| Category | Package | Started | Completed | Duration | Options | Log | MalScore |
|---|---|---|---|---|---|---|---|
| FILE | doc | 2026-04-14 20:03:49 | 2026-04-14 20:06:57 | 188 seconds | Show Options | Show Log | 1.0 |
procdump=1
amsidump=1
2025-12-02 01:27:17,031 [root] INFO: Date set to: 20260414T13:03:48, timeout set to: 150
2026-04-14 14:03:48,015 [root] DEBUG: Starting analyzer from: C:\tmpdlc5ruzl
2026-04-14 14:03:48,015 [root] DEBUG: Storing results at: C:\AjCWZHyUB
2026-04-14 14:03:48,015 [root] DEBUG: Pipe server name: \\.\PIPE\FQYTRc
2026-04-14 14:03:48,015 [root] DEBUG: Python path: C:\olddocs
2026-04-14 14:03:48,015 [root] INFO: Analysis package "doc" has been specified
2026-04-14 14:03:48,015 [root] DEBUG: Importing analysis package "doc"...
2026-04-14 14:03:48,031 [root] DEBUG: Initializing analysis package "doc"...
2026-04-14 14:03:48,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL option
2026-04-14 14:03:48,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL_64 option
2026-04-14 14:03:48,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader option
2026-04-14 14:03:48,031 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader_64 option
2026-04-14 14:03:48,062 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"...
2026-04-14 14:03:48,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"...
2026-04-14 14:03:48,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"...
2026-04-14 14:03:48,078 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"...
2026-04-14 14:03:48,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"...
2026-04-14 14:03:48,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"...
2026-04-14 14:03:48,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"...
2026-04-14 14:03:48,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"...
2026-04-14 14:03:48,140 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"...
2026-04-14 14:03:48,140 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-04-14 14:03:48,234 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-04-14 14:03:48,234 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-04-14 14:03:48,234 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"...
2026-04-14 14:03:48,249 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"...
2026-04-14 14:03:48,249 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"...
2026-04-14 14:03:48,249 [root] DEBUG: Initializing auxiliary module "Browser"...
2026-04-14 14:03:48,249 [root] DEBUG: Started auxiliary module Browser
2026-04-14 14:03:48,249 [root] DEBUG: Initializing auxiliary module "Curtain"...
2026-04-14 14:03:48,249 [root] DEBUG: Started auxiliary module Curtain
2026-04-14 14:03:48,249 [root] DEBUG: Initializing auxiliary module "DefaultApps"...
2026-04-14 14:03:48,296 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI
2026-04-14 14:03:48,296 [root] DEBUG: Started auxiliary module DefaultApps
2026-04-14 14:03:48,312 [root] DEBUG: Initializing auxiliary module "DigiSig"...
2026-04-14 14:03:48,312 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/
2026-04-14 14:03:48,312 [modules.auxiliary.digisig] INFO: doc
2026-04-14 14:03:48,312 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package
2026-04-14 14:03:48,312 [root] DEBUG: Started auxiliary module DigiSig
2026-04-14 14:03:48,312 [root] DEBUG: Initializing auxiliary module "Disguise"...
2026-04-14 14:03:48,687 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory
2026-04-14 14:03:48,687 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified
2026-04-14 14:03:48,687 [root] DEBUG: Initializing auxiliary module "Evtx"...
2026-04-14 14:03:48,687 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpdlc5ruzl\bin\auditpol.csv
2026-04-14 14:03:48,968 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:03:49,890 [root] DEBUG: Started auxiliary module Evtx
2026-04-14 14:03:49,890 [root] DEBUG: Initializing auxiliary module "Fiddler"...
2026-04-14 14:03:49,890 [modules.auxiliary.fiddler] INFO: fiddler package: doc
2026-04-14 14:03:49,890 [root] DEBUG: Started auxiliary module Fiddler
2026-04-14 14:03:49,890 [root] DEBUG: Initializing auxiliary module "Human"...
2026-04-14 14:03:49,890 [root] DEBUG: Started auxiliary module Human
2026-04-14 14:03:49,890 [root] DEBUG: Initializing auxiliary module "Screenshots"...
2026-04-14 14:03:49,890 [root] DEBUG: Started auxiliary module Screenshots
2026-04-14 14:03:49,890 [root] DEBUG: Initializing auxiliary module "Sysmon"...
2026-04-14 14:03:49,890 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config
2026-04-14 14:03:49,890 [root] DEBUG: Started auxiliary module Sysmon
2026-04-14 14:03:49,890 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"...
2026-04-14 14:03:49,906 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable
2026-04-14 14:03:49,906 [modules.auxiliary.sysmon] INFO: Found Sysmon config
2026-04-14 14:03:49,906 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 556
2026-04-14 14:03:49,906 [lib.api.process] INFO: Monitor config for process 556: C:\tmpdlc5ruzl\dll\556.ini
2026-04-14 14:03:49,906 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor
2026-04-14 14:03:49,906 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor
2026-04-14 14:03:49,906 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor
2026-04-14 14:03:49,906 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor
2026-04-14 14:03:49,906 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor
2026-04-14 14:03:49,906 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2026-04-14 14:03:49,906 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-04-14 14:03:49,906 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpdlc5ruzl\dll\PhdqsQU.dll, loader C:\tmpdlc5ruzl\bin\uHyrbDXh.exe
2026-04-14 14:03:49,937 [root] DEBUG: Loader: IAT patching disabled.
2026-04-14 14:03:49,937 [root] DEBUG: Loader: Injecting process 556 with C:\tmpdlc5ruzl\dll\PhdqsQU.dll.
2026-04-14 14:03:50,000 [root] DEBUG: 556: Python path set to 'C:\olddocs'.
2026-04-14 14:03:50,000 [root] DEBUG: 556: Disabling sleep skipping.
2026-04-14 14:03:50,000 [root] DEBUG: 556: Process dumps enabled.
2026-04-14 14:03:50,000 [root] DEBUG: 556: AMSI dumping enabled.
2026-04-14 14:03:50,000 [root] DEBUG: 556: Monitor config - unrecognised key office.
2026-04-14 14:03:50,000 [root] DEBUG: 556: In-monitor YARA scans disabled.
2026-04-14 14:03:50,000 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEF53E0000, thread 1720, image base 0x00000000FF070000, stack from 0x0000000001FE3000-0x0000000001FF0000
2026-04-14 14:03:50,015 [root] DEBUG: 556: Commandline: C:\Windows\system32\lsass.exe
2026-04-14 14:03:50,015 [root] DEBUG: 556: Hooked 5 out of 5 functions
2026-04-14 14:03:50,015 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-14 14:03:50,031 [root] DEBUG: Successfully injected DLL C:\tmpdlc5ruzl\dll\PhdqsQU.dll.
2026-04-14 14:03:50,031 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 556
2026-04-14 14:03:50,031 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets
2026-04-14 14:03:50,031 [root] DEBUG: Initializing auxiliary module "Usage"...
2026-04-14 14:03:50,031 [root] DEBUG: Started auxiliary module Usage
2026-04-14 14:03:52,046 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs
2026-04-14 14:03:52,796 [root] INFO: Restarting WMI Service
2026-04-14 14:04:01,906 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" with arguments ""C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx" /q" with pid 2620
2026-04-14 14:04:01,906 [lib.api.process] INFO: Monitor config for process 2620: C:\tmpdlc5ruzl\dll\2620.ini
2026-04-14 14:04:01,921 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor
2026-04-14 14:04:01,921 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor
2026-04-14 14:04:01,921 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor
2026-04-14 14:04:01,921 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor
2026-04-14 14:04:01,921 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor
2026-04-14 14:04:01,921 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2026-04-14 14:04:01,921 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpdlc5ruzl\dll\bFNTQByw.dll, loader C:\tmpdlc5ruzl\bin\QRCYZmL.exe
2026-04-14 14:04:01,953 [root] DEBUG: Loader: IAT patching disabled.
2026-04-14 14:04:01,953 [root] DEBUG: Loader: Injecting process 2620 (thread 2896) with C:\tmpdlc5ruzl\dll\bFNTQByw.dll.
2026-04-14 14:04:01,953 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2026-04-14 14:04:01,953 [root] DEBUG: Successfully injected DLL C:\tmpdlc5ruzl\dll\bFNTQByw.dll.
2026-04-14 14:04:01,953 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 2620
2026-04-14 14:04:02,046 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:04:03,953 [lib.api.process] INFO: Successfully resumed process with pid 2620
2026-04-14 14:04:04,046 [root] DEBUG: 2620: Python path set to 'C:\olddocs'.
2026-04-14 14:04:04,046 [root] DEBUG: 2620: Disabling sleep skipping.
2026-04-14 14:04:04,046 [root] DEBUG: 2620: Process dumps enabled.
2026-04-14 14:04:04,046 [root] DEBUG: 2620: AMSI dumping enabled.
2026-04-14 14:04:04,046 [root] DEBUG: 2620: Monitor config - unrecognised key office.
2026-04-14 14:04:04,046 [root] DEBUG: 2620: In-monitor YARA scans disabled.
2026-04-14 14:04:04,046 [root] DEBUG: 2620: Dropped file limit defaulting to 100.
2026-04-14 14:04:04,046 [root] DEBUG: 2620: Microsoft Office settings enabled.
2026-04-14 14:04:04,046 [root] DEBUG: 2620: Monitor initialised: 32-bit capemon loaded in process 2620 at 0x73900000, thread 2896, image base 0xd60000, stack from 0x173000-0x180000
2026-04-14 14:04:04,062 [root] DEBUG: 2620: Commandline: "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" "C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx" /q
2026-04-14 14:04:04,078 [root] DEBUG: 2620: Hooked 456 out of 456 functions
2026-04-14 14:04:04,093 [root] INFO: Loaded monitor into process with pid 2620
2026-04-14 14:04:04,343 [root] DEBUG: 2620: DLL loaded at 0x6F860000: C:\Program Files (x86)\Microsoft Office\Office15\wwlib (0x14bc000 bytes).
2026-04-14 14:04:04,359 [root] DEBUG: 2620: DLL loaded at 0x73770000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus (0x190000 bytes).
2026-04-14 14:04:04,546 [root] DEBUG: 2620: DLL loaded at 0x6EAB0000: C:\Program Files (x86)\Microsoft Office\Office15\oart (0xda8000 bytes).
2026-04-14 14:04:04,546 [root] DEBUG: 2620: DLL loaded at 0x73F10000: C:\Windows\system32\MSVCP100 (0x69000 bytes).
2026-04-14 14:04:04,609 [root] DEBUG: 2620: DLL loaded at 0x71E90000: C:\Windows\system32\d2d1 (0x347000 bytes).
2026-04-14 14:04:04,890 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:04:04,937 [root] DEBUG: 2620: DLL loaded at 0x6D1C0000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso (0x18e4000 bytes).
2026-04-14 14:04:04,984 [root] DEBUG: 2620: DLL loaded at 0x72C10000: C:\Windows\system32\MSIMG32 (0x5000 bytes).
2026-04-14 14:04:05,031 [root] DEBUG: 2620: DLL loaded at 0x72E00000: C:\Windows\system32\uxtheme (0x80000 bytes).
2026-04-14 14:04:05,046 [root] DEBUG: 2620: DLL loaded at 0x72D20000: C:\Windows\system32\WTSAPI32 (0xd000 bytes).
2026-04-14 14:04:05,046 [root] DEBUG: 2620: DLL loaded at 0x740B0000: C:\Windows\system32\WINSTA (0x29000 bytes).
2026-04-14 14:04:05,078 [root] DEBUG: 2620: DLL loaded at 0x73720000: C:\Windows\system32\dxgi (0x4c000 bytes).
2026-04-14 14:04:05,078 [root] DEBUG: 2620: DLL loaded at 0x72D30000: C:\Windows\system32\VERSION (0x9000 bytes).
2026-04-14 14:04:05,093 [root] DEBUG: 2620: DLL loaded at 0x74090000: C:\Windows\system32\dwmapi (0x13000 bytes).
2026-04-14 14:04:05,125 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-14 14:04:05,125 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:05,125 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:05,140 [root] DEBUG: 2620: DLL loaded at 0x75A50000: C:\Windows\syswow64\WINTRUST (0x2f000 bytes).
2026-04-14 14:04:05,156 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-14 14:04:05,156 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:05,156 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:05,171 [root] DEBUG: 2620: DLL loaded at 0x71C50000: C:\Windows\system32\msi (0x240000 bytes).
2026-04-14 14:04:05,203 [lib.common.results] INFO: File 1776200645109375000.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:04:05,234 [lib.common.results] INFO: File 1776200645093750000.Application.evtx.gz size is 6911, Max size: 100000000
2026-04-14 14:04:05,234 [lib.common.results] INFO: File 1776200645109375000.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:04:05,234 [lib.common.results] INFO: File 1776200645109375000.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:04:05,296 [lib.common.results] INFO: File 1776200645218750000.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:04:05,296 [lib.common.results] INFO: File 1776200645218750000.Security.evtx.gz size is 7700, Max size: 100000000
2026-04-14 14:04:05,296 [lib.common.results] INFO: File 1776200645218750000.System.evtx.gz size is 8923, Max size: 100000000
2026-04-14 14:04:05,296 [lib.common.results] INFO: File 1776200645187500000.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:04:05,328 [lib.common.results] INFO: File 1776200645281250000.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:04:05,453 [root] DEBUG: 2620: DLL loaded at 0x71630000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSPTLS (0x116000 bytes).
2026-04-14 14:04:05,609 [root] DEBUG: 2620: DLL loaded at 0x74DF0000: C:\Windows\syswow64\SHELL32 (0xc4a000 bytes).
2026-04-14 14:04:05,609 [root] DEBUG: 2620: DLL loaded at 0x749C0000: C:\Windows\syswow64\profapi (0xb000 bytes).
2026-04-14 14:04:05,687 [root] DEBUG: 2620: DLL loaded at 0x72E90000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32 (0x19e000 bytes).
2026-04-14 14:04:05,765 [root] DEBUG: 2620: DLL loaded at 0x73EE0000: C:\Windows\system32\d3d10_1 (0x2c000 bytes).
2026-04-14 14:04:05,781 [root] DEBUG: 2620: DLL loaded at 0x736D0000: C:\Windows\system32\d3d10_1core (0x41000 bytes).
2026-04-14 14:04:05,796 [root] DEBUG: 2620: DLL loaded at 0x71130000: C:\Windows\system32\d3d11 (0x175000 bytes).
2026-04-14 14:04:05,828 [root] DEBUG: 2620: DLL loaded at 0x70F40000: C:\Windows\system32\D3D10Warp (0x1e9000 bytes).
2026-04-14 14:04:05,828 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-14 14:04:05,843 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:05,843 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:05,843 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-14 14:04:05,843 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:05,843 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:05,875 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-14 14:04:05,875 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:05,875 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:05,890 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-14 14:04:05,890 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:05,890 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:06,000 [root] DEBUG: 2620: DLL loaded at 0x70E10000: C:\Windows\system32\WindowsCodecs (0x130000 bytes).
2026-04-14 14:04:06,000 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-14 14:04:06,000 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:06,000 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:06,015 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\setupapi (0x19d000 bytes).
2026-04-14 14:04:06,015 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:06,015 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:06,046 [root] DEBUG: 2620: DLL loaded at 0x6D080000: C:\Windows\system32\DWrite (0x135000 bytes).
2026-04-14 14:04:06,078 [root] DEBUG: 2620: DLL loaded at 0x70DC0000: C:\Windows\system32\mscoree (0x4a000 bytes).
2026-04-14 14:04:06,093 [root] DEBUG: 2620: DLL loaded at 0x70D30000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes).
2026-04-14 14:04:06,203 [root] DEBUG: 2620: DLL loaded at 0x6CFC0000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\adal (0xb5000 bytes).
2026-04-14 14:04:06,218 [root] DEBUG: 2620: DLL loaded at 0x6CF60000: C:\Windows\system32\WINHTTP (0x58000 bytes).
2026-04-14 14:04:06,218 [root] DEBUG: 2620: DLL loaded at 0x6CF10000: C:\Windows\system32\webio (0x50000 bytes).
2026-04-14 14:04:06,249 [root] DEBUG: 2620: DLL loaded at 0x76310000: C:\Windows\syswow64\WININET (0x1e4000 bytes).
2026-04-14 14:04:06,265 [root] DEBUG: 2620: DLL loaded at 0x76260000: C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes).
2026-04-14 14:04:06,265 [root] DEBUG: 2620: DLL loaded at 0x75A40000: C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes).
2026-04-14 14:04:06,265 [root] DEBUG: 2620: DLL loaded at 0x76500000: C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes).
2026-04-14 14:04:06,265 [root] DEBUG: 2620: DLL loaded at 0x74B70000: C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes).
2026-04-14 14:04:06,265 [root] DEBUG: 2620: DLL loaded at 0x76AA0000: C:\Windows\syswow64\normaliz (0x3000 bytes).
2026-04-14 14:04:06,296 [root] DEBUG: 2620: DLL loaded at 0x75DE0000: C:\Windows\syswow64\iertutil (0x232000 bytes).
2026-04-14 14:04:06,296 [root] DEBUG: 2620: DLL loaded at 0x760F0000: C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes).
2026-04-14 14:04:06,296 [root] DEBUG: 2620: DLL loaded at 0x75AE0000: C:\Windows\syswow64\USERENV (0x17000 bytes).
2026-04-14 14:04:06,312 [root] DEBUG: 2620: DLL loaded at 0x741A0000: C:\Windows\system32\Secur32 (0x8000 bytes).
2026-04-14 14:04:06,406 [root] DEBUG: 2620: DLL loaded at 0x765C0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes).
2026-04-14 14:04:06,406 [root] DEBUG: 2620: DLL loaded at 0x6CEB0000: C:\Windows\System32\netprofm (0x5a000 bytes).
2026-04-14 14:04:06,406 [root] DEBUG: 2620: DLL loaded at 0x740F0000: C:\Windows\System32\nlaapi (0x10000 bytes).
2026-04-14 14:04:06,421 [root] DEBUG: 2620: DLL loaded at 0x72CD0000: C:\Windows\system32\CRYPTSP (0x17000 bytes).
2026-04-14 14:04:06,453 [root] DEBUG: 2620: DLL loaded at 0x72C90000: C:\Windows\system32\rsaenh (0x3b000 bytes).
2026-04-14 14:04:06,468 [root] DEBUG: 2620: DLL loaded at 0x734E0000: C:\Windows\system32\RpcRtRemote (0xe000 bytes).
2026-04-14 14:04:06,468 [root] DEBUG: 2620: DLL loaded at 0x74080000: C:\Windows\System32\npmproxy (0x8000 bytes).
2026-04-14 14:04:06,703 [root] DEBUG: 2620: DLL loaded at 0x6CD20000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20 (0x18e000 bytes).
2026-04-14 14:04:07,125 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200647.125.sysmon.evtx.gz to host
2026-04-14 14:04:07,125 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 9793, Max size: 100000000
2026-04-14 14:04:07,640 [root] DEBUG: 2620: DLL loaded at 0x73510000: C:\Windows\system32\IPHLPAPI (0x1c000 bytes).
2026-04-14 14:04:07,640 [root] DEBUG: 2620: DLL loaded at 0x73500000: C:\Windows\system32\WINNSI (0x7000 bytes).
2026-04-14 14:04:07,640 [root] DEBUG: 2620: DLL loaded at 0x74020000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes).
2026-04-14 14:04:07,640 [root] DEBUG: 2620: DLL loaded at 0x735F0000: C:\Windows\system32\dhcpcsvc (0x12000 bytes).
2026-04-14 14:04:07,656 [root] DEBUG: 2620: DLL loaded at 0x68000000: C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppc (0x2d000 bytes).
2026-04-14 14:04:07,656 [root] DEBUG: 2620: DLL loaded at 0x73ED0000: C:\Windows\system32\credssp (0x8000 bytes).
2026-04-14 14:04:07,656 [root] DEBUG: 2620: DLL loaded at 0x734A0000: C:\Windows\system32\mswsock (0x3c000 bytes).
2026-04-14 14:04:07,656 [root] DEBUG: 2620: DLL loaded at 0x73490000: C:\Windows\System32\wshtcpip (0x5000 bytes).
2026-04-14 14:04:07,671 [root] DEBUG: 2620: DLL loaded at 0x73480000: C:\Windows\System32\wship6 (0x6000 bytes).
2026-04-14 14:04:07,671 [root] DEBUG: 2620: DLL loaded at 0x67FB0000: C:\Windows\system32\DNSAPI (0x44000 bytes).
2026-04-14 14:04:07,750 [root] DEBUG: 2620: DLL loaded at 0x67F60000: C:\Windows\SysWOW64\schannel (0x41000 bytes).
2026-04-14 14:04:07,765 [root] DEBUG: 2620: DLL loaded at 0x67F00000: C:\Windows\system32\WINSPOOL.DRV (0x51000 bytes).
2026-04-14 14:04:07,781 [root] DEBUG: 556: DLL loaded at 0x000007FEF19F0000: C:\Windows\system32\dssenh (0x32000 bytes).
2026-04-14 14:04:07,812 [root] DEBUG: 2620: DLL loaded at 0x75C20000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes).
2026-04-14 14:04:07,812 [root] DEBUG: 2620: DLL loaded at 0x76A70000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes).
2026-04-14 14:04:07,812 [root] DEBUG: 2620: DLL loaded at 0x75DC0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes).
2026-04-14 14:04:07,828 [root] DEBUG: 2620: DLL loaded at 0x67E00000: C:\Windows\system32\propsys (0xf5000 bytes).
2026-04-14 14:04:07,843 [root] DEBUG: 2620: DLL loaded at 0x72D80000: C:\Windows\system32\ntmarta (0x21000 bytes).
2026-04-14 14:04:07,843 [root] DEBUG: 2620: DLL loaded at 0x749D0000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes).
2026-04-14 14:04:07,906 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm
2026-04-14 14:04:07,953 [root] DEBUG: 2620: DLL loaded at 0x67CA0000: C:\Windows\System32\msxml6 (0x158000 bytes).
2026-04-14 14:04:08,093 [root] DEBUG: 556: DLL loaded at 0x000007FEFA370000: C:\Windows\system32\keyiso (0xb000 bytes).
2026-04-14 14:04:08,140 [root] DEBUG: 2620: DLL loaded at 0x67C70000: C:\Windows\system32\XmlLite (0x2f000 bytes).
2026-04-14 14:04:08,281 [root] DEBUG: 2620: DLL loaded at 0x76AB0000: C:\Windows\SysWOW64\urlmon (0x14a000 bytes).
2026-04-14 14:04:08,281 [root] DEBUG: 2620: DLL loaded at 0x74B40000: C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes).
2026-04-14 14:04:08,296 [root] DEBUG: 2620: DLL loaded at 0x73CD0000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes).
2026-04-14 14:04:08,312 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\~$34_as_password_ha.docx
2026-04-14 14:04:08,484 [root] DEBUG: 2620: DLL loaded at 0x67C10000: C:\Windows\system32\SXS (0x5f000 bytes).
2026-04-14 14:04:08,781 [root] DEBUG: 556: TLS 1.2 secrets logged to: C:\AjCWZHyUB\tlsdump\tlsdump.log
2026-04-14 14:04:08,859 [root] DEBUG: 556: DLL loaded at 0x000007FEF9EA0000: C:\Windows\system32\cryptnet (0x27000 bytes).
2026-04-14 14:04:08,875 [root] DEBUG: 556: DLL loaded at 0x000007FEFD110000: C:\Windows\system32\WLDAP32 (0x52000 bytes).
2026-04-14 14:04:08,921 [root] DEBUG: 2620: DLL loaded at 0x67BD0000: C:\Windows\system32\ncrypt (0x39000 bytes).
2026-04-14 14:04:08,937 [root] DEBUG: 2620: DLL loaded at 0x67B90000: C:\Windows\SysWOW64\bcryptprimitives (0x3d000 bytes).
2026-04-14 14:04:09,109 [root] DEBUG: 2620: DLL loaded at 0x67B70000: C:\Windows\system32\GPAPI (0x16000 bytes).
2026-04-14 14:04:09,296 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10
2026-04-14 14:04:09,312 [root] DEBUG: 2620: DLL loaded at 0x67AA0000: C:\Windows\system32\webservices (0xc2000 bytes).
2026-04-14 14:04:09,328 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma00546271.png0 size is 119666, Max size: 100000000
2026-04-14 14:04:09,343 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02786999.png0 size is 8127, Max size: 100000000
2026-04-14 14:04:09,359 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900771.png0 size is 10213, Max size: 100000000
2026-04-14 14:04:09,375 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382936.png0 size is 37573, Max size: 100000000
2026-04-14 14:04:09,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382941.png0 size is 96333, Max size: 100000000
2026-04-14 14:04:09,421 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02835058.png0 size is 186365, Max size: 100000000
2026-04-14 14:04:09,453 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03978815.png0 size is 711398, Max size: 100000000
2026-04-14 14:04:09,468 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78018332.png0 size is 26105, Max size: 100000000
2026-04-14 14:04:09,484 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392850.png0 size is 280509, Max size: 100000000
2026-04-14 14:04:09,500 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45325165.png0 size is 9149, Max size: 100000000
2026-04-14 14:04:09,515 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03982351.png0 size is 12860, Max size: 100000000
2026-04-14 14:04:09,515 [root] DEBUG: 2620: DLL loaded at 0x67A80000: C:\Windows\system32\cryptnet (0x1d000 bytes).
2026-04-14 14:04:09,531 [root] DEBUG: 2620: DLL loaded at 0x70D20000: C:\Windows\system32\SensApi (0x6000 bytes).
2026-04-14 14:04:09,531 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392877.png0 size is 86215, Max size: 100000000
2026-04-14 14:04:09,546 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16402488.png0 size is 114584, Max size: 100000000
2026-04-14 14:04:09,625 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16412178.png0 size is 283253, Max size: 100000000
2026-04-14 14:04:09,625 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma56348247.png0 size is 55049, Max size: 100000000
2026-04-14 14:04:09,640 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900720.png0 size is 22877, Max size: 100000000
2026-04-14 14:04:09,672 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma88924273.png0 size is 103770, Max size: 100000000
2026-04-14 14:04:09,696 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02836342.png0 size is 26220, Max size: 100000000
2026-04-14 14:04:09,727 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02892315.png0 size is 20776, Max size: 100000000
2026-04-14 14:04:09,750 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002124.png0 size is 11329, Max size: 100000000
2026-04-14 14:04:09,774 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78500733.png0 size is 10169, Max size: 100000000
2026-04-14 14:04:09,805 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02911863.png0 size is 41743, Max size: 100000000
2026-04-14 14:04:09,829 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900688.png0 size is 8561, Max size: 100000000
2026-04-14 14:04:09,852 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900722.png0 size is 19188, Max size: 100000000
2026-04-14 14:04:09,875 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900743.png0 size is 33070, Max size: 100000000
2026-04-14 14:04:09,899 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02923944.png0 size is 4886, Max size: 100000000
2026-04-14 14:04:09,938 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002117.png0 size is 4962, Max size: 100000000
2026-04-14 14:04:09,985 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt16402400.png0 size is 33856, Max size: 100000000
2026-04-14 14:04:09,993 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt22746018.png0 size is 18469, Max size: 100000000
2026-04-14 14:04:10,016 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45088960.png0 size is 40992, Max size: 100000000
2026-04-14 14:04:10,024 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45420242.png0 size is 13339, Max size: 100000000
2026-04-14 14:04:11,587 [root] DEBUG: 2620: DLL loaded at 0x67A50000: C:\Windows\system32\POWRPROF (0x25000 bytes).
2026-04-14 14:04:12,996 [lib.common.results] INFO: File c:\olddocs\1776200647968.saz size is 6630, Max size: 100000000
2026-04-14 14:04:13,011 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:04:20,359 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:04:20,632 [lib.common.results] INFO: File 1776200660578125000.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:04:20,648 [lib.common.results] INFO: File 1776200660578125000.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:04:20,648 [lib.common.results] INFO: File 1776200660578125000.Application.evtx.gz size is 6839, Max size: 100000000
2026-04-14 14:04:20,648 [lib.common.results] INFO: File 1776200660578125000.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:04:20,671 [lib.common.results] INFO: File 1776200660625000000.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:04:20,687 [lib.common.results] INFO: File 1776200660632812500.Security.evtx.gz size is 8235, Max size: 100000000
2026-04-14 14:04:20,695 [lib.common.results] INFO: File 1776200660640625000.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:04:20,710 [lib.common.results] INFO: File 1776200660640625000.System.evtx.gz size is 8717, Max size: 100000000
2026-04-14 14:04:20,726 [lib.common.results] INFO: File 1776200660671875000.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:04:22,156 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:04:27,280 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200667.2802734.sysmon.evtx.gz to host
2026-04-14 14:04:27,280 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 80660, Max size: 100000000
2026-04-14 14:04:33,126 [lib.common.results] INFO: File c:\olddocs\1776200668092.saz size is 12860, Max size: 100000000
2026-04-14 14:04:33,142 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:04:35,777 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:04:36,020 [lib.common.results] INFO: File 1776200675973632800.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:04:36,043 [lib.common.results] INFO: File 1776200675973632800.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:04:36,043 [lib.common.results] INFO: File 1776200675973632800.Application.evtx.gz size is 6839, Max size: 100000000
2026-04-14 14:04:36,043 [lib.common.results] INFO: File 1776200675973632800.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:04:36,083 [lib.common.results] INFO: File 1776200676020507800.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:04:36,083 [lib.common.results] INFO: File 1776200676028320300.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:04:36,090 [lib.common.results] INFO: File 1776200676028320300.Security.evtx.gz size is 8347, Max size: 100000000
2026-04-14 14:04:36,090 [lib.common.results] INFO: File 1776200676036132800.System.evtx.gz size is 8369, Max size: 100000000
2026-04-14 14:04:36,129 [lib.common.results] INFO: File 1776200676083007800.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:04:42,295 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:04:47,384 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200687.3691404.sysmon.evtx.gz to host
2026-04-14 14:04:47,384 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6596, Max size: 100000000
2026-04-14 14:04:51,183 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:04:51,430 [lib.common.results] INFO: File 1776200691381835900.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:04:51,446 [lib.common.results] INFO: File 1776200691382812500.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:04:51,446 [lib.common.results] INFO: File 1776200691382812500.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:04:51,454 [lib.common.results] INFO: File 1776200691381835900.Application.evtx.gz size is 6839, Max size: 100000000
2026-04-14 14:04:51,477 [lib.common.results] INFO: File 1776200691430664000.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:04:51,500 [lib.common.results] INFO: File 1776200691446289000.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:04:51,500 [lib.common.results] INFO: File 1776200691446289000.Security.evtx.gz size is 7934, Max size: 100000000
2026-04-14 14:04:51,508 [lib.common.results] INFO: File 1776200691454101500.System.evtx.gz size is 8399, Max size: 100000000
2026-04-14 14:04:51,524 [lib.common.results] INFO: File 1776200691477539000.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:04:53,251 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:05:02,406 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:05:06,549 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:05:06,768 [lib.common.results] INFO: File 1776200706721679600.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:05:06,784 [lib.common.results] INFO: File 1776200706721679600.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:05:06,784 [lib.common.results] INFO: File 1776200706721679600.Application.evtx.gz size is 6910, Max size: 100000000
2026-04-14 14:05:06,799 [lib.common.results] INFO: File 1776200706721679600.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:05:06,815 [lib.common.results] INFO: File 1776200706768554600.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:05:06,831 [lib.common.results] INFO: File 1776200706768554600.Security.evtx.gz size is 7934, Max size: 100000000
2026-04-14 14:05:06,831 [lib.common.results] INFO: File 1776200706784179600.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:05:06,862 [lib.common.results] INFO: File 1776200706799804600.System.evtx.gz size is 8408, Max size: 100000000
2026-04-14 14:05:06,877 [lib.common.results] INFO: File 1776200706815429600.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:05:07,498 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200707.4980466.sysmon.evtx.gz to host
2026-04-14 14:05:07,498 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6685, Max size: 100000000
2026-04-14 14:05:13,343 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:05:21,928 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:05:22,155 [lib.common.results] INFO: File 1776200722100585900.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:05:22,170 [lib.common.results] INFO: File 1776200722108398400.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:05:22,170 [lib.common.results] INFO: File 1776200722100585900.Application.evtx.gz size is 6844, Max size: 100000000
2026-04-14 14:05:22,178 [lib.common.results] INFO: File 1776200722108398400.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:05:22,217 [lib.common.results] INFO: File 1776200722163085900.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:05:22,217 [lib.common.results] INFO: File 1776200722155273400.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:05:22,225 [lib.common.results] INFO: File 1776200722163085900.Security.evtx.gz size is 7839, Max size: 100000000
2026-04-14 14:05:22,225 [lib.common.results] INFO: File 1776200722163085900.System.evtx.gz size is 8383, Max size: 100000000
2026-04-14 14:05:22,264 [lib.common.results] INFO: File 1776200722217773400.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:05:22,514 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:05:27,588 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200727.5888672.sysmon.evtx.gz to host
2026-04-14 14:05:27,588 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 6667, Max size: 100000000
2026-04-14 14:05:33,431 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:05:37,324 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:05:37,542 [lib.common.results] INFO: File 1776200737511718700.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:05:37,571 [lib.common.results] INFO: File 1776200737511718700.Application.evtx.gz size is 6844, Max size: 100000000
2026-04-14 14:05:37,574 [lib.common.results] INFO: File 1776200737511718700.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:05:37,579 [lib.common.results] INFO: File 1776200737511718700.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:05:37,610 [lib.common.results] INFO: File 1776200737542968700.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:05:37,618 [lib.common.results] INFO: File 1776200737562500000.Security.evtx.gz size is 7881, Max size: 100000000
2026-04-14 14:05:37,625 [lib.common.results] INFO: File 1776200737571289000.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:05:37,633 [lib.common.results] INFO: File 1776200737579101500.System.evtx.gz size is 8387, Max size: 100000000
2026-04-14 14:05:37,657 [lib.common.results] INFO: File 1776200737610351500.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:05:42,605 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:05:47,669 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200747.6699219.sysmon.evtx.gz to host
2026-04-14 14:05:47,669 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5247, Max size: 100000000
2026-04-14 14:05:52,680 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:05:52,907 [lib.common.results] INFO: File 1776200752860351500.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:05:52,907 [lib.common.results] INFO: File 1776200752860351500.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:05:52,922 [lib.common.results] INFO: File 1776200752860351500.Application.evtx.gz size is 6844, Max size: 100000000
2026-04-14 14:05:52,922 [lib.common.results] INFO: File 1776200752860351500.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:05:52,969 [lib.common.results] INFO: File 1776200752907226500.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:05:52,969 [lib.common.results] INFO: File 1776200752907226500.Security.evtx.gz size is 8193, Max size: 100000000
2026-04-14 14:05:52,969 [lib.common.results] INFO: File 1776200752907226500.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:05:52,985 [lib.common.results] INFO: File 1776200752922851500.System.evtx.gz size is 8403, Max size: 100000000
2026-04-14 14:05:53,000 [lib.common.results] INFO: File 1776200752969726500.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:05:53,548 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:06:02,686 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:06:07,736 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200767.7363281.sysmon.evtx.gz to host
2026-04-14 14:06:07,736 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5469, Max size: 100000000
2026-04-14 14:06:08,036 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:06:08,254 [lib.common.results] INFO: File 1776200768208007800.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:06:08,262 [lib.common.results] INFO: File 1776200768208007800.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:06:08,262 [lib.common.results] INFO: File 1776200768208007800.Application.evtx.gz size is 6844, Max size: 100000000
2026-04-14 14:06:08,278 [lib.common.results] INFO: File 1776200768208007800.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:06:08,333 [lib.common.results] INFO: File 1776200768254882800.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:06:08,333 [lib.common.results] INFO: File 1776200768262695300.Security.evtx.gz size is 7918, Max size: 100000000
2026-04-14 14:06:08,340 [lib.common.results] INFO: File 1776200768262695300.System.evtx.gz size is 8385, Max size: 100000000
2026-04-14 14:06:08,340 [lib.common.results] INFO: File 1776200768262695300.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:06:08,379 [lib.common.results] INFO: File 1776200768325195300.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:06:13,617 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:06:22,755 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:06:23,427 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:06:23,662 [lib.common.results] INFO: File 1776200783599609300.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:06:23,662 [lib.common.results] INFO: File 1776200783599609300.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:06:23,677 [lib.common.results] INFO: File 1776200783599609300.Application.evtx.gz size is 6844, Max size: 100000000
2026-04-14 14:06:23,693 [lib.common.results] INFO: File 1776200783615234300.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:06:23,724 [lib.common.results] INFO: File 1776200783662109300.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:06:23,724 [lib.common.results] INFO: File 1776200783677734300.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:06:23,740 [lib.common.results] INFO: File 1776200783662109300.Security.evtx.gz size is 7865, Max size: 100000000
2026-04-14 14:06:23,740 [lib.common.results] INFO: File 1776200783693359300.System.evtx.gz size is 8408, Max size: 100000000
2026-04-14 14:06:23,771 [lib.common.results] INFO: File 1776200783724609300.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:06:27,845 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200787.8457031.sysmon.evtx.gz to host
2026-04-14 14:06:27,845 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5288, Max size: 100000000
2026-04-14 14:06:33,700 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:06:34,325 [root] INFO: Analysis timeout hit, terminating analysis
2026-04-14 14:06:34,325 [lib.api.process] INFO: Terminate event set for process 2620
2026-04-14 14:06:34,325 [root] DEBUG: 2620: Terminate Event: Attempting to dump process 2620
2026-04-14 14:06:34,325 [root] DEBUG: 2620: VerifyCodeSection: Executable code does not match, 0x64c of 0x154f matching
2026-04-14 14:06:34,325 [root] DEBUG: 2620: DoProcessDump: Code modification detected, dumping Imagebase at 0x00D60000.
2026-04-14 14:06:34,325 [root] DEBUG: 2620: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-14 14:06:34,325 [root] DEBUG: 2620: DumpProcess: Instantiating PeParser with address: 0x00D60000.
2026-04-14 14:06:34,325 [root] DEBUG: 2620: DumpProcess: Module entry point VA is 0x000010D4.
2026-04-14 14:06:34,356 [lib.common.results] INFO: File C:\AjCWZHyUB\CAPE\2620_139403462114242026 size is 1915904, Max size: 100000000
2026-04-14 14:06:34,372 [root] DEBUG: 2620: DumpProcess: Module image dump success - dump size 0x1d3c00.
2026-04-14 14:06:34,403 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx
2026-04-14 14:06:34,403 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Office\Word15.customUI
2026-04-14 14:06:34,403 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{AE58CC0B-5B3A-480D-B32E-00A87201BFFE}.tmp
2026-04-14 14:06:34,403 [lib.api.process] INFO: Termination confirmed for process 2620
2026-04-14 14:06:34,403 [root] INFO: Terminate event set for process 2620
2026-04-14 14:06:34,403 [root] DEBUG: 2620: Terminate Event: monitor shutdown complete for process 2620
2026-04-14 14:06:34,403 [root] INFO: Created shutdown mutex
2026-04-14 14:06:35,404 [root] INFO: Shutting down package
2026-04-14 14:06:35,404 [root] INFO: Stopping auxiliary modules
2026-04-14 14:06:35,404 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid
2026-04-14 14:06:35,412 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000
2026-04-14 14:06:35,427 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:06:35,654 [lib.common.results] INFO: File 1776200795607421800.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:06:35,654 [lib.common.results] INFO: File 1776200795607421800.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:06:35,669 [lib.common.results] INFO: File 1776200795607421800.Application.evtx.gz size is 6844, Max size: 100000000
2026-04-14 14:06:35,669 [lib.common.results] INFO: File 1776200795615234300.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:06:35,701 [lib.common.results] INFO: File 1776200795654296800.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:06:35,716 [lib.common.results] INFO: File 1776200795669921800.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:06:35,716 [lib.common.results] INFO: File 1776200795654296800.Security.evtx.gz size is 8097, Max size: 100000000
2026-04-14 14:06:35,732 [lib.common.results] INFO: File 1776200795669921800.System.evtx.gz size is 8389, Max size: 100000000
2026-04-14 14:06:35,763 [lib.common.results] INFO: File 1776200795701171800.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:06:38,805 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell
2026-04-14 14:06:39,000 [lib.common.results] INFO: File 1776200798954101500.InternetExplorer.evtx.gz size is 253, Max size: 100000000
2026-04-14 14:06:39,016 [lib.common.results] INFO: File 1776200798954101500.Application.evtx.gz size is 6844, Max size: 100000000
2026-04-14 14:06:39,016 [lib.common.results] INFO: File 1776200798954101500.HardwareEvents.evtx.gz size is 214, Max size: 100000000
2026-04-14 14:06:39,016 [lib.common.results] INFO: File 1776200798954101500.KeyManagementService.evtx.gz size is 8649, Max size: 100000000
2026-04-14 14:06:39,047 [lib.common.results] INFO: File 1776200799000976500.OAlerts.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:06:39,063 [lib.common.results] INFO: File 1776200799000976500.Setup.evtx.gz size is 247, Max size: 100000000
2026-04-14 14:06:39,063 [lib.common.results] INFO: File 1776200799000976500.Security.evtx.gz size is 7872, Max size: 100000000
2026-04-14 14:06:39,063 [lib.common.results] INFO: File 1776200799016601500.System.evtx.gz size is 8391, Max size: 100000000
2026-04-14 14:06:39,110 [lib.common.results] INFO: File 1776200799047851500.WindowsPowerShell.evtx.gz size is 2097, Max size: 100000000
2026-04-14 14:06:40,877 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine
2026-04-14 14:06:40,877 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump
2026-04-14 14:06:42,893 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs
2026-04-14 14:06:45,956 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200805.9560544.sysmon.evtx.gz to host
2026-04-14 14:06:45,956 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 11337, Max size: 100000000
2026-04-14 14:06:45,971 [root] INFO: Finishing auxiliary modules
2026-04-14 14:06:45,971 [root] INFO: Shutting down pipe server and dumping dropped files
2026-04-14 14:06:45,971 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm size is 17789, Max size: 100000000
2026-04-14 14:06:45,987 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\~$34_as_password_ha.docx size is 162, Max size: 100000000
2026-04-14 14:06:45,987 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10 size is 23349, Max size: 100000000
2026-04-14 14:06:46,018 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx size is 107520, Max size: 100000000
2026-04-14 14:06:46,034 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\Word15.customUI size is 3514, Max size: 100000000
2026-04-14 14:06:46,049 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{AE58CC0B-5B3A-480D-B32E-00A87201BFFE}.tmp size is 1024, Max size: 100000000
2026-04-14 14:06:46,065 [root] WARNING: Folder at path "C:\AjCWZHyUB\debugger" does not exist, skipping
2026-04-14 14:06:46,065 [root] INFO: Uploading files at path "C:\AjCWZHyUB\tlsdump"
2026-04-14 14:06:46,065 [lib.common.results] INFO: File C:\AjCWZHyUB\tlsdump\tlsdump.log size is 1644, Max size: 100000000
2026-04-14 14:06:46,081 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win7office2k3flash2800137TWN3H100 | win7office2k3flash2800137TWN3H100 | KVM | 2026-04-14 20:03:49 | 2026-04-14 20:06:57 | internet |
| File Name | 1234_as_password_ha.docx |
|---|---|
| File Size | 107520 bytes |
| File Type | CDFV2 Encrypted |
| MD5 | 31ecd43e3606e0e4fe8ed3dc515e8b69 |
| SHA1 | b5f7856b2a0ca9bce5355bfb6e81e5991183ebf4 |
| SHA256 | af46d415f384795c00d2c08071848cf6c304e116b0db05e85a74ca3aeb783af0 |
| SHA512 | 077abf6135aa0927ec816fab927a5665eb826b3620174749c954c5b3c950889cef2693d86a065aaf036591b9bc29e96275ce54663754a032146a9fc29dc65ec6 |
| SHA3-384 | 5681b7a8afe9ce13719632b96a2cec0a09512fd2fa77d030f5077867fc5ea0e313c2e0a52c993a9359be977ce86776d2 |
| CRC32 | 445C5EE7 |
| TLSH | T1B5B31276C4A4CCDBE0222DB97247D40550236D8ED6813E663FAAB5050AF02B66FEC5FD |
| Ssdeep | 3072:SKoFaUTc1xuMY8n2+IuyiVVZOTAduwe/N/:JoRT8k+ZwAkw4 |
File
|
|
| Direct | IP | Country Name |
|---|---|---|
| Y | 8.8.8.8 [VT] | United States |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| roaming.svc.cloud.microsoft [VT] |
CNAME eur.roaming1.live.com.akadns.net
[VT]
A 52.110.10.42 [VT] CNAME roaming-prod-weightedww.trafficmanager.net [VT] A 52.110.10.72 [VT] CNAME atm.office.mira.tm.svc.cloud.microsoft [VT] A 52.110.10.65 [VT] A 52.110.10.21 [VT] CNAME prod.roaming1.live.com.akadns.net [VT] |
52.110.10.27 [VT] |
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP