| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 19:34:07 | 2026-05-28 19:35:33 | 86s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 19:33:25,382 [root] INFO: Date set to: 20260528T19:34:15, timeout set to: 200
2026-05-28 19:34:15,004 [root] DEBUG: Starting analyzer from: C:\hsngo5k_
2026-05-28 19:34:15,005 [root] DEBUG: Storing results at: C:\nhdjfgMY
2026-05-28 19:34:15,005 [root] DEBUG: Pipe server name: \\.\PIPE\KLuGAxLLsj
2026-05-28 19:34:15,005 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 19:34:15,005 [root] INFO: analysis running as an admin
2026-05-28 19:34:15,005 [root] INFO: analysis package specified: "edge"
2026-05-28 19:34:15,005 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 19:34:15,007 [root] DEBUG: imported analysis package "edge"
2026-05-28 19:34:15,007 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 19:34:15,007 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-28 19:34:15,007 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 19:34:15,008 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 19:34:15,008 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 19:34:15,008 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 19:34:15,021 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 19:34:15,042 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 19:34:15,052 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 19:34:15,057 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 19:34:15,059 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 19:34:15,060 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 19:34:15,060 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 19:34:15,061 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 19:34:15,061 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 19:34:15,061 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 19:34:15,062 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 19:34:15,062 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 19:34:15,063 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 19:34:15,063 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 19:34:15,063 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 19:34:15,064 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 19:34:15,064 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 19:34:15,064 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 19:34:15,064 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 19:34:15,064 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 19:34:15,064 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 19:34:15,065 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 19:34:15,065 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 19:34:15,067 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 680)
2026-05-28 19:34:15,067 [modules.auxiliary.disguise] INFO: Disguising GUID to b9707053-9b47-434e-80d6-fdf06c9a7deb
2026-05-28 19:34:15,067 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 19:34:15,068 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 19:34:15,068 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 19:34:15,068 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 19:34:15,068 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 19:34:15,069 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 19:34:15,069 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 19:34:15,069 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 19:34:15,070 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 19:34:15,070 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 19:34:15,070 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 19:34:15,070 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 19:34:15,070 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 19:34:15,070 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 19:34:15,071 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 19:34:15,071 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 19:34:15,072 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 19:34:15,073 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 19:34:15,073 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 19:34:15,096 [lib.api.process] INFO: Monitor config for process 4692: C:\hsngo5k_\dll\4692.ini
2026-05-28 19:34:15,097 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:15,099 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:15,189 [root] DEBUG: Loader: Injecting process 4692 with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:15,364 [root] DEBUG: 4692: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:34:15,365 [root] DEBUG: 4692: Disabling sleep skipping.
2026-05-28 19:34:15,365 [root] DEBUG: 4692: Interactive desktop enabled.
2026-05-28 19:34:15,365 [root] DEBUG: 4692: Dropped file limit defaulting to 100.
2026-05-28 19:34:15,366 [root] DEBUG: 4692: Interactive desktop - injecting Explorer Shell
2026-05-28 19:34:15,370 [root] DEBUG: 4692: YaraInit: Compiled 44 rule files
2026-05-28 19:34:15,371 [root] DEBUG: 4692: YaraInit: Compiled rules saved to file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:34:15,473 [root] DEBUG: 4692: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:34:15,476 [root] DEBUG: 4692: YaraScan: Scanning 0x00007FF627610000, size 0x545316
2026-05-28 19:34:15,545 [root] DEBUG: 4692: Monitor initialised: 64-bit capemon loaded in process 4692 at 0x00007FFB863A0000, thread 5576, image base 0x00007FF627610000, stack from 0x0000000010B51000-0x0000000010B60000
2026-05-28 19:34:15,547 [root] DEBUG: 4692: Commandline: C:\Windows\Explorer.EXE
2026-05-28 19:34:15,557 [root] DEBUG: 4692: Hooked 69 out of 69 functions
2026-05-28 19:34:15,586 [root] DEBUG: 4692: Syscall hook installed, syscall logging level 1
2026-05-28 19:34:15,599 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:34:15,600 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:15,601 [lib.api.process] INFO: Injected into 64-bit <Process 4692 explorer.exe>
2026-05-28 19:34:18,791 [root] DEBUG: 4692: caller_dispatch: Added region at 0x00007FF627610000 to tracked regions list (ntdll::NtDuplicateObject returns to 0x00007FF62762C161, thread 4696).
2026-05-28 19:34:18,792 [root] DEBUG: 4692: YaraScan: Scanning 0x00007FF627610000, size 0x545316
2026-05-28 19:34:18,830 [root] DEBUG: 4692: ProcessImageBase: Main module image at 0x00007FF627610000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:34:20,246 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9D80000: C:\Windows\System32\dlnashext (0x56000 bytes).
2026-05-28 19:34:20,251 [root] DEBUG: 4692: DLL loaded at 0x00007FFB881F0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 19:34:20,251 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4520000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-05-28 19:34:20,296 [root] DEBUG: 4692: api-rate-cap: CoCreateInstance hook disabled due to rate
2026-05-28 19:34:21,553 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB5020000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 19:34:21,569 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA650000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:34:21,575 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA650000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:34:21,580 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA650000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:34:22,702 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAC200000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:34:22,732 [root] INFO: Restarting WMI Service
2026-05-28 19:34:24,767 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 19:34:24,767 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 19:34:24,768 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 19:34:24,770 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 5704
2026-05-28 19:34:24,770 [lib.api.process] INFO: Monitor config for process 5704: C:\hsngo5k_\dll\5704.ini
2026-05-28 19:34:24,771 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:24,772 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:24,776 [root] DEBUG: Loader: Injecting process 5704 (thread 3916) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:24,777 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:34:24,777 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:24,778 [lib.api.process] INFO: Injected into 64-bit <Process 5704 msedge.exe>
2026-05-28 19:34:26,786 [lib.api.process] INFO: Successfully resumed process with pid 5704
2026-05-28 19:34:26,837 [root] DEBUG: 5704: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:34:26,838 [root] DEBUG: 5704: Disabling sleep skipping.
2026-05-28 19:34:26,838 [root] DEBUG: 5704: Interactive desktop enabled.
2026-05-28 19:34:26,839 [root] DEBUG: 5704: Dropped file limit defaulting to 100.
2026-05-28 19:34:26,847 [root] DEBUG: 5704: Edge-specific hook-set enabled.
2026-05-28 19:34:26,850 [root] DEBUG: 5704: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:34:26,861 [root] DEBUG: 5704: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:34:26,862 [root] DEBUG: 5704: Monitor initialised: 64-bit capemon loaded in process 5704 at 0x00007FFB863A0000, thread 3916, image base 0x00007FF66C3B0000, stack from 0x00000095AB5F4000-0x00000095AB600000
2026-05-28 19:34:26,862 [root] DEBUG: 5704: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-28 19:34:26,871 [root] DEBUG: 5704: Hooked 2 out of 2 functions
2026-05-28 19:34:27,026 [root] DEBUG: 5704: Syscall hook installed, syscall logging level 1
2026-05-28 19:34:27,031 [root] DEBUG: 5704: RestoreHeaders: Restored original import table.
2026-05-28 19:34:27,032 [root] INFO: Loaded monitor into process with pid 5704
2026-05-28 19:34:27,034 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:34:27,039 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB4F50000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 19:34:27,040 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:34:27,041 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4BF0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 19:34:27,042 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC3310000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:34:27,042 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:34:27,043 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4350000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:34:27,289 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB35A0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 19:34:27,290 [root] DEBUG: 5704: DLL loaded at 0x00007FFB71750000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:34:27,296 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB33A0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 19:34:27,300 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:34:27,306 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:34:27,307 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 4136: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:27,307 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 4136
2026-05-28 19:34:27,308 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:34:27,308 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 4136
2026-05-28 19:34:27,309 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB1AA0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 19:34:27,310 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:34:27,310 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:34:27,316 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC5120000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 19:34:27,318 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC3AC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 19:34:27,319 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4390000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 19:34:27,321 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4700000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 19:34:27,322 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:34:27,322 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAD7D0000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 19:34:27,324 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:34:27,325 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4AF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:34:27,325 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4C60000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:34:27,326 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC6800000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:34:27,326 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBCE20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:34:27,328 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAD720000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 19:34:27,329 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAD950000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 19:34:27,330 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:34:27,330 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4C20000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:34:27,332 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB3170000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 19:34:27,332 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:34:27,333 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4AF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 19:34:27,333 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC0F30000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 19:34:27,335 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC5160000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 19:34:27,345 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAD970000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 19:34:27,346 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC7690000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:34:27,347 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBA6F0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 19:34:27,348 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:34:27,349 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:34:27,351 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB7F30000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 19:34:27,353 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBE780000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:34:27,354 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB1750000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 19:34:27,356 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4FB0000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 19:34:27,357 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC45F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:34:27,357 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC09B0000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 19:34:27,358 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC58E0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:34:27,360 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB9B80000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 19:34:27,360 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC6CF0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:34:27,361 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBEFD0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 19:34:27,362 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 19:34:27,363 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBDC90000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:34:27,364 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4630000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 19:34:27,365 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB5D90000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:34:27,369 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC2820000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:34:27,370 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC1080000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:34:27,370 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC2140000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 19:34:27,371 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB9560000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 19:34:27,371 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB5CA0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 19:34:27,375 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBF7E0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:34:27,376 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB55B0000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:34:27,378 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB1AE0000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 19:34:27,383 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBF690000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 19:34:27,384 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB5200000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 19:34:27,389 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBFB00000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 19:34:27,390 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB9400000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 19:34:27,391 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB9660000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 19:34:27,393 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB9F00000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:34:27,393 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB5110000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 19:34:27,396 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC0EE0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 19:34:27,398 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBF590000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 19:34:27,398 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBF5B0000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 19:34:27,399 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4B90000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 19:34:27,432 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 19:34:27,440 [root] DEBUG: 5704: DLL loaded at 0x00007FFB6FDF0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 19:34:27,451 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB81B0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 19:34:27,454 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 8524: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:27,454 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB6910000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 19:34:27,455 [root] DEBUG: 5704: caller_dispatch: Added region at 0x00007FF66C3B0000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF66C4A7D66, thread 8224).
2026-05-28 19:34:27,455 [root] DEBUG: 5704: caller_dispatch: Added region at 0x00007FF66C3B0000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF66C4A7D66, thread 8224).
2026-05-28 19:34:27,456 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8524
2026-05-28 19:34:27,460 [root] DEBUG: 5704: ProcessImageBase: Main module image at 0x00007FF66C3B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:34:27,462 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 8560: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:27,462 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8560
2026-05-28 19:34:27,473 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8560
2026-05-28 19:34:27,475 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 8604: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:27,475 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC5030000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 19:34:27,479 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8604
2026-05-28 19:34:27,480 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB4F60000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 19:34:27,491 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8604
2026-05-28 19:34:27,511 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC0580000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:34:27,514 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAE420000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 19:34:27,564 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC3AF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 19:34:27,565 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC1C00000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 19:34:27,565 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC1E70000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 19:34:27,566 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB1D70000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 19:34:27,596 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAD7D0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 19:34:27,613 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC2D40000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 19:34:27,621 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB0FD0000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 19:34:27,621 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 8900: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:27,622 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 8908: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:27,622 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8900
2026-05-28 19:34:27,622 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8908
2026-05-28 19:34:27,623 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB6C40000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 19:34:27,623 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8900
2026-05-28 19:34:27,623 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8908
2026-05-28 19:34:27,730 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB2FE0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 19:34:27,737 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB6E10000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:34:27,745 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAD430000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 19:34:27,756 [root] DEBUG: 5704: DLL loaded at 0x00007FFBA7AE0000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 19:34:27,760 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4D80000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 19:34:27,763 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4AF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:34:27,765 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4230000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 19:34:27,814 [root] DEBUG: 5704: DLL loaded at 0x00007FFB6D120000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 19:34:28,997 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAD2F0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:34:29,317 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:34:29,322 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:34:29,328 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB0A40000: C:\Windows\system32\explorerframe (0x244000 bytes).
2026-05-28 19:34:29,350 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC6820000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 19:34:29,356 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 9208: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:29,359 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 8552: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:29,361 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC0660000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 19:34:29,362 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8552
2026-05-28 19:34:29,364 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9208
2026-05-28 19:34:29,367 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 8552
2026-05-28 19:34:29,369 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9208
2026-05-28 19:34:29,387 [root] DEBUG: 5704: DLL loaded at 0x00007FFB6CD30000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 19:34:29,406 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4F50000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 19:34:29,407 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBD900000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:34:29,408 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB0E60000: C:\Windows\System32\Windows.FileExplorer.Common (0x61000 bytes).
2026-05-28 19:34:29,413 [root] DEBUG: 5704: DLL loaded at 0x00007FFB6C6D0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 19:34:29,420 [root] DEBUG: 5704: DLL loaded at 0x00007FFB6F800000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 19:34:29,422 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC5930000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:34:29,423 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC3E50000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 19:34:29,424 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC3E10000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 19:34:29,426 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAD6F0000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 19:34:29,430 [root] DEBUG: 5704: DLL loaded at 0x00007FFB6C650000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 19:34:29,436 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC6DE0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 19:34:29,440 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 7488: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF64B540000
2026-05-28 19:34:29,441 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 7488
2026-05-28 19:34:29,442 [lib.api.process] INFO: Monitor config for process 7488: C:\hsngo5k_\dll\7488.ini
2026-05-28 19:34:29,446 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC2F30000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:34:29,447 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC0D70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:34:29,447 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 9228: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:29,449 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB08E0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:34:29,451 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:29,452 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9228
2026-05-28 19:34:29,453 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 9260: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:29,456 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9260
2026-05-28 19:34:29,457 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9228
2026-05-28 19:34:29,461 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9260
2026-05-28 19:34:29,482 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBFEB0000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 19:34:29,491 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB0100000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:34:29,498 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:34:29,498 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:34:29,944 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:34:29,944 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:34:29,948 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:29,953 [root] DEBUG: Loader: Injecting process 7488 (thread 2544) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:29,953 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:34:29,954 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:29,955 [lib.api.process] INFO: Injected into 64-bit <Process 7488 identity_helper.exe>
2026-05-28 19:34:29,964 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBCF40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:34:29,965 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBBA60000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 19:34:29,966 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 9452: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF64B540000
2026-05-28 19:34:29,968 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9452
2026-05-28 19:34:29,968 [lib.api.process] INFO: Monitor config for process 9452: C:\hsngo5k_\dll\9452.ini
2026-05-28 19:34:29,969 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:29,984 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBD0C0000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 19:34:29,992 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB3900000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:34:29,993 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBE410000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 19:34:30,015 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4C60000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:34:30,016 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4C20000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:34:30,017 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB3170000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 19:34:30,017 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBCFA0000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 19:34:30,018 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC6800000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:34:30,019 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBCE20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:34:30,020 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB23C0000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 19:34:30,028 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC4900000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 19:34:30,045 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:34:30,046 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:34:30,049 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:30,054 [root] DEBUG: Loader: Injecting process 9452 (thread 9456) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:30,054 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:34:30,055 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:30,056 [lib.api.process] INFO: Injected into 64-bit <Process 9452 identity_helper.exe>
2026-05-28 19:34:30,058 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9452
2026-05-28 19:34:30,058 [lib.api.process] INFO: Monitor config for process 9452: C:\hsngo5k_\dll\9452.ini
2026-05-28 19:34:30,058 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:30,126 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:34:30,126 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:34:30,128 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:30,132 [root] DEBUG: Loader: Injecting process 9452 (thread 9456) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:30,132 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:34:30,133 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:30,134 [lib.api.process] INFO: Injected into 64-bit <Process 9452 identity_helper.exe>
2026-05-28 19:34:30,144 [root] DEBUG: 9452: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:34:30,145 [root] DEBUG: 9452: Interactive desktop enabled.
2026-05-28 19:34:30,145 [root] DEBUG: 9452: Dropped file limit defaulting to 100.
2026-05-28 19:34:30,152 [root] DEBUG: 9452: Disabling sleep skipping.
2026-05-28 19:34:30,153 [root] DEBUG: 9452: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:34:30,164 [root] DEBUG: 9452: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:34:30,164 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FF64B540000, size 0x28b4d8
2026-05-28 19:34:30,181 [root] DEBUG: 9452: Monitor initialised: 64-bit capemon loaded in process 9452 at 0x00007FFB863A0000, thread 9456, image base 0x00007FF64B540000, stack from 0x000000445D724000-0x000000445D730000
2026-05-28 19:34:30,181 [root] DEBUG: 9452: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5816,i,7984218614831481947,5522388298470254199,524288 --field-trial-handle=2320,i,14929327369621157306,4202929281633177340,262144 --variations-seed-version --pseudonymization-salt-handle=2324,i,18132106635844096711,14831399794136510
2026-05-28 19:34:30,182 [root] DEBUG: 9452: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 19:34:30,194 [root] DEBUG: 9452: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:34:30,216 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:34:30,217 [root] DEBUG: 9452: set_hooks: Unable to hook LockResource
2026-05-28 19:34:30,223 [root] DEBUG: 9452: Hooked 627 out of 628 functions
2026-05-28 19:34:30,238 [root] DEBUG: 9452: Syscall hook installed, syscall logging level 1
2026-05-28 19:34:30,242 [root] DEBUG: 9452: RestoreHeaders: Restored original import table.
2026-05-28 19:34:30,243 [root] INFO: Loaded monitor into process with pid 9452
2026-05-28 19:34:30,244 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FFB84E10000, size 0x4b9994
2026-05-28 19:34:30,284 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FFB84E10000, size 0x4b9994
2026-05-28 19:34:30,308 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FFB84E10000, size 0x4b9994
2026-05-28 19:34:30,333 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FFB84E10000, size 0x4b9994
2026-05-28 19:34:30,357 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FFB84E10000, size 0x4b9994
2026-05-28 19:34:30,382 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FFB84E10000, size 0x4b9994
2026-05-28 19:34:30,406 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FFB84E10000, size 0x4b9994
2026-05-28 19:34:30,434 [root] DEBUG: 9452: caller_dispatch: Added region at 0x00007FFB84E10000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFB8500F156, thread 9456).
2026-05-28 19:34:30,435 [root] DEBUG: 9452: caller_dispatch: Scanning calling region at 0x00007FFB84E10000...
2026-05-28 19:34:30,439 [root] DEBUG: 9452: ProcessTrackedRegion: Region at 0x00007FFB84E10000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 19:34:30,441 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:34:30,465 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FF64B540000, size 0x28b4d8
2026-05-28 19:34:30,480 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FF64B540000, size 0x28b4d8
2026-05-28 19:34:30,496 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FF64B540000, size 0x28b4d8
2026-05-28 19:34:30,511 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FF64B540000, size 0x28b4d8
2026-05-28 19:34:30,526 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FF64B540000, size 0x28b4d8
2026-05-28 19:34:30,542 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FF64B540000, size 0x28b4d8
2026-05-28 19:34:30,559 [root] DEBUG: 9452: caller_dispatch: Added region at 0x00007FF64B540000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF64B634096, thread 9456).
2026-05-28 19:34:30,560 [root] DEBUG: 9452: YaraScan: Scanning 0x00007FF64B540000, size 0x28b4d8
2026-05-28 19:34:30,576 [root] DEBUG: 9452: ProcessImageBase: Main module image at 0x00007FF64B540000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:34:30,579 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:34:30,611 [root] DEBUG: 9452: DLL loaded at 0x000001BCEB000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:34:30,614 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:34:30,618 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC7690000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:34:30,652 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:34:30,657 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:34:30,713 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:34:30,717 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 19:34:30,718 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC2820000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:34:30,720 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB5020000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 19:34:30,802 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC1080000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:34:30,803 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC2F30000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:34:30,804 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC0D70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:34:30,804 [root] DEBUG: 9452: DLL loaded at 0x00007FFBBF7E0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:34:30,805 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB08E0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:34:30,923 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB6E10000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:34:30,932 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB3400000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 19:34:30,938 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC42C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:34:30,939 [root] DEBUG: 9452: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:34:30,957 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC0580000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:34:30,973 [root] DEBUG: 9452: DLL loaded at 0x00007FFBBE780000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:34:30,984 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB5D90000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:34:30,992 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC5930000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:34:30,993 [root] DEBUG: 9452: DLL loaded at 0x00007FFBBCF40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:34:31,014 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC4D80000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 19:34:31,040 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB3900000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:34:31,115 [root] DEBUG: 9452: DLL loaded at 0x00007FFB888B0000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 19:34:31,176 [lib.api.process] INFO: Monitor config for process 844: C:\hsngo5k_\dll\844.ini
2026-05-28 19:34:31,180 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:31,183 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:31,193 [root] DEBUG: Loader: Injecting process 844 with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:31,198 [root] DEBUG: 844: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:34:31,201 [root] DEBUG: 844: Disabling sleep skipping.
2026-05-28 19:34:31,204 [root] DEBUG: 844: Interactive desktop enabled.
2026-05-28 19:34:31,206 [root] DEBUG: 844: Dropped file limit defaulting to 100.
2026-05-28 19:34:31,232 [root] DEBUG: 844: Services hook set enabled
2026-05-28 19:34:31,234 [root] DEBUG: 844: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:34:31,246 [root] DEBUG: 844: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:34:31,247 [root] DEBUG: 844: Monitor initialised: 64-bit capemon loaded in process 844 at 0x00007FFB863A0000, thread 9968, image base 0x00007FF6A8E20000, stack from 0x00000092395F4000-0x0000009239600000
2026-05-28 19:34:31,247 [root] DEBUG: 844: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 19:34:31,261 [root] DEBUG: 844: Hooked 69 out of 69 functions
2026-05-28 19:34:31,262 [root] INFO: Loaded monitor into process with pid 844
2026-05-28 19:34:31,262 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:34:31,263 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:31,264 [lib.api.process] INFO: Injected into 64-bit <Process 844 svchost.exe>
2026-05-28 19:34:33,323 [root] DEBUG: 9452: DLL loaded at 0x00007FFBBAD00000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 19:34:33,327 [root] DEBUG: 9452: DLL loaded at 0x00007FFBBADC0000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 19:34:33,328 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB0CC0000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 19:34:33,329 [root] DEBUG: 9452: DLL loaded at 0x00007FFBAC310000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 19:34:33,339 [root] DEBUG: 9452: DLL loaded at 0x00007FFBBDCB0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 19:34:33,412 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC3AF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 19:34:33,414 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC1C00000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 19:34:33,439 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB7020000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 19:34:33,442 [root] DEBUG: 9452: DLL loaded at 0x00007FFBAC200000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:34:33,623 [root] DEBUG: 9452: DLL loaded at 0x00007FFBAD3E0000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 19:34:33,739 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC5120000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:34:33,742 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC4BF0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 19:34:33,743 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC3310000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:34:33,744 [root] DEBUG: 9452: DLL loaded at 0x00007FFBBB460000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 19:34:33,746 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB1090000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 19:34:34,024 [root] DEBUG: 9452: DLL loaded at 0x00007FFBAC570000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 19:34:34,072 [root] DEBUG: 9452: DLL loaded at 0x00007FFBB55B0000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:34:34,102 [root] DEBUG: 9452: DLL loaded at 0x00007FFBC58E0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:34:44,198 [root] INFO: Process with pid 9452 has terminated
2026-05-28 19:34:44,201 [root] DEBUG: 9452: NtTerminateProcess hook: Attempting to dump process 9452
2026-05-28 19:34:44,205 [root] DEBUG: 9452: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:34:50,749 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAC470000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 19:34:50,932 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 9560: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:50,933 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9560
2026-05-28 19:34:50,934 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9560
2026-05-28 19:34:56,647 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 7760: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:56,648 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 7760
2026-05-28 19:34:56,649 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 7760
2026-05-28 19:34:57,312 [root] DEBUG: 5704: DLL loaded at 0x00007FFBC0960000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 19:34:57,406 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 2224: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:34:57,407 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 2224
2026-05-28 19:34:57,407 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 2224
2026-05-28 19:34:58,400 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBA6C0000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 19:34:58,401 [root] DEBUG: 5704: DLL loaded at 0x00007FFBBA360000: C:\Windows\SYSTEM32\urlmon (0x1ed000 bytes).
2026-05-28 19:34:58,404 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB3880000: C:\Windows\SYSTEM32\FLTLIB (0xb000 bytes).
2026-05-28 19:34:58,405 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB6ED0000: C:\Windows\SYSTEM32\virtdisk (0x13000 bytes).
2026-05-28 19:34:58,406 [root] DEBUG: 5704: DLL loaded at 0x00007FFBB6CF0000: C:\Windows\System32\smartscreenps (0x52000 bytes).
2026-05-28 19:34:58,407 [root] DEBUG: 5704: DLL loaded at 0x00007FFBAA3E0000: C:\Windows\SYSTEM32\shdocvw (0x41000 bytes).
2026-05-28 19:34:58,739 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4B60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 19:34:58,753 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7561000, size: 0x1000.
2026-05-28 19:34:58,756 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7551000, size: 0x1000.
2026-05-28 19:34:58,756 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7541000, size: 0x1000.
2026-05-28 19:34:58,757 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7531000, size: 0x1000.
2026-05-28 19:34:58,764 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7521000, size: 0x1000.
2026-05-28 19:34:58,770 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBD8B0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 19:34:58,783 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 4404: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF630AD0000
2026-05-28 19:34:58,784 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 4404
2026-05-28 19:34:58,784 [lib.api.process] INFO: Monitor config for process 4404: C:\hsngo5k_\dll\4404.ini
2026-05-28 19:34:58,785 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:58,786 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:58,790 [root] DEBUG: Loader: Injecting process 4404 (thread 4268) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:58,791 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:34:58,791 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:58,793 [lib.api.process] INFO: Injected into 64-bit <Process 4404 CHXSmartScreen.exe>
2026-05-28 19:34:58,794 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 4404
2026-05-28 19:34:58,794 [lib.api.process] INFO: Monitor config for process 4404: C:\hsngo5k_\dll\4404.ini
2026-05-28 19:34:58,794 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:58,795 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:58,801 [root] DEBUG: Loader: Injecting process 4404 (thread 4268) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:58,801 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:34:58,802 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:58,803 [lib.api.process] INFO: Injected into 64-bit <Process 4404 CHXSmartScreen.exe>
2026-05-28 19:34:58,805 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 4404
2026-05-28 19:34:58,805 [lib.api.process] INFO: Monitor config for process 4404: C:\hsngo5k_\dll\4404.ini
2026-05-28 19:34:58,805 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:34:58,806 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:34:58,811 [root] DEBUG: Loader: Injecting process 4404 with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:58,812 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 4268, handle 0x120
2026-05-28 19:34:58,813 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:34:58,813 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:34:58,815 [lib.api.process] INFO: Injected into 64-bit <Process 4404 CHXSmartScreen.exe>
2026-05-28 19:35:00,458 [root] DEBUG: 5704: CreateProcessHandler: Injection info set for new process 9420: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:35:00,459 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9420
2026-05-28 19:35:00,460 [root] DEBUG: 5704: ProcessMessage: Skipping monitoring process 9420
2026-05-28 19:35:00,575 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 19:35:00,578 [lib.api.process] INFO: Monitor config for process 632: C:\hsngo5k_\dll\632.ini
2026-05-28 19:35:00,587 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:35:00,588 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:35:00,602 [root] DEBUG: Loader: Injecting process 632 with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:00,614 [root] DEBUG: Loader: Copied config file C:\hsngo5k_\dll\632.ini to system path C:\632.ini
2026-05-28 19:35:00,618 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 632 C:\hsngo5k_\dll\gIlsNlf.dll
2026-05-28 19:35:00,621 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:00,625 [lib.api.process] INFO: Injected into 64-bit <Process 632 services.exe>
2026-05-28 19:35:01,140 [root] INFO: Process with pid 5704 appears to have terminated
2026-05-28 19:35:04,215 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAF610000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:35:04,286 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAA9A0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:35:04,293 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6D450000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:35:04,310 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6D060000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:35:04,531 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 8996: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF69BCF0000
2026-05-28 19:35:04,532 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8996
2026-05-28 19:35:04,533 [lib.api.process] INFO: Monitor config for process 8996: C:\hsngo5k_\dll\8996.ini
2026-05-28 19:35:04,534 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:35:04,539 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:35:04,544 [root] DEBUG: Loader: Injecting process 8996 (thread 9004) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:04,545 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:35:04,546 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:04,550 [lib.api.process] INFO: Injected into 64-bit <Process 8996 dllhost.exe>
2026-05-28 19:35:04,554 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8996
2026-05-28 19:35:04,554 [lib.api.process] INFO: Monitor config for process 8996: C:\hsngo5k_\dll\8996.ini
2026-05-28 19:35:04,555 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:35:04,558 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:35:04,562 [root] DEBUG: Loader: Injecting process 8996 (thread 9004) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:04,563 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:35:04,564 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:04,565 [lib.api.process] INFO: Injected into 64-bit <Process 8996 dllhost.exe>
2026-05-28 19:35:04,589 [root] DEBUG: 8996: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:35:04,590 [root] DEBUG: 8996: Interactive desktop enabled.
2026-05-28 19:35:04,590 [root] DEBUG: 8996: Dropped file limit defaulting to 100.
2026-05-28 19:35:04,596 [root] DEBUG: 8996: Disabling sleep skipping.
2026-05-28 19:35:04,598 [root] DEBUG: 8996: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:35:04,611 [root] DEBUG: 8996: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:35:04,612 [root] DEBUG: 8996: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:35:04,614 [root] DEBUG: 8996: Monitor initialised: 64-bit capemon loaded in process 8996 at 0x00007FFB863A0000, thread 9004, image base 0x00007FF69BCF0000, stack from 0x000000790B0F4000-0x000000790B100000
2026-05-28 19:35:04,618 [root] DEBUG: 8996: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:35:04,630 [root] DEBUG: 8996: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:35:04,652 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:35:04,653 [root] DEBUG: 8996: set_hooks: Unable to hook LockResource
2026-05-28 19:35:04,658 [root] DEBUG: 8996: Hooked 627 out of 628 functions
2026-05-28 19:35:04,659 [root] DEBUG: 8996: Syscall hook installed, syscall logging level 1
2026-05-28 19:35:04,666 [root] DEBUG: 8996: RestoreHeaders: Restored original import table.
2026-05-28 19:35:04,667 [root] INFO: Loaded monitor into process with pid 8996
2026-05-28 19:35:04,668 [root] DEBUG: 8996: caller_dispatch: Added region at 0x00007FF69BCF0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF69BCF12F2, thread 9004).
2026-05-28 19:35:04,668 [root] DEBUG: 8996: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:35:04,669 [root] DEBUG: 8996: ProcessImageBase: Main module image at 0x00007FF69BCF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:35:04,672 [root] DEBUG: 8996: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:35:04,675 [root] DEBUG: 8996: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:35:04,677 [root] DEBUG: 8996: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:35:04,691 [root] DEBUG: 8996: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:35:04,706 [root] DEBUG: 8996: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:35:04,706 [root] DEBUG: 8996: DLL loaded at 0x00007FFBB0100000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:35:04,712 [root] DEBUG: 8996: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:35:07,182 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4BE0000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 19:35:07,205 [root] DEBUG: 4692: DLL loaded at 0x00007FFBC0930000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 19:35:07,228 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4AC0000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 19:35:07,237 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBD8A0000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 19:35:07,237 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4500000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 19:35:07,260 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6CFF0000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 19:35:07,274 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB2520000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 19:35:09,300 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7560000.
2026-05-28 19:35:09,301 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7550000.
2026-05-28 19:35:09,302 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7540000.
2026-05-28 19:35:09,303 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7530000.
2026-05-28 19:35:09,325 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 8836: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF630AD0000
2026-05-28 19:35:09,326 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 8836
2026-05-28 19:35:09,326 [lib.api.process] INFO: Monitor config for process 8836: C:\hsngo5k_\dll\8836.ini
2026-05-28 19:35:09,329 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:35:09,332 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:35:09,337 [root] DEBUG: Loader: Injecting process 8836 (thread 10052) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:09,337 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:35:09,338 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:09,340 [lib.api.process] INFO: Injected into 64-bit <Process 8836 CHXSmartScreen.exe>
2026-05-28 19:35:09,341 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 8836
2026-05-28 19:35:09,342 [lib.api.process] INFO: Monitor config for process 8836: C:\hsngo5k_\dll\8836.ini
2026-05-28 19:35:09,342 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:35:09,344 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:35:09,348 [root] DEBUG: Loader: Injecting process 8836 (thread 10052) with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:09,349 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:35:09,350 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:09,351 [lib.api.process] INFO: Injected into 64-bit <Process 8836 CHXSmartScreen.exe>
2026-05-28 19:35:09,352 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 8836
2026-05-28 19:35:09,354 [lib.api.process] INFO: Monitor config for process 8836: C:\hsngo5k_\dll\8836.ini
2026-05-28 19:35:09,354 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:35:09,356 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\gIlsNlf.dll, loader C:\hsngo5k_\bin\vouhCgRr.exe
2026-05-28 19:35:09,362 [root] DEBUG: Loader: Injecting process 8836 with C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:09,363 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10052, handle 0x120
2026-05-28 19:35:09,363 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:35:09,364 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\gIlsNlf.dll.
2026-05-28 19:35:09,365 [lib.api.process] INFO: Injected into 64-bit <Process 8836 CHXSmartScreen.exe>
2026-05-28 19:35:12,406 [root] INFO: Process with pid 8996 has terminated
2026-05-28 19:35:12,407 [root] DEBUG: 8996: NtTerminateProcess hook: Attempting to dump process 8996
2026-05-28 19:35:12,408 [root] DEBUG: 8996: DoProcessDump: Skipping process dump as code is identical on disk.
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 19:34:07 | 2026-05-28 19:35:32 | none |
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 23.202.166.56 [VT] | unknown | - |
| Y | 162.159.137.232 [VT] | unknown | - |
| N | 162.159.130.235 [VT] | unknown | - |
| Y | 199.232.83.82 [VT] | unknown | - |
| Y | 150.171.109.17 [VT] | unknown | - |
| Y | 199.232.210.172 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| Y | 40.115.75.193 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 23.216.106.59 [VT] | unknown | - |
| N | 162.159.128.235 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| Y | 149.135.84.155 [VT] | unknown | - |
| Y | 162.159.134.233 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| Y | 172.172.255.216 [VT] | unknown | - |
| Y | 162.254.194.57 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Y | 162.159.133.233 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| latency.discord.media [VT] |
A 162.159.128.235
[VT]
A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.130.235 [VT] A 162.159.129.235 [VT] |
162.159.129.235 [VT] |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.8.8 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| gateway-us-east1-d.discord.gg [VT] |
A 162.159.133.234
[VT]
A 162.159.134.234 [VT] A 162.159.130.234 [VT] A 162.159.135.234 [VT] A 162.159.136.234 [VT] |
162.159.130.234 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.