| Category | Package | Started | Completed | Duration | Options | Log |
|---|---|---|---|---|---|---|
| FILE | chrome | 2026-04-14 10:06:35 | 2026-04-14 10:09:38 | 183 seconds | Show Options | Show Log |
procdump=1
amsidump=1
2025-12-02 01:31:19,000 [root] INFO: Date set to: 20260414T03:06:29, timeout set to: 150 2026-04-14 04:06:29,015 [root] DEBUG: Starting analyzer from: C:\tmpn7j73yx1 2026-04-14 04:06:29,015 [root] DEBUG: Storing results at: C:\xIxZfzpRZ 2026-04-14 04:06:29,015 [root] DEBUG: Pipe server name: \\.\PIPE\CQGnLcofE 2026-04-14 04:06:29,015 [root] DEBUG: Python path: C:\olddocs 2026-04-14 04:06:29,015 [root] DEBUG: No analysis package specified, trying to detect it automagically 2026-04-14 04:06:29,015 [root] INFO: Automatically selected analysis package "chrome" 2026-04-14 04:06:29,015 [root] DEBUG: Importing analysis package "chrome"... 2026-04-14 04:06:29,031 [root] DEBUG: Initializing analysis package "chrome"... 2026-04-14 04:06:29,031 [root] INFO: Analyzer: Package modules.packages.chrome does not specify a DLL option 2026-04-14 04:06:29,031 [root] INFO: Analyzer: Package modules.packages.chrome does not specify a DLL_64 option 2026-04-14 04:06:29,031 [root] INFO: Analyzer: Package modules.packages.chrome does not specify a loader option 2026-04-14 04:06:29,031 [root] INFO: Analyzer: Package modules.packages.chrome does not specify a loader_64 option 2026-04-14 04:06:29,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2026-04-14 04:06:29,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2026-04-14 04:06:29,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2026-04-14 04:06:29,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2026-04-14 04:06:29,140 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2026-04-14 04:06:29,156 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2026-04-14 04:06:29,187 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2026-04-14 04:06:29,187 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2026-04-14 04:06:29,203 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2026-04-14 04:06:29,203 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-04-14 04:06:29,296 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2026-04-14 04:06:29,296 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2026-04-14 04:06:29,312 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2026-04-14 04:06:29,312 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2026-04-14 04:06:29,312 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2026-04-14 04:06:29,312 [root] DEBUG: Initializing auxiliary module "Browser"... 2026-04-14 04:06:29,312 [root] DEBUG: Started auxiliary module Browser 2026-04-14 04:06:29,312 [root] DEBUG: Initializing auxiliary module "Curtain"... 2026-04-14 04:06:29,312 [root] DEBUG: Started auxiliary module Curtain 2026-04-14 04:06:29,312 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2026-04-14 04:06:29,359 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2026-04-14 04:06:29,359 [root] DEBUG: Started auxiliary module DefaultApps 2026-04-14 04:06:29,359 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2026-04-14 04:06:29,359 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2026-04-14 04:06:29,359 [modules.auxiliary.digisig] INFO: dummy 2026-04-14 04:06:29,359 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2026-04-14 04:06:29,375 [root] DEBUG: Started auxiliary module DigiSig 2026-04-14 04:06:29,375 [root] DEBUG: Initializing auxiliary module "Disguise"... 2026-04-14 04:06:29,687 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2026-04-14 04:06:29,687 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2026-04-14 04:06:29,687 [root] DEBUG: Initializing auxiliary module "Evtx"... 2026-04-14 04:06:29,687 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpn7j73yx1\bin\auditpol.csv 2026-04-14 04:06:29,890 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:06:31,000 [root] DEBUG: Started auxiliary module Evtx 2026-04-14 04:06:31,000 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2026-04-14 04:06:31,000 [modules.auxiliary.fiddler] INFO: fiddler package: dummy 2026-04-14 04:06:31,015 [root] DEBUG: Started auxiliary module Fiddler 2026-04-14 04:06:31,015 [root] DEBUG: Initializing auxiliary module "Human"... 2026-04-14 04:06:31,015 [root] DEBUG: Started auxiliary module Human 2026-04-14 04:06:31,015 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2026-04-14 04:06:31,015 [root] DEBUG: Started auxiliary module Screenshots 2026-04-14 04:06:31,015 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2026-04-14 04:06:31,015 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2026-04-14 04:06:31,015 [root] DEBUG: Started auxiliary module Sysmon 2026-04-14 04:06:31,015 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2026-04-14 04:06:31,015 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2026-04-14 04:06:31,015 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2026-04-14 04:06:31,031 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 560 2026-04-14 04:06:31,031 [lib.api.process] INFO: Monitor config for process 560: C:\tmpn7j73yx1\dll\560.ini 2026-04-14 04:06:31,031 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2026-04-14 04:06:31,031 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2026-04-14 04:06:31,031 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2026-04-14 04:06:31,031 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpn7j73yx1\dll\ySRzCS.dll, loader C:\tmpn7j73yx1\bin\mTYBCMuS.exe 2026-04-14 04:06:31,078 [root] DEBUG: Loader: Injecting process 560 with C:\tmpn7j73yx1\dll\ySRzCS.dll. 2026-04-14 04:06:31,125 [root] DEBUG: 560: Python path set to 'C:\olddocs'. 2026-04-14 04:06:31,125 [root] DEBUG: 560: Disabling sleep skipping. 2026-04-14 04:06:31,125 [root] DEBUG: 560: Process dumps enabled. 2026-04-14 04:06:31,125 [root] DEBUG: 560: AMSI dumping enabled. 2026-04-14 04:06:31,125 [root] DEBUG: 560: TLS secret dump mode enabled. 2026-04-14 04:06:31,140 [root] DEBUG: 560: Monitor initialised: 64-bit capemon loaded in process 560 at 0x000007FEF5C00000, thread 2900, image base 0x00000000FF510000, stack from 0x0000000001A72000-0x0000000001A80000 2026-04-14 04:06:31,140 [root] DEBUG: 560: Commandline: C:\Windows\system32\lsass.exe 2026-04-14 04:06:31,156 [root] DEBUG: 560: Hooked 5 out of 5 functions 2026-04-14 04:06:31,156 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-04-14 04:06:31,156 [root] DEBUG: Successfully injected DLL C:\tmpn7j73yx1\dll\ySRzCS.dll. 2026-04-14 04:06:31,156 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 560 2026-04-14 04:06:31,156 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2026-04-14 04:06:31,156 [root] DEBUG: Initializing auxiliary module "Usage"... 2026-04-14 04:06:31,156 [root] DEBUG: Started auxiliary module Usage 2026-04-14 04:06:33,203 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2026-04-14 04:06:33,906 [root] INFO: Restarting WMI Service 2026-04-14 04:06:38,062 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files\Google\Chrome\Application\chrome.exe" with arguments "--no-sandbox --test-type --ignore-ssl-errors "C:\Users\pgabriel\AppData\Local\Temp\Minyrefydd _ 221_m_.html"" with pid 2252 2026-04-14 04:06:38,062 [lib.api.process] INFO: Monitor config for process 2252: C:\tmpn7j73yx1\dll\2252.ini 2026-04-14 04:06:38,062 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2026-04-14 04:06:38,062 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2026-04-14 04:06:38,062 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpn7j73yx1\dll\ySRzCS.dll, loader C:\tmpn7j73yx1\bin\mTYBCMuS.exe 2026-04-14 04:06:38,078 [root] DEBUG: Loader: Injecting process 2252 (thread 2208) with C:\tmpn7j73yx1\dll\ySRzCS.dll. 2026-04-14 04:06:38,078 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-04-14 04:06:38,093 [root] DEBUG: Successfully injected DLL C:\tmpn7j73yx1\dll\ySRzCS.dll. 2026-04-14 04:06:38,093 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 2252 2026-04-14 04:06:40,093 [lib.api.process] INFO: Successfully resumed process with pid 2252 2026-04-14 04:06:40,156 [root] DEBUG: 2252: Python path set to 'C:\olddocs'. 2026-04-14 04:06:40,156 [root] DEBUG: 2252: Disabling sleep skipping. 2026-04-14 04:06:40,156 [root] DEBUG: 2252: Process dumps enabled. 2026-04-14 04:06:40,156 [root] DEBUG: 2252: AMSI dumping enabled. 2026-04-14 04:06:40,156 [root] DEBUG: 2252: Dropped file limit defaulting to 100. 2026-04-14 04:06:40,171 [root] DEBUG: 2252: Chrome-specific hook-set enabled. 2026-04-14 04:06:40,171 [root] DEBUG: 2252: Monitor initialised: 64-bit capemon loaded in process 2252 at 0x000007FEF5C00000, thread 2208, image base 0x000000013F490000, stack from 0x00000000009A2000-0x00000000009B0000 2026-04-14 04:06:40,171 [root] DEBUG: 2252: Commandline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-sandbox --test-type --ignore-ssl-errors "C:\Users\pgabriel\AppData\Local\Temp\Minyrefydd _ 221_m_.html" 2026-04-14 04:06:40,187 [root] DEBUG: 2252: Hooked 16 out of 16 functions 2026-04-14 04:06:40,218 [root] DEBUG: 2252: RestoreHeaders: Restored original import table. 2026-04-14 04:06:40,218 [root] INFO: Loaded monitor into process with pid 2252 2026-04-14 04:06:40,218 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD140000: C:\Windows\system32\cryptbase (0xf000 bytes). 2026-04-14 04:06:40,234 [root] DEBUG: 2252: DLL loaded at 0x000007FEF8EA0000: C:\Windows\system32\WINMM (0x3b000 bytes). 2026-04-14 04:06:40,234 [root] DEBUG: 2252: caller_dispatch: Added region at 0x000000013F490000 to tracked regions list (ntdll::NtClose returns to 0x000000013F597089, thread 2208). 2026-04-14 04:06:40,234 [root] DEBUG: 2252: caller_dispatch: Scanning calling region at 0x000000013F490000... 2026-04-14 04:06:40,249 [root] DEBUG: 2252: ProcessImageBase: Main module image at 0x000000013F490000 unmodified (entropy change 0.000000e+00) 2026-04-14 04:06:40,249 [root] DEBUG: 2252: DLL loaded at 0x000007FEFC020000: C:\Windows\system32\ntmarta (0x2d000 bytes). 2026-04-14 04:06:40,249 [root] DEBUG: 2252: DLL loaded at 0x000007FEFF190000: C:\Windows\system32\WLDAP32 (0x52000 bytes). 2026-04-14 04:06:40,249 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 3020: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:40,249 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3020 2026-04-14 04:06:40,265 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD0E0000: C:\Windows\system32\apphelp (0x57000 bytes). 2026-04-14 04:06:40,265 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3020 2026-04-14 04:06:40,281 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat 2026-04-14 04:06:40,281 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAAA0000: C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0 (0x4000 bytes). 2026-04-14 04:06:40,296 [root] DEBUG: 2252: DLL loaded at 0x000007FEFE360000: C:\Windows\system32\shell32 (0xd88000 bytes). 2026-04-14 04:06:43,203 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:06:45,203 [root] DEBUG: 2252: DLL loaded at 0x000007FEDF1A0000: C:\Program Files\Google\Chrome\Application\92.0.4515.131\chrome (0xa41f000 bytes). 2026-04-14 04:06:45,218 [root] DEBUG: 2252: DLL loaded at 0x000007FEEB6A0000: C:\Windows\system32\dbghelp (0x125000 bytes). 2026-04-14 04:06:45,218 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB010000: C:\Windows\system32\IPHLPAPI (0x27000 bytes). 2026-04-14 04:06:45,218 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB080000: C:\Windows\system32\WINNSI (0xb000 bytes). 2026-04-14 04:06:45,249 [root] DEBUG: 2252: DLL loaded at 0x000007FEEB5E0000: C:\Windows\system32\UIAutomationCore (0xba000 bytes). 2026-04-14 04:06:45,249 [root] DEBUG: 2252: DLL loaded at 0x00000000776F0000: C:\Windows\system32\PSAPI (0x7000 bytes). 2026-04-14 04:06:45,265 [root] DEBUG: 2252: DLL loaded at 0x000007FEF2120000: C:\Windows\system32\OLEACC (0x54000 bytes). 2026-04-14 04:06:45,265 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD070000: C:\Windows\system32\Secur32 (0xb000 bytes). 2026-04-14 04:06:45,265 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD410000: C:\Windows\system32\USERENV (0x1e000 bytes). 2026-04-14 04:06:45,265 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD2E0000: C:\Windows\system32\profapi (0xf000 bytes). 2026-04-14 04:06:45,265 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD470000: C:\Windows\system32\WINTRUST (0x3b000 bytes). 2026-04-14 04:06:45,312 [root] DEBUG: 2252: DLL loaded at 0x000007FEEEE30000: C:\Windows\system32\DWrite (0x196000 bytes). 2026-04-14 04:06:45,328 [root] DEBUG: 2252: DLL loaded at 0x000007FEF9A40000: C:\Windows\system32\WINSPOOL.DRV (0x71000 bytes). 2026-04-14 04:06:45,343 [root] DEBUG: 2252: DLL loaded at 0x000007FEFA290000: C:\Windows\system32\WINHTTP (0x71000 bytes). 2026-04-14 04:06:45,359 [root] DEBUG: 2252: DLL loaded at 0x000007FEFA220000: C:\Windows\system32\webio (0x65000 bytes). 2026-04-14 04:06:45,359 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAE80000: C:\Windows\system32\dhcpcsvc (0x18000 bytes). 2026-04-14 04:06:45,375 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAAA0000: C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0 (0x4000 bytes). 2026-04-14 04:06:45,375 [root] DEBUG: 2252: DLL loaded at 0x000007FEFE360000: C:\Windows\system32\shell32 (0xd88000 bytes). 2026-04-14 04:06:45,406 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB8A0000: C:\Windows\system32\uxtheme (0x56000 bytes). 2026-04-14 04:06:45,406 [root] DEBUG: 2252: DLL loaded at 0x000007FEFC590000: C:\Windows\system32\GPAPI (0x1b000 bytes). 2026-04-14 04:06:45,421 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAC90000: C:\Windows\system32\wkscli (0x15000 bytes). 2026-04-14 04:06:45,421 [root] DEBUG: 2252: DLL loaded at 0x000007FEFACF0000: C:\Windows\system32\netutils (0xc000 bytes). 2026-04-14 04:06:45,500 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAD00000: C:\Windows\system32\netapi32 (0x16000 bytes). 2026-04-14 04:06:45,500 [root] DEBUG: 2252: DLL loaded at 0x000007FEFCE60000: C:\Windows\system32\srvcli (0x23000 bytes). 2026-04-14 04:06:45,515 [root] DEBUG: 2252: DLL loaded at 0x000007FEFBD10000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\COMCTL32 (0x1f4000 bytes). 2026-04-14 04:06:45,562 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB390000: C:\Windows\system32\NLAapi (0x15000 bytes). 2026-04-14 04:06:45,578 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAEE0000: C:\Windows\system32\dhcpcsvc6 (0x11000 bytes). 2026-04-14 04:06:45,593 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB4C0000: C:\Windows\system32\dwmapi (0x18000 bytes). 2026-04-14 04:06:45,593 [root] DEBUG: 2252: DLL loaded at 0x000007FEFF0F0000: C:\Windows\system32\CLBCatQ (0x99000 bytes). 2026-04-14 04:06:45,593 [root] DEBUG: 2252: DLL loaded at 0x000007FEFE360000: C:\Windows\system32\SHELL32 (0xd88000 bytes). 2026-04-14 04:06:45,609 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAEC0000: C:\Windows\system32\WTSAPI32 (0x11000 bytes). 2026-04-14 04:06:45,625 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD210000: C:\Windows\system32\WINSTA (0x3d000 bytes). 2026-04-14 04:06:45,656 [root] DEBUG: 2252: DLL loaded at 0x000007FEEB540000: C:\Windows\system32\mscms (0x9c000 bytes). 2026-04-14 04:06:45,656 [root] DEBUG: 2252: DLL loaded at 0x000007FEFBBE0000: C:\Windows\System32\MMDevApi (0x4b000 bytes). 2026-04-14 04:06:45,656 [root] DEBUG: 2252: DLL loaded at 0x000007FEFBAB0000: C:\Windows\System32\PROPSYS (0x12c000 bytes). 2026-04-14 04:06:45,671 [root] DEBUG: 2252: DLL loaded at 0x000007FEFF2D0000: C:\Windows\system32\SETUPAPI (0x1d7000 bytes). 2026-04-14 04:06:45,671 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 2624: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:45,671 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD430000: C:\Windows\system32\CFGMGR32 (0x36000 bytes). 2026-04-14 04:06:45,671 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 2624 2026-04-14 04:06:45,671 [root] DEBUG: 2252: DLL loaded at 0x000007FEFD680000: C:\Windows\system32\DEVOBJ (0x1a000 bytes). 2026-04-14 04:06:45,671 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 2624 2026-04-14 04:06:45,687 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index 2026-04-14 04:06:45,687 [root] DEBUG: 2252: DLL loaded at 0x000007FEEF9E0000: C:\Windows\System32\Wpc (0x6f000 bytes). 2026-04-14 04:06:45,703 [root] DEBUG: 2252: DLL loaded at 0x000007FEFCCF0000: C:\Windows\System32\wevtapi (0x6d000 bytes). 2026-04-14 04:06:45,703 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 1812: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:45,703 [root] DEBUG: 2252: DLL loaded at 0x000007FEFABF0000: C:\Windows\system32\samcli (0x14000 bytes). 2026-04-14 04:06:45,718 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 1812 2026-04-14 04:06:45,718 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Last Version 2026-04-14 04:06:45,718 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 1812 2026-04-14 04:06:45,718 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB920000: C:\Windows\system32\SAMLIB (0x1d000 bytes). 2026-04-14 04:06:45,765 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 216: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:45,765 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 216 2026-04-14 04:06:45,765 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 216 2026-04-14 04:06:45,781 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History 2026-04-14 04:06:45,843 [root] DEBUG: 2252: DLL loaded at 0x000007FEFC3E0000: C:\Windows\system32\FirewallAPI (0xbb000 bytes). 2026-04-14 04:06:45,875 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF13e727.TMP size is 327, Max size: 100000000 2026-04-14 04:06:45,875 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOCK 2026-04-14 04:06:45,875 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\MANIFEST-000001 2026-04-14 04:06:45,875 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\000003.log 2026-04-14 04:06:45,875 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG 2026-04-14 04:06:45,875 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\000003.log size is 0, Max size: 100000000 2026-04-14 04:06:45,890 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\CURRENT size is 16, Max size: 100000000 2026-04-14 04:06:45,906 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG size is 351, Max size: 100000000 2026-04-14 04:06:45,906 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old size is 311, Max size: 100000000 2026-04-14 04:06:45,921 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\MANIFEST-000001 size is 41, Max size: 100000000 2026-04-14 04:06:45,937 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOCK size is 0, Max size: 100000000 2026-04-14 04:06:45,968 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\MANIFEST-000001 2026-04-14 04:06:45,984 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\000001.dbtmp 2026-04-14 04:06:46,000 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:06:46,390 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\ccb0ef20-3dd7-48c2-9a5e-93bc2c6e8172.tmp 2026-04-14 04:06:46,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\ccb0ef20-3dd7-48c2-9a5e-93bc2c6e8172.tmp size is 1, Max size: 100000000 2026-04-14 04:06:46,500 [lib.common.results] INFO: File 1776164806296875000.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:06:46,531 [lib.common.results] INFO: File 1776164806312500000.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:06:46,531 [lib.common.results] INFO: File 1776164806281250000.Application.evtx.gz size is 6956, Max size: 100000000 2026-04-14 04:06:46,609 [lib.common.results] INFO: File 1776164806437500000.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:06:46,625 [lib.common.results] INFO: File 1776164806484375000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:06:46,656 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAAA0000: C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0 (0x4000 bytes). 2026-04-14 04:06:46,656 [lib.common.results] INFO: File 1776164806515625000.Security.evtx.gz size is 16009, Max size: 100000000 2026-04-14 04:06:46,671 [lib.common.results] INFO: File 1776164806531250000.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:06:46,734 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF13eaa2.TMP size is 329, Max size: 100000000 2026-04-14 04:06:46,750 [lib.common.results] INFO: File 1776164806609375000.System.evtx.gz size is 8716, Max size: 100000000 2026-04-14 04:06:46,765 [lib.common.results] INFO: File 1776164806609375000.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:06:46,796 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\GrShaderCache\GPUCache\index 2026-04-14 04:06:46,812 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001 2026-04-14 04:06:46,828 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log 2026-04-14 04:06:46,890 [root] DEBUG: 2252: DLL loaded at 0x000007FEFBC30000: C:\Windows\system32\POWRPROF (0x2c000 bytes). 2026-04-14 04:06:46,924 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index 2026-04-14 04:06:46,924 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 1820: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:46,924 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 1820 2026-04-14 04:06:46,924 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 1820 2026-04-14 04:06:46,940 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 200: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:46,940 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 200 2026-04-14 04:06:47,133 [root] DEBUG: 2252: DLL loaded at 0x000007FEF9780000: C:\Windows\system32\explorerframe (0x1ca000 bytes). 2026-04-14 04:06:47,133 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB530000: C:\Windows\system32\DUser (0x43000 bytes). 2026-04-14 04:06:47,180 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB580000: C:\Windows\system32\DUI70 (0xf2000 bytes). 2026-04-14 04:06:47,196 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old~RF13ec57.TMP size is 317, Max size: 100000000 2026-04-14 04:06:47,229 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000001 2026-04-14 04:06:47,276 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 1776: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:47,276 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 1776 2026-04-14 04:06:47,276 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 1776 2026-04-14 04:06:47,345 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG 2026-04-14 04:06:47,360 [root] DEBUG: 2252: DLL loaded at 0x000007FEEF380000: C:\Windows\system32\wlanapi (0x20000 bytes). 2026-04-14 04:06:47,368 [root] DEBUG: 2252: DLL loaded at 0x000007FEFACB0000: C:\Windows\system32\wlanutil (0x7000 bytes). 2026-04-14 04:06:47,398 [root] DEBUG: 2252: DLL loaded at 0x000007FEFBC30000: C:\Windows\system32\POWRPROF (0x2c000 bytes). 2026-04-14 04:06:47,409 [root] DEBUG: 2252: DLL loaded at 0x000007FEFBC30000: C:\Windows\system32\POWRPROF (0x2c000 bytes). 2026-04-14 04:06:47,453 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 1960: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:47,460 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 1960 2026-04-14 04:06:47,462 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 1960 2026-04-14 04:06:47,503 [root] DEBUG: 2252: DLL loaded at 0x000007FEFCA30000: C:\Windows\system32\mswsock (0x55000 bytes). 2026-04-14 04:06:47,510 [root] DEBUG: 2252: DLL loaded at 0x000007FEFC4A0000: C:\Windows\System32\wshtcpip (0x7000 bytes). 2026-04-14 04:06:47,617 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\bd5f3c8b-a2f5-40ac-8db0-6a9590b97347.tmp 2026-04-14 04:06:47,640 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF13ee0d.TMP size is 9213, Max size: 100000000 2026-04-14 04:06:47,716 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\a3a7a75b-1f7e-40ba-8d9c-0be7ab7f6d33.tmp 2026-04-14 04:06:47,727 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old~RF13ee3b.TMP size is 323, Max size: 100000000 2026-04-14 04:06:47,737 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF13ee7a.TMP size is 9054, Max size: 100000000 2026-04-14 04:06:47,916 [root] DEBUG: 560: DLL loaded at 0x000007FEF8CD0000: C:\Windows\system32\keyiso (0xb000 bytes). 2026-04-14 04:06:47,946 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\b2be79ea-1479-4bdf-851d-346a6a6a4f8c.tmp 2026-04-14 04:06:48,002 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\c173785e-3285-4249-871e-e1ebfcef5048.tmp 2026-04-14 04:06:48,134 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\6b579f61-4572-4118-a1c6-f74e948dfbb0.tmp 2026-04-14 04:06:48,134 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\9b73eeed-f5b4-42fb-a184-71517e121a51.tmp 2026-04-14 04:06:48,396 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mpbjkejclgfgadiemmefgebjfooflfhl\LOG.old~RF13f10a.TMP size is 405, Max size: 100000000 2026-04-14 04:06:48,405 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164808.4042966.sysmon.evtx.gz to host 2026-04-14 04:06:48,405 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 28131, Max size: 100000000 2026-04-14 04:06:48,460 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF13f158.TMP size is 405, Max size: 100000000 2026-04-14 04:06:48,599 [root] DEBUG: 560: DLL loaded at 0x000007FEDDFE0000: C:\Windows\system32\dssenh (0x32000 bytes). 2026-04-14 04:06:48,635 [root] DEBUG: 560: TLS 1.2 secrets logged to: C:\xIxZfzpRZ\tlsdump\tlsdump.log 2026-04-14 04:06:48,712 [root] DEBUG: 560: DLL loaded at 0x000007FEFA580000: C:\Windows\system32\cryptnet (0x27000 bytes). 2026-04-14 04:06:48,713 [root] DEBUG: 560: DLL loaded at 0x000007FEFF190000: C:\Windows\system32\WLDAP32 (0x52000 bytes). 2026-04-14 04:06:48,787 [root] DEBUG: 2252: DLL loaded at 0x000007FEFCA90000: C:\Windows\system32\CRYPTSP (0x18000 bytes). 2026-04-14 04:06:48,793 [root] DEBUG: 2252: DLL loaded at 0x000007FEFC790000: C:\Windows\system32\rsaenh (0x47000 bytes). 2026-04-14 04:06:48,808 [root] DEBUG: 2252: DLL loaded at 0x000007FEFCC60000: C:\Windows\system32\ncrypt (0x50000 bytes). 2026-04-14 04:06:48,817 [root] DEBUG: 2252: DLL loaded at 0x000007FEFCBA0000: C:\Windows\system32\bcryptprimitives (0x4c000 bytes). 2026-04-14 04:06:48,967 [root] DEBUG: 2252: DLL loaded at 0x000007FEFA580000: C:\Windows\system32\cryptnet (0x27000 bytes). 2026-04-14 04:06:51,145 [root] DEBUG: 2252: DLL loaded at 0x000007FEEF380000: C:\Windows\system32\wlanapi (0x20000 bytes). 2026-04-14 04:06:51,145 [root] DEBUG: 2252: DLL loaded at 0x000007FEFACB0000: C:\Windows\system32\wlanutil (0x7000 bytes). 2026-04-14 04:06:51,161 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma size is 1048576, Max size: 100000000 2026-04-14 04:06:51,239 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-66299726-990.pma size is 4194304, Max size: 100000000 2026-04-14 04:06:51,317 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-69DE1FC5-8CC.pma size is 4194304, Max size: 100000000 2026-04-14 04:06:52,150 [root] DEBUG: 2252: DLL loaded at 0x000007FEDEDA0000: C:\Windows\system32\mf (0x3f1000 bytes). 2026-04-14 04:06:52,150 [root] DEBUG: 2252: DLL loaded at 0x000007FEFB330000: C:\Windows\system32\ATL (0x19000 bytes). 2026-04-14 04:06:52,150 [root] DEBUG: 2252: DLL loaded at 0x000007FEEECD0000: C:\Windows\system32\MFPlat (0x6d000 bytes). 2026-04-14 04:06:52,150 [root] DEBUG: 2252: DLL loaded at 0x000007FEFBA70000: C:\Windows\system32\AVRT (0x9000 bytes). 2026-04-14 04:06:52,166 [root] DEBUG: 2252: DLL loaded at 0x0000000074460000: C:\Windows\system32\ksuser (0x6000 bytes). 2026-04-14 04:06:52,166 [root] DEBUG: 2252: DLL loaded at 0x000007FEDDF90000: C:\Windows\system32\mfreadwrite (0x42000 bytes). 2026-04-14 04:06:53,155 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt size is 4, Max size: 100000000 2026-04-14 04:06:54,173 [lib.common.results] INFO: File c:\olddocs\1776164809158.saz size is 383787, Max size: 100000000 2026-04-14 04:06:54,220 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:06:54,762 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF1409f1.TMP size is 139, Max size: 100000000 2026-04-14 04:06:54,840 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Last Browser 2026-04-14 04:06:55,153 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 3232: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:55,153 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3232 2026-04-14 04:06:55,153 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3232 2026-04-14 04:06:55,262 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000038.dbtmp 2026-04-14 04:06:55,278 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF140be5.TMP size is 16, Max size: 100000000 2026-04-14 04:06:55,387 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000037.log size is 0, Max size: 100000000 2026-04-14 04:06:55,403 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000036 size is 50, Max size: 100000000 2026-04-14 04:06:55,637 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\f5ae6413-9fb0-41dd-9bd0-5366a79fa49c.tmp 2026-04-14 04:06:55,653 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Local State~RF140d5c.TMP size is 312116, Max size: 100000000 2026-04-14 04:06:55,825 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOG.old~RF140e18.TMP size is 0, Max size: 100000000 2026-04-14 04:06:55,833 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOCK 2026-04-14 04:06:55,834 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOG 2026-04-14 04:06:55,834 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOG.old~RF140e27.TMP size is 0, Max size: 100000000 2026-04-14 04:06:55,834 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOCK 2026-04-14 04:06:55,834 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOG 2026-04-14 04:06:55,850 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old~RF140e27.TMP size is 0, Max size: 100000000 2026-04-14 04:06:55,866 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 3304: C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\SwReporter\92.267.200\software_reporter_tool.exe, ImageBase: 0x000000013FAB0000 2026-04-14 04:06:55,866 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3304 2026-04-14 04:06:55,881 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3304 2026-04-14 04:06:55,881 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOCK 2026-04-14 04:06:55,881 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG 2026-04-14 04:06:55,897 [root] DEBUG: 2252: DLL loaded at 0x000007FEEF0D0000: C:\Windows\system32\bthprops.cpl (0xb5000 bytes). 2026-04-14 04:06:56,334 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old~RF14100c.TMP size is 0, Max size: 100000000 2026-04-14 04:06:56,397 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOCK 2026-04-14 04:06:56,397 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG 2026-04-14 04:06:56,413 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old~RF14105a.TMP size is 0, Max size: 100000000 2026-04-14 04:06:56,413 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOCK 2026-04-14 04:06:56,413 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG 2026-04-14 04:06:56,491 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache size is 6, Max size: 100000000 2026-04-14 04:06:56,553 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache 2026-04-14 04:06:56,616 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old~RF141135.TMP size is 333, Max size: 100000000 2026-04-14 04:06:56,979 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old~RF14128c.TMP size is 0, Max size: 100000000 2026-04-14 04:06:56,995 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOCK 2026-04-14 04:06:56,995 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG 2026-04-14 04:06:57,057 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 3492: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:06:57,057 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3492 2026-04-14 04:06:57,057 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old~RF1412ea.TMP size is 341, Max size: 100000000 2026-04-14 04:06:57,057 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3492 2026-04-14 04:06:57,120 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF141329.TMP size is 323, Max size: 100000000 2026-04-14 04:06:57,604 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\c36f0e58-4e7f-4500-ac4d-8179501a3c77.tmp 2026-04-14 04:06:57,604 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF14150d.TMP size is 9054, Max size: 100000000 2026-04-14 04:06:57,666 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOG.old~RF14154b.TMP size is 0, Max size: 100000000 2026-04-14 04:06:57,682 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOCK 2026-04-14 04:06:57,682 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOG 2026-04-14 04:06:57,729 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old~RF14158a.TMP size is 0, Max size: 100000000 2026-04-14 04:06:57,745 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOCK 2026-04-14 04:06:57,745 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG 2026-04-14 04:07:01,819 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:07:02,116 [lib.common.results] INFO: File 1776164822053710900.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:02,131 [lib.common.results] INFO: File 1776164822053710900.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:02,147 [lib.common.results] INFO: File 1776164822053710900.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:07:02,147 [lib.common.results] INFO: File 1776164822053710900.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:07:02,178 [lib.common.results] INFO: File 1776164822116210900.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:07:02,178 [lib.common.results] INFO: File 1776164822116210900.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:07:02,194 [lib.common.results] INFO: File 1776164822116210900.Security.evtx.gz size is 8036, Max size: 100000000 2026-04-14 04:07:02,194 [lib.common.results] INFO: File 1776164822116210900.System.evtx.gz size is 8526, Max size: 100000000 2026-04-14 04:07:02,241 [lib.common.results] INFO: File 1776164822178710900.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:07:03,417 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:07:04,074 [root] INFO: Process with pid 1960 has terminated 2026-04-14 04:07:07,001 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\a721ecf4-8b18-4d15-b82f-78e89206c31a.tmp 2026-04-14 04:07:07,017 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Module Info Cache~RF1439cb.TMP size is 66968, Max size: 100000000 2026-04-14 04:07:08,665 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164828.665039.sysmon.evtx.gz to host 2026-04-14 04:07:08,665 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 238250, Max size: 100000000 2026-04-14 04:07:12,335 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\fafc2258-f183-46a1-8a84-74163748914e.tmp 2026-04-14 04:07:12,351 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Local State~RF144e9b.TMP size is 398780, Max size: 100000000 2026-04-14 04:07:14,324 [lib.common.results] INFO: File c:\olddocs\1776164829305.saz size is 51225, Max size: 100000000 2026-04-14 04:07:14,324 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:07:17,272 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:07:17,522 [lib.common.results] INFO: File 1776164837459960900.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:17,522 [lib.common.results] INFO: File 1776164837459960900.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:17,538 [lib.common.results] INFO: File 1776164837459960900.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:07:17,553 [lib.common.results] INFO: File 1776164837475585900.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:07:17,600 [lib.common.results] INFO: File 1776164837522460900.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:07:17,600 [lib.common.results] INFO: File 1776164837522460900.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:07:17,600 [lib.common.results] INFO: File 1776164837522460900.Security.evtx.gz size is 7697, Max size: 100000000 2026-04-14 04:07:17,600 [lib.common.results] INFO: File 1776164837538085900.System.evtx.gz size is 8155, Max size: 100000000 2026-04-14 04:07:17,631 [lib.common.results] INFO: File 1776164837600585900.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:07:21,566 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\a29bdb05-eb2a-49a1-9e4f-6f25b7ce8969.tmp 2026-04-14 04:07:21,582 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF1472ae.TMP size is 9274, Max size: 100000000 2026-04-14 04:07:23,683 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:07:25,844 [root] DEBUG: 2252: DLL loaded at 0x000007FEFAD00000: C:\Windows\system32\NETAPI32 (0x16000 bytes). 2026-04-14 04:07:25,844 [root] DEBUG: 2252: DLL loaded at 0x000007FEFCE60000: C:\Windows\system32\srvcli (0x23000 bytes). 2026-04-14 04:07:25,860 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 3336: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:07:25,860 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3336 2026-04-14 04:07:25,860 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3336 2026-04-14 04:07:28,779 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164848.7792969.sysmon.evtx.gz to host 2026-04-14 04:07:28,779 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 23659, Max size: 100000000 2026-04-14 04:07:32,663 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:07:32,901 [lib.common.results] INFO: File 1776164852838867100.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:32,901 [lib.common.results] INFO: File 1776164852838867100.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:32,916 [lib.common.results] INFO: File 1776164852854492100.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:07:32,916 [lib.common.results] INFO: File 1776164852838867100.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:07:32,948 [lib.common.results] INFO: File 1776164852901367100.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:07:32,963 [lib.common.results] INFO: File 1776164852901367100.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:07:32,963 [lib.common.results] INFO: File 1776164852901367100.Security.evtx.gz size is 7704, Max size: 100000000 2026-04-14 04:07:32,979 [lib.common.results] INFO: File 1776164852916992100.System.evtx.gz size is 8045, Max size: 100000000 2026-04-14 04:07:32,995 [lib.common.results] INFO: File 1776164852948242100.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:07:34,435 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:07:35,861 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\10ebcb80-06a8-4a70-80bc-786a152d6260.tmp 2026-04-14 04:07:35,866 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\528c8507-2f31-4bd4-b65c-2e4dee475fa8.tmp 2026-04-14 04:07:35,866 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Module Info Cache~RF14aa87.TMP size is 67612, Max size: 100000000 2026-04-14 04:07:35,866 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Local State~RF14aa87.TMP size is 398780, Max size: 100000000 2026-04-14 04:07:40,252 [root] DEBUG: 2252: Dropped file limit reached. 2026-04-14 04:07:43,804 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:07:47,536 [root] DEBUG: 2252: CreateProcessHandler: Injection info set for new process 3120: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x000000013F490000 2026-04-14 04:07:47,536 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3120 2026-04-14 04:07:47,536 [root] DEBUG: 2252: ProcessMessage: Skipping monitoring process 3120 2026-04-14 04:07:48,036 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:07:48,317 [lib.common.results] INFO: File 1776164868254882800.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:48,333 [lib.common.results] INFO: File 1776164868254882800.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:07:48,348 [lib.common.results] INFO: File 1776164868254882800.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:07:48,348 [lib.common.results] INFO: File 1776164868254882800.Application.evtx.gz size is 6954, Max size: 100000000 2026-04-14 04:07:48,379 [lib.common.results] INFO: File 1776164868317382800.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:07:48,379 [lib.common.results] INFO: File 1776164868317382800.Security.evtx.gz size is 7753, Max size: 100000000 2026-04-14 04:07:48,395 [lib.common.results] INFO: File 1776164868317382800.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:07:48,395 [lib.common.results] INFO: File 1776164868317382800.System.evtx.gz size is 8033, Max size: 100000000 2026-04-14 04:07:48,426 [lib.common.results] INFO: File 1776164868379882800.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:07:48,958 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164868.9580078.sysmon.evtx.gz to host 2026-04-14 04:07:48,958 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 28155, Max size: 100000000 2026-04-14 04:07:54,520 [lib.common.results] INFO: File c:\olddocs\1776164869494.saz size is 12966, Max size: 100000000 2026-04-14 04:07:54,536 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:08:03,448 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:08:03,698 [lib.common.results] INFO: File 1776164883651367100.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:03,698 [lib.common.results] INFO: File 1776164883651367100.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:03,713 [lib.common.results] INFO: File 1776164883651367100.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:08:03,745 [lib.common.results] INFO: File 1776164883682617100.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:08:03,745 [lib.common.results] INFO: File 1776164883698242100.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:08:03,745 [lib.common.results] INFO: File 1776164883698242100.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:08:03,776 [lib.common.results] INFO: File 1776164883698242100.Security.evtx.gz size is 7838, Max size: 100000000 2026-04-14 04:08:03,791 [lib.common.results] INFO: File 1776164883745117100.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:08:03,791 [lib.common.results] INFO: File 1776164883745117100.System.evtx.gz size is 8029, Max size: 100000000 2026-04-14 04:08:03,979 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:08:09,074 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164889.0742188.sysmon.evtx.gz to host 2026-04-14 04:08:09,074 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 34620, Max size: 100000000 2026-04-14 04:08:14,610 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:08:18,830 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:08:19,064 [lib.common.results] INFO: File 1776164899001953100.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:19,064 [lib.common.results] INFO: File 1776164899017578100.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:19,080 [lib.common.results] INFO: File 1776164899001953100.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:08:19,080 [lib.common.results] INFO: File 1776164899017578100.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:08:19,111 [lib.common.results] INFO: File 1776164899064453100.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:08:19,126 [lib.common.results] INFO: File 1776164899064453100.Security.evtx.gz size is 7835, Max size: 100000000 2026-04-14 04:08:19,126 [lib.common.results] INFO: File 1776164899080078100.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:08:19,158 [lib.common.results] INFO: File 1776164899080078100.System.evtx.gz size is 8042, Max size: 100000000 2026-04-14 04:08:19,158 [lib.common.results] INFO: File 1776164899111328100.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:08:24,074 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:08:29,115 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164909.1152344.sysmon.evtx.gz to host 2026-04-14 04:08:29,115 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6470, Max size: 100000000 2026-04-14 04:08:34,188 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:08:34,422 [lib.common.results] INFO: File 1776164914360351500.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:34,422 [lib.common.results] INFO: File 1776164914360351500.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:08:34,438 [lib.common.results] INFO: File 1776164914360351500.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:08:34,438 [lib.common.results] INFO: File 1776164914360351500.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:34,485 [lib.common.results] INFO: File 1776164914422851500.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:08:34,485 [lib.common.results] INFO: File 1776164914422851500.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:08:34,485 [lib.common.results] INFO: File 1776164914422851500.Security.evtx.gz size is 7825, Max size: 100000000 2026-04-14 04:08:34,485 [lib.common.results] INFO: File 1776164914422851500.System.evtx.gz size is 8051, Max size: 100000000 2026-04-14 04:08:34,516 [lib.common.results] INFO: File 1776164914485351500.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:08:34,677 [lib.common.results] INFO: File c:\olddocs\1776164909660.saz size is 6984, Max size: 100000000 2026-04-14 04:08:34,693 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:08:44,136 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:08:49,208 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164929.2080076.sysmon.evtx.gz to host 2026-04-14 04:08:49,208 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6878, Max size: 100000000 2026-04-14 04:08:49,559 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:08:49,825 [lib.common.results] INFO: File 1776164929762695300.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:49,856 [lib.common.results] INFO: File 1776164929762695300.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:08:49,856 [lib.common.results] INFO: File 1776164929731445300.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:08:49,856 [lib.common.results] INFO: File 1776164929793945300.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:08:49,887 [lib.common.results] INFO: File 1776164929825195300.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:08:49,903 [lib.common.results] INFO: File 1776164929840820300.Security.evtx.gz size is 7781, Max size: 100000000 2026-04-14 04:08:49,918 [lib.common.results] INFO: File 1776164929856445300.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:08:49,918 [lib.common.results] INFO: File 1776164929856445300.System.evtx.gz size is 8071, Max size: 100000000 2026-04-14 04:08:49,934 [lib.common.results] INFO: File 1776164929887695300.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:08:54,854 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:09:04,229 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 04:09:04,979 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:09:05,202 [lib.common.results] INFO: File 1776164945155273400.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:05,217 [lib.common.results] INFO: File 1776164945155273400.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:05,233 [lib.common.results] INFO: File 1776164945155273400.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:09:05,233 [lib.common.results] INFO: File 1776164945170898400.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:09:05,280 [lib.common.results] INFO: File 1776164945202148400.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:09:05,280 [lib.common.results] INFO: File 1776164945202148400.Security.evtx.gz size is 7762, Max size: 100000000 2026-04-14 04:09:05,280 [lib.common.results] INFO: File 1776164945217773400.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:09:05,280 [lib.common.results] INFO: File 1776164945233398400.System.evtx.gz size is 8063, Max size: 100000000 2026-04-14 04:09:05,311 [lib.common.results] INFO: File 1776164945264648400.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:09:09,284 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164949.2841797.sysmon.evtx.gz to host 2026-04-14 04:09:09,284 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6237, Max size: 100000000 2026-04-14 04:09:10,226 [root] INFO: Analysis timeout hit, terminating analysis 2026-04-14 04:09:10,226 [lib.api.process] INFO: Terminate event set for process 2252 2026-04-14 04:09:10,226 [root] DEBUG: 2252: Terminate Event: Attempting to dump process 2252 2026-04-14 04:09:10,226 [root] DEBUG: 2252: DoProcessDump: Skipping process dump as code is identical on disk. 2026-04-14 04:09:10,242 [lib.api.process] INFO: Termination confirmed for process 2252 2026-04-14 04:09:10,242 [root] DEBUG: 2252: Terminate Event: monitor shutdown complete for process 2252 2026-04-14 04:09:10,257 [root] INFO: Terminate event set for process 2252 2026-04-14 04:09:10,257 [root] INFO: Created shutdown mutex 2026-04-14 04:09:11,257 [root] INFO: Shutting down package 2026-04-14 04:09:11,257 [root] INFO: Stopping auxiliary modules 2026-04-14 04:09:11,258 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2026-04-14 04:09:11,260 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2026-04-14 04:09:11,278 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:09:11,528 [lib.common.results] INFO: File 1776164951450195300.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:11,543 [lib.common.results] INFO: File 1776164951465820300.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:09:11,543 [lib.common.results] INFO: File 1776164951450195300.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:09:11,543 [lib.common.results] INFO: File 1776164951450195300.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:11,575 [lib.common.results] INFO: File 1776164951528320300.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:09:11,575 [lib.common.results] INFO: File 1776164951528320300.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:09:11,590 [lib.common.results] INFO: File 1776164951528320300.Security.evtx.gz size is 7682, Max size: 100000000 2026-04-14 04:09:11,590 [lib.common.results] INFO: File 1776164951528320300.System.evtx.gz size is 8064, Max size: 100000000 2026-04-14 04:09:11,622 [lib.common.results] INFO: File 1776164951575195300.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:09:14,930 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:09:16,731 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 04:09:16,731 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2026-04-14 04:09:20,372 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 04:09:20,606 [lib.common.results] INFO: File 1776164960559570300.InternetExplorer.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:20,606 [lib.common.results] INFO: File 1776164960559570300.Application.evtx.gz size is 6890, Max size: 100000000 2026-04-14 04:09:20,622 [lib.common.results] INFO: File 1776164960559570300.KeyManagementService.evtx.gz size is 2105, Max size: 100000000 2026-04-14 04:09:20,637 [lib.common.results] INFO: File 1776164960559570300.HardwareEvents.evtx.gz size is 250, Max size: 100000000 2026-04-14 04:09:20,653 [lib.common.results] INFO: File 1776164960606445300.Security.evtx.gz size is 7642, Max size: 100000000 2026-04-14 04:09:20,668 [lib.common.results] INFO: File 1776164960606445300.Setup.evtx.gz size is 241, Max size: 100000000 2026-04-14 04:09:20,668 [lib.common.results] INFO: File 1776164960606445300.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 04:09:20,668 [lib.common.results] INFO: File 1776164960606445300.System.evtx.gz size is 8047, Max size: 100000000 2026-04-14 04:09:20,700 [lib.common.results] INFO: File 1776164960653320300.WindowsPowerShell.evtx.gz size is 2058, Max size: 100000000 2026-04-14 04:09:21,793 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776164961.7939453.sysmon.evtx.gz to host 2026-04-14 04:09:21,793 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5942, Max size: 100000000 2026-04-14 04:09:21,809 [root] INFO: Finishing auxiliary modules 2026-04-14 04:09:21,809 [root] INFO: Shutting down pipe server and dumping dropped files 2026-04-14 04:09:21,809 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat size is 40, Max size: 100000000 2026-04-14 04:09:21,825 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\google\chrome\user data\shadercache\gpucache\index": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\google\\chrome\\user data\\shadercache\\gpucache\\index' 2026-04-14 04:09:21,825 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Last Version size is 13, Max size: 100000000 2026-04-14 04:09:21,840 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History size is 126976, Max size: 100000000 2026-04-14 04:09:21,856 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\MANIFEST-000001 size is 41, Max size: 100000000 2026-04-14 04:09:21,856 [lib.common.results] INFO: File c:\users\pgabriel\appdata\local\google\chrome\user data\default\site characteristics database\current size is 16, Max size: 100000000 2026-04-14 04:09:21,872 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\google\chrome\user data\grshadercache\gpucache\index": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\google\\chrome\\user data\\grshadercache\\gpucache\\index' 2026-04-14 04:09:21,872 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001 size is 41, Max size: 100000000 2026-04-14 04:09:21,872 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log size is 5424, Max size: 100000000 2026-04-14 04:09:21,872 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\google\chrome\user data\default\gpucache\index": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\google\\chrome\\user data\\default\\gpucache\\index' 2026-04-14 04:09:21,872 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000001 size is 41, Max size: 100000000 2026-04-14 04:09:21,887 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG size is 335, Max size: 100000000 2026-04-14 04:09:21,887 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\bd5f3c8b-a2f5-40ac-8db0-6a9590b97347.tmp does not exist, skipping 2026-04-14 04:09:21,887 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\a3a7a75b-1f7e-40ba-8d9c-0be7ab7f6d33.tmp does not exist, skipping 2026-04-14 04:09:21,887 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\temp\b2be79ea-1479-4bdf-851d-346a6a6a4f8c.tmp": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\temp\\b2be79ea-1479-4bdf-851d-346a6a6a4f8c.tmp' 2026-04-14 04:09:21,887 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\temp\c173785e-3285-4249-871e-e1ebfcef5048.tmp": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\temp\\c173785e-3285-4249-871e-e1ebfcef5048.tmp' 2026-04-14 04:09:21,887 [root] INFO: Error dumping file from path "c:\users\pgabriel\appdata\local\temp\6b579f61-4572-4118-a1c6-f74e948dfbb0.tmp": [Errno 13] Permission denied: 'c:\\users\\pgabriel\\appdata\\local\\temp\\6b579f61-4572-4118-a1c6-f74e948dfbb0.tmp' 2026-04-14 04:09:21,887 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\9b73eeed-f5b4-42fb-a184-71517e121a51.tmp does not exist, skipping 2026-04-14 04:09:21,887 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Last Browser size is 106, Max size: 100000000 2026-04-14 04:09:21,918 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\data_reduction_proxy_leveldb\000038.dbtmp does not exist, skipping 2026-04-14 04:09:21,918 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\f5ae6413-9fb0-41dd-9bd0-5366a79fa49c.tmp does not exist, skipping 2026-04-14 04:09:21,918 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:21,934 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store\LOG size is 0, Max size: 100000000 2026-04-14 04:09:21,950 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:21,965 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_and_features_store\LOG size is 0, Max size: 100000000 2026-04-14 04:09:21,981 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:21,997 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,012 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,028 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,043 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,059 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,075 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache size is 936, Max size: 100000000 2026-04-14 04:09:22,090 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,106 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,122 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\c36f0e58-4e7f-4500-ac4d-8179501a3c77.tmp does not exist, skipping 2026-04-14 04:09:22,122 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,137 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,153 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOCK size is 0, Max size: 100000000 2026-04-14 04:09:22,168 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG size is 0, Max size: 100000000 2026-04-14 04:09:22,184 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\a721ecf4-8b18-4d15-b82f-78e89206c31a.tmp does not exist, skipping 2026-04-14 04:09:22,184 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\fafc2258-f183-46a1-8a84-74163748914e.tmp does not exist, skipping 2026-04-14 04:09:22,184 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\default\a29bdb05-eb2a-49a1-9e4f-6f25b7ce8969.tmp does not exist, skipping 2026-04-14 04:09:22,184 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\10ebcb80-06a8-4a70-80bc-786a152d6260.tmp does not exist, skipping 2026-04-14 04:09:22,184 [root] WARNING: File at path c:\users\pgabriel\appdata\local\google\chrome\user data\528c8507-2f31-4bd4-b65c-2e4dee475fa8.tmp does not exist, skipping 2026-04-14 04:09:22,184 [root] WARNING: Folder at path "C:\xIxZfzpRZ\debugger" does not exist, skipping 2026-04-14 04:09:22,184 [root] INFO: Uploading files at path "C:\xIxZfzpRZ\tlsdump" 2026-04-14 04:09:22,184 [lib.common.results] INFO: File C:\xIxZfzpRZ\tlsdump\tlsdump.log size is 4932, Max size: 100000000 2026-04-14 04:09:22,184 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win7office2k3flash2800137TWN3H105 | win7office2k3flash2800137TWN3H105 | KVM | 2026-04-14 10:06:35 | 2026-04-14 10:09:38 | internet |
| File Name | Minyrefydd _ 221_m_.html |
|---|---|
| File Size | 29660 bytes |
| File Type | HTML document, UTF-8 Unicode text, with CRLF line terminators |
| MD5 | 5922e7d916836879dfe297d96222b5ec |
| SHA1 | c3619c4c292c845078a5947c494fdb87d4ffc326 |
| SHA256 | ee4e5081311c090fde92c8ebb597663c4d319b94eeec4bb827a15f46ce125adf |
| SHA512 | 807cc300bd45f35ebc20496492526e42199fc4e9ed892e2be0cd434adc26ba227dc62c17a7ec6272c723f8adc4596f812a867c6197aa79a8540931349a8219e3 |
| SHA3-384 | 67b6b192f500a2498924d7399bfe4805e6aaace2a7bd28fb085241f76fc9f3f281eed2e958bc9fbe3c805025689282af |
| CRC32 | 6879B7E4 |
| TLSH | T16ED29536A9C0143700B3537AAAB19B58FF628207D6024A1535BE57DB2FFAC848D57F5C |
| Ssdeep | 384:vQhLExeymv6Pt7AIAitvz8L9D+cpkqQEvVvjtMB:veLt6PdSBEqQSiB |
File
|
|
<!doctype html>
<html lang="en" class="h-100">
<head>
<!-- Required meta tags -->
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
<title>Minyrefydd – 221 m² sold £262k | SA66 7LF</title>
<meta name="description"
content="Shows plot boundary on a map, old photos. Value of £1,188 per sqm (110/ft²) on 2018-12-20.">
<meta name="geo.region" content="GB">
<meta name="geo.placename" content="United Kingdom">
<meta name="language" content="en-GB">
<link rel="shortcut icon" href="https://dfwqq1t8g50i2.cloudfront.net/static/favicon.ico">
<link rel="apple-touch-icon" sizes="180x180" href="https://dfwqq1t8g50i2.cloudfront.net/static/apple-touch-icon.png">
<!-- Nullify requests for other sizes and precomposed versions -->
<link rel="apple-touch-icon" sizes="120x120" href="data:,">
<link rel="apple-touch-icon-precomposed" href="data:,">
<link rel="apple-touch-icon" sizes="120x120-precomposed" href="data:,">
<link rel="canonical"
href="https://housemetric.co.uk/23755535/SA66-7LF/Minyrefydd" />
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/bootstrap@5.0.0-beta1/dist/css/bootstrap.min.css">
<script>window.STATIC_CDN_URL = "https://dfwqq1t8g50i2.cloudfront.net";</script>
<!-- Global site tag (gtag.js) - Google Analytics -->
<script async src="https://www.googletagmanager.com/gtag/js?id=G-LL8JR2NFTT"></script>
<script>
window.dataLayer = window.dataLayer || [];
function gtag() {
dataLayer.push(arguments);
}
gtag('js', new Date());
gtag('config', 'G-LL8JR2NFTT');
</script>
<style>
/*custom description list styling - used by all users*/
.custom-dl dt {
width: 100%;
}
@media (min-width: 768px) {
.custom-dl dt {
width: 25%;
}
}
.custom-dl dd {
width: 100%;
}
@media (min-width: 768px) {
.custom-dl dd {
width: 75%;
}
}
/* Premium content styles - only load for premium users */
</style>
<!-- Structured Data for SEO -->
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "House",
"name": "Minyrefydd SA66 7LF",
"description": "Property sold for £262,500 in December 2018. 221 square metres (2,379 square feet). Price per square metre: £1,187. Previously listed as sales property. reduced on 24/08/2018. Last appeared January 2019.",
"url": "https://housemetric.co.uk/23755535/SA66-7LF/Minyrefydd",
"address": {
"@type": "PostalAddress",
"streetAddress": "Minyrefydd",
"addressLocality": "Llandissilio",
"postalCode": "SA66 7LF",
"addressCountry": "GB"
},
"floorSize": {
"@type": "QuantitativeValue",
"value": 221,
"unitCode": "MTK"
},
"additionalProperty": [
{
"@type": "PropertyValue",
"name": "Last Sold Price",
"value": 262500,
"unitCode": "GBP"
}
,{
"@type": "PropertyValue",
"name": "Sale Date",
"value": "2018-12-20"
}
,{
"@type": "PropertyValue",
"name": "Price per square metre",
"value": 1187,
"unitCode": "GBP"
}
,{
"@type": "PropertyValue",
"name": "Council Tax Band",
"value": "F"
}
,{
"@type": "PropertyValue",
"name": "Plot Size",
"value": 604,
"unitText": "square metres"
}
,
{
"@type": "PropertyValue",
"name": "Listing Type",
"value": "Sales"
}
,{
"@type": "PropertyValue",
"name": "Last Listed",
"value": "2019-01-01"
}
,{
"@type": "PropertyValue",
"name": "Listed Bedrooms",
"value": 4
}
,{
"@type": "PropertyValue",
"name": "Listed Bathrooms",
"value": 3
}
],
"publisher": {
"@type": "Organization",
"name": "HouseMetric",
"url": "https://housemetric.co.uk"
}
}
</script>
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "BreadcrumbList",
"itemListElement": [{
"@type": "ListItem",
"item": "https://housemetric.co.uk",
"name": "Home",
"position": 1
},{
"@type": "ListItem",
"item": "https://housemetric.co.uk/analysis/sector/SA66-7/Llandissilio",
"name": "SA66 7",
"position": 2
},{
"@type": "ListItem",
"item": "https://housemetric.co.uk/house-prices/na/SA66-7LF/",
"name": "SA66 7LF",
"position": 3
},{
"@type": "ListItem",
"item": "https://housemetric.co.uk/23755535/SA66-7LF/Minyrefydd",
"name": "Minyrefydd",
"position": 4
}]
}
</script>
</head>
<body class="d-flex flex-column h-100">
<nav class="navbar navbar-expand-md navbar-dark pt-2 pb-2 mb-2" style="background-color: #234e70;" aria-label="navbar">
<div class="container-fluid">
<a class="navbar-brand pt-0" href="/">
<span class="mb-0 fs-4">HouseMetric</span>
</a>
<button class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target="#navbarsExample04" aria-controls="navbarsExample04" aria-expanded="false" aria-label="Toggle navigation">
<span class="navbar-toggler-icon"></span>
</button>
<div class="collapse navbar-collapse" id="navbarsExample04">
<ul class="navbar-nav me-auto mb-2 mb-md-0">
<li class="nav-item">
<a class="nav-link hover-underline"
href="/map/SA66-7/">
Map</a>
</li>
<li class="nav-item dropdown">
<a class="nav-link dropdown-toggle hover-underline" href="#" id="market-analysis-dropdown" data-bs-toggle="dropdown" aria-expanded="false">
Analysis
</a>
<ul class="dropdown-menu" aria-labelledby="market-analysis-dropdown">
<li><a class="dropdown-item hover-underline" href="/geography-search">Local analysis</a></li>
<li><a class="dropdown-item hover-underline" href="/custom-charts">Custom histogram</a></li>
</ul>
</li>
<li class="nav-item dropdown">
<a class="nav-link dropdown-toggle hover-underline" href="#" id="rawDataDropdown" role="button" data-bs-toggle="dropdown" aria-expanded="false">
Search
</a>
<ul class="dropdown-menu" aria-labelledby="rawDataDropdown">
<li><a class="dropdown-item hover-underline" href="/basic-search">Basic search</a></li>
<li><a class="dropdown-item hover-underline" href="/advanced-search">Advanced search</a></li>
<li><a class="dropdown-item hover-underline" href="/epc-search">EPC search</a></li>
<li><a class="dropdown-item hover-underline" href="/company-search">Company search</a></li>
</ul>
</li>
</ul>
<ul class="navbar-nav">
<li class="nav-item">
<a class="nav-link hover-underline" href="/login">Login</a>
</li>
</ul>
</div>
</div>
</nav>
<style>
.hover-underline {
position: relative;
text-decoration: none;
}
.hover-underline::after {
content: '';
position: absolute;
width: 100%;
height: 2px;
bottom: 0;
left: 0;
background-color: #fff;
transform: scaleX(0);
transition: transform 0.3s ease-out;
}
.hover-underline:hover::after {
transform: scaleX(1);
}
.dropdown-menu {
background-color: #234e70;
}
.dropdown-item {
color: rgba(255, 255, 255, 0.55);
}
.dropdown-item:hover, .dropdown-item:focus {
background-color: rgba(255, 255, 255, 0.1);
color: #fff;
}
.dropdown-item.hover-underline::after {
bottom: 2px;
}
</style>
<!-- BEGIN page content (includes messages and app_content)-->
<truncated>
|
| Direct | IP | Country Name |
|---|---|---|
| N | 142.250.151.94 [VT] | United States |
| N | 52.222.161.106 [VT] | United States |
| N | 192.178.223.84 [VT] | United States |
| Y | 8.8.8.8 [VT] | United States |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| accounts.google.com [VT] | A 192.178.223.84 [VT] | 192.178.223.84 [VT] |
| dfwqq1t8g50i2.cloudfront.net [VT] |
A 52.222.161.174
[VT]
A 52.222.161.164 [VT] A 52.222.161.171 [VT] A 52.222.161.106 [VT] |
52.222.161.106 [VT] |
| _googlecast._tcp.local [VT] | ||
| www.gstatic.com [VT] | A 142.250.151.94 [VT] | 142.250.140.94 [VT] |
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP