Category | Package | Started | Completed | Duration | Log(s) |
---|---|---|---|---|---|
FILE | 2025-02-17 14:01:54 | 2025-02-17 14:07:34 | 340 seconds | Show Analysis Log |
2024-11-25 13:38:18,100 [root] INFO: Date set to: 20250217T14:00:30, timeout set to: 200 2025-02-17 14:00:30,031 [root] DEBUG: Starting analyzer from: C:\tmp_gell1p8 2025-02-17 14:00:30,031 [root] DEBUG: Storing results at: C:\wRQhaNwUv 2025-02-17 14:00:30,031 [root] DEBUG: Pipe server name: \\.\PIPE\uCXdXx 2025-02-17 14:00:30,031 [root] DEBUG: Python path: C:\Users\Packager\AppData\Local\Programs\Python\Python310-32 2025-02-17 14:00:30,031 [root] INFO: analysis running as an admin 2025-02-17 14:00:30,031 [root] DEBUG: no analysis package configured, picking one for you 2025-02-17 14:00:32,250 [root] INFO: analysis package selected: "zip" 2025-02-17 14:00:32,250 [root] DEBUG: importing analysis package module: "modules.packages.zip"... 2025-02-17 14:00:32,297 [root] DEBUG: imported analysis package "zip" 2025-02-17 14:00:32,297 [root] DEBUG: initializing analysis package "zip"... 2025-02-17 14:00:32,297 [lib.common.common] INFO: wrapping 2025-02-17 14:00:32,297 [lib.core.compound] INFO: C:\Users\Packager\AppData\Local\Temp already exists, skipping creation 2025-02-17 14:00:32,297 [root] DEBUG: New location of moved file: C:\Users\Packager\AppData\Local\Temp\JetBrains_PyCharmPro.zip 2025-02-17 14:00:32,297 [root] INFO: Analyzer: Package modules.packages.zip does not specify a DLL option 2025-02-17 14:00:32,297 [root] INFO: Analyzer: Package modules.packages.zip does not specify a DLL_64 option 2025-02-17 14:00:32,297 [root] INFO: Analyzer: Package modules.packages.zip does not specify a loader option 2025-02-17 14:00:32,297 [root] INFO: Analyzer: Package modules.packages.zip does not specify a loader_64 option 2025-02-17 14:00:32,437 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2025-02-17 14:00:32,453 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2025-02-17 14:00:32,469 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2025-02-17 14:00:32,484 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2025-02-17 14:00:32,500 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2025-02-17 14:00:32,500 [lib.api.screenshot] ERROR: No module named 'PIL' 2025-02-17 14:00:32,500 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots" 2025-02-17 14:00:32,500 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2025-02-17 14:00:32,500 [root] DEBUG: Initialized auxiliary module "Browser" 2025-02-17 14:00:32,500 [root] DEBUG: attempting to configure 'Browser' from data 2025-02-17 14:00:32,500 [root] DEBUG: module Browser does not support data configuration, ignoring 2025-02-17 14:00:32,500 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2025-02-17 14:00:32,500 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2025-02-17 14:00:32,500 [root] DEBUG: Initialized auxiliary module "DigiSig" 2025-02-17 14:00:32,500 [root] DEBUG: attempting to configure 'DigiSig' from data 2025-02-17 14:00:32,500 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2025-02-17 14:00:32,500 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2025-02-17 14:00:32,500 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature 2025-02-17 14:00:35,453 [modules.auxiliary.digisig] DEBUG: File format not recognized 2025-02-17 14:00:35,453 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json 2025-02-17 14:00:35,453 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2025-02-17 14:00:35,453 [root] DEBUG: Initialized auxiliary module "Disguise" 2025-02-17 14:00:35,453 [root] DEBUG: attempting to configure 'Disguise' from data 2025-02-17 14:00:35,453 [root] DEBUG: module Disguise does not support data configuration, ignoring 2025-02-17 14:00:35,453 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2025-02-17 14:00:35,453 [modules.auxiliary.disguise] INFO: Disguising GUID to b3124c33-8696-4805-8a42-f6e841a2b993 2025-02-17 14:00:35,453 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2025-02-17 14:00:35,453 [root] DEBUG: Initialized auxiliary module "Human" 2025-02-17 14:00:35,453 [root] DEBUG: attempting to configure 'Human' from data 2025-02-17 14:00:35,453 [root] DEBUG: module Human does not support data configuration, ignoring 2025-02-17 14:00:35,453 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2025-02-17 14:00:35,453 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2025-02-17 14:00:35,453 [root] DEBUG: Initialized auxiliary module "Screenshots" 2025-02-17 14:00:35,453 [root] DEBUG: attempting to configure 'Screenshots' from data 2025-02-17 14:00:35,453 [root] DEBUG: module Screenshots does not support data configuration, ignoring 2025-02-17 14:00:35,453 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"... 2025-02-17 14:00:35,453 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2025-02-17 14:00:35,453 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots 2025-02-17 14:00:35,453 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2025-02-17 14:00:35,453 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2025-02-17 14:00:35,453 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2025-02-17 14:00:35,453 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2025-02-17 14:00:35,453 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 696 2025-02-17 14:00:35,515 [lib.api.process] INFO: Monitor config for <Process 696 lsass.exe>: C:\tmp_gell1p8\dll\696.ini 2025-02-17 14:00:35,515 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor 2025-02-17 14:00:35,531 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp_gell1p8\dll\KuolGmJ.dll, loader C:\tmp_gell1p8\bin\SGtTThPa.exe 2025-02-17 14:00:35,625 [root] DEBUG: Loader: Injecting process 696 with C:\tmp_gell1p8\dll\KuolGmJ.dll. 2025-02-17 14:00:35,656 [root] DEBUG: 696: Python path set to 'C:\Users\Packager\AppData\Local\Programs\Python\Python310-32'. 2025-02-17 14:00:35,656 [root] INFO: Disabling sleep skipping. 2025-02-17 14:00:35,656 [root] DEBUG: 696: TLS secret dump mode enabled. 2025-02-17 14:00:35,656 [root] DEBUG: 696: InternalYaraScan: Scanning 0x00007FF84A790000, size 0x1f4542 2025-02-17 14:00:35,672 [root] DEBUG: 696: InternalYaraScan hit: RtlInsertInvertedFunctionTable 2025-02-17 14:00:35,672 [root] DEBUG: 696: RtlInsertInvertedFunctionTable 0x00007FF84A7A090E, LdrpInvertedFunctionTableSRWLock 0x00007FF84A8FB4F0 2025-02-17 14:00:35,672 [root] DEBUG: 696: Monitor initialised: 64-bit capemon loaded in process 696 at 0x00007FF824D70000, thread 2080, image base 0x00007FF60D500000, stack from 0x0000008EFABF4000-0x0000008EFAC00000 2025-02-17 14:00:35,672 [root] DEBUG: 696: Commandline: C:\Windows\system32\lsass.exe 2025-02-17 14:00:35,687 [root] DEBUG: 696: Hooked 5 out of 5 functions 2025-02-17 14:00:35,687 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2025-02-17 14:00:35,687 [root] DEBUG: Successfully injected DLL C:\tmp_gell1p8\dll\KuolGmJ.dll. 2025-02-17 14:00:35,687 [lib.api.process] INFO: Injected into 64-bit <Process 696 lsass.exe> 2025-02-17 14:00:35,687 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2025-02-17 14:00:40,984 [root] INFO: Restarting WMI Service 2025-02-17 14:00:43,062 [root] DEBUG: package modules.packages.zip does not support configure, ignoring 2025-02-17 14:00:43,062 [root] WARNING: configuration error for package modules.packages.zip: error importing data.packages.zip: No module named 'data.packages' 2025-02-17 14:00:45,359 [lib.common.zip_utils] INFO: Uploading C:\Users\Packager\AppData\Local\Temp\JetBrains_PyCharmProfessional_243.24978.54_x64_MUI_01/Doc/Package Documentation of JetBrains_PyCharmProfessional_243.24978.54_x64_MUI_01.txt to host 2025-02-17 14:00:45,375 [lib.common.results] INFO: Uploading file C:\Users\Packager\AppData\Local\Temp\JetBrains_PyCharmProfessional_243.24978.54_x64_MUI_01/D <truncated>
Name | Label | Manager | Started On | Shutdown On | Route |
---|---|---|---|---|---|
win10-2 | win10-2 | KVM | 2025-02-17 14:01:54 | 2025-02-17 14:07:14 | none |
File Name |
JetBrains_PyCharmPro.zip
|
---|---|
File Type | Zip archive data, at least v2.0 to extract, compression method=deflate |
File Size | 877870178 bytes |
MD5 | 22404113afcacd5996ab0810f1f5cfcd |
SHA1 | ea6b4b739c85037bd128a29ecdb50ceb1a53ecde |
SHA256 | 30afccb46f1065dd87d3b739313e6ebaff3bcab19184c57eea1c419370e8aa87 [VT] [MWDB] [Bazaar] |
SHA3-384 | 05cf67e327f9a1bd08572859013cf1113246c570e12979af4ff07da171647acdb6c2c25ce076f0e86b8e5c5db8f848c6 |
CRC32 | 13F505D7 |
TLSH | T1E299336BB802CCC5EA6CDDB65C438BD52608AB7BC74FF4CCF4C61B5E2939109A10E596 |
Ssdeep | 12582912:Q3j6qR8VJ2aojrLJK8pHgNn99RrqVmLpZ4BgKK+nhuf3SEHO4pj29Pa4f2irK:Q7RF9fXpHMnnGWn2k+nwqKOyeVf2AK |
Yara |
|
File Strings BinGraph Vba2Graph VirusTotal |
No hosts contacted.
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP