| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 19:54:51 | 2026-05-28 19:58:34 | 223s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 19:52:07,786 [root] INFO: Date set to: 20260528T19:54:58, timeout set to: 200
2026-05-28 19:54:58,005 [root] DEBUG: Starting analyzer from: C:\_3mo6uuq
2026-05-28 19:54:58,006 [root] DEBUG: Storing results at: C:\VuqQjay
2026-05-28 19:54:58,006 [root] DEBUG: Pipe server name: \\.\PIPE\UxkCwQtaaT
2026-05-28 19:54:58,006 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 19:54:58,006 [root] INFO: analysis running as an admin
2026-05-28 19:54:58,007 [root] INFO: analysis package specified: "edge"
2026-05-28 19:54:58,007 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 19:54:58,012 [root] DEBUG: imported analysis package "edge"
2026-05-28 19:54:58,012 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 19:54:58,012 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-28 19:54:58,013 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 19:54:58,013 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 19:54:58,013 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 19:54:58,013 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 19:54:58,025 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 19:54:58,037 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 19:54:58,043 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 19:54:58,050 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 19:54:58,060 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 19:54:58,061 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 19:54:58,061 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 19:54:58,063 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 19:54:58,063 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 19:54:58,063 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 19:54:58,064 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 19:54:58,064 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 19:54:58,064 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 19:54:58,064 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 19:54:58,065 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 19:54:58,065 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 19:54:58,065 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 19:54:58,065 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 19:54:58,066 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 19:54:58,067 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 19:54:58,067 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 19:54:58,067 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 19:54:58,067 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 19:54:58,076 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 8248)
2026-05-28 19:54:58,077 [modules.auxiliary.disguise] INFO: Disguising GUID to b2b693ff-413e-463f-a5c2-27019b5d7ef7
2026-05-28 19:54:58,077 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 19:54:58,077 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 19:54:58,077 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 19:54:58,078 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 19:54:58,078 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 19:54:58,078 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 19:54:58,078 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 19:54:58,079 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 19:54:58,080 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 19:54:58,080 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 19:54:58,080 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 19:54:58,080 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 19:54:58,080 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 19:54:58,081 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 19:54:58,081 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 19:54:58,083 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 19:54:58,085 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 19:54:58,085 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 19:54:58,085 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 19:54:58,109 [lib.api.process] INFO: Monitor config for process 4372: C:\_3mo6uuq\dll\4372.ini
2026-05-28 19:54:58,110 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:54:58,112 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:54:58,135 [root] DEBUG: Loader: Injecting process 4372 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:54:58,331 [root] DEBUG: 4372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:54:58,333 [root] DEBUG: 4372: Disabling sleep skipping.
2026-05-28 19:54:58,333 [root] DEBUG: 4372: Interactive desktop enabled.
2026-05-28 19:54:58,334 [root] DEBUG: 4372: Dropped file limit defaulting to 100.
2026-05-28 19:54:58,334 [root] DEBUG: 4372: Interactive desktop - injecting Explorer Shell
2026-05-28 19:54:58,340 [root] DEBUG: 4372: YaraInit: Compiled 44 rule files
2026-05-28 19:54:58,342 [root] DEBUG: 4372: YaraInit: Compiled rules saved to file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:54:58,362 [root] DEBUG: 4372: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:54:58,363 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 19:54:58,509 [root] DEBUG: 4372: Monitor initialised: 64-bit capemon loaded in process 4372 at 0x00007FFEAF1A0000, thread 600, image base 0x00007FF65F9E0000, stack from 0x000000000A7C1000-0x000000000A7D0000
2026-05-28 19:54:58,510 [root] DEBUG: 4372: Commandline: C:\Windows\Explorer.EXE
2026-05-28 19:54:58,524 [root] DEBUG: 4372: Hooked 69 out of 69 functions
2026-05-28 19:54:58,557 [root] DEBUG: 4372: Syscall hook installed, syscall logging level 1
2026-05-28 19:54:58,568 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:54:58,569 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:54:58,570 [lib.api.process] INFO: Injected into 64-bit <Process 4372 explorer.exe>
2026-05-28 19:55:05,709 [root] INFO: Restarting WMI Service
2026-05-28 19:55:07,738 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 19:55:07,740 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 19:55:07,740 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 19:55:07,741 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 3512
2026-05-28 19:55:07,742 [lib.api.process] INFO: Monitor config for process 3512: C:\_3mo6uuq\dll\3512.ini
2026-05-28 19:55:07,742 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:07,743 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:07,748 [root] DEBUG: Loader: Injecting process 3512 (thread 3244) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:07,748 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:55:07,749 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:07,750 [lib.api.process] INFO: Injected into 64-bit <Process 3512 msedge.exe>
2026-05-28 19:55:09,761 [lib.api.process] INFO: Successfully resumed process with pid 3512
2026-05-28 19:55:09,847 [root] DEBUG: 3512: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:55:09,847 [root] DEBUG: 3512: Disabling sleep skipping.
2026-05-28 19:55:09,848 [root] DEBUG: 3512: Interactive desktop enabled.
2026-05-28 19:55:09,848 [root] DEBUG: 3512: Dropped file limit defaulting to 100.
2026-05-28 19:55:09,856 [root] DEBUG: 3512: Edge-specific hook-set enabled.
2026-05-28 19:55:09,860 [root] DEBUG: 3512: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:55:09,872 [root] DEBUG: 3512: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:55:09,872 [root] DEBUG: 3512: Monitor initialised: 64-bit capemon loaded in process 3512 at 0x00007FFEAF1A0000, thread 3244, image base 0x00007FF60A060000, stack from 0x000000A6225F4000-0x000000A622600000
2026-05-28 19:55:09,873 [root] DEBUG: 3512: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-28 19:55:09,883 [root] DEBUG: 3512: Hooked 2 out of 2 functions
2026-05-28 19:55:09,918 [root] DEBUG: 3512: Syscall hook installed, syscall logging level 1
2026-05-28 19:55:09,923 [root] DEBUG: 3512: RestoreHeaders: Restored original import table.
2026-05-28 19:55:09,923 [root] INFO: Loaded monitor into process with pid 3512
2026-05-28 19:55:09,926 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:55:09,931 [root] DEBUG: 3512: DLL loaded at 0x00007FFED9040000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 19:55:09,932 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:55:09,934 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 19:55:09,936 [root] DEBUG: 3512: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:55:09,937 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 19:55:09,939 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:55:10,102 [root] DEBUG: 3512: DLL loaded at 0x00007FFED8180000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 19:55:10,103 [root] DEBUG: 3512: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:55:10,106 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDD470000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 19:55:10,110 [root] DEBUG: 3512: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:55:10,116 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 7552: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:10,117 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 7552
2026-05-28 19:55:10,117 [root] DEBUG: 3512: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:55:10,118 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 7552
2026-05-28 19:55:10,119 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:55:10,121 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE86F0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 19:55:10,123 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:55:10,123 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:55:10,128 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 19:55:10,129 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEDFA0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 19:55:10,130 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE870000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 19:55:10,131 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 19:55:10,132 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:55:10,133 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE5A50000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 19:55:10,134 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:55:10,135 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:55:10,135 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:55:10,136 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:55:10,136 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE6C20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:55:10,137 [root] DEBUG: 3512: DLL loaded at 0x00007FFED4750000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 19:55:10,139 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE86B0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 19:55:10,140 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:55:10,142 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:55:10,144 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 19:55:10,144 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:55:10,145 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 19:55:10,145 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEB400000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 19:55:10,146 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF640000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 19:55:10,155 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE86D0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 19:55:10,156 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:55:10,157 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE6360000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 19:55:10,158 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:55:10,159 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:55:10,160 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE23A0000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 19:55:10,163 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 19:55:10,164 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:55:10,164 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF430000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 19:55:10,166 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:55:10,166 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEAE30000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 19:55:10,167 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:55:10,169 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE8E40000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 19:55:10,170 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:55:10,171 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE5AC0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 19:55:10,172 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE8D30000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:55:10,174 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEB280000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 19:55:10,175 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEEB10000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 19:55:10,177 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:55:10,180 [root] DEBUG: 3512: DLL loaded at 0x00007FFEECCF0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:55:10,181 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:55:10,181 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEC530000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 19:55:10,181 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE3AB0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 19:55:10,183 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDF7D0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 19:55:10,187 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:55:10,189 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDAFC0000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 19:55:10,189 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDF190000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:55:10,192 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE9A90000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 19:55:10,195 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDEC10000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 19:55:10,196 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE96E0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 19:55:10,196 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE3950000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 19:55:10,197 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE3BB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 19:55:10,201 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 19:55:10,202 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF440000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 19:55:10,209 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE8F40000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 19:55:10,210 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE8F60000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 19:55:10,211 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 19:55:10,212 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDEB40000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 19:55:10,213 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 19:55:10,226 [root] DEBUG: 3512: DLL loaded at 0x00007FFE99CC0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 19:55:10,281 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE2620000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 19:55:10,284 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 9120: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:10,287 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE0DA0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 19:55:10,289 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9120
2026-05-28 19:55:10,291 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9120
2026-05-28 19:55:10,295 [root] DEBUG: 3512: caller_dispatch: Added region at 0x00007FF60A060000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF60A157D66, thread 4744).
2026-05-28 19:55:10,300 [root] DEBUG: 3512: ProcessImageBase: Main module image at 0x00007FF60A060000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:55:10,302 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 8072: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:10,302 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 8072
2026-05-28 19:55:10,303 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 8072
2026-05-28 19:55:10,313 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 9180: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:10,313 [root] DEBUG: 3512: DLL loaded at 0x00007FFED7420000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 19:55:10,315 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9180
2026-05-28 19:55:10,316 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9180
2026-05-28 19:55:10,332 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF4A0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 19:55:10,348 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:55:10,348 [root] DEBUG: 3512: DLL loaded at 0x00007FFED6CB0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 19:55:10,355 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEDFD0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 19:55:10,357 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEBC70000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 19:55:10,358 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEC340000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 19:55:10,359 [root] DEBUG: 3512: DLL loaded at 0x00007FFED88A0000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 19:55:10,378 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE86A0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 19:55:10,392 [root] DEBUG: 3512: DLL loaded at 0x00007FFEED220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 19:55:10,398 [root] DEBUG: 3512: DLL loaded at 0x00007FFED8910000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 19:55:10,399 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 1048: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:10,400 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 972: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:10,401 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 1048
2026-05-28 19:55:10,405 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 972
2026-05-28 19:55:10,405 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 1048
2026-05-28 19:55:10,405 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE1330000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 19:55:10,406 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 972
2026-05-28 19:55:10,468 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 19:55:10,475 [root] DEBUG: 4372: caller_dispatch: Added region at 0x00007FF65F9E0000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF65FA499CA, thread 5632).
2026-05-28 19:55:10,475 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 19:55:10,501 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDCBB0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 19:55:10,506 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDFDE0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 19:55:10,507 [root] DEBUG: 4372: ProcessImageBase: Main module image at 0x00007FF65F9E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:55:10,512 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:55:10,520 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF210000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 19:55:10,522 [root] DEBUG: 3512: DLL loaded at 0x00007FFED9A80000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 19:55:10,523 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 19:55:10,525 [root] DEBUG: 4372: ProcessImageBase: Main module image at 0x00007FF65F9E0000 unmodified (entropy change 1.234764e-06)
2026-05-28 19:55:10,527 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 19:55:10,557 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE85F0000: C:\Windows\System32\aadWamExtension (0x36000 bytes).
2026-05-28 19:55:10,585 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDFA20000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 19:55:11,756 [root] DEBUG: 3512: DLL loaded at 0x00007FFED5C90000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:55:12,144 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:55:12,149 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:55:15,433 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 4596: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:15,442 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 4596
2026-05-28 19:55:15,444 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 4596
2026-05-28 19:55:15,464 [root] DEBUG: 3512: DLL loaded at 0x00007FFED8C50000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 19:55:15,507 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF0250000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 19:55:15,509 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEADC0000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 19:55:15,512 [root] DEBUG: 3512: DLL loaded at 0x00007FFE96BA0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 19:55:15,522 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 19:55:15,523 [root] DEBUG: 3512: DLL loaded at 0x00007FFE99850000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 19:55:15,526 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 19:55:15,533 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:55:15,536 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE330000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 19:55:15,538 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE2C0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 19:55:15,548 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE8480000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 19:55:15,552 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE59B0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 19:55:15,558 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 5624: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF6401A0000
2026-05-28 19:55:15,559 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 5624
2026-05-28 19:55:15,560 [root] DEBUG: 3512: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:55:15,560 [lib.api.process] INFO: Monitor config for process 5624: C:\_3mo6uuq\dll\5624.ini
2026-05-28 19:55:15,561 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:55:15,563 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:55:15,563 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:16,006 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:55:16,007 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:55:16,011 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:16,015 [root] DEBUG: Loader: Injecting process 5624 (thread 6172) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:16,016 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:55:16,017 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:16,018 [lib.api.process] INFO: Injected into 64-bit <Process 5624 identity_helper.exe>
2026-05-28 19:55:16,031 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE6C40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:55:16,037 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE0440000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 19:55:16,038 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 8212: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF6401A0000
2026-05-28 19:55:16,039 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8212
2026-05-28 19:55:16,039 [lib.api.process] INFO: Monitor config for process 8212: C:\_3mo6uuq\dll\8212.ini
2026-05-28 19:55:16,045 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:16,099 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE6BA0000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 19:55:16,107 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDFE80000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:55:16,107 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEA040000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 19:55:16,120 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:55:16,121 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:55:16,122 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:16,126 [root] DEBUG: Loader: Injecting process 8212 (thread 7312) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:16,127 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:55:16,127 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:16,129 [lib.api.process] INFO: Injected into 64-bit <Process 8212 identity_helper.exe>
2026-05-28 19:55:16,130 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8212
2026-05-28 19:55:16,131 [lib.api.process] INFO: Monitor config for process 8212: C:\_3mo6uuq\dll\8212.ini
2026-05-28 19:55:16,131 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:16,202 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 19:55:16,202 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 19:55:16,210 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:16,216 [root] DEBUG: Loader: Injecting process 8212 (thread 7312) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:16,217 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:55:16,217 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:16,218 [lib.api.process] INFO: Injected into 64-bit <Process 8212 identity_helper.exe>
2026-05-28 19:55:16,236 [root] DEBUG: 8212: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:55:16,237 [root] DEBUG: 8212: Interactive desktop enabled.
2026-05-28 19:55:16,237 [root] DEBUG: 8212: Dropped file limit defaulting to 100.
2026-05-28 19:55:16,244 [root] DEBUG: 8212: Disabling sleep skipping.
2026-05-28 19:55:16,245 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 19:55:16,245 [root] DEBUG: 8212: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:55:16,246 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 19:55:16,247 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 19:55:16,249 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE6DC0000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 19:55:16,250 [root] DEBUG: 3512: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 19:55:16,250 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE6C20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 19:55:16,251 [root] DEBUG: 3512: DLL loaded at 0x00007FFEDBC30000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 19:55:16,256 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEEDE0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 19:55:16,258 [root] DEBUG: 8212: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:55:16,258 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FF6401A0000, size 0x28b4d8
2026-05-28 19:55:16,277 [root] DEBUG: 8212: Monitor initialised: 64-bit capemon loaded in process 8212 at 0x00007FFEAF1A0000, thread 7312, image base 0x00007FF6401A0000, stack from 0x000000471B9C4000-0x000000471B9D0000
2026-05-28 19:55:16,277 [root] DEBUG: 8212: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5788,i,3782550250464517460,15688583949529781944,524288 --field-trial-handle=2328,i,13988907005621982619,15811277251529615185,262144 --variations-seed-version --pseudonymization-salt-handle=2348,i,13679356427538762278,130458462841030
2026-05-28 19:55:16,278 [root] DEBUG: 8212: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 19:55:16,288 [root] DEBUG: 8212: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 19:55:16,314 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:55:16,314 [root] DEBUG: 8212: set_hooks: Unable to hook LockResource
2026-05-28 19:55:16,322 [root] DEBUG: 8212: Hooked 627 out of 628 functions
2026-05-28 19:55:16,337 [root] DEBUG: 8212: Syscall hook installed, syscall logging level 1
2026-05-28 19:55:16,341 [root] DEBUG: 8212: RestoreHeaders: Restored original import table.
2026-05-28 19:55:16,342 [root] INFO: Loaded monitor into process with pid 8212
2026-05-28 19:55:16,343 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 19:55:16,398 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 19:55:16,422 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 19:55:16,448 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 19:55:16,476 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 19:55:16,500 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 19:55:16,524 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 19:55:16,551 [root] DEBUG: 8212: caller_dispatch: Added region at 0x00007FFEAECE0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFEAEEDF156, thread 7312).
2026-05-28 19:55:16,552 [root] DEBUG: 8212: caller_dispatch: Scanning calling region at 0x00007FFEAECE0000...
2026-05-28 19:55:16,556 [root] DEBUG: 8212: ProcessTrackedRegion: Region at 0x00007FFEAECE0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 19:55:16,557 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 19:55:16,582 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FF6401A0000, size 0x28b4d8
2026-05-28 19:55:16,597 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FF6401A0000, size 0x28b4d8
2026-05-28 19:55:16,612 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FF6401A0000, size 0x28b4d8
2026-05-28 19:55:16,627 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FF6401A0000, size 0x28b4d8
2026-05-28 19:55:16,642 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FF6401A0000, size 0x28b4d8
2026-05-28 19:55:16,657 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FF6401A0000, size 0x28b4d8
2026-05-28 19:55:16,674 [root] DEBUG: 8212: caller_dispatch: Added region at 0x00007FF6401A0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF640294096, thread 7312).
2026-05-28 19:55:16,675 [root] DEBUG: 8212: YaraScan: Scanning 0x00007FF6401A0000, size 0x28b4d8
2026-05-28 19:55:16,691 [root] DEBUG: 8212: ProcessImageBase: Main module image at 0x00007FF6401A0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:55:16,693 [root] DEBUG: 8212: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:55:16,714 [root] DEBUG: 8212: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 19:55:16,717 [root] DEBUG: 8212: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:55:16,720 [root] DEBUG: 8212: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:55:16,747 [root] DEBUG: 8212: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:55:16,753 [root] DEBUG: 8212: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:55:16,757 [root] DEBUG: 8212: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:55:16,757 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEB280000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 19:55:16,757 [root] DEBUG: 8212: DLL loaded at 0x00007FFEECCF0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 19:55:16,758 [root] DEBUG: 8212: DLL loaded at 0x00007FFEDCB10000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 19:55:16,769 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:55:16,771 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:55:16,772 [root] DEBUG: 8212: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:55:16,772 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:55:16,773 [root] DEBUG: 8212: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:55:16,781 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:55:16,791 [root] DEBUG: 8212: DLL loaded at 0x00007FFEDE2F0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 19:55:16,797 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 19:55:16,797 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 19:55:16,799 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:55:16,809 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:55:16,812 [root] DEBUG: 8212: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 19:55:16,819 [root] DEBUG: 8212: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 19:55:16,819 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE6C40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 19:55:16,821 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEF210000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 19:55:16,831 [root] DEBUG: 8212: DLL loaded at 0x00007FFEDFE80000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 19:55:16,838 [root] DEBUG: 8212: DLL loaded at 0x0000022E9C7F0000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 19:55:16,845 [lib.api.process] INFO: Monitor config for process 848: C:\_3mo6uuq\dll\848.ini
2026-05-28 19:55:16,846 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:16,846 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:16,850 [root] DEBUG: Loader: Injecting process 848 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:16,852 [root] DEBUG: 848: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:55:16,852 [root] DEBUG: 848: Disabling sleep skipping.
2026-05-28 19:55:16,853 [root] DEBUG: 848: Interactive desktop enabled.
2026-05-28 19:55:16,853 [root] DEBUG: 848: Dropped file limit defaulting to 100.
2026-05-28 19:55:16,854 [root] DEBUG: 848: Services hook set enabled
2026-05-28 19:55:16,855 [root] DEBUG: 848: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:55:16,866 [root] DEBUG: 848: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:55:16,867 [root] DEBUG: 848: Monitor initialised: 64-bit capemon loaded in process 848 at 0x00007FFEAF1A0000, thread 9252, image base 0x00007FF6A8D80000, stack from 0x0000006A4DD74000-0x0000006A4DD80000
2026-05-28 19:55:16,867 [root] DEBUG: 848: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 19:55:16,879 [root] DEBUG: 848: Hooked 69 out of 69 functions
2026-05-28 19:55:16,880 [root] INFO: Loaded monitor into process with pid 848
2026-05-28 19:55:16,880 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:55:16,880 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:16,882 [lib.api.process] INFO: Injected into 64-bit <Process 848 svchost.exe>
2026-05-28 19:55:18,898 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE5370000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 19:55:18,899 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE4650000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 19:55:18,900 [root] DEBUG: 8212: DLL loaded at 0x00007FFEDAE80000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 19:55:18,901 [root] DEBUG: 8212: DLL loaded at 0x00007FFED4AB0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 19:55:18,910 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE9FE0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 19:55:18,936 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEDFD0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 19:55:18,937 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEBC70000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 19:55:19,357 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE1590000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 19:55:19,358 [root] DEBUG: 8212: DLL loaded at 0x00007FFED4800000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 19:55:19,374 [root] DEBUG: 8212: DLL loaded at 0x00007FFED5E10000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 19:55:19,393 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 19:55:19,394 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEF080000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 19:55:19,394 [root] DEBUG: 8212: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 19:55:19,394 [root] DEBUG: 8212: DLL loaded at 0x00007FFEE4250000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 19:55:19,395 [root] DEBUG: 8212: DLL loaded at 0x00007FFEDA8F0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 19:55:19,414 [root] DEBUG: 8212: DLL loaded at 0x00007FFED4BF0000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 19:55:19,431 [root] DEBUG: 8212: DLL loaded at 0x00007FFEDF190000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 19:55:19,458 [root] DEBUG: 8212: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 19:55:29,555 [root] INFO: Process with pid 8212 has terminated
2026-05-28 19:55:29,560 [root] DEBUG: 8212: NtTerminateProcess hook: Attempting to dump process 8212
2026-05-28 19:55:29,565 [root] DEBUG: 8212: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:55:37,307 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 9580: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:37,308 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9580
2026-05-28 19:55:37,309 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9580
2026-05-28 19:55:38,333 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 9692: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:38,333 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9692
2026-05-28 19:55:38,334 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9692
2026-05-28 19:55:40,124 [root] DEBUG: 3512: DLL loaded at 0x00007FFEE6130000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 19:55:40,214 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 9812: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:55:40,215 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9812
2026-05-28 19:55:40,216 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 9812
2026-05-28 19:55:41,927 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9908: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF65CEB0000
2026-05-28 19:55:41,928 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9908
2026-05-28 19:55:41,929 [lib.api.process] INFO: Monitor config for process 9908: C:\_3mo6uuq\dll\9908.ini
2026-05-28 19:55:41,930 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:41,930 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:41,935 [root] DEBUG: Loader: Injecting process 9908 (thread 9912) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,935 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:55:41,936 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,937 [lib.api.process] INFO: Injected into 64-bit <Process 9908 backgroundTaskHost.exe>
2026-05-28 19:55:41,938 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9908
2026-05-28 19:55:41,938 [lib.api.process] INFO: Monitor config for process 9908: C:\_3mo6uuq\dll\9908.ini
2026-05-28 19:55:41,938 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9980: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF65CEB0000
2026-05-28 19:55:41,939 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:41,939 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9980
2026-05-28 19:55:41,939 [lib.api.process] INFO: Monitor config for process 9980: C:\_3mo6uuq\dll\9980.ini
2026-05-28 19:55:41,940 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:41,940 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:41,941 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:41,944 [root] DEBUG: Loader: Injecting process 9908 (thread 9912) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,945 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:55:41,945 [root] DEBUG: Loader: Injecting process 9980 (thread 9984) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,945 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,945 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:55:41,946 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,946 [lib.api.process] INFO: Injected into 64-bit <Process 9908 backgroundTaskHost.exe>
2026-05-28 19:55:41,947 [lib.api.process] INFO: Injected into 64-bit <Process 9980 backgroundTaskHost.exe>
2026-05-28 19:55:41,947 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9908
2026-05-28 19:55:41,949 [lib.api.process] INFO: Monitor config for process 9908: C:\_3mo6uuq\dll\9908.ini
2026-05-28 19:55:41,949 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:41,949 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9980
2026-05-28 19:55:41,950 [lib.api.process] INFO: Monitor config for process 9980: C:\_3mo6uuq\dll\9980.ini
2026-05-28 19:55:41,950 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:41,950 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:41,951 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:41,955 [root] DEBUG: Loader: Injecting process 9980 (thread 9984) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,956 [root] DEBUG: Loader: Injecting process 9908 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,956 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:55:41,956 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9912, handle 0x120
2026-05-28 19:55:41,957 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,957 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:55:41,958 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,958 [lib.api.process] INFO: Injected into 64-bit <Process 9980 backgroundTaskHost.exe>
2026-05-28 19:55:41,959 [lib.api.process] INFO: Injected into 64-bit <Process 9908 backgroundTaskHost.exe>
2026-05-28 19:55:41,959 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9980
2026-05-28 19:55:41,959 [lib.api.process] INFO: Monitor config for process 9980: C:\_3mo6uuq\dll\9980.ini
2026-05-28 19:55:41,960 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:55:41,961 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:55:41,966 [root] DEBUG: Loader: Injecting process 9980 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,967 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9984, handle 0x120
2026-05-28 19:55:41,967 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:55:41,967 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:55:41,969 [lib.api.process] INFO: Injected into 64-bit <Process 9980 backgroundTaskHost.exe>
2026-05-28 19:56:02,763 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9468: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 19:56:02,764 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9468
2026-05-28 19:56:02,765 [lib.api.process] INFO: Monitor config for process 9468: C:\_3mo6uuq\dll\9468.ini
2026-05-28 19:56:02,766 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:56:02,766 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:56:02,771 [root] DEBUG: Loader: Injecting process 9468 (thread 8224) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:02,772 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:56:02,772 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:02,774 [lib.api.process] INFO: Injected into 64-bit <Process 9468 dllhost.exe>
2026-05-28 19:56:02,775 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9468
2026-05-28 19:56:02,775 [lib.api.process] INFO: Monitor config for process 9468: C:\_3mo6uuq\dll\9468.ini
2026-05-28 19:56:02,775 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:56:02,776 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:56:02,781 [root] DEBUG: Loader: Injecting process 9468 (thread 8224) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:02,781 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:56:02,782 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:02,783 [lib.api.process] INFO: Injected into 64-bit <Process 9468 dllhost.exe>
2026-05-28 19:56:02,793 [root] DEBUG: 9468: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:56:02,793 [root] DEBUG: 9468: Interactive desktop enabled.
2026-05-28 19:56:02,794 [root] DEBUG: 9468: Dropped file limit defaulting to 100.
2026-05-28 19:56:02,797 [root] DEBUG: 9468: Disabling sleep skipping.
2026-05-28 19:56:02,798 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 7412: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7D5630000
2026-05-28 19:56:02,798 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 7412
2026-05-28 19:56:02,798 [root] DEBUG: 9468: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:56:02,799 [lib.api.process] INFO: Monitor config for process 7412: C:\_3mo6uuq\dll\7412.ini
2026-05-28 19:56:02,799 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:56:02,810 [root] DEBUG: 9468: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:56:02,810 [root] DEBUG: 9468: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 19:56:02,812 [root] DEBUG: 9468: Monitor initialised: 64-bit capemon loaded in process 9468 at 0x00007FFEAF1A0000, thread 8224, image base 0x00007FF6868D0000, stack from 0x00000064E8AF4000-0x00000064E8B00000
2026-05-28 19:56:02,812 [root] DEBUG: 9468: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 19:56:02,822 [root] DEBUG: 9468: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 19:56:02,843 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:56:02,844 [root] DEBUG: 9468: set_hooks: Unable to hook LockResource
2026-05-28 19:56:02,848 [root] DEBUG: 9468: Hooked 627 out of 628 functions
2026-05-28 19:56:02,849 [root] DEBUG: 9468: Syscall hook installed, syscall logging level 1
2026-05-28 19:56:02,853 [root] DEBUG: 9468: RestoreHeaders: Restored original import table.
2026-05-28 19:56:02,854 [root] INFO: Loaded monitor into process with pid 9468
2026-05-28 19:56:02,854 [root] DEBUG: 9468: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 8224).
2026-05-28 19:56:02,855 [root] DEBUG: 9468: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 19:56:02,856 [root] DEBUG: 9468: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:56:02,858 [root] DEBUG: 9468: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:56:02,859 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:56:02,861 [root] DEBUG: 9468: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:56:02,874 [root] DEBUG: 9468: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:56:02,893 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 19:56:02,893 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 19:56:02,894 [root] DEBUG: 9468: DLL loaded at 0x00007FFEE8D30000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 19:56:02,896 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 19:56:02,897 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:56:02,897 [root] DEBUG: 9468: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:56:02,898 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 19:56:02,898 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 19:56:02,899 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEF640000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 19:56:02,899 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEB240000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 19:56:02,900 [root] DEBUG: 9468: DLL loaded at 0x00007FFEEEB10000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 19:56:02,901 [root] DEBUG: 9468: DLL loaded at 0x00007FFE96F10000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 19:56:02,903 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:56:02,908 [root] DEBUG: Loader: Injecting process 7412 (thread 9524) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:02,908 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:56:02,909 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:02,909 [root] DEBUG: 9468: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 19:56:02,910 [lib.api.process] INFO: Injected into 64-bit <Process 7412 WmiPrvSE.exe>
2026-05-28 19:56:02,911 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 7412
2026-05-28 19:56:02,911 [lib.api.process] INFO: Monitor config for process 7412: C:\_3mo6uuq\dll\7412.ini
2026-05-28 19:56:02,911 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:56:02,916 [root] DEBUG: 9468: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 19:56:02,988 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:56:02,992 [root] DEBUG: Loader: Injecting process 7412 (thread 9524) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:02,993 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:56:02,993 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:02,994 [lib.api.process] INFO: Injected into 64-bit <Process 7412 WmiPrvSE.exe>
2026-05-28 19:56:03,000 [root] DEBUG: 7412: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:56:03,001 [root] DEBUG: 7412: Interactive desktop enabled.
2026-05-28 19:56:03,001 [root] DEBUG: 7412: Dropped file limit defaulting to 100.
2026-05-28 19:56:03,003 [root] DEBUG: 7412: Disabling sleep skipping.
2026-05-28 19:56:03,004 [root] DEBUG: 7412: Services hook set enabled
2026-05-28 19:56:03,005 [root] DEBUG: 7412: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:56:03,017 [root] DEBUG: 7412: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:56:03,017 [root] DEBUG: 7412: Monitor initialised: 64-bit capemon loaded in process 7412 at 0x00007FFEAF1A0000, thread 9524, image base 0x00007FF7D5630000, stack from 0x000000CA6B470000-0x000000CA6B480000
2026-05-28 19:56:03,018 [root] DEBUG: 7412: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 19:56:03,029 [root] DEBUG: 7412: Hooked 69 out of 69 functions
2026-05-28 19:56:03,032 [root] DEBUG: 7412: RestoreHeaders: Restored original import table.
2026-05-28 19:56:03,032 [root] INFO: Loaded monitor into process with pid 7412
2026-05-28 19:56:03,035 [root] DEBUG: 7412: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:56:03,036 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:56:03,037 [root] DEBUG: 7412: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:56:03,039 [lib.api.process] INFO: Monitor config for process 7348: C:\_3mo6uuq\dll\7348.ini
2026-05-28 19:56:03,040 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:56:03,041 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:56:03,045 [root] DEBUG: Loader: Injecting process 7348 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:03,047 [root] DEBUG: 7348: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:56:03,047 [root] DEBUG: 7348: Disabling sleep skipping.
2026-05-28 19:56:03,047 [root] DEBUG: 7348: Interactive desktop enabled.
2026-05-28 19:56:03,048 [root] DEBUG: 7348: Dropped file limit defaulting to 100.
2026-05-28 19:56:03,048 [root] DEBUG: 7348: Services hook set enabled
2026-05-28 19:56:03,049 [root] DEBUG: 7348: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:56:03,060 [root] DEBUG: 7348: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:56:03,061 [root] DEBUG: 7348: Monitor initialised: 64-bit capemon loaded in process 7348 at 0x00007FFEAF1A0000, thread 8280, image base 0x00007FF6A8D80000, stack from 0x0000002A13B74000-0x0000002A13B80000
2026-05-28 19:56:03,061 [root] DEBUG: 7348: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 19:56:03,072 [root] DEBUG: 7348: Hooked 69 out of 69 functions
2026-05-28 19:56:03,073 [root] INFO: Loaded monitor into process with pid 7348
2026-05-28 19:56:03,074 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 19:56:03,074 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:56:03,076 [lib.api.process] INFO: Injected into 64-bit <Process 7348 svchost.exe>
2026-05-28 19:56:04,686 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 1360: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:56:04,687 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 1360
2026-05-28 19:56:04,687 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 1360
2026-05-28 19:56:05,089 [root] DEBUG: 7412: DLL loaded at 0x00007FFEDD9B0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 19:56:05,092 [root] DEBUG: 7412: DLL loaded at 0x00007FFED9650000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 19:56:05,099 [root] DEBUG: 7412: DLL loaded at 0x00007FFED9620000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 19:56:05,106 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 19:56:05,106 [root] DEBUG: 7412: DLL loaded at 0x00007FFE959F0000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 19:56:05,107 [root] DEBUG: 7412: DLL loaded at 0x00007FFE95A50000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 19:56:05,108 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 19:56:05,114 [root] DEBUG: 7412: DLL loaded at 0x0000029C7F6F0000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 19:56:05,115 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEA840000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 19:56:05,116 [root] DEBUG: 7412: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 19:56:07,933 [root] INFO: Process with pid 9468 has terminated
2026-05-28 19:56:07,934 [root] DEBUG: 9468: NtTerminateProcess hook: Attempting to dump process 9468
2026-05-28 19:56:07,934 [root] DEBUG: 9468: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:56:09,099 [root] DEBUG: 4372: DLL loaded at 0x00007FFE96F60000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 19:56:09,102 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE1490000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 19:56:09,109 [root] DEBUG: 4372: DLL loaded at 0x00007FFEB2550000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 19:56:09,110 [root] DEBUG: 4372: DLL loaded at 0x00007FFE96F40000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 19:56:09,121 [root] DEBUG: 4372: DLL loaded at 0x00007FFE959F0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 19:56:09,121 [root] DEBUG: 4372: DLL loaded at 0x00007FFEED410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 19:56:09,122 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95910000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 19:56:09,127 [root] DEBUG: 4372: DLL loaded at 0x00007FFE96F20000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 19:56:09,132 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95820000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 19:56:10,199 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 19:56:10,201 [root] DEBUG: 3512: DLL loaded at 0x00007FFEEE250000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-28 19:56:10,203 [root] DEBUG: 3512: DLL loaded at 0x00007FFED5C00000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-28 19:56:10,215 [root] DEBUG: 3512: DLL loaded at 0x00007FFED5BE0000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 19:56:10,324 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 10628: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:56:10,325 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 10628
2026-05-28 19:56:10,326 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 10628
2026-05-28 19:56:10,410 [root] DEBUG: 3512: DLL loaded at 0x00007FFED5210000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-28 19:56:11,205 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 10836: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:56:11,206 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 10836
2026-05-28 19:56:11,209 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 10836
2026-05-28 19:56:56,029 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 2464: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:56:56,031 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 2464
2026-05-28 19:56:56,032 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 2464
2026-05-28 19:57:02,321 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 19:57:02,322 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEF440000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 19:57:02,324 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 19:57:02,324 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 19:57:02,325 [root] DEBUG: 7412: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 19:57:02,326 [root] DEBUG: 7412: DLL loaded at 0x00007FFEE6180000: C:\Windows\SYSTEM32\SAMCLI (0x19000 bytes).
2026-05-28 19:57:02,327 [root] DEBUG: 7412: DLL loaded at 0x00007FFEE61A0000: C:\Windows\SYSTEM32\SRVCLI (0x28000 bytes).
2026-05-28 19:57:02,328 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-28 19:57:02,329 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\SYSTEM32\LOGONCLI (0x43000 bytes).
2026-05-28 19:57:02,330 [root] DEBUG: 7412: DLL loaded at 0x00007FFEE6100000: C:\Windows\SYSTEM32\SCHEDCLI (0xc000 bytes).
2026-05-28 19:57:02,331 [root] DEBUG: 7412: DLL loaded at 0x00007FFEEE870000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-28 19:57:02,332 [root] DEBUG: 7412: DLL loaded at 0x00007FFEED1A0000: C:\Windows\SYSTEM32\DSROLE (0xa000 bytes).
2026-05-28 19:57:10,214 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 1724: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:57:10,215 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 1724
2026-05-28 19:57:10,216 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 1724
2026-05-28 19:57:42,109 [root] DEBUG: 3512: CreateProcessHandler: Injection info set for new process 4272: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 19:57:42,110 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 4272
2026-05-28 19:57:42,111 [root] DEBUG: 3512: ProcessMessage: Skipping monitoring process 4272
2026-05-28 19:57:42,293 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 19:57:42,295 [lib.api.process] INFO: Monitor config for process 708: C:\_3mo6uuq\dll\708.ini
2026-05-28 19:57:42,302 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:57:42,305 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:57:42,315 [root] DEBUG: Loader: Injecting process 708 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:57:42,318 [root] DEBUG: Loader: Copied config file C:\_3mo6uuq\dll\708.ini to system path C:\708.ini
2026-05-28 19:57:42,322 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 708 C:\_3mo6uuq\dll\ogDVTOPr.dll
2026-05-28 19:57:42,332 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:57:42,337 [lib.api.process] INFO: Injected into 64-bit <Process 708 services.exe>
2026-05-28 19:57:42,453 [root] INFO: Process with pid 3512 appears to have terminated
2026-05-28 19:57:56,738 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE85F0000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 19:57:56,791 [lib.api.process] INFO: Monitor config for process 4372: C:\_3mo6uuq\dll\4372.ini
2026-05-28 19:57:56,792 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:57:56,795 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:57:56,799 [root] DEBUG: Loader: Injecting process 4372 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:57:56,800 [root] DEBUG: 4372: caller_dispatch: Added region at 0x0000000000710000 to tracked regions list (ntdll::LdrLoadDll returns to 0x0000000000710044, thread 1752).
2026-05-28 19:57:56,801 [root] DEBUG: 4372: DumpPEsInRange: Scanning range 0x0000000000710000 - 0x0000000000710135.
2026-05-28 19:57:56,801 [root] DEBUG: 4372: ScanForDisguisedPE: Size too small: 0x135 bytes
2026-05-28 19:57:56,806 [lib.common.results] INFO: Uploading file C:\VuqQjay\CAPE\4372_3284156572328452026 to CAPE\4180f878de3160504965bec3a0117d2335648664adb213397ac5b41c929f3ceb; Size is 309; Max size: 100000000
2026-05-28 19:57:56,808 [root] DEBUG: 4372: DumpMemory: Payload successfully created: C:\VuqQjay\CAPE\4372_3284156572328452026 (size 309 bytes)
2026-05-28 19:57:56,808 [root] DEBUG: 4372: DumpRegion: Dumped entire allocation from 0x0000000000710000, size 4096 bytes.
2026-05-28 19:57:56,809 [root] DEBUG: 4372: ProcessTrackedRegion: Dumped region at 0x0000000000710000.
2026-05-28 19:57:56,809 [root] DEBUG: 4372: YaraScan: Scanning 0x0000000000710000, size 0x135
2026-05-28 19:57:56,811 [root] DEBUG: 4372: Monitor config - unrecognised key host-ip.
2026-05-28 19:57:56,812 [root] DEBUG: 4372: Monitor config - unrecognised key host-port.
2026-05-28 19:57:56,812 [root] DEBUG: 4372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:57:56,813 [root] DEBUG: 4372: Dropped file limit defaulting to 100.
2026-05-28 19:57:56,830 [root] DEBUG: 4372: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 19:57:56,873 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:57:56,874 [root] DEBUG: 4372: set_hooks: Unable to hook LockResource
2026-05-28 19:57:56,896 [root] DEBUG: 4372: Hooked 627 out of 628 functions
2026-05-28 19:57:56,926 [root] INFO: Loaded monitor into process with pid 4372
2026-05-28 19:57:56,930 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 19:57:56,930 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:57:57,495 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:57:57,496 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6220, handle 0x1ad8: Error obtaining target process name
2026-05-28 19:57:57,497 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:57:57,497 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 8780, handle 0x17bc: Error obtaining target process name
2026-05-28 19:57:57,498 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:57:57,499 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6028, handle 0x21f0: Error obtaining target process name
2026-05-28 19:57:57,499 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:57:57,500 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6632, handle 0x21e8: Error obtaining target process name
2026-05-28 19:57:57,501 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:57:57,502 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 7448, handle 0x1308: Error obtaining target process name
2026-05-28 19:57:58,992 [root] DEBUG: 4372: DLL loaded at 0x00007FFE96540000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 19:57:58,993 [root] DEBUG: 4372: DLL loaded at 0x00007FFE96540000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 19:57:59,020 [root] DEBUG: 4372: DLL loaded at 0x00007FFED52A0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 19:57:59,021 [root] DEBUG: 4372: DLL loaded at 0x00007FFED52A0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 19:57:59,108 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFF70000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:57:59,109 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFF70000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 19:57:59,117 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE41B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 19:57:59,118 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE41B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 19:57:59,131 [root] DEBUG: 4372: DLL loaded at 0x00007FFED51F0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:57:59,132 [root] DEBUG: 4372: DLL loaded at 0x00007FFED51F0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 19:57:59,183 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5BD0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 19:57:59,184 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5BD0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 19:57:59,187 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 19:57:59,189 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95430000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:57:59,189 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95430000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 19:57:59,299 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 19:57:59,652 [root] DEBUG: 4372: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 19:57:59,654 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4610000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 19:57:59,655 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4610000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 19:57:59,777 [root] DEBUG: 4372: api-rate-cap: IsDebuggerPresent hook disabled due to rate
2026-05-28 19:57:59,826 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8610000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 19:57:59,827 [root] DEBUG: 4372: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 19:57:59,829 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8610000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 19:57:59,863 [root] DEBUG: 4372: DLL loaded at 0x00007FFED8180000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 19:57:59,864 [root] DEBUG: 4372: DLL loaded at 0x00007FFED8180000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 19:58:00,071 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 4616: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 19:58:00,072 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4616
2026-05-28 19:58:00,074 [lib.api.process] INFO: Monitor config for process 4616: C:\_3mo6uuq\dll\4616.ini
2026-05-28 19:58:00,078 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:00,083 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:00,089 [root] DEBUG: Loader: Injecting process 4616 (thread 2484) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:00,091 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:00,092 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:00,093 [lib.api.process] INFO: Injected into 64-bit <Process 4616 dllhost.exe>
2026-05-28 19:58:00,095 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4616
2026-05-28 19:58:00,096 [lib.api.process] INFO: Monitor config for process 4616: C:\_3mo6uuq\dll\4616.ini
2026-05-28 19:58:00,096 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:00,099 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:00,107 [root] DEBUG: Loader: Injecting process 4616 (thread 2484) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:00,108 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:00,109 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:00,110 [lib.api.process] INFO: Injected into 64-bit <Process 4616 dllhost.exe>
2026-05-28 19:58:00,117 [root] DEBUG: 4616: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:58:00,118 [root] DEBUG: 4616: Interactive desktop enabled.
2026-05-28 19:58:00,119 [root] DEBUG: 4616: Dropped file limit defaulting to 100.
2026-05-28 19:58:00,122 [root] DEBUG: 4616: Disabling sleep skipping.
2026-05-28 19:58:00,123 [root] DEBUG: 4616: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:58:00,135 [root] DEBUG: 4616: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:58:00,136 [root] DEBUG: 4616: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 19:58:00,137 [root] DEBUG: 4616: Monitor initialised: 64-bit capemon loaded in process 4616 at 0x00007FFEAF1A0000, thread 2484, image base 0x00007FF6868D0000, stack from 0x0000000A454F4000-0x0000000A45500000
2026-05-28 19:58:00,138 [root] DEBUG: 4616: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:58:00,147 [root] DEBUG: 4616: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 19:58:00,168 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:58:00,168 [root] DEBUG: 4616: set_hooks: Unable to hook LockResource
2026-05-28 19:58:00,173 [root] DEBUG: 4616: Hooked 627 out of 628 functions
2026-05-28 19:58:00,174 [root] DEBUG: 4616: Syscall hook installed, syscall logging level 1
2026-05-28 19:58:00,179 [root] DEBUG: 4616: RestoreHeaders: Restored original import table.
2026-05-28 19:58:00,179 [root] INFO: Loaded monitor into process with pid 4616
2026-05-28 19:58:00,180 [root] DEBUG: 4616: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12C5, thread 2484).
2026-05-28 19:58:00,181 [root] DEBUG: 4616: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 19:58:00,182 [root] DEBUG: 4616: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:58:00,184 [root] DEBUG: 4616: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:58:00,185 [root] DEBUG: 4616: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:58:00,188 [root] DEBUG: 4616: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:58:00,206 [root] DEBUG: 4616: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:58:00,220 [root] DEBUG: 4616: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:58:00,221 [root] DEBUG: 4616: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:58:00,227 [root] DEBUG: 4616: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:58:01,379 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 11652: C:\Windows\System32\rundll32.exe, ImageBase: 0x00007FF6C5DC0000
2026-05-28 19:58:01,380 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 11652
2026-05-28 19:58:01,380 [lib.api.process] INFO: Monitor config for process 11652: C:\_3mo6uuq\dll\11652.ini
2026-05-28 19:58:01,382 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:01,383 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:01,387 [root] DEBUG: Loader: Injecting process 11652 (thread 11656) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:01,388 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:01,388 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:01,389 [lib.api.process] INFO: Injected into 64-bit <Process 11652 rundll32.exe>
2026-05-28 19:58:01,390 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 11652
2026-05-28 19:58:01,391 [lib.api.process] INFO: Monitor config for process 11652: C:\_3mo6uuq\dll\11652.ini
2026-05-28 19:58:01,391 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:01,393 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:01,398 [root] DEBUG: Loader: Injecting process 11652 (thread 11656) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:01,398 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:58:01,399 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:01,400 [lib.api.process] INFO: Injected into 64-bit <Process 11652 rundll32.exe>
2026-05-28 19:58:01,406 [root] DEBUG: 11652: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:58:01,406 [root] DEBUG: 11652: Interactive desktop enabled.
2026-05-28 19:58:01,407 [root] DEBUG: 11652: Dropped file limit defaulting to 100.
2026-05-28 19:58:01,409 [root] DEBUG: 11652: Disabling sleep skipping.
2026-05-28 19:58:01,410 [root] DEBUG: 11652: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:58:01,421 [root] DEBUG: 11652: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:58:01,421 [root] DEBUG: 11652: YaraScan: Scanning 0x00007FF6C5DC0000, size 0x16100
2026-05-28 19:58:01,422 [root] DEBUG: 11652: Monitor initialised: 64-bit capemon loaded in process 11652 at 0x00007FFEAF1A0000, thread 11656, image base 0x00007FF6C5DC0000, stack from 0x0000001B59874000-0x0000001B59880000
2026-05-28 19:58:01,423 [root] DEBUG: 11652: Commandline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
2026-05-28 19:58:01,431 [root] DEBUG: 11652: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 19:58:01,452 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:58:01,453 [root] DEBUG: 11652: set_hooks: Unable to hook LockResource
2026-05-28 19:58:01,459 [root] DEBUG: 11652: Hooked 627 out of 628 functions
2026-05-28 19:58:01,460 [root] DEBUG: 11652: Syscall hook installed, syscall logging level 1
2026-05-28 19:58:01,465 [root] DEBUG: 11652: RestoreHeaders: Restored original import table.
2026-05-28 19:58:01,465 [root] INFO: Loaded monitor into process with pid 11652
2026-05-28 19:58:01,466 [root] DEBUG: 11652: caller_dispatch: Added region at 0x00007FF6C5DC0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6C5DC6D01, thread 11656).
2026-05-28 19:58:01,467 [root] DEBUG: 11652: YaraScan: Scanning 0x00007FF6C5DC0000, size 0x16100
2026-05-28 19:58:01,468 [root] DEBUG: 11652: ProcessImageBase: Main module image at 0x00007FF6C5DC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:58:01,472 [root] DEBUG: 11652: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:58:01,475 [root] DEBUG: 11652: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 19:58:01,476 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 11652, handle 0x26c4: C:\Windows\System32\rundll32.exe
2026-05-28 19:58:01,479 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5160000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 19:58:01,480 [root] DEBUG: 4372: DLL loaded at 0x00007FFED5160000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 19:58:01,491 [root] DEBUG: 11652: NtTerminateProcess hook: Attempting to dump process 11652
2026-05-28 19:58:01,491 [root] DEBUG: 11652: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:58:01,501 [root] INFO: Process with pid 11652 has terminated
2026-05-28 19:58:02,721 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE40A0000: C:\Windows\System32\smartscreenps (0x52000 bytes).
2026-05-28 19:58:02,722 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE40A0000: C:\Windows\System32\smartscreenps (0x52000 bytes).
2026-05-28 19:58:03,639 [root] DEBUG: 7412: NtTerminateProcess hook: Attempting to dump process 7412
2026-05-28 19:58:03,640 [root] DEBUG: 7412: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:58:03,642 [root] INFO: Process with pid 7412 has terminated
2026-05-28 19:58:03,668 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDEB00000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 19:58:03,669 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDEB00000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 19:58:03,685 [root] DEBUG: 4372: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49C5C1000, size: 0x1000.
2026-05-28 19:58:03,688 [root] DEBUG: 4372: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49C5B1000, size: 0x1000.
2026-05-28 19:58:03,688 [root] DEBUG: 4372: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49C5A1000, size: 0x1000.
2026-05-28 19:58:03,690 [root] DEBUG: 4372: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49C591000, size: 0x1000.
2026-05-28 19:58:03,707 [root] DEBUG: 4372: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49C581000, size: 0x1000.
2026-05-28 19:58:03,719 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8480000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 19:58:03,720 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8480000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 19:58:03,729 [root] DEBUG: 4372: DLL loaded at 0x00007FFEEC890000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 19:58:03,734 [root] DEBUG: 4372: DLL loaded at 0x00007FFEEC890000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 19:58:03,748 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12172: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF6B0370000
2026-05-28 19:58:03,750 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12180: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF739760000
2026-05-28 19:58:03,751 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 12172
2026-05-28 19:58:03,752 [lib.api.process] INFO: Monitor config for process 12172: C:\_3mo6uuq\dll\12172.ini
2026-05-28 19:58:03,752 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 12180
2026-05-28 19:58:03,753 [lib.api.process] INFO: Monitor config for process 12180: C:\_3mo6uuq\dll\12180.ini
2026-05-28 19:58:03,753 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:03,754 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:03,757 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:03,759 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:03,764 [root] DEBUG: Loader: Injecting process 12180 (thread 12184) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,765 [root] DEBUG: Loader: Injecting process 12172 (thread 12176) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,765 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:03,766 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,766 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:03,767 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,767 [lib.api.process] INFO: Injected into 64-bit <Process 12180 SecurityHealthHost.exe>
2026-05-28 19:58:03,769 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 12180
2026-05-28 19:58:03,769 [lib.api.process] INFO: Injected into 64-bit <Process 12172 CHXSmartScreen.exe>
2026-05-28 19:58:03,770 [lib.api.process] INFO: Monitor config for process 12180: C:\_3mo6uuq\dll\12180.ini
2026-05-28 19:58:03,770 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:03,771 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 12172
2026-05-28 19:58:03,772 [lib.api.process] INFO: Monitor config for process 12172: C:\_3mo6uuq\dll\12172.ini
2026-05-28 19:58:03,772 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:03,774 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:03,776 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:03,779 [root] DEBUG: Loader: Injecting process 12180 (thread 12184) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,780 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:58:03,781 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,782 [root] DEBUG: Loader: Injecting process 12172 (thread 12176) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,783 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:03,783 [lib.api.process] INFO: Injected into 64-bit <Process 12180 SecurityHealthHost.exe>
2026-05-28 19:58:03,783 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,785 [lib.api.process] INFO: Injected into 64-bit <Process 12172 CHXSmartScreen.exe>
2026-05-28 19:58:03,786 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 12172
2026-05-28 19:58:03,787 [lib.api.process] INFO: Monitor config for process 12172: C:\_3mo6uuq\dll\12172.ini
2026-05-28 19:58:03,787 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:03,790 [root] DEBUG: 12180: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:58:03,790 [root] DEBUG: 12180: Interactive desktop enabled.
2026-05-28 19:58:03,791 [root] DEBUG: 12180: Dropped file limit defaulting to 100.
2026-05-28 19:58:03,791 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:03,794 [root] DEBUG: 12180: Disabling sleep skipping.
2026-05-28 19:58:03,795 [root] DEBUG: 12180: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:58:03,797 [root] DEBUG: Loader: Injecting process 12172 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,798 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12176, handle 0x100
2026-05-28 19:58:03,798 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:58:03,799 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:03,800 [lib.api.process] INFO: Injected into 64-bit <Process 12172 CHXSmartScreen.exe>
2026-05-28 19:58:03,809 [root] DEBUG: 12180: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:58:03,810 [root] DEBUG: 12180: YaraScan: Scanning 0x00007FF739760000, size 0x19174
2026-05-28 19:58:03,812 [root] DEBUG: 12180: Monitor initialised: 64-bit capemon loaded in process 12180 at 0x00007FFEAF1A0000, thread 12184, image base 0x00007FF739760000, stack from 0x00000008BE544000-0x00000008BE550000
2026-05-28 19:58:03,815 [root] DEBUG: 12180: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-28 19:58:03,827 [root] DEBUG: 12180: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 19:58:03,843 [root] DEBUG: 4372: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 19:58:03,849 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:58:03,850 [root] DEBUG: 12180: set_hooks: Unable to hook LockResource
2026-05-28 19:58:03,858 [root] DEBUG: 12180: Hooked 627 out of 628 functions
2026-05-28 19:58:03,860 [root] DEBUG: 12180: Syscall hook installed, syscall logging level 1
2026-05-28 19:58:03,864 [root] DEBUG: 12180: RestoreHeaders: Restored original import table.
2026-05-28 19:58:03,865 [root] INFO: Loaded monitor into process with pid 12180
2026-05-28 19:58:03,866 [root] DEBUG: 12180: caller_dispatch: Added region at 0x00007FF739760000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF73976D3B2, thread 12184).
2026-05-28 19:58:03,867 [root] DEBUG: 12180: YaraScan: Scanning 0x00007FF739760000, size 0x19174
2026-05-28 19:58:03,868 [root] DEBUG: 12180: ProcessImageBase: Main module image at 0x00007FF739760000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:58:03,873 [root] DEBUG: 12180: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:58:03,875 [root] DEBUG: 12180: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:58:03,877 [root] DEBUG: 12180: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:58:03,905 [root] DEBUG: 12180: DLL loaded at 0x00007FFEEF080000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 19:58:03,906 [root] DEBUG: 12180: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 19:58:03,907 [root] DEBUG: 12180: DLL loaded at 0x00007FFED4C60000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-28 19:58:03,914 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 12156, handle 0x27c0: C:\Windows\System32\rundll32.exe
2026-05-28 19:58:03,934 [root] DEBUG: 12180: DLL loaded at 0x00007FFEEC890000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 19:58:03,937 [root] DEBUG: 12180: DLL loaded at 0x00007FFEEAA90000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 19:58:03,944 [root] DEBUG: 12180: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:58:03,945 [root] DEBUG: 12180: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 19:58:03,946 [root] DEBUG: 12180: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 19:58:03,947 [root] DEBUG: 12180: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 19:58:03,947 [root] DEBUG: 12180: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 19:58:03,949 [root] DEBUG: 12180: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 19:58:03,954 [root] DEBUG: 12180: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 19:58:03,966 [root] DEBUG: 12180: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 19:58:03,975 [root] DEBUG: 12180: DLL loaded at 0x00007FFED5C90000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 19:58:04,009 [root] DEBUG: 4372: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49C571000, size: 0x1000.
2026-05-28 19:58:04,012 [root] DEBUG: 12180: NtTerminateProcess hook: Attempting to dump process 12180
2026-05-28 19:58:04,015 [root] DEBUG: 4372: AllocationHandler: Adding allocation to tracked region list: 0x00007DF49C561000, size: 0x1000.
2026-05-28 19:58:04,015 [root] DEBUG: 12180: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:58:04,017 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C560000.
2026-05-28 19:58:04,017 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,019 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C570000.
2026-05-28 19:58:04,020 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,023 [root] INFO: Process with pid 12180 has terminated
2026-05-28 19:58:04,033 [root] DEBUG: 4372: AllocationHandler: Allocation already in tracked region list: 0x00007DF49C570000.
2026-05-28 19:58:04,036 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C560000.
2026-05-28 19:58:04,036 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,038 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C570000.
2026-05-28 19:58:04,038 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,102 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12532: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF648C80000
2026-05-28 19:58:04,105 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 12532
2026-05-28 19:58:04,106 [lib.api.process] INFO: Monitor config for process 12532: C:\_3mo6uuq\dll\12532.ini
2026-05-28 19:58:04,109 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:04,132 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C580000.
2026-05-28 19:58:04,133 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,134 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C5B0000.
2026-05-28 19:58:04,136 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,138 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C590000.
2026-05-28 19:58:04,139 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,140 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C5A0000.
2026-05-28 19:58:04,142 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,144 [root] DEBUG: 4372: FreeHandler: Address: 0x00007DF49C5C0000.
2026-05-28 19:58:04,147 [root] DEBUG: 4372: ScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:04,905 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:04,910 [root] DEBUG: Loader: Injecting process 12532 (thread 12536) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:04,911 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:04,912 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:04,914 [lib.api.process] INFO: Injected into 64-bit <Process 12532 ShellExperienceHost.exe>
2026-05-28 19:58:04,915 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 12532
2026-05-28 19:58:04,916 [lib.api.process] INFO: Monitor config for process 12532: C:\_3mo6uuq\dll\12532.ini
2026-05-28 19:58:04,916 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:05,325 [root] INFO: Process with pid 4616 has terminated
2026-05-28 19:58:05,325 [root] DEBUG: 4616: NtTerminateProcess hook: Attempting to dump process 4616
2026-05-28 19:58:05,327 [root] DEBUG: 4616: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:58:06,016 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:06,020 [root] DEBUG: Loader: Injecting process 12532 (thread 12536) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:06,021 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:06,021 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:06,023 [lib.api.process] INFO: Injected into 64-bit <Process 12532 ShellExperienceHost.exe>
2026-05-28 19:58:06,024 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 12532
2026-05-28 19:58:06,025 [lib.api.process] INFO: Monitor config for process 12532: C:\_3mo6uuq\dll\12532.ini
2026-05-28 19:58:06,026 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:07,007 [root] DEBUG: 4372: OpenProcessHandler: Image base for process 6632 (handle 0x28d0): 0x00007FF6CE2A0000.
2026-05-28 19:58:07,099 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:07,105 [root] DEBUG: Loader: Injecting process 12532 with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:07,108 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12536, handle 0x124
2026-05-28 19:58:07,109 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 19:58:07,110 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:07,112 [lib.api.process] INFO: Injected into 64-bit <Process 12532 ShellExperienceHost.exe>
2026-05-28 19:58:07,515 [root] DEBUG: 4372: api-cap: RegQueryValueExW hook disabled due to count: 5001
2026-05-28 19:58:07,519 [root] DEBUG: 4372: api-cap: RegQueryValueExW hook disabled due to count: 5001
2026-05-28 19:58:11,074 [root] DEBUG: 4372: OpenProcessHandler: Image base for process 3856 (handle 0x2894): 0x00007FF66D090000.
2026-05-28 19:58:11,075 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 3856, handle 0x2894: C:\Windows\System32\conhost.exe
2026-05-28 19:58:11,103 [root] DEBUG: 4372: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 19:58:29,423 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 19:58:29,440 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 4272, handle 0x28b0: Error obtaining target process name
2026-05-28 19:58:29,547 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13252: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 19:58:29,563 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13252
2026-05-28 19:58:29,564 [lib.api.process] INFO: Monitor config for process 13252: C:\_3mo6uuq\dll\13252.ini
2026-05-28 19:58:29,567 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:29,569 [root] DEBUG: 4372: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 19:58:29,571 [root] DEBUG: 4372: api-cap: NtQueryInformationToken hook disabled due to count: 5001
2026-05-28 19:58:29,571 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:29,591 [root] DEBUG: Loader: Injecting process 13252 (thread 13256) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:29,606 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:29,612 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:29,627 [lib.api.process] INFO: Injected into 64-bit <Process 13252 dllhost.exe>
2026-05-28 19:58:29,644 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13252
2026-05-28 19:58:29,651 [lib.api.process] INFO: Monitor config for process 13252: C:\_3mo6uuq\dll\13252.ini
2026-05-28 19:58:29,653 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 19:58:29,659 [lib.api.process] INFO: 64-bit DLL to inject is C:\_3mo6uuq\dll\ogDVTOPr.dll, loader C:\_3mo6uuq\bin\wYfqTdCn.exe
2026-05-28 19:58:29,667 [root] DEBUG: Loader: Injecting process 13252 (thread 13256) with C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:29,669 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 19:58:29,670 [root] DEBUG: Successfully injected DLL C:\_3mo6uuq\dll\ogDVTOPr.dll.
2026-05-28 19:58:29,673 [lib.api.process] INFO: Injected into 64-bit <Process 13252 dllhost.exe>
2026-05-28 19:58:29,679 [root] DEBUG: 13252: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 19:58:29,682 [root] DEBUG: 13252: Interactive desktop enabled.
2026-05-28 19:58:29,683 [root] DEBUG: 13252: Dropped file limit defaulting to 100.
2026-05-28 19:58:29,685 [root] DEBUG: 13252: Disabling sleep skipping.
2026-05-28 19:58:29,687 [root] DEBUG: 13252: YaraInit: Compiled rules loaded from existing file C:\_3mo6uuq\data\yara\capemon.yac
2026-05-28 19:58:29,701 [root] DEBUG: 13252: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 19:58:29,703 [root] DEBUG: 13252: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 19:58:29,706 [root] DEBUG: 13252: Monitor initialised: 64-bit capemon loaded in process 13252 at 0x00007FFEAF1A0000, thread 13256, image base 0x00007FF6868D0000, stack from 0x0000004686CF4000-0x0000004686D00000
2026-05-28 19:58:29,706 [root] DEBUG: 13252: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 19:58:29,715 [root] DEBUG: 13252: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 19:58:29,738 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 19:58:29,738 [root] DEBUG: 13252: set_hooks: Unable to hook LockResource
2026-05-28 19:58:29,744 [root] DEBUG: 13252: Hooked 627 out of 628 functions
2026-05-28 19:58:29,746 [root] DEBUG: 13252: Syscall hook installed, syscall logging level 1
2026-05-28 19:58:29,752 [root] DEBUG: 13252: RestoreHeaders: Restored original import table.
2026-05-28 19:58:29,753 [root] INFO: Loaded monitor into process with pid 13252
2026-05-28 19:58:29,755 [root] DEBUG: 13252: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 13256).
2026-05-28 19:58:29,755 [root] DEBUG: 13252: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 19:58:29,757 [root] DEBUG: 13252: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 19:58:29,759 [root] DEBUG: 13252: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 19:58:29,760 [root] DEBUG: 13252: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 19:58:29,764 [root] DEBUG: 13252: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 19:58:29,778 [root] DEBUG: 13252: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 19:58:29,795 [root] DEBUG: 13252: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 19:58:29,796 [root] DEBUG: 13252: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 19:58:29,802 [root] DEBUG: 13252: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 19:58:29,911 [root] DEBUG: 4372: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 19:58:30,123 [root] INFO: Analysis timeout hit, terminating analysis
2026-05-28 19:58:30,124 [lib.api.process] INFO: Terminate event set for process 848
2026-05-28 19:58:30,125 [root] DEBUG: 848: Terminate Event: Attempting to dump process 848
2026-05-28 19:58:30,126 [root] DEBUG: 848: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:58:30,128 [lib.api.process] INFO: Termination confirmed for process 848
2026-05-28 19:58:30,128 [root] DEBUG: 848: Terminate Event: monitor shutdown complete for process 848
2026-05-28 19:58:30,128 [root] INFO: Terminate event set for process 848
2026-05-28 19:58:30,130 [lib.api.process] INFO: Terminate event set for process 7348
2026-05-28 19:58:30,131 [root] DEBUG: 7348: Terminate Event: Attempting to dump process 7348
2026-05-28 19:58:30,132 [root] DEBUG: 7348: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:58:30,133 [lib.api.process] INFO: Termination confirmed for process 7348
2026-05-28 19:58:30,134 [root] INFO: Terminate event set for process 7348
2026-05-28 19:58:30,134 [root] DEBUG: 7348: Terminate Event: monitor shutdown complete for process 7348
2026-05-28 19:58:30,135 [lib.api.process] INFO: Terminate event set for process 4372
2026-05-28 19:58:30,136 [root] DEBUG: 4372: Terminate Event: Attempting to dump process 4372
2026-05-28 19:58:30,147 [root] DEBUG: 4372: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:58:30,164 [root] DEBUG: 4372: ReverseScanForNonZero: Error - Supplied size zero.
2026-05-28 19:58:30,164 [root] DEBUG: 4372: GetPageAddress: Error - Supplied address zero.
2026-05-28 19:58:30,165 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-28 19:58:30,169 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Discord\app.ico
2026-05-28 19:58:30,174 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 19:58:30,185 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
2026-05-28 19:58:30,197 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
2026-05-28 19:58:30,244 [root] DEBUG: 4372: Dropped file limit reached.
2026-05-28 19:58:30,244 [lib.api.process] INFO: Termination confirmed for process 4372
2026-05-28 19:58:30,244 [root] INFO: Terminate event set for process 4372
2026-05-28 19:58:30,245 [lib.api.process] INFO: Terminate event set for process 13252
2026-05-28 19:58:30,246 [root] DEBUG: 4372: Terminate Event: monitor shutdown complete for process 4372
2026-05-28 19:58:30,246 [root] DEBUG: 13252: Terminate Event: Attempting to dump process 13252
2026-05-28 19:58:30,247 [root] DEBUG: 13252: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 19:58:30,252 [lib.api.process] INFO: Termination confirmed for process 13252
2026-05-28 19:58:30,253 [root] DEBUG: 13252: Terminate Event: monitor shutdown complete for process 13252
2026-05-28 19:58:30,253 [root] INFO: Terminate event set for process 13252
2026-05-28 19:58:30,254 [root] INFO: Created shutdown mutex
2026-05-28 19:58:31,264 [root] INFO: Shutting down package
2026-05-28 19:58:31,264 [root] INFO: Stopping auxiliary modules
2026-05-28 19:58:31,265 [root] INFO: Stopping auxiliary module: Browser
2026-05-28 19:58:31,265 [root] INFO: Stopping auxiliary module: Human
2026-05-28 19:58:31,266 [root] INFO: Stopping auxiliary module: Screenshots
2026-05-28 19:58:31,266 [root] INFO: Finishing auxiliary modules
2026-05-28 19:58:31,266 [root] INFO: Shutting down pipe server and dumping dropped files
2026-05-28 19:58:31,269 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db to files\dfb29c5939881d30755fe81a53c05b434b69634ae87539cd92bf663f21abb4c6; Size is 58320; Max size: 100000000
2026-05-28 19:58:31,281 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db to files\305a606ac7e41f3da01799d6eeede5fbad01260bb39bf72d03c326ca80942050; Size is 1048576; Max size: 100000000
2026-05-28 19:58:31,287 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db to files\dd99e60a9415909238ec04c20a82759325692e674e62f343b8731785a7948c0f; Size is 1048576; Max size: 100000000
2026-05-28 19:58:31,294 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Discord\app.ico to files\dfcea1bea8a924252d507d0316d8cf38efc61cf1314e47dca3eb723f47d5fe43; Size is 285478; Max size: 100000000
2026-05-28 19:58:31,300 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db to files\c98338ddb81ae2e36ec278ddbfa303642efe7ca0f5bccb59ad8ad3d4ec02bcfe; Size is 14688; Max size: 100000000
2026-05-28 19:58:31,305 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db to files\c6644555c4e579451f74d4843be40d2df30e9937bafb122dafa9ced8fc306100; Size is 1048576; Max size: 100000000
2026-05-28 19:58:31,313 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db to files\b02ec916d941aa9bd471d898682d7ecd34b7b4b2f22508a3942bbe02b43bf3c5; Size is 1048576; Max size: 100000000
2026-05-28 19:58:31,322 [root] WARNING: Folder at path "C:\VuqQjay\debugger" does not exist, skipping
2026-05-28 19:58:31,323 [root] WARNING: Folder at path "C:\VuqQjay\tlsdump" does not exist, skipping
2026-05-28 19:58:31,520 [root] WARNING: Monitor injection attempted but failed for process 5624
2026-05-28 19:58:31,520 [root] WARNING: Monitor injection attempted but failed for process 9908
2026-05-28 19:58:31,521 [root] WARNING: Monitor injection attempted but failed for process 9980
2026-05-28 19:58:31,521 [root] WARNING: Monitor injection attempted but failed for process 12172
2026-05-28 19:58:31,521 [root] WARNING: Monitor injection attempted but failed for process 12532
2026-05-28 19:58:31,521 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 19:54:51 | 2026-05-28 19:58:34 | none |
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 204.79.197.203 [VT] | unknown | - |
| Y | 149.135.84.209 [VT] | unknown | - |
| Y | 149.135.84.50 [VT] | unknown | - |
| Y | 18.155.216.20 [VT] | unknown | - |
| Y | 104.18.33.89 [VT] | unknown | - |
| Y | 150.171.109.19 [VT] | unknown | - |
| Y | 150.171.28.10 [VT] | unknown | - |
| Y | 23.219.86.106 [VT] | unknown | - |
| Y | 172.172.255.216 [VT] | unknown | - |
| N | 23.209.40.123 [VT] | unknown | - |
| Y | 13.107.213.31 [VT] | unknown | - |
| Y | 20.190.167.20 [VT] | unknown | - |
| Y | 150.171.28.12 [VT] | unknown | - |
| Y | 162.159.128.233 [VT] | unknown | - |
| Y | 150.171.109.25 [VT] | unknown | - |
| N | 162.159.136.234 [VT] | unknown | - |
| N | 205.196.6.132 [VT] | unknown | - |
| Y | 162.159.128.235 [VT] | unknown | - |
| N | 23.209.40.114 [VT] | unknown | - |
| N | 162.159.130.234 [VT] | unknown | - |
| Y | 23.56.110.169 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 23.202.165.41 [VT] | unknown | - |
| Y | 162.159.61.3 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| Y | 162.159.130.233 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| Y | 162.159.134.233 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 172.172.255.217 [VT] | unknown | - |
| Y | 162.254.194.57 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 13.70.178.62 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| disabled.invalid [VT] | NXDOMAIN | |
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.8.8 [VT] |
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.160
[VT]
A 149.135.84.155 [VT] |
23.56.110.24 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| cmp1-sea1.steamserver.net [VT] | A 205.196.6.132 [VT] | 205.196.6.132 [VT] |
| gateway-us-east1-d.discord.gg [VT] |
A 162.159.133.234
[VT]
A 162.159.135.234 [VT] A 162.159.130.234 [VT] A 162.159.134.234 [VT] A 162.159.136.234 [VT] |
162.159.134.234 [VT] |
| client-update.akamai.steamstatic.com [VT] |
A 23.209.40.114
[VT]
CNAME client-update.akamai.steamstatic.com.akamaized.net [VT] CNAME a78.dscw27.akamai.net [VT] A 23.209.40.123 [VT] |
23.45.168.193 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.