| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 19:37:06 | 2026-05-28 19:40:52 | 226s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 19:33:25,405 [root] INFO: Date set to: 20260528T19:37:13, timeout set to: 200
2026-05-28 19:37:13,007 [root] DEBUG: Starting analyzer from: C:\hsngo5k_
2026-05-28 19:37:13,008 [root] DEBUG: Storing results at: C:\uLNdYAvqyx
2026-05-28 19:37:13,008 [root] DEBUG: Pipe server name: \\.\PIPE\FOePnOP
2026-05-28 19:37:13,008 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 19:37:13,008 [root] INFO: analysis running as an admin
2026-05-28 19:37:13,008 [root] INFO: analysis package specified: "edge"
2026-05-28 19:37:13,008 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 19:37:13,010 [root] DEBUG: imported analysis package "edge"
2026-05-28 19:37:13,010 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 19:37:13,010 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-28 19:37:13,010 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 19:37:13,011 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 19:37:13,011 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 19:37:13,011 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 19:37:13,026 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 19:37:13,045 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 19:37:13,052 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 19:37:13,058 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 19:37:13,060 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 19:37:13,060 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 19:37:13,061 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 19:37:13,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 19:37:13,063 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 19:37:13,063 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 19:37:13,063 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 19:37:13,063 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 19:37:13,064 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 19:37:13,064 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 19:37:13,064 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 19:37:13,064 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 19:37:13,065 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 19:37:13,065 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 19:37:13,065 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 19:37:13,065 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 19:37:13,065 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 19:37:13,065 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 19:37:13,065 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 19:37:13,068 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 588)
2026-05-28 19:37:13,068 [modules.auxiliary.disguise] INFO: Disguising GUID to 4749da65-5d40-46bc-8ec9-2485aadd23d2
2026-05-28 19:37:13,068 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 19:37:13,068 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 19:37:13,068 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 19:37:13,071 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 19:37:13,071 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 19:37:13,072 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 19:37:13,073 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 19:37:13,073 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 19:37:13,074 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 19:37:13,074 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 19:37:13,074 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 19:37:13,074 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 19:37:13,075 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 19:37:13,075 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 19:37:13,075 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 19:37:13,076 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 19:37:13,077 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 19:37:13,077 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 19:37:13,078 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 19:37:13,100 [lib.api.process] INFO: Monitor config for process 4692: C:\hsngo5k_\dll\4692.ini
2026-05-28 19:37:13,102 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:13,104 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:13,204 [root] DEBUG: Loader: Injecting process 4692 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:13,374 [root] DEBUG: 4692: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:37:13,375 [root] DEBUG: 4692: Disabling sleep skipping.
2026-05-28 19:37:13,376 [root] DEBUG: 4692: Interactive desktop enabled.
2026-05-28 19:37:13,377 [root] DEBUG: 4692: Dropped file limit defaulting to 100.
2026-05-28 19:37:13,377 [root] DEBUG: 4692: Interactive desktop - injecting Explorer Shell
2026-05-28 19:37:13,383 [root] DEBUG: 4692: YaraInit: Compiled 44 rule files
2026-05-28 19:37:13,385 [root] DEBUG: 4692: YaraInit: Compiled rules saved to file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:37:13,436 [root] DEBUG: 4692: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:37:13,437 [root] DEBUG: 4692: YaraScan: Scanning 0x00007FF627610000, size 0x545316
2026-05-28 19:37:13,499 [root] DEBUG: 4692: Monitor initialised: 64-bit capemon loaded in process 4692 at 0x00007FFB86300000, thread 1032, image base 0x00007FF627610000, stack from 0x0000000010B51000-0x0000000010B60000
2026-05-28 19:37:13,500 [root] DEBUG: 4692: Commandline: C:\Windows\Explorer.EXE
2026-05-28 19:37:13,510 [root] DEBUG: 4692: Hooked 69 out of 69 functions
2026-05-28 19:37:13,544 [root] DEBUG: 4692: Syscall hook installed, syscall logging level 1
2026-05-28 19:37:13,559 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:37:13,560 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:13,563 [lib.api.process] INFO: Injected into 64-bit <Process 4692 explorer.exe>
2026-05-28 19:37:18,543 [root] DEBUG: 4692: caller_dispatch: Added region at 0x00007FF627610000 to tracked regions list (kernel32::CreateRemoteThreadEx returns to 0x00007FF627844E81, thread 4864).
2026-05-28 19:37:18,547 [root] DEBUG: 4692: YaraScan: Scanning 0x00007FF627610000, size 0x545316
2026-05-28 19:37:18,586 [root] DEBUG: 4692: ProcessImageBase: Main module image at 0x00007FF627610000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:37:18,597 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA640000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:37:18,641 [lib.api.process] INFO: Monitor config for process 4692: C:\hsngo5k_\dll\4692.ini
2026-05-28 19:37:18,642 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:18,644 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:18,650 [root] DEBUG: Loader: Injecting process 4692 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:18,652 [root] DEBUG: 4692: caller_dispatch: Added region at 0x00000000079E0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00000000079E0044, thread 692).
2026-05-28 19:37:18,653 [root] DEBUG: 4692: DumpPEsInRange: Scanning range 0x00000000079E0000 - 0x00000000079E0135.
2026-05-28 19:37:18,654 [root] DEBUG: 4692: ScanForDisguisedPE: Size too small: 0x135 bytes
2026-05-28 19:37:18,658 [lib.common.results] INFO: Uploading file C:\uLNdYAvqyx\CAPE\4692_2681418372328452026 to CAPE\130ad660c5666e53cb9b7826ef92b6e55015e00ad80880676bd86498cb47b8aa; Size is 309; Max size: 100000000
2026-05-28 19:37:18,660 [root] DEBUG: 4692: DumpMemory: Payload successfully created: C:\uLNdYAvqyx\CAPE\4692_2681418372328452026 (size 309 bytes)
2026-05-28 19:37:18,661 [root] DEBUG: 4692: DumpRegion: Dumped entire allocation from 0x00000000079E0000, size 4096 bytes.
2026-05-28 19:37:18,661 [root] DEBUG: 4692: ProcessTrackedRegion: Dumped region at 0x00000000079E0000.
2026-05-28 19:37:18,662 [root] DEBUG: 4692: YaraScan: Scanning 0x00000000079E0000, size 0x135
2026-05-28 19:37:18,663 [root] DEBUG: 4692: Monitor config - unrecognised key host-ip.
2026-05-28 19:37:18,668 [root] DEBUG: 4692: Monitor config - unrecognised key host-port.
2026-05-28 19:37:18,669 [root] DEBUG: 4692: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:37:18,669 [root] DEBUG: 4692: Dropped file limit defaulting to 100.
2026-05-28 19:37:18,688 [root] DEBUG: 4692: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:37:18,737 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:37:18,739 [root] DEBUG: 4692: set_hooks: Unable to hook LockResource
2026-05-28 19:37:18,764 [root] DEBUG: 4692: Hooked 627 out of 628 functions
2026-05-28 19:37:18,795 [root] INFO: Loaded monitor into process with pid 4692
2026-05-28 19:37:18,801 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 19:37:18,802 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:19,560 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB5020000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 19:37:19,562 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB5020000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 19:37:19,583 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA660000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:37:19,584 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA660000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:37:19,603 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA660000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:37:19,604 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA660000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:37:19,618 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA660000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:37:19,619 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBA660000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 19:37:20,715 [root] INFO: Restarting WMI Service
2026-05-28 19:37:20,890 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAA9A0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:37:20,891 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAA9A0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:37:20,907 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9DD0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:37:20,908 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9DD0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:37:20,938 [root] DEBUG: 4692: DLL loaded at 0x00000000158A0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 19:37:20,939 [root] DEBUG: 4692: DLL loaded at 0x00000000158A0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 19:37:20,940 [root] DEBUG: 4692: DLL loaded at 0x00007FFB85F10000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:37:20,940 [root] DEBUG: 4692: DLL loaded at 0x00007FFB85F10000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:37:21,001 [lib.api.process] INFO: Monitor config for process 844: C:\hsngo5k_\dll\844.ini
2026-05-28 19:37:21,002 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:21,004 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:21,009 [root] DEBUG: Loader: Injecting process 844 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:21,012 [root] DEBUG: 844: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:37:21,013 [root] DEBUG: 844: Disabling sleep skipping.
2026-05-28 19:37:21,014 [root] DEBUG: 844: Interactive desktop enabled.
2026-05-28 19:37:21,014 [root] DEBUG: 844: Dropped file limit defaulting to 100.
2026-05-28 19:37:21,015 [root] DEBUG: 844: Services hook set enabled
2026-05-28 19:37:21,018 [root] DEBUG: 844: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:37:21,030 [root] DEBUG: 844: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:37:21,031 [root] DEBUG: 844: Monitor initialised: 64-bit capemon loaded in process 844 at 0x00007FFB86300000, thread 8176, image base 0x00007FF6A8E20000, stack from 0x0000009239574000-0x0000009239580000
2026-05-28 19:37:21,031 [root] DEBUG: 844: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 19:37:21,042 [root] DEBUG: 844: Hooked 69 out of 69 functions
2026-05-28 19:37:21,043 [root] INFO: Loaded monitor into process with pid 844
2026-05-28 19:37:21,043 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:37:21,044 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:21,045 [lib.api.process] INFO: Injected into 64-bit <Process 844 svchost.exe>
2026-05-28 19:37:22,755 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 19:37:22,757 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 19:37:22,761 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 19:37:22,769 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 5568
2026-05-28 19:37:22,770 [lib.api.process] INFO: Monitor config for process 5568: C:\hsngo5k_\dll\5568.ini
2026-05-28 19:37:22,776 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:22,779 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:22,787 [root] DEBUG: Loader: Injecting process 5568 (thread 696) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:22,787 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:37:22,788 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:22,789 [lib.api.process] INFO: Injected into 64-bit <Process 5568 msedge.exe>
2026-05-28 19:37:23,474 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 3704: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF69BCF0000
2026-05-28 19:37:23,475 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3704
2026-05-28 19:37:23,475 [lib.api.process] INFO: Monitor config for process 3704: C:\hsngo5k_\dll\3704.ini
2026-05-28 19:37:23,476 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:23,477 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:23,483 [root] DEBUG: Loader: Injecting process 3704 (thread 8196) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:23,485 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:37:23,486 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:23,487 [lib.api.process] INFO: Injected into 64-bit <Process 3704 dllhost.exe>
2026-05-28 19:37:23,488 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3704
2026-05-28 19:37:23,489 [lib.api.process] INFO: Monitor config for process 3704: C:\hsngo5k_\dll\3704.ini
2026-05-28 19:37:23,490 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:23,491 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:23,498 [root] DEBUG: Loader: Injecting process 3704 (thread 8196) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:23,499 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:37:23,499 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:23,501 [lib.api.process] INFO: Injected into 64-bit <Process 3704 dllhost.exe>
2026-05-28 19:37:23,506 [root] DEBUG: 3704: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:37:23,507 [root] DEBUG: 3704: Interactive desktop enabled.
2026-05-28 19:37:23,508 [root] DEBUG: 3704: Dropped file limit defaulting to 100.
2026-05-28 19:37:23,510 [root] DEBUG: 3704: Disabling sleep skipping.
2026-05-28 19:37:23,511 [root] DEBUG: 3704: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:37:23,527 [root] DEBUG: 3704: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:37:23,529 [root] DEBUG: 3704: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:37:23,530 [root] DEBUG: 3704: Monitor initialised: 64-bit capemon loaded in process 3704 at 0x00007FFB86300000, thread 8196, image base 0x00007FF69BCF0000, stack from 0x0000002635D24000-0x0000002635D30000
2026-05-28 19:37:23,531 [root] DEBUG: 3704: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:37:23,541 [root] DEBUG: 3704: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:37:23,566 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:37:23,567 [root] DEBUG: 3704: set_hooks: Unable to hook LockResource
2026-05-28 19:37:23,572 [root] DEBUG: 3704: Hooked 627 out of 628 functions
2026-05-28 19:37:23,574 [root] DEBUG: 3704: Syscall hook installed, syscall logging level 1
2026-05-28 19:37:23,579 [root] DEBUG: 3704: RestoreHeaders: Restored original import table.
2026-05-28 19:37:23,580 [root] INFO: Loaded monitor into process with pid 3704
2026-05-28 19:37:23,584 [root] DEBUG: 3704: caller_dispatch: Added region at 0x00007FF69BCF0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF69BCF12F2, thread 8196).
2026-05-28 19:37:23,585 [root] DEBUG: 3704: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:37:23,587 [root] DEBUG: 3704: ProcessImageBase: Main module image at 0x00007FF69BCF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:37:23,589 [root] DEBUG: 3704: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:37:23,591 [root] DEBUG: 3704: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:37:23,593 [root] DEBUG: 3704: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:37:23,606 [root] DEBUG: 3704: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:37:23,620 [root] DEBUG: 3704: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:37:23,621 [root] DEBUG: 3704: DLL loaded at 0x00007FFBB0100000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:37:23,626 [root] DEBUG: 3704: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:37:23,651 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:37:23,653 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 6852, handle 0x2b08: Error obtaining target process name
2026-05-28 19:37:23,654 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:37:23,656 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 6136, handle 0x2b38: Error obtaining target process name
2026-05-28 19:37:23,658 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:37:23,659 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 5648, handle 0x2ad4: Error obtaining target process name
2026-05-28 19:37:23,660 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:37:23,662 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 5404, handle 0x2ae8: Error obtaining target process name
2026-05-28 19:37:23,663 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:37:23,665 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 7012, handle 0x2b04: Error obtaining target process name
2026-05-28 19:37:24,803 [lib.api.process] INFO: Successfully resumed process with pid 5568
2026-05-28 19:37:24,915 [root] DEBUG: 5568: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:37:24,916 [root] DEBUG: 5568: Interactive desktop enabled.
2026-05-28 19:37:24,916 [root] DEBUG: 5568: Dropped file limit defaulting to 100.
2026-05-28 19:37:24,926 [root] DEBUG: 5568: Edge-specific hook-set enabled.
2026-05-28 19:37:24,928 [root] DEBUG: 5568: Disabling sleep skipping.
2026-05-28 19:37:24,930 [root] DEBUG: 5568: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:37:24,941 [root] DEBUG: 5568: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:37:24,941 [root] DEBUG: 5568: Monitor initialised: 64-bit capemon loaded in process 5568 at 0x00007FFB86300000, thread 696, image base 0x00007FF66C3B0000, stack from 0x00000053217F4000-0x0000005321800000
2026-05-28 19:37:24,942 [root] DEBUG: 5568: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-28 19:37:24,951 [root] DEBUG: 5568: Hooked 2 out of 2 functions
2026-05-28 19:37:24,994 [root] DEBUG: 5568: Syscall hook installed, syscall logging level 1
2026-05-28 19:37:24,998 [root] DEBUG: 5568: RestoreHeaders: Restored original import table.
2026-05-28 19:37:24,999 [root] INFO: Loaded monitor into process with pid 5568
2026-05-28 19:37:25,002 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:37:25,008 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB4F50000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 19:37:25,009 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:37:25,010 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4BF0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 19:37:25,011 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC3310000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:37:25,012 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:37:25,013 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4350000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:37:25,270 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB35A0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 19:37:25,271 [root] DEBUG: 5568: DLL loaded at 0x000001FF91000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:37:25,275 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB33A0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 19:37:25,278 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:37:25,284 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 9612: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:25,284 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:37:25,285 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 9612
2026-05-28 19:37:25,286 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 9612
2026-05-28 19:37:25,286 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:37:25,288 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9DB0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 19:37:25,290 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:37:25,290 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:37:25,295 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC5120000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 19:37:25,296 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC3AC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 19:37:25,297 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 9612, handle 0x2b38: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 19:37:25,297 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4390000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 19:37:25,298 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4700000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 19:37:25,299 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:37:25,299 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB4560000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 19:37:25,301 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:37:25,301 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4AF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:37:25,302 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4C60000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:37:25,302 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC6800000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:37:25,304 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBCE20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:37:25,304 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB2660000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 19:37:25,305 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9D70000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 19:37:25,305 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:37:25,306 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4C20000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:37:25,309 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB3170000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 19:37:25,310 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:37:25,310 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4AF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 19:37:25,310 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC0F30000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 19:37:25,312 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC5160000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 19:37:25,321 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9D90000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 19:37:25,322 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC7690000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:37:25,323 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBA6F0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 19:37:25,323 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 5568, handle 0x2ad0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 19:37:25,324 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:37:25,325 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:37:25,327 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB7F30000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 19:37:25,331 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB1750000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 19:37:25,331 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBE780000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:37:25,332 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4FB0000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 19:37:25,333 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC45F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:37:25,335 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC09B0000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 19:37:25,336 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC6CF0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:37:25,337 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC58E0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:37:25,338 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBEFD0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 19:37:25,338 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9B80000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 19:37:25,339 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBDC90000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:37:25,340 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4630000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 19:37:25,341 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 19:37:25,343 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB5D90000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:37:25,345 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC2820000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:37:25,346 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC1080000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:37:25,346 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC2140000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 19:37:25,346 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9560000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 19:37:25,349 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB5CA0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 19:37:25,350 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBF7E0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:37:25,352 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB1AE0000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 19:37:25,353 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB55B0000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:37:25,355 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBF690000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 19:37:25,358 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB5200000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 19:37:25,360 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBFB00000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 19:37:25,361 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9400000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 19:37:25,361 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9660000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 19:37:25,363 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9F00000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:37:25,364 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB5110000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 19:37:25,365 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC0EE0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 19:37:25,391 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4B90000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 19:37:25,399 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 19:37:25,403 [lib.api.process] INFO: Monitor config for process 632: C:\hsngo5k_\dll\632.ini
2026-05-28 19:37:25,405 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:25,405 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:25,412 [root] DEBUG: Loader: Injecting process 632 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:25,416 [root] DEBUG: 5568: DLL loaded at 0x00007FFB71DC0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 19:37:25,416 [root] DEBUG: Loader: Copied config file C:\hsngo5k_\dll\632.ini to system path C:\632.ini
2026-05-28 19:37:25,419 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 632 C:\hsngo5k_\dll\LjVHGInK.dll
2026-05-28 19:37:25,420 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:25,422 [lib.api.process] INFO: Injected into 64-bit <Process 632 services.exe>
2026-05-28 19:37:25,424 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 19:37:25,426 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBF590000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 19:37:25,427 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBF5B0000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 19:37:25,431 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB81B0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 19:37:25,432 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB6910000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 19:37:25,440 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 10220: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:25,441 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 10220
2026-05-28 19:37:25,442 [root] DEBUG: 5568: caller_dispatch: Added region at 0x00007FF66C3B0000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF66C4A7D66, thread 9804).
2026-05-28 19:37:25,442 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 10220
2026-05-28 19:37:25,447 [root] DEBUG: 5568: ProcessImageBase: Main module image at 0x00007FF66C3B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:37:25,458 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 4920: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:25,462 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 6976: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:25,464 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB4F60000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 19:37:25,466 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 4920
2026-05-28 19:37:25,467 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 6976
2026-05-28 19:37:25,469 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 4920
2026-05-28 19:37:25,469 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 6976
2026-05-28 19:37:25,561 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC3AF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 19:37:25,562 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC1C00000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 19:37:25,562 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC1E70000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 19:37:25,563 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB1D70000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 19:37:25,601 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB9D20000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 19:37:25,633 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB0FD0000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 19:37:25,635 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 10512: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:25,636 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 10540: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:25,637 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 10540: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:25,637 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB6C40000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 19:37:25,638 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 10512
2026-05-28 19:37:25,639 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 10540
2026-05-28 19:37:25,642 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 10540
2026-05-28 19:37:25,735 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC2D40000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 19:37:25,744 [root] DEBUG: 4692: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 19:37:25,791 [root] DEBUG: 5568: DLL loaded at 0x00007FFBADAA0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 19:37:25,801 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4D80000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 19:37:25,813 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4AF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:37:25,817 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4230000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 19:37:25,842 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB2FE0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 19:37:25,852 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB6E10000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:37:25,855 [root] DEBUG: 5568: DLL loaded at 0x00007FFBA7AE0000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 19:37:25,898 [root] DEBUG: 5568: DLL loaded at 0x00007FFBADA10000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 19:37:27,297 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:37:27,302 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:37:27,801 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4BE0000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 19:37:27,802 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4BE0000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 19:37:27,805 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9D80000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 19:37:27,806 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9D80000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 19:37:27,828 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9CD0000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 19:37:27,828 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9CD0000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 19:37:27,837 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9D70000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 19:37:27,839 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB9D70000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 19:37:27,840 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4AC0000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 19:37:27,841 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4AC0000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 19:37:27,920 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB31E0000: C:\Windows\System32\dlnashext (0x56000 bytes).
2026-05-28 19:37:27,921 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB31E0000: C:\Windows\System32\dlnashext (0x56000 bytes).
2026-05-28 19:37:27,927 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAD9A0000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 19:37:27,927 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAD9A0000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 19:37:27,935 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAD6F0000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-05-28 19:37:27,936 [root] DEBUG: 4692: DLL loaded at 0x00007FFBAD6F0000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-05-28 19:37:27,947 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4510000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 19:37:27,950 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4510000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 19:37:28,521 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC5030000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 19:37:28,531 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC0580000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:37:28,535 [root] DEBUG: 5568: DLL loaded at 0x00007FFBAE420000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 19:37:29,779 [root] DEBUG: 5568: DLL loaded at 0x00007FFBAD2F0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:37:29,878 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB0A40000: C:\Windows\system32\explorerframe (0x244000 bytes).
2026-05-28 19:37:29,881 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC0660000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 19:37:29,882 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 12084: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:29,883 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 12084
2026-05-28 19:37:29,885 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC6820000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 19:37:29,886 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 12084
2026-05-28 19:37:29,886 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 12108: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:29,887 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 12108
2026-05-28 19:37:29,887 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBD900000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:37:29,888 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 12108
2026-05-28 19:37:29,914 [root] DEBUG: 5568: DLL loaded at 0x00007FFB6DB80000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 19:37:29,939 [root] DEBUG: 5568: DLL loaded at 0x00007FFB6D520000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 19:37:29,943 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4F50000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 19:37:29,944 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC3E50000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 19:37:29,945 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC3E10000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 19:37:29,946 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB0E60000: C:\Windows\System32\Windows.FileExplorer.Common (0x61000 bytes).
2026-05-28 19:37:29,946 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC5930000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:37:29,947 [root] DEBUG: 5568: DLL loaded at 0x00007FFB705C0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 19:37:29,949 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB44F0000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 19:37:29,950 [root] DEBUG: 5568: DLL loaded at 0x00007FFBAD7C0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 19:37:29,956 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 12240: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7C1040000
2026-05-28 19:37:29,956 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC2F30000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:37:29,957 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12240
2026-05-28 19:37:29,957 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC0D70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:37:29,957 [lib.api.process] INFO: Monitor config for process 12240: C:\hsngo5k_\dll\12240.ini
2026-05-28 19:37:29,958 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB08E0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:37:29,958 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:29,962 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC6DE0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 19:37:29,977 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 8112: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:29,978 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 12028: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:29,979 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 8112
2026-05-28 19:37:29,980 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 12028
2026-05-28 19:37:29,980 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 8112
2026-05-28 19:37:29,981 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 12028
2026-05-28 19:37:30,000 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBFEB0000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 19:37:30,008 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB0100000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:37:30,018 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC42C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:37:30,020 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:37:30,366 [root] DEBUG: 4692: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 19:37:30,498 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:37:30,498 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:37:30,501 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:30,505 [root] DEBUG: Loader: Injecting process 12240 (thread 12244) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:30,506 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:37:30,506 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:30,508 [lib.api.process] INFO: Injected into 64-bit <Process 12240 identity_helper.exe>
2026-05-28 19:37:30,508 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB3900000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:37:30,509 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBD0C0000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 19:37:30,510 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBE410000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 19:37:30,514 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBCF40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:37:30,520 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBBA60000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 19:37:30,522 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 12620: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7C1040000
2026-05-28 19:37:30,523 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12620
2026-05-28 19:37:30,523 [lib.api.process] INFO: Monitor config for process 12620: C:\hsngo5k_\dll\12620.ini
2026-05-28 19:37:30,524 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:30,548 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4C60000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:37:30,548 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4C20000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:37:30,549 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB3170000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 19:37:30,549 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBCFA0000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 19:37:30,550 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC6800000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:37:30,551 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBCE20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:37:30,552 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB23C0000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 19:37:30,555 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC4900000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 19:37:30,596 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:37:30,596 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:37:30,598 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:30,603 [root] DEBUG: Loader: Injecting process 12620 (thread 12624) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:30,603 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:37:30,604 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:30,605 [lib.api.process] INFO: Injected into 64-bit <Process 12620 identity_helper.exe>
2026-05-28 19:37:30,607 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12620
2026-05-28 19:37:30,608 [lib.api.process] INFO: Monitor config for process 12620: C:\hsngo5k_\dll\12620.ini
2026-05-28 19:37:30,608 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:37:30,677 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:37:30,678 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:37:30,679 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:37:30,684 [root] DEBUG: Loader: Injecting process 12620 (thread 12624) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:30,685 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:37:30,686 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:37:30,687 [lib.api.process] INFO: Injected into 64-bit <Process 12620 identity_helper.exe>
2026-05-28 19:37:30,712 [root] DEBUG: 12620: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:37:30,713 [root] DEBUG: 12620: Interactive desktop enabled.
2026-05-28 19:37:30,714 [root] DEBUG: 12620: Dropped file limit defaulting to 100.
2026-05-28 19:37:30,720 [root] DEBUG: 12620: Disabling sleep skipping.
2026-05-28 19:37:30,721 [root] DEBUG: 12620: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:37:30,734 [root] DEBUG: 12620: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:37:30,734 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FF7C1040000, size 0x28b4d8
2026-05-28 19:37:30,753 [root] DEBUG: 12620: Monitor initialised: 64-bit capemon loaded in process 12620 at 0x00007FFB86300000, thread 12624, image base 0x00007FF7C1040000, stack from 0x000000EEC5CF4000-0x000000EEC5D00000
2026-05-28 19:37:30,753 [root] DEBUG: 12620: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5708,i,12960369996331212703,6315776218184804396,524288 --field-trial-handle=2428,i,1252875946092603729,9946263229739000074,262144 --variations-seed-version --pseudonymization-salt-handle=2436,i,3950052428767732296,16495838250368074
2026-05-28 19:37:30,753 [root] DEBUG: 12620: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 19:37:30,766 [root] DEBUG: 12620: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:37:30,788 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:37:30,789 [root] DEBUG: 12620: set_hooks: Unable to hook LockResource
2026-05-28 19:37:30,794 [root] DEBUG: 12620: Hooked 627 out of 628 functions
2026-05-28 19:37:30,810 [root] DEBUG: 12620: Syscall hook installed, syscall logging level 1
2026-05-28 19:37:30,815 [root] DEBUG: 12620: RestoreHeaders: Restored original import table.
2026-05-28 19:37:30,816 [root] INFO: Loaded monitor into process with pid 12620
2026-05-28 19:37:30,816 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FFB85A50000, size 0x4b9994
2026-05-28 19:37:30,852 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FFB85A50000, size 0x4b9994
2026-05-28 19:37:30,877 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FFB85A50000, size 0x4b9994
2026-05-28 19:37:30,901 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FFB85A50000, size 0x4b9994
2026-05-28 19:37:30,928 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FFB85A50000, size 0x4b9994
2026-05-28 19:37:30,953 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FFB85A50000, size 0x4b9994
2026-05-28 19:37:30,993 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FFB85A50000, size 0x4b9994
2026-05-28 19:37:31,022 [root] DEBUG: 12620: caller_dispatch: Added region at 0x00007FFB85A50000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFB85C4F156, thread 12624).
2026-05-28 19:37:31,022 [root] DEBUG: 12620: caller_dispatch: Scanning calling region at 0x00007FFB85A50000...
2026-05-28 19:37:31,027 [root] DEBUG: 12620: ProcessTrackedRegion: Region at 0x00007FFB85A50000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 19:37:31,029 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:37:31,052 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FF7C1040000, size 0x28b4d8
2026-05-28 19:37:31,069 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FF7C1040000, size 0x28b4d8
2026-05-28 19:37:31,085 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FF7C1040000, size 0x28b4d8
2026-05-28 19:37:31,100 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FF7C1040000, size 0x28b4d8
2026-05-28 19:37:31,115 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FF7C1040000, size 0x28b4d8
2026-05-28 19:37:31,132 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FF7C1040000, size 0x28b4d8
2026-05-28 19:37:31,149 [root] DEBUG: 12620: caller_dispatch: Added region at 0x00007FF7C1040000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7C1134096, thread 12624).
2026-05-28 19:37:31,150 [root] DEBUG: 12620: YaraScan: Scanning 0x00007FF7C1040000, size 0x28b4d8
2026-05-28 19:37:31,166 [root] DEBUG: 12620: ProcessImageBase: Main module image at 0x00007FF7C1040000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:37:31,169 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:37:31,194 [root] DEBUG: 12620: DLL loaded at 0x000002431D000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:37:31,197 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:37:31,200 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC7690000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:37:31,201 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 12620, handle 0x2db4: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 19:37:31,228 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:37:31,232 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:37:31,236 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:37:31,236 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 19:37:31,236 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC2820000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:37:31,237 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB5020000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 19:37:31,286 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC1080000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:37:31,287 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC2F30000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:37:31,288 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC0D70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:37:31,288 [root] DEBUG: 12620: DLL loaded at 0x00007FFBBF7E0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:37:31,289 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB08E0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:37:31,386 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB6E10000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:37:31,395 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB3400000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 19:37:31,401 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC42C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:37:31,402 [root] DEBUG: 12620: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:37:31,418 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC0580000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:37:31,428 [root] DEBUG: 12620: DLL loaded at 0x00007FFBBE780000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:37:31,430 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB5D90000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:37:31,436 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC5930000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:37:31,437 [root] DEBUG: 12620: DLL loaded at 0x00007FFBBCF40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:37:31,439 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC4D80000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 19:37:31,529 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB3900000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:37:31,638 [root] DEBUG: 12620: DLL loaded at 0x00007FFB888B0000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 19:37:31,739 [root] DEBUG: 12620: DLL loaded at 0x00007FFBBAD00000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 19:37:31,742 [root] DEBUG: 12620: DLL loaded at 0x00007FFBBADC0000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 19:37:31,743 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB0CC0000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 19:37:31,745 [root] DEBUG: 12620: DLL loaded at 0x00007FFBAC310000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 19:37:31,782 [root] DEBUG: 12620: DLL loaded at 0x00007FFBBDCB0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 19:37:31,930 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC3AF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 19:37:31,935 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC1C00000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 19:37:31,953 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB7020000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 19:37:31,954 [root] DEBUG: 12620: DLL loaded at 0x00007FFBAC200000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:37:32,252 [root] DEBUG: 12620: DLL loaded at 0x00007FFBAD3E0000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 19:37:32,402 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC5120000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:37:32,402 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC4BF0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 19:37:32,403 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC3310000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:37:32,404 [root] DEBUG: 12620: DLL loaded at 0x00007FFBBB460000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 19:37:32,404 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB1090000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 19:37:32,566 [root] DEBUG: 12620: DLL loaded at 0x00007FFBAC570000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 19:37:32,638 [root] DEBUG: 12620: DLL loaded at 0x00007FFBB55B0000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:37:32,671 [root] DEBUG: 12620: DLL loaded at 0x00007FFBC58E0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:37:33,274 [root] INFO: Process with pid 3704 has terminated
2026-05-28 19:37:33,276 [root] DEBUG: 3704: NtTerminateProcess hook: Attempting to dump process 3704
2026-05-28 19:37:33,278 [root] DEBUG: 3704: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:37:42,746 [root] INFO: Process with pid 12620 has terminated
2026-05-28 19:37:42,746 [root] DEBUG: 12620: NtTerminateProcess hook: Attempting to dump process 12620
2026-05-28 19:37:42,748 [root] DEBUG: 12620: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:37:51,902 [root] DEBUG: 5568: DLL loaded at 0x00007FFBAC470000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 19:37:52,229 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 2604: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:52,230 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 2604
2026-05-28 19:37:52,231 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 2604
2026-05-28 19:37:54,628 [root] DEBUG: 4692: OpenProcessHandler: Image base for process 5568 (handle 0x2db8): 0x00007FF66C3B0000.
2026-05-28 19:37:54,662 [root] DEBUG: 4692: api-cap: SystemParametersInfoW hook disabled due to count: 5000
2026-05-28 19:37:55,288 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC0940000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 19:37:55,379 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 12980: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:55,380 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 12980
2026-05-28 19:37:55,381 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 12980
2026-05-28 19:37:55,850 [root] INFO: Added new file to list with pid 4692 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 19:37:55,852 [root] INFO: Added new file to list with pid 4692 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 19:37:58,945 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 2284: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:37:58,946 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 2284
2026-05-28 19:37:58,946 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 2284
2026-05-28 19:37:59,182 [root] DEBUG: 4692: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 19:38:00,527 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBA6C0000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 19:38:00,528 [root] DEBUG: 5568: DLL loaded at 0x00007FFBBA360000: C:\Windows\SYSTEM32\urlmon (0x1ed000 bytes).
2026-05-28 19:38:00,531 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB3880000: C:\Windows\SYSTEM32\FLTLIB (0xb000 bytes).
2026-05-28 19:38:00,531 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB6ED0000: C:\Windows\SYSTEM32\virtdisk (0x13000 bytes).
2026-05-28 19:38:00,533 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB6CF0000: C:\Windows\System32\smartscreenps (0x52000 bytes).
2026-05-28 19:38:00,534 [root] DEBUG: 5568: DLL loaded at 0x00007FFBAA3E0000: C:\Windows\SYSTEM32\shdocvw (0x41000 bytes).
2026-05-28 19:38:00,956 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4B60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 19:38:00,957 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB4B60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 19:38:00,975 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7561000, size: 0x1000.
2026-05-28 19:38:00,977 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7551000, size: 0x1000.
2026-05-28 19:38:00,978 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7541000, size: 0x1000.
2026-05-28 19:38:00,980 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7531000, size: 0x1000.
2026-05-28 19:38:00,993 [root] DEBUG: 4692: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4C7521000, size: 0x1000.
2026-05-28 19:38:01,003 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBD7C0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 19:38:01,004 [root] DEBUG: 4692: DLL loaded at 0x00007FFBBD7C0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 19:38:01,017 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 1564: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF6EEAC0000
2026-05-28 19:38:01,017 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 1564
2026-05-28 19:38:01,018 [lib.api.process] INFO: Monitor config for process 1564: C:\hsngo5k_\dll\1564.ini
2026-05-28 19:38:01,019 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:01,021 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:01,026 [root] DEBUG: Loader: Injecting process 1564 (thread 12980) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,027 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:01,028 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,029 [lib.api.process] INFO: Injected into 64-bit <Process 1564 CHXSmartScreen.exe>
2026-05-28 19:38:01,030 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 1564
2026-05-28 19:38:01,030 [lib.api.process] INFO: Monitor config for process 1564: C:\hsngo5k_\dll\1564.ini
2026-05-28 19:38:01,031 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:01,033 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:01,035 [root] DEBUG: 4692: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 19:38:01,037 [root] DEBUG: Loader: Injecting process 1564 (thread 12980) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,038 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:01,039 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,040 [lib.api.process] INFO: Injected into 64-bit <Process 1564 CHXSmartScreen.exe>
2026-05-28 19:38:01,041 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 1564
2026-05-28 19:38:01,041 [lib.api.process] INFO: Monitor config for process 1564: C:\hsngo5k_\dll\1564.ini
2026-05-28 19:38:01,042 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:01,044 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:01,049 [root] DEBUG: Loader: Injecting process 1564 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,049 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12980, handle 0x120
2026-05-28 19:38:01,050 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:38:01,050 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,051 [lib.api.process] INFO: Injected into 64-bit <Process 1564 CHXSmartScreen.exe>
2026-05-28 19:38:01,236 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 6660, handle 0x2ab0: C:\Windows\System32\rundll32.exe
2026-05-28 19:38:01,477 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7520000.
2026-05-28 19:38:01,479 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:01,480 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7530000.
2026-05-28 19:38:01,481 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:01,482 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7540000.
2026-05-28 19:38:01,483 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:01,484 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7560000.
2026-05-28 19:38:01,485 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:01,562 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 13344: C:\Windows\System32\RuntimeBroker.exe, ImageBase: 0x00007FF6AE420000
2026-05-28 19:38:01,563 [root] INFO: Announced 64-bit process name: RuntimeBroker.exe pid: 13344
2026-05-28 19:38:01,564 [lib.api.process] INFO: Monitor config for process 13344: C:\hsngo5k_\dll\13344.ini
2026-05-28 19:38:01,564 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:01,569 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:01,573 [root] DEBUG: Loader: Injecting process 13344 (thread 13348) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,576 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:01,576 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,577 [lib.api.process] INFO: Injected into 64-bit <Process 13344 RuntimeBroker.exe>
2026-05-28 19:38:01,579 [root] INFO: Announced 64-bit process name: RuntimeBroker.exe pid: 13344
2026-05-28 19:38:01,579 [lib.api.process] INFO: Monitor config for process 13344: C:\hsngo5k_\dll\13344.ini
2026-05-28 19:38:01,580 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:01,585 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:01,591 [root] DEBUG: Loader: Injecting process 13344 (thread 13348) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,592 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:38:01,592 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:01,594 [lib.api.process] INFO: Injected into 64-bit <Process 13344 RuntimeBroker.exe>
2026-05-28 19:38:01,600 [root] DEBUG: 13344: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:38:01,601 [root] DEBUG: 13344: Interactive desktop enabled.
2026-05-28 19:38:01,601 [root] DEBUG: 13344: Dropped file limit defaulting to 100.
2026-05-28 19:38:01,603 [root] DEBUG: 13344: Disabling sleep skipping.
2026-05-28 19:38:01,604 [root] DEBUG: 13344: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:38:01,616 [root] DEBUG: 13344: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:38:01,617 [root] DEBUG: 13344: YaraScan: Scanning 0x00007FF6AE420000, size 0x1b158
2026-05-28 19:38:01,618 [root] DEBUG: 13344: Monitor initialised: 64-bit capemon loaded in process 13344 at 0x00007FFB86300000, thread 13348, image base 0x00007FF6AE420000, stack from 0x000000BB671D4000-0x000000BB671E0000
2026-05-28 19:38:01,618 [root] DEBUG: 13344: Commandline: C:\Windows\System32\RuntimeBroker.exe -Embedding
2026-05-28 19:38:01,628 [root] DEBUG: 13344: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:38:01,650 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:38:01,651 [root] DEBUG: 13344: set_hooks: Unable to hook LockResource
2026-05-28 19:38:01,655 [root] DEBUG: 13344: Hooked 627 out of 628 functions
2026-05-28 19:38:01,656 [root] DEBUG: 13344: Syscall hook installed, syscall logging level 1
2026-05-28 19:38:01,661 [root] DEBUG: 13344: RestoreHeaders: Restored original import table.
2026-05-28 19:38:01,662 [root] INFO: Loaded monitor into process with pid 13344
2026-05-28 19:38:01,666 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\System32\UMPDC (0x12000 bytes).
2026-05-28 19:38:01,668 [root] DEBUG: 13344: caller_dispatch: Added region at 0x00007FF6AE420000 to tracked regions list (ntdll::NtAllocateVirtualMemoryEx returns to 0x00007FF6AE426182, thread 13348).
2026-05-28 19:38:01,668 [root] DEBUG: 13344: YaraScan: Scanning 0x00007FF6AE420000, size 0x1b158
2026-05-28 19:38:01,670 [root] DEBUG: 13344: ProcessImageBase: Main module image at 0x00007FF6AE420000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:38:01,671 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:38:01,673 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:38:01,693 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:38:01,694 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\System32\UxTheme (0x9e000 bytes).
2026-05-28 19:38:01,694 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC3AF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 19:38:01,695 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC1C00000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 19:38:01,696 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 19:38:01,700 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB7020000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 19:38:01,701 [root] DEBUG: 13344: DLL loaded at 0x00007FFBAC200000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:38:01,713 [root] DEBUG: 13344: DLL loaded at 0x00007FFBAD2F0000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:38:01,720 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC1080000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 19:38:01,722 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBBA60000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 19:38:01,726 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC4BF0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 19:38:01,727 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC3310000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-28 19:38:01,735 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC42C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:38:01,735 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:38:01,760 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB4F60000: C:\Windows\System32\LINKINFO (0xd000 bytes).
2026-05-28 19:38:01,784 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC2A60000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 19:38:01,788 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBB460000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 19:38:01,789 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC3D40000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 19:38:01,790 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC3D70000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 19:38:01,790 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC5120000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:38:01,791 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB16C0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 19:38:01,823 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC58E0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:38:01,843 [root] DEBUG: 13344: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 19:38:01,844 [root] DEBUG: 13344: api-rate-cap: NtReleaseMutant hook disabled due to rate
2026-05-28 19:38:02,035 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC6DE0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 19:38:02,107 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC5160000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 19:38:02,379 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBAD00000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 19:38:02,380 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBADC0000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 19:38:02,381 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB0CC0000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 19:38:02,383 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC0EE0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 19:38:02,390 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB5D90000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:38:02,408 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBB900000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 19:38:02,415 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBE410000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 19:38:02,424 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBB3F0000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 19:38:02,455 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB9F00000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:38:02,455 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB3170000: C:\Windows\System32\NETAPI32 (0x19000 bytes).
2026-05-28 19:38:02,457 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB4F50000: C:\Windows\System32\VERSION (0xa000 bytes).
2026-05-28 19:38:02,459 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 19:38:02,459 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC4700000: C:\Windows\System32\NETUTILS (0xc000 bytes).
2026-05-28 19:38:02,460 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC4390000: C:\Windows\System32\WKSCLI (0x19000 bytes).
2026-05-28 19:38:02,460 [root] DEBUG: 13344: DLL loaded at 0x00007FFBAEE20000: C:\Windows\System32\ieframe (0x76c000 bytes).
2026-05-28 19:38:02,464 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB1750000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32 (0x29a000 bytes).
2026-05-28 19:38:02,470 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB6910000: C:\Windows\System32\Secur32 (0xc000 bytes).
2026-05-28 19:38:02,472 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC20B0000: C:\Windows\System32\MLANG (0x42000 bytes).
2026-05-28 19:38:02,867 [root] DEBUG: 13344: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 19:38:04,150 [root] DEBUG: 4692: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 19:38:05,313 [root] DEBUG: 4692: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 19:38:05,314 [root] DEBUG: 4692: api-cap: RegCloseKey hook disabled due to count: 5001
2026-05-28 19:38:05,487 [root] DEBUG: 4692: api-rate-cap: NtQueryKey hook disabled due to rate
2026-05-28 19:38:05,503 [root] DEBUG: 4692: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 19:38:05,717 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7560000.
2026-05-28 19:38:05,719 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7540000.
2026-05-28 19:38:05,719 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7550000.
2026-05-28 19:38:05,721 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7530000.
2026-05-28 19:38:05,751 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 14220: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF6EEAC0000
2026-05-28 19:38:05,752 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 14220
2026-05-28 19:38:05,752 [lib.api.process] INFO: Monitor config for process 14220: C:\hsngo5k_\dll\14220.ini
2026-05-28 19:38:05,753 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:05,754 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:05,760 [root] DEBUG: Loader: Injecting process 14220 (thread 14224) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:05,760 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:05,761 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:05,763 [lib.api.process] INFO: Injected into 64-bit <Process 14220 CHXSmartScreen.exe>
2026-05-28 19:38:05,764 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 14220
2026-05-28 19:38:05,765 [lib.api.process] INFO: Monitor config for process 14220: C:\hsngo5k_\dll\14220.ini
2026-05-28 19:38:05,765 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:05,767 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:05,771 [root] DEBUG: Loader: Injecting process 14220 (thread 14224) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:05,771 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:05,772 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:05,775 [lib.api.process] INFO: Injected into 64-bit <Process 14220 CHXSmartScreen.exe>
2026-05-28 19:38:05,776 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 14220
2026-05-28 19:38:05,776 [lib.api.process] INFO: Monitor config for process 14220: C:\hsngo5k_\dll\14220.ini
2026-05-28 19:38:05,786 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:05,787 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:05,792 [root] DEBUG: Loader: Injecting process 14220 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:05,792 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 14224, handle 0x120
2026-05-28 19:38:05,793 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:38:05,793 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:05,795 [lib.api.process] INFO: Injected into 64-bit <Process 14220 CHXSmartScreen.exe>
2026-05-28 19:38:06,184 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7520000.
2026-05-28 19:38:06,185 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:06,186 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7540000.
2026-05-28 19:38:06,187 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:06,188 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7530000.
2026-05-28 19:38:06,189 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:06,190 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7550000.
2026-05-28 19:38:06,191 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:06,192 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7560000.
2026-05-28 19:38:06,193 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:11,161 [root] DEBUG: 4692: OpenProcessHandler: Image base for process 6852 (handle 0xbf4): 0x00007FF6B1E90000.
2026-05-28 19:38:25,369 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC3D40000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 19:38:25,370 [root] DEBUG: 5568: DLL loaded at 0x00007FFBC3D70000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-28 19:38:25,377 [root] DEBUG: 5568: DLL loaded at 0x00007FFBAD080000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-28 19:38:25,381 [root] DEBUG: 5568: DLL loaded at 0x00007FFBAD060000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 19:38:25,478 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 5424: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:38:25,479 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 5424
2026-05-28 19:38:25,480 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 5424
2026-05-28 19:38:25,508 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBE780000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:38:25,515 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB55B0000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:38:25,524 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB9B80000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 19:38:25,537 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB67D0000: C:\Windows\System32\MSWB7 (0x46000 bytes).
2026-05-28 19:38:25,551 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBA6C0000: C:\Windows\system32\srvcli (0x28000 bytes).
2026-05-28 19:38:25,552 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBA360000: C:\Windows\system32\urlmon (0x1ed000 bytes).
2026-05-28 19:38:25,556 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB5CA0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 19:38:25,588 [root] DEBUG: 13344: DLL loaded at 0x00007FFB6CD30000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 19:38:25,628 [root] DEBUG: 13344: DLL loaded at 0x00007FFB6CCC0000: C:\Windows\system32\mssvp (0x63000 bytes).
2026-05-28 19:38:25,660 [root] DEBUG: 13344: DLL loaded at 0x00007FFBC4970000: C:\Windows\system32\cryptdll (0x15000 bytes).
2026-05-28 19:38:25,661 [root] DEBUG: 13344: DLL loaded at 0x00007FFBB5970000: C:\Windows\system32\tquery (0x32e000 bytes).
2026-05-28 19:38:25,725 [root] DEBUG: 5568: DLL loaded at 0x00007FFB6CC00000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-28 19:38:25,764 [root] DEBUG: 13344: DLL loaded at 0x00007FFB6CB90000: C:\Windows\system32\mssvp (0x63000 bytes).
2026-05-28 19:38:25,860 [root] DEBUG: 13344: DLL loaded at 0x00007FFB6CB90000: C:\Windows\system32\mssvp (0x63000 bytes).
2026-05-28 19:38:26,082 [root] INFO: Announced starting service "b'BITS'"
2026-05-28 19:38:26,271 [root] DEBUG: 4692: api-rate-cap: IsDebuggerPresent hook disabled due to rate
2026-05-28 19:38:26,774 [root] DEBUG: 4692: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-28 19:38:26,776 [root] DEBUG: 4692: api-cap: NtOpenKeyEx hook disabled due to count: 5001
2026-05-28 19:38:26,777 [root] DEBUG: 4692: api-cap: NtOpenKeyEx hook disabled due to count: 5002
2026-05-28 19:38:26,789 [root] DEBUG: 4692: api-rate-cap: RtlSetCurrentTransaction hook disabled due to rate
2026-05-28 19:38:26,861 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 14588: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF69BCF0000
2026-05-28 19:38:26,862 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14588
2026-05-28 19:38:26,862 [lib.api.process] INFO: Monitor config for process 14588: C:\hsngo5k_\dll\14588.ini
2026-05-28 19:38:26,865 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:26,866 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:26,874 [lib.api.process] INFO: Injected into 64-bit <Process 14588 dllhost.exe>
2026-05-28 19:38:26,875 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 14588
2026-05-28 19:38:26,876 [lib.api.process] INFO: Monitor config for process 14588: C:\hsngo5k_\dll\14588.ini
2026-05-28 19:38:26,876 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:26,878 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:26,890 [root] DEBUG: Loader: Injecting process 14588 (thread 14592) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:26,890 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:26,891 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:26,893 [lib.api.process] INFO: Injected into 64-bit <Process 14588 dllhost.exe>
2026-05-28 19:38:26,900 [root] DEBUG: 14588: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:38:26,902 [root] DEBUG: 14588: Interactive desktop enabled.
2026-05-28 19:38:26,903 [root] DEBUG: 14588: Dropped file limit defaulting to 100.
2026-05-28 19:38:26,906 [root] DEBUG: 14588: Disabling sleep skipping.
2026-05-28 19:38:26,907 [root] DEBUG: 14588: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:38:26,918 [root] DEBUG: 14588: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:38:26,919 [root] DEBUG: 14588: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:38:26,920 [root] DEBUG: 14588: Monitor initialised: 64-bit capemon loaded in process 14588 at 0x00007FFB86300000, thread 14592, image base 0x00007FF69BCF0000, stack from 0x0000002516384000-0x0000002516390000
2026-05-28 19:38:26,920 [root] DEBUG: 14588: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:38:26,932 [root] DEBUG: 14588: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:38:26,938 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB6910000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 19:38:26,939 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB6910000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 19:38:26,940 [root] DEBUG: 4692: DLL loaded at 0x00007FFBC20B0000: C:\Windows\SYSTEM32\MLANG (0x42000 bytes).
2026-05-28 19:38:26,940 [root] DEBUG: 4692: DLL loaded at 0x00007FFBC20B0000: C:\Windows\SYSTEM32\MLANG (0x42000 bytes).
2026-05-28 19:38:26,955 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:38:26,955 [root] DEBUG: 14588: set_hooks: Unable to hook LockResource
2026-05-28 19:38:26,962 [root] DEBUG: 14588: Hooked 627 out of 628 functions
2026-05-28 19:38:26,963 [root] DEBUG: 14588: Syscall hook installed, syscall logging level 1
2026-05-28 19:38:26,968 [root] DEBUG: 14588: RestoreHeaders: Restored original import table.
2026-05-28 19:38:26,969 [root] INFO: Loaded monitor into process with pid 14588
2026-05-28 19:38:26,970 [root] DEBUG: 14588: caller_dispatch: Added region at 0x00007FF69BCF0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF69BCF12F2, thread 14592).
2026-05-28 19:38:26,970 [root] DEBUG: 14588: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:38:26,971 [root] DEBUG: 14588: ProcessImageBase: Main module image at 0x00007FF69BCF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:38:26,974 [root] DEBUG: 14588: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:38:26,975 [root] DEBUG: 14588: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:38:26,978 [root] DEBUG: 14588: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:38:26,990 [root] DEBUG: 14588: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:38:27,002 [root] DEBUG: 14588: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:38:27,003 [root] DEBUG: 14588: DLL loaded at 0x00007FFBB0100000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:38:27,009 [root] DEBUG: 14588: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:38:31,446 [root] DEBUG: 5568: DLL loaded at 0x00007FFBB1AC0000: C:\Windows\System32\BitsProxy (0x16000 bytes).
2026-05-28 19:38:31,993 [root] DEBUG: 13344: DLL loaded at 0x00007FFBBE410000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 19:38:32,149 [root] INFO: Process with pid 14588 has terminated
2026-05-28 19:38:32,150 [root] DEBUG: 14588: NtTerminateProcess hook: Attempting to dump process 14588
2026-05-28 19:38:32,151 [root] DEBUG: 14588: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:38:32,286 [root] DEBUG: 13344: api-cap: NtQueryValueKey hook disabled due to count: 5000
2026-05-28 19:38:38,433 [root] DEBUG: 4692: api-cap: NtQueryValueKey hook disabled due to count: 5000
2026-05-28 19:38:39,281 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 5840: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF69BCF0000
2026-05-28 19:38:39,283 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5840
2026-05-28 19:38:39,284 [lib.api.process] INFO: Monitor config for process 5840: C:\hsngo5k_\dll\5840.ini
2026-05-28 19:38:39,286 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:39,288 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:39,288 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 14280: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF792430000
2026-05-28 19:38:39,290 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 14280
2026-05-28 19:38:39,291 [lib.api.process] INFO: Monitor config for process 14280: C:\hsngo5k_\dll\14280.ini
2026-05-28 19:38:39,292 [root] DEBUG: Loader: Injecting process 5840 (thread 14476) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,292 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:39,292 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:39,295 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,298 [lib.api.process] INFO: Injected into 64-bit <Process 5840 dllhost.exe>
2026-05-28 19:38:39,299 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5840
2026-05-28 19:38:39,300 [lib.api.process] INFO: Monitor config for process 5840: C:\hsngo5k_\dll\5840.ini
2026-05-28 19:38:39,300 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:39,308 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:39,312 [root] DEBUG: Loader: Injecting process 5840 (thread 14476) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,312 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:39,313 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,314 [lib.api.process] INFO: Injected into 64-bit <Process 5840 dllhost.exe>
2026-05-28 19:38:39,321 [root] DEBUG: 5840: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:38:39,322 [root] DEBUG: 5840: Interactive desktop enabled.
2026-05-28 19:38:39,322 [root] DEBUG: 5840: Dropped file limit defaulting to 100.
2026-05-28 19:38:39,324 [root] DEBUG: 5840: Disabling sleep skipping.
2026-05-28 19:38:39,325 [root] DEBUG: 5840: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:38:39,339 [root] DEBUG: 5840: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:38:39,340 [root] DEBUG: 5840: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:38:39,341 [root] DEBUG: 5840: Monitor initialised: 64-bit capemon loaded in process 5840 at 0x00007FFB86300000, thread 14476, image base 0x00007FF69BCF0000, stack from 0x000000E74CCF4000-0x000000E74CD00000
2026-05-28 19:38:39,341 [root] DEBUG: 5840: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 19:38:39,352 [root] DEBUG: 5840: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:38:39,373 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:38:39,374 [root] DEBUG: 5840: set_hooks: Unable to hook LockResource
2026-05-28 19:38:39,379 [root] DEBUG: 5840: Hooked 627 out of 628 functions
2026-05-28 19:38:39,380 [root] DEBUG: 5840: Syscall hook installed, syscall logging level 1
2026-05-28 19:38:39,384 [root] DEBUG: 5840: RestoreHeaders: Restored original import table.
2026-05-28 19:38:39,385 [root] INFO: Loaded monitor into process with pid 5840
2026-05-28 19:38:39,386 [root] DEBUG: 5840: caller_dispatch: Added region at 0x00007FF69BCF0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF69BCF12F2, thread 14476).
2026-05-28 19:38:39,387 [root] DEBUG: 5840: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:38:39,388 [root] DEBUG: 5840: ProcessImageBase: Main module image at 0x00007FF69BCF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:38:39,390 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:38:39,391 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:38:39,394 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:38:39,409 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:38:39,449 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC4710000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:38:39,450 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC4700000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 19:38:39,450 [root] DEBUG: 5840: DLL loaded at 0x00007FFBBDC90000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:38:39,453 [root] DEBUG: 5840: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 19:38:39,454 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC4350000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:38:39,455 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:38:39,456 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC45F0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:38:39,457 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC5120000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 19:38:39,459 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC5160000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 19:38:39,459 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC0D70000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 19:38:39,462 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC4630000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 19:38:39,463 [root] DEBUG: 5840: DLL loaded at 0x00007FFB6C490000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 19:38:39,466 [root] DEBUG: 5840: DLL loaded at 0x00007FFBC6CF0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:38:39,475 [root] DEBUG: 5840: DLL loaded at 0x00007FFBB6E10000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:38:39,604 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:39,610 [root] DEBUG: Loader: Injecting process 14280 (thread 6356) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,611 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:39,611 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,612 [lib.api.process] INFO: Injected into 64-bit <Process 14280 WmiPrvSE.exe>
2026-05-28 19:38:39,614 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 14280
2026-05-28 19:38:39,615 [lib.api.process] INFO: Monitor config for process 14280: C:\hsngo5k_\dll\14280.ini
2026-05-28 19:38:39,615 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:39,879 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:39,883 [root] DEBUG: Loader: Injecting process 14280 (thread 6356) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,884 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:38:39,884 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,886 [lib.api.process] INFO: Injected into 64-bit <Process 14280 WmiPrvSE.exe>
2026-05-28 19:38:39,898 [root] DEBUG: 14280: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:38:39,899 [root] DEBUG: 14280: Interactive desktop enabled.
2026-05-28 19:38:39,900 [root] DEBUG: 14280: Dropped file limit defaulting to 100.
2026-05-28 19:38:39,902 [root] DEBUG: 14280: Disabling sleep skipping.
2026-05-28 19:38:39,902 [root] DEBUG: 14280: Services hook set enabled
2026-05-28 19:38:39,904 [root] DEBUG: 14280: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:38:39,916 [root] DEBUG: 14280: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:38:39,917 [root] DEBUG: 14280: Monitor initialised: 64-bit capemon loaded in process 14280 at 0x00007FFB86300000, thread 6356, image base 0x00007FF792430000, stack from 0x000000D09B590000-0x000000D09B5A0000
2026-05-28 19:38:39,918 [root] DEBUG: 14280: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 19:38:39,930 [root] DEBUG: 14280: Hooked 69 out of 69 functions
2026-05-28 19:38:39,934 [root] DEBUG: 14280: RestoreHeaders: Restored original import table.
2026-05-28 19:38:39,934 [root] INFO: Loaded monitor into process with pid 14280
2026-05-28 19:38:39,937 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:38:39,938 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:38:39,940 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:38:39,942 [lib.api.process] INFO: Monitor config for process 2384: C:\hsngo5k_\dll\2384.ini
2026-05-28 19:38:39,943 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:39,946 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:39,950 [root] DEBUG: Loader: Injecting process 2384 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,952 [root] DEBUG: 2384: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:38:39,953 [root] DEBUG: 2384: Disabling sleep skipping.
2026-05-28 19:38:39,954 [root] DEBUG: 2384: Interactive desktop enabled.
2026-05-28 19:38:39,954 [root] DEBUG: 2384: Dropped file limit defaulting to 100.
2026-05-28 19:38:39,955 [root] DEBUG: 2384: Services hook set enabled
2026-05-28 19:38:39,956 [root] DEBUG: 2384: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:38:39,968 [root] DEBUG: 2384: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:38:39,969 [root] DEBUG: 2384: Monitor initialised: 64-bit capemon loaded in process 2384 at 0x00007FFB86300000, thread 15776, image base 0x00007FF6A8E20000, stack from 0x0000003E2FD74000-0x0000003E2FD80000
2026-05-28 19:38:39,969 [root] DEBUG: 2384: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 19:38:39,982 [root] DEBUG: 2384: Hooked 69 out of 69 functions
2026-05-28 19:38:39,983 [root] INFO: Loaded monitor into process with pid 2384
2026-05-28 19:38:39,983 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:38:39,984 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:39,985 [lib.api.process] INFO: Injected into 64-bit <Process 2384 svchost.exe>
2026-05-28 19:38:40,093 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 15936: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF7A2CE0000
2026-05-28 19:38:40,094 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 15936
2026-05-28 19:38:40,095 [lib.api.process] INFO: Monitor config for process 15936: C:\hsngo5k_\dll\15936.ini
2026-05-28 19:38:40,096 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:40,098 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:40,102 [root] DEBUG: Loader: Injecting process 15936 (thread 15940) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:40,102 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:40,103 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:40,104 [lib.api.process] INFO: Injected into 64-bit <Process 15936 MoUsoCoreWorker.exe>
2026-05-28 19:38:40,105 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 15936
2026-05-28 19:38:40,105 [lib.api.process] INFO: Monitor config for process 15936: C:\hsngo5k_\dll\15936.ini
2026-05-28 19:38:40,106 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:40,108 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:40,112 [root] DEBUG: Loader: Injecting process 15936 (thread 15940) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:40,112 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:40,113 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:40,114 [lib.api.process] INFO: Injected into 64-bit <Process 15936 MoUsoCoreWorker.exe>
2026-05-28 19:38:40,122 [root] DEBUG: 15936: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:38:40,122 [root] DEBUG: 15936: Interactive desktop enabled.
2026-05-28 19:38:40,123 [root] DEBUG: 15936: Dropped file limit defaulting to 100.
2026-05-28 19:38:40,125 [root] DEBUG: 15936: VerifyCodeSection: Exception rebasing image from 0x00007FF7A2CE0000 to 0x0000000140000000.
2026-05-28 19:38:40,127 [root] DEBUG: 15936: Disabling sleep skipping.
2026-05-28 19:38:40,128 [root] DEBUG: 15936: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:38:40,140 [root] DEBUG: 15936: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:38:40,141 [root] DEBUG: 15936: YaraScan: Scanning 0x00007FF7A2CE0000, size 0x1ad000
2026-05-28 19:38:40,150 [root] DEBUG: 15936: Monitor initialised: 64-bit capemon loaded in process 15936 at 0x00007FFB86300000, thread 15940, image base 0x00007FF7A2CE0000, stack from 0x00000003145C4000-0x00000003145D0000
2026-05-28 19:38:40,150 [root] DEBUG: 15936: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-05-28 19:38:40,161 [root] DEBUG: 15936: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:38:40,182 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:38:40,183 [root] DEBUG: 15936: set_hooks: Unable to hook LockResource
2026-05-28 19:38:40,188 [root] DEBUG: 15936: Hooked 627 out of 628 functions
2026-05-28 19:38:40,198 [root] DEBUG: 15936: Syscall hook installed, syscall logging level 1
2026-05-28 19:38:40,203 [root] DEBUG: 15936: RestoreHeaders: Restored original import table.
2026-05-28 19:38:40,203 [root] INFO: Loaded monitor into process with pid 15936
2026-05-28 19:38:40,211 [root] DEBUG: 15936: caller_dispatch: Added region at 0x00007FF7A2CE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7A2DFF712, thread 15940).
2026-05-28 19:38:40,211 [root] DEBUG: 15936: YaraScan: Scanning 0x00007FF7A2CE0000, size 0x1ad000
2026-05-28 19:38:40,223 [root] DEBUG: 15936: ProcessImageBase: Main module image at 0x00007FF7A2CE0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:38:40,227 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:38:40,228 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:38:40,257 [root] DEBUG: 15936: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 19:38:40,281 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:38:40,297 [root] DEBUG: 15936: DLL loaded at 0x00007FFBB4AB0000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-05-28 19:38:40,502 [root] DEBUG: 15936: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 19:38:40,503 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC4FB0000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 19:38:40,504 [root] DEBUG: 15936: DLL loaded at 0x00007FFB6B860000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-05-28 19:38:40,511 [root] DEBUG: 15936: DLL loaded at 0x00007FFBAE330000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 19:38:40,513 [root] DEBUG: 15936: DLL loaded at 0x00007FFBAC630000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 19:38:40,516 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC0EE0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 19:38:40,518 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC4B90000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-05-28 19:38:40,626 [root] DEBUG: 15936: DLL loaded at 0x00007FFBAC630000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 19:38:40,876 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B750000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 19:38:40,879 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B750000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 19:38:40,908 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB6110000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 19:38:40,909 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB6110000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 19:38:40,917 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B470000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 19:38:40,917 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B470000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 19:38:40,924 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B330000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 19:38:40,925 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B330000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 19:38:40,925 [root] DEBUG: 4692: DLL loaded at 0x00007FFBC2F60000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 19:38:40,926 [root] DEBUG: 4692: DLL loaded at 0x00007FFBC2F60000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 19:38:40,927 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B390000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 19:38:40,927 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B390000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 19:38:40,934 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B310000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 19:38:40,934 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B310000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 19:38:40,942 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6CD30000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 19:38:40,942 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6CD30000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 19:38:41,993 [root] DEBUG: 14280: DLL loaded at 0x00007FFBADB60000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 19:38:41,997 [root] DEBUG: 14280: DLL loaded at 0x00007FFBAD7A0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 19:38:42,008 [root] DEBUG: 14280: DLL loaded at 0x00007FFBAD970000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 19:38:42,016 [root] DEBUG: 15936: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 19:38:42,017 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:38:42,018 [root] DEBUG: 14280: DLL loaded at 0x00007FFB6B330000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 19:38:42,018 [root] DEBUG: 14280: DLL loaded at 0x00007FFB6B540000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 19:38:42,019 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:38:42,025 [root] DEBUG: 14280: DLL loaded at 0x0000029882770000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 19:38:42,026 [root] DEBUG: 14280: DLL loaded at 0x00007FFBBF7C0000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 19:38:42,027 [root] DEBUG: 14280: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 19:38:43,841 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC42C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:38:43,842 [root] DEBUG: 15936: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:38:43,847 [root] DEBUG: 15936: DLL loaded at 0x00007FFB6B510000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 19:38:43,852 [root] DEBUG: 15936: DLL loaded at 0x00007FFBAD600000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 19:38:43,855 [root] DEBUG: 15936: DLL loaded at 0x00007FFBB0F10000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 19:38:43,858 [root] DEBUG: 15936: DLL loaded at 0x00007FFBBD900000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:38:43,862 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC1080000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 19:38:43,869 [root] DEBUG: 15936: DLL loaded at 0x00007FFBAD400000: C:\Windows\SYSTEM32\productenumerator (0xe000 bytes).
2026-05-28 19:38:44,166 [root] INFO: Stopping Task Scheduler Service
2026-05-28 19:38:44,176 [root] INFO: Stopped Task Scheduler Service
2026-05-28 19:38:44,180 [root] INFO: Starting Task Scheduler Service
2026-05-28 19:38:44,189 [root] INFO: Started Task Scheduler Service
2026-05-28 19:38:44,190 [lib.api.process] INFO: Monitor config for process 1324: C:\hsngo5k_\dll\1324.ini
2026-05-28 19:38:44,191 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:44,192 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:44,196 [root] DEBUG: Loader: Injecting process 1324 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:44,198 [root] DEBUG: 1324: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:38:44,198 [root] DEBUG: 1324: Disabling sleep skipping.
2026-05-28 19:38:44,199 [root] DEBUG: 1324: Interactive desktop enabled.
2026-05-28 19:38:44,199 [root] DEBUG: 1324: Dropped file limit defaulting to 100.
2026-05-28 19:38:44,200 [root] DEBUG: 1324: Services hook set enabled
2026-05-28 19:38:44,201 [root] DEBUG: 1324: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:38:44,213 [root] DEBUG: 1324: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:38:44,214 [root] DEBUG: 1324: Monitor initialised: 64-bit capemon loaded in process 1324 at 0x00007FFB86300000, thread 16504, image base 0x00007FF6A8E20000, stack from 0x000000868ADF4000-0x000000868AE00000
2026-05-28 19:38:44,214 [root] DEBUG: 1324: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-28 19:38:44,227 [root] DEBUG: 1324: Hooked 69 out of 69 functions
2026-05-28 19:38:44,228 [root] INFO: Loaded monitor into process with pid 1324
2026-05-28 19:38:44,229 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:38:44,230 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:44,231 [lib.api.process] INFO: Injected into 64-bit <Process 1324 svchost.exe>
2026-05-28 19:38:44,479 [root] INFO: Process with pid 5840 has terminated
2026-05-28 19:38:44,480 [root] DEBUG: 5840: NtTerminateProcess hook: Attempting to dump process 5840
2026-05-28 19:38:44,482 [root] DEBUG: 5840: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:38:46,242 [root] DEBUG: 15936: DLL loaded at 0x00007FFBC05A0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 19:38:46,286 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-28 19:38:47,313 [root] DEBUG: 15936: DLL loaded at 0x00007FFBAD050000: C:\Windows\system32\WaaSMedicPS (0xc000 bytes).
2026-05-28 19:38:47,445 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\3f3b49cb731ab01c26913ac326df1d2a3c6b240c9d04c6033d52b7e844187d6e; Size is 8720; Max size: 100000000
2026-05-28 19:38:47,486 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\9ac0c008a5519ea68743176bb0ddc453839f1d1185c903eb8686bde55bc24a5b; Size is 8720; Max size: 100000000
2026-05-28 19:38:47,530 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\2bbc4ad26665f1caddbb1c54c225a460ab688629984f875937e5d52b1843e774; Size is 8720; Max size: 100000000
2026-05-28 19:38:47,549 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\143d396ca6c2649789e42a182db1d4f892dcc2eb16644db868d59aa9c4ac2e00; Size is 8720; Max size: 100000000
2026-05-28 19:38:47,568 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\3cf3f0d52d66f803ee336c7099106faa519ec8d202eae839153f0660cbfcbef9; Size is 8720; Max size: 100000000
2026-05-28 19:38:47,614 [root] DEBUG: 15936: api-rate-cap: NtReadFile hook disabled due to rate
2026-05-28 19:38:47,643 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\a2956bee2e7eb6816cc02447f94886ff0dec3b63849dc612671b29a6686d75b6; Size is 12824; Max size: 100000000
2026-05-28 19:38:50,424 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7560000.
2026-05-28 19:38:50,426 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7550000.
2026-05-28 19:38:50,426 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7540000.
2026-05-28 19:38:50,428 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7530000.
2026-05-28 19:38:50,447 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 16840: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF6EEAC0000
2026-05-28 19:38:50,448 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 16840
2026-05-28 19:38:50,449 [lib.api.process] INFO: Monitor config for process 16840: C:\hsngo5k_\dll\16840.ini
2026-05-28 19:38:50,450 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:50,454 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:50,459 [root] DEBUG: Loader: Injecting process 16840 (thread 16844) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:50,460 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:50,460 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:50,462 [lib.api.process] INFO: Injected into 64-bit <Process 16840 CHXSmartScreen.exe>
2026-05-28 19:38:50,463 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 16840
2026-05-28 19:38:50,464 [lib.api.process] INFO: Monitor config for process 16840: C:\hsngo5k_\dll\16840.ini
2026-05-28 19:38:50,464 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:50,467 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:50,471 [root] DEBUG: Loader: Injecting process 16840 (thread 16844) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:50,472 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:50,473 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:50,474 [lib.api.process] INFO: Injected into 64-bit <Process 16840 CHXSmartScreen.exe>
2026-05-28 19:38:50,475 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 16840
2026-05-28 19:38:50,475 [lib.api.process] INFO: Monitor config for process 16840: C:\hsngo5k_\dll\16840.ini
2026-05-28 19:38:50,476 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:50,479 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:50,484 [root] DEBUG: Loader: Injecting process 16840 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:50,485 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16844, handle 0x124
2026-05-28 19:38:50,485 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:38:50,487 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:50,488 [lib.api.process] INFO: Injected into 64-bit <Process 16840 CHXSmartScreen.exe>
2026-05-28 19:38:50,577 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 16996, handle 0x2404: C:\Windows\System32\rundll32.exe
2026-05-28 19:38:50,736 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7520000.
2026-05-28 19:38:50,737 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:50,738 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7540000.
2026-05-28 19:38:50,738 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:50,739 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7530000.
2026-05-28 19:38:50,740 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:50,740 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7550000.
2026-05-28 19:38:50,741 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:50,742 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7560000.
2026-05-28 19:38:50,743 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:51,523 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 17084: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:38:51,524 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 17084
2026-05-28 19:38:51,525 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 17084
2026-05-28 19:38:51,968 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6C420000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:38:51,970 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6C420000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:38:52,036 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6C3F0000: C:\Windows\System32\shacct (0x29000 bytes).
2026-05-28 19:38:52,037 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6C3F0000: C:\Windows\System32\shacct (0x29000 bytes).
2026-05-28 19:38:52,044 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B220000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 19:38:52,044 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B220000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 19:38:52,070 [root] DEBUG: 4692: DLL loaded at 0x0000000009450000: C:\Windows\system32\sfc (0x3000 bytes).
2026-05-28 19:38:52,071 [root] DEBUG: 4692: DLL loaded at 0x0000000009450000: C:\Windows\system32\sfc (0x3000 bytes).
2026-05-28 19:38:52,073 [root] DEBUG: 4692: DLL loaded at 0x00007FFB89FD0000: C:\Windows\system32\msi (0x337000 bytes).
2026-05-28 19:38:52,073 [root] DEBUG: 4692: DLL loaded at 0x00007FFB89FD0000: C:\Windows\system32\msi (0x337000 bytes).
2026-05-28 19:38:52,075 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB3130000: C:\Windows\system32\sfc_os (0x12000 bytes).
2026-05-28 19:38:52,075 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB3130000: C:\Windows\system32\sfc_os (0x12000 bytes).
2026-05-28 19:38:52,076 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6C3D0000: C:\Windows\system32\acppage (0x19000 bytes).
2026-05-28 19:38:52,077 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6C3D0000: C:\Windows\system32\acppage (0x19000 bytes).
2026-05-28 19:38:52,094 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B1D0000: C:\Windows\system32\zipfldr (0x4a000 bytes).
2026-05-28 19:38:52,095 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B1D0000: C:\Windows\system32\zipfldr (0x4a000 bytes).
2026-05-28 19:38:52,147 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B1A0000: C:\Windows\System32\sendmail (0x2b000 bytes).
2026-05-28 19:38:52,148 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B1A0000: C:\Windows\System32\sendmail (0x2b000 bytes).
2026-05-28 19:38:52,165 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B490000: C:\Windows\system32\mydocs (0x11000 bytes).
2026-05-28 19:38:52,166 [root] DEBUG: 4692: DLL loaded at 0x00007FFB6B490000: C:\Windows\system32\mydocs (0x11000 bytes).
2026-05-28 19:38:53,396 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7560000.
2026-05-28 19:38:53,398 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7550000.
2026-05-28 19:38:53,399 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7550000.
2026-05-28 19:38:53,401 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7530000.
2026-05-28 19:38:53,422 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 16400: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF6EEAC0000
2026-05-28 19:38:53,423 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 16400
2026-05-28 19:38:53,424 [lib.api.process] INFO: Monitor config for process 16400: C:\hsngo5k_\dll\16400.ini
2026-05-28 19:38:53,425 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:53,428 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:53,432 [root] DEBUG: Loader: Injecting process 16400 (thread 16392) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:53,432 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:53,433 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:53,434 [lib.api.process] INFO: Injected into 64-bit <Process 16400 CHXSmartScreen.exe>
2026-05-28 19:38:53,436 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 16400
2026-05-28 19:38:53,437 [lib.api.process] INFO: Monitor config for process 16400: C:\hsngo5k_\dll\16400.ini
2026-05-28 19:38:53,438 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:53,441 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:53,445 [root] DEBUG: Loader: Injecting process 16400 (thread 16392) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:53,445 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:38:53,446 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:53,447 [lib.api.process] INFO: Injected into 64-bit <Process 16400 CHXSmartScreen.exe>
2026-05-28 19:38:53,448 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 16400
2026-05-28 19:38:53,449 [lib.api.process] INFO: Monitor config for process 16400: C:\hsngo5k_\dll\16400.ini
2026-05-28 19:38:53,450 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:38:53,454 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:38:53,459 [root] DEBUG: Loader: Injecting process 16400 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:53,460 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16392, handle 0xb4
2026-05-28 19:38:53,461 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:38:53,461 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:38:53,463 [lib.api.process] INFO: Injected into 64-bit <Process 16400 CHXSmartScreen.exe>
2026-05-28 19:38:53,682 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7520000.
2026-05-28 19:38:53,683 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:53,684 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7540000.
2026-05-28 19:38:53,685 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:53,686 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7530000.
2026-05-28 19:38:53,686 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:53,687 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7550000.
2026-05-28 19:38:53,688 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:38:53,690 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7560000.
2026-05-28 19:38:53,690 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:39:01,562 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 5648
2026-05-28 19:39:01,564 [lib.api.process] INFO: Monitor config for process 5648: C:\hsngo5k_\dll\5648.ini
2026-05-28 19:39:01,565 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:02,092 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:02,097 [root] DEBUG: Loader: Injecting process 5648 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:02,098 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 19:39:02,099 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:02,165 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 3028: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:02,168 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3028
2026-05-28 19:39:02,169 [lib.api.process] INFO: Monitor config for process 3028: C:\hsngo5k_\dll\3028.ini
2026-05-28 19:39:02,170 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:02,733 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:02,737 [root] DEBUG: Loader: Injecting process 3028 (thread 444) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:02,738 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:02,739 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:02,740 [lib.api.process] INFO: Injected into 64-bit <Process 3028 SearchApp.exe>
2026-05-28 19:39:02,743 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3028
2026-05-28 19:39:02,743 [lib.api.process] INFO: Monitor config for process 3028: C:\hsngo5k_\dll\3028.ini
2026-05-28 19:39:02,744 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:03,240 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:03,248 [root] DEBUG: Loader: Injecting process 3028 (thread 444) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:03,249 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:03,250 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:03,252 [lib.api.process] INFO: Injected into 64-bit <Process 3028 SearchApp.exe>
2026-05-28 19:39:03,254 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3028
2026-05-28 19:39:03,255 [lib.api.process] INFO: Monitor config for process 3028: C:\hsngo5k_\dll\3028.ini
2026-05-28 19:39:03,255 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:03,749 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:03,754 [root] DEBUG: Loader: Injecting process 3028 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:03,755 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 444, handle 0x124
2026-05-28 19:39:03,755 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:03,756 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:03,757 [lib.api.process] INFO: Injected into 64-bit <Process 3028 SearchApp.exe>
2026-05-28 19:39:04,136 [root] DEBUG: 4692: api-cap: NtSetInformationThread hook disabled due to count: 5000
2026-05-28 19:39:04,138 [root] DEBUG: 4692: api-cap: NtSetInformationThread hook disabled due to count: 5001
2026-05-28 19:39:04,138 [root] DEBUG: 4692: api-cap: NtSetInformationThread hook disabled due to count: 5002
2026-05-28 19:39:04,140 [root] DEBUG: 4692: api-cap: NtSetInformationThread hook disabled due to count: 5003
2026-05-28 19:39:04,163 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 1856: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:04,167 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 1856
2026-05-28 19:39:04,167 [lib.api.process] INFO: Monitor config for process 1856: C:\hsngo5k_\dll\1856.ini
2026-05-28 19:39:04,169 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:04,308 [root] DEBUG: 5568: CreateProcessHandler: Injection info set for new process 2808: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF66C3B0000
2026-05-28 19:39:04,309 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 2808
2026-05-28 19:39:04,311 [root] DEBUG: 5568: ProcessMessage: Skipping monitoring process 2808
2026-05-28 19:39:04,377 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 2580, handle 0x1970: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 19:39:04,385 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 2808, handle 0x1970: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 19:39:04,516 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 19:39:04,575 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 14404, handle 0x1970: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 19:39:04,688 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:04,693 [root] DEBUG: Loader: Injecting process 1856 (thread 2692) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:04,694 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:04,694 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:04,695 [lib.api.process] INFO: Injected into 64-bit <Process 1856 SearchApp.exe>
2026-05-28 19:39:04,697 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 1856
2026-05-28 19:39:04,698 [lib.api.process] INFO: Monitor config for process 1856: C:\hsngo5k_\dll\1856.ini
2026-05-28 19:39:04,698 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:05,099 [root] INFO: Process with pid 5568 appears to have terminated
2026-05-28 19:39:05,369 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:05,375 [root] DEBUG: Loader: Injecting process 1856 (thread 2692) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:05,376 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:05,377 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:05,378 [lib.api.process] INFO: Injected into 64-bit <Process 1856 SearchApp.exe>
2026-05-28 19:39:05,379 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 1856
2026-05-28 19:39:05,379 [lib.api.process] INFO: Monitor config for process 1856: C:\hsngo5k_\dll\1856.ini
2026-05-28 19:39:05,380 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:05,913 [root] DEBUG: 4692: OpenProcessHandler: Image base for process 6496 (handle 0x30f4): 0x00007FF617360000.
2026-05-28 19:39:05,914 [root] DEBUG: 4692: OpenProcessHandler: Injection info created for process 6496, handle 0x30f4: C:\Windows\System32\conhost.exe
2026-05-28 19:39:05,952 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:05,960 [root] DEBUG: Loader: Injecting process 1856 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:05,961 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 2692, handle 0x80
2026-05-28 19:39:05,962 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:05,963 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:05,964 [lib.api.process] INFO: Injected into 64-bit <Process 1856 SearchApp.exe>
2026-05-28 19:39:05,971 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 1568: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:05,972 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 1568
2026-05-28 19:39:05,973 [lib.api.process] INFO: Monitor config for process 1568: C:\hsngo5k_\dll\1568.ini
2026-05-28 19:39:05,974 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:06,588 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:06,593 [root] DEBUG: Loader: Injecting process 1568 (thread 1744) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:06,594 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:06,595 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:06,596 [lib.api.process] INFO: Injected into 64-bit <Process 1568 SearchApp.exe>
2026-05-28 19:39:06,597 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 1568
2026-05-28 19:39:06,597 [lib.api.process] INFO: Monitor config for process 1568: C:\hsngo5k_\dll\1568.ini
2026-05-28 19:39:06,598 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:07,219 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:07,224 [root] DEBUG: Loader: Injecting process 1568 (thread 1744) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:07,225 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:07,226 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:07,228 [lib.api.process] INFO: Injected into 64-bit <Process 1568 SearchApp.exe>
2026-05-28 19:39:07,231 [root] INFO: Process with pid 1568 has terminated
2026-05-28 19:39:07,253 [root] INFO: Announced starting service "b'lfsvc'"
2026-05-28 19:39:08,462 [root] DEBUG: 844: DLL loaded at 0x00007FFBB5D90000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:39:08,523 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 12284: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:08,524 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 12284
2026-05-28 19:39:08,524 [lib.api.process] INFO: Monitor config for process 12284: C:\hsngo5k_\dll\12284.ini
2026-05-28 19:39:08,525 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:09,122 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:09,127 [root] DEBUG: Loader: Injecting process 12284 (thread 10776) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:09,128 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:09,128 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:09,130 [lib.api.process] INFO: Injected into 64-bit <Process 12284 SearchApp.exe>
2026-05-28 19:39:09,131 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 12284
2026-05-28 19:39:09,132 [lib.api.process] INFO: Monitor config for process 12284: C:\hsngo5k_\dll\12284.ini
2026-05-28 19:39:09,132 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:09,799 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:09,804 [root] DEBUG: Loader: Injecting process 12284 (thread 10776) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:09,806 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:09,806 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:09,808 [lib.api.process] INFO: Injected into 64-bit <Process 12284 SearchApp.exe>
2026-05-28 19:39:09,809 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 12284
2026-05-28 19:39:09,811 [lib.api.process] INFO: Monitor config for process 12284: C:\hsngo5k_\dll\12284.ini
2026-05-28 19:39:09,811 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:10,470 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:10,474 [root] DEBUG: Loader: Injecting process 12284 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:10,475 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10776, handle 0x120
2026-05-28 19:39:10,476 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:10,476 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:10,478 [lib.api.process] INFO: Injected into 64-bit <Process 12284 SearchApp.exe>
2026-05-28 19:39:10,483 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 9788: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:10,484 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 9788
2026-05-28 19:39:10,485 [lib.api.process] INFO: Monitor config for process 9788: C:\hsngo5k_\dll\9788.ini
2026-05-28 19:39:10,487 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:11,090 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:11,095 [root] DEBUG: Loader: Injecting process 9788 (thread 14556) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:11,095 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:11,096 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:11,097 [lib.api.process] INFO: Injected into 64-bit <Process 9788 SearchApp.exe>
2026-05-28 19:39:11,100 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 9788
2026-05-28 19:39:11,100 [lib.api.process] INFO: Monitor config for process 9788: C:\hsngo5k_\dll\9788.ini
2026-05-28 19:39:11,101 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:11,792 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:11,797 [root] DEBUG: Loader: Injecting process 9788 (thread 14556) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:11,797 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:11,798 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:11,799 [lib.api.process] INFO: Injected into 64-bit <Process 9788 SearchApp.exe>
2026-05-28 19:39:11,800 [root] INFO: Process with pid 9788 has terminated
2026-05-28 19:39:12,508 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 10428: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:12,509 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 10428
2026-05-28 19:39:12,510 [lib.api.process] INFO: Monitor config for process 10428: C:\hsngo5k_\dll\10428.ini
2026-05-28 19:39:12,511 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:13,066 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:13,071 [root] DEBUG: Loader: Injecting process 10428 (thread 10436) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:13,073 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:13,074 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:13,076 [lib.api.process] INFO: Injected into 64-bit <Process 10428 SearchApp.exe>
2026-05-28 19:39:13,078 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 10428
2026-05-28 19:39:13,079 [lib.api.process] INFO: Monitor config for process 10428: C:\hsngo5k_\dll\10428.ini
2026-05-28 19:39:13,080 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:13,755 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:13,760 [root] DEBUG: Loader: Injecting process 10428 (thread 10436) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:13,761 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:13,761 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:13,762 [lib.api.process] INFO: Injected into 64-bit <Process 10428 SearchApp.exe>
2026-05-28 19:39:13,764 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 10428
2026-05-28 19:39:13,764 [lib.api.process] INFO: Monitor config for process 10428: C:\hsngo5k_\dll\10428.ini
2026-05-28 19:39:13,765 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:14,312 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:14,317 [root] DEBUG: Loader: Injecting process 10428 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:14,317 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10436, handle 0xb4
2026-05-28 19:39:14,318 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:14,319 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:14,320 [lib.api.process] INFO: Injected into 64-bit <Process 10428 SearchApp.exe>
2026-05-28 19:39:14,326 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 9680: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:14,329 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 9680
2026-05-28 19:39:14,329 [lib.api.process] INFO: Monitor config for process 9680: C:\hsngo5k_\dll\9680.ini
2026-05-28 19:39:14,330 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:14,922 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:14,926 [root] DEBUG: Loader: Injecting process 9680 (thread 9676) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:14,927 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:14,928 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:14,929 [lib.api.process] INFO: Injected into 64-bit <Process 9680 SearchApp.exe>
2026-05-28 19:39:14,930 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 9680
2026-05-28 19:39:14,931 [lib.api.process] INFO: Monitor config for process 9680: C:\hsngo5k_\dll\9680.ini
2026-05-28 19:39:14,932 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:15,615 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:15,620 [root] DEBUG: Loader: Injecting process 9680 (thread 9676) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:15,621 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:15,622 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:15,623 [lib.api.process] INFO: Injected into 64-bit <Process 9680 SearchApp.exe>
2026-05-28 19:39:15,624 [root] INFO: Process with pid 9680 has terminated
2026-05-28 19:39:16,337 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 5772: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:16,338 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 5772
2026-05-28 19:39:16,339 [lib.api.process] INFO: Monitor config for process 5772: C:\hsngo5k_\dll\5772.ini
2026-05-28 19:39:16,340 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:16,972 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:16,976 [root] DEBUG: Loader: Injecting process 5772 (thread 5760) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:16,977 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:16,978 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:16,979 [lib.api.process] INFO: Injected into 64-bit <Process 5772 SearchApp.exe>
2026-05-28 19:39:16,982 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 5772
2026-05-28 19:39:16,982 [lib.api.process] INFO: Monitor config for process 5772: C:\hsngo5k_\dll\5772.ini
2026-05-28 19:39:16,983 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:17,640 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:17,645 [root] DEBUG: Loader: Injecting process 5772 (thread 5760) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:17,646 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:17,647 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:17,648 [lib.api.process] INFO: Injected into 64-bit <Process 5772 SearchApp.exe>
2026-05-28 19:39:17,649 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 5772
2026-05-28 19:39:17,649 [lib.api.process] INFO: Monitor config for process 5772: C:\hsngo5k_\dll\5772.ini
2026-05-28 19:39:17,650 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:18,303 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:18,308 [root] DEBUG: Loader: Injecting process 5772 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:18,308 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 5760, handle 0xe8
2026-05-28 19:39:18,309 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:18,310 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:18,312 [lib.api.process] INFO: Injected into 64-bit <Process 5772 SearchApp.exe>
2026-05-28 19:39:18,319 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 3588: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:18,320 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3588
2026-05-28 19:39:18,320 [lib.api.process] INFO: Monitor config for process 3588: C:\hsngo5k_\dll\3588.ini
2026-05-28 19:39:18,322 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:18,917 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:18,922 [root] DEBUG: Loader: Injecting process 3588 (thread 3668) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:18,923 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:18,923 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:18,925 [lib.api.process] INFO: Injected into 64-bit <Process 3588 SearchApp.exe>
2026-05-28 19:39:18,927 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3588
2026-05-28 19:39:18,928 [lib.api.process] INFO: Monitor config for process 3588: C:\hsngo5k_\dll\3588.ini
2026-05-28 19:39:18,928 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:19,657 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:19,662 [root] DEBUG: Loader: Injecting process 3588 (thread 3668) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:19,663 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:19,664 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:19,666 [lib.api.process] INFO: Injected into 64-bit <Process 3588 SearchApp.exe>
2026-05-28 19:39:19,668 [root] INFO: Process with pid 3588 has terminated
2026-05-28 19:39:19,863 [root] DEBUG: 4692: api-cap: GetSystemTimeAsFileTime hook disabled due to count: 5000
2026-05-28 19:39:20,329 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 16136: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:20,330 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16136
2026-05-28 19:39:20,331 [lib.api.process] INFO: Monitor config for process 16136: C:\hsngo5k_\dll\16136.ini
2026-05-28 19:39:20,333 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:20,667 [root] DEBUG: 4692: api-cap: NtWaitForSingleObject hook disabled due to count: 5000
2026-05-28 19:39:20,920 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:20,925 [root] DEBUG: Loader: Injecting process 16136 (thread 16148) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:20,925 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:20,926 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:20,927 [lib.api.process] INFO: Injected into 64-bit <Process 16136 SearchApp.exe>
2026-05-28 19:39:20,928 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16136
2026-05-28 19:39:20,929 [lib.api.process] INFO: Monitor config for process 16136: C:\hsngo5k_\dll\16136.ini
2026-05-28 19:39:20,930 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:20,972 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7560000.
2026-05-28 19:39:20,974 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7550000.
2026-05-28 19:39:20,975 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7540000.
2026-05-28 19:39:20,977 [root] DEBUG: 4692: AllocationHandler: Allocation already in tracked region list: 0x00007DF4C7530000.
2026-05-28 19:39:20,998 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 10988: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF6EEAC0000
2026-05-28 19:39:21,000 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 10988
2026-05-28 19:39:21,001 [lib.api.process] INFO: Monitor config for process 10988: C:\hsngo5k_\dll\10988.ini
2026-05-28 19:39:21,002 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:21,007 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:21,012 [root] DEBUG: Loader: Injecting process 10988 (thread 10456) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:21,013 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:21,014 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:21,017 [lib.api.process] INFO: Injected into 64-bit <Process 10988 CHXSmartScreen.exe>
2026-05-28 19:39:21,019 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 10988
2026-05-28 19:39:21,019 [lib.api.process] INFO: Monitor config for process 10988: C:\hsngo5k_\dll\10988.ini
2026-05-28 19:39:21,020 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:21,025 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:21,029 [root] DEBUG: Loader: Injecting process 10988 (thread 10456) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:21,031 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:21,032 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:21,033 [lib.api.process] INFO: Injected into 64-bit <Process 10988 CHXSmartScreen.exe>
2026-05-28 19:39:21,034 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 10988
2026-05-28 19:39:21,035 [lib.api.process] INFO: Monitor config for process 10988: C:\hsngo5k_\dll\10988.ini
2026-05-28 19:39:21,035 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:21,045 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:21,051 [root] DEBUG: Loader: Injecting process 10988 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:21,052 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10456, handle 0x124
2026-05-28 19:39:21,053 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:21,053 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:21,055 [lib.api.process] INFO: Injected into 64-bit <Process 10988 CHXSmartScreen.exe>
2026-05-28 19:39:21,311 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7520000.
2026-05-28 19:39:21,312 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:39:21,314 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7540000.
2026-05-28 19:39:21,314 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:39:21,315 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7530000.
2026-05-28 19:39:21,316 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:39:21,317 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7550000.
2026-05-28 19:39:21,319 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:39:21,320 [root] DEBUG: 4692: FreeHandler: Address: 0x00007DF4C7560000.
2026-05-28 19:39:21,321 [root] DEBUG: 4692: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:39:21,482 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:21,486 [root] DEBUG: Loader: Injecting process 16136 (thread 16148) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:21,487 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:21,488 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:21,489 [lib.api.process] INFO: Injected into 64-bit <Process 16136 SearchApp.exe>
2026-05-28 19:39:21,490 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16136
2026-05-28 19:39:21,490 [lib.api.process] INFO: Monitor config for process 16136: C:\hsngo5k_\dll\16136.ini
2026-05-28 19:39:21,491 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:22,160 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:22,164 [root] DEBUG: Loader: Injecting process 16136 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:22,165 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16148, handle 0x12c
2026-05-28 19:39:22,166 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:22,166 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:22,167 [lib.api.process] INFO: Injected into 64-bit <Process 16136 SearchApp.exe>
2026-05-28 19:39:22,174 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 6168: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:22,174 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6168
2026-05-28 19:39:22,175 [lib.api.process] INFO: Monitor config for process 6168: C:\hsngo5k_\dll\6168.ini
2026-05-28 19:39:22,177 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:22,753 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:22,758 [root] DEBUG: Loader: Injecting process 6168 (thread 16656) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:22,759 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:22,759 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:22,760 [lib.api.process] INFO: Injected into 64-bit <Process 6168 SearchApp.exe>
2026-05-28 19:39:22,762 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6168
2026-05-28 19:39:22,762 [lib.api.process] INFO: Monitor config for process 6168: C:\hsngo5k_\dll\6168.ini
2026-05-28 19:39:22,763 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:23,427 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:23,431 [root] DEBUG: Loader: Injecting process 6168 (thread 16656) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:23,433 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:23,433 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:23,435 [lib.api.process] INFO: Injected into 64-bit <Process 6168 SearchApp.exe>
2026-05-28 19:39:23,436 [root] INFO: Process with pid 6168 has terminated
2026-05-28 19:39:23,612 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 3668: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:23,614 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3668
2026-05-28 19:39:23,615 [lib.api.process] INFO: Monitor config for process 3668: C:\hsngo5k_\dll\3668.ini
2026-05-28 19:39:23,617 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:24,190 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:24,196 [root] DEBUG: Loader: Injecting process 3668 (thread 15456) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:24,197 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:24,197 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:24,199 [lib.api.process] INFO: Injected into 64-bit <Process 3668 SearchApp.exe>
2026-05-28 19:39:24,201 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3668
2026-05-28 19:39:24,201 [lib.api.process] INFO: Monitor config for process 3668: C:\hsngo5k_\dll\3668.ini
2026-05-28 19:39:24,202 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:24,900 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:24,905 [root] DEBUG: Loader: Injecting process 3668 (thread 15456) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:24,905 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:24,906 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:24,907 [lib.api.process] INFO: Injected into 64-bit <Process 3668 SearchApp.exe>
2026-05-28 19:39:24,909 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3668
2026-05-28 19:39:24,910 [lib.api.process] INFO: Monitor config for process 3668: C:\hsngo5k_\dll\3668.ini
2026-05-28 19:39:24,910 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:25,571 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:25,575 [root] DEBUG: Loader: Injecting process 3668 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:25,576 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15456, handle 0x124
2026-05-28 19:39:25,577 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:25,577 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:25,579 [lib.api.process] INFO: Injected into 64-bit <Process 3668 SearchApp.exe>
2026-05-28 19:39:31,482 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 1476: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:39:31,483 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 1476
2026-05-28 19:39:31,484 [lib.api.process] INFO: Monitor config for process 1476: C:\hsngo5k_\dll\1476.ini
2026-05-28 19:39:31,485 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:32,150 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:32,154 [root] DEBUG: Loader: Injecting process 1476 (thread 1884) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:32,155 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:32,156 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:32,157 [lib.api.process] INFO: Injected into 64-bit <Process 1476 SearchApp.exe>
2026-05-28 19:39:32,158 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 1476
2026-05-28 19:39:32,159 [lib.api.process] INFO: Monitor config for process 1476: C:\hsngo5k_\dll\1476.ini
2026-05-28 19:39:32,159 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:32,928 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:32,934 [root] DEBUG: Loader: Injecting process 1476 (thread 1884) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:32,935 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:32,936 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:32,937 [lib.api.process] INFO: Injected into 64-bit <Process 1476 SearchApp.exe>
2026-05-28 19:39:32,939 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 1476
2026-05-28 19:39:32,939 [lib.api.process] INFO: Monitor config for process 1476: C:\hsngo5k_\dll\1476.ini
2026-05-28 19:39:32,940 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:33,626 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:33,630 [root] DEBUG: Loader: Injecting process 1476 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:33,631 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 1884, handle 0x120
2026-05-28 19:39:33,631 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:33,632 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:33,634 [lib.api.process] INFO: Injected into 64-bit <Process 1476 SearchApp.exe>
2026-05-28 19:39:34,296 [root] INFO: Process with pid 13344 has terminated
2026-05-28 19:39:34,297 [root] DEBUG: 13344: NtTerminateProcess hook: Attempting to dump process 13344
2026-05-28 19:39:34,298 [root] DEBUG: 13344: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:39:38,879 [root] DEBUG: 1324: CreateProcessHandler: Injection info set for new process 10948: C:\Windows\system32\sc.exe, ImageBase: 0x00007FF6BEA50000
2026-05-28 19:39:38,880 [root] DEBUG: 1324: CreateProcessHandler: Injection info set for new process 10592: C:\Windows\system32\taskhostw.exe, ImageBase: 0x00007FF633FB0000
2026-05-28 19:39:38,881 [root] INFO: Announced 64-bit process name: sc.exe pid: 10948
2026-05-28 19:39:38,882 [lib.api.process] INFO: Monitor config for process 10948: C:\hsngo5k_\dll\10948.ini
2026-05-28 19:39:38,882 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 10592
2026-05-28 19:39:38,883 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:38,884 [lib.api.process] INFO: Monitor config for process 10592: C:\hsngo5k_\dll\10592.ini
2026-05-28 19:39:38,886 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:38,887 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:38,893 [root] DEBUG: Loader: Injecting process 10948 (thread 10328) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,893 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:38,894 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:38,894 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,896 [lib.api.process] INFO: Injected into 64-bit <Process 10948 sc.exe>
2026-05-28 19:39:38,898 [root] INFO: Announced 64-bit process name: sc.exe pid: 10948
2026-05-28 19:39:38,898 [lib.api.process] INFO: Monitor config for process 10948: C:\hsngo5k_\dll\10948.ini
2026-05-28 19:39:38,899 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:38,899 [root] DEBUG: Loader: Injecting process 10592 (thread 16152) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,900 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:38,901 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,902 [lib.api.process] INFO: Injected into 64-bit <Process 10592 taskhostw.exe>
2026-05-28 19:39:38,904 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:38,906 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 10592
2026-05-28 19:39:38,907 [lib.api.process] INFO: Monitor config for process 10592: C:\hsngo5k_\dll\10592.ini
2026-05-28 19:39:38,908 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:38,910 [root] DEBUG: Loader: Injecting process 10948 (thread 10328) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,911 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:38,912 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,913 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:38,913 [lib.api.process] INFO: Injected into 64-bit <Process 10948 sc.exe>
2026-05-28 19:39:38,914 [root] INFO: Announced 64-bit process name: sc.exe pid: 10948
2026-05-28 19:39:38,915 [lib.api.process] INFO: Monitor config for process 10948: C:\hsngo5k_\dll\10948.ini
2026-05-28 19:39:38,916 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:38,916 [root] DEBUG: Loader: Injecting process 10592 (thread 16152) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,917 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:38,918 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,919 [lib.api.process] INFO: Injected into 64-bit <Process 10592 taskhostw.exe>
2026-05-28 19:39:38,920 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:38,921 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 10592
2026-05-28 19:39:38,922 [lib.api.process] INFO: Monitor config for process 10592: C:\hsngo5k_\dll\10592.ini
2026-05-28 19:39:38,922 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:38,925 [root] DEBUG: Loader: Injecting process 10948 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,926 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10328, handle 0x120
2026-05-28 19:39:38,927 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:38,927 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:38,928 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,929 [lib.api.process] INFO: Injected into 64-bit <Process 10948 sc.exe>
2026-05-28 19:39:38,931 [root] DEBUG: Loader: Injecting process 10592 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,932 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16152, handle 0xec
2026-05-28 19:39:38,933 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:39:38,934 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:38,935 [lib.api.process] INFO: Injected into 64-bit <Process 10592 taskhostw.exe>
2026-05-28 19:39:38,944 [root] DEBUG: 10592: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:39:38,946 [root] DEBUG: 10592: Interactive desktop enabled.
2026-05-28 19:39:38,948 [root] DEBUG: 10592: Dropped file limit defaulting to 100.
2026-05-28 19:39:38,951 [root] DEBUG: 10592: Disabling sleep skipping.
2026-05-28 19:39:38,953 [root] DEBUG: 10592: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:39:38,956 [root] DEBUG: 10948: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:39:38,957 [root] DEBUG: 10948: Interactive desktop enabled.
2026-05-28 19:39:38,957 [root] DEBUG: 10948: Dropped file limit defaulting to 100.
2026-05-28 19:39:38,959 [root] DEBUG: 10948: Disabling sleep skipping.
2026-05-28 19:39:38,961 [root] DEBUG: 10948: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:39:38,967 [root] DEBUG: 10592: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:39:38,968 [root] DEBUG: 10592: YaraScan: Scanning 0x00007FF633FB0000, size 0x192fc
2026-05-28 19:39:38,970 [root] DEBUG: 10592: Monitor initialised: 64-bit capemon loaded in process 10592 at 0x00007FFB86300000, thread 16152, image base 0x00007FF633FB0000, stack from 0x0000001299A74000-0x0000001299A80000
2026-05-28 19:39:38,971 [root] DEBUG: 10592: Commandline: taskhostw.exe
2026-05-28 19:39:38,975 [root] DEBUG: 10948: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:39:38,978 [root] DEBUG: 10948: YaraScan: Scanning 0x00007FF6BEA50000, size 0x1607c
2026-05-28 19:39:38,980 [root] DEBUG: 10948: Monitor initialised: 64-bit capemon loaded in process 10948 at 0x00007FFB86300000, thread 10328, image base 0x00007FF6BEA50000, stack from 0x000000FC51874000-0x000000FC51880000
2026-05-28 19:39:38,981 [root] DEBUG: 10948: Commandline: "C:\Windows\system32\sc.exe" start pushtoinstall registration
2026-05-28 19:39:38,986 [root] DEBUG: 10592: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:39:38,992 [root] DEBUG: 10948: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:39:39,012 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:39:39,013 [root] DEBUG: 10592: set_hooks: Unable to hook LockResource
2026-05-28 19:39:39,020 [root] DEBUG: 10592: Hooked 627 out of 628 functions
2026-05-28 19:39:39,020 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:39:39,021 [root] DEBUG: 10948: set_hooks: Unable to hook LockResource
2026-05-28 19:39:39,022 [root] DEBUG: 10592: Syscall hook installed, syscall logging level 1
2026-05-28 19:39:39,026 [root] DEBUG: 10948: Hooked 627 out of 628 functions
2026-05-28 19:39:39,027 [root] DEBUG: 10592: RestoreHeaders: Restored original import table.
2026-05-28 19:39:39,028 [root] INFO: Loaded monitor into process with pid 10592
2026-05-28 19:39:39,029 [root] DEBUG: 10948: Syscall hook installed, syscall logging level 1
2026-05-28 19:39:39,029 [root] DEBUG: 10592: caller_dispatch: Added region at 0x00007FF633FB0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF633FB5CA1, thread 16152).
2026-05-28 19:39:39,031 [root] DEBUG: 10592: YaraScan: Scanning 0x00007FF633FB0000, size 0x192fc
2026-05-28 19:39:39,033 [root] DEBUG: 10592: ProcessImageBase: Main module image at 0x00007FF633FB0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:39:39,034 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC7530000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-05-28 19:39:39,035 [root] DEBUG: 10948: RestoreHeaders: Restored original import table.
2026-05-28 19:39:39,036 [root] INFO: Loaded monitor into process with pid 10948
2026-05-28 19:39:39,037 [root] DEBUG: 10948: caller_dispatch: Added region at 0x00007FF6BEA50000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6BEA524F1, thread 10328).
2026-05-28 19:39:39,039 [root] DEBUG: 10948: YaraScan: Scanning 0x00007FF6BEA50000, size 0x1607c
2026-05-28 19:39:39,040 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:39:39,041 [root] DEBUG: 10948: ProcessImageBase: Main module image at 0x00007FF6BEA50000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:39:39,042 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:39:39,048 [root] INFO: Announced starting service "b'PushToInstall'"
2026-05-28 19:39:39,050 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:39:39,054 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4AF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 19:39:39,055 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB6F90000: C:\Windows\System32\wosc (0x4e000 bytes).
2026-05-28 19:39:39,060 [root] DEBUG: 10592: DLL loaded at 0x00007FFBAD600000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 19:39:39,063 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:39:39,064 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB0F10000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 19:39:39,074 [root] DEBUG: 10592: DLL loaded at 0x00007FFBBD900000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:39:39,082 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC1080000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 19:39:39,085 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC45F0000: C:\Windows\System32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:39:39,086 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC6CF0000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:39:39,089 [root] DEBUG: 10592: DLL loaded at 0x00007FFBA7F20000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-05-28 19:39:39,092 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC5160000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 19:39:39,093 [root] DEBUG: 10592: DLL loaded at 0x00007FFBBD4C0000: C:\Windows\System32\Cabinet (0x29000 bytes).
2026-05-28 19:39:39,094 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC5120000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:39:39,096 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC5930000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:39:39,097 [root] DEBUG: 10592: DLL loaded at 0x00007FFBAC5E0000: C:\Windows\System32\UpdatePolicy (0x43000 bytes).
2026-05-28 19:39:39,098 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4D80000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 19:39:39,102 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC42C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:39:39,103 [root] DEBUG: 10592: DLL loaded at 0x00007FFBBF330000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:39:39,107 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB9F00000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:39:39,107 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB5110000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 19:39:39,139 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4710000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:39:39,140 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC2120000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 19:39:39,157 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:39:39,158 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4700000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 19:39:39,160 [root] DEBUG: 10592: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 19:39:39,161 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4350000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:39:39,163 [root] DEBUG: 10592: DLL loaded at 0x00007FFBAAFE0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 19:39:39,165 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 19:39:39,171 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB1B90000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-28 19:39:39,176 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC0940000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 19:39:39,183 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB6F40000: C:\Windows\system32\fcon (0x45000 bytes).
2026-05-28 19:39:39,192 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4230000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 19:39:39,221 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4710000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:39:39,223 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC2120000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 19:39:39,236 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:39:39,237 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4700000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 19:39:39,238 [root] DEBUG: 10592: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 19:39:39,239 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4350000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:39:39,240 [root] DEBUG: 10592: DLL loaded at 0x00007FFBAAFE0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 19:39:39,241 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 19:39:39,244 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB1B90000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-28 19:39:39,301 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4710000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:39:39,303 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC2120000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 19:39:39,360 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:39:39,361 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4710000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:39:39,361 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4700000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 19:39:39,362 [root] DEBUG: 10592: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 19:39:39,364 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4350000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:39:39,364 [root] DEBUG: 10592: DLL loaded at 0x00007FFBAAFE0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 19:39:39,365 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 19:39:39,369 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC2120000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 19:39:39,391 [root] DEBUG: 10592: api-rate-cap: RegQueryValueExW hook disabled due to rate
2026-05-28 19:39:39,405 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC3D40000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 19:39:39,405 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC3D70000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-05-28 19:39:39,496 [root] DEBUG: 10592: api-rate-cap: ReadProcessMemory hook disabled due to rate
2026-05-28 19:39:39,503 [root] DEBUG: 10592: api-rate-cap: NtReadVirtualMemory hook disabled due to rate
2026-05-28 19:39:39,570 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB3170000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 19:39:39,572 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC0F30000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 19:39:39,587 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC58E0000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 19:39:39,588 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4F50000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 19:39:39,590 [root] DEBUG: 10592: DLL loaded at 0x00007FFBAA510000: C:\Windows\SYSTEM32\dmEnrollEngine (0xdf000 bytes).
2026-05-28 19:39:39,591 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC2100000: C:\Windows\SYSTEM32\enrollmentapi (0x11000 bytes).
2026-05-28 19:39:39,620 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4FE0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:39:39,621 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4710000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:39:39,622 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4700000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 19:39:39,622 [root] DEBUG: 10592: DLL loaded at 0x00007FFBBF9F0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 19:39:39,623 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4350000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:39:39,624 [root] DEBUG: 10592: DLL loaded at 0x00007FFBAAFE0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 19:39:39,626 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC4FC0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 19:39:39,628 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC2120000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 19:39:39,649 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC05A0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 19:39:39,652 [root] DEBUG: 10592: DLL loaded at 0x00007FFBC0D70000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:39:39,658 [root] DEBUG: 10592: DLL loaded at 0x00007FFBB4C00000: C:\Windows\SYSTEM32\dmiso8601utils (0x9000 bytes).
2026-05-28 19:39:39,691 [root] DEBUG: 10592: NtTerminateProcess hook: Attempting to dump process 10592
2026-05-28 19:39:39,692 [root] DEBUG: 10592: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:39:39,700 [root] INFO: Process with pid 10592 has terminated
2026-05-28 19:39:39,704 [root] INFO: Process with pid 10592 has terminated
2026-05-28 19:39:40,073 [root] DEBUG: 10948: NtTerminateProcess hook: Attempting to dump process 10948
2026-05-28 19:39:40,074 [root] DEBUG: 10948: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:39:40,082 [root] INFO: Process with pid 10948 has terminated
2026-05-28 19:39:40,085 [root] INFO: Process with pid 10948 has terminated
2026-05-28 19:39:40,142 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC0EE0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 19:39:40,144 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC4B90000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 19:39:40,146 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC58E0000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 19:39:40,148 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC4F50000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 19:39:40,150 [root] DEBUG: 14280: DLL loaded at 0x00007FFBB3170000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 19:39:40,151 [root] DEBUG: 14280: DLL loaded at 0x00007FFBB9EE0000: C:\Windows\SYSTEM32\SAMCLI (0x19000 bytes).
2026-05-28 19:39:40,153 [root] DEBUG: 14280: DLL loaded at 0x00007FFBBA6C0000: C:\Windows\SYSTEM32\SRVCLI (0x28000 bytes).
2026-05-28 19:39:40,155 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC4700000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-28 19:39:40,157 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC4710000: C:\Windows\SYSTEM32\LOGONCLI (0x43000 bytes).
2026-05-28 19:39:40,159 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC2130000: C:\Windows\SYSTEM32\SCHEDCLI (0xc000 bytes).
2026-05-28 19:39:40,160 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC4390000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-28 19:39:40,161 [root] DEBUG: 14280: DLL loaded at 0x00007FFBC0920000: C:\Windows\SYSTEM32\DSROLE (0xa000 bytes).
2026-05-28 19:39:46,144 [root] DEBUG: 4692: api-cap: NtOpenProcessToken hook disabled due to count: 5001
2026-05-28 19:39:46,145 [root] DEBUG: 4692: api-cap: NtOpenProcessToken hook disabled due to count: 5002
2026-05-28 19:39:46,149 [root] DEBUG: 4692: api-cap: NtOpenProcessToken hook disabled due to count: 5000
2026-05-28 19:39:46,153 [root] DEBUG: 4692: api-cap: NtOpenProcessToken hook disabled due to count: 5003
2026-05-28 19:39:46,272 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 18232: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF69BCF0000
2026-05-28 19:39:46,277 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 18232
2026-05-28 19:39:46,278 [lib.api.process] INFO: Monitor config for process 18232: C:\hsngo5k_\dll\18232.ini
2026-05-28 19:39:46,280 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:46,287 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:46,294 [root] DEBUG: Loader: Injecting process 18232 (thread 18236) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:46,297 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:46,299 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:46,302 [lib.api.process] INFO: Injected into 64-bit <Process 18232 dllhost.exe>
2026-05-28 19:39:46,305 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 18232
2026-05-28 19:39:46,307 [lib.api.process] INFO: Monitor config for process 18232: C:\hsngo5k_\dll\18232.ini
2026-05-28 19:39:46,308 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:39:46,318 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:39:46,324 [root] DEBUG: Loader: Injecting process 18232 (thread 18236) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:46,326 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:39:46,327 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:39:46,329 [lib.api.process] INFO: Injected into 64-bit <Process 18232 dllhost.exe>
2026-05-28 19:39:46,337 [root] DEBUG: 18232: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:39:46,338 [root] DEBUG: 18232: Interactive desktop enabled.
2026-05-28 19:39:46,339 [root] DEBUG: 18232: Dropped file limit defaulting to 100.
2026-05-28 19:39:46,342 [root] DEBUG: 18232: Disabling sleep skipping.
2026-05-28 19:39:46,343 [root] DEBUG: 18232: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
2026-05-28 19:39:46,356 [root] DEBUG: 18232: RtlInsertInvertedFunctionTable 0x00007FFBC7B6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFBC7CBD4F0
2026-05-28 19:39:46,359 [root] DEBUG: 18232: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:39:46,360 [root] DEBUG: 18232: Monitor initialised: 64-bit capemon loaded in process 18232 at 0x00007FFB86300000, thread 18236, image base 0x00007FF69BCF0000, stack from 0x0000007153CF4000-0x0000007153D00000
2026-05-28 19:39:46,361 [root] DEBUG: 18232: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:39:46,371 [root] DEBUG: 18232: hook_api: LdrpCallInitRoutine export address 0x00007FFBC7B699BC obtained via GetFunctionAddress
2026-05-28 19:39:46,394 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:39:46,395 [root] DEBUG: 18232: set_hooks: Unable to hook LockResource
2026-05-28 19:39:46,400 [root] DEBUG: 18232: Hooked 627 out of 628 functions
2026-05-28 19:39:46,401 [root] DEBUG: 18232: Syscall hook installed, syscall logging level 1
2026-05-28 19:39:46,407 [root] DEBUG: 18232: RestoreHeaders: Restored original import table.
2026-05-28 19:39:46,408 [root] INFO: Loaded monitor into process with pid 18232
2026-05-28 19:39:46,409 [root] DEBUG: 18232: caller_dispatch: Added region at 0x00007FF69BCF0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF69BCF12F2, thread 18236).
2026-05-28 19:39:46,411 [root] DEBUG: 18232: YaraScan: Scanning 0x00007FF69BCF0000, size 0x8026
2026-05-28 19:39:46,412 [root] DEBUG: 18232: ProcessImageBase: Main module image at 0x00007FF69BCF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:39:46,417 [root] DEBUG: 18232: DLL loaded at 0x00007FFBC3110000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:39:46,418 [root] DEBUG: 18232: DLL loaded at 0x00007FFBC5750000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:39:46,421 [root] DEBUG: 18232: DLL loaded at 0x00007FFBC7A60000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:39:46,437 [root] DEBUG: 18232: DLL loaded at 0x00007FFBC2BF0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:39:46,452 [root] DEBUG: 18232: DLL loaded at 0x00007FFBC5C20000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:39:46,453 [root] DEBUG: 18232: DLL loaded at 0x00007FFBB0100000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:39:46,462 [root] DEBUG: 18232: DLL loaded at 0x00007FFBC0DB0000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:39:46,511 [root] DEBUG: 4692: api-cap: NtReleaseMutant hook disabled due to count: 5000
2026-05-28 19:39:47,846 [root] DEBUG: 4692: api-cap: NtOpenProcess hook disabled due to count: 5000
2026-05-28 19:39:49,297 [root] INFO: Added new file to list with pid 15936 and path C:\ProgramData\USOPrivate\UpdateStore\store.db
2026-05-28 19:39:49,298 [root] INFO: Added new file to list with pid 15936 and path C:\ProgramData\USOShared\Logs\System\WuProvider.cdad9388-ca43-478b-b063-e9834370f6e4.1.etl
2026-05-28 19:39:49,300 [root] INFO: Added new file to list with pid 15936 and path C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.a4c64109-e2ee-4e63-80d2-6ae7fb207acf.1.etl
2026-05-28 19:39:49,300 [root] DEBUG: 15936: NtTerminateProcess hook: Attempting to dump process 15936
2026-05-28 19:39:49,302 [root] DEBUG: 15936: CAPEExceptionFilter: Exception 0xc0000005 accessing 0xa2e8d004 caught at RVA 0x75419 in capemon (expected in memory scans), passing to next handler.
2026-05-28 19:39:49,303 [root] DEBUG: 15936: VerifyCodeSection: Exception rebasing image from 0x00007FF7A2CE0000 to 0x0000000140000000.
2026-05-28 19:39:49,304 [root] DEBUG: 15936: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:39:49,313 [root] INFO: Process with pid 15936 has terminated
2026-05-28 19:39:51,618 [root] INFO: Process with pid 18232 has terminated
2026-05-28 19:39:51,619 [root] DEBUG: 18232: NtTerminateProcess hook: Attempting to dump process 18232
2026-05-28 19:39:51,620 [root] DEBUG: 18232: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:40:08,151 [root] DEBUG: 4692: api-cap: NtReadFile hook disabled due to count: 5000
2026-05-28 19:40:14,275 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 16688: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:40:14,277 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16688
2026-05-28 19:40:14,277 [lib.api.process] INFO: Monitor config for process 16688: C:\hsngo5k_\dll\16688.ini
2026-05-28 19:40:14,280 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:15,913 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:15,918 [root] DEBUG: Loader: Injecting process 16688 (thread 16692) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:15,919 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:40:15,919 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:15,920 [lib.api.process] INFO: Injected into 64-bit <Process 16688 SearchApp.exe>
2026-05-28 19:40:15,923 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16688
2026-05-28 19:40:15,925 [lib.api.process] INFO: Monitor config for process 16688: C:\hsngo5k_\dll\16688.ini
2026-05-28 19:40:15,925 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:17,540 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:17,544 [root] DEBUG: Loader: Injecting process 16688 (thread 16692) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:17,546 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:40:17,548 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:17,549 [lib.api.process] INFO: Injected into 64-bit <Process 16688 SearchApp.exe>
2026-05-28 19:40:17,551 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16688
2026-05-28 19:40:17,552 [lib.api.process] INFO: Monitor config for process 16688: C:\hsngo5k_\dll\16688.ini
2026-05-28 19:40:17,552 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:19,231 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:19,236 [root] DEBUG: Loader: Injecting process 16688 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:19,238 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16692, handle 0x120
2026-05-28 19:40:19,239 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:40:19,240 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:19,241 [lib.api.process] INFO: Injected into 64-bit <Process 16688 SearchApp.exe>
2026-05-28 19:40:19,545 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 3396: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:40:19,547 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3396
2026-05-28 19:40:19,548 [lib.api.process] INFO: Monitor config for process 3396: C:\hsngo5k_\dll\3396.ini
2026-05-28 19:40:19,551 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:21,356 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:21,364 [root] DEBUG: Loader: Injecting process 3396 (thread 1276) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:21,367 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:40:21,368 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:21,370 [lib.api.process] INFO: Injected into 64-bit <Process 3396 SearchApp.exe>
2026-05-28 19:40:21,372 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3396
2026-05-28 19:40:21,373 [lib.api.process] INFO: Monitor config for process 3396: C:\hsngo5k_\dll\3396.ini
2026-05-28 19:40:21,374 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:23,187 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:23,192 [root] DEBUG: Loader: Injecting process 3396 (thread 1276) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:23,193 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:40:23,195 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:23,197 [lib.api.process] INFO: Injected into 64-bit <Process 3396 SearchApp.exe>
2026-05-28 19:40:23,199 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 3396
2026-05-28 19:40:23,201 [lib.api.process] INFO: Monitor config for process 3396: C:\hsngo5k_\dll\3396.ini
2026-05-28 19:40:23,202 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:24,731 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:24,736 [root] DEBUG: Loader: Injecting process 3396 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:24,738 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 1276, handle 0x120
2026-05-28 19:40:24,739 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:40:24,740 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:24,741 [lib.api.process] INFO: Injected into 64-bit <Process 3396 SearchApp.exe>
2026-05-28 19:40:32,670 [root] DEBUG: 4692: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5001
2026-05-28 19:40:32,671 [root] DEBUG: 4692: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5001
2026-05-28 19:40:32,672 [root] DEBUG: 4692: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5002
2026-05-28 19:40:32,734 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 17136: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF705540000
2026-05-28 19:40:32,737 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17136
2026-05-28 19:40:32,741 [lib.api.process] INFO: Monitor config for process 17136: C:\hsngo5k_\dll\17136.ini
2026-05-28 19:40:32,743 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:33,732 [root] DEBUG: 4692: api-cap: NtQueryInformationThread hook disabled due to count: 5001
2026-05-28 19:40:33,734 [root] DEBUG: 4692: api-cap: NtQueryInformationThread hook disabled due to count: 5001
2026-05-28 19:40:34,337 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:34,342 [root] DEBUG: Loader: Injecting process 17136 (thread 17884) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:34,343 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:40:34,344 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:34,345 [lib.api.process] INFO: Injected into 64-bit <Process 17136 SearchApp.exe>
2026-05-28 19:40:34,349 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17136
2026-05-28 19:40:34,349 [lib.api.process] INFO: Monitor config for process 17136: C:\hsngo5k_\dll\17136.ini
2026-05-28 19:40:34,350 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:36,032 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:36,039 [root] DEBUG: Loader: Injecting process 17136 (thread 17884) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:36,042 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:40:36,043 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:36,045 [lib.api.process] INFO: Injected into 64-bit <Process 17136 SearchApp.exe>
2026-05-28 19:40:36,046 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17136
2026-05-28 19:40:36,048 [lib.api.process] INFO: Monitor config for process 17136: C:\hsngo5k_\dll\17136.ini
2026-05-28 19:40:36,049 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:37,662 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:37,667 [root] DEBUG: Loader: Injecting process 17136 with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:37,668 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17884, handle 0x48
2026-05-28 19:40:37,669 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:40:37,670 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:37,671 [lib.api.process] INFO: Injected into 64-bit <Process 17136 SearchApp.exe>
2026-05-28 19:40:40,305 [root] DEBUG: 14280: NtTerminateProcess hook: Attempting to dump process 14280
2026-05-28 19:40:40,306 [root] DEBUG: 14280: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:40:40,309 [root] INFO: Process with pid 14280 has terminated
2026-05-28 19:40:40,375 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB6930000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 19:40:40,377 [root] DEBUG: 4692: DLL loaded at 0x00007FFBB6930000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 19:40:40,389 [root] DEBUG: 844: CreateProcessHandler: Injection info set for new process 5732: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF7BE6C0000
2026-05-28 19:40:40,392 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 5732
2026-05-28 19:40:40,394 [lib.api.process] INFO: Monitor config for process 5732: C:\hsngo5k_\dll\5732.ini
2026-05-28 19:40:40,398 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:40,408 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:40,414 [root] DEBUG: Loader: Injecting process 5732 (thread 1308) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:40,416 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:40:40,417 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:40,419 [lib.api.process] INFO: Injected into 64-bit <Process 5732 SecurityHealthHost.exe>
2026-05-28 19:40:40,423 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 5732
2026-05-28 19:40:40,424 [lib.api.process] INFO: Monitor config for process 5732: C:\hsngo5k_\dll\5732.ini
2026-05-28 19:40:40,425 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:40:40,431 [lib.api.process] INFO: 64-bit DLL to inject is C:\hsngo5k_\dll\LjVHGInK.dll, loader C:\hsngo5k_\bin\PAWPxvZd.exe
2026-05-28 19:40:40,436 [root] DEBUG: Loader: Injecting process 5732 (thread 1308) with C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:40,438 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:40:40,439 [root] DEBUG: Successfully injected DLL C:\hsngo5k_\dll\LjVHGInK.dll.
2026-05-28 19:40:40,441 [lib.api.process] INFO: Injected into 64-bit <Process 5732 SecurityHealthHost.exe>
2026-05-28 19:40:40,457 [root] DEBUG: 5732: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:40:40,459 [root] DEBUG: 5732: Interactive desktop enabled.
2026-05-28 19:40:40,463 [root] DEBUG: 5732: Dropped file limit defaulting to 100.
2026-05-28 19:40:40,472 [root] DEBUG: 5732: Disabling sleep skipping.
2026-05-28 19:40:40,479 [root] DEBUG: 5732: YaraInit: Compiled rules loaded from existing file C:\hsngo5k_\data\yara\capemon.yac
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 19:37:06 | 2026-05-28 19:40:52 | none |
| Process: RuntimeBroker.exe (13344) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (13344) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (13344) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: RuntimeBroker.exe (13344) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 204.79.197.203 [VT] | unknown | - |
| Y | 149.135.84.50 [VT] | unknown | - |
| Y | 18.155.216.20 [VT] | unknown | - |
| Y | 172.64.154.167 [VT] | unknown | - |
| Y | 149.135.84.40 [VT] | unknown | - |
| Y | 150.171.27.12 [VT] | unknown | - |
| Y | 150.171.109.19 [VT] | unknown | - |
| Y | 150.171.27.10 [VT] | unknown | - |
| Y | 149.135.84.25 [VT] | unknown | - |
| N | 199.232.83.82 [VT] | unknown | - |
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 40.115.75.193 [VT] | unknown | - |
| Y | 150.171.109.24 [VT] | unknown | - |
| Y | 4.237.153.9 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 162.159.137.232 [VT] | unknown | - |
| Y | 162.159.135.232 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| Y | 162.254.194.57 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| N | 162.159.138.234 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| Y | 199.232.210.172 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| Y | 151.101.11.82 [VT] | unknown | - |
| Y | 162.159.134.233 [VT] | unknown | - |
| Y | 40.126.14.161 [VT] | unknown | - |
| Y | 172.172.255.216 [VT] | unknown | - |
| Y | 162.159.133.233 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| latency.discord.media [VT] |
A 162.159.128.235
[VT]
A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.130.235 [VT] A 162.159.129.235 [VT] |
162.159.130.235 [VT] |
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| dns.google [VT] |
A 8.8.8.8
[VT]
A 8.8.4.4 [VT] |
8.8.4.4 [VT] |
| steamconnecttest.com [VT] |
A 149.135.84.155
[VT]
A 149.135.84.160 [VT] |
23.56.110.51 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| gateway-us-east1-d.discord.gg [VT] |
A 162.159.133.234
[VT]
A 162.159.134.234 [VT] A 162.159.130.234 [VT] A 162.159.135.234 [VT] A 162.159.136.234 [VT] |
162.159.136.234 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| client-update.fastly.steamstatic.com [VT] |
CNAME valve.map.fastly.net
[VT]
A 199.232.83.82 [VT] |
199.232.211.82 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.