| Category | Package | Started | Completed | Duration | Options | Log | MalScore |
|---|---|---|---|---|---|---|---|
| FILE | doc | 2026-04-14 20:04:26 | 2026-04-14 20:06:27 | 121 seconds | Show Options | Show Log | 1.5 |
procdump=1
amsidump=1
2025-12-02 01:28:04,656 [root] INFO: Date set to: 20260414T13:04:25, timeout set to: 150 2026-04-14 14:04:25,031 [root] DEBUG: Starting analyzer from: C:\tmpu4fqq8td 2026-04-14 14:04:25,031 [root] DEBUG: Storing results at: C:\WzRRSPxxH 2026-04-14 14:04:25,031 [root] DEBUG: Pipe server name: \\.\PIPE\VaTxnjdOv 2026-04-14 14:04:25,031 [root] DEBUG: Python path: C:\olddocs 2026-04-14 14:04:25,031 [root] INFO: Analysis package "doc" has been specified 2026-04-14 14:04:25,031 [root] DEBUG: Importing analysis package "doc"... 2026-04-14 14:04:25,046 [root] DEBUG: Initializing analysis package "doc"... 2026-04-14 14:04:25,046 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL option 2026-04-14 14:04:25,046 [root] INFO: Analyzer: Package modules.packages.doc does not specify a DLL_64 option 2026-04-14 14:04:25,046 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader option 2026-04-14 14:04:25,046 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader_64 option 2026-04-14 14:04:25,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.browser"... 2026-04-14 14:04:25,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.curtain"... 2026-04-14 14:04:25,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.default_apps"... 2026-04-14 14:04:25,093 [root] DEBUG: Importing auxiliary module "modules.auxiliary.digisig"... 2026-04-14 14:04:25,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.disguise"... 2026-04-14 14:04:25,109 [root] DEBUG: Importing auxiliary module "modules.auxiliary.evtx"... 2026-04-14 14:04:25,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.fiddler"... 2026-04-14 14:04:25,125 [root] DEBUG: Importing auxiliary module "modules.auxiliary.human"... 2026-04-14 14:04:25,140 [root] DEBUG: Importing auxiliary module "modules.auxiliary.screenshots"... 2026-04-14 14:04:25,156 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-04-14 14:04:25,265 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab' 2026-04-14 14:04:25,281 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw' 2026-04-14 14:04:25,281 [root] DEBUG: Importing auxiliary module "modules.auxiliary.sysmon"... 2026-04-14 14:04:25,281 [root] DEBUG: Importing auxiliary module "modules.auxiliary.tlsdump"... 2026-04-14 14:04:25,281 [root] DEBUG: Importing auxiliary module "modules.auxiliary.usage"... 2026-04-14 14:04:25,296 [root] DEBUG: Initializing auxiliary module "Browser"... 2026-04-14 14:04:25,296 [root] DEBUG: Started auxiliary module Browser 2026-04-14 14:04:25,296 [root] DEBUG: Initializing auxiliary module "Curtain"... 2026-04-14 14:04:25,296 [root] DEBUG: Started auxiliary module Curtain 2026-04-14 14:04:25,296 [root] DEBUG: Initializing auxiliary module "DefaultApps"... 2026-04-14 14:04:25,343 [modules.auxiliary.default_apps] DEBUG: Getting current user SID using WinAPI 2026-04-14 14:04:25,343 [root] DEBUG: Started auxiliary module DefaultApps 2026-04-14 14:04:25,343 [root] DEBUG: Initializing auxiliary module "DigiSig"... 2026-04-14 14:04:25,343 [modules.auxiliary.digisig] INFO: signtool.exe was not found in bin/ 2026-04-14 14:04:25,343 [modules.auxiliary.digisig] INFO: doc 2026-04-14 14:04:25,343 [modules.auxiliary.digisig] INFO: Skipping authenticode validation, unsupported analyzer package 2026-04-14 14:04:25,343 [root] DEBUG: Started auxiliary module DigiSig 2026-04-14 14:04:25,343 [root] DEBUG: Initializing auxiliary module "Disguise"... 2026-04-14 14:04:25,593 [modules.auxiliary.disguise] INFO: Setting NoRecentDocsHistory 2026-04-14 14:04:25,593 [root] WARNING: Cannot execute auxiliary module Disguise: [WinError 2] The system cannot find the file specified 2026-04-14 14:04:25,593 [root] DEBUG: Initializing auxiliary module "Evtx"... 2026-04-14 14:04:25,593 [modules.auxiliary.evtx] INFO: Loading audit policy C:\tmpu4fqq8td\bin\auditpol.csv 2026-04-14 14:04:25,828 [modules.auxiliary.evtx] INFO: Wiping logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:04:26,656 [root] DEBUG: Started auxiliary module Evtx 2026-04-14 14:04:26,656 [root] DEBUG: Initializing auxiliary module "Fiddler"... 2026-04-14 14:04:26,671 [modules.auxiliary.fiddler] INFO: fiddler package: doc 2026-04-14 14:04:26,671 [root] DEBUG: Started auxiliary module Fiddler 2026-04-14 14:04:26,671 [root] DEBUG: Initializing auxiliary module "Human"... 2026-04-14 14:04:26,671 [root] DEBUG: Started auxiliary module Human 2026-04-14 14:04:26,671 [root] DEBUG: Initializing auxiliary module "Screenshots"... 2026-04-14 14:04:26,671 [root] DEBUG: Started auxiliary module Screenshots 2026-04-14 14:04:26,671 [root] DEBUG: Initializing auxiliary module "Sysmon"... 2026-04-14 14:04:26,671 [modules.auxiliary.sysmon] INFO: Seeing if we need to update sysmon config 2026-04-14 14:04:26,671 [root] DEBUG: Started auxiliary module Sysmon 2026-04-14 14:04:26,671 [root] DEBUG: Initializing auxiliary module "TLSDumpMasterSecrets"... 2026-04-14 14:04:26,671 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 556 2026-04-14 14:04:26,687 [modules.auxiliary.sysmon] INFO: Found Sysmon Executable 2026-04-14 14:04:26,687 [modules.auxiliary.sysmon] INFO: Found Sysmon config 2026-04-14 14:04:26,687 [lib.api.process] INFO: Monitor config for process 556: C:\tmpu4fqq8td\dll\556.ini 2026-04-14 14:04:26,687 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2026-04-14 14:04:26,687 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2026-04-14 14:04:26,687 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2026-04-14 14:04:26,687 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2026-04-14 14:04:26,687 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2026-04-14 14:04:26,687 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2026-04-14 14:04:26,687 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2026-04-14 14:04:26,687 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpu4fqq8td\dll\nkEgfpU.dll, loader C:\tmpu4fqq8td\bin\GqzrpdtJ.exe 2026-04-14 14:04:26,718 [root] DEBUG: Loader: IAT patching disabled. 2026-04-14 14:04:26,718 [root] DEBUG: Loader: Injecting process 556 with C:\tmpu4fqq8td\dll\nkEgfpU.dll. 2026-04-14 14:04:26,765 [root] DEBUG: 556: Python path set to 'C:\olddocs'. 2026-04-14 14:04:26,765 [root] DEBUG: 556: Disabling sleep skipping. 2026-04-14 14:04:26,765 [root] DEBUG: 556: Process dumps enabled. 2026-04-14 14:04:26,765 [root] DEBUG: 556: AMSI dumping enabled. 2026-04-14 14:04:26,781 [root] DEBUG: 556: Monitor config - unrecognised key office. 2026-04-14 14:04:26,781 [root] DEBUG: 556: In-monitor YARA scans disabled. 2026-04-14 14:04:26,781 [root] DEBUG: 556: TLS secret dump mode enabled. 2026-04-14 14:04:26,781 [root] DEBUG: 556: Monitor initialised: 64-bit capemon loaded in process 556 at 0x000007FEF5AC0000, thread 2260, image base 0x00000000FF4A0000, stack from 0x0000000001D93000-0x0000000001DA0000 2026-04-14 14:04:26,781 [root] DEBUG: 556: Commandline: C:\Windows\system32\lsass.exe 2026-04-14 14:04:26,796 [root] DEBUG: 556: Hooked 5 out of 5 functions 2026-04-14 14:04:26,796 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-04-14 14:04:26,796 [root] DEBUG: Successfully injected DLL C:\tmpu4fqq8td\dll\nkEgfpU.dll. 2026-04-14 14:04:26,796 [lib.api.process] INFO: Injected into suspended 64-bit process with pid 556 2026-04-14 14:04:26,796 [root] DEBUG: Started auxiliary module TLSDumpMasterSecrets 2026-04-14 14:04:26,796 [root] DEBUG: Initializing auxiliary module "Usage"... 2026-04-14 14:04:26,796 [root] DEBUG: Started auxiliary module Usage 2026-04-14 14:04:28,859 [modules.auxiliary.sysmon] INFO: Clearing existing sysmon logs 2026-04-14 14:04:29,593 [root] INFO: Restarting WMI Service 2026-04-14 14:04:38,703 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" with arguments ""C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx" /q" with pid 1556 2026-04-14 14:04:38,703 [lib.api.process] INFO: Monitor config for process 1556: C:\tmpu4fqq8td\dll\1556.ini 2026-04-14 14:04:38,703 [lib.api.process] INFO: Option 'procdump' with value '1' sent to monitor 2026-04-14 14:04:38,703 [lib.api.process] INFO: Option 'amsidump' with value '1' sent to monitor 2026-04-14 14:04:38,703 [lib.api.process] INFO: Option 'disable_hook_content' with value '4' sent to monitor 2026-04-14 14:04:38,703 [lib.api.process] INFO: Option 'office' with value '1' sent to monitor 2026-04-14 14:04:38,703 [lib.api.process] INFO: Option 'yarascan' with value '0' sent to monitor 2026-04-14 14:04:38,703 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor 2026-04-14 14:04:38,703 [lib.api.process] INFO: 32-bit DLL to inject is C:\tmpu4fqq8td\dll\OFlFcyS.dll, loader C:\tmpu4fqq8td\bin\vvUEZDF.exe 2026-04-14 14:04:38,734 [root] DEBUG: Loader: IAT patching disabled. 2026-04-14 14:04:38,734 [root] DEBUG: Loader: Injecting process 1556 (thread 2656) with C:\tmpu4fqq8td\dll\OFlFcyS.dll. 2026-04-14 14:04:38,734 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued. 2026-04-14 14:04:38,734 [root] DEBUG: Successfully injected DLL C:\tmpu4fqq8td\dll\OFlFcyS.dll. 2026-04-14 14:04:38,750 [lib.api.process] INFO: Injected into suspended 32-bit process with pid 1556 2026-04-14 14:04:38,859 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 14:04:40,750 [lib.api.process] INFO: Successfully resumed process with pid 1556 2026-04-14 14:04:40,937 [root] DEBUG: 1556: Python path set to 'C:\olddocs'. 2026-04-14 14:04:40,937 [root] DEBUG: 1556: Disabling sleep skipping. 2026-04-14 14:04:40,937 [root] DEBUG: 1556: Process dumps enabled. 2026-04-14 14:04:40,937 [root] DEBUG: 1556: AMSI dumping enabled. 2026-04-14 14:04:40,937 [root] DEBUG: 1556: Monitor config - unrecognised key office. 2026-04-14 14:04:40,937 [root] DEBUG: 1556: In-monitor YARA scans disabled. 2026-04-14 14:04:40,937 [root] DEBUG: 1556: Dropped file limit defaulting to 100. 2026-04-14 14:04:40,937 [root] DEBUG: 1556: Microsoft Office settings enabled. 2026-04-14 14:04:40,953 [root] DEBUG: 1556: Monitor initialised: 32-bit capemon loaded in process 1556 at 0x73e20000, thread 2656, image base 0xd00000, stack from 0x183000-0x190000 2026-04-14 14:04:40,953 [root] DEBUG: 1556: Commandline: "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" "C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx" /q 2026-04-14 14:04:40,984 [root] DEBUG: 1556: Hooked 456 out of 456 functions 2026-04-14 14:04:40,984 [root] INFO: Loaded monitor into process with pid 1556 2026-04-14 14:04:41,218 [root] DEBUG: 1556: DLL loaded at 0x6FD50000: C:\Program Files (x86)\Microsoft Office\Office15\wwlib (0x14bc000 bytes). 2026-04-14 14:04:41,249 [root] DEBUG: 1556: DLL loaded at 0x73C90000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus (0x190000 bytes). 2026-04-14 14:04:41,406 [root] DEBUG: 1556: DLL loaded at 0x6EFA0000: C:\Program Files (x86)\Microsoft Office\Office15\oart (0xda8000 bytes). 2026-04-14 14:04:41,406 [root] DEBUG: 1556: DLL loaded at 0x743D0000: C:\Windows\system32\MSVCP100 (0x69000 bytes). 2026-04-14 14:04:41,453 [root] DEBUG: 1556: DLL loaded at 0x72380000: C:\Windows\system32\d2d1 (0x347000 bytes). 2026-04-14 14:04:41,656 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:04:41,781 [root] DEBUG: 1556: DLL loaded at 0x6D6B0000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso (0x18e4000 bytes). 2026-04-14 14:04:41,796 [root] DEBUG: 1556: DLL loaded at 0x73130000: C:\Windows\system32\MSIMG32 (0x5000 bytes). 2026-04-14 14:04:41,828 [root] DEBUG: 1556: DLL loaded at 0x73320000: C:\Windows\system32\uxtheme (0x80000 bytes). 2026-04-14 14:04:41,859 [root] DEBUG: 1556: DLL loaded at 0x73240000: C:\Windows\system32\WTSAPI32 (0xd000 bytes). 2026-04-14 14:04:41,875 [root] DEBUG: 1556: DLL loaded at 0x74600000: C:\Windows\system32\WINSTA (0x29000 bytes). 2026-04-14 14:04:41,890 [root] DEBUG: 1556: DLL loaded at 0x744F0000: C:\Windows\system32\dxgi (0x4c000 bytes). 2026-04-14 14:04:41,906 [root] DEBUG: 1556: DLL loaded at 0x73250000: C:\Windows\system32\VERSION (0x9000 bytes). 2026-04-14 14:04:41,906 [root] DEBUG: 1556: DLL loaded at 0x743B0000: C:\Windows\system32\dwmapi (0x13000 bytes). 2026-04-14 14:04:41,906 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 14:04:41,921 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:41,921 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:41,937 [root] DEBUG: 1556: DLL loaded at 0x750A0000: C:\Windows\syswow64\WINTRUST (0x2f000 bytes). 2026-04-14 14:04:41,953 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 14:04:41,953 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:41,953 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:41,953 [lib.common.results] INFO: File 1776200681875000000.HardwareEvents.evtx.gz size is 251, Max size: 100000000 2026-04-14 14:04:41,968 [root] DEBUG: 1556: DLL loaded at 0x72140000: C:\Windows\system32\msi (0x240000 bytes). 2026-04-14 14:04:41,984 [lib.common.results] INFO: File 1776200681890625000.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2026-04-14 14:04:41,984 [lib.common.results] INFO: File 1776200681859375000.Application.evtx.gz size is 6945, Max size: 100000000 2026-04-14 14:04:41,984 [lib.common.results] INFO: File 1776200681906250000.KeyManagementService.evtx.gz size is 3253, Max size: 100000000 2026-04-14 14:04:42,062 [lib.common.results] INFO: File 1776200681953125000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 14:04:42,078 [lib.common.results] INFO: File 1776200681984375000.System.evtx.gz size is 9136, Max size: 100000000 2026-04-14 14:04:42,078 [lib.common.results] INFO: File 1776200681984375000.Setup.evtx.gz size is 242, Max size: 100000000 2026-04-14 14:04:42,078 [lib.common.results] INFO: File 1776200681968750000.Security.evtx.gz size is 15862, Max size: 100000000 2026-04-14 14:04:42,109 [lib.common.results] INFO: File 1776200682046875000.WindowsPowerShell.evtx.gz size is 5412, Max size: 100000000 2026-04-14 14:04:42,218 [root] DEBUG: 1556: DLL loaded at 0x71B20000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSPTLS (0x116000 bytes). 2026-04-14 14:04:42,234 [root] DEBUG: 1556: DLL loaded at 0x75EB0000: C:\Windows\syswow64\SHELL32 (0xc4a000 bytes). 2026-04-14 14:04:42,234 [root] DEBUG: 1556: DLL loaded at 0x75080000: C:\Windows\syswow64\profapi (0xb000 bytes). 2026-04-14 14:04:42,265 [root] DEBUG: 1556: DLL loaded at 0x733B0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\Comctl32 (0x19e000 bytes). 2026-04-14 14:04:42,359 [root] DEBUG: 1556: DLL loaded at 0x73BA0000: C:\Windows\system32\d3d10_1 (0x2c000 bytes). 2026-04-14 14:04:42,359 [root] DEBUG: 1556: DLL loaded at 0x73B50000: C:\Windows\system32\d3d10_1core (0x41000 bytes). 2026-04-14 14:04:42,359 [root] DEBUG: 1556: DLL loaded at 0x71620000: C:\Windows\system32\d3d11 (0x175000 bytes). 2026-04-14 14:04:42,375 [root] DEBUG: 1556: DLL loaded at 0x71430000: C:\Windows\system32\D3D10Warp (0x1e9000 bytes). 2026-04-14 14:04:42,375 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 14:04:42,375 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:42,375 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:42,390 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 14:04:42,390 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:42,390 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:42,421 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 14:04:42,421 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:42,421 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:42,437 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 14:04:42,437 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:42,437 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:42,515 [root] DEBUG: 1556: DLL loaded at 0x71300000: C:\Windows\system32\WindowsCodecs (0x130000 bytes). 2026-04-14 14:04:42,531 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 14:04:42,531 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:42,531 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:42,546 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\setupapi (0x19d000 bytes). 2026-04-14 14:04:42,546 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:42,546 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:42,562 [root] DEBUG: 1556: DLL loaded at 0x6D570000: C:\Windows\system32\DWrite (0x135000 bytes). 2026-04-14 14:04:42,578 [root] DEBUG: 1556: DLL loaded at 0x73B00000: C:\Windows\system32\mscoree (0x4a000 bytes). 2026-04-14 14:04:42,578 [root] DEBUG: 1556: DLL loaded at 0x71270000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes). 2026-04-14 14:04:42,593 [root] DEBUG: 1556: DLL loaded at 0x6D4B0000: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\adal (0xb5000 bytes). 2026-04-14 14:04:42,609 [root] DEBUG: 1556: DLL loaded at 0x71210000: C:\Windows\system32\WINHTTP (0x58000 bytes). 2026-04-14 14:04:42,609 [root] DEBUG: 1556: DLL loaded at 0x6D460000: C:\Windows\system32\webio (0x50000 bytes). 2026-04-14 14:04:42,609 [root] DEBUG: 1556: DLL loaded at 0x753F0000: C:\Windows\syswow64\WININET (0x1e4000 bytes). 2026-04-14 14:04:42,609 [root] DEBUG: 1556: DLL loaded at 0x75090000: C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0 (0x4000 bytes). 2026-04-14 14:04:42,625 [root] DEBUG: 1556: DLL loaded at 0x75C60000: C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0 (0x4000 bytes). 2026-04-14 14:04:42,625 [root] DEBUG: 1556: DLL loaded at 0x755E0000: C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0 (0x4000 bytes). 2026-04-14 14:04:42,625 [root] DEBUG: 1556: DLL loaded at 0x74EE0000: C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0 (0x3000 bytes). 2026-04-14 14:04:42,625 [root] DEBUG: 1556: DLL loaded at 0x75870000: C:\Windows\syswow64\normaliz (0x3000 bytes). 2026-04-14 14:04:42,625 [root] DEBUG: 1556: DLL loaded at 0x75A00000: C:\Windows\syswow64\iertutil (0x232000 bytes). 2026-04-14 14:04:42,625 [root] DEBUG: 1556: DLL loaded at 0x76FC0000: C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0 (0x5000 bytes). 2026-04-14 14:04:42,625 [root] DEBUG: 1556: DLL loaded at 0x76BB0000: C:\Windows\syswow64\USERENV (0x17000 bytes). 2026-04-14 14:04:42,625 [root] DEBUG: 1556: DLL loaded at 0x746C0000: C:\Windows\system32\Secur32 (0x8000 bytes). 2026-04-14 14:04:42,718 [root] DEBUG: 1556: DLL loaded at 0x750D0000: C:\Windows\syswow64\CLBCatQ (0x83000 bytes). 2026-04-14 14:04:42,718 [root] DEBUG: 1556: DLL loaded at 0x6D400000: C:\Windows\System32\netprofm (0x5a000 bytes). 2026-04-14 14:04:42,718 [root] DEBUG: 1556: DLL loaded at 0x74450000: C:\Windows\System32\nlaapi (0x10000 bytes). 2026-04-14 14:04:42,734 [root] DEBUG: 1556: DLL loaded at 0x72A50000: C:\Windows\system32\CRYPTSP (0x17000 bytes). 2026-04-14 14:04:42,750 [root] DEBUG: 1556: DLL loaded at 0x72A10000: C:\Windows\system32\rsaenh (0x3b000 bytes). 2026-04-14 14:04:42,750 [root] DEBUG: 1556: DLL loaded at 0x73A00000: C:\Windows\system32\RpcRtRemote (0xe000 bytes). 2026-04-14 14:04:42,750 [root] DEBUG: 1556: DLL loaded at 0x743A0000: C:\Windows\System32\npmproxy (0x8000 bytes). 2026-04-14 14:04:42,937 [root] DEBUG: 1556: DLL loaded at 0x6D270000: C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20 (0x18e000 bytes). 2026-04-14 14:04:43,875 [root] DEBUG: 1556: DLL loaded at 0x72A70000: C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\osppc (0x2d000 bytes). 2026-04-14 14:04:43,875 [root] DEBUG: 1556: DLL loaded at 0x73A30000: C:\Windows\system32\IPHLPAPI (0x1c000 bytes). 2026-04-14 14:04:43,875 [root] DEBUG: 1556: DLL loaded at 0x73A20000: C:\Windows\system32\WINNSI (0x7000 bytes). 2026-04-14 14:04:43,890 [root] DEBUG: 1556: DLL loaded at 0x74390000: C:\Windows\system32\dhcpcsvc6 (0xd000 bytes). 2026-04-14 14:04:43,890 [root] DEBUG: 1556: DLL loaded at 0x68560000: C:\Windows\system32\dhcpcsvc (0x12000 bytes). 2026-04-14 14:04:43,953 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200683.9531252.sysmon.evtx.gz to host 2026-04-14 14:04:43,953 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 9784, Max size: 100000000 2026-04-14 14:04:43,984 [root] DEBUG: 1556: DLL loaded at 0x68550000: C:\Windows\system32\credssp (0x8000 bytes). 2026-04-14 14:04:43,984 [root] DEBUG: 1556: DLL loaded at 0x739C0000: C:\Windows\system32\mswsock (0x3c000 bytes). 2026-04-14 14:04:43,984 [root] DEBUG: 1556: DLL loaded at 0x739B0000: C:\Windows\System32\wshtcpip (0x5000 bytes). 2026-04-14 14:04:44,000 [root] DEBUG: 1556: DLL loaded at 0x684F0000: C:\Windows\system32\WINSPOOL.DRV (0x51000 bytes). 2026-04-14 14:04:44,000 [root] DEBUG: 1556: DLL loaded at 0x739A0000: C:\Windows\System32\wship6 (0x6000 bytes). 2026-04-14 14:04:44,000 [root] DEBUG: 1556: DLL loaded at 0x684A0000: C:\Windows\system32\DNSAPI (0x44000 bytes). 2026-04-14 14:04:44,046 [root] DEBUG: 1556: DLL loaded at 0x68450000: C:\Windows\SysWOW64\schannel (0x41000 bytes). 2026-04-14 14:04:44,078 [root] DEBUG: 556: DLL loaded at 0x000007FEF15A0000: C:\Windows\system32\dssenh (0x32000 bytes). 2026-04-14 14:04:44,093 [root] DEBUG: 1556: DLL loaded at 0x75160000: C:\Windows\syswow64\SETUPAPI (0x19d000 bytes). 2026-04-14 14:04:44,109 [root] DEBUG: 1556: DLL loaded at 0x75D80000: C:\Windows\syswow64\CFGMGR32 (0x27000 bytes). 2026-04-14 14:04:44,109 [root] DEBUG: 1556: DLL loaded at 0x756F0000: C:\Windows\syswow64\DEVOBJ (0x12000 bytes). 2026-04-14 14:04:44,109 [root] DEBUG: 1556: DLL loaded at 0x68350000: C:\Windows\system32\propsys (0xf5000 bytes). 2026-04-14 14:04:44,109 [root] DEBUG: 1556: DLL loaded at 0x732F0000: C:\Windows\system32\ntmarta (0x21000 bytes). 2026-04-14 14:04:44,125 [root] DEBUG: 1556: DLL loaded at 0x76D90000: C:\Windows\syswow64\WLDAP32 (0x45000 bytes). 2026-04-14 14:04:44,187 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm 2026-04-14 14:04:44,218 [root] DEBUG: 1556: DLL loaded at 0x681F0000: C:\Windows\System32\msxml6 (0x158000 bytes). 2026-04-14 14:04:44,296 [root] DEBUG: 556: DLL loaded at 0x000007FEF8F70000: C:\Windows\system32\keyiso (0xb000 bytes). 2026-04-14 14:04:44,312 [root] DEBUG: 1556: DLL loaded at 0x681C0000: C:\Windows\system32\XmlLite (0x2f000 bytes). 2026-04-14 14:04:44,515 [root] DEBUG: 1556: DLL loaded at 0x76FD0000: C:\Windows\SysWOW64\urlmon (0x14a000 bytes). 2026-04-14 14:04:44,515 [root] DEBUG: 1556: DLL loaded at 0x75DB0000: C:\Windows\syswow64\api-ms-win-downlevel-ole32-l1-1-0 (0x4000 bytes). 2026-04-14 14:04:44,531 [root] DEBUG: 1556: DLL loaded at 0x681B0000: C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0 (0x4000 bytes). 2026-04-14 14:04:44,531 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx 2026-04-14 14:04:44,546 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\~$34_as_password_ha.docx 2026-04-14 14:04:44,703 [root] DEBUG: 1556: DLL loaded at 0x68170000: C:\Windows\system32\windowscodecsext (0x37000 bytes). 2026-04-14 14:04:44,718 [root] DEBUG: 1556: DLL loaded at 0x680F0000: C:\Windows\system32\mscms (0x79000 bytes). 2026-04-14 14:04:44,734 [root] DEBUG: 1556: DLL loaded at 0x680B0000: C:\Windows\system32\icm32 (0x38000 bytes). 2026-04-14 14:04:45,140 [root] DEBUG: 1556: DLL loaded at 0x68070000: C:\Windows\SysWOW64\bcryptprimitives (0x3d000 bytes). 2026-04-14 14:04:45,281 [root] DEBUG: 556: TLS 1.2 secrets logged to: C:\WzRRSPxxH\tlsdump\tlsdump.log 2026-04-14 14:04:45,359 [root] DEBUG: 556: DLL loaded at 0x000007FEFA370000: C:\Windows\system32\cryptnet (0x27000 bytes). 2026-04-14 14:04:45,359 [root] DEBUG: 556: DLL loaded at 0x000007FEFE7B0000: C:\Windows\system32\WLDAP32 (0x52000 bytes). 2026-04-14 14:04:45,406 [root] DEBUG: 1556: DLL loaded at 0x68030000: C:\Windows\system32\ncrypt (0x39000 bytes). 2026-04-14 14:04:45,531 [root] DEBUG: 1556: DLL loaded at 0x67FF0000: C:\Windows\system32\WINMM (0x32000 bytes). 2026-04-14 14:04:46,015 [root] DEBUG: 1556: DLL loaded at 0x67FD0000: C:\Windows\system32\GPAPI (0x16000 bytes). 2026-04-14 14:04:46,156 [root] DEBUG: 1556: DLL loaded at 0x67F90000: C:\Program Files (x86)\Microsoft Office\Office15\msproof7 (0x37000 bytes). 2026-04-14 14:04:46,171 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC 2026-04-14 14:04:46,171 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10 2026-04-14 14:04:46,203 [root] DEBUG: 1556: DLL loaded at 0x67EC0000: C:\Windows\system32\webservices (0xc2000 bytes). 2026-04-14 14:04:46,296 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma00546271.png0 size is 119666, Max size: 100000000 2026-04-14 14:04:46,343 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02786999.png0 size is 8127, Max size: 100000000 2026-04-14 14:04:46,359 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900771.png0 size is 10213, Max size: 100000000 2026-04-14 14:04:46,375 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382936.png0 size is 37573, Max size: 100000000 2026-04-14 14:04:46,390 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16382941.png0 size is 96333, Max size: 100000000 2026-04-14 14:04:46,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma02835058.png0 size is 186365, Max size: 100000000 2026-04-14 14:04:46,437 [root] DEBUG: 1556: DLL loaded at 0x67EA0000: C:\Windows\system32\cryptnet (0x1d000 bytes). 2026-04-14 14:04:46,453 [root] DEBUG: 1556: DLL loaded at 0x67E90000: C:\Windows\system32\SensApi (0x6000 bytes). 2026-04-14 14:04:46,453 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03978815.png0 size is 711398, Max size: 100000000 2026-04-14 14:04:46,484 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78018332.png0 size is 26105, Max size: 100000000 2026-04-14 14:04:46,515 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392850.png0 size is 280509, Max size: 100000000 2026-04-14 14:04:46,531 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45325165.png0 size is 9149, Max size: 100000000 2026-04-14 14:04:46,562 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma03982351.png0 size is 12860, Max size: 100000000 2026-04-14 14:04:46,593 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16392877.png0 size is 86215, Max size: 100000000 2026-04-14 14:04:46,609 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16402488.png0 size is 114584, Max size: 100000000 2026-04-14 14:04:46,640 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma16412178.png0 size is 283253, Max size: 100000000 2026-04-14 14:04:46,687 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma56348247.png0 size is 55049, Max size: 100000000 2026-04-14 14:04:46,703 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900720.png0 size is 22877, Max size: 100000000 2026-04-14 14:04:46,734 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-ma88924273.png0 size is 103770, Max size: 100000000 2026-04-14 14:04:46,750 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02836342.png0 size is 26220, Max size: 100000000 2026-04-14 14:04:46,781 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02892315.png0 size is 20776, Max size: 100000000 2026-04-14 14:04:46,796 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002124.png0 size is 11329, Max size: 100000000 2026-04-14 14:04:46,812 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt78500733.png0 size is 10169, Max size: 100000000 2026-04-14 14:04:46,843 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02911863.png0 size is 41743, Max size: 100000000 2026-04-14 14:04:46,859 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900688.png0 size is 8561, Max size: 100000000 2026-04-14 14:04:46,875 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900722.png0 size is 19188, Max size: 100000000 2026-04-14 14:04:46,906 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02900743.png0 size is 33070, Max size: 100000000 2026-04-14 14:04:46,937 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt02923944.png0 size is 4886, Max size: 100000000 2026-04-14 14:04:47,000 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt10002117.png0 size is 4962, Max size: 100000000 2026-04-14 14:04:47,062 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt16402400.png0 size is 33856, Max size: 100000000 2026-04-14 14:04:47,093 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt22746018.png0 size is 18469, Max size: 100000000 2026-04-14 14:04:47,109 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45088960.png0 size is 40992, Max size: 100000000 2026-04-14 14:04:47,125 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\binaries.templates.cdn.office.net\support-templates-en-us-mt45420242.png0 size is 13339, Max size: 100000000 2026-04-14 14:04:47,859 [root] DEBUG: 1556: DLL loaded at 0x67E60000: C:\Windows\system32\POWRPROF (0x25000 bytes). 2026-04-14 14:04:48,437 [root] DEBUG: 1556: DLL loaded at 0x67A00000: C:\Program Files (x86)\Microsoft Office\OFFICE15\PROOF\1033\MSGR3EN (0x486000 bytes). 2026-04-14 14:04:48,453 [root] DEBUG: 1556: DLL loaded at 0x67970000: C:\Program Files (x86)\Microsoft Office\Office15\PROOF\msspell7 (0x8a000 bytes). 2026-04-14 14:04:48,531 [root] DEBUG: 1556: DLL loaded at 0x677B0000: C:\Program Files (x86)\Microsoft Office\OFFICE15\mscss7en (0x61000 bytes). 2026-04-14 14:04:48,546 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex 2026-04-14 14:04:48,578 [root] DEBUG: 1556: DLL loaded at 0x67730000: C:\Program Files (x86)\Microsoft Office\OFFICE15\css7Data0009 (0x7f000 bytes). 2026-04-14 14:04:49,765 [lib.common.results] INFO: File c:\olddocs\1776200684765.saz size is 6636, Max size: 100000000 2026-04-14 14:04:49,781 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 14:04:57,140 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:04:57,406 [lib.common.results] INFO: File 1776200697343750000.HardwareEvents.evtx.gz size is 251, Max size: 100000000 2026-04-14 14:04:57,406 [lib.common.results] INFO: File 1776200697343750000.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2026-04-14 14:04:57,406 [lib.common.results] INFO: File 1776200697343750000.KeyManagementService.evtx.gz size is 3253, Max size: 100000000 2026-04-14 14:04:57,421 [lib.common.results] INFO: File 1776200697343750000.Application.evtx.gz size is 6864, Max size: 100000000 2026-04-14 14:04:57,468 [lib.common.results] INFO: File 1776200697406250000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 14:04:57,468 [lib.common.results] INFO: File 1776200697406250000.Setup.evtx.gz size is 242, Max size: 100000000 2026-04-14 14:04:57,468 [lib.common.results] INFO: File 1776200697406250000.System.evtx.gz size is 8878, Max size: 100000000 2026-04-14 14:04:57,468 [lib.common.results] INFO: File 1776200697406250000.Security.evtx.gz size is 7422, Max size: 100000000 2026-04-14 14:04:57,515 [lib.common.results] INFO: File 1776200697468750000.WindowsPowerShell.evtx.gz size is 5412, Max size: 100000000 2026-04-14 14:04:58,968 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 14:05:03,484 [root] DEBUG: 1556: DLL loaded at 0x67110000: C:\Windows\system32\SXS (0x5f000 bytes). 2026-04-14 14:05:04,109 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200704.109375.sysmon.evtx.gz to host 2026-04-14 14:05:04,109 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 102046, Max size: 100000000 2026-04-14 14:05:09,859 [lib.common.results] INFO: File c:\olddocs\1776200704859.saz size is 19461, Max size: 100000000 2026-04-14 14:05:09,875 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 14:05:12,531 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:05:12,812 [lib.common.results] INFO: File 1776200712750000000.HardwareEvents.evtx.gz size is 251, Max size: 100000000 2026-04-14 14:05:12,812 [lib.common.results] INFO: File 1776200712750000000.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2026-04-14 14:05:12,828 [lib.common.results] INFO: File 1776200712750000000.KeyManagementService.evtx.gz size is 3253, Max size: 100000000 2026-04-14 14:05:12,828 [lib.common.results] INFO: File 1776200712750000000.Application.evtx.gz size is 6808, Max size: 100000000 2026-04-14 14:05:12,859 [lib.common.results] INFO: File 1776200712812500000.Security.evtx.gz size is 7339, Max size: 100000000 2026-04-14 14:05:12,875 [lib.common.results] INFO: File 1776200712812500000.Setup.evtx.gz size is 242, Max size: 100000000 2026-04-14 14:05:12,875 [lib.common.results] INFO: File 1776200712812500000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 14:05:12,890 [lib.common.results] INFO: File 1776200712812500000.System.evtx.gz size is 8549, Max size: 100000000 2026-04-14 14:05:12,921 [lib.common.results] INFO: File 1776200712859375000.WindowsPowerShell.evtx.gz size is 5412, Max size: 100000000 2026-04-14 14:05:19,125 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 14:05:24,187 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200724.1875.sysmon.evtx.gz to host 2026-04-14 14:05:24,187 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5828, Max size: 100000000 2026-04-14 14:05:27,953 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:05:28,171 [lib.common.results] INFO: File 1776200728125000000.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2026-04-14 14:05:28,187 [lib.common.results] INFO: File 1776200728125000000.KeyManagementService.evtx.gz size is 3253, Max size: 100000000 2026-04-14 14:05:28,187 [lib.common.results] INFO: File 1776200728125000000.Application.evtx.gz size is 6808, Max size: 100000000 2026-04-14 14:05:28,187 [lib.common.results] INFO: File 1776200728125000000.HardwareEvents.evtx.gz size is 251, Max size: 100000000 2026-04-14 14:05:28,234 [lib.common.results] INFO: File 1776200728171875000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 14:05:28,249 [lib.common.results] INFO: File 1776200728187500000.Setup.evtx.gz size is 242, Max size: 100000000 2026-04-14 14:05:28,249 [lib.common.results] INFO: File 1776200728187500000.Security.evtx.gz size is 7434, Max size: 100000000 2026-04-14 14:05:28,249 [lib.common.results] INFO: File 1776200728187500000.System.evtx.gz size is 8567, Max size: 100000000 2026-04-14 14:05:28,281 [lib.common.results] INFO: File 1776200728234375000.WindowsPowerShell.evtx.gz size is 5412, Max size: 100000000 2026-04-14 14:05:29,937 [modules.auxiliary.human] INFO: Doing office click around. 2026-04-14 14:05:29,968 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 14:05:30,703 [root] DEBUG: 1556: DLL loaded at 0x66870000: C:\Program Files (x86)\Microsoft Office\Office15\igx (0x893000 bytes). 2026-04-14 14:05:30,796 [root] DEBUG: 1556: DLL loaded at 0x67970000: C:\Windows\system32\UIAutomationCore (0x8c000 bytes). 2026-04-14 14:05:30,796 [root] DEBUG: 1556: DLL loaded at 0x75880000: C:\Windows\syswow64\PSAPI (0x5000 bytes). 2026-04-14 14:05:30,796 [root] DEBUG: 1556: DLL loaded at 0x67930000: C:\Windows\system32\OLEACC (0x3c000 bytes). 2026-04-14 14:05:30,984 [root] DEBUG: 1556: set_hooks_by_export_directory: Hooked 0 out of 456 functions 2026-04-14 14:05:30,984 [root] DEBUG: 1556: DLL loaded at 0x678F0000: C:\Program Files (x86)\Microsoft Office\Office15\IEAWSDC (0x31000 bytes). 2026-04-14 14:05:31,093 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7CEC.tmp 2026-04-14 14:05:31,093 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7CEB.tmp 2026-04-14 14:05:31,249 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7D6A.tmp 2026-04-14 14:05:31,281 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7D9A.tmp 2026-04-14 14:05:31,296 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7DAA.tmp 2026-04-14 14:05:31,437 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7E48.tmp 2026-04-14 14:05:31,593 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7EE5.tmp 2026-04-14 14:05:31,656 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7F05.tmp 2026-04-14 14:05:31,765 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7F83.tmp 2026-04-14 14:05:31,921 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab7FE2.tmp 2026-04-14 14:05:32,000 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD 2026-04-14 14:05:32,000 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD 2026-04-14 14:05:32,000 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab8041.tmp 2026-04-14 14:05:32,109 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab80DE.tmp 2026-04-14 14:05:32,203 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F90F18257CBB4D84216AC1E1F3BB2C76 2026-04-14 14:05:32,203 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F90F18257CBB4D84216AC1E1F3BB2C76 2026-04-14 14:05:32,234 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab814C.tmp 2026-04-14 14:05:32,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD81CB.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD821A.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,421 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab81AB.tmp 2026-04-14 14:05:32,500 [root] DEBUG: 1556: DLL loaded at 0x678D0000: C:\Windows\system32\Cabinet (0x15000 bytes). 2026-04-14 14:05:32,562 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD82A9.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,562 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD82AB.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,578 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab8298.tmp 2026-04-14 14:05:32,578 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD82AA.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,593 [root] DEBUG: 1556: DLL loaded at 0x678C0000: C:\Windows\system32\DEVRTL (0xe000 bytes). 2026-04-14 14:05:32,656 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD821A.tmp\Banded.thmx 2026-04-14 14:05:32,656 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD830B.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,656 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD831B.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,671 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\cab830A.tmp 2026-04-14 14:05:32,671 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD821A.tmp\content.inf 2026-04-14 14:05:32,687 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD82AA.tmp\content.inf 2026-04-14 14:05:32,687 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD82A9.tmp\Basis.thmx 2026-04-14 14:05:32,703 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD82AB.tmp\Dividend.thmx 2026-04-14 14:05:32,718 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD81CB.tmp\Frame.thmx 2026-04-14 14:05:32,718 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD81CB.tmp\Frame.thmx 2026-04-14 14:05:32,718 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD82A9.tmp\content.inf 2026-04-14 14:05:32,750 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab7CEC.tmp size is 307348, Max size: 100000000 2026-04-14 14:05:32,750 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD82AA.tmp\Metropolitan.thmx 2026-04-14 14:05:32,750 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD82AA.tmp\Metropolitan.thmx 2026-04-14 14:05:32,750 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab7D9A.tmp size is 276650, Max size: 100000000 2026-04-14 14:05:32,765 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab7DAA.tmp size is 271273, Max size: 100000000 2026-04-14 14:05:32,765 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD830B.tmp\content.inf 2026-04-14 14:05:32,796 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD831B.tmp\Parallax.thmx 2026-04-14 14:05:32,796 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD838A.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,812 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\cab7CEB.tmp size is 295527, Max size: 100000000 2026-04-14 14:05:32,812 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\TCD83BA.tmp size is 0, Max size: 100000000 2026-04-14 14:05:32,828 [root] INFO: Added new file to list with pid None and path C:\Users\pgabriel\AppData\Local\Temp\TCD830B.tmp\View.thmx 2026-04-14 14:05:32,859 [root] DEBUG: 1556: Dropped file limit reached. 2026-04-14 14:05:39,218 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 14:05:43,312 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:05:43,562 [lib.common.results] INFO: File 1776200743515625000.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2026-04-14 14:05:43,593 [lib.common.results] INFO: File 1776200743515625000.KeyManagementService.evtx.gz size is 3253, Max size: 100000000 2026-04-14 14:05:43,593 [lib.common.results] INFO: File 1776200743515625000.HardwareEvents.evtx.gz size is 251, Max size: 100000000 2026-04-14 14:05:43,593 [lib.common.results] INFO: File 1776200743515625000.Application.evtx.gz size is 6958, Max size: 100000000 2026-04-14 14:05:43,625 [lib.common.results] INFO: File 1776200743562500000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 14:05:43,625 [lib.common.results] INFO: File 1776200743578125000.Setup.evtx.gz size is 242, Max size: 100000000 2026-04-14 14:05:43,640 [lib.common.results] INFO: File 1776200743578125000.Security.evtx.gz size is 7333, Max size: 100000000 2026-04-14 14:05:43,656 [lib.common.results] INFO: File 1776200743578125000.System.evtx.gz size is 8562, Max size: 100000000 2026-04-14 14:05:43,671 [lib.common.results] INFO: File 1776200743625000000.WindowsPowerShell.evtx.gz size is 5412, Max size: 100000000 2026-04-14 14:05:44,343 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200744.34375.sysmon.evtx.gz to host 2026-04-14 14:05:44,343 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 59373, Max size: 100000000 2026-04-14 14:05:50,078 [lib.common.results] INFO: File c:\olddocs\1776200745046.saz size is 19087643, Max size: 100000000 2026-04-14 14:05:50,218 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 14:05:57,125 [modules.auxiliary.human] INFO: Closing Office window 2026-04-14 14:05:57,578 [root] DEBUG: 1556: DLL loaded at 0x67FA0000: C:\Windows\system32\POWRPROF (0x25000 bytes). 2026-04-14 14:05:57,750 [root] DEBUG: 1556: NtTerminateProcess hook: Attempting to dump process 1556 2026-04-14 14:05:57,765 [root] DEBUG: 1556: VerifyCodeSection: Executable code does not match, 0x64c of 0x154f matching 2026-04-14 14:05:57,765 [root] DEBUG: 1556: DoProcessDump: Code modification detected, dumping Imagebase at 0x00D00000. 2026-04-14 14:05:57,765 [root] DEBUG: 1556: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2026-04-14 14:05:57,765 [root] DEBUG: 1556: DumpProcess: Instantiating PeParser with address: 0x00D00000. 2026-04-14 14:05:57,765 [root] DEBUG: 1556: DumpProcess: Module entry point VA is 0x000010D4. 2026-04-14 14:05:57,781 [lib.common.results] INFO: File C:\WzRRSPxxH\CAPE\1556_88502855752114242026 size is 1915904, Max size: 100000000 2026-04-14 14:05:57,812 [root] DEBUG: 1556: DumpProcess: Module image dump success - dump size 0x1d3c00. 2026-04-14 14:05:57,843 [root] INFO: Process with pid 1556 has terminated 2026-04-14 14:05:58,703 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:05:58,921 [lib.common.results] INFO: File 1776200758875000000.HardwareEvents.evtx.gz size is 251, Max size: 100000000 2026-04-14 14:05:58,921 [lib.common.results] INFO: File 1776200758875000000.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2026-04-14 14:05:58,937 [lib.common.results] INFO: File 1776200758859375000.Application.evtx.gz size is 6891, Max size: 100000000 2026-04-14 14:05:58,984 [lib.common.results] INFO: File 1776200758921875000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 14:05:58,984 [lib.common.results] INFO: File 1776200758921875000.KeyManagementService.evtx.gz size is 3253, Max size: 100000000 2026-04-14 14:05:58,984 [lib.common.results] INFO: File 1776200758937500000.Setup.evtx.gz size is 242, Max size: 100000000 2026-04-14 14:05:59,000 [lib.common.results] INFO: File 1776200758921875000.Security.evtx.gz size is 7291, Max size: 100000000 2026-04-14 14:05:59,031 [lib.common.results] INFO: File 1776200758984375000.WindowsPowerShell.evtx.gz size is 5412, Max size: 100000000 2026-04-14 14:05:59,046 [lib.common.results] INFO: File 1776200758968750000.System.evtx.gz size is 8576, Max size: 100000000 2026-04-14 14:05:59,359 [modules.auxiliary.sysmon] INFO: Dumping sysmon logs 2026-04-14 14:06:04,437 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200764.4375.sysmon.evtx.gz to host 2026-04-14 14:06:04,437 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 14896, Max size: 100000000 2026-04-14 14:06:04,796 [root] INFO: Process list is empty, terminating analysis 2026-04-14 14:06:05,812 [root] INFO: Created shutdown mutex 2026-04-14 14:06:06,812 [root] INFO: Shutting down package 2026-04-14 14:06:06,812 [root] INFO: Stopping auxiliary modules 2026-04-14 14:06:06,812 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [WinError 6] The handle is invalid 2026-04-14 14:06:06,812 [lib.common.results] INFO: File C:\curtain.log size is 0, Max size: 100000000 2026-04-14 14:06:06,828 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:06:07,078 [lib.common.results] INFO: File 1776200767015625000.HardwareEvents.evtx.gz size is 251, Max size: 100000000 2026-04-14 14:06:07,093 [lib.common.results] INFO: File 1776200767000000000.Application.evtx.gz size is 6891, Max size: 100000000 2026-04-14 14:06:07,109 [lib.common.results] INFO: File 1776200767062500000.KeyManagementService.evtx.gz size is 3253, Max size: 100000000 2026-04-14 14:06:07,125 [lib.common.results] INFO: File 1776200767062500000.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2026-04-14 14:06:07,140 [lib.common.results] INFO: File 1776200767062500000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 14:06:07,140 [lib.common.results] INFO: File 1776200767093750000.Security.evtx.gz size is 7489, Max size: 100000000 2026-04-14 14:06:07,156 [lib.common.results] INFO: File 1776200767109375000.Setup.evtx.gz size is 242, Max size: 100000000 2026-04-14 14:06:07,187 [lib.common.results] INFO: File 1776200767109375000.System.evtx.gz size is 8602, Max size: 100000000 2026-04-14 14:06:07,187 [lib.common.results] INFO: File 1776200767140625000.WindowsPowerShell.evtx.gz size is 5412, Max size: 100000000 2026-04-14 14:06:10,296 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 14:06:12,281 [modules.auxiliary.fiddler] ERROR: Saz log file not found in guest machine 2026-04-14 14:06:12,281 [modules.auxiliary.sysmon] INFO: Doing final sysmon log dump 2026-04-14 14:06:14,093 [modules.auxiliary.evtx] INFO: Collecting logs: Application, HardwareEvents, Internet Explorer, Key Management Service, OAlerts, Security, Setup, System, Windows PowerShell 2026-04-14 14:06:14,328 [lib.common.results] INFO: File 1776200774281250000.HardwareEvents.evtx.gz size is 251, Max size: 100000000 2026-04-14 14:06:14,343 [lib.common.results] INFO: File 1776200774281250000.Application.evtx.gz size is 6891, Max size: 100000000 2026-04-14 14:06:14,375 [lib.common.results] INFO: File 1776200774312500000.InternetExplorer.evtx.gz size is 249, Max size: 100000000 2026-04-14 14:06:14,390 [lib.common.results] INFO: File 1776200774312500000.KeyManagementService.evtx.gz size is 3253, Max size: 100000000 2026-04-14 14:06:14,406 [lib.common.results] INFO: File 1776200774328125000.OAlerts.evtx.gz size is 244, Max size: 100000000 2026-04-14 14:06:14,421 [lib.common.results] INFO: File 1776200774343750000.Security.evtx.gz size is 7525, Max size: 100000000 2026-04-14 14:06:14,421 [lib.common.results] INFO: File 1776200774375000000.Setup.evtx.gz size is 242, Max size: 100000000 2026-04-14 14:06:14,437 [lib.common.results] INFO: File 1776200774375000000.System.evtx.gz size is 8600, Max size: 100000000 2026-04-14 14:06:14,453 [lib.common.results] INFO: File 1776200774406250000.WindowsPowerShell.evtx.gz size is 5412, Max size: 100000000 2026-04-14 14:06:17,343 [modules.auxiliary.sysmon] INFO: Uploading sysmon/1776200777.34375.sysmon.evtx.gz to host 2026-04-14 14:06:17,343 [lib.common.results] INFO: File C:\Sysmon.evtx.gz size is 5998, Max size: 100000000 2026-04-14 14:06:17,359 [root] INFO: Finishing auxiliary modules 2026-04-14 14:06:17,359 [root] INFO: Shutting down pipe server and dumping dropped files 2026-04-14 14:06:17,359 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Roaming\Microsoft\Templates\Normal.dotm size is 17789, Max size: 100000000 2026-04-14 14:06:17,359 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Temp\1234_as_password_ha.docx size is 103867, Max size: 100000000 2026-04-14 14:06:17,375 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\~$34_as_password_ha.docx does not exist, skipping 2026-04-14 14:06:17,375 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC size is 22, Max size: 100000000 2026-04-14 14:06:17,375 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Local\Microsoft\Office\15.0\WebServiceCache\AllUsers\office15client.microsoft.com\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10 size is 23349, Max size: 100000000 2026-04-14 14:06:17,390 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex size is 2, Max size: 100000000 2026-04-14 14:06:17,390 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab7d6a.tmp does not exist, skipping 2026-04-14 14:06:17,390 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab7e48.tmp does not exist, skipping 2026-04-14 14:06:17,390 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab7ee5.tmp does not exist, skipping 2026-04-14 14:06:17,390 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab7f05.tmp does not exist, skipping 2026-04-14 14:06:17,390 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab7f83.tmp does not exist, skipping 2026-04-14 14:06:17,390 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab7fe2.tmp does not exist, skipping 2026-04-14 14:06:17,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD size is 767, Max size: 100000000 2026-04-14 14:06:17,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD size is 244, Max size: 100000000 2026-04-14 14:06:17,406 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab8041.tmp does not exist, skipping 2026-04-14 14:06:17,406 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab80de.tmp does not exist, skipping 2026-04-14 14:06:17,406 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F90F18257CBB4D84216AC1E1F3BB2C76 size is 519, Max size: 100000000 2026-04-14 14:06:17,421 [lib.common.results] INFO: File C:\Users\pgabriel\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F90F18257CBB4D84216AC1E1F3BB2C76 size is 252, Max size: 100000000 2026-04-14 14:06:17,421 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab814c.tmp does not exist, skipping 2026-04-14 14:06:17,421 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab81ab.tmp does not exist, skipping 2026-04-14 14:06:17,421 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab8298.tmp does not exist, skipping 2026-04-14 14:06:17,421 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\cab830a.tmp does not exist, skipping 2026-04-14 14:06:17,421 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\tcd821a.tmp\content.inf does not exist, skipping 2026-04-14 14:06:17,421 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\tcd82aa.tmp\content.inf does not exist, skipping 2026-04-14 14:06:17,421 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\tcd82a9.tmp\content.inf does not exist, skipping 2026-04-14 14:06:17,421 [lib.common.results] INFO: File c:\users\pgabriel\appdata\roaming\microsoft\templates\livecontent\15\managed\document themes\1033\tm03090430[[fn=banded]].thmx size is 562113, Max size: 100000000 2026-04-14 14:06:17,453 [lib.common.results] INFO: File c:\users\pgabriel\appdata\roaming\microsoft\templates\livecontent\15\managed\document themes\1033\tm03457464[[fn=dividend]].thmx size is 570901, Max size: 100000000 2026-04-14 14:06:17,468 [lib.common.results] INFO: File c:\users\pgabriel\appdata\roaming\microsoft\templates\livecontent\15\managed\document themes\1033\tm03457475[[fn=frame]].thmx size is 523048, Max size: 100000000 2026-04-14 14:06:17,468 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\tcd82aa.tmp\metropolitan.thmx does not exist, skipping 2026-04-14 14:06:17,484 [lib.common.results] INFO: File c:\users\pgabriel\appdata\roaming\microsoft\templates\livecontent\15\managed\document themes\1033\tm03457444[[fn=basis]].thmx size is 558035, Max size: 100000000 2026-04-14 14:06:17,500 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\tcd830b.tmp\content.inf does not exist, skipping 2026-04-14 14:06:17,500 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\tcd831b.tmp\parallax.thmx does not exist, skipping 2026-04-14 14:06:17,500 [root] WARNING: File at path c:\users\pgabriel\appdata\local\temp\tcd830b.tmp\view.thmx does not exist, skipping 2026-04-14 14:06:17,500 [root] WARNING: Folder at path "C:\WzRRSPxxH\debugger" does not exist, skipping 2026-04-14 14:06:17,500 [root] INFO: Uploading files at path "C:\WzRRSPxxH\tlsdump" 2026-04-14 14:06:17,500 [lib.common.results] INFO: File C:\WzRRSPxxH\tlsdump\tlsdump.log size is 20550, Max size: 100000000 2026-04-14 14:06:17,515 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win7office2k3flash2800137TWN3H101 | win7office2k3flash2800137TWN3H101 | KVM | 2026-04-14 20:04:26 | 2026-04-14 20:06:27 | internet |
| File Name | 1234_as_password_ha.docx |
|---|---|
| File Size | 103867 bytes |
| File Type | Microsoft Word 2007+ |
| MD5 | 572312c9ea3f6515036ba67dbf94612e |
| SHA1 | 39de356d1245c84d34380e801e271557dc8f6844 |
| SHA256 | c4bcd28cc650de8bd7546643786316f8a36aa6086c046094a24867e606d2e28e |
| SHA512 | adeb1c901a67a83a1c31efca5b6dc73406bd85e69330395670829f6d05e4dfaf732959f05425a577d81c0fb798009a5a13133c47bcf1aaed29f5d6d3d3508f52 |
| SHA3-384 | b09e1caaadb85d3c8c57bfc7ee82998dedeae9e36f4ebda2b68a55e6c51a969e8e2c93d02ef75e2044a8f6384a1b3cf9 |
| CRC32 | 5086EBBD |
| TLSH | T153A3126FDAF5CA7AFE051C79F85B8162F0066405430E26B114018D6ACB42BA42FF36FE |
| Ssdeep | 3072:pnnEtyfyKvDdpmn1Xi8BRaVpeT3wQRT3IB3:hEty6KvDe1XnRag3VRT3IJ |
File
|
|
| Direct | IP | Country Name |
|---|---|---|
| N | 2.19.252.136 [VT] | Europe |
| N | 23.1.228.180 [VT] | United States |
| Y | 8.8.8.8 [VT] | United States |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| roaming.svc.cloud.microsoft [VT] |
CNAME eur.roaming1.live.com.akadns.net
[VT]
A 52.110.10.34 [VT] A 52.110.10.50 [VT] A 52.110.10.22 [VT] A 52.110.10.74 [VT] CNAME roaming-prod-weightedww.trafficmanager.net [VT] CNAME atm.office.mira.tm.svc.cloud.microsoft [VT] CNAME prod.roaming1.live.com.akadns.net [VT] |
52.110.10.37 [VT] |
| metadata.templates.cdn.office.net [VT] |
CNAME templatesmetadata.office.net.edgekey.net
[VT]
A 23.1.228.141 [VT] CNAME templatesmetadata.office.net [VT] CNAME e26769.dscb.akamaiedge.net [VT] A 23.1.228.180 [VT] |
92.123.236.82 [VT] |
| binaries.templates.cdn.office.net [VT] |
CNAME a1847.dscg2.akamai.net
[VT]
A 2.19.252.143 [VT] A 2.19.252.136 [VT] CNAME binaries.templates.cdn.office.net.edgesuite.net [VT] |
96.17.206.216 [VT] |
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP