| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 18:39:48 | 2026-05-28 18:40:28 | 40s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 18:30:47,539 [root] INFO: Date set to: 20260528T18:39:54, timeout set to: 200 2026-05-28 18:39:54,008 [root] DEBUG: Starting analyzer from: C:\2unxg6vp 2026-05-28 18:39:54,009 [root] DEBUG: Storing results at: C:\VIcpuJ 2026-05-28 18:39:54,009 [root] DEBUG: Pipe server name: \\.\PIPE\ErNkLiu 2026-05-28 18:39:54,009 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64 2026-05-28 18:39:54,009 [root] INFO: analysis running as an admin 2026-05-28 18:39:54,009 [root] INFO: analysis package specified: "edge" 2026-05-28 18:39:54,010 [root] DEBUG: importing analysis package module: "modules.packages.edge"... 2026-05-28 18:39:54,012 [root] DEBUG: imported analysis package "edge" 2026-05-28 18:39:54,012 [root] DEBUG: initializing analysis package "edge"... 2026-05-28 18:39:54,012 [root] DEBUG: New location of moved file: https://sugarcraft.net/ 2026-05-28 18:39:54,012 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option 2026-05-28 18:39:54,013 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option 2026-05-28 18:39:54,013 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option 2026-05-28 18:39:54,013 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option 2026-05-28 18:39:54,031 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2026-05-28 18:39:54,090 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2026-05-28 18:39:54,115 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2026-05-28 18:39:54,123 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2026-05-28 18:39:54,128 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-05-28 18:39:54,128 [lib.api.screenshot] ERROR: No module named 'PIL' 2026-05-28 18:39:54,129 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots" 2026-05-28 18:39:54,130 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2026-05-28 18:39:54,130 [root] DEBUG: Initialized auxiliary module "Browser" 2026-05-28 18:39:54,130 [root] DEBUG: attempting to configure 'Browser' from data 2026-05-28 18:39:54,131 [root] DEBUG: module Browser does not support data configuration, ignoring 2026-05-28 18:39:54,131 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2026-05-28 18:39:54,131 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2026-05-28 18:39:54,132 [root] DEBUG: Initialized auxiliary module "DigiSig" 2026-05-28 18:39:54,132 [root] DEBUG: attempting to configure 'DigiSig' from data 2026-05-28 18:39:54,132 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2026-05-28 18:39:54,133 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2026-05-28 18:39:54,133 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file 2026-05-28 18:39:54,133 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2026-05-28 18:39:54,133 [root] DEBUG: Initialized auxiliary module "Disguise" 2026-05-28 18:39:54,133 [root] DEBUG: attempting to configure 'Disguise' from data 2026-05-28 18:39:54,134 [root] DEBUG: module Disguise does not support data configuration, ignoring 2026-05-28 18:39:54,134 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2026-05-28 18:39:54,136 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 9076) 2026-05-28 18:39:54,136 [modules.auxiliary.disguise] INFO: Disguising GUID to c4c51385-09ca-4586-b0d1-9de74128966f 2026-05-28 18:39:54,137 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2026-05-28 18:39:54,137 [root] DEBUG: Initialized auxiliary module "Human" 2026-05-28 18:39:54,137 [root] DEBUG: attempting to configure 'Human' from data 2026-05-28 18:39:54,137 [root] DEBUG: module Human does not support data configuration, ignoring 2026-05-28 18:39:54,137 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2026-05-28 18:39:54,138 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2026-05-28 18:39:54,138 [root] DEBUG: Initialized auxiliary module "Screenshots" 2026-05-28 18:39:54,138 [root] DEBUG: attempting to configure 'Screenshots' from data 2026-05-28 18:39:54,139 [root] DEBUG: module Screenshots does not support data configuration, ignoring 2026-05-28 18:39:54,139 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"... 2026-05-28 18:39:54,139 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2026-05-28 18:39:54,139 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots 2026-05-28 18:39:54,139 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2026-05-28 18:39:54,139 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2026-05-28 18:39:54,140 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2026-05-28 18:39:54,140 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2026-05-28 18:39:54,141 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process 2026-05-28 18:39:54,141 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2026-05-28 18:39:54,142 [root] INFO: Interactive mode enabled - injecting into explorer shell 2026-05-28 18:39:54,169 [lib.api.process] INFO: Monitor config for process 4676: C:\2unxg6vp\dll\4676.ini 2026-05-28 18:39:54,170 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:39:54,173 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\VoSHwIb.dll, loader C:\2unxg6vp\bin\BNPlngov.exe 2026-05-28 18:39:54,196 [root] DEBUG: Loader: Injecting process 4676 with C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:39:54,364 [root] DEBUG: 4676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 18:39:54,366 [root] DEBUG: 4676: Disabling sleep skipping. 2026-05-28 18:39:54,367 [root] DEBUG: 4676: Interactive desktop enabled. 2026-05-28 18:39:54,367 [root] DEBUG: 4676: Dropped file limit defaulting to 100. 2026-05-28 18:39:54,368 [root] DEBUG: 4676: Interactive desktop - injecting Explorer Shell 2026-05-28 18:39:54,375 [root] DEBUG: 4676: YaraInit: Compiled 44 rule files 2026-05-28 18:39:54,377 [root] DEBUG: 4676: YaraInit: Compiled rules saved to file C:\2unxg6vp\data\yara\capemon.yac 2026-05-28 18:39:54,393 [root] DEBUG: 4676: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0 2026-05-28 18:39:54,394 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316 2026-05-28 18:39:54,450 [root] DEBUG: 4676: Monitor initialised: 64-bit capemon loaded in process 4676 at 0x00007FFF52E70000, thread 960, image base 0x00007FF663980000, stack from 0x0000000010E51000-0x0000000010E60000 2026-05-28 18:39:54,451 [root] DEBUG: 4676: Commandline: C:\Windows\Explorer.EXE 2026-05-28 18:39:54,465 [root] DEBUG: 4676: Hooked 69 out of 69 functions 2026-05-28 18:39:54,494 [root] DEBUG: 4676: Syscall hook installed, syscall logging level 1 2026-05-28 18:39:54,501 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-05-28 18:39:54,501 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:39:54,503 [lib.api.process] INFO: Injected into 64-bit <Process 4676 explorer.exe> 2026-05-28 18:40:01,803 [root] INFO: Restarting WMI Service 2026-05-28 18:40:03,848 [root] DEBUG: package modules.packages.edge does not support configure, ignoring 2026-05-28 18:40:03,850 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages' 2026-05-28 18:40:03,852 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation 2026-05-28 18:40:03,857 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://sugarcraft.net/"" with pid 6572 2026-05-28 18:40:03,859 [lib.api.process] INFO: Monitor config for process 6572: C:\2unxg6vp\dll\6572.ini 2026-05-28 18:40:03,862 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:40:03,866 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\VoSHwIb.dll, loader C:\2unxg6vp\bin\BNPlngov.exe 2026-05-28 18:40:03,881 [root] DEBUG: Loader: Injecting process 6572 (thread 6536) with C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:03,882 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 18:40:03,884 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:03,886 [lib.api.process] INFO: Injected into 64-bit <Process 6572 msedge.exe> 2026-05-28 18:40:05,899 [lib.api.process] INFO: Successfully resumed process with pid 6572 2026-05-28 18:40:05,986 [root] DEBUG: 6572: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 18:40:05,987 [root] DEBUG: 6572: Disabling sleep skipping. 2026-05-28 18:40:05,987 [root] DEBUG: 6572: Interactive desktop enabled. 2026-05-28 18:40:05,987 [root] DEBUG: 6572: Dropped file limit defaulting to 100. 2026-05-28 18:40:05,995 [root] DEBUG: 6572: Edge-specific hook-set enabled. 2026-05-28 18:40:05,999 [root] DEBUG: 6572: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac 2026-05-28 18:40:06,012 [root] DEBUG: 6572: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0 2026-05-28 18:40:06,012 [root] DEBUG: 6572: Monitor initialised: 64-bit capemon loaded in process 6572 at 0x00007FFF52E70000, thread 6536, image base 0x00007FF6F9430000, stack from 0x00000024BB7F4000-0x00000024BB800000 2026-05-28 18:40:06,013 [root] DEBUG: 6572: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://sugarcraft.net/" 2026-05-28 18:40:06,022 [root] DEBUG: 6572: Hooked 2 out of 2 functions 2026-05-28 18:40:06,056 [root] DEBUG: 6572: Syscall hook installed, syscall logging level 1 2026-05-28 18:40:06,061 [root] DEBUG: 6572: RestoreHeaders: Restored original import table. 2026-05-28 18:40:06,061 [root] INFO: Loaded monitor into process with pid 6572 2026-05-28 18:40:06,065 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptprimitives (0x82000 bytes). 2026-05-28 18:40:06,071 [root] DEBUG: 6572: DLL loaded at 0x00007FFF853A0000: C:\Windows\SYSTEM32\version (0xa000 bytes). 2026-05-28 18:40:06,072 [root] DEBUG: 6572: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes). 2026-05-28 18:40:06,074 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95CA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes). 2026-05-28 18:40:06,074 [root] DEBUG: 6572: DLL loaded at 0x00007FFF94410000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes). 2026-05-28 18:40:06,075 [root] DEBUG: 6572: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\SHCORE (0xad000 bytes). 2026-05-28 18:40:06,076 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-05-28 18:40:06,219 [root] DEBUG: 6572: DLL loaded at 0x00007FFF84A60000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes). 2026-05-28 18:40:06,220 [root] DEBUG: 6572: DLL loaded at 0x00007FFF3EE40000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes). 2026-05-28 18:40:06,223 [root] DEBUG: 6572: DLL loaded at 0x00007FFF833E0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes). 2026-05-28 18:40:06,226 [root] DEBUG: 6572: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-05-28 18:40:06,232 [root] DEBUG: 6572: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-05-28 18:40:06,233 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 6320: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:40:06,233 [root] DEBUG: 6572: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-05-28 18:40:06,233 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 6320 2026-05-28 18:40:06,234 [root] DEBUG: 6572: DLL loaded at 0x00007FFF92010000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes). 2026-05-28 18:40:06,234 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 6320 2026-05-28 18:40:06,235 [root] DEBUG: 6572: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:40:06,235 [root] DEBUG: 6572: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 18:40:06,239 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96220000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes). 2026-05-28 18:40:06,240 [root] DEBUG: 6572: DLL loaded at 0x00007FFF94BC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes). 2026-05-28 18:40:06,241 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95490000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes). 2026-05-28 18:40:06,242 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95850000: C:\Windows\SYSTEM32\netutils (0xc000 bytes). 2026-05-28 18:40:06,242 [root] DEBUG: 6572: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:40:06,243 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8C000000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes). 2026-05-28 18:40:06,244 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes). 2026-05-28 18:40:06,245 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes). 2026-05-28 18:40:06,245 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95D10000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes). 2026-05-28 18:40:06,246 [root] DEBUG: 6572: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes). 2026-05-28 18:40:06,246 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes). 2026-05-28 18:40:06,246 [root] DEBUG: 6572: DLL loaded at 0x00007FFF82660000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes). 2026-05-28 18:40:06,247 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8BFC0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes). 2026-05-28 18:40:06,248 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes). 2026-05-28 18:40:06,248 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95CD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes). 2026-05-28 18:40:06,251 [root] DEBUG: 6572: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes). 2026-05-28 18:40:06,253 [root] DEBUG: 6572: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:40:06,254 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes). 2026-05-28 18:40:06,254 [root] DEBUG: 6572: DLL loaded at 0x00007FFF92030000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes). 2026-05-28 18:40:06,256 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96260000: C:\Windows\SYSTEM32\profapi (0x25000 bytes). 2026-05-28 18:40:06,263 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8C050000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes). 2026-05-28 18:40:06,264 [root] DEBUG: 6572: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes). 2026-05-28 18:40:06,265 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8CEF0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes). 2026-05-28 18:40:06,266 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes). 2026-05-28 18:40:06,266 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes). 2026-05-28 18:40:06,268 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8A140000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes). 2026-05-28 18:40:06,272 [root] DEBUG: 6572: DLL loaded at 0x00007FFF82ED0000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes). 2026-05-28 18:40:06,273 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8F850000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes). 2026-05-28 18:40:06,274 [root] DEBUG: 6572: DLL loaded at 0x00007FFF960B0000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes). 2026-05-28 18:40:06,275 [root] DEBUG: 6572: DLL loaded at 0x00007FFF956F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes). 2026-05-28 18:40:06,276 [root] DEBUG: 6572: DLL loaded at 0x00007FFF91940000: C:\Windows\system32\NLAapi (0x1d000 bytes). 2026-05-28 18:40:06,277 [root] DEBUG: 6572: DLL loaded at 0x00007FFF98020000: C:\Windows\System32\NSI (0x8000 bytes). 2026-05-28 18:40:06,278 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96AF0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-05-28 18:40:06,279 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8EAD0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes). 2026-05-28 18:40:06,280 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8BEB0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes). 2026-05-28 18:40:06,282 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8EAB0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes). 2026-05-28 18:40:06,285 [root] DEBUG: 6572: DLL loaded at 0x00007FFF91EB0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes). 2026-05-28 18:40:06,286 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95730000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes). 2026-05-28 18:40:06,288 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8B820000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-05-28 18:40:06,291 [root] DEBUG: 6572: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-05-28 18:40:06,291 [root] DEBUG: 6572: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes). 2026-05-28 18:40:06,292 [root] DEBUG: 6572: DLL loaded at 0x00007FFF93160000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes). 2026-05-28 18:40:06,292 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8A6E0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-05-28 18:40:06,293 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8B750000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes). 2026-05-28 18:40:06,296 [root] DEBUG: 6572: DLL loaded at 0x00007FFF90DA0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes). 2026-05-28 18:40:06,297 [root] DEBUG: 6572: DLL loaded at 0x00007FFF82BC0000: C:\Windows\system32\twinapi (0xa9000 bytes). 2026-05-28 18:40:06,298 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8A550000: C:\Windows\system32\mssprxy (0x28000 bytes). 2026-05-28 18:40:06,300 [root] DEBUG: 6572: DLL loaded at 0x00007FFF905B0000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes). 2026-05-28 18:40:06,303 [root] DEBUG: 6572: DLL loaded at 0x00007FFF86740000: C:\Windows\SYSTEM32\edputil (0x24000 bytes). 2026-05-28 18:40:06,304 [root] DEBUG: 6572: DLL loaded at 0x00007FFF90FB0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes). 2026-05-28 18:40:06,304 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8A580000: C:\Windows\System32\InputHost (0x152000 bytes). 2026-05-28 18:40:06,305 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8A7E0000: C:\Windows\System32\Windows.UI (0x141000 bytes). 2026-05-28 18:40:06,307 [root] DEBUG: 6572: DLL loaded at 0x00007FFF91FE0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes). 2026-05-28 18:40:06,309 [root] DEBUG: 6572: DLL loaded at 0x00007FFF90620000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes). 2026-05-28 18:40:06,310 [root] DEBUG: 6572: DLL loaded at 0x00007FFF90660000: C:\Windows\SYSTEM32\mscms (0xae000 bytes). 2026-05-28 18:40:06,311 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95FF0000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes). 2026-05-28 18:40:06,314 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8C3B0000: C:\Windows\System32\iertutil (0x2bc000 bytes). 2026-05-28 18:40:06,318 [root] DEBUG: 6572: DLL loaded at 0x00007FFF865D0000: C:\Windows\System32\Windows.Web (0xc3000 bytes). 2026-05-28 18:40:06,322 [root] DEBUG: 6572: DLL loaded at 0x00007FFF90780000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes). 2026-05-28 18:40:06,326 [root] DEBUG: 6572: DLL loaded at 0x00007FFF3D4E0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes). 2026-05-28 18:40:06,337 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 9044: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:40:06,338 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 9044 2026-05-28 18:40:06,339 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 9044 2026-05-28 18:40:06,340 [root] DEBUG: 6572: caller_dispatch: Added region at 0x00007FF6F9430000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF6F9527D66, thread 8340). 2026-05-28 18:40:06,344 [root] DEBUG: 6572: ProcessImageBase: Main module image at 0x00007FF6F9430000 unmodified (entropy change 0.000000e+00) 2026-05-28 18:40:06,345 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8A3C0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes). 2026-05-28 18:40:06,346 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 8964: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:40:06,347 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 8964 2026-05-28 18:40:06,347 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 8964 2026-05-28 18:40:06,348 [root] DEBUG: 6572: DLL loaded at 0x00007FFF960C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes). 2026-05-28 18:40:06,366 [root] DEBUG: 6572: DLL loaded at 0x00007FFF916B0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes). 2026-05-28 18:40:06,367 [root] DEBUG: 6572: DLL loaded at 0x00007FFF7DDC0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes). 2026-05-28 18:40:06,387 [root] DEBUG: 6572: DLL loaded at 0x00007FFF87320000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes). 2026-05-28 18:40:06,449 [root] DEBUG: 6572: DLL loaded at 0x00007FFF853F0000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes). 2026-05-28 18:40:06,461 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 2120: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:40:06,463 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 2120 2026-05-28 18:40:06,465 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 2120 2026-05-28 18:40:06,507 [root] DEBUG: 6572: DLL loaded at 0x00007FFF94BF0000: C:\Windows\system32\dxgi (0xf3000 bytes). 2026-05-28 18:40:06,508 [root] DEBUG: 6572: DLL loaded at 0x00007FFF92740000: C:\Windows\system32\d3d11 (0x263000 bytes). 2026-05-28 18:40:06,508 [root] DEBUG: 6572: DLL loaded at 0x00007FFF929B0000: C:\Windows\system32\dcomp (0x1e3000 bytes). 2026-05-28 18:40:06,509 [root] DEBUG: 6572: DLL loaded at 0x00007FFF80590000: C:\Windows\system32\dataexchange (0x3e000 bytes). 2026-05-28 18:40:06,530 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8BF90000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes). 2026-05-28 18:40:06,544 [root] DEBUG: 6572: DLL loaded at 0x00007FFF93E40000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes). 2026-05-28 18:40:06,550 [root] DEBUG: 6572: DLL loaded at 0x00007FFF80840000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes). 2026-05-28 18:40:06,551 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 2796: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:40:06,551 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 3212: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:40:06,552 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 2796 2026-05-28 18:40:06,552 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 3212 2026-05-28 18:40:06,552 [root] DEBUG: 6572: DLL loaded at 0x00007FFF877F0000: C:\Windows\system32\directmanipulation (0x9d000 bytes). 2026-05-28 18:40:06,553 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 2796 2026-05-28 18:40:06,553 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 3212 2026-05-28 18:40:06,591 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316 2026-05-28 18:40:06,594 [root] DEBUG: 4676: caller_dispatch: Added region at 0x00007FF663980000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF6639ACA89, thread 4900). 2026-05-28 18:40:06,595 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316 2026-05-28 18:40:06,639 [root] DEBUG: 6572: DLL loaded at 0x00007FFF81570000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes). 2026-05-28 18:40:06,640 [root] DEBUG: 4676: ProcessImageBase: Main module image at 0x00007FF663980000 unmodified (entropy change 0.000000e+00) 2026-05-28 18:40:06,641 [root] DEBUG: 4676: ProcessImageBase: Main module image at 0x00007FF663980000 unmodified (entropy change 0.000000e+00) 2026-05-28 18:40:06,694 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95E30000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes). 2026-05-28 18:40:06,700 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes). 2026-05-28 18:40:06,703 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95330000: C:\Windows\system32\rsaenh (0x34000 bytes). 2026-05-28 18:40:06,720 [root] DEBUG: 6572: DLL loaded at 0x00007FFF84F00000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes). 2026-05-28 18:40:06,732 [root] DEBUG: 6572: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes). 2026-05-28 18:40:06,734 [root] DEBUG: 6572: DLL loaded at 0x00007FFF78140000: C:\Windows\System32\vaultcli (0x51000 bytes). 2026-05-28 18:40:06,764 [root] DEBUG: 6572: DLL loaded at 0x00007FFF7FB90000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes). 2026-05-28 18:40:06,816 [root] DEBUG: 4676: DLL loaded at 0x00007FFF7C210000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes). 2026-05-28 18:40:07,873 [root] DEBUG: 6572: DLL loaded at 0x00007FFF7CEE0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes). 2026-05-28 18:40:08,244 [root] DEBUG: 6572: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:40:08,245 [root] DEBUG: 6572: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 18:40:13,330 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 5760: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:40:13,331 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 5760 2026-05-28 18:40:13,332 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 5760 2026-05-28 18:40:14,408 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 1688: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:40:14,410 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 1688 2026-05-28 18:40:14,411 [root] DEBUG: 6572: ProcessMessage: Skipping monitoring process 1688 2026-05-28 18:40:14,439 [root] DEBUG: 6572: DLL loaded at 0x00007FFF3A630000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes). 2026-05-28 18:40:14,482 [root] DEBUG: 6572: DLL loaded at 0x00007FFF986E0000: C:\Windows\System32\SETUPAPI (0x46e000 bytes). 2026-05-28 18:40:14,485 [root] DEBUG: 6572: DLL loaded at 0x00007FFF91760000: C:\Windows\System32\netprofm (0x3f000 bytes). 2026-05-28 18:40:14,487 [root] DEBUG: 6572: DLL loaded at 0x00007FFF39FD0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes). 2026-05-28 18:40:14,492 [root] DEBUG: 6572: DLL loaded at 0x00007FFF3D070000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes). 2026-05-28 18:40:14,493 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96050000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes). 2026-05-28 18:40:14,494 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8E350000: C:\Windows\System32\npmproxy (0x10000 bytes). 2026-05-28 18:40:14,495 [root] DEBUG: 6572: DLL loaded at 0x00007FFF96A80000: C:\Windows\System32\WINTRUST (0x67000 bytes). 2026-05-28 18:40:14,500 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8BF70000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes). 2026-05-28 18:40:14,501 [root] DEBUG: 6572: DLL loaded at 0x00007FFF94F50000: C:\Windows\System32\FirewallAPI (0x96000 bytes). 2026-05-28 18:40:14,504 [root] DEBUG: 6572: DLL loaded at 0x00007FFF94F10000: C:\Windows\System32\fwbase (0x36000 bytes). 2026-05-28 18:40:14,509 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 7864: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000 2026-05-28 18:40:14,510 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 7864 2026-05-28 18:40:14,511 [lib.api.process] INFO: Monitor config for process 7864: C:\2unxg6vp\dll\7864.ini 2026-05-28 18:40:14,511 [root] DEBUG: 6572: DLL loaded at 0x00007FFF7FAB0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes). 2026-05-28 18:40:14,512 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:40:14,519 [root] DEBUG: 6572: DLL loaded at 0x00007FFF94110000: C:\Windows\System32\RMCLIENT (0x2a000 bytes). 2026-05-28 18:40:14,520 [root] DEBUG: 6572: DLL loaded at 0x00007FFF91E70000: C:\Windows\System32\XmlLite (0x36000 bytes). 2026-05-28 18:40:14,520 [root] DEBUG: 6572: DLL loaded at 0x00007FFF82770000: C:\Windows\System32\wpnapps (0x15b000 bytes). 2026-05-28 18:40:14,915 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 18:40:14,915 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 18:40:14,919 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\VoSHwIb.dll, loader C:\2unxg6vp\bin\BNPlngov.exe 2026-05-28 18:40:14,923 [root] DEBUG: Loader: Injecting process 7864 (thread 8896) with C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:14,924 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 18:40:14,924 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:14,927 [lib.api.process] INFO: Injected into 64-bit <Process 7864 identity_helper.exe> 2026-05-28 18:40:14,973 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8E6A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes). 2026-05-28 18:40:14,982 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8B370000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes). 2026-05-28 18:40:14,983 [root] DEBUG: 6572: CreateProcessHandler: Injection info set for new process 9276: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000 2026-05-28 18:40:14,984 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9276 2026-05-28 18:40:14,984 [lib.api.process] INFO: Monitor config for process 9276: C:\2unxg6vp\dll\9276.ini 2026-05-28 18:40:14,985 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:40:15,024 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8E370000: C:\Windows\system32\wlanapi (0x74000 bytes). 2026-05-28 18:40:15,032 [root] DEBUG: 6572: DLL loaded at 0x00007FFF85060000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes). 2026-05-28 18:40:15,034 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8ED20000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes). 2026-05-28 18:40:15,068 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 18:40:15,069 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 18:40:15,070 [root] DEBUG: 6572: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes). 2026-05-28 18:40:15,073 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\VoSHwIb.dll, loader C:\2unxg6vp\bin\BNPlngov.exe 2026-05-28 18:40:15,078 [root] DEBUG: Loader: Injecting process 9276 (thread 9280) with C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:15,079 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 18:40:15,079 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:15,081 [lib.api.process] INFO: Injected into 64-bit <Process 9276 identity_helper.exe> 2026-05-28 18:40:15,083 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9276 2026-05-28 18:40:15,084 [lib.api.process] INFO: Monitor config for process 9276: C:\2unxg6vp\dll\9276.ini 2026-05-28 18:40:15,084 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:40:15,091 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95D10000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes). 2026-05-28 18:40:15,091 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95CD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes). 2026-05-28 18:40:15,092 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8E580000: C:\Windows\system32\PCPKsp (0x118000 bytes). 2026-05-28 18:40:15,093 [root] DEBUG: 6572: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes). 2026-05-28 18:40:15,094 [root] DEBUG: 6572: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes). 2026-05-28 18:40:15,095 [root] DEBUG: 6572: DLL loaded at 0x00007FFF834F0000: C:\Windows\system32\ncryptprov (0x5a000 bytes). 2026-05-28 18:40:15,170 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 18:40:15,170 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 18:40:15,172 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\VoSHwIb.dll, loader C:\2unxg6vp\bin\BNPlngov.exe 2026-05-28 18:40:15,176 [root] DEBUG: Loader: Injecting process 9276 (thread 9280) with C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:15,177 [root] DEBUG: InjectDllViaIAT: This image has already been patched. 2026-05-28 18:40:15,177 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:15,178 [lib.api.process] INFO: Injected into 64-bit <Process 9276 identity_helper.exe> 2026-05-28 18:40:15,205 [root] DEBUG: 9276: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 18:40:15,206 [root] DEBUG: 9276: Interactive desktop enabled. 2026-05-28 18:40:15,207 [root] DEBUG: 9276: Dropped file limit defaulting to 100. 2026-05-28 18:40:15,212 [root] DEBUG: 9276: Disabling sleep skipping. 2026-05-28 18:40:15,213 [root] DEBUG: 9276: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac 2026-05-28 18:40:15,224 [root] DEBUG: 9276: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0 2026-05-28 18:40:15,225 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:40:15,247 [root] DEBUG: 9276: Monitor initialised: 64-bit capemon loaded in process 9276 at 0x00007FFF52E70000, thread 9280, image base 0x00007FF61EFC0000, stack from 0x00000006B8F14000-0x00000006B8F20000 2026-05-28 18:40:15,248 [root] DEBUG: 9276: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5416,i,11841412995553795422,14086158004574912410,524288 --field-trial-handle=2384,i,4288227368743217175,9291041716561652224,262144 --variations-seed-version --pseudonymization-salt-handle=2388,i,6327506887006876338,10762903194929324 2026-05-28 18:40:15,248 [root] DEBUG: 9276: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll 2026-05-28 18:40:15,260 [root] DEBUG: 9276: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress 2026-05-28 18:40:15,286 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-05-28 18:40:15,287 [root] DEBUG: 9276: set_hooks: Unable to hook LockResource 2026-05-28 18:40:15,296 [root] DEBUG: 9276: Hooked 627 out of 628 functions 2026-05-28 18:40:15,311 [root] DEBUG: 9276: Syscall hook installed, syscall logging level 1 2026-05-28 18:40:15,314 [root] DEBUG: 6572: DLL loaded at 0x00007FFF95A00000: C:\Windows\system32\mswsock (0x6a000 bytes). 2026-05-28 18:40:15,317 [root] DEBUG: 9276: RestoreHeaders: Restored original import table. 2026-05-28 18:40:15,317 [root] INFO: Loaded monitor into process with pid 9276 2026-05-28 18:40:15,318 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994 2026-05-28 18:40:15,437 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994 2026-05-28 18:40:15,463 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994 2026-05-28 18:40:15,488 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994 2026-05-28 18:40:15,513 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994 2026-05-28 18:40:15,539 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994 2026-05-28 18:40:15,563 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994 2026-05-28 18:40:15,594 [root] DEBUG: 9276: caller_dispatch: Added region at 0x00007FFF52500000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF526FF156, thread 9280). 2026-05-28 18:40:15,595 [root] DEBUG: 9276: caller_dispatch: Scanning calling region at 0x00007FFF52500000... 2026-05-28 18:40:15,616 [root] DEBUG: 9276: ProcessTrackedRegion: Region at 0x00007FFF52500000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping 2026-05-28 18:40:15,618 [root] DEBUG: 9276: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptprimitives (0x82000 bytes). 2026-05-28 18:40:15,644 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:40:15,660 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:40:15,676 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:40:15,693 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:40:15,709 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:40:15,725 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:40:15,743 [root] DEBUG: 9276: caller_dispatch: Added region at 0x00007FF61EFC0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF61F0B4096, thread 9280). 2026-05-28 18:40:15,744 [root] DEBUG: 9276: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:40:15,761 [root] DEBUG: 9276: ProcessImageBase: Main module image at 0x00007FF61EFC0000 unmodified (entropy change 0.000000e+00) 2026-05-28 18:40:15,766 [root] DEBUG: 9276: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes). 2026-05-28 18:40:15,792 [root] DEBUG: 9276: DLL loaded at 0x0000013800000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes). 2026-05-28 18:40:15,797 [root] DEBUG: 9276: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-05-28 18:40:15,800 [root] DEBUG: 9276: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes). 2026-05-28 18:40:15,826 [root] DEBUG: 9276: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-05-28 18:40:15,831 [root] DEBUG: 9276: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-05-28 18:40:15,836 [root] DEBUG: 9276: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes). 2026-05-28 18:40:15,837 [root] DEBUG: 9276: DLL loaded at 0x00007FFF91EB0000: C:\Windows\System32\PROPSYS (0xf6000 bytes). 2026-05-28 18:40:15,837 [root] DEBUG: 9276: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-05-28 18:40:15,838 [root] DEBUG: 9276: DLL loaded at 0x00007FFF84D00000: C:\Windows\System32\execmodelclient (0x63000 bytes). 2026-05-28 18:40:15,849 [root] DEBUG: 9276: DLL loaded at 0x00007FFF90DA0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes). 2026-05-28 18:40:15,851 [root] DEBUG: 9276: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes). 2026-05-28 18:40:15,851 [root] DEBUG: 9276: DLL loaded at 0x00007FFF94110000: C:\Windows\System32\RMCLIENT (0x2a000 bytes). 2026-05-28 18:40:15,852 [root] DEBUG: 9276: DLL loaded at 0x00007FFF91E70000: C:\Windows\System32\XmlLite (0x36000 bytes). 2026-05-28 18:40:15,852 [root] DEBUG: 9276: DLL loaded at 0x00007FFF82770000: C:\Windows\System32\wpnapps (0x15b000 bytes). 2026-05-28 18:40:15,860 [root] DEBUG: 9276: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes). 2026-05-28 18:40:15,870 [root] DEBUG: 9276: DLL loaded at 0x00007FFF833F0000: C:\Windows\system32\execmodelproxy (0x18000 bytes). 2026-05-28 18:40:15,871 [root] DEBUG: 9276: DLL loaded at 0x00007FFF916B0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes). 2026-05-28 18:40:15,877 [root] DEBUG: 9276: DLL loaded at 0x00007FFF953C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:40:15,878 [root] DEBUG: 9276: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 18:40:15,881 [root] DEBUG: 9276: DLL loaded at 0x00007FFF8F850000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes). 2026-05-28 18:40:15,891 [root] DEBUG: 9276: DLL loaded at 0x00007FFF8B820000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-05-28 18:40:15,902 [root] DEBUG: 9276: DLL loaded at 0x00007FFF96A80000: C:\Windows\System32\WINTRUST (0x67000 bytes). 2026-05-28 18:40:15,902 [root] DEBUG: 9276: DLL loaded at 0x00007FFF8E6A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes). 2026-05-28 18:40:15,905 [root] DEBUG: 9276: DLL loaded at 0x00007FFF95E30000: C:\Windows\System32\MSASN1 (0x12000 bytes). 2026-05-28 18:40:15,912 [root] DEBUG: 9276: DLL loaded at 0x00007FFF85060000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes). 2026-05-28 18:40:15,919 [root] DEBUG: 9276: DLL loaded at 0x00007FFF70D80000: C:\Windows\System32\CryptoWinRT (0x61000 bytes). 2026-05-28 18:40:15,935 [lib.api.process] INFO: Monitor config for process 840: C:\2unxg6vp\dll\840.ini 2026-05-28 18:40:15,936 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:40:15,937 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\VoSHwIb.dll, loader C:\2unxg6vp\bin\BNPlngov.exe 2026-05-28 18:40:15,941 [root] DEBUG: Loader: Injecting process 840 with C:\2unxg6vp\dll\VoSHwIb.dll. 2026-05-28 18:40:15,943 [root] DEBUG: 840: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 18:40:15,944 [root] DEBUG: 840: Disabling sleep skipping. 2026-05-28 18:40:15,944 [root] DEBUG: 840: Interactive desktop enabled. 2026-05-28 18:40:15,945 [root] DEBUG: 840: Dropped file limit defaulting to 100. 2026-05-28 18:40:15,946 [root] DEBUG: 840: Services hook set enabled
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 18:39:48 | 2026-05-28 18:40:28 | none |
Seek in progress...
No results found.
No behavioral analysis data available.
No dropped files found.