| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 18:23:59 | 2026-05-28 18:27:46 | 227s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 17:52:19,127 [root] INFO: Date set to: 20260528T18:24:07, timeout set to: 200
2026-05-28 18:24:07,015 [root] DEBUG: Starting analyzer from: C:\piknapjj
2026-05-28 18:24:07,017 [root] DEBUG: Storing results at: C:\RulsVhT
2026-05-28 18:24:07,018 [root] DEBUG: Pipe server name: \\.\PIPE\jyzrRast
2026-05-28 18:24:07,018 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 18:24:07,018 [root] INFO: analysis running as an admin
2026-05-28 18:24:07,022 [root] INFO: analysis package specified: "edge"
2026-05-28 18:24:07,022 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 18:24:07,024 [root] DEBUG: imported analysis package "edge"
2026-05-28 18:24:07,029 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 18:24:07,030 [root] DEBUG: New location of moved file: https://sugarcraft.net/
2026-05-28 18:24:07,030 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 18:24:07,030 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 18:24:07,030 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 18:24:07,030 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 18:24:07,044 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 18:24:07,056 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 18:24:07,063 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 18:24:07,072 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 18:24:07,075 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 18:24:07,075 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 18:24:07,076 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 18:24:07,077 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 18:24:07,077 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 18:24:07,077 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 18:24:07,078 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 18:24:07,078 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 18:24:07,078 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 18:24:07,078 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 18:24:07,079 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 18:24:07,079 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 18:24:07,080 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 18:24:07,083 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 18:24:07,084 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 18:24:07,086 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 18:24:07,086 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 18:24:07,086 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 18:24:07,087 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 18:24:07,089 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 7924)
2026-05-28 18:24:07,089 [modules.auxiliary.disguise] INFO: Disguising GUID to ec82439f-b13e-40f2-bdaa-5f02c32145ae
2026-05-28 18:24:07,090 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 18:24:07,090 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 18:24:07,091 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 18:24:07,091 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 18:24:07,092 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 18:24:07,094 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 18:24:07,094 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 18:24:07,101 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 18:24:07,105 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 18:24:07,105 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 18:24:07,107 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 18:24:07,107 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 18:24:07,108 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 18:24:07,109 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 18:24:07,109 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 18:24:07,109 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 18:24:07,111 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 18:24:07,113 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 18:24:07,115 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 18:24:07,169 [lib.api.process] INFO: Monitor config for process 4584: C:\piknapjj\dll\4584.ini
2026-05-28 18:24:07,170 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:24:07,172 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:24:07,263 [root] DEBUG: Loader: Injecting process 4584 with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:07,443 [root] DEBUG: 4584: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:24:07,444 [root] DEBUG: 4584: Disabling sleep skipping.
2026-05-28 18:24:07,445 [root] DEBUG: 4584: Interactive desktop enabled.
2026-05-28 18:24:07,446 [root] DEBUG: 4584: Dropped file limit defaulting to 100.
2026-05-28 18:24:07,447 [root] DEBUG: 4584: Interactive desktop - injecting Explorer Shell
2026-05-28 18:24:07,452 [root] DEBUG: 4584: YaraInit: Compiled 44 rule files
2026-05-28 18:24:07,460 [root] DEBUG: 4584: YaraInit: Compiled rules saved to file C:\piknapjj\data\yara\capemon.yac
2026-05-28 18:24:07,492 [root] DEBUG: 4584: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:24:07,494 [root] DEBUG: 4584: YaraScan: Scanning 0x00007FF65E010000, size 0x545316
2026-05-28 18:24:07,572 [root] DEBUG: 4584: Monitor initialised: 64-bit capemon loaded in process 4584 at 0x00007FFC33960000, thread 3936, image base 0x00007FF65E010000, stack from 0x000000000F882000-0x000000000F890000
2026-05-28 18:24:07,574 [root] DEBUG: 4584: Commandline: C:\Windows\Explorer.EXE
2026-05-28 18:24:07,589 [root] DEBUG: 4584: Hooked 69 out of 69 functions
2026-05-28 18:24:07,622 [root] DEBUG: 4584: Syscall hook installed, syscall logging level 1
2026-05-28 18:24:07,634 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:24:07,635 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:07,637 [lib.api.process] INFO: Injected into 64-bit <Process 4584 explorer.exe>
2026-05-28 18:24:13,542 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC61000, size: 0x1000.
2026-05-28 18:24:13,555 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC51000, size: 0x1000.
2026-05-28 18:24:13,556 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC41000, size: 0x1000.
2026-05-28 18:24:13,637 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC31000, size: 0x1000.
2026-05-28 18:24:14,728 [root] DEBUG: 4584: caller_dispatch: Added region at 0x00007FF65E010000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF65E0B8FBA, thread 4636).
2026-05-28 18:24:14,732 [root] DEBUG: 4584: YaraScan: Scanning 0x00007FF65E010000, size 0x545316
2026-05-28 18:24:14,782 [root] DEBUG: 4584: YaraScan: Scanning 0x00007FF65E010000, size 0x545316
2026-05-28 18:24:14,783 [root] DEBUG: 4584: ProcessImageBase: Main module image at 0x00007FF65E010000 unmodified (entropy change 1.333794e-06)
2026-05-28 18:24:14,822 [root] DEBUG: 4584: ProcessImageBase: Main module image at 0x00007FF65E010000 unmodified (entropy change 3.734225e-05)
2026-05-28 18:24:14,836 [root] INFO: Restarting WMI Service
2026-05-28 18:24:15,625 [lib.api.process] INFO: Monitor config for process 740: C:\piknapjj\dll\740.ini
2026-05-28 18:24:15,634 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:24:15,636 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:24:15,643 [root] DEBUG: Loader: Injecting process 740 with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:15,645 [root] DEBUG: 740: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:24:15,646 [root] DEBUG: 740: Disabling sleep skipping.
2026-05-28 18:24:15,646 [root] DEBUG: 740: Interactive desktop enabled.
2026-05-28 18:24:15,646 [root] DEBUG: 740: Dropped file limit defaulting to 100.
2026-05-28 18:24:15,647 [root] DEBUG: 740: Services hook set enabled
2026-05-28 18:24:15,649 [root] DEBUG: 740: YaraInit: Compiled rules loaded from existing file C:\piknapjj\data\yara\capemon.yac
2026-05-28 18:24:15,662 [root] DEBUG: 740: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:24:15,663 [root] DEBUG: 740: Monitor initialised: 64-bit capemon loaded in process 740 at 0x00007FFC33960000, thread 3008, image base 0x00007FF780360000, stack from 0x000000754D075000-0x000000754D080000
2026-05-28 18:24:15,663 [root] DEBUG: 740: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 18:24:15,673 [root] DEBUG: 740: Hooked 69 out of 69 functions
2026-05-28 18:24:15,674 [root] INFO: Loaded monitor into process with pid 740
2026-05-28 18:24:15,676 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:24:15,676 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:15,678 [lib.api.process] INFO: Injected into 64-bit <Process 740 svchost.exe>
2026-05-28 18:24:16,897 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 18:24:16,897 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 18:24:16,898 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 18:24:16,916 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://sugarcraft.net/"" with pid 4708
2026-05-28 18:24:16,921 [lib.api.process] INFO: Monitor config for process 4708: C:\piknapjj\dll\4708.ini
2026-05-28 18:24:16,922 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:24:16,923 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:24:16,927 [root] DEBUG: Loader: Injecting process 4708 (thread 4924) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:16,929 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:24:16,930 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:16,931 [lib.api.process] INFO: Injected into 64-bit <Process 4708 msedge.exe>
2026-05-28 18:24:17,755 [root] DEBUG: 4584: CreateProcessHandler: Injection info set for new process 4796: C:\Windows\system32\taskmgr.exe, ImageBase: 0x00007FF737580000
2026-05-28 18:24:17,756 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 4796
2026-05-28 18:24:17,757 [lib.api.process] INFO: Monitor config for process 4796: C:\piknapjj\dll\4796.ini
2026-05-28 18:24:17,758 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:24:17,759 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:24:17,763 [root] DEBUG: Loader: Injecting process 4796 (thread 4816) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:17,763 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:24:17,764 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:17,765 [lib.api.process] INFO: Injected into 64-bit <Process 4796 Taskmgr.exe>
2026-05-28 18:24:17,767 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 4796
2026-05-28 18:24:17,767 [lib.api.process] INFO: Monitor config for process 4796: C:\piknapjj\dll\4796.ini
2026-05-28 18:24:17,767 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:24:17,769 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:24:17,773 [root] DEBUG: Loader: Injecting process 4796 (thread 4816) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:17,773 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:24:17,774 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:17,775 [lib.api.process] INFO: Injected into 64-bit <Process 4796 Taskmgr.exe>
2026-05-28 18:24:17,776 [root] DEBUG: 4584: DLL loaded at 0x00007FFC64EC0000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 18:24:17,777 [root] DEBUG: 4584: DLL loaded at 0x00007FFC66D50000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 18:24:17,777 [root] DEBUG: 4584: DLL loaded at 0x00007FFC630F0000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 18:24:17,782 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 4796
2026-05-28 18:24:17,783 [lib.api.process] INFO: Monitor config for process 4796: C:\piknapjj\dll\4796.ini
2026-05-28 18:24:17,783 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:24:17,785 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:24:17,789 [root] DEBUG: Loader: Injecting process 4796 with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:17,789 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 4816, handle 0x124
2026-05-28 18:24:17,789 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:24:17,790 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:17,791 [lib.api.process] INFO: Injected into 64-bit <Process 4796 Taskmgr.exe>
2026-05-28 18:24:17,864 [root] DEBUG: 4796: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:24:17,865 [root] DEBUG: 4796: Interactive desktop enabled.
2026-05-28 18:24:17,866 [root] DEBUG: 4796: Dropped file limit defaulting to 100.
2026-05-28 18:24:17,868 [root] DEBUG: 4796: Disabling sleep skipping.
2026-05-28 18:24:17,869 [root] DEBUG: 4796: YaraInit: Compiled rules loaded from existing file C:\piknapjj\data\yara\capemon.yac
2026-05-28 18:24:17,881 [root] DEBUG: 4796: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:24:17,881 [root] DEBUG: 4796: YaraScan: Scanning 0x00007FF737580000, size 0x12fcfe
2026-05-28 18:24:17,889 [root] DEBUG: 4796: Monitor initialised: 64-bit capemon loaded in process 4796 at 0x00007FFC33960000, thread 4816, image base 0x00007FF737580000, stack from 0x000000B0C00C4000-0x000000B0C00D0000
2026-05-28 18:24:17,889 [root] DEBUG: 4796: Commandline: "C:\Windows\system32\taskmgr.exe" /4
2026-05-28 18:24:17,898 [root] DEBUG: 4796: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 18:24:17,921 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:24:17,922 [root] DEBUG: 4796: set_hooks: Unable to hook LockResource
2026-05-28 18:24:17,928 [root] DEBUG: 4796: Hooked 627 out of 628 functions
2026-05-28 18:24:17,935 [root] DEBUG: 4796: Syscall hook installed, syscall logging level 1
2026-05-28 18:24:17,940 [root] DEBUG: 4796: RestoreHeaders: Restored original import table.
2026-05-28 18:24:17,941 [root] INFO: Loaded monitor into process with pid 4796
2026-05-28 18:24:17,944 [root] DEBUG: 4796: DLL loaded at 0x00007FFC75440000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 18:24:17,968 [root] DEBUG: 4796: caller_dispatch: Added region at 0x00007FF737580000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7375AFF02, thread 4816).
2026-05-28 18:24:17,969 [root] DEBUG: 4796: YaraScan: Scanning 0x00007FF737580000, size 0x12fcfe
2026-05-28 18:24:17,977 [root] DEBUG: 4796: ProcessImageBase: Main module image at 0x00007FF737580000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:24:17,986 [root] DEBUG: 4796: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:24:17,990 [root] DEBUG: 4796: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:24:17,996 [root] DEBUG: 4796: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:24:18,008 [root] DEBUG: 4796: DLL loaded at 0x00007FFC66930000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 18:24:18,023 [root] DEBUG: 4796: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:24:18,023 [root] DEBUG: 4796: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:24:18,024 [root] DEBUG: 4796: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:24:18,024 [root] DEBUG: 4796: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 18:24:18,025 [root] DEBUG: 4796: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 18:24:18,037 [root] DEBUG: 4796: DLL loaded at 0x00007FFC74740000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:24:18,038 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:24:18,056 [root] DEBUG: 4796: DLL loaded at 0x00007FFC68F00000: C:\Windows\System32\NetworkUXBroker (0x6d000 bytes).
2026-05-28 18:24:18,071 [root] DEBUG: 4796: DLL loaded at 0x00007FFC65620000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes).
2026-05-28 18:24:18,086 [root] DEBUG: 4796: DLL loaded at 0x00007FFC72B20000: C:\Windows\system32\WTSAPI32 (0x14000 bytes).
2026-05-28 18:24:18,089 [root] DEBUG: 4796: DLL loaded at 0x00007FFC75370000: C:\Windows\system32\WINSTA (0x5b000 bytes).
2026-05-28 18:24:18,092 [root] DEBUG: 4796: DLL loaded at 0x00007FFC711F0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 18:24:18,096 [root] DEBUG: 4796: DLL loaded at 0x00007FFC75020000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 18:24:18,097 [root] DEBUG: 4796: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:24:18,136 [root] DEBUG: 4796: DLL loaded at 0x00007FFC65120000: C:\Windows\system32\srumapi (0x14000 bytes).
2026-05-28 18:24:18,147 [root] DEBUG: 4796: DLL loaded at 0x00007FFC701E0000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 18:24:18,174 [root] DEBUG: 4796: DLL loaded at 0x00007FFC755E0000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 18:24:18,196 [root] DEBUG: 4796: DLL loaded at 0x00007FFC69BE0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 18:24:18,202 [root] DEBUG: 4796: DLL loaded at 0x00007FFC5F9A0000: C:\Windows\system32\OLEACC (0x66000 bytes).
2026-05-28 18:24:18,253 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6EDF0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 18:24:18,260 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6BB00000: C:\Windows\system32\samcli (0x19000 bytes).
2026-05-28 18:24:18,265 [root] DEBUG: 4796: api-rate-cap: NtReleaseMutant hook disabled due to rate
2026-05-28 18:24:18,266 [root] DEBUG: 4796: DLL loaded at 0x00007FFC72AF0000: C:\Windows\system32\SAMLIB (0x28000 bytes).
2026-05-28 18:24:18,266 [root] DEBUG: 4796: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 18:24:18,277 [root] DEBUG: 4796: DLL loaded at 0x00007FFC74B80000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 18:24:18,279 [root] DEBUG: 4796: DLL loaded at 0x00007FFC5F2A0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 18:24:18,281 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 92, handle 0x57c:
2026-05-28 18:24:18,283 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 428, handle 0x57c: C:\Windows\System32\csrss.exe
2026-05-28 18:24:18,296 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 512, handle 0x57c: C:\Windows\System32\csrss.exe
2026-05-28 18:24:18,299 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 600, handle 0x57c: C:\Windows\System32\winlogon.exe
2026-05-28 18:24:18,302 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 600 (handle 0x57c): 0x00007FF767B80000.
2026-05-28 18:24:18,315 [root] DEBUG: 4796: DLL loaded at 0x00007FFC728F0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 18:24:18,317 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 740, handle 0x57c: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,329 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 756, handle 0x64c: C:\Windows\System32\fontdrvhost.exe
2026-05-28 18:24:18,333 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 756 (handle 0x64c): 0x00007FF7EE860000.
2026-05-28 18:24:18,334 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 900, handle 0x650: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,337 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 900 (handle 0x650): 0x00007FF780360000.
2026-05-28 18:24:18,338 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 420, handle 0x650: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,342 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 420 (handle 0x650): 0x00007FF780360000.
2026-05-28 18:24:18,344 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 712, handle 0x650: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,354 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1064, handle 0x650: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,357 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1064 (handle 0x650): 0x00007FF780360000.
2026-05-28 18:24:18,358 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1144, handle 0x650: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,361 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1208, handle 0x650: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,371 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1208 (handle 0x650): 0x00007FF780360000.
2026-05-28 18:24:18,373 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1260, handle 0x650: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,380 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1260 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,383 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1432, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,386 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1432 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,387 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1520, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,389 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1520 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,390 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1620, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,393 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1620 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,405 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1720, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,408 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1720 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,410 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1748, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,412 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1748 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,427 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1844, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,430 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1844 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,431 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1892, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,434 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1892 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,436 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1976, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,438 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1976 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,439 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 348, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,447 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 348 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,448 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2100, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,451 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2100 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,452 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2276, handle 0x674: C:\Windows\System32\spoolsv.exe
2026-05-28 18:24:18,455 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2276 (handle 0x674): 0x00007FF7722E0000.
2026-05-28 18:24:18,456 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2348, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,461 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2348 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,461 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:24:18,462 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2512, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,462 [root] DEBUG: 4796: DLL loaded at 0x00007FFC63700000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:24:18,464 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2512 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,466 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2636, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,469 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2636 (handle 0x674): 0x00007FF780360000.
2026-05-28 18:24:18,470 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2792, handle 0x674: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,471 [root] DEBUG: 4796: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:24:18,472 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2792 (handle 0x6d0): 0x00007FF780360000.
2026-05-28 18:24:18,473 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2808, handle 0x6d0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,477 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2808 (handle 0x6d0): 0x00007FF780360000.
2026-05-28 18:24:18,481 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2996, handle 0x6d0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,484 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2996 (handle 0x6d0): 0x00007FF780360000.
2026-05-28 18:24:18,485 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3824, handle 0x6d0: C:\Windows\System32\SearchIndexer.exe
2026-05-28 18:24:18,489 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3824 (handle 0x6d8): 0x00007FF781A20000.
2026-05-28 18:24:18,490 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2344, handle 0x6d8: C:\Windows\System32\sihost.exe
2026-05-28 18:24:18,492 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2344 (handle 0x6d8): 0x00007FF6BC710000.
2026-05-28 18:24:18,492 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2464, handle 0x6d8: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,495 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2464 (handle 0x6d8): 0x00007FF780360000.
2026-05-28 18:24:18,496 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3752, handle 0x6d8: C:\Windows\System32\taskhostw.exe
2026-05-28 18:24:18,499 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3752 (handle 0x6d8): 0x00007FF77B4D0000.
2026-05-28 18:24:18,500 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 392, handle 0x6d8: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,502 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 392 (handle 0x6d8): 0x00007FF780360000.
2026-05-28 18:24:18,505 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4276, handle 0x6d8: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,509 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4484, handle 0x6d8: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,511 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4484 (handle 0x6d8): 0x00007FF780360000.
2026-05-28 18:24:18,512 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4728, handle 0x6d8: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,514 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4728 (handle 0x6d8): 0x00007FF780360000.
2026-05-28 18:24:18,514 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3060, handle 0x6d8: C:\Windows\System32\SearchProtocolHost.exe
2026-05-28 18:24:18,515 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3060 (handle 0x6d8): 0x00007FF716940000.
2026-05-28 18:24:18,516 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5152, handle 0x6d8: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2026-05-28 18:24:18,519 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6A640000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 18:24:18,520 [root] DEBUG: 4796: DLL loaded at 0x00007FFC741C0000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 18:24:18,521 [root] DEBUG: 4796: DLL loaded at 0x00007FFC741F0000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 18:24:18,521 [root] DEBUG: 4796: DLL loaded at 0x00007FFC75560000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 18:24:18,522 [root] DEBUG: 4796: DLL loaded at 0x00007FFC610F0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 18:24:18,600 [root] DEBUG: 4796: DLL loaded at 0x00007FFC72EF0000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 18:24:18,608 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6AB30000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 18:24:18,609 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6AC50000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 18:24:18,609 [root] DEBUG: 4796: DLL loaded at 0x00007FFC61260000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 18:24:18,631 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6A6A0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 18:24:18,640 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6A120000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 18:24:18,648 [root] DEBUG: 4796: DLL loaded at 0x00007FFC70130000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 18:24:18,648 [root] DEBUG: 4796: DLL loaded at 0x00007FFC69E70000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 18:24:18,649 [root] DEBUG: 4796: DLL loaded at 0x00007FFC69FD0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 18:24:18,653 [root] DEBUG: 4796: DLL loaded at 0x00007FFC69D20000: C:\Windows\SYSTEM32\languageoverlayutil (0x41000 bytes).
2026-05-28 18:24:18,656 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6A6C0000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 18:24:18,659 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6B370000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 18:24:18,675 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5152 (handle 0x77c): 0x00007FF70F680000.
2026-05-28 18:24:18,686 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5216, handle 0x78c: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe
2026-05-28 18:24:18,689 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5216 (handle 0x78c): 0x00007FF6B6CB0000.
2026-05-28 18:24:18,690 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5328, handle 0x78c: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,692 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5328 (handle 0x78c): 0x00007FF780360000.
2026-05-28 18:24:18,692 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5536, handle 0x78c: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
2026-05-28 18:24:18,710 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5536 (handle 0x798): 0x00007FF6EB870000.
2026-05-28 18:24:18,711 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5796, handle 0x7a0: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 18:24:18,716 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5796 (handle 0x7a0): 0x00007FF77B710000.
2026-05-28 18:24:18,717 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5956, handle 0x7a0: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 18:24:18,718 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5956 (handle 0x7a0): 0x00007FF77B710000.
2026-05-28 18:24:18,719 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3680, handle 0x7a0: C:\Windows\System32\SecurityHealthSystray.exe
2026-05-28 18:24:18,721 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3680 (handle 0x7a0): 0x00007FF661AB0000.
2026-05-28 18:24:18,722 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6084, handle 0x7a0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,724 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6084 (handle 0x7a0): 0x00007FF780360000.
2026-05-28 18:24:18,724 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4944, handle 0x7a0: C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2026-05-28 18:24:18,725 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4944 (handle 0x7a0): 0x0000000000320000.
2026-05-28 18:24:18,726 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5876, handle 0x7a0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,728 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5876 (handle 0x7a0): 0x00007FF780360000.
2026-05-28 18:24:18,729 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3552, handle 0x7a0: C:\Program Files (x86)\Steam\steam.exe
2026-05-28 18:24:18,729 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3552 (handle 0x7a0): 0x00007FF7CB360000.
2026-05-28 18:24:18,730 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6200, handle 0x7a0: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:24:18,733 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6200 (handle 0x7a8): 0x00007FF6B1860000.
2026-05-28 18:24:18,734 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6600, handle 0x7a8: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:24:18,737 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6600 (handle 0x7a8): 0x00007FF6B1860000.
2026-05-28 18:24:18,738 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3392, handle 0x7a8: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:24:18,739 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3392 (handle 0x7a8): 0x00007FF7D0050000.
2026-05-28 18:24:18,739 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6908, handle 0x7a8: C:\Program Files (x86)\Common Files\Steam\steamservice.exe
2026-05-28 18:24:18,740 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6908 (handle 0x7a8): 0x0000000000390000.
2026-05-28 18:24:18,741 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6448, handle 0x7a8: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:24:18,742 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6448 (handle 0x7a8): 0x00007FF7D0050000.
2026-05-28 18:24:18,742 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 7632, handle 0x7a8: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:24:18,743 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 7632 (handle 0x7a8): 0x00007FF7D0050000.
2026-05-28 18:24:18,744 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 7988, handle 0x7a8: C:\Windows\System32\svchost.exe
2026-05-28 18:24:18,746 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 7988 (handle 0x7a8): 0x00007FF780360000.
2026-05-28 18:24:18,748 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 708, handle 0x7a0: C:\Windows\System32\ApplicationFrameHost.exe
2026-05-28 18:24:18,749 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 708 (handle 0x7a0): 0x00007FF7EECE0000.
2026-05-28 18:24:18,750 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 7924, handle 0x7a0: C:\Windows\System32\notepad.exe
2026-05-28 18:24:18,752 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 7924 (handle 0x7a0): 0x00007FF7241A0000.
2026-05-28 18:24:18,753 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2900, handle 0x7a0: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
2026-05-28 18:24:18,765 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2900 (handle 0x79c): 0x00007FF616AA0000.
2026-05-28 18:24:18,768 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4708, handle 0x794: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:18,769 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4708 (handle 0x794): 0x00007FF734750000.
2026-05-28 18:24:18,814 [root] INFO: Added new file to list with pid 4796 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 18:24:18,855 [root] INFO: Added new file to list with pid 4796 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 18:24:18,949 [lib.api.process] INFO: Successfully resumed process with pid 4708
2026-05-28 18:24:19,000 [root] DEBUG: 4796: DLL loaded at 0x00007FFC74A70000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:24:19,006 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6E0E0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 18:24:19,006 [root] DEBUG: 4708: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:24:19,007 [root] DEBUG: 4708: Interactive desktop enabled.
2026-05-28 18:24:19,008 [root] DEBUG: 4708: Dropped file limit defaulting to 100.
2026-05-28 18:24:19,019 [root] DEBUG: 4708: Edge-specific hook-set enabled.
2026-05-28 18:24:19,021 [root] DEBUG: 4708: Disabling sleep skipping.
2026-05-28 18:24:19,024 [root] DEBUG: 4796: api-rate-cap: NtQueryValueKey hook disabled due to rate
2026-05-28 18:24:19,024 [root] DEBUG: 4708: YaraInit: Compiled rules loaded from existing file C:\piknapjj\data\yara\capemon.yac
2026-05-28 18:24:19,040 [root] DEBUG: 4708: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:24:19,040 [root] DEBUG: 4708: Monitor initialised: 64-bit capemon loaded in process 4708 at 0x00007FFC33960000, thread 4924, image base 0x00007FF734750000, stack from 0x0000007C9C7F4000-0x0000007C9C800000
2026-05-28 18:24:19,041 [root] DEBUG: 4708: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://sugarcraft.net/"
2026-05-28 18:24:19,053 [root] DEBUG: 4708: Hooked 2 out of 2 functions
2026-05-28 18:24:19,091 [root] DEBUG: 4708: Syscall hook installed, syscall logging level 1
2026-05-28 18:24:19,096 [root] DEBUG: 4708: RestoreHeaders: Restored original import table.
2026-05-28 18:24:19,097 [root] INFO: Loaded monitor into process with pid 4708
2026-05-28 18:24:19,099 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 18:24:19,103 [root] DEBUG: 4708: DLL loaded at 0x00007FFC63BA0000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 18:24:19,104 [root] DEBUG: 4708: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:24:19,107 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75020000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 18:24:19,108 [root] DEBUG: 4708: DLL loaded at 0x00007FFC73790000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:24:19,109 [root] DEBUG: 4708: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 18:24:19,110 [root] DEBUG: 4708: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:24:19,213 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5CA40000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 18:24:19,216 [root] DEBUG: 4708: DLL loaded at 0x00007FFC1EAA0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 18:24:19,222 [root] DEBUG: 4708: DLL loaded at 0x00007FFC620A0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 18:24:19,224 [root] DEBUG: 4708: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:24:19,229 [root] DEBUG: 4708: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:24:19,233 [root] DEBUG: 4708: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:24:19,234 [root] DEBUG: 4708: CreateProcessHandler: Injection info set for new process 8560: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:24:19,235 [root] DEBUG: 4708: DLL loaded at 0x00007FFC63BD0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 18:24:19,236 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 8560
2026-05-28 18:24:19,237 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:24:19,238 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 8560
2026-05-28 18:24:19,238 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:24:19,254 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75560000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 18:24:19,257 [root] DEBUG: 4708: DLL loaded at 0x00007FFC73F40000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 18:24:19,258 [root] DEBUG: 4708: DLL loaded at 0x00007FFC747D0000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 18:24:19,260 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74B80000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 18:24:19,261 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:24:19,265 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5FA20000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 18:24:19,267 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:24:19,268 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 18:24:19,268 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75090000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 18:24:19,269 [root] DEBUG: 4708: DLL loaded at 0x00007FFC77F00000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:24:19,269 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6DA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:24:19,270 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5B690000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 18:24:19,271 [root] DEBUG: 4708: DLL loaded at 0x00007FFC601B0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 18:24:19,271 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:24:19,272 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75050000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 18:24:19,274 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6C4D0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 18:24:19,275 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:24:19,276 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 18:24:19,276 [root] DEBUG: 4708: DLL loaded at 0x00007FFC72B70000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 18:24:19,282 [root] DEBUG: 4708: DLL loaded at 0x00007FFC755E0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 18:24:19,289 [root] DEBUG: 4708: DLL loaded at 0x00007FFC77400000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:24:19,291 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:24:19,291 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:24:19,294 [root] DEBUG: 4708: DLL loaded at 0x00007FFC601D0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 18:24:19,296 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6BCE0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 18:24:19,298 [root] DEBUG: 4708: DLL loaded at 0x00007FFC69960000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 18:24:19,304 [root] DEBUG: 4708: DLL loaded at 0x00007FFC61E00000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 18:24:19,305 [root] DEBUG: 4796: DLL loaded at 0x00007FFC73480000: C:\Windows\system32\dwmapi (0x2f000 bytes).
2026-05-28 18:24:19,306 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6F400000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 18:24:19,307 [root] DEBUG: 4796: DLL loaded at 0x0000026100F30000: C:\Windows\system32\d3d9 (0x1cd000 bytes).
2026-05-28 18:24:19,311 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75430000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 18:24:19,313 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74A70000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:24:19,314 [root] DEBUG: 4796: DLL loaded at 0x00007FFC731A0000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 18:24:19,314 [root] DEBUG: 4708: DLL loaded at 0x00007FFC70B80000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 18:24:19,315 [root] DEBUG: 4708: DLL loaded at 0x00007FFC771D0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 18:24:19,317 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6E0C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 18:24:19,319 [root] DEBUG: 4796: DLL loaded at 0x00007FFC1E8D0000: C:\Windows\system32\D3D12Core (0x1cd000 bytes).
2026-05-28 18:24:19,319 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:24:19,320 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75F50000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 18:24:19,322 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6BA50000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 18:24:19,323 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6E3B0000: C:\Windows\system32\d3d10warp (0x6f6000 bytes).
2026-05-28 18:24:19,325 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74AB0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 18:24:19,331 [root] DEBUG: 4708: DLL loaded at 0x00007FFC728F0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 18:24:19,331 [root] DEBUG: 4796: DLL loaded at 0x00007FFC5F430000: C:\Windows\system32\dxilconv (0x139000 bytes).
2026-05-28 18:24:19,333 [root] DEBUG: 4708: DLL loaded at 0x00007FFC729F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:24:19,333 [root] DEBUG: 4708: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:24:19,334 [root] DEBUG: 4708: DLL loaded at 0x00007FFC72590000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 18:24:19,335 [root] DEBUG: 4796: DLL loaded at 0x00007FFC5FAE0000: C:\Windows\system32\D3DSCache (0x2a000 bytes).
2026-05-28 18:24:19,335 [root] DEBUG: 4708: DLL loaded at 0x00007FFC69D70000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 18:24:19,337 [root] DEBUG: 4708: DLL loaded at 0x00007FFC665A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:24:19,339 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:24:19,347 [root] DEBUG: 4708: DLL loaded at 0x00007FFC60C70000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 18:24:19,350 [root] DEBUG: 4708: DLL loaded at 0x00007FFC664D0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 18:24:19,351 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6ED50000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 18:24:19,355 [root] DEBUG: 4708: DLL loaded at 0x00007FFC70130000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 18:24:19,358 [root] DEBUG: 4708: DLL loaded at 0x00007FFC69E70000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 18:24:19,358 [root] DEBUG: 4708: DLL loaded at 0x00007FFC69FD0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 18:24:19,368 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6E3B0000: C:\Windows\system32\d3d10warp (0x6f6000 bytes).
2026-05-28 18:24:19,371 [root] DEBUG: 4708: DLL loaded at 0x00007FFC65B50000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 18:24:19,376 [root] DEBUG: 4796: DLL loaded at 0x00007FFC753D0000: C:\Windows\system32\DEVOBJ (0x33000 bytes).
2026-05-28 18:24:19,383 [root] DEBUG: 4708: DLL loaded at 0x00007FFC72B20000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 18:24:19,385 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 336, handle 0x7fc: C:\Windows\System32\smss.exe
2026-05-28 18:24:19,385 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6E0C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 18:24:19,392 [root] DEBUG: 4708: DLL loaded at 0x00007FFC75370000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 18:24:19,395 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 18:24:19,395 [lib.api.process] INFO: Monitor config for process 592: C:\piknapjj\dll\592.ini
2026-05-28 18:24:19,396 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:24:19,399 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6FD90000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 18:24:19,400 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:24:19,403 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:24:19,404 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6FDB0000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 18:24:19,407 [root] DEBUG: 4708: DLL loaded at 0x00007FFC707B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 18:24:19,408 [root] DEBUG: 4796: DLL loaded at 0x00007FFC74AB0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 18:24:19,410 [root] DEBUG: Loader: Injecting process 592 with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:19,411 [root] DEBUG: Loader: Copied config file C:\piknapjj\dll\592.ini to system path C:\592.ini
2026-05-28 18:24:19,415 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 500, handle 0x7b0: C:\Windows\System32\wininit.exe
2026-05-28 18:24:19,423 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 592, handle 0x638: C:\Windows\System32\services.exe
2026-05-28 18:24:19,428 [root] DEBUG: 4708: DLL loaded at 0x00007FFC1E300000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 18:24:19,430 [root] DEBUG: 4796: DLL loaded at 0x00007FFC747D0000: C:\Windows\system32\wkscli (0x19000 bytes).
2026-05-28 18:24:19,433 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 640, handle 0x7b0: C:\Windows\System32\lsass.exe
2026-05-28 18:24:19,438 [root] DEBUG: 4708: DLL loaded at 0x00007FFC650F0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 18:24:19,441 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 592 C:\piknapjj\dll\OlNWZu.dll
2026-05-28 18:24:19,443 [root] DEBUG: 4708: DLL loaded at 0x00007FFC69BE0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 18:24:19,447 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 640 (handle 0xa70): 0x00007FF657A90000.
2026-05-28 18:24:19,501 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:24:19,504 [root] DEBUG: 4708: DLL loaded at 0x00007FFC68DC0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 18:24:19,505 [root] DEBUG: 4708: CreateProcessHandler: Injection info set for new process 9052: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:24:19,507 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 748, handle 0xa70: C:\Windows\System32\fontdrvhost.exe
2026-05-28 18:24:19,507 [lib.api.process] INFO: Injected into 64-bit <Process 592 services.exe>
2026-05-28 18:24:19,508 [root] DEBUG: 4708: caller_dispatch: Added region at 0x00007FF734750000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF734847D66, thread 8960).
2026-05-28 18:24:19,510 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6B370000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 18:24:19,511 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9052
2026-05-28 18:24:19,522 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 860, handle 0xa70: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,525 [root] DEBUG: 4708: DLL loaded at 0x00007FFC65020000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 18:24:19,525 [root] DEBUG: 4708: ProcessImageBase: Main module image at 0x00007FF734750000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:24:19,530 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9052
2026-05-28 18:24:19,530 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 860 (handle 0xa70): 0x00007FF780360000.
2026-05-28 18:24:19,532 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5E640000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 18:24:19,536 [root] DEBUG: 4708: CreateProcessHandler: Injection info set for new process 9268: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:24:19,537 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 984, handle 0xa70: C:\Windows\System32\dwm.exe
2026-05-28 18:24:19,542 [root] DEBUG: 4708: CreateProcessHandler: Injection info set for new process 9288: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:24:19,549 [root] DEBUG: 4708: DLL loaded at 0x00007FFC73F70000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 18:24:19,550 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9268
2026-05-28 18:24:19,550 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 984 (handle 0xa14): 0x00007FF6D4CD0000.
2026-05-28 18:24:19,551 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9288
2026-05-28 18:24:19,552 [root] DEBUG: 4708: DLL loaded at 0x00007FFC71690000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 18:24:19,552 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9268
2026-05-28 18:24:19,552 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 492, handle 0xa14: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,554 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9288
2026-05-28 18:24:19,554 [root] DEBUG: 4708: DLL loaded at 0x00007FFC72020000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 18:24:19,555 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 492 (handle 0xa14): 0x00007FF780360000.
2026-05-28 18:24:19,555 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5F830000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 18:24:19,556 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 560, handle 0xa14: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,558 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 560 (handle 0xa14): 0x00007FF780360000.
2026-05-28 18:24:19,560 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1072, handle 0xa14: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,562 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1072 (handle 0xa14): 0x00007FF780360000.
2026-05-28 18:24:19,563 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1172, handle 0xa14: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,659 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5F9A0000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 18:24:19,677 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1172 (handle 0xa14): 0x00007FF780360000.
2026-05-28 18:24:19,681 [root] DEBUG: 4708: CreateProcessHandler: Injection info set for new process 9476: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:24:19,683 [root] DEBUG: 4708: CreateProcessHandler: Injection info set for new process 9484: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:24:19,688 [root] DEBUG: 4708: DLL loaded at 0x00007FFC67700000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 18:24:19,690 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1224, handle 0xa14: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,690 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9476
2026-05-28 18:24:19,691 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9484
2026-05-28 18:24:19,694 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9484
2026-05-28 18:24:19,695 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 9476
2026-05-28 18:24:19,696 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1224 (handle 0xa14): 0x00007FF780360000.
2026-05-28 18:24:19,697 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1316, handle 0xa14: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,734 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1316 (handle 0xa14): 0x00007FF780360000.
2026-05-28 18:24:19,757 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5FA60000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 18:24:19,758 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1468, handle 0xa14: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,802 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1468 (handle 0xa14): 0x00007FF780360000.
2026-05-28 18:24:19,835 [root] DEBUG: 4708: DLL loaded at 0x00007FFC73480000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 18:24:19,841 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1604, handle 0xa14: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,941 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1604 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:19,942 [root] DEBUG: 4708: DLL loaded at 0x00007FFC1A380000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 18:24:19,943 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1688, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,945 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1688 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:19,946 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1732, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,946 [root] DEBUG: 4708: DLL loaded at 0x00007FFC751B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 18:24:19,949 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1732 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:19,949 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74F70000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 18:24:19,951 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1852, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,951 [root] DEBUG: 4708: DLL loaded at 0x00007FFC746B0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 18:24:19,954 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1852 (handle 0xa70): 0x00007FF780360000.
2026-05-28 18:24:19,955 [root] DEBUG: 4708: DLL loaded at 0x00007FFC63280000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 18:24:19,960 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1900, handle 0xa70: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,960 [root] DEBUG: 4708: DLL loaded at 0x00007FFC66790000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:24:19,963 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1900 (handle 0xa70): 0x00007FF780360000.
2026-05-28 18:24:19,964 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5E650000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 18:24:19,965 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1396, handle 0xa70: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,975 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1396 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:19,987 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1644, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:19,998 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1644 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:19,999 [root] DEBUG: 4708: DLL loaded at 0x00007FFC1A2F0000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 18:24:20,000 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2184, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,003 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2184 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,004 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2308, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,014 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2308 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,016 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2504, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,022 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2504 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,027 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2628, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,029 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2628 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,030 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2644, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,032 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2644 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,033 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2800, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,035 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2800 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,036 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2932, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,037 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2932 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,039 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3672, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,041 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3672 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,042 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 736, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,044 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 736 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,044 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3068, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,046 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3068 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,047 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2672, handle 0x7b0: C:\Windows\System32\taskhostw.exe
2026-05-28 18:24:20,049 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2672 (handle 0xa88): 0x00007FF77B4D0000.
2026-05-28 18:24:20,050 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3456, handle 0xa88: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,051 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3456 (handle 0xa88): 0x00007FF780360000.
2026-05-28 18:24:20,052 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4148, handle 0xa88: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,058 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4148 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,059 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4344, handle 0x7b0: C:\Windows\System32\ctfmon.exe
2026-05-28 18:24:20,063 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4344 (handle 0xa3c): 0x00007FF7DC490000.
2026-05-28 18:24:20,063 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4584, handle 0xa3c: C:\Windows\explorer.exe
2026-05-28 18:24:20,066 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4584 (handle 0xa30): 0x00007FF65E010000.
2026-05-28 18:24:20,067 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4836, handle 0xa30: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,069 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4836 (handle 0xa30): 0x00007FF780360000.
2026-05-28 18:24:20,069 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4128, handle 0xa30: C:\Windows\System32\dllhost.exe
2026-05-28 18:24:20,075 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4128 (handle 0xa14): 0x00007FF699DF0000.
2026-05-28 18:24:20,076 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5176, handle 0xa14: C:\Windows\servicing\TrustedInstaller.exe
2026-05-28 18:24:20,080 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5176 (handle 0xa88): 0x00007FF662190000.
2026-05-28 18:24:20,081 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5320, handle 0xa88: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 18:24:20,086 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5320 (handle 0xa88): 0x00007FF77B710000.
2026-05-28 18:24:20,089 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5416, handle 0xa3c: C:\Windows\System32\MoUsoCoreWorker.exe
2026-05-28 18:24:20,094 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5416 (handle 0xa8c): 0x00007FF68F1D0000.
2026-05-28 18:24:20,095 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5684, handle 0xa8c: C:\Windows\System32\SearchFilterHost.exe
2026-05-28 18:24:20,097 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5684 (handle 0xa94): 0x00007FF6EC310000.
2026-05-28 18:24:20,098 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3120, handle 0xa94: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,101 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3280, handle 0xa30: C:\Windows\System32\smartscreen.exe
2026-05-28 18:24:20,106 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3280 (handle 0xa14): 0x00007FF7AC790000.
2026-05-28 18:24:20,106 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3692, handle 0xa14: C:\Windows\System32\SecurityHealthService.exe
2026-05-28 18:24:20,110 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6040, handle 0xa88: C:\Windows\System32\conhost.exe
2026-05-28 18:24:20,113 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6040 (handle 0xa70): 0x00007FF799880000.
2026-05-28 18:24:20,114 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5920, handle 0xa70: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,117 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5920 (handle 0xa70): 0x00007FF780360000.
2026-05-28 18:24:20,118 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3484, handle 0xa70: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:24:20,120 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3484 (handle 0xa70): 0x00007FF6B1860000.
2026-05-28 18:24:20,121 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3344, handle 0xa70: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:24:20,122 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3344 (handle 0xa70): 0x00007FF6B1860000.
2026-05-28 18:24:20,123 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6236, handle 0xa70: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:24:20,124 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6236 (handle 0xa70): 0x00007FF6B1860000.
2026-05-28 18:24:20,125 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6772, handle 0xa70: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 18:24:20,126 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6772 (handle 0x7b0): 0x00007FF6B1860000.
2026-05-28 18:24:20,129 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6580, handle 0x7b0: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:24:20,130 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6580 (handle 0x7b0): 0x00007FF7D0050000.
2026-05-28 18:24:20,133 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 7052, handle 0x7b0: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:24:20,134 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 7052 (handle 0x7b0): 0x00007FF7D0050000.
2026-05-28 18:24:20,135 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6320, handle 0x7b0: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:24:20,136 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6320 (handle 0x7b0): 0x00007FF7D0050000.
2026-05-28 18:24:20,137 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 7956, handle 0x7b0: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,138 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 7956 (handle 0x7b0): 0x00007FF780360000.
2026-05-28 18:24:20,139 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4576, handle 0x7b0: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:24:20,140 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4576 (handle 0x7b0): 0x00007FF7D0050000.
2026-05-28 18:24:20,141 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 1092, handle 0x7b0: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe
2026-05-28 18:24:20,156 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6E250000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 18:24:20,171 [root] DEBUG: 4796: DLL loaded at 0x00007FFC6E250000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 18:24:20,182 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 1092 (handle 0xa40): 0x00007FF7C48B0000.
2026-05-28 18:24:20,183 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4020, handle 0xa94: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 18:24:20,188 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4020 (handle 0xa94): 0x00007FF77B710000.
2026-05-28 18:24:20,193 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6560, handle 0xa40: C:\Windows\System32\svchost.exe
2026-05-28 18:24:20,195 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 6560 (handle 0xa40): 0x00007FF780360000.
2026-05-28 18:24:20,198 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 8560, handle 0xa9c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:20,199 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 8560 (handle 0xa9c): 0x00007FF734750000.
2026-05-28 18:24:20,329 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9136, handle 0xa30: C:\piknapjj\bin\PPLinject64.exe
2026-05-28 18:24:20,338 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9136 (handle 0xa40): 0x00007FF6638D0000.
2026-05-28 18:24:20,339 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9152, handle 0xa40: C:\Windows\System32\conhost.exe
2026-05-28 18:24:20,342 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9152 (handle 0xa40): 0x00007FF799880000.
2026-05-28 18:24:20,343 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9052, handle 0xa40: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:20,345 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9052 (handle 0xa40): 0x00007FF734750000.
2026-05-28 18:24:20,348 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9268, handle 0xa40: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:20,350 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9268 (handle 0xa40): 0x00007FF734750000.
2026-05-28 18:24:20,352 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9288, handle 0xa40: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:20,354 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9288 (handle 0xa40): 0x00007FF734750000.
2026-05-28 18:24:20,355 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9476, handle 0xa40: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:20,357 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9476 (handle 0xa40): 0x00007FF734750000.
2026-05-28 18:24:20,358 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9484, handle 0xa40: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:20,359 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9484 (handle 0xa40): 0x00007FF734750000.
2026-05-28 18:24:21,239 [root] DEBUG: 4708: DLL loaded at 0x00007FFC74740000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:24:21,240 [root] DEBUG: 4708: DLL loaded at 0x00007FFC6FCE0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:24:22,571 [root] DEBUG: 4708: DLL loaded at 0x00007FFC754B0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 18:24:22,578 [root] DEBUG: 4708: DLL loaded at 0x00007FFC70650000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:24:22,578 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5D4D0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 18:24:22,688 [root] DEBUG: 4796: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 18:24:22,689 [root] DEBUG: 4796: DLL loaded at 0x00007FFC674F0000: C:\Windows\system32\CHARTV (0x25000 bytes).
2026-05-28 18:24:23,709 [root] DEBUG: 4708: DLL loaded at 0x00007FFC5CAE0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 18:24:36,122 [root] DEBUG: 4708: CreateProcessHandler: Injection info set for new process 10492: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:24:36,126 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 10492
2026-05-28 18:24:36,127 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 10492
2026-05-28 18:24:37,230 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10492, handle 0xab4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:38,023 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10492 (handle 0xab4): 0x00007FF734750000.
2026-05-28 18:24:40,228 [root] DEBUG: 4708: DLL loaded at 0x00007FFC73380000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:24:40,232 [root] DEBUG: 4708: DLL loaded at 0x00007FFC711F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:24:40,234 [root] DEBUG: 4708: DLL loaded at 0x00007FFC60E20000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:24:40,585 [root] DEBUG: 4708: CreateProcessHandler: Injection info set for new process 10640: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF734750000
2026-05-28 18:24:40,586 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 10640
2026-05-28 18:24:40,587 [root] DEBUG: 4708: ProcessMessage: Skipping monitoring process 10640
2026-05-28 18:24:40,877 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 18:24:41,059 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10640, handle 0xac4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:41,062 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10640 (handle 0xac4): 0x00007FF734750000.
2026-05-28 18:24:41,063 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10680, handle 0xac4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:41,064 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10680 (handle 0xac4): 0x00007FF734750000.
2026-05-28 18:24:41,065 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10912, handle 0xac4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:41,067 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10912 (handle 0xac4): 0x00007FF734750000.
2026-05-28 18:24:41,068 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10920, handle 0xac4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:41,069 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10920 (handle 0xac4): 0x00007FF734750000.
2026-05-28 18:24:41,070 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10928, handle 0xac4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:41,072 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10928 (handle 0xac4): 0x00007FF734750000.
2026-05-28 18:24:41,434 [root] INFO: Process with pid 4708 appears to have terminated
2026-05-28 18:24:42,056 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 11236, handle 0xac4: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 18:24:42,061 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 11236 (handle 0xac8): 0x00007FF6DDDD0000.
2026-05-28 18:24:47,088 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5468, handle 0xab4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:47,090 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5468 (handle 0xab4): 0x00007FF734750000.
2026-05-28 18:24:47,091 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 7764, handle 0xab4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:47,092 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 7764 (handle 0xab4): 0x00007FF734750000.
2026-05-28 18:24:47,559 [root] INFO: Announced starting service "b'lfsvc'"
2026-05-28 18:24:48,087 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4956, handle 0xac0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:24:48,089 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4956 (handle 0xac0): 0x00007FF734750000.
2026-05-28 18:24:49,088 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3584, handle 0xabc: C:\Windows\System32\svchost.exe
2026-05-28 18:24:49,091 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3584 (handle 0xabc): 0x00007FF780360000.
2026-05-28 18:25:14,220 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 9552: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF699DF0000
2026-05-28 18:25:14,223 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9552
2026-05-28 18:25:14,224 [lib.api.process] INFO: Monitor config for process 9552: C:\piknapjj\dll\9552.ini
2026-05-28 18:25:14,226 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:25:14,228 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:25:14,270 [root] DEBUG: Loader: Injecting process 9552 (thread 9556) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,271 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 9532: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF6209B0000
2026-05-28 18:25:14,272 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:25:14,273 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 9532
2026-05-28 18:25:14,273 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,273 [lib.api.process] INFO: Monitor config for process 9532: C:\piknapjj\dll\9532.ini
2026-05-28 18:25:14,275 [lib.api.process] INFO: Injected into 64-bit <Process 9552 dllhost.exe>
2026-05-28 18:25:14,275 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:25:14,278 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9552
2026-05-28 18:25:14,278 [lib.api.process] INFO: Monitor config for process 9552: C:\piknapjj\dll\9552.ini
2026-05-28 18:25:14,279 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:25:14,281 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:25:14,287 [root] DEBUG: Loader: Injecting process 9552 (thread 9556) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,288 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:25:14,292 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,298 [lib.api.process] INFO: Injected into 64-bit <Process 9552 dllhost.exe>
2026-05-28 18:25:14,307 [root] DEBUG: 9552: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:25:14,309 [root] DEBUG: 9552: Interactive desktop enabled.
2026-05-28 18:25:14,310 [root] DEBUG: 9552: Dropped file limit defaulting to 100.
2026-05-28 18:25:14,313 [root] DEBUG: 9552: Disabling sleep skipping.
2026-05-28 18:25:14,315 [root] DEBUG: 9552: YaraInit: Compiled rules loaded from existing file C:\piknapjj\data\yara\capemon.yac
2026-05-28 18:25:14,346 [root] DEBUG: 9552: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:25:14,356 [root] DEBUG: 9552: YaraScan: Scanning 0x00007FF699DF0000, size 0x8026
2026-05-28 18:25:14,357 [root] DEBUG: 9552: Monitor initialised: 64-bit capemon loaded in process 9552 at 0x00007FFC33960000, thread 9556, image base 0x00007FF699DF0000, stack from 0x0000008BCF2F4000-0x0000008BCF300000
2026-05-28 18:25:14,358 [root] DEBUG: 9552: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 18:25:14,369 [root] DEBUG: 9552: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 18:25:14,391 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:25:14,392 [root] DEBUG: 9552: set_hooks: Unable to hook LockResource
2026-05-28 18:25:14,399 [root] DEBUG: 9552: Hooked 627 out of 628 functions
2026-05-28 18:25:14,401 [root] DEBUG: 9552: Syscall hook installed, syscall logging level 1
2026-05-28 18:25:14,406 [root] DEBUG: 9552: RestoreHeaders: Restored original import table.
2026-05-28 18:25:14,407 [root] INFO: Loaded monitor into process with pid 9552
2026-05-28 18:25:14,409 [root] DEBUG: 9552: caller_dispatch: Added region at 0x00007FF699DF0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF699DF1349, thread 9556).
2026-05-28 18:25:14,414 [root] DEBUG: 9552: YaraScan: Scanning 0x00007FF699DF0000, size 0x8026
2026-05-28 18:25:14,416 [root] DEBUG: 9552: ProcessImageBase: Main module image at 0x00007FF699DF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:25:14,418 [root] DEBUG: 9552: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:25:14,420 [root] DEBUG: 9552: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:25:14,423 [root] DEBUG: 9552: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:25:14,439 [root] DEBUG: 9552: DLL loaded at 0x00007FFC730A0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:25:14,462 [root] DEBUG: 9552: DLL loaded at 0x00007FFC74BA0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 18:25:14,464 [root] DEBUG: 9552: DLL loaded at 0x00007FFC74B80000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 18:25:14,465 [root] DEBUG: 9552: DLL loaded at 0x00007FFC6E0A0000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:25:14,467 [root] DEBUG: 9552: DLL loaded at 0x00007FFC707B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 18:25:14,468 [root] DEBUG: 9552: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:25:14,469 [root] DEBUG: 9552: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:25:14,471 [root] DEBUG: 9552: DLL loaded at 0x00007FFC74A70000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:25:14,476 [root] DEBUG: 9552: DLL loaded at 0x00007FFC75560000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 18:25:14,477 [root] DEBUG: 9552: DLL loaded at 0x00007FFC755E0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 18:25:14,478 [root] DEBUG: 9552: DLL loaded at 0x00007FFC711F0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 18:25:14,480 [root] DEBUG: 9552: DLL loaded at 0x00007FFC74AB0000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 18:25:14,481 [root] DEBUG: 9552: DLL loaded at 0x00007FFC19800000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 18:25:14,483 [root] DEBUG: 9552: DLL loaded at 0x00007FFC771D0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 18:25:14,491 [root] DEBUG: 9552: DLL loaded at 0x00007FFC66790000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:25:14,792 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:25:14,797 [root] DEBUG: Loader: Injecting process 9532 (thread 8956) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,798 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:25:14,799 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,800 [lib.api.process] INFO: Injected into 64-bit <Process 9532 WmiPrvSE.exe>
2026-05-28 18:25:14,802 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 9532
2026-05-28 18:25:14,802 [lib.api.process] INFO: Monitor config for process 9532: C:\piknapjj\dll\9532.ini
2026-05-28 18:25:14,803 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:25:14,886 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:25:14,891 [root] DEBUG: Loader: Injecting process 9532 (thread 8956) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,892 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:25:14,893 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,894 [lib.api.process] INFO: Injected into 64-bit <Process 9532 WmiPrvSE.exe>
2026-05-28 18:25:14,904 [root] DEBUG: 9532: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:25:14,905 [root] DEBUG: 9532: Interactive desktop enabled.
2026-05-28 18:25:14,905 [root] DEBUG: 9532: Dropped file limit defaulting to 100.
2026-05-28 18:25:14,907 [root] DEBUG: 9532: Disabling sleep skipping.
2026-05-28 18:25:14,907 [root] DEBUG: 9532: Services hook set enabled
2026-05-28 18:25:14,909 [root] DEBUG: 9532: YaraInit: Compiled rules loaded from existing file C:\piknapjj\data\yara\capemon.yac
2026-05-28 18:25:14,924 [root] DEBUG: 9532: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:25:14,925 [root] DEBUG: 9532: Monitor initialised: 64-bit capemon loaded in process 9532 at 0x00007FFC33960000, thread 8956, image base 0x00007FF6209B0000, stack from 0x0000003F0ADC0000-0x0000003F0ADD0000
2026-05-28 18:25:14,926 [root] DEBUG: 9532: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 18:25:14,937 [root] DEBUG: 9532: Hooked 69 out of 69 functions
2026-05-28 18:25:14,940 [root] DEBUG: 9532: RestoreHeaders: Restored original import table.
2026-05-28 18:25:14,944 [root] INFO: Loaded monitor into process with pid 9532
2026-05-28 18:25:14,946 [root] DEBUG: 9532: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:25:14,947 [root] DEBUG: 9532: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:25:14,949 [root] DEBUG: 9532: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:25:14,951 [lib.api.process] INFO: Monitor config for process 6560: C:\piknapjj\dll\6560.ini
2026-05-28 18:25:14,953 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:25:14,954 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:25:14,961 [root] DEBUG: Loader: Injecting process 6560 with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,963 [root] DEBUG: 6560: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:25:14,964 [root] DEBUG: 6560: Disabling sleep skipping.
2026-05-28 18:25:14,964 [root] DEBUG: 6560: Interactive desktop enabled.
2026-05-28 18:25:14,965 [root] DEBUG: 6560: Dropped file limit defaulting to 100.
2026-05-28 18:25:14,966 [root] DEBUG: 6560: Services hook set enabled
2026-05-28 18:25:14,968 [root] DEBUG: 6560: YaraInit: Compiled rules loaded from existing file C:\piknapjj\data\yara\capemon.yac
2026-05-28 18:25:14,980 [root] DEBUG: 6560: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:25:14,981 [root] DEBUG: 6560: Monitor initialised: 64-bit capemon loaded in process 6560 at 0x00007FFC33960000, thread 10304, image base 0x00007FF780360000, stack from 0x0000009CC26F4000-0x0000009CC2700000
2026-05-28 18:25:14,982 [root] DEBUG: 6560: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 18:25:14,994 [root] DEBUG: 6560: Hooked 69 out of 69 functions
2026-05-28 18:25:14,996 [root] INFO: Loaded monitor into process with pid 6560
2026-05-28 18:25:14,997 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:25:14,997 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:25:14,999 [lib.api.process] INFO: Injected into 64-bit <Process 6560 svchost.exe>
2026-05-28 18:25:15,166 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10556, handle 0x6f8: C:\Windows\System32\svchost.exe
2026-05-28 18:25:15,169 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9552, handle 0x6f8: C:\Windows\System32\dllhost.exe
2026-05-28 18:25:15,170 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9552 (handle 0x6f8): 0x00007FF699DF0000.
2026-05-28 18:25:15,171 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9532, handle 0x6f8: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-28 18:25:15,174 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9532 (handle 0xad0): 0x00007FF6209B0000.
2026-05-28 18:25:15,175 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9896, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 18:25:15,178 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9896 (handle 0xad0): 0x00007FF780360000.
2026-05-28 18:25:15,179 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 11256, handle 0xad0: C:\Windows\System32\SgrmBroker.exe
2026-05-28 18:25:15,183 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2416, handle 0x6bc: C:\Windows\System32\sppsvc.exe
2026-05-28 18:25:16,166 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10592, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 18:25:16,169 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10592 (handle 0xad0): 0x00007FF780360000.
2026-05-28 18:25:16,170 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10788, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 18:25:16,172 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9596, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 18:25:16,174 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9596 (handle 0xad0): 0x00007FF780360000.
2026-05-28 18:25:17,004 [root] DEBUG: 9532: DLL loaded at 0x00007FFC61080000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 18:25:17,010 [root] DEBUG: 9532: DLL loaded at 0x00007FFC63BB0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 18:25:17,017 [root] DEBUG: 9532: DLL loaded at 0x00007FFC6CC40000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 18:25:17,025 [root] DEBUG: 9532: DLL loaded at 0x00007FFC75460000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:25:17,026 [root] DEBUG: 9532: DLL loaded at 0x00007FFC18AB0000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 18:25:17,026 [root] DEBUG: 9532: DLL loaded at 0x00007FFC18B10000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 18:25:17,027 [root] DEBUG: 9532: DLL loaded at 0x00007FFC75440000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:25:17,038 [root] DEBUG: 9532: DLL loaded at 0x0000016EC1330000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 18:25:17,039 [root] DEBUG: 9532: DLL loaded at 0x00007FFC6F2C0000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 18:25:17,040 [root] DEBUG: 9532: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 18:25:19,509 [root] INFO: Process with pid 9552 has terminated
2026-05-28 18:25:19,522 [root] DEBUG: 9552: NtTerminateProcess hook: Attempting to dump process 9552
2026-05-28 18:25:19,556 [root] DEBUG: 9552: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:25:21,366 [root] DEBUG: 4584: DLL loaded at 0x00007FFC1A350000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 18:25:21,402 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6A330000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 18:25:21,437 [root] DEBUG: 4584: DLL loaded at 0x00007FFC50D30000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 18:25:21,454 [root] DEBUG: 4584: DLL loaded at 0x00007FFC6D900000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 18:25:21,491 [root] DEBUG: 4584: DLL loaded at 0x00007FFC18AB0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 18:25:21,567 [root] DEBUG: 4584: DLL loaded at 0x00007FFC732A0000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 18:25:21,598 [root] DEBUG: 4584: DLL loaded at 0x00007FFC1A270000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 18:25:21,615 [root] DEBUG: 4584: DLL loaded at 0x00007FFC1A250000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 18:25:21,674 [root] DEBUG: 4584: DLL loaded at 0x00007FFC1A160000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 18:25:39,191 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10308, handle 0x314: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 18:25:39,203 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10308 (handle 0x314): 0x00007FF7D0050000.
2026-05-28 18:26:14,205 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 10540, handle 0xabc: C:\Windows\System32\taskhostw.exe
2026-05-28 18:26:14,238 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 10540 (handle 0xabc): 0x00007FF77B4D0000.
2026-05-28 18:26:32,177 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2140, handle 0xa48: C:\Windows\System32\sppsvc.exe
2026-05-28 18:26:41,186 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 3096, handle 0x888: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:26:41,204 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 3096 (handle 0x888): 0x00007FF734750000.
2026-05-28 18:26:45,557 [root] DEBUG: 9532: NtTerminateProcess hook: Attempting to dump process 9532
2026-05-28 18:26:45,612 [root] DEBUG: 9532: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:26:45,643 [root] INFO: Process with pid 9532 has terminated
2026-05-28 18:27:15,741 [root] DEBUG: 4584: DLL loaded at 0x00007FFC72E00000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 18:27:15,951 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 5640: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF751250000
2026-05-28 18:27:16,027 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 5640
2026-05-28 18:27:16,041 [lib.api.process] INFO: Monitor config for process 5640: C:\piknapjj\dll\5640.ini
2026-05-28 18:27:16,108 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:27:16,126 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:16,274 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5640, handle 0x7b0: C:\Windows\System32\SecurityHealthHost.exe
2026-05-28 18:27:16,328 [root] DEBUG: Loader: Injecting process 5640 (thread 5292) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:16,383 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5376, handle 0x7b0: C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:16,464 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:27:16,540 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5376 (handle 0x88c): 0x00007FF7F3980000.
2026-05-28 18:27:16,607 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:16,806 [lib.api.process] INFO: Injected into 64-bit <Process 5640 SecurityHealthHost.exe>
2026-05-28 18:27:16,915 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 5640
2026-05-28 18:27:16,939 [lib.api.process] INFO: Monitor config for process 5640: C:\piknapjj\dll\5640.ini
2026-05-28 18:27:16,973 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:27:17,026 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:17,206 [root] DEBUG: Loader: Injecting process 5640 (thread 5292) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:17,208 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 9460, handle 0xac0: C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:17,244 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:27:17,265 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 9460 (handle 0xab4): 0x00007FF7F3980000.
2026-05-28 18:27:17,266 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:17,341 [lib.api.process] INFO: Injected into 64-bit <Process 5640 SecurityHealthHost.exe>
2026-05-28 18:27:17,464 [root] DEBUG: 5640: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:27:17,602 [root] DEBUG: 5640: Interactive desktop enabled.
2026-05-28 18:27:17,649 [root] DEBUG: 5640: Dropped file limit defaulting to 100.
2026-05-28 18:27:17,759 [root] DEBUG: 5640: Disabling sleep skipping.
2026-05-28 18:27:17,808 [root] DEBUG: 5640: YaraInit: Compiled rules loaded from existing file C:\piknapjj\data\yara\capemon.yac
2026-05-28 18:27:17,937 [root] DEBUG: 5640: RtlInsertInvertedFunctionTable 0x00007FFC77FE090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC7813D4F0
2026-05-28 18:27:18,047 [root] DEBUG: 5640: YaraScan: Scanning 0x00007FF751250000, size 0x19174
2026-05-28 18:27:18,115 [root] DEBUG: 5640: Monitor initialised: 64-bit capemon loaded in process 5640 at 0x00007FFC33960000, thread 5292, image base 0x00007FF751250000, stack from 0x000000B92CD34000-0x000000B92CD40000
2026-05-28 18:27:18,189 [root] DEBUG: 5640: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-28 18:27:18,193 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5640 (handle 0xab4): 0x00007FF751250000.
2026-05-28 18:27:18,335 [root] DEBUG: 5640: hook_api: LdrpCallInitRoutine export address 0x00007FFC77FE99BC obtained via GetFunctionAddress
2026-05-28 18:27:18,384 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:27:18,420 [root] DEBUG: 5640: set_hooks: Unable to hook LockResource
2026-05-28 18:27:18,470 [root] DEBUG: 5640: Hooked 627 out of 628 functions
2026-05-28 18:27:18,503 [root] DEBUG: 5640: Syscall hook installed, syscall logging level 1
2026-05-28 18:27:18,545 [root] DEBUG: 5640: RestoreHeaders: Restored original import table.
2026-05-28 18:27:18,588 [root] INFO: Loaded monitor into process with pid 5640
2026-05-28 18:27:18,700 [root] DEBUG: 5640: caller_dispatch: Added region at 0x00007FF751250000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF75125D3B2, thread 5292).
2026-05-28 18:27:18,796 [root] DEBUG: 5640: YaraScan: Scanning 0x00007FF751250000, size 0x19174
2026-05-28 18:27:18,848 [root] DEBUG: 5640: ProcessImageBase: Main module image at 0x00007FF751250000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:27:18,909 [root] DEBUG: 5640: DLL loaded at 0x00007FFC734B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:27:18,977 [root] DEBUG: 5640: DLL loaded at 0x00007FFC75FA0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:27:19,076 [root] DEBUG: 5640: DLL loaded at 0x00007FFC765F0000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:27:19,212 [root] DEBUG: 5640: DLL loaded at 0x00007FFC75020000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 18:27:19,289 [root] DEBUG: 5640: DLL loaded at 0x00007FFC747F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:27:19,371 [root] DEBUG: 5640: DLL loaded at 0x00007FFC5C110000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-28 18:27:19,498 [root] DEBUG: 5640: DLL loaded at 0x00007FFC72E00000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 18:27:19,651 [root] DEBUG: 5640: DLL loaded at 0x00007FFC70910000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 18:27:19,703 [root] DEBUG: 5640: DLL loaded at 0x00007FFC775B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:27:19,799 [root] DEBUG: 5640: DLL loaded at 0x00007FFC71EC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:27:19,864 [root] DEBUG: 5640: DLL loaded at 0x00007FFC73380000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:27:19,980 [root] DEBUG: 5640: DLL loaded at 0x00007FFC711F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:27:20,055 [root] DEBUG: 5640: DLL loaded at 0x00007FFC6FF20000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:27:20,182 [root] DEBUG: 5640: DLL loaded at 0x00007FFC60E20000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:27:20,249 [root] DEBUG: 5640: DLL loaded at 0x00007FFC70650000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:27:20,313 [root] DEBUG: 5640: DLL loaded at 0x00007FFC6F400000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 18:27:20,473 [root] DEBUG: 5640: DLL loaded at 0x00007FFC5CAE0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 18:27:20,673 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC21000, size: 0x1000.
2026-05-28 18:27:20,772 [root] DEBUG: 4584: AllocationHandler: Adding allocation to tracked region list: 0x00007DF47AC11000, size: 0x1000.
2026-05-28 18:27:20,917 [root] DEBUG: 4584: AllocationHandler: Allocation already in tracked region list: 0x00007DF47AC20000.
2026-05-28 18:27:21,029 [root] DEBUG: 5640: NtTerminateProcess hook: Attempting to dump process 5640
2026-05-28 18:27:21,152 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 4240: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF6F75A0000
2026-05-28 18:27:21,209 [root] DEBUG: 5640: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:27:21,268 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 4240
2026-05-28 18:27:21,279 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4240, handle 0xac0: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
2026-05-28 18:27:21,280 [lib.api.process] INFO: Monitor config for process 4240: C:\piknapjj\dll\4240.ini
2026-05-28 18:27:21,340 [root] INFO: Process with pid 5640 has terminated
2026-05-28 18:27:21,440 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:27:21,664 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:21,895 [root] DEBUG: Loader: Injecting process 4240 (thread 5180) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:21,996 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:27:22,081 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:22,301 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 6104, handle 0xa94: C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:22,353 [lib.api.process] INFO: Injected into 64-bit <Process 4240 ShellExperienceHost.exe>
2026-05-28 18:27:22,493 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 4240
2026-05-28 18:27:22,571 [lib.api.process] INFO: Monitor config for process 4240: C:\piknapjj\dll\4240.ini
2026-05-28 18:27:22,637 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:27:22,870 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:23,074 [root] DEBUG: Loader: Injecting process 4240 (thread 5180) with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:23,146 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:27:23,292 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 4156, handle 0xa94: C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:23,392 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:23,496 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 4156 (handle 0xac4): 0x00007FF7F3980000.
2026-05-28 18:27:23,668 [lib.api.process] INFO: Injected into 64-bit <Process 4240 ShellExperienceHost.exe>
2026-05-28 18:27:23,782 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 4240
2026-05-28 18:27:23,848 [lib.api.process] INFO: Monitor config for process 4240: C:\piknapjj\dll\4240.ini
2026-05-28 18:27:23,910 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:27:24,133 [lib.api.process] INFO: 64-bit DLL to inject is C:\piknapjj\dll\OlNWZu.dll, loader C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:24,304 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 2164, handle 0xac8: C:\piknapjj\bin\mutnqHVT.exe
2026-05-28 18:27:24,356 [root] DEBUG: Loader: Injecting process 4240 with C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:24,476 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 2164 (handle 0x6f8): 0x00007FF7F3980000.
2026-05-28 18:27:24,542 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 5180, handle 0x120
2026-05-28 18:27:24,679 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:27:24,778 [root] DEBUG: Successfully injected DLL C:\piknapjj\dll\OlNWZu.dll.
2026-05-28 18:27:25,040 [lib.api.process] INFO: Injected into 64-bit <Process 4240 ShellExperienceHost.exe>
2026-05-28 18:27:26,313 [root] DEBUG: 4796: OpenProcessHandler: Injection info created for process 5244, handle 0x6f8: C:\Windows\System32\rundll32.exe
2026-05-28 18:27:26,440 [root] DEBUG: 4796: OpenProcessHandler: Image base for process 5244 (handle 0xac8): 0x00007FF610E90000.
2026-05-28 18:27:39,442 [root] INFO: Analysis timeout hit, terminating analysis
2026-05-28 18:27:39,552 [lib.api.process] INFO: Terminate event set for process 740
2026-05-28 18:27:39,630 [root] DEBUG: 740: Terminate Event: Attempting to dump process 740
2026-05-28 18:27:39,792 [root] DEBUG: 740: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:27:39,849 [lib.api.process] INFO: Termination confirmed for process 740
2026-05-28 18:27:39,904 [root] DEBUG: 740: Terminate Event: monitor shutdown complete for process 740
2026-05-28 18:27:39,913 [root] INFO: Terminate event set for process 740
2026-05-28 18:27:39,997 [lib.api.process] INFO: Terminate event set for process 4796
2026-05-28 18:27:40,030 [root] DEBUG: 4796: Terminate Event: Attempting to dump process 4796
2026-05-28 18:27:40,176 [root] DEBUG: 4796: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:27:40,831 [lib.api.process] INFO: Termination confirmed for process 4796
2026-05-28 18:27:40,925 [root] INFO: Terminate event set for process 4796
2026-05-28 18:27:40,941 [root] DEBUG: 4796: Terminate Event: monitor shutdown complete for process 4796
2026-05-28 18:27:41,049 [lib.api.process] INFO: Terminate event set for process 6560
2026-05-28 18:27:41,097 [root] DEBUG: 6560: Terminate Event: Attempting to dump process 6560
2026-05-28 18:27:41,403 [root] DEBUG: 6560: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:27:41,506 [lib.api.process] INFO: Termination confirmed for process 6560
2026-05-28 18:27:41,523 [root] DEBUG: 6560: Terminate Event: monitor shutdown complete for process 6560
2026-05-28 18:27:41,583 [root] INFO: Terminate event set for process 6560
2026-05-28 18:27:41,726 [root] INFO: Created shutdown mutex
2026-05-28 18:27:42,816 [root] INFO: Shutting down package
2026-05-28 18:27:42,959 [root] INFO: Stopping auxiliary modules
2026-05-28 18:27:43,037 [root] INFO: Stopping auxiliary module: Browser
2026-05-28 18:27:43,071 [root] INFO: Stopping auxiliary module: Human
2026-05-28 18:27:43,150 [root] INFO: Stopping auxiliary module: Screenshots
2026-05-28 18:27:43,223 [root] INFO: Finishing auxiliary modules
2026-05-28 18:27:43,332 [root] INFO: Shutting down pipe server and dumping dropped files
2026-05-28 18:27:43,457 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db to files\799a6da83f8d1a45fbc9c2afa04f366c6a81dd621a5472fa1b60be8e9499ff7c; Size is 29232; Max size: 100000000
2026-05-28 18:27:43,563 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db to files\8e2c71f751364d0883920e65d0872b847e11ecd4a972ddc07313e85393ffc05a; Size is 1048576; Max size: 100000000
2026-05-28 18:27:43,631 [root] WARNING: Folder at path "C:\RulsVhT\debugger" does not exist, skipping
2026-05-28 18:27:43,632 [root] WARNING: Folder at path "C:\RulsVhT\tlsdump" does not exist, skipping
2026-05-28 18:27:43,656 [root] WARNING: Monitor injection attempted but failed for process 4240
2026-05-28 18:27:43,678 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 18:23:59 | 2026-05-28 18:27:45 | none |
Seek in progress...
No results found.
No behavioral analysis data available.
No dropped files found.