| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 18:01:45 | 2026-05-28 18:03:34 | 109s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 17:52:18,890 [root] INFO: Date set to: 20260528T18:01:50, timeout set to: 200
2026-05-28 18:01:50,012 [root] DEBUG: Starting analyzer from: C:\_a4sjgfa
2026-05-28 18:01:50,013 [root] DEBUG: Storing results at: C:\nKjZGmJV
2026-05-28 18:01:50,013 [root] DEBUG: Pipe server name: \\.\PIPE\vgJhjNQ
2026-05-28 18:01:50,013 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 18:01:50,014 [root] INFO: analysis running as an admin
2026-05-28 18:01:50,014 [root] INFO: analysis package specified: "edge"
2026-05-28 18:01:50,014 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 18:01:50,015 [root] DEBUG: imported analysis package "edge"
2026-05-28 18:01:50,015 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 18:01:50,015 [root] DEBUG: New location of moved file: https://sugarcraft.net/
2026-05-28 18:01:50,015 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 18:01:50,015 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 18:01:50,015 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 18:01:50,016 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 18:01:50,030 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 18:01:50,042 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 18:01:50,048 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 18:01:50,057 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 18:01:50,060 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 18:01:50,060 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 18:01:50,061 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 18:01:50,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 18:01:50,062 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 18:01:50,062 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 18:01:50,062 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 18:01:50,063 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 18:01:50,063 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 18:01:50,063 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 18:01:50,063 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 18:01:50,064 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 18:01:50,064 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 18:01:50,064 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 18:01:50,064 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 18:01:50,064 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 18:01:50,065 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 18:01:50,065 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 18:01:50,065 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 18:01:50,067 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 7940)
2026-05-28 18:01:50,068 [modules.auxiliary.disguise] INFO: Disguising GUID to f236088c-d77a-4da3-9aa2-7c7045457595
2026-05-28 18:01:50,068 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 18:01:50,073 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 18:01:50,073 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 18:01:50,073 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 18:01:50,074 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 18:01:50,074 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 18:01:50,075 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 18:01:50,075 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 18:01:50,075 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 18:01:50,076 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 18:01:50,077 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 18:01:50,077 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 18:01:50,078 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 18:01:50,078 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 18:01:50,078 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 18:01:50,079 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 18:01:50,081 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 18:01:50,081 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 18:01:50,081 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 18:01:50,115 [lib.api.process] INFO: Monitor config for process 4584: C:\_a4sjgfa\dll\4584.ini
2026-05-28 18:01:50,119 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:01:50,121 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:01:50,164 [root] DEBUG: Loader: Injecting process 4584 with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:50,340 [root] DEBUG: 4584: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:01:50,341 [root] DEBUG: 4584: Disabling sleep skipping.
2026-05-28 18:01:50,341 [root] DEBUG: 4584: Interactive desktop enabled.
2026-05-28 18:01:50,342 [root] DEBUG: 4584: Dropped file limit defaulting to 100.
2026-05-28 18:01:50,343 [root] DEBUG: 4584: Interactive desktop - injecting Explorer Shell
2026-05-28 18:01:50,348 [root] DEBUG: 4584: YaraInit: Compiled 44 rule files
2026-05-28 18:01:50,354 [root] DEBUG: 4584: YaraInit: Compiled rules saved to file C:\_a4sjgfa\data\yara\capemon.yac
2026-05-28 18:01:50,374 [root] DEBUG: 4584: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:01:50,375 [root] DEBUG: 4584: YaraScan: Scanning 0x00007FF65E010000, size 0x545316
2026-05-28 18:01:50,463 [root] DEBUG: 4584: Monitor initialised: 64-bit capemon loaded in process 4584 at 0x00007FFC33AB0000, thread 5268, image base 0x00007FF65E010000, stack from 0x000000000F0F1000-0x000000000F100000
2026-05-28 18:01:50,464 [root] DEBUG: 4584: Commandline: C:\Windows\Explorer.EXE
2026-05-28 18:01:50,477 [root] DEBUG: 4584: Hooked 69 out of 69 functions
2026-05-28 18:01:50,509 [root] DEBUG: 4584: Syscall hook installed, syscall logging level 1
2026-05-28 18:01:50,515 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:01:50,516 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:50,517 [lib.api.process] INFO: Injected into 64-bit <Process 4584 explorer.exe>
2026-05-28 18:01:52,673 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC61000, size: 0x1000.
2026-05-28 18:01:52,703 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC51000, size: 0x1000.
2026-05-28 18:01:52,703 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC41000, size: 0x1000.
2026-05-28 18:01:52,705 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC31000, size: 0x1000.
2026-05-28 18:01:53,918 [root] DEBUG: 4584: caller_dispatch: Added region at 0x00007FF65E010000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF65E0B8FBA, thread 4636).
2026-05-28 18:01:53,921 [root] DEBUG: 4584: YaraScan: Scanning 0x00007FF65E010000, size 0x545316
2026-05-28 18:01:53,923 [root] DEBUG: 4584: YaraScan: Scanning 0x00007FF65E010000, size 0x545316
2026-05-28 18:01:53,960 [root] DEBUG: 4584: ProcessImageBase: Main module image at 0x00007FF65E010000 unmodified (entropy change 5.180712e-07)
2026-05-28 18:01:53,962 [root] DEBUG: 4584: ProcessImageBase: Main module image at 0x00007FF65E010000 unmodified (entropy change 5.180712e-07)
2026-05-28 18:01:54,650 [lib.api.process] INFO: Monitor config for process 740: C:\_a4sjgfa\dll\740.ini
2026-05-28 18:01:54,652 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:01:54,653 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:01:54,658 [root] DEBUG: Loader: Injecting process 740 with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:54,659 [root] DEBUG: 740: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:01:54,660 [root] DEBUG: 740: Disabling sleep skipping.
2026-05-28 18:01:54,660 [root] DEBUG: 740: Interactive desktop enabled.
2026-05-28 18:01:54,660 [root] DEBUG: 740: Dropped file limit defaulting to 100.
2026-05-28 18:01:54,663 [root] DEBUG: 740: Services hook set enabled
2026-05-28 18:01:54,665 [root] DEBUG: 740: YaraInit: Compiled rules loaded from existing file C:\_a4sjgfa\data\yara\capemon.yac
2026-05-28 18:01:54,677 [root] DEBUG: 740: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:01:54,677 [root] DEBUG: 740: Monitor initialised: 64-bit capemon loaded in process 740 at 0x00007FFC33AB0000, thread 4964, image base 0x00007FF780360000, stack from 0x000000754D074000-0x000000754D080000
2026-05-28 18:01:54,678 [root] DEBUG: 740: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 18:01:54,688 [root] DEBUG: 740: Hooked 69 out of 69 functions
2026-05-28 18:01:54,689 [root] INFO: Loaded monitor into process with pid 740
2026-05-28 18:01:54,690 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:01:54,690 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:54,691 [lib.api.process] INFO: Injected into 64-bit <Process 740 svchost.exe>
2026-05-28 18:01:56,732 [root] DEBUG: 4584: CreateProcessHandler: Injection info set for new process 7912: C:\Windows\system32\taskmgr.exe, ImageBase: 0x00007FF6C28B0000
2026-05-28 18:01:56,733 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 7912
2026-05-28 18:01:56,733 [lib.api.process] INFO: Monitor config for process 7912: C:\_a4sjgfa\dll\7912.ini
2026-05-28 18:01:56,734 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:01:56,735 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:01:56,740 [root] DEBUG: Loader: Injecting process 7912 (thread 1496) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:56,741 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:01:56,741 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:56,742 [lib.api.process] INFO: Injected into 64-bit <Process 7912 Taskmgr.exe>
2026-05-28 18:01:56,744 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 7912
2026-05-28 18:01:56,744 [lib.api.process] INFO: Monitor config for process 7912: C:\_a4sjgfa\dll\7912.ini
2026-05-28 18:01:56,745 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:01:56,745 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:01:56,749 [root] DEBUG: Loader: Injecting process 7912 (thread 1496) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:56,750 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:01:56,750 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:56,751 [lib.api.process] INFO: Injected into 64-bit <Process 7912 Taskmgr.exe>
2026-05-28 18:01:56,753 [root] DEBUG: 4584: DLL loaded at 0x00007FFC64EC0000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 18:01:56,753 [root] DEBUG: 4584: DLL loaded at 0x00007FFC66D50000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 18:01:56,754 [root] DEBUG: 4584: DLL loaded at 0x00007FFC630F0000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 18:01:56,760 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 7912
2026-05-28 18:01:56,760 [lib.api.process] INFO: Monitor config for process 7912: C:\_a4sjgfa\dll\7912.ini
2026-05-28 18:01:56,761 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:01:56,761 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:01:56,765 [root] DEBUG: Loader: Injecting process 7912 with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:56,766 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 1496, handle 0x124
2026-05-28 18:01:56,766 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:01:56,767 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:56,768 [lib.api.process] INFO: Injected into 64-bit <Process 7912 Taskmgr.exe>
2026-05-28 18:01:56,866 [root] DEBUG: 7912: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:01:56,867 [root] DEBUG: 7912: Interactive desktop enabled.
2026-05-28 18:01:56,867 [root] DEBUG: 7912: Dropped file limit defaulting to 100.
2026-05-28 18:01:56,951 [root] DEBUG: 7912: Disabling sleep skipping.
2026-05-28 18:01:56,955 [root] DEBUG: 7912: YaraInit: Compiled rules loaded from existing file C:\_a4sjgfa\data\yara\capemon.yac
2026-05-28 18:01:56,970 [root] DEBUG: 7912: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:01:56,971 [root] DEBUG: 7912: YaraScan: Scanning 0x00007FF6C28B0000, size 0x12fcfe
2026-05-28 18:01:56,978 [root] DEBUG: 7912: Monitor initialised: 64-bit capemon loaded in process 7912 at 0x00007FFC33AB0000, thread 1496, image base 0x00007FF6C28B0000, stack from 0x000000F09D764000-0x000000F09D770000
2026-05-28 18:01:56,979 [root] DEBUG: 7912: Commandline: "C:\Windows\system32\taskmgr.exe" /4
2026-05-28 18:01:56,988 [root] DEBUG: 7912: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 18:01:57,027 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:01:57,028 [root] DEBUG: 7912: set_hooks: Unable to hook LockResource
2026-05-28 18:01:57,044 [root] DEBUG: 7912: Hooked 627 out of 628 functions
2026-05-28 18:01:57,052 [root] DEBUG: 7912: Syscall hook installed, syscall logging level 1
2026-05-28 18:01:57,057 [root] DEBUG: 7912: RestoreHeaders: Restored original import table.
2026-05-28 18:01:57,057 [root] INFO: Loaded monitor into process with pid 7912
2026-05-28 18:01:57,068 [root] DEBUG: 7912: DLL loaded at 0x00007FFC75440000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 18:01:57,156 [root] DEBUG: 7912: caller_dispatch: Added region at 0x00007FF6C28B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6C28DFF02, thread 1496).
2026-05-28 18:01:57,157 [root] DEBUG: 7912: YaraScan: Scanning 0x00007FF6C28B0000, size 0x12fcfe
2026-05-28 18:01:57,165 [root] DEBUG: 7912: ProcessImageBase: Main module image at 0x00007FF6C28B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:01:57,196 [root] DEBUG: 7912: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:01:57,202 [root] DEBUG: 7912: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:01:57,212 [root] DEBUG: 7912: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:01:57,254 [root] DEBUG: 7912: DLL loaded at 0x00007FFC66930000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 18:01:57,281 [root] DEBUG: 7912: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:01:57,282 [root] DEBUG: 7912: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:01:57,283 [root] DEBUG: 7912: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:01:57,283 [root] DEBUG: 7912: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 18:01:57,284 [root] DEBUG: 7912: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 18:01:57,305 [root] DEBUG: 7912: DLL loaded at 0x00007FFC74740000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:01:57,306 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:01:57,415 [root] DEBUG: 7912: DLL loaded at 0x00007FFC68F00000: C:\Windows\System32\NetworkUXBroker (0x6d000 bytes).
2026-05-28 18:01:57,436 [root] DEBUG: 7912: DLL loaded at 0x00007FFC65120000: C:\Windows\system32\srumapi (0x14000 bytes).
2026-05-28 18:01:57,438 [root] DEBUG: 7912: DLL loaded at 0x00007FFC65620000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes).
2026-05-28 18:01:57,442 [root] DEBUG: 7912: DLL loaded at 0x00007FFC72B20000: C:\Windows\system32\WTSAPI32 (0x14000 bytes).
2026-05-28 18:01:57,446 [root] DEBUG: 7912: DLL loaded at 0x00007FFC75020000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 18:01:57,447 [root] DEBUG: 7912: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:01:57,473 [root] DEBUG: 7912: DLL loaded at 0x00007FFC75370000: C:\Windows\system32\WINSTA (0x5b000 bytes).
2026-05-28 18:01:57,492 [root] DEBUG: 7912: DLL loaded at 0x00007FFC711F0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 18:01:57,496 [root] DEBUG: 7912: DLL loaded at 0x00007FFC701E0000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 18:01:57,575 [root] DEBUG: 7912: DLL loaded at 0x00007FFC755E0000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 18:01:57,577 [root] DEBUG: 7912: DLL loaded at 0x00007FFC69BE0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 18:01:57,580 [root] DEBUG: 7912: DLL loaded at 0x00007FFC5F9A0000: C:\Windows\system32\OLEACC (0x66000 bytes).
2026-05-28 18:01:57,614 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6EDF0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 18:01:57,626 [root] DEBUG: 7912: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 18:01:57,628 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6BB00000: C:\Windows\system32\samcli (0x19000 bytes).
2026-05-28 18:01:57,642 [root] DEBUG: 7912: DLL loaded at 0x00007FFC72AF0000: C:\Windows\system32\SAMLIB (0x28000 bytes).
2026-05-28 18:01:57,643 [root] DEBUG: 7912: api-rate-cap: NtReleaseMutant hook disabled due to rate
2026-05-28 18:01:57,656 [root] DEBUG: 7912: DLL loaded at 0x00007FFC74B80000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 18:01:57,659 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 92, handle 0x5e4:
2026-05-28 18:01:57,661 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 428, handle 0x5b0: C:\Windows\System32\csrss.exe
2026-05-28 18:01:57,663 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 512, handle 0x5a8: C:\Windows\System32\csrss.exe
2026-05-28 18:01:57,664 [root] DEBUG: 7912: DLL loaded at 0x00007FFC5F2A0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 18:01:57,666 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 600, handle 0x5a8: C:\Windows\System32\winlogon.exe
2026-05-28 18:01:57,669 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 600 (handle 0x610): 0x00007FF767B80000.
2026-05-28 18:01:57,670 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 740, handle 0x610: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,672 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 740 (handle 0x634): 0x00007FF780360000.
2026-05-28 18:01:57,673 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 756, handle 0x634: C:\Windows\System32\fontdrvhost.exe
2026-05-28 18:01:57,675 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 756 (handle 0x634): 0x00007FF7EE860000.
2026-05-28 18:01:57,676 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 900, handle 0x634: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,691 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 900 (handle 0x634): 0x00007FF780360000.
2026-05-28 18:01:57,693 [root] DEBUG: 7912: DLL loaded at 0x00007FFC728F0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 18:01:57,698 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 420, handle 0x634: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,701 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 420 (handle 0x654): 0x00007FF780360000.
2026-05-28 18:01:57,702 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 712, handle 0x654: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,705 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1064, handle 0x654: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,713 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1064 (handle 0x644): 0x00007FF780360000.
2026-05-28 18:01:57,714 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1144, handle 0x644: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,721 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1144 (handle 0x644): 0x00007FF780360000.
2026-05-28 18:01:57,722 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1208, handle 0x644: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,733 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1208 (handle 0x644): 0x00007FF780360000.
2026-05-28 18:01:57,734 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1260, handle 0x644: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,737 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1260 (handle 0x644): 0x00007FF780360000.
2026-05-28 18:01:57,738 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1432, handle 0x644: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,746 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1432 (handle 0x6a0): 0x00007FF780360000.
2026-05-28 18:01:57,750 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1520, handle 0x6a0: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,757 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1520 (handle 0x6a0): 0x00007FF780360000.
2026-05-28 18:01:57,764 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1620, handle 0x6a0: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,766 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1620 (handle 0x6a0): 0x00007FF780360000.
2026-05-28 18:01:57,767 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1720, handle 0x6a0: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,769 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1720 (handle 0x6a0): 0x00007FF780360000.
2026-05-28 18:01:57,776 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1748, handle 0x6a0: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,778 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1748 (handle 0x6a0): 0x00007FF780360000.
2026-05-28 18:01:57,782 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1844, handle 0x6a0: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,785 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1844 (handle 0x6a0): 0x00007FF780360000.
2026-05-28 18:01:57,789 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1892, handle 0x6a0: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,792 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1892 (handle 0x6a0): 0x00007FF780360000.
2026-05-28 18:01:57,793 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1976, handle 0x6a0: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,796 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1976 (handle 0x6a0): 0x00007FF780360000.
2026-05-28 18:01:57,796 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 348, handle 0x6a0: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,799 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 348 (handle 0x6a8): 0x00007FF780360000.
2026-05-28 18:01:57,800 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2100, handle 0x6a8: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,805 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2100 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,807 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2276, handle 0x6ac: C:\Windows\System32\spoolsv.exe
2026-05-28 18:01:57,810 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2348, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,816 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2348 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,824 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2512, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,827 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2512 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,828 [root] INFO: Restarting WMI Service
2026-05-28 18:01:57,830 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:01:57,831 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2636, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,835 [root] DEBUG: 7912: DLL loaded at 0x00007FFC63700000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:01:57,836 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2636 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,845 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2792, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,846 [root] DEBUG: 7912: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:01:57,851 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2792 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,852 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2808, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,854 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2808 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,855 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2996, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,857 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2996 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,858 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3824, handle 0x6ac: C:\Windows\System32\SearchIndexer.exe
2026-05-28 18:01:57,860 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3824 (handle 0x6ac): 0x00007FF781A20000.
2026-05-28 18:01:57,861 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2344, handle 0x6ac: C:\Windows\System32\sihost.exe
2026-05-28 18:01:57,862 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2344 (handle 0x6ac): 0x00007FF6BC710000.
2026-05-28 18:01:57,862 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2464, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,865 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2464 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,865 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3752, handle 0x6ac: C:\Windows\System32\taskhostw.exe
2026-05-28 18:01:57,867 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3752 (handle 0x6ac): 0x00007FF77B4D0000.
2026-05-28 18:01:57,868 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 392, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,870 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 392 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,871 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4276, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,873 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4484, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,875 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4484 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,876 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4728, handle 0x6ac: C:\Windows\System32\svchost.exe
2026-05-28 18:01:57,878 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4728 (handle 0x6ac): 0x00007FF780360000.
2026-05-28 18:01:57,879 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3060, handle 0x6ac: C:\Windows\System32\SearchProtocolHost.exe
2026-05-28 18:01:57,934 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3060 (handle 0x6ac): 0x00007FF716940000.
2026-05-28 18:01:57,938 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5152, handle 0x6ac: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2026-05-28 18:01:57,941 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6A640000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 18:01:57,969 [root] DEBUG: 7912: DLL loaded at 0x00007FFC741C0000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 18:01:57,970 [root] DEBUG: 7912: DLL loaded at 0x00007FFC741F0000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 18:01:57,970 [root] DEBUG: 7912: DLL loaded at 0x00007FFC75560000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 18:01:57,970 [root] DEBUG: 7912: DLL loaded at 0x00007FFC610F0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 18:01:57,991 [root] DEBUG: 7912: DLL loaded at 0x00007FFC72EF0000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 18:01:57,997 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6AB30000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 18:01:57,998 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6AC50000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 18:01:57,998 [root] DEBUG: 7912: DLL loaded at 0x00007FFC61260000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 18:01:58,017 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6A6A0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 18:01:58,022 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6A120000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 18:01:58,030 [root] DEBUG: 7912: DLL loaded at 0x00007FFC70130000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 18:01:58,031 [root] DEBUG: 7912: DLL loaded at 0x00007FFC69E70000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 18:01:58,031 [root] DEBUG: 7912: DLL loaded at 0x00007FFC69FD0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 18:01:58,034 [root] DEBUG: 7912: DLL loaded at 0x00007FFC69D20000: C:\Windows\SYSTEM32\languageoverlayutil (0x41000 bytes).
2026-05-28 18:01:58,040 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6A6C0000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 18:01:58,042 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6B370000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 18:01:58,055 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5152 (handle 0x740): 0x00007FF70F680000.
2026-05-28 18:01:58,062 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5216, handle 0x798: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe
2026-05-28 18:01:58,065 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5216 (handle 0x798): 0x00007FF6B6CB0000.
2026-05-28 18:01:58,066 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5328, handle 0x798: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,069 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5328 (handle 0x798): 0x00007FF780360000.
2026-05-28 18:01:58,070 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5536, handle 0x798: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
2026-05-28 18:01:58,088 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5536 (handle 0x7a8): 0x00007FF6EB870000.
2026-05-28 18:01:58,090 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5796, handle 0x7a8: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 18:01:58,094 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5796 (handle 0x7a8): 0x00007FF77B710000.
2026-05-28 18:01:58,095 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5956, handle 0x7a8: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 18:01:58,096 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5956 (handle 0x7a8): 0x00007FF77B710000.
2026-05-28 18:01:58,097 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3680, handle 0x7a8: C:\Windows\System32\SecurityHealthSystray.exe
2026-05-28 18:01:58,100 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3680 (handle 0x7a8): 0x00007FF661AB0000.
2026-05-28 18:01:58,101 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6084, handle 0x7a8: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,102 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6084 (handle 0x7a8): 0x00007FF780360000.
2026-05-28 18:01:58,103 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4944, handle 0x7a8: C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2026-05-28 18:01:58,104 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4944 (handle 0x7a8): 0x0000000000320000.
2026-05-28 18:01:58,105 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5876, handle 0x7a8: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,106 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5876 (handle 0x7a8): 0x00007FF780360000.
2026-05-28 18:01:58,107 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3552, handle 0x7a8: C:\Program Files (x86)\Steam\steam.exe
2026-05-28 18:01:58,108 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3552 (handle 0x7a8): 0x00007FF7CB360000.
2026-05-28 18:01:58,109 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6200, handle 0x7a8: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:01:58,110 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6200 (handle 0x7a8): 0x00007FF6B1860000.
2026-05-28 18:01:58,110 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6600, handle 0x7a8: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:01:58,111 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6600 (handle 0x7a8): 0x00007FF6B1860000.
2026-05-28 18:01:58,112 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3392, handle 0x7a8: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:01:58,114 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3392 (handle 0x7a8): 0x00007FF7D0050000.
2026-05-28 18:01:58,117 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6908, handle 0x7a8: C:\Program Files (x86)\Common Files\Steam\steamservice.exe
2026-05-28 18:01:58,118 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6908 (handle 0x7a8): 0x0000000000390000.
2026-05-28 18:01:58,119 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6448, handle 0x7a8: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:01:58,120 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6448 (handle 0x7a8): 0x00007FF7D0050000.
2026-05-28 18:01:58,120 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 7632, handle 0x7a8: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:01:58,121 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 7632 (handle 0x7a8): 0x00007FF7D0050000.
2026-05-28 18:01:58,122 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 7988, handle 0x7a8: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,124 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 7988 (handle 0x7a8): 0x00007FF780360000.
2026-05-28 18:01:58,124 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 796, handle 0x7a8: C:\Windows\System32\ApplicationFrameHost.exe
2026-05-28 18:01:58,126 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 796 (handle 0x7a8): 0x00007FF7EECE0000.
2026-05-28 18:01:58,126 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 7940, handle 0x7a8: C:\Windows\System32\notepad.exe
2026-05-28 18:01:58,128 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 7940 (handle 0x7a8): 0x00007FF7241A0000.
2026-05-28 18:01:58,129 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4452, handle 0x7a8: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
2026-05-28 18:01:58,141 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4452 (handle 0x7a4): 0x00007FF78C870000.
2026-05-28 18:01:58,203 [root] INFO: Added new file to list with pid 7912 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 18:01:58,223 [root] INFO: Added new file to list with pid 7912 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 18:01:58,350 [root] DEBUG: 7912: DLL loaded at 0x00007FFC74A70000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:01:58,353 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6E0E0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 18:01:58,374 [root] DEBUG: 7912: api-rate-cap: NtQueryValueKey hook disabled due to rate
2026-05-28 18:01:58,572 [root] DEBUG: 7912: DLL loaded at 0x00007FFC73480000: C:\Windows\system32\dwmapi (0x2f000 bytes).
2026-05-28 18:01:58,573 [root] DEBUG: 7912: DLL loaded at 0x0000029255550000: C:\Windows\system32\d3d9 (0x1cd000 bytes).
2026-05-28 18:01:58,600 [root] DEBUG: 7912: DLL loaded at 0x00007FFC731A0000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 18:01:58,606 [root] DEBUG: 7912: DLL loaded at 0x00007FFC5EEF0000: C:\Windows\system32\D3D12Core (0x1cd000 bytes).
2026-05-28 18:01:58,609 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6E3B0000: C:\Windows\system32\d3d10warp (0x6f6000 bytes).
2026-05-28 18:01:58,614 [root] DEBUG: 7912: DLL loaded at 0x00007FFC5F430000: C:\Windows\system32\dxilconv (0x139000 bytes).
2026-05-28 18:01:58,616 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6A9E0000: C:\Windows\system32\D3DSCache (0x2a000 bytes).
2026-05-28 18:01:58,639 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6E3B0000: C:\Windows\system32\d3d10warp (0x6f6000 bytes).
2026-05-28 18:01:58,642 [root] DEBUG: 7912: DLL loaded at 0x00007FFC753D0000: C:\Windows\system32\DEVOBJ (0x33000 bytes).
2026-05-28 18:01:58,644 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6E0C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 18:01:58,648 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 336, handle 0x808: C:\Windows\System32\smss.exe
2026-05-28 18:01:58,649 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:01:58,651 [root] DEBUG: 7912: DLL loaded at 0x00007FFC74AB0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 18:01:58,656 [root] DEBUG: 7912: DLL loaded at 0x00007FFC747D0000: C:\Windows\system32\wkscli (0x19000 bytes).
2026-05-28 18:01:58,668 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 500, handle 0xa44: C:\Windows\System32\wininit.exe
2026-05-28 18:01:58,673 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 592, handle 0xa30: C:\Windows\System32\services.exe
2026-05-28 18:01:58,678 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 640, handle 0x7d4: C:\Windows\System32\lsass.exe
2026-05-28 18:01:58,681 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 640 (handle 0xa3c): 0x00007FF657A90000.
2026-05-28 18:01:58,682 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 748, handle 0xa3c: C:\Windows\System32\fontdrvhost.exe
2026-05-28 18:01:58,682 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 860, handle 0xa3c: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,684 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 860 (handle 0xa3c): 0x00007FF780360000.
2026-05-28 18:01:58,684 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 984, handle 0xa3c: C:\Windows\System32\dwm.exe
2026-05-28 18:01:58,689 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 984 (handle 0xa30): 0x00007FF6D4CD0000.
2026-05-28 18:01:58,689 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 492, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,691 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 492 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,694 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 560, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,696 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 560 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,696 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1072, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,698 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1072 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,699 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1172, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,700 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1172 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,701 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1224, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,703 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1224 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,704 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1316, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,706 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1316 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,706 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1468, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,709 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1468 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,709 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1604, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,711 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1604 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,712 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1688, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,713 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1688 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,714 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1732, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,716 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1732 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,716 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1852, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,718 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1852 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,719 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1900, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,720 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1900 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,721 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1396, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,724 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1396 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,725 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1644, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,726 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1644 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,727 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2184, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,729 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2184 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,729 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2308, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,731 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2308 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,732 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2504, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,733 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2504 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,734 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2628, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,736 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2628 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,737 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2644, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,741 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2644 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,742 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2800, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,743 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2800 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,744 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2932, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,746 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2932 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,746 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3672, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,748 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3672 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,749 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 736, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,750 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 736 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,751 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3068, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,753 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3068 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,755 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2672, handle 0xa30: C:\Windows\System32\taskhostw.exe
2026-05-28 18:01:58,757 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2672 (handle 0xa30): 0x00007FF77B4D0000.
2026-05-28 18:01:58,758 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3456, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,760 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3456 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,760 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4148, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,762 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4148 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:01:58,763 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4344, handle 0xa30: C:\Windows\System32\ctfmon.exe
2026-05-28 18:01:58,766 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4344 (handle 0xa3c): 0x00007FF7DC490000.
2026-05-28 18:01:58,766 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4584, handle 0xa3c: C:\Windows\explorer.exe
2026-05-28 18:01:58,769 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4584 (handle 0xa30): 0x00007FF65E010000.
2026-05-28 18:01:58,772 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4836, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,774 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4836 (handle 0x7d4): 0x00007FF780360000.
2026-05-28 18:01:58,775 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4128, handle 0x7d4: C:\Windows\System32\dllhost.exe
2026-05-28 18:01:58,779 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4128 (handle 0xa30): 0x00007FF699DF0000.
2026-05-28 18:01:58,780 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5176, handle 0xa30: C:\Windows\servicing\TrustedInstaller.exe
2026-05-28 18:01:58,784 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5176 (handle 0xa50): 0x00007FF662190000.
2026-05-28 18:01:58,785 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5320, handle 0xa50: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 18:01:58,792 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5320 (handle 0xa50): 0x00007FF77B710000.
2026-05-28 18:01:58,793 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5416, handle 0xa50: C:\Windows\System32\MoUsoCoreWorker.exe
2026-05-28 18:01:58,798 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5416 (handle 0xa38): 0x00007FF68F1D0000.
2026-05-28 18:01:58,799 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5684, handle 0xa38: C:\Windows\System32\SearchFilterHost.exe
2026-05-28 18:01:58,802 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5684 (handle 0xa30): 0x00007FF6EC310000.
2026-05-28 18:01:58,802 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3120, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,804 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3280, handle 0xa30: C:\Windows\System32\smartscreen.exe
2026-05-28 18:01:58,808 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3280 (handle 0x7d4): 0x00007FF7AC790000.
2026-05-28 18:01:58,809 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3692, handle 0x7d4: C:\Windows\System32\SecurityHealthService.exe
2026-05-28 18:01:58,813 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6040, handle 0xa50: C:\Windows\System32\conhost.exe
2026-05-28 18:01:58,816 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6040 (handle 0xa90): 0x00007FF799880000.
2026-05-28 18:01:58,816 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5920, handle 0xa90: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,819 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5920 (handle 0xa90): 0x00007FF780360000.
2026-05-28 18:01:58,820 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3484, handle 0xa90: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:01:58,821 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3484 (handle 0xa90): 0x00007FF6B1860000.
2026-05-28 18:01:58,822 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3344, handle 0xa90: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:01:58,823 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3344 (handle 0xa90): 0x00007FF6B1860000.
2026-05-28 18:01:58,823 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6236, handle 0xa90: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:01:58,825 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6236 (handle 0xa90): 0x00007FF6B1860000.
2026-05-28 18:01:58,826 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6772, handle 0xa90: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:01:58,827 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6772 (handle 0xa90): 0x00007FF6B1860000.
2026-05-28 18:01:58,828 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6580, handle 0xa90: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:01:58,829 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6580 (handle 0xa90): 0x00007FF7D0050000.
2026-05-28 18:01:58,829 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 7052, handle 0xa90: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:01:58,830 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 7052 (handle 0xa90): 0x00007FF7D0050000.
2026-05-28 18:01:58,831 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 6320, handle 0xa90: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:01:58,832 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 6320 (handle 0xa90): 0x00007FF7D0050000.
2026-05-28 18:01:58,833 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 7956, handle 0xa90: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,835 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 7956 (handle 0xa90): 0x00007FF780360000.
2026-05-28 18:01:58,836 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4576, handle 0xa90: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:01:58,837 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4576 (handle 0xa90): 0x00007FF7D0050000.
2026-05-28 18:01:58,838 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1084, handle 0xa90: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe
2026-05-28 18:01:58,847 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6E250000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 18:01:58,860 [root] DEBUG: 7912: DLL loaded at 0x00007FFC6E250000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 18:01:58,871 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1084 (handle 0x7d4): 0x00007FF69C720000.
2026-05-28 18:01:58,872 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 7444, handle 0x7d4: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 18:01:58,877 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 7444 (handle 0x7d4): 0x00007FF77B710000.
2026-05-28 18:01:58,881 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2904, handle 0xa98: C:\Windows\System32\net.exe
2026-05-28 18:01:58,884 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2904 (handle 0xa94): 0x00007FF7EC240000.
2026-05-28 18:01:58,884 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1016, handle 0xa94: C:\Windows\System32\net1.exe
2026-05-28 18:01:58,888 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1016 (handle 0xa94): 0x00007FF6BAB80000.
2026-05-28 18:01:58,889 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 8196, handle 0xa94: C:\Windows\System32\svchost.exe
2026-05-28 18:01:58,891 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 8196 (handle 0xa94): 0x00007FF780360000.
2026-05-28 18:01:59,860 [root] DEBUG: 7912: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 18:01:59,861 [root] DEBUG: 7912: DLL loaded at 0x00007FFC63C20000: C:\Windows\system32\CHARTV (0x25000 bytes).
2026-05-28 18:01:59,869 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 18:01:59,870 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 18:01:59,871 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 18:01:59,874 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://sugarcraft.net/"" with pid 9188
2026-05-28 18:01:59,875 [lib.api.process] INFO: Monitor config for process 9188: C:\_a4sjgfa\dll\9188.ini
2026-05-28 18:01:59,877 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:01:59,879 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:01:59,885 [root] DEBUG: Loader: Injecting process 9188 (thread 9192) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:59,886 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:01:59,886 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:01:59,889 [lib.api.process] INFO: Injected into 64-bit <Process 9188 msedge.exe>
2026-05-28 18:02:00,368 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9188, handle 0xa9c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:00,371 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9188 (handle 0xa84): 0x00007FF734750000.
2026-05-28 18:02:01,899 [lib.api.process] INFO: Successfully resumed process with pid 9188
2026-05-28 18:02:01,979 [root] DEBUG: 9188: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:02:01,980 [root] DEBUG: 9188: Interactive desktop enabled.
2026-05-28 18:02:01,980 [root] DEBUG: 9188: Dropped file limit defaulting to 100.
2026-05-28 18:02:01,989 [root] DEBUG: 9188: Edge-specific hook-set enabled.
2026-05-28 18:02:01,991 [root] DEBUG: 9188: Disabling sleep skipping.
2026-05-28 18:02:01,992 [root] DEBUG: 9188: YaraInit: Compiled rules loaded from existing file C:\_a4sjgfa\data\yara\capemon.yac
2026-05-28 18:02:02,003 [root] DEBUG: 9188: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:02:02,003 [root] DEBUG: 9188: Monitor initialised: 64-bit capemon loaded in process 9188 at 0x00007FFC33AB0000, thread 9192, image base 0x00007FF734750000, stack from 0x000000C8193F4000-0x000000C819400000
2026-05-28 18:02:02,004 [root] DEBUG: 9188: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://sugarcraft.net/"
2026-05-28 18:02:02,015 [root] DEBUG: 9188: Hooked 2 out of 2 functions
2026-05-28 18:02:02,051 [root] DEBUG: 9188: Syscall hook installed, syscall logging level 1
2026-05-28 18:02:02,057 [root] DEBUG: 9188: RestoreHeaders: Restored original import table.
2026-05-28 18:02:02,057 [root] INFO: Loaded monitor into process with pid 9188
2026-05-28 18:02:02,059 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 18:02:02,064 [root] DEBUG: 9188: DLL loaded at 0x00007FFC63BA0000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 18:02:02,068 [root] DEBUG: 9188: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:02:02,070 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 18:02:02,070 [root] DEBUG: 9188: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:02:02,071 [root] DEBUG: 9188: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 18:02:02,072 [root] DEBUG: 9188: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:02:02,216 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5CA40000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 18:02:02,217 [root] DEBUG: 9188: DLL loaded at 0x00007FFC1E940000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 18:02:02,219 [root] DEBUG: 9188: DLL loaded at 0x00007FFC620A0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 18:02:02,221 [root] DEBUG: 9188: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:02:02,226 [root] DEBUG: 9188: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:02:02,226 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 9204: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:02,227 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9204
2026-05-28 18:02:02,228 [root] DEBUG: 9188: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:02:02,228 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9204
2026-05-28 18:02:02,229 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6AA20000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 18:02:02,230 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:02:02,231 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:02:02,235 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75560000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 18:02:02,236 [root] DEBUG: 9188: DLL loaded at 0x00007FFC73F40000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 18:02:02,237 [root] DEBUG: 9188: DLL loaded at 0x00007FFC747D0000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 18:02:02,238 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74B80000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 18:02:02,240 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:02:02,241 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5FA20000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 18:02:02,243 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:02:02,243 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 18:02:02,244 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75090000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 18:02:02,245 [root] DEBUG: 9188: DLL loaded at 0x00007FFC77F00000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:02:02,245 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6DA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:02:02,246 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5B690000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 18:02:02,246 [root] DEBUG: 9188: DLL loaded at 0x00007FFC63BE0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 18:02:02,247 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:02:02,247 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75050000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 18:02:02,249 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6C4D0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 18:02:02,250 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:02:02,250 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 18:02:02,251 [root] DEBUG: 9188: DLL loaded at 0x00007FFC72B70000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 18:02:02,252 [root] DEBUG: 9188: DLL loaded at 0x00007FFC755E0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 18:02:02,259 [root] DEBUG: 9188: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:02:02,261 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6A9C0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 18:02:02,261 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:02:02,262 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:02:02,263 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6BCE0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 18:02:02,264 [root] DEBUG: 9188: DLL loaded at 0x00007FFC69960000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 18:02:02,267 [root] DEBUG: 9188: DLL loaded at 0x00007FFC61E00000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 18:02:02,268 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75430000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 18:02:02,269 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6F400000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 18:02:02,270 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74A70000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:02:02,271 [root] DEBUG: 9188: DLL loaded at 0x00007FFC70B80000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 18:02:02,272 [root] DEBUG: 9188: DLL loaded at 0x00007FFC771D0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 18:02:02,274 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6E0C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 18:02:02,274 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75F50000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 18:02:02,275 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6BA50000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 18:02:02,276 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:02:02,277 [root] DEBUG: 9188: DLL loaded at 0x00007FFC728F0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 18:02:02,278 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74AB0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 18:02:02,280 [root] DEBUG: 9188: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:02:02,282 [root] DEBUG: 9188: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:02:02,283 [root] DEBUG: 9188: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:02:02,284 [root] DEBUG: 9188: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 18:02:02,285 [root] DEBUG: 9188: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 18:02:02,289 [root] DEBUG: 9188: DLL loaded at 0x00007FFC664D0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 18:02:02,290 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:02:02,292 [root] DEBUG: 9188: DLL loaded at 0x00007FFC60C70000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 18:02:02,294 [root] DEBUG: 9188: DLL loaded at 0x00007FFC65B50000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 18:02:02,295 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6ED50000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 18:02:02,298 [root] DEBUG: 9188: DLL loaded at 0x00007FFC70130000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 18:02:02,298 [root] DEBUG: 9188: DLL loaded at 0x00007FFC69E70000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 18:02:02,299 [root] DEBUG: 9188: DLL loaded at 0x00007FFC69FD0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 18:02:02,300 [root] DEBUG: 9188: DLL loaded at 0x00007FFC650F0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 18:02:02,314 [root] DEBUG: 9188: DLL loaded at 0x00007FFC72B20000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 18:02:02,316 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75370000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 18:02:02,320 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6FD90000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 18:02:02,320 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6FDB0000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 18:02:02,323 [root] DEBUG: 9188: DLL loaded at 0x00007FFC707B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 18:02:02,325 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 18:02:02,325 [lib.api.process] INFO: Monitor config for process 592: C:\_a4sjgfa\dll\592.ini
2026-05-28 18:02:02,326 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:02:02,327 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:02:02,332 [root] DEBUG: Loader: Injecting process 592 with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:02:02,332 [root] DEBUG: 9188: DLL loaded at 0x00007FFC1E370000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 18:02:02,334 [root] DEBUG: Loader: Copied config file C:\_a4sjgfa\dll\592.ini to system path C:\592.ini
2026-05-28 18:02:02,337 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 592 C:\_a4sjgfa\dll\tHnPbxs.dll
2026-05-28 18:02:02,338 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:02:02,341 [lib.api.process] INFO: Injected into 64-bit <Process 592 services.exe>
2026-05-28 18:02:02,345 [root] DEBUG: 9188: DLL loaded at 0x00007FFC68DC0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 18:02:02,350 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6B370000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 18:02:02,354 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 9660: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:02,355 [root] DEBUG: 9188: DLL loaded at 0x00007FFC65020000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 18:02:02,361 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9660
2026-05-28 18:02:02,368 [root] DEBUG: 9188: DLL loaded at 0x00007FFC69BE0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 18:02:02,370 [root] DEBUG: 9188: caller_dispatch: Added region at 0x00007FF734750000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF734847D66, thread 9472).
2026-05-28 18:02:02,421 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9660
2026-05-28 18:02:02,435 [root] DEBUG: 9188: ProcessImageBase: Main module image at 0x00007FF734750000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:02:02,437 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9204, handle 0xa88: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:02,437 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5E640000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 18:02:02,440 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 9744: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:02,472 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 9756: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:02,473 [root] DEBUG: 9188: DLL loaded at 0x00007FFC73F70000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 18:02:02,478 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9744
2026-05-28 18:02:02,479 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9204 (handle 0xa88): 0x00007FF734750000.
2026-05-28 18:02:02,480 [root] DEBUG: 9188: DLL loaded at 0x00007FFC71690000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 18:02:02,481 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9616, handle 0xa88: C:\_a4sjgfa\bin\PPLinject64.exe
2026-05-28 18:02:02,481 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9744
2026-05-28 18:02:02,482 [root] DEBUG: 9188: DLL loaded at 0x00007FFC72020000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 18:02:02,483 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9756
2026-05-28 18:02:02,484 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9756
2026-05-28 18:02:02,490 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5F830000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 18:02:02,602 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9616 (handle 0xaa4): 0x00007FF668FE0000.
2026-05-28 18:02:02,612 [root] DEBUG: 9188: DLL loaded at 0x00007FFC63BF0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 18:02:02,621 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9632, handle 0xaa4: C:\Windows\System32\conhost.exe
2026-05-28 18:02:02,624 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 10004: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:02,624 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 9972: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:02,625 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 10004
2026-05-28 18:02:02,626 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9972
2026-05-28 18:02:02,627 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 10004
2026-05-28 18:02:02,627 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9632 (handle 0xaa4): 0x00007FF799880000.
2026-05-28 18:02:02,628 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 9972
2026-05-28 18:02:02,629 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9660, handle 0xaa4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:02,642 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9660 (handle 0xaa4): 0x00007FF734750000.
2026-05-28 18:02:02,649 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5F9A0000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 18:02:02,672 [root] DEBUG: 9188: DLL loaded at 0x00007FFC67700000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 18:02:02,752 [root] DEBUG: 9188: DLL loaded at 0x00007FFC73480000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 18:02:02,824 [root] DEBUG: 9188: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 18:02:02,853 [root] DEBUG: 9188: DLL loaded at 0x00007FFC1A480000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 18:02:02,870 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 18:02:02,873 [root] DEBUG: 9188: DLL loaded at 0x00007FFC746B0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 18:02:02,883 [root] DEBUG: 9188: DLL loaded at 0x00007FFC63280000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 18:02:02,887 [root] DEBUG: 9188: DLL loaded at 0x00007FFC66790000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:02:02,889 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5E650000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 18:02:02,914 [root] DEBUG: 9188: DLL loaded at 0x00007FFC1A3F0000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 18:02:03,376 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9744, handle 0xaa8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:03,379 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9744 (handle 0xaa8): 0x00007FF734750000.
2026-05-28 18:02:03,380 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9756, handle 0xaa8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:03,384 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9756 (handle 0xaa8): 0x00007FF734750000.
2026-05-28 18:02:03,386 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9972, handle 0xaa8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:03,388 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9972 (handle 0xab0): 0x00007FF734750000.
2026-05-28 18:02:03,388 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 10004, handle 0xab0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:03,390 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 10004 (handle 0xab0): 0x00007FF734750000.
2026-05-28 18:02:04,232 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:02:04,234 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:02:05,391 [root] DEBUG: 9188: DLL loaded at 0x00007FFC754B0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 18:02:05,402 [root] DEBUG: 9188: DLL loaded at 0x00007FFC70650000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:02:05,403 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5D4D0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 18:02:06,624 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5CAE0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 18:02:09,177 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 10420: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:09,178 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 10420
2026-05-28 18:02:09,180 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 10420
2026-05-28 18:02:09,389 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 10420, handle 0xa84: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:09,400 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 10420 (handle 0xa84): 0x00007FF734750000.
2026-05-28 18:02:10,390 [root] DEBUG: 9188: DLL loaded at 0x00007FFC77700000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 18:02:10,392 [root] DEBUG: 9188: DLL loaded at 0x00007FFC70770000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 18:02:10,393 [root] DEBUG: 9188: DLL loaded at 0x00007FFC753D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 18:02:10,394 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 18:02:10,395 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6CEE0000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 18:02:10,450 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 10532: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:10,452 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 10532
2026-05-28 18:02:10,454 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 10532
2026-05-28 18:02:10,472 [root] DEBUG: 9188: DLL loaded at 0x00007FFC1A000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 18:02:10,533 [root] DEBUG: 9188: DLL loaded at 0x00007FFC199A0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 18:02:10,558 [root] DEBUG: 9188: DLL loaded at 0x00007FFC1CB70000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 18:02:10,561 [root] DEBUG: 9188: DLL loaded at 0x00007FFC742D0000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 18:02:10,563 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74290000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 18:02:10,588 [root] DEBUG: 9188: DLL loaded at 0x00007FFC67500000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 18:02:10,592 [root] DEBUG: 9188: DLL loaded at 0x00007FFC5FA10000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 18:02:10,614 [root] DEBUG: 9188: DLL loaded at 0x00007FFC73380000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:02:10,616 [root] DEBUG: 9188: DLL loaded at 0x00007FFC711F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:02:10,617 [root] DEBUG: 9188: DLL loaded at 0x00007FFC60E20000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:02:10,689 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 10636: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF66CA90000
2026-05-28 18:02:10,691 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 10636
2026-05-28 18:02:10,691 [lib.api.process] INFO: Monitor config for process 10636: C:\_a4sjgfa\dll\10636.ini
2026-05-28 18:02:10,692 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:02:11,512 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 10532, handle 0xa84: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:11,531 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 10532 (handle 0xa84): 0x00007FF734750000.
2026-05-28 18:02:11,534 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 10636, handle 0xa84: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 18:02:11,777 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:02:11,778 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:02:11,785 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:02:11,791 [root] DEBUG: Loader: Injecting process 10636 (thread 10640) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:02:11,792 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:02:11,792 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:02:11,794 [lib.api.process] INFO: Injected into 64-bit <Process 10636 identity_helper.exe>
2026-05-28 18:02:11,811 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6DB50000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 18:02:11,814 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6A6A0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 18:02:11,816 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 10720: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF66CA90000
2026-05-28 18:02:11,817 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 10720
2026-05-28 18:02:11,818 [lib.api.process] INFO: Monitor config for process 10720: C:\_a4sjgfa\dll\10720.ini
2026-05-28 18:02:11,819 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:02:11,926 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:02:11,927 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:02:11,929 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:02:11,934 [root] DEBUG: Loader: Injecting process 10720 (thread 10724) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:02:11,935 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:02:11,937 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:02:11,939 [lib.api.process] INFO: Injected into 64-bit <Process 10720 identity_helper.exe>
2026-05-28 18:02:11,942 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 10720
2026-05-28 18:02:11,942 [lib.api.process] INFO: Monitor config for process 10720: C:\_a4sjgfa\dll\10720.ini
2026-05-28 18:02:11,942 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:02:12,052 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:02:12,058 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:02:12,063 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:02:12,069 [root] DEBUG: Loader: Injecting process 10720 (thread 10724) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:02:12,070 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:02:12,085 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:02:12,088 [lib.api.process] INFO: Injected into 64-bit <Process 10720 identity_helper.exe>
2026-05-28 18:02:12,112 [root] DEBUG: 10720: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:02:12,113 [root] DEBUG: 10720: Interactive desktop enabled.
2026-05-28 18:02:12,114 [root] DEBUG: 10720: Dropped file limit defaulting to 100.
2026-05-28 18:02:12,120 [root] DEBUG: 10720: Disabling sleep skipping.
2026-05-28 18:02:12,122 [root] DEBUG: 10720: YaraInit: Compiled rules loaded from existing file C:\_a4sjgfa\data\yara\capemon.yac
2026-05-28 18:02:12,139 [root] DEBUG: 10720: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:02:12,140 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FF66CA90000, size 0x28b4d8
2026-05-28 18:02:12,177 [root] DEBUG: 10720: Monitor initialised: 64-bit capemon loaded in process 10720 at 0x00007FFC33AB0000, thread 10724, image base 0x00007FF66CA90000, stack from 0x000000B8F7924000-0x000000B8F7930000
2026-05-28 18:02:12,179 [root] DEBUG: 10720: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5988,i,16463646965434194640,9756354988950792942,524288 --field-trial-handle=2464,i,11618049249894349634,12934656804764563957,262144 --variations-seed-version --pseudonymization-salt-handle=2472,i,15884246703223372676,91259951654935
2026-05-28 18:02:12,179 [root] DEBUG: 10720: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 18:02:12,190 [root] DEBUG: 10720: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 18:02:12,217 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:02:12,218 [root] DEBUG: 10720: set_hooks: Unable to hook LockResource
2026-05-28 18:02:12,224 [root] DEBUG: 10720: Hooked 627 out of 628 functions
2026-05-28 18:02:12,252 [root] DEBUG: 10720: Syscall hook installed, syscall logging level 1
2026-05-28 18:02:12,257 [root] DEBUG: 10720: RestoreHeaders: Restored original import table.
2026-05-28 18:02:12,258 [root] INFO: Loaded monitor into process with pid 10720
2026-05-28 18:02:12,261 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FFC32000000, size 0x4b9994
2026-05-28 18:02:12,332 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FFC32000000, size 0x4b9994
2026-05-28 18:02:12,368 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FFC32000000, size 0x4b9994
2026-05-28 18:02:12,426 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 10720, handle 0xa84: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 18:02:12,433 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FFC32000000, size 0x4b9994
2026-05-28 18:02:12,467 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 10720 (handle 0xab0): 0x00007FF66CA90000.
2026-05-28 18:02:12,470 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FFC32000000, size 0x4b9994
2026-05-28 18:02:12,521 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FFC32000000, size 0x4b9994
2026-05-28 18:02:12,570 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FFC32000000, size 0x4b9994
2026-05-28 18:02:12,619 [root] DEBUG: 10720: caller_dispatch: Added region at 0x00007FFC32000000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFC321FF156, thread 10724).
2026-05-28 18:02:12,620 [root] DEBUG: 10720: caller_dispatch: Scanning calling region at 0x00007FFC32000000...
2026-05-28 18:02:12,625 [root] DEBUG: 10720: ProcessTrackedRegion: Region at 0x00007FFC32000000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 18:02:12,629 [root] DEBUG: 10720: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 18:02:12,671 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FF66CA90000, size 0x28b4d8
2026-05-28 18:02:12,692 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FF66CA90000, size 0x28b4d8
2026-05-28 18:02:12,711 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FF66CA90000, size 0x28b4d8
2026-05-28 18:02:12,745 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FF66CA90000, size 0x28b4d8
2026-05-28 18:02:12,769 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FF66CA90000, size 0x28b4d8
2026-05-28 18:02:12,787 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FF66CA90000, size 0x28b4d8
2026-05-28 18:02:12,822 [root] DEBUG: 10720: caller_dispatch: Added region at 0x00007FF66CA90000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF66CB84096, thread 10724).
2026-05-28 18:02:12,823 [root] DEBUG: 10720: YaraScan: Scanning 0x00007FF66CA90000, size 0x28b4d8
2026-05-28 18:02:12,845 [root] DEBUG: 10720: ProcessImageBase: Main module image at 0x00007FF66CA90000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:02:12,851 [root] DEBUG: 10720: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:02:12,876 [root] DEBUG: 10720: DLL loaded at 0x00007FFC1E940000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 18:02:12,915 [root] DEBUG: 10720: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:02:12,938 [root] DEBUG: 10720: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:02:12,942 [root] DEBUG: 10720: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:02:13,248 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6D710000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 18:02:13,251 [root] DEBUG: 9188: DLL loaded at 0x00007FFC63700000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:02:13,252 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6E250000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 18:02:13,600 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6C4D0000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 18:02:13,602 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75090000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 18:02:13,604 [root] DEBUG: 9188: DLL loaded at 0x00007FFC75050000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 18:02:13,605 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6DA30000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 18:02:13,607 [root] DEBUG: 9188: DLL loaded at 0x00007FFC77F00000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:02:13,608 [root] DEBUG: 9188: DLL loaded at 0x00007FFC6DA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:02:13,609 [root] DEBUG: 9188: DLL loaded at 0x00007FFC61590000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 18:02:13,796 [root] DEBUG: 9188: DLL loaded at 0x00007FFC74D80000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 18:02:13,850 [root] DEBUG: 10720: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:02:13,855 [root] DEBUG: 10720: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:02:13,856 [root] DEBUG: 10720: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:02:13,857 [root] DEBUG: 10720: DLL loaded at 0x00007FFC73380000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:02:13,875 [root] DEBUG: 10720: DLL loaded at 0x00007FFC711F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:02:13,876 [root] DEBUG: 10720: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:02:13,877 [root] DEBUG: 10720: DLL loaded at 0x00007FFC60E20000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:02:13,920 [root] DEBUG: 10720: DLL loaded at 0x00007FFC70650000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:02:13,928 [root] DEBUG: 10720: DLL loaded at 0x00007FFC6F400000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 18:02:13,971 [root] DEBUG: 10720: DLL loaded at 0x00007FFC728F0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 18:02:13,973 [root] DEBUG: 10720: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:02:13,974 [root] DEBUG: 10720: DLL loaded at 0x00007FFC63990000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 18:02:13,993 [root] DEBUG: 10720: DLL loaded at 0x00007FFC66790000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:02:14,000 [root] DEBUG: 10720: DLL loaded at 0x00007FFC614E0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 18:02:14,006 [root] DEBUG: 10720: DLL loaded at 0x00007FFC74740000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:02:14,007 [root] DEBUG: 10720: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:02:14,027 [root] DEBUG: 10720: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:02:14,035 [root] DEBUG: 10720: DLL loaded at 0x00007FFC75EE0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 18:02:14,036 [root] DEBUG: 10720: DLL loaded at 0x00007FFC6DB50000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 18:02:14,038 [root] DEBUG: 10720: DLL loaded at 0x00007FFC751B0000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 18:02:14,053 [root] DEBUG: 10720: DLL loaded at 0x00007FFC5B720000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 18:02:14,088 [root] DEBUG: 10720: DLL loaded at 0x00007FFC5B910000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 18:02:14,120 [root] DEBUG: 10720: DLL loaded at 0x00007FFC75020000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 18:02:14,122 [root] DEBUG: 10720: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:02:14,141 [root] DEBUG: 10720: DLL loaded at 0x00007FFC65B50000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 18:02:14,219 [root] DEBUG: 10720: DLL loaded at 0x00007FFC75F50000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 18:02:14,245 [root] DEBUG: 10720: DLL loaded at 0x00007FFC63700000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:02:14,254 [root] DEBUG: 10720: DLL loaded at 0x00007FFC51A40000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 18:02:14,279 [root] DEBUG: 10720: DLL loaded at 0x00007FFC6AB30000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 18:02:14,281 [root] DEBUG: 10720: DLL loaded at 0x00007FFC6AC50000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 18:02:14,282 [root] DEBUG: 10720: DLL loaded at 0x00007FFC61260000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 18:02:14,295 [root] DEBUG: 10720: DLL loaded at 0x00007FFC6E1F0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 18:02:14,311 [root] DEBUG: 10720: DLL loaded at 0x00007FFC73F70000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 18:02:14,312 [root] DEBUG: 10720: DLL loaded at 0x00007FFC71690000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 18:02:14,819 [root] DEBUG: 10720: DLL loaded at 0x00007FFC67810000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 18:02:14,821 [root] DEBUG: 10720: DLL loaded at 0x00007FFC5B5A0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 18:02:14,850 [root] DEBUG: 10720: DLL loaded at 0x00007FFC5CBD0000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 18:02:14,876 [root] DEBUG: 10720: DLL loaded at 0x00007FFC75560000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 18:02:14,878 [root] DEBUG: 10720: DLL loaded at 0x00007FFC6A640000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 18:02:14,879 [root] DEBUG: 10720: DLL loaded at 0x00007FFC5FB10000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 18:02:26,741 [root] INFO: Process with pid 10720 has terminated
2026-05-28 18:02:26,953 [root] INFO: Process lock is locked
2026-05-28 18:02:27,619 [root] DEBUG: 10720: NtTerminateProcess hook: Attempting to dump process 10720
2026-05-28 18:02:28,502 [root] DEBUG: 10720: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:02:33,115 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 5484: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:34,211 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 5484, handle 0xab0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:35,151 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 5484
2026-05-28 18:02:35,355 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 5484
2026-05-28 18:02:35,634 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 5484 (handle 0xab0): 0x00007FF734750000.
2026-05-28 18:02:38,111 [root] DEBUG: 9188: DLL loaded at 0x00007FFC708F0000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 18:02:39,462 [root] DEBUG: 9188: DLL loaded at 0x00007FFC708D0000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 18:02:39,775 [root] DEBUG: 9188: CreateProcessHandler: Injection info set for new process 3656: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:02:39,777 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 3656
2026-05-28 18:02:39,778 [root] DEBUG: 9188: ProcessMessage: Skipping monitoring process 3656
2026-05-28 18:02:40,076 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 18:02:40,465 [root] INFO: Process with pid 9188 appears to have terminated
2026-05-28 18:02:40,502 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3656, handle 0xac8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:40,504 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 3656 (handle 0xac8): 0x00007FF734750000.
2026-05-28 18:02:40,505 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2196, handle 0xac8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:40,506 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2196 (handle 0xac8): 0x00007FF734750000.
2026-05-28 18:02:40,507 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 764, handle 0xac8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:40,509 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 764 (handle 0xac8): 0x00007FF734750000.
2026-05-28 18:02:40,510 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 1180, handle 0xac8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:40,514 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 1180 (handle 0xac0): 0x00007FF734750000.
2026-05-28 18:02:40,516 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 2660, handle 0xac0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:40,517 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 2660 (handle 0xac0): 0x00007FF734750000.
2026-05-28 18:02:40,518 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 11124, handle 0xac0: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 18:02:40,520 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 11124 (handle 0xac0): 0x00007FF66CA90000.
2026-05-28 18:02:45,499 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9856, handle 0xac0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:45,530 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9856 (handle 0xac0): 0x00007FF734750000.
2026-05-28 18:02:45,547 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 10572, handle 0xac0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:02:45,566 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 10572 (handle 0xac0): 0x00007FF734750000.
2026-05-28 18:02:57,530 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 3640, handle 0x320: C:\Windows\System32\svchost.exe
2026-05-28 18:03:00,018 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 9716: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 18:03:00,062 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 9816: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF6209B0000
2026-05-28 18:03:00,095 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9716
2026-05-28 18:03:00,112 [lib.api.process] INFO: Monitor config for process 9716: C:\_a4sjgfa\dll\9716.ini
2026-05-28 18:03:00,111 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 9816
2026-05-28 18:03:00,125 [lib.api.process] INFO: Monitor config for process 9816: C:\_a4sjgfa\dll\9816.ini
2026-05-28 18:03:00,134 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:03:00,152 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:03:00,169 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:03:00,260 [root] DEBUG: Loader: Injecting process 9716 (thread 9720) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:00,337 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:03:00,394 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:03:00,397 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:00,447 [root] DEBUG: Loader: Injecting process 9816 (thread 9648) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:00,469 [lib.api.process] INFO: Injected into 64-bit <Process 9716 dllhost.exe>
2026-05-28 18:03:00,480 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:03:00,517 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9716
2026-05-28 18:03:00,527 [lib.api.process] INFO: Monitor config for process 9716: C:\_a4sjgfa\dll\9716.ini
2026-05-28 18:03:00,527 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:00,527 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:03:00,540 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9192, handle 0x8dc: C:\Windows\System32\svchost.exe
2026-05-28 18:03:00,543 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:03:00,565 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9192 (handle 0x8dc): 0x00007FF780360000.
2026-05-28 18:03:00,569 [lib.api.process] INFO: Injected into 64-bit <Process 9816 WmiPrvSE.exe>
2026-05-28 18:03:00,592 [root] DEBUG: Loader: Injecting process 9716 (thread 9720) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:00,600 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9492, handle 0x8dc: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
2026-05-28 18:03:00,619 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:03:00,620 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 9816
2026-05-28 18:03:00,623 [lib.api.process] INFO: Monitor config for process 9816: C:\_a4sjgfa\dll\9816.ini
2026-05-28 18:03:00,624 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:03:00,627 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:00,623 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9492 (handle 0xad0): 0x0000000000030000.
2026-05-28 18:03:00,733 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9716, handle 0xad0: C:\Windows\System32\dllhost.exe
2026-05-28 18:03:00,733 [lib.api.process] INFO: Injected into 64-bit <Process 9716 dllhost.exe>
2026-05-28 18:03:00,777 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 9816, handle 0xad0: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-28 18:03:00,781 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:03:00,871 [root] DEBUG: 9716: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:03:00,871 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9816 (handle 0xa74): 0x00007FF6209B0000.
2026-05-28 18:03:00,928 [root] DEBUG: 9716: Interactive desktop enabled.
2026-05-28 18:03:00,966 [root] DEBUG: Loader: Injecting process 9816 (thread 9648) with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:00,979 [root] DEBUG: 9716: Dropped file limit defaulting to 100.
2026-05-28 18:03:00,990 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:03:01,037 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:01,040 [root] DEBUG: 9716: Disabling sleep skipping.
2026-05-28 18:03:01,082 [lib.api.process] INFO: Injected into 64-bit <Process 9816 WmiPrvSE.exe>
2026-05-28 18:03:01,104 [root] DEBUG: 9716: YaraInit: Compiled rules loaded from existing file C:\_a4sjgfa\data\yara\capemon.yac
2026-05-28 18:03:01,104 [root] DEBUG: 9816: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:03:01,125 [root] DEBUG: 9716: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:03:01,127 [root] DEBUG: 9816: Interactive desktop enabled.
2026-05-28 18:03:01,158 [root] DEBUG: 9716: YaraScan: Scanning 0x00007FF699DF0000, size 0x8026
2026-05-28 18:03:01,184 [root] DEBUG: 9816: Dropped file limit defaulting to 100.
2026-05-28 18:03:01,189 [root] DEBUG: 9716: Monitor initialised: 64-bit capemon loaded in process 9716 at 0x00007FFC33AB0000, thread 9720, image base 0x00007FF699DF0000, stack from 0x0000009B1AFD4000-0x0000009B1AFE0000
2026-05-28 18:03:01,201 [root] DEBUG: 9816: Disabling sleep skipping.
2026-05-28 18:03:01,201 [root] DEBUG: 9716: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 18:03:01,239 [root] DEBUG: 9816: Services hook set enabled
2026-05-28 18:03:01,244 [root] DEBUG: 9716: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 18:03:01,317 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:03:01,319 [root] DEBUG: 9816: YaraInit: Compiled rules loaded from existing file C:\_a4sjgfa\data\yara\capemon.yac
2026-05-28 18:03:01,353 [root] DEBUG: 9716: set_hooks: Unable to hook LockResource
2026-05-28 18:03:01,380 [root] DEBUG: 9816: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:03:01,457 [root] DEBUG: 9716: Hooked 627 out of 628 functions
2026-05-28 18:03:01,461 [root] DEBUG: 9816: Monitor initialised: 64-bit capemon loaded in process 9816 at 0x00007FFC33AB0000, thread 9648, image base 0x00007FF6209B0000, stack from 0x000000DA57190000-0x000000DA571A0000
2026-05-28 18:03:01,475 [root] DEBUG: 9716: Syscall hook installed, syscall logging level 1
2026-05-28 18:03:01,490 [root] DEBUG: 9816: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 18:03:01,534 [root] DEBUG: 9716: RestoreHeaders: Restored original import table.
2026-05-28 18:03:01,538 [root] DEBUG: 9816: Hooked 69 out of 69 functions
2026-05-28 18:03:01,563 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 9716 (handle 0xa60): 0x00007FF699DF0000.
2026-05-28 18:03:01,583 [root] INFO: Loaded monitor into process with pid 9716
2026-05-28 18:03:01,598 [root] DEBUG: 9816: RestoreHeaders: Restored original import table.
2026-05-28 18:03:01,604 [root] DEBUG: 9716: caller_dispatch: Added region at 0x00007FF699DF0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF699DF1349, thread 9720).
2026-05-28 18:03:01,608 [root] INFO: Loaded monitor into process with pid 9816
2026-05-28 18:03:01,624 [root] DEBUG: 9716: YaraScan: Scanning 0x00007FF699DF0000, size 0x8026
2026-05-28 18:03:01,641 [root] DEBUG: 9816: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:03:01,664 [root] DEBUG: 9716: ProcessImageBase: Main module image at 0x00007FF699DF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:03:01,692 [root] DEBUG: 9816: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:03:01,704 [root] DEBUG: 9716: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:03:01,738 [root] DEBUG: 9716: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:03:01,783 [root] DEBUG: 9816: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:03:01,822 [root] DEBUG: 9716: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:03:01,857 [lib.api.process] INFO: Monitor config for process 8196: C:\_a4sjgfa\dll\8196.ini
2026-05-28 18:03:01,931 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:03:01,943 [lib.api.process] INFO: 64-bit DLL to inject is C:\_a4sjgfa\dll\tHnPbxs.dll, loader C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:03:02,001 [root] DEBUG: 9716: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:03:02,029 [root] DEBUG: Loader: Injecting process 8196 with C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:02,090 [root] DEBUG: 8196: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:03:02,158 [root] DEBUG: 9716: DLL loaded at 0x00007FFC74BA0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 18:03:02,176 [root] DEBUG: 8196: Disabling sleep skipping.
2026-05-28 18:03:02,193 [root] DEBUG: 9716: DLL loaded at 0x00007FFC74B80000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 18:03:02,213 [root] DEBUG: 8196: Interactive desktop enabled.
2026-05-28 18:03:02,224 [root] DEBUG: 9716: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:03:02,245 [root] DEBUG: 8196: Dropped file limit defaulting to 100.
2026-05-28 18:03:02,250 [root] DEBUG: 9716: DLL loaded at 0x00007FFC707B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 18:03:02,282 [root] DEBUG: 8196: Services hook set enabled
2026-05-28 18:03:02,302 [root] DEBUG: 9716: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:03:02,356 [root] DEBUG: 8196: YaraInit: Compiled rules loaded from existing file C:\_a4sjgfa\data\yara\capemon.yac
2026-05-28 18:03:02,392 [root] DEBUG: 9716: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:03:02,393 [root] DEBUG: 8196: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:03:02,410 [root] DEBUG: 9716: DLL loaded at 0x00007FFC74A70000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:03:02,430 [root] DEBUG: 8196: Monitor initialised: 64-bit capemon loaded in process 8196 at 0x00007FFC33AB0000, thread 2780, image base 0x00007FF780360000, stack from 0x00000093D7AF4000-0x00000093D7B00000
2026-05-28 18:03:02,444 [root] DEBUG: 9716: DLL loaded at 0x00007FFC75560000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 18:03:02,447 [root] DEBUG: 8196: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 18:03:02,488 [root] DEBUG: 9716: DLL loaded at 0x00007FFC755E0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 18:03:02,525 [root] DEBUG: 8196: Hooked 69 out of 69 functions
2026-05-28 18:03:02,552 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 4608, handle 0xa60: C:\_a4sjgfa\bin\GGsGuLID.exe
2026-05-28 18:03:02,566 [root] INFO: Loaded monitor into process with pid 8196
2026-05-28 18:03:02,584 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 4608 (handle 0xa74): 0x00007FF79BBD0000.
2026-05-28 18:03:02,606 [root] DEBUG: 9716: DLL loaded at 0x00007FFC711F0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 18:03:02,615 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:03:02,645 [root] DEBUG: 9716: DLL loaded at 0x00007FFC74AB0000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 18:03:02,653 [root] DEBUG: Successfully injected DLL C:\_a4sjgfa\dll\tHnPbxs.dll.
2026-05-28 18:03:02,683 [root] DEBUG: 9716: DLL loaded at 0x00007FFC1A000000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 18:03:02,723 [lib.api.process] INFO: Injected into 64-bit <Process 8196 svchost.exe>
2026-05-28 18:03:02,754 [root] DEBUG: 9716: DLL loaded at 0x00007FFC771D0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 18:03:02,785 [root] DEBUG: 9716: DLL loaded at 0x00007FFC66790000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:03:04,615 [root] DEBUG: 4584: DLL loaded at 0x00007FFC601B0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 18:03:04,625 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6A330000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 18:03:04,652 [root] DEBUG: 4584: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 18:03:04,677 [root] DEBUG: 4584: DLL loaded at 0x00007FFC63BE0000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 18:03:04,738 [root] DEBUG: 4584: DLL loaded at 0x00007FFC19950000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 18:03:04,797 [root] DEBUG: 4584: DLL loaded at 0x00007FFC732A0000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 18:03:04,830 [root] DEBUG: 9816: DLL loaded at 0x00007FFC61080000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 18:03:04,830 [root] DEBUG: 4584: DLL loaded at 0x00007FFC199B0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 18:03:04,879 [root] DEBUG: 4584: DLL loaded at 0x00007FFC5FAF0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 18:03:04,895 [root] DEBUG: 9816: DLL loaded at 0x00007FFC63BB0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 18:03:04,968 [root] DEBUG: 4584: DLL loaded at 0x00007FFC19860000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 18:03:05,118 [root] DEBUG: 9816: DLL loaded at 0x00007FFC708E0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 18:03:05,332 [root] DEBUG: 9816: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:03:05,363 [root] DEBUG: 9816: DLL loaded at 0x00007FFC19950000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 18:03:05,411 [root] DEBUG: 9816: DLL loaded at 0x00007FFC19650000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 18:03:05,449 [root] DEBUG: 9816: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:03:05,551 [root] DEBUG: 9816: DLL loaded at 0x000002C2EE1B0000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 18:03:05,567 [root] DEBUG: 9816: DLL loaded at 0x00007FFC6F2C0000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 18:03:05,624 [root] DEBUG: 9816: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 18:03:06,551 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 11284, handle 0xa60: C:\Windows\System32\svchost.exe
2026-05-28 18:03:06,589 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 11284 (handle 0xa60): 0x00007FF780360000.
2026-05-28 18:03:06,628 [root] DEBUG: 7912: OpenProcessHandler: Injection info created for process 11304, handle 0xa60: C:\Windows\System32\svchost.exe
2026-05-28 18:03:06,665 [root] DEBUG: 7912: OpenProcessHandler: Image base for process 11304 (handle 0xa60): 0x00007FF780360000.
2026-05-28 18:03:07,932 [root] INFO: Process with pid 9716 has terminated
2026-05-28 18:03:08,022 [root] DEBUG: 9716: NtTerminateProcess hook: Attempting to dump process 9716
2026-05-28 18:03:08,093 [root] DEBUG: 9716: DoProcessDump: Skipping process dump as code is identical on disk.
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 18:01:45 | 2026-05-28 18:03:34 | none |
Seek in progress...
No results found.
No behavioral analysis data available.
No dropped files found.