| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| FILE | doc | 2026-06-30 15:56:13 | 2026-06-30 15:57:15 | 62s |
|
|||||
| Reports | JSON | |||||||||
vnc_port=5900
2026-06-30 06:08:42,660 [root] INFO: Date set to: 20260630T15:56:17, timeout set to: 30
2026-06-30 15:56:17,064 [root] DEBUG: Starting analyzer from: C:\n5g3jpk_
2026-06-30 15:56:17,073 [root] DEBUG: Storing results at: C:\fYGInlZoy
2026-06-30 15:56:17,074 [root] DEBUG: Pipe server name: \\.\PIPE\CQrFeDF
2026-06-30 15:56:17,074 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314
2026-06-30 15:56:17,075 [root] INFO: analysis running as an admin
2026-06-30 15:56:17,075 [root] INFO: analysis package specified: "doc"
2026-06-30 15:56:17,075 [root] DEBUG: importing analysis package module: "modules.packages.doc"...
2026-06-30 15:56:17,097 [root] DEBUG: imported analysis package "doc"
2026-06-30 15:56:17,098 [root] DEBUG: initializing analysis package "doc"...
2026-06-30 15:56:17,099 [lib.common.common] INFO: no wrapping
2026-06-30 15:56:17,106 [lib.core.compound] INFO: C:\Program Files\Microsoft Office\root\Templates created
2026-06-30 15:56:17,111 [root] DEBUG: New location of moved file: C:\Program Files\Microsoft Office\root\Templates\BreakingBadNewsThatIs.docx
2026-06-30 15:56:17,112 [root] INFO: Analyzer: Package modules.packages.doc does not specify a dll option
2026-06-30 15:56:17,113 [root] INFO: Analyzer: Package modules.packages.doc does not specify a dll_64 option
2026-06-30 15:56:17,113 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader option
2026-06-30 15:56:17,113 [root] INFO: Analyzer: Package modules.packages.doc does not specify a loader_64 option
2026-06-30 15:56:17,222 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-06-30 15:56:17,323 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-06-30 15:56:17,498 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-06-30 15:56:18,735 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-06-30 15:56:18,800 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-06-30 15:56:18,804 [root] DEBUG: Initialized auxiliary module "Browser"
2026-06-30 15:56:18,806 [root] DEBUG: attempting to configure 'Browser' from data
2026-06-30 15:56:18,817 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-06-30 15:56:18,819 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-06-30 15:56:19,040 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-06-30 15:56:19,041 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-06-30 15:56:19,042 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-06-30 15:56:19,042 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-06-30 15:56:19,043 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-06-30 15:56:19,043 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-06-30 15:56:19,627 [modules.auxiliary.digisig] DEBUG: File has an invalid signature
2026-06-30 15:56:19,628 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-06-30 15:56:19,634 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-06-30 15:56:19,635 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-06-30 15:56:19,635 [root] DEBUG: attempting to configure 'Disguise' from data
2026-06-30 15:56:19,636 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-06-30 15:56:19,636 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-06-30 15:56:19,670 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 3996)
2026-06-30 15:56:19,698 [modules.auxiliary.disguise] INFO: Disguising GUID to 072ee77d-f8af-40fb-9420-c750df99aba8
2026-06-30 15:56:19,699 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-06-30 15:56:19,701 [root] DEBUG: Initialized auxiliary module "Human"
2026-06-30 15:56:19,702 [root] DEBUG: attempting to configure 'Human' from data
2026-06-30 15:56:19,703 [root] DEBUG: module Human does not support data configuration, ignoring
2026-06-30 15:56:19,706 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-06-30 15:56:19,708 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-06-30 15:56:19,709 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-06-30 15:56:19,710 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-06-30 15:56:19,710 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-06-30 15:56:19,710 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-06-30 15:56:19,712 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-06-30 15:56:19,713 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-06-30 15:56:26,674 [root] INFO: Restarting WMI Service
2026-06-30 15:56:28,883 [root] DEBUG: package modules.packages.doc does not support configure, ignoring
2026-06-30 15:56:28,884 [root] WARNING: configuration error for package modules.packages.doc: error importing data.packages.doc: No module named 'data.packages'
2026-06-30 15:56:28,886 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-30 15:56:28,903 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" with arguments ""C:\Program Files\Microsoft Office\root\Templates\BreakingBadNewsThatIs.docx" /q" with pid 1932
2026-06-30 15:56:29,230 [lib.api.process] INFO: Monitor config for process 1932: C:\n5g3jpk_\dll\1932.ini
2026-06-30 15:56:30,905 [lib.api.process] INFO: Potential dll side-loading detected in local directory: dbghelp.dll
2026-06-30 15:56:31,085 [lib.api.process] INFO: 64-bit DLL to inject is C:\n5g3jpk_\dll\lrmtLFC.dll, loader C:\n5g3jpk_\bin\mfLocqkM.exe
2026-06-30 15:56:31,104 [root] DEBUG: Loader: Injecting process 1932 (thread 540) with C:\n5g3jpk_\dll\lrmtLFC.dll.
2026-06-30 15:56:31,105 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-30 15:56:31,106 [root] DEBUG: Successfully injected DLL C:\n5g3jpk_\dll\lrmtLFC.dll.
2026-06-30 15:56:31,110 [lib.api.process] INFO: Injected into 64-bit <Process 1932 WINWORD.EXE>
2026-06-30 15:56:33,111 [lib.api.process] INFO: Successfully resumed process with pid 1932
2026-06-30 15:56:33,415 [root] DEBUG: 1932: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-30 15:56:33,417 [root] DEBUG: 1932: Disabling sleep skipping.
2026-06-30 15:56:33,419 [root] DEBUG: 1932: Dropped file limit defaulting to 100.
2026-06-30 15:56:33,421 [root] DEBUG: 1932: Microsoft Office settings enabled.
2026-06-30 15:56:33,495 [root] DEBUG: 1932: RtlInsertInvertedFunctionTable 0x00007FF82D5E090E, LdrpInvertedFunctionTableSRWLock 0x00007FF82D73B4F0
2026-06-30 15:56:33,496 [root] DEBUG: 1932: Monitor initialised: 64-bit capemon loaded in process 1932 at 0x00007FF801740000, thread 540, image base 0x00007FF6F37C0000, stack from 0x000000ED69911000-0x000000ED69920000
2026-06-30 15:56:33,497 [root] DEBUG: 1932: Commandline: "C:\Program Files\Microsoft Office\Office16\WINWORD.EXE" "C:\Program Files\Microsoft Office\root\Templates\BreakingBadNewsThatIs.docx" /q
2026-06-30 15:56:33,548 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-30 15:56:33,550 [root] DEBUG: 1932: set_hooks: Unable to hook LockResource
2026-06-30 15:56:33,569 [root] DEBUG: 1932: Hooked 428 out of 429 functions
2026-06-30 15:56:33,650 [root] DEBUG: 1932: Syscall hook installed, syscall logging level 1
2026-06-30 15:56:33,654 [root] DEBUG: 1932: RestoreHeaders: Restored original import table.
2026-06-30 15:56:33,655 [root] INFO: Loaded monitor into process with pid 1932
2026-06-30 15:56:33,758 [root] DEBUG: 1932: DLL loaded at 0x00007FF8295E0000: C:\Windows\SYSTEM32\dxgi (0xf4000 bytes).
2026-06-30 15:56:33,759 [root] DEBUG: 1932: DLL loaded at 0x00007FF827210000: C:\Windows\SYSTEM32\d3d11 (0x264000 bytes).
2026-06-30 15:56:33,761 [root] DEBUG: 1932: DLL loaded at 0x00007FF80DC10000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1288_none_91a663c8cc864906\gdiplus (0x1a9000 bytes).
2026-06-30 15:56:33,762 [root] DEBUG: 1932: DLL loaded at 0x00007FF813C40000: C:\Windows\SYSTEM32\VCRUNTIME140_1 (0xc000 bytes).
2026-06-30 15:56:33,768 [root] DEBUG: 1932: DLL loaded at 0x00007FF813C50000: C:\Windows\SYSTEM32\MSVCP140 (0x9d000 bytes).
2026-06-30 15:56:33,769 [root] DEBUG: 1932: DLL loaded at 0x00007FFFFEE80000: C:\Program Files\Microsoft Office\Office16\oart (0x116c000 bytes).
2026-06-30 15:56:33,771 [root] DEBUG: 1932: DLL loaded at 0x00007FFFFBB00000: C:\Program Files\Microsoft Office\Office16\wwlib (0x239f000 bytes).
2026-06-30 15:56:33,796 [root] DEBUG: 1932: DLL loaded at 0x00007FF800850000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso20win32client (0x304000 bytes).
2026-06-30 15:56:33,811 [root] DEBUG: 1932: DLL loaded at 0x00007FFFFEA00000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client (0x478000 bytes).
2026-06-30 15:56:33,818 [root] DEBUG: 1932: DLL loaded at 0x00007FFFFB210000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso40uiwin32client (0x8eb000 bytes).
2026-06-30 15:56:33,827 [root] DEBUG: 1932: DLL loaded at 0x00007FF81C4B0000: C:\Windows\SYSTEM32\MSIMG32 (0x7000 bytes).
2026-06-30 15:56:33,828 [root] DEBUG: 1932: DLL loaded at 0x00007FF829840000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-06-30 15:56:33,831 [root] DEBUG: 1932: DLL loaded at 0x00007FF829870000: C:\Windows\SYSTEM32\SLC (0x29000 bytes).
2026-06-30 15:56:33,832 [root] DEBUG: 1932: DLL loaded at 0x00007FFFFAA40000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso99Lwin32client (0x7cc000 bytes).
2026-06-30 15:56:33,847 [root] DEBUG: 1932: DLL loaded at 0x00007FFFF9760000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso (0x12dc000 bytes).
2026-06-30 15:56:33,888 [root] DEBUG: 1932: DLL loaded at 0x00007FF813910000: C:\Windows\SYSTEM32\msi (0x32d000 bytes).
2026-06-30 15:56:33,899 [root] DEBUG: 1932: DLL loaded at 0x00007FF816530000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\Comctl32 (0x29a000 bytes).
2026-06-30 15:56:33,917 [root] DEBUG: 1932: DLL loaded at 0x00007FF828C10000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-30 15:56:33,918 [root] DEBUG: 1932: DLL loaded at 0x00007FF80E1C0000: C:\Windows\SYSTEM32\srpapi (0x2c000 bytes).
2026-06-30 15:56:34,055 [root] DEBUG: 1932: DLL loaded at 0x00007FF827680000: C:\Windows\SYSTEM32\d2d1 (0x5c0000 bytes).
2026-06-30 15:56:34,063 [root] DEBUG: 1932: DLL loaded at 0x00007FF828730000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-30 15:56:34,069 [root] DEBUG: 1932: DLL loaded at 0x00007FF82B620000: C:\Windows\System32\MSCTF (0x115000 bytes).
2026-06-30 15:56:34,073 [root] DEBUG: 1932: DLL loaded at 0x00007FF826110000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-06-30 15:56:34,082 [root] DEBUG: 1932: DLL loaded at 0x00007FF82AA30000: C:\Windows\SYSTEM32\WINSTA (0x5a000 bytes).
2026-06-30 15:56:34,096 [root] DEBUG: 1932: DLL loaded at 0x00007FF828810000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-06-30 15:56:34,134 [root] DEBUG: 1932: DLL loaded at 0x00007FF82B380000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-30 15:56:34,148 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Local\Temp\{39163DD4-19E1-47F3-A5C7-57740568BB04} - OProcSessId.dat
2026-06-30 15:56:34,806 [root] DEBUG: 1932: DLL loaded at 0x00007FF804480000: C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSPTLS (0x170000 bytes).
2026-06-30 15:56:34,819 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A670000: C:\Windows\SYSTEM32\Wldp (0x2c000 bytes).
2026-06-30 15:56:34,821 [root] DEBUG: 1932: DLL loaded at 0x00007FF828E10000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes).
2026-06-30 15:56:34,829 [root] DEBUG: 1932: DLL loaded at 0x00007FF82C9E0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-06-30 15:56:34,837 [root] DEBUG: 1932: DLL loaded at 0x00007FF82AC30000: C:\Windows\SYSTEM32\profapi (0x1f000 bytes).
2026-06-30 15:56:34,880 [root] DEBUG: 1932: DLL loaded at 0x00007FF8247A0000: C:\Windows\SYSTEM32\d3d10_1core (0xd000 bytes).
2026-06-30 15:56:34,881 [root] DEBUG: 1932: DLL loaded at 0x00007FF820E70000: C:\Windows\SYSTEM32\d3d10_1 (0x31000 bytes).
2026-06-30 15:56:34,888 [root] DEBUG: 1932: DLL loaded at 0x00007FF81DF00000: C:\Windows\SYSTEM32\D3D10Warp (0x6f6000 bytes).
2026-06-30 15:56:34,917 [root] DEBUG: 1932: DLL loaded at 0x00007FF82AE40000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-06-30 15:56:34,919 [root] DEBUG: 1932: DLL loaded at 0x00007FF81DA80000: C:\Windows\SYSTEM32\dxcore (0x3b000 bytes).
2026-06-30 15:56:34,936 [root] DEBUG: 1932: DLL loaded at 0x00007FF81DC70000: C:\Windows\SYSTEM32\DWrite (0x283000 bytes).
2026-06-30 15:56:37,322 [root] DEBUG: 1932: DLL loaded at 0x00007FF81FAD0000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-06-30 15:56:37,388 [root] DEBUG: 1932: DLL loaded at 0x00007FF820E00000: C:\Windows\SYSTEM32\netapi32 (0x18000 bytes).
2026-06-30 15:56:37,392 [root] DEBUG: 1932: DLL loaded at 0x00007FF829DE0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-06-30 15:56:37,393 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A5C0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-06-30 15:56:37,394 [root] DEBUG: 1932: DLL loaded at 0x00007FF824020000: C:\Windows\SYSTEM32\DSREG (0x13f000 bytes).
2026-06-30 15:56:37,397 [root] DEBUG: 1932: DLL loaded at 0x00007FF803E30000: C:\Windows\SYSTEM32\mscoree (0x65000 bytes).
2026-06-30 15:56:37,406 [root] DEBUG: 1932: DLL loaded at 0x00007FF803D80000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei (0xaa000 bytes).
2026-06-30 15:56:37,422 [root] DEBUG: 1932: DLL loaded at 0x00007FF819A50000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-06-30 15:56:37,428 [root] DEBUG: 1932: DLL loaded at 0x00007FF802230000: C:\Program Files\Common Files\Microsoft Shared\Office16\riched20 (0x223000 bytes).
2026-06-30 15:56:37,453 [root] DEBUG: 1932: DLL loaded at 0x00007FF82C2A0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-30 15:56:37,462 [root] DEBUG: 1932: DLL loaded at 0x00007FF8264B0000: C:\Windows\System32\netprofm (0x3e000 bytes).
2026-06-30 15:56:37,496 [root] DEBUG: 1932: DLL loaded at 0x00007FF824160000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-06-30 15:56:37,516 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A0C0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-06-30 15:56:37,520 [root] DEBUG: 1932: DLL loaded at 0x00007FF82D580000: C:\Windows\System32\NSI (0x8000 bytes).
2026-06-30 15:56:37,598 [root] DEBUG: 1932: DLL loaded at 0x00007FF828B00000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-06-30 15:56:37,619 [root] DEBUG: 1932: DLL loaded at 0x00007FF819F70000: C:\Windows\SYSTEM32\WINSPOOL.DRV (0x95000 bytes).
2026-06-30 15:56:37,631 [root] DEBUG: 1932: DLL loaded at 0x00007FF825EC0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-06-30 15:56:37,635 [root] DEBUG: 1932: DLL loaded at 0x00007FF825EA0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-06-30 15:56:37,639 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A100000: C:\Windows\SYSTEM32\DNSAPI (0xcc000 bytes).
2026-06-30 15:56:37,689 [root] DEBUG: 1932: DLL loaded at 0x00007FF82AA90000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-06-30 15:56:37,710 [root] DEBUG: 1932: DLL loaded at 0x00007FF82D3D0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-06-30 15:56:37,868 [root] DEBUG: 1932: DLL loaded at 0x00007FF82BFA0000: C:\Windows\System32\Normaliz (0x8000 bytes).
2026-06-30 15:56:37,875 [root] DEBUG: 1932: DLL loaded at 0x00007FF824E40000: C:\Windows\SYSTEM32\WINHTTP (0x108000 bytes).
2026-06-30 15:56:37,891 [root] DEBUG: 1932: DLL loaded at 0x00007FF80E090000: C:\Windows\system32\OnDemandConnRouteHelper (0x17000 bytes).
2026-06-30 15:56:37,905 [root] DEBUG: 1932: DLL loaded at 0x00007FF82AA20000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-06-30 15:56:37,909 [root] DEBUG: 1932: DLL loaded at 0x00007FF8229B0000: C:\Windows\SYSTEM32\iertutil (0x2b0000 bytes).
2026-06-30 15:56:37,910 [root] DEBUG: 1932: DLL loaded at 0x00007FF823A50000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-06-30 15:56:37,911 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A1D0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-06-30 15:56:37,918 [root] DEBUG: 1932: DLL loaded at 0x00007FF822C60000: C:\Windows\SYSTEM32\urlmon (0x1eb000 bytes).
2026-06-30 15:56:37,995 [root] DEBUG: 1932: DLL loaded at 0x00007FF81CD70000: C:\Windows\SYSTEM32\WININET (0x4d0000 bytes).
2026-06-30 15:56:38,036 [root] DEBUG: 1932: DLL loaded at 0x00007FF80E090000: C:\Windows\SYSTEM32\ondemandconnroutehelper (0x17000 bytes).
2026-06-30 15:56:38,053 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A3D0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-06-30 15:56:38,062 [root] DEBUG: 1932: DLL loaded at 0x00007FF823AD0000: C:\Windows\SYSTEM32\webio (0x99000 bytes).
2026-06-30 15:56:38,068 [root] DEBUG: 1932: DLL loaded at 0x00007FF825EE0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-06-30 15:56:38,097 [root] DEBUG: 1932: DLL loaded at 0x00007FF824980000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-06-30 15:56:38,200 [root] DEBUG: 1932: DLL loaded at 0x00007FF825300000: C:\Windows\System32\fwpuclnt (0x7f000 bytes).
2026-06-30 15:56:38,236 [root] DEBUG: 1932: DLL loaded at 0x00007FF829C70000: C:\Windows\system32\schannel (0x91000 bytes).
2026-06-30 15:56:38,254 [root] DEBUG: 1932: DLL loaded at 0x00007FF812F60000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-06-30 15:56:38,257 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A6A0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-06-30 15:56:38,267 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A800000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-06-30 15:56:38,294 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A6E0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-06-30 15:56:38,299 [root] DEBUG: 1932: DLL loaded at 0x00007FF812FB0000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-06-30 15:56:38,371 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\790FA9B6-8072-4BBC-B3D3-2D041488FD6B
2026-06-30 15:56:38,377 [root] DEBUG: 1932: DLL loaded at 0x00007FF820920000: C:\Windows\SYSTEM32\webservices (0x153000 bytes).
2026-06-30 15:56:38,712 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Local\Microsoft\Office\16.0\winword.exe_Rules.xml
2026-06-30 15:56:38,753 [root] DEBUG: 1932: DLL loaded at 0x00007FF825410000: C:\Windows\SYSTEM32\XmlLite (0x36000 bytes).
2026-06-30 15:56:39,010 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Office\16.0\winword.exe_Rules.xml to files\c88a0b907419a70c27ab7c1f8e5fb54441a4d9c3567e4c928fa7b2091194aecf; Size is 7; Max size: 100000000
2026-06-30 15:56:39,105 [root] DEBUG: 1932: api-rate-cap: ReadProcessMemory hook disabled due to rate
2026-06-30 15:56:39,212 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\00629556-76D9-4812-80A7-AF694A154468 to files\6c10ae4557c831e59c61c0df7fed2ef3f38968ed6669c60179ac1df185152cee; Size is 193445; Max size: 100000000
2026-06-30 15:56:39,224 [root] DEBUG: 1932: api-rate-cap: NtReadVirtualMemory hook disabled due to rate
2026-06-30 15:56:39,240 [root] DEBUG: 1932: DLL loaded at 0x00007FF82A5C0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-06-30 15:56:39,243 [root] DEBUG: 1932: DLL loaded at 0x00007FF829D50000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-06-30 15:56:39,247 [root] DEBUG: 1932: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-06-30 15:56:39,702 [root] DEBUG: 1932: api-cap: NtQueryKey hook disabled due to count: 5000
2026-06-30 15:56:39,991 [root] DEBUG: 1932: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-06-30 15:56:40,383 [root] DEBUG: 1932: api-cap: RegCloseKey hook disabled due to count: 5000
2026-06-30 15:56:40,484 [root] DEBUG: 1932: api-cap: RegEnumKeyExW hook disabled due to count: 5000
2026-06-30 15:56:41,370 [root] DEBUG: 1932: api-cap: NtClose hook disabled due to count: 5000
2026-06-30 15:56:41,380 [root] DEBUG: 1932: api-cap: NtEnumerateKey hook disabled due to count: 5000
2026-06-30 15:56:42,338 [root] DEBUG: 1932: DLL loaded at 0x00007FF82AB60000: C:\Windows\SYSTEM32\POWRPROF (0x4b000 bytes).
2026-06-30 15:56:42,342 [root] DEBUG: 1932: DLL loaded at 0x00007FF82AB40000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-06-30 15:56:42,405 [root] DEBUG: 1932: DLL loaded at 0x00007FF825200000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-06-30 15:56:42,494 [root] DEBUG: 1932: DLL loaded at 0x00007FF81C6A0000: C:\Windows\system32\mlang (0x42000 bytes).
2026-06-30 15:56:42,560 [root] DEBUG: 1932: DLL loaded at 0x00007FF81AD70000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-06-30 15:56:42,614 [root] DEBUG: 1932: DLL loaded at 0x00007FF823BB0000: C:\Windows\System32\twinapi.appcore (0x201000 bytes).
2026-06-30 15:56:42,625 [root] DEBUG: 1932: DLL loaded at 0x00007FF816A40000: C:\Windows\system32\twinapi (0xa8000 bytes).
2026-06-30 15:56:42,706 [root] DEBUG: 1932: DLL loaded at 0x00007FFFF8C60000: C:\Program Files\Microsoft Office\Office16\chart (0xaf9000 bytes).
2026-06-30 15:56:42,780 [root] DEBUG: 1932: DLL loaded at 0x00007FF81BA20000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2026-06-30 15:56:42,861 [root] DEBUG: 1932: DLL loaded at 0x00007FF81BAD0000: C:\Windows\SYSTEM32\Cabinet (0x29000 bytes).
2026-06-30 15:56:42,903 [root] DEBUG: 1932: DLL loaded at 0x00007FF8299E0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-06-30 15:56:42,905 [root] DEBUG: 1932: DLL loaded at 0x00007FF828350000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-06-30 15:56:42,906 [root] DEBUG: 1932: DLL loaded at 0x00007FF826C50000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes).
2026-06-30 15:56:42,909 [root] DEBUG: 1932: DLL loaded at 0x00007FF827FF0000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes).
2026-06-30 15:56:42,910 [root] DEBUG: 1932: DLL loaded at 0x00007FF81FDF0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-06-30 15:56:43,381 [root] DEBUG: 1932: DLL loaded at 0x00007FF824780000: C:\Windows\SYSTEM32\usp10 (0x19000 bytes).
2026-06-30 15:56:43,446 [root] DEBUG: 1932: DLL loaded at 0x00007FF811D10000: C:\Windows\SYSTEM32\UIAutomationCore (0x2f5000 bytes).
2026-06-30 15:56:43,475 [root] DEBUG: 1932: DLL loaded at 0x00007FF827490000: C:\Windows\system32\dcomp (0x1e5000 bytes).
2026-06-30 15:56:43,476 [root] DEBUG: 1932: DLL loaded at 0x00007FF8153A0000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-06-30 15:56:43,758 [root] DEBUG: 1932: DLL loaded at 0x00007FF8154E0000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-06-30 15:56:43,766 [root] DEBUG: 1932: DLL loaded at 0x00007FF814230000: C:\Windows\SYSTEM32\ntshrui (0x7d000 bytes).
2026-06-30 15:56:43,775 [root] DEBUG: 1932: DLL loaded at 0x00007FF8167D0000: C:\Windows\SYSTEM32\cscapi (0x12000 bytes).
2026-06-30 15:56:43,832 [root] DEBUG: 1932: DLL loaded at 0x00007FF8150E0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-06-30 15:56:43,958 [root] INFO: Announced 64-bit process name: explorer.exe pid: 2604
2026-06-30 15:56:43,960 [lib.api.process] INFO: Monitor config for process 2604: C:\n5g3jpk_\dll\2604.ini
2026-06-30 15:56:43,971 [lib.api.process] INFO: 64-bit DLL to inject is C:\n5g3jpk_\dll\lrmtLFC.dll, loader C:\n5g3jpk_\bin\mfLocqkM.exe
2026-06-30 15:56:43,982 [root] DEBUG: Loader: Injecting process 2604 with C:\n5g3jpk_\dll\lrmtLFC.dll.
2026-06-30 15:56:43,988 [root] DEBUG: 2604: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-30 15:56:43,989 [root] DEBUG: 2604: Disabling sleep skipping.
2026-06-30 15:56:43,990 [root] DEBUG: 2604: Dropped file limit defaulting to 100.
2026-06-30 15:56:44,004 [root] DEBUG: 2604: YaraInit: Compiled 44 rule files
2026-06-30 15:56:44,007 [root] DEBUG: 2604: YaraInit: Compiled rules saved to file C:\n5g3jpk_\data\yara\capemon.yac
2026-06-30 15:56:44,028 [root] DEBUG: 2604: RtlInsertInvertedFunctionTable 0x00007FF82D5E090E, LdrpInvertedFunctionTableSRWLock 0x00007FF82D73B4F0
2026-06-30 15:56:44,030 [root] DEBUG: 2604: YaraScan: Scanning 0x00007FF684380000, size 0x49c0a4
2026-06-30 15:56:44,163 [root] DEBUG: 1932: DLL loaded at 0x00007FF820BF0000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes).
2026-06-30 15:56:44,165 [root] DEBUG: 1932: DLL loaded at 0x00007FF820B80000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-06-30 15:56:44,167 [root] DEBUG: 1932: DLL loaded at 0x00007FF81DAC0000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2026-06-30 15:56:44,179 [root] DEBUG: 1932: DLL loaded at 0x00007FF820740000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-06-30 15:56:44,198 [root] DEBUG: 2604: Monitor initialised: 64-bit capemon loaded in process 2604 at 0x00007FF801740000, thread 1992, image base 0x00007FF684380000, stack from 0x00000000085E1000-0x00000000085F0000
2026-06-30 15:56:44,202 [root] DEBUG: 2604: Commandline: C:\Windows\Explorer.EXE
2026-06-30 15:56:44,218 [root] DEBUG: 2604: hook_api: LdrpCallInitRoutine export address 0x00007FF82D5E99BC obtained via GetFunctionAddress
2026-06-30 15:56:44,280 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-30 15:56:44,282 [root] DEBUG: 2604: set_hooks: Unable to hook LockResource
2026-06-30 15:56:44,306 [root] DEBUG: 2604: Hooked 630 out of 631 functions
2026-06-30 15:56:44,355 [root] DEBUG: 2604: Syscall hook installed, syscall logging level 1
2026-06-30 15:56:44,372 [root] INFO: Loaded monitor into process with pid 2604
2026-06-30 15:56:44,378 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-30 15:56:44,379 [root] DEBUG: Successfully injected DLL C:\n5g3jpk_\dll\lrmtLFC.dll.
2026-06-30 15:56:44,383 [root] DEBUG: 2604: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-06-30 15:56:44,384 [lib.api.process] INFO: Injected into 64-bit <Process 2604 explorer.exe>
2026-06-30 15:56:44,422 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Roaming\Microsoft\Office\Recent\BreakingBadNewsThatIs.docx.LNK to files\6bd7191da98267fa0508815946ff12a92529fc7a0d4d7837b93fac3289a257d7; Size is 1353; Max size: 100000000
2026-06-30 15:56:44,493 [root] DEBUG: 2604: caller_dispatch: Added region at 0x00007FF684380000 to tracked regions list (user32::PostMessageW returns to 0x00007FF6843A5C18, thread 2752).
2026-06-30 15:56:44,497 [root] DEBUG: 2604: YaraScan: Scanning 0x00007FF684380000, size 0x49c0a4
2026-06-30 15:56:44,581 [root] DEBUG: 2604: ProcessImageBase: Main module image at 0x00007FF684380000 unmodified (entropy change 0.000000e+00)
2026-06-30 15:56:44,605 [root] DEBUG: 2604: OpenProcessHandler: Injection info created for process 1932, handle 0x178c: C:\Program Files\Microsoft Office\Office16\WINWORD.EXE
2026-06-30 15:56:45,535 [root] DEBUG: 1932: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-06-30 15:56:45,568 [root] DEBUG: 1932: api-cap: RegCloseKey hook disabled due to count: 5000
2026-06-30 15:56:45,932 [root] DEBUG: 1932: DLL loaded at 0x00007FF803D20000: C:\Program Files\Microsoft Office\Office16\msproof7 (0x54000 bytes).
2026-06-30 15:56:46,735 [root] DEBUG: 1932: api-cap: NtQueryPerformanceCounter hook disabled due to count: 5000
2026-06-30 15:56:48,086 [root] DEBUG: 1932: DLL loaded at 0x00007FF826DB0000: C:\Windows\SYSTEM32\d3dcompiler_47 (0x45d000 bytes).
2026-06-30 15:56:48,173 [root] DEBUG: 1932: DLL loaded at 0x00007FF81C7D0000: C:\Windows\SYSTEM32\PhotoMetadataHandler (0x81000 bytes).
2026-06-30 15:56:48,468 [root] DEBUG: 1932: DLL loaded at 0x00007FF802D80000: C:\Program Files\Microsoft Office\Office16\PROOF\msspell7 (0xcd000 bytes).
2026-06-30 15:56:48,536 [root] DEBUG: 1932: DLL loaded at 0x00007FF8038F0000: C:\Program Files\Microsoft Office\OFFICE16\mscss7en (0x96000 bytes).
2026-06-30 15:56:48,554 [root] DEBUG: 1932: DLL loaded at 0x00007FF8016B0000: C:\Program Files\Microsoft Office\OFFICE16\PROOF\1033\MSGR8EN (0x8d000 bytes).
2026-06-30 15:56:48,595 [root] DEBUG: 1932: DLL loaded at 0x00007FF801610000: C:\Program Files\Microsoft Office\OFFICE16\css7Data0009 (0x9a000 bytes).
2026-06-30 15:56:49,640 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-30 15:56:49,643 [root] DEBUG: 2604: OpenProcessHandler: Injection info created for process 3660, handle 0x49c: Error obtaining target process name
2026-06-30 15:56:49,644 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-30 15:56:49,645 [root] DEBUG: 2604: OpenProcessHandler: Injection info created for process 3424, handle 0x24d8: Error obtaining target process name
2026-06-30 15:56:49,647 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-30 15:56:49,648 [root] DEBUG: 2604: OpenProcessHandler: Injection info created for process 4124, handle 0x488: Error obtaining target process name
2026-06-30 15:56:57,957 [root] DEBUG: 2604: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-06-30 15:57:03,549 [root] INFO: Analysis timeout hit, terminating analysis
2026-06-30 15:57:03,550 [lib.api.process] INFO: Terminate event set for process 1932
2026-06-30 15:57:03,557 [root] DEBUG: 1932: Terminate Event: Attempting to dump process 1932
2026-06-30 15:57:03,558 [root] DEBUG: 1932: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-30 15:57:03,580 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex
2026-06-30 15:57:03,581 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
2026-06-30 15:57:03,583 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Roaming\Microsoft\Office\Recent\index.dat
2026-06-30 15:57:03,584 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Roaming\Microsoft\Office\Recent\BreakingBadNewsThatIs.docx.LNK
2026-06-30 15:57:03,585 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{E7728AC3-3259-47E8-BD54-A93A292C0C29}.tmp
2026-06-30 15:57:03,586 [root] INFO: Added new file to list with pid 1932 and path C:\Program Files\Microsoft Office\root\Templates\BreakingBadNewsThatIs.docx
2026-06-30 15:57:03,588 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Local\Microsoft\Office\Word16.customUI
2026-06-30 15:57:03,589 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{51A5872D-9D46-4CF3-99DE-38D108284A41}.tmp
2026-06-30 15:57:03,590 [root] INFO: Added new file to list with pid 1932 and path C:\Users\Rajesh\AppData\Roaming\Microsoft\Templates\Normal.dotm
2026-06-30 15:57:03,592 [lib.api.process] INFO: Termination confirmed for process 1932
2026-06-30 15:57:03,592 [root] DEBUG: 1932: Terminate Event: monitor shutdown complete for process 1932
2026-06-30 15:57:03,592 [root] INFO: Terminate event set for process 1932
2026-06-30 15:57:03,594 [lib.api.process] INFO: Terminate event set for process 2604
2026-06-30 15:57:03,595 [root] DEBUG: 2604: Terminate Event: Attempting to dump process 2604
2026-06-30 15:57:03,615 [root] DEBUG: 2604: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-30 15:57:03,643 [root] DEBUG: 2604: Terminate Event: Shutdown complete for process 2604 but failed to inform analyzer.
2026-06-30 15:57:05,222 [root] DEBUG: 1932: api-cap: NtFindAtom hook disabled due to count: 5000
2026-06-30 15:57:08,582 [lib.api.process] INFO: Termination confirmed for process 2604
2026-06-30 15:57:08,583 [root] INFO: Terminate event set for process 2604
2026-06-30 15:57:08,583 [root] INFO: Created shutdown mutex
2026-06-30 15:57:09,589 [root] INFO: Shutting down package
2026-06-30 15:57:09,620 [root] INFO: Stopping auxiliary modules
2026-06-30 15:57:09,621 [root] INFO: Stopping auxiliary module: Browser
2026-06-30 15:57:09,621 [root] INFO: Stopping auxiliary module: Human
2026-06-30 15:57:10,262 [root] INFO: Finishing auxiliary modules
2026-06-30 15:57:10,262 [root] INFO: Shutting down pipe server and dumping dropped files
2026-06-30 15:57:10,265 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\790FA9B6-8072-4BBC-B3D3-2D041488FD6B to files\3cffeeec0d1190fd5dc814988e9ae8f97de3196a2eebe97996f458f7958a876d; Size is 193445; Max size: 100000000
2026-06-30 15:57:10,279 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0409.lex to files\b3d510ef04275ca8e698e5b3cbb0ece3949ef9252f0cdc839e9ee347409a2209; Size is 2; Max size: 100000000
2026-06-30 15:57:10,282 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC to files\70207627bd6325a13873112a3091551abf48dc5ea5f12903f11132514f633c6a; Size is 18; Max size: 100000000
2026-06-30 15:57:10,295 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Roaming\Microsoft\Office\Recent\index.dat to files\361c0704f573c7b0627e2d07a8c69201936dbf143692c963ae6d67440a763eca; Size is 211; Max size: 100000000
2026-06-30 15:57:10,300 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Roaming\Microsoft\Office\Recent\BreakingBadNewsThatIs.docx.LNK to files\6bd7191da98267fa0508815946ff12a92529fc7a0d4d7837b93fac3289a257d7; Size is 1353; Max size: 100000000
2026-06-30 15:57:10,309 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{E7728AC3-3259-47E8-BD54-A93A292C0C29}.tmp to files\15412fd2abe9d9b26dc4af10447b13adf83c5293de470eaf6d1774f94036be95; Size is 32000; Max size: 100000000
2026-06-30 15:57:10,326 [lib.common.results] INFO: Uploading file C:\Program Files\Microsoft Office\root\Templates\BreakingBadNewsThatIs.docx to files\32c106467e6143556824b8dfc8cc0eb14ef0ae3988cbc6b1ad02ab061888d1c4; Size is 166741; Max size: 100000000
2026-06-30 15:57:10,343 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Office\Word16.customUI to files\7652d386ecc37eb37531307922404843a3a8f8532209fe189f4e3df88bd8bbae; Size is 3514; Max size: 100000000
2026-06-30 15:57:10,358 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{51A5872D-9D46-4CF3-99DE-38D108284A41}.tmp to files\4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1; Size is 1024; Max size: 100000000
2026-06-30 15:57:10,373 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Roaming\Microsoft\Templates\Normal.dotm to files\9bc8dd51624a40769c112579bbd23940c14dcc51ac025f3b2af3b17bd8744f4b; Size is 17999; Max size: 100000000
2026-06-30 15:57:10,389 [root] WARNING: Folder at path "C:\fYGInlZoy\debugger" does not exist, skipping
2026-06-30 15:57:10,389 [root] WARNING: Folder at path "C:\fYGInlZoy\tlsdump" does not exist, skipping
2026-06-30 15:57:10,390 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-30 15:56:13 | 2026-06-30 15:57:15 | internet |
| File Name |
BreakingBadNewsThatIs.docx
|
|---|---|
| File Type | Microsoft Word 2007+ |
| File Size | 166741 bytes |
| MD5 | 7465a966dcc7381c570373327221d468 |
| SHA1 | 90f9988afef5041c7f16089e360a4a3921cd6840 |
| SHA256 | 32c106467e6143556824b8dfc8cc0eb14ef0ae3988cbc6b1ad02ab061888d1c4 VT MWDB Bazaar |
| SHA3-384 | 2f0417c4d7c66bd9cc4e690a9766bef54180c3f1158bf32f2e3c543aba769bd892ac61a31c915363d5d002f62d859303 |
| CRC32 | 692D20BF |
| TLSH | T138F312736980DE1FF88D48BE1DE7BD48F2AD0A5126098B1E7D2DF24686C134607D479B |
| Ssdeep | 3072:zFztQC8eVjQ+tLQGVAPjsBKnyEO685desCVmhNWYLtB9N9r8hXNB3wxXCz1wlkrg:zgCpRQ+tGLsOO68jzOYBB9N58DBgx+1k |
={vMM
+c#cGm
kzo.N
!=mn`uw
#[{3v
~5 1,i
W^yE\
*NKK;u
`<1GZQ
H*]C|
@ln8H
EW-Ln
7CPn|+}u
Fk{{2|
!Yb*J
2t?zu{
z18)~+
&wWQQq
~:,aO
bp9l.
m2^^^
_rels/.rels
.9evA
]{~C:
:8=9=Y
4NMUp
li,Ul
/Or57
j1Tf;
)v$5+
NRJSB
>{s]T
[Content_Types].xml
|s3op
E#}b$
dsR?CbG]
ap8vK
Q6a7g
m1,kZYvn<
+PHI|
ck;vi
JWFz<u
e}iJ_
r6/>^
kHety*[
8f5=`pp
qQ<=;V
zSB+Mn
(`1,'
V%(R7
word/webSettings.xmlPK
,/If-=m\
-d31U
%M9v#Q7_
Y4Febi
54=Ws|HBO
kzM%uu
C11)}
\~o~w
nj0V-=
|b6;t<2
5Tos.
fM-mA
Z2)I?#
[u86:
*:j0k
S?f%<l
pd`|w
/O/)3
r_ES2
FK#8F
eF>WmA
mcBI 5f
4kjqe5
ER<Vn
RVN(K
p_iv>
kFSO(C
z???ik
mGqBv
",Q)o
word/media/image2.png
M|_oG
UUCNX
hKJJ~
word/settings.xmlPK
7_IeA
7eSWRY
YZde>
P-$Qp
PqU%O
3Dp\zH
];UZE$u
dCJes
@uiHf
J-<5ij@D
F<#UivS
~Gqt
.b*lI
8q"94
l<'dD|
jZv68c
C"l+h
{]4=E
L>><~
u&uQc
9g7'k
qTX!5p
]9MnS
BkBwG
N$skU
m_]w'
f<{+0
pDas,
xN(%7
VHHHTT
Bb 7I
W7$Yi@
JCnUCt
a*uJb8
docProps/app.xmlPK
91~s$e
>N\vqf
-xVT{
QcYs.[
*+/]2
W]uUh
TiS(,
zj?t~%-
)gVIIH2
AGIDATF
{.66v
E*J%H\
r[=1ipz
<05 h
ieSrT
9m*QIZY
J>_{bf
#Td5+=
6$S0k[
VJ2!X
|Z-MGl
{TglE
@ln0l
8s)TZ
1,zCJ
?eL>[o
'mg0z
y7uKPn
QE?@z
b7.98
lLee%
Zqxen#W1 ,3
}a%zU(
bK^HrkV
'K-bH
-az,X
HKKKP:
Xi}lk[A
(9X=:
J.W_ gX
+w|"_
HzUgV
`[xA%
P=r+s
word/webSettings.xml
$YknX
t&un]
{2v9W
Apj^Z
i-:Nz
dI>~)
Yt,$O
CX"J?N*g
[OxGo[Zl1
aca<el^
gT-98
_.k/5z/
g~uUX
Q$1%W
69J&I
*chLX
*cN8K
9,sI]
dHFuG!$
Z36n^
eJ8%Y5
[} q>%>
QRRRTTD
/{Cwj
^}l.?'
word/document.xmlPK
*Z4ur]
>>>^}$
B2o6h
gOqEn
;wf1<x
Yx`<f;#{V
K;R!5p
'I*n'
<;x8k
_#$zo
j|ShOQ
+9akS
]Br;Ek
drL6c
}fMJ2
&Mj6&
H23H2
<K^mU7
ldSv}6
1wZ5Y
cV}cwY
\!::z
;/;/}
K\v#Z
o;LcPR
yjolE
Fu-Qob
4%OtYt
^78@J
%4\bs]V
ebccI
=[6sss
.]Zn{
^:\%;u5a+c
OX=P2
word/settings.xml
^@n(@
lTY$@$
}UN'-8
S)Nu%o
?2<3D
cZSP
mlE;RH
hLY+'
']g,Y
$92hN
{C;C+
T-YK4
1f- f
1<?}}
z@=kC
M'iwV
DOJz"
[7yxm
nH>_y
oSKrh
:}9Oy
ddy97
N97W>|X
:>snq
yff?Z
iA[#&
/k1qF
HOZXX
-gI#=
HLLd:*
+4I1L
=???Z
>H3_}
~*cb[
niR6I
f{Zs[$P
2KO;Mo
NH>x~%
rH23Hrd
~RnE6K:
{DIvgDI
)5pa'y
IDATx^
?&-s*
?MQFZ:
&T5!!
::<jOOO
2m4Hrd
/7>kJ9HG
#{g/k
LHeiJ
|Azl9
,eJKK
sUQ)o
!555lS
Z:Fzr{
B+[8^{
word/media/image1.pngPK
<|~ed
_(SUU
H`!5p
@\ffO
Ly?._
G%Cee
\Vm=ulH=,
U6Wjv
*1LmY
)c.Sbk
Wtt4OE>
wX^l,8
ZgXU9
_K#)0
u`` u
UGbG'
#e~Ek
O=li.
%sCGI
Bcn4.w
Kjkk;
d<+xX
,,q3I
~IkYQo
`o2Ov
All,9w
i;r"-
/1I&'&&
8pnYt
CvbY0k
word/styles.xml
b;N/Ns
]zJ<w
sssY;
l6[jj*e*
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
q8cUD
/X`da
%::Z\
t$${>
pmHV(
word/styles.xmlPK
w_~hLT
aJvRlJ
_?I}I
o>;VL
word/media/image2.pngPK
K[nO9
K9z1,
/)$/9
docProps/app.xml
471o)
eiDYc$
EA]}1
f|y7.G
wu}J5l
RXEk!
VzU0#p
m;a(c
s^&16
WDVM"
4OC%G
H23Hrd
dOX20
S\YZ[H
J?L84
W@QGq|`>
2s+px
J|K2).
O,\h|
p2111w
CoTsC
word/media/image3.jpegPK
]TgXU
docProps/core.xmlPK
&9;.,
_o4*W6z
q4s~O+=
word/fontTable.xmlPK
MQ].{
F#i'=
K-ytTTyu
?~<55
=f~mw
gm1Hrd
kC2Cy
JN/KN
Fw'>T
<%{\.
5r|Hr
B.11q
l6gee
hUW1\
gefdd
Z?K5"U
D>#dL
LlLPP
YQ^6(
eHw)C
B234}
ZC+O]
D+yc833
X]w%!
06RljC
He(^m
;RXl1
&P#=j
Sp0_kQ
.q7K;
O1Blr
@kp9l
O_JOx
word/media/image1.png
kl}\c
a/P('gV'
,67XN-
$9ll(
bBi [du
>*>iH
Eavv6
|P:7m
'<ouX
D:Y]emE
w1<|Y
2A4eV
Q2vfl
1I&h\K
s8eXv
word/_rels/document.xml.rels
QdQ)o
L{B^I
n&E%U
wk/qk
!CXKZZ
s"tQkyU
,Sea#
zQ*U6
~O2eQ
5Hr`@
S;\>OYO
U~=FM
[Content_Types].xmlPK
e1_lI
"5^7$
J[p4cMH
Yyivgn
^WvbV"S
VO{N5
6$S:}
oD;7-
2Bba]
L~_NZp@
|un\v
1,w!=
`K2a+
9SzN9
SyzoU
docProps/core.xml
^n/_g
\B4w\'
Xi?Gzp
9M4W=
|F(1X
1x_*R
4]p`X
y3:U12
7-VUU
5Xqh,kC
7(}LxvX`F+
g7'{N
QIkR>
cGu!Ou<
W3om}
&Cr^]*-
}m8wdk
UCz<9
DjXiD
AIZN`
L'BeI
Fjl'${
L&SJJJhhhrrrKK
ZcTr<
3H23Hrd
N:=v~
NzKrL
5L=3|
yz;99
1r$UP!5
uOZ3(
YXTTTWW
|+y9g
n{9lK
Rw'+uu81
.I9qy/
word/document.xml
1i<uj$
Br'!$
word/_rels/document.xml.relsPK
9lkZ>R
l;txl
pja1L
IIIay
f3M7^a
>,-s%
316&Or
8>>^l
_&Y1|
<a3Hrx
tNY7x
_u$vQ
miiaWG?
_dFRR
qNl3o
NIgRoN
i~hXx
[m$]!
~]xwkJh'
Gs'Uy
&+y`|
=y@c]
4%orw
0)D)V
fw'>T
;S|([
[u:VL
7k_0\e
2)gE^
sss))}
7/[w%
~1|Gn
@c])h
m `I&
EI&jkk
vw'>T
e=g}-
&s/^7
Kge>O
$9r19
O>)m!al
7yuiF
}xS5D
{W@%G
acY<^r
9k<>1W
Ombcc)
Z*1o)
svz}^Y
dkh1{
UK1LyV)
u}q}^^e6
2FuF*
R&::z
/6B0?!
Z'vt5
QBnjj:w
z1$S<
8]ze3+x
<9,IP
B2E,KK
7$IK@}
%=i7:
<|Tr\
9[K|xIKK
+"$Y0
't/IZ
+EPQ,
zeRSi
,A)}32
qpa=j;
T]]MaUU
Hs[4H2
)~_=>
word/stylesWithEffects.xmlPK
op^%3
~Ezl+
r,EPi
3~2kd
htt=&
$jl'$o?
bXMG:
#`I>U
j$=VO
Ssrrt
<I6;m
&4BXg
pJrG3H2
/HCzj
DS2Mc
O[?T=
word/stylesWithEffects.xml
Vx!#M
$9D\6
KG%]{Ln
)y0j|
`JvR]8%
EmL&`v
-jn65^/
1++Kzv
SVp<g0
$Yn$U
[@V(SY%
ut!5p
\cc@LO@
n!%Yj
lMo3v9r
][O$b
$92hV
.Xkp4
g|WMo'9
YSK)WkT
({o.P
/<5{G
_rels/.relsPK
9C2UZE
/"bH4
]k/<;,0
XW|(X
H-B[H
,98zO
y=~U0^
[UUUjj*
u$!PCB]
B3ba&
S;DKq
#R!5p
k]7$s
o5 \V
dq`l/;
s_UOy
&}87m
v1,k?
5BgVK!m
1cX3iJ
)G2V+t
,t?'|Vf?
Ce\X{
\X^#/
9#L5%0
b@\Ww8f
Wq6c^
8t~Eh
>c5Ib\
jx(m8Cz
dp{3/
]2RHc
<|~eT
=5=-`Pjy
3Z4q-
efRtrR
jT2@%
D0sOO
,Hvgn
^Q=[>W
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
mW-LnT
:.(+^N
[%fhL
Q$kWB
?$=VM|
A+i0T
,vssg\
}Q*gJG|\
N^Nlv
A$>"f3
;<&S7
l;3os
DI[)`
Nul(b
u35-`
y't@`'
hI>zq
PINk%yYv4
^^e6k
*yqVu|t
n^Ao'
wR3X?
$O3g,i
<W^yxW
(5RHf-
@1b1lrfX
#1xK]
z)8oL
'3Zuz
*}SXr\`o^NZ
_?V{m
#I,YX
ZMx;t
|~4c-K
vOPIZ
x<3hhn]
KJ=L3
<`sOX
dkvmTUI
aQVq/
u$OE8
_iOo6
X\X9,
ta[BI@Fu\a
z)_YsO[,
m+SIZ
~{s:FXI
gAXPl%
word/fontTable.xml
*j/h<Oc
a%gTk
RFjCS
fmYKnH
h%MB[
QQZ%wL
#TpW]
-[wvuH
=V[(--
')gV]T
Q>l:>
word/theme/theme1.xml
'M%t=
0(Plx[
YgU7YoC
O<!)(=
<x"`@\
word/theme/theme1.xmlPK
P*+:XK
Yl.QWW
FY---
x<-`PQS
\n}8c
`)W_m
^@My<UD
<~G_I
Hu3!yf
M1Ozf
$92xk
GHm91
TjCc\
\.!"z
1,Aem
{hu:l
{!ndr/
0T2+cO
I/paK
[.r<.U
c*v:2}
WDarYI
.w'>T
v1,`23O
SO=|G"8>
.Ka1r5
Y}}=k
~}cS>J
word/media/image3.jpeg
xsW&|]
=vL>p@>{V
_)k8kwZ
)OY%k
<UxDcT
CrVM"
U;?5d
:Uo6on
csZi:
-gG]'
<;-fi
=ssjj
*y`|7
(j4sW
~1|{n
~%hVcI&
^SPy4i|
Br'9aHV
Np#1#g~
`vMRyk>b0
No results found.
No behavioral analysis data available.
No dropped files found.