| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 18:46:27 | 2026-05-28 18:48:52 | 145s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 18:30:47,900 [root] INFO: Date set to: 20260528T18:46:33, timeout set to: 600
2026-05-28 18:46:33,011 [root] DEBUG: Starting analyzer from: C:\2unxg6vp
2026-05-28 18:46:33,012 [root] DEBUG: Storing results at: C:\uJcYLDyRT
2026-05-28 18:46:33,013 [root] DEBUG: Pipe server name: \\.\PIPE\ueorrrZss
2026-05-28 18:46:33,013 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 18:46:33,014 [root] INFO: analysis running as an admin
2026-05-28 18:46:33,014 [root] INFO: analysis package specified: "edge"
2026-05-28 18:46:33,014 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 18:46:33,018 [root] DEBUG: imported analysis package "edge"
2026-05-28 18:46:33,018 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 18:46:33,018 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-28 18:46:33,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 18:46:33,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 18:46:33,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 18:46:33,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 18:46:33,036 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 18:46:33,107 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 18:46:33,129 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 18:46:33,136 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 18:46:33,139 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 18:46:33,139 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 18:46:33,139 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 18:46:33,141 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 18:46:33,142 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 18:46:33,142 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 18:46:33,142 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 18:46:33,142 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 18:46:33,143 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 18:46:33,143 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 18:46:33,143 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 18:46:33,143 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 18:46:33,143 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 18:46:33,144 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 18:46:33,144 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 18:46:33,144 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 18:46:33,144 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 18:46:33,145 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 18:46:33,145 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 18:46:33,147 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 484)
2026-05-28 18:46:33,147 [modules.auxiliary.disguise] INFO: Disguising GUID to 047115a3-8618-46b8-9011-82fa18449ee6
2026-05-28 18:46:33,148 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 18:46:33,148 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 18:46:33,148 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 18:46:33,148 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 18:46:33,148 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 18:46:33,149 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 18:46:33,149 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 18:46:33,150 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 18:46:33,150 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 18:46:33,150 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 18:46:33,150 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 18:46:33,150 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 18:46:33,151 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 18:46:33,151 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 18:46:33,151 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 18:46:33,151 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 18:46:33,153 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 18:46:33,153 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 18:46:33,153 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 18:46:33,180 [lib.api.process] INFO: Monitor config for process 4676: C:\2unxg6vp\dll\4676.ini
2026-05-28 18:46:33,184 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:46:33,187 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:46:33,212 [root] DEBUG: Loader: Injecting process 4676 with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:33,387 [root] DEBUG: 4676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:46:33,391 [root] DEBUG: 4676: Disabling sleep skipping.
2026-05-28 18:46:33,392 [root] DEBUG: 4676: Interactive desktop enabled.
2026-05-28 18:46:33,394 [root] DEBUG: 4676: Dropped file limit defaulting to 100.
2026-05-28 18:46:33,397 [root] DEBUG: 4676: Interactive desktop - injecting Explorer Shell
2026-05-28 18:46:33,405 [root] DEBUG: 4676: YaraInit: Compiled 44 rule files
2026-05-28 18:46:33,406 [root] DEBUG: 4676: YaraInit: Compiled rules saved to file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:46:33,428 [root] DEBUG: 4676: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:46:33,429 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316
2026-05-28 18:46:33,466 [root] DEBUG: 4676: Monitor initialised: 64-bit capemon loaded in process 4676 at 0x00007FFF52E70000, thread 1860, image base 0x00007FF663980000, stack from 0x0000000010E51000-0x0000000010E60000
2026-05-28 18:46:33,467 [root] DEBUG: 4676: Commandline: C:\Windows\Explorer.EXE
2026-05-28 18:46:33,480 [root] DEBUG: 4676: Hooked 69 out of 69 functions
2026-05-28 18:46:33,513 [root] DEBUG: 4676: Syscall hook installed, syscall logging level 1
2026-05-28 18:46:33,519 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:46:33,520 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:33,521 [lib.api.process] INFO: Injected into 64-bit <Process 4676 explorer.exe>
2026-05-28 18:46:41,270 [root] INFO: Restarting WMI Service
2026-05-28 18:46:42,082 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316
2026-05-28 18:46:42,102 [root] DEBUG: 4676: caller_dispatch: Added region at 0x00007FF663980000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF6639E9D10, thread 5468).
2026-05-28 18:46:42,104 [root] DEBUG: 4676: YaraScan: Scanning 0x00007FF663980000, size 0x545316
2026-05-28 18:46:42,144 [root] DEBUG: 4676: ProcessImageBase: Main module image at 0x00007FF663980000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:46:42,151 [root] DEBUG: 4676: ProcessImageBase: Main module image at 0x00007FF663980000 unmodified (entropy change 8.858189e-07)
2026-05-28 18:46:43,306 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 18:46:43,306 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 18:46:43,306 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 18:46:43,307 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 3940
2026-05-28 18:46:43,307 [lib.api.process] INFO: Monitor config for process 3940: C:\2unxg6vp\dll\3940.ini
2026-05-28 18:46:43,308 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:46:43,309 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:46:43,314 [root] DEBUG: Loader: Injecting process 3940 (thread 460) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:43,315 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:46:43,316 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:43,318 [lib.api.process] INFO: Injected into 64-bit <Process 3940 msedge.exe>
2026-05-28 18:46:45,328 [lib.api.process] INFO: Successfully resumed process with pid 3940
2026-05-28 18:46:45,379 [root] DEBUG: 3940: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:46:45,379 [root] DEBUG: 3940: Disabling sleep skipping.
2026-05-28 18:46:45,380 [root] DEBUG: 3940: Interactive desktop enabled.
2026-05-28 18:46:45,380 [root] DEBUG: 3940: Dropped file limit defaulting to 100.
2026-05-28 18:46:45,393 [root] DEBUG: 3940: Edge-specific hook-set enabled.
2026-05-28 18:46:45,397 [root] DEBUG: 3940: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:46:45,409 [root] DEBUG: 3940: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:46:45,411 [root] DEBUG: 3940: Monitor initialised: 64-bit capemon loaded in process 3940 at 0x00007FFF52E70000, thread 460, image base 0x00007FF6F9430000, stack from 0x000000E4C07F4000-0x000000E4C0800000
2026-05-28 18:46:45,411 [root] DEBUG: 3940: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-28 18:46:45,421 [root] DEBUG: 3940: Hooked 2 out of 2 functions
2026-05-28 18:46:45,457 [root] DEBUG: 3940: Syscall hook installed, syscall logging level 1
2026-05-28 18:46:45,462 [root] DEBUG: 3940: RestoreHeaders: Restored original import table.
2026-05-28 18:46:45,462 [root] INFO: Loaded monitor into process with pid 3940
2026-05-28 18:46:45,465 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 18:46:45,472 [root] DEBUG: 3940: DLL loaded at 0x00007FFF853A0000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 18:46:45,473 [root] DEBUG: 3940: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:46:45,475 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95CA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 18:46:45,476 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94410000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:46:45,476 [root] DEBUG: 3940: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 18:46:45,478 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:46:45,626 [root] DEBUG: 3940: DLL loaded at 0x00007FFF84A60000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 18:46:45,628 [root] DEBUG: 3940: DLL loaded at 0x00007FFF3EA50000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 18:46:45,648 [root] DEBUG: 3940: DLL loaded at 0x00007FFF833E0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 18:46:45,667 [root] DEBUG: 3940: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:46:45,702 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:46:45,705 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 8320: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:45,706 [root] DEBUG: 3940: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:46:45,708 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 8320
2026-05-28 18:46:45,709 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 8320
2026-05-28 18:46:45,709 [root] DEBUG: 3940: DLL loaded at 0x00007FFF92010000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 18:46:45,711 [root] DEBUG: 3940: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:46:45,712 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:46:45,717 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96220000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 18:46:45,718 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94BC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 18:46:45,719 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95490000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 18:46:45,721 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95850000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 18:46:45,722 [root] DEBUG: 3940: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:46:45,724 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7FEB0000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 18:46:45,727 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:46:45,730 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 18:46:45,731 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95D10000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 18:46:45,731 [root] DEBUG: 3940: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:46:45,732 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:46:45,732 [root] DEBUG: 3940: DLL loaded at 0x00007FFF82660000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 18:46:45,733 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8BF80000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 18:46:45,734 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:46:45,735 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95CD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 18:46:45,737 [root] DEBUG: 3940: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 18:46:45,738 [root] DEBUG: 3940: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:46:45,738 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 18:46:45,738 [root] DEBUG: 3940: DLL loaded at 0x00007FFF92030000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 18:46:45,740 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96260000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 18:46:45,749 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8BFA0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 18:46:45,750 [root] DEBUG: 3940: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:46:45,751 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8CEF0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 18:46:45,752 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:46:45,752 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:46:45,754 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8A140000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 18:46:45,757 [root] DEBUG: 3940: DLL loaded at 0x00007FFF82ED0000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 18:46:45,758 [root] DEBUG: 3940: DLL loaded at 0x00007FFF960B0000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 18:46:45,759 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8F850000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 18:46:45,760 [root] DEBUG: 3940: DLL loaded at 0x00007FFF956F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:46:45,761 [root] DEBUG: 3940: DLL loaded at 0x00007FFF91940000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 18:46:45,762 [root] DEBUG: 3940: DLL loaded at 0x00007FFF98020000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 18:46:45,763 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8EAD0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 18:46:45,764 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96AF0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 18:46:45,764 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8EAB0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:46:45,765 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8BEB0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 18:46:45,766 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95730000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 18:46:45,767 [root] DEBUG: 3940: DLL loaded at 0x00007FFF91EB0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 18:46:45,770 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8B820000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:46:45,772 [root] DEBUG: 3940: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:46:45,773 [root] DEBUG: 3940: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:46:45,773 [root] DEBUG: 3940: DLL loaded at 0x00007FFF93160000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 18:46:45,775 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8A6E0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 18:46:45,776 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8B750000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 18:46:45,778 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90DA0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:46:45,780 [root] DEBUG: 3940: DLL loaded at 0x00007FFF82BC0000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 18:46:45,781 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8A550000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 18:46:45,783 [root] DEBUG: 3940: DLL loaded at 0x00007FFF905B0000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 18:46:45,787 [root] DEBUG: 3940: DLL loaded at 0x00007FFF86740000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 18:46:45,788 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90FB0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 18:46:45,789 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8A580000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 18:46:45,790 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8A7E0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 18:46:45,792 [root] DEBUG: 3940: DLL loaded at 0x00007FFF91FE0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 18:46:45,802 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90620000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 18:46:45,802 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90660000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 18:46:45,804 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8C3B0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 18:46:45,805 [root] DEBUG: 3940: DLL loaded at 0x00007FFF865D0000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 18:46:45,806 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95FF0000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 18:46:45,817 [root] DEBUG: 3940: DLL loaded at 0x00007FFF3E480000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 18:46:45,828 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90780000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 18:46:45,830 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8A3C0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 18:46:45,832 [root] DEBUG: 3940: DLL loaded at 0x00007FFF87320000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 18:46:45,839 [root] DEBUG: 3940: DLL loaded at 0x00007FFF960C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 18:46:45,840 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 3224: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:45,840 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 3224
2026-05-28 18:46:45,841 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 3224
2026-05-28 18:46:45,852 [root] DEBUG: 3940: caller_dispatch: Added region at 0x00007FF6F9430000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF6F9527D66, thread 8956).
2026-05-28 18:46:45,853 [root] DEBUG: 3940: ProcessImageBase: Main module image at 0x00007FF6F9430000 unmodified (entropy change 4.579478e-05)
2026-05-28 18:46:45,854 [root] DEBUG: 3940: DLL loaded at 0x00007FFF853F0000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 18:46:45,857 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 8248: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:45,857 [root] DEBUG: 3940: ProcessImageBase: Main module image at 0x00007FF6F9430000 unmodified (entropy change 4.579478e-05)
2026-05-28 18:46:45,858 [root] DEBUG: 3940: DLL loaded at 0x00007FFF916B0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:46:45,858 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 8248
2026-05-28 18:46:45,858 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7DDC0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 18:46:45,859 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 6572: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:45,859 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 8248
2026-05-28 18:46:45,860 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 6572
2026-05-28 18:46:45,861 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 6572
2026-05-28 18:46:45,899 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94BF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 18:46:45,900 [root] DEBUG: 3940: DLL loaded at 0x00007FFF92740000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 18:46:45,901 [root] DEBUG: 3940: DLL loaded at 0x00007FFF929B0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 18:46:45,901 [root] DEBUG: 3940: DLL loaded at 0x00007FFF80590000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 18:46:45,923 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8BF70000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 18:46:45,939 [root] DEBUG: 3940: DLL loaded at 0x00007FFF93E40000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 18:46:45,947 [root] DEBUG: 3940: DLL loaded at 0x00007FFF80840000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 18:46:45,948 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 1104: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:45,948 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 4756: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:45,948 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 1104
2026-05-28 18:46:45,949 [root] DEBUG: 3940: DLL loaded at 0x00007FFF877F0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 18:46:45,949 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 4756
2026-05-28 18:46:45,949 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 1104
2026-05-28 18:46:45,950 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 4756
2026-05-28 18:46:46,012 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7ECC0000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 18:46:46,039 [root] DEBUG: 3940: DLL loaded at 0x00007FFF85400000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 18:46:46,058 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7D430000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 18:46:46,084 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95E30000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 18:46:46,087 [root] DEBUG: 3940: DLL loaded at 0x00007FFF84F00000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 18:46:46,088 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95BF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 18:46:46,089 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95330000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 18:46:46,102 [root] DEBUG: 3940: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:46:46,106 [root] DEBUG: 3940: DLL loaded at 0x00007FFF78140000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 18:46:46,157 [root] DEBUG: 3940: DLL loaded at 0x00007FFF81660000: C:\Windows\System32\aadWamExtension (0x36000 bytes).
2026-05-28 18:46:46,163 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7D3A0000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 18:46:47,278 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7CEE0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 18:46:47,520 [root] DEBUG: 3940: DLL loaded at 0x00007FFF80180000: C:\Windows\system32\explorerframe (0x244000 bytes).
2026-05-28 18:46:47,526 [root] DEBUG: 3940: DLL loaded at 0x00007FFF986E0000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 18:46:47,528 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 3132: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:47,528 [root] DEBUG: 3940: DLL loaded at 0x00007FFF91760000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 18:46:47,528 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 3132
2026-05-28 18:46:47,529 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 3132
2026-05-28 18:46:47,558 [root] DEBUG: 3940: DLL loaded at 0x00007FFF3A240000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 18:46:47,583 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96050000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 18:46:47,584 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8E350000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 18:46:47,586 [root] DEBUG: 3940: DLL loaded at 0x00007FFF39BE0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 18:46:47,589 [root] DEBUG: 3940: DLL loaded at 0x00007FFF3CC80000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 18:46:47,590 [root] DEBUG: 3940: DLL loaded at 0x00007FFF96A80000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 18:46:47,591 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94F50000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 18:46:47,592 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94F10000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 18:46:47,593 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8BE70000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 18:46:47,597 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7FAB0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 18:46:47,603 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94110000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:46:47,604 [root] DEBUG: 3940: DLL loaded at 0x00007FFF91E70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:46:47,604 [root] DEBUG: 3940: DLL loaded at 0x00007FFF82770000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:46:47,613 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 4348: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000
2026-05-28 18:46:47,614 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 4348
2026-05-28 18:46:47,614 [lib.api.process] INFO: Monitor config for process 4348: C:\2unxg6vp\dll\4348.ini
2026-05-28 18:46:47,618 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:46:47,690 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7A380000: C:\Windows\System32\Windows.FileExplorer.Common (0x61000 bytes).
2026-05-28 18:46:47,700 [root] DEBUG: 3940: DLL loaded at 0x00007FFF973C0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 18:46:47,706 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 5832: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:47,707 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 9232: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:46:47,708 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 5832
2026-05-28 18:46:47,709 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 9232
2026-05-28 18:46:47,710 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 5832
2026-05-28 18:46:47,711 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 9232
2026-05-28 18:46:47,723 [root] DEBUG: 3940: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:46:47,724 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:46:47,761 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90A00000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 18:46:47,770 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7FFF0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 18:46:47,779 [root] DEBUG: 3940: DLL loaded at 0x00007FFF953C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:46:47,780 [root] DEBUG: 3940: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:46:48,078 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:46:48,078 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:46:48,082 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:46:48,086 [root] DEBUG: Loader: Injecting process 4348 (thread 6624) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:48,087 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:46:48,087 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:48,088 [lib.api.process] INFO: Injected into 64-bit <Process 4348 identity_helper.exe>
2026-05-28 18:46:48,093 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8E6A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 18:46:48,094 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8B370000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 18:46:48,096 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 9476: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000
2026-05-28 18:46:48,096 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9476
2026-05-28 18:46:48,096 [lib.api.process] INFO: Monitor config for process 9476: C:\2unxg6vp\dll\9476.ini
2026-05-28 18:46:48,097 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:46:48,121 [root] DEBUG: 3940: DLL loaded at 0x00007FFF85060000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:46:48,122 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8E370000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 18:46:48,123 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8ED20000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 18:46:48,168 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95D10000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 18:46:48,169 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95CD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 18:46:48,170 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8E580000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 18:46:48,172 [root] DEBUG: 3940: DLL loaded at 0x00007FFF98560000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 18:46:48,173 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8E460000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 18:46:48,176 [root] DEBUG: 3940: DLL loaded at 0x00007FFF834F0000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 18:46:48,184 [root] DEBUG: 3940: DLL loaded at 0x00007FFF95A00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 18:46:48,192 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:46:48,192 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:46:48,193 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:46:48,198 [root] DEBUG: Loader: Injecting process 9476 (thread 9480) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:48,199 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:46:48,199 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:48,200 [lib.api.process] INFO: Injected into 64-bit <Process 9476 identity_helper.exe>
2026-05-28 18:46:48,202 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9476
2026-05-28 18:46:48,204 [lib.api.process] INFO: Monitor config for process 9476: C:\2unxg6vp\dll\9476.ini
2026-05-28 18:46:48,204 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:46:48,282 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:46:48,282 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:46:48,290 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:46:48,295 [root] DEBUG: Loader: Injecting process 9476 (thread 9480) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:48,295 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:46:48,295 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:48,297 [lib.api.process] INFO: Injected into 64-bit <Process 9476 identity_helper.exe>
2026-05-28 18:46:48,312 [root] DEBUG: 9476: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:46:48,312 [root] DEBUG: 9476: Interactive desktop enabled.
2026-05-28 18:46:48,313 [root] DEBUG: 9476: Dropped file limit defaulting to 100.
2026-05-28 18:46:48,322 [root] DEBUG: 9476: Disabling sleep skipping.
2026-05-28 18:46:48,323 [root] DEBUG: 9476: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:46:48,336 [root] DEBUG: 9476: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:46:48,336 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:46:48,355 [root] DEBUG: 9476: Monitor initialised: 64-bit capemon loaded in process 9476 at 0x00007FFF52E70000, thread 9480, image base 0x00007FF61EFC0000, stack from 0x00000049BDCF4000-0x00000049BDD00000
2026-05-28 18:46:48,355 [root] DEBUG: 9476: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5596,i,5403315618307945275,2768811709255029521,524288 --field-trial-handle=2372,i,17606549636661606670,2325760670314557549,262144 --variations-seed-version --pseudonymization-salt-handle=2424,i,443589302954170710,1374137757521252920
2026-05-28 18:46:48,356 [root] DEBUG: 9476: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 18:46:48,369 [root] DEBUG: 9476: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:46:48,394 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:46:48,395 [root] DEBUG: 9476: set_hooks: Unable to hook LockResource
2026-05-28 18:46:48,399 [root] DEBUG: 9476: Hooked 627 out of 628 functions
2026-05-28 18:46:48,415 [root] DEBUG: 9476: Syscall hook installed, syscall logging level 1
2026-05-28 18:46:48,420 [root] DEBUG: 9476: RestoreHeaders: Restored original import table.
2026-05-28 18:46:48,420 [root] INFO: Loaded monitor into process with pid 9476
2026-05-28 18:46:48,421 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:46:48,507 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:46:48,539 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:46:48,566 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:46:48,591 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:46:48,616 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:46:48,640 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:46:48,667 [root] DEBUG: 9476: caller_dispatch: Added region at 0x00007FFF52110000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF5230F156, thread 9480).
2026-05-28 18:46:48,668 [root] DEBUG: 9476: caller_dispatch: Scanning calling region at 0x00007FFF52110000...
2026-05-28 18:46:48,675 [root] DEBUG: 9476: ProcessTrackedRegion: Region at 0x00007FFF52110000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 18:46:48,677 [root] DEBUG: 9476: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 18:46:48,700 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:46:48,717 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:46:48,733 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:46:48,749 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:46:48,765 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:46:48,781 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:46:48,798 [root] DEBUG: 9476: caller_dispatch: Added region at 0x00007FF61EFC0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF61F0B4096, thread 9480).
2026-05-28 18:46:48,798 [root] DEBUG: 9476: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:46:48,815 [root] DEBUG: 9476: ProcessImageBase: Main module image at 0x00007FF61EFC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:46:48,820 [root] DEBUG: 9476: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:46:48,846 [root] DEBUG: 9476: DLL loaded at 0x0000022139000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 18:46:48,851 [root] DEBUG: 9476: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:46:48,853 [root] DEBUG: 9476: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:46:48,884 [root] DEBUG: 9476: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:46:48,889 [root] DEBUG: 9476: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:46:48,895 [root] DEBUG: 9476: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:46:48,896 [root] DEBUG: 9476: DLL loaded at 0x00007FFF91EB0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 18:46:48,896 [root] DEBUG: 9476: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:46:48,897 [root] DEBUG: 9476: DLL loaded at 0x00007FFF84D00000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 18:46:48,904 [root] DEBUG: 9476: DLL loaded at 0x00007FFF90DA0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:46:48,905 [root] DEBUG: 9476: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:46:48,906 [root] DEBUG: 9476: DLL loaded at 0x00007FFF94110000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:46:48,907 [root] DEBUG: 9476: DLL loaded at 0x00007FFF91E70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:46:48,909 [root] DEBUG: 9476: DLL loaded at 0x00007FFF82770000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:46:48,917 [root] DEBUG: 9476: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:46:48,925 [root] DEBUG: 9476: DLL loaded at 0x00007FFF833F0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 18:46:48,931 [root] DEBUG: 9476: DLL loaded at 0x00007FFF953C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:46:48,932 [root] DEBUG: 9476: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:46:48,934 [root] DEBUG: 9476: DLL loaded at 0x00007FFF916B0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:46:48,944 [root] DEBUG: 9476: DLL loaded at 0x00007FFF8B820000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:46:48,946 [root] DEBUG: 9476: DLL loaded at 0x00007FFF8F850000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 18:46:48,953 [root] DEBUG: 9476: DLL loaded at 0x00007FFF96A80000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 18:46:48,953 [root] DEBUG: 9476: DLL loaded at 0x00007FFF8E6A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 18:46:48,957 [root] DEBUG: 9476: DLL loaded at 0x00007FFF95E30000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 18:46:48,969 [root] DEBUG: 9476: DLL loaded at 0x00007FFF85060000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:46:48,977 [root] DEBUG: 9476: DLL loaded at 0x00007FFF70D80000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 18:46:48,982 [lib.api.process] INFO: Monitor config for process 840: C:\2unxg6vp\dll\840.ini
2026-05-28 18:46:48,982 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:46:48,983 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:46:48,990 [root] DEBUG: Loader: Injecting process 840 with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:48,992 [root] DEBUG: 840: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:46:48,992 [root] DEBUG: 840: Disabling sleep skipping.
2026-05-28 18:46:48,992 [root] DEBUG: 840: Interactive desktop enabled.
2026-05-28 18:46:48,993 [root] DEBUG: 840: Dropped file limit defaulting to 100.
2026-05-28 18:46:48,993 [root] DEBUG: 840: Services hook set enabled
2026-05-28 18:46:48,995 [root] DEBUG: 840: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:46:49,007 [root] DEBUG: 840: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:46:49,007 [root] DEBUG: 840: Monitor initialised: 64-bit capemon loaded in process 840 at 0x00007FFF52E70000, thread 9984, image base 0x00007FF71F590000, stack from 0x000000B0F62F4000-0x000000B0F6300000
2026-05-28 18:46:49,008 [root] DEBUG: 840: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 18:46:49,020 [root] DEBUG: 840: Hooked 69 out of 69 functions
2026-05-28 18:46:49,021 [root] INFO: Loaded monitor into process with pid 840
2026-05-28 18:46:49,022 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:46:49,022 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:46:49,024 [lib.api.process] INFO: Injected into 64-bit <Process 840 svchost.exe>
2026-05-28 18:46:51,038 [root] DEBUG: 9476: DLL loaded at 0x00007FFF89AB0000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 18:46:51,039 [root] DEBUG: 9476: DLL loaded at 0x00007FFF89B70000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 18:46:51,039 [root] DEBUG: 9476: DLL loaded at 0x00007FFF82980000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 18:46:51,041 [root] DEBUG: 9476: DLL loaded at 0x00007FFF7D640000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 18:46:51,055 [root] DEBUG: 9476: DLL loaded at 0x00007FFF8ECC0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 18:46:51,083 [root] DEBUG: 9476: DLL loaded at 0x00007FFF94BF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 18:46:51,084 [root] DEBUG: 9476: DLL loaded at 0x00007FFF92740000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 18:46:51,098 [root] DEBUG: 9476: DLL loaded at 0x00007FFF87A50000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 18:46:51,099 [root] DEBUG: 9476: DLL loaded at 0x00007FFF7C210000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 18:46:51,122 [root] DEBUG: 9476: DLL loaded at 0x00007FFF7D000000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 18:46:51,144 [root] DEBUG: 9476: DLL loaded at 0x00007FFF96220000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 18:46:51,144 [root] DEBUG: 9476: DLL loaded at 0x00007FFF95CA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 18:46:51,145 [root] DEBUG: 9476: DLL loaded at 0x00007FFF94410000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:46:51,146 [root] DEBUG: 9476: DLL loaded at 0x00007FFF8B3C0000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 18:46:51,146 [root] DEBUG: 9476: DLL loaded at 0x00007FFF81F70000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 18:46:51,171 [root] DEBUG: 9476: DLL loaded at 0x00007FFF7C440000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 18:46:51,251 [root] DEBUG: 9476: DLL loaded at 0x00007FFF8A550000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 18:46:51,293 [root] DEBUG: 9476: DLL loaded at 0x00007FFF96AF0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 18:47:01,382 [root] INFO: Process with pid 9476 has terminated
2026-05-28 18:47:01,383 [root] DEBUG: 9476: NtTerminateProcess hook: Attempting to dump process 9476
2026-05-28 18:47:01,386 [root] DEBUG: 9476: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:47:07,990 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 1716: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:47:07,991 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 1716
2026-05-28 18:47:07,993 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 1716
2026-05-28 18:47:13,427 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8B970000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 18:47:13,430 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8B390000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 18:47:13,434 [root] DEBUG: 3940: DLL loaded at 0x00007FFF86C10000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 18:47:15,671 [root] DEBUG: 3940: DLL loaded at 0x00007FFF8BE10000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 18:47:15,812 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 6736: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:47:15,813 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 6736
2026-05-28 18:47:15,815 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 6736
2026-05-28 18:47:16,642 [root] DEBUG: 4676: DLL loaded at 0x00007FFF816D0000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 18:47:16,690 [lib.api.process] INFO: Monitor config for process 4676: C:\2unxg6vp\dll\4676.ini
2026-05-28 18:47:16,691 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:16,692 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:16,696 [root] DEBUG: Loader: Injecting process 4676 with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:16,697 [root] DEBUG: 4676: caller_dispatch: Added region at 0x0000000001360000 to tracked regions list (ntdll::LdrLoadDll returns to 0x0000000001360043, thread 10232).
2026-05-28 18:47:16,697 [root] DEBUG: 4676: DumpPEsInRange: Scanning range 0x0000000001360000 - 0x0000000001360134.
2026-05-28 18:47:16,697 [root] DEBUG: 4676: ScanForDisguisedPE: Size too small: 0x134 bytes
2026-05-28 18:47:16,699 [lib.common.results] INFO: Uploading file C:\uJcYLDyRT\CAPE\4676_2812616472228452026 to CAPE\f754d4d1b39837a4af2b3a4667e142d75512f7888597d22da01fcd45c9548325; Size is 308; Max size: 100000000
2026-05-28 18:47:16,700 [root] DEBUG: 4676: DumpMemory: Payload successfully created: C:\uJcYLDyRT\CAPE\4676_2812616472228452026 (size 308 bytes)
2026-05-28 18:47:16,701 [root] DEBUG: 4676: DumpRegion: Dumped entire allocation from 0x0000000001360000, size 4096 bytes.
2026-05-28 18:47:16,701 [root] DEBUG: 4676: ProcessTrackedRegion: Dumped region at 0x0000000001360000.
2026-05-28 18:47:16,701 [root] DEBUG: 4676: YaraScan: Scanning 0x0000000001360000, size 0x134
2026-05-28 18:47:16,703 [root] DEBUG: 4676: Monitor config - unrecognised key host-ip.
2026-05-28 18:47:16,703 [root] DEBUG: 4676: Monitor config - unrecognised key host-port.
2026-05-28 18:47:16,704 [root] DEBUG: 4676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:16,704 [root] DEBUG: 4676: Dropped file limit defaulting to 100.
2026-05-28 18:47:16,723 [root] DEBUG: 4676: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:47:16,760 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:47:16,761 [root] DEBUG: 4676: set_hooks: Unable to hook LockResource
2026-05-28 18:47:16,779 [root] DEBUG: 4676: Hooked 627 out of 628 functions
2026-05-28 18:47:16,808 [root] INFO: Loaded monitor into process with pid 4676
2026-05-28 18:47:16,811 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 18:47:16,811 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:18,116 [root] DEBUG: 4676: OpenProcessHandler: Image base for process 3940 (handle 0x2614): 0x00007FF6F9430000.
2026-05-28 18:47:18,123 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 3940, handle 0x2614: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:47:18,137 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 18:47:18,137 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 6404, handle 0x45c: Error obtaining target process name
2026-05-28 18:47:18,137 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 18:47:18,138 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 5968, handle 0x2214: Error obtaining target process name
2026-05-28 18:47:18,138 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 18:47:18,139 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 5676, handle 0x22f0: Error obtaining target process name
2026-05-28 18:47:18,139 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 18:47:18,139 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 3720, handle 0x22fc: Error obtaining target process name
2026-05-28 18:47:18,140 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 18:47:18,140 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 8812, handle 0x26c0: Error obtaining target process name
2026-05-28 18:47:18,141 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 18:47:18,142 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 5032, handle 0x20ec: Error obtaining target process name
2026-05-28 18:47:18,144 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 18:47:18,146 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 8804, handle 0x2330: Error obtaining target process name
2026-05-28 18:47:18,147 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 18:47:18,147 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 8172, handle 0xf30: Error obtaining target process name
2026-05-28 18:47:18,223 [root] DEBUG: 4676: OpenProcessHandler: Image base for process 5032 (handle 0x2184): 0x00007FF7013D0000.
2026-05-28 18:47:18,858 [root] DEBUG: 4676: DLL loaded at 0x0000000009A20000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 18:47:18,860 [root] DEBUG: 4676: DLL loaded at 0x0000000009A20000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 18:47:18,864 [root] DEBUG: 4676: DLL loaded at 0x0000000009470000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 18:47:18,866 [root] DEBUG: 4676: DLL loaded at 0x0000000009470000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 18:47:18,893 [root] INFO: Added new file to list with pid 4676 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 18:47:18,945 [root] DEBUG: 4676: DLL loaded at 0x00007FFF7AAD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 18:47:18,945 [root] DEBUG: 4676: DLL loaded at 0x00007FFF7AAD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 18:47:18,954 [root] DEBUG: 4676: DLL loaded at 0x00007FFF8ACE0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 18:47:18,954 [root] DEBUG: 4676: DLL loaded at 0x00007FFF8ACE0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 18:47:18,968 [root] DEBUG: 4676: DLL loaded at 0x00007FFF3A190000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 18:47:18,971 [root] DEBUG: 4676: DLL loaded at 0x00007FFF3A190000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 18:47:19,026 [root] DEBUG: 4676: DLL loaded at 0x00007FFF816C0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 18:47:19,027 [root] DEBUG: 4676: DLL loaded at 0x00007FFF816C0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 18:47:19,034 [root] DEBUG: 4676: DLL loaded at 0x00007FFF397F0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 18:47:19,035 [root] DEBUG: 4676: DLL loaded at 0x00007FFF397F0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 18:47:19,154 [root] INFO: Added new file to list with pid 4676 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 18:47:19,494 [root] DEBUG: 4676: DLL loaded at 0x00007FFF7C0E0000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 18:47:19,495 [root] DEBUG: 4676: DLL loaded at 0x00007FFF7C0E0000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 18:47:19,498 [root] DEBUG: 4676: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 18:47:19,617 [root] DEBUG: 4676: api-rate-cap: IsDebuggerPresent hook disabled due to rate
2026-05-28 18:47:19,653 [root] INFO: Added new file to list with pid 4676 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 18:47:19,666 [root] DEBUG: 4676: DLL loaded at 0x00007FFF816A0000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 18:47:19,667 [root] DEBUG: 4676: DLL loaded at 0x00007FFF816A0000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 18:47:19,712 [root] DEBUG: 4676: DLL loaded at 0x00007FFF84A60000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 18:47:19,713 [root] DEBUG: 4676: DLL loaded at 0x00007FFF84A60000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 18:47:19,855 [root] DEBUG: 4676: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 18:47:19,895 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 10520: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:47:19,896 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10520
2026-05-28 18:47:19,896 [lib.api.process] INFO: Monitor config for process 10520: C:\2unxg6vp\dll\10520.ini
2026-05-28 18:47:19,897 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:19,898 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:19,903 [root] DEBUG: Loader: Injecting process 10520 (thread 10524) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:19,904 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:19,905 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:19,908 [lib.api.process] INFO: Injected into 64-bit <Process 10520 dllhost.exe>
2026-05-28 18:47:19,909 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10520
2026-05-28 18:47:19,909 [lib.api.process] INFO: Monitor config for process 10520: C:\2unxg6vp\dll\10520.ini
2026-05-28 18:47:19,910 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:19,911 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:19,915 [root] DEBUG: Loader: Injecting process 10520 (thread 10524) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:19,920 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:19,921 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:19,923 [lib.api.process] INFO: Injected into 64-bit <Process 10520 dllhost.exe>
2026-05-28 18:47:19,932 [root] DEBUG: 10520: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:19,933 [root] DEBUG: 10520: Interactive desktop enabled.
2026-05-28 18:47:19,933 [root] DEBUG: 10520: Dropped file limit defaulting to 100.
2026-05-28 18:47:19,935 [root] DEBUG: 10520: Disabling sleep skipping.
2026-05-28 18:47:19,937 [root] DEBUG: 10520: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:47:19,949 [root] DEBUG: 10520: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:47:19,950 [root] DEBUG: 10520: YaraScan: Scanning 0x00007FF7BDF50000, size 0x8026
2026-05-28 18:47:19,951 [root] DEBUG: 10520: Monitor initialised: 64-bit capemon loaded in process 10520 at 0x00007FFF52E70000, thread 10524, image base 0x00007FF7BDF50000, stack from 0x0000000128CF4000-0x0000000128D00000
2026-05-28 18:47:19,951 [root] DEBUG: 10520: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 18:47:19,962 [root] DEBUG: 10520: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:47:19,983 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:47:19,983 [root] DEBUG: 10520: set_hooks: Unable to hook LockResource
2026-05-28 18:47:19,990 [root] DEBUG: 10520: Hooked 627 out of 628 functions
2026-05-28 18:47:19,991 [root] DEBUG: 10520: Syscall hook installed, syscall logging level 1
2026-05-28 18:47:20,000 [root] DEBUG: 10520: RestoreHeaders: Restored original import table.
2026-05-28 18:47:20,002 [root] INFO: Loaded monitor into process with pid 10520
2026-05-28 18:47:20,005 [root] DEBUG: 10520: caller_dispatch: Added region at 0x00007FF7BDF50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7BDF512F2, thread 10524).
2026-05-28 18:47:20,006 [root] DEBUG: 10520: YaraScan: Scanning 0x00007FF7BDF50000, size 0x8026
2026-05-28 18:47:20,008 [root] DEBUG: 10520: ProcessImageBase: Main module image at 0x00007FF7BDF50000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:47:20,011 [root] DEBUG: 10520: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:47:20,012 [root] DEBUG: 10520: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:47:20,014 [root] DEBUG: 10520: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:47:20,028 [root] DEBUG: 10520: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:47:20,044 [root] DEBUG: 10520: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:47:20,045 [root] DEBUG: 10520: DLL loaded at 0x00007FFF7FFF0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 18:47:20,051 [root] DEBUG: 10520: DLL loaded at 0x00007FFF91EB0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 18:47:22,354 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 12204: C:\Windows\System32\rundll32.exe, ImageBase: 0x00007FF6347E0000
2026-05-28 18:47:22,355 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 12204
2026-05-28 18:47:22,356 [lib.api.process] INFO: Monitor config for process 12204: C:\2unxg6vp\dll\12204.ini
2026-05-28 18:47:22,356 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:22,357 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:22,362 [root] DEBUG: Loader: Injecting process 12204 (thread 12208) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:22,363 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:22,363 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:22,364 [lib.api.process] INFO: Injected into 64-bit <Process 12204 rundll32.exe>
2026-05-28 18:47:22,365 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 12204
2026-05-28 18:47:22,365 [lib.api.process] INFO: Monitor config for process 12204: C:\2unxg6vp\dll\12204.ini
2026-05-28 18:47:22,366 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:22,366 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:22,370 [root] DEBUG: Loader: Injecting process 12204 (thread 12208) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:22,371 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:47:22,372 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:22,373 [lib.api.process] INFO: Injected into 64-bit <Process 12204 rundll32.exe>
2026-05-28 18:47:22,380 [root] DEBUG: 12204: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:22,381 [root] DEBUG: 12204: Interactive desktop enabled.
2026-05-28 18:47:22,381 [root] DEBUG: 12204: Dropped file limit defaulting to 100.
2026-05-28 18:47:22,382 [root] DEBUG: 12204: Disabling sleep skipping.
2026-05-28 18:47:22,383 [root] DEBUG: 12204: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:47:22,395 [root] DEBUG: 12204: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:47:22,395 [root] DEBUG: 12204: YaraScan: Scanning 0x00007FF6347E0000, size 0x16100
2026-05-28 18:47:22,396 [root] DEBUG: 12204: Monitor initialised: 64-bit capemon loaded in process 12204 at 0x00007FFF52E70000, thread 12208, image base 0x00007FF6347E0000, stack from 0x0000008CF1DF4000-0x0000008CF1E00000
2026-05-28 18:47:22,397 [root] DEBUG: 12204: Commandline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
2026-05-28 18:47:22,408 [root] DEBUG: 12204: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:47:22,429 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:47:22,429 [root] DEBUG: 12204: set_hooks: Unable to hook LockResource
2026-05-28 18:47:22,433 [root] DEBUG: 12204: Hooked 627 out of 628 functions
2026-05-28 18:47:22,434 [root] DEBUG: 12204: Syscall hook installed, syscall logging level 1
2026-05-28 18:47:22,439 [root] DEBUG: 12204: RestoreHeaders: Restored original import table.
2026-05-28 18:47:22,440 [root] INFO: Loaded monitor into process with pid 12204
2026-05-28 18:47:22,440 [root] DEBUG: 12204: caller_dispatch: Added region at 0x00007FF6347E0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6347E6D01, thread 12208).
2026-05-28 18:47:22,441 [root] DEBUG: 12204: YaraScan: Scanning 0x00007FF6347E0000, size 0x16100
2026-05-28 18:47:22,442 [root] DEBUG: 12204: ProcessImageBase: Main module image at 0x00007FF6347E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:47:22,447 [root] DEBUG: 12204: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:47:22,448 [root] DEBUG: 12204: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:47:22,449 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 12204, handle 0x297c: C:\Windows\System32\rundll32.exe
2026-05-28 18:47:22,453 [root] DEBUG: 4676: DLL loaded at 0x00007FFF82E70000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 18:47:22,454 [root] DEBUG: 4676: DLL loaded at 0x00007FFF82E70000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 18:47:22,464 [root] DEBUG: 12204: NtTerminateProcess hook: Attempting to dump process 12204
2026-05-28 18:47:22,464 [root] DEBUG: 12204: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:47:22,472 [root] INFO: Process with pid 12204 has terminated
2026-05-28 18:47:23,945 [root] DEBUG: 4676: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 18:47:24,253 [root] DEBUG: 4676: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 18:47:25,146 [root] INFO: Process with pid 10520 has terminated
2026-05-28 18:47:25,148 [root] DEBUG: 10520: NtTerminateProcess hook: Attempting to dump process 10520
2026-05-28 18:47:25,149 [root] DEBUG: 10520: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:47:25,504 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 12408: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000
2026-05-28 18:47:25,505 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12408
2026-05-28 18:47:25,506 [lib.api.process] INFO: Monitor config for process 12408: C:\2unxg6vp\dll\12408.ini
2026-05-28 18:47:25,507 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:25,778 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:47:25,778 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:47:25,783 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:25,787 [root] DEBUG: Loader: Injecting process 12408 (thread 12412) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:25,788 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:25,788 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:25,790 [lib.api.process] INFO: Injected into 64-bit <Process 12408 identity_helper.exe>
2026-05-28 18:47:25,793 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 12464: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF61EFC0000
2026-05-28 18:47:25,793 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12464
2026-05-28 18:47:25,794 [lib.api.process] INFO: Monitor config for process 12464: C:\2unxg6vp\dll\12464.ini
2026-05-28 18:47:25,795 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:26,024 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:47:26,025 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:47:26,029 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:26,033 [root] DEBUG: Loader: Injecting process 12464 (thread 12468) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:26,034 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:26,035 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:26,036 [lib.api.process] INFO: Injected into 64-bit <Process 12464 identity_helper.exe>
2026-05-28 18:47:26,038 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12464
2026-05-28 18:47:26,039 [lib.api.process] INFO: Monitor config for process 12464: C:\2unxg6vp\dll\12464.ini
2026-05-28 18:47:26,039 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:26,281 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 18:47:26,282 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 18:47:26,285 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:26,290 [root] DEBUG: Loader: Injecting process 12464 (thread 12468) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:26,291 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:47:26,291 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:26,293 [lib.api.process] INFO: Injected into 64-bit <Process 12464 identity_helper.exe>
2026-05-28 18:47:26,299 [root] DEBUG: 12464: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:26,299 [root] DEBUG: 12464: Interactive desktop enabled.
2026-05-28 18:47:26,300 [root] DEBUG: 12464: Dropped file limit defaulting to 100.
2026-05-28 18:47:26,303 [root] DEBUG: 12464: Disabling sleep skipping.
2026-05-28 18:47:26,304 [root] DEBUG: 12464: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:47:26,316 [root] DEBUG: 12464: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:47:26,316 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:47:26,331 [root] DEBUG: 12464: Monitor initialised: 64-bit capemon loaded in process 12464 at 0x00007FFF52E70000, thread 12468, image base 0x00007FF61EFC0000, stack from 0x0000001D154F4000-0x0000001D15500000
2026-05-28 18:47:26,331 [root] DEBUG: 12464: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --ssd-no-pressure-read-main-dll --metrics-shmem-handle=6912,i,9149147640595882975,10546786927356998515,524288 --field-trial-handle=2372,i,17606549636661606670,2325760670314557549,262144 --variations-seed-version --pseudonymization-salt-handle=2424,i,443589302954170710,137413
2026-05-28 18:47:26,332 [root] DEBUG: 12464: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 18:47:26,342 [root] DEBUG: 12464: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:47:26,364 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:47:26,365 [root] DEBUG: 12464: set_hooks: Unable to hook LockResource
2026-05-28 18:47:26,369 [root] DEBUG: 12464: Hooked 627 out of 628 functions
2026-05-28 18:47:26,383 [root] DEBUG: 12464: Syscall hook installed, syscall logging level 1
2026-05-28 18:47:26,388 [root] DEBUG: 12464: RestoreHeaders: Restored original import table.
2026-05-28 18:47:26,388 [root] INFO: Loaded monitor into process with pid 12464
2026-05-28 18:47:26,389 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:47:26,415 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:47:26,440 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:47:26,465 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:47:26,491 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:47:26,515 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:47:26,540 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FFF52110000, size 0x4b9994
2026-05-28 18:47:26,567 [root] DEBUG: 12464: caller_dispatch: Added region at 0x00007FFF52110000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF5230F156, thread 12468).
2026-05-28 18:47:26,568 [root] DEBUG: 12464: caller_dispatch: Scanning calling region at 0x00007FFF52110000...
2026-05-28 18:47:26,572 [root] DEBUG: 12464: ProcessTrackedRegion: Region at 0x00007FFF52110000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 18:47:26,574 [root] DEBUG: 12464: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 18:47:26,598 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:47:26,614 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:47:26,628 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:47:26,643 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:47:26,658 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:47:26,673 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:47:26,690 [root] DEBUG: 12464: caller_dispatch: Added region at 0x00007FF61EFC0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF61F0B4096, thread 12468).
2026-05-28 18:47:26,691 [root] DEBUG: 12464: YaraScan: Scanning 0x00007FF61EFC0000, size 0x28b4d8
2026-05-28 18:47:26,706 [root] DEBUG: 12464: ProcessImageBase: Main module image at 0x00007FF61EFC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:47:26,709 [root] DEBUG: 12464: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:47:26,734 [root] DEBUG: 12464: DLL loaded at 0x0000015C59000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 18:47:26,737 [root] DEBUG: 12464: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:47:26,740 [root] DEBUG: 12464: DLL loaded at 0x00007FFF97F00000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 18:47:26,742 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 12464, handle 0x2228: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 18:47:26,767 [root] DEBUG: 12464: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:47:26,770 [root] DEBUG: 12464: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:47:26,772 [root] DEBUG: 12464: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:47:26,775 [root] DEBUG: 12464: DLL loaded at 0x00007FFF90DA0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 18:47:26,776 [root] DEBUG: 12464: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:47:26,777 [root] DEBUG: 12464: DLL loaded at 0x00007FFF85060000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 18:47:26,782 [root] DEBUG: 12464: DLL loaded at 0x00007FFF92180000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 18:47:26,783 [root] DEBUG: 12464: DLL loaded at 0x00007FFF70D80000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 18:47:26,807 [root] DEBUG: 12464: DLL loaded at 0x00007FFF94110000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 18:47:26,808 [root] DEBUG: 12464: DLL loaded at 0x00007FFF91E70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 18:47:26,809 [root] DEBUG: 12464: DLL loaded at 0x00007FFF82770000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 18:47:26,820 [root] DEBUG: 12464: DLL loaded at 0x00007FFF89AB0000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 18:47:26,820 [root] DEBUG: 12464: DLL loaded at 0x00007FFF89B70000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 18:47:26,821 [root] DEBUG: 12464: DLL loaded at 0x00007FFF82980000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 18:47:26,823 [root] DEBUG: 12464: DLL loaded at 0x00007FFF916B0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 18:47:26,829 [root] DEBUG: 12464: DLL loaded at 0x00007FFF8ECC0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 18:47:26,841 [root] DEBUG: 12464: DLL loaded at 0x00007FFF8B820000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 18:47:26,855 [root] DEBUG: 12464: DLL loaded at 0x00007FFF94BF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 18:47:26,856 [root] DEBUG: 12464: DLL loaded at 0x00007FFF92740000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 18:47:26,857 [root] DEBUG: 12464: DLL loaded at 0x00007FFF91EB0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 18:47:26,862 [root] DEBUG: 12464: DLL loaded at 0x00007FFF87A50000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 18:47:26,863 [root] DEBUG: 12464: DLL loaded at 0x00007FFF7C210000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 18:47:26,870 [root] DEBUG: 12464: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:47:26,883 [root] DEBUG: 12464: DLL loaded at 0x00007FFF7D000000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 18:47:26,906 [root] DEBUG: 12464: DLL loaded at 0x00007FFF96220000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 18:47:26,907 [root] DEBUG: 12464: DLL loaded at 0x00007FFF95CA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 18:47:26,908 [root] DEBUG: 12464: DLL loaded at 0x00007FFF94410000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 18:47:26,908 [root] DEBUG: 12464: DLL loaded at 0x00007FFF93840000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 18:47:26,909 [root] DEBUG: 12464: DLL loaded at 0x00007FFF8B3C0000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 18:47:26,910 [root] DEBUG: 12464: DLL loaded at 0x00007FFF81F70000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 18:47:31,855 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 13060: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:47:31,857 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 13060
2026-05-28 18:47:31,858 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 13060
2026-05-28 18:47:36,926 [root] INFO: Process with pid 12464 has terminated
2026-05-28 18:47:36,927 [root] DEBUG: 12464: NtTerminateProcess hook: Attempting to dump process 12464
2026-05-28 18:47:36,928 [root] DEBUG: 12464: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:47:41,663 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 12436: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:47:41,664 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12436
2026-05-28 18:47:41,665 [lib.api.process] INFO: Monitor config for process 12436: C:\2unxg6vp\dll\12436.ini
2026-05-28 18:47:41,665 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:41,669 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:41,671 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 12504: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7C5600000
2026-05-28 18:47:41,673 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 12504
2026-05-28 18:47:41,674 [lib.api.process] INFO: Monitor config for process 12504: C:\2unxg6vp\dll\12504.ini
2026-05-28 18:47:41,675 [root] DEBUG: Loader: Injecting process 12436 (thread 12432) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:41,675 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:41,676 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:41,676 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:41,678 [lib.api.process] INFO: Injected into 64-bit <Process 12436 dllhost.exe>
2026-05-28 18:47:41,679 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12436
2026-05-28 18:47:41,680 [lib.api.process] INFO: Monitor config for process 12436: C:\2unxg6vp\dll\12436.ini
2026-05-28 18:47:41,681 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:41,684 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:41,689 [root] DEBUG: Loader: Injecting process 12436 (thread 12432) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:41,691 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:41,691 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:41,692 [lib.api.process] INFO: Injected into 64-bit <Process 12436 dllhost.exe>
2026-05-28 18:47:41,700 [root] DEBUG: 12436: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:41,701 [root] DEBUG: 12436: Interactive desktop enabled.
2026-05-28 18:47:41,702 [root] DEBUG: 12436: Dropped file limit defaulting to 100.
2026-05-28 18:47:41,705 [root] DEBUG: 12436: Disabling sleep skipping.
2026-05-28 18:47:41,706 [root] DEBUG: 12436: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:47:41,717 [root] DEBUG: 12436: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:47:41,718 [root] DEBUG: 12436: YaraScan: Scanning 0x00007FF7BDF50000, size 0x8026
2026-05-28 18:47:41,720 [root] DEBUG: 12436: Monitor initialised: 64-bit capemon loaded in process 12436 at 0x00007FFF52E70000, thread 12432, image base 0x00007FF7BDF50000, stack from 0x000000EEFFFC4000-0x000000EEFFFD0000
2026-05-28 18:47:41,721 [root] DEBUG: 12436: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 18:47:41,731 [root] DEBUG: 12436: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:47:41,753 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:47:41,754 [root] DEBUG: 12436: set_hooks: Unable to hook LockResource
2026-05-28 18:47:41,759 [root] DEBUG: 12436: Hooked 627 out of 628 functions
2026-05-28 18:47:41,760 [root] DEBUG: 12436: Syscall hook installed, syscall logging level 1
2026-05-28 18:47:41,766 [root] DEBUG: 12436: RestoreHeaders: Restored original import table.
2026-05-28 18:47:41,768 [root] INFO: Loaded monitor into process with pid 12436
2026-05-28 18:47:41,769 [root] DEBUG: 12436: caller_dispatch: Added region at 0x00007FF7BDF50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7BDF512F2, thread 12432).
2026-05-28 18:47:41,769 [root] DEBUG: 12436: YaraScan: Scanning 0x00007FF7BDF50000, size 0x8026
2026-05-28 18:47:41,771 [root] DEBUG: 12436: ProcessImageBase: Main module image at 0x00007FF7BDF50000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:47:41,774 [root] DEBUG: 12436: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:47:41,776 [root] DEBUG: 12436: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:47:41,779 [root] DEBUG: 12436: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:47:41,795 [root] DEBUG: 12436: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:47:41,810 [root] DEBUG: 12436: DLL loaded at 0x00007FFF95800000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 18:47:41,811 [root] DEBUG: 12436: DLL loaded at 0x00007FFF95850000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 18:47:41,812 [root] DEBUG: 12436: DLL loaded at 0x00007FFF8EAB0000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 18:47:41,814 [root] DEBUG: 12436: DLL loaded at 0x00007FFF90780000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 18:47:41,815 [root] DEBUG: 12436: DLL loaded at 0x00007FFF95450000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 18:47:41,816 [root] DEBUG: 12436: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:47:41,817 [root] DEBUG: 12436: DLL loaded at 0x00007FFF956F0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 18:47:41,818 [root] DEBUG: 12436: DLL loaded at 0x00007FFF96220000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 18:47:41,819 [root] DEBUG: 12436: DLL loaded at 0x00007FFF96260000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 18:47:41,819 [root] DEBUG: 12436: DLL loaded at 0x00007FFF91E70000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 18:47:41,820 [root] DEBUG: 12436: DLL loaded at 0x00007FFF95730000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 18:47:41,822 [root] DEBUG: 12436: DLL loaded at 0x00007FFF393F0000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 18:47:41,825 [root] DEBUG: 12436: DLL loaded at 0x00007FFF98020000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 18:47:41,831 [root] DEBUG: 12436: DLL loaded at 0x00007FFF874D0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 18:47:42,237 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:42,242 [root] DEBUG: Loader: Injecting process 12504 (thread 12500) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,243 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:42,245 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,246 [lib.api.process] INFO: Injected into 64-bit <Process 12504 WmiPrvSE.exe>
2026-05-28 18:47:42,247 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 12504
2026-05-28 18:47:42,248 [lib.api.process] INFO: Monitor config for process 12504: C:\2unxg6vp\dll\12504.ini
2026-05-28 18:47:42,248 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:42,521 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 13548: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF6D47B0000
2026-05-28 18:47:42,522 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 13548
2026-05-28 18:47:42,523 [lib.api.process] INFO: Monitor config for process 13548: C:\2unxg6vp\dll\13548.ini
2026-05-28 18:47:42,524 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:42,528 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:42,533 [root] DEBUG: Loader: Injecting process 13548 (thread 13552) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,534 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:42,534 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,536 [lib.api.process] INFO: Injected into 64-bit <Process 13548 MoUsoCoreWorker.exe>
2026-05-28 18:47:42,537 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 13548
2026-05-28 18:47:42,538 [lib.api.process] INFO: Monitor config for process 13548: C:\2unxg6vp\dll\13548.ini
2026-05-28 18:47:42,538 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:42,541 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:42,546 [root] DEBUG: Loader: Injecting process 13548 (thread 13552) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,548 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:47:42,549 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,550 [lib.api.process] INFO: Injected into 64-bit <Process 13548 MoUsoCoreWorker.exe>
2026-05-28 18:47:42,564 [root] DEBUG: 13548: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:42,565 [root] DEBUG: 13548: Interactive desktop enabled.
2026-05-28 18:47:42,565 [root] DEBUG: 13548: Dropped file limit defaulting to 100.
2026-05-28 18:47:42,567 [root] DEBUG: 13548: VerifyCodeSection: Exception rebasing image from 0x00007FF6D47B0000 to 0x0000000140000000.
2026-05-28 18:47:42,570 [root] DEBUG: 13548: Disabling sleep skipping.
2026-05-28 18:47:42,571 [root] DEBUG: 13548: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:47:42,583 [root] DEBUG: 13548: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:47:42,584 [root] DEBUG: 13548: YaraScan: Scanning 0x00007FF6D47B0000, size 0x1ad000
2026-05-28 18:47:42,594 [root] DEBUG: 13548: Monitor initialised: 64-bit capemon loaded in process 13548 at 0x00007FFF52E70000, thread 13552, image base 0x00007FF6D47B0000, stack from 0x0000008094554000-0x0000008094560000
2026-05-28 18:47:42,595 [root] DEBUG: 13548: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-05-28 18:47:42,611 [root] DEBUG: 13548: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:47:42,633 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:47:42,634 [root] DEBUG: 13548: set_hooks: Unable to hook LockResource
2026-05-28 18:47:42,643 [root] DEBUG: 13548: Hooked 627 out of 628 functions
2026-05-28 18:47:42,653 [root] DEBUG: 13548: Syscall hook installed, syscall logging level 1
2026-05-28 18:47:42,659 [root] DEBUG: 13548: RestoreHeaders: Restored original import table.
2026-05-28 18:47:42,661 [root] INFO: Loaded monitor into process with pid 13548
2026-05-28 18:47:42,668 [root] DEBUG: 13548: caller_dispatch: Added region at 0x00007FF6D47B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6D48CF712, thread 13552).
2026-05-28 18:47:42,669 [root] DEBUG: 13548: YaraScan: Scanning 0x00007FF6D47B0000, size 0x1ad000
2026-05-28 18:47:42,681 [root] DEBUG: 13548: ProcessImageBase: Main module image at 0x00007FF6D47B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:47:42,685 [root] DEBUG: 13548: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:47:42,687 [root] DEBUG: 13548: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:47:42,717 [root] DEBUG: 13548: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 18:47:42,735 [root] DEBUG: 13548: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:47:42,752 [root] DEBUG: 13548: DLL loaded at 0x00007FFF8A930000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-05-28 18:47:42,795 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:42,803 [root] DEBUG: Loader: Injecting process 12504 (thread 12500) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,804 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:47:42,805 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,806 [lib.api.process] INFO: Injected into 64-bit <Process 12504 WmiPrvSE.exe>
2026-05-28 18:47:42,817 [root] DEBUG: 12504: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:42,818 [root] DEBUG: 12504: Interactive desktop enabled.
2026-05-28 18:47:42,819 [root] DEBUG: 12504: Dropped file limit defaulting to 100.
2026-05-28 18:47:42,820 [root] DEBUG: 12504: Disabling sleep skipping.
2026-05-28 18:47:42,821 [root] DEBUG: 12504: Services hook set enabled
2026-05-28 18:47:42,823 [root] DEBUG: 12504: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:47:42,836 [root] DEBUG: 12504: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:47:42,838 [root] DEBUG: 12504: Monitor initialised: 64-bit capemon loaded in process 12504 at 0x00007FFF52E70000, thread 12500, image base 0x00007FF7C5600000, stack from 0x000000176BF40000-0x000000176BF50000
2026-05-28 18:47:42,840 [root] DEBUG: 12504: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 18:47:42,853 [root] DEBUG: 12504: Hooked 69 out of 69 functions
2026-05-28 18:47:42,857 [root] DEBUG: 12504: RestoreHeaders: Restored original import table.
2026-05-28 18:47:42,858 [root] INFO: Loaded monitor into process with pid 12504
2026-05-28 18:47:42,861 [root] DEBUG: 12504: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:47:42,862 [root] DEBUG: 12504: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:47:42,866 [root] DEBUG: 12504: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:47:42,869 [lib.api.process] INFO: Monitor config for process 3788: C:\2unxg6vp\dll\3788.ini
2026-05-28 18:47:42,870 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:42,874 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:42,879 [root] DEBUG: Loader: Injecting process 3788 with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,881 [root] DEBUG: 3788: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:42,882 [root] DEBUG: 3788: Disabling sleep skipping.
2026-05-28 18:47:42,882 [root] DEBUG: 3788: Interactive desktop enabled.
2026-05-28 18:47:42,883 [root] DEBUG: 3788: Dropped file limit defaulting to 100.
2026-05-28 18:47:42,884 [root] DEBUG: 3788: Services hook set enabled
2026-05-28 18:47:42,886 [root] DEBUG: 3788: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:47:42,898 [root] DEBUG: 3788: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:47:42,899 [root] DEBUG: 3788: Monitor initialised: 64-bit capemon loaded in process 3788 at 0x00007FFF52E70000, thread 14056, image base 0x00007FF71F590000, stack from 0x000000AEDC874000-0x000000AEDC880000
2026-05-28 18:47:42,899 [root] DEBUG: 3788: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 18:47:42,912 [root] DEBUG: 3788: Hooked 69 out of 69 functions
2026-05-28 18:47:42,913 [root] INFO: Loaded monitor into process with pid 3788
2026-05-28 18:47:42,914 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:47:42,914 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:42,916 [lib.api.process] INFO: Injected into 64-bit <Process 3788 svchost.exe>
2026-05-28 18:47:42,967 [root] DEBUG: 13548: DLL loaded at 0x00007FFF90780000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 18:47:42,968 [root] DEBUG: 13548: DLL loaded at 0x00007FFF960B0000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 18:47:42,969 [root] DEBUG: 13548: DLL loaded at 0x00007FFF388C0000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-05-28 18:47:42,988 [root] DEBUG: 13548: DLL loaded at 0x00007FFF80CA0000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 18:47:43,007 [root] DEBUG: 13548: DLL loaded at 0x00007FFF93940000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 18:47:43,009 [root] DEBUG: 13548: DLL loaded at 0x00007FFF91FE0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 18:47:43,011 [root] DEBUG: 13548: DLL loaded at 0x00007FFF95FF0000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-05-28 18:47:43,062 [root] DEBUG: 13548: api-rate-cap: NtReadFile hook disabled due to rate
2026-05-28 18:47:43,106 [root] DEBUG: 13548: DLL loaded at 0x00007FFF93940000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 18:47:43,360 [root] DEBUG: 4676: DLL loaded at 0x00007FFF387B0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 18:47:43,361 [root] DEBUG: 4676: DLL loaded at 0x00007FFF387B0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 18:47:43,398 [root] DEBUG: 4676: DLL loaded at 0x00007FFF869C0000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 18:47:43,399 [root] DEBUG: 4676: DLL loaded at 0x00007FFF869C0000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 18:47:43,446 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38790000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 18:47:43,447 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38790000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 18:47:43,509 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38650000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 18:47:43,510 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38650000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 18:47:43,511 [root] DEBUG: 4676: DLL loaded at 0x00007FFF94030000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 18:47:43,512 [root] DEBUG: 4676: DLL loaded at 0x00007FFF94030000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 18:47:43,512 [root] DEBUG: 4676: DLL loaded at 0x00007FFF386B0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 18:47:43,513 [root] DEBUG: 4676: DLL loaded at 0x00007FFF386B0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 18:47:43,631 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38630000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 18:47:43,633 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38630000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 18:47:43,689 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38540000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 18:47:43,690 [root] DEBUG: 4676: DLL loaded at 0x00007FFF38540000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 18:47:44,923 [root] DEBUG: 12504: DLL loaded at 0x00007FFF82DC0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 18:47:44,960 [root] DEBUG: 12504: DLL loaded at 0x00007FFF82A50000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 18:47:44,989 [root] DEBUG: 12504: DLL loaded at 0x00007FFF81590000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 18:47:45,003 [root] DEBUG: 12504: DLL loaded at 0x00007FFF96190000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 18:47:45,004 [root] DEBUG: 12504: DLL loaded at 0x00007FFF38650000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 18:47:45,005 [root] DEBUG: 12504: DLL loaded at 0x00007FFF38020000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 18:47:45,006 [root] DEBUG: 12504: DLL loaded at 0x00007FFF96170000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 18:47:45,014 [root] DEBUG: 12504: DLL loaded at 0x0000013F84810000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 18:47:45,015 [root] DEBUG: 12504: DLL loaded at 0x00007FFF90640000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 18:47:45,017 [root] DEBUG: 12504: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 18:47:45,036 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 13912: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:47:45,038 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 13912
2026-05-28 18:47:45,042 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 13912
2026-05-28 18:47:45,696 [root] DEBUG: 13548: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 18:47:45,797 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94E40000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 18:47:45,799 [root] DEBUG: 3940: DLL loaded at 0x00007FFF94E70000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-28 18:47:45,800 [root] DEBUG: 3940: DLL loaded at 0x00007FFF38520000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-28 18:47:45,815 [root] DEBUG: 3940: DLL loaded at 0x00007FFF38500000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 18:47:45,853 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 14036: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:47:45,854 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 14036
2026-05-28 18:47:45,855 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 14036
2026-05-28 18:47:45,955 [root] DEBUG: 3940: DLL loaded at 0x00007FFF383D0000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-28 18:47:46,393 [root] INFO: Announced starting service "b'BITS'"
2026-05-28 18:47:46,395 [lib.api.process] INFO: Monitor config for process 672: C:\2unxg6vp\dll\672.ini
2026-05-28 18:47:46,396 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:46,400 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:46,404 [root] DEBUG: Loader: Injecting process 672 with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:46,405 [root] DEBUG: Loader: Copied config file C:\2unxg6vp\dll\672.ini to system path C:\672.ini
2026-05-28 18:47:46,408 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 672 C:\2unxg6vp\dll\lvMMtOS.dll
2026-05-28 18:47:46,409 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:46,410 [lib.api.process] INFO: Injected into 64-bit <Process 672 services.exe>
2026-05-28 18:47:46,846 [root] INFO: Process with pid 12436 has terminated
2026-05-28 18:47:46,847 [root] DEBUG: 12436: NtTerminateProcess hook: Attempting to dump process 12436
2026-05-28 18:47:46,848 [root] DEBUG: 12436: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:47:47,578 [root] DEBUG: 13548: DLL loaded at 0x00007FFF953C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 18:47:47,579 [root] DEBUG: 13548: DLL loaded at 0x00007FFF90020000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 18:47:47,584 [root] DEBUG: 13548: DLL loaded at 0x00007FFF39450000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 18:47:47,585 [root] DEBUG: 13548: DLL loaded at 0x00007FFF80EB0000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 18:47:47,587 [root] DEBUG: 13548: DLL loaded at 0x00007FFF82B00000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 18:47:47,590 [root] DEBUG: 13548: DLL loaded at 0x00007FFF8E350000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 18:47:47,595 [root] DEBUG: 13548: DLL loaded at 0x00007FFF92180000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 18:47:47,600 [root] DEBUG: 13548: DLL loaded at 0x00007FFF82D10000: C:\Windows\SYSTEM32\productenumerator (0xe000 bytes).
2026-05-28 18:47:47,895 [root] INFO: Stopping Task Scheduler Service
2026-05-28 18:47:47,908 [root] INFO: Stopped Task Scheduler Service
2026-05-28 18:47:47,912 [root] INFO: Starting Task Scheduler Service
2026-05-28 18:47:47,922 [root] INFO: Started Task Scheduler Service
2026-05-28 18:47:47,924 [lib.api.process] INFO: Monitor config for process 1384: C:\2unxg6vp\dll\1384.ini
2026-05-28 18:47:47,926 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:47:47,930 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:47:47,934 [root] DEBUG: Loader: Injecting process 1384 with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:47,937 [root] DEBUG: 1384: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:47:47,938 [root] DEBUG: 1384: Disabling sleep skipping.
2026-05-28 18:47:47,938 [root] DEBUG: 1384: Interactive desktop enabled.
2026-05-28 18:47:47,939 [root] DEBUG: 1384: Dropped file limit defaulting to 100.
2026-05-28 18:47:47,941 [root] DEBUG: 1384: Services hook set enabled
2026-05-28 18:47:47,943 [root] DEBUG: 1384: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:47:47,954 [root] DEBUG: 1384: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:47:47,955 [root] DEBUG: 1384: Monitor initialised: 64-bit capemon loaded in process 1384 at 0x00007FFF52E70000, thread 14936, image base 0x00007FF71F590000, stack from 0x000000173BDF5000-0x000000173BE00000
2026-05-28 18:47:47,956 [root] DEBUG: 1384: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-28 18:47:47,969 [root] DEBUG: 1384: Hooked 69 out of 69 functions
2026-05-28 18:47:47,970 [root] INFO: Loaded monitor into process with pid 1384
2026-05-28 18:47:47,970 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 18:47:47,971 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:47:47,973 [lib.api.process] INFO: Injected into 64-bit <Process 1384 svchost.exe>
2026-05-28 18:47:49,984 [root] DEBUG: 13548: DLL loaded at 0x00007FFF913D0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 18:47:50,044 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-28 18:47:51,078 [root] DEBUG: 13548: DLL loaded at 0x00007FFF81580000: C:\Windows\system32\WaaSMedicPS (0xc000 bytes).
2026-05-28 18:47:51,195 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\a6b47188e77e3e06260644ebe7512b745cc6d9a008ef72c46678dcf97a0b5f54; Size is 8720; Max size: 100000000
2026-05-28 18:47:51,230 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\fa17aed7c05897fc7340f5a25ecf7e2eb97449c2208a42f7de2cb685d96395de; Size is 8720; Max size: 100000000
2026-05-28 18:47:51,258 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\32e6fb614cf11d69d3257f65a2c45473a520837c93e3d203868f9a5a105a364a; Size is 8720; Max size: 100000000
2026-05-28 18:47:51,278 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\aae2871b4f6eb730063d0de55a249c29416db79f266093f4057e81c638edad64; Size is 8720; Max size: 100000000
2026-05-28 18:47:51,367 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\421b1b8865fa81af6b58aede5447d4f33ff34002e12abc85450494e29a5e3c95; Size is 8720; Max size: 100000000
2026-05-28 18:47:51,425 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\75a2545951bf26a31c19e93092342261d0dea7ce55cb5d81c2da90f5bc83e580; Size is 12824; Max size: 100000000
2026-05-28 18:47:52,255 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 15268: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:47:52,257 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 15268
2026-05-28 18:47:52,258 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 15268
2026-05-28 18:47:53,735 [root] DEBUG: 3940: DLL loaded at 0x00007FFF7FD30000: C:\Windows\System32\BitsProxy (0x16000 bytes).
2026-05-28 18:47:55,132 [root] DEBUG: 3940: CreateProcessHandler: Injection info set for new process 14848: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6F9430000
2026-05-28 18:47:55,133 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 14848
2026-05-28 18:47:55,134 [root] DEBUG: 3940: ProcessMessage: Skipping monitoring process 14848
2026-05-28 18:47:55,201 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 14900, handle 0x2b38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:47:55,208 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 14848, handle 0x2be8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 18:47:55,321 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 18:47:55,378 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 9332, handle 0x2be8: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 18:47:56,078 [root] INFO: Process with pid 3940 appears to have terminated
2026-05-28 18:47:56,550 [root] DEBUG: 4676: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 18:47:59,758 [root] INFO: Announced starting service "b'lfsvc'"
2026-05-28 18:48:00,074 [root] DEBUG: 4676: DLL loaded at 0x00007FFF861A0000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 18:48:00,076 [root] DEBUG: 4676: DLL loaded at 0x00007FFF861A0000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 18:48:00,098 [root] DEBUG: 4676: AllocationHandler: Adding allocation to tracked region list: 0x00007DF45BCF1000, size: 0x1000.
2026-05-28 18:48:00,101 [root] DEBUG: 4676: AllocationHandler: Adding allocation to tracked region list: 0x00007DF45BCD1000, size: 0x1000.
2026-05-28 18:48:00,104 [root] DEBUG: 4676: AllocationHandler: Adding allocation to tracked region list: 0x00007DF45BCC1000, size: 0x1000.
2026-05-28 18:48:00,118 [root] DEBUG: 4676: AllocationHandler: Adding allocation to tracked region list: 0x00007DF45BCB1000, size: 0x1000.
2026-05-28 18:48:00,127 [root] DEBUG: 4676: DLL loaded at 0x00007FFF81680000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 18:48:00,128 [root] DEBUG: 4676: DLL loaded at 0x00007FFF81680000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 18:48:00,152 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 2264: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF7DA400000
2026-05-28 18:48:00,153 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 2264
2026-05-28 18:48:00,155 [lib.api.process] INFO: Monitor config for process 2264: C:\2unxg6vp\dll\2264.ini
2026-05-28 18:48:00,156 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:00,161 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:00,166 [root] DEBUG: Loader: Injecting process 2264 (thread 3676) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:00,166 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:00,167 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:00,168 [lib.api.process] INFO: Injected into 64-bit <Process 2264 CHXSmartScreen.exe>
2026-05-28 18:48:00,170 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 2264
2026-05-28 18:48:00,170 [lib.api.process] INFO: Monitor config for process 2264: C:\2unxg6vp\dll\2264.ini
2026-05-28 18:48:00,171 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:00,173 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:00,180 [root] DEBUG: Loader: Injecting process 2264 (thread 3676) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:00,181 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:00,182 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:00,183 [lib.api.process] INFO: Injected into 64-bit <Process 2264 CHXSmartScreen.exe>
2026-05-28 18:48:00,186 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 2264
2026-05-28 18:48:00,187 [lib.api.process] INFO: Monitor config for process 2264: C:\2unxg6vp\dll\2264.ini
2026-05-28 18:48:00,190 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:00,197 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:00,202 [root] DEBUG: Loader: Injecting process 2264 with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:00,203 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 3676, handle 0x124
2026-05-28 18:48:00,206 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:48:00,207 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:00,209 [lib.api.process] INFO: Injected into 64-bit <Process 2264 CHXSmartScreen.exe>
2026-05-28 18:48:00,338 [root] DEBUG: 4676: OpenProcessHandler: Injection info created for process 2444, handle 0xb98: C:\Windows\System32\rundll32.exe
2026-05-28 18:48:00,695 [root] DEBUG: 4676: FreeHandler: Address: 0x00007DF45BCB0000.
2026-05-28 18:48:00,696 [root] DEBUG: 4676: ScanForNonZero: Error - Supplied size zero.
2026-05-28 18:48:00,697 [root] DEBUG: 4676: FreeHandler: Address: 0x00007DF45BCD0000.
2026-05-28 18:48:00,698 [root] DEBUG: 4676: ScanForNonZero: Error - Supplied size zero.
2026-05-28 18:48:00,701 [root] DEBUG: 4676: FreeHandler: Address: 0x00007DF45BCC0000.
2026-05-28 18:48:00,704 [root] DEBUG: 4676: ScanForNonZero: Error - Supplied size zero.
2026-05-28 18:48:04,017 [root] DEBUG: 4676: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 18:48:04,018 [root] DEBUG: 4676: api-cap: NtQueryInformationToken hook disabled due to count: 5001
2026-05-28 18:48:08,012 [root] DEBUG: 4676: api-rate-cap: NtQueryKey hook disabled due to rate
2026-05-28 18:48:08,217 [root] DEBUG: 4676: AllocationHandler: Allocation already in tracked region list: 0x00007DF45BCF0000.
2026-05-28 18:48:08,220 [root] DEBUG: 4676: AllocationHandler: Adding allocation to tracked region list: 0x00007DF45BCE1000, size: 0x1000.
2026-05-28 18:48:08,220 [root] DEBUG: 4676: AllocationHandler: Allocation already in tracked region list: 0x00007DF45BCD0000.
2026-05-28 18:48:08,221 [root] DEBUG: 4676: AllocationHandler: Allocation already in tracked region list: 0x00007DF45BCC0000.
2026-05-28 18:48:08,239 [root] DEBUG: 4676: AllocationHandler: Allocation already in tracked region list: 0x00007DF45BCB0000.
2026-05-28 18:48:08,259 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 5944: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF7DA400000
2026-05-28 18:48:08,261 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 5944
2026-05-28 18:48:08,261 [lib.api.process] INFO: Monitor config for process 5944: C:\2unxg6vp\dll\5944.ini
2026-05-28 18:48:08,263 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:08,267 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:08,271 [root] DEBUG: Loader: Injecting process 5944 (thread 6076) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:08,272 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:08,273 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:08,274 [lib.api.process] INFO: Injected into 64-bit <Process 5944 CHXSmartScreen.exe>
2026-05-28 18:48:08,276 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 5944
2026-05-28 18:48:08,276 [lib.api.process] INFO: Monitor config for process 5944: C:\2unxg6vp\dll\5944.ini
2026-05-28 18:48:08,277 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:08,280 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:08,285 [root] DEBUG: Loader: Injecting process 5944 (thread 6076) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:08,286 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:08,286 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:08,288 [lib.api.process] INFO: Injected into 64-bit <Process 5944 CHXSmartScreen.exe>
2026-05-28 18:48:08,289 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 5944
2026-05-28 18:48:08,290 [lib.api.process] INFO: Monitor config for process 5944: C:\2unxg6vp\dll\5944.ini
2026-05-28 18:48:08,290 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:08,296 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:08,300 [root] DEBUG: Loader: Injecting process 5944 with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:08,301 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 6076, handle 0x84
2026-05-28 18:48:08,302 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 18:48:08,302 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:08,304 [lib.api.process] INFO: Injected into 64-bit <Process 5944 CHXSmartScreen.exe>
2026-05-28 18:48:08,530 [root] DEBUG: 4676: FreeHandler: Address: 0x00007DF45BCB0000.
2026-05-28 18:48:08,531 [root] DEBUG: 4676: ScanForNonZero: Error - Supplied size zero.
2026-05-28 18:48:08,532 [root] DEBUG: 4676: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 18:48:08,532 [root] DEBUG: 4676: FreeHandler: Address: 0x00007DF45BCD0000.
2026-05-28 18:48:08,533 [root] DEBUG: 4676: ScanForNonZero: Error - Supplied size zero.
2026-05-28 18:48:08,535 [root] DEBUG: 4676: FreeHandler: Address: 0x00007DF45BCC0000.
2026-05-28 18:48:08,536 [root] DEBUG: 4676: ScanForNonZero: Error - Supplied size zero.
2026-05-28 18:48:08,537 [root] DEBUG: 4676: FreeHandler: Address: 0x00007DF45BCE0000.
2026-05-28 18:48:08,538 [root] DEBUG: 4676: ScanForNonZero: Error - Supplied size zero.
2026-05-28 18:48:08,539 [root] DEBUG: 4676: FreeHandler: Address: 0x00007DF45BCF0000.
2026-05-28 18:48:08,539 [root] DEBUG: 4676: ScanForNonZero: Error - Supplied size zero.
2026-05-28 18:48:12,598 [root] DEBUG: 4676: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 18:48:26,016 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 3632: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:48:26,019 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3632
2026-05-28 18:48:26,020 [lib.api.process] INFO: Monitor config for process 3632: C:\2unxg6vp\dll\3632.ini
2026-05-28 18:48:26,025 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:26,028 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:26,031 [root] DEBUG: 4676: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-28 18:48:26,033 [root] DEBUG: 4676: api-cap: NtOpenKeyEx hook disabled due to count: 5001
2026-05-28 18:48:26,037 [root] DEBUG: Loader: Injecting process 3632 (thread 6668) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:26,039 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:26,048 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:26,052 [lib.api.process] INFO: Injected into 64-bit <Process 3632 dllhost.exe>
2026-05-28 18:48:26,056 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3632
2026-05-28 18:48:26,057 [lib.api.process] INFO: Monitor config for process 3632: C:\2unxg6vp\dll\3632.ini
2026-05-28 18:48:26,062 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:26,069 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:26,079 [root] DEBUG: Loader: Injecting process 3632 (thread 6668) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:26,085 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:26,086 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:26,089 [lib.api.process] INFO: Injected into 64-bit <Process 3632 dllhost.exe>
2026-05-28 18:48:26,110 [root] DEBUG: 3632: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 18:48:26,111 [root] DEBUG: 3632: Interactive desktop enabled.
2026-05-28 18:48:26,113 [root] DEBUG: 3632: Dropped file limit defaulting to 100.
2026-05-28 18:48:26,116 [root] DEBUG: 3632: Disabling sleep skipping.
2026-05-28 18:48:26,118 [root] DEBUG: 3632: YaraInit: Compiled rules loaded from existing file C:\2unxg6vp\data\yara\capemon.yac
2026-05-28 18:48:26,133 [root] DEBUG: 3632: RtlInsertInvertedFunctionTable 0x00007FFF98C6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF98DBD4F0
2026-05-28 18:48:26,134 [root] DEBUG: 3632: YaraScan: Scanning 0x00007FF7BDF50000, size 0x8026
2026-05-28 18:48:26,135 [root] DEBUG: 3632: Monitor initialised: 64-bit capemon loaded in process 3632 at 0x00007FFF52E70000, thread 6668, image base 0x00007FF7BDF50000, stack from 0x00000005BD6F4000-0x00000005BD700000
2026-05-28 18:48:26,136 [root] DEBUG: 3632: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 18:48:26,139 [root] DEBUG: 4676: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-05-28 18:48:26,147 [root] DEBUG: 3632: hook_api: LdrpCallInitRoutine export address 0x00007FFF98C699BC obtained via GetFunctionAddress
2026-05-28 18:48:26,170 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 18:48:26,173 [root] DEBUG: 3632: set_hooks: Unable to hook LockResource
2026-05-28 18:48:26,177 [root] DEBUG: 3632: Hooked 627 out of 628 functions
2026-05-28 18:48:26,179 [root] DEBUG: 3632: Syscall hook installed, syscall logging level 1
2026-05-28 18:48:26,183 [root] DEBUG: 3632: RestoreHeaders: Restored original import table.
2026-05-28 18:48:26,184 [root] INFO: Loaded monitor into process with pid 3632
2026-05-28 18:48:26,184 [root] DEBUG: 3632: caller_dispatch: Added region at 0x00007FF7BDF50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7BDF512F2, thread 6668).
2026-05-28 18:48:26,185 [root] DEBUG: 3632: YaraScan: Scanning 0x00007FF7BDF50000, size 0x8026
2026-05-28 18:48:26,187 [root] DEBUG: 3632: ProcessImageBase: Main module image at 0x00007FF7BDF50000 unmodified (entropy change 0.000000e+00)
2026-05-28 18:48:26,188 [root] DEBUG: 3632: DLL loaded at 0x00007FFF94210000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 18:48:26,190 [root] DEBUG: 3632: DLL loaded at 0x00007FFF96C20000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 18:48:26,192 [root] DEBUG: 3632: DLL loaded at 0x00007FFF98230000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 18:48:26,206 [root] DEBUG: 3632: DLL loaded at 0x00007FFF93CF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 18:48:26,221 [root] DEBUG: 3632: DLL loaded at 0x00007FFF984B0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 18:48:26,222 [root] DEBUG: 3632: DLL loaded at 0x00007FFF7FFF0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 18:48:26,228 [root] DEBUG: 3632: DLL loaded at 0x00007FFF91EB0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 18:48:30,899 [root] INFO: Added new file to list with pid 4676 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
2026-05-28 18:48:30,904 [root] INFO: Added new file to list with pid 4676 and path C:\Users\admin\AppData\Local\Discord\app.ico
2026-05-28 18:48:31,395 [root] INFO: Process with pid 3632 has terminated
2026-05-28 18:48:31,396 [root] DEBUG: 3632: NtTerminateProcess hook: Attempting to dump process 3632
2026-05-28 18:48:31,398 [root] DEBUG: 3632: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 18:48:31,456 [root] DEBUG: 4676: api-cap: NtWaitForSingleObject hook disabled due to count: 5000
2026-05-28 18:48:31,457 [root] DEBUG: 4676: api-cap: NtWaitForSingleObject hook disabled due to count: 5001
2026-05-28 18:48:31,457 [root] DEBUG: 4676: api-cap: NtWaitForSingleObject hook disabled due to count: 5002
2026-05-28 18:48:31,506 [root] DEBUG: 4676: api-cap: NtQueryValueKey hook disabled due to count: 5000
2026-05-28 18:48:32,495 [root] DEBUG: 4676: api-cap: NtOpenProcessToken hook disabled due to count: 5000
2026-05-28 18:48:36,747 [root] DEBUG: 4676: api-cap: NtSetInformationThread hook disabled due to count: 5000
2026-05-28 18:48:36,748 [root] DEBUG: 4676: api-cap: NtSetInformationThread hook disabled due to count: 5001
2026-05-28 18:48:36,752 [root] DEBUG: 4676: api-cap: NtSetInformationThread hook disabled due to count: 5002
2026-05-28 18:48:36,770 [root] DEBUG: 4676: OpenProcessHandler: Image base for process 5968 (handle 0x2d08): 0x00007FF6F8D10000.
2026-05-28 18:48:36,860 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 15524: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:48:36,863 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15524
2026-05-28 18:48:36,864 [lib.api.process] INFO: Monitor config for process 15524: C:\2unxg6vp\dll\15524.ini
2026-05-28 18:48:36,866 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:36,870 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:36,877 [root] DEBUG: Loader: Injecting process 15524 (thread 15528) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,878 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:36,879 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,881 [lib.api.process] INFO: Injected into 64-bit <Process 15524 dllhost.exe>
2026-05-28 18:48:36,883 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15524
2026-05-28 18:48:36,884 [lib.api.process] INFO: Monitor config for process 15524: C:\2unxg6vp\dll\15524.ini
2026-05-28 18:48:36,885 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:36,889 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:36,893 [root] DEBUG: Loader: Injecting process 15524 (thread 15528) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,894 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:36,895 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,896 [lib.api.process] INFO: Injected into 64-bit <Process 15524 dllhost.exe>
2026-05-28 18:48:36,902 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 15616: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:48:36,904 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15616
2026-05-28 18:48:36,905 [lib.api.process] INFO: Monitor config for process 15616: C:\2unxg6vp\dll\15616.ini
2026-05-28 18:48:36,907 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:36,913 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:36,917 [root] DEBUG: Loader: Injecting process 15616 (thread 15620) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,918 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:36,920 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,923 [lib.api.process] INFO: Injected into 64-bit <Process 15616 dllhost.exe>
2026-05-28 18:48:36,926 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15616
2026-05-28 18:48:36,929 [lib.api.process] INFO: Monitor config for process 15616: C:\2unxg6vp\dll\15616.ini
2026-05-28 18:48:36,930 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:36,939 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:36,944 [root] DEBUG: Loader: Injecting process 15616 (thread 15620) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,946 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:36,948 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,950 [lib.api.process] INFO: Injected into 64-bit <Process 15616 dllhost.exe>
2026-05-28 18:48:36,954 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 15704: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:48:36,956 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15704
2026-05-28 18:48:36,958 [lib.api.process] INFO: Monitor config for process 15704: C:\2unxg6vp\dll\15704.ini
2026-05-28 18:48:36,960 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:36,970 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:36,975 [root] DEBUG: Loader: Injecting process 15704 (thread 15708) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,976 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:36,977 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,978 [lib.api.process] INFO: Injected into 64-bit <Process 15704 dllhost.exe>
2026-05-28 18:48:36,980 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15704
2026-05-28 18:48:36,980 [lib.api.process] INFO: Monitor config for process 15704: C:\2unxg6vp\dll\15704.ini
2026-05-28 18:48:36,981 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:36,986 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:36,991 [root] DEBUG: Loader: Injecting process 15704 (thread 15708) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,992 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:36,993 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:36,996 [lib.api.process] INFO: Injected into 64-bit <Process 15704 dllhost.exe>
2026-05-28 18:48:37,000 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 15792: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:48:37,001 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15792
2026-05-28 18:48:37,001 [lib.api.process] INFO: Monitor config for process 15792: C:\2unxg6vp\dll\15792.ini
2026-05-28 18:48:37,003 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:37,007 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:37,012 [root] DEBUG: Loader: Injecting process 15792 (thread 15796) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,012 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:37,014 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,016 [lib.api.process] INFO: Injected into 64-bit <Process 15792 dllhost.exe>
2026-05-28 18:48:37,020 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15792
2026-05-28 18:48:37,021 [lib.api.process] INFO: Monitor config for process 15792: C:\2unxg6vp\dll\15792.ini
2026-05-28 18:48:37,022 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:37,028 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:37,034 [root] DEBUG: Loader: Injecting process 15792 (thread 15796) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,034 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:37,035 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,037 [lib.api.process] INFO: Injected into 64-bit <Process 15792 dllhost.exe>
2026-05-28 18:48:37,041 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 15880: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:48:37,042 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15880
2026-05-28 18:48:37,043 [lib.api.process] INFO: Monitor config for process 15880: C:\2unxg6vp\dll\15880.ini
2026-05-28 18:48:37,045 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:37,051 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:37,056 [root] DEBUG: Loader: Injecting process 15880 (thread 15884) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,058 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:37,060 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,061 [lib.api.process] INFO: Injected into 64-bit <Process 15880 dllhost.exe>
2026-05-28 18:48:37,064 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15880
2026-05-28 18:48:37,065 [lib.api.process] INFO: Monitor config for process 15880: C:\2unxg6vp\dll\15880.ini
2026-05-28 18:48:37,066 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:37,071 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:37,076 [root] DEBUG: Loader: Injecting process 15880 (thread 15884) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,078 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:37,079 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,082 [lib.api.process] INFO: Injected into 64-bit <Process 15880 dllhost.exe>
2026-05-28 18:48:37,088 [root] DEBUG: 840: CreateProcessHandler: Injection info set for new process 15968: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF7BDF50000
2026-05-28 18:48:37,090 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15968
2026-05-28 18:48:37,090 [lib.api.process] INFO: Monitor config for process 15968: C:\2unxg6vp\dll\15968.ini
2026-05-28 18:48:37,092 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:37,098 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:37,102 [root] DEBUG: Loader: Injecting process 15968 (thread 15972) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,103 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:37,104 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,105 [lib.api.process] INFO: Injected into 64-bit <Process 15968 dllhost.exe>
2026-05-28 18:48:37,107 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15968
2026-05-28 18:48:37,108 [lib.api.process] INFO: Monitor config for process 15968: C:\2unxg6vp\dll\15968.ini
2026-05-28 18:48:37,110 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 18:48:37,114 [lib.api.process] INFO: 64-bit DLL to inject is C:\2unxg6vp\dll\lvMMtOS.dll, loader C:\2unxg6vp\bin\KIsHRknn.exe
2026-05-28 18:48:37,120 [root] DEBUG: Loader: Injecting process 15968 (thread 15972) with C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,122 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 18:48:37,123 [root] DEBUG: Successfully injected DLL C:\2unxg6vp\dll\lvMMtOS.dll.
2026-05-28 18:48:37,125 [lib.api.process] INFO: Injected into 64-bit <Process 15968 dllhost.exe>
2026-05-28 18:48:37,831 [root] DEBUG: 4676: OpenProcessHandler: Image base for process 5676 (handle 0x2d08): 0x00007FF6C0B10000.
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 18:46:27 | 2026-05-28 18:48:51 | none |
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 150.171.109.24 [VT] | unknown | - |
| Y | 204.79.197.203 [VT] | unknown | - |
| Y | 4.237.153.9 [VT] | unknown | - |
| N | 151.101.11.82 [VT] | unknown | - |
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 150.171.109.25 [VT] | unknown | - |
| Y | 20.190.122.23 [VT] | unknown | - |
| Y | 162.159.138.234 [VT] | unknown | - |
| Y | 199.232.191.82 [VT] | unknown | - |
| N | 23.209.183.176 [VT] | unknown | - |
| N | 205.196.6.133 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 162.159.134.233 [VT] | unknown | - |
| Y | 162.159.128.233 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| Y | 162.159.137.232 [VT] | unknown | - |
| N | 162.159.136.234 [VT] | unknown | - |
| Y | 162.159.135.233 [VT] | unknown | - |
| N | 199.232.211.52 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| N | 199.232.215.52 [VT] | unknown | - |
| N | 149.135.84.160 [VT] | unknown | - |
| Y | 172.172.255.217 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| Y | 205.196.6.132 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| disabled.invalid [VT] | NXDOMAIN | |
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-http.steamserver.net [VT] |
CNAME syd.http.ipv6check.akadns.net
[VT]
CNAME http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.160
[VT]
A 149.135.84.155 [VT] |
23.62.157.110 [VT] |
| gateway-us-east1-b.discord.gg [VT] |
A 162.159.136.234
[VT]
A 162.159.130.234 [VT] A 162.159.133.234 [VT] A 162.159.135.234 [VT] A 162.159.134.234 [VT] |
162.159.136.234 [VT] |
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| dns.google [VT] |
A 8.8.8.8
[VT]
A 8.8.4.4 [VT] |
8.8.4.4 [VT] |
| cmp2-sea1.steamserver.net [VT] | A 205.196.6.133 [VT] | 205.196.6.133 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.24 [VT] |
| clientconfig.akamai.steamstatic.com [VT] |
A 23.209.183.106
[VT]
A 23.209.183.176 [VT] |
23.211.125.111 [VT] |
| shared.steamstatic.com [VT] |
CNAME shared.valve.map.fastly.net
[VT]
A 199.232.215.52 [VT] A 199.232.211.52 [VT] |
199.232.211.52 [VT] |
| client-update.fastly.steamstatic.com [VT] |
CNAME valve.map.fastly.net
[VT]
A 151.101.11.82 [VT] |
199.232.211.82 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.