| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 18:31:38 | 2026-05-28 18:33:15 | 97s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 18:30:47,626 [root] INFO: Date set to: 20260528T18:31:44, timeout set to: 200
2026-05-28 18:31:44,004 [root] DEBUG: Starting analyzer from: C:\2unxg6vp
2026-05-28 18:31:44,005 [root] DEBUG: Storing results at: C:\qkWlOOMgP
2026-05-28 18:31:44,005 [root] DEBUG: Pipe server name: \\.\PIPE\yISllA
2026-05-28 18:31:44,005 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 18:31:44,005 [root] INFO: analysis running as an admin
2026-05-28 18:31:44,005 [root] INFO: analysis package specified: "edge"
2026-05-28 18:31:44,005 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 18:31:44,007 [root] DEBUG: imported analysis package "edge"
2026-05-28 18:31:44,008 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 18:31:44,009 [root] DEBUG: New location of moved file: https://sugarcraft.net/
2026-05-28 18:31:44,010 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 18:31:44,010 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 18:31:44,010 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 18:31:44,010 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 18:31:44,030 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 18:31:44,090 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 18:31:44,112 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 18:31:44,127 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 18:31:44,130 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 18:31:44,131 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 18:31:44,131 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 18:31:44,132 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 18:31:44,133 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 18:31:44,133 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 18:31:44,134 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 18:31:44,134 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 18:31:44,134 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 18:31:44,135 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 18:31:44,135 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 18:31:44,135 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 18:31:44,135 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 18:31:44,135 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 18:31:44,135 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 18:31:44,136 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 18:31:44,136 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 18:31:44,136 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 18:31:44,136 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 18:31:44,138 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 4828)
2026-05-28 18:31:44,138 [modules.auxiliary.disguise] INFO: Disguising GUID to 91524b71-1c67-410a-aa95-1d6d743ad05d
2026-05-28 18:31:44,139 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 18:31:44,139 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 18:31:44,139 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 18:31:44,139 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 18:31:44,139 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 18:31:44,140 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 18:31:44,140 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 18:31:44,140 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 18:31:44,140 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 18:31:44,140 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 18:31:44,141 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 18:31:44,141 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 18:31:44,141 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 18:31:44,141 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 18:31:44,141 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 18:31:44,141 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 18:31:44,143 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 18:31:44,143 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 18:31:44,143 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 18:31:44,168 [lib.api.process] INFO: Monitor config for process 4676: C:\2unxg6vp\dll\4676.ini
2026-05-28 18:31:44,169 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:44,171 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:44,197 [root] DEBUG: Loader: Injecting process 4676 with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:44,379 [root] DEBUG: 4676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:31:44,382 [root] DEBUG: 4676: Disabling sleep skipping.
2026-05-28 18:31:44,385 [root] DEBUG: 4676: Interactive desktop enabled.
2026-05-28 18:31:44,387 [root] DEBUG: 4676: Dropped file limit defaulting to 100.
2026-05-28 18:31:44,388 [root] DEBUG: 4676: Interactive desktop - injecting Explorer Shell
2026-05-28 18:31:44,398 [root] DEBUG: 4676: YaraInit: Compiled 44 rule files
2026-05-28 18:31:44,401 [root] DEBUG: 4676: YaraInit: Compiled rules saved to file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:31:44,436 [root] DEBUG: 4676: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:31:44,437 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316
2026-05-28 18:31:44,482 [root] DEBUG: 4676: Monitor initialised: 64-bit capemon loaded in process 4676 at 0x00007FFF52E70000, thread 9116, image base 0x00007FF663980000, stack from 0x0000000010E52000-0x0000000010E60000
2026-05-28 18:31:44,483 [root] DEBUG: 4676: Commandline: C:\Windows\Explorer.EXE
2026-05-28 18:31:44,495 [root] DEBUG: 4676: Hooked 69 out of 69 functions
2026-05-28 18:31:44,525 [root] DEBUG: 4676: Syscall hook installed, syscall logging level 1
2026-05-28 18:31:44,532 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:31:44,532 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:44,533 [lib.api.process] INFO: Injected into 64-bit <Process 4676 explorer.exe>
2026-05-28 18:31:54,599 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316
2026-05-28 18:31:54,633 [root] DEBUG: 4676: caller_dispatch: Added region at 0x00007FF663980000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF663A28FBA, thread 4824).
2026-05-28 18:31:54,636 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316
2026-05-28 18:31:54,673 [root] DEBUG: 4676: ProcessImageBase: Main module image at 0x00007FF663980000 unmodified (entropy change 1.067672e-06)
2026-05-28 18:31:54,679 [root] DEBUG: 4676: ProcessImageBase: Main module image at 0x00007FF663980000 unmodified (entropy change 5.913137e-06)
2026-05-28 18:31:54,936 [root] INFO: Restarting WMI Service
2026-05-28 18:31:56,990 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 18:31:56,992 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 18:31:56,993 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 18:31:56,998 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://sugarcraft.net/"" with pid 7284
2026-05-28 18:31:56,999 [lib.api.process] INFO: Monitor config for process 7284: C:\2unxg6vp\dll\7284.ini
2026-05-28 18:31:57,002 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:57,005 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:57,014 [root] DEBUG: Loader: Injecting process 7284 (thread 7496) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:57,014 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:31:57,015 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:57,016 [lib.api.process] INFO: Injected into 64-bit <Process 7284 msedge.exe>
2026-05-28 18:31:57,284 [lib.api.process] INFO: Monitor config for process 840: C:\2unxg6vp\dll\840.ini
2026-05-28 18:31:57,285 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:57,286 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:57,290 [root] DEBUG: Loader: Injecting process 840 with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:57,293 [root] DEBUG: 840: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:31:57,293 [root] DEBUG: 840: Disabling sleep skipping.
2026-05-28 18:31:57,294 [root] DEBUG: 840: Interactive desktop enabled.
2026-05-28 18:31:57,294 [root] DEBUG: 840: Dropped file limit defaulting to 100.
2026-05-28 18:31:57,295 [root] DEBUG: 840: Services hook set enabled
2026-05-28 18:31:57,298 [root] DEBUG: 840: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:31:57,311 [root] DEBUG: 840: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:31:57,311 [root] DEBUG: 840: Monitor initialised: 64-bit capemon loaded in process 840 at 0x00007FFF52E70000, thread 7192, image base 0x00007FF71F590000, stack from 0x000000B0F6374000-0x000000B0F6380000
2026-05-28 18:31:57,312 [root] DEBUG: 840: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 18:31:57,324 [root] DEBUG: 840: Hooked 69 out of 69 functions
2026-05-28 18:31:57,325 [root] INFO: Loaded monitor into process with pid 840
2026-05-28 18:31:57,326 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:31:57,326 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:57,327 [lib.api.process] INFO: Injected into 64-bit <Process 840 svchost.exe>
2026-05-28 18:31:59,032 [lib.api.process] INFO: Successfully resumed process with pid 7284
2026-05-28 18:31:59,049 [root] DEBUG: 4676: CreateProcessHandler: Injection info set for new process 8372: C:\Windows\system32\msinfo32.exe, ImageBase: 0x00007FF726AD0000
2026-05-28 18:31:59,050 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 8372
2026-05-28 18:31:59,050 [lib.api.process] INFO: Monitor config for process 8372: C:\2unxg6vp\dll\8372.ini
2026-05-28 18:31:59,051 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:59,052 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:59,057 [root] DEBUG: Loader: Injecting process 8372 (thread 7460) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,058 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:31:59,059 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,060 [lib.api.process] INFO: Injected into 64-bit <Process 8372 msinfo32.exe>
2026-05-28 18:31:59,062 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 8372
2026-05-28 18:31:59,062 [lib.api.process] INFO: Monitor config for process 8372: C:\2unxg6vp\dll\8372.ini
2026-05-28 18:31:59,063 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:59,063 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:59,069 [root] DEBUG: Loader: Injecting process 8372 (thread 7460) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,070 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:31:59,070 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,072 [lib.api.process] INFO: Injected into 64-bit <Process 8372 msinfo32.exe>
2026-05-28 18:31:59,080 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 8372
2026-05-28 18:31:59,081 [lib.api.process] INFO: Monitor config for process 8372: C:\2unxg6vp\dll\8372.ini
2026-05-28 18:31:59,083 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:59,086 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:59,088 [root] DEBUG: 7284: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:31:59,089 [root] DEBUG: 4676: DLL loaded at 0x00007FFF7C210000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 18:31:59,091 [root] DEBUG: 7284: Disabling sleep skipping.
2026-05-28 18:31:59,091 [root] DEBUG: Loader: Injecting process 8372 with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,091 [root] DEBUG: 7284: Interactive desktop enabled.
2026-05-28 18:31:59,092 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 7460, handle 0x120
2026-05-28 18:31:59,092 [root] DEBUG: 7284: Dropped file limit defaulting to 100.
2026-05-28 18:31:59,093 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:31:59,093 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,096 [lib.api.process] INFO: Injected into 64-bit <Process 8372 msinfo32.exe>
2026-05-28 18:31:59,101 [root] DEBUG: 7284: Edge-specific hook-set enabled.
2026-05-28 18:31:59,104 [root] DEBUG: 7284: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:31:59,109 [root] DEBUG: 8372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:31:59,110 [root] DEBUG: 8372: Interactive desktop enabled.
2026-05-28 18:31:59,110 [root] DEBUG: 8372: Dropped file limit defaulting to 100.
2026-05-28 18:31:59,113 [root] DEBUG: 8372: Disabling sleep skipping.
2026-05-28 18:31:59,114 [root] DEBUG: 8372: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:31:59,116 [root] DEBUG: 7284: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:31:59,116 [root] DEBUG: 7284: Monitor initialised: 64-bit capemon loaded in process 7284 at 0x00007FFF52E70000, thread 7496, image base 0x00007FF6F9430000, stack from 0x000000F98C3F4000-0x000000F98C400000
2026-05-28 18:31:59,117 [root] DEBUG: 7284: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://sugarcraft.net/"
2026-05-28 18:31:59,127 [root] DEBUG: 7284: Hooked 2 out of 2 functions
2026-05-28 18:31:59,128 [root] DEBUG: 8372: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:31:59,128 [root] DEBUG: 8372: YaraScan: Scanning 0x00007FF726AD0000, size 0x66322
2026-05-28 18:31:59,130 [root] DEBUG: 8372: Monitor initialised: 64-bit capemon loaded in process 8372 at 0x00007FFF52E70000, thread 7460, image base 0x00007FF726AD0000, stack from 0x0000009D40CD4000-0x0000009D40CE0000
2026-05-28 18:31:59,131 [root] DEBUG: 8372: Commandline: "C:\Windows\system32\msinfo32.exe"
2026-05-28 18:31:59,140 [root] DEBUG: 8372: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:31:59,162 [root] DEBUG: 7284: Syscall hook installed, syscall logging level 1
2026-05-28 18:31:59,166 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:31:59,167 [root] DEBUG: 8372: set_hooks: Unable to hook LockResource
2026-05-28 18:31:59,168 [root] DEBUG: 7284: RestoreHeaders: Restored original import table.
2026-05-28 18:31:59,168 [root] INFO: Loaded monitor into process with pid 7284
2026-05-28 18:31:59,172 [root] DEBUG: 8372: Hooked 627 out of 628 functions
2026-05-28 18:31:59,172 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 18:31:59,174 [root] DEBUG: 8372: Syscall hook installed, syscall logging level 1
2026-05-28 18:31:59,178 [root] DEBUG: 7284: DLL loaded at 0x00007FFF853A0000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 18:31:59,179 [root] DEBUG: 8372: RestoreHeaders: Restored original import table.
2026-05-28 18:31:59,179 [root] DEBUG: 7284: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:31:59,179 [root] INFO: Loaded monitor into process with pid 8372
2026-05-28 18:31:59,181 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95CA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 18:31:59,181 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94410000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:31:59,182 [root] DEBUG: 7284: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 18:31:59,183 [root] DEBUG: 8372: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:31:59,184 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:31:59,194 [root] DEBUG: 8372: DLL loaded at 0x00007FFF96170000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 18:31:59,198 [root] DEBUG: 8372: caller_dispatch: Added region at 0x00007FF726AD0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF726AF1A71, thread 7460).
2026-05-28 18:31:59,199 [root] DEBUG: 8372: YaraScan: Scanning 0x00007FF726AD0000, size 0x66322
2026-05-28 18:31:59,203 [root] DEBUG: 8372: ProcessImageBase: Main module image at 0x00007FF726AD0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:31:59,206 [root] DEBUG: 8372: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:31:59,208 [root] DEBUG: 8372: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:31:59,216 [root] DEBUG: 8372: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:31:59,262 [root] DEBUG: 8372: DLL loaded at 0x00007FFF87FF0000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 18:31:59,317 [lib.api.process] INFO: Monitor config for process 5020: C:\2unxg6vp\dll\5020.ini
2026-05-28 18:31:59,321 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:59,323 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:59,326 [root] DEBUG: 7284: DLL loaded at 0x00007FFF84A60000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 18:31:59,327 [root] DEBUG: 7284: DLL loaded at 0x00007FFF3EE40000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 18:31:59,328 [root] DEBUG: Loader: Injecting process 5020 with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,330 [root] DEBUG: 7284: DLL loaded at 0x00007FFF833E0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 18:31:59,330 [root] DEBUG: 5020: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:31:59,331 [root] DEBUG: 5020: Disabling sleep skipping.
2026-05-28 18:31:59,331 [root] DEBUG: 8372: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:31:59,331 [root] DEBUG: 5020: Interactive desktop enabled.
2026-05-28 18:31:59,331 [root] DEBUG: 8372: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:31:59,332 [root] DEBUG: 5020: Dropped file limit defaulting to 100.
2026-05-28 18:31:59,332 [root] DEBUG: 7284: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:31:59,333 [root] DEBUG: 5020: Services hook set enabled
2026-05-28 18:31:59,333 [root] DEBUG: 8372: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:31:59,334 [root] DEBUG: 8372: DLL loaded at 0x00007FFF93160000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 18:31:59,334 [root] DEBUG: 8372: DLL loaded at 0x00007FFF8A6E0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 18:31:59,336 [root] DEBUG: 5020: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:31:59,338 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:31:59,338 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 5600: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:31:59,338 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 5600
2026-05-28 18:31:59,339 [root] DEBUG: 7284: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:31:59,339 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 5600
2026-05-28 18:31:59,340 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8D840000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 18:31:59,341 [root] DEBUG: 7284: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:31:59,342 [root] DEBUG: 7284: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:31:59,346 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96220000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 18:31:59,347 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94BC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 18:31:59,347 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95490000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 18:31:59,351 [root] DEBUG: 5020: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:31:59,352 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95850000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 18:31:59,355 [root] DEBUG: 5020: Monitor initialised: 64-bit capemon loaded in process 5020 at 0x00007FFF52E70000, thread 668, image base 0x00007FF71F590000, stack from 0x000000E4C4DF4000-0x000000E4C4E00000
2026-05-28 18:31:59,357 [root] DEBUG: 7284: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:31:59,358 [root] DEBUG: 5020: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 18:31:59,359 [root] DEBUG: 7284: DLL loaded at 0x00007FFF7FD70000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 18:31:59,361 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:31:59,362 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 18:31:59,364 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95D10000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 18:31:59,365 [root] DEBUG: 7284: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:31:59,366 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:31:59,366 [root] DEBUG: 7284: DLL loaded at 0x00007FFF82660000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 18:31:59,367 [root] DEBUG: 7284: DLL loaded at 0x00007FFF82E70000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 18:31:59,370 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:31:59,371 [root] DEBUG: 5020: Hooked 69 out of 69 functions
2026-05-28 18:31:59,372 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95CD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 18:31:59,372 [root] INFO: Loaded monitor into process with pid 5020
2026-05-28 18:31:59,373 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:31:59,374 [root] DEBUG: 7284: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 18:31:59,374 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,375 [root] DEBUG: 7284: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:31:59,375 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 18:31:59,375 [lib.api.process] INFO: Injected into 64-bit <Process 5020 svchost.exe>
2026-05-28 18:31:59,376 [root] DEBUG: 7284: DLL loaded at 0x00007FFF92030000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 18:31:59,377 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96260000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 18:31:59,390 [root] DEBUG: 4676: CreateProcessHandler: Injection info set for new process 2380: C:\Windows\system32\msinfo32.exe, ImageBase: 0x00007FF726AD0000
2026-05-28 18:31:59,390 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 2380
2026-05-28 18:31:59,390 [lib.api.process] INFO: Monitor config for process 2380: C:\2unxg6vp\dll\2380.ini
2026-05-28 18:31:59,391 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:59,392 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:59,397 [root] DEBUG: Loader: Injecting process 2380 (thread 2404) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,397 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:31:59,397 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,399 [lib.api.process] INFO: Injected into 64-bit <Process 2380 msinfo32.exe>
2026-05-28 18:31:59,400 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 2380
2026-05-28 18:31:59,401 [lib.api.process] INFO: Monitor config for process 2380: C:\2unxg6vp\dll\2380.ini
2026-05-28 18:31:59,401 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:59,402 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:59,406 [root] DEBUG: Loader: Injecting process 2380 (thread 2404) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,406 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:31:59,406 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,408 [lib.api.process] INFO: Injected into 64-bit <Process 2380 msinfo32.exe>
2026-05-28 18:31:59,408 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8D820000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 18:31:59,409 [root] INFO: Announced 64-bit process name: msinfo32.exe pid: 2380
2026-05-28 18:31:59,409 [root] DEBUG: 7284: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:31:59,409 [lib.api.process] INFO: Monitor config for process 2380: C:\2unxg6vp\dll\2380.ini
2026-05-28 18:31:59,410 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:59,410 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8CEF0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 18:31:59,411 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:59,411 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:31:59,412 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:31:59,413 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8A140000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 18:31:59,416 [root] DEBUG: Loader: Injecting process 2380 with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,417 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 2404, handle 0x120
2026-05-28 18:31:59,417 [root] DEBUG: 7284: DLL loaded at 0x00007FFF82ED0000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 18:31:59,418 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:31:59,418 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,419 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8F850000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 18:31:59,422 [root] DEBUG: 7284: DLL loaded at 0x00007FFF960B0000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 18:31:59,423 [lib.api.process] INFO: Injected into 64-bit <Process 2380 msinfo32.exe>
2026-05-28 18:31:59,424 [root] DEBUG: 7284: DLL loaded at 0x00007FFF956F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:31:59,424 [root] DEBUG: 7284: DLL loaded at 0x00007FFF91940000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 18:31:59,426 [root] DEBUG: 7284: DLL loaded at 0x00007FFF98020000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 18:31:59,426 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96AF0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 18:31:59,427 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8BEB0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 18:31:59,428 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8EAD0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 18:31:59,429 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8EAB0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:31:59,429 [root] DEBUG: 7284: DLL loaded at 0x00007FFF91EB0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 18:31:59,430 [root] DEBUG: 2380: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:31:59,430 [root] DEBUG: 2380: Interactive desktop enabled.
2026-05-28 18:31:59,430 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95730000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 18:31:59,431 [root] DEBUG: 2380: Dropped file limit defaulting to 100.
2026-05-28 18:31:59,432 [root] DEBUG: 2380: Disabling sleep skipping.
2026-05-28 18:31:59,433 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8B820000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:31:59,433 [root] DEBUG: 2380: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:31:59,436 [root] DEBUG: 7284: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:31:59,436 [root] DEBUG: 7284: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:31:59,437 [root] DEBUG: 7284: DLL loaded at 0x00007FFF93160000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 18:31:59,437 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8A6E0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 18:31:59,438 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8B750000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 18:31:59,440 [root] DEBUG: 7284: DLL loaded at 0x00007FFF90DA0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:31:59,442 [root] DEBUG: 7284: DLL loaded at 0x00007FFF82BC0000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 18:31:59,443 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8A550000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 18:31:59,445 [root] DEBUG: 7284: DLL loaded at 0x00007FFF905B0000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 18:31:59,445 [root] DEBUG: 2380: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:31:59,446 [root] DEBUG: 2380: YaraScan: Scanning 0x00007FF726AD0000, size 0x66322
2026-05-28 18:31:59,448 [root] DEBUG: 2380: Monitor initialised: 64-bit capemon loaded in process 2380 at 0x00007FFF52E70000, thread 2404, image base 0x00007FF726AD0000, stack from 0x000000DDD5594000-0x000000DDD55A0000
2026-05-28 18:31:59,449 [root] DEBUG: 7284: DLL loaded at 0x00007FFF86740000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 18:31:59,449 [root] DEBUG: 2380: Commandline: "C:\Windows\system32\msinfo32.exe"
2026-05-28 18:31:59,451 [root] DEBUG: 7284: DLL loaded at 0x00007FFF90FB0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 18:31:59,452 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8A580000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 18:31:59,452 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8A7E0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 18:31:59,456 [root] DEBUG: 7284: DLL loaded at 0x00007FFF91FE0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 18:31:59,457 [root] DEBUG: 7284: DLL loaded at 0x00007FFF90620000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 18:31:59,458 [root] DEBUG: 7284: DLL loaded at 0x00007FFF90660000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 18:31:59,459 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8C3B0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 18:31:59,460 [root] DEBUG: 7284: DLL loaded at 0x00007FFF865D0000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 18:31:59,461 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95FF0000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 18:31:59,463 [root] DEBUG: 2380: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:31:59,468 [root] DEBUG: 7284: DLL loaded at 0x00007FFF90780000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 18:31:59,473 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 18:31:59,473 [lib.api.process] INFO: Monitor config for process 672: C:\2unxg6vp\dll\672.ini
2026-05-28 18:31:59,474 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:31:59,475 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:31:59,486 [root] DEBUG: 7284: DLL loaded at 0x00007FFF3D4E0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 18:31:59,487 [root] DEBUG: Loader: Injecting process 672 with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,489 [root] DEBUG: Loader: Copied config file C:\2unxg6vp\dll\672.ini to system path C:\672.ini
2026-05-28 18:31:59,491 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:31:59,491 [root] DEBUG: 2380: set_hooks: Unable to hook LockResource
2026-05-28 18:31:59,493 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 672 C:\2unxg6vp\dll\qmRoKOe.dll
2026-05-28 18:31:59,494 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:31:59,496 [lib.api.process] INFO: Injected into 64-bit <Process 672 services.exe>
2026-05-28 18:31:59,497 [root] DEBUG: 2380: Hooked 627 out of 628 functions
2026-05-28 18:31:59,497 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8A3C0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 18:31:59,498 [root] DEBUG: 7284: DLL loaded at 0x00007FFF87320000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 18:31:59,501 [root] DEBUG: 2380: Syscall hook installed, syscall logging level 1
2026-05-28 18:31:59,501 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 8728: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:31:59,502 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 8728
2026-05-28 18:31:59,503 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 8728
2026-05-28 18:31:59,503 [root] DEBUG: 7284: caller_dispatch: Added region at 0x00007FF6F9430000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF6F9527D66, thread 2744).
2026-05-28 18:31:59,508 [root] DEBUG: 2380: RestoreHeaders: Restored original import table.
2026-05-28 18:31:59,508 [root] DEBUG: 7284: ProcessImageBase: Main module image at 0x00007FF6F9430000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:31:59,518 [root] INFO: Loaded monitor into process with pid 2380
2026-05-28 18:31:59,525 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 9256: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:31:59,532 [root] DEBUG: 2380: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:31:59,534 [root] DEBUG: 7284: DLL loaded at 0x00007FFF853F0000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 18:31:59,534 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 9276: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:31:59,538 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 9256
2026-05-28 18:31:59,541 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 9276
2026-05-28 18:31:59,542 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 9256
2026-05-28 18:31:59,551 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 9276
2026-05-28 18:31:59,552 [root] DEBUG: 2380: DLL loaded at 0x00007FFF96170000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 18:31:59,578 [root] DEBUG: 2380: caller_dispatch: Added region at 0x00007FF726AD0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF726AF1A71, thread 2404).
2026-05-28 18:31:59,584 [root] DEBUG: 2380: YaraScan: Scanning 0x00007FF726AD0000, size 0x66322
2026-05-28 18:31:59,595 [root] DEBUG: 2380: ProcessImageBase: Main module image at 0x00007FF726AD0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:31:59,599 [root] DEBUG: 2380: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:31:59,603 [root] DEBUG: 2380: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:31:59,618 [root] DEBUG: 2380: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:31:59,620 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94BF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 18:31:59,622 [root] DEBUG: 7284: DLL loaded at 0x00007FFF92740000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 18:31:59,625 [root] DEBUG: 7284: DLL loaded at 0x00007FFF929B0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 18:31:59,626 [root] DEBUG: 7284: DLL loaded at 0x00007FFF80590000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 18:31:59,661 [root] DEBUG: 2380: DLL loaded at 0x00007FFF87FF0000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 18:31:59,705 [root] DEBUG: 2380: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:31:59,706 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8D6A0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 18:31:59,716 [root] DEBUG: 2380: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:31:59,720 [root] DEBUG: 2380: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:31:59,720 [root] DEBUG: 2380: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:31:59,721 [root] DEBUG: 2380: DLL loaded at 0x00007FFF93160000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 18:31:59,721 [root] DEBUG: 2380: DLL loaded at 0x00007FFF8A6E0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 18:31:59,723 [root] DEBUG: 2380: DLL loaded at 0x00007FFF8CFE0000: C:\Windows\SYSTEM32\wbemcomn (0x90000 bytes).
2026-05-28 18:31:59,723 [root] DEBUG: 2380: DLL loaded at 0x00007FFF82DC0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 18:31:59,733 [root] DEBUG: 2380: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 18:31:59,746 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 9620: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:31:59,747 [root] DEBUG: 7284: DLL loaded at 0x00007FFF80840000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 18:31:59,748 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 9648: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:31:59,752 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 9620
2026-05-28 18:31:59,753 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 9648
2026-05-28 18:31:59,756 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 9620
2026-05-28 18:31:59,757 [root] DEBUG: 7284: DLL loaded at 0x00007FFF877F0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 18:31:59,758 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 9648
2026-05-28 18:31:59,761 [root] DEBUG: 5020: DLL loaded at 0x00007FFF8C090000: C:\Windows\SYSTEM32\VssTrace (0x18000 bytes).
2026-05-28 18:31:59,767 [root] DEBUG: 5020: DLL loaded at 0x00007FFF8C0B0000: C:\Windows\SYSTEM32\vssapi (0x19e000 bytes).
2026-05-28 18:31:59,771 [root] DEBUG: 5020: DLL loaded at 0x00007FFF8C070000: C:\Windows\SYSTEM32\samcli (0x19000 bytes).
2026-05-28 18:31:59,773 [root] DEBUG: 5020: DLL loaded at 0x00007FFF95850000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 18:31:59,779 [root] DEBUG: 5020: DLL loaded at 0x00007FFF91FB0000: C:\Windows\SYSTEM32\SAMLIB (0x28000 bytes).
2026-05-28 18:31:59,781 [root] DEBUG: 5020: DLL loaded at 0x00007FFF8E940000: C:\Windows\System32\ES (0x6c000 bytes).
2026-05-28 18:31:59,792 [root] DEBUG: 5020: DLL loaded at 0x00007FFF91EB0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 18:31:59,796 [root] DEBUG: 5020: DLL loaded at 0x00007FFF7FC20000: C:\Windows\system32\wbem\FastProx (0x10b000 bytes).
2026-05-28 18:31:59,797 [root] DEBUG: 5020: DLL loaded at 0x00007FFF7FBA0000: C:\Windows\system32\wbem\esscli (0x7d000 bytes).
2026-05-28 18:31:59,797 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56920000: C:\Windows\system32\wbem\wbemcore (0x1e9000 bytes).
2026-05-28 18:31:59,816 [root] DEBUG: 5020: DLL loaded at 0x00007FFF82A50000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 18:31:59,820 [root] DEBUG: 2380: DLL loaded at 0x00007FFF82A50000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 18:31:59,833 [root] DEBUG: 5020: DLL loaded at 0x00007FFF95060000: C:\Windows\system32\authZ (0x4f000 bytes).
2026-05-28 18:31:59,842 [root] DEBUG: 5020: DLL loaded at 0x00007FFF8BE60000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 18:31:59,843 [root] DEBUG: 7284: DLL loaded at 0x00007FFF93E40000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 18:31:59,849 [root] DEBUG: 5020: DLL loaded at 0x00007FFF7FAB0000: C:\Windows\system32\wbem\repdrvfs (0x71000 bytes).
2026-05-28 18:31:59,854 [root] DEBUG: 5020: DLL loaded at 0x00007FFF905B0000: C:\Windows\system32\Wevtapi (0x65000 bytes).
2026-05-28 18:31:59,867 [root] DEBUG: 7284: DLL loaded at 0x00007FFF84F00000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 18:31:59,884 [root] DEBUG: 7284: DLL loaded at 0x00007FFF7D100000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 18:31:59,897 [root] DEBUG: 7284: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:31:59,898 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95E30000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 18:31:59,900 [root] DEBUG: 7284: DLL loaded at 0x00007FFF78140000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 18:31:59,902 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 18:31:59,915 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95330000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 18:31:59,954 [root] DEBUG: 7284: DLL loaded at 0x00007FFF59130000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 18:31:59,990 [root] DEBUG: 5020: DLL loaded at 0x00007FFF973C0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 18:32:00,005 [root] DEBUG: 5020: DLL loaded at 0x00007FFF7D520000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 18:32:00,006 [root] DEBUG: 5020: DLL loaded at 0x00007FFF96220000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 18:32:00,007 [root] DEBUG: 5020: DLL loaded at 0x00007FFF96260000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 18:32:00,008 [root] DEBUG: 5020: DLL loaded at 0x00007FFF7D4D0000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 18:32:00,009 [root] DEBUG: 5020: DLL loaded at 0x00007FFF853A0000: C:\Windows\system32\version (0xa000 bytes).
2026-05-28 18:32:00,018 [root] DEBUG: 5020: DLL loaded at 0x00007FFF8BF60000: C:\Windows\SYSTEM32\NCObjAPI (0x18000 bytes).
2026-05-28 18:32:00,019 [root] DEBUG: 5020: DLL loaded at 0x00007FFF3A940000: C:\Windows\system32\wbem\wmiprvsd (0xd7000 bytes).
2026-05-28 18:32:00,022 [root] DEBUG: 5020: DLL loaded at 0x00007FFF590A0000: C:\Windows\system32\wbem\wbemess (0x83000 bytes).
2026-05-28 18:32:00,024 [root] DEBUG: 5020: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 18:32:00,025 [root] DEBUG: 5020: DLL loaded at 0x00007FFF95330000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 18:32:00,041 [root] DEBUG: 2380: DLL loaded at 0x00007FFF7FC20000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2026-05-28 18:32:00,043 [root] DEBUG: 2380: DLL loaded at 0x00007FFF7D520000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 18:32:00,044 [root] DEBUG: 2380: DLL loaded at 0x00007FFF96220000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 18:32:00,050 [root] DEBUG: 2380: DLL loaded at 0x00007FFF96260000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 18:32:00,051 [root] DEBUG: 2380: DLL loaded at 0x00007FFF7D4D0000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 18:32:00,053 [root] DEBUG: 2380: DLL loaded at 0x00007FFF853A0000: C:\Windows\system32\version (0xa000 bytes).
2026-05-28 18:32:00,055 [root] DEBUG: 2380: Successfully installed hook on COM Object function IWbemServices_ExecQuery
2026-05-28 18:32:00,055 [root] DEBUG: 2380: Successfully installed hook on COM Object function IWbemServices_ExecQueryAsync
2026-05-28 18:32:00,056 [root] DEBUG: 2380: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnum
2026-05-28 18:32:00,056 [root] DEBUG: 2380: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnumAsync
2026-05-28 18:32:00,057 [root] DEBUG: 2380: Successfully installed hook on COM Object function IWbemServices_GetObjectW
2026-05-28 18:32:00,058 [root] DEBUG: 2380: Successfully installed hook on COM Object function IWbemServices_GetObjectAsync
2026-05-28 18:32:00,058 [root] DEBUG: 2380: Successfully installed hook on COM Object function IWbemServices_ExecMethod
2026-05-28 18:32:00,060 [root] DEBUG: 2380: Successfully installed hook on COM Object function IWbemServices_ExecMethodAsync
2026-05-28 18:32:00,082 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 9420: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7C5600000
2026-05-28 18:32:00,082 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 9420
2026-05-28 18:32:00,083 [lib.api.process] INFO: Monitor config for process 9420: C:\2unxg6vp\dll\9420.ini
2026-05-28 18:32:00,083 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:00,519 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:00,523 [root] DEBUG: Loader: Injecting process 9420 (thread 1716) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:00,523 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:32:00,524 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:00,525 [lib.api.process] INFO: Injected into 64-bit <Process 9420 WmiPrvSE.exe>
2026-05-28 18:32:00,526 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 9420
2026-05-28 18:32:00,526 [lib.api.process] INFO: Monitor config for process 9420: C:\2unxg6vp\dll\9420.ini
2026-05-28 18:32:00,526 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:00,601 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:00,606 [root] DEBUG: Loader: Injecting process 9420 (thread 1716) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:00,607 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:32:00,608 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:00,610 [lib.api.process] INFO: Injected into 64-bit <Process 9420 WmiPrvSE.exe>
2026-05-28 18:32:00,622 [root] DEBUG: 9420: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:32:00,623 [root] DEBUG: 9420: Interactive desktop enabled.
2026-05-28 18:32:00,624 [root] DEBUG: 9420: Dropped file limit defaulting to 100.
2026-05-28 18:32:00,626 [root] DEBUG: 9420: Disabling sleep skipping.
2026-05-28 18:32:00,626 [root] DEBUG: 9420: Services hook set enabled
2026-05-28 18:32:00,628 [root] DEBUG: 9420: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:32:00,639 [root] DEBUG: 9420: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:32:00,640 [root] DEBUG: 9420: Monitor initialised: 64-bit capemon loaded in process 9420 at 0x00007FFF52E70000, thread 1716, image base 0x00007FF7C5600000, stack from 0x00000002AB940000-0x00000002AB950000
2026-05-28 18:32:00,640 [root] DEBUG: 9420: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 18:32:00,654 [root] DEBUG: 9420: Hooked 69 out of 69 functions
2026-05-28 18:32:00,659 [root] DEBUG: 9420: RestoreHeaders: Restored original import table.
2026-05-28 18:32:00,660 [root] INFO: Loaded monitor into process with pid 9420
2026-05-28 18:32:00,662 [root] DEBUG: 9420: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:32:00,663 [root] DEBUG: 9420: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:32:00,665 [root] DEBUG: 9420: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:32:00,667 [root] DEBUG: 9420: DLL loaded at 0x00007FFF82DC0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 18:32:00,672 [root] DEBUG: 9420: DLL loaded at 0x00007FFF82A50000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 18:32:00,682 [root] DEBUG: 9420: DLL loaded at 0x00007FFF8BE60000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 18:32:00,697 [root] DEBUG: 9420: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:32:00,698 [root] DEBUG: 9420: DLL loaded at 0x00007FFF3A6D0000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 18:32:00,698 [root] DEBUG: 9420: DLL loaded at 0x00007FFF3A730000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 18:32:00,699 [root] DEBUG: 9420: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:32:00,711 [root] DEBUG: 9420: DLL loaded at 0x00007FFF91070000: C:\Windows\SYSTEM32\winbrand (0x35000 bytes).
2026-05-28 18:32:00,714 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95CA0000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 18:32:00,716 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95CA0000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 18:32:00,718 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95CA0000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 18:32:00,720 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95CA0000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 18:32:00,721 [root] DEBUG: 9420: DLL loaded at 0x000001BF1FC80000: C:\Windows\SYSTEM32\SECURITY (0x3000 bytes).
2026-05-28 18:32:00,722 [root] DEBUG: 9420: DLL loaded at 0x00007FFF87320000: C:\Windows\SYSTEM32\SECUR32 (0xc000 bytes).
2026-05-28 18:32:00,723 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95240000: C:\Windows\system32\schannel (0x97000 bytes).
2026-05-28 18:32:00,723 [root] DEBUG: 9420: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 18:32:00,742 [root] DEBUG: 9420: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 18:32:00,743 [root] DEBUG: 9420: DLL loaded at 0x00007FFF8C070000: C:\Windows\SYSTEM32\SAMCLI (0x19000 bytes).
2026-05-28 18:32:00,744 [root] DEBUG: 9420: DLL loaded at 0x00007FFF8CEC0000: C:\Windows\SYSTEM32\SRVCLI (0x28000 bytes).
2026-05-28 18:32:00,745 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95850000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-28 18:32:00,746 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95800000: C:\Windows\SYSTEM32\LOGONCLI (0x43000 bytes).
2026-05-28 18:32:00,746 [root] DEBUG: 9420: DLL loaded at 0x00007FFF8BE20000: C:\Windows\SYSTEM32\SCHEDCLI (0xc000 bytes).
2026-05-28 18:32:00,747 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95490000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-28 18:32:00,748 [root] DEBUG: 9420: DLL loaded at 0x00007FFF917A0000: C:\Windows\SYSTEM32\DSROLE (0xa000 bytes).
2026-05-28 18:32:00,750 [root] DEBUG: 9420: DLL loaded at 0x00007FFF82EB0000: C:\Windows\SYSTEM32\cscapi (0x12000 bytes).
2026-05-28 18:32:00,789 [root] DEBUG: 9420: DLL loaded at 0x00007FFF91FE0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 18:32:00,790 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95FF0000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 18:32:00,792 [root] DEBUG: 9420: DLL loaded at 0x00007FFF96AF0000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 18:32:00,794 [root] DEBUG: 9420: DLL loaded at 0x00007FFF96050000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 18:32:00,798 [root] DEBUG: 9420: DLL loaded at 0x000001BF1FCC0000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 18:32:00,799 [root] DEBUG: 9420: DLL loaded at 0x00007FFF90640000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 18:32:00,813 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 10576: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7C5600000
2026-05-28 18:32:00,814 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 10576
2026-05-28 18:32:00,814 [lib.api.process] INFO: Monitor config for process 10576: C:\2unxg6vp\dll\10576.ini
2026-05-28 18:32:00,814 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:00,888 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:00,893 [root] DEBUG: Loader: Injecting process 10576 (thread 10580) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:00,894 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:32:00,894 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:00,895 [lib.api.process] INFO: Injected into 64-bit <Process 10576 WmiPrvSE.exe>
2026-05-28 18:32:00,896 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 10576
2026-05-28 18:32:00,896 [lib.api.process] INFO: Monitor config for process 10576: C:\2unxg6vp\dll\10576.ini
2026-05-28 18:32:00,897 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:00,973 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:00,978 [root] DEBUG: Loader: Injecting process 10576 (thread 10580) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:00,979 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:32:00,979 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:00,980 [lib.api.process] INFO: Injected into 64-bit <Process 10576 WmiPrvSE.exe>
2026-05-28 18:32:00,985 [root] DEBUG: 10576: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:32:00,986 [root] DEBUG: 10576: Interactive desktop enabled.
2026-05-28 18:32:00,986 [root] DEBUG: 10576: Dropped file limit defaulting to 100.
2026-05-28 18:32:00,988 [root] DEBUG: 10576: Disabling sleep skipping.
2026-05-28 18:32:00,989 [root] DEBUG: 10576: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:32:01,001 [root] DEBUG: 10576: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:32:01,002 [root] DEBUG: 10576: YaraScan: Scanning 0x00007FF7C5600000, size 0x7dcfe
2026-05-28 18:32:01,005 [root] DEBUG: 10576: Monitor initialised: 64-bit capemon loaded in process 10576 at 0x00007FFF52E70000, thread 10580, image base 0x00007FF7C5600000, stack from 0x000000D783BE0000-0x000000D783BF0000
2026-05-28 18:32:01,006 [root] DEBUG: 10576: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -Embedding
2026-05-28 18:32:01,017 [root] DEBUG: 10576: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:32:01,040 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:32:01,040 [root] DEBUG: 10576: set_hooks: Unable to hook LockResource
2026-05-28 18:32:01,044 [root] DEBUG: 10576: Hooked 627 out of 628 functions
2026-05-28 18:32:01,047 [root] DEBUG: 10576: Syscall hook installed, syscall logging level 1
2026-05-28 18:32:01,053 [root] DEBUG: 10576: RestoreHeaders: Restored original import table.
2026-05-28 18:32:01,053 [root] INFO: Loaded monitor into process with pid 10576
2026-05-28 18:32:01,054 [root] DEBUG: 10576: caller_dispatch: Added region at 0x00007FF7C5600000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7C5612CD1, thread 10580).
2026-05-28 18:32:01,054 [root] DEBUG: 10576: YaraScan: Scanning 0x00007FF7C5600000, size 0x7dcfe
2026-05-28 18:32:01,058 [root] DEBUG: 10576: ProcessImageBase: Main module image at 0x00007FF7C5600000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:32:01,063 [root] DEBUG: 10576: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:32:01,064 [root] DEBUG: 10576: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:32:01,068 [root] DEBUG: 10576: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:32:01,071 [root] DEBUG: 10576: DLL loaded at 0x00007FFF82DC0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 18:32:01,078 [root] DEBUG: 10576: DLL loaded at 0x00007FFF82A50000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 18:32:01,103 [root] DEBUG: 10576: DLL loaded at 0x00007FFF8BE60000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 18:32:01,124 [root] DEBUG: 10576: DLL loaded at 0x00007FFF7F2F0000: C:\Windows\SYSTEM32\pdh (0x49000 bytes).
2026-05-28 18:32:01,125 [root] DEBUG: 10576: DLL loaded at 0x00007FFF905B0000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 18:32:01,126 [root] DEBUG: 10576: DLL loaded at 0x00007FFF82E80000: C:\Windows\System32\wbem\WmiPerfClass (0x27000 bytes).
2026-05-28 18:32:01,172 [root] DEBUG: 2380: DLL loaded at 0x00007FFF8D860000: C:\Windows\system32\fveapi (0xf5000 bytes).
2026-05-28 18:32:01,177 [root] DEBUG: 2380: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:32:01,178 [root] DEBUG: 2380: DLL loaded at 0x00007FFF8E460000: C:\Windows\system32\tbs (0x1b000 bytes).
2026-05-28 18:32:01,210 [root] DEBUG: 9420: DLL loaded at 0x00007FFF3A670000: C:\Windows\SYSTEM32\PROVTHRD (0x52000 bytes).
2026-05-28 18:32:01,210 [root] DEBUG: 9420: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:32:01,211 [root] DEBUG: 9420: DLL loaded at 0x00007FFF905B0000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 18:32:01,211 [root] DEBUG: 9420: DLL loaded at 0x00007FFF7D0B0000: C:\Windows\system32\wbem\ntevt (0x43000 bytes).
2026-05-28 18:32:01,231 [root] DEBUG: 9420: DLL loaded at 0x000001BF1FCE0000: C:\Windows\SYSTEM32\tzres (0x3000 bytes).
2026-05-28 18:32:01,234 [root] DEBUG: 2380: DLL loaded at 0x00007FFF91EB0000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-05-28 18:32:01,264 [root] DEBUG: 9420: DLL loaded at 0x00007FFF8BE10000: C:\Windows\System32\Win32_DeviceGuard (0xc000 bytes).
2026-05-28 18:32:01,267 [root] DEBUG: 9420: DLL loaded at 0x00007FFF8BDB0000: C:\Windows\SYSTEM32\miutils (0x60000 bytes).
2026-05-28 18:32:01,267 [root] DEBUG: 9420: DLL loaded at 0x00007FFF8BE30000: C:\Windows\SYSTEM32\mi (0x23000 bytes).
2026-05-28 18:32:01,268 [root] DEBUG: 9420: DLL loaded at 0x00007FFF59060000: C:\Windows\system32\wmitomi (0x3a000 bytes).
2026-05-28 18:32:01,274 [root] DEBUG: 9420: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 18:32:01,280 [root] DEBUG: 2380: DLL loaded at 0x00007FFF8D860000: C:\Windows\SYSTEM32\fveapi (0xf5000 bytes).
2026-05-28 18:32:01,309 [root] DEBUG: 2380: DLL loaded at 0x00007FFF96050000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 18:32:01,354 [root] DEBUG: 7284: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:32:01,355 [root] DEBUG: 7284: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:32:01,377 [root] DEBUG: 2380: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:32:01,378 [root] DEBUG: 2380: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:32:01,380 [root] DEBUG: 2380: DLL loaded at 0x00007FFF7FB70000: C:\Windows\SYSTEM32\reinfo (0x30000 bytes).
2026-05-28 18:32:01,384 [root] DEBUG: 8372: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:32:01,387 [root] DEBUG: 8372: DLL loaded at 0x00007FFF8CFE0000: C:\Windows\SYSTEM32\wbemcomn (0x90000 bytes).
2026-05-28 18:32:01,388 [root] DEBUG: 8372: DLL loaded at 0x00007FFF82DC0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 18:32:01,389 [root] DEBUG: 8372: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 18:32:01,396 [root] DEBUG: 8372: DLL loaded at 0x00007FFF82A50000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 18:32:01,400 [root] DEBUG: 8372: DLL loaded at 0x00007FFF7FC20000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2026-05-28 18:32:01,403 [root] DEBUG: 8372: DLL loaded at 0x00007FFF7D520000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 18:32:01,404 [root] DEBUG: 8372: DLL loaded at 0x00007FFF96220000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 18:32:01,405 [root] DEBUG: 8372: DLL loaded at 0x00007FFF96260000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 18:32:01,407 [root] DEBUG: 8372: DLL loaded at 0x00007FFF7D4D0000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 18:32:01,410 [root] DEBUG: 8372: DLL loaded at 0x00007FFF853A0000: C:\Windows\system32\version (0xa000 bytes).
2026-05-28 18:32:01,413 [root] DEBUG: 8372: Successfully installed hook on COM Object function IWbemServices_ExecQuery
2026-05-28 18:32:01,414 [root] DEBUG: 8372: Successfully installed hook on COM Object function IWbemServices_ExecQueryAsync
2026-05-28 18:32:01,414 [root] DEBUG: 8372: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnum
2026-05-28 18:32:01,415 [root] DEBUG: 8372: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnumAsync
2026-05-28 18:32:01,415 [root] DEBUG: 8372: Successfully installed hook on COM Object function IWbemServices_GetObjectW
2026-05-28 18:32:01,416 [root] DEBUG: 8372: Successfully installed hook on COM Object function IWbemServices_GetObjectAsync
2026-05-28 18:32:01,416 [root] DEBUG: 8372: Successfully installed hook on COM Object function IWbemServices_ExecMethod
2026-05-28 18:32:01,416 [root] DEBUG: 8372: Successfully installed hook on COM Object function IWbemServices_ExecMethodAsync
2026-05-28 18:32:01,458 [root] DEBUG: 8372: DLL loaded at 0x00007FFF8D860000: C:\Windows\system32\fveapi (0xf5000 bytes).
2026-05-28 18:32:01,461 [root] DEBUG: 8372: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:32:01,462 [root] DEBUG: 8372: DLL loaded at 0x00007FFF8E460000: C:\Windows\system32\tbs (0x1b000 bytes).
2026-05-28 18:32:01,475 [root] DEBUG: 9420: DLL loaded at 0x000001BF1FCE0000: C:\Windows\SYSTEM32\tzres (0x3000 bytes).
2026-05-28 18:32:01,477 [root] DEBUG: 8372: DLL loaded at 0x00007FFF91EB0000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-05-28 18:32:01,493 [root] DEBUG: 8372: DLL loaded at 0x00007FFF8D860000: C:\Windows\SYSTEM32\fveapi (0xf5000 bytes).
2026-05-28 18:32:01,522 [root] DEBUG: 8372: DLL loaded at 0x00007FFF96050000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 18:32:01,583 [root] DEBUG: 8372: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:32:01,584 [root] DEBUG: 8372: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:32:01,586 [root] DEBUG: 8372: DLL loaded at 0x00007FFF7FB70000: C:\Windows\SYSTEM32\reinfo (0x30000 bytes).
2026-05-28 18:32:02,579 [root] DEBUG: 7284: DLL loaded at 0x00007FFF960C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 18:32:02,585 [root] DEBUG: 7284: DLL loaded at 0x00007FFF916B0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:32:02,586 [root] DEBUG: 7284: DLL loaded at 0x00007FFF7DDC0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 18:32:03,296 [root] DEBUG: 2380: NtTerminateProcess hook: Attempting to dump process 2380
2026-05-28 18:32:03,297 [root] DEBUG: 2380: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:32:03,319 [root] INFO: Process with pid 2380 has terminated
2026-05-28 18:32:03,825 [root] DEBUG: 7284: DLL loaded at 0x00007FFF7CEE0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 18:32:06,343 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 11572: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:32:06,344 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 11572
2026-05-28 18:32:06,345 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 11572
2026-05-28 18:32:07,492 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 11652: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:32:07,493 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 11652
2026-05-28 18:32:07,495 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 11652
2026-05-28 18:32:07,522 [root] DEBUG: 7284: DLL loaded at 0x00007FFF3A280000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 18:32:07,551 [root] DEBUG: 7284: DLL loaded at 0x00007FFF39C20000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 18:32:07,558 [root] DEBUG: 7284: DLL loaded at 0x00007FFF91760000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 18:32:07,559 [root] DEBUG: 7284: DLL loaded at 0x00007FFF986E0000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 18:32:07,560 [root] DEBUG: 7284: DLL loaded at 0x00007FFF3D070000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 18:32:07,561 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96050000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 18:32:07,562 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8E350000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 18:32:07,565 [root] DEBUG: 7284: DLL loaded at 0x00007FFF83180000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 18:32:07,571 [root] DEBUG: 7284: DLL loaded at 0x00007FFF96A80000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 18:32:07,572 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94F50000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 18:32:07,573 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94F10000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 18:32:07,576 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 11752: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000
2026-05-28 18:32:07,576 [root] DEBUG: 7284: DLL loaded at 0x00007FFF39BA0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 18:32:07,579 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 11752
2026-05-28 18:32:07,579 [lib.api.process] INFO: Monitor config for process 11752: C:\2unxg6vp\dll\11752.ini
2026-05-28 18:32:07,581 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:07,582 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94110000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:32:07,583 [root] DEBUG: 7284: DLL loaded at 0x00007FFF91E70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:32:07,583 [root] DEBUG: 7284: DLL loaded at 0x00007FFF82770000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:32:07,703 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:32:07,703 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:32:07,713 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:07,717 [root] DEBUG: Loader: Injecting process 11752 (thread 11756) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:07,718 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:32:07,719 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:07,721 [lib.api.process] INFO: Injected into 64-bit <Process 11752 identity_helper.exe>
2026-05-28 18:32:07,737 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8E6A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 18:32:07,743 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8B370000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 18:32:07,745 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 11832: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000
2026-05-28 18:32:07,746 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 11832
2026-05-28 18:32:07,746 [lib.api.process] INFO: Monitor config for process 11832: C:\2unxg6vp\dll\11832.ini
2026-05-28 18:32:07,751 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:07,840 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:32:07,840 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:32:07,843 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:07,847 [root] DEBUG: Loader: Injecting process 11832 (thread 11836) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:07,848 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:32:07,848 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:07,849 [lib.api.process] INFO: Injected into 64-bit <Process 11832 identity_helper.exe>
2026-05-28 18:32:07,859 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 11832
2026-05-28 18:32:07,859 [lib.api.process] INFO: Monitor config for process 11832: C:\2unxg6vp\dll\11832.ini
2026-05-28 18:32:07,871 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:07,963 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:32:07,963 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:32:07,965 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:07,970 [root] DEBUG: Loader: Injecting process 11832 (thread 11836) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:07,970 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:32:07,970 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:07,972 [lib.api.process] INFO: Injected into 64-bit <Process 11832 identity_helper.exe>
2026-05-28 18:32:07,992 [root] DEBUG: 11832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:32:07,994 [root] DEBUG: 11832: Interactive desktop enabled.
2026-05-28 18:32:07,995 [root] DEBUG: 11832: Dropped file limit defaulting to 100.
2026-05-28 18:32:08,002 [root] DEBUG: 11832: Disabling sleep skipping.
2026-05-28 18:32:08,003 [root] DEBUG: 11832: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:32:08,009 [root] DEBUG: 7284: DLL loaded at 0x00007FFF85060000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:32:08,011 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8ED20000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 18:32:08,012 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8E370000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 18:32:08,015 [root] DEBUG: 11832: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:32:08,016 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:32:08,042 [root] DEBUG: 11832: Monitor initialised: 64-bit capemon loaded in process 11832 at 0x00007FFF52E70000, thread 11836, image base 0x00007FF61EFC0000, stack from 0x000000AE0A954000-0x000000AE0A960000
2026-05-28 18:32:08,043 [root] DEBUG: 11832: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5952,i,11470755141613762127,4055455473900018829,524288 --field-trial-handle=2264,i,16983387269976259416,4354945647829116387,262144 --variations-seed-version --pseudonymization-salt-handle=2320,i,3707866102701366264,3666518045583744
2026-05-28 18:32:08,044 [root] DEBUG: 11832: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 18:32:08,057 [root] DEBUG: 11832: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:32:08,077 [root] DEBUG: 7284: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 18:32:08,080 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:32:08,080 [root] DEBUG: 11832: set_hooks: Unable to hook LockResource
2026-05-28 18:32:08,085 [root] DEBUG: 11832: Hooked 627 out of 628 functions
2026-05-28 18:32:08,094 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95D10000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 18:32:08,095 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95CD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 18:32:08,095 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8E580000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 18:32:08,096 [root] DEBUG: 7284: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:32:08,097 [root] DEBUG: 7284: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:32:08,098 [root] DEBUG: 7284: DLL loaded at 0x00007FFF834F0000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 18:32:08,100 [root] DEBUG: 11832: Syscall hook installed, syscall logging level 1
2026-05-28 18:32:08,105 [root] DEBUG: 11832: RestoreHeaders: Restored original import table.
2026-05-28 18:32:08,107 [root] INFO: Loaded monitor into process with pid 11832
2026-05-28 18:32:08,108 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994
2026-05-28 18:32:08,170 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994
2026-05-28 18:32:08,195 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994
2026-05-28 18:32:08,218 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994
2026-05-28 18:32:08,248 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994
2026-05-28 18:32:08,273 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994
2026-05-28 18:32:08,289 [root] DEBUG: 7284: DLL loaded at 0x00007FFF95A00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 18:32:08,299 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994
2026-05-28 18:32:08,327 [root] DEBUG: 11832: caller_dispatch: Added region at 0x00007FFF52500000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF526FF156, thread 11836).
2026-05-28 18:32:08,328 [root] DEBUG: 11832: caller_dispatch: Scanning calling region at 0x00007FFF52500000...
2026-05-28 18:32:08,338 [root] DEBUG: 11832: ProcessTrackedRegion: Region at 0x00007FFF52500000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 18:32:08,340 [root] DEBUG: 11832: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 18:32:08,362 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:32:08,382 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:32:08,398 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:32:08,415 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:32:08,431 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:32:08,446 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:32:08,463 [root] DEBUG: 11832: caller_dispatch: Added region at 0x00007FF61EFC0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF61F0B4096, thread 11836).
2026-05-28 18:32:08,464 [root] DEBUG: 11832: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:32:08,480 [root] DEBUG: 11832: ProcessImageBase: Main module image at 0x00007FF61EFC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:32:08,484 [root] DEBUG: 11832: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:32:08,512 [root] DEBUG: 11832: DLL loaded at 0x0000024AC5000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 18:32:08,516 [root] DEBUG: 11832: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:32:08,518 [root] DEBUG: 11832: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:32:08,552 [root] DEBUG: 11832: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:32:08,557 [root] DEBUG: 11832: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:32:08,561 [root] DEBUG: 11832: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:32:08,561 [root] DEBUG: 11832: DLL loaded at 0x00007FFF91EB0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 18:32:08,562 [root] DEBUG: 11832: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:32:08,565 [root] DEBUG: 11832: DLL loaded at 0x00007FFF84D00000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 18:32:08,573 [root] DEBUG: 11832: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:32:08,573 [root] DEBUG: 11832: DLL loaded at 0x00007FFF94110000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:32:08,574 [root] DEBUG: 11832: DLL loaded at 0x00007FFF91E70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:32:08,574 [root] DEBUG: 11832: DLL loaded at 0x00007FFF90DA0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:32:08,575 [root] DEBUG: 11832: DLL loaded at 0x00007FFF82770000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:32:08,586 [root] DEBUG: 11832: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:32:08,592 [root] DEBUG: 11832: DLL loaded at 0x00007FFF833F0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 18:32:08,597 [root] DEBUG: 11832: DLL loaded at 0x00007FFF953C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:32:08,598 [root] DEBUG: 11832: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:32:08,600 [root] DEBUG: 11832: DLL loaded at 0x00007FFF916B0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:32:08,609 [root] DEBUG: 11832: DLL loaded at 0x00007FFF8F850000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 18:32:08,610 [root] DEBUG: 11832: DLL loaded at 0x00007FFF8B820000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:32:08,617 [root] DEBUG: 11832: DLL loaded at 0x00007FFF96A80000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 18:32:08,618 [root] DEBUG: 11832: DLL loaded at 0x00007FFF8E6A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 18:32:08,620 [root] DEBUG: 11832: DLL loaded at 0x00007FFF95E30000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 18:32:08,630 [root] DEBUG: 11832: DLL loaded at 0x00007FFF7D640000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 18:32:08,647 [root] DEBUG: 11832: DLL loaded at 0x00007FFF85060000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:32:08,652 [root] DEBUG: 11832: DLL loaded at 0x00007FFF70D80000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 18:32:08,665 [root] DEBUG: 11832: DLL loaded at 0x00007FFF89AB0000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 18:32:08,665 [root] DEBUG: 11832: DLL loaded at 0x00007FFF89B70000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 18:32:08,666 [root] DEBUG: 11832: DLL loaded at 0x00007FFF82980000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 18:32:08,673 [root] DEBUG: 11832: DLL loaded at 0x00007FFF8ECC0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 18:32:08,675 [root] DEBUG: 11832: DLL loaded at 0x00007FFF7C440000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 18:32:08,682 [root] DEBUG: 11832: DLL loaded at 0x00007FFF95CA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 18:32:08,686 [root] DEBUG: 11832: DLL loaded at 0x00007FFF94410000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:32:08,703 [root] DEBUG: 11832: DLL loaded at 0x00007FFF8A550000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 18:32:08,732 [root] DEBUG: 11832: DLL loaded at 0x00007FFF96AF0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 18:32:08,769 [root] DEBUG: 11832: DLL loaded at 0x00007FFF94BF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 18:32:08,770 [root] DEBUG: 11832: DLL loaded at 0x00007FFF92740000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 18:32:08,778 [root] DEBUG: 11832: DLL loaded at 0x00007FFF87A50000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 18:32:08,779 [root] DEBUG: 11832: DLL loaded at 0x00007FFF7C210000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 18:32:08,791 [root] DEBUG: 11832: DLL loaded at 0x00007FFF7D000000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 18:32:08,810 [root] DEBUG: 11832: DLL loaded at 0x00007FFF96220000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 18:32:08,812 [root] DEBUG: 11832: DLL loaded at 0x00007FFF8B3C0000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 18:32:08,813 [root] DEBUG: 11832: DLL loaded at 0x00007FFF81F70000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 18:32:18,876 [root] INFO: Process with pid 11832 has terminated
2026-05-28 18:32:18,877 [root] DEBUG: 11832: NtTerminateProcess hook: Attempting to dump process 11832
2026-05-28 18:32:18,879 [root] DEBUG: 11832: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:32:29,346 [root] DEBUG: 7284: DLL loaded at 0x00007FFF82E60000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 18:32:29,480 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 8148: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:32:29,481 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 8148
2026-05-28 18:32:29,482 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 8148
2026-05-28 18:32:47,779 [root] DEBUG: 5020: DLL loaded at 0x00007FFF7FB70000: C:\Windows\system32\wbem\ncprov (0x21000 bytes).
2026-05-28 18:32:48,680 [root] DEBUG: 8372: NtTerminateProcess hook: Attempting to dump process 8372
2026-05-28 18:32:48,681 [root] DEBUG: 8372: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:32:48,699 [root] INFO: Process with pid 8372 has terminated
2026-05-28 18:32:52,957 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 3704: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:32:52,959 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3704
2026-05-28 18:32:52,960 [lib.api.process] INFO: Monitor config for process 3704: C:\2unxg6vp\dll\3704.ini
2026-05-28 18:32:52,962 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:52,964 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:52,970 [root] DEBUG: Loader: Injecting process 3704 (thread 3808) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:52,971 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:32:52,975 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:52,976 [lib.api.process] INFO: Injected into 64-bit <Process 3704 dllhost.exe>
2026-05-28 18:32:52,978 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3704
2026-05-28 18:32:52,978 [lib.api.process] INFO: Monitor config for process 3704: C:\2unxg6vp\dll\3704.ini
2026-05-28 18:32:52,979 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:52,981 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:52,987 [root] DEBUG: Loader: Injecting process 3704 (thread 3808) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:52,988 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:32:52,988 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:52,990 [lib.api.process] INFO: Injected into 64-bit <Process 3704 dllhost.exe>
2026-05-28 18:32:52,999 [root] DEBUG: 3704: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:32:53,000 [root] DEBUG: 3704: Interactive desktop enabled.
2026-05-28 18:32:53,000 [root] DEBUG: 3704: Dropped file limit defaulting to 100.
2026-05-28 18:32:53,003 [root] DEBUG: 3704: Disabling sleep skipping.
2026-05-28 18:32:53,004 [root] DEBUG: 3704: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:32:53,016 [root] DEBUG: 3704: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:32:53,017 [root] DEBUG: 3704: YaraScan: Scanning 0x00007FF7BDF50000, size 0x8026
2026-05-28 18:32:53,018 [root] DEBUG: 3704: Monitor initialised: 64-bit capemon loaded in process 3704 at 0x00007FFF52E70000, thread 3808, image base 0x00007FF7BDF50000, stack from 0x0000009287FD4000-0x0000009287FE0000
2026-05-28 18:32:53,019 [root] DEBUG: 3704: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 18:32:53,038 [root] DEBUG: 3704: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:32:53,077 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:32:53,080 [root] DEBUG: 3704: set_hooks: Unable to hook LockResource
2026-05-28 18:32:53,086 [root] DEBUG: 3704: Hooked 627 out of 628 functions
2026-05-28 18:32:53,087 [root] DEBUG: 3704: Syscall hook installed, syscall logging level 1
2026-05-28 18:32:53,092 [root] DEBUG: 3704: RestoreHeaders: Restored original import table.
2026-05-28 18:32:53,093 [root] INFO: Loaded monitor into process with pid 3704
2026-05-28 18:32:53,093 [root] DEBUG: 3704: caller_dispatch: Added region at 0x00007FF7BDF50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7BDF512F2, thread 3808).
2026-05-28 18:32:53,094 [root] DEBUG: 3704: YaraScan: Scanning 0x00007FF7BDF50000, size 0x8026
2026-05-28 18:32:53,095 [root] DEBUG: 3704: ProcessImageBase: Main module image at 0x00007FF7BDF50000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:32:53,097 [root] DEBUG: 3704: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:32:53,098 [root] DEBUG: 3704: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:32:53,101 [root] DEBUG: 3704: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:32:53,123 [root] DEBUG: 3704: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:32:53,139 [root] DEBUG: 3704: DLL loaded at 0x00007FFF95800000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 18:32:53,140 [root] DEBUG: 3704: DLL loaded at 0x00007FFF95850000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 18:32:53,141 [root] DEBUG: 3704: DLL loaded at 0x00007FFF8EAB0000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:32:53,143 [root] DEBUG: 3704: DLL loaded at 0x00007FFF90780000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 18:32:53,144 [root] DEBUG: 3704: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:32:53,144 [root] DEBUG: 3704: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:32:53,145 [root] DEBUG: 3704: DLL loaded at 0x00007FFF956F0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:32:53,146 [root] DEBUG: 3704: DLL loaded at 0x00007FFF96220000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 18:32:53,146 [root] DEBUG: 3704: DLL loaded at 0x00007FFF96260000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 18:32:53,147 [root] DEBUG: 3704: DLL loaded at 0x00007FFF91E70000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 18:32:53,149 [root] DEBUG: 3704: DLL loaded at 0x00007FFF95730000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 18:32:53,150 [root] DEBUG: 3704: DLL loaded at 0x00007FFF3A0B0000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 18:32:53,152 [root] DEBUG: 3704: DLL loaded at 0x00007FFF98020000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 18:32:53,158 [root] DEBUG: 3704: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:32:53,648 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 8032: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF6D47B0000
2026-05-28 18:32:53,649 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 8032
2026-05-28 18:32:53,650 [lib.api.process] INFO: Monitor config for process 8032: C:\2unxg6vp\dll\8032.ini
2026-05-28 18:32:53,651 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:53,654 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:53,660 [root] DEBUG: Loader: Injecting process 8032 (thread 4572) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:53,661 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:32:53,662 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:53,663 [lib.api.process] INFO: Injected into 64-bit <Process 8032 MoUsoCoreWorker.exe>
2026-05-28 18:32:53,664 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 8032
2026-05-28 18:32:53,665 [lib.api.process] INFO: Monitor config for process 8032: C:\2unxg6vp\dll\8032.ini
2026-05-28 18:32:53,665 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:53,667 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:53,671 [root] DEBUG: Loader: Injecting process 8032 (thread 4572) with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:53,672 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:32:53,672 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:53,674 [lib.api.process] INFO: Injected into 64-bit <Process 8032 MoUsoCoreWorker.exe>
2026-05-28 18:32:53,694 [root] DEBUG: 8032: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:32:53,695 [root] DEBUG: 8032: Interactive desktop enabled.
2026-05-28 18:32:53,696 [root] DEBUG: 8032: Dropped file limit defaulting to 100.
2026-05-28 18:32:53,700 [root] DEBUG: 8032: VerifyCodeSection: Exception rebasing image from 0x00007FF6D47B0000 to 0x0000000140000000.
2026-05-28 18:32:53,703 [root] DEBUG: 8032: Disabling sleep skipping.
2026-05-28 18:32:53,705 [root] DEBUG: 8032: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:32:53,716 [root] DEBUG: 8032: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:32:53,717 [root] DEBUG: 8032: YaraScan: Scanning 0x00007FF6D47B0000, size 0x1ad000
2026-05-28 18:32:53,728 [root] DEBUG: 8032: Monitor initialised: 64-bit capemon loaded in process 8032 at 0x00007FFF52E70000, thread 4572, image base 0x00007FF6D47B0000, stack from 0x0000003FA3D54000-0x0000003FA3D60000
2026-05-28 18:32:53,728 [root] DEBUG: 8032: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-05-28 18:32:53,740 [root] DEBUG: 8032: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:32:53,762 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:32:53,763 [root] DEBUG: 8032: set_hooks: Unable to hook LockResource
2026-05-28 18:32:53,776 [root] DEBUG: 8032: Hooked 627 out of 628 functions
2026-05-28 18:32:53,792 [root] DEBUG: 8032: Syscall hook installed, syscall logging level 1
2026-05-28 18:32:53,797 [root] DEBUG: 8032: RestoreHeaders: Restored original import table.
2026-05-28 18:32:53,798 [root] INFO: Loaded monitor into process with pid 8032
2026-05-28 18:32:53,809 [root] DEBUG: 8032: caller_dispatch: Added region at 0x00007FF6D47B0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x00007FF6D48D1219, thread 4572).
2026-05-28 18:32:53,810 [root] DEBUG: 8032: YaraScan: Scanning 0x00007FF6D47B0000, size 0x1ad000
2026-05-28 18:32:53,822 [root] DEBUG: 8032: ProcessImageBase: Main module image at 0x00007FF6D47B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:32:53,826 [root] DEBUG: 8032: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:32:53,828 [root] DEBUG: 8032: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:32:53,856 [root] DEBUG: 8032: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 18:32:53,882 [root] DEBUG: 8032: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:32:53,901 [root] DEBUG: 8032: DLL loaded at 0x00007FFF7DE30000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-05-28 18:32:54,131 [root] DEBUG: 8032: DLL loaded at 0x00007FFF90780000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 18:32:54,134 [root] DEBUG: 8032: DLL loaded at 0x00007FFF960B0000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 18:32:54,135 [root] DEBUG: 8032: DLL loaded at 0x00007FFF392B0000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-05-28 18:32:54,142 [root] DEBUG: 8032: DLL loaded at 0x00007FFF80CA0000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 18:32:54,144 [root] DEBUG: 8032: DLL loaded at 0x00007FFF93940000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 18:32:54,146 [root] DEBUG: 8032: DLL loaded at 0x00007FFF91FE0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 18:32:54,149 [root] DEBUG: 8032: DLL loaded at 0x00007FFF95FF0000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-05-28 18:32:54,254 [root] DEBUG: 8032: DLL loaded at 0x00007FFF93940000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 18:32:54,591 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38EE0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 18:32:54,594 [root] DEBUG: 4676: DLL loaded at 0x00007FFF869C0000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 18:32:54,602 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38EC0000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 18:32:54,606 [root] DEBUG: 4676: DLL loaded at 0x00007FFF3A6D0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 18:32:54,608 [root] DEBUG: 4676: DLL loaded at 0x00007FFF94030000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 18:32:54,609 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38DE0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 18:32:54,636 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38DC0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 18:32:54,648 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38CD0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 18:32:56,114 [root] DEBUG: 8032: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 18:32:58,173 [root] INFO: Process with pid 3704 has terminated
2026-05-28 18:32:58,175 [root] DEBUG: 3704: NtTerminateProcess hook: Attempting to dump process 3704
2026-05-28 18:32:58,176 [root] DEBUG: 3704: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:32:58,495 [root] DEBUG: 8032: DLL loaded at 0x00007FFF953C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:32:58,496 [root] DEBUG: 8032: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:32:58,504 [root] DEBUG: 8032: DLL loaded at 0x00007FFF3A110000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 18:32:58,505 [root] DEBUG: 8032: DLL loaded at 0x00007FFF80EB0000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 18:32:58,508 [root] DEBUG: 8032: DLL loaded at 0x00007FFF82B00000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 18:32:58,511 [root] DEBUG: 8032: DLL loaded at 0x00007FFF8E350000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 18:32:58,517 [root] DEBUG: 8032: DLL loaded at 0x00007FFF92180000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 18:32:58,525 [root] DEBUG: 8032: DLL loaded at 0x00007FFF7D020000: C:\Windows\SYSTEM32\productenumerator (0xe000 bytes).
2026-05-28 18:32:58,928 [root] INFO: Stopping Task Scheduler Service
2026-05-28 18:32:58,943 [root] INFO: Stopped Task Scheduler Service
2026-05-28 18:32:58,951 [root] INFO: Starting Task Scheduler Service
2026-05-28 18:32:58,966 [root] INFO: Started Task Scheduler Service
2026-05-28 18:32:58,968 [lib.api.process] INFO: Monitor config for process 1384: C:\2unxg6vp\dll\1384.ini
2026-05-28 18:32:58,971 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:32:58,977 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\qmRoKOe.dll, loader C:\2unxg6vp\bin\eOrEOjSc.exe
2026-05-28 18:32:58,983 [root] DEBUG: Loader: Injecting process 1384 with C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:58,985 [root] DEBUG: 1384: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:32:58,987 [root] DEBUG: 1384: Disabling sleep skipping.
2026-05-28 18:32:58,989 [root] DEBUG: 1384: Interactive desktop enabled.
2026-05-28 18:32:58,990 [root] DEBUG: 1384: Dropped file limit defaulting to 100.
2026-05-28 18:32:58,994 [root] DEBUG: 1384: Services hook set enabled
2026-05-28 18:32:58,997 [root] DEBUG: 1384: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:32:59,014 [root] DEBUG: 1384: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:32:59,015 [root] DEBUG: 1384: Monitor initialised: 64-bit capemon loaded in process 1384 at 0x00007FFF52E70000, thread 13104, image base 0x00007FF71F590000, stack from 0x000000173BDF4000-0x000000173BE00000
2026-05-28 18:32:59,016 [root] DEBUG: 1384: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-28 18:32:59,028 [root] DEBUG: 1384: Hooked 69 out of 69 functions
2026-05-28 18:32:59,030 [root] INFO: Loaded monitor into process with pid 1384
2026-05-28 18:32:59,034 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:32:59,036 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\qmRoKOe.dll.
2026-05-28 18:32:59,039 [lib.api.process] INFO: Injected into 64-bit <Process 1384 svchost.exe>
2026-05-28 18:32:59,459 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94E40000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 18:32:59,460 [root] DEBUG: 7284: DLL loaded at 0x00007FFF94E70000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-28 18:32:59,461 [root] DEBUG: 7284: DLL loaded at 0x00007FFF391C0000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-28 18:32:59,476 [root] DEBUG: 7284: DLL loaded at 0x00007FFF391A0000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 18:32:59,551 [root] DEBUG: 7284: CreateProcessHandler: Injection info set for new process 13228: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:32:59,552 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 13228
2026-05-28 18:32:59,554 [root] DEBUG: 7284: ProcessMessage: Skipping monitoring process 13228
2026-05-28 18:32:59,691 [root] DEBUG: 7284: DLL loaded at 0x00007FFF39030000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-28 18:33:00,080 [root] INFO: Announced starting service "b'BITS'"
2026-05-28 18:33:01,054 [root] DEBUG: 8032: DLL loaded at 0x00007FFF913D0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 18:33:01,108 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-28 18:33:02,141 [root] DEBUG: 8032: DLL loaded at 0x0000018CEB640000: C:\Windows\system32\WaaSMedicPS (0xc000 bytes).
2026-05-28 18:33:02,285 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\237c6c609dce209c2cbaaace9f781120c6935b987fc61fc6fc2ecc5ea9c4892b; Size is 8720; Max size: 100000000
2026-05-28 18:33:02,319 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\80ef5df696bf1f3c09c36b276d4bc0a81d7a1e83e970c10d466fd42ce5f239e2; Size is 8720; Max size: 100000000
2026-05-28 18:33:02,386 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\866fe1662e0c3fac01b71d4b39b0f0bee2d7411e841de5b85c19741d1af11d90; Size is 8720; Max size: 100000000
2026-05-28 18:33:02,409 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\5459aaa7b94b326d2321e6e5a992ca0a4a9d36780f94b66fac585854ed582f5a; Size is 8720; Max size: 100000000
2026-05-28 18:33:02,437 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\418e6950457c5d3dc17c89249ac7da769bbbcbf2247411e8898f511f45c65624; Size is 8720; Max size: 100000000
2026-05-28 18:33:02,572 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\e910871b6e02883f21522e53168ffe0a267f7e309af573325892e5a1f1eed49d; Size is 12824; Max size: 100000000
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 18:31:38 | 2026-05-28 18:33:15 | none |
Seek in progress...
No results found.
No behavioral analysis data available.
No dropped files found.