| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 18:43:32 | 2026-05-28 18:44:11 | 39s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 18:30:47,582 [root] INFO: Date set to: 20260528T18:43:38, timeout set to: 200 2026-05-28 18:43:38,010 [root] DEBUG: Starting analyzer from: C:\2unxg6vp 2026-05-28 18:43:38,011 [root] DEBUG: Storing results at: C:\uJcYLDyRT 2026-05-28 18:43:38,011 [root] DEBUG: Pipe server name: \\.\PIPE\ueorrrZss 2026-05-28 18:43:38,012 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64 2026-05-28 18:43:38,017 [root] INFO: analysis running as an admin 2026-05-28 18:43:38,017 [root] INFO: analysis package specified: "edge" 2026-05-28 18:43:38,017 [root] DEBUG: importing analysis package module: "modules.packages.edge"... 2026-05-28 18:43:38,019 [root] DEBUG: imported analysis package "edge" 2026-05-28 18:43:38,020 [root] DEBUG: initializing analysis package "edge"... 2026-05-28 18:43:38,021 [root] DEBUG: New location of moved file: https://sugarcraft.net/ 2026-05-28 18:43:38,021 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option 2026-05-28 18:43:38,022 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option 2026-05-28 18:43:38,022 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option 2026-05-28 18:43:38,022 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option 2026-05-28 18:43:38,042 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2026-05-28 18:43:38,107 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2026-05-28 18:43:38,131 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2026-05-28 18:43:38,137 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2026-05-28 18:43:38,140 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-05-28 18:43:38,140 [lib.api.screenshot] ERROR: No module named 'PIL' 2026-05-28 18:43:38,141 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots" 2026-05-28 18:43:38,142 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2026-05-28 18:43:38,142 [root] DEBUG: Initialized auxiliary module "Browser" 2026-05-28 18:43:38,142 [root] DEBUG: attempting to configure 'Browser' from data 2026-05-28 18:43:38,143 [root] DEBUG: module Browser does not support data configuration, ignoring 2026-05-28 18:43:38,143 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2026-05-28 18:43:38,143 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2026-05-28 18:43:38,143 [root] DEBUG: Initialized auxiliary module "DigiSig" 2026-05-28 18:43:38,145 [root] DEBUG: attempting to configure 'DigiSig' from data 2026-05-28 18:43:38,146 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2026-05-28 18:43:38,146 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2026-05-28 18:43:38,147 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file 2026-05-28 18:43:38,147 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2026-05-28 18:43:38,148 [root] DEBUG: Initialized auxiliary module "Disguise" 2026-05-28 18:43:38,148 [root] DEBUG: attempting to configure 'Disguise' from data 2026-05-28 18:43:38,148 [root] DEBUG: module Disguise does not support data configuration, ignoring 2026-05-28 18:43:38,148 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2026-05-28 18:43:38,151 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 9032) 2026-05-28 18:43:38,152 [modules.auxiliary.disguise] INFO: Disguising GUID to 20a4cdc9-c6ba-4179-8ff7-a3938a3b568d 2026-05-28 18:43:38,152 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2026-05-28 18:43:38,152 [root] DEBUG: Initialized auxiliary module "Human" 2026-05-28 18:43:38,153 [root] DEBUG: attempting to configure 'Human' from data 2026-05-28 18:43:38,153 [root] DEBUG: module Human does not support data configuration, ignoring 2026-05-28 18:43:38,153 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2026-05-28 18:43:38,154 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2026-05-28 18:43:38,154 [root] DEBUG: Initialized auxiliary module "Screenshots" 2026-05-28 18:43:38,155 [root] DEBUG: attempting to configure 'Screenshots' from data 2026-05-28 18:43:38,155 [root] DEBUG: module Screenshots does not support data configuration, ignoring 2026-05-28 18:43:38,155 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"... 2026-05-28 18:43:38,155 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2026-05-28 18:43:38,155 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots 2026-05-28 18:43:38,156 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2026-05-28 18:43:38,156 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2026-05-28 18:43:38,156 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2026-05-28 18:43:38,156 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2026-05-28 18:43:38,158 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process 2026-05-28 18:43:38,158 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2026-05-28 18:43:38,158 [root] INFO: Interactive mode enabled - injecting into explorer shell 2026-05-28 18:43:38,220 [lib.api.process] INFO: Monitor config for process 4676: C:\2unxg6vp\dll\4676.ini 2026-05-28 18:43:38,221 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:43:38,223 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe 2026-05-28 18:43:38,263 [root] DEBUG: Loader: Injecting process 4676 with C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:38,444 [root] DEBUG: 4676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 18:43:38,448 [root] DEBUG: 4676: Disabling sleep skipping. 2026-05-28 18:43:38,451 [root] DEBUG: 4676: Interactive desktop enabled. 2026-05-28 18:43:38,453 [root] DEBUG: 4676: Dropped file limit defaulting to 100. 2026-05-28 18:43:38,457 [root] DEBUG: 4676: Interactive desktop - injecting Explorer Shell 2026-05-28 18:43:38,471 [root] DEBUG: 4676: YaraInit: Compiled 44 rule files 2026-05-28 18:43:38,472 [root] DEBUG: 4676: YaraInit: Compiled rules saved to file C:\2unxg6vp\data\yara\capemon.yac 2026-05-28 18:43:38,500 [root] DEBUG: 4676: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0 2026-05-28 18:43:38,500 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316 2026-05-28 18:43:38,571 [root] DEBUG: 4676: Monitor initialised: 64-bit capemon loaded in process 4676 at 0x00007FFF52E70000, thread 908, image base 0x00007FF663980000, stack from 0x0000000010E52000-0x0000000010E60000 2026-05-28 18:43:38,572 [root] DEBUG: 4676: Commandline: C:\Windows\Explorer.EXE 2026-05-28 18:43:38,584 [root] DEBUG: 4676: Hooked 69 out of 69 functions 2026-05-28 18:43:38,621 [root] DEBUG: 4676: Syscall hook installed, syscall logging level 1 2026-05-28 18:43:38,627 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-05-28 18:43:38,628 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:38,630 [lib.api.process] INFO: Injected into 64-bit <Process 4676 explorer.exe> 2026-05-28 18:43:45,926 [root] INFO: Restarting WMI Service 2026-05-28 18:43:48,024 [root] DEBUG: package modules.packages.edge does not support configure, ignoring 2026-05-28 18:43:48,026 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages' 2026-05-28 18:43:48,028 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation 2026-05-28 18:43:48,033 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://sugarcraft.net/"" with pid 6712 2026-05-28 18:43:48,034 [lib.api.process] INFO: Monitor config for process 6712: C:\2unxg6vp\dll\6712.ini 2026-05-28 18:43:48,037 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:43:48,040 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe 2026-05-28 18:43:48,049 [root] DEBUG: Loader: Injecting process 6712 (thread 5976) with C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:48,049 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 18:43:48,050 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:48,051 [lib.api.process] INFO: Injected into 64-bit <Process 6712 msedge.exe> 2026-05-28 18:43:50,058 [lib.api.process] INFO: Successfully resumed process with pid 6712 2026-05-28 18:43:50,191 [root] DEBUG: 6712: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 18:43:50,192 [root] DEBUG: 6712: Disabling sleep skipping. 2026-05-28 18:43:50,193 [root] DEBUG: 6712: Interactive desktop enabled. 2026-05-28 18:43:50,194 [root] DEBUG: 6712: Dropped file limit defaulting to 100. 2026-05-28 18:43:50,234 [root] DEBUG: 6712: Edge-specific hook-set enabled. 2026-05-28 18:43:50,244 [root] DEBUG: 6712: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac 2026-05-28 18:43:50,265 [root] DEBUG: 6712: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0 2026-05-28 18:43:50,266 [root] DEBUG: 6712: Monitor initialised: 64-bit capemon loaded in process 6712 at 0x00007FFF52E70000, thread 5976, image base 0x00007FF6F9430000, stack from 0x0000000ED37F4000-0x0000000ED3800000 2026-05-28 18:43:50,266 [root] DEBUG: 6712: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://sugarcraft.net/" 2026-05-28 18:43:50,278 [root] DEBUG: 6712: Hooked 2 out of 2 functions 2026-05-28 18:43:50,312 [root] DEBUG: 6712: Syscall hook installed, syscall logging level 1 2026-05-28 18:43:50,316 [root] DEBUG: 6712: RestoreHeaders: Restored original import table. 2026-05-28 18:43:50,317 [root] INFO: Loaded monitor into process with pid 6712 2026-05-28 18:43:50,319 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptprimitives (0x82000 bytes). 2026-05-28 18:43:50,325 [root] DEBUG: 6712: DLL loaded at 0x00007FFF853A0000: C:\Windows\SYSTEM32\version (0xa000 bytes). 2026-05-28 18:43:50,326 [root] DEBUG: 6712: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes). 2026-05-28 18:43:50,327 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95CA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes). 2026-05-28 18:43:50,327 [root] DEBUG: 6712: DLL loaded at 0x00007FFF94410000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes). 2026-05-28 18:43:50,328 [root] DEBUG: 6712: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\SHCORE (0xad000 bytes). 2026-05-28 18:43:50,329 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-05-28 18:43:50,478 [root] DEBUG: 6712: DLL loaded at 0x00007FFF84A60000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes). 2026-05-28 18:43:50,479 [root] DEBUG: 6712: DLL loaded at 0x00007FFF3EE40000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes). 2026-05-28 18:43:50,482 [root] DEBUG: 6712: DLL loaded at 0x00007FFF833E0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes). 2026-05-28 18:43:50,484 [root] DEBUG: 6712: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-05-28 18:43:50,488 [root] DEBUG: 6712: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-05-28 18:43:50,489 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 7104: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:43:50,489 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 7104 2026-05-28 18:43:50,490 [root] DEBUG: 6712: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-05-28 18:43:50,490 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 7104 2026-05-28 18:43:50,491 [root] DEBUG: 6712: DLL loaded at 0x00007FFF92010000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes). 2026-05-28 18:43:50,492 [root] DEBUG: 6712: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:43:50,493 [root] DEBUG: 6712: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 18:43:50,496 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96220000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes). 2026-05-28 18:43:50,497 [root] DEBUG: 6712: DLL loaded at 0x00007FFF94BC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes). 2026-05-28 18:43:50,498 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95490000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes). 2026-05-28 18:43:50,499 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95850000: C:\Windows\SYSTEM32\netutils (0xc000 bytes). 2026-05-28 18:43:50,500 [root] DEBUG: 6712: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:43:50,500 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8C000000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes). 2026-05-28 18:43:50,502 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes). 2026-05-28 18:43:50,502 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes). 2026-05-28 18:43:50,503 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95D10000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes). 2026-05-28 18:43:50,503 [root] DEBUG: 6712: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes). 2026-05-28 18:43:50,503 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes). 2026-05-28 18:43:50,504 [root] DEBUG: 6712: DLL loaded at 0x00007FFF82660000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes). 2026-05-28 18:43:50,504 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8BFC0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes). 2026-05-28 18:43:50,505 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes). 2026-05-28 18:43:50,506 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95CD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes). 2026-05-28 18:43:50,507 [root] DEBUG: 6712: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes). 2026-05-28 18:43:50,508 [root] DEBUG: 6712: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:43:50,509 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes). 2026-05-28 18:43:50,509 [root] DEBUG: 6712: DLL loaded at 0x00007FFF92030000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes). 2026-05-28 18:43:50,510 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96260000: C:\Windows\SYSTEM32\profapi (0x25000 bytes). 2026-05-28 18:43:50,518 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8C050000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes). 2026-05-28 18:43:50,519 [root] DEBUG: 6712: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes). 2026-05-28 18:43:50,520 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8CEF0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes). 2026-05-28 18:43:50,520 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes). 2026-05-28 18:43:50,521 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes). 2026-05-28 18:43:50,522 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8A140000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes). 2026-05-28 18:43:50,525 [root] DEBUG: 6712: DLL loaded at 0x00007FFF82ED0000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes). 2026-05-28 18:43:50,525 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8F850000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes). 2026-05-28 18:43:50,526 [root] DEBUG: 6712: DLL loaded at 0x00007FFF960B0000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes). 2026-05-28 18:43:50,528 [root] DEBUG: 6712: DLL loaded at 0x00007FFF956F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes). 2026-05-28 18:43:50,528 [root] DEBUG: 6712: DLL loaded at 0x00007FFF91940000: C:\Windows\system32\NLAapi (0x1d000 bytes). 2026-05-28 18:43:50,530 [root] DEBUG: 6712: DLL loaded at 0x00007FFF98020000: C:\Windows\System32\NSI (0x8000 bytes). 2026-05-28 18:43:50,530 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96AF0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-05-28 18:43:50,531 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8EAD0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes). 2026-05-28 18:43:50,531 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8BEB0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes). 2026-05-28 18:43:50,532 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8EAB0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes). 2026-05-28 18:43:50,533 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95730000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes). 2026-05-28 18:43:50,534 [root] DEBUG: 6712: DLL loaded at 0x00007FFF91EB0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes). 2026-05-28 18:43:50,536 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8B820000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-05-28 18:43:50,538 [root] DEBUG: 6712: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-05-28 18:43:50,538 [root] DEBUG: 6712: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes). 2026-05-28 18:43:50,539 [root] DEBUG: 6712: DLL loaded at 0x00007FFF93160000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes). 2026-05-28 18:43:50,539 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8A6E0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-05-28 18:43:50,541 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8B750000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes). 2026-05-28 18:43:50,543 [root] DEBUG: 6712: DLL loaded at 0x00007FFF90DA0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes). 2026-05-28 18:43:50,545 [root] DEBUG: 6712: DLL loaded at 0x00007FFF82BC0000: C:\Windows\system32\twinapi (0xa9000 bytes). 2026-05-28 18:43:50,546 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8A550000: C:\Windows\system32\mssprxy (0x28000 bytes). 2026-05-28 18:43:50,549 [root] DEBUG: 6712: DLL loaded at 0x00007FFF905B0000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes). 2026-05-28 18:43:50,551 [root] DEBUG: 6712: DLL loaded at 0x00007FFF86740000: C:\Windows\SYSTEM32\edputil (0x24000 bytes). 2026-05-28 18:43:50,553 [root] DEBUG: 6712: DLL loaded at 0x00007FFF90FB0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes). 2026-05-28 18:43:50,554 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8A580000: C:\Windows\System32\InputHost (0x152000 bytes). 2026-05-28 18:43:50,554 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8A7E0000: C:\Windows\System32\Windows.UI (0x141000 bytes). 2026-05-28 18:43:50,556 [root] DEBUG: 6712: DLL loaded at 0x00007FFF91FE0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes). 2026-05-28 18:43:50,557 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8C3B0000: C:\Windows\System32\iertutil (0x2bc000 bytes). 2026-05-28 18:43:50,559 [root] DEBUG: 6712: DLL loaded at 0x00007FFF865D0000: C:\Windows\System32\Windows.Web (0xc3000 bytes). 2026-05-28 18:43:50,560 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95FF0000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes). 2026-05-28 18:43:50,562 [root] DEBUG: 6712: DLL loaded at 0x00007FFF90620000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes). 2026-05-28 18:43:50,563 [root] DEBUG: 6712: DLL loaded at 0x00007FFF90660000: C:\Windows\SYSTEM32\mscms (0xae000 bytes). 2026-05-28 18:43:50,570 [root] DEBUG: 6712: DLL loaded at 0x00007FFF90780000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes). 2026-05-28 18:43:50,575 [root] DEBUG: 6712: DLL loaded at 0x00007FFF3D4E0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes). 2026-05-28 18:43:50,584 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 1392: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:43:50,584 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 1392 2026-05-28 18:43:50,586 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 1392 2026-05-28 18:43:50,587 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8A3C0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes). 2026-05-28 18:43:50,588 [root] DEBUG: 6712: DLL loaded at 0x00007FFF87320000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes). 2026-05-28 18:43:50,591 [root] DEBUG: 6712: caller_dispatch: Added region at 0x00007FF6F9430000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF6F9527D66, thread 8324). 2026-05-28 18:43:50,596 [root] DEBUG: 6712: ProcessImageBase: Main module image at 0x00007FF6F9430000 unmodified (entropy change 0.000000e+00) 2026-05-28 18:43:50,597 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 9044: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:43:50,598 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 9044 2026-05-28 18:43:50,598 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 9044 2026-05-28 18:43:50,603 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 8452: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:43:50,608 [root] DEBUG: 6712: DLL loaded at 0x00007FFF960C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes). 2026-05-28 18:43:50,611 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 8452 2026-05-28 18:43:50,612 [root] DEBUG: 6712: DLL loaded at 0x00007FFF853F0000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes). 2026-05-28 18:43:50,615 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 8452 2026-05-28 18:43:50,616 [root] DEBUG: 6712: DLL loaded at 0x00007FFF916B0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes). 2026-05-28 18:43:50,616 [root] DEBUG: 6712: DLL loaded at 0x00007FFF7DDC0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes). 2026-05-28 18:43:50,647 [root] DEBUG: 6712: DLL loaded at 0x00007FFF94BF0000: C:\Windows\system32\dxgi (0xf3000 bytes). 2026-05-28 18:43:50,648 [root] DEBUG: 6712: DLL loaded at 0x00007FFF92740000: C:\Windows\system32\d3d11 (0x263000 bytes). 2026-05-28 18:43:50,649 [root] DEBUG: 6712: DLL loaded at 0x00007FFF929B0000: C:\Windows\system32\dcomp (0x1e3000 bytes). 2026-05-28 18:43:50,649 [root] DEBUG: 6712: DLL loaded at 0x00007FFF80590000: C:\Windows\system32\dataexchange (0x3e000 bytes). 2026-05-28 18:43:50,671 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8BF90000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes). 2026-05-28 18:43:50,684 [root] DEBUG: 6712: DLL loaded at 0x00007FFF93E40000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes). 2026-05-28 18:43:50,690 [root] DEBUG: 6712: DLL loaded at 0x00007FFF80840000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes). 2026-05-28 18:43:50,691 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 2976: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:43:50,691 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 2976 2026-05-28 18:43:50,691 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 4752: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:43:50,692 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 2976 2026-05-28 18:43:50,692 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 4752 2026-05-28 18:43:50,692 [root] DEBUG: 6712: DLL loaded at 0x00007FFF877F0000: C:\Windows\system32\directmanipulation (0x9d000 bytes). 2026-05-28 18:43:50,693 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 4752 2026-05-28 18:43:50,728 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316 2026-05-28 18:43:50,732 [root] DEBUG: 4676: caller_dispatch: Added region at 0x00007FF663980000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF6639ACA89, thread 4900). 2026-05-28 18:43:50,733 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316 2026-05-28 18:43:50,784 [root] DEBUG: 4676: ProcessImageBase: Main module image at 0x00007FF663980000 unmodified (entropy change 0.000000e+00) 2026-05-28 18:43:50,785 [root] DEBUG: 6712: DLL loaded at 0x00007FFF81570000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes). 2026-05-28 18:43:50,785 [root] DEBUG: 4676: ProcessImageBase: Main module image at 0x00007FF663980000 unmodified (entropy change 0.000000e+00) 2026-05-28 18:43:50,850 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95E30000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes). 2026-05-28 18:43:50,858 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes). 2026-05-28 18:43:50,859 [root] DEBUG: 6712: DLL loaded at 0x00007FFF84F00000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes). 2026-05-28 18:43:50,860 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95330000: C:\Windows\system32\rsaenh (0x34000 bytes). 2026-05-28 18:43:50,880 [root] DEBUG: 6712: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes). 2026-05-28 18:43:50,882 [root] DEBUG: 6712: DLL loaded at 0x00007FFF78140000: C:\Windows\System32\vaultcli (0x51000 bytes). 2026-05-28 18:43:50,900 [root] DEBUG: 6712: DLL loaded at 0x00007FFF7FD60000: C:\Windows\System32\aadWamExtension (0x36000 bytes). 2026-05-28 18:43:50,904 [root] DEBUG: 6712: DLL loaded at 0x00007FFF7FB90000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes). 2026-05-28 18:43:52,005 [root] DEBUG: 6712: DLL loaded at 0x00007FFF7CEE0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes). 2026-05-28 18:43:52,505 [root] DEBUG: 6712: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 18:43:52,506 [root] DEBUG: 6712: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 18:43:54,255 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 6460: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:43:54,257 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 6460 2026-05-28 18:43:54,258 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 6460 2026-05-28 18:43:55,318 [root] DEBUG: 6712: DLL loaded at 0x00007FFF986E0000: C:\Windows\System32\SETUPAPI (0x46e000 bytes). 2026-05-28 18:43:55,320 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 8668: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000 2026-05-28 18:43:55,321 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 8668 2026-05-28 18:43:55,322 [root] DEBUG: 6712: DLL loaded at 0x00007FFF91760000: C:\Windows\System32\netprofm (0x3f000 bytes). 2026-05-28 18:43:55,323 [root] DEBUG: 6712: ProcessMessage: Skipping monitoring process 8668 2026-05-28 18:43:55,401 [root] DEBUG: 6712: DLL loaded at 0x00007FFF3A630000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes). 2026-05-28 18:43:55,444 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96050000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes). 2026-05-28 18:43:55,445 [root] DEBUG: 6712: DLL loaded at 0x00007FFF96A80000: C:\Windows\System32\WINTRUST (0x67000 bytes). 2026-05-28 18:43:55,446 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8E350000: C:\Windows\System32\npmproxy (0x10000 bytes). 2026-05-28 18:43:55,449 [root] DEBUG: 6712: DLL loaded at 0x00007FFF39FD0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes). 2026-05-28 18:43:55,456 [root] DEBUG: 6712: DLL loaded at 0x00007FFF3D070000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes). 2026-05-28 18:43:55,460 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8BF70000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes). 2026-05-28 18:43:55,463 [root] DEBUG: 6712: DLL loaded at 0x00007FFF94F50000: C:\Windows\System32\FirewallAPI (0x96000 bytes). 2026-05-28 18:43:55,464 [root] DEBUG: 6712: DLL loaded at 0x00007FFF94F10000: C:\Windows\System32\fwbase (0x36000 bytes). 2026-05-28 18:43:55,466 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 3144: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000 2026-05-28 18:43:55,467 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 3144 2026-05-28 18:43:55,468 [lib.api.process] INFO: Monitor config for process 3144: C:\2unxg6vp\dll\3144.ini 2026-05-28 18:43:55,472 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:43:55,484 [root] DEBUG: 6712: DLL loaded at 0x00007FFF7FAB0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes). 2026-05-28 18:43:56,101 [root] DEBUG: 6712: DLL loaded at 0x00007FFF94110000: C:\Windows\System32\RMCLIENT (0x2a000 bytes). 2026-05-28 18:43:56,102 [root] DEBUG: 6712: DLL loaded at 0x00007FFF91E70000: C:\Windows\System32\XmlLite (0x36000 bytes). 2026-05-28 18:43:56,103 [root] DEBUG: 6712: DLL loaded at 0x00007FFF82770000: C:\Windows\System32\wpnapps (0x15b000 bytes). 2026-05-28 18:43:58,815 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 18:43:58,816 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 18:43:58,821 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe 2026-05-28 18:43:58,827 [root] DEBUG: Loader: Injecting process 3144 (thread 2216) with C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:58,828 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 18:43:58,828 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:58,830 [lib.api.process] INFO: Injected into 64-bit <Process 3144 identity_helper.exe> 2026-05-28 18:43:58,835 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8E6A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes). 2026-05-28 18:43:58,844 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8B370000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes). 2026-05-28 18:43:58,845 [root] DEBUG: 6712: CreateProcessHandler: Injection info set for new process 9356: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000 2026-05-28 18:43:58,846 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9356 2026-05-28 18:43:58,846 [lib.api.process] INFO: Monitor config for process 9356: C:\2unxg6vp\dll\9356.ini 2026-05-28 18:43:58,847 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:43:58,861 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8E370000: C:\Windows\system32\wlanapi (0x74000 bytes). 2026-05-28 18:43:58,882 [root] DEBUG: 6712: DLL loaded at 0x00007FFF85060000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes). 2026-05-28 18:43:58,883 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8ED20000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes). 2026-05-28 18:43:58,932 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 18:43:58,932 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 18:43:58,934 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe 2026-05-28 18:43:58,939 [root] DEBUG: Loader: Injecting process 9356 (thread 9360) with C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:58,940 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 18:43:58,940 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:58,942 [lib.api.process] INFO: Injected into 64-bit <Process 9356 identity_helper.exe> 2026-05-28 18:43:58,944 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9356 2026-05-28 18:43:58,944 [lib.api.process] INFO: Monitor config for process 9356: C:\2unxg6vp\dll\9356.ini 2026-05-28 18:43:58,958 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 18:43:59,026 [root] DEBUG: 6712: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes). 2026-05-28 18:43:59,032 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 18:43:59,033 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 18:43:59,043 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe 2026-05-28 18:43:59,049 [root] DEBUG: Loader: Injecting process 9356 (thread 9360) with C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:59,050 [root] DEBUG: InjectDllViaIAT: This image has already been patched. 2026-05-28 18:43:59,050 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll. 2026-05-28 18:43:59,052 [lib.api.process] INFO: Injected into 64-bit <Process 9356 identity_helper.exe> 2026-05-28 18:43:59,077 [root] DEBUG: 9356: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 18:43:59,079 [root] DEBUG: 9356: Interactive desktop enabled. 2026-05-28 18:43:59,079 [root] DEBUG: 9356: Dropped file limit defaulting to 100. 2026-05-28 18:43:59,084 [root] DEBUG: 9356: Disabling sleep skipping. 2026-05-28 18:43:59,085 [root] DEBUG: 9356: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac 2026-05-28 18:43:59,096 [root] DEBUG: 9356: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0 2026-05-28 18:43:59,097 [root] DEBUG: 9356: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8 2026-05-28 18:43:59,143 [root] DEBUG: 9356: Monitor initialised: 64-bit capemon loaded in process 9356 at 0x00007FFF52E70000, thread 9360, image base 0x00007FF61EFC0000, stack from 0x0000003FF8DD4000-0x0000003FF8DE0000 2026-05-28 18:43:59,144 [root] DEBUG: 9356: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5452,i,6144736785640467952,18088932084502277173,524288 --field-trial-handle=2380,i,7766555859985167370,5263872035744863658,262144 --variations-seed-version --pseudonymization-salt-handle=2392,i,16352508375692784064,75618776120992641 2026-05-28 18:43:59,144 [root] DEBUG: 9356: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll 2026-05-28 18:43:59,156 [root] DEBUG: 9356: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress 2026-05-28 18:43:59,180 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-05-28 18:43:59,181 [root] DEBUG: 9356: set_hooks: Unable to hook LockResource 2026-05-28 18:43:59,186 [root] DEBUG: 9356: Hooked 627 out of 628 functions 2026-05-28 18:43:59,193 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95D10000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes). 2026-05-28 18:43:59,194 [root] DEBUG: 6712: DLL loaded at 0x00007FFF95CD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes). 2026-05-28 18:43:59,195 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8E580000: C:\Windows\system32\PCPKsp (0x118000 bytes). 2026-05-28 18:43:59,199 [root] DEBUG: 6712: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes). 2026-05-28 18:43:59,200 [root] DEBUG: 6712: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes). 2026-05-28 18:43:59,201 [root] DEBUG: 6712: DLL loaded at 0x00007FFF834F0000: C:\Windows\system32\ncryptprov (0x5a000 bytes). 2026-05-28 18:43:59,203 [root] DEBUG: 9356: Syscall hook installed, syscall logging level 1 2026-05-28 18:43:59,209 [root] DEBUG: 9356: RestoreHeaders: Restored original import table. 2026-05-28 18:43:59,210 [root] INFO: Loaded monitor into process with pid 9356 2026-05-28 18:43:59,210 [root] DEBUG: 9356: YaraScan: Scanning 0x00007FFF52500000, size 0x4b9994
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 18:43:32 | 2026-05-28 18:44:11 | none |
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 150.171.28.12 [VT] | unknown | - |
| Y | 199.232.191.82 [VT] | unknown | - |
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 162.159.128.233 [VT] | unknown | - |
| Y | 162.159.138.234 [VT] | unknown | - |
| Y | 162.159.136.234 [VT] | unknown | - |
| Y | 4.237.153.9 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 172.64.41.3 [VT] | unknown | - |
| N | 104.16.80.73 [VT] | unknown | - |
| N | 104.26.3.143 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| Y | 162.159.137.232 [VT] | unknown | - |
| Y | 162.159.135.233 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| N | 149.135.84.160 [VT] | unknown | - |
| Y | 172.172.255.217 [VT] | unknown | - |
| Y | 205.196.6.132 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| disabled.invalid [VT] | NXDOMAIN | |
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-http.steamserver.net [VT] |
CNAME syd.http.ipv6check.akadns.net
[VT]
CNAME http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.160
[VT]
A 149.135.84.155 [VT] |
23.56.110.51 [VT] |
| sugarcraft.net [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| cdn.tailwindcss.com [VT] |
A 104.26.2.143
[VT]
A 172.67.68.11 [VT] A 104.26.3.143 [VT] |
104.26.3.143 [VT] |
| static.cloudflareinsights.com [VT] |
A 104.16.79.73
[VT]
A 104.16.80.73 [VT] |
104.16.80.73 [VT] |
| dns.google [VT] |
A 8.8.8.8
[VT]
A 8.8.4.4 [VT] |
8.8.4.4 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.24 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.