| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 19:02:59 | 2026-05-28 19:04:36 | 97s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 19:02:06,635 [root] INFO: Date set to: 20260528T19:03:06, timeout set to: 200
2026-05-28 19:03:06,004 [root] DEBUG: Starting analyzer from: C:\c6kogbu7
2026-05-28 19:03:06,005 [root] DEBUG: Storing results at: C:\aVnrzw
2026-05-28 19:03:06,005 [root] DEBUG: Pipe server name: \\.\PIPE\yEXqxLd
2026-05-28 19:03:06,005 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 19:03:06,005 [root] INFO: analysis running as an admin
2026-05-28 19:03:06,005 [root] INFO: analysis package specified: "edge"
2026-05-28 19:03:06,005 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 19:03:06,007 [root] DEBUG: imported analysis package "edge"
2026-05-28 19:03:06,007 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 19:03:06,007 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-28 19:03:06,007 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 19:03:06,007 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 19:03:06,007 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 19:03:06,008 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 19:03:06,022 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 19:03:06,025 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 19:03:06,032 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 19:03:06,037 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 19:03:06,039 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 19:03:06,040 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 19:03:06,040 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 19:03:06,042 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 19:03:06,042 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 19:03:06,042 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 19:03:06,043 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 19:03:06,043 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 19:03:06,043 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 19:03:06,043 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 19:03:06,044 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 19:03:06,044 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 19:03:06,044 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 19:03:06,044 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 19:03:06,045 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 19:03:06,046 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 19:03:06,046 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 19:03:06,046 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 19:03:06,046 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 19:03:06,049 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 4744)
2026-05-28 19:03:06,049 [modules.auxiliary.disguise] INFO: Disguising GUID to 29ab09c4-377b-4dda-a308-dadd88fffbe4
2026-05-28 19:03:06,049 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 19:03:06,049 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 19:03:06,050 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 19:03:06,050 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 19:03:06,050 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 19:03:06,050 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 19:03:06,051 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 19:03:06,051 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 19:03:06,051 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 19:03:06,052 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 19:03:06,052 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 19:03:06,052 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 19:03:06,052 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 19:03:06,053 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 19:03:06,053 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 19:03:06,053 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 19:03:06,054 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 19:03:06,054 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 19:03:06,055 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 19:03:06,080 [lib.api.process] INFO: Monitor config for process 4712: C:\c6kogbu7\dll\4712.ini
2026-05-28 19:03:06,081 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:06,083 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:06,142 [root] DEBUG: Loader: Injecting process 4712 with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:06,306 [root] DEBUG: 4712: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:03:06,310 [root] DEBUG: 4712: Disabling sleep skipping.
2026-05-28 19:03:06,313 [root] DEBUG: 4712: Interactive desktop enabled.
2026-05-28 19:03:06,314 [root] DEBUG: 4712: Dropped file limit defaulting to 100.
2026-05-28 19:03:06,314 [root] DEBUG: 4712: Interactive desktop - injecting Explorer Shell
2026-05-28 19:03:06,323 [root] DEBUG: 4712: YaraInit: Compiled 44 rule files
2026-05-28 19:03:06,325 [root] DEBUG: 4712: YaraInit: Compiled rules saved to file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:03:06,345 [root] DEBUG: 4712: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:03:06,345 [root] DEBUG: 4712: YaraScan: Scanning 0x00007FF7DD790000, size 0x545316
2026-05-28 19:03:06,387 [root] DEBUG: 4712: Monitor initialised: 64-bit capemon loaded in process 4712 at 0x00007FFE35340000, thread 5548, image base 0x00007FF7DD790000, stack from 0x000000000B4F1000-0x000000000B500000
2026-05-28 19:03:06,388 [root] DEBUG: 4712: Commandline: C:\Windows\Explorer.EXE
2026-05-28 19:03:06,399 [root] DEBUG: 4712: Hooked 69 out of 69 functions
2026-05-28 19:03:06,428 [root] DEBUG: 4712: Syscall hook installed, syscall logging level 1
2026-05-28 19:03:06,435 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:03:06,436 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:06,437 [lib.api.process] INFO: Injected into 64-bit <Process 4712 explorer.exe>
2026-05-28 19:03:13,603 [root] INFO: Restarting WMI Service
2026-05-28 19:03:15,640 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 19:03:15,640 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 19:03:15,641 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 19:03:15,644 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 336
2026-05-28 19:03:15,644 [lib.api.process] INFO: Monitor config for process 336: C:\c6kogbu7\dll\336.ini
2026-05-28 19:03:15,645 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:15,647 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:15,654 [root] DEBUG: Loader: Injecting process 336 (thread 7592) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:15,657 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:15,662 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:15,664 [lib.api.process] INFO: Injected into 64-bit <Process 336 msedge.exe>
2026-05-28 19:03:17,666 [lib.api.process] INFO: Successfully resumed process with pid 336
2026-05-28 19:03:17,719 [root] DEBUG: 336: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:03:17,719 [root] DEBUG: 336: Disabling sleep skipping.
2026-05-28 19:03:17,720 [root] DEBUG: 336: Interactive desktop enabled.
2026-05-28 19:03:17,720 [root] DEBUG: 336: Dropped file limit defaulting to 100.
2026-05-28 19:03:17,730 [root] DEBUG: 336: Edge-specific hook-set enabled.
2026-05-28 19:03:17,732 [root] DEBUG: 336: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:03:17,744 [root] DEBUG: 336: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:03:17,744 [root] DEBUG: 336: Monitor initialised: 64-bit capemon loaded in process 336 at 0x00007FFE35340000, thread 7592, image base 0x00007FF6D90F0000, stack from 0x00000047D55F4000-0x00000047D5600000
2026-05-28 19:03:17,744 [root] DEBUG: 336: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-28 19:03:17,754 [root] DEBUG: 336: Hooked 2 out of 2 functions
2026-05-28 19:03:17,799 [root] DEBUG: 336: Syscall hook installed, syscall logging level 1
2026-05-28 19:03:17,804 [root] DEBUG: 336: RestoreHeaders: Restored original import table.
2026-05-28 19:03:17,804 [root] INFO: Loaded monitor into process with pid 336
2026-05-28 19:03:17,806 [root] DEBUG: 336: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:03:17,837 [root] DEBUG: 336: DLL loaded at 0x00007FFE5D810000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 19:03:17,839 [root] DEBUG: 336: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:03:17,840 [root] DEBUG: 336: DLL loaded at 0x00007FFE73720000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 19:03:17,841 [root] DEBUG: 336: DLL loaded at 0x00007FFE71E90000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:03:17,843 [root] DEBUG: 336: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:03:17,844 [root] DEBUG: 336: DLL loaded at 0x00007FFE72EF0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:03:18,011 [root] DEBUG: 336: DLL loaded at 0x00007FFE61E90000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 19:03:18,014 [root] DEBUG: 336: DLL loaded at 0x0000024190000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:03:18,017 [root] DEBUG: 336: DLL loaded at 0x00007FFE626C0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 19:03:18,019 [root] DEBUG: 336: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:03:18,024 [root] DEBUG: 336: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:03:18,024 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 1332: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:18,024 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 1332
2026-05-28 19:03:18,025 [root] DEBUG: 336: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:03:18,025 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 1332
2026-05-28 19:03:18,026 [root] DEBUG: 336: DLL loaded at 0x00007FFE6BD30000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 19:03:18,027 [root] DEBUG: 336: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:03:18,028 [root] DEBUG: 336: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:03:18,036 [root] DEBUG: 336: DLL loaded at 0x00007FFE73CA0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 19:03:18,037 [root] DEBUG: 336: DLL loaded at 0x00007FFE72640000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 19:03:18,038 [root] DEBUG: 336: DLL loaded at 0x00007FFE72ED0000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 19:03:18,039 [root] DEBUG: 336: DLL loaded at 0x00007FFE73280000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 19:03:18,039 [root] DEBUG: 336: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:03:18,040 [root] DEBUG: 336: DLL loaded at 0x00007FFE69AD0000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 19:03:18,041 [root] DEBUG: 336: DLL loaded at 0x00007FFE73C10000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:03:18,041 [root] DEBUG: 336: DLL loaded at 0x00007FFE73670000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:03:18,043 [root] DEBUG: 336: DLL loaded at 0x00007FFE73790000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:03:18,044 [root] DEBUG: 336: DLL loaded at 0x00007FFE752B0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:03:18,044 [root] DEBUG: 336: DLL loaded at 0x00007FFE6C350000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:03:18,044 [root] DEBUG: 336: DLL loaded at 0x00007FFE61130000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 19:03:18,045 [root] DEBUG: 336: DLL loaded at 0x00007FFE69A90000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 19:03:18,046 [root] DEBUG: 336: DLL loaded at 0x00007FFE73BF0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:03:18,046 [root] DEBUG: 336: DLL loaded at 0x00007FFE73750000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:03:18,048 [root] DEBUG: 336: DLL loaded at 0x00007FFE600F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 19:03:18,049 [root] DEBUG: 336: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:03:18,049 [root] DEBUG: 336: DLL loaded at 0x00007FFE73670000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 19:03:18,050 [root] DEBUG: 336: DLL loaded at 0x00007FFE71270000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 19:03:18,051 [root] DEBUG: 336: DLL loaded at 0x00007FFE73CE0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 19:03:18,058 [root] DEBUG: 336: DLL loaded at 0x00007FFE6BD10000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 19:03:18,060 [root] DEBUG: 336: DLL loaded at 0x00007FFE75A80000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:03:18,060 [root] DEBUG: 336: DLL loaded at 0x00007FFE699E0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 19:03:18,062 [root] DEBUG: 336: DLL loaded at 0x00007FFE73C10000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:03:18,063 [root] DEBUG: 336: DLL loaded at 0x00007FFE73BF0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:03:18,064 [root] DEBUG: 336: DLL loaded at 0x00007FFE661E0000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 19:03:18,067 [root] DEBUG: 336: DLL loaded at 0x00007FFE60710000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 19:03:18,068 [root] DEBUG: 336: DLL loaded at 0x00007FFE6CDC0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:03:18,068 [root] DEBUG: 336: DLL loaded at 0x00007FFE73B30000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 19:03:18,070 [root] DEBUG: 336: DLL loaded at 0x00007FFE73170000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:03:18,070 [root] DEBUG: 336: DLL loaded at 0x00007FFE6F2A0000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 19:03:18,071 [root] DEBUG: 336: DLL loaded at 0x00007FFE752A0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:03:18,072 [root] DEBUG: 336: DLL loaded at 0x00007FFE6D680000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 19:03:18,073 [root] DEBUG: 336: DLL loaded at 0x00007FFE73E80000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:03:18,075 [root] DEBUG: 336: DLL loaded at 0x00007FFE6D660000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:03:18,076 [root] DEBUG: 336: DLL loaded at 0x00007FFE67B80000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 19:03:18,077 [root] DEBUG: 336: DLL loaded at 0x00007FFE731B0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 19:03:18,079 [root] DEBUG: 336: DLL loaded at 0x00007FFE6F930000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 19:03:18,081 [root] DEBUG: 336: DLL loaded at 0x00007FFE696D0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:03:18,083 [root] DEBUG: 336: DLL loaded at 0x00007FFE71170000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:03:18,084 [root] DEBUG: 336: DLL loaded at 0x00007FFE70740000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:03:18,084 [root] DEBUG: 336: DLL loaded at 0x00007FFE70E10000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 19:03:18,085 [root] DEBUG: 336: DLL loaded at 0x00007FFE688F0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 19:03:18,086 [root] DEBUG: 336: DLL loaded at 0x00007FFE69500000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 19:03:18,088 [root] DEBUG: 336: DLL loaded at 0x00007FFE6E670000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:03:18,091 [root] DEBUG: 336: DLL loaded at 0x00007FFE60410000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 19:03:18,091 [root] DEBUG: 336: DLL loaded at 0x00007FFE68250000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:03:18,094 [root] DEBUG: 336: DLL loaded at 0x00007FFE6DB20000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 19:03:18,098 [root] DEBUG: 336: DLL loaded at 0x00007FFE6E8B0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 19:03:18,098 [root] DEBUG: 336: DLL loaded at 0x00007FFE68790000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 19:03:18,099 [root] DEBUG: 336: DLL loaded at 0x00007FFE69000000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 19:03:18,099 [root] DEBUG: 336: DLL loaded at 0x00007FFE64970000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 19:03:18,100 [root] DEBUG: 336: DLL loaded at 0x00007FFE6FA60000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 19:03:18,101 [root] DEBUG: 336: DLL loaded at 0x00007FFE73A70000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 19:03:18,103 [root] DEBUG: 336: DLL loaded at 0x00007FFE6DF20000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 19:03:18,104 [root] DEBUG: 336: DLL loaded at 0x00007FFE6E120000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 19:03:18,106 [root] DEBUG: 336: DLL loaded at 0x00007FFE69C90000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:03:18,107 [root] DEBUG: 336: DLL loaded at 0x00007FFE64040000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 19:03:18,114 [root] DEBUG: 336: DLL loaded at 0x00007FFE6ED00000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 19:03:18,118 [root] DEBUG: 336: DLL loaded at 0x00007FFE1FCC0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 19:03:18,147 [root] DEBUG: 336: DLL loaded at 0x00007FFE682C0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 19:03:18,150 [root] DEBUG: 336: DLL loaded at 0x00007FFE64CF0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 19:03:18,153 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 3980: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:18,160 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 3980
2026-05-28 19:03:18,161 [root] DEBUG: 336: caller_dispatch: Added region at 0x00007FF6D90F0000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF6D91E7D66, thread 3244).
2026-05-28 19:03:18,163 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 3980
2026-05-28 19:03:18,169 [root] DEBUG: 336: ProcessImageBase: Main module image at 0x00007FF6D90F0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:03:18,181 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 796: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:18,188 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 796
2026-05-28 19:03:18,189 [root] DEBUG: 336: DLL loaded at 0x00007FFE604C0000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 19:03:18,189 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 5196: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:18,189 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 796
2026-05-28 19:03:18,190 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 5196
2026-05-28 19:03:18,191 [root] DEBUG: 336: DLL loaded at 0x00007FFE73B40000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 19:03:18,191 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 5196
2026-05-28 19:03:18,238 [root] DEBUG: 336: DLL loaded at 0x00007FFE6EF30000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:03:18,239 [root] DEBUG: 336: DLL loaded at 0x00007FFE5D100000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 19:03:18,253 [root] DEBUG: 336: DLL loaded at 0x00007FFE72670000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 19:03:18,254 [root] DEBUG: 336: DLL loaded at 0x00007FFE6FA80000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 19:03:18,254 [root] DEBUG: 336: DLL loaded at 0x00007FFE708A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 19:03:18,254 [root] DEBUG: 336: DLL loaded at 0x00007FFE60630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 19:03:18,274 [root] DEBUG: 336: DLL loaded at 0x00007FFE6BC80000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 19:03:18,297 [root] DEBUG: 336: DLL loaded at 0x00007FFE719A0000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 19:03:18,302 [root] DEBUG: 336: DLL loaded at 0x00007FFE5F8F0000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 19:03:18,303 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 7548: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:18,303 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 424: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:18,304 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 7548
2026-05-28 19:03:18,304 [root] DEBUG: 336: DLL loaded at 0x00007FFE65220000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 19:03:18,305 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 424
2026-05-28 19:03:18,305 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 7548
2026-05-28 19:03:18,306 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 424
2026-05-28 19:03:18,337 [root] DEBUG: 4712: YaraScan: Scanning 0x00007FF7DD790000, size 0x545316
2026-05-28 19:03:18,344 [root] DEBUG: 4712: caller_dispatch: Added region at 0x00007FF7DD790000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF7DD7BCA89, thread 4160).
2026-05-28 19:03:18,345 [root] DEBUG: 4712: YaraScan: Scanning 0x00007FF7DD790000, size 0x545316
2026-05-28 19:03:18,424 [root] DEBUG: 336: DLL loaded at 0x00007FFE61110000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 19:03:18,424 [root] DEBUG: 4712: ProcessImageBase: Main module image at 0x00007FF7DD790000 unmodified (entropy change 1.270765e-06)
2026-05-28 19:03:18,427 [root] DEBUG: 4712: ProcessImageBase: Main module image at 0x00007FF7DD790000 unmodified (entropy change 1.270765e-06)
2026-05-28 19:03:18,459 [root] DEBUG: 336: DLL loaded at 0x00007FFE738B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 19:03:18,461 [root] DEBUG: 336: DLL loaded at 0x00007FFE73670000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:03:18,462 [root] DEBUG: 336: DLL loaded at 0x00007FFE72DB0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 19:03:18,465 [root] DEBUG: 336: DLL loaded at 0x00007FFE625A0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 19:03:18,473 [root] DEBUG: 336: DLL loaded at 0x00007FFE64F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:03:18,476 [root] DEBUG: 336: DLL loaded at 0x00007FFE56690000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 19:03:18,497 [root] DEBUG: 336: DLL loaded at 0x00007FFE5C390000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 19:03:19,608 [root] DEBUG: 336: DLL loaded at 0x00007FFE5C110000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:03:20,007 [root] DEBUG: 336: DLL loaded at 0x00007FFE5F4C0000: C:\Windows\system32\explorerframe (0x244000 bytes).
2026-05-28 19:03:20,013 [root] DEBUG: 336: DLL loaded at 0x00007FFE752D0000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 19:03:20,021 [root] DEBUG: 336: DLL loaded at 0x00007FFE73AD0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 19:03:20,023 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 8340: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:20,028 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 8352: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:20,030 [root] DEBUG: 336: DLL loaded at 0x00007FFE73F00000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:03:20,030 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 8352
2026-05-28 19:03:20,031 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 8340
2026-05-28 19:03:20,031 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 8352
2026-05-28 19:03:20,032 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 8340
2026-05-28 19:03:20,061 [root] DEBUG: 336: DLL loaded at 0x00007FFE1CE10000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 19:03:20,081 [root] DEBUG: 336: DLL loaded at 0x00007FFE6E980000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 19:03:20,082 [root] DEBUG: 336: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:03:20,083 [root] DEBUG: 336: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:03:20,084 [root] DEBUG: 336: DLL loaded at 0x00007FFE1F850000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 19:03:20,085 [root] DEBUG: 336: DLL loaded at 0x00007FFE63F90000: C:\Windows\System32\Windows.FileExplorer.Common (0x61000 bytes).
2026-05-28 19:03:20,089 [root] DEBUG: 336: DLL loaded at 0x00007FFE1C7B0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 19:03:20,093 [root] DEBUG: 336: DLL loaded at 0x00007FFE69A90000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 19:03:20,094 [root] DEBUG: 336: DLL loaded at 0x00007FFE6C120000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:03:20,099 [root] DEBUG: 336: DLL loaded at 0x00007FFE764D0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 19:03:20,100 [root] DEBUG: 336: DLL loaded at 0x00007FFE729D0000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 19:03:20,101 [root] DEBUG: 336: DLL loaded at 0x00007FFE72990000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 19:03:20,105 [root] DEBUG: 336: DLL loaded at 0x00007FFE5C090000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 19:03:20,106 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 8508: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:20,106 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 8536: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:20,107 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 8508
2026-05-28 19:03:20,107 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 8536
2026-05-28 19:03:20,108 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 8508
2026-05-28 19:03:20,109 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 8536
2026-05-28 19:03:20,116 [root] DEBUG: 336: DLL loaded at 0x00007FFE719D0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:03:20,119 [root] DEBUG: 336: DLL loaded at 0x00007FFE6F8F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:03:20,119 [root] DEBUG: 336: DLL loaded at 0x00007FFE5F360000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:03:20,159 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 8664: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF71D800000
2026-05-28 19:03:20,160 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8664
2026-05-28 19:03:20,161 [lib.api.process] INFO: Monitor config for process 8664: C:\c6kogbu7\dll\8664.ini
2026-05-28 19:03:20,161 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:20,182 [root] DEBUG: 336: DLL loaded at 0x00007FFE6E390000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 19:03:20,192 [root] DEBUG: 336: DLL loaded at 0x00007FFE605C0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:03:20,197 [root] DEBUG: 336: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:03:20,198 [root] DEBUG: 336: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:03:20,750 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:03:20,750 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:03:20,755 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:20,760 [root] DEBUG: Loader: Injecting process 8664 (thread 8668) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:20,762 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:20,762 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:20,765 [lib.api.process] INFO: Injected into 64-bit <Process 8664 identity_helper.exe>
2026-05-28 19:03:20,770 [root] DEBUG: 336: DLL loaded at 0x00007FFE6C2A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:03:20,771 [root] DEBUG: 336: DLL loaded at 0x00007FFE68280000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 19:03:20,772 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 8760: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF71D800000
2026-05-28 19:03:20,772 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8760
2026-05-28 19:03:20,773 [lib.api.process] INFO: Monitor config for process 8760: C:\c6kogbu7\dll\8760.ini
2026-05-28 19:03:20,773 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:20,778 [root] DEBUG: 336: DLL loaded at 0x00007FFE6BAA0000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 19:03:20,781 [root] DEBUG: 336: DLL loaded at 0x00007FFE626E0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:03:20,782 [root] DEBUG: 336: DLL loaded at 0x00007FFE6C5B0000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 19:03:20,803 [root] DEBUG: 336: DLL loaded at 0x00007FFE73790000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:03:20,804 [root] DEBUG: 336: DLL loaded at 0x00007FFE73750000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:03:20,806 [root] DEBUG: 336: DLL loaded at 0x00007FFE6BF00000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 19:03:20,807 [root] DEBUG: 336: DLL loaded at 0x00007FFE752B0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:03:20,807 [root] DEBUG: 336: DLL loaded at 0x00007FFE6C350000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:03:20,808 [root] DEBUG: 336: DLL loaded at 0x00007FFE600F0000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 19:03:20,809 [root] DEBUG: 336: DLL loaded at 0x00007FFE60FF0000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 19:03:20,852 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:03:20,853 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:03:20,854 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:20,859 [root] DEBUG: Loader: Injecting process 8760 (thread 8764) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:20,860 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:20,860 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:20,861 [lib.api.process] INFO: Injected into 64-bit <Process 8760 identity_helper.exe>
2026-05-28 19:03:20,864 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8760
2026-05-28 19:03:20,864 [lib.api.process] INFO: Monitor config for process 8760: C:\c6kogbu7\dll\8760.ini
2026-05-28 19:03:20,864 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:20,888 [root] DEBUG: 336: DLL loaded at 0x00007FFE73480000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 19:03:20,943 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:03:20,943 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:03:20,945 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:20,950 [root] DEBUG: Loader: Injecting process 8760 (thread 8764) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:20,951 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:03:20,952 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:20,953 [lib.api.process] INFO: Injected into 64-bit <Process 8760 identity_helper.exe>
2026-05-28 19:03:20,965 [root] DEBUG: 8760: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:03:20,966 [root] DEBUG: 8760: Interactive desktop enabled.
2026-05-28 19:03:20,966 [root] DEBUG: 8760: Dropped file limit defaulting to 100.
2026-05-28 19:03:20,973 [root] DEBUG: 8760: Disabling sleep skipping.
2026-05-28 19:03:20,974 [root] DEBUG: 8760: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:03:20,986 [root] DEBUG: 8760: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:03:20,987 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FF71D800000, size 0x28b4d8
2026-05-28 19:03:21,012 [root] DEBUG: 8760: Monitor initialised: 64-bit capemon loaded in process 8760 at 0x00007FFE35340000, thread 8764, image base 0x00007FF71D800000, stack from 0x000000A61D0F4000-0x000000A61D100000
2026-05-28 19:03:21,012 [root] DEBUG: 8760: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=6568,i,12605315847689057570,469360284072590098,524288 --field-trial-handle=1536,i,1177238224952366695,8713284821405921237,262144 --variations-seed-version --pseudonymization-salt-handle=2324,i,4492895292330900347,2973157943565449811
2026-05-28 19:03:21,013 [root] DEBUG: 8760: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 19:03:21,023 [root] DEBUG: 8760: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:03:21,044 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:03:21,045 [root] DEBUG: 8760: set_hooks: Unable to hook LockResource
2026-05-28 19:03:21,052 [root] DEBUG: 8760: Hooked 627 out of 628 functions
2026-05-28 19:03:21,066 [root] DEBUG: 8760: Syscall hook installed, syscall logging level 1
2026-05-28 19:03:21,071 [root] DEBUG: 8760: RestoreHeaders: Restored original import table.
2026-05-28 19:03:21,071 [root] INFO: Loaded monitor into process with pid 8760
2026-05-28 19:03:21,071 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FFE34CE0000, size 0x4b9994
2026-05-28 19:03:21,110 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FFE34CE0000, size 0x4b9994
2026-05-28 19:03:21,134 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FFE34CE0000, size 0x4b9994
2026-05-28 19:03:21,157 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FFE34CE0000, size 0x4b9994
2026-05-28 19:03:21,182 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FFE34CE0000, size 0x4b9994
2026-05-28 19:03:21,206 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FFE34CE0000, size 0x4b9994
2026-05-28 19:03:21,233 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FFE34CE0000, size 0x4b9994
2026-05-28 19:03:21,260 [root] DEBUG: 8760: caller_dispatch: Added region at 0x00007FFE34CE0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFE34EDF156, thread 8764).
2026-05-28 19:03:21,261 [root] DEBUG: 8760: caller_dispatch: Scanning calling region at 0x00007FFE34CE0000...
2026-05-28 19:03:21,279 [root] DEBUG: 8760: ProcessTrackedRegion: Region at 0x00007FFE34CE0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 19:03:21,282 [root] DEBUG: 8760: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:03:21,359 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FF71D800000, size 0x28b4d8
2026-05-28 19:03:21,385 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FF71D800000, size 0x28b4d8
2026-05-28 19:03:21,400 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FF71D800000, size 0x28b4d8
2026-05-28 19:03:21,414 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FF71D800000, size 0x28b4d8
2026-05-28 19:03:21,429 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FF71D800000, size 0x28b4d8
2026-05-28 19:03:21,444 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FF71D800000, size 0x28b4d8
2026-05-28 19:03:21,461 [root] DEBUG: 8760: caller_dispatch: Added region at 0x00007FF71D800000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF71D8F4096, thread 8764).
2026-05-28 19:03:21,461 [root] DEBUG: 8760: YaraScan: Scanning 0x00007FF71D800000, size 0x28b4d8
2026-05-28 19:03:21,478 [root] DEBUG: 8760: ProcessImageBase: Main module image at 0x00007FF71D800000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:03:21,482 [root] DEBUG: 8760: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:03:21,506 [root] DEBUG: 8760: DLL loaded at 0x0000028A6A000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:03:21,509 [root] DEBUG: 8760: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:03:21,512 [root] DEBUG: 8760: DLL loaded at 0x00007FFE75A80000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:03:21,550 [root] DEBUG: 8760: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:03:21,561 [root] DEBUG: 8760: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:03:21,586 [root] DEBUG: 8760: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:03:21,587 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6F930000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 19:03:21,587 [root] DEBUG: 8760: DLL loaded at 0x00007FFE71170000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:03:21,588 [root] DEBUG: 8760: DLL loaded at 0x00007FFE62A90000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 19:03:21,663 [root] DEBUG: 8760: DLL loaded at 0x00007FFE70740000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:03:21,664 [root] DEBUG: 8760: DLL loaded at 0x00007FFE719D0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:03:21,664 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6F8F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:03:21,665 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6E670000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:03:21,666 [root] DEBUG: 8760: DLL loaded at 0x00007FFE5F360000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:03:21,800 [root] DEBUG: 8760: DLL loaded at 0x00007FFE64F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:03:21,810 [root] DEBUG: 8760: DLL loaded at 0x00007FFE61280000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 19:03:21,814 [root] DEBUG: 8760: DLL loaded at 0x00007FFE72E40000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:03:21,815 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:03:21,843 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6EF30000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:03:21,855 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6CDC0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:03:21,859 [root] DEBUG: 8760: DLL loaded at 0x00007FFE696D0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:03:21,871 [root] DEBUG: 8760: DLL loaded at 0x00007FFE73F00000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:03:21,872 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6C2A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:03:21,891 [root] DEBUG: 8760: DLL loaded at 0x00007FFE738B0000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 19:03:21,908 [root] DEBUG: 8760: DLL loaded at 0x00007FFE626E0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:03:21,972 [root] DEBUG: 8760: DLL loaded at 0x0000028A68F90000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 19:03:22,025 [lib.api.process] INFO: Monitor config for process 836: C:\c6kogbu7\dll\836.ini
2026-05-28 19:03:22,030 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:22,034 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:22,053 [root] DEBUG: Loader: Injecting process 836 with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:22,057 [root] DEBUG: 836: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:03:22,058 [root] DEBUG: 836: Disabling sleep skipping.
2026-05-28 19:03:22,060 [root] DEBUG: 836: Interactive desktop enabled.
2026-05-28 19:03:22,061 [root] DEBUG: 836: Dropped file limit defaulting to 100.
2026-05-28 19:03:22,069 [root] DEBUG: 836: Services hook set enabled
2026-05-28 19:03:22,073 [root] DEBUG: 836: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:03:22,095 [root] DEBUG: 836: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:03:22,096 [root] DEBUG: 836: Monitor initialised: 64-bit capemon loaded in process 836 at 0x00007FFE35340000, thread 8324, image base 0x00007FF7BE050000, stack from 0x000000D9C50F4000-0x000000D9C5100000
2026-05-28 19:03:22,097 [root] DEBUG: 836: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 19:03:22,110 [root] DEBUG: 836: Hooked 69 out of 69 functions
2026-05-28 19:03:22,111 [root] INFO: Loaded monitor into process with pid 836
2026-05-28 19:03:22,112 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:03:22,112 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:22,114 [lib.api.process] INFO: Injected into 64-bit <Process 836 svchost.exe>
2026-05-28 19:03:24,173 [root] DEBUG: 8760: DLL loaded at 0x00007FFE67520000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 19:03:24,175 [root] DEBUG: 8760: DLL loaded at 0x00007FFE675E0000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 19:03:24,176 [root] DEBUG: 8760: DLL loaded at 0x00007FFE5F710000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 19:03:24,179 [root] DEBUG: 8760: DLL loaded at 0x00007FFE5B080000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 19:03:24,210 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6D600000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 19:03:24,298 [root] DEBUG: 8760: DLL loaded at 0x00007FFE72670000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 19:03:24,299 [root] DEBUG: 8760: DLL loaded at 0x00007FFE6FA80000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 19:03:24,328 [root] DEBUG: 8760: DLL loaded at 0x00007FFE654C0000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 19:03:24,330 [root] DEBUG: 8760: DLL loaded at 0x00007FFE5ADA0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:03:24,582 [root] DEBUG: 8760: DLL loaded at 0x00007FFE5C5A0000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 19:03:24,672 [root] DEBUG: 8760: DLL loaded at 0x00007FFE73CA0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:03:24,674 [root] DEBUG: 8760: DLL loaded at 0x00007FFE73720000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 19:03:24,676 [root] DEBUG: 8760: DLL loaded at 0x00007FFE71E90000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:03:24,677 [root] DEBUG: 8760: DLL loaded at 0x00007FFE69670000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 19:03:24,678 [root] DEBUG: 8760: DLL loaded at 0x00007FFE5FA10000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 19:03:24,774 [root] DEBUG: 8760: DLL loaded at 0x00007FFE5B260000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 19:03:24,798 [root] DEBUG: 8760: DLL loaded at 0x00007FFE68250000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:03:24,832 [root] DEBUG: 8760: DLL loaded at 0x00007FFE73E80000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:03:26,880 [root] DEBUG: 336: DLL loaded at 0x00007FFE69820000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 19:03:26,880 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 3612: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:26,882 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 3612
2026-05-28 19:03:26,883 [root] DEBUG: 336: DLL loaded at 0x00007FFE69600000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 19:03:26,883 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 3612
2026-05-28 19:03:26,885 [root] DEBUG: 336: DLL loaded at 0x00007FFE376D0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 19:03:27,077 [root] DEBUG: 336: DLL loaded at 0x00007FFE5D470000: C:\Windows\System32\provsvc (0x7d000 bytes).
2026-05-28 19:03:27,097 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 9244: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:03:27,099 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9244
2026-05-28 19:03:27,099 [lib.api.process] INFO: Monitor config for process 9244: C:\c6kogbu7\dll\9244.ini
2026-05-28 19:03:27,101 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:27,103 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:27,121 [root] DEBUG: Loader: Injecting process 9244 (thread 9248) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:27,125 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:27,126 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:27,130 [lib.api.process] INFO: Injected into 64-bit <Process 9244 dllhost.exe>
2026-05-28 19:03:27,132 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9244
2026-05-28 19:03:27,133 [lib.api.process] INFO: Monitor config for process 9244: C:\c6kogbu7\dll\9244.ini
2026-05-28 19:03:27,133 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:27,135 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:27,143 [root] DEBUG: Loader: Injecting process 9244 (thread 9248) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:27,144 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:27,145 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:27,147 [lib.api.process] INFO: Injected into 64-bit <Process 9244 dllhost.exe>
2026-05-28 19:03:27,153 [root] DEBUG: 9244: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:03:27,154 [root] DEBUG: 9244: Interactive desktop enabled.
2026-05-28 19:03:27,155 [root] DEBUG: 9244: Dropped file limit defaulting to 100.
2026-05-28 19:03:27,182 [root] DEBUG: 9244: Disabling sleep skipping.
2026-05-28 19:03:27,183 [root] DEBUG: 9244: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:03:27,198 [root] DEBUG: 9244: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:03:27,200 [root] DEBUG: 9244: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:03:27,201 [root] DEBUG: 9244: Monitor initialised: 64-bit capemon loaded in process 9244 at 0x00007FFE35340000, thread 9248, image base 0x00007FF687D50000, stack from 0x000000BE60EF4000-0x000000BE60F00000
2026-05-28 19:03:27,202 [root] DEBUG: 9244: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:03:27,212 [root] DEBUG: 9244: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:03:27,234 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:03:27,235 [root] DEBUG: 9244: set_hooks: Unable to hook LockResource
2026-05-28 19:03:27,239 [root] DEBUG: 9244: Hooked 627 out of 628 functions
2026-05-28 19:03:27,240 [root] DEBUG: 9244: Syscall hook installed, syscall logging level 1
2026-05-28 19:03:27,244 [root] DEBUG: 9244: RestoreHeaders: Restored original import table.
2026-05-28 19:03:27,245 [root] INFO: Loaded monitor into process with pid 9244
2026-05-28 19:03:27,246 [root] DEBUG: 9244: caller_dispatch: Added region at 0x00007FF687D50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF687D512F2, thread 9248).
2026-05-28 19:03:27,248 [root] DEBUG: 9244: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:03:27,249 [root] DEBUG: 9244: ProcessImageBase: Main module image at 0x00007FF687D50000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:03:27,251 [root] DEBUG: 9244: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:03:27,252 [root] DEBUG: 9244: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:03:27,254 [root] DEBUG: 9244: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:03:27,268 [root] DEBUG: 9244: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:03:27,282 [root] DEBUG: 9244: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:03:27,282 [root] DEBUG: 9244: DLL loaded at 0x00007FFE605C0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:03:27,289 [root] DEBUG: 9244: DLL loaded at 0x00007FFE6F930000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:03:27,295 [root] DEBUG: 336: DLL loaded at 0x00007FFE715E0000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 19:03:27,297 [root] DEBUG: 9244: DLL loaded at 0x00007FFE6E390000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 19:03:27,298 [root] DEBUG: 9244: DLL loaded at 0x00007FFE5BEF0000: C:\Windows\system32\PhotoMetadataHandler (0x84000 bytes).
2026-05-28 19:03:27,391 [root] DEBUG: 9244: DLL loaded at 0x00007FFE6CDC0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:03:28,094 [root] DEBUG: 336: CreateProcessHandler: Injection info set for new process 9532: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:03:28,095 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 9532
2026-05-28 19:03:28,096 [root] DEBUG: 336: ProcessMessage: Skipping monitoring process 9532
2026-05-28 19:03:28,241 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 19:03:28,254 [lib.api.process] INFO: Monitor config for process 672: C:\c6kogbu7\dll\672.ini
2026-05-28 19:03:28,259 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:28,261 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:28,269 [root] DEBUG: Loader: Injecting process 672 with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:28,283 [root] DEBUG: Loader: Copied config file C:\c6kogbu7\dll\672.ini to system path C:\672.ini
2026-05-28 19:03:28,289 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 672 C:\c6kogbu7\dll\HuBDrjs.dll
2026-05-28 19:03:28,292 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:28,298 [lib.api.process] INFO: Injected into 64-bit <Process 672 services.exe>
2026-05-28 19:03:28,776 [root] INFO: Process with pid 336 appears to have terminated
2026-05-28 19:03:29,316 [root] DEBUG: 4712: DLL loaded at 0x00007FFE69A70000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:03:29,356 [lib.api.process] INFO: Monitor config for process 4712: C:\c6kogbu7\dll\4712.ini
2026-05-28 19:03:29,356 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:29,359 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:29,363 [root] DEBUG: Loader: Injecting process 4712 with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:29,364 [root] DEBUG: 4712: caller_dispatch: Added region at 0x0000000007960000 to tracked regions list (ntdll::LdrLoadDll returns to 0x0000000007960043, thread 1520).
2026-05-28 19:03:29,365 [root] DEBUG: 4712: DumpPEsInRange: Scanning range 0x0000000007960000 - 0x0000000007960134.
2026-05-28 19:03:29,365 [root] DEBUG: 4712: ScanForDisguisedPE: Size too small: 0x134 bytes
2026-05-28 19:03:29,367 [lib.common.results] INFO: Uploading file C:\aVnrzw\CAPE\4712_145142932328452026 to CAPE\27701ceeb6266ab02c37e0de937261e49c587b20261e4ee8f51a002ae83655d8; Size is 308; Max size: 100000000
2026-05-28 19:03:29,371 [root] DEBUG: 4712: DumpMemory: Payload successfully created: C:\aVnrzw\CAPE\4712_145142932328452026 (size 308 bytes)
2026-05-28 19:03:29,371 [root] DEBUG: 4712: DumpRegion: Dumped entire allocation from 0x0000000007960000, size 4096 bytes.
2026-05-28 19:03:29,372 [root] DEBUG: 4712: ProcessTrackedRegion: Dumped region at 0x0000000007960000.
2026-05-28 19:03:29,373 [root] DEBUG: 4712: YaraScan: Scanning 0x0000000007960000, size 0x134
2026-05-28 19:03:29,374 [root] DEBUG: 4712: Monitor config - unrecognised key host-ip.
2026-05-28 19:03:29,374 [root] DEBUG: 4712: Monitor config - unrecognised key host-port.
2026-05-28 19:03:29,375 [root] DEBUG: 4712: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:03:29,375 [root] DEBUG: 4712: Dropped file limit defaulting to 100.
2026-05-28 19:03:29,393 [root] DEBUG: 4712: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:03:29,435 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:03:29,436 [root] DEBUG: 4712: set_hooks: Unable to hook LockResource
2026-05-28 19:03:29,459 [root] DEBUG: 4712: Hooked 627 out of 628 functions
2026-05-28 19:03:29,488 [root] INFO: Loaded monitor into process with pid 4712
2026-05-28 19:03:29,492 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 19:03:29,492 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:29,792 [root] INFO: Process with pid 8760 appears to have terminated
2026-05-28 19:03:30,763 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:03:30,764 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 5396, handle 0xfe0: Error obtaining target process name
2026-05-28 19:03:30,765 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:03:30,765 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 2328, handle 0x101c: Error obtaining target process name
2026-05-28 19:03:30,766 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:03:30,766 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 5612, handle 0x410: Error obtaining target process name
2026-05-28 19:03:30,767 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:03:30,767 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 5336, handle 0x1020: Error obtaining target process name
2026-05-28 19:03:30,768 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:03:30,768 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 7024, handle 0x1014: Error obtaining target process name
2026-05-28 19:03:30,855 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 7024 (handle 0x254c): 0x00007FF6CF3E0000.
2026-05-28 19:03:31,588 [root] DEBUG: 4712: DLL loaded at 0x00007FFE59540000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:03:31,589 [root] DEBUG: 4712: DLL loaded at 0x00007FFE59540000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:03:31,616 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5BE40000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:03:31,617 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5BE40000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:03:31,650 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1C6E0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:03:31,652 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1C6E0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:03:31,910 [root] DEBUG: 4712: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 19:03:36,547 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 12104: C:\Windows\System32\rundll32.exe, ImageBase: 0x00007FF708BF0000
2026-05-28 19:03:36,548 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 12104
2026-05-28 19:03:36,549 [lib.api.process] INFO: Monitor config for process 12104: C:\c6kogbu7\dll\12104.ini
2026-05-28 19:03:36,551 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:36,555 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:36,561 [root] DEBUG: Loader: Injecting process 12104 (thread 12108) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:36,562 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:36,563 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:36,564 [lib.api.process] INFO: Injected into 64-bit <Process 12104 rundll32.exe>
2026-05-28 19:03:36,565 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 12104
2026-05-28 19:03:36,566 [lib.api.process] INFO: Monitor config for process 12104: C:\c6kogbu7\dll\12104.ini
2026-05-28 19:03:36,567 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:36,571 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:36,575 [root] DEBUG: Loader: Injecting process 12104 (thread 12108) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:36,576 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:03:36,577 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:36,578 [lib.api.process] INFO: Injected into 64-bit <Process 12104 rundll32.exe>
2026-05-28 19:03:36,589 [root] DEBUG: 12104: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:03:36,590 [root] DEBUG: 12104: Interactive desktop enabled.
2026-05-28 19:03:36,592 [root] DEBUG: 12104: Dropped file limit defaulting to 100.
2026-05-28 19:03:36,594 [root] DEBUG: 12104: Disabling sleep skipping.
2026-05-28 19:03:36,595 [root] DEBUG: 12104: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:03:36,609 [root] DEBUG: 12104: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:03:36,610 [root] DEBUG: 12104: YaraScan: Scanning 0x00007FF708BF0000, size 0x16100
2026-05-28 19:03:36,611 [root] DEBUG: 12104: Monitor initialised: 64-bit capemon loaded in process 12104 at 0x00007FFE35340000, thread 12108, image base 0x00007FF708BF0000, stack from 0x0000006DAC4C4000-0x0000006DAC4D0000
2026-05-28 19:03:36,611 [root] DEBUG: 12104: Commandline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
2026-05-28 19:03:36,621 [root] DEBUG: 12104: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:03:36,643 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:03:36,644 [root] DEBUG: 12104: set_hooks: Unable to hook LockResource
2026-05-28 19:03:36,649 [root] DEBUG: 12104: Hooked 627 out of 628 functions
2026-05-28 19:03:36,651 [root] DEBUG: 12104: Syscall hook installed, syscall logging level 1
2026-05-28 19:03:36,657 [root] DEBUG: 12104: RestoreHeaders: Restored original import table.
2026-05-28 19:03:36,658 [root] INFO: Loaded monitor into process with pid 12104
2026-05-28 19:03:36,659 [root] DEBUG: 12104: caller_dispatch: Added region at 0x00007FF708BF0000 to tracked regions list (ntdll::NtQuerySystemInformation returns to 0x00007FF708BF3F67, thread 12108).
2026-05-28 19:03:36,660 [root] DEBUG: 12104: YaraScan: Scanning 0x00007FF708BF0000, size 0x16100
2026-05-28 19:03:36,661 [root] DEBUG: 12104: ProcessImageBase: Main module image at 0x00007FF708BF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:03:36,668 [root] DEBUG: 12104: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:03:36,670 [root] DEBUG: 12104: DLL loaded at 0x00007FFE75A80000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:03:36,671 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 12104, handle 0xe08: C:\Windows\System32\rundll32.exe
2026-05-28 19:03:36,677 [root] DEBUG: 4712: DLL loaded at 0x00007FFE69A70000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 19:03:36,678 [root] DEBUG: 4712: DLL loaded at 0x00007FFE69A70000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 19:03:36,680 [root] DEBUG: 4712: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 19:03:36,686 [root] DEBUG: 12104: NtTerminateProcess hook: Attempting to dump process 12104
2026-05-28 19:03:36,687 [root] DEBUG: 12104: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:03:36,694 [root] INFO: Process with pid 12104 has terminated
2026-05-28 19:03:37,706 [root] INFO: Announced starting service "b'lfsvc'"
2026-05-28 19:03:42,077 [root] DEBUG: 4712: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 19:03:43,463 [root] DEBUG: 4712: api-rate-cap: NtQueryKey hook disabled due to rate
2026-05-28 19:03:43,507 [root] DEBUG: 4712: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 19:03:43,608 [root] INFO: Process with pid 9244 has terminated
2026-05-28 19:03:43,609 [root] DEBUG: 9244: NtTerminateProcess hook: Attempting to dump process 9244
2026-05-28 19:03:43,610 [root] DEBUG: 9244: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:03:44,468 [root] DEBUG: 4712: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4559C1000, size: 0x1000.
2026-05-28 19:03:44,471 [root] DEBUG: 4712: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4559B1000, size: 0x1000.
2026-05-28 19:03:44,472 [root] DEBUG: 4712: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4559A1000, size: 0x1000.
2026-05-28 19:03:44,474 [root] DEBUG: 4712: AllocationHandler: Adding allocation to tracked region list: 0x00007DF455991000, size: 0x1000.
2026-05-28 19:03:44,503 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5C370000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 19:03:44,504 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5C370000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 19:03:44,518 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 14044: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF6EC920000
2026-05-28 19:03:44,519 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 14044
2026-05-28 19:03:44,519 [lib.api.process] INFO: Monitor config for process 14044: C:\c6kogbu7\dll\14044.ini
2026-05-28 19:03:44,521 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:44,524 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:44,530 [root] DEBUG: Loader: Injecting process 14044 (thread 14048) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:44,531 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:44,531 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:44,533 [lib.api.process] INFO: Injected into 64-bit <Process 14044 CHXSmartScreen.exe>
2026-05-28 19:03:44,534 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 14044
2026-05-28 19:03:44,535 [lib.api.process] INFO: Monitor config for process 14044: C:\c6kogbu7\dll\14044.ini
2026-05-28 19:03:44,535 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:44,538 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:44,543 [root] DEBUG: Loader: Injecting process 14044 (thread 14048) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:44,544 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:44,544 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:44,546 [lib.api.process] INFO: Injected into 64-bit <Process 14044 CHXSmartScreen.exe>
2026-05-28 19:03:44,547 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 14044
2026-05-28 19:03:44,547 [lib.api.process] INFO: Monitor config for process 14044: C:\c6kogbu7\dll\14044.ini
2026-05-28 19:03:44,548 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:44,551 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:44,556 [lib.api.process] INFO: Injected into 64-bit <Process 14044 CHXSmartScreen.exe>
2026-05-28 19:03:44,720 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 14296, handle 0x1114: C:\Windows\System32\rundll32.exe
2026-05-28 19:03:44,931 [root] DEBUG: 4712: FreeHandler: Address: 0x00007DF4559A0000.
2026-05-28 19:03:44,932 [root] DEBUG: 4712: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:03:44,933 [root] DEBUG: 4712: FreeHandler: Address: 0x00007DF455990000.
2026-05-28 19:03:44,934 [root] DEBUG: 4712: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:03:44,935 [root] DEBUG: 4712: FreeHandler: Address: 0x00007DF4559B0000.
2026-05-28 19:03:44,936 [root] DEBUG: 4712: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:03:44,937 [root] DEBUG: 4712: FreeHandler: Address: 0x00007DF4559C0000.
2026-05-28 19:03:44,938 [root] DEBUG: 4712: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:03:45,034 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 13516: C:\Windows\System32\RuntimeBroker.exe, ImageBase: 0x00007FF7509C0000
2026-05-28 19:03:45,035 [root] INFO: Announced 64-bit process name: RuntimeBroker.exe pid: 13516
2026-05-28 19:03:45,036 [lib.api.process] INFO: Monitor config for process 13516: C:\c6kogbu7\dll\13516.ini
2026-05-28 19:03:45,039 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:45,041 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:45,046 [root] DEBUG: Loader: Injecting process 13516 (thread 5148) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:45,047 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:03:45,047 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:45,049 [lib.api.process] INFO: Injected into 64-bit <Process 13516 RuntimeBroker.exe>
2026-05-28 19:03:45,050 [root] INFO: Announced 64-bit process name: RuntimeBroker.exe pid: 13516
2026-05-28 19:03:45,051 [lib.api.process] INFO: Monitor config for process 13516: C:\c6kogbu7\dll\13516.ini
2026-05-28 19:03:45,051 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:03:45,054 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:03:45,058 [root] DEBUG: Loader: Injecting process 13516 (thread 5148) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:45,059 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:03:45,060 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:03:45,061 [lib.api.process] INFO: Injected into 64-bit <Process 13516 RuntimeBroker.exe>
2026-05-28 19:03:45,068 [root] DEBUG: 13516: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:03:45,068 [root] DEBUG: 13516: Interactive desktop enabled.
2026-05-28 19:03:45,069 [root] DEBUG: 13516: Dropped file limit defaulting to 100.
2026-05-28 19:03:45,072 [root] DEBUG: 13516: Disabling sleep skipping.
2026-05-28 19:03:45,073 [root] DEBUG: 13516: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:03:45,085 [root] DEBUG: 13516: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:03:45,086 [root] DEBUG: 13516: YaraScan: Scanning 0x00007FF7509C0000, size 0x1b158
2026-05-28 19:03:45,087 [root] DEBUG: 13516: Monitor initialised: 64-bit capemon loaded in process 13516 at 0x00007FFE35340000, thread 5148, image base 0x00007FF7509C0000, stack from 0x00000097AE384000-0x00000097AE390000
2026-05-28 19:03:45,088 [root] DEBUG: 13516: Commandline: C:\Windows\System32\RuntimeBroker.exe -Embedding
2026-05-28 19:03:45,102 [root] DEBUG: 13516: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:03:45,122 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:03:45,123 [root] DEBUG: 13516: set_hooks: Unable to hook LockResource
2026-05-28 19:03:45,128 [root] DEBUG: 13516: Hooked 627 out of 628 functions
2026-05-28 19:03:45,129 [root] DEBUG: 13516: Syscall hook installed, syscall logging level 1
2026-05-28 19:03:45,133 [root] DEBUG: 13516: RestoreHeaders: Restored original import table.
2026-05-28 19:03:45,134 [root] INFO: Loaded monitor into process with pid 13516
2026-05-28 19:03:45,137 [root] DEBUG: 13516: DLL loaded at 0x00007FFE73BF0000: C:\Windows\System32\UMPDC (0x12000 bytes).
2026-05-28 19:03:45,138 [root] DEBUG: 13516: caller_dispatch: Added region at 0x00007FF7509C0000 to tracked regions list (ntdll::NtAllocateVirtualMemoryEx returns to 0x00007FF7509C6182, thread 5148).
2026-05-28 19:03:45,139 [root] DEBUG: 13516: YaraScan: Scanning 0x00007FF7509C0000, size 0x1b158
2026-05-28 19:03:45,140 [root] DEBUG: 13516: ProcessImageBase: Main module image at 0x00007FF7509C0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:03:45,142 [root] DEBUG: 13516: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:03:45,144 [root] DEBUG: 13516: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:03:45,165 [root] DEBUG: 13516: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:03:45,168 [root] DEBUG: 13516: DLL loaded at 0x00007FFE71770000: C:\Windows\System32\UxTheme (0x9e000 bytes).
2026-05-28 19:03:45,169 [root] DEBUG: 13516: DLL loaded at 0x00007FFE72670000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 19:03:45,170 [root] DEBUG: 13516: DLL loaded at 0x00007FFE6FA80000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 19:03:45,170 [root] DEBUG: 13516: DLL loaded at 0x00007FFE6F930000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 19:03:45,175 [root] DEBUG: 13516: DLL loaded at 0x00007FFE654C0000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 19:03:45,175 [root] DEBUG: 13516: DLL loaded at 0x00007FFE5ADA0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:03:45,189 [root] DEBUG: 13516: DLL loaded at 0x00007FFE5C110000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:03:45,197 [root] DEBUG: 13516: DLL loaded at 0x00007FFE70740000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 19:03:45,200 [root] DEBUG: 13516: DLL loaded at 0x00007FFE68280000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 19:03:45,204 [root] DEBUG: 13516: DLL loaded at 0x00007FFE73720000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 19:03:45,205 [root] DEBUG: 13516: DLL loaded at 0x00007FFE71E90000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-28 19:03:45,213 [root] DEBUG: 13516: DLL loaded at 0x00007FFE72E40000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:03:45,214 [root] DEBUG: 13516: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:03:45,237 [root] DEBUG: 13516: DLL loaded at 0x00007FFE604C0000: C:\Windows\System32\LINKINFO (0xd000 bytes).
2026-05-28 19:03:45,263 [root] DEBUG: 13516: DLL loaded at 0x00007FFE715E0000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 19:03:45,266 [root] DEBUG: 13516: DLL loaded at 0x00007FFE69670000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 19:03:45,267 [root] DEBUG: 13516: DLL loaded at 0x00007FFE728C0000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 19:03:45,267 [root] DEBUG: 13516: DLL loaded at 0x00007FFE728F0000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 19:03:45,268 [root] DEBUG: 13516: DLL loaded at 0x00007FFE73CA0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:03:45,269 [root] DEBUG: 13516: DLL loaded at 0x00007FFE60060000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 19:03:45,300 [root] DEBUG: 13516: DLL loaded at 0x00007FFE73E80000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:03:45,320 [root] DEBUG: 13516: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 19:03:45,322 [root] DEBUG: 13516: api-rate-cap: NtReleaseMutant hook disabled due to rate
2026-05-28 19:03:45,500 [root] DEBUG: 13516: DLL loaded at 0x00007FFE764D0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 19:03:45,572 [root] DEBUG: 13516: DLL loaded at 0x00007FFE73CE0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 19:03:45,982 [root] DEBUG: 13516: DLL loaded at 0x00007FFE67520000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 19:03:45,983 [root] DEBUG: 13516: DLL loaded at 0x00007FFE675E0000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 19:03:45,984 [root] DEBUG: 13516: DLL loaded at 0x00007FFE5F710000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 19:03:45,987 [root] DEBUG: 13516: DLL loaded at 0x00007FFE6FA60000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 19:03:45,995 [root] DEBUG: 13516: DLL loaded at 0x00007FFE696D0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:03:46,016 [root] DEBUG: 13516: DLL loaded at 0x00007FFE69820000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 19:03:46,023 [root] DEBUG: 13516: DLL loaded at 0x00007FFE6C5B0000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 19:03:46,032 [root] DEBUG: 13516: DLL loaded at 0x00007FFE69600000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 19:03:46,065 [root] DEBUG: 13516: DLL loaded at 0x00007FFE69C90000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:03:46,067 [root] DEBUG: 13516: DLL loaded at 0x00007FFE600F0000: C:\Windows\System32\NETAPI32 (0x19000 bytes).
2026-05-28 19:03:46,068 [root] DEBUG: 13516: DLL loaded at 0x00007FFE5D810000: C:\Windows\System32\VERSION (0xa000 bytes).
2026-05-28 19:03:46,070 [root] DEBUG: 13516: DLL loaded at 0x00007FFE6ED00000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 19:03:46,071 [root] DEBUG: 13516: DLL loaded at 0x00007FFE73280000: C:\Windows\System32\NETUTILS (0xc000 bytes).
2026-05-28 19:03:46,072 [root] DEBUG: 13516: DLL loaded at 0x00007FFE72ED0000: C:\Windows\System32\WKSCLI (0x19000 bytes).
2026-05-28 19:03:46,073 [root] DEBUG: 13516: DLL loaded at 0x00007FFE5D820000: C:\Windows\System32\ieframe (0x76c000 bytes).
2026-05-28 19:03:46,080 [root] DEBUG: 13516: DLL loaded at 0x00007FFE60710000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32 (0x29a000 bytes).
2026-05-28 19:03:46,086 [root] DEBUG: 13516: DLL loaded at 0x00007FFE64CF0000: C:\Windows\System32\Secur32 (0xc000 bytes).
2026-05-28 19:03:46,088 [root] DEBUG: 13516: DLL loaded at 0x00007FFE71590000: C:\Windows\System32\MLANG (0x42000 bytes).
2026-05-28 19:03:46,482 [root] DEBUG: 13516: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 19:03:47,141 [root] DEBUG: 4712: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 19:04:09,780 [root] DEBUG: 4712: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 19:04:09,804 [root] DEBUG: 4712: api-cap: IsDebuggerPresent hook disabled due to count: 5000
2026-05-28 19:04:10,220 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:04:10,222 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 9532, handle 0x2ef0: Error obtaining target process name
2026-05-28 19:04:10,379 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 15228: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:04:10,379 [root] DEBUG: 4712: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 19:04:10,382 [root] DEBUG: 4712: api-cap: RegCloseKey hook disabled due to count: 5003
2026-05-28 19:04:10,384 [root] DEBUG: 4712: api-cap: RegCloseKey hook disabled due to count: 5001
2026-05-28 19:04:10,388 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15228
2026-05-28 19:04:10,393 [lib.api.process] INFO: Monitor config for process 15228: C:\c6kogbu7\dll\15228.ini
2026-05-28 19:04:10,394 [root] DEBUG: 4712: api-cap: RegCloseKey hook disabled due to count: 5002
2026-05-28 19:04:10,399 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:10,402 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:10,415 [root] DEBUG: Loader: Injecting process 15228 (thread 15232) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:10,417 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:10,423 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:10,424 [lib.api.process] INFO: Injected into 64-bit <Process 15228 dllhost.exe>
2026-05-28 19:04:10,426 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15228
2026-05-28 19:04:10,427 [lib.api.process] INFO: Monitor config for process 15228: C:\c6kogbu7\dll\15228.ini
2026-05-28 19:04:10,428 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:10,432 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:10,440 [root] DEBUG: Loader: Injecting process 15228 (thread 15232) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:10,441 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:10,441 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:10,443 [lib.api.process] INFO: Injected into 64-bit <Process 15228 dllhost.exe>
2026-05-28 19:04:10,450 [root] DEBUG: 15228: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:04:10,451 [root] DEBUG: 15228: Interactive desktop enabled.
2026-05-28 19:04:10,452 [root] DEBUG: 15228: Dropped file limit defaulting to 100.
2026-05-28 19:04:10,454 [root] DEBUG: 15228: Disabling sleep skipping.
2026-05-28 19:04:10,456 [root] DEBUG: 15228: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:04:10,469 [root] DEBUG: 15228: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:04:10,470 [root] DEBUG: 15228: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:04:10,471 [root] DEBUG: 15228: Monitor initialised: 64-bit capemon loaded in process 15228 at 0x00007FFE35340000, thread 15232, image base 0x00007FF687D50000, stack from 0x0000007F1AEF4000-0x0000007F1AF00000
2026-05-28 19:04:10,472 [root] DEBUG: 15228: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:04:10,482 [root] DEBUG: 15228: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:04:10,504 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:04:10,504 [root] DEBUG: 15228: set_hooks: Unable to hook LockResource
2026-05-28 19:04:10,506 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 14964: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:04:10,507 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14964
2026-05-28 19:04:10,507 [lib.api.process] INFO: Monitor config for process 14964: C:\c6kogbu7\dll\14964.ini
2026-05-28 19:04:10,510 [root] DEBUG: 15228: Hooked 627 out of 628 functions
2026-05-28 19:04:10,510 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:10,511 [root] DEBUG: 15228: Syscall hook installed, syscall logging level 1
2026-05-28 19:04:10,513 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:10,517 [root] DEBUG: 15228: RestoreHeaders: Restored original import table.
2026-05-28 19:04:10,517 [root] INFO: Loaded monitor into process with pid 15228
2026-05-28 19:04:10,518 [root] DEBUG: 15228: caller_dispatch: Added region at 0x00007FF687D50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF687D512F2, thread 15232).
2026-05-28 19:04:10,519 [root] DEBUG: Loader: Injecting process 14964 (thread 14960) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:10,520 [root] DEBUG: 15228: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:04:10,520 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:10,521 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:10,522 [root] DEBUG: 15228: ProcessImageBase: Main module image at 0x00007FF687D50000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:04:10,522 [lib.api.process] INFO: Injected into 64-bit <Process 14964 dllhost.exe>
2026-05-28 19:04:10,523 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14964
2026-05-28 19:04:10,524 [lib.api.process] INFO: Monitor config for process 14964: C:\c6kogbu7\dll\14964.ini
2026-05-28 19:04:10,524 [root] DEBUG: 15228: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:04:10,524 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:10,526 [root] DEBUG: 15228: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:04:10,527 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:10,529 [root] DEBUG: 15228: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:04:10,536 [root] DEBUG: Loader: Injecting process 14964 (thread 14960) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:10,537 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:10,538 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:10,540 [lib.api.process] INFO: Injected into 64-bit <Process 14964 dllhost.exe>
2026-05-28 19:04:10,548 [root] DEBUG: 15228: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:04:10,550 [root] DEBUG: 14964: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:04:10,555 [root] DEBUG: 14964: Interactive desktop enabled.
2026-05-28 19:04:10,556 [root] DEBUG: 14964: Dropped file limit defaulting to 100.
2026-05-28 19:04:10,556 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 1972: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF65D570000
2026-05-28 19:04:10,563 [root] DEBUG: 14964: Disabling sleep skipping.
2026-05-28 19:04:10,563 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 1972
2026-05-28 19:04:10,564 [lib.api.process] INFO: Monitor config for process 1972: C:\c6kogbu7\dll\1972.ini
2026-05-28 19:04:10,564 [root] DEBUG: 14964: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:04:10,565 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:10,567 [root] DEBUG: 15228: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:04:10,568 [root] DEBUG: 15228: DLL loaded at 0x00007FFE605C0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:04:10,575 [root] DEBUG: 15228: DLL loaded at 0x00007FFE6F930000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:04:10,577 [root] DEBUG: 14964: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:04:10,578 [root] DEBUG: 14964: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:04:10,579 [root] DEBUG: 14964: Monitor initialised: 64-bit capemon loaded in process 14964 at 0x00007FFE35340000, thread 14960, image base 0x00007FF687D50000, stack from 0x000000DFAD104000-0x000000DFAD110000
2026-05-28 19:04:10,580 [root] DEBUG: 14964: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 19:04:10,592 [root] DEBUG: 4712: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 19:04:10,594 [root] DEBUG: 14964: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:04:10,617 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:04:10,617 [root] DEBUG: 14964: set_hooks: Unable to hook LockResource
2026-05-28 19:04:10,623 [root] DEBUG: 14964: Hooked 627 out of 628 functions
2026-05-28 19:04:10,624 [root] DEBUG: 14964: Syscall hook installed, syscall logging level 1
2026-05-28 19:04:10,629 [root] DEBUG: 14964: RestoreHeaders: Restored original import table.
2026-05-28 19:04:10,630 [root] INFO: Loaded monitor into process with pid 14964
2026-05-28 19:04:10,631 [root] DEBUG: 14964: caller_dispatch: Added region at 0x00007FF687D50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF687D512F2, thread 14960).
2026-05-28 19:04:10,631 [root] DEBUG: 14964: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:04:10,633 [root] DEBUG: 14964: ProcessImageBase: Main module image at 0x00007FF687D50000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:04:10,635 [root] DEBUG: 14964: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:04:10,638 [root] DEBUG: 14964: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:04:10,640 [root] DEBUG: 14964: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:04:10,659 [root] DEBUG: 14964: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:04:10,675 [root] DEBUG: 14964: DLL loaded at 0x00007FFE732A0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:04:10,677 [root] DEBUG: 14964: DLL loaded at 0x00007FFE73280000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 19:04:10,677 [root] DEBUG: 14964: DLL loaded at 0x00007FFE6D660000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:04:10,680 [root] DEBUG: 14964: DLL loaded at 0x00007FFE6ED00000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 19:04:10,681 [root] DEBUG: 14964: DLL loaded at 0x00007FFE72EF0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:04:10,681 [root] DEBUG: 14964: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:04:10,682 [root] DEBUG: 14964: DLL loaded at 0x00007FFE73170000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:04:10,683 [root] DEBUG: 14964: DLL loaded at 0x00007FFE73CA0000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 19:04:10,683 [root] DEBUG: 14964: DLL loaded at 0x00007FFE73CE0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 19:04:10,685 [root] DEBUG: 14964: DLL loaded at 0x00007FFE6F8F0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 19:04:10,686 [root] DEBUG: 14964: DLL loaded at 0x00007FFE731B0000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 19:04:10,687 [root] DEBUG: 14964: DLL loaded at 0x00007FFE1AEA0000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 19:04:10,690 [root] DEBUG: 14964: DLL loaded at 0x00007FFE752A0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:04:10,696 [root] DEBUG: 14964: DLL loaded at 0x00007FFE64F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:04:10,713 [root] DEBUG: 4712: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-05-28 19:04:10,732 [root] DEBUG: 4712: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-28 19:04:11,056 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:11,061 [root] DEBUG: Loader: Injecting process 1972 (thread 9700) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,062 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:11,063 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,064 [lib.api.process] INFO: Injected into 64-bit <Process 1972 WmiPrvSE.exe>
2026-05-28 19:04:11,066 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 1972
2026-05-28 19:04:11,067 [lib.api.process] INFO: Monitor config for process 1972: C:\c6kogbu7\dll\1972.ini
2026-05-28 19:04:11,067 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:11,399 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 16044: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF76A390000
2026-05-28 19:04:11,400 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 16044
2026-05-28 19:04:11,402 [lib.api.process] INFO: Monitor config for process 16044: C:\c6kogbu7\dll\16044.ini
2026-05-28 19:04:11,406 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:11,414 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:11,422 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A3B0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 19:04:11,423 [root] DEBUG: Loader: Injecting process 16044 (thread 16048) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,424 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:11,424 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A3B0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 19:04:11,425 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,426 [root] DEBUG: 4712: DLL loaded at 0x00007FFE64440000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 19:04:11,427 [lib.api.process] INFO: Injected into 64-bit <Process 16044 MoUsoCoreWorker.exe>
2026-05-28 19:04:11,427 [root] DEBUG: 4712: DLL loaded at 0x00007FFE64440000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 19:04:11,429 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 16044
2026-05-28 19:04:11,429 [lib.api.process] INFO: Monitor config for process 16044: C:\c6kogbu7\dll\16044.ini
2026-05-28 19:04:11,430 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:11,434 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:11,436 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A330000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 19:04:11,436 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A330000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 19:04:11,440 [root] DEBUG: Loader: Injecting process 16044 (thread 16048) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,441 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:11,442 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,443 [lib.api.process] INFO: Injected into 64-bit <Process 16044 MoUsoCoreWorker.exe>
2026-05-28 19:04:11,444 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A1F0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 19:04:11,444 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A1F0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 19:04:11,446 [root] DEBUG: 4712: DLL loaded at 0x00007FFE71A00000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 19:04:11,446 [root] DEBUG: 4712: DLL loaded at 0x00007FFE71A00000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 19:04:11,448 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A250000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 19:04:11,450 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A250000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 19:04:11,453 [root] DEBUG: 16044: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:04:11,455 [root] DEBUG: 16044: Interactive desktop enabled.
2026-05-28 19:04:11,456 [root] DEBUG: 16044: Dropped file limit defaulting to 100.
2026-05-28 19:04:11,457 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A160000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 19:04:11,458 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A160000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 19:04:11,459 [root] DEBUG: 16044: VerifyCodeSection: Exception rebasing image from 0x00007FF76A390000 to 0x0000000140000000.
2026-05-28 19:04:11,462 [root] DEBUG: 16044: Disabling sleep skipping.
2026-05-28 19:04:11,464 [root] DEBUG: 16044: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:04:11,473 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A070000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 19:04:11,474 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1A070000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 19:04:11,477 [root] DEBUG: 16044: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:04:11,478 [root] DEBUG: 16044: YaraScan: Scanning 0x00007FF76A390000, size 0x1ad000
2026-05-28 19:04:11,488 [root] DEBUG: 16044: Monitor initialised: 64-bit capemon loaded in process 16044 at 0x00007FFE35340000, thread 16048, image base 0x00007FF76A390000, stack from 0x000000B4B1CD4000-0x000000B4B1CE0000
2026-05-28 19:04:11,489 [root] DEBUG: 16044: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-05-28 19:04:11,490 [root] DEBUG: 4712: DLL loaded at 0x00007FFE6EF50000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 19:04:11,491 [root] DEBUG: 4712: DLL loaded at 0x00007FFE6EF50000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 19:04:11,501 [root] DEBUG: 16044: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:04:11,524 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:04:11,525 [root] DEBUG: 16044: set_hooks: Unable to hook LockResource
2026-05-28 19:04:11,531 [root] DEBUG: 16044: Hooked 627 out of 628 functions
2026-05-28 19:04:11,540 [root] DEBUG: 4712: AllocationHandler: Allocation already in tracked region list: 0x00007DF4559C0000.
2026-05-28 19:04:11,544 [root] DEBUG: 4712: AllocationHandler: Allocation already in tracked region list: 0x00007DF4559B0000.
2026-05-28 19:04:11,545 [root] DEBUG: 16044: Syscall hook installed, syscall logging level 1
2026-05-28 19:04:11,547 [root] DEBUG: 4712: FreeHandler: Address: 0x00007DF4559B0000.
2026-05-28 19:04:11,548 [root] DEBUG: 4712: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:04:11,550 [root] DEBUG: 4712: FreeHandler: Address: 0x00007DF4559C0000.
2026-05-28 19:04:11,553 [root] DEBUG: 4712: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:04:11,554 [root] DEBUG: 16044: RestoreHeaders: Restored original import table.
2026-05-28 19:04:11,554 [root] INFO: Loaded monitor into process with pid 16044
2026-05-28 19:04:11,562 [root] DEBUG: 16044: caller_dispatch: Added region at 0x00007FF76A390000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF76A4AF712, thread 16048).
2026-05-28 19:04:11,564 [root] DEBUG: 16044: YaraScan: Scanning 0x00007FF76A390000, size 0x1ad000
2026-05-28 19:04:11,571 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 15652: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF62DCE0000
2026-05-28 19:04:11,572 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 15652
2026-05-28 19:04:11,573 [lib.api.process] INFO: Monitor config for process 15652: C:\c6kogbu7\dll\15652.ini
2026-05-28 19:04:11,577 [root] DEBUG: 16044: ProcessImageBase: Main module image at 0x00007FF76A390000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:04:11,577 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:11,581 [root] DEBUG: 16044: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:04:11,582 [root] DEBUG: 16044: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:04:11,589 [root] DEBUG: 4712: AllocationHandler: Allocation already in tracked region list: 0x00007DF4559B0000.
2026-05-28 19:04:11,591 [root] DEBUG: 4712: FreeHandler: Address: 0x00007DF4559B0000.
2026-05-28 19:04:11,591 [root] DEBUG: 4712: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:04:11,595 [root] DEBUG: 4712: FreeHandler: Address: 0x00007DF4559C0000.
2026-05-28 19:04:11,596 [root] DEBUG: 4712: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:04:11,606 [root] DEBUG: 16044: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 19:04:11,631 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:11,633 [root] DEBUG: 16044: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:04:11,636 [root] DEBUG: Loader: Injecting process 1972 (thread 9700) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,638 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:04:11,640 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,642 [lib.api.process] INFO: Injected into 64-bit <Process 1972 WmiPrvSE.exe>
2026-05-28 19:04:11,651 [root] DEBUG: 1972: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:04:11,654 [root] DEBUG: 1972: Interactive desktop enabled.
2026-05-28 19:04:11,655 [root] DEBUG: 16044: DLL loaded at 0x00007FFE5C330000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-05-28 19:04:11,656 [root] DEBUG: 1972: Dropped file limit defaulting to 100.
2026-05-28 19:04:11,659 [root] DEBUG: 1972: Disabling sleep skipping.
2026-05-28 19:04:11,660 [root] DEBUG: 1972: Services hook set enabled
2026-05-28 19:04:11,663 [root] DEBUG: 1972: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:04:11,675 [root] DEBUG: 1972: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:04:11,676 [root] DEBUG: 1972: Monitor initialised: 64-bit capemon loaded in process 1972 at 0x00007FFE35340000, thread 9700, image base 0x00007FF65D570000, stack from 0x00000086301A0000-0x00000086301B0000
2026-05-28 19:04:11,676 [root] DEBUG: 1972: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 19:04:11,689 [root] DEBUG: 1972: Hooked 69 out of 69 functions
2026-05-28 19:04:11,693 [root] DEBUG: 1972: RestoreHeaders: Restored original import table.
2026-05-28 19:04:11,693 [root] INFO: Loaded monitor into process with pid 1972
2026-05-28 19:04:11,698 [root] DEBUG: 1972: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:04:11,700 [root] DEBUG: 1972: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:04:11,702 [root] DEBUG: 1972: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:04:11,704 [lib.api.process] INFO: Monitor config for process 3644: C:\c6kogbu7\dll\3644.ini
2026-05-28 19:04:11,706 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:11,709 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:11,713 [root] DEBUG: Loader: Injecting process 3644 with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,717 [root] DEBUG: 3644: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:04:11,719 [root] DEBUG: 3644: Disabling sleep skipping.
2026-05-28 19:04:11,720 [root] DEBUG: 3644: Interactive desktop enabled.
2026-05-28 19:04:11,721 [root] DEBUG: 3644: Dropped file limit defaulting to 100.
2026-05-28 19:04:11,722 [root] DEBUG: 3644: Services hook set enabled
2026-05-28 19:04:11,723 [root] DEBUG: 3644: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:04:11,735 [root] DEBUG: 3644: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:04:11,736 [root] DEBUG: 3644: Monitor initialised: 64-bit capemon loaded in process 3644 at 0x00007FFE35340000, thread 16456, image base 0x00007FF7BE050000, stack from 0x0000008224575000-0x0000008224580000
2026-05-28 19:04:11,738 [root] DEBUG: 3644: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 19:04:11,752 [root] DEBUG: 3644: Hooked 69 out of 69 functions
2026-05-28 19:04:11,754 [root] INFO: Loaded monitor into process with pid 3644
2026-05-28 19:04:11,755 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:04:11,756 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:11,758 [lib.api.process] INFO: Injected into 64-bit <Process 3644 svchost.exe>
2026-05-28 19:04:11,857 [root] DEBUG: 16044: DLL loaded at 0x00007FFE6ED00000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 19:04:11,858 [root] DEBUG: 16044: DLL loaded at 0x00007FFE73B30000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 19:04:11,859 [root] DEBUG: 16044: DLL loaded at 0x00007FFE1A3F0000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-05-28 19:04:11,866 [root] DEBUG: 16044: DLL loaded at 0x00007FFE5C940000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 19:04:11,868 [root] DEBUG: 16044: DLL loaded at 0x00007FFE5B130000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 19:04:11,871 [root] DEBUG: 16044: DLL loaded at 0x00007FFE6FA60000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 19:04:11,873 [root] DEBUG: 16044: DLL loaded at 0x00007FFE73A70000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-05-28 19:04:11,973 [root] DEBUG: 16044: DLL loaded at 0x00007FFE5B130000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 19:04:12,042 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:12,047 [root] DEBUG: Loader: Injecting process 15652 (thread 15696) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:12,048 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:12,049 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:12,050 [lib.api.process] INFO: Injected into 64-bit <Process 15652 ShellExperienceHost.exe>
2026-05-28 19:04:12,052 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 15652
2026-05-28 19:04:12,052 [lib.api.process] INFO: Monitor config for process 15652: C:\c6kogbu7\dll\15652.ini
2026-05-28 19:04:12,053 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:12,523 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:12,529 [root] DEBUG: Loader: Injecting process 15652 (thread 15696) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:12,530 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:12,530 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:12,532 [lib.api.process] INFO: Injected into 64-bit <Process 15652 ShellExperienceHost.exe>
2026-05-28 19:04:12,533 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 15652
2026-05-28 19:04:12,534 [lib.api.process] INFO: Monitor config for process 15652: C:\c6kogbu7\dll\15652.ini
2026-05-28 19:04:12,534 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:13,045 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:13,052 [root] DEBUG: Loader: Injecting process 15652 with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:13,053 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15696, handle 0x120
2026-05-28 19:04:13,053 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:04:13,054 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:13,056 [lib.api.process] INFO: Injected into 64-bit <Process 15652 ShellExperienceHost.exe>
2026-05-28 19:04:13,152 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 16740, handle 0x301c: C:\Windows\System32\rundll32.exe
2026-05-28 19:04:13,458 [root] DEBUG: 16044: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 19:04:13,762 [root] DEBUG: 1972: DLL loaded at 0x00007FFE5C5C0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 19:04:13,773 [root] DEBUG: 1972: DLL loaded at 0x00007FFE5C200000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 19:04:13,813 [root] DEBUG: 1972: DLL loaded at 0x00007FFE1C3D0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 19:04:13,838 [root] DEBUG: 1972: DLL loaded at 0x00007FFE73C10000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:04:13,839 [root] DEBUG: 1972: DLL loaded at 0x00007FFE1A1F0000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 19:04:13,840 [root] DEBUG: 1972: DLL loaded at 0x00007FFE19E60000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 19:04:13,840 [root] DEBUG: 1972: DLL loaded at 0x00007FFE73BF0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:04:13,861 [root] DEBUG: 1972: DLL loaded at 0x000001B170010000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 19:04:13,863 [root] DEBUG: 1972: DLL loaded at 0x00007FFE6E960000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 19:04:13,864 [root] DEBUG: 1972: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 19:04:15,148 [root] DEBUG: 16044: DLL loaded at 0x00007FFE72E40000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:04:15,150 [root] DEBUG: 16044: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:04:15,157 [root] DEBUG: 16044: DLL loaded at 0x00007FFE5D170000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 19:04:15,160 [root] DEBUG: 16044: DLL loaded at 0x00007FFE19E30000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 19:04:15,161 [root] DEBUG: 16044: DLL loaded at 0x00007FFE5FFA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 19:04:15,165 [root] DEBUG: 16044: DLL loaded at 0x00007FFE6C120000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:04:15,171 [root] DEBUG: 16044: DLL loaded at 0x00007FFE70740000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 19:04:15,176 [root] DEBUG: 16044: DLL loaded at 0x00007FFE5BEF0000: C:\Windows\SYSTEM32\productenumerator (0xe000 bytes).
2026-05-28 19:04:15,532 [root] INFO: Stopping Task Scheduler Service
2026-05-28 19:04:15,546 [root] INFO: Stopped Task Scheduler Service
2026-05-28 19:04:15,549 [root] INFO: Starting Task Scheduler Service
2026-05-28 19:04:15,562 [root] INFO: Started Task Scheduler Service
2026-05-28 19:04:15,563 [lib.api.process] INFO: Monitor config for process 1248: C:\c6kogbu7\dll\1248.ini
2026-05-28 19:04:15,565 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:15,568 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:15,573 [root] DEBUG: Loader: Injecting process 1248 with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:15,577 [root] DEBUG: 1248: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:04:15,591 [root] DEBUG: 1248: Disabling sleep skipping.
2026-05-28 19:04:15,593 [root] DEBUG: 13516: DLL loaded at 0x00007FFE6C5B0000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 19:04:15,594 [root] DEBUG: 1248: Interactive desktop enabled.
2026-05-28 19:04:15,595 [root] DEBUG: 1248: Dropped file limit defaulting to 100.
2026-05-28 19:04:15,596 [root] DEBUG: 1248: Services hook set enabled
2026-05-28 19:04:15,598 [root] DEBUG: 1248: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:04:15,611 [root] DEBUG: 1248: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:04:15,612 [root] DEBUG: 1248: Monitor initialised: 64-bit capemon loaded in process 1248 at 0x00007FFE35340000, thread 17168, image base 0x00007FF7BE050000, stack from 0x0000002A1C5F4000-0x0000002A1C600000
2026-05-28 19:04:15,613 [root] DEBUG: 1248: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-28 19:04:15,629 [root] DEBUG: 1248: Hooked 69 out of 69 functions
2026-05-28 19:04:15,631 [root] INFO: Loaded monitor into process with pid 1248
2026-05-28 19:04:15,632 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:04:15,633 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:15,634 [lib.api.process] INFO: Injected into 64-bit <Process 1248 svchost.exe>
2026-05-28 19:04:15,710 [root] INFO: Process with pid 14964 has terminated
2026-05-28 19:04:15,711 [root] DEBUG: 14964: NtTerminateProcess hook: Attempting to dump process 14964
2026-05-28 19:04:15,712 [root] DEBUG: 14964: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:04:15,780 [root] INFO: Process with pid 15228 has terminated
2026-05-28 19:04:15,782 [root] DEBUG: 15228: NtTerminateProcess hook: Attempting to dump process 15228
2026-05-28 19:04:15,783 [root] DEBUG: 15228: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:04:17,639 [root] DEBUG: 16044: DLL loaded at 0x00007FFE6F1B0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 19:04:17,675 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-28 19:04:18,699 [root] DEBUG: 16044: DLL loaded at 0x00007FFE5BDF0000: C:\Windows\system32\WaaSMedicPS (0xc000 bytes).
2026-05-28 19:04:18,817 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\efb4d55f2abc15fd0be87d71dca14cc2cf209d35ccef2ca20fc628f985862e4b; Size is 8720; Max size: 100000000
2026-05-28 19:04:18,845 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\fe42955bc7fd9e89c6ed41d40681083afb2c9dfe3ddf3fb6ad8548a3d3a057e5; Size is 8720; Max size: 100000000
2026-05-28 19:04:18,884 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\b3a3cb276447087768d46a4d5db9b326d0dd5baf7b77d33dba19f22eae333db5; Size is 8720; Max size: 100000000
2026-05-28 19:04:18,907 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\2052de0a0b761aad13c7a2aa7ebff069df7a2f27215e6ddcee8927531e10d56b; Size is 8720; Max size: 100000000
2026-05-28 19:04:18,928 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\254bac028994b834b4d87ba8b9cab91db0bf3ee5982fbd2d46c13fb41f8443b2; Size is 8720; Max size: 100000000
2026-05-28 19:04:19,041 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\6ae9ecea2d2143ee17737dc6fd1a628cc151a2a2b7938588dde4c0cf4f1081da; Size is 12824; Max size: 100000000
2026-05-28 19:04:21,980 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 5612 (handle 0x3034): 0x00007FF7E2400000.
2026-05-28 19:04:22,050 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 3988: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:04:22,051 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3988
2026-05-28 19:04:22,052 [lib.api.process] INFO: Monitor config for process 3988: C:\c6kogbu7\dll\3988.ini
2026-05-28 19:04:22,053 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,060 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,065 [root] DEBUG: Loader: Injecting process 3988 (thread 3496) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,068 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,069 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,071 [lib.api.process] INFO: Injected into 64-bit <Process 3988 dllhost.exe>
2026-05-28 19:04:22,073 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3988
2026-05-28 19:04:22,073 [lib.api.process] INFO: Monitor config for process 3988: C:\c6kogbu7\dll\3988.ini
2026-05-28 19:04:22,078 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,088 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,096 [root] DEBUG: Loader: Injecting process 3988 (thread 3496) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,099 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,100 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,101 [lib.api.process] INFO: Injected into 64-bit <Process 3988 dllhost.exe>
2026-05-28 19:04:22,107 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 17084: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:04:22,108 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 17084
2026-05-28 19:04:22,109 [lib.api.process] INFO: Monitor config for process 17084: C:\c6kogbu7\dll\17084.ini
2026-05-28 19:04:22,110 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,113 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,118 [root] DEBUG: Loader: Injecting process 17084 (thread 17136) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,118 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,119 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,121 [lib.api.process] INFO: Injected into 64-bit <Process 17084 dllhost.exe>
2026-05-28 19:04:22,123 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 17084
2026-05-28 19:04:22,125 [lib.api.process] INFO: Monitor config for process 17084: C:\c6kogbu7\dll\17084.ini
2026-05-28 19:04:22,125 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,131 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,136 [root] DEBUG: Loader: Injecting process 17084 (thread 17136) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,137 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,138 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,139 [lib.api.process] INFO: Injected into 64-bit <Process 17084 dllhost.exe>
2026-05-28 19:04:22,143 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 15524: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:04:22,144 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15524
2026-05-28 19:04:22,145 [lib.api.process] INFO: Monitor config for process 15524: C:\c6kogbu7\dll\15524.ini
2026-05-28 19:04:22,147 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,154 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,159 [root] DEBUG: Loader: Injecting process 15524 (thread 15536) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,160 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,161 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,163 [lib.api.process] INFO: Injected into 64-bit <Process 15524 dllhost.exe>
2026-05-28 19:04:22,164 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15524
2026-05-28 19:04:22,166 [lib.api.process] INFO: Monitor config for process 15524: C:\c6kogbu7\dll\15524.ini
2026-05-28 19:04:22,166 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,170 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,174 [root] DEBUG: Loader: Injecting process 15524 (thread 15536) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,175 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,176 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,177 [lib.api.process] INFO: Injected into 64-bit <Process 15524 dllhost.exe>
2026-05-28 19:04:22,181 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 14868: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:04:22,182 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14868
2026-05-28 19:04:22,183 [lib.api.process] INFO: Monitor config for process 14868: C:\c6kogbu7\dll\14868.ini
2026-05-28 19:04:22,186 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,194 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,202 [root] DEBUG: Loader: Injecting process 14868 (thread 16984) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,203 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,205 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,206 [lib.api.process] INFO: Injected into 64-bit <Process 14868 dllhost.exe>
2026-05-28 19:04:22,209 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14868
2026-05-28 19:04:22,210 [lib.api.process] INFO: Monitor config for process 14868: C:\c6kogbu7\dll\14868.ini
2026-05-28 19:04:22,210 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,214 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,221 [root] DEBUG: Loader: Injecting process 14868 (thread 16984) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,223 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,225 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,227 [lib.api.process] INFO: Injected into 64-bit <Process 14868 dllhost.exe>
2026-05-28 19:04:22,231 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 15676: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:04:22,233 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15676
2026-05-28 19:04:22,234 [lib.api.process] INFO: Monitor config for process 15676: C:\c6kogbu7\dll\15676.ini
2026-05-28 19:04:22,243 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,253 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,260 [root] DEBUG: Loader: Injecting process 15676 (thread 15632) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,263 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,265 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,266 [lib.api.process] INFO: Injected into 64-bit <Process 15676 dllhost.exe>
2026-05-28 19:04:22,268 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15676
2026-05-28 19:04:22,269 [lib.api.process] INFO: Monitor config for process 15676: C:\c6kogbu7\dll\15676.ini
2026-05-28 19:04:22,269 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,273 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,278 [root] DEBUG: Loader: Injecting process 15676 (thread 15632) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,280 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,281 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,283 [lib.api.process] INFO: Injected into 64-bit <Process 15676 dllhost.exe>
2026-05-28 19:04:22,287 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 17116: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:04:22,288 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 17116
2026-05-28 19:04:22,289 [lib.api.process] INFO: Monitor config for process 17116: C:\c6kogbu7\dll\17116.ini
2026-05-28 19:04:22,290 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,293 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,299 [root] DEBUG: Loader: Injecting process 17116 (thread 17108) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,300 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,301 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,302 [lib.api.process] INFO: Injected into 64-bit <Process 17116 dllhost.exe>
2026-05-28 19:04:22,304 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 17116
2026-05-28 19:04:22,304 [lib.api.process] INFO: Monitor config for process 17116: C:\c6kogbu7\dll\17116.ini
2026-05-28 19:04:22,305 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:04:22,310 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\HuBDrjs.dll, loader C:\c6kogbu7\bin\bTDQtiyH.exe
2026-05-28 19:04:22,314 [root] DEBUG: Loader: Injecting process 17116 (thread 17108) with C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,315 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:04:22,316 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\HuBDrjs.dll.
2026-05-28 19:04:22,319 [lib.api.process] INFO: Injected into 64-bit <Process 17116 dllhost.exe>
2026-05-28 19:04:23,037 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 5336 (handle 0x3044): 0x00007FF637DB0000.
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 19:02:59 | 2026-05-28 19:04:36 | none |
| Process: RuntimeBroker.exe (13516) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (13516) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (13516) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (13516) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 162.159.135.232 [VT] | unknown | - |
| Y | 150.171.109.25 [VT] | unknown | - |
| Y | 40.115.75.193 [VT] | unknown | - |
| Y | 204.79.197.203 [VT] | unknown | - |
| Y | 150.171.27.12 [VT] | unknown | - |
| Y | 149.135.84.50 [VT] | unknown | - |
| Y | 18.155.216.83 [VT] | unknown | - |
| Y | 104.18.33.89 [VT] | unknown | - |
| Y | 149.135.84.32 [VT] | unknown | - |
| Y | 150.171.109.19 [VT] | unknown | - |
| Y | 150.171.28.10 [VT] | unknown | - |
| Y | 149.135.84.27 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| N | 162.159.134.234 [VT] | unknown | - |
| N | 162.254.195.69 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| Y | 162.159.130.235 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 172.64.41.3 [VT] | unknown | - |
| Y | 162.159.133.233 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Y | 172.172.255.217 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-http.steamserver.net [VT] |
CNAME syd.http.ipv6check.akadns.net
[VT]
CNAME http.ipv6check.akadns.net [VT] |
|
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| cmp1-lax1.steamserver.net [VT] | A 162.254.195.69 [VT] | 162.254.195.69 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.24 [VT] |
| dns.google [VT] |
A 8.8.8.8
[VT]
A 8.8.4.4 [VT] |
8.8.8.8 [VT] |
| gateway-us-east1-c.discord.gg [VT] |
A 162.159.136.234
[VT]
A 162.159.130.234 [VT] A 162.159.133.234 [VT] A 162.159.134.234 [VT] A 162.159.135.234 [VT] |
162.159.135.234 [VT] |
| disabled.invalid [VT] | NXDOMAIN |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.