG: 2416: DLL loaded at 0x000007FEDE2F0000: C:\Windows\system32\mfreadwrite (0x42000 bytes). 2026-04-14 04:06:51,725 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt size is 4, Max size: 100000000 2026-04-14 04:06:53,812 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF13d852.TMP size is 139, Max size: 100000000 2026-04-14 04:06:53,875 [lib.common.results] INFO: File c:\olddocs\1776164808864.saz size is 415614, Max size: 100000000 2026-04-14 04:06:53,890 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:06:54,437 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000038.dbtmp 2026-04-14 04:06:54,437 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF13dac3.TMP size is 16, Max size: 100000000 2026-04-14 04:06:54,593 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000037.log size is 0, Max size: 100000000 2026-04-14 04:06:54,609 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000036 size is 50, Max size: 100000000 2026-04-14 04:06:54,671 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Last Browser 2026-04-14 04:06:54,734 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 3212: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:54,734 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3212 2026-04-14 04:06:54,859 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\129c29e3-0c30-4763-9ad5-ab6034b32198.tmp 2026-04-14 04:06:54,859 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Local State~RF13dc69.TMP size is 312116, Max size: 100000000 2026-04-14 04:06:55,191 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 3228: C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\SwReporter\92.267.200\software_reporter_tool.exe, ImageBase: 0x000000013FEF0000 2026-04-14 04:06:55,191 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3228 2026-04-14 04:06:55,191 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3228 2026-04-14 04:06:55,628 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old~RF13df67.TMP size is 0, Max size: 100000000 2026-04-14 04:06:55,691 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOCK 2026-04-14 04:06:55,691 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG 2026-04-14 04:06:55,707 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOG.old~RF13dfa5.TMP size is 0, Max size: 100000000 2026-04-14 04:06:55,722 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOCK 2026-04-14 04:06:55,722 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOG 2026-04-14 04:06:55,722 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOG.old~RF13dfc4.TMP size is 0, Max size: 100000000 2026-04-14 04:06:55,738 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOCK 2026-04-14 04:06:55,738 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOG 2026-04-14 04:06:55,785 [root] DEBUG: 2416: DLL loaded at 0x000007FEF2350000: C:\Windows\system32\bthprops.cpl (0xb5000 bytes). 2026-04-14 04:06:55,832 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old~RF13e032.TMP size is 333, Max size: 100000000 2026-04-14 04:06:56,675 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old~RF13e37d.TMP size is 0, Max size: 100000000 2026-04-14 04:06:56,691 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOCK 2026-04-14 04:06:56,691 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG 2026-04-14 04:06:56,691 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old~RF13e38d.TMP size is 0, Max size: 100000000 2026-04-14 04:06:56,707 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOCK 2026-04-14 04:06:56,707 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG 2026-04-14 04:06:56,707 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache size is 6, Max size: 100000000 2026-04-14 04:06:56,707 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache 2026-04-14 04:06:56,722 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF13e39d.TMP size is 0, Max size: 100000000 2026-04-14 04:06:56,738 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOCK 2026-04-14 04:06:56,738 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG 2026-04-14 04:06:56,753 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 3476: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:06:56,753 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3476 2026-04-14 04:06:56,753 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3476 2026-04-14 04:06:56,753 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old~RF13e3cc.TMP size is 341, Max size: 100000000 2026-04-14 04:06:56,769 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF13e3db.TMP size is 323, Max size: 100000000 2026-04-14 04:06:57,035 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\766bcae1-de0e-45b0-89f4-6a050c3a979f.tmp 2026-04-14 04:06:57,035 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF13e4e5.TMP size is 9054, Max size: 100000000 2026-04-14 04:06:57,227 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOG.old~RF13e591.TMP size is 0, Max size: 100000000 2026-04-14 04:06:57,243 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOCK 2026-04-14 04:06:57,243 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOG 2026-04-14 04:06:57,430 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old~RF13e66b.TMP size is 0, Max size: 100000000 2026-04-14 04:06:57,446 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOCK 2026-04-14 04:06:57,446 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG 2026-04-14 04:07:01,691 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:07:01,941 [lib.common.results] INFO: File 1776164821878906200.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:07:01,957 [lib.common.results] INFO: File 1776164821894531200.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:01,957 [lib.common.results] INFO: File 1776164821878906200.Application.evtx.gz size is 6840, Max size: 100000000 2026-04-14 04:07:01,957 [lib.common.results] INFO: File 1776164821894531200.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:07:02,003 [lib.common.results] INFO: File 1776164821941406200.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:07:02,003 [lib.common.results] INFO: File 1776164821941406200.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:07:02,019 [lib.common.results] INFO: File 1776164821941406200.Security.evtx.gz size is 8630, Max size: 100000000 2026-04-14 04:07:02,035 [lib.common.results] INFO: File 1776164821957031200.System.evtx.gz size is 8621, Max size: 100000000 2026-04-14 04:07:02,050 [lib.common.results] INFO: File 1776164822003906200.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:07:03,133 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:07:03,383 [root] INFO: Process with pid 2164 has terminated 2026-04-14 04:07:06,748 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\49f92ecc-3c92-4e05-98cf-93924d4c677e.tmp 2026-04-14 04:07:06,763 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Module Info Cache~RF140acc.TMP size is 66968, Max size: 100000000 2026-04-14 04:07:08,373 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164828.3730469.sysmon.evtx.gz to host 2026-04-14 04:07:08,373 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 252195, Max size: 100000000 2026-04-14 04:07:11,848 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\effd3eb4-84ba-43b9-a169-f52dcfeac960.tmp 2026-04-14 04:07:11,848 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Local State~RF141ec1.TMP size is 398783, Max size: 100000000 2026-04-14 04:07:13,991 [lib.common.results] INFO: File c:\olddocs\1776164828967.saz size is 12444, Max size: 100000000 2026-04-14 04:07:14,006 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:07:16,609 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\e7334b49-97cb-4c32-82ea-ec7b681db51b.tmp 2026-04-14 04:07:16,625 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF14315f.TMP size is 9233, Max size: 100000000 2026-04-14 04:07:17,093 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:07:17,359 [lib.common.results] INFO: File 1776164837296875000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:17,359 [lib.common.results] INFO: File 1776164837296875000.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:07:17,359 [lib.common.results] INFO: File 1776164837296875000.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:07:17,375 [lib.common.results] INFO: File 1776164837296875000.Application.evtx.gz size is 6840, Max size: 100000000 2026-04-14 04:07:17,421 [lib.common.results] INFO: File 1776164837359375000.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:07:17,437 [lib.common.results] INFO: File 1776164837359375000.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:07:17,437 [lib.common.results] INFO: File 1776164837359375000.Security.evtx.gz size is 7963, Max size: 100000000 2026-04-14 04:07:17,453 [lib.common.results] INFO: File 1776164837359375000.System.evtx.gz size is 8295, Max size: 100000000 2026-04-14 04:07:17,468 [lib.common.results] INFO: File 1776164837406250000.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:07:23,399 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:07:25,185 [root] DEBUG: 2416: DLL loaded at 0x000007FEFB2B0000: C:\Windows\system32\NETAPI32 (0x16000 bytes). 2026-04-14 04:07:25,185 [root] DEBUG: 2416: DLL loaded at 0x000007FEFD2F0000: C:\Windows\system32\srvcli (0x23000 bytes). 2026-04-14 04:07:25,185 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 3404: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:07:25,201 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3404 2026-04-14 04:07:25,201 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 3404 2026-04-14 04:07:25,201 [root] DEBUG: 2416: Dropped file limit reached. 2026-04-14 04:07:28,485 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164848.4853513.sysmon.evtx.gz to host 2026-04-14 04:07:28,485 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 7639, Max size: 100000000 2026-04-14 04:07:32,512 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:07:32,793 [lib.common.results] INFO: File 1776164852715820300.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:07:32,809 [lib.common.results] INFO: File 1776164852715820300.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:07:32,809 [lib.common.results] INFO: File 1776164852715820300.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:32,809 [lib.common.results] INFO: File 1776164852715820300.Application.evtx.gz size is 6840, Max size: 100000000 2026-04-14 04:07:32,840 [lib.common.results] INFO: File 1776164852793945300.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:07:32,840 [lib.common.results] INFO: File 1776164852793945300.Security.evtx.gz size is 8072, Max size: 100000000 2026-04-14 04:07:32,856 [lib.common.results] INFO: File 1776164852778320300.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:07:32,856 [lib.common.results] INFO: File 1776164852793945300.System.evtx.gz size is 8287, Max size: 100000000 2026-04-14 04:07:32,887 [lib.common.results] INFO: File 1776164852840820300.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:07:34,126 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:07:43,514 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:07:47,165 [root] DEBUG: 2416: CreateProcessHandler: Injection info set for new process 4080: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F290000 2026-04-14 04:07:47,165 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 4080 2026-04-14 04:07:47,165 [root] DEBUG: 2416: ProcessMessage: Skipping monitoring process 4080 2026-04-14 04:07:47,930 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:07:48,180 [lib.common.results] INFO: File 1776164868118164000.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:07:48,196 [lib.common.results] INFO: File 1776164868102539000.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:07:48,211 [lib.common.results] INFO: File 1776164868118164000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:48,211 [lib.common.results] INFO: File 1776164868102539000.Application.evtx.gz size is 6915, Max size: 100000000 2026-04-14 04:07:48,243 [lib.common.results] INFO: File 1776164868180664000.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:07:48,258 [lib.common.results] INFO: File 1776164868180664000.Security.evtx.gz size is 7960, Max size: 100000000 2026-04-14 04:07:48,274 [lib.common.results] INFO: File 1776164868196289000.System.evtx.gz size is 8316, Max size: 100000000 2026-04-14 04:07:48,290 [lib.common.results] INFO: File 1776164868180664000.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:07:48,305 [lib.common.results] INFO: File 1776164868243164000.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:07:48,602 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164868.6015627.sysmon.evtx.gz to host 2026-04-14 04:07:48,602 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 28346, Max size: 100000000 2026-04-14 04:07:54,236 [lib.common.results] INFO: File c:\olddocs\1776164869198.saz size is 12943, Max size: 100000000 2026-04-14 04:07:54,251 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:08:03,389 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:08:03,608 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:08:03,670 [lib.common.results] INFO: File 1776164883608398400.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:08:03,702 [lib.common.results] INFO: File 1776164883608398400.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:08:03,702 [lib.common.results] INFO: File 1776164883608398400.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:03,702 [lib.common.results] INFO: File 1776164883608398400.Application.evtx.gz size is 6848, Max size: 100000000 2026-04-14 04:08:03,749 [lib.common.results] INFO: File 1776164883670898400.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:08:03,764 [lib.common.results] INFO: File 1776164883670898400.Security.evtx.gz size is 8283, Max size: 100000000 2026-04-14 04:08:03,764 [lib.common.results] INFO: File 1776164883686523400.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:08:03,780 [lib.common.results] INFO: File 1776164883686523400.System.evtx.gz size is 8300, Max size: 100000000 2026-04-14 04:08:03,795 [lib.common.results] INFO: File 1776164883733398400.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:08:08,740 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164888.7402341.sysmon.evtx.gz to host 2026-04-14 04:08:08,740 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 34667, Max size: 100000000 2026-04-14 04:08:14,346 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:08:18,828 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:08:19,057 [lib.common.results] INFO: File 1776164899012695300.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:08:19,063 [lib.common.results] INFO: File 1776164899014648400.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:19,067 [lib.common.results] INFO: File 1776164899009765600.Application.evtx.gz size is 6848, Max size: 100000000 2026-04-14 04:08:19,070 [lib.common.results] INFO: File 1776164899014648400.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:08:19,096 [lib.common.results] INFO: File 1776164899056640600.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:08:19,127 [lib.common.results] INFO: File 1776164899063476500.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:08:19,127 [lib.common.results] INFO: File 1776164899063476500.Security.evtx.gz size is 7976, Max size: 100000000 2026-04-14 04:08:19,127 [lib.common.results] INFO: File 1776164899068359300.System.evtx.gz size is 8339, Max size: 100000000 2026-04-14 04:08:19,143 [lib.common.results] INFO: File 1776164899096679600.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:08:23,755 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:08:28,825 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164908.8251953.sysmon.evtx.gz to host 2026-04-14 04:08:28,825 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6371, Max size: 100000000 2026-04-14 04:08:34,169 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:08:34,404 [lib.common.results] INFO: File c:\olddocs\1776164909403.saz size is 6999, Max size: 100000000 2026-04-14 04:08:34,404 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:08:34,419 [lib.common.results] INFO: File 1776164914373046800.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:08:34,435 [lib.common.results] INFO: File 1776164914373046800.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:08:34,451 [lib.common.results] INFO: File 1776164914373046800.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:34,451 [lib.common.results] INFO: File 1776164914373046800.Application.evtx.gz size is 6848, Max size: 100000000 2026-04-14 04:08:34,482 [lib.common.results] INFO: File 1776164914419921800.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:08:34,498 [lib.common.results] INFO: File 1776164914451171800.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:08:34,513 [lib.common.results] INFO: File 1776164914435546800.Security.evtx.gz size is 8059, Max size: 100000000 2026-04-14 04:08:34,513 [lib.common.results] INFO: File 1776164914451171800.System.evtx.gz size is 8329, Max size: 100000000 2026-04-14 04:08:34,529 [lib.common.results] INFO: File 1776164914482421800.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:08:43,842 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:08:48,948 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164928.9482422.sysmon.evtx.gz to host 2026-04-14 04:08:48,948 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6667, Max size: 100000000 2026-04-14 04:08:49,557 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:08:49,791 [lib.common.results] INFO: File 1776164929729492100.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:08:49,791 [lib.common.results] INFO: File 1776164929729492100.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:08:49,807 [lib.common.results] INFO: File 1776164929729492100.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:49,807 [lib.common.results] INFO: File 1776164929729492100.Application.evtx.gz size is 6848, Max size: 100000000 2026-04-14 04:08:49,854 [lib.common.results] INFO: File 1776164929791992100.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:08:49,870 [lib.common.results] INFO: File 1776164929791992100.Security.evtx.gz size is 8173, Max size: 100000000 2026-04-14 04:08:49,885 [lib.common.results] INFO: File 1776164929807617100.System.evtx.gz size is 8321, Max size: 100000000 2026-04-14 04:08:49,901 [lib.common.results] INFO: File 1776164929791992100.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:08:49,916 [lib.common.results] INFO: File 1776164929854492100.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:08:54,503 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:09:03,966 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:09:04,951 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:09:05,169 [lib.common.results] INFO: File 1776164945123046800.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:05,169 [lib.common.results] INFO: File 1776164945123046800.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:09:05,185 [lib.common.results] INFO: File 1776164945123046800.Application.evtx.gz size is 6848, Max size: 100000000 2026-04-14 04:09:05,216 [lib.common.results] INFO: File 1776164945169921800.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:09:05,216 [lib.common.results] INFO: File 1776164945154296800.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:09:05,216 [lib.common.results] INFO: File 1776164945169921800.Security.evtx.gz size is 8123, Max size: 100000000 2026-04-14 04:09:05,248 [lib.common.results] INFO: File 1776164945185546800.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:09:05,263 [lib.common.results] INFO: File 1776164945216796800.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:09:05,279 [lib.common.results] INFO: File 1776164945216796800.System.evtx.gz size is 8330, Max size: 100000000 2026-04-14 04:09:09,038 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164949.038086.sysmon.evtx.gz to host 2026-04-14 04:09:09,038 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5844, Max size: 100000000 2026-04-14 04:09:10,499 [root] INFO: Analysis timeout hit, terminating analysis 2026-04-14 04:09:10,499 [lib.api.process] INFO: Terminate event set for process 2416 2026-04-14 04:09:10,499 [root] DEBUG: 2416: Terminate Event: Attempting to dump process 2416 2026-04-14 04:09:10,499 [root] DEBUG: 2416: DoProcessDump: Skipping process dump as code is identical on disk. 2026-04-14 04:09:10,530 [lib.api.process] INFO: Termination confirmed for process 2416 2026-04-14 04:09:10,530 [root] INFO: Terminate event set for process 2416 2026-04-14 04:09:10,530 [root] DEBUG: 2416: Terminate Event: monitor shutdown complete for process 2416 2026-04-14 04:09:10,530 [root] INFO: Created shutdown mutex 2026-04-14 04:09:11,535 [root] INFO: Shutting down package 2026-04-14 04:09:11,535 [root] INFO: Stopping auxiliary modules 2026-04-14 04:09:11,535 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2026-04-14 04:09:11,535 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2026-04-14 04:09:11,550 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:09:11,769 [lib.common.results] INFO: File 1776164951707031200.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:11,769 [lib.common.results] INFO: File 1776164951707031200.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:09:11,769 [lib.common.results] INFO: File 1776164951707031200.Application.evtx.gz size is 6848, Max size: 100000000 2026-04-14 04:09:11,769 [lib.common.results] INFO: File 1776164951722656200.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:09:11,800 [lib.common.results] INFO: File 1776164951769531200.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:09:11,816 [lib.common.results] INFO: File 1776164951769531200.Security.evtx.gz size is 8029, Max size: 100000000 2026-04-14 04:09:11,832 [lib.common.results] INFO: File 1776164951769531200.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:09:11,847 [lib.common.results] INFO: File 1776164951769531200.System.evtx.gz size is 8304, Max size: 100000000 2026-04-14 04:09:11,863 [lib.common.results] INFO: File 1776164951800781200.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:09:14,588 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:09:16,968 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:09:16,968 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2026-04-14 04:09:20,312 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:09:20,531 [lib.common.results] INFO: File 1776164960484375000.KeyManagementService.evtx.gz size is 259, Max size: 100000000 2026-04-14 04:09:20,531 [lib.common.results] INFO: File 1776164960484375000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:20,531 [lib.common.results] INFO: File 1776164960484375000.Application.evtx.gz size is 6848, Max size: 100000000 2026-04-14 04:09:20,546 [lib.common.results] INFO: File 1776164960484375000.HardwareEvents.evtx.gz size is 214, Max size: 100000000 2026-04-14 04:09:20,593 [lib.common.results] INFO: File 1776164960531250000.OAlerts.evtx.gz size is 249, Max size: 100000000 2026-04-14 04:09:20,593 [lib.common.results] INFO: File 1776164960531250000.Security.evtx.gz size is 8025, Max size: 100000000 2026-04-14 04:09:20,609 [lib.common.results] INFO: File 1776164960531250000.Setup.evtx.gz size is 248, Max size: 100000000 2026-04-14 04:09:20,625 [lib.common.results] INFO: File 1776164960531250000.System.evtx.gz size is 8312, Max size: 100000000 2026-04-14 04:09:20,640 [lib.common.results] INFO: File 1776164960593750000.WindowsPowerShell.evtx.gz size is 260, Max size: 100000000 2026-04-14 04:09:22,031 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164962.03125.sysmon.evtx.gz to host 2026-04-14 04:09:22,031 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5931, Max size: 100000000 2026-04-14 04:09:22,031 [root] INFO: Finishing auxiliary modules 2026-04-14 04:09:22,031 [root] INFO: Shutting down pipe server and dumping dropped files 2026-04-14 04:09:22,046 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat size is 40, Max size: 100000000 2026-04-14 04:09:22,062 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\google\chrome\user data\shadercache\gpucache\index": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\google\\chrome\\user data\\shadercache\\gpucache\\index' 2026-04-14 04:09:22,062 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Last Version size is 13, Max size: 100000000 2026-04-14 04:09:22,078 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History size is 126976, Max size: 100000000 2026-04-14 04:09:22,093 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\MANIFEST-000001 size is 41, Max size: 100000000 2026-04-14 04:09:22,109 [lib.common.results] INFO: File c:\users\pgabriel\appdata\local\google\chrome\user data\default\site characteristics database\current size is 16, Max size: 100000000 2026-04-14 04:09:22,109 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\google\chrome\user data\default\gpucache\index": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\google\\chrome\\user data\\default\\gpucache\\index' 2026-04-14 04:09:22,109 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001 size is 41, Max size: 100000000 2026-04-14 04:09:22,125 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log size is 5424, Max size: 100000000 2026-04-14 04:09:22,140 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\google\chrome\user data\grshadercache\gpucache\index": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\google\\chrome\\user data\\grshadercache\\gpucache\\index' 2026-04-14 04:09:22,140 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG size is 323, Max size: 100000000 2026-04-14 04:09:22,156 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000001 size is 41, Max size: 100000000 2026-04-14 04:09:22,156 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\temp\bab46678-5e73-4523-9dd3-8bbcef6f3df0.tmp": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\temp\\bab46678-5e73-4523-9dd3-8bbcef6f3df0.tmp' 2026-04-14 04:09:22,156 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\temp\dc84d642-186b-45f8-b9c6-6e17e6feee3f.tmp": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\temp\\dc84d642-186b-45f8-b9c6-6e17e6feee3f.tmp' 2026-04-14 04:09:22,156 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\6ff088e8-aaa2-4072-9649-feb065e97630.tmp does not exist, skipping 2026-04-14 04:09:22,156 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\7dadc225-9d11-47ef-aadc-71d10289ac30.tmp does not exist, skipping 2026-04-14 04:09:22,156 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\80b5107f-8821-4775-bc73-d3dff4e26f4e.tmp does not exist, skipping 2026-04-14 04:09:22,156 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\temp\c12eca5d-579f-400c-ab85-2e06e51eec47.tmp": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\temp\\c12eca5d-579f-400c-ab85-2e06e51eec47.tmp' 2026-04-14 04:09:22,156 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\data_reduction_proxy_leveldb\000038.dbtmp does not exist, skipping 2026-04-14 04:09:22,156 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Last Browser size is 106, Max size: 100000000 2026-04-14 04:09:22,171 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\129c29e3-0c30-4763-9ad5-ab6034b32198.tmp does not exist, skipping 2026-04-14 04:09:22,171 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,187 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,187 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,203 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,203 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,218 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,218 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,218 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,218 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,234 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,234 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache size is 950, Max size: 100000000 2026-04-14 04:09:22,234 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,249 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,265 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\766bcae1-de0e-45b0-89f4-6a050c3a979f.tmp does not exist, skipping 2026-04-14 04:09:22,265 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,281 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,296 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,312 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,328 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\49f92ecc-3c92-4e05-98cf-93924d4c677e.tmp does not exist, skipping 2026-04-14 04:09:22,328 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\effd3eb4-84ba-43b9-a169-f52dcfeac960.tmp does not exist, skipping 2026-04-14 04:09:22,328 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\e7334b49-97cb-4c32-82ea-ec7b681db51b.tmp does not exist, skipping 2026-04-14 04:09:22,328 [root] WARNING: Folder at path "C:\wzMwqPEfuI\debugger" does not exist, skipping 2026-04-14 04:09:22,328 [root] INFO: Uploading files at path "C:\wzMwqPEfuI\tlsdump" 2026-04-14 04:09:22,328 [lib.common.results] INFO: File C:\wzMwqPEfuI\tlsdump\tlsdump.log size is 4384, Max size: 100000000 2026-04-14 04:09:22,343 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win7office2k3flash2800137TWN3H106 | win7office2k3flash2800137TWN3H106 | KVM | 2026-04-14 10:06:30 | 2026-04-14 10:09:33 | internet |
| File Name | Silver Birch _ 217_.html |
|---|---|
| File Size | 27094 bytes |
| File Type | HTML document, UTF-8 Unicode text, with CRLF line terminators |
| MD5 | 65a27e394fa8a4aa14e7ec4d5d695fda |
| SHA1 | 5bb5ff4e1eb0390e53bf5daa225f8866a9f617e4 |
| SHA256 | c17489cfc96c1a040dc3ce6532563e223a8c664f400597bdad90adb56d936a03 |
| SHA512 | cf54bbe0505e0dff4f025aaebe2b00a100dbd466e389c49e7bf623dae1f48799396c805c68e1e5f8d8b551f15c709f90274cc22949f8597f401d401f07ebc6a6 |
| SHA3-384 | bd08648332f3a10e45bccafa5eed9dd51c32adb8cbe63800374ba4ceb497168b03d8c5d7455fed8bad53c0768b0533db |
| CRC32 | 04BFD427 |
| TLSH | T1AEC29336A9C0143601B353BA6A719F58FFA38207D6025A0635BE56DB2FF6C808D67F5C |
| Ssdeep | 384:Xt4QhLNmT5oxCvymv61AAoO5Hm8L9D+cpkqQEvVvjtMB:Xt4eLNmT5vv6EqXBEqQSiB |
File
|
|
<!doctype html>
<html lang="en" class="h-100">
<head>
<!-- Required meta tags -->
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
<title>Silver Birch – 217 m² sold £59k | SA66 7LF</title>
<meta name="description"
content="Shows plot boundary on a map, planning applications. Value of £274 per sqm (25/ft²) on 2002-11-08.">
<meta name="geo.region" content="GB">
<meta name="geo.placename" content="United Kingdom">
<meta name="language" content="en-GB">
<link rel="shortcut icon" href="https://dfwqq1t8g50i2.cloudfront.net/static/favicon.ico">
<link rel="apple-touch-icon" sizes="180x180" href="https://dfwqq1t8g50i2.cloudfront.net/static/apple-touch-icon.png">
<!-- Nullify requests for other sizes and precomposed versions -->
<link rel="apple-touch-icon" sizes="120x120" href="data:,">
<link rel="apple-touch-icon-precomposed" href="data:,">
<link rel="apple-touch-icon" sizes="120x120-precomposed" href="data:,">
<link rel="canonical"
href="https://housemetric.co.uk/5962480/SA66-7LF/Silver+Birch" />
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/bootstrap@5.0.0-beta1/dist/css/bootstrap.min.css">
<script>window.STATIC_CDN_URL = "https://dfwqq1t8g50i2.cloudfront.net";</script>
<!-- Global site tag (gtag.js) - Google Analytics -->
<script async src="https://www.googletagmanager.com/gtag/js?id=G-LL8JR2NFTT"></script>
<script>
window.dataLayer = window.dataLayer || [];
function gtag() {
dataLayer.push(arguments);
}
gtag('js', new Date());
gtag('config', 'G-LL8JR2NFTT');
</script>
<style>
/*custom description list styling - used by all users*/
.custom-dl dt {
width: 100%;
}
@media (min-width: 768px) {
.custom-dl dt {
width: 25%;
}
}
.custom-dl dd {
width: 100%;
}
@media (min-width: 768px) {
.custom-dl dd {
width: 75%;
}
}
/* Premium content styles - only load for premium users */
</style>
<!-- Structured Data for SEO -->
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "House",
"name": "Silver Birch SA66 7LF",
"description": "Property sold for £59,500 in November 2002. 217 square metres (2,336 square feet). Price per square metre: £274. Has 1 planning application on record.",
"url": "https://housemetric.co.uk/5962480/SA66-7LF/Silver+Birch",
"address": {
"@type": "PostalAddress",
"streetAddress": "Silver Birch",
"addressLocality": "Llandissilio",
"postalCode": "SA66 7LF",
"addressCountry": "GB"
},
"floorSize": {
"@type": "QuantitativeValue",
"value": 217,
"unitCode": "MTK"
},
"additionalProperty": [
{
"@type": "PropertyValue",
"name": "Last Sold Price",
"value": 59500,
"unitCode": "GBP"
}
,{
"@type": "PropertyValue",
"name": "Sale Date",
"value": "2002-11-08"
}
,{
"@type": "PropertyValue",
"name": "Price per square metre",
"value": 274,
"unitCode": "GBP"
}
,
{
"@type": "PropertyValue",
"name": "Planning Application 1",
"value": "Full and householder planning - Approved (July 2008)"
}
],
"hasMap": "https://housemetric.co.uk/5962480/SA66-7LF/Silver+Birch",
"publisher": {
"@type": "Organization",
"name": "HouseMetric",
"url": "https://housemetric.co.uk"
}
}
</script>
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "BreadcrumbList",
"itemListElement": [{
"@type": "ListItem",
"item": "https://housemetric.co.uk",
"name": "Home",
"position": 1
},{
"@type": "ListItem",
"item": "https://housemetric.co.uk/analysis/sector/SA66-7/Llandissilio",
"name": "SA66 7",
"position": 2
},{
"@type": "ListItem",
"item": "https://housemetric.co.uk/house-prices/na/SA66-7LF/",
"name": "SA66 7LF",
"position": 3
},{
"@type": "ListItem",
"item": "https://housemetric.co.uk/5962480/SA66-7LF/Silver+Birch",
"name": "Silver Birch",
"position": 4
}]
}
</script>
</head>
<body class="d-flex flex-column h-100">
<nav class="navbar navbar-expand-md navbar-dark pt-2 pb-2 mb-2" style="background-color: #234e70;" aria-label="navbar">
<div class="container-fluid">
<a class="navbar-brand pt-0" href="/">
<span class="mb-0 fs-4">HouseMetric</span>
</a>
<button class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target="#navbarsExample04" aria-controls="navbarsExample04" aria-expanded="false" aria-label="Toggle navigation">
<span class="navbar-toggler-icon"></span>
</button>
<div class="collapse navbar-collapse" id="navbarsExample04">
<ul class="navbar-nav me-auto mb-2 mb-md-0">
<li class="nav-item">
<a class="nav-link hover-underline"
href="/map/SA66-7/">
Map</a>
</li>
<li class="nav-item dropdown">
<a class="nav-link dropdown-toggle hover-underline" href="#" id="market-analysis-dropdown" data-bs-toggle="dropdown" aria-expanded="false">
Analysis
</a>
<ul class="dropdown-menu" aria-labelledby="market-analysis-dropdown">
<li><a class="dropdown-item hover-underline" href="/geography-search">Local analysis</a></li>
<li><a class="dropdown-item hover-underline" href="/custom-charts">Custom histogram</a></li>
</ul>
</li>
<li class="nav-item dropdown">
<a class="nav-link dropdown-toggle hover-underline" href="#" id="rawDataDropdown" role="button" data-bs-toggle="dropdown" aria-expanded="false">
Search
</a>
<ul class="dropdown-menu" aria-labelledby="rawDataDropdown">
<li><a class="dropdown-item hover-underline" href="/basic-search">Basic search</a></li>
<li><a class="dropdown-item hover-underline" href="/advanced-search">Advanced search</a></li>
<li><a class="dropdown-item hover-underline" href="/epc-search">EPC search</a></li>
<li><a class="dropdown-item hover-underline" href="/company-search">Company search</a></li>
</ul>
</li>
</ul>
<ul class="navbar-nav">
<li class="nav-item">
<a class="nav-link hover-underline" href="/login">Login</a>
</li>
</ul>
</div>
</div>
</nav>
<style>
.hover-underline {
position: relative;
text-decoration: none;
}
.hover-underline::after {
content: '';
position: absolute;
width: 100%;
height: 2px;
bottom: 0;
left: 0;
background-color: #fff;
transform: scaleX(0);
transition: transform 0.3s ease-out;
}
.hover-underline:hover::after {
transform: scaleX(1);
}
.dropdown-menu {
background-color: #234e70;
}
.dropdown-item {
color: rgba(255, 255, 255, 0.55);
}
.dropdown-item:hover, .dropdown-item:focus {
background-color: rgba(255, 255, 255, 0.1);
color: #fff;
}
.dropdown-item.hover-underline::after {
bottom: 2px;
}
</style>
<!-- BEGIN page content (includes messages and app_content)-->
<main>
<div class="container-xxl">
<!-- messageblock -->
<!-- app_content block-->
<!-- Breadcrumbs -->
<div>
<nav aria-label="breadcrumb">
<ol class="breadcrumb">
<li class="breadcrumb-item"><a
href="https://housemetric.co.uk/analysis/sector/SA66-7/Llandissilio">SA66 7</a></li>
<truncated>
|
| Direct | IP | Country Name |
|---|---|---|
| N | 142.250.151.94 [VT] | United States |
| N | 52.222.161.174 [VT] | United States |
| N | 192.178.223.84 [VT] | United States |
| Y | 8.8.8.8 [VT] | United States |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| accounts.google.com [VT] | A 192.178.223.84 [VT] | 192.178.223.84 [VT] |
| dfwqq1t8g50i2.cloudfront.net [VT] |
A 52.222.161.174
[VT]
A 52.222.161.164 [VT] A 52.222.161.171 [VT] A 52.222.161.106 [VT] |
52.222.161.106 [VT] |
| _googlecast._tcp.local [VT] | ||
| www.gstatic.com [VT] | A 142.250.151.94 [VT] | 142.250.140.94 [VT] |
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP