| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 17:52:25 | 2026-05-28 17:55:47 | 202s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 17:51:56,420 [root] INFO: Date set to: 20260528T17:52:30, timeout set to: 200
2026-05-28 17:52:30,024 [root] DEBUG: Starting analyzer from: C:\mtfrhoy9
2026-05-28 17:52:30,024 [root] DEBUG: Storing results at: C:\LJDkwoHS
2026-05-28 17:52:30,024 [root] DEBUG: Pipe server name: \\.\PIPE\cVTwrG
2026-05-28 17:52:30,025 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 17:52:30,025 [root] INFO: analysis running as an admin
2026-05-28 17:52:30,025 [root] INFO: analysis package specified: "edge"
2026-05-28 17:52:30,025 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 17:52:30,027 [root] DEBUG: imported analysis package "edge"
2026-05-28 17:52:30,027 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 17:52:30,027 [root] DEBUG: New location of moved file: https://sugarcraft.net/
2026-05-28 17:52:30,027 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 17:52:30,027 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 17:52:30,028 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 17:52:30,028 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 17:52:30,050 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 17:52:30,071 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 17:52:30,078 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 17:52:30,086 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 17:52:30,095 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 17:52:30,102 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 17:52:30,102 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 17:52:30,105 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 17:52:30,105 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 17:52:30,105 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 17:52:30,106 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 17:52:30,107 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 17:52:30,107 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 17:52:30,107 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 17:52:30,108 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 17:52:30,108 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 17:52:30,108 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 17:52:30,108 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 17:52:30,108 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 17:52:30,109 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 17:52:30,109 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 17:52:30,110 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 17:52:30,110 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 17:52:30,112 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 7912)
2026-05-28 17:52:30,113 [modules.auxiliary.disguise] INFO: Disguising GUID to 0d1ed887-b65b-4405-858b-42ac1fe0c1d4
2026-05-28 17:52:30,118 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 17:52:30,118 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 17:52:30,119 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 17:52:30,119 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 17:52:30,119 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 17:52:30,120 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 17:52:30,120 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 17:52:30,121 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 17:52:30,121 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 17:52:30,121 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 17:52:30,123 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 17:52:30,123 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 17:52:30,124 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 17:52:30,125 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 17:52:30,125 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 17:52:30,126 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 17:52:30,129 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 17:52:30,130 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 17:52:30,130 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 17:52:30,211 [lib.api.process] INFO: Monitor config for process 4584: C:\mtfrhoy9\dll\4584.ini
2026-05-28 17:52:30,213 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:30,216 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:30,295 [root] DEBUG: Loader: Injecting process 4584 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:30,470 [root] DEBUG: 4584: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:30,477 [root] DEBUG: 4584: Disabling sleep skipping.
2026-05-28 17:52:30,486 [root] DEBUG: 4584: Interactive desktop enabled.
2026-05-28 17:52:30,492 [root] DEBUG: 4584: Dropped file limit defaulting to 100.
2026-05-28 17:52:30,494 [root] DEBUG: 4584: Interactive desktop - injecting Explorer Shell
2026-05-28 17:52:30,523 [root] DEBUG: 4584: YaraInit: Compiled 44 rule files
2026-05-28 17:52:30,525 [root] DEBUG: 4584: YaraInit: Compiled rules saved to file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:52:30,571 [root] DEBUG: 4584: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:52:30,585 [root] DEBUG: 4584: YaraScan: Scanning 0x00007FF65E010000, size 0x545316
2026-05-28 17:52:30,721 [root] DEBUG: 4584: Monitor initialised: 64-bit capemon loaded in process 4584 at 0x00007FFC37E40000, thread 7996, image base 0x00007FF65E010000, stack from 0x000000000F4E1000-0x000000000F4F0000
2026-05-28 17:52:30,722 [root] DEBUG: 4584: Commandline: C:\Windows\Explorer.EXE
2026-05-28 17:52:30,734 [root] DEBUG: 4584: Hooked 69 out of 69 functions
2026-05-28 17:52:30,765 [root] DEBUG: 4584: Syscall hook installed, syscall logging level 1
2026-05-28 17:52:30,773 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:52:30,774 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:30,775 [lib.api.process] INFO: Injected into 64-bit <Process 4584 explorer.exe>
2026-05-28 17:52:30,797 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5B090000: C:\Windows\SYSTEM32\UIAutomationCore (0x2f5000 bytes).
2026-05-28 17:52:30,805 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC71000, size: 0x1000.
2026-05-28 17:52:30,891 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC61000, size: 0x1000.
2026-05-28 17:52:30,892 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC51000, size: 0x1000.
2026-05-28 17:52:30,900 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC41000, size: 0x1000.
2026-05-28 17:52:31,145 [root] DEBUG: 4584: caller_dispatch: Added region at 0x00007FF65E010000 to tracked regions list (ntdll::NtDuplicateObject returns to 0x00007FF65E1ED17E, thread 4668).
2026-05-28 17:52:31,146 [root] DEBUG: 4584: YaraScan: Scanning 0x00007FF65E010000, size 0x545316
2026-05-28 17:52:31,184 [root] DEBUG: 4584: ProcessImageBase: Main module image at 0x00007FF65E010000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:52:33,339 [root] DEBUG: 4584: DLL loaded at 0x00007FFC67CF0000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-28 17:52:33,341 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6AB00000: C:\Windows\system32\WindowsInternal.ComposableShell.DesktopHosting (0x2e000 bytes).
2026-05-28 17:52:33,344 [root] DEBUG: 4584: DLL loaded at 0x00007FFC36BA0000: C:\Windows\ShellComponents\WindowsInternal.ComposableShell.Experiences.Switcher (0x24d000 bytes).
2026-05-28 17:52:33,348 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6AA80000: C:\Windows\ShellExperiences\TileControl (0x7d000 bytes).
2026-05-28 17:52:33,353 [root] DEBUG: 4584: DLL loaded at 0x00007FFC36980000: C:\Windows\ShellComponents\TaskFlowUI (0x215000 bytes).
2026-05-28 17:52:33,370 [root] DEBUG: 4584: DLL loaded at 0x00007FFC628B0000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-28 17:52:33,374 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC31000, size: 0x1000.
2026-05-28 17:52:33,737 [lib.api.process] INFO: Monitor config for process 740: C:\mtfrhoy9\dll\740.ini
2026-05-28 17:52:33,915 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:33,957 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:33,966 [root] DEBUG: Loader: Injecting process 740 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:33,970 [root] DEBUG: 740: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:33,971 [root] DEBUG: 740: Disabling sleep skipping.
2026-05-28 17:52:33,971 [root] DEBUG: 740: Interactive desktop enabled.
2026-05-28 17:52:33,972 [root] DEBUG: 740: Dropped file limit defaulting to 100.
2026-05-28 17:52:33,973 [root] DEBUG: 740: Services hook set enabled
2026-05-28 17:52:33,977 [root] DEBUG: 740: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:52:34,134 [root] DEBUG: 740: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:52:34,136 [root] DEBUG: 740: Monitor initialised: 64-bit capemon loaded in process 740 at 0x00007FFC37E40000, thread 1768, image base 0x00007FF780360000, stack from 0x000000754D074000-0x000000754D080000
2026-05-28 17:52:34,137 [root] DEBUG: 740: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 17:52:34,173 [root] DEBUG: 740: Hooked 69 out of 69 functions
2026-05-28 17:52:34,182 [root] INFO: Loaded monitor into process with pid 740
2026-05-28 17:52:34,189 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:52:34,202 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:34,205 [lib.api.process] INFO: Injected into 64-bit <Process 740 svchost.exe>
2026-05-28 17:52:36,280 [root] DEBUG: 4584: DLL loaded at 0x00007FFC68DC0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 17:52:36,286 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6B960000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes).
2026-05-28 17:52:36,316 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 3336: C:\Windows\ImmersiveControlPanel\SystemSettings.exe, ImageBase: 0x00007FF68FA00000
2026-05-28 17:52:36,319 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 3128: C:\Windows\system32\ApplicationFrameHost.exe, ImageBase: 0x00007FF7EECE0000
2026-05-28 17:52:36,320 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 3336
2026-05-28 17:52:36,321 [lib.api.process] INFO: Monitor config for process 3336: C:\mtfrhoy9\dll\3336.ini
2026-05-28 17:52:36,321 [root] INFO: Announced 64-bit process name: ApplicationFrameHost.exe pid: 3128
2026-05-28 17:52:36,322 [lib.api.process] INFO: Monitor config for process 3128: C:\mtfrhoy9\dll\3128.ini
2026-05-28 17:52:36,323 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:36,324 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:36,345 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:36,382 [root] DEBUG: 4584: DLL loaded at 0x00007FFC60E20000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 17:52:36,405 [root] DEBUG: Loader: Injecting process 3128 (thread 3328) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:36,440 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:52:36,454 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:36,466 [root] INFO: Announced starting service "b'Winmgmt'"
2026-05-28 17:52:36,471 [lib.api.process] INFO: Monitor config for process 592: C:\mtfrhoy9\dll\592.ini
2026-05-28 17:52:36,472 [lib.api.process] INFO: Injected into 64-bit <Process 3128 ApplicationFrameHost.exe>
2026-05-28 17:52:36,481 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:36,481 [root] INFO: Announced 64-bit process name: ApplicationFrameHost.exe pid: 3128
2026-05-28 17:52:36,482 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:36,482 [lib.api.process] INFO: Monitor config for process 3128: C:\mtfrhoy9\dll\3128.ini
2026-05-28 17:52:36,484 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:36,486 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:36,495 [root] DEBUG: Loader: Injecting process 3128 (thread 3328) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:36,496 [root] DEBUG: Loader: Injecting process 592 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:36,502 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:52:36,510 [root] DEBUG: Loader: Copied config file C:\mtfrhoy9\dll\592.ini to system path C:\592.ini
2026-05-28 17:52:36,514 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:36,515 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 592 C:\mtfrhoy9\dll\WqtqHcg.dll
2026-05-28 17:52:36,521 [lib.api.process] INFO: Injected into 64-bit <Process 3128 ApplicationFrameHost.exe>
2026-05-28 17:52:36,522 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:36,525 [lib.api.process] INFO: Injected into 64-bit <Process 592 services.exe>
2026-05-28 17:52:36,593 [root] DEBUG: 3128: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:36,595 [root] DEBUG: 3128: Interactive desktop enabled.
2026-05-28 17:52:36,596 [root] DEBUG: 3128: Dropped file limit defaulting to 100.
2026-05-28 17:52:36,606 [root] DEBUG: 3128: Disabling sleep skipping.
2026-05-28 17:52:36,608 [root] DEBUG: 3128: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:52:36,622 [root] DEBUG: 3128: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:52:36,622 [root] DEBUG: 3128: YaraScan: Scanning 0x00007FF7EECE0000, size 0x14222
2026-05-28 17:52:36,624 [root] DEBUG: 3128: Monitor initialised: 64-bit capemon loaded in process 3128 at 0x00007FFC37E40000, thread 3328, image base 0x00007FF7EECE0000, stack from 0x0000009F735E4000-0x0000009F735F0000
2026-05-28 17:52:36,627 [root] DEBUG: 3128: Commandline: C:\Windows\system32\ApplicationFrameHost.exe -Embedding
2026-05-28 17:52:36,637 [root] DEBUG: 3128: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:52:36,671 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:52:36,672 [root] DEBUG: 3128: set_hooks: Unable to hook LockResource
2026-05-28 17:52:36,681 [root] DEBUG: 3128: Hooked 627 out of 628 functions
2026-05-28 17:52:36,682 [root] DEBUG: 3128: Syscall hook installed, syscall logging level 1
2026-05-28 17:52:36,687 [root] DEBUG: 3128: RestoreHeaders: Restored original import table.
2026-05-28 17:52:36,689 [root] INFO: Loaded monitor into process with pid 3128
2026-05-28 17:52:36,697 [root] DEBUG: 3128: caller_dispatch: Added region at 0x00007FF7EECE0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7EECE2DE1, thread 3328).
2026-05-28 17:52:36,698 [root] DEBUG: 3128: YaraScan: Scanning 0x00007FF7EECE0000, size 0x14222
2026-05-28 17:52:36,700 [root] DEBUG: 3128: ProcessImageBase: Main module image at 0x00007FF7EECE0000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:52:36,702 [root] DEBUG: 3128: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:52:36,703 [root] DEBUG: 3128: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:52:36,705 [root] DEBUG: 3128: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:52:36,714 [root] DEBUG: 3128: DLL loaded at 0x00007FFC728F0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 17:52:36,715 [root] DEBUG: 3128: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 17:52:36,715 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 17:52:36,716 [root] DEBUG: 3128: DLL loaded at 0x00007FFC730A0000: C:\Windows\System32\UxTheme (0x9e000 bytes).
2026-05-28 17:52:36,716 [root] DEBUG: 3128: DLL loaded at 0x00007FFC75F50000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 17:52:36,717 [root] DEBUG: 3128: DLL loaded at 0x00007FFC753D0000: C:\Windows\System32\DEVOBJ (0x33000 bytes).
2026-05-28 17:52:36,718 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6A6C0000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 17:52:36,720 [root] DEBUG: 3128: DLL loaded at 0x00007FFC60C70000: C:\Windows\System32\TWINAPI (0xa9000 bytes).
2026-05-28 17:52:36,721 [root] DEBUG: 3128: DLL loaded at 0x00007FFC71900000: C:\Windows\System32\d2d1 (0x5c0000 bytes).
2026-05-28 17:52:36,722 [root] DEBUG: 3128: DLL loaded at 0x00007FFC71690000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 17:52:36,727 [root] DEBUG: 3128: DLL loaded at 0x00007FFC73480000: C:\Windows\System32\dwmapi (0x2f000 bytes).
2026-05-28 17:52:36,729 [root] DEBUG: 3128: DLL loaded at 0x00007FFC5E6C0000: C:\Windows\System32\ApplicationFrame (0xa9000 bytes).
2026-05-28 17:52:36,758 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6F400000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 17:52:36,767 [root] DEBUG: 3128: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 17:52:36,772 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6E3B0000: C:\Windows\system32\D3D10Warp (0x6f6000 bytes).
2026-05-28 17:52:36,776 [root] DEBUG: 3128: DLL loaded at 0x00007FFC731A0000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 17:52:36,787 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6E370000: C:\Windows\SYSTEM32\dxcore (0x3b000 bytes).
2026-05-28 17:52:36,792 [root] DEBUG: 3128: DLL loaded at 0x00007FFC72020000: C:\Windows\System32\dcomp (0x1e3000 bytes).
2026-05-28 17:52:36,794 [root] DEBUG: 3128: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 17:52:36,811 [root] DEBUG: 3128: DLL loaded at 0x00007FFC5B090000: C:\Windows\system32\UIAutomationCore (0x2f5000 bytes).
2026-05-28 17:52:36,849 [root] DEBUG: 3128: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C01E1000, size: 0x1000.
2026-05-28 17:52:36,874 [root] DEBUG: 3128: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C01D1000, size: 0x1000.
2026-05-28 17:52:36,875 [root] DEBUG: 3128: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C01C1000, size: 0x1000.
2026-05-28 17:52:36,883 [root] DEBUG: 3128: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C01B1000, size: 0x1000.
2026-05-28 17:52:36,908 [root] DEBUG: 3128: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 17:52:36,915 [root] DEBUG: 3128: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 17:52:36,923 [root] DEBUG: 3128: DLL loaded at 0x00007FFC755E0000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 17:52:36,932 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6A6A0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 17:52:36,942 [root] DEBUG: 3128: DLL loaded at 0x00007FFC701E0000: C:\Windows\system32\windowscodecs (0x1b4000 bytes).
2026-05-28 17:52:36,950 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6A120000: C:\Windows\SYSTEM32\mrmcorer (0xf4000 bytes).
2026-05-28 17:52:36,956 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6B370000: C:\Windows\SYSTEM32\iertutil (0x2bc000 bytes).
2026-05-28 17:52:36,967 [root] DEBUG: 3128: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 17:52:36,970 [root] DEBUG: 3128: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 17:52:36,971 [root] DEBUG: 3128: DLL loaded at 0x00007FFC70130000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 17:52:36,972 [root] DEBUG: 3128: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:52:36,974 [root] DEBUG: 3128: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 17:52:36,974 [root] DEBUG: 3128: DLL loaded at 0x00007FFC69D70000: C:\Windows\System32\TextInputFramework (0xf9000 bytes).
2026-05-28 17:52:36,975 [root] DEBUG: 3128: DLL loaded at 0x00007FFC69E70000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 17:52:36,976 [root] DEBUG: 3128: DLL loaded at 0x00007FFC69FD0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 17:52:37,001 [root] DEBUG: 3128: DLL loaded at 0x00007FFC66930000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 17:52:37,013 [root] DEBUG: 3128: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C01A1000, size: 0x1000.
2026-05-28 17:52:37,312 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:37,335 [root] DEBUG: Loader: Injecting process 3336 (thread 3220) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:37,336 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:52:37,338 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:37,339 [lib.api.process] INFO: Injected into 64-bit <Process 3336 SystemSettings.exe>
2026-05-28 17:52:37,343 [root] DEBUG: 740: DLL loaded at 0x00007FFC72EF0000: C:\Windows\system32\apphelp (0x90000 bytes).
2026-05-28 17:52:37,344 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 3336
2026-05-28 17:52:37,345 [lib.api.process] INFO: Monitor config for process 3336: C:\mtfrhoy9\dll\3336.ini
2026-05-28 17:52:37,345 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:37,409 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:37,413 [root] DEBUG: Loader: Injecting process 3336 (thread 3220) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:37,414 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:52:37,414 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:37,415 [lib.api.process] INFO: Injected into 64-bit <Process 3336 SystemSettings.exe>
2026-05-28 17:52:37,416 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 3336
2026-05-28 17:52:37,416 [lib.api.process] INFO: Monitor config for process 3336: C:\mtfrhoy9\dll\3336.ini
2026-05-28 17:52:37,417 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:37,481 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:37,485 [root] DEBUG: Loader: Injecting process 3336 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:37,486 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 3220, handle 0xec
2026-05-28 17:52:37,486 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:52:37,487 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:37,488 [lib.api.process] INFO: Injected into 64-bit <Process 3336 SystemSettings.exe>
2026-05-28 17:52:37,604 [root] DEBUG: 3336: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:37,605 [root] DEBUG: 3336: Interactive desktop enabled.
2026-05-28 17:52:37,605 [root] DEBUG: 3336: Dropped file limit defaulting to 100.
2026-05-28 17:52:37,607 [root] DEBUG: 3336: Disabling sleep skipping.
2026-05-28 17:52:37,608 [root] DEBUG: 3336: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:52:37,619 [root] DEBUG: 3336: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:52:37,619 [root] DEBUG: 3336: YaraScan: Scanning 0x00007FF68FA00000, size 0x1903c
2026-05-28 17:52:37,620 [root] DEBUG: 3336: Monitor initialised: 64-bit capemon loaded in process 3336 at 0x00007FFC37E40000, thread 3220, image base 0x00007FF68FA00000, stack from 0x000000FA83284000-0x000000FA83290000
2026-05-28 17:52:37,621 [root] DEBUG: 3336: Commandline: "C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
2026-05-28 17:52:37,630 [root] DEBUG: 3336: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:52:37,652 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:52:37,652 [root] DEBUG: 3336: set_hooks: Unable to hook LockResource
2026-05-28 17:52:37,658 [root] DEBUG: 3336: Hooked 627 out of 628 functions
2026-05-28 17:52:37,659 [root] DEBUG: 3336: Syscall hook installed, syscall logging level 1
2026-05-28 17:52:37,665 [root] DEBUG: 3336: RestoreHeaders: Restored original import table.
2026-05-28 17:52:37,665 [root] INFO: Loaded monitor into process with pid 3336
2026-05-28 17:52:37,666 [root] DEBUG: 3336: caller_dispatch: Added region at 0x00007FF68FA00000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF68FA043D1, thread 3220).
2026-05-28 17:52:37,667 [root] DEBUG: 3336: YaraScan: Scanning 0x00007FF68FA00000, size 0x1903c
2026-05-28 17:52:37,668 [root] DEBUG: 3336: ProcessImageBase: Main module image at 0x00007FF68FA00000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:52:37,670 [root] DEBUG: 3336: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:52:37,670 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:52:37,673 [root] DEBUG: 3336: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:52:37,677 [root] DEBUG: 3336: DLL loaded at 0x00007FFC729F0000: C:\Windows\SYSTEM32\CoreMessaging (0xf2000 bytes).
2026-05-28 17:52:37,677 [root] DEBUG: 3336: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:52:37,678 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A640000: C:\Windows\SYSTEM32\Bcp47Langs (0x5b000 bytes).
2026-05-28 17:52:37,678 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6B370000: C:\Windows\SYSTEM32\iertutil (0x2bc000 bytes).
2026-05-28 17:52:37,679 [root] DEBUG: 3336: DLL loaded at 0x00007FFC72020000: C:\Windows\SYSTEM32\dcomp (0x1e3000 bytes).
2026-05-28 17:52:37,679 [root] DEBUG: 3336: DLL loaded at 0x00007FFC67CF0000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-28 17:52:37,681 [root] DEBUG: 3336: DLL loaded at 0x00007FFC61E00000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\Comctl32 (0x29a000 bytes).
2026-05-28 17:52:37,685 [root] DEBUG: 3336: DLL loaded at 0x00007FFC747D0000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 17:52:37,686 [root] DEBUG: 3336: DLL loaded at 0x00007FFC74B80000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 17:52:37,686 [root] DEBUG: 3336: DLL loaded at 0x00007FFC728F0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 17:52:37,687 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A120000: C:\Windows\SYSTEM32\MrmCoreR (0xf4000 bytes).
2026-05-28 17:52:37,687 [root] DEBUG: 3336: DLL loaded at 0x00007FFC71900000: C:\Windows\SYSTEM32\d2d1 (0x5c0000 bytes).
2026-05-28 17:52:37,688 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 17:52:37,688 [root] DEBUG: 3336: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 17:52:37,688 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A260000: C:\Windows\SYSTEM32\wincorlib (0x6f000 bytes).
2026-05-28 17:52:37,689 [root] DEBUG: 3336: DLL loaded at 0x00007FFC741C0000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 17:52:37,689 [root] DEBUG: 3336: DLL loaded at 0x00007FFC741F0000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-05-28 17:52:37,690 [root] DEBUG: 3336: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 17:52:37,690 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 17:52:37,691 [root] DEBUG: 3336: DLL loaded at 0x00007FFC36DF0000: C:\Windows\SYSTEM32\WinLangdb (0x34000 bytes).
2026-05-28 17:52:37,693 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 17:52:37,693 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6AA20000: C:\Windows\SYSTEM32\elscore (0x19000 bytes).
2026-05-28 17:52:37,694 [root] DEBUG: 3336: DLL loaded at 0x000002B892500000: C:\Windows\ImmersiveControlPanel\SystemSettings (0x5fb000 bytes).
2026-05-28 17:52:37,696 [root] DEBUG: 3336: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 17:52:37,700 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A6A0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 17:52:37,704 [root] DEBUG: 3336: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 17:52:37,704 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6FF20000: C:\Windows\SYSTEM32\twinapi.appcore (0x203000 bytes).
2026-05-28 17:52:37,705 [root] DEBUG: 3336: DLL loaded at 0x00007FFC70130000: C:\Windows\SYSTEM32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 17:52:37,705 [root] DEBUG: 3336: DLL loaded at 0x00007FFC72590000: C:\Windows\SYSTEM32\CoreUIComponents (0x35b000 bytes).
2026-05-28 17:52:37,706 [root] DEBUG: 3336: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\TextInputFramework (0xf9000 bytes).
2026-05-28 17:52:37,706 [root] DEBUG: 3336: DLL loaded at 0x00007FFC69E70000: C:\Windows\SYSTEM32\InputHost (0x152000 bytes).
2026-05-28 17:52:37,706 [root] DEBUG: 3336: DLL loaded at 0x00007FFC69FD0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 17:52:37,711 [root] DEBUG: 3336: DLL loaded at 0x00007FFC69D20000: C:\Windows\SYSTEM32\languageoverlayutil (0x41000 bytes).
2026-05-28 17:52:37,715 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A6C0000: C:\Windows\SYSTEM32\bcp47mrm (0x2d000 bytes).
2026-05-28 17:52:37,717 [root] DEBUG: 3336: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 17:52:37,746 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6F400000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 17:52:37,755 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6B340000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 17:52:37,757 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6C2E0000: C:\Windows\SYSTEM32\urlmon (0x1ed000 bytes).
2026-05-28 17:52:37,762 [root] DEBUG: 3336: DLL loaded at 0x00007FFC73F70000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 17:52:37,765 [root] DEBUG: 3336: DLL loaded at 0x00007FFC731A0000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 17:52:37,768 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A9F0000: C:\Windows\ImmersiveControlPanel\Telemetry.Common (0x12000 bytes).
2026-05-28 17:52:37,771 [root] DEBUG: 3336: DLL loaded at 0x00007FFC71690000: C:\Windows\SYSTEM32\d3d11 (0x263000 bytes).
2026-05-28 17:52:37,774 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6E3B0000: C:\Windows\SYSTEM32\d3d10warp (0x6f6000 bytes).
2026-05-28 17:52:37,778 [root] DEBUG: 3336: DLL loaded at 0x00007FFC69030000: C:\Windows\System32\Windows.UI.Xaml.Controls (0x3dc000 bytes).
2026-05-28 17:52:37,780 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75F50000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 17:52:37,781 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6E370000: C:\Windows\SYSTEM32\dxcore (0x3b000 bytes).
2026-05-28 17:52:37,784 [root] DEBUG: 3336: DLL loaded at 0x00007FFC65A90000: C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop (0xbc000 bytes).
2026-05-28 17:52:37,787 [root] DEBUG: 3336: DLL loaded at 0x00007FFC69960000: C:\Windows\SYSTEM32\dwrite (0x27f000 bytes).
2026-05-28 17:52:37,788 [root] DEBUG: 3336: DLL loaded at 0x00007FFC63700000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 17:52:37,791 [root] DEBUG: 3336: DLL loaded at 0x00007FFC66930000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2026-05-28 17:52:37,794 [root] DEBUG: 3336: AllocationHandler: Adding allocation to tracked region list: 0x00007DF494311000, size: 0x1000.
2026-05-28 17:52:37,795 [root] DEBUG: 3336: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\msctf (0x114000 bytes).
2026-05-28 17:52:37,797 [root] DEBUG: 3336: DLL loaded at 0x00007FFC64B20000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 17:52:37,803 [root] DEBUG: 3336: DLL loaded at 0x00007FFC614E0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 17:52:37,809 [root] DEBUG: 3336: DLL loaded at 0x00007FFC73380000: C:\Windows\SYSTEM32\RMCLIENT (0x2a000 bytes).
2026-05-28 17:52:37,815 [root] DEBUG: 3336: DLL loaded at 0x00007FFC628B0000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-28 17:52:37,830 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5D300000: C:\Windows\SYSTEM32\windows.ui.core.textinput (0x104000 bytes).
2026-05-28 17:52:37,841 [root] DEBUG: 3336: DLL loaded at 0x00007FFC755E0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 17:52:37,842 [root] DEBUG: 3336: DLL loaded at 0x00007FFC69BE0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 17:52:37,848 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5F830000: C:\Windows\system32\DataExchange (0x3e000 bytes).
2026-05-28 17:52:37,875 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6BCE0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 17:52:37,877 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6E1F0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 17:52:37,889 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 17:52:37,890 [root] DEBUG: 3336: DLL loaded at 0x00007FFC57190000: C:\Windows\SYSTEM32\REGAPI (0x3b000 bytes).
2026-05-28 17:52:37,890 [root] DEBUG: 3336: DLL loaded at 0x00007FFC753D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 17:52:37,891 [root] DEBUG: 3336: DLL loaded at 0x00007FFC571D0000: C:\Windows\SYSTEM32\SettingsEnvironment.Desktop (0x94000 bytes).
2026-05-28 17:52:37,892 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 17:52:37,912 [root] DEBUG: 3336: DLL loaded at 0x00007FFC72B20000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 17:52:37,913 [root] DEBUG: 3336: DLL loaded at 0x00007FFC68F00000: C:\Windows\System32\NetworkUXBroker (0x6d000 bytes).
2026-05-28 17:52:37,915 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75370000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 17:52:37,918 [root] DEBUG: 3336: DLL loaded at 0x00007FFC74A70000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 17:52:37,920 [root] DEBUG: 3336: DLL loaded at 0x00007FFC707B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 17:52:37,920 [root] DEBUG: 3336: DLL loaded at 0x00007FFC68EC0000: C:\Windows\System32\EthernetMediaManager (0x34000 bytes).
2026-05-28 17:52:37,922 [root] DEBUG: 3336: DLL loaded at 0x00007FFC771D0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 17:52:37,924 [root] DEBUG: 3336: DLL loaded at 0x00007FFC70770000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 17:52:37,928 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6CEE0000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 17:52:37,946 [root] DEBUG: 3336: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 17:52:37,964 [root] INFO: Restarting WMI Service
2026-05-28 17:52:37,974 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6BB00000: C:\Windows\SYSTEM32\samcli (0x19000 bytes).
2026-05-28 17:52:37,975 [root] DEBUG: 3336: DLL loaded at 0x00007FFC659D0000: C:\Windows\system32\credprovhost (0x69000 bytes).
2026-05-28 17:52:38,015 [root] DEBUG: 3336: DLL loaded at 0x00007FFC697B0000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2026-05-28 17:52:38,027 [root] DEBUG: 3336: DLL loaded at 0x00007FFC69670000: C:\Windows\System32\Windows.UI.Xaml.Phone (0x13c000 bytes).
2026-05-28 17:52:38,055 [root] DEBUG: 3336: DLL loaded at 0x00007FFC73480000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 17:52:38,056 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5E770000: C:\Windows\SYSTEM32\pdh (0x49000 bytes).
2026-05-28 17:52:38,057 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5E7C0000: C:\Windows\system32\twinui (0x5f4000 bytes).
2026-05-28 17:52:38,061 [root] DEBUG: 3336: DLL loaded at 0x00007FFC57480000: C:\Windows\SYSTEM32\MFPlat (0x1bb000 bytes).
2026-05-28 17:52:38,065 [root] DEBUG: 3336: DLL loaded at 0x00007FFC65640000: C:\Windows\SYSTEM32\RTWorkQ (0x34000 bytes).
2026-05-28 17:52:38,075 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A9E0000: C:\Windows\SYSTEM32\NcaApi (0xb000 bytes).
2026-05-28 17:52:38,083 [root] DEBUG: 3336: DLL loaded at 0x00007FFC66790000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 17:52:38,087 [root] DEBUG: 3336: DLL loaded at 0x00007FFC65020000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 17:52:38,105 [root] DEBUG: 3336: DLL loaded at 0x00007FFC60C70000: C:\Windows\System32\twinapi (0xa9000 bytes).
2026-05-28 17:52:38,119 [root] INFO: Added new file to list with pid 3336 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0YGUNPUJCYXKZMXY9829.temp
2026-05-28 17:52:38,125 [root] INFO: Added new file to list with pid 3336 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\f18460fded109990.customDestinations-ms
2026-05-28 17:52:38,159 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\f18460fded109990.customDestinations-ms~RFb46b.TMP to files\90bf6baa6f968a285f88620fbf91e1f5aa3e66e2bad50fd16f37913280ad8228; Size is 24; Max size: 100000000
2026-05-28 17:52:38,166 [root] DEBUG: 3336: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 17:52:38,166 [root] DEBUG: 3336: DLL loaded at 0x00007FFC72B70000: C:\Windows\SYSTEM32\dsreg (0x141000 bytes).
2026-05-28 17:52:38,167 [root] DEBUG: 3336: DLL loaded at 0x00007FFC645C0000: C:\Windows\SYSTEM32\cdp (0x4d4000 bytes).
2026-05-28 17:52:38,168 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5D550000: C:\Windows\System32\TaskFlowDataEngine (0x17e000 bytes).
2026-05-28 17:52:38,174 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:52:38,176 [root] DEBUG: 3336: OpenProcessHandler: Injection info created for process 4584, handle 0xa90: Error obtaining target process name
2026-05-28 17:52:38,178 [root] INFO: Announced 64-bit process name: explorer.exe pid: 4584
2026-05-28 17:52:38,179 [lib.api.process] INFO: Monitor config for process 4584: C:\mtfrhoy9\dll\4584.ini
2026-05-28 17:52:38,179 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:38,180 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:38,182 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75560000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 17:52:38,185 [root] DEBUG: Loader: Injecting process 4584 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:38,186 [root] DEBUG: 4584: caller_dispatch: Added region at 0x000000000A6C0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x000000000A6C0043, thread 9020).
2026-05-28 17:52:38,187 [root] DEBUG: 4584: DumpPEsInRange: Scanning range 0x000000000A6C0000 - 0x000000000A6C0134.
2026-05-28 17:52:38,187 [root] DEBUG: 4584: ScanForDisguisedPE: Size too small: 0x134 bytes
2026-05-28 17:52:38,189 [lib.common.results] INFO: Uploading file C:\LJDkwoHS\CAPE\4584_721638522128452026 to CAPE\3b25aecdd2d944b4f8b8fd9ec6d106b380556231b23856cb96cb95b7cf03503a; Size is 308; Max size: 100000000
2026-05-28 17:52:38,190 [root] DEBUG: 4584: DumpMemory: Payload successfully created: C:\LJDkwoHS\CAPE\4584_721638522128452026 (size 308 bytes)
2026-05-28 17:52:38,191 [root] DEBUG: 4584: DumpRegion: Dumped entire allocation from 0x000000000A6C0000, size 4096 bytes.
2026-05-28 17:52:38,193 [root] DEBUG: 4584: ProcessTrackedRegion: Dumped region at 0x000000000A6C0000.
2026-05-28 17:52:38,195 [root] DEBUG: 4584: YaraScan: Scanning 0x000000000A6C0000, size 0x134
2026-05-28 17:52:38,196 [root] DEBUG: 4584: Monitor config - unrecognised key host-ip.
2026-05-28 17:52:38,196 [root] DEBUG: 4584: Monitor config - unrecognised key host-port.
2026-05-28 17:52:38,197 [root] DEBUG: 4584: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:38,197 [root] DEBUG: 4584: Dropped file limit defaulting to 100.
2026-05-28 17:52:38,217 [root] DEBUG: 4584: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:52:38,222 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6BA50000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 17:52:38,255 [root] DEBUG: 3336: DLL loaded at 0x00007FFC664D0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 17:52:38,263 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:52:38,263 [root] DEBUG: 4584: set_hooks: Unable to hook LockResource
2026-05-28 17:52:38,266 [root] DEBUG: 3336: DLL loaded at 0x00007FFC65B50000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 17:52:38,287 [root] DEBUG: 3336: DLL loaded at 0x00007FFC650F0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 17:52:38,293 [root] DEBUG: 4584: Hooked 627 out of 628 functions
2026-05-28 17:52:38,326 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 3336, handle 0x23c4: C:\Windows\ImmersiveControlPanel\SystemSettings.exe
2026-05-28 17:52:38,327 [root] DEBUG: 3336: DLL loaded at 0x00007FFC67700000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 17:52:38,333 [root] INFO: Loaded monitor into process with pid 4584
2026-05-28 17:52:38,338 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 17:52:38,338 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:38,344 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6EC20000: C:\Windows\System32\Windows.Graphics (0x8d000 bytes).
2026-05-28 17:52:38,349 [root] DEBUG: 3336: DLL loaded at 0x00007FFC66860000: C:\Windows\System32\threadpoolwinrt (0x14000 bytes).
2026-05-28 17:52:38,353 [root] DEBUG: 3336: DLL loaded at 0x00007FFC59D80000: C:\Windows\SYSTEM32\msftedit (0x34d000 bytes).
2026-05-28 17:52:38,361 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A5D0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 17:52:38,421 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6E250000: C:\Windows\SYSTEM32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 17:52:38,422 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6A9D0000: C:\Windows\SYSTEM32\ErrorDetailsCore (0x10000 bytes).
2026-05-28 17:52:38,422 [root] DEBUG: 3336: DLL loaded at 0x000002B899DD0000: C:\Windows\System32\SettingsHandlers_nt (0x3d8000 bytes).
2026-05-28 17:52:38,771 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6EDF0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 17:52:38,865 [root] DEBUG: 4584: CreateProcessHandler: Injection info set for new process 7800: C:\Windows\system32\taskmgr.exe, ImageBase: 0x00007FF7A5E30000
2026-05-28 17:52:38,866 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 7800
2026-05-28 17:52:38,866 [lib.api.process] INFO: Monitor config for process 7800: C:\mtfrhoy9\dll\7800.ini
2026-05-28 17:52:38,867 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:38,868 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:38,873 [root] DEBUG: Loader: Injecting process 7800 (thread 7028) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:38,874 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:52:38,875 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:38,876 [lib.api.process] INFO: Injected into 64-bit <Process 7800 Taskmgr.exe>
2026-05-28 17:52:38,881 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 7800
2026-05-28 17:52:38,881 [lib.api.process] INFO: Monitor config for process 7800: C:\mtfrhoy9\dll\7800.ini
2026-05-28 17:52:38,882 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:38,883 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:38,888 [root] DEBUG: Loader: Injecting process 7800 (thread 7028) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:38,889 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:52:38,890 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:38,891 [lib.api.process] INFO: Injected into 64-bit <Process 7800 Taskmgr.exe>
2026-05-28 17:52:38,901 [root] DEBUG: 4584: DLL loaded at 0x00007FFC64EC0000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 17:52:38,902 [root] DEBUG: 4584: DLL loaded at 0x00007FFC64EC0000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 17:52:38,902 [root] DEBUG: 4584: DLL loaded at 0x00007FFC66D50000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 17:52:38,903 [root] DEBUG: 4584: DLL loaded at 0x00007FFC66D50000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 17:52:38,905 [root] DEBUG: 4584: DLL loaded at 0x00007FFC630F0000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 17:52:38,906 [root] DEBUG: 4584: DLL loaded at 0x00007FFC630F0000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 17:52:38,924 [root] DEBUG: 3336: DLL loaded at 0x00007FFC65950000: C:\Windows\System32\SystemSettings.SettingsExtensibility (0x2a000 bytes).
2026-05-28 17:52:38,928 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 7800
2026-05-28 17:52:38,929 [lib.api.process] INFO: Monitor config for process 7800: C:\mtfrhoy9\dll\7800.ini
2026-05-28 17:52:38,929 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:38,930 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:38,937 [root] DEBUG: Loader: Injecting process 7800 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:38,937 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 7028, handle 0x120
2026-05-28 17:52:38,938 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:52:38,939 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:38,940 [lib.api.process] INFO: Injected into 64-bit <Process 7800 Taskmgr.exe>
2026-05-28 17:52:39,015 [root] DEBUG: 3336: AllocationHandler: Adding allocation to tracked region list: 0x00007DF494301000, size: 0x1000.
2026-05-28 17:52:39,016 [root] DEBUG: 7800: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:39,017 [root] DEBUG: 7800: Interactive desktop enabled.
2026-05-28 17:52:39,018 [root] DEBUG: 7800: Dropped file limit defaulting to 100.
2026-05-28 17:52:39,022 [root] DEBUG: 7800: Disabling sleep skipping.
2026-05-28 17:52:39,025 [root] DEBUG: 7800: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:52:39,030 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5A0D0000: C:\Windows\System32\Windows.Web.Http (0x177000 bytes).
2026-05-28 17:52:39,041 [root] DEBUG: 7800: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:52:39,041 [root] DEBUG: 3336: DLL loaded at 0x00007FFC67810000: C:\Windows\SYSTEM32\WININET (0x4d6000 bytes).
2026-05-28 17:52:39,041 [root] DEBUG: 7800: YaraScan: Scanning 0x00007FF7A5E30000, size 0x12fcfe
2026-05-28 17:52:39,049 [root] DEBUG: 7800: Monitor initialised: 64-bit capemon loaded in process 7800 at 0x00007FFC37E40000, thread 7028, image base 0x00007FF7A5E30000, stack from 0x000000FCCB564000-0x000000FCCB570000
2026-05-28 17:52:39,050 [root] DEBUG: 7800: Commandline: "C:\Windows\system32\taskmgr.exe" /4
2026-05-28 17:52:39,058 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5C9D0000: C:\Windows\SYSTEM32\ondemandconnroutehelper (0x17000 bytes).
2026-05-28 17:52:39,059 [root] DEBUG: 7800: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:52:39,063 [root] DEBUG: 3336: DLL loaded at 0x00007FFC74AB0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 17:52:39,064 [root] DEBUG: 3336: DLL loaded at 0x00007FFC742D0000: C:\Windows\SYSTEM32\firewallapi (0x96000 bytes).
2026-05-28 17:52:39,070 [root] DEBUG: 3336: DLL loaded at 0x00007FFC74290000: C:\Windows\SYSTEM32\fwbase (0x36000 bytes).
2026-05-28 17:52:39,075 [root] DEBUG: 3336: DLL loaded at 0x00007FFC74D80000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 17:52:39,078 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6E0E0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 17:52:39,080 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75430000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 17:52:39,084 [root] DEBUG: 3336: DLL loaded at 0x00007FFC746B0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 17:52:39,085 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:52:39,087 [root] DEBUG: 7800: set_hooks: Unable to hook LockResource
2026-05-28 17:52:39,103 [root] DEBUG: 7800: Hooked 627 out of 628 functions
2026-05-28 17:52:39,119 [root] DEBUG: 7800: Syscall hook installed, syscall logging level 1
2026-05-28 17:52:39,156 [root] DEBUG: 7800: RestoreHeaders: Restored original import table.
2026-05-28 17:52:39,175 [root] INFO: Loaded monitor into process with pid 7800
2026-05-28 17:52:39,182 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6CAE0000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-05-28 17:52:39,185 [root] DEBUG: 3128: DLL loaded at 0x00007FFC6FED0000: C:\Windows\System32\UIAnimation (0x47000 bytes).
2026-05-28 17:52:39,187 [root] DEBUG: 7800: DLL loaded at 0x00007FFC75440000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 17:52:39,214 [root] DEBUG: 3128: OpenProcessHandler: Injection info created for process 3336, handle 0x6a8: C:\Windows\ImmersiveControlPanel\SystemSettings.exe
2026-05-28 17:52:39,217 [root] DEBUG: 4584: DLL loaded at 0x00007FFC65760000: C:\Windows\System32\NPSMDesktopProvider (0x38000 bytes).
2026-05-28 17:52:39,221 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6CF10000: C:\Windows\System32\fwpuclnt (0x80000 bytes).
2026-05-28 17:52:39,222 [root] DEBUG: 7800: caller_dispatch: Added region at 0x00007FF7A5E30000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7A5E5FF02, thread 7028).
2026-05-28 17:52:39,239 [root] DEBUG: 4584: DLL loaded at 0x00007FFC65760000: C:\Windows\System32\NPSMDesktopProvider (0x38000 bytes).
2026-05-28 17:52:39,243 [root] DEBUG: 7800: YaraScan: Scanning 0x00007FF7A5E30000, size 0x12fcfe
2026-05-28 17:52:39,250 [root] DEBUG: 3336: DLL loaded at 0x00007FFC745C0000: C:\Windows\system32\schannel (0x97000 bytes).
2026-05-28 17:52:39,268 [root] DEBUG: 7800: ProcessImageBase: Main module image at 0x00007FF7A5E30000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:52:39,292 [root] DEBUG: 3336: DLL loaded at 0x00007FFC579D0000: C:\Windows\SYSTEM32\rometadata (0x3b000 bytes).
2026-05-28 17:52:39,295 [root] DEBUG: 7800: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:52:39,296 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5DCC0000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-05-28 17:52:39,315 [root] INFO: Announced starting service "b'BthAvctpSvc'"
2026-05-28 17:52:39,315 [root] DEBUG: 7800: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:52:39,316 [root] DEBUG: 3128: DLL loaded at 0x00007FFC579D0000: C:\Windows\SYSTEM32\rometadata (0x3b000 bytes).
2026-05-28 17:52:39,320 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75050000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 17:52:39,325 [root] DEBUG: 7800: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 17:52:39,326 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5D6D0000: C:\Windows\System32\cryptnet (0x31000 bytes).
2026-05-28 17:52:39,348 [root] DEBUG: 7800: DLL loaded at 0x00007FFC66930000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 17:52:39,360 [root] DEBUG: 3336: DLL loaded at 0x00007FFC75090000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 17:52:39,362 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5DD10000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-05-28 17:52:39,374 [root] DEBUG: 7800: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:52:39,377 [root] DEBUG: 7800: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 17:52:39,378 [root] DEBUG: 3336: DLL loaded at 0x00007FFC76590000: C:\Windows\System32\WLDAP32 (0x56000 bytes).
2026-05-28 17:52:39,380 [root] DEBUG: 7800: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 17:52:39,382 [root] DEBUG: 3336: DLL loaded at 0x00007FFC673E0000: C:\Windows\SYSTEM32\certca (0xcd000 bytes).
2026-05-28 17:52:39,383 [root] DEBUG: 7800: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 17:52:39,385 [root] DEBUG: 3336: DLL loaded at 0x00007FFC6C910000: C:\Windows\SYSTEM32\DSPARSE (0xc000 bytes).
2026-05-28 17:52:39,386 [root] DEBUG: 7800: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 17:52:39,387 [root] DEBUG: 3336: DLL loaded at 0x00007FFC66E70000: C:\Windows\System32\certenroll (0x338000 bytes).
2026-05-28 17:52:39,418 [root] DEBUG: 7800: DLL loaded at 0x00007FFC74740000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 17:52:39,419 [root] DEBUG: 3336: DLL loaded at 0x00007FFC5CE70000: C:\Windows\system32\mlang (0x42000 bytes).
2026-05-28 17:52:39,420 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 17:52:39,438 [root] DEBUG: 7800: DLL loaded at 0x00007FFC68F00000: C:\Windows\System32\NetworkUXBroker (0x6d000 bytes).
2026-05-28 17:52:39,455 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:52:39,461 [root] DEBUG: 7800: DLL loaded at 0x00007FFC65620000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes).
2026-05-28 17:52:39,464 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 8020, handle 0x2380: Error obtaining target process name
2026-05-28 17:52:39,470 [root] DEBUG: 4584: api-rate-cap: GetSystemMetrics hook disabled due to rate
2026-05-28 17:52:39,471 [root] DEBUG: 7800: DLL loaded at 0x00007FFC65120000: C:\Windows\system32\srumapi (0x14000 bytes).
2026-05-28 17:52:39,493 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:52:39,494 [root] DEBUG: 7800: DLL loaded at 0x00007FFC72B20000: C:\Windows\system32\WTSAPI32 (0x14000 bytes).
2026-05-28 17:52:39,495 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 5536, handle 0x238c: Error obtaining target process name
2026-05-28 17:52:39,498 [root] DEBUG: 7800: DLL loaded at 0x00007FFC75370000: C:\Windows\system32\WINSTA (0x5b000 bytes).
2026-05-28 17:52:39,500 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:52:39,502 [root] DEBUG: 7800: DLL loaded at 0x00007FFC711F0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 17:52:39,512 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 5152, handle 0x2394: Error obtaining target process name
2026-05-28 17:52:39,513 [root] DEBUG: 7800: DLL loaded at 0x00007FFC701E0000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 17:52:39,518 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:52:39,534 [root] DEBUG: 7800: DLL loaded at 0x00007FFC755E0000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 17:52:39,545 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 3392, handle 0x232c: Error obtaining target process name
2026-05-28 17:52:39,546 [root] DEBUG: 7800: DLL loaded at 0x00007FFC69BE0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 17:52:39,559 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:52:39,562 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6BB00000: C:\Windows\system32\samcli (0x19000 bytes).
2026-05-28 17:52:39,563 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 3484, handle 0x23b4: Error obtaining target process name
2026-05-28 17:52:39,565 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:52:39,565 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 3128, handle 0x239c: Error obtaining target process name
2026-05-28 17:52:39,569 [root] DEBUG: 7800: DLL loaded at 0x00007FFC75020000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 17:52:39,572 [root] DEBUG: 7800: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 17:52:39,669 [root] DEBUG: 7800: DLL loaded at 0x00007FFC5F9A0000: C:\Windows\system32\OLEACC (0x66000 bytes).
2026-05-28 17:52:39,695 [root] DEBUG: 7800: api-rate-cap: NtReleaseMutant hook disabled due to rate
2026-05-28 17:52:39,708 [root] DEBUG: 7800: DLL loaded at 0x00007FFC72AF0000: C:\Windows\system32\SAMLIB (0x28000 bytes).
2026-05-28 17:52:39,717 [root] DEBUG: 7800: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 17:52:39,736 [root] DEBUG: 7800: DLL loaded at 0x00007FFC74B80000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 17:52:39,738 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6EDF0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 17:52:39,746 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 92, handle 0x5a4:
2026-05-28 17:52:39,750 [root] DEBUG: 7800: DLL loaded at 0x00007FFC5F2A0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 17:52:39,751 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 428, handle 0x5a4: C:\Windows\System32\csrss.exe
2026-05-28 17:52:39,766 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 512, handle 0x5a4: C:\Windows\System32\csrss.exe
2026-05-28 17:52:39,769 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 600, handle 0x5e4: C:\Windows\System32\winlogon.exe
2026-05-28 17:52:39,774 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 600 (handle 0x5e4): 0x00007FF767B80000.
2026-05-28 17:52:39,779 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 740, handle 0x5e4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:39,782 [root] DEBUG: 7800: DLL loaded at 0x00007FFC728F0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 17:52:39,794 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 740 (handle 0x5e4): 0x00007FF780360000.
2026-05-28 17:52:39,806 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 756, handle 0x5e4: C:\Windows\System32\fontdrvhost.exe
2026-05-28 17:52:39,809 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 756 (handle 0x5e4): 0x00007FF7EE860000.
2026-05-28 17:52:39,814 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 9864: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF6209B0000
2026-05-28 17:52:39,827 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 900, handle 0x5e4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:39,833 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 9864
2026-05-28 17:52:39,835 [lib.api.process] INFO: Monitor config for process 9864: C:\mtfrhoy9\dll\9864.ini
2026-05-28 17:52:39,835 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 900 (handle 0x5e4): 0x00007FF780360000.
2026-05-28 17:52:39,838 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:39,839 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 420, handle 0x5e4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:39,842 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 420 (handle 0x5e4): 0x00007FF780360000.
2026-05-28 17:52:39,847 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 712, handle 0x5e4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:39,936 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:39,939 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 17:52:39,945 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1064, handle 0x5e4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:39,948 [root] DEBUG: Loader: Injecting process 9864 (thread 9868) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:39,948 [root] DEBUG: 7800: DLL loaded at 0x00007FFC63700000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 17:52:39,949 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:52:39,956 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1064 (handle 0x5e4): 0x00007FF780360000.
2026-05-28 17:52:39,957 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:39,965 [root] DEBUG: 7800: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 17:52:39,979 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1144, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:39,984 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1144 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:39,984 [lib.api.process] INFO: Injected into 64-bit <Process 9864 WmiPrvSE.exe>
2026-05-28 17:52:39,986 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 9864
2026-05-28 17:52:39,986 [lib.api.process] INFO: Monitor config for process 9864: C:\mtfrhoy9\dll\9864.ini
2026-05-28 17:52:39,987 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:40,023 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1208, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,068 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:40,068 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1208 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,078 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1260, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,083 [root] DEBUG: Loader: Injecting process 9864 (thread 9868) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:40,085 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1260 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,086 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:52:40,087 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1432, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,088 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 17:52:40,088 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 17:52:40,089 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 17:52:40,091 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://sugarcraft.net/"" with pid 10028
2026-05-28 17:52:40,092 [lib.api.process] INFO: Monitor config for process 10028: C:\mtfrhoy9\dll\10028.ini
2026-05-28 17:52:40,094 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:40,095 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1432 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,096 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:40,100 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:40,107 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1520, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,110 [lib.api.process] INFO: Injected into 64-bit <Process 9864 WmiPrvSE.exe>
2026-05-28 17:52:40,110 [root] DEBUG: Loader: Injecting process 10028 (thread 10032) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:40,115 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1520 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,123 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:52:40,124 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1620, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,126 [root] DEBUG: 9864: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:40,127 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1620 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,128 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:40,130 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1720, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,134 [root] DEBUG: 9864: Interactive desktop enabled.
2026-05-28 17:52:40,135 [lib.api.process] INFO: Injected into 64-bit <Process 10028 msedge.exe>
2026-05-28 17:52:40,136 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1720 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,137 [root] DEBUG: 9864: Dropped file limit defaulting to 100.
2026-05-28 17:52:40,138 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1748, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,143 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1748 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,144 [root] DEBUG: 9864: Disabling sleep skipping.
2026-05-28 17:52:40,146 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1844, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,148 [root] DEBUG: 9864: Services hook set enabled
2026-05-28 17:52:40,149 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1844 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,152 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1892, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,154 [root] DEBUG: 9864: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:52:40,155 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1892 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,169 [root] DEBUG: 9864: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:52:40,170 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1976, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,172 [root] DEBUG: 9864: Monitor initialised: 64-bit capemon loaded in process 9864 at 0x00007FFC37E40000, thread 9868, image base 0x00007FF6209B0000, stack from 0x000000E134FC0000-0x000000E134FD0000
2026-05-28 17:52:40,173 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1976 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,174 [root] DEBUG: 9864: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 17:52:40,193 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 348, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,197 [root] DEBUG: 9864: Hooked 69 out of 69 functions
2026-05-28 17:52:40,201 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 348 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,202 [root] DEBUG: 9864: RestoreHeaders: Restored original import table.
2026-05-28 17:52:40,202 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2100, handle 0x6d4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,205 [root] INFO: Loaded monitor into process with pid 9864
2026-05-28 17:52:40,206 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2100 (handle 0x6d4): 0x00007FF780360000.
2026-05-28 17:52:40,214 [root] DEBUG: 9864: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:52:40,215 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2276, handle 0x6d4: C:\Windows\System32\spoolsv.exe
2026-05-28 17:52:40,216 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:52:40,219 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2276 (handle 0x6f8): 0x00007FF7722E0000.
2026-05-28 17:52:40,221 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2348, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,224 [root] DEBUG: 9864: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:52:40,226 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2348 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,228 [lib.api.process] INFO: Monitor config for process 8832: C:\mtfrhoy9\dll\8832.ini
2026-05-28 17:52:40,229 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2512, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,231 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2512 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,231 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:52:40,232 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:52:40,233 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2636, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,239 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2636 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,240 [root] DEBUG: Loader: Injecting process 8832 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:40,241 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2792, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,245 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2792 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,246 [root] DEBUG: 8832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:40,246 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2808, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,248 [root] DEBUG: 8832: Disabling sleep skipping.
2026-05-28 17:52:40,249 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2808 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,249 [root] DEBUG: 8832: Interactive desktop enabled.
2026-05-28 17:52:40,250 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2996, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,252 [root] DEBUG: 8832: Dropped file limit defaulting to 100.
2026-05-28 17:52:40,252 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2996 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,253 [root] DEBUG: 8832: Services hook set enabled
2026-05-28 17:52:40,259 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3824, handle 0x6f8: C:\Windows\System32\SearchIndexer.exe
2026-05-28 17:52:40,264 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3824 (handle 0x6f8): 0x00007FF781A20000.
2026-05-28 17:52:40,265 [root] DEBUG: 8832: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:52:40,265 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2344, handle 0x6f8: C:\Windows\System32\sihost.exe
2026-05-28 17:52:40,278 [root] DEBUG: 8832: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:52:40,279 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2344 (handle 0x6f8): 0x00007FF6BC710000.
2026-05-28 17:52:40,279 [root] DEBUG: 8832: Monitor initialised: 64-bit capemon loaded in process 8832 at 0x00007FFC37E40000, thread 9932, image base 0x00007FF780360000, stack from 0x000000E0A0274000-0x000000E0A0280000
2026-05-28 17:52:40,280 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2464, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,280 [root] DEBUG: 8832: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 17:52:40,296 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2464 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,296 [root] DEBUG: 8832: Hooked 69 out of 69 functions
2026-05-28 17:52:40,297 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3752, handle 0x6f8: C:\Windows\System32\taskhostw.exe
2026-05-28 17:52:40,298 [root] INFO: Loaded monitor into process with pid 8832
2026-05-28 17:52:40,300 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3752 (handle 0x6f8): 0x00007FF77B4D0000.
2026-05-28 17:52:40,303 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:52:40,305 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 392, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,308 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:52:40,309 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 392 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,310 [lib.api.process] INFO: Injected into 64-bit <Process 8832 svchost.exe>
2026-05-28 17:52:40,311 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4276, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,313 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4484, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,315 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4484 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,316 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4728, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,323 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4728 (handle 0x6f8): 0x00007FF780360000.
2026-05-28 17:52:40,326 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3060, handle 0x6f8: C:\Windows\System32\SearchProtocolHost.exe
2026-05-28 17:52:40,333 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3060 (handle 0x6f8): 0x00007FF716940000.
2026-05-28 17:52:40,335 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5152, handle 0x6f8: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2026-05-28 17:52:40,338 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6A640000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 17:52:40,339 [root] DEBUG: 7800: DLL loaded at 0x00007FFC741C0000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 17:52:40,340 [root] DEBUG: 7800: DLL loaded at 0x00007FFC741F0000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 17:52:40,342 [root] DEBUG: 7800: DLL loaded at 0x00007FFC75560000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 17:52:40,343 [root] DEBUG: 7800: DLL loaded at 0x00007FFC610F0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 17:52:40,352 [root] DEBUG: 7800: DLL loaded at 0x00007FFC72EF0000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 17:52:40,360 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6A9C0000: C:\Windows\System32\WppRecorderUM (0x7000 bytes).
2026-05-28 17:52:40,361 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6AB30000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 17:52:40,361 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6A9C0000: C:\Windows\System32\WppRecorderUM (0x7000 bytes).
2026-05-28 17:52:40,362 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6AC50000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 17:52:40,362 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5FA20000: C:\Windows\System32\BthAvctpSvc (0x64000 bytes).
2026-05-28 17:52:40,364 [root] DEBUG: 7800: DLL loaded at 0x00007FFC61260000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 17:52:40,365 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5FA20000: C:\Windows\System32\BthAvctpSvc (0x64000 bytes).
2026-05-28 17:52:40,390 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6A6A0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 17:52:40,398 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6A120000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 17:52:40,403 [root] DEBUG: 7800: DLL loaded at 0x00007FFC70130000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 17:52:40,404 [root] DEBUG: 7800: DLL loaded at 0x00007FFC69E70000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 17:52:40,404 [root] DEBUG: 7800: DLL loaded at 0x00007FFC69FD0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 17:52:40,407 [root] DEBUG: 7800: DLL loaded at 0x00007FFC69D20000: C:\Windows\SYSTEM32\languageoverlayutil (0x41000 bytes).
2026-05-28 17:52:40,410 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6A6C0000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 17:52:40,413 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6B370000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 17:52:40,424 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5152 (handle 0x78c): 0x00007FF70F680000.
2026-05-28 17:52:40,429 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5216, handle 0x784: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe
2026-05-28 17:52:40,431 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5216 (handle 0x784): 0x00007FF6B6CB0000.
2026-05-28 17:52:40,432 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5328, handle 0x784: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,434 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5328 (handle 0x784): 0x00007FF780360000.
2026-05-28 17:52:40,435 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5536, handle 0x784: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
2026-05-28 17:52:40,455 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5536 (handle 0x79c): 0x00007FF6EB870000.
2026-05-28 17:52:40,458 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5796, handle 0x79c: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 17:52:40,465 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5796 (handle 0x7a0): 0x00007FF77B710000.
2026-05-28 17:52:40,467 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5956, handle 0x79c: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 17:52:40,469 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5956 (handle 0x79c): 0x00007FF77B710000.
2026-05-28 17:52:40,470 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3680, handle 0x79c: C:\Windows\System32\SecurityHealthSystray.exe
2026-05-28 17:52:40,474 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3680 (handle 0x79c): 0x00007FF661AB0000.
2026-05-28 17:52:40,475 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6084, handle 0x79c: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,477 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6084 (handle 0x79c): 0x00007FF780360000.
2026-05-28 17:52:40,478 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4944, handle 0x79c: C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2026-05-28 17:52:40,480 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4944 (handle 0x79c): 0x0000000000320000.
2026-05-28 17:52:40,481 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5876, handle 0x79c: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,483 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5876 (handle 0x79c): 0x00007FF780360000.
2026-05-28 17:52:40,484 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3552, handle 0x79c: C:\Program Files (x86)\Steam\steam.exe
2026-05-28 17:52:40,485 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3552 (handle 0x79c): 0x00007FF7CB360000.
2026-05-28 17:52:40,486 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6200, handle 0x79c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:52:40,489 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6200 (handle 0x79c): 0x00007FF6B1860000.
2026-05-28 17:52:40,490 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6600, handle 0x79c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:52:40,491 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6600 (handle 0x79c): 0x00007FF6B1860000.
2026-05-28 17:52:40,492 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3392, handle 0x79c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:52:40,493 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3392 (handle 0x79c): 0x00007FF7D0050000.
2026-05-28 17:52:40,494 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6908, handle 0x79c: C:\Program Files (x86)\Common Files\Steam\steamservice.exe
2026-05-28 17:52:40,495 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6908 (handle 0x79c): 0x0000000000390000.
2026-05-28 17:52:40,496 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6448, handle 0x79c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:52:40,497 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6448 (handle 0x79c): 0x00007FF7D0050000.
2026-05-28 17:52:40,498 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 7700, handle 0x79c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:52:40,499 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 7700 (handle 0x79c): 0x00007FF7D0050000.
2026-05-28 17:52:40,500 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 8020, handle 0x79c: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
2026-05-28 17:52:40,522 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 8020 (handle 0x7ac): 0x00007FF7C7220000.
2026-05-28 17:52:40,538 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 7988, handle 0x7ac: C:\Windows\System32\svchost.exe
2026-05-28 17:52:40,542 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 7988 (handle 0x7ac): 0x00007FF780360000.
2026-05-28 17:52:40,544 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3128, handle 0x7ac: C:\Windows\System32\ApplicationFrameHost.exe
2026-05-28 17:52:40,545 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3128 (handle 0x7ac): 0x00007FF7EECE0000.
2026-05-28 17:52:40,546 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 7968, handle 0x7ac: C:\Windows\System32\conhost.exe
2026-05-28 17:52:40,549 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 7968 (handle 0x7ac): 0x00007FF799880000.
2026-05-28 17:52:40,633 [root] INFO: Added new file to list with pid 7800 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 17:52:40,658 [root] INFO: Added new file to list with pid 7800 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 17:52:40,763 [root] DEBUG: 7800: DLL loaded at 0x00007FFC74A70000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 17:52:40,766 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6E0E0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 17:52:40,796 [root] DEBUG: 7800: api-rate-cap: NtQueryValueKey hook disabled due to rate
2026-05-28 17:52:41,000 [root] DEBUG: 4584: DLL loaded at 0x00007FFC63990000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 17:52:41,001 [root] DEBUG: 4584: DLL loaded at 0x00007FFC63990000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 17:52:41,003 [root] DEBUG: 7800: DLL loaded at 0x00007FFC73480000: C:\Windows\system32\dwmapi (0x2f000 bytes).
2026-05-28 17:52:41,005 [root] DEBUG: 7800: DLL loaded at 0x000002EA3E570000: C:\Windows\system32\d3d9 (0x1cd000 bytes).
2026-05-28 17:52:41,010 [root] DEBUG: 7800: DLL loaded at 0x00007FFC731A0000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 17:52:41,015 [root] DEBUG: 7800: DLL loaded at 0x00007FFC35400000: C:\Windows\system32\D3D12Core (0x1cd000 bytes).
2026-05-28 17:52:41,020 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6E3B0000: C:\Windows\system32\d3d10warp (0x6f6000 bytes).
2026-05-28 17:52:41,023 [root] DEBUG: 4584: DLL loaded at 0x00007FFC601D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 17:52:41,023 [root] DEBUG: 4584: DLL loaded at 0x00007FFC601D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 17:52:41,027 [root] DEBUG: 7800: DLL loaded at 0x00007FFC352C0000: C:\Windows\system32\dxilconv (0x139000 bytes).
2026-05-28 17:52:41,030 [root] DEBUG: 7800: DLL loaded at 0x00007FFC601C0000: C:\Windows\system32\D3DSCache (0x2a000 bytes).
2026-05-28 17:52:41,042 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5FAF0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 17:52:41,042 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5FAF0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 17:52:41,049 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6E3B0000: C:\Windows\system32\d3d10warp (0x6f6000 bytes).
2026-05-28 17:52:41,051 [root] DEBUG: 7800: DLL loaded at 0x00007FFC753D0000: C:\Windows\system32\DEVOBJ (0x33000 bytes).
2026-05-28 17:52:41,053 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6E0C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 17:52:41,055 [root] DEBUG: 7800: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 17:52:41,057 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 336, handle 0xa54: C:\Windows\System32\smss.exe
2026-05-28 17:52:41,057 [root] DEBUG: 7800: DLL loaded at 0x00007FFC74AB0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 17:52:41,062 [root] DEBUG: 7800: DLL loaded at 0x00007FFC747D0000: C:\Windows\system32\wkscli (0x19000 bytes).
2026-05-28 17:52:41,075 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 500, handle 0xa30: C:\Windows\System32\wininit.exe
2026-05-28 17:52:41,079 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 592, handle 0x7f8: C:\Windows\System32\services.exe
2026-05-28 17:52:41,086 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 640, handle 0xa38: C:\Windows\System32\lsass.exe
2026-05-28 17:52:41,089 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 640 (handle 0xa50): 0x00007FF657A90000.
2026-05-28 17:52:41,090 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 748, handle 0xa50: C:\Windows\System32\fontdrvhost.exe
2026-05-28 17:52:41,090 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 860, handle 0xa50: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,092 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 860 (handle 0xa50): 0x00007FF780360000.
2026-05-28 17:52:41,093 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 984, handle 0xa50: C:\Windows\System32\dwm.exe
2026-05-28 17:52:41,098 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 984 (handle 0xa28): 0x00007FF6D4CD0000.
2026-05-28 17:52:41,099 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 492, handle 0xa28: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,101 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 492 (handle 0xa28): 0x00007FF780360000.
2026-05-28 17:52:41,101 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 560, handle 0xa28: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,103 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 560 (handle 0xa28): 0x00007FF780360000.
2026-05-28 17:52:41,104 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1072, handle 0xa28: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,106 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1072 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,106 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1172, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,108 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1172 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,109 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1224, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,110 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1224 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,111 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1316, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,114 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1316 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,115 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1468, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,116 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1468 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,117 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1604, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,119 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1604 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,119 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1688, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,121 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1688 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,122 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1732, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,123 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1732 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,124 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1852, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,125 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1852 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,126 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1900, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,128 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1900 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,130 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1396, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,131 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1396 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,132 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1644, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,134 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1644 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,134 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2184, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,136 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2184 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,137 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2308, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,138 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2308 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,139 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2504, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,141 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2504 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,141 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2628, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,143 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2628 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,144 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2644, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,147 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2644 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,148 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2800, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,150 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2800 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,150 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2932, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,152 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2932 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,152 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3672, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,154 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3672 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,155 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 736, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,157 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 736 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,158 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3068, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,159 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3068 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,161 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2672, handle 0xa98: C:\Windows\System32\taskhostw.exe
2026-05-28 17:52:41,163 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2672 (handle 0xa98): 0x00007FF77B4D0000.
2026-05-28 17:52:41,164 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3456, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,165 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3456 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,166 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4148, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,167 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4148 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,168 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4344, handle 0xa98: C:\Windows\System32\ctfmon.exe
2026-05-28 17:52:41,171 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4344 (handle 0xaa4): 0x00007FF7DC490000.
2026-05-28 17:52:41,172 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4584, handle 0xaa4: C:\Windows\explorer.exe
2026-05-28 17:52:41,177 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4584 (handle 0xaa0): 0x00007FF65E010000.
2026-05-28 17:52:41,178 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4836, handle 0xaa0: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,179 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4836 (handle 0xaa0): 0x00007FF780360000.
2026-05-28 17:52:41,180 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4128, handle 0xaa0: C:\Windows\System32\dllhost.exe
2026-05-28 17:52:41,184 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4128 (handle 0xa28): 0x00007FF699DF0000.
2026-05-28 17:52:41,184 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5176, handle 0xa28: C:\Windows\servicing\TrustedInstaller.exe
2026-05-28 17:52:41,188 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5176 (handle 0xa98): 0x00007FF662190000.
2026-05-28 17:52:41,189 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5320, handle 0xa98: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 17:52:41,196 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5320 (handle 0xa98): 0x00007FF77B710000.
2026-05-28 17:52:41,198 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5416, handle 0xa98: C:\Windows\System32\MoUsoCoreWorker.exe
2026-05-28 17:52:41,202 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5416 (handle 0xaa0): 0x00007FF68F1D0000.
2026-05-28 17:52:41,203 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5684, handle 0xaa0: C:\Windows\System32\SearchFilterHost.exe
2026-05-28 17:52:41,205 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5684 (handle 0xa50): 0x00007FF6EC310000.
2026-05-28 17:52:41,206 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3120, handle 0xa50: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,208 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3280, handle 0xa50: C:\Windows\System32\smartscreen.exe
2026-05-28 17:52:41,212 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3280 (handle 0xa98): 0x00007FF7AC790000.
2026-05-28 17:52:41,212 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3692, handle 0xa98: C:\Windows\System32\SecurityHealthService.exe
2026-05-28 17:52:41,216 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6040, handle 0xaa0: C:\Windows\System32\conhost.exe
2026-05-28 17:52:41,218 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6040 (handle 0xaa0): 0x00007FF799880000.
2026-05-28 17:52:41,218 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5920, handle 0xaa0: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,220 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5920 (handle 0xaa0): 0x00007FF780360000.
2026-05-28 17:52:41,221 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3484, handle 0xaa0: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:52:41,223 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3484 (handle 0xaa0): 0x00007FF6B1860000.
2026-05-28 17:52:41,224 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3344, handle 0xaa0: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:52:41,225 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3344 (handle 0xaa0): 0x00007FF6B1860000.
2026-05-28 17:52:41,226 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6236, handle 0xaa0: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:52:41,227 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6236 (handle 0xaa0): 0x00007FF6B1860000.
2026-05-28 17:52:41,227 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6772, handle 0xaa0: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:52:41,228 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6772 (handle 0xaa0): 0x00007FF6B1860000.
2026-05-28 17:52:41,229 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6580, handle 0xaa0: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:52:41,230 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6580 (handle 0xaa0): 0x00007FF7D0050000.
2026-05-28 17:52:41,231 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 7052, handle 0xaa0: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:52:41,232 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 7052 (handle 0xaa0): 0x00007FF7D0050000.
2026-05-28 17:52:41,233 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6320, handle 0xaa0: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:52:41,234 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6320 (handle 0xaa0): 0x00007FF7D0050000.
2026-05-28 17:52:41,234 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 7912, handle 0xaa0: C:\Windows\System32\notepad.exe
2026-05-28 17:52:41,237 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 7912 (handle 0xaa4): 0x00007FF7241A0000.
2026-05-28 17:52:41,239 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3744, handle 0xaa4: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,241 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3744 (handle 0xaa4): 0x00007FF780360000.
2026-05-28 17:52:41,242 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3336, handle 0xaa4: C:\Windows\ImmersiveControlPanel\SystemSettings.exe
2026-05-28 17:52:41,266 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3336 (handle 0xa9c): 0x00007FF68FA00000.
2026-05-28 17:52:41,268 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5936, handle 0xa9c: C:\mtfrhoy9\bin\PPLinject64.exe
2026-05-28 17:52:41,276 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5936 (handle 0xa98): 0x00007FF70AAC0000.
2026-05-28 17:52:41,277 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 8832, handle 0xa98: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,279 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 8832 (handle 0xa98): 0x00007FF780360000.
2026-05-28 17:52:41,279 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 9864, handle 0xa98: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-28 17:52:41,282 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 9864 (handle 0xaa4): 0x00007FF6209B0000.
2026-05-28 17:52:41,283 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 10028, handle 0xaa4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:41,286 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 10028 (handle 0xa50): 0x00007FF734750000.
2026-05-28 17:52:41,286 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 10324, handle 0xa50: C:\Windows\System32\svchost.exe
2026-05-28 17:52:41,288 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 10324 (handle 0xa50): 0x00007FF780360000.
2026-05-28 17:52:41,374 [root] DEBUG: 4584: OpenProcessHandler: Image base for process 3128 (handle 0x1e28): 0x00007FF7EECE0000.
2026-05-28 17:52:41,376 [root] INFO: Added new file to list with pid 4584 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 17:52:41,657 [root] DEBUG: 3336: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 17:52:41,721 [root] DEBUG: 3128: FreeHandler: Address: 0x00007DF4C01A0000.
2026-05-28 17:52:41,722 [root] DEBUG: 3128: ScanForNonZero: Error - Supplied size zero.
2026-05-28 17:52:41,723 [root] DEBUG: 3128: FreeHandler: Address: 0x00007DF4C01D0000.
2026-05-28 17:52:41,724 [root] DEBUG: 3128: ScanForNonZero: Error - Supplied size zero.
2026-05-28 17:52:41,725 [root] DEBUG: 3128: FreeHandler: Address: 0x00007DF4C01B0000.
2026-05-28 17:52:41,726 [root] DEBUG: 3128: ScanForNonZero: Error - Supplied size zero.
2026-05-28 17:52:41,728 [root] DEBUG: 3128: FreeHandler: Address: 0x00007DF4C01C0000.
2026-05-28 17:52:41,729 [root] DEBUG: 3128: ScanForNonZero: Error - Supplied size zero.
2026-05-28 17:52:41,731 [root] DEBUG: 3128: FreeHandler: Address: 0x00007DF4C01E0000.
2026-05-28 17:52:41,732 [root] DEBUG: 3128: ScanForNonZero: Error - Supplied size zero.
2026-05-28 17:52:42,144 [lib.api.process] INFO: Successfully resumed process with pid 10028
2026-05-28 17:52:42,148 [root] INFO: Process with pid 3336 appears to have terminated
2026-05-28 17:52:42,205 [root] DEBUG: 10028: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:52:42,208 [root] DEBUG: 10028: Interactive desktop enabled.
2026-05-28 17:52:42,209 [root] DEBUG: 10028: Dropped file limit defaulting to 100.
2026-05-28 17:52:42,231 [root] DEBUG: 10028: Edge-specific hook-set enabled.
2026-05-28 17:52:42,233 [root] DEBUG: 10028: Disabling sleep skipping.
2026-05-28 17:52:42,235 [root] DEBUG: 10028: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:52:42,247 [root] DEBUG: 10028: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:52:42,248 [root] DEBUG: 10028: Monitor initialised: 64-bit capemon loaded in process 10028 at 0x00007FFC37E40000, thread 10032, image base 0x00007FF734750000, stack from 0x000000ED6C3F4000-0x000000ED6C400000
2026-05-28 17:52:42,249 [root] DEBUG: 10028: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://sugarcraft.net/"
2026-05-28 17:52:42,261 [root] DEBUG: 10028: Hooked 2 out of 2 functions
2026-05-28 17:52:42,322 [root] DEBUG: 9864: DLL loaded at 0x00007FFC61080000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 17:52:42,325 [root] DEBUG: 10028: Syscall hook installed, syscall logging level 1
2026-05-28 17:52:42,332 [root] DEBUG: 10028: RestoreHeaders: Restored original import table.
2026-05-28 17:52:42,332 [root] DEBUG: 9864: DLL loaded at 0x00007FFC63BB0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 17:52:42,335 [root] INFO: Loaded monitor into process with pid 10028
2026-05-28 17:52:42,345 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 17:52:42,346 [root] DEBUG: 9864: DLL loaded at 0x00007FFC656B0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 17:52:42,355 [root] DEBUG: 10028: DLL loaded at 0x00007FFC63BA0000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 17:52:42,358 [root] DEBUG: 10028: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 17:52:42,369 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 17:52:42,369 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 17:52:42,371 [root] DEBUG: 10028: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 17:52:42,371 [root] DEBUG: 9864: DLL loaded at 0x00007FFC65AF0000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 17:52:42,373 [root] DEBUG: 10028: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 17:52:42,373 [root] DEBUG: 9864: DLL loaded at 0x00007FFC358E0000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 17:52:42,379 [root] DEBUG: 10028: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:52:42,382 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 17:52:42,726 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5CA40000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 17:52:42,729 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75F50000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 17:52:42,730 [root] DEBUG: 9864: DLL loaded at 0x00007FFC753D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 17:52:42,732 [root] DEBUG: 9864: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 17:52:42,734 [root] DEBUG: 9864: DLL loaded at 0x00007FFC73F70000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 17:52:42,735 [root] DEBUG: 9864: DLL loaded at 0x00007FFC77700000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 17:52:42,737 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 17:52:42,749 [root] DEBUG: 9864: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 17:52:42,752 [root] DEBUG: 9864: DLL loaded at 0x00007FFC73F70000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 17:52:42,754 [root] DEBUG: 9864: DLL loaded at 0x00007FFC77700000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 17:52:42,756 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 17:52:42,757 [root] DEBUG: 9864: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 17:52:42,759 [root] DEBUG: 9864: DLL loaded at 0x00007FFC77700000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 17:52:42,761 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 17:52:42,763 [root] DEBUG: 10028: DLL loaded at 0x00007FFC21D40000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 17:52:42,766 [root] DEBUG: 9864: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 17:52:42,779 [root] DEBUG: 10028: DLL loaded at 0x00007FFC620A0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 17:52:42,846 [root] DEBUG: 9864: DLL loaded at 0x00007FFC72B20000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 17:52:42,848 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75370000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 17:52:42,850 [root] DEBUG: 9864: DLL loaded at 0x00000206AC420000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 17:52:42,852 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6F2C0000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 17:52:42,854 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6C4D0000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 17:52:42,855 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6BB00000: C:\Windows\SYSTEM32\SAMCLI (0x19000 bytes).
2026-05-28 17:52:42,856 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6B340000: C:\Windows\SYSTEM32\SRVCLI (0x28000 bytes).
2026-05-28 17:52:42,858 [root] DEBUG: 9864: DLL loaded at 0x00007FFC74B80000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-28 17:52:42,859 [root] DEBUG: 9864: DLL loaded at 0x00007FFC74BA0000: C:\Windows\SYSTEM32\LOGONCLI (0x43000 bytes).
2026-05-28 17:52:42,860 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6AA30000: C:\Windows\SYSTEM32\SCHEDCLI (0xc000 bytes).
2026-05-28 17:52:42,861 [root] DEBUG: 9864: DLL loaded at 0x00007FFC747D0000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-28 17:52:42,862 [root] DEBUG: 9864: DLL loaded at 0x00007FFC70B70000: C:\Windows\SYSTEM32\DSROLE (0xa000 bytes).
2026-05-28 17:52:42,878 [root] DEBUG: 10028: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 17:52:42,878 [root] DEBUG: 9864: DLL loaded at 0x00007FFC73F70000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 17:52:42,883 [root] DEBUG: 9864: DLL loaded at 0x00007FFC77700000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 17:52:42,885 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 17:52:42,886 [root] DEBUG: 9864: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 17:52:42,888 [root] DEBUG: 9864: DLL loaded at 0x00007FFC73F70000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 17:52:42,889 [root] DEBUG: 9864: DLL loaded at 0x00007FFC77700000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 17:52:42,890 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 17:52:42,892 [root] DEBUG: 9864: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 17:52:42,893 [root] DEBUG: 9864: DLL loaded at 0x00007FFC77700000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 17:52:42,894 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 17:52:42,895 [root] DEBUG: 9864: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 17:52:42,964 [root] DEBUG: 10028: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:52:42,974 [root] DEBUG: 10028: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:52:42,989 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6A9F0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 17:52:42,991 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 17:52:42,992 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 17:52:42,996 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75560000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 17:52:42,998 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 11796: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:52:42,998 [root] DEBUG: 10028: DLL loaded at 0x00007FFC73F40000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 17:52:43,000 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 11796
2026-05-28 17:52:43,000 [root] DEBUG: 10028: DLL loaded at 0x00007FFC747D0000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 17:52:43,003 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 11796
2026-05-28 17:52:43,003 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74B80000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 17:52:43,019 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 17:52:43,022 [root] DEBUG: 10028: DLL loaded at 0x00007FFC659D0000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 17:52:43,025 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 11796, handle 0x23dc: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:43,025 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 17:52:43,026 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 17:52:43,027 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75090000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 17:52:43,028 [root] DEBUG: 10028: DLL loaded at 0x00007FFC77F00000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 17:52:43,029 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6DA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 17:52:43,029 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5B690000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 17:52:43,030 [root] DEBUG: 10028: DLL loaded at 0x00007FFC65AB0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 17:52:43,031 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 17:52:43,032 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75050000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 17:52:43,035 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6C4D0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 17:52:43,036 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 17:52:43,037 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 17:52:43,038 [root] DEBUG: 10028: DLL loaded at 0x00007FFC72B70000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 17:52:43,040 [root] DEBUG: 10028: DLL loaded at 0x00007FFC755E0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 17:52:43,054 [root] DEBUG: 10028: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 17:52:43,056 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 10028, handle 0x23dc: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:43,056 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 17:52:43,058 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 17:52:43,059 [root] DEBUG: 10028: DLL loaded at 0x00007FFC69960000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 17:52:43,063 [root] DEBUG: 10028: DLL loaded at 0x00007FFC61E00000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 17:52:43,066 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75430000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 17:52:43,068 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74A70000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 17:52:43,069 [root] DEBUG: 10028: DLL loaded at 0x00007FFC70B80000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 17:52:43,070 [root] DEBUG: 10028: DLL loaded at 0x00007FFC771D0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 17:52:43,071 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6E0C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 17:52:43,072 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 17:52:43,074 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74AB0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 17:52:43,089 [root] DEBUG: 10028: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 17:52:43,090 [root] DEBUG: 10028: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 17:52:43,091 [root] DEBUG: 10028: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 17:52:43,092 [root] DEBUG: 10028: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 17:52:43,096 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 17:52:43,098 [root] DEBUG: 10028: DLL loaded at 0x00007FFC60C70000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 17:52:43,103 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6ED50000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 17:52:43,107 [root] DEBUG: 10028: DLL loaded at 0x00007FFC70130000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 17:52:43,108 [root] DEBUG: 10028: DLL loaded at 0x00007FFC728F0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 17:52:43,109 [root] DEBUG: 10028: DLL loaded at 0x00007FFC69E70000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 17:52:43,109 [root] DEBUG: 10028: DLL loaded at 0x00007FFC69FD0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 17:52:43,124 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75F50000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 17:52:43,129 [root] DEBUG: 10028: DLL loaded at 0x00007FFC72B20000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 17:52:43,148 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75370000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 17:52:43,156 [root] DEBUG: 10028: DLL loaded at 0x00007FFC21770000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 17:52:43,156 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 17:52:43,167 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6FD90000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 17:52:43,168 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6FDB0000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 17:52:43,172 [root] DEBUG: 10028: DLL loaded at 0x00007FFC68DC0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 17:52:43,195 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6A9D0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 17:52:43,204 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6BCE0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 17:52:43,215 [root] DEBUG: 10028: DLL loaded at 0x00007FFC707B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 17:52:43,219 [root] DEBUG: 10028: DLL loaded at 0x00007FFC69BE0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 17:52:43,419 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5E640000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 17:52:43,442 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 12264: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:52:43,446 [root] DEBUG: 10028: caller_dispatch: Added region at 0x00007FF734750000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF734847D66, thread 12136).
2026-05-28 17:52:43,450 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 12264
2026-05-28 17:52:43,451 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6F400000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 17:52:43,461 [root] DEBUG: 10028: ProcessImageBase: Main module image at 0x00007FF734750000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:52:43,465 [root] DEBUG: 10028: DLL loaded at 0x00007FFC73F70000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 17:52:43,468 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 9188: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:52:43,479 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 12264
2026-05-28 17:52:43,483 [root] DEBUG: 10028: DLL loaded at 0x00007FFC71690000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 17:52:43,484 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 9188
2026-05-28 17:52:43,516 [root] DEBUG: 10028: DLL loaded at 0x00007FFC72020000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 17:52:43,516 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 9188
2026-05-28 17:52:43,624 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5F830000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 17:52:43,710 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 8692: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:52:43,741 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5F9A0000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 17:52:43,746 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 7932: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:52:43,748 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 4608: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:52:43,749 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 8692
2026-05-28 17:52:43,750 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 11796, handle 0xa50: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:43,750 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 7932
2026-05-28 17:52:43,755 [root] DEBUG: 10028: DLL loaded at 0x00007FFC67700000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 17:52:43,755 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 8692
2026-05-28 17:52:43,758 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 4608
2026-05-28 17:52:43,769 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 7932
2026-05-28 17:52:43,844 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 11796 (handle 0xaa0): 0x00007FF734750000.
2026-05-28 17:52:44,395 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6BA50000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 17:52:44,890 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 4608
2026-05-28 17:52:45,212 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 12264, handle 0xaa0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:45,542 [root] DEBUG: 10028: DLL loaded at 0x00007FFC65AC0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 17:52:45,648 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 12264 (handle 0xaa0): 0x00007FF734750000.
2026-05-28 17:52:45,813 [root] DEBUG: 10028: DLL loaded at 0x00007FFC73480000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 17:52:45,906 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 9188, handle 0xaa0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:45,935 [root] DEBUG: 10028: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 17:52:45,936 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 9188 (handle 0xaa0): 0x00007FF734750000.
2026-05-28 17:52:45,947 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 17:52:45,947 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 8692, handle 0xaa0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:45,950 [root] DEBUG: 10028: DLL loaded at 0x00007FFC746B0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 17:52:45,950 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 8692 (handle 0xaa0): 0x00007FF734750000.
2026-05-28 17:52:45,980 [root] DEBUG: 10028: DLL loaded at 0x00007FFC35630000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 17:52:45,981 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 7932, handle 0xaa0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:45,983 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 7932 (handle 0xaa0): 0x00007FF734750000.
2026-05-28 17:52:45,988 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4608, handle 0xaa0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:45,988 [root] DEBUG: 10028: DLL loaded at 0x00007FFC754B0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 17:52:45,993 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4608 (handle 0xaa0): 0x00007FF734750000.
2026-05-28 17:52:45,996 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 17:52:46,001 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 17:52:46,010 [root] DEBUG: 10028: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 17:52:46,015 [root] DEBUG: 10028: DLL loaded at 0x00007FFC63280000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 17:52:46,017 [root] DEBUG: 10028: DLL loaded at 0x00007FFC70650000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 17:52:46,028 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5D4D0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 17:52:46,030 [root] DEBUG: 10028: DLL loaded at 0x00007FFC664D0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 17:52:46,043 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6B370000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 17:52:46,046 [root] DEBUG: 10028: DLL loaded at 0x00007FFC65B50000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 17:52:46,052 [root] DEBUG: 10028: DLL loaded at 0x00007FFC66790000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 17:52:46,054 [root] DEBUG: 10028: DLL loaded at 0x00007FFC650F0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 17:52:46,070 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5E650000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 17:52:46,089 [root] DEBUG: 10028: DLL loaded at 0x00007FFC65020000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 17:52:46,137 [root] DEBUG: 10028: DLL loaded at 0x00007FFC1D890000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 17:52:46,240 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 12404, handle 0xa7c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:52:46,243 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 12404 (handle 0xa7c): 0x00007FF7D0050000.
2026-05-28 17:52:46,746 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 12840, handle 0xa6c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:52:46,748 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 12840 (handle 0xa6c): 0x00007FF7D0050000.
2026-05-28 17:52:47,184 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5CAE0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 17:52:51,888 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 13028: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:52:52,078 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 13028, handle 0xa68: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:52:52,817 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 13028
2026-05-28 17:52:55,065 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 13028
2026-05-28 17:52:55,530 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 13028 (handle 0xaa0): 0x00007FF734750000.
2026-05-28 17:52:56,570 [root] DEBUG: 4584: OpenProcessHandler: Image base for process 10028 (handle 0x22ec): 0x00007FF734750000.
2026-05-28 17:52:58,074 [root] DEBUG: 4584: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2026-05-28 17:53:01,022 [root] DEBUG: 10028: DLL loaded at 0x00007FFC77700000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 17:53:01,403 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 13204: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:53:02,044 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 13204, handle 0xa24: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:02,447 [root] DEBUG: 4584: DLL loaded at 0x00007FFC65A00000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 17:53:02,611 [root] DEBUG: 10028: DLL loaded at 0x00007FFC753D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 17:53:02,717 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 13204
2026-05-28 17:53:02,858 [root] DEBUG: 4584: DLL loaded at 0x00007FFC65A00000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 17:53:02,959 [root] DEBUG: 10028: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 17:53:03,135 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 13204 (handle 0xa24): 0x00007FF734750000.
2026-05-28 17:53:03,241 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 13204
2026-05-28 17:53:03,328 [root] DEBUG: 10028: DLL loaded at 0x00007FFC73380000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 17:53:03,594 [root] DEBUG: 10028: DLL loaded at 0x00007FFC711F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 17:53:03,925 [root] DEBUG: 10028: DLL loaded at 0x00007FFC60E20000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 17:53:04,071 [root] DEBUG: 10028: DLL loaded at 0x00007FFC70770000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 17:53:04,071 [lib.api.process] INFO: Monitor config for process 4584: C:\mtfrhoy9\dll\4584.ini
2026-05-28 17:53:04,075 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:04,076 [root] DEBUG: 10028: DLL loaded at 0x00007FFC1D180000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 17:53:04,077 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:04,085 [root] DEBUG: Loader: Injecting process 4584 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:04,233 [root] DEBUG: 10028: DLL loaded at 0x00007FFC6CEE0000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 17:53:04,233 [root] DEBUG: 4584: caller_dispatch: Added region at 0x00000000087D0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00000000087D0043, thread 12676).
2026-05-28 17:53:04,239 [root] DEBUG: 4584: DumpPEsInRange: Scanning range 0x00000000087D0000 - 0x00000000087D0134.
2026-05-28 17:53:04,241 [root] DEBUG: 4584: ScanForDisguisedPE: Size too small: 0x134 bytes
2026-05-28 17:53:04,243 [lib.common.results] INFO: Uploading file C:\LJDkwoHS\CAPE\4584_98814532128452026 to CAPE\e01c74f30aa62cd96b531e0e2ec04139ce4ac06ca8ba3e3cb6b884a14e425870; Size is 308; Max size: 100000000
2026-05-28 17:53:04,244 [root] DEBUG: 4584: DumpMemory: Payload successfully created: C:\LJDkwoHS\CAPE\4584_98814532128452026 (size 308 bytes)
2026-05-28 17:53:04,245 [root] DEBUG: 4584: DumpRegion: Dumped entire allocation from 0x00000000087D0000, size 4096 bytes.
2026-05-28 17:53:04,246 [root] DEBUG: 4584: ProcessTrackedRegion: Dumped region at 0x00000000087D0000.
2026-05-28 17:53:04,246 [root] DEBUG: 4584: YaraScan: Scanning 0x00000000087D0000, size 0x134
2026-05-28 17:53:04,249 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:53:04,262 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:04,265 [lib.api.process] INFO: Injected into 64-bit <Process 4584 explorer.exe>
2026-05-28 17:53:04,297 [root] DEBUG: 10028: DLL loaded at 0x00007FFC1CE40000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 17:53:04,676 [root] DEBUG: 10028: DLL loaded at 0x00007FFC1FF70000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 17:53:04,682 [root] DEBUG: 10028: DLL loaded at 0x00007FFC742D0000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 17:53:04,683 [root] DEBUG: 10028: DLL loaded at 0x00007FFC74290000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 17:53:04,695 [root] DEBUG: 10028: DLL loaded at 0x00007FFC65AA0000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 17:53:04,705 [root] DEBUG: 10028: DLL loaded at 0x00007FFC5EE50000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 17:53:04,873 [root] DEBUG: 10028: CreateProcessHandler: Injection info set for new process 6028: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 17:53:04,875 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 6028
2026-05-28 17:53:04,876 [root] DEBUG: 10028: ProcessMessage: Skipping monitoring process 6028
2026-05-28 17:53:04,944 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 6028, handle 0x1ed0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:05,144 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 3360, handle 0x1ed0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:05,182 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 17:53:05,778 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6028, handle 0xa38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:05,780 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 6028 (handle 0xa38): 0x00007FF734750000.
2026-05-28 17:53:05,781 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 3360, handle 0xa38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:05,783 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 3360 (handle 0xa38): 0x00007FF734750000.
2026-05-28 17:53:05,784 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1636, handle 0xa38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:05,786 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1636 (handle 0xa38): 0x00007FF734750000.
2026-05-28 17:53:05,787 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1740, handle 0xa38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:05,788 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1740 (handle 0xa38): 0x00007FF734750000.
2026-05-28 17:53:05,790 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1776, handle 0xa38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:05,794 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1776 (handle 0xa38): 0x00007FF734750000.
2026-05-28 17:53:05,983 [root] INFO: Process with pid 10028 appears to have terminated
2026-05-28 17:53:06,316 [root] DEBUG: 4584: DLL loaded at 0x00007FFC601F0000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 17:53:06,366 [root] DEBUG: 4584: DLL loaded at 0x00007FFC601F0000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 17:53:06,393 [root] DEBUG: 4584: DLL loaded at 0x00007FFC657A0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 17:53:06,407 [root] DEBUG: 4584: DLL loaded at 0x00007FFC657A0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 17:53:06,474 [root] DEBUG: 4584: DLL loaded at 0x00007FFC59D80000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 17:53:06,502 [root] DEBUG: 4584: DLL loaded at 0x00007FFC59D80000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 17:53:06,551 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6A5D0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 17:53:06,566 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6A5D0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 17:53:06,645 [root] DEBUG: 4584: DLL loaded at 0x00007FFC1D7E0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 17:53:06,669 [root] DEBUG: 4584: DLL loaded at 0x00007FFC1D7E0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 17:53:06,752 [root] DEBUG: 4584: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 17:53:06,781 [root] DEBUG: 4584: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 17:53:06,824 [root] DEBUG: 4584: DLL loaded at 0x00007FFC1CA50000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 17:53:06,867 [root] DEBUG: 4584: DLL loaded at 0x00007FFC1CA50000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 17:53:06,893 [root] DEBUG: 4584: DLL loaded at 0x00007FFC659F0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 17:53:06,900 [root] DEBUG: 4584: DLL loaded at 0x00007FFC659F0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 17:53:07,516 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5B420000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 17:53:07,526 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5B420000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 17:53:08,041 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5CA40000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 17:53:08,066 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5CA40000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 17:53:08,115 [root] DEBUG: 4584: api-cap: IsDebuggerPresent hook disabled due to count: 5000
2026-05-28 17:53:09,867 [root] DEBUG: 4584: DLL loaded at 0x00007FFC67500000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 17:53:09,883 [root] DEBUG: 4584: DLL loaded at 0x00007FFC67500000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 17:53:10,190 [root] INFO: Added new file to list with pid 4584 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
2026-05-28 17:53:10,332 [root] DEBUG: 4584: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 17:53:10,345 [root] INFO: Added new file to list with pid 4584 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
2026-05-28 17:53:10,425 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 13632: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 17:53:10,447 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13632
2026-05-28 17:53:10,450 [lib.api.process] INFO: Monitor config for process 13632: C:\mtfrhoy9\dll\13632.ini
2026-05-28 17:53:10,457 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:10,458 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:10,558 [root] DEBUG: Loader: Injecting process 13632 (thread 13636) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:10,624 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:10,674 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:10,697 [lib.api.process] INFO: Injected into 64-bit <Process 13632 dllhost.exe>
2026-05-28 17:53:10,753 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13632
2026-05-28 17:53:10,772 [lib.api.process] INFO: Monitor config for process 13632: C:\mtfrhoy9\dll\13632.ini
2026-05-28 17:53:10,780 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:10,781 [root] INFO: Added new file to list with pid 4584 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 17:53:10,783 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:10,830 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 13632, handle 0xa6c: C:\Windows\System32\dllhost.exe
2026-05-28 17:53:10,840 [root] DEBUG: Loader: Injecting process 13632 (thread 13636) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:10,877 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:10,897 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 13808, handle 0xa6c: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:10,925 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 13808 (handle 0xa14): 0x00007FF631A20000.
2026-05-28 17:53:10,952 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:11,002 [lib.api.process] INFO: Injected into 64-bit <Process 13632 dllhost.exe>
2026-05-28 17:53:11,125 [root] DEBUG: 13632: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:53:11,188 [root] DEBUG: 13632: Interactive desktop enabled.
2026-05-28 17:53:11,242 [root] DEBUG: 13632: Dropped file limit defaulting to 100.
2026-05-28 17:53:11,312 [root] DEBUG: 13632: Disabling sleep skipping.
2026-05-28 17:53:11,357 [root] DEBUG: 13632: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:53:11,392 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 13936, handle 0x2820: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 17:53:11,404 [root] DEBUG: 13632: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:53:11,452 [root] DEBUG: 13632: YaraScan: Scanning 0x00007FF699DF0000, size 0x8026
2026-05-28 17:53:11,497 [root] DEBUG: 13632: Monitor initialised: 64-bit capemon loaded in process 13632 at 0x00007FFC37E40000, thread 13636, image base 0x00007FF699DF0000, stack from 0x00000079496F4000-0x0000007949700000
2026-05-28 17:53:11,549 [root] DEBUG: 13632: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 17:53:11,613 [root] DEBUG: 13632: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:53:11,663 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:53:11,728 [root] DEBUG: 13632: set_hooks: Unable to hook LockResource
2026-05-28 17:53:11,774 [root] DEBUG: 13632: Hooked 627 out of 628 functions
2026-05-28 17:53:11,834 [root] DEBUG: 13632: Syscall hook installed, syscall logging level 1
2026-05-28 17:53:11,844 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 13632 (handle 0xa74): 0x00007FF699DF0000.
2026-05-28 17:53:11,862 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 13936, handle 0xa74: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 17:53:11,868 [root] DEBUG: 13632: RestoreHeaders: Restored original import table.
2026-05-28 17:53:11,886 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 13936 (handle 0xa6c): 0x00007FF681F60000.
2026-05-28 17:53:11,929 [root] INFO: Loaded monitor into process with pid 13632
2026-05-28 17:53:11,951 [root] DEBUG: 13632: caller_dispatch: Added region at 0x00007FF699DF0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF699DF1349, thread 13636).
2026-05-28 17:53:11,976 [root] DEBUG: 13632: YaraScan: Scanning 0x00007FF699DF0000, size 0x8026
2026-05-28 17:53:12,010 [root] DEBUG: 13632: ProcessImageBase: Main module image at 0x00007FF699DF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:53:12,027 [root] DEBUG: 13632: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:53:12,052 [root] DEBUG: 13632: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:53:12,103 [root] DEBUG: 13632: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:53:12,222 [root] DEBUG: 13632: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 17:53:12,375 [root] DEBUG: 13632: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 17:53:12,408 [root] DEBUG: 13632: DLL loaded at 0x00007FFC5F2A0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 17:53:12,714 [root] DEBUG: 13632: DLL loaded at 0x00007FFC728F0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 17:53:13,193 [root] INFO: Added new file to list with pid 4584 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-28 17:53:13,896 [root] INFO: Added new file to list with pid 4584 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
2026-05-28 17:53:13,922 [root] DEBUG: 4584: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 17:53:18,333 [root] INFO: Process with pid 13632 has terminated
2026-05-28 17:53:18,502 [root] DEBUG: 13632: NtTerminateProcess hook: Attempting to dump process 13632
2026-05-28 17:53:18,553 [root] DEBUG: 13632: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:53:18,855 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 12556, handle 0xa38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:18,875 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 12556 (handle 0xa38): 0x00007FF734750000.
2026-05-28 17:53:18,894 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 12424, handle 0xa38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:18,964 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 12424 (handle 0xa38): 0x00007FF734750000.
2026-05-28 17:53:28,543 [root] DEBUG: 4584: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 17:53:29,425 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 12588: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 17:53:29,492 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12588
2026-05-28 17:53:29,543 [lib.api.process] INFO: Monitor config for process 12588: C:\mtfrhoy9\dll\12588.ini
2026-05-28 17:53:29,801 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:29,892 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 12588, handle 0xa24: C:\Windows\System32\dllhost.exe
2026-05-28 17:53:29,894 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:30,403 [root] DEBUG: Loader: Injecting process 12588 (thread 12608) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:30,609 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:30,752 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:30,891 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 11280, handle 0xa6c: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:30,923 [lib.api.process] INFO: Injected into 64-bit <Process 12588 dllhost.exe>
2026-05-28 17:53:31,155 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12588
2026-05-28 17:53:31,247 [lib.api.process] INFO: Monitor config for process 12588: C:\mtfrhoy9\dll\12588.ini
2026-05-28 17:53:31,321 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:31,380 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:31,579 [root] DEBUG: Loader: Injecting process 12588 (thread 12608) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:31,820 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:31,861 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1104, handle 0xa6c: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:31,952 [root] DEBUG: 4584: api-rate-cap: NtQueryKey hook disabled due to rate
2026-05-28 17:53:31,993 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:32,034 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1104 (handle 0xaa0): 0x00007FF631A20000.
2026-05-28 17:53:32,144 [lib.api.process] INFO: Injected into 64-bit <Process 12588 dllhost.exe>
2026-05-28 17:53:32,321 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 14028: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 17:53:32,478 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14028
2026-05-28 17:53:32,549 [lib.api.process] INFO: Monitor config for process 14028: C:\mtfrhoy9\dll\14028.ini
2026-05-28 17:53:32,757 [root] DEBUG: 4584: CreateProcessHandler: Injection info set for new process 13892: C:\Windows\system32\msinfo32.exe, ImageBase: 0x00007FF6D6CB0000
2026-05-28 17:53:32,762 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:32,805 [root] DEBUG: 4584: CreateProcessHandler: Injection info set for new process 13892: C:\Windows\system32\msinfo32.exe, ImageBase: 0x00007FF6D6CB0000
2026-05-28 17:53:32,817 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:32,875 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 14028, handle 0xa6c: C:\Windows\System32\dllhost.exe
2026-05-28 17:53:32,953 [root] DEBUG: 4584: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 17:53:33,030 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 13892
2026-05-28 17:53:33,102 [lib.api.process] INFO: Monitor config for process 13892: C:\mtfrhoy9\dll\13892.ini
2026-05-28 17:53:33,109 [root] DEBUG: Loader: Injecting process 14028 (thread 13636) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:33,194 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:33,214 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 13892, handle 0xa6c: C:\Windows\System32\msinfo32.exe
2026-05-28 17:53:33,216 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:33,276 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:33,342 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:33,435 [root] DEBUG: Loader: Injecting process 13892 (thread 12416) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:33,485 [lib.api.process] INFO: Injected into 64-bit <Process 14028 dllhost.exe>
2026-05-28 17:53:33,546 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:33,610 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14028
2026-05-28 17:53:33,670 [lib.api.process] INFO: Monitor config for process 14028: C:\mtfrhoy9\dll\14028.ini
2026-05-28 17:53:33,701 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:33,728 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:33,836 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:33,883 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 6864, handle 0xa6c: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:33,912 [lib.api.process] INFO: Injected into 64-bit <Process 13892 msinfo32.exe>
2026-05-28 17:53:34,055 [root] DEBUG: Loader: Injecting process 14028 (thread 13636) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:34,153 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 13892
2026-05-28 17:53:34,171 [lib.api.process] INFO: Monitor config for process 13892: C:\mtfrhoy9\dll\13892.ini
2026-05-28 17:53:34,172 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:34,172 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:34,177 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:34,271 [root] DEBUG: 4584: CreateProcessHandler: Injection info set for new process 13580: C:\Windows\system32\msinfo32.exe, ImageBase: 0x00007FF6D6CB0000
2026-05-28 17:53:34,296 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:34,297 [root] DEBUG: Loader: Injecting process 13892 (thread 12416) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:34,379 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 13580
2026-05-28 17:53:34,399 [lib.api.process] INFO: Injected into 64-bit <Process 14028 dllhost.exe>
2026-05-28 17:53:34,430 [lib.api.process] INFO: Monitor config for process 13580: C:\mtfrhoy9\dll\13580.ini
2026-05-28 17:53:34,434 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:34,488 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:34,490 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 10668: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 17:53:34,540 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:34,540 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:34,634 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10668
2026-05-28 17:53:34,685 [lib.api.process] INFO: Injected into 64-bit <Process 13892 msinfo32.exe>
2026-05-28 17:53:34,701 [lib.api.process] INFO: Monitor config for process 10668: C:\mtfrhoy9\dll\10668.ini
2026-05-28 17:53:34,732 [root] DEBUG: Loader: Injecting process 13580 (thread 7844) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:34,806 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:34,899 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:34,901 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:34,913 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 13892 (handle 0xa24): 0x00007FF6D6CB0000.
2026-05-28 17:53:35,002 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 13892
2026-05-28 17:53:35,080 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:35,082 [lib.api.process] INFO: Monitor config for process 13892: C:\mtfrhoy9\dll\13892.ini
2026-05-28 17:53:35,151 [root] DEBUG: Loader: Injecting process 10668 (thread 11280) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:35,197 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:35,198 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 13580, handle 0xa24: C:\Windows\System32\msinfo32.exe
2026-05-28 17:53:35,299 [lib.api.process] INFO: Injected into 64-bit <Process 13580 msinfo32.exe>
2026-05-28 17:53:35,304 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:35,305 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:35,353 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 10668, handle 0xa24: C:\Windows\System32\dllhost.exe
2026-05-28 17:53:35,372 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 13580
2026-05-28 17:53:35,430 [lib.api.process] INFO: Monitor config for process 13580: C:\mtfrhoy9\dll\13580.ini
2026-05-28 17:53:35,469 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:35,509 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:35,545 [root] DEBUG: Loader: Injecting process 13892 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:35,560 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:35,619 [lib.api.process] INFO: Injected into 64-bit <Process 10668 dllhost.exe>
2026-05-28 17:53:35,653 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12416, handle 0x120
2026-05-28 17:53:35,711 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10668
2026-05-28 17:53:35,724 [lib.api.process] INFO: Monitor config for process 10668: C:\mtfrhoy9\dll\10668.ini
2026-05-28 17:53:35,754 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:53:35,770 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:35,789 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:35,821 [root] DEBUG: Loader: Injecting process 13580 (thread 7844) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:35,844 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:35,896 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 13580 (handle 0xaa0): 0x00007FF6D6CB0000.
2026-05-28 17:53:35,921 [root] DEBUG: Loader: Injecting process 10668 (thread 11280) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:35,962 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:36,092 [lib.api.process] INFO: Injected into 64-bit <Process 13892 msinfo32.exe>
2026-05-28 17:53:36,123 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4064, handle 0xaa0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:53:36,146 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:36,199 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:36,265 [lib.api.process] INFO: Injected into 64-bit <Process 13580 msinfo32.exe>
2026-05-28 17:53:36,266 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4064 (handle 0xaa0): 0x00007FF734750000.
2026-05-28 17:53:36,288 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:36,311 [root] DEBUG: 13892: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:53:36,318 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 13580
2026-05-28 17:53:36,320 [lib.api.process] INFO: Monitor config for process 13580: C:\mtfrhoy9\dll\13580.ini
2026-05-28 17:53:36,322 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:36,326 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:36,409 [lib.api.process] INFO: Injected into 64-bit <Process 10668 dllhost.exe>
2026-05-28 17:53:36,410 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2320, handle 0xaa0: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:36,488 [root] DEBUG: 13892: Interactive desktop enabled.
2026-05-28 17:53:36,545 [root] DEBUG: Loader: Injecting process 13580 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:36,561 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 14432: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 17:53:36,608 [root] DEBUG: 13892: Dropped file limit defaulting to 100.
2026-05-28 17:53:36,648 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 7844, handle 0x120
2026-05-28 17:53:36,657 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14432
2026-05-28 17:53:36,680 [lib.api.process] INFO: Monitor config for process 14432: C:\mtfrhoy9\dll\14432.ini
2026-05-28 17:53:36,699 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:53:36,699 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:36,712 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:36,744 [root] DEBUG: 13892: Disabling sleep skipping.
2026-05-28 17:53:36,845 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:36,867 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 14408, handle 0xa68: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:36,928 [lib.api.process] INFO: Injected into 64-bit <Process 13580 msinfo32.exe>
2026-05-28 17:53:36,945 [root] DEBUG: 13892: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:53:36,992 [root] DEBUG: Loader: Injecting process 14432 (thread 14436) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:37,051 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 14408 (handle 0xa24): 0x00007FF631A20000.
2026-05-28 17:53:37,052 [root] DEBUG: 13580: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:53:37,082 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:37,105 [root] DEBUG: 13892: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:53:37,148 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 14432, handle 0xa24: C:\Windows\System32\dllhost.exe
2026-05-28 17:53:37,192 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:37,233 [root] DEBUG: 13892: YaraScan: Scanning 0x00007FF6D6CB0000, size 0x66322
2026-05-28 17:53:37,286 [lib.api.process] INFO: Injected into 64-bit <Process 14432 dllhost.exe>
2026-05-28 17:53:37,286 [root] DEBUG: 13580: Interactive desktop enabled.
2026-05-28 17:53:37,287 [root] DEBUG: 13892: Monitor initialised: 64-bit capemon loaded in process 13892 at 0x00007FFC37E40000, thread 12416, image base 0x00007FF6D6CB0000, stack from 0x00000019903B4000-0x00000019903C0000
2026-05-28 17:53:37,344 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 14476, handle 0xa24: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:37,408 [root] DEBUG: 13580: Dropped file limit defaulting to 100.
2026-05-28 17:53:37,485 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14432
2026-05-28 17:53:37,487 [lib.api.process] INFO: Monitor config for process 14432: C:\mtfrhoy9\dll\14432.ini
2026-05-28 17:53:37,488 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:37,487 [root] DEBUG: 13892: Commandline: "C:\Windows\system32\msinfo32.exe"
2026-05-28 17:53:37,494 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:37,497 [root] DEBUG: 13580: Disabling sleep skipping.
2026-05-28 17:53:37,540 [root] DEBUG: 13892: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:53:37,634 [root] DEBUG: 13580: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:53:37,770 [root] DEBUG: Loader: Injecting process 14432 (thread 14436) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:37,801 [root] DEBUG: 13580: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:53:37,802 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:37,838 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:53:37,880 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 14600, handle 0xa24: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:38,028 [root] DEBUG: 13580: YaraScan: Scanning 0x00007FF6D6CB0000, size 0x66322
2026-05-28 17:53:38,086 [root] DEBUG: 13892: set_hooks: Unable to hook LockResource
2026-05-28 17:53:38,127 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:38,157 [root] DEBUG: 13580: Monitor initialised: 64-bit capemon loaded in process 13580 at 0x00007FFC37E40000, thread 7844, image base 0x00007FF6D6CB0000, stack from 0x00000064538A4000-0x00000064538B0000
2026-05-28 17:53:38,212 [lib.api.process] INFO: Injected into 64-bit <Process 14432 dllhost.exe>
2026-05-28 17:53:38,272 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 14600 (handle 0xa68): 0x00007FF631A20000.
2026-05-28 17:53:38,393 [root] DEBUG: 13580: Commandline: "C:\Windows\system32\msinfo32.exe"
2026-05-28 17:53:38,463 [root] DEBUG: 13892: Hooked 627 out of 628 functions
2026-05-28 17:53:38,513 [root] DEBUG: 13580: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:53:38,604 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 14688: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 17:53:38,605 [root] DEBUG: 13892: Syscall hook installed, syscall logging level 1
2026-05-28 17:53:38,710 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:53:38,729 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14688
2026-05-28 17:53:38,745 [root] DEBUG: 13892: RestoreHeaders: Restored original import table.
2026-05-28 17:53:38,748 [lib.api.process] INFO: Monitor config for process 14688: C:\mtfrhoy9\dll\14688.ini
2026-05-28 17:53:38,750 [root] DEBUG: 13580: set_hooks: Unable to hook LockResource
2026-05-28 17:53:38,757 [root] INFO: Loaded monitor into process with pid 13892
2026-05-28 17:53:38,805 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:38,834 [root] DEBUG: 13580: Hooked 627 out of 628 functions
2026-05-28 17:53:38,853 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:38,856 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 14688, handle 0xa68: C:\Windows\System32\dllhost.exe
2026-05-28 17:53:38,887 [root] DEBUG: 13892: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:53:38,956 [root] DEBUG: 13580: Syscall hook installed, syscall logging level 1
2026-05-28 17:53:38,997 [root] DEBUG: 13892: DLL loaded at 0x00007FFC75440000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 17:53:39,033 [root] DEBUG: Loader: Injecting process 14688 (thread 14692) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:39,051 [root] DEBUG: 13892: caller_dispatch: Added region at 0x00007FF6D6CB0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6D6CD1A71, thread 12416).
2026-05-28 17:53:39,095 [root] DEBUG: 13580: RestoreHeaders: Restored original import table.
2026-05-28 17:53:39,135 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:39,141 [root] DEBUG: 13892: YaraScan: Scanning 0x00007FF6D6CB0000, size 0x66322
2026-05-28 17:53:39,154 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:39,232 [root] DEBUG: 13892: ProcessImageBase: Main module image at 0x00007FF6D6CB0000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:53:39,267 [lib.api.process] INFO: Injected into 64-bit <Process 14688 dllhost.exe>
2026-05-28 17:53:39,277 [root] INFO: Loaded monitor into process with pid 13580
2026-05-28 17:53:39,334 [root] DEBUG: 13892: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:53:39,367 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14688
2026-05-28 17:53:39,379 [lib.api.process] INFO: Monitor config for process 14688: C:\mtfrhoy9\dll\14688.ini
2026-05-28 17:53:39,380 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:39,379 [root] DEBUG: 13892: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 17:53:39,386 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:39,410 [root] DEBUG: 13580: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:53:39,535 [root] DEBUG: Loader: Injecting process 14688 (thread 14692) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:39,554 [root] DEBUG: 13892: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 17:53:39,597 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:39,632 [root] DEBUG: 13580: DLL loaded at 0x00007FFC75440000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 17:53:39,636 [root] DEBUG: 13892: DLL loaded at 0x00007FFC66930000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 17:53:39,655 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:39,727 [root] DEBUG: 13580: caller_dispatch: Added region at 0x00007FF6D6CB0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6D6CD1A71, thread 7844).
2026-05-28 17:53:39,745 [lib.api.process] INFO: Injected into 64-bit <Process 14688 dllhost.exe>
2026-05-28 17:53:39,830 [root] DEBUG: 13580: YaraScan: Scanning 0x00007FF6D6CB0000, size 0x66322
2026-05-28 17:53:40,021 [root] DEBUG: 13892: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:53:40,047 [root] DEBUG: 13580: ProcessImageBase: Main module image at 0x00007FF6D6CB0000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:53:40,070 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 14884: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 17:53:40,084 [root] DEBUG: 13580: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:53:40,099 [root] DEBUG: 13892: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 17:53:40,154 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14884
2026-05-28 17:53:40,177 [lib.api.process] INFO: Monitor config for process 14884: C:\mtfrhoy9\dll\14884.ini
2026-05-28 17:53:40,204 [root] DEBUG: 13892: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 17:53:40,240 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:40,240 [root] DEBUG: 13580: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 17:53:40,250 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:40,271 [root] DEBUG: 13892: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 17:53:40,323 [root] DEBUG: 13580: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 17:53:40,360 [root] DEBUG: Loader: Injecting process 14884 (thread 14888) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:40,480 [root] DEBUG: 13892: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 17:53:40,629 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:40,766 [root] DEBUG: 13580: DLL loaded at 0x00007FFC66930000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 17:53:40,818 [root] DEBUG: 13892: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:53:40,828 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:40,878 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 14884, handle 0xa24: C:\Windows\System32\dllhost.exe
2026-05-28 17:53:40,894 [root] DEBUG: 13892: DLL loaded at 0x00007FFC6B8D0000: C:\Windows\SYSTEM32\wbemcomn (0x90000 bytes).
2026-05-28 17:53:40,894 [lib.api.process] INFO: Injected into 64-bit <Process 14884 dllhost.exe>
2026-05-28 17:53:40,960 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 14932, handle 0xa24: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:40,987 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14884
2026-05-28 17:53:41,007 [lib.api.process] INFO: Monitor config for process 14884: C:\mtfrhoy9\dll\14884.ini
2026-05-28 17:53:41,033 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:41,073 [root] DEBUG: 13892: DLL loaded at 0x00007FFC61080000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 17:53:41,127 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:41,232 [root] DEBUG: 13892: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 17:53:41,288 [root] DEBUG: 13580: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:53:41,376 [root] DEBUG: Loader: Injecting process 14884 (thread 14888) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:41,414 [root] DEBUG: 13892: DLL loaded at 0x00007FFC63BB0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 17:53:41,490 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:41,555 [root] DEBUG: 13580: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 17:53:41,596 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:41,655 [root] DEBUG: 13580: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 17:53:41,737 [lib.api.process] INFO: Injected into 64-bit <Process 14884 dllhost.exe>
2026-05-28 17:53:41,831 [root] DEBUG: 13580: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 17:53:41,989 [root] DEBUG: 13580: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 17:53:42,039 [root] DEBUG: 13892: DLL loaded at 0x00007FFC600A0000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2026-05-28 17:53:42,141 [root] DEBUG: 13580: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:53:42,186 [root] DEBUG: 13892: DLL loaded at 0x00007FFC5F5C0000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 17:53:42,264 [root] DEBUG: 13580: DLL loaded at 0x00007FFC6B8D0000: C:\Windows\SYSTEM32\wbemcomn (0x90000 bytes).
2026-05-28 17:53:42,334 [root] DEBUG: 13892: DLL loaded at 0x00007FFC75560000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 17:53:42,417 [root] DEBUG: 13580: DLL loaded at 0x00007FFC61080000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 17:53:42,422 [root] DEBUG: 13892: DLL loaded at 0x00007FFC755E0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 17:53:42,429 [root] DEBUG: 13580: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 17:53:42,551 [root] DEBUG: 13892: DLL loaded at 0x00007FFC5F570000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 17:53:42,564 [root] DEBUG: 13580: DLL loaded at 0x00007FFC63BB0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 17:53:42,598 [root] DEBUG: 13892: DLL loaded at 0x00007FFC63BA0000: C:\Windows\system32\version (0xa000 bytes).
2026-05-28 17:53:42,690 [root] DEBUG: 13892: Successfully installed hook on COM Object function IWbemServices_ExecQuery
2026-05-28 17:53:42,741 [root] DEBUG: 13580: DLL loaded at 0x00007FFC600A0000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2026-05-28 17:53:42,805 [root] DEBUG: 13892: Successfully installed hook on COM Object function IWbemServices_ExecQueryAsync
2026-05-28 17:53:42,913 [root] DEBUG: 13580: DLL loaded at 0x00007FFC5F5C0000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 17:53:42,966 [root] DEBUG: 13892: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnum
2026-05-28 17:53:42,967 [root] DEBUG: 13580: DLL loaded at 0x00007FFC75560000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 17:53:43,015 [root] DEBUG: 13892: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnumAsync
2026-05-28 17:53:43,015 [root] DEBUG: 13580: DLL loaded at 0x00007FFC755E0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 17:53:43,067 [root] DEBUG: 13892: Successfully installed hook on COM Object function IWbemServices_GetObjectW
2026-05-28 17:53:43,117 [root] DEBUG: 13580: DLL loaded at 0x00007FFC5F570000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 17:53:43,175 [root] DEBUG: 13580: DLL loaded at 0x00007FFC63BA0000: C:\Windows\system32\version (0xa000 bytes).
2026-05-28 17:53:43,249 [root] DEBUG: 13892: Successfully installed hook on COM Object function IWbemServices_GetObjectAsync
2026-05-28 17:53:43,251 [root] DEBUG: 13580: Successfully installed hook on COM Object function IWbemServices_ExecQuery
2026-05-28 17:53:43,310 [root] DEBUG: 13892: Successfully installed hook on COM Object function IWbemServices_ExecMethod
2026-05-28 17:53:43,315 [root] DEBUG: 13580: Successfully installed hook on COM Object function IWbemServices_ExecQueryAsync
2026-05-28 17:53:43,366 [root] DEBUG: 13892: Successfully installed hook on COM Object function IWbemServices_ExecMethodAsync
2026-05-28 17:53:43,408 [root] DEBUG: 13580: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnum
2026-05-28 17:53:43,484 [root] DEBUG: 13580: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnumAsync
2026-05-28 17:53:43,534 [root] DEBUG: 13580: Successfully installed hook on COM Object function IWbemServices_GetObjectW
2026-05-28 17:53:43,640 [root] DEBUG: 13580: Successfully installed hook on COM Object function IWbemServices_GetObjectAsync
2026-05-28 17:53:43,738 [root] DEBUG: 13580: Successfully installed hook on COM Object function IWbemServices_ExecMethod
2026-05-28 17:53:43,829 [root] DEBUG: 13580: Successfully installed hook on COM Object function IWbemServices_ExecMethodAsync
2026-05-28 17:53:44,515 [root] DEBUG: 13580: NtTerminateProcess hook: Attempting to dump process 13580
2026-05-28 17:53:44,663 [root] DEBUG: 13580: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:53:44,776 [root] INFO: Process with pid 13580 has terminated
2026-05-28 17:53:44,882 [root] DEBUG: 4584: api-cap: NtSetInformationThread hook disabled due to count: 5000
2026-05-28 17:53:45,018 [root] DEBUG: 4584: api-cap: NtSetInformationThread hook disabled due to count: 5001
2026-05-28 17:53:45,108 [root] DEBUG: 4584: api-cap: NtSetInformationThread hook disabled due to count: 5004
2026-05-28 17:53:45,185 [root] DEBUG: 4584: api-cap: NtSetInformationThread hook disabled due to count: 5003
2026-05-28 17:53:45,224 [root] DEBUG: 4584: api-cap: NtSetInformationThread hook disabled due to count: 5005
2026-05-28 17:53:45,354 [root] DEBUG: 4584: api-cap: NtSetInformationThread hook disabled due to count: 5004
2026-05-28 17:53:47,320 [root] DEBUG: 9864: DLL loaded at 0x00007FFC70730000: C:\Windows\SYSTEM32\winbrand (0x35000 bytes).
2026-05-28 17:53:47,476 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 17:53:47,632 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 17:53:47,848 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 17:53:47,988 [root] DEBUG: 9864: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 17:53:48,145 [root] DEBUG: 9864: DLL loaded at 0x00000206AC410000: C:\Windows\SYSTEM32\SECURITY (0x3000 bytes).
2026-05-28 17:53:48,268 [root] DEBUG: 9864: DLL loaded at 0x00007FFC68DC0000: C:\Windows\SYSTEM32\SECUR32 (0xc000 bytes).
2026-05-28 17:53:48,395 [root] DEBUG: 9864: DLL loaded at 0x00007FFC745C0000: C:\Windows\system32\schannel (0x97000 bytes).
2026-05-28 17:53:48,547 [root] DEBUG: 9864: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 17:53:49,009 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6C4D0000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 17:53:49,208 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6BB00000: C:\Windows\SYSTEM32\SAMCLI (0x19000 bytes).
2026-05-28 17:53:49,365 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6B340000: C:\Windows\SYSTEM32\SRVCLI (0x28000 bytes).
2026-05-28 17:53:49,544 [root] DEBUG: 9864: DLL loaded at 0x00007FFC74B80000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-28 17:53:49,724 [root] DEBUG: 9864: DLL loaded at 0x00007FFC74BA0000: C:\Windows\SYSTEM32\LOGONCLI (0x43000 bytes).
2026-05-28 17:53:49,895 [root] DEBUG: 9864: DLL loaded at 0x00007FFC708C0000: C:\Windows\SYSTEM32\SCHEDCLI (0xc000 bytes).
2026-05-28 17:53:50,012 [root] DEBUG: 9864: DLL loaded at 0x00007FFC747D0000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-28 17:53:50,167 [root] DEBUG: 9864: DLL loaded at 0x00007FFC70B70000: C:\Windows\SYSTEM32\DSROLE (0xa000 bytes).
2026-05-28 17:53:50,424 [root] DEBUG: 9864: DLL loaded at 0x00007FFC61DE0000: C:\Windows\SYSTEM32\cscapi (0x12000 bytes).
2026-05-28 17:53:55,485 [root] DEBUG: 8832: DLL loaded at 0x00007FFC6CE00000: C:\Windows\system32\wbem\ncprov (0x21000 bytes).
2026-05-28 17:53:56,614 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 15396: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF6209B0000
2026-05-28 17:53:56,753 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 15396
2026-05-28 17:53:56,803 [lib.api.process] INFO: Monitor config for process 15396: C:\mtfrhoy9\dll\15396.ini
2026-05-28 17:53:56,876 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 15396, handle 0xa68: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-28 17:53:56,985 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:57,004 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 15396 (handle 0xa68): 0x00007FF6209B0000.
2026-05-28 17:53:57,326 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:57,645 [root] DEBUG: Loader: Injecting process 15396 (thread 15400) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:57,769 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:53:57,904 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 15432, handle 0xa68: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:57,941 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:58,082 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 15432 (handle 0x6bc): 0x00007FF631A20000.
2026-05-28 17:53:58,299 [lib.api.process] INFO: Injected into 64-bit <Process 15396 WmiPrvSE.exe>
2026-05-28 17:53:58,499 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 15396
2026-05-28 17:53:58,559 [lib.api.process] INFO: Monitor config for process 15396: C:\mtfrhoy9\dll\15396.ini
2026-05-28 17:53:58,669 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:58,965 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:59,036 [root] INFO: Announced 64-bit process name: Discord.exe pid: 3484
2026-05-28 17:53:59,161 [lib.api.process] INFO: Monitor config for process 3484: C:\mtfrhoy9\dll\3484.ini
2026-05-28 17:53:59,300 [root] DEBUG: Loader: Injecting process 15396 (thread 15400) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:59,308 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:53:59,503 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:53:59,563 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 17:53:59,708 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:59,738 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:59,826 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 15516, handle 0x6bc: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:53:59,939 [root] DEBUG: Loader: Injecting process 3484 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:53:59,954 [lib.api.process] INFO: Injected into 64-bit <Process 15396 WmiPrvSE.exe>
2026-05-28 17:54:00,098 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 15556, handle 0x6bc: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:54:00,196 [root] DEBUG: 15396: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:54:00,238 [root] DEBUG: 3484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:54:00,347 [root] DEBUG: 15396: Interactive desktop enabled.
2026-05-28 17:54:00,404 [root] DEBUG: 3484: Interactive desktop enabled.
2026-05-28 17:54:00,517 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 15556 (handle 0xa68): 0x00007FF631A20000.
2026-05-28 17:54:00,624 [root] DEBUG: 3484: Dropped file limit defaulting to 100.
2026-05-28 17:54:00,675 [root] DEBUG: 15396: Dropped file limit defaulting to 100.
2026-05-28 17:54:00,895 [root] DEBUG: 3484: Disabling sleep skipping.
2026-05-28 17:54:01,094 [root] DEBUG: 3484: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:54:01,182 [root] DEBUG: 15396: Disabling sleep skipping.
2026-05-28 17:54:01,263 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 15580, handle 0x6bc: C:\Windows\System32\svchost.exe
2026-05-28 17:54:01,395 [root] DEBUG: 3484: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:54:01,473 [root] DEBUG: 15396: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:54:01,585 [root] DEBUG: 3484: YaraScan: Scanning 0x00007FF6B1860000, size 0xbe3adda
2026-05-28 17:54:01,693 [root] DEBUG: 15396: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:54:01,926 [root] DEBUG: 15396: YaraScan: Scanning 0x00007FF6209B0000, size 0x7dcfe
2026-05-28 17:54:02,211 [root] DEBUG: 15396: Monitor initialised: 64-bit capemon loaded in process 15396 at 0x00007FFC37E40000, thread 15400, image base 0x00007FF6209B0000, stack from 0x0000009B68CF0000-0x0000009B68D00000
2026-05-28 17:54:02,506 [root] DEBUG: 15396: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -Embedding
2026-05-28 17:54:02,694 [root] DEBUG: 3484: Yara error: Scanning timed out
2026-05-28 17:54:02,722 [root] DEBUG: 15396: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:54:02,833 [root] DEBUG: 3484: Monitor initialised: 64-bit capemon loaded in process 3484 at 0x00007FFC37E40000, thread 15592, image base 0x00007FF6B1860000, stack from 0x000000B02F9F4000-0x000000B02FA00000
2026-05-28 17:54:02,889 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:54:02,900 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 15768, handle 0x6c8: C:\Windows\System32\svchost.exe
2026-05-28 17:54:02,988 [root] DEBUG: 3484: Commandline: "C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe"
2026-05-28 17:54:03,088 [root] DEBUG: 15396: set_hooks: Unable to hook LockResource
2026-05-28 17:54:03,248 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 15768 (handle 0x6c8): 0x00007FF780360000.
2026-05-28 17:54:03,334 [root] DEBUG: 15396: Hooked 627 out of 628 functions
2026-05-28 17:54:03,395 [root] DEBUG: 3484: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:54:03,521 [root] DEBUG: 15396: Syscall hook installed, syscall logging level 1
2026-05-28 17:54:03,561 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:54:03,649 [root] DEBUG: 15396: RestoreHeaders: Restored original import table.
2026-05-28 17:54:03,698 [root] DEBUG: 3484: set_hooks: Unable to hook LockResource
2026-05-28 17:54:03,868 [root] INFO: Loaded monitor into process with pid 15396
2026-05-28 17:54:03,963 [root] DEBUG: 3484: Hooked 627 out of 628 functions
2026-05-28 17:54:04,175 [root] DEBUG: 15396: caller_dispatch: Added region at 0x00007FF6209B0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6209C2CD1, thread 15400).
2026-05-28 17:54:04,397 [root] DEBUG: 15396: YaraScan: Scanning 0x00007FF6209B0000, size 0x7dcfe
2026-05-28 17:54:04,628 [root] DEBUG: 15396: ProcessImageBase: Main module image at 0x00007FF6209B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:54:04,912 [root] DEBUG: 15396: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:54:05,161 [root] DEBUG: 15396: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:54:05,276 [root] DEBUG: 3484: Yara error: Scanning timed out
2026-05-28 17:54:05,309 [root] DEBUG: 15396: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:54:05,395 [root] DEBUG: 3484: Syscall hook installed, syscall logging level 1
2026-05-28 17:54:05,535 [root] INFO: Loaded monitor into process with pid 3484
2026-05-28 17:54:05,632 [root] DEBUG: 15396: DLL loaded at 0x00007FFC61080000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 17:54:05,677 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:54:05,738 [root] DEBUG: 3484: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 17:54:05,858 [root] DEBUG: 15396: DLL loaded at 0x00007FFC63BB0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 17:54:05,992 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:06,208 [root] DEBUG: 3484: YaraScan: Scanning 0x00007FF6B1860000, size 0xbe3adda
2026-05-28 17:54:06,331 [lib.api.process] INFO: Injected into 64-bit <Process 3484 Discord.exe>
2026-05-28 17:54:06,732 [root] DEBUG: 3484: caller_dispatch: Added region at 0x00007FF6B1860000 to tracked regions list (ntdll::NtSetInformationThread returns to 0x00007FF6B3EE52C0, thread 3496).
2026-05-28 17:54:06,949 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 16052: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 17:54:07,147 [root] DEBUG: 3484: YaraScan: Scanning 0x00007FF6B1860000, size 0xbe3adda
2026-05-28 17:54:07,236 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 15988, handle 0x6c8: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
2026-05-28 17:54:07,704 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 16052
2026-05-28 17:54:07,757 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6CDC0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 17:54:07,757 [lib.api.process] INFO: Monitor config for process 16052: C:\mtfrhoy9\dll\16052.ini
2026-05-28 17:54:07,829 [root] DEBUG: 3484: Yara error: Scanning timed out
2026-05-28 17:54:07,970 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:54:08,071 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:54:08,250 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 15988 (handle 0x740): 0x0000000000030000.
2026-05-28 17:54:08,286 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6CDC0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 17:54:08,316 [root] DEBUG: 3484: ProcessImageBase: Main module image at 0x00007FF6B1860000 unmodified (entropy change 1.671899e-07)
2026-05-28 17:54:08,339 [root] DEBUG: 3484: Yara error: Scanning timed out
2026-05-28 17:54:08,522 [root] DEBUG: Loader: Injecting process 16052 (thread 16056) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:08,555 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6A330000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 17:54:08,658 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 16052, handle 0x740: C:\Windows\System32\dllhost.exe
2026-05-28 17:54:08,721 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:54:08,739 [root] DEBUG: 15396: DLL loaded at 0x00007FFC656B0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 17:54:08,757 [root] DEBUG: 3484: ProcessImageBase: Main module image at 0x00007FF6B1860000 unmodified (entropy change 1.618634e-07)
2026-05-28 17:54:08,784 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6A330000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 17:54:08,890 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:09,050 [lib.api.process] INFO: Injected into 64-bit <Process 16052 dllhost.exe>
2026-05-28 17:54:09,105 [root] DEBUG: 4584: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 17:54:09,186 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 16148, handle 0x740: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:54:09,279 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 16052
2026-05-28 17:54:09,298 [lib.api.process] INFO: Monitor config for process 16052: C:\mtfrhoy9\dll\16052.ini
2026-05-28 17:54:09,340 [root] DEBUG: 4584: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 17:54:09,351 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:54:09,467 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:54:09,479 [root] DEBUG: 4584: DLL loaded at 0x00007FFC65AD0000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 17:54:09,641 [root] DEBUG: 4584: DLL loaded at 0x00007FFC65AD0000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 17:54:09,660 [root] DEBUG: Loader: Injecting process 16052 (thread 16056) with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:09,879 [root] DEBUG: 4584: DLL loaded at 0x00007FFC65AF0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 17:54:09,905 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:54:09,992 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 16288, handle 0x740: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:54:10,312 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:10,430 [root] DEBUG: 4584: OpenProcessHandler: Image base for process 3484 (handle 0x21ac): 0x00007FF6B1860000.
2026-05-28 17:54:10,548 [root] DEBUG: 4584: DLL loaded at 0x00007FFC65AF0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 17:54:10,598 [lib.api.process] INFO: Injected into 64-bit <Process 16052 dllhost.exe>
2026-05-28 17:54:10,709 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 16288 (handle 0xa68): 0x00007FF631A20000.
2026-05-28 17:54:10,851 [root] DEBUG: 4584: DLL loaded at 0x00007FFC732A0000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 17:54:10,998 [root] DEBUG: 16052: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:54:11,058 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 16052 (handle 0x740): 0x00007FF699DF0000.
2026-05-28 17:54:11,194 [root] DEBUG: 4584: DLL loaded at 0x00007FFC732A0000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 17:54:11,249 [root] DEBUG: 16052: Interactive desktop enabled.
2026-05-28 17:54:11,325 [root] INFO: Announced 32-bit process name: OneDrive.exe pid: 4944
2026-05-28 17:54:11,372 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 16336, handle 0x740: C:\Windows\System32\svchost.exe
2026-05-28 17:54:11,388 [lib.api.process] INFO: Monitor config for process 4944: C:\mtfrhoy9\dll\4944.ini
2026-05-28 17:54:11,449 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5C0A0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 17:54:11,583 [root] DEBUG: 16052: Dropped file limit defaulting to 100.
2026-05-28 17:54:11,717 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:54:11,716 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 16336 (handle 0x740): 0x00007FF780360000.
2026-05-28 17:54:11,727 [lib.api.process] INFO: 32-bit DLL to inject is C:\mtfrhoy9\dll\XMmUhAK.dll, loader C:\mtfrhoy9\bin\vBlSepb.exe
2026-05-28 17:54:11,815 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5C0A0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 17:54:11,943 [root] INFO: Added new file to list with pid 3484 and path C:\Users\admin\AppData\Roaming\discord\settings.json
2026-05-28 17:54:12,138 [root] DEBUG: Loader: Injecting process 4944 with C:\mtfrhoy9\dll\XMmUhAK.dll.
2026-05-28 17:54:12,302 [root] DEBUG: 16052: Disabling sleep skipping.
2026-05-28 17:54:12,400 [root] DEBUG: 4584: DLL loaded at 0x00007FFC659D0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 17:54:12,564 [root] DEBUG: 4944: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:54:12,689 [root] DEBUG: 16052: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:54:12,773 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 1416, handle 0xa4c: C:\mtfrhoy9\bin\vBlSepb.exe
2026-05-28 17:54:12,862 [root] INFO: Process with pid 6600 has terminated
2026-05-28 17:54:12,951 [root] DEBUG: 4944: Interactive desktop enabled.
2026-05-28 17:54:13,048 [root] INFO: Added new file to list with pid 3484 and path C:\Users\admin\AppData\Roaming\discord\userDataCache.json
2026-05-28 17:54:13,145 [root] DEBUG: 4944: Dropped file limit defaulting to 100.
2026-05-28 17:54:13,296 [root] DEBUG: 16052: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:54:13,438 [root] DEBUG: 4584: DLL loaded at 0x00007FFC659D0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 17:54:13,626 [root] DEBUG: 16052: YaraScan: Scanning 0x00007FF699DF0000, size 0x8026
2026-05-28 17:54:13,794 [root] DEBUG: 4944: Disabling sleep skipping.
2026-05-28 17:54:13,906 [root] DEBUG: 16052: Monitor initialised: 64-bit capemon loaded in process 16052 at 0x00007FFC37E40000, thread 16056, image base 0x00007FF699DF0000, stack from 0x0000008FF7DB4000-0x0000008FF7DC0000
2026-05-28 17:54:14,006 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 1416 (handle 0x6a4): 0x0000000000170000.
2026-05-28 17:54:14,211 [root] DEBUG: 4944: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:54:14,234 [root] DEBUG: 16052: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 17:54:14,331 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4492, handle 0x740: C:\Windows\System32\svchost.exe
2026-05-28 17:54:14,375 [root] DEBUG: 4944: YaraScan: Scanning 0x00320000, size 0x2424d2
2026-05-28 17:54:14,396 [root] DEBUG: 16052: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:54:14,495 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4492 (handle 0x740): 0x00007FF780360000.
2026-05-28 17:54:14,540 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:54:14,653 [root] DEBUG: 4944: Monitor initialised: 32-bit capemon loaded in process 4944 at 0x6ad10000, thread 15748, image base 0x320000, stack from 0x4ca5000-0x4cb0000
2026-05-28 17:54:14,750 [root] DEBUG: 16052: set_hooks: Unable to hook LockResource
2026-05-28 17:54:14,853 [root] DEBUG: 4944: Commandline: "C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
2026-05-28 17:54:14,971 [root] DEBUG: 16052: Hooked 627 out of 628 functions
2026-05-28 17:54:15,030 [root] DEBUG: 4944: hook_api: LdrpCallInitRoutine export address 0x777A2B50 obtained via GetFunctionAddress
2026-05-28 17:54:15,234 [root] DEBUG: 16052: Syscall hook installed, syscall logging level 1
2026-05-28 17:54:15,335 [root] DEBUG: 4944: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-28 17:54:15,499 [root] DEBUG: 4944: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-28 17:54:15,714 [root] DEBUG: 4944: Hooked 632 out of 632 functions
2026-05-28 17:54:15,828 [root] DEBUG: 16052: RestoreHeaders: Restored original import table.
2026-05-28 17:54:15,894 [root] DEBUG: 4944: Syscall hook installed, syscall logging level 1
2026-05-28 17:54:16,266 [root] INFO: Loaded monitor into process with pid 16052
2026-05-28 17:54:16,421 [root] DEBUG: 16052: caller_dispatch: Added region at 0x00007FF699DF0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF699DF12F2, thread 16056).
2026-05-28 17:54:16,494 [root] INFO: Loaded monitor into process with pid 4944
2026-05-28 17:54:16,569 [root] DEBUG: 16052: YaraScan: Scanning 0x00007FF699DF0000, size 0x8026
2026-05-28 17:54:16,702 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:54:16,910 [root] DEBUG: 4944: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 17:54:17,014 [root] DEBUG: 16052: ProcessImageBase: Main module image at 0x00007FF699DF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:54:17,078 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\XMmUhAK.dll.
2026-05-28 17:54:17,279 [root] DEBUG: 16052: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:54:17,329 [lib.api.process] INFO: Injected into 32-bit <Process 4944 OneDrive.exe>
2026-05-28 17:54:17,379 [root] DEBUG: 15396: DLL loaded at 0x00007FFC5E770000: C:\Windows\SYSTEM32\pdh (0x49000 bytes).
2026-05-28 17:54:17,964 [root] DEBUG: 16052: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:54:18,050 [root] DEBUG: 15396: DLL loaded at 0x00007FFC6ED50000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 17:54:18,192 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Roaming\discord\DIPS-wal to files\cc125032afdf134b33385b69bb946de7fc48127866638c91d214913fd1822c8e; Size is 119512; Max size: 100000000
2026-05-28 17:54:18,343 [root] DEBUG: 16052: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:54:18,405 [root] DEBUG: 3484: OpenProcessHandler: Image base for process 6236 (handle 0x9b8): 0x00007FF6B1860000.
2026-05-28 17:54:18,472 [root] DEBUG: 15396: DLL loaded at 0x00007FFC66B50000: C:\Windows\System32\wbem\WmiPerfClass (0x27000 bytes).
2026-05-28 17:54:18,568 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5BAB0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 17:54:18,668 [root] DEBUG: 3484: OpenProcessHandler: Injection info created for process 6236, handle 0x9b8: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:54:18,830 [root] DEBUG: 16052: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 17:54:18,901 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5BAB0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 17:54:19,165 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5932, handle 0x8e0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:54:19,329 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 5932 (handle 0x8e0): 0x00007FF734750000.
2026-05-28 17:54:19,484 [root] DEBUG: 16052: DLL loaded at 0x00007FFC74BA0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 17:54:19,650 [root] DEBUG: 16052: DLL loaded at 0x00007FFC74B80000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 17:54:19,879 [root] DEBUG: 16052: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 17:54:19,950 [root] DEBUG: 13892: DLL loaded at 0x00007FFC6C970000: C:\Windows\system32\fveapi (0xf5000 bytes).
2026-05-28 17:54:20,071 [root] DEBUG: 16052: DLL loaded at 0x00007FFC707B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 17:54:20,164 [root] DEBUG: 13892: DLL loaded at 0x00007FFC77F00000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 17:54:20,251 [root] DEBUG: 16052: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:54:20,386 [root] DEBUG: 13892: DLL loaded at 0x00007FFC6DA10000: C:\Windows\system32\tbs (0x1b000 bytes).
2026-05-28 17:54:20,435 [root] DEBUG: 16052: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 17:54:20,595 [root] DEBUG: 16052: DLL loaded at 0x00007FFC74A70000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 17:54:20,789 [root] INFO: Announced 64-bit process name: steam.exe pid: 3552
2026-05-28 17:54:20,897 [lib.api.process] INFO: Monitor config for process 3552: C:\mtfrhoy9\dll\3552.ini
2026-05-28 17:54:20,897 [root] DEBUG: 16052: DLL loaded at 0x00007FFC75560000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 17:54:21,057 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:54:21,302 [root] DEBUG: 16052: DLL loaded at 0x00007FFC755E0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 17:54:21,385 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:54:21,478 [root] DEBUG: 16052: DLL loaded at 0x00007FFC711F0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 17:54:21,650 [root] DEBUG: 16052: DLL loaded at 0x00007FFC74AB0000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 17:54:21,717 [root] DEBUG: Loader: Injecting process 3552 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:21,979 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2368, handle 0xa94: C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:54:22,069 [root] DEBUG: 3552: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:54:22,146 [root] DEBUG: 16052: DLL loaded at 0x00007FFC5B990000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 17:54:22,191 [root] DEBUG: 3552: Interactive desktop enabled.
2026-05-28 17:54:22,327 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2368 (handle 0x8e0): 0x00007FF631A20000.
2026-05-28 17:54:22,456 [root] DEBUG: 3552: Dropped file limit defaulting to 100.
2026-05-28 17:54:22,525 [root] DEBUG: 16052: DLL loaded at 0x00007FFC771D0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 17:54:22,907 [root] DEBUG: 3552: Disabling sleep skipping.
2026-05-28 17:54:23,109 [root] DEBUG: 3552: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:54:23,213 [root] DEBUG: 16052: DLL loaded at 0x00007FFC66790000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 17:54:23,274 [root] DEBUG: 3552: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:54:23,392 [root] DEBUG: 3552: YaraScan: Scanning 0x00007FF7CB360000, size 0x7074ee
2026-05-28 17:54:23,672 [root] DEBUG: 3552: Monitor initialised: 64-bit capemon loaded in process 3552 at 0x00007FFC37E40000, thread 4060, image base 0x00007FF7CB360000, stack from 0x000000BA843F4000-0x000000BA84400000
2026-05-28 17:54:23,885 [root] DEBUG: 3552: Commandline: "C:\Program Files (x86)\Steam\steam.exe" -silent
2026-05-28 17:54:24,046 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\crashhandler64.dll
2026-05-28 17:54:24,239 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\steamui.dll
2026-05-28 17:54:24,395 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\libavcodec-62.dll
2026-05-28 17:54:24,640 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\libavutil-60.dll
2026-05-28 17:54:24,927 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\SDL3.dll
2026-05-28 17:54:25,206 [root] INFO: Process with pid 6200 has terminated
2026-05-28 17:54:25,311 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\tier0_s64.dll
2026-05-28 17:54:25,365 [root] INFO: Process with pid 6200 has terminated
2026-05-28 17:54:25,493 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 2156, handle 0x8e0: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:54:25,578 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\video64.dll
2026-05-28 17:54:25,658 [root] INFO: Process with pid 6772 has terminated
2026-05-28 17:54:25,828 [root] INFO: Process with pid 6772 has terminated
2026-05-28 17:54:25,925 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 2156 (handle 0x8e0): 0x00007FF7D0050000.
2026-05-28 17:54:26,113 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\vstdlib_s64.dll
2026-05-28 17:54:26,184 [root] DEBUG: 9864: DLL loaded at 0x00007FFC55370000: C:\Windows\SYSTEM32\PROVTHRD (0x52000 bytes).
2026-05-28 17:54:26,296 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\libavfilter-11.dll
2026-05-28 17:54:26,390 [root] DEBUG: 3484: NtTerminateProcess hook: Attempting to dump process 3484
2026-05-28 17:54:26,489 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\libavformat-62.dll
2026-05-28 17:54:26,593 [root] DEBUG: 9864: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:54:26,678 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\libswresample-6.dll
2026-05-28 17:54:26,749 [root] DEBUG: 3484: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:54:26,898 [root] DEBUG: 9864: DLL loaded at 0x00007FFC6ED50000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 17:54:27,109 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\libswscale-9.dll
2026-05-28 17:54:27,223 [root] INFO: Process with pid 3484 has terminated
2026-05-28 17:54:27,327 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\steamclient64.dll
2026-05-28 17:54:27,393 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4676, handle 0x740: C:\Windows\System32\wermgr.exe
2026-05-28 17:54:27,580 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\libusb-1.0.dll
2026-05-28 17:54:27,642 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4676 (handle 0x6a4): 0x00007FF612680000.
2026-05-28 17:54:27,796 [root] DEBUG: 9864: DLL loaded at 0x00007FFC668E0000: C:\Windows\system32\wbem\ntevt (0x43000 bytes).
2026-05-28 17:54:27,827 [root] DEBUG: 3552: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Steam\openvr_api.dll
2026-05-28 17:54:27,945 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 4700, handle 0x6a4: C:\Windows\System32\taskhostw.exe
2026-05-28 17:54:28,035 [root] DEBUG: 3552: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:54:28,145 [root] DEBUG: 13892: NtTerminateProcess hook: Attempting to dump process 13892
2026-05-28 17:54:28,345 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:54:28,473 [root] DEBUG: 13892: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:54:28,592 [root] DEBUG: 7800: OpenProcessHandler: Image base for process 4700 (handle 0x6a4): 0x00007FF77B4D0000.
2026-05-28 17:54:28,691 [root] INFO: Process with pid 13892 appears to have terminated
2026-05-28 17:54:28,992 [root] DEBUG: 3552: set_hooks: Unable to hook LockResource
2026-05-28 17:54:29,167 [root] INFO: Process with pid 13892 has terminated
2026-05-28 17:54:29,345 [root] INFO: Process with pid 16052 has terminated
2026-05-28 17:54:29,460 [root] DEBUG: 3552: Hooked 627 out of 628 functions
2026-05-28 17:54:29,521 [root] DEBUG: 7800: OpenProcessHandler: Injection info created for process 5632, handle 0xa94: C:\Windows\System32\SgrmBroker.exe
2026-05-28 17:54:29,828 [root] DEBUG: 16052: NtTerminateProcess hook: Attempting to dump process 16052
2026-05-28 17:54:29,883 [root] DEBUG: 3552: Syscall hook installed, syscall logging level 1
2026-05-28 17:54:30,277 [root] DEBUG: 16052: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:54:30,383 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:54:30,558 [root] INFO: Loaded monitor into process with pid 3552
2026-05-28 17:54:30,721 [root] DEBUG: 3552: OpenProcessHandler: Injection info created for process 3392, handle 0xf60: Error obtaining target process name
2026-05-28 17:54:30,760 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:54:30,916 [root] DEBUG: 3552: ProcessTrackedRegion: Entropy for tracked region at 0x00007FFC4D950000: 5.358190e+00
2026-05-28 17:54:31,007 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:31,111 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4D950000 to tracked regions list (ntdll::NtWaitForSingleObject returns to 0x00007FFC4D966846, thread 7580).
2026-05-28 17:54:31,274 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FF7CB360000 to tracked regions list (ntdll::NtWaitForSingleObject returns to 0x00007FF7CB535776, thread 13004).
2026-05-28 17:54:31,274 [lib.api.process] INFO: Injected into 64-bit <Process 3552 steam.exe>
2026-05-28 17:54:31,500 [root] DEBUG: 3552: YaraScan: Scanning 0x00007FF7CB360000, size 0x7074ee
2026-05-28 17:54:31,687 [root] DEBUG: 3552: ProcessTrackedRegion: Interesting region at 0x00007FFC4D950000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\tier0_s64.dll, dumping
2026-05-28 17:54:31,754 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC38C80000 to tracked regions list (ntdll::NtDelayExecution returns to 0x00007FFC3926937A, thread 7544).
2026-05-28 17:54:31,850 [root] DEBUG: 3552: YaraScan: Scanning 0x00007FF7CB360000, size 0x7074ee
2026-05-28 17:54:31,923 [root] DEBUG: 3552: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC4D950000: 5.358189e+00 (from 5.358190e+00)
2026-05-28 17:54:32,268 [root] DEBUG: 3552: DumpPEsInRange: Scanning range 0x00007FFC4D950000 - 0x00007FFC4DDCD762.
2026-05-28 17:54:32,424 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC38C80000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\steamclient64.dll appears unmodified, skipping
2026-05-28 17:54:32,532 [root] DEBUG: 3552: ProcessImageBase: Main module image at 0x00007FF7CB360000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:54:32,630 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4D950000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\tier0_s64.dll appears unmodified, skipping
2026-05-28 17:54:32,782 [root] DEBUG: 3552: ProcessImageBase: Main module image at 0x00007FF7CB360000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:54:32,846 [root] DEBUG: 3552: ScanForDisguisedPE: PE image located at: 0x00007FFC4D950000
2026-05-28 17:54:33,238 [root] DEBUG: 3552: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-05-28 17:54:33,801 [root] DEBUG: 3552: DumpProcess: Instantiating PeParser with address: 0x00007FFC4D950000.
2026-05-28 17:54:33,898 [root] DEBUG: 4584: DLL loaded at 0x00007FFC66B10000: C:\Windows\System32\Windows.Energy (0x35000 bytes).
2026-05-28 17:54:33,986 [root] DEBUG: 3552: DumpProcess: Module entry point VA is 0x00007FFC4D972144.
2026-05-28 17:54:34,211 [root] DEBUG: 7800: api-cap: NtOpenProcess hook disabled due to count: 5000
2026-05-28 17:54:34,408 [lib.common.results] INFO: Uploading file C:\LJDkwoHS\CAPE\3552_574034542128452026 to CAPE\4cbae1cf83784149c5b7942e7c859a45469c254f862a2126804c695f47aab974; Size is 1687552; Max size: 100000000
2026-05-28 17:54:34,571 [root] DEBUG: 4584: DLL loaded at 0x00007FFC66B10000: C:\Windows\System32\Windows.Energy (0x35000 bytes).
2026-05-28 17:54:34,737 [root] DEBUG: 3552: DumpProcess: Module image dump success - dump size 0x19c000.
2026-05-28 17:54:34,903 [root] DEBUG: 3552: ScanForDisguisedPE: PE image located at: 0x00007FFC4DAF0000
2026-05-28 17:54:35,214 [root] DEBUG: 3552: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-05-28 17:54:35,397 [root] DEBUG: 3552: DumpProcess: Instantiating PeParser with address: 0x00007FFC4DAF0000.
2026-05-28 17:54:35,735 [root] DEBUG: 3552: DumpProcess: Module entry point VA is 0x00007FFC4DCC92F0.
2026-05-28 17:54:36,119 [lib.common.results] INFO: Uploading file C:\LJDkwoHS\CAPE\3552_1614015835542128452026 to CAPE\74c9d20553c2495deca7dd3f8b6bf0be902efb7db3a44d758bc20ae9df021152; Size is 2988544; Max size: 100000000
2026-05-28 17:54:36,281 [root] DEBUG: 3552: DumpProcess: Module image dump success - dump size 0x2d9a00.
2026-05-28 17:54:36,534 [root] DEBUG: 3552: ScanForDisguisedPE: No PE image located in range 0x00007FFC4DAF1000-0x00007FFC4DDCD762.
2026-05-28 17:54:36,850 [root] DEBUG: 3552: DumpRegion: Dumped PE image(s) from base address 0x00007FFC4D950000, size 4710400 bytes.
2026-05-28 17:54:37,348 [root] DEBUG: 3552: ProcessTrackedRegion: Dumped region at 0x00007FFC4D950000.
2026-05-28 17:54:37,786 [root] DEBUG: 3552: YaraScan: Scanning 0x00007FFC4D950000, size 0x47d762
2026-05-28 17:54:38,097 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4FB00000 to tracked regions list (kernel32::GetSystemTimeAsFileTime returns to 0x00007FFC5005B537, thread 3580).
2026-05-28 17:54:38,338 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4FB00000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\SteamUI.dll appears unmodified, skipping
2026-05-28 17:54:38,607 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4DAF0000 to tracked regions list (ntdll::NtPowerInformation returns to 0x00007FFC4DC785A3, thread 7580).
2026-05-28 17:54:38,678 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4FB00000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\SteamUI.dll appears unmodified, skipping
2026-05-28 17:54:38,829 [root] INFO: Announced 64-bit process name: SecurityHealthSystray.exe pid: 3680
2026-05-28 17:54:39,044 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4DAF0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\SDL3.dll appears unmodified, skipping
2026-05-28 17:54:39,054 [lib.api.process] INFO: Monitor config for process 3680: C:\mtfrhoy9\dll\3680.ini
2026-05-28 17:54:39,188 [root] DEBUG: 3552: DLL loaded at 0x00007FFC6E0E0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 17:54:39,473 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:54:39,508 [lib.api.process] INFO: 64-bit DLL to inject is C:\mtfrhoy9\dll\WqtqHcg.dll, loader C:\mtfrhoy9\bin\wFPspkOk.exe
2026-05-28 17:54:39,922 [root] DEBUG: Loader: Injecting process 3680 with C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:40,182 [root] DEBUG: 3680: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:54:40,531 [root] DEBUG: 3680: Interactive desktop enabled.
2026-05-28 17:54:40,894 [root] DEBUG: 3680: Dropped file limit defaulting to 100.
2026-05-28 17:54:41,376 [root] DEBUG: 3680: Disabling sleep skipping.
2026-05-28 17:54:41,541 [root] DEBUG: 4584: OpenProcessHandler: Image base for process 3552 (handle 0x253c): 0x00007FF7CB360000.
2026-05-28 17:54:41,752 [root] DEBUG: 3680: YaraInit: Compiled rules loaded from existing file C:\mtfrhoy9\data\yara\capemon.yac
2026-05-28 17:54:41,959 [root] DEBUG: 4584: OpenProcessHandler: Injection info created for process 3552, handle 0x253c: C:\Program Files (x86)\Steam\steam.exe
2026-05-28 17:54:42,082 [root] DEBUG: 3680: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 17:54:42,443 [root] DEBUG: 3680: YaraScan: Scanning 0x00007FF661AB0000, size 0x18090
2026-05-28 17:54:42,752 [root] DEBUG: 3680: Monitor initialised: 64-bit capemon loaded in process 3680 at 0x00007FFC37E40000, thread 15036, image base 0x00007FF661AB0000, stack from 0x0000000219974000-0x0000000219980000
2026-05-28 17:54:42,945 [root] INFO: Added new file to list with pid 3552 and path C:\Program Files (x86)\Steam\userdata\736595453\config\localconfig.vdf.async3552.tmp
2026-05-28 17:54:43,103 [root] DEBUG: 3680: Commandline: "C:\Windows\System32\SecurityHealthSystray.exe"
2026-05-28 17:54:43,331 [root] INFO: Added new file to list with pid 3552 and path C:\Program Files (x86)\Steam\userdata\736595453\config\localconfig.vdf
2026-05-28 17:54:43,500 [root] DEBUG: 3680: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 17:54:43,903 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:54:44,307 [root] DEBUG: 3680: set_hooks: Unable to hook LockResource
2026-05-28 17:54:44,619 [root] DEBUG: 3680: Hooked 627 out of 628 functions
2026-05-28 17:54:44,914 [root] DEBUG: 3680: Syscall hook installed, syscall logging level 1
2026-05-28 17:54:45,218 [root] INFO: Loaded monitor into process with pid 3680
2026-05-28 17:54:45,596 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:54:45,635 [lib.common.results] INFO: Uploading file C:\Program Files (x86)\Steam\userdata\736595453\config\localconfig.vdf~RF2a1e3.TMP to files\76f78f63f64f4d682bf6da09854a8e33e9390a331edfe06b3d6f4bc153274a41; Size is 31029; Max size: 100000000
2026-05-28 17:54:45,792 [root] DEBUG: Successfully injected DLL C:\mtfrhoy9\dll\WqtqHcg.dll.
2026-05-28 17:54:46,180 [lib.api.process] INFO: Injected into 64-bit <Process 3680 SecurityHealthSystray.exe>
2026-05-28 17:54:46,490 [root] DEBUG: 4584: OpenProcessHandler: Image base for process 3392 (handle 0x2254): 0x00007FF7D0050000.
2026-05-28 17:54:46,648 [root] DEBUG: 4584: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5001
2026-05-28 17:54:46,725 [root] DEBUG: 4584: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5002
2026-05-28 17:54:46,951 [root] DEBUG: 4584: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5002
2026-05-28 17:54:47,107 [root] INFO: Added new file to list with pid 3552 and path C:\program files (x86)\Steam\config\DialogConfig.vdf
2026-05-28 17:54:47,332 [root] DEBUG: 4584: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5003
2026-05-28 17:54:47,875 [root] DEBUG: 3552: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 17:54:49,158 [root] INFO: Process with pid 3392 has terminated
2026-05-28 17:54:49,600 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC38C20000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FFC38C4529C, thread 7580).
2026-05-28 17:54:50,097 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC38C20000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\libusb-1.0.dll appears unmodified, skipping
2026-05-28 17:54:50,930 [root] INFO: Added new file to list with pid 3552 and path C:\Program Files (x86)\Steam\logs\timedtrial_log.txt
2026-05-28 17:54:51,337 [root] DEBUG: 4584: OpenProcessHandler: Image base for process 5536 (handle 0x248c): 0x00007FF6EB870000.
2026-05-28 17:54:51,509 [root] DEBUG: 4584: api-cap: NtQueryInformationThread hook disabled due to count: 5001
2026-05-28 17:54:51,709 [root] DEBUG: 4584: api-cap: NtQueryInformationThread hook disabled due to count: 5002
2026-05-28 17:54:51,931 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC38A60000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFC38AB5D92, thread 3580).
2026-05-28 17:54:52,009 [root] DEBUG: 4584: api-cap: NtQueryInformationThread hook disabled due to count: 5003
2026-05-28 17:54:52,132 [root] DEBUG: 4584: api-cap: NtQueryInformationThread hook disabled due to count: 5001
2026-05-28 17:54:52,325 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC38A60000...
2026-05-28 17:54:52,439 [root] DEBUG: 4584: OpenProcessHandler: Image base for process 5152 (handle 0x24e0): 0x00007FF70F680000.
2026-05-28 17:54:52,517 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC38A60000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\openvr_api.dll appears unmodified, skipping
2026-05-28 17:54:53,361 [root] DEBUG: 3552: NtTerminateProcess hook: Attempting to dump process 3552
2026-05-28 17:54:53,662 [root] DEBUG: 3552: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:54:53,951 [root] DEBUG: 3552: DLL loaded at 0x00007FFC74B80000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 17:54:54,023 [root] DEBUG: 7800: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 17:54:54,145 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4D2B0000 to tracked regions list (ntdll::NtSetInformationThread returns to 0x00007FFC4D37D3E6, thread 3580).
2026-05-28 17:54:54,319 [root] INFO: Process with pid 3552 appears to have terminated
2026-05-28 17:54:54,377 [root] DEBUG: 7800: DLL loaded at 0x00007FFC66BC0000: C:\Windows\system32\CHARTV (0x25000 bytes).
2026-05-28 17:54:54,554 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC4D2B0000...
2026-05-28 17:54:54,728 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4D2B0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\video64.dll appears unmodified, skipping
2026-05-28 17:54:55,096 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4CDB0000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFC4CDE5055, thread 3580).
2026-05-28 17:54:55,308 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC4CDB0000...
2026-05-28 17:54:55,569 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4CDB0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\libswresample-6.dll appears unmodified, skipping
2026-05-28 17:54:55,691 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4CE80000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFC4CF8D5ED, thread 3580).
2026-05-28 17:54:55,928 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC4CE80000...
2026-05-28 17:54:56,150 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4CE80000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\libavformat-62.dll appears unmodified, skipping
2026-05-28 17:54:56,358 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4D0C0000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFC4D0FEB5D, thread 3580).
2026-05-28 17:54:56,702 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC4D0C0000...
2026-05-28 17:54:57,077 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4D0C0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\libavfilter-11.dll appears unmodified, skipping
2026-05-28 17:54:57,178 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4CBA0000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFC4CC9B045, thread 3580).
2026-05-28 17:54:57,529 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC4CBA0000...
2026-05-28 17:54:57,866 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4CBA0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\libswscale-9.dll appears unmodified, skipping
2026-05-28 17:54:58,250 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4F350000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFC4F8E0A39, thread 3580).
2026-05-28 17:54:58,509 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC4F350000...
2026-05-28 17:54:58,754 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4F350000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\libavcodec-62.dll appears unmodified, skipping
2026-05-28 17:54:59,080 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC4DDD0000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFC4DED5D1D, thread 3580).
2026-05-28 17:54:59,372 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC4DDD0000...
2026-05-28 17:54:59,662 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC4DDD0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\libavutil-60.dll appears unmodified, skipping
2026-05-28 17:54:59,899 [root] DEBUG: 3552: caller_dispatch: Added region at 0x00007FFC55810000 to tracked regions list (ntdll::NtSetInformationThread returns to 0x00007FFC55822186, thread 3580).
2026-05-28 17:55:00,162 [root] DEBUG: 3552: caller_dispatch: Scanning calling region at 0x00007FFC55810000...
2026-05-28 17:55:00,401 [root] DEBUG: 3552: ProcessTrackedRegion: Region at 0x00007FFC55810000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Steam\crashhandler64.dll appears unmodified, skipping
2026-05-28 17:55:00,758 [root] INFO: Process with pid 3552 has terminated
2026-05-28 17:55:13,788 [root] DEBUG: 3680: caller_dispatch: Added region at 0x00007FF661AB0000 to tracked regions list (ntdll::NtFindAtom returns to 0x00007FF661AB3CB2, thread 3608).
2026-05-28 17:55:14,078 [root] DEBUG: 3680: YaraScan: Scanning 0x00007FF661AB0000, size 0x18090
2026-05-28 17:55:14,302 [root] DEBUG: 3680: ProcessImageBase: Main module image at 0x00007FF661AB0000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:55:16,852 [root] DEBUG: 4584: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-05-28 17:55:28,194 [root] DEBUG: 7800: api-cap: NtClose hook disabled due to count: 5000
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 17:52:25 | 2026-05-28 17:55:47 | none |
Seek in progress...
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.