Edit tour

Windows Analysis Report
terraform-ls.exe

Overview

General Information

Sample Name:terraform-ls.exe
Analysis ID:1340442
MD5:8a26932d0bf750242cc86a9b29e4d190
SHA1:ab3fafbb67203bd56b68161b4fb39aef6b665d8e
SHA256:7220f6ced1c530e3d7af9ef8062c56afc8718495ac429bf22e846be163daec1d
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Sample execution stops while process was sleeping (likely an evasion)
Program does not show much activity (idle)
PE file contains sections with non-standard names

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • terraform-ls.exe (PID: 6136 cmdline: C:\Users\user\Desktop\terraform-ls.exe MD5: 8A26932D0BF750242CC86A9B29E4D190)
    • conhost.exe (PID: 6708 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: terraform-ls.exeStatic PE information: certificate valid
Source: terraform-ls.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: terraform-ls.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: terraform-ls.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: terraform-ls.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: terraform-ls.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: terraform-ls.exeString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: terraform-ls.exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: terraform-ls.exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: terraform-ls.exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: terraform-ls.exeString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: terraform-ls.exeString found in binary or memory: http://ocsp.digicert.com0
Source: terraform-ls.exeString found in binary or memory: http://ocsp.digicert.com0A
Source: terraform-ls.exeString found in binary or memory: http://ocsp.digicert.com0C
Source: terraform-ls.exeString found in binary or memory: http://ocsp.digicert.com0X
Source: terraform-ls.exeString found in binary or memory: http://the.earth.li/~sgtatham/putty/0.66/htmldoc/Chapter9.html#pageant).all
Source: terraform-ls.exeString found in binary or memory: http://www.digicert.com/CPS0
Source: terraform-ls.exeString found in binary or memory: https://cloud.google.com/storage/docs/json_api/v1/buckets/get#http-request)).If
Source: terraform-ls.exeString found in binary or memory: https://intl.cloud.tencent.com/document/product/598/10603).
Source: terraform-ls.exeString found in binary or memory: https://kubernetes.io/docs/reference/access-authn-authz/authentication/#client-go-credential-plugins
Source: terraform-ls.exeString found in binary or memory: https://passlib.readthedocs.io/en/stable/modular_crypt_format.html)
Source: terraform-ls.exeString found in binary or memory: https://pkg.go.dev/embed
Source: terraform-ls.exeString found in binary or memory: https://registry.terraform.io%s:
Source: terraform-ls.exeString found in binary or memory: https://registry.terraform.io/providers/%s/%s/%s/docsFailed
Source: terraform-ls.exeString found in binary or memory: https://tools.ietf.org/html/rfc3339)
Source: terraform-ls.exeString found in binary or memory: https://tools.ietf.org/html/rfc4122#section-4.3)
Source: terraform-ls.exeString found in binary or memory: https://tools.ietf.org/html/rfc4632#section-3.1).
Source: terraform-ls.exeString found in binary or memory: https://unicode.org/reports/tr29/#Grapheme_Cluster_Boundaries)
Source: terraform-ls.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\terraform-ls.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: terraform-ls.exeString found in binary or memory: 'github.com/posener/complete/cmd/install
Source: terraform-ls.exeString found in binary or memory: &*embedded.Int64ObservableUpDownCounter&*fiat.p224MontgomeryDomainFieldElement&*fiat.p384MontgomeryDomainFieldElement&*fiat.p521MontgomeryDomainFieldElement&*func(bisect.Writer, string, int) bool&*schemacontext.blockNestingLevelCtxKey&*struct { anchor []uint8; alias bool }&*map.bucket[string]yaml.resolveMapItem'github.com/posener/complete/cmd/install'*map[string]version.constraintOperation'*func(uintptr, uint32, uintptr) uintptr'*map.bucket[runtime._typePair]struct {}'*func(interface {}, interface {}) int64'*func(string, string) map[string]string'*func(...interface {}) ([]uint8, error)'*map[module.ProviderRef]tfaddr.Provider'*func(document.DirHandle) (bool, error)'*func(context.Context, ...job.ID) error'github.com/hashicorp/hcl-lang/reference'*map.bucket[uintptr]*pprof.profMapEntry'*func(context.Context, *jrpc2.Response)'*func([]uint8) (*ecdh.PublicKey, error)'*func(*ecdh.PrivateKey) *ecdh.PublicKey
Source: terraform-ls.exeString found in binary or memory: /github.com/hashicorp/terraform-registry-address
Source: terraform-ls.exeString found in binary or memory: json:"responseFields,omitempty".*func(context.Context, bool) reference.Origins.*func(lang.Path) (*decoder.PathContext, error).*func(lang.Path) (*decoder.PathDecoder, error).*map.bucket[string]command.providerRequirement.*[]metric.Float64ObservableUpDownCounterOption.*func(metric.RecordConfig) metric.RecordConfig.*struct { F uintptr; hf *[]hpack.HeaderField }.*struct { F uintptr; conv convert.conversion }/*func([]uint8, []uint8, []uint8, []int) []uint8/*func(interface {}, interface {}) (bool, error)/github.com/hashicorp/terraform-registry-address/*func(context.Context, job.Job) (job.ID, error)/*map.bucket[tfaddr.Provider]version.Constraints/*struct { F uintptr; R *langserver.langServer }/*struct { F uintptr; session *session.session }/*func(string, string) (trace.TraceState, error)/*func(reflect.StructField, reflect.Value) error
Source: terraform-ls.exeString found in binary or memory: --Fromxn--[%s]%s}) or %q, whencheftagscostvalsseqsmapssetssha1sortvarsuuidrepoetcdexeccert%04dyearelemflag...`.inf.nanTrueTRUENullNULL.NaN.NAN.Inf.INFyamlcx16sse2servechdir<nil>writemkdirchmodchowncloseLstat-help( |$)debugamd64defersweepschedhchansudoggscanmheaptracepanicsleep cnt=gcing MB, other got= ...
Source: terraform-ls.exeString found in binary or memory: %s}bastion_private_keybastion_certificatevariable_validationThe repository nameThe container name.resource_group_namearm_subscription_iduse_microsoft_graphtablestore_endpointskip_table_creationskip_index_creationallowed_account_idsAWS region for STS.shared_config_filestransitive_tag_keysuse_legacy_workflowproject_domain_nameterraform-terraformmissing header lineThe string to trim.Algolia for Go (%s)> ALGOLIA DEBUG: %sInvalid array valueMismatched bracketsInvalid JSON numberInvalid JSON stringMissing block labelproxy_user_passwordvalue must be knownwhile parsing a tagautocomplete-installinvalid write resultSeek: invalid whenceSeek: invalid offsetfloating point errorGC sweep terminationResetDebugLog (test)chan send (nil chan)malloc during signalclose of nil channelinconsistent lockedmnotetsleep not on g0bad system page size to unallocated span/gc/scan/stack:bytes/gc/scan/total:bytes/gc/heap/frees:bytes/gc/gomemlimit:bytesp mcache not flushed markroot jobs done
Source: terraform-ls.exeString found in binary or memory: ^(\s*(%s)\s*(%s)\s*)((?:\s+|,\s*)(%s)\s*(%s)\s*)*$data/registry.terraform.io/alertmixer/amixr/0.2.3/data/registry.terraform.io/alkiranet/alkira/1.1.0/data/registry.terraform.io/circonus-labs/circonus/data/registry.terraform.io/ciscodevnet/intersight/data/registry.terraform.io/ciscodevnet/aci/2.10.1/data/registry.terraform.io/ciscodevnet/cml2/0.6.2/data/registry.terraform.io/ciscodevnet/dcnm/1.2.7/data/registry.terraform.io/ciscodevnet/mso/0.11.1/data/registry.terraform.io/ciscodevnet/nxos/0.5.1/data/registry.terraform.io/codefresh-io/codefresh/data/registry.terraform.io/confluentinc/confluent/data/registry.terraform.io/consensys/quorum/0.3.0/data/registry.terraform.io/datadog/datadog/3.32.0/data/registry.terraform.io/enterprisedb/biganimal/data/registry.terraform.io/equinix/equinix/1.19.0/data/registry.terraform.io/gitlabhq/gitlab/16.5.0/data/registry.terraform.io/harness/harness/0.28.3/data/registry.terraform.io/hashicorp/awscc/0.63.0/data/registry.terraform.io/hashicorp/google/5.5.0/data/registry.terraform.io/hashicorp/random/3.5.1/data/registry.terraform.io/hashicorp/vault/3.22.0/data/registry.terraform.io/hewlettpackard/oneview/data/registry.terraform.io/ionos-cloud/ionoscloud/data/registry.terraform.io/nirmata/nirmata/1.1.13/data/registry.terraform.io/nullstone-io/ns/0.6.22/data/registry.terraform.io/paloaltonetworks/panos/data/registry.terraform.io/phoenixnap/pnap/0.22.0/data/registry.terraform.io/rancher/rancher2/3.2.0/data/registry.terraform.io/rollbar/rollbar/1.13.0/data/registry.terraform.io/splunk/artifacts/1.1.0/data/registry.terraform.io/splunk/victorops/0.1.4/data/registry.terraform.io/valtix-security/valtix/data/registry.terraform.io/vmware/wavefront/5.0.4/data/registry.terraform.io/zenlayer/zenlayercloud/net/http: cannot rewind body after connection losshttp: putIdleConn: CloseIdleConnections was calledgot CONTINUATION for stream %d; expected stream %dhttp: suspiciously long trailer after chunked bodynet/http: Transport failed to read from server: %vnet/http: HTTP/1.x transport connection broken: %wmust be between one and 64 ASCII letters or digitsgo.opentelemetry.io/otel/instrumentation/httptraceThis map does not have an element with the key %q.ExpandFinal set on function call with no argumentsThe key expression produced an invalid result: %s.For expression requires variable name after 'for'.Key expression is not valid when building a tuple.Expected an attribute access or an index operator.Terraform cannot be initialised with empty workdircannot unmarshal UserData from search response: %vedwards25519: invalid SetUniformBytes input lengthtls: received unexpected CertificateStatus messagetls: invalid signature by the server certificate: element types must all match for conversion to mapelement types must all match for conversion to setRun the provisioner when the resource is destroyed`tobool` converts its argument to a boolean value.TableStore table for state locking and consistencynot a valid RFC3339 timestamp: cannot use %q as %s
Source: terraform-ls.exeString found in binary or memory: ^(\s*(%s)\s*(%s)\s*)((?:\s+|,\s*)(%s)\s*(%s)\s*)*$data/registry.terraform.io/alertmixer/amixr/0.2.3/data/registry.terraform.io/alkiranet/alkira/1.1.0/data/registry.terraform.io/circonus-labs/circonus/data/registry.terraform.io/ciscodevnet/intersight/data/registry.terraform.io/ciscodevnet/aci/2.10.1/data/registry.terraform.io/ciscodevnet/cml2/0.6.2/data/registry.terraform.io/ciscodevnet/dcnm/1.2.7/data/registry.terraform.io/ciscodevnet/mso/0.11.1/data/registry.terraform.io/ciscodevnet/nxos/0.5.1/data/registry.terraform.io/codefresh-io/codefresh/data/registry.terraform.io/confluentinc/confluent/data/registry.terraform.io/consensys/quorum/0.3.0/data/registry.terraform.io/datadog/datadog/3.32.0/data/registry.terraform.io/enterprisedb/biganimal/data/registry.terraform.io/equinix/equinix/1.19.0/data/registry.terraform.io/gitlabhq/gitlab/16.5.0/data/registry.terraform.io/harness/harness/0.28.3/data/registry.terraform.io/hashicorp/awscc/0.63.0/data/registry.terraform.io/hashicorp/google/5.5.0/data/registry.terraform.io/hashicorp/random/3.5.1/data/registry.terraform.io/hashicorp/vault/3.22.0/data/registry.terraform.io/hewlettpackard/oneview/data/registry.terraform.io/ionos-cloud/ionoscloud/data/registry.terraform.io/nirmata/nirmata/1.1.13/data/registry.terraform.io/nullstone-io/ns/0.6.22/data/registry.terraform.io/paloaltonetworks/panos/data/registry.terraform.io/phoenixnap/pnap/0.22.0/data/registry.terraform.io/rancher/rancher2/3.2.0/data/registry.terraform.io/rollbar/rollbar/1.13.0/data/registry.terraform.io/splunk/artifacts/1.1.0/data/registry.terraform.io/splunk/victorops/0.1.4/data/registry.terraform.io/valtix-security/valtix/data/registry.terraform.io/vmware/wavefront/5.0.4/data/registry.terraform.io/zenlayer/zenlayercloud/net/http: cannot rewind body after connection losshttp: putIdleConn: CloseIdleConnections was calledgot CONTINUATION for stream %d; expected stream %dhttp: suspiciously long trailer after chunked bodynet/http: Transport failed to read from server: %vnet/http: HTTP/1.x transport connection broken: %wmust be between one and 64 ASCII letters or digitsgo.opentelemetry.io/otel/instrumentation/httptraceThis map does not have an element with the key %q.ExpandFinal set on function call with no argumentsThe key expression produced an invalid result: %s.For expression requires variable name after 'for'.Key expression is not valid when building a tuple.Expected an attribute access or an index operator.Terraform cannot be initialised with empty workdircannot unmarshal UserData from search response: %vedwards25519: invalid SetUniformBytes input lengthtls: received unexpected CertificateStatus messagetls: invalid signature by the server certificate: element types must all match for conversion to mapelement types must all match for conversion to setRun the provisioner when the resource is destroyed`tobool` converts its argument to a boolean value.TableStore table for state locking and consistencynot a valid RFC3339 timestamp: cannot use %q as %s
Source: terraform-ls.exeString found in binary or memory: url=%sThe JavaScript identifier %q cannot be used in JSON.internal error: missing handler for resolver table: port number to listen on (turns server into TCP mode)compileCallback: argument size is larger than uintptrsync/atomic: compare and swap of nil value into Valuebufio.Scan: too many empty tokens without progressingreflect: non-interface type passed to Type.Implementsreflect.Value.Slice: string slice index out of boundscrypto/elliptic: attempted operation on invalid pointx509: certificate specifies an incompatible key usagepem: cannot encode a header key that contains a colonmath/big: internal error: cannot find (D/n) = -1 for cannot append two slices with different type (%s, %s)data/registry.terraform.io/a10networks/thunder/1.3.0/data/registry.terraform.io/assistanz/stackbill/0.1.0/data/registry.terraform.io/bluecatlabs/bluecat/1.1.1/data/registry.terraform.io/brightbox/brightbox/3.4.3/data/registry.terraform.io/buildkite/buildkite/1.0.6/data/registry.terraform.io/chainguard-dev/oci/0.0.10/data/registry.terraform.io/configcat/configcat/2.0.2/data/registry.terraform.io/crunchydata/crunchybridge/data/registry.terraform.io/devcyclehq/devcycle/1.0.2/data/registry.terraform.io/digitalocean/digitalocean/data/registry.terraform.io/flagsmith/flagsmith/0.6.0/data/registry.terraform.io/fortinetdev/fortianalyzer/data/registry.terraform.io/hashicorp/googleworkspace/data/registry.terraform.io/hashicorp/boundary/1.1.10/data/registry.terraform.io/hashicorp/cloudinit/2.3.2/data/registry.terraform.io/infracost/infracost/0.0.9/data/registry.terraform.io/kaleido-io/kaleido/0.2.15/data/registry.terraform.io/kentik/kentik-cloudexport/data/registry.terraform.io/launchdarkly/launchdarkly/data/registry.terraform.io/logicmonitor/logicmonitor/data/registry.terraform.io/navercloudplatform/ncloud/data/registry.terraform.io/netapp/netapp-ontap/1.0.0/data/registry.terraform.io/orcasecurity/orcasecurity/data/registry.terraform.io/packetfabric/packetfabric/data/registry.terraform.io/pagerduty/pagerduty/3.1.1/data/registry.terraform.io/rafaysystems/rafay/1.1.17/data/registry.terraform.io/spectrocloud/spectrocloud/data/registry.terraform.io/splunk-terraform/signalfx/data/registry.terraform.io/splunk/splunkconfig/1.7.2/data/registry.terraform.io/spotinst/spotinst/1.148.0/data/registry.terraform.io/stackpath/stackpath/1.5.0/data/registry.terraform.io/syntropynet/syntropystack/data/registry.terraform.io/thousandeyes/thousandeyes/data/registry.terraform.io/tidbcloud/tidbcloud/0.2.1/data/registry.terraform.io/timescale/timescale/1.1.0/data/registry.terraform.io/venafi/venafi-token/0.2.0/data/registry.terraform.io/zentralopensource/zentral/http: putIdleConn: too many idle connections for hosthttp2: Framer %p: failed to decode just-written frameillegal use of AllowIllegalReads with ReadMetaHeadershttp2: Transport failed to get client conn for %s: %vhttps://registry.terraform.io/providers/%s/%s/%s/docsFailed to recognize the value of this number literal.parseFor called with peeker
Source: terraform-ls.exeString found in binary or memory: bytes.Buffer: UnreadRune: previous operation was not a successful ReadRuneIgnoring removed folder %s: %s. This is most likely bug, please report it.data/registry.terraform.io/aristanetworks/cloudvision/0.1.6/schema.json.gzdata/registry.terraform.io/checkpointsw/infinity-next/1.0.3/schema.json.gzdata/registry.terraform.io/cloudtamer-io/cloudtamerio/0.2.0/schema.json.gzdata/registry.terraform.io/digitalocean/digitalocean/2.31.0/schema.json.gzdata/registry.terraform.io/launchdarkly/launchdarkly/2.16.0/schema.json.gzdata/registry.terraform.io/logicmonitor/logicmonitor/2.0.11/schema.json.gzdata/registry.terraform.io/mariadb-corporation/skysql/1.2.6/schema.json.gzdata/registry.terraform.io/materializeinc/materialize/0.2.0/schema.json.gzdata/registry.terraform.io/navercloudplatform/ncloud/2.3.18/schema.json.gzdata/registry.terraform.io/snyk-terraform-assets/snyk/0.0.5/schema.json.gzdata/registry.terraform.io/zentralopensource/zentral/0.1.42/schema.json.gzmalformed response from server: malformed non-numeric status pseudo headernet/http: server replied with more than declared Content-Length; truncatedThe "source" attribute must be in the format "[hostname/][namespace/]name"A value of type %s cannot be used as the collection in a 'for' expression.Splat expressions (with the * symbol) cannot be applied to null sequences.The argument %q was already set at %s. Each argument may be set only once.number value contains big.Float value %s, rather than pointer to big.FloatThe %s type constructor requires one argument specifying the element type.Optional attribute modifier expects only one argument: the attribute type.tls: certificate RSA key size too small for supported signature algorithmsCustom validation rule to restrict what value is expected for the variableWorkspace mapping strategy, either workspace `tags` or `name` is required.Import resources into Terraform to bring them under Terraform's management`sum` takes a list or set of numbers and returns the sum of those numbers.The ID of the Tenant (Identity v2) or Project (Identity v3) to login with.data/registry.terraform.io/metalsoft-io/metalcloud/2.4.0-pre/schema.json.gzdata/registry.terraform.io/paloaltonetworks/bridgecrew/0.3.7/schema.json.gzdata/registry.terraform.io/purestorage-openconnect/cbs/0.9.0/schema.json.gzUnsolicited response received on idle HTTP channel starting with %q; err=%vExpected the start of an expression, but found an invalid expression token.Expected an equals sign ("=") to mark the beginning of the attribute value.tls: internal error: attempted to read record with pending application dataValue, typically a reference to an attribute of a resource or a data sourceLifecycle customizations to change default resource behaviours during apply`newbits` is the number of additional bits with which to extend the prefix.`trimsuffix` removes the specified suffix from the end of the given string.Path of the default state file;
Source: terraform-ls.exeString found in binary or memory: depgithub.com/hashicorp/terraform-registry-addressv0.2.3h1:2TAiKJ1A3MAkZlH1YI/aTVcLZRu7JseiXNRHbOAyoTI=
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.bash.Install
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.bash.cmd
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.bash.Uninstall
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.fish.Install
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.fish.Uninstall
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.fish.cmd
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.Install
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.Uninstall
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.installers
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.fishConfigDir
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.getConfigHomePath
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.getBinaryPath
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.rcFile
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.lineInFile
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.lineInFile.func1
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.createFile
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.createFile.func1
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.appendToFile
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.appendToFile.func1
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.removeFromFile
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.removeContentToTempFile
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.removeContentToTempFile.func2
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.removeContentToTempFile.func1
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.copyFile
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.copyFile.func2
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.copyFile.func1
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.zsh.Install
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.zsh.cmd
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.zsh.Uninstall
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.(*bash).Install
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.(*bash).Uninstall
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.(*fish).Install
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.(*fish).Uninstall
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.(*zsh).Install
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete/cmd/install.(*zsh).Uninstall
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*ParserError).Error
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.ParseModuleSource
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.parseModuleRegistryName
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.parseModuleRegistryTargetSystem
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Module.String
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Module.ForDisplay
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.splitPackageSubdir
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.sourceDirSubdir
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.ModulePackage.String
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.ModulePackage.ForDisplay
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.ModulePackage.ForRegistryProtocol
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.String
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.IsZero
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.ForDisplay
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.NewProvider
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.LegacyString
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.HasKnownNamespace
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.IsBuiltIn
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.LessThan
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.IsLegacy
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.Provider.Equals
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.ParseProviderSource
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.parseSourceStringParts
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.ParseProviderPart
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.MustParseProviderPart
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.init
Source: terraform-ls.exeString found in binary or memory: type:.eq.github.com/hashicorp/terraform-registry-address.ParserError
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*ModulePackage).ForDisplay
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*ModulePackage).ForRegistryProtocol
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*ModulePackage).String
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Module).ForDisplay
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Module).String
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).Equals
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).ForDisplay
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).HasKnownNamespace
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).IsBuiltIn
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).IsLegacy
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).IsZero
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).LegacyString
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).LessThan
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address.(*Provider).String
Source: terraform-ls.exeString found in binary or memory: type:.eq.github.com/hashicorp/terraform-registry-address.Provider
Source: terraform-ls.exeString found in binary or memory: type:.eq.github.com/hashicorp/terraform-registry-address.ModulePackage
Source: terraform-ls.exeString found in binary or memory: type:.eq.github.com/hashicorp/terraform-registry-address.Module
Source: terraform-ls.exeString found in binary or memory: type:.hash.github.com/hashicorp/terraform-registry-address.Provider
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-schema/internal/addr.NewBuiltInProvider
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-schema/internal/addr.NewDefaultProvider
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-schema/internal/addr.NewLegacyProvider
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete@v1.1.1/cmd/install/bash.go
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete@v1.1.1/cmd/install/fish.go
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete@v1.1.1/cmd/install/install.go
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete@v1.1.1/cmd/install/utils.go
Source: terraform-ls.exeString found in binary or memory: github.com/posener/complete@v1.1.1/cmd/install/zsh.go
Source: terraform-ls.exeString found in binary or memory: net/addrselect.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/hcl-lang@v0.0.0-20231107133629-c89603e93360/lang/address.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/hcl-lang@v0.0.0-20231107133629-c89603e93360/lang/address_steps.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/hcl-lang@v0.0.0-20231107133629-c89603e93360/schema/address.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address@v0.2.3/errors.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address@v0.2.3/module.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address@v0.2.3/module_package.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-registry-address@v0.2.3/provider.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-schema@v0.0.0-20231103135256-8af5a0749d10/internal/addr/addr.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-ls/internal/state/installed_providers.go
Source: terraform-ls.exeString found in binary or memory: github.com/hashicorp/terraform-schema@v0.0.0-20231103135256-8af5a0749d10/earlydecoder/load_module.go
Source: C:\Users\user\Desktop\terraform-ls.exeFile opened: C:\Windows\system32\2d506e4caa14e81d91d31ecdc5f40af2d1f2556ca4ebb8d729ea05fe54fcb9c3AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJump to behavior
Source: terraform-ls.exeBinary string: bindm in unexpected GOOSrunqsteal: runq overflowdouble traceGCSweepStartfloating point exceptionconnection reset by peerlevel 2 not synchronizedlink number out of rangeout of streams resourcesfunction not implementedstructure needs cleaningnot supported by windowsCertFreeCertificateChainCreateToolhelp32SnapshotGetUserProfileDirectoryWSA Pacific Standard TimeSA Eastern Standard TimeUS Eastern Standard TimeSA Western Standard TimeMontevideo Standard TimeMagallanes Standard TimePacific SA Standard TimeAzerbaijan Standard TimeBangladesh Standard TimeNorth Asia Standard TimeCape Verde Standard Timedoes not installed in %sexpected float; found %sgenSelfSignedCertWithKey@&%?,=[]_:-+*$#!'^~;()/.\Device\NamedPipe\cygwinfailed to parse path: %wunexpected priority: %#vfailed to copy a job: %wExecution of %q canceledexecution returned errorcancelling walk of %s...Server (pid %d) stopped.TCP server running at %qStarting loop server ...Incoming %s for %q%s: %sreceived candidates: %#vreceived hover data: %#vtextDocument/declarationworkspace/executeCommandinvalid tracestate valuejson: unsupported type: reflect.StructOf: field reflect.MapIter.SetValuereflect.Value.SetComplexreflect.Value.UnsafeAddr116415321826934814453125582076609134674072265625x509: malformed validityunexpected mantissa baseunexpected exponent baseRat.Scan: invalid syntaxinvalid argument to IntnInvalid Semantic VersionSetConsoleCursorPositionAllocateAndInitializeSidBuildSecurityDescriptorWAssignProcessToJobObjectGenerateConsoleCtrlEventGetMaximumProcessorCountGetNamedPipeHandleStateWSetDefaultDllDirectoriesNtQuerySystemInformationSetupDiCreateDeviceInfoWSetupDiGetSelectedDeviceSetupDiSetSelectedDeviceGetWindowThreadProcessIdschema file not readabledecodeProviderSchemaDataunexpected buffer len=%vinvalid pseudo-header %qframe_headers_prio_shortinvalid request :path %qread_frame_conn_error_%sapplication/octet-streamRequest Entity Too Largehttp: nil Request.Headerinvalid namespace %q: %sindex '%s' is not uniqueCall to unknown functionIncorrect condition typeInvalid block definitionInvalid 'for' expressioninvalid type descriptioncty.GetAttrStep{Name:%q}Length on non-tuple Typeunsupported attribute %qrefining %#v to be > %#vrefining %#v to be < %#vwrapVal is not a pointercty.CapsuleVal(%#v, %#v)NumberLowerBound for %#vNumberUpperBound for %#vLengthLowerBound for %#vLengthUpperBound for %#vexec: Stdout already setexec: Stderr already setvalidation output is niltabwriter: panic during unexpected label (%d) %q{
Source: classification engineClassification label: clean1.winEXE@2/0@0/0
Source: unknownProcess created: C:\Users\user\Desktop\terraform-ls.exe C:\Users\user\Desktop\terraform-ls.exe
Source: C:\Users\user\Desktop\terraform-ls.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6708:120:WilError_03
Source: terraform-ls.exeStatic file information: File size 24584880 > 1048576
Source: terraform-ls.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: terraform-ls.exeStatic PE information: certificate valid
Source: terraform-ls.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x6c9200
Source: terraform-ls.exeStatic PE information: Raw size of .rdata is bigger than: 0x100000 < 0xfe1a00
Source: terraform-ls.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: terraform-ls.exeStatic PE information: section name: .xdata
Source: terraform-ls.exeStatic PE information: section name: .symtab
Source: C:\Users\user\Desktop\terraform-ls.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: terraform-ls.exeBinary or memory string: DEPRECATED: Use the `prefix` option insteadA PEM-encoded private key, required if client_certificate_pem is specified.The remote backend hostname to connect to (defaults to `app.terraform.io`).Ignoring workspace folder %s: %s. This is most likely bug, please report it.data/registry.terraform.io/betterstackhq/better-uptime/0.3.20/schema.json.gzdata/registry.terraform.io/delphix-integrations/delphix/3.0.0/schema.json.gzdata/registry.terraform.io/netapp/netapp-cloudmanager/23.10.1/schema.json.gzdata/registry.terraform.io/paloaltonetworks/prismacloud/1.5.0/schema.json.gzdata/registry.terraform.io/shorelinesoftware/shoreline/1.14.8/schema.json.gzdata/registry.terraform.io/versa-networks/versadirector/0.0.1/schema.json.gzdata/registry.terraform.io/vmware/tanzu-mission-control/1.3.0/schema.json.gznon-empty IncludeNewlinesStack after parse with %d calls unaccounted for:
Source: terraform-ls.exeBinary or memory string: sync/atomic: swap of inconsistently typed value into ValueUnable to ignore path (unsupported or invalid URI): %s: %sjson: cannot set embedded pointer to unexported struct: %vcrypto/elliptic: ScalarMult was called on an invalid pointx509: failed to parse RSA private key embedded in PKCS#8: x509: provided PrivateKey doesn't match parent's PublicKeydata/registry.terraform.io/aviatrixsystems/aviatrix/3.1.3/data/registry.terraform.io/barracudanetworks/barracudawaf/data/registry.terraform.io/circonus-labs/circonus/0.12.15/data/registry.terraform.io/civo/civo/1.0.39/schema.json.gzdata/registry.terraform.io/cloudscale-ch/cloudscale/4.2.2/data/registry.terraform.io/dynatrace-oss/dynatrace/1.46.0/data/registry.terraform.io/elastic/ec/0.9.0/schema.json.gzdata/registry.terraform.io/fortinetdev/fortimanager/1.9.0/data/registry.terraform.io/honeycombio/honeycombio/0.18.2/data/registry.terraform.io/hpe/hpegl/0.3.19/schema.json.gzdata/registry.terraform.io/instaclustr/instaclustr/2.0.84/data/registry.terraform.io/ionos-cloud/profitbricks/1.6.5/data/registry.terraform.io/ionos-developer/ionosdeveloper/data/registry.terraform.io/jfrog/xray/2.0.2/schema.json.gzdata/registry.terraform.io/keeper-security/secretsmanager/data/registry.terraform.io/kentik/kentik-synthetics/0.2.1/data/registry.terraform.io/netskopeoss/netskopebwan/0.0.2/data/registry.terraform.io/nttcom/ecl/2.5.2/schema.json.gzdata/registry.terraform.io/nttcom/fic/0.5.6/schema.json.gzdata/registry.terraform.io/prefecthq/prefect/0.0.0-alpha5/data/registry.terraform.io/purestorage-openconnect/fusion/data/registry.terraform.io/rubrikinc/polaris/0.8.0-beta.4/data/registry.terraform.io/siderolabs/talos/0.4.0-alpha.0/data/registry.terraform.io/singlestore-labs/singlestoredb/data/registry.terraform.io/statuscakedev/statuscake/2.2.2/data/registry.terraform.io/tencentcloudstack/tencentcloud/data/registry.terraform.io/valtix-security/valtix/23.10.1/data/registry.terraform.io/vmware/vcf/0.5.0/schema.json.gzdata/registry.terraform.io/vmware/vra/0.8.3/schema.json.gzhttp2: client connection force closed via ClientConn.CloseGODEBUG=execwait=2 detected a leaked exec.Cmd created by:
Source: terraform-ls.exeBinary or memory string: internal error: call to fastSource.SeedRtlDosPathNameToNtPathName_U_WithStatusexpected directory name, got a path: %qdata/registry.terraform.io/a10networks/data/registry.terraform.io/bluecatlabs/data/registry.terraform.io/ciscodevnet/data/registry.terraform.io/clumio-code/data/registry.terraform.io/cockroachdb/data/registry.terraform.io/crunchydata/data/registry.terraform.io/dnsmadeeasy/data/registry.terraform.io/firehydrant/data/registry.terraform.io/fortinetdev/data/registry.terraform.io/honeycombio/data/registry.terraform.io/instaclustr/data/registry.terraform.io/ionos-cloud/data/registry.terraform.io/itglobalcom/data/registry.terraform.io/mypurecloud/data/registry.terraform.io/netskopeoss/data/registry.terraform.io/satoricyber/data/registry.terraform.io/syntropynet/data/registry.terraform.io/thalesgroup/data/registry.terraform.io/timeplus-io/data/registry.terraform.io/transloadit/data/registry.terraform.io/aiven/aiven/data/registry.terraform.io/ariga/atlas/data/registry.terraform.io/aruba/aoscx/data/registry.terraform.io/auth0/auth0/data/registry.terraform.io/azure/azapi/data/registry.terraform.io/azure/modtm/data/registry.terraform.io/buddy/buddy/data/registry.terraform.io/coder/coder/data/registry.terraform.io/dome9/dome9/data/registry.terraform.io/ilert/ilert/data/registry.terraform.io/koyeb/koyeb/data/registry.terraform.io/ngrok/ngrok/data/registry.terraform.io/nobl9/nobl9/data/registry.terraform.io/rancher/rke/data/registry.terraform.io/vmware/nsxt/data/registry.terraform.io/vmware/vcda/data/registry.terraform.io/vmware/vra7/data/registry.terraform.io/vultr/vultr/data/registry.terraform.io/zscaler/zia/data/registry.terraform.io/zscaler/zpa/http: putIdleConn: keep alives disabledinvalid HTTP header value for header %qusername/password authentication failedUnsuitable value for right operand: %s.Unsuitable value for unary operand: %s.Missing false expression in conditionalDot must be followed by attribute name.All %s blocks must have %d labels (%s).unsupported value type %#v in RawEqualscan't use ElementIterator on null valueexec: environment variable contains NULunable to parse provider version %q: %wnegative minwidth, tabwidth, or paddingIPv4 field must have at least one digitmissing type in dynamically-typed valuetls: unsupported certificate curve (%s)tls: internal error: wrong nonce lengthno mutually supported protocol versionschain is not signed by an acceptable CAinvalid indexed representation index %dpanic in function implementation: %s
Source: terraform-ls.exeBinary or memory string: ^(\s*(%s)\s*(%s)\s*)((?:\s+|,\s*)(%s)\s*(%s)\s*)*$data/registry.terraform.io/alertmixer/amixr/0.2.3/data/registry.terraform.io/alkiranet/alkira/1.1.0/data/registry.terraform.io/circonus-labs/circonus/data/registry.terraform.io/ciscodevnet/intersight/data/registry.terraform.io/ciscodevnet/aci/2.10.1/data/registry.terraform.io/ciscodevnet/cml2/0.6.2/data/registry.terraform.io/ciscodevnet/dcnm/1.2.7/data/registry.terraform.io/ciscodevnet/mso/0.11.1/data/registry.terraform.io/ciscodevnet/nxos/0.5.1/data/registry.terraform.io/codefresh-io/codefresh/data/registry.terraform.io/confluentinc/confluent/data/registry.terraform.io/consensys/quorum/0.3.0/data/registry.terraform.io/datadog/datadog/3.32.0/data/registry.terraform.io/enterprisedb/biganimal/data/registry.terraform.io/equinix/equinix/1.19.0/data/registry.terraform.io/gitlabhq/gitlab/16.5.0/data/registry.terraform.io/harness/harness/0.28.3/data/registry.terraform.io/hashicorp/awscc/0.63.0/data/registry.terraform.io/hashicorp/google/5.5.0/data/registry.terraform.io/hashicorp/random/3.5.1/data/registry.terraform.io/hashicorp/vault/3.22.0/data/registry.terraform.io/hewlettpackard/oneview/data/registry.terraform.io/ionos-cloud/ionoscloud/data/registry.terraform.io/nirmata/nirmata/1.1.13/data/registry.terraform.io/nullstone-io/ns/0.6.22/data/registry.terraform.io/paloaltonetworks/panos/data/registry.terraform.io/phoenixnap/pnap/0.22.0/data/registry.terraform.io/rancher/rancher2/3.2.0/data/registry.terraform.io/rollbar/rollbar/1.13.0/data/registry.terraform.io/splunk/artifacts/1.1.0/data/registry.terraform.io/splunk/victorops/0.1.4/data/registry.terraform.io/valtix-security/valtix/data/registry.terraform.io/vmware/wavefront/5.0.4/data/registry.terraform.io/zenlayer/zenlayercloud/net/http: cannot rewind body after connection losshttp: putIdleConn: CloseIdleConnections was calledgot CONTINUATION for stream %d; expected stream %dhttp: suspiciously long trailer after chunked bodynet/http: Transport failed to read from server: %vnet/http: HTTP/1.x transport connection broken: %wmust be between one and 64 ASCII letters or digitsgo.opentelemetry.io/otel/instrumentation/httptraceThis map does not have an element with the key %q.ExpandFinal set on function call with no argumentsThe key expression produced an invalid result: %s.For expression requires variable name after 'for'.Key expression is not valid when building a tuple.Expected an attribute access or an index operator.Terraform cannot be initialised with empty workdircannot unmarshal UserData from search response: %vedwards25519: invalid SetUniformBytes input lengthtls: received unexpected CertificateStatus messagetls: invalid signature by the server certificate: element types must all match for conversion to mapelement types must all match for conversion to setRun the provisioner when the resource is destroyed`tobool` converts its argument to a boolean value.TableStore table for state locking and consistencynot a valid RFC3339 timestamp: cannot use %q as %s
Source: terraform-ls.exe, 00000000.00000002.2109914764.000001D13959C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid Accounts2
Command and Scripting Interpreter
Path Interception1
Process Injection
1
Process Injection
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataSIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1340442 Sample: terraform-ls.exe Startdate: 10/11/2023 Architecture: WINDOWS Score: 1 5 terraform-ls.exe 1 2->5         started        process3 7 conhost.exe 5->7         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
terraform-ls.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://pkg.go.dev/embed0%Avira URL Cloudsafe
https://registry.terraform.io%s:0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://passlib.readthedocs.io/en/stable/modular_crypt_format.html)terraform-ls.exefalse
    high
    https://registry.terraform.io%s:terraform-ls.exefalse
    • Avira URL Cloud: safe
    low
    https://intl.cloud.tencent.com/document/product/598/10603).terraform-ls.exefalse
      high
      https://pkg.go.dev/embedterraform-ls.exefalse
      • Avira URL Cloud: safe
      unknown
      https://kubernetes.io/docs/reference/access-authn-authz/authentication/#client-go-credential-pluginsterraform-ls.exefalse
        high
        https://tools.ietf.org/html/rfc3339)terraform-ls.exefalse
          high
          https://unicode.org/reports/tr29/#Grapheme_Cluster_Boundaries)terraform-ls.exefalse
            high
            http://the.earth.li/~sgtatham/putty/0.66/htmldoc/Chapter9.html#pageant).allterraform-ls.exefalse
              high
              https://registry.terraform.io/providers/%s/%s/%s/docsFailedterraform-ls.exefalse
                high
                https://tools.ietf.org/html/rfc4632#section-3.1).terraform-ls.exefalse
                  high
                  https://cloud.google.com/storage/docs/json_api/v1/buckets/get#http-request)).Ifterraform-ls.exefalse
                    high
                    https://tools.ietf.org/html/rfc4122#section-4.3)terraform-ls.exefalse
                      high
                      No contacted IP infos
                      Joe Sandbox Version:38.0.0 Ammolite
                      Analysis ID:1340442
                      Start date and time:2023-11-10 09:57:02 +01:00
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 2m 24s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:3
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample file name:terraform-ls.exe
                      Detection:CLEAN
                      Classification:clean1.winEXE@2/0@0/0
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Stop behavior analysis, all processes terminated
                      • Exclude process from analysis (whitelisted): dllhost.exe
                      • Excluded domains from analysis (whitelisted): client.wns.windows.com
                      • Not all processes where analyzed, report is missing behavior information
                      • VT rate limit hit for: terraform-ls.exe
                      No simulations
                      No context
                      No context
                      No context
                      No context
                      No context
                      No created / dropped files found
                      File type:PE32+ executable (console) x86-64, for MS Windows
                      Entropy (8bit):7.187828500788254
                      TrID:
                      • Win64 Executable Console (202006/5) 92.65%
                      • Win64 Executable (generic) (12005/4) 5.51%
                      • Generic Win/DOS Executable (2004/3) 0.92%
                      • DOS Executable Generic (2002/1) 0.92%
                      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                      File name:terraform-ls.exe
                      File size:24'584'880 bytes
                      MD5:8a26932d0bf750242cc86a9b29e4d190
                      SHA1:ab3fafbb67203bd56b68161b4fb39aef6b665d8e
                      SHA256:7220f6ced1c530e3d7af9ef8062c56afc8718495ac429bf22e846be163daec1d
                      SHA512:be8e16f78b9130f7dd5cf1d2dbe65d72eb15ab0583c5bc12d32cd01664d66dddff2e5cdbef6ec92078408061349acd6f96bf5c2c68090eeb50c7243fcaf42841
                      SSDEEP:393216:HQZ6CIp372jvgaSkvSH1hvKqmZZwMzcn35gCowoqIFIlbtpCLqT8S:HQGpr2jvyka0ZiMzTCfoqrbpCL4F
                      TLSH:F6479D07E86581A4C0AEE534C9B6D223BB717C494B3423D76BA0F7643E77BE0667A740
                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........v.......".......l..6................@...............................}.....;.w...`... ............................
                      Icon Hash:00928e8e8686b000
                      Entrypoint:0x46fba0
                      Entrypoint Section:.text
                      Digitally signed:true
                      Imagebase:0x400000
                      Subsystem:windows cui
                      Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                      DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                      Time Stamp:0x0 [Thu Jan 1 00:00:00 1970 UTC]
                      TLS Callbacks:
                      CLR (.Net) Version:
                      OS Version Major:6
                      OS Version Minor:1
                      File Version Major:6
                      File Version Minor:1
                      Subsystem Version Major:6
                      Subsystem Version Minor:1
                      Import Hash:ea509d361799935a94335b88f534a970
                      Signature Valid:true
                      Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                      Signature Validation Error:The operation completed successfully
                      Error Number:0
                      Not Before, Not After
                      • 10/01/2023 01:00:00 10/01/2026 00:59:59
                      Subject Chain
                      • CN="HashiCorp, Inc.", OU=HashiCorp Security, O="HashiCorp, Inc.", L=San Francisco, S=California, C=US
                      Version:3
                      Thumbprint MD5:FA839AEA713AC65409D9B5CDB665E59B
                      Thumbprint SHA-1:7868E4F55FD7B047CD8BF93FEA8C38509CFB5939
                      Thumbprint SHA-256:0F3E822C8907D52A1A7DCCDD6EFC6626270187FDB263E50BFC37AA2515F4CEA8
                      Serial:0B26FB4E1C1A6BC3264602189258449D
                      Instruction
                      jmp 00007FB1E04E4D00h
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      int3
                      pushfd
                      cld
                      dec eax
                      sub esp, 000000E0h
                      dec eax
                      mov dword ptr [esp], edi
                      dec eax
                      mov dword ptr [esp+08h], esi
                      dec eax
                      mov dword ptr [esp+10h], ebp
                      dec eax
                      mov dword ptr [esp+18h], ebx
                      dec esp
                      mov dword ptr [esp+20h], esp
                      dec esp
                      mov dword ptr [esp+28h], ebp
                      dec esp
                      mov dword ptr [esp+30h], esi
                      dec esp
                      mov dword ptr [esp+38h], edi
                      movups dqword ptr [esp+40h], xmm6
                      movups dqword ptr [esp+50h], xmm7
                      inc esp
                      movups dqword ptr [esp+60h], xmm0
                      inc esp
                      movups dqword ptr [esp+70h], xmm1
                      inc esp
                      movups dqword ptr [esp+00000080h], xmm2
                      inc esp
                      movups dqword ptr [esp+00000090h], xmm3
                      inc esp
                      movups dqword ptr [esp+000000A0h], xmm4
                      inc esp
                      movups dqword ptr [esp+000000B0h], xmm5
                      inc esp
                      movups dqword ptr [esp+000000C0h], xmm6
                      inc esp
                      movups dqword ptr [esp+000000D0h], xmm7
                      inc ebp
                      xorps xmm7, xmm7
                      dec ebp
                      xor esi, esi
                      dec eax
                      mov eax, dword ptr [0171A41Eh]
                      dec eax
                      mov eax, dword ptr [eax]
                      dec eax
                      cmp eax, 00000000h
                      je 00007FB1E04E8625h
                      dec esp
                      mov esi, dword ptr [eax]
                      dec eax
                      sub esp, 10h
                      dec eax
                      mov eax, ecx
                      dec eax
                      mov ebx, edx
                      call 00007FB1E04C9F1Fh
                      dec eax
                      NameVirtual AddressVirtual Size Is in Section
                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IMPORT0x17bf0000x552.idata
                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x17990000x2433c.pdata
                      IMAGE_DIRECTORY_ENTRY_SECURITY0x17700000x22b0.data
                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x17c00000x1c818.reloc
                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IAT0x16ae7600x180.data
                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                      NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                      .text0x10000x6c903b0x6c9200unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      .rdata0x6cb0000xfe18a80xfe1a00unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .data0x16ad0000xeb5900x83600False0.30081841698382494data5.360339280001104IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .pdata0x17990000x2433c0x24400False0.40272090517241377data5.835038424198755IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .xdata0x17be0000xa80x200False0.19921875data1.6345075234569126IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .idata0x17bf0000x5520x600False0.375data4.201250632238315IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .reloc0x17c00000x1c8180x1ca00False0.20346615720524017data5.441121324055091IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      .symtab0x17dd0000x40x200False0.02734375data0.020393135236084953IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      DLLImport
                      kernel32.dllWriteFile, WriteConsoleW, WerSetFlags, WerGetFlags, WaitForMultipleObjects, WaitForSingleObject, VirtualQuery, VirtualFree, VirtualAlloc, TlsAlloc, SwitchToThread, SuspendThread, SetWaitableTimer, SetUnhandledExceptionFilter, SetThreadPriority, SetProcessPriorityBoost, SetEvent, SetErrorMode, SetConsoleCtrlHandler, ResumeThread, RaiseFailFastException, PostQueuedCompletionStatus, LoadLibraryW, LoadLibraryExW, SetThreadContext, GetThreadContext, GetSystemInfo, GetSystemDirectoryA, GetStdHandle, GetQueuedCompletionStatusEx, GetProcessAffinityMask, GetProcAddress, GetErrorMode, GetEnvironmentStringsW, GetCurrentThreadId, GetConsoleMode, FreeEnvironmentStringsW, ExitProcess, DuplicateHandle, CreateWaitableTimerExW, CreateWaitableTimerA, CreateThread, CreateIoCompletionPort, CreateFileA, CreateEventA, CloseHandle, AddVectoredExceptionHandler
                      No network behavior found
                      0246810s020406080100

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:09:57:51
                      Start date:10/11/2023
                      Path:C:\Users\user\Desktop\terraform-ls.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Users\user\Desktop\terraform-ls.exe
                      Imagebase:0x9a0000
                      File size:24'584'880 bytes
                      MD5 hash:8A26932D0BF750242CC86A9B29E4D190
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:Go lang
                      Reputation:low
                      Has exited:true

                      Target ID:2
                      Start time:09:57:52
                      Start date:10/11/2023
                      Path:C:\Windows\System32\conhost.exe
                      Wow64 process (32bit):false
                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Imagebase:0x7ff66e660000
                      File size:862'208 bytes
                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:high
                      Has exited:true

                      No disassembly