| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 20:43:30 | 2026-05-28 20:50:01 | 391s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 19:52:07,662 [root] INFO: Date set to: 20260528T20:43:37, timeout set to: 1200
2026-05-28 20:43:37,006 [root] DEBUG: Starting analyzer from: C:\6lreqs2g
2026-05-28 20:43:37,006 [root] DEBUG: Storing results at: C:\SBYTiH
2026-05-28 20:43:37,007 [root] DEBUG: Pipe server name: \\.\PIPE\gCndozO
2026-05-28 20:43:37,007 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 20:43:37,007 [root] INFO: analysis running as an admin
2026-05-28 20:43:37,007 [root] INFO: analysis package specified: "edge"
2026-05-28 20:43:37,007 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 20:43:37,026 [root] DEBUG: imported analysis package "edge"
2026-05-28 20:43:37,028 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 20:43:37,028 [root] DEBUG: New location of moved file: https://github.com/ytisf/theZoo
2026-05-28 20:43:37,028 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 20:43:37,029 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 20:43:37,029 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 20:43:37,029 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 20:43:37,056 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 20:43:37,078 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 20:43:37,094 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 20:43:37,127 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 20:43:37,140 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 20:43:37,140 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 20:43:37,141 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 20:43:37,142 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 20:43:37,142 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 20:43:37,143 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 20:43:37,143 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 20:43:37,143 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 20:43:37,144 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 20:43:37,144 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 20:43:37,144 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 20:43:37,145 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 20:43:37,145 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 20:43:37,145 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 20:43:37,145 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 20:43:37,145 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 20:43:37,146 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 20:43:37,146 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 20:43:37,146 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 20:43:37,156 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 1776)
2026-05-28 20:43:37,156 [modules.auxiliary.disguise] INFO: Disguising GUID to e9bc0f4e-81e9-44b0-98f2-d516689749d4
2026-05-28 20:43:37,157 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 20:43:37,157 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 20:43:37,157 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 20:43:37,157 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 20:43:37,157 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 20:43:37,158 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 20:43:37,158 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 20:43:37,160 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 20:43:37,160 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 20:43:37,160 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 20:43:37,161 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 20:43:37,161 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 20:43:37,161 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 20:43:37,161 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 20:43:37,162 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 20:43:37,162 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 20:43:37,164 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 20:43:37,164 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 20:43:37,164 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 20:43:37,225 [lib.api.process] INFO: Monitor config for process 4372: C:\6lreqs2g\dll\4372.ini
2026-05-28 20:43:37,226 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:43:37,228 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:43:37,258 [root] DEBUG: Loader: Injecting process 4372 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:37,436 [root] DEBUG: 4372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:43:37,437 [root] DEBUG: 4372: Disabling sleep skipping.
2026-05-28 20:43:37,437 [root] DEBUG: 4372: Interactive desktop enabled.
2026-05-28 20:43:37,438 [root] DEBUG: 4372: Dropped file limit defaulting to 100.
2026-05-28 20:43:37,438 [root] DEBUG: 4372: Interactive desktop - injecting Explorer Shell
2026-05-28 20:43:37,443 [root] DEBUG: 4372: YaraInit: Compiled 44 rule files
2026-05-28 20:43:37,444 [root] DEBUG: 4372: YaraInit: Compiled rules saved to file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:43:37,493 [root] DEBUG: 4372: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:43:37,494 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 20:43:37,569 [root] DEBUG: 4372: Monitor initialised: 64-bit capemon loaded in process 4372 at 0x00007FFEAF1A0000, thread 8388, image base 0x00007FF65F9E0000, stack from 0x000000000A7C2000-0x000000000A7D0000
2026-05-28 20:43:37,570 [root] DEBUG: 4372: Commandline: C:\Windows\Explorer.EXE
2026-05-28 20:43:37,584 [root] DEBUG: 4372: Hooked 69 out of 69 functions
2026-05-28 20:43:37,614 [root] DEBUG: 4372: Syscall hook installed, syscall logging level 1
2026-05-28 20:43:37,623 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:43:37,623 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:37,625 [lib.api.process] INFO: Injected into 64-bit <Process 4372 explorer.exe>
2026-05-28 20:43:44,739 [root] INFO: Restarting WMI Service
2026-05-28 20:43:46,780 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 20:43:46,781 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 20:43:46,781 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 20:43:46,783 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://github.com/ytisf/theZoo"" with pid 7356
2026-05-28 20:43:46,783 [lib.api.process] INFO: Monitor config for process 7356: C:\6lreqs2g\dll\7356.ini
2026-05-28 20:43:46,785 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:43:46,787 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:43:46,793 [root] DEBUG: Loader: Injecting process 7356 (thread 7368) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:46,795 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:43:46,796 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:46,798 [lib.api.process] INFO: Injected into 64-bit <Process 7356 msedge.exe>
2026-05-28 20:43:48,807 [lib.api.process] INFO: Successfully resumed process with pid 7356
2026-05-28 20:43:48,863 [root] DEBUG: 7356: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:43:48,864 [root] DEBUG: 7356: Disabling sleep skipping.
2026-05-28 20:43:48,864 [root] DEBUG: 7356: Interactive desktop enabled.
2026-05-28 20:43:48,865 [root] DEBUG: 7356: Dropped file limit defaulting to 100.
2026-05-28 20:43:48,873 [root] DEBUG: 7356: Edge-specific hook-set enabled.
2026-05-28 20:43:48,875 [root] DEBUG: 7356: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:43:48,886 [root] DEBUG: 7356: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:43:48,887 [root] DEBUG: 7356: Monitor initialised: 64-bit capemon loaded in process 7356 at 0x00007FFEAF1A0000, thread 7368, image base 0x00007FF60A060000, stack from 0x00000086149F4000-0x0000008614A00000
2026-05-28 20:43:48,888 [root] DEBUG: 7356: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://github.com/ytisf/theZoo"
2026-05-28 20:43:48,902 [root] DEBUG: 7356: Hooked 2 out of 2 functions
2026-05-28 20:43:48,937 [root] DEBUG: 7356: Syscall hook installed, syscall logging level 1
2026-05-28 20:43:48,944 [root] DEBUG: 7356: RestoreHeaders: Restored original import table.
2026-05-28 20:43:48,945 [root] INFO: Loaded monitor into process with pid 7356
2026-05-28 20:43:48,947 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:43:48,954 [root] DEBUG: 7356: DLL loaded at 0x00007FFED9040000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 20:43:48,955 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:43:48,957 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:43:48,957 [root] DEBUG: 7356: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:43:48,958 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:43:48,960 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:43:49,122 [root] DEBUG: 7356: DLL loaded at 0x00007FFED8180000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 20:43:49,124 [root] DEBUG: 7356: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:43:49,127 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDD470000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 20:43:49,129 [root] DEBUG: 7356: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:43:49,135 [root] DEBUG: 7356: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:43:49,135 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 892: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:43:49,136 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 892
2026-05-28 20:43:49,136 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:43:49,137 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 892
2026-05-28 20:43:49,138 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE8610000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 20:43:49,141 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:43:49,142 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:43:49,146 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:43:49,147 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEDFA0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:43:49,148 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE870000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 20:43:49,149 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 20:43:49,150 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:43:49,151 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE5A50000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 20:43:49,153 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:43:49,153 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:43:49,154 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 20:43:49,156 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:43:49,156 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE6C20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 20:43:49,157 [root] DEBUG: 7356: DLL loaded at 0x00007FFED4750000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 20:43:49,157 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE6110000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 20:43:49,158 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:43:49,159 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:43:49,160 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 20:43:49,161 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:43:49,162 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:43:49,162 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEB400000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 20:43:49,163 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF640000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 20:43:49,173 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE85F0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 20:43:49,174 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:43:49,175 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE6360000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 20:43:49,176 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:43:49,176 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:43:49,178 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE23A0000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 20:43:49,180 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 20:43:49,182 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF430000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 20:43:49,183 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:43:49,184 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:43:49,185 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEAE30000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 20:43:49,186 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:43:49,189 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE8E40000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 20:43:49,190 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:43:49,191 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE5AC0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 20:43:49,192 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE8D30000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:43:49,193 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEB280000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 20:43:49,194 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEEB10000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 20:43:49,196 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:43:49,199 [root] DEBUG: 7356: DLL loaded at 0x00007FFEECCF0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:43:49,200 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:43:49,200 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEC530000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 20:43:49,201 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE3AB0000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 20:43:49,202 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDF7D0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 20:43:49,206 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:43:49,207 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDAFC0000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 20:43:49,209 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDF190000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 20:43:49,211 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE9A90000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 20:43:49,215 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE96E0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 20:43:49,215 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE3950000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 20:43:49,216 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE3BB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 20:43:49,217 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDEC10000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 20:43:49,219 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 20:43:49,221 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF440000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 20:43:49,231 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE8F40000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 20:43:49,232 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE8F60000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 20:43:49,233 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:43:49,234 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDEB40000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:43:49,235 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 20:43:49,254 [root] DEBUG: 7356: DLL loaded at 0x00007FFE99CC0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 20:43:49,259 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE2620000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 20:43:49,260 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 5336: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:43:49,261 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 5336
2026-05-28 20:43:49,262 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE0DA0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 20:43:49,262 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 5336
2026-05-28 20:43:49,263 [root] DEBUG: 7356: caller_dispatch: Added region at 0x00007FF60A060000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF60A157D66, thread 3608).
2026-05-28 20:43:49,268 [root] DEBUG: 7356: ProcessImageBase: Main module image at 0x00007FF60A060000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:43:49,269 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 752: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:43:49,270 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 752
2026-05-28 20:43:49,271 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 752
2026-05-28 20:43:49,283 [root] DEBUG: 7356: DLL loaded at 0x00007FFED7420000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 20:43:49,284 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 1440: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:43:49,285 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF4A0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 20:43:49,286 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 1440
2026-05-28 20:43:49,288 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 1440
2026-05-28 20:43:49,298 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:43:49,300 [root] DEBUG: 7356: DLL loaded at 0x00007FFED6CB0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 20:43:49,327 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEDFD0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 20:43:49,328 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEBC70000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 20:43:49,329 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEC340000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 20:43:49,331 [root] DEBUG: 7356: DLL loaded at 0x00007FFED88A0000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 20:43:49,352 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE8470000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 20:43:49,367 [root] DEBUG: 7356: DLL loaded at 0x00007FFEED220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 20:43:49,374 [root] DEBUG: 7356: DLL loaded at 0x00007FFED8910000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 20:43:49,376 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 1120: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:43:49,377 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 80: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:43:49,378 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 1120
2026-05-28 20:43:49,378 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE1330000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 20:43:49,378 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 80
2026-05-28 20:43:49,379 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 1120
2026-05-28 20:43:49,379 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 80
2026-05-28 20:43:49,395 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDA250000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 20:43:49,398 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 20:43:49,414 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 20:43:49,429 [root] DEBUG: 4372: caller_dispatch: Added region at 0x00007FF65F9E0000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF65FA0CA89, thread 8880).
2026-05-28 20:43:49,432 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 20:43:49,434 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDCBB0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 20:43:49,456 [root] DEBUG: 4372: ProcessImageBase: Main module image at 0x00007FF65F9E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:43:49,472 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:43:49,474 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF210000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:43:49,477 [root] DEBUG: 4372: ProcessImageBase: Main module image at 0x00007FF65F9E0000 unmodified (entropy change 6.345788e-07)
2026-05-28 20:43:49,484 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDFDE0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 20:43:49,530 [root] DEBUG: 7356: DLL loaded at 0x00007FFED9A80000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 20:43:49,534 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:43:49,535 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:43:49,553 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE6110000: C:\Windows\System32\aadWamExtension (0x36000 bytes).
2026-05-28 20:43:49,555 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDFA80000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 20:43:51,115 [root] DEBUG: 7356: DLL loaded at 0x00007FFED5C90000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 20:43:51,156 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:43:51,159 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:43:55,783 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 6604: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:43:55,784 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF0250000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 20:43:55,784 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 6604
2026-05-28 20:43:55,785 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEADC0000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:43:55,785 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 6604
2026-05-28 20:43:55,820 [root] DEBUG: 7356: DLL loaded at 0x00007FFED8C50000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 20:43:55,851 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:43:55,852 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:43:55,854 [root] DEBUG: 7356: DLL loaded at 0x00007FFE96BA0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 20:43:55,858 [root] DEBUG: 7356: DLL loaded at 0x00007FFE99850000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 20:43:55,860 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:43:55,863 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE330000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 20:43:55,863 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE2C0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 20:43:55,865 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE5A10000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 20:43:55,866 [root] DEBUG: 7356: DLL loaded at 0x00007FFED96D0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 20:43:55,874 [root] DEBUG: 7356: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:43:55,875 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:43:55,876 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:43:55,880 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 8840: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7AFA40000
2026-05-28 20:43:55,881 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8840
2026-05-28 20:43:55,881 [lib.api.process] INFO: Monitor config for process 8840: C:\6lreqs2g\dll\8840.ini
2026-05-28 20:43:55,882 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:43:56,396 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:43:56,396 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:43:56,400 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:43:56,406 [root] DEBUG: Loader: Injecting process 8840 (thread 7744) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:56,408 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:43:56,408 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:56,410 [lib.api.process] INFO: Injected into 64-bit <Process 8840 identity_helper.exe>
2026-05-28 20:43:56,416 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE6C40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 20:43:56,417 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE0440000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 20:43:56,419 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 6168: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7AFA40000
2026-05-28 20:43:56,419 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 6168
2026-05-28 20:43:56,419 [lib.api.process] INFO: Monitor config for process 6168: C:\6lreqs2g\dll\6168.ini
2026-05-28 20:43:56,420 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:43:56,435 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDFE80000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 20:43:56,436 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE6BA0000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 20:43:56,437 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEA040000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 20:43:56,501 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:43:56,502 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:43:56,504 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:43:56,509 [root] DEBUG: Loader: Injecting process 6168 (thread 6164) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:56,509 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:43:56,510 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:56,511 [lib.api.process] INFO: Injected into 64-bit <Process 6168 identity_helper.exe>
2026-05-28 20:43:56,515 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 6168
2026-05-28 20:43:56,516 [lib.api.process] INFO: Monitor config for process 6168: C:\6lreqs2g\dll\6168.ini
2026-05-28 20:43:56,517 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:43:56,596 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:43:56,596 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:43:56,598 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:43:56,603 [root] DEBUG: Loader: Injecting process 6168 (thread 6164) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:56,603 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:43:56,604 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:56,606 [lib.api.process] INFO: Injected into 64-bit <Process 6168 identity_helper.exe>
2026-05-28 20:43:56,615 [root] DEBUG: 6168: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:43:56,615 [root] DEBUG: 6168: Interactive desktop enabled.
2026-05-28 20:43:56,616 [root] DEBUG: 6168: Dropped file limit defaulting to 100.
2026-05-28 20:43:56,621 [root] DEBUG: 6168: Disabling sleep skipping.
2026-05-28 20:43:56,624 [root] DEBUG: 6168: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:43:56,635 [root] DEBUG: 6168: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:43:56,636 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7AFA40000, size 0x28b4d8
2026-05-28 20:43:56,664 [root] DEBUG: 6168: Monitor initialised: 64-bit capemon loaded in process 6168 at 0x00007FFEAF1A0000, thread 6164, image base 0x00007FF7AFA40000, stack from 0x0000003B30F34000-0x0000003B30F40000
2026-05-28 20:43:56,666 [root] DEBUG: 6168: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5720,i,903182962105644930,8468401534647197767,524288 --field-trial-handle=2324,i,2507240065479828097,12982049577213720454,262144 --variations-seed-version --pseudonymization-salt-handle=2328,i,3928996663565784297,1367980688369731802
2026-05-28 20:43:56,666 [root] DEBUG: 6168: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 20:43:56,676 [root] DEBUG: 6168: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:43:56,695 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 20:43:56,696 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:43:56,697 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE6DC0000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 20:43:56,698 [root] DEBUG: 7356: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:43:56,699 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE6C20000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 20:43:56,700 [root] DEBUG: 7356: DLL loaded at 0x00007FFEDBC30000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 20:43:56,705 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEEDE0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 20:43:56,706 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:43:56,706 [root] DEBUG: 6168: set_hooks: Unable to hook LockResource
2026-05-28 20:43:56,724 [root] DEBUG: 6168: Hooked 627 out of 628 functions
2026-05-28 20:43:56,739 [root] DEBUG: 6168: Syscall hook installed, syscall logging level 1
2026-05-28 20:43:56,743 [root] DEBUG: 6168: RestoreHeaders: Restored original import table.
2026-05-28 20:43:56,744 [root] INFO: Loaded monitor into process with pid 6168
2026-05-28 20:43:56,744 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:43:56,798 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:43:56,828 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:43:56,854 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:43:56,882 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:43:56,909 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:43:56,934 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FFEAECE0000, size 0x4b9994
2026-05-28 20:43:56,962 [root] DEBUG: 6168: caller_dispatch: Added region at 0x00007FFEAECE0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFEAEEDF156, thread 6164).
2026-05-28 20:43:56,963 [root] DEBUG: 6168: caller_dispatch: Scanning calling region at 0x00007FFEAECE0000...
2026-05-28 20:43:56,967 [root] DEBUG: 6168: ProcessTrackedRegion: Region at 0x00007FFEAECE0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 20:43:56,970 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:43:56,993 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7AFA40000, size 0x28b4d8
2026-05-28 20:43:57,009 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7AFA40000, size 0x28b4d8
2026-05-28 20:43:57,025 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7AFA40000, size 0x28b4d8
2026-05-28 20:43:57,041 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7AFA40000, size 0x28b4d8
2026-05-28 20:43:57,059 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7AFA40000, size 0x28b4d8
2026-05-28 20:43:57,074 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7AFA40000, size 0x28b4d8
2026-05-28 20:43:57,095 [root] DEBUG: 6168: caller_dispatch: Added region at 0x00007FF7AFA40000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7AFB34096, thread 6164).
2026-05-28 20:43:57,096 [root] DEBUG: 6168: YaraScan: Scanning 0x00007FF7AFA40000, size 0x28b4d8
2026-05-28 20:43:57,113 [root] DEBUG: 6168: ProcessImageBase: Main module image at 0x00007FF7AFA40000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:43:57,118 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:43:57,141 [root] DEBUG: 6168: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:43:57,146 [root] DEBUG: 6168: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:43:57,149 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:43:57,179 [root] DEBUG: 6168: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:43:57,185 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:43:57,191 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:43:57,191 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEB280000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 20:43:57,192 [root] DEBUG: 6168: DLL loaded at 0x00007FFEECCF0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:43:57,192 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDCB10000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 20:43:57,201 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:43:57,201 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDFE80000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 20:43:57,211 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:43:57,211 [root] DEBUG: 6168: DLL loaded at 0x000001E0D2D00000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 20:43:57,216 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:43:57,220 [lib.api.process] INFO: Monitor config for process 848: C:\6lreqs2g\dll\848.ini
2026-05-28 20:43:57,221 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:43:57,222 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:43:57,224 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDE2F0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 20:43:57,228 [root] DEBUG: Loader: Injecting process 848 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:57,230 [root] DEBUG: 848: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:43:57,231 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:43:57,232 [root] DEBUG: 848: Disabling sleep skipping.
2026-05-28 20:43:57,232 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:43:57,233 [root] DEBUG: 848: Interactive desktop enabled.
2026-05-28 20:43:57,233 [root] DEBUG: 848: Dropped file limit defaulting to 100.
2026-05-28 20:43:57,234 [root] DEBUG: 848: Services hook set enabled
2026-05-28 20:43:57,236 [root] DEBUG: 848: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:43:57,245 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:43:57,248 [root] DEBUG: 848: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:43:57,249 [root] DEBUG: 848: Monitor initialised: 64-bit capemon loaded in process 848 at 0x00007FFEAF1A0000, thread 9340, image base 0x00007FF6A8D80000, stack from 0x0000006A4DD74000-0x0000006A4DD80000
2026-05-28 20:43:57,249 [root] DEBUG: 848: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 20:43:57,255 [root] DEBUG: 6168: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:43:57,256 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE6C40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 20:43:57,258 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEF210000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 20:43:57,261 [root] DEBUG: 848: Hooked 69 out of 69 functions
2026-05-28 20:43:57,263 [root] INFO: Loaded monitor into process with pid 848
2026-05-28 20:43:57,264 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:43:57,265 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:43:57,266 [lib.api.process] INFO: Injected into 64-bit <Process 848 svchost.exe>
2026-05-28 20:43:59,296 [root] DEBUG: 6168: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:43:59,297 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:43:59,298 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:43:59,360 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE5370000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 20:43:59,361 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE4650000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 20:43:59,362 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDAE80000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 20:43:59,364 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:43:59,376 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE9FE0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 20:43:59,388 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:43:59,411 [root] DEBUG: 6168: DLL loaded at 0x00007FFED4AB0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 20:43:59,434 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEDFD0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 20:43:59,435 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEBC70000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 20:43:59,887 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE1590000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 20:43:59,889 [root] DEBUG: 6168: DLL loaded at 0x00007FFED4800000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 20:43:59,903 [root] DEBUG: 6168: DLL loaded at 0x00007FFED5E10000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 20:43:59,926 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:43:59,927 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEF080000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 20:43:59,927 [root] DEBUG: 6168: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:43:59,928 [root] DEBUG: 6168: DLL loaded at 0x00007FFEE4250000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 20:43:59,928 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDA8F0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 20:43:59,957 [root] DEBUG: 6168: DLL loaded at 0x00007FFED4BF0000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 20:43:59,975 [root] DEBUG: 6168: DLL loaded at 0x00007FFEDF190000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 20:44:00,003 [root] DEBUG: 6168: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:44:10,080 [root] INFO: Process with pid 6168 has terminated
2026-05-28 20:44:10,081 [root] DEBUG: 6168: NtTerminateProcess hook: Attempting to dump process 6168
2026-05-28 20:44:10,083 [root] DEBUG: 6168: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:44:19,135 [root] DEBUG: 7356: DLL loaded at 0x00007FFEE59F0000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 20:44:19,245 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 9752: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:44:19,246 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 9752
2026-05-28 20:44:19,247 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 9752
2026-05-28 20:44:21,891 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE59D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:44:21,907 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9868: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe, ImageBase: 0x00007FF63BEB0000
2026-05-28 20:44:21,908 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9844: C:\Windows\system32\ApplicationFrameHost.exe, ImageBase: 0x00007FF6477E0000
2026-05-28 20:44:21,908 [root] INFO: Announced 64-bit process name: WinStore.App.exe pid: 9868
2026-05-28 20:44:21,908 [root] INFO: Announced 64-bit process name: ApplicationFrameHost.exe pid: 9844
2026-05-28 20:44:21,909 [lib.api.process] INFO: Monitor config for process 9868: C:\6lreqs2g\dll\9868.ini
2026-05-28 20:44:21,909 [lib.api.process] INFO: Monitor config for process 9844: C:\6lreqs2g\dll\9844.ini
2026-05-28 20:44:21,909 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:21,910 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:21,911 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:21,915 [root] DEBUG: Loader: Injecting process 9844 (thread 9848) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:21,916 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:21,917 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:21,918 [lib.api.process] INFO: Injected into 64-bit <Process 9844 ApplicationFrameHost.exe>
2026-05-28 20:44:21,920 [root] INFO: Announced 64-bit process name: ApplicationFrameHost.exe pid: 9844
2026-05-28 20:44:21,920 [lib.api.process] INFO: Monitor config for process 9844: C:\6lreqs2g\dll\9844.ini
2026-05-28 20:44:21,921 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:21,922 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:21,925 [root] DEBUG: Loader: Injecting process 9844 (thread 9848) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:21,926 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:21,926 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:21,927 [lib.api.process] INFO: Injected into 64-bit <Process 9844 ApplicationFrameHost.exe>
2026-05-28 20:44:21,934 [root] DEBUG: 9844: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:21,934 [root] DEBUG: 9844: Interactive desktop enabled.
2026-05-28 20:44:21,935 [root] DEBUG: 9844: Dropped file limit defaulting to 100.
2026-05-28 20:44:21,936 [root] DEBUG: 9844: Disabling sleep skipping.
2026-05-28 20:44:21,937 [root] DEBUG: 9844: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:21,948 [root] DEBUG: 9844: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:21,949 [root] DEBUG: 9844: YaraScan: Scanning 0x00007FF6477E0000, size 0x14222
2026-05-28 20:44:21,950 [root] DEBUG: 9844: Monitor initialised: 64-bit capemon loaded in process 9844 at 0x00007FFEAF1A0000, thread 9848, image base 0x00007FF6477E0000, stack from 0x00000034BE674000-0x00000034BE680000
2026-05-28 20:44:21,951 [root] DEBUG: 9844: Commandline: C:\Windows\system32\ApplicationFrameHost.exe -Embedding
2026-05-28 20:44:21,961 [root] DEBUG: 9844: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:44:21,982 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:44:21,983 [root] DEBUG: 9844: set_hooks: Unable to hook LockResource
2026-05-28 20:44:21,988 [root] DEBUG: 9844: Hooked 627 out of 628 functions
2026-05-28 20:44:21,989 [root] DEBUG: 9844: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:21,993 [root] DEBUG: 9844: RestoreHeaders: Restored original import table.
2026-05-28 20:44:21,994 [root] INFO: Loaded monitor into process with pid 9844
2026-05-28 20:44:21,998 [root] DEBUG: 9844: caller_dispatch: Added region at 0x00007FF6477E0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6477E2DE1, thread 9848).
2026-05-28 20:44:21,998 [root] DEBUG: 9844: YaraScan: Scanning 0x00007FF6477E0000, size 0x14222
2026-05-28 20:44:21,999 [root] DEBUG: 9844: ProcessImageBase: Main module image at 0x00007FF6477E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:44:22,001 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:22,001 [root] DEBUG: 9844: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:22,002 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:44:22,004 [root] DEBUG: 9844: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:44:22,005 [root] DEBUG: Loader: Injecting process 9868 (thread 9872) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,005 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:22,006 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,007 [lib.api.process] INFO: Injected into 64-bit <Process 9868 WinStore.App.exe>
2026-05-28 20:44:22,008 [root] INFO: Announced 64-bit process name: WinStore.App.exe pid: 9868
2026-05-28 20:44:22,008 [lib.api.process] INFO: Monitor config for process 9868: C:\6lreqs2g\dll\9868.ini
2026-05-28 20:44:22,008 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:22,009 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEB280000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 20:44:22,010 [root] DEBUG: 9844: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:44:22,011 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:44:22,011 [root] DEBUG: 9844: DLL loaded at 0x00007FFEED0B0000: C:\Windows\System32\UxTheme (0x9e000 bytes).
2026-05-28 20:44:22,012 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:44:22,012 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\System32\DEVOBJ (0x33000 bytes).
2026-05-28 20:44:22,013 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE41E0000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 20:44:22,013 [root] DEBUG: 9844: DLL loaded at 0x00007FFEDAFC0000: C:\Windows\System32\TWINAPI (0xa9000 bytes).
2026-05-28 20:44:22,014 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEB6B0000: C:\Windows\System32\d2d1 (0x5c0000 bytes).
2026-05-28 20:44:22,014 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEBC70000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 20:44:22,015 [root] DEBUG: 9844: DLL loaded at 0x00007FFEED220000: C:\Windows\System32\dwmapi (0x2f000 bytes).
2026-05-28 20:44:22,015 [root] DEBUG: 9844: DLL loaded at 0x00007FFED78B0000: C:\Windows\System32\ApplicationFrame (0xa9000 bytes).
2026-05-28 20:44:22,034 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:44:22,041 [root] DEBUG: 9844: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:44:22,045 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE6F40000: C:\Windows\system32\D3D10Warp (0x6f6000 bytes).
2026-05-28 20:44:22,047 [root] DEBUG: 9844: DLL loaded at 0x00007FFEED200000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 20:44:22,055 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE6D80000: C:\Windows\SYSTEM32\dxcore (0x3b000 bytes).
2026-05-28 20:44:22,058 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEC340000: C:\Windows\System32\dcomp (0x1e3000 bytes).
2026-05-28 20:44:22,060 [root] DEBUG: 9844: DLL loaded at 0x00007FFEECCF0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:44:22,072 [root] DEBUG: 9844: DLL loaded at 0x00007FFED4310000: C:\Windows\system32\UIAutomationCore (0x2f5000 bytes).
2026-05-28 20:44:22,079 [root] DEBUG: 9844: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4B0B21000, size: 0x1000.
2026-05-28 20:44:22,081 [root] DEBUG: 9844: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4B0B11000, size: 0x1000.
2026-05-28 20:44:22,082 [root] DEBUG: 9844: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4B0B01000, size: 0x1000.
2026-05-28 20:44:22,083 [root] DEBUG: 9844: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4B0AF1000, size: 0x1000.
2026-05-28 20:44:22,099 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:22,099 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:44:22,100 [root] DEBUG: 9844: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:44:22,104 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEF640000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 20:44:22,106 [root] DEBUG: Loader: Injecting process 9868 (thread 9872) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,106 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:22,107 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE0440000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 20:44:22,108 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,110 [lib.api.process] INFO: Injected into 64-bit <Process 9868 WinStore.App.exe>
2026-05-28 20:44:22,111 [root] INFO: Announced 64-bit process name: WinStore.App.exe pid: 9868
2026-05-28 20:44:22,111 [lib.api.process] INFO: Monitor config for process 9868: C:\6lreqs2g\dll\9868.ini
2026-05-28 20:44:22,112 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:22,116 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE9310000: C:\Windows\system32\windowscodecs (0x1b4000 bytes).
2026-05-28 20:44:22,118 [root] DEBUG: 9844: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:44:22,122 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE3D00000: C:\Windows\SYSTEM32\mrmcorer (0xf4000 bytes).
2026-05-28 20:44:22,123 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\SYSTEM32\iertutil (0x2bc000 bytes).
2026-05-28 20:44:22,134 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEA040000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 20:44:22,141 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:44:22,142 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE96E0000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 20:44:22,143 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:44:22,143 [root] DEBUG: 9844: DLL loaded at 0x00007FFEEC530000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 20:44:22,144 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE3AB0000: C:\Windows\System32\TextInputFramework (0xf9000 bytes).
2026-05-28 20:44:22,144 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE3950000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 20:44:22,145 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE3BB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 20:44:22,148 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE0BF0000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 20:44:22,156 [root] DEBUG: 9844: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4B0AE1000, size: 0x1000.
2026-05-28 20:44:22,203 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:22,208 [root] DEBUG: Loader: Injecting process 9868 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,208 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9872, handle 0x120
2026-05-28 20:44:22,209 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:22,209 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,210 [lib.api.process] INFO: Injected into 64-bit <Process 9868 WinStore.App.exe>
2026-05-28 20:44:22,222 [root] DEBUG: 9844: FreeHandler: Address: 0x00007DF4B0B00000.
2026-05-28 20:44:22,223 [root] DEBUG: 9844: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:44:22,223 [root] DEBUG: 9844: FreeHandler: Address: 0x00007DF4B0AE0000.
2026-05-28 20:44:22,224 [root] DEBUG: 9844: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:44:22,224 [root] DEBUG: 9844: FreeHandler: Address: 0x00007DF4B0AF0000.
2026-05-28 20:44:22,225 [root] DEBUG: 9844: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:44:22,225 [root] DEBUG: 9844: FreeHandler: Address: 0x00007DF4B0B10000.
2026-05-28 20:44:22,225 [root] DEBUG: 9844: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:44:22,227 [root] DEBUG: 9844: FreeHandler: Address: 0x00007DF4B0B20000.
2026-05-28 20:44:22,227 [root] DEBUG: 9844: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:44:22,748 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9268: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF6357C0000
2026-05-28 20:44:22,749 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9268
2026-05-28 20:44:22,750 [lib.api.process] INFO: Monitor config for process 9268: C:\6lreqs2g\dll\9268.ini
2026-05-28 20:44:22,750 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:22,751 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:22,755 [root] DEBUG: Loader: Injecting process 9268 (thread 8636) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,756 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:22,756 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,757 [lib.api.process] INFO: Injected into 64-bit <Process 9268 backgroundTaskHost.exe>
2026-05-28 20:44:22,758 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9268
2026-05-28 20:44:22,758 [lib.api.process] INFO: Monitor config for process 9268: C:\6lreqs2g\dll\9268.ini
2026-05-28 20:44:22,759 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:22,760 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:22,764 [root] DEBUG: Loader: Injecting process 9268 (thread 8636) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,764 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:22,765 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,766 [lib.api.process] INFO: Injected into 64-bit <Process 9268 backgroundTaskHost.exe>
2026-05-28 20:44:22,766 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9268
2026-05-28 20:44:22,767 [lib.api.process] INFO: Monitor config for process 9268: C:\6lreqs2g\dll\9268.ini
2026-05-28 20:44:22,767 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:22,768 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:22,771 [root] DEBUG: Loader: Injecting process 9268 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,772 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8636, handle 0x120
2026-05-28 20:44:22,772 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:22,772 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:22,774 [lib.api.process] INFO: Injected into 64-bit <Process 9268 backgroundTaskHost.exe>
2026-05-28 20:44:32,734 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFC80000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:44:32,743 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 8992: C:\Windows\ImmersiveControlPanel\SystemSettings.exe, ImageBase: 0x00007FF6CF200000
2026-05-28 20:44:32,745 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 8992
2026-05-28 20:44:32,745 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE6F40000: C:\Windows\system32\D3D10Warp (0x6f6000 bytes).
2026-05-28 20:44:32,745 [lib.api.process] INFO: Monitor config for process 8992: C:\6lreqs2g\dll\8992.ini
2026-05-28 20:44:32,746 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:32,757 [root] DEBUG: 9844: AllocationHandler: Allocation already in tracked region list: 0x00007DF4B0B20000.
2026-05-28 20:44:32,760 [root] DEBUG: 9844: AllocationHandler: Allocation already in tracked region list: 0x00007DF4B0B10000.
2026-05-28 20:44:32,760 [root] DEBUG: 9844: AllocationHandler: Allocation already in tracked region list: 0x00007DF4B0B00000.
2026-05-28 20:44:32,762 [root] DEBUG: 9844: AllocationHandler: Allocation already in tracked region list: 0x00007DF4B0AF0000.
2026-05-28 20:44:32,800 [root] DEBUG: 9844: api-rate-cap: NtSetInformationThread hook disabled due to rate
2026-05-28 20:44:32,830 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:32,834 [root] DEBUG: Loader: Injecting process 8992 (thread 9824) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:32,835 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:32,836 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:32,837 [lib.api.process] INFO: Injected into 64-bit <Process 8992 SystemSettings.exe>
2026-05-28 20:44:32,839 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 8992
2026-05-28 20:44:32,839 [lib.api.process] INFO: Monitor config for process 8992: C:\6lreqs2g\dll\8992.ini
2026-05-28 20:44:32,840 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:32,915 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:32,920 [root] DEBUG: Loader: Injecting process 8992 (thread 9824) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:32,920 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:32,921 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:32,922 [lib.api.process] INFO: Injected into 64-bit <Process 8992 SystemSettings.exe>
2026-05-28 20:44:32,923 [root] INFO: Announced 64-bit process name: SystemSettings.exe pid: 8992
2026-05-28 20:44:32,923 [lib.api.process] INFO: Monitor config for process 8992: C:\6lreqs2g\dll\8992.ini
2026-05-28 20:44:32,923 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:32,999 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:33,003 [root] DEBUG: Loader: Injecting process 8992 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,004 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9824, handle 0x120
2026-05-28 20:44:33,004 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:33,005 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,006 [lib.api.process] INFO: Injected into 64-bit <Process 8992 SystemSettings.exe>
2026-05-28 20:44:33,013 [root] DEBUG: 8992: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:33,014 [root] DEBUG: 8992: Interactive desktop enabled.
2026-05-28 20:44:33,014 [root] DEBUG: 8992: Dropped file limit defaulting to 100.
2026-05-28 20:44:33,015 [root] DEBUG: 8992: Disabling sleep skipping.
2026-05-28 20:44:33,016 [root] DEBUG: 8992: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:33,027 [root] DEBUG: 8992: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:33,028 [root] DEBUG: 8992: YaraScan: Scanning 0x00007FF6CF200000, size 0x1903c
2026-05-28 20:44:33,028 [root] DEBUG: 8992: Monitor initialised: 64-bit capemon loaded in process 8992 at 0x00007FFEAF1A0000, thread 9824, image base 0x00007FF6CF200000, stack from 0x00000069C11A4000-0x00000069C11B0000
2026-05-28 20:44:33,029 [root] DEBUG: 8992: Commandline: "C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
2026-05-28 20:44:33,037 [root] DEBUG: 8992: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:44:33,058 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:44:33,059 [root] DEBUG: 8992: set_hooks: Unable to hook LockResource
2026-05-28 20:44:33,063 [root] DEBUG: 8992: Hooked 627 out of 628 functions
2026-05-28 20:44:33,064 [root] DEBUG: 8992: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:33,069 [root] DEBUG: 8992: RestoreHeaders: Restored original import table.
2026-05-28 20:44:33,070 [root] INFO: Loaded monitor into process with pid 8992
2026-05-28 20:44:33,070 [root] DEBUG: 8992: caller_dispatch: Added region at 0x00007FF6CF200000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6CF2043D1, thread 9824).
2026-05-28 20:44:33,071 [root] DEBUG: 8992: YaraScan: Scanning 0x00007FF6CF200000, size 0x1903c
2026-05-28 20:44:33,072 [root] DEBUG: 8992: ProcessImageBase: Main module image at 0x00007FF6CF200000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:44:33,074 [root] DEBUG: 8992: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:33,075 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:44:33,078 [root] DEBUG: 8992: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:44:33,081 [root] DEBUG: 8992: DLL loaded at 0x00007FFEECCF0000: C:\Windows\SYSTEM32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:44:33,081 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:44:33,082 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE4250000: C:\Windows\SYSTEM32\Bcp47Langs (0x5b000 bytes).
2026-05-28 20:44:33,082 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\SYSTEM32\iertutil (0x2bc000 bytes).
2026-05-28 20:44:33,082 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEC340000: C:\Windows\SYSTEM32\dcomp (0x1e3000 bytes).
2026-05-28 20:44:33,083 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE2840000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-28 20:44:33,084 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\Comctl32 (0x29a000 bytes).
2026-05-28 20:44:33,091 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEE870000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 20:44:33,092 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 20:44:33,092 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEB280000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 20:44:33,093 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE3D00000: C:\Windows\SYSTEM32\MrmCoreR (0xf4000 bytes).
2026-05-28 20:44:33,093 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEB6B0000: C:\Windows\SYSTEM32\d2d1 (0x5c0000 bytes).
2026-05-28 20:44:33,093 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:44:33,094 [root] DEBUG: 8992: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:44:33,094 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE3E40000: C:\Windows\SYSTEM32\wincorlib (0x6f000 bytes).
2026-05-28 20:44:33,094 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:44:33,095 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEE250000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-05-28 20:44:33,095 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:44:33,096 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:44:33,096 [root] DEBUG: 8992: DLL loaded at 0x0000026171650000: C:\Windows\SYSTEM32\WinLangdb (0x34000 bytes).
2026-05-28 20:44:33,097 [root] DEBUG: 8992: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:44:33,097 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEC8B0000: C:\Windows\SYSTEM32\elscore (0x19000 bytes).
2026-05-28 20:44:33,097 [root] DEBUG: 8992: DLL loaded at 0x00007FFE965A0000: C:\Windows\ImmersiveControlPanel\SystemSettings (0x5fb000 bytes).
2026-05-28 20:44:33,099 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF210000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:44:33,106 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE0440000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 20:44:33,110 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:44:33,110 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE94D0000: C:\Windows\SYSTEM32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:44:33,111 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE96E0000: C:\Windows\SYSTEM32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 20:44:33,111 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEC530000: C:\Windows\SYSTEM32\CoreUIComponents (0x35b000 bytes).
2026-05-28 20:44:33,111 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE3AB0000: C:\Windows\SYSTEM32\TextInputFramework (0xf9000 bytes).
2026-05-28 20:44:33,112 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE3950000: C:\Windows\SYSTEM32\InputHost (0x152000 bytes).
2026-05-28 20:44:33,112 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE3BB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 20:44:33,117 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE3900000: C:\Windows\SYSTEM32\languageoverlayutil (0x41000 bytes).
2026-05-28 20:44:33,121 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE41E0000: C:\Windows\SYSTEM32\bcp47mrm (0x2d000 bytes).
2026-05-28 20:44:33,123 [root] DEBUG: 8992: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:44:33,156 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:44:33,163 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE61A0000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 20:44:33,165 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE5430000: C:\Windows\SYSTEM32\urlmon (0x1ed000 bytes).
2026-05-28 20:44:33,173 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEDFD0000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 20:44:33,176 [root] DEBUG: 8992: DLL loaded at 0x00007FFEED200000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 20:44:33,180 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEBC70000: C:\Windows\SYSTEM32\d3d11 (0x263000 bytes).
2026-05-28 20:44:33,181 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDFC80000: C:\Windows\ImmersiveControlPanel\Telemetry.Common (0x12000 bytes).
2026-05-28 20:44:33,182 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE6F40000: C:\Windows\SYSTEM32\d3d10warp (0x6f6000 bytes).
2026-05-28 20:44:33,186 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:44:33,187 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE6D80000: C:\Windows\SYSTEM32\dxcore (0x3b000 bytes).
2026-05-28 20:44:33,191 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE23A0000: C:\Windows\SYSTEM32\dwrite (0x27f000 bytes).
2026-05-28 20:44:33,192 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE1A70000: C:\Windows\System32\Windows.UI.Xaml.Controls (0x3dc000 bytes).
2026-05-28 20:44:33,195 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE0BF0000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2026-05-28 20:44:33,197 [root] DEBUG: 8992: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4076E1000, size: 0x1000.
2026-05-28 20:44:33,199 [root] DEBUG: 8992: DLL loaded at 0x00007FFE97140000: C:\Windows\ImmersiveControlPanel\SystemSettingsViewModel.Desktop (0xbc000 bytes).
2026-05-28 20:44:33,204 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDFE80000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 20:44:33,209 [root] DEBUG: 8992: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\msctf (0x114000 bytes).
2026-05-28 20:44:33,213 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDEB00000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 20:44:33,217 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDE2F0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 20:44:33,225 [root] DEBUG: 8992: DLL loaded at 0x00007FFEED4F0000: C:\Windows\SYSTEM32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:44:33,235 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDC530000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-28 20:44:33,251 [root] DEBUG: 8992: DLL loaded at 0x00007FFED61D0000: C:\Windows\SYSTEM32\windows.ui.core.textinput (0x104000 bytes).
2026-05-28 20:44:33,262 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF640000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 20:44:33,262 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE2620000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 20:44:33,270 [root] DEBUG: 8992: DLL loaded at 0x00007FFED88A0000: C:\Windows\system32\DataExchange (0x3e000 bytes).
2026-05-28 20:44:33,299 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE6360000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 20:44:33,304 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE9FE0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 20:44:33,316 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:44:33,316 [root] DEBUG: 8992: DLL loaded at 0x00007FFED0720000: C:\Windows\SYSTEM32\REGAPI (0x3b000 bytes).
2026-05-28 20:44:33,316 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:44:33,317 [root] DEBUG: 8992: DLL loaded at 0x00007FFED0760000: C:\Windows\SYSTEM32\SettingsEnvironment.Desktop (0x94000 bytes).
2026-05-28 20:44:33,317 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:44:33,339 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 20:44:33,341 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF440000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 20:44:33,343 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE1520000: C:\Windows\System32\NetworkUXBroker (0x6d000 bytes).
2026-05-28 20:44:33,349 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:44:33,350 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 20:44:33,351 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE14E0000: C:\Windows\System32\EthernetMediaManager (0x34000 bytes).
2026-05-28 20:44:33,352 [root] DEBUG: 8992: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:44:33,354 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEADC0000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:44:33,358 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:44:33,372 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:44:33,403 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE6180000: C:\Windows\SYSTEM32\samcli (0x19000 bytes).
2026-05-28 20:44:33,405 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDFA10000: C:\Windows\system32\credprovhost (0x69000 bytes).
2026-05-28 20:44:33,429 [root] DEBUG: 8992: api-rate-cap: IsDebuggerPresent hook disabled due to rate
2026-05-28 20:44:33,445 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE21F0000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2026-05-28 20:44:33,459 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE20B0000: C:\Windows\System32\Windows.UI.Xaml.Phone (0x13c000 bytes).
2026-05-28 20:44:33,489 [root] DEBUG: 8992: DLL loaded at 0x00007FFEED220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 20:44:33,490 [root] DEBUG: 8992: DLL loaded at 0x00007FFED7960000: C:\Windows\SYSTEM32\pdh (0x49000 bytes).
2026-05-28 20:44:33,490 [root] DEBUG: 8992: DLL loaded at 0x00007FFED79B0000: C:\Windows\system32\twinui (0x5f4000 bytes).
2026-05-28 20:44:33,509 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:44:33,526 [root] DEBUG: 8992: DLL loaded at 0x00007FFED98B0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 20:44:33,527 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDEB40000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:44:33,541 [root] DEBUG: 8992: DLL loaded at 0x00007FFED95F0000: C:\Windows\System32\CloudExperienceHostBroker (0x57000 bytes).
2026-05-28 20:44:33,546 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDCBB0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 20:44:33,551 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:44:33,551 [root] DEBUG: 8992: DLL loaded at 0x00007FFED9890000: C:\Windows\SYSTEM32\credui (0x19000 bytes).
2026-05-28 20:44:33,552 [root] DEBUG: 8992: DLL loaded at 0x00007FFE96F90000: C:\Windows\SYSTEM32\DUI70 (0x1ae000 bytes).
2026-05-28 20:44:33,553 [root] DEBUG: 8992: DLL loaded at 0x00007FFED5DA0000: C:\Windows\System32\oobe\UserOOBE (0x6d000 bytes).
2026-05-28 20:44:33,562 [root] INFO: Added new file to list with pid 8992 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\R27Q88QHEI29DO8CQYD2.temp
2026-05-28 20:44:33,566 [root] INFO: Added new file to list with pid 8992 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\f18460fded109990.customDestinations-ms
2026-05-28 20:44:33,574 [root] DEBUG: 8992: DLL loaded at 0x00007FFED95A0000: C:\Windows\SYSTEM32\wdscore (0x43000 bytes).
2026-05-28 20:44:33,578 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDE100000: C:\Windows\system32\dbghelp (0x1e4000 bytes).
2026-05-28 20:44:33,581 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDE0C0000: C:\Windows\SYSTEM32\dbgcore (0x34000 bytes).
2026-05-28 20:44:33,588 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:44:33,589 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEB400000: C:\Windows\SYSTEM32\dsreg (0x141000 bytes).
2026-05-28 20:44:33,589 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDE340000: C:\Windows\SYSTEM32\cdp (0x4d4000 bytes).
2026-05-28 20:44:33,590 [root] DEBUG: 8992: DLL loaded at 0x00007FFED6EF0000: C:\Windows\System32\TaskFlowDataEngine (0x17e000 bytes).
2026-05-28 20:44:33,596 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:44:33,597 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:44:33,598 [root] DEBUG: 8992: OpenProcessHandler: Injection info created for process 4372, handle 0xa24: Error obtaining target process name
2026-05-28 20:44:33,600 [root] INFO: Announced 64-bit process name: explorer.exe pid: 4372
2026-05-28 20:44:33,600 [lib.api.process] INFO: Monitor config for process 4372: C:\6lreqs2g\dll\4372.ini
2026-05-28 20:44:33,601 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:33,601 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 10664: C:\Windows\System32\oobe\UserOOBEBroker.exe, ImageBase: 0x00007FF6A3ED0000
2026-05-28 20:44:33,602 [root] INFO: Announced 64-bit process name: UserOOBEBroker.exe pid: 10664
2026-05-28 20:44:33,602 [lib.api.process] INFO: Monitor config for process 10664: C:\6lreqs2g\dll\10664.ini
2026-05-28 20:44:33,603 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:33,603 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:33,607 [root] DEBUG: Loader: Injecting process 4372 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,608 [root] DEBUG: 4372: caller_dispatch: Added region at 0x0000000008800000 to tracked regions list (ntdll::LdrLoadDll returns to 0x0000000008800044, thread 10708).
2026-05-28 20:44:33,609 [root] DEBUG: 4372: DumpPEsInRange: Scanning range 0x0000000008800000 - 0x0000000008800135.
2026-05-28 20:44:33,609 [root] DEBUG: 4372: ScanForDisguisedPE: Size too small: 0x135 bytes
2026-05-28 20:44:33,611 [lib.common.results] INFO: Uploading file C:\SBYTiH\CAPE\4372_246823344029552026 to CAPE\b3c26870976880f255a78702f0b558827b005975dd89a64f0eff0b54f313fcea; Size is 309; Max size: 100000000
2026-05-28 20:44:33,612 [root] DEBUG: 4372: DumpMemory: Payload successfully created: C:\SBYTiH\CAPE\4372_246823344029552026 (size 309 bytes)
2026-05-28 20:44:33,613 [root] DEBUG: 4372: DumpRegion: Dumped entire allocation from 0x0000000008800000, size 4096 bytes.
2026-05-28 20:44:33,613 [root] DEBUG: 4372: ProcessTrackedRegion: Dumped region at 0x0000000008800000.
2026-05-28 20:44:33,613 [root] DEBUG: 4372: YaraScan: Scanning 0x0000000008800000, size 0x135
2026-05-28 20:44:33,614 [root] DEBUG: 4372: Monitor config - unrecognised key host-ip.
2026-05-28 20:44:33,615 [root] DEBUG: 4372: Monitor config - unrecognised key host-port.
2026-05-28 20:44:33,615 [root] DEBUG: 4372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:33,615 [root] DEBUG: 4372: Dropped file limit defaulting to 100.
2026-05-28 20:44:33,634 [root] DEBUG: 4372: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:44:33,655 [root] DEBUG: 8992: DLL loaded at 0x00007FFED47D0000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 20:44:33,659 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 10784: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF6D0370000
2026-05-28 20:44:33,660 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 10784
2026-05-28 20:44:33,660 [lib.api.process] INFO: Monitor config for process 10784: C:\6lreqs2g\dll\10784.ini
2026-05-28 20:44:33,661 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:33,662 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:33,666 [root] DEBUG: Loader: Injecting process 10784 (thread 10788) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,667 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:33,668 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,668 [root] DEBUG: 8992: DLL loaded at 0x00007FFED47A0000: C:\Windows\System32\Windows.Internal.Taskbar (0x30000 bytes).
2026-05-28 20:44:33,670 [lib.api.process] INFO: Injected into 64-bit <Process 10784 MoUsoCoreWorker.exe>
2026-05-28 20:44:33,672 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 10784
2026-05-28 20:44:33,672 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE02C0000: C:\Windows\System32\threadpoolwinrt (0x14000 bytes).
2026-05-28 20:44:33,673 [lib.api.process] INFO: Monitor config for process 10784: C:\6lreqs2g\dll\10784.ini
2026-05-28 20:44:33,673 [root] DEBUG: 8992: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 20:44:33,674 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:33,676 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:44:33,676 [root] DEBUG: 4372: set_hooks: Unable to hook LockResource
2026-05-28 20:44:33,676 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:33,677 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDDEA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:44:33,680 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDAFC0000: C:\Windows\System32\twinapi (0xa9000 bytes).
2026-05-28 20:44:33,682 [root] DEBUG: Loader: Injecting process 10784 (thread 10788) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,682 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:33,683 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,684 [lib.api.process] INFO: Injected into 64-bit <Process 10784 MoUsoCoreWorker.exe>
2026-05-28 20:44:33,691 [root] DEBUG: 10784: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:33,692 [root] DEBUG: 10784: Interactive desktop enabled.
2026-05-28 20:44:33,692 [root] DEBUG: 10784: Dropped file limit defaulting to 100.
2026-05-28 20:44:33,694 [root] DEBUG: 10784: VerifyCodeSection: Exception rebasing image from 0x00007FF6D0370000 to 0x0000000140000000.
2026-05-28 20:44:33,697 [root] DEBUG: 10784: Disabling sleep skipping.
2026-05-28 20:44:33,697 [root] DEBUG: 4372: Hooked 627 out of 628 functions
2026-05-28 20:44:33,698 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 8992, handle 0x1194: C:\Windows\ImmersiveControlPanel\SystemSettings.exe
2026-05-28 20:44:33,698 [root] DEBUG: 10784: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:33,708 [root] DEBUG: 8992: DLL loaded at 0x00007FFED4750000: C:\Windows\System32\Windows.Management.InprocObjects (0x4f000 bytes).
2026-05-28 20:44:33,709 [root] DEBUG: 10784: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:33,710 [root] DEBUG: 10784: YaraScan: Scanning 0x00007FF6D0370000, size 0x1ad000
2026-05-28 20:44:33,715 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:33,719 [root] DEBUG: Loader: Injecting process 10664 (thread 10668) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,719 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:33,720 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,720 [root] DEBUG: 10784: Monitor initialised: 64-bit capemon loaded in process 10784 at 0x00007FFEAF1A0000, thread 10788, image base 0x00007FF6D0370000, stack from 0x000000A592CB4000-0x000000A592CC0000
2026-05-28 20:44:33,721 [root] DEBUG: 10784: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-05-28 20:44:33,721 [lib.api.process] INFO: Injected into 64-bit <Process 10664 UserOOBEBroker.exe>
2026-05-28 20:44:33,724 [root] INFO: Announced 64-bit process name: UserOOBEBroker.exe pid: 10664
2026-05-28 20:44:33,724 [lib.api.process] INFO: Monitor config for process 10664: C:\6lreqs2g\dll\10664.ini
2026-05-28 20:44:33,725 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:33,726 [root] INFO: Loaded monitor into process with pid 4372
2026-05-28 20:44:33,730 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 20:44:33,730 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,731 [root] DEBUG: 10784: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:44:33,753 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:44:33,754 [root] DEBUG: 10784: set_hooks: Unable to hook LockResource
2026-05-28 20:44:33,760 [root] DEBUG: 10784: Hooked 627 out of 628 functions
2026-05-28 20:44:33,761 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDA210000: C:\Windows\System32\CapabilityAccessManagerClient (0x3f000 bytes).
2026-05-28 20:44:33,763 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE1330000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 20:44:33,770 [root] DEBUG: 10784: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:33,774 [root] DEBUG: 10784: RestoreHeaders: Restored original import table.
2026-05-28 20:44:33,776 [root] DEBUG: 8992: DLL loaded at 0x00007FFED0560000: C:\Windows\SYSTEM32\MFPlat (0x1bb000 bytes).
2026-05-28 20:44:33,776 [root] INFO: Loaded monitor into process with pid 10784
2026-05-28 20:44:33,781 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDFD90000: C:\Windows\SYSTEM32\RTWorkQ (0x34000 bytes).
2026-05-28 20:44:33,782 [root] DEBUG: 10784: caller_dispatch: Added region at 0x00007FF6D0370000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6D048F712, thread 10788).
2026-05-28 20:44:33,783 [root] DEBUG: 10784: YaraScan: Scanning 0x00007FF6D0370000, size 0x1ad000
2026-05-28 20:44:33,794 [root] DEBUG: 10784: ProcessImageBase: Main module image at 0x00007FF6D0370000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:44:33,797 [root] DEBUG: 10784: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:33,798 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:44:33,799 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE9310000: C:\Windows\system32\windowscodecs (0x1b4000 bytes).
2026-05-28 20:44:33,817 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:33,822 [root] DEBUG: Loader: Injecting process 10664 (thread 10668) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,822 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:33,823 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:33,824 [lib.api.process] INFO: Injected into 64-bit <Process 10664 UserOOBEBroker.exe>
2026-05-28 20:44:33,825 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDFF70000: C:\Windows\SYSTEM32\msftedit (0x34d000 bytes).
2026-05-28 20:44:33,825 [root] DEBUG: 10784: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:44:33,830 [root] DEBUG: 10664: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:33,830 [root] DEBUG: 10664: Interactive desktop enabled.
2026-05-28 20:44:33,830 [root] DEBUG: 10664: Dropped file limit defaulting to 100.
2026-05-28 20:44:33,832 [root] DEBUG: 10664: Disabling sleep skipping.
2026-05-28 20:44:33,833 [root] DEBUG: 10664: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:33,834 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE41B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 20:44:33,842 [root] DEBUG: 10784: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:44:33,844 [root] DEBUG: 10664: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:33,845 [root] DEBUG: 10664: YaraScan: Scanning 0x00007FF6A3ED0000, size 0x192fe
2026-05-28 20:44:33,846 [root] DEBUG: 10664: Monitor initialised: 64-bit capemon loaded in process 10664 at 0x00007FFEAF1A0000, thread 10668, image base 0x00007FF6A3ED0000, stack from 0x000000F0C8F94000-0x000000F0C8FA0000
2026-05-28 20:44:33,847 [root] DEBUG: 10664: Commandline: C:\Windows\System32\oobe\UserOOBEBroker.exe -Embedding
2026-05-28 20:44:33,856 [root] DEBUG: 10784: DLL loaded at 0x00007FFED0B00000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-05-28 20:44:33,857 [root] DEBUG: 10664: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:44:33,877 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:44:33,878 [root] DEBUG: 10664: set_hooks: Unable to hook LockResource
2026-05-28 20:44:33,879 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE78F0000: C:\Windows\System32\Windows.Graphics (0x8d000 bytes).
2026-05-28 20:44:33,883 [root] DEBUG: 10664: Hooked 627 out of 628 functions
2026-05-28 20:44:33,884 [root] DEBUG: 10664: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:33,889 [root] DEBUG: 10664: RestoreHeaders: Restored original import table.
2026-05-28 20:44:33,889 [root] INFO: Loaded monitor into process with pid 10664
2026-05-28 20:44:33,890 [root] DEBUG: 10664: caller_dispatch: Added region at 0x00007FF6A3ED0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6A3EDD371, thread 10668).
2026-05-28 20:44:33,891 [root] DEBUG: 10664: YaraScan: Scanning 0x00007FF6A3ED0000, size 0x192fe
2026-05-28 20:44:33,892 [root] DEBUG: 10664: ProcessImageBase: Main module image at 0x00007FF6A3ED0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:44:33,894 [root] DEBUG: 10664: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:33,895 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:44:33,897 [root] DEBUG: 10664: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:44:33,914 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:44:33,922 [root] DEBUG: 10664: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:44:33,922 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEE870000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 20:44:33,923 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 20:44:33,924 [root] DEBUG: 10664: DLL loaded at 0x00007FFEE6180000: C:\Windows\SYSTEM32\samcli (0x19000 bytes).
2026-05-28 20:44:33,924 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:44:33,925 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:44:33,925 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:44:33,926 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:44:33,926 [root] DEBUG: 10664: DLL loaded at 0x00007FFED9890000: C:\Windows\SYSTEM32\credui (0x19000 bytes).
2026-05-28 20:44:33,927 [root] DEBUG: 10664: DLL loaded at 0x00007FFE96F90000: C:\Windows\SYSTEM32\DUI70 (0x1ae000 bytes).
2026-05-28 20:44:33,927 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:44:33,927 [root] DEBUG: 10664: DLL loaded at 0x00007FFEEE250000: C:\Windows\SYSTEM32\SLC (0x29000 bytes).
2026-05-28 20:44:33,928 [root] DEBUG: 10664: DLL loaded at 0x00007FFED5DA0000: C:\Windows\System32\oobe\UserOOBE (0x6d000 bytes).
2026-05-28 20:44:33,929 [root] DEBUG: 10664: DLL loaded at 0x00007FFED95A0000: C:\Windows\SYSTEM32\wdscore (0x43000 bytes).
2026-05-28 20:44:33,930 [root] DEBUG: 10664: DLL loaded at 0x00007FFEDE100000: C:\Windows\system32\dbghelp (0x1e4000 bytes).
2026-05-28 20:44:33,932 [root] DEBUG: 10664: DLL loaded at 0x00007FFEDE0C0000: C:\Windows\SYSTEM32\dbgcore (0x34000 bytes).
2026-05-28 20:44:33,940 [root] DEBUG: 10664: DLL loaded at 0x00007FFEE88C0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 20:44:33,944 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDEC10000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 20:44:33,945 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE88C0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 20:44:33,950 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 11372: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exe, ImageBase: 0x0000000000610000
2026-05-28 20:44:33,951 [root] INFO: Announced 32-bit process name: FileCoAuth.exe pid: 11372
2026-05-28 20:44:33,951 [lib.api.process] INFO: Monitor config for process 11372: C:\6lreqs2g\dll\11372.ini
2026-05-28 20:44:33,952 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:33,984 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDE9E0000: C:\Windows\SYSTEM32\FLTLIB (0xb000 bytes).
2026-05-28 20:44:33,985 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEC8E0000: C:\Windows\SYSTEM32\virtdisk (0x13000 bytes).
2026-05-28 20:44:34,001 [root] DEBUG: 8992: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4076D1000, size: 0x1000.
2026-05-28 20:44:34,004 [root] DEBUG: 8992: DLL loaded at 0x00007FFEEB240000: C:\Windows\SYSTEM32\XmlLite (0x36000 bytes).
2026-05-28 20:44:34,006 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDDAE0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 20:44:34,018 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE6C40000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 20:44:34,021 [root] DEBUG: 8992: CreateProcessHandler: Injection info set for new process 11432: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:44:34,022 [root] INFO: Announced 64-bit process name: msedge.exe pid: 11432
2026-05-28 20:44:34,022 [lib.api.process] INFO: Monitor config for process 11432: C:\6lreqs2g\dll\11432.ini
2026-05-28 20:44:34,023 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:34,024 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:34,028 [root] DEBUG: Loader: Injecting process 11432 (thread 11436) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,029 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:34,029 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,030 [root] DEBUG: 8992: DLL loaded at 0x00007FFED4610000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 20:44:34,030 [lib.api.process] INFO: Injected into 64-bit <Process 11432 msedge.exe>
2026-05-28 20:44:34,032 [root] INFO: Announced 64-bit process name: msedge.exe pid: 11432
2026-05-28 20:44:34,032 [lib.api.process] INFO: Monitor config for process 11432: C:\6lreqs2g\dll\11432.ini
2026-05-28 20:44:34,033 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:34,034 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:34,038 [root] DEBUG: Loader: Injecting process 11432 (thread 11436) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,039 [root] DEBUG: 8992: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4076C1000, size: 0x1000.
2026-05-28 20:44:34,039 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:34,040 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,040 [root] DEBUG: 8992: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4076B1000, size: 0x1000.
2026-05-28 20:44:34,041 [lib.api.process] INFO: Injected into 64-bit <Process 11432 msedge.exe>
2026-05-28 20:44:34,045 [root] DEBUG: 8992: DLL loaded at 0x00007FFEE8A00000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 20:44:34,045 [root] DEBUG: 8992: DLL loaded at 0x00007FFED0AA0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 20:44:34,047 [root] DEBUG: 8992: DLL loaded at 0x00007FFEDD4B0000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 20:44:34,052 [root] DEBUG: 8992: DLL loaded at 0x00007FFEF0250000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 20:44:34,053 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-28 20:44:34,058 [root] INFO: Announced 64-bit process name: msedge.exe pid: 11432
2026-05-28 20:44:34,058 [lib.api.process] INFO: Monitor config for process 11432: C:\6lreqs2g\dll\11432.ini
2026-05-28 20:44:34,058 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:34,060 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:34,064 [root] DEBUG: Loader: Injecting process 11432 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,065 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 11436, handle 0x130
2026-05-28 20:44:34,065 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:34,065 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,066 [lib.api.process] INFO: 32-bit DLL to inject is C:\6lreqs2g\dll\zcbhSwuz.dll, loader C:\6lreqs2g\bin\NdEGsDk.exe
2026-05-28 20:44:34,067 [lib.api.process] INFO: Injected into 64-bit <Process 11432 msedge.exe>
2026-05-28 20:44:34,070 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 20:44:34,070 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEF430000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 20:44:34,071 [root] DEBUG: 10784: DLL loaded at 0x00007FFED48E0000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-05-28 20:44:34,075 [root] DEBUG: Loader: Injecting process 11372 (thread 11376) with C:\6lreqs2g\dll\zcbhSwuz.dll.
2026-05-28 20:44:34,076 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:34,076 [root] DEBUG: 11432: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:34,076 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\zcbhSwuz.dll.
2026-05-28 20:44:34,077 [root] DEBUG: 11432: Interactive desktop enabled.
2026-05-28 20:44:34,077 [root] DEBUG: 11432: Dropped file limit defaulting to 100.
2026-05-28 20:44:34,077 [root] DEBUG: 10784: DLL loaded at 0x00007FFEDDB70000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 20:44:34,078 [lib.api.process] INFO: Injected into 32-bit <Process 11372 FileCoAuth.exe>
2026-05-28 20:44:34,079 [root] INFO: Announced 32-bit process name: FileCoAuth.exe pid: 11372
2026-05-28 20:44:34,079 [root] DEBUG: 10784: DLL loaded at 0x00007FFED0890000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 20:44:34,079 [lib.api.process] INFO: Monitor config for process 11372: C:\6lreqs2g\dll\11372.ini
2026-05-28 20:44:34,080 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:34,080 [root] DEBUG: 11432: Edge-specific hook-set enabled.
2026-05-28 20:44:34,081 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 20:44:34,081 [root] DEBUG: 11432: Disabling sleep skipping.
2026-05-28 20:44:34,082 [root] DEBUG: 11432: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:34,083 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEF440000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-05-28 20:44:34,095 [root] DEBUG: 11432: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:34,095 [root] DEBUG: 11432: Monitor initialised: 64-bit capemon loaded in process 11432 at 0x00007FFEAF1A0000, thread 11436, image base 0x00007FF60A060000, stack from 0x000000A3BCDF4000-0x000000A3BCE00000
2026-05-28 20:44:34,096 [root] DEBUG: 11432: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --default-search-provider=? --out-pipe-name=MSEdgeDefault6552b470h1c18h43e1hbe9ehd852e84e3496
2026-05-28 20:44:34,108 [root] DEBUG: 11432: Hooked 2 out of 2 functions
2026-05-28 20:44:34,135 [root] DEBUG: 11432: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:34,140 [root] DEBUG: 11432: RestoreHeaders: Restored original import table.
2026-05-28 20:44:34,140 [root] INFO: Loaded monitor into process with pid 11432
2026-05-28 20:44:34,141 [root] DEBUG: 11432: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:44:34,143 [root] DEBUG: 11432: DLL loaded at 0x00007FFED9040000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 20:44:34,144 [root] DEBUG: 11432: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:44:34,145 [root] DEBUG: 11432: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:44:34,162 [root] DEBUG: 11432: DLL loaded at 0x00007FFED8180000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 20:44:34,162 [root] DEBUG: 11432: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:44:34,165 [root] DEBUG: 11432: DLL loaded at 0x00007FFEDD470000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 20:44:34,167 [root] DEBUG: 11432: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:44:34,169 [lib.api.process] INFO: Potential dll side-loading detected in local directory: ucrtbase.dll
2026-05-28 20:44:34,171 [root] DEBUG: 11432: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:34,173 [lib.api.process] INFO: 32-bit DLL to inject is C:\6lreqs2g\dll\zcbhSwuz.dll, loader C:\6lreqs2g\bin\NdEGsDk.exe
2026-05-28 20:44:34,180 [root] DEBUG: Loader: Injecting process 11372 (thread 11376) with C:\6lreqs2g\dll\zcbhSwuz.dll.
2026-05-28 20:44:34,182 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:34,183 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\zcbhSwuz.dll.
2026-05-28 20:44:34,184 [lib.api.process] INFO: Injected into 32-bit <Process 11372 FileCoAuth.exe>
2026-05-28 20:44:34,193 [root] DEBUG: 10784: DLL loaded at 0x00007FFED0890000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 20:44:34,195 [root] DEBUG: 11372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:34,196 [root] DEBUG: 11372: Interactive desktop enabled.
2026-05-28 20:44:34,197 [root] DEBUG: 11372: Dropped file limit defaulting to 100.
2026-05-28 20:44:34,199 [root] DEBUG: 11372: Disabling sleep skipping.
2026-05-28 20:44:34,200 [root] DEBUG: 11372: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:34,201 [root] DEBUG: 11372: YaraScan: Scanning 0x00610000, size 0xa2732
2026-05-28 20:44:34,208 [root] DEBUG: 11372: Monitor initialised: 32-bit capemon loaded in process 11372 at 0x6c5b0000, thread 11376, image base 0x610000, stack from 0x5334000-0x5340000
2026-05-28 20:44:34,209 [root] DEBUG: 11372: Commandline: "C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuth.exe" -Embedding
2026-05-28 20:44:34,209 [root] DEBUG: 11372: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\UpdateRingSettings.dll
2026-05-28 20:44:34,210 [root] DEBUG: 11372: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\MSVCP140.dll
2026-05-28 20:44:34,211 [root] DEBUG: 11372: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\VCRUNTIME140.dll
2026-05-28 20:44:34,211 [root] DEBUG: 11372: add_all_dlls_to_dll_ranges: skipping C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\LoggingPlatform.DLL
2026-05-28 20:44:34,235 [root] DEBUG: 11372: hook_api: LdrpCallInitRoutine export address 0x776C2B50 obtained via GetFunctionAddress
2026-05-28 20:44:34,249 [root] DEBUG: 11372: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-28 20:44:34,250 [root] DEBUG: 11372: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-28 20:44:34,256 [root] DEBUG: 11372: Hooked 632 out of 632 functions
2026-05-28 20:44:34,261 [root] DEBUG: 11372: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:34,266 [root] DEBUG: 11372: RestoreHeaders: Restored original import table.
2026-05-28 20:44:34,267 [root] INFO: Loaded monitor into process with pid 11372
2026-05-28 20:44:34,269 [root] DEBUG: 11372: YaraScan: Scanning 0x740B0000, size 0x13ac6
2026-05-28 20:44:34,270 [root] DEBUG: 11372: caller_dispatch: Added region at 0x740B0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x740B7916, thread 11376).
2026-05-28 20:44:34,270 [root] DEBUG: 11372: caller_dispatch: Scanning calling region at 0x740B0000...
2026-05-28 20:44:34,271 [root] DEBUG: 11372: ProcessTrackedRegion: Region at 0x740B0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\vcruntime140.dll appears unmodified, skipping
2026-05-28 20:44:34,272 [root] DEBUG: 11372: YaraScan: Scanning 0x740D0000, size 0x6c6de
2026-05-28 20:44:34,274 [root] DEBUG: 11372: caller_dispatch: Added region at 0x740D0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x740FE9DC, thread 11376).
2026-05-28 20:44:34,276 [root] DEBUG: 11372: caller_dispatch: Scanning calling region at 0x740D0000...
2026-05-28 20:44:34,278 [root] DEBUG: 11372: ProcessTrackedRegion: Region at 0x740D0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\msvcp140.dll appears unmodified, skipping
2026-05-28 20:44:34,279 [root] DEBUG: 11372: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:44:34,282 [root] DEBUG: 11372: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:44:34,285 [root] DEBUG: 11372: YaraScan: Scanning 0x74140000, size 0x7ebdc
2026-05-28 20:44:34,288 [root] DEBUG: 11372: caller_dispatch: Added region at 0x74140000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x7418AF34, thread 11376).
2026-05-28 20:44:34,289 [root] DEBUG: 11372: caller_dispatch: Scanning calling region at 0x74140000...
2026-05-28 20:44:34,291 [root] DEBUG: 11372: ProcessTrackedRegion: Region at 0x74140000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\LoggingPlatform.dll appears unmodified, skipping
2026-05-28 20:44:34,292 [root] DEBUG: 11372: DLL loaded at 0x76970000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-28 20:44:34,293 [root] DEBUG: 11372: YaraScan: Scanning 0x737B0000, size 0x6ce84
2026-05-28 20:44:34,297 [root] DEBUG: 11372: caller_dispatch: Added region at 0x737B0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x737F0864, thread 11376).
2026-05-28 20:44:34,298 [root] DEBUG: 11372: caller_dispatch: Scanning calling region at 0x737B0000...
2026-05-28 20:44:34,299 [root] DEBUG: 11372: ProcessTrackedRegion: Region at 0x737B0000 mapped as \Device\HarddiskVolume2\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\UpdateRingSettings.dll appears unmodified, skipping
2026-05-28 20:44:34,300 [root] DEBUG: 11372: caller_dispatch: Added region at 0x00610000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00662D18, thread 11376).
2026-05-28 20:44:34,301 [root] DEBUG: 11372: YaraScan: Scanning 0x00610000, size 0xa2732
2026-05-28 20:44:34,305 [root] DEBUG: 11372: ProcessImageBase: Main module image at 0x00610000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:44:34,312 [root] DEBUG: 11372: DLL loaded at 0x74080000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-28 20:44:34,313 [root] DEBUG: 11372: DLL loaded at 0x74050000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2026-05-28 20:44:34,315 [root] DEBUG: 11372: DLL loaded at 0x748E0000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-28 20:44:34,316 [root] DEBUG: 11372: DLL loaded at 0x74910000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-28 20:44:34,317 [root] DEBUG: 11372: DLL loaded at 0x77250000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-28 20:44:34,319 [root] DEBUG: 11372: DLL loaded at 0x74030000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-28 20:44:34,329 [root] DEBUG: 11372: DLL loaded at 0x73E50000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-05-28 20:44:34,330 [root] DEBUG: 11372: DLL loaded at 0x73E90000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\OneDriveTelemetryStable (0x19a000 bytes).
2026-05-28 20:44:34,331 [root] DEBUG: 11372: DLL loaded at 0x74880000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncTelemetryExtensions (0x10000 bytes).
2026-05-28 20:44:34,336 [root] INFO: Added new file to list with pid 11372 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Common\DeviceHealthSummaryConfiguration.ini
2026-05-28 20:44:34,338 [root] INFO: Process with pid 11432 appears to have terminated
2026-05-28 20:44:34,339 [root] DEBUG: 11372: DLL loaded at 0x74800000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-28 20:44:34,340 [root] DEBUG: 11372: DLL loaded at 0x74F60000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-05-28 20:44:34,342 [root] DEBUG: 11372: DLL loaded at 0x75550000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-28 20:44:34,424 [root] DEBUG: 11372: DLL loaded at 0x74860000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileCoAuthLib (0x2a000 bytes).
2026-05-28 20:44:34,474 [root] DEBUG: 10664: DLL loaded at 0x00007FFED0270000: C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\amd64\FileCoAuthLib64 (0x31000 bytes).
2026-05-28 20:44:34,618 [root] DEBUG: 8992: OpenProcessHandler: Injection info created for process 4100, handle 0xee8: C:\Windows\System32\sihost.exe
2026-05-28 20:44:34,626 [root] DEBUG: 8992: CreateProcessHandler: Injection info set for new process 12124: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:44:34,626 [root] INFO: Announced 64-bit process name: msedge.exe pid: 12124
2026-05-28 20:44:34,626 [lib.api.process] INFO: Monitor config for process 12124: C:\6lreqs2g\dll\12124.ini
2026-05-28 20:44:34,630 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:34,635 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:34,639 [root] DEBUG: Loader: Injecting process 12124 (thread 12128) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,639 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:34,640 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,641 [lib.api.process] INFO: Injected into 64-bit <Process 12124 msedge.exe>
2026-05-28 20:44:34,643 [root] INFO: Announced 64-bit process name: msedge.exe pid: 12124
2026-05-28 20:44:34,643 [lib.api.process] INFO: Monitor config for process 12124: C:\6lreqs2g\dll\12124.ini
2026-05-28 20:44:34,644 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:34,652 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:34,657 [root] DEBUG: Loader: Injecting process 12124 (thread 12128) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,658 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:34,658 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,660 [lib.api.process] INFO: Injected into 64-bit <Process 12124 msedge.exe>
2026-05-28 20:44:34,664 [root] INFO: Announced 64-bit process name: msedge.exe pid: 12124
2026-05-28 20:44:34,665 [lib.api.process] INFO: Monitor config for process 12124: C:\6lreqs2g\dll\12124.ini
2026-05-28 20:44:34,667 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:34,670 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:34,674 [root] DEBUG: Loader: Injecting process 12124 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,675 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12128, handle 0x120
2026-05-28 20:44:34,675 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:34,676 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:34,677 [lib.api.process] INFO: Injected into 64-bit <Process 12124 msedge.exe>
2026-05-28 20:44:34,684 [root] DEBUG: 12124: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:34,685 [root] DEBUG: 12124: Interactive desktop enabled.
2026-05-28 20:44:34,685 [root] DEBUG: 12124: Dropped file limit defaulting to 100.
2026-05-28 20:44:34,688 [root] DEBUG: 12124: Edge-specific hook-set enabled.
2026-05-28 20:44:34,689 [root] DEBUG: 12124: Disabling sleep skipping.
2026-05-28 20:44:34,690 [root] DEBUG: 12124: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:34,702 [root] DEBUG: 12124: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:34,702 [root] DEBUG: 12124: Monitor initialised: 64-bit capemon loaded in process 12124 at 0x00007FFEAF1A0000, thread 12128, image base 0x00007FF60A060000, stack from 0x00000036FA7F4000-0x00000036FA800000
2026-05-28 20:44:34,703 [root] DEBUG: 12124: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --default-search-provider=? --out-pipe-name=MSEdgeDefault380a3d0eh6309h424fhb8c1h5aef19278608
2026-05-28 20:44:34,715 [root] DEBUG: 12124: Hooked 2 out of 2 functions
2026-05-28 20:44:34,742 [root] DEBUG: 12124: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:34,746 [root] DEBUG: 12124: RestoreHeaders: Restored original import table.
2026-05-28 20:44:34,747 [root] INFO: Loaded monitor into process with pid 12124
2026-05-28 20:44:34,748 [root] DEBUG: 12124: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:44:34,750 [root] DEBUG: 12124: DLL loaded at 0x00007FFED9040000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 20:44:34,751 [root] DEBUG: 12124: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:44:34,752 [root] DEBUG: 12124: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:44:34,769 [root] DEBUG: 12124: DLL loaded at 0x00007FFED8180000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 20:44:34,769 [root] DEBUG: 12124: DLL loaded at 0x00007FFE9B620000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:44:34,772 [root] DEBUG: 12124: DLL loaded at 0x00007FFEDD470000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 20:44:34,774 [root] DEBUG: 12124: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:44:34,778 [root] DEBUG: 12124: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:35,353 [root] INFO: Process with pid 12124 appears to have terminated
2026-05-28 20:44:35,830 [root] DEBUG: 10784: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 20:44:37,706 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 7356, handle 0x21f8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 20:44:37,762 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:44:37,763 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6220, handle 0x21fc: Error obtaining target process name
2026-05-28 20:44:37,763 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:44:37,764 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 8780, handle 0x20b8: Error obtaining target process name
2026-05-28 20:44:37,768 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:44:37,769 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6028, handle 0x209c: Error obtaining target process name
2026-05-28 20:44:37,770 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:44:37,770 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6632, handle 0x162c: Error obtaining target process name
2026-05-28 20:44:37,771 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:44:37,771 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 9844, handle 0x1fc4: Error obtaining target process name
2026-05-28 20:44:37,772 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:44:37,772 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 7448, handle 0xeb0: Error obtaining target process name
2026-05-28 20:44:37,816 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:44:37,817 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:44:37,822 [root] DEBUG: 10784: DLL loaded at 0x00007FFED47D0000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 20:44:37,824 [root] DEBUG: 10784: DLL loaded at 0x00007FFED8B50000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 20:44:37,827 [root] DEBUG: 10784: DLL loaded at 0x00007FFEDDEA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:44:37,830 [root] DEBUG: 10784: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:44:37,834 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEB550000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 20:44:37,841 [root] DEBUG: 10784: DLL loaded at 0x00007FFEE6100000: C:\Windows\SYSTEM32\productenumerator (0xe000 bytes).
2026-05-28 20:44:38,184 [root] INFO: Stopping Task Scheduler Service
2026-05-28 20:44:38,196 [root] INFO: Stopped Task Scheduler Service
2026-05-28 20:44:38,200 [root] INFO: Starting Task Scheduler Service
2026-05-28 20:44:38,209 [root] INFO: Started Task Scheduler Service
2026-05-28 20:44:38,210 [lib.api.process] INFO: Monitor config for process 1212: C:\6lreqs2g\dll\1212.ini
2026-05-28 20:44:38,211 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:38,214 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:38,218 [root] DEBUG: Loader: Injecting process 1212 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:38,221 [root] DEBUG: 1212: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:38,222 [root] DEBUG: 1212: Disabling sleep skipping.
2026-05-28 20:44:38,222 [root] DEBUG: 1212: Interactive desktop enabled.
2026-05-28 20:44:38,223 [root] DEBUG: 1212: Dropped file limit defaulting to 100.
2026-05-28 20:44:38,224 [root] DEBUG: 1212: Services hook set enabled
2026-05-28 20:44:38,225 [root] DEBUG: 1212: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:38,239 [root] DEBUG: 1212: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:38,240 [root] DEBUG: 1212: Monitor initialised: 64-bit capemon loaded in process 1212 at 0x00007FFEAF1A0000, thread 9144, image base 0x00007FF6A8D80000, stack from 0x0000004FD9CF4000-0x0000004FD9D00000
2026-05-28 20:44:38,241 [root] DEBUG: 1212: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-28 20:44:38,252 [root] DEBUG: 1212: Hooked 69 out of 69 functions
2026-05-28 20:44:38,253 [root] INFO: Loaded monitor into process with pid 1212
2026-05-28 20:44:38,254 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:44:38,255 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:38,257 [lib.api.process] INFO: Injected into 64-bit <Process 1212 svchost.exe>
2026-05-28 20:44:40,273 [root] DEBUG: 10784: DLL loaded at 0x00007FFEEACF0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 20:44:40,311 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-28 20:44:40,312 [lib.api.process] INFO: Monitor config for process 708: C:\6lreqs2g\dll\708.ini
2026-05-28 20:44:40,313 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:40,314 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:40,319 [root] DEBUG: Loader: Injecting process 708 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:40,320 [root] DEBUG: Loader: Copied config file C:\6lreqs2g\dll\708.ini to system path C:\708.ini
2026-05-28 20:44:40,323 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 708 C:\6lreqs2g\dll\TXUMxByw.dll
2026-05-28 20:44:40,323 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:40,325 [lib.api.process] INFO: Injected into 64-bit <Process 708 services.exe>
2026-05-28 20:44:40,528 [root] INFO: Added new file to list with pid 11372 and path C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Common\FileCoAuth-2026-05-29.0044.11372.1.aodl
2026-05-28 20:44:40,532 [root] DEBUG: 11372: NtTerminateProcess hook: Attempting to dump process 11372
2026-05-28 20:44:40,533 [root] DEBUG: 11372: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:44:40,540 [root] INFO: Process with pid 11372 has terminated
2026-05-28 20:44:41,879 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12628: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:44:41,879 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12628
2026-05-28 20:44:41,880 [lib.api.process] INFO: Monitor config for process 12628: C:\6lreqs2g\dll\12628.ini
2026-05-28 20:44:41,881 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:41,885 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:41,890 [root] DEBUG: Loader: Injecting process 12628 (thread 12632) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:41,890 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:41,891 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:41,892 [lib.api.process] INFO: Injected into 64-bit <Process 12628 dllhost.exe>
2026-05-28 20:44:41,894 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12628
2026-05-28 20:44:41,894 [lib.api.process] INFO: Monitor config for process 12628: C:\6lreqs2g\dll\12628.ini
2026-05-28 20:44:41,895 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:41,898 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:41,903 [root] DEBUG: Loader: Injecting process 12628 (thread 12632) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:41,903 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:41,904 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:41,906 [lib.api.process] INFO: Injected into 64-bit <Process 12628 dllhost.exe>
2026-05-28 20:44:41,918 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12844: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7D5630000
2026-05-28 20:44:41,919 [root] DEBUG: 12628: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:41,920 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 12844
2026-05-28 20:44:41,920 [root] DEBUG: 12628: Interactive desktop enabled.
2026-05-28 20:44:41,921 [root] DEBUG: 12628: Dropped file limit defaulting to 100.
2026-05-28 20:44:41,921 [lib.api.process] INFO: Monitor config for process 12844: C:\6lreqs2g\dll\12844.ini
2026-05-28 20:44:41,923 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:41,924 [root] DEBUG: 12628: Disabling sleep skipping.
2026-05-28 20:44:41,925 [root] DEBUG: 12628: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:41,937 [root] DEBUG: 12628: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:41,938 [root] DEBUG: 12628: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:44:41,939 [root] DEBUG: 12628: Monitor initialised: 64-bit capemon loaded in process 12628 at 0x00007FFEAF1A0000, thread 12632, image base 0x00007FF6868D0000, stack from 0x0000005DB93E4000-0x0000005DB93F0000
2026-05-28 20:44:41,940 [root] DEBUG: 12628: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 20:44:41,951 [root] DEBUG: 12628: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:44:41,972 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:44:41,973 [root] DEBUG: 12628: set_hooks: Unable to hook LockResource
2026-05-28 20:44:41,977 [root] DEBUG: 12628: Hooked 627 out of 628 functions
2026-05-28 20:44:41,978 [root] DEBUG: 12628: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:41,983 [root] DEBUG: 12628: RestoreHeaders: Restored original import table.
2026-05-28 20:44:41,984 [root] INFO: Loaded monitor into process with pid 12628
2026-05-28 20:44:41,985 [root] DEBUG: 12628: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 12632).
2026-05-28 20:44:41,985 [root] DEBUG: 12628: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:44:41,986 [root] DEBUG: 12628: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:44:41,988 [root] DEBUG: 12628: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:41,990 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:44:41,992 [root] DEBUG: 12628: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:44:42,005 [root] DEBUG: 12628: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:44:42,020 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:44:42,021 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:44:42,022 [root] DEBUG: 12628: DLL loaded at 0x00007FFEE8D30000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:44:42,024 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:44:42,025 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:44:42,027 [root] DEBUG: 12628: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:44:42,028 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:44:42,030 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:44:42,031 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEF640000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 20:44:42,032 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEB240000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 20:44:42,033 [root] DEBUG: 12628: DLL loaded at 0x00007FFEEEB10000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 20:44:42,034 [root] DEBUG: 12628: DLL loaded at 0x00007FFE95A40000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 20:44:42,038 [root] DEBUG: 12628: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:44:42,046 [root] DEBUG: 12628: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:44:42,441 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:42,445 [root] DEBUG: Loader: Injecting process 12844 (thread 12848) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:42,446 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:42,447 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:42,448 [lib.api.process] INFO: Injected into 64-bit <Process 12844 WmiPrvSE.exe>
2026-05-28 20:44:42,450 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 12844
2026-05-28 20:44:42,451 [lib.api.process] INFO: Monitor config for process 12844: C:\6lreqs2g\dll\12844.ini
2026-05-28 20:44:42,451 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:42,974 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:42,979 [root] DEBUG: Loader: Injecting process 12844 (thread 12848) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:42,980 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:44:42,980 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:42,981 [lib.api.process] INFO: Injected into 64-bit <Process 12844 WmiPrvSE.exe>
2026-05-28 20:44:42,989 [root] DEBUG: 12844: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:42,990 [root] DEBUG: 12844: Interactive desktop enabled.
2026-05-28 20:44:42,991 [root] DEBUG: 12844: Dropped file limit defaulting to 100.
2026-05-28 20:44:42,992 [root] DEBUG: 12844: Disabling sleep skipping.
2026-05-28 20:44:42,993 [root] DEBUG: 12844: Services hook set enabled
2026-05-28 20:44:42,996 [root] DEBUG: 12844: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:43,007 [root] DEBUG: 12844: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:43,008 [root] DEBUG: 12844: Monitor initialised: 64-bit capemon loaded in process 12844 at 0x00007FFEAF1A0000, thread 12848, image base 0x00007FF7D5630000, stack from 0x0000004A96D50000-0x0000004A96D60000
2026-05-28 20:44:43,008 [root] DEBUG: 12844: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 20:44:43,021 [root] DEBUG: 12844: Hooked 69 out of 69 functions
2026-05-28 20:44:43,024 [root] DEBUG: 12844: RestoreHeaders: Restored original import table.
2026-05-28 20:44:43,025 [root] INFO: Loaded monitor into process with pid 12844
2026-05-28 20:44:43,028 [root] DEBUG: 12844: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:43,029 [root] DEBUG: 12844: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:44:43,031 [root] DEBUG: 12844: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:44:43,033 [lib.api.process] INFO: Monitor config for process 9092: C:\6lreqs2g\dll\9092.ini
2026-05-28 20:44:43,034 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:43,037 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:43,041 [root] DEBUG: Loader: Injecting process 9092 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:43,043 [root] DEBUG: 9092: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:43,044 [root] DEBUG: 9092: Disabling sleep skipping.
2026-05-28 20:44:43,044 [root] DEBUG: 9092: Interactive desktop enabled.
2026-05-28 20:44:43,045 [root] DEBUG: 9092: Dropped file limit defaulting to 100.
2026-05-28 20:44:43,046 [root] DEBUG: 9092: Services hook set enabled
2026-05-28 20:44:43,048 [root] DEBUG: 9092: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:43,059 [root] DEBUG: 9092: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:43,060 [root] DEBUG: 9092: Monitor initialised: 64-bit capemon loaded in process 9092 at 0x00007FFEAF1A0000, thread 4136, image base 0x00007FF6A8D80000, stack from 0x000000E79F5F4000-0x000000E79F600000
2026-05-28 20:44:43,060 [root] DEBUG: 9092: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 20:44:43,073 [root] DEBUG: 9092: Hooked 69 out of 69 functions
2026-05-28 20:44:43,074 [root] INFO: Loaded monitor into process with pid 9092
2026-05-28 20:44:43,075 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:44:43,075 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:43,077 [lib.api.process] INFO: Injected into 64-bit <Process 9092 svchost.exe>
2026-05-28 20:44:43,366 [root] DEBUG: 10784: DLL loaded at 0x00007FFEDD7C0000: C:\Windows\system32\WaaSMedicPS (0xc000 bytes).
2026-05-28 20:44:43,471 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\b7df40f421d14f13e6c4abd28c18c07434174606d1c864ac3e6a43b99259e610; Size is 8720; Max size: 100000000
2026-05-28 20:44:43,491 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\30df4577598b6c4324577401e3f54701147b91991b6d2c700a8d1d579b33d44e; Size is 8720; Max size: 100000000
2026-05-28 20:44:43,520 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\375f900b4077cdb0bf337dd41be414b510fc5c3bfe839116102d3f9dcabcbccb; Size is 8720; Max size: 100000000
2026-05-28 20:44:43,540 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\8aa475d97d2e4e812f011019cd6e9d0968e1c4e41f1a7ba29956e70f7ac0a94c; Size is 8720; Max size: 100000000
2026-05-28 20:44:43,560 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\9c0c00cc44772749325103b72125411b932377bfe3393c4cc878f53ad1bfff81; Size is 8720; Max size: 100000000
2026-05-28 20:44:43,674 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\2d7bda7be1d0cdf6d682f97858d25b61f0128a84f394de0172f5760e65691cb0; Size is 12824; Max size: 100000000
2026-05-28 20:44:45,089 [root] DEBUG: 12844: DLL loaded at 0x00007FFEDD9B0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:44:45,092 [root] DEBUG: 12844: DLL loaded at 0x00007FFED9650000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:44:45,103 [root] DEBUG: 12844: DLL loaded at 0x00007FFED0440000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 20:44:45,112 [root] DEBUG: 12844: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:44:45,112 [root] DEBUG: 12844: DLL loaded at 0x00007FFE94C10000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 20:44:45,113 [root] DEBUG: 12844: DLL loaded at 0x00007FFE94C70000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 20:44:45,114 [root] DEBUG: 12844: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:44:45,121 [root] DEBUG: 12844: DLL loaded at 0x00000234E4230000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 20:44:45,122 [root] DEBUG: 12844: DLL loaded at 0x00007FFEEA840000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 20:44:45,123 [root] DEBUG: 12844: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:44:47,059 [root] INFO: Process with pid 12628 has terminated
2026-05-28 20:44:47,060 [root] DEBUG: 12628: NtTerminateProcess hook: Attempting to dump process 12628
2026-05-28 20:44:47,061 [root] DEBUG: 12628: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:44:47,834 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 20:44:47,859 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
2026-05-28 20:44:47,973 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 20:44:47,994 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
2026-05-28 20:44:47,995 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 20:44:48,016 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
2026-05-28 20:44:48,029 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13820: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:44:48,030 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13820
2026-05-28 20:44:48,031 [lib.api.process] INFO: Monitor config for process 13820: C:\6lreqs2g\dll\13820.ini
2026-05-28 20:44:48,035 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:48,038 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:48,071 [root] DEBUG: Loader: Injecting process 13820 (thread 13824) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:48,076 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:48,078 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:48,085 [lib.api.process] INFO: Injected into 64-bit <Process 13820 dllhost.exe>
2026-05-28 20:44:48,088 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13820
2026-05-28 20:44:48,088 [lib.api.process] INFO: Monitor config for process 13820: C:\6lreqs2g\dll\13820.ini
2026-05-28 20:44:48,089 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:44:48,093 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:44:48,098 [root] DEBUG: Loader: Injecting process 13820 (thread 13824) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:48,102 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:44:48,103 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:44:48,105 [lib.api.process] INFO: Injected into 64-bit <Process 13820 dllhost.exe>
2026-05-28 20:44:48,112 [root] DEBUG: 13820: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:44:48,113 [root] DEBUG: 13820: Interactive desktop enabled.
2026-05-28 20:44:48,113 [root] DEBUG: 13820: Dropped file limit defaulting to 100.
2026-05-28 20:44:48,116 [root] DEBUG: 13820: Disabling sleep skipping.
2026-05-28 20:44:48,118 [root] DEBUG: 13820: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:44:48,126 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Discord\app.ico
2026-05-28 20:44:48,132 [root] DEBUG: 13820: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:44:48,133 [root] DEBUG: 13820: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:44:48,134 [root] DEBUG: 13820: Monitor initialised: 64-bit capemon loaded in process 13820 at 0x00007FFEAF1A0000, thread 13824, image base 0x00007FF6868D0000, stack from 0x0000006B5DEF4000-0x0000006B5DF00000
2026-05-28 20:44:48,135 [root] DEBUG: 13820: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:44:48,150 [root] DEBUG: 13820: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:44:48,172 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:44:48,173 [root] DEBUG: 13820: set_hooks: Unable to hook LockResource
2026-05-28 20:44:48,178 [root] DEBUG: 13820: Hooked 627 out of 628 functions
2026-05-28 20:44:48,181 [root] DEBUG: 13820: Syscall hook installed, syscall logging level 1
2026-05-28 20:44:48,192 [root] DEBUG: 13820: RestoreHeaders: Restored original import table.
2026-05-28 20:44:48,197 [root] INFO: Loaded monitor into process with pid 13820
2026-05-28 20:44:48,199 [root] DEBUG: 13820: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 13824).
2026-05-28 20:44:48,202 [root] DEBUG: 13820: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:44:48,205 [root] DEBUG: 13820: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:44:48,211 [root] DEBUG: 13820: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:44:48,211 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95A90000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 20:44:48,212 [root] DEBUG: 13820: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:44:48,213 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95A90000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 20:44:48,215 [root] DEBUG: 13820: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:44:48,216 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE1490000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 20:44:48,219 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE1490000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 20:44:48,230 [root] DEBUG: 4372: DLL loaded at 0x000000000FFA0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 20:44:48,231 [root] DEBUG: 4372: DLL loaded at 0x000000000FFA0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 20:44:48,232 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95A70000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 20:44:48,233 [root] DEBUG: 13820: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:44:48,234 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95A70000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 20:44:48,248 [root] DEBUG: 13820: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:44:48,250 [root] DEBUG: 13820: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:44:48,250 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94C10000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 20:44:48,252 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94C10000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 20:44:48,253 [root] DEBUG: 4372: DLL loaded at 0x00007FFEED410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:44:48,254 [root] DEBUG: 4372: DLL loaded at 0x00007FFEED410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:44:48,256 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94B30000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 20:44:48,257 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94B30000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 20:44:48,259 [root] DEBUG: 13820: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:44:48,280 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-28 20:44:48,292 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95A50000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 20:44:48,294 [root] DEBUG: 4372: DLL loaded at 0x00007FFE95A50000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 20:44:48,302 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94A40000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 20:44:48,304 [root] DEBUG: 4372: DLL loaded at 0x00007FFE94A40000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 20:44:48,341 [root] DEBUG: 4372: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 20:44:49,216 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:44:49,217 [root] DEBUG: 7356: DLL loaded at 0x00007FFEEE250000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-28 20:44:49,219 [root] DEBUG: 7356: DLL loaded at 0x00007FFE94A20000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-28 20:44:49,243 [root] DEBUG: 7356: DLL loaded at 0x00007FFE94A00000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 20:44:49,293 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 12908: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:44:49,294 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 12908
2026-05-28 20:44:49,296 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 12908
2026-05-28 20:44:49,396 [root] DEBUG: 7356: DLL loaded at 0x00007FFE94890000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-28 20:44:50,180 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 10412: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:44:50,181 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 10412
2026-05-28 20:44:50,182 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 10412
2026-05-28 20:44:53,434 [root] INFO: Process with pid 13820 has terminated
2026-05-28 20:44:53,436 [root] DEBUG: 13820: NtTerminateProcess hook: Attempting to dump process 13820
2026-05-28 20:44:53,437 [root] DEBUG: 13820: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:45:10,372 [root] DEBUG: 4372: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 20:45:41,360 [root] DEBUG: 1212: CreateProcessHandler: Injection info set for new process 14808: C:\Windows\system32\taskhostw.exe, ImageBase: 0x00007FF753750000
2026-05-28 20:45:41,361 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 14808
2026-05-28 20:45:41,361 [lib.api.process] INFO: Monitor config for process 14808: C:\6lreqs2g\dll\14808.ini
2026-05-28 20:45:41,363 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:45:41,366 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:45:41,370 [root] DEBUG: Loader: Injecting process 14808 (thread 14812) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:41,371 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:45:41,372 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:41,373 [lib.api.process] INFO: Injected into 64-bit <Process 14808 taskhostw.exe>
2026-05-28 20:45:41,375 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 14808
2026-05-28 20:45:41,376 [lib.api.process] INFO: Monitor config for process 14808: C:\6lreqs2g\dll\14808.ini
2026-05-28 20:45:41,376 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:45:41,379 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:45:41,383 [root] DEBUG: Loader: Injecting process 14808 (thread 14812) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:41,384 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:45:41,385 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:41,386 [lib.api.process] INFO: Injected into 64-bit <Process 14808 taskhostw.exe>
2026-05-28 20:45:41,387 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 14808
2026-05-28 20:45:41,388 [lib.api.process] INFO: Monitor config for process 14808: C:\6lreqs2g\dll\14808.ini
2026-05-28 20:45:41,389 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:45:41,393 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:45:41,398 [root] DEBUG: Loader: Injecting process 14808 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:41,398 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 14812, handle 0x120
2026-05-28 20:45:41,399 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:45:41,400 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:41,402 [lib.api.process] INFO: Injected into 64-bit <Process 14808 taskhostw.exe>
2026-05-28 20:45:41,411 [root] DEBUG: 14808: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:45:41,411 [root] DEBUG: 14808: Interactive desktop enabled.
2026-05-28 20:45:41,413 [root] DEBUG: 14808: Dropped file limit defaulting to 100.
2026-05-28 20:45:41,414 [root] DEBUG: 14808: Disabling sleep skipping.
2026-05-28 20:45:41,415 [root] DEBUG: 14808: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:45:41,427 [root] DEBUG: 14808: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:45:41,427 [root] DEBUG: 14808: YaraScan: Scanning 0x00007FF753750000, size 0x192fc
2026-05-28 20:45:41,429 [root] DEBUG: 14808: Monitor initialised: 64-bit capemon loaded in process 14808 at 0x00007FFEAF1A0000, thread 14812, image base 0x00007FF753750000, stack from 0x00000052A1394000-0x00000052A13A0000
2026-05-28 20:45:41,431 [root] DEBUG: 14808: Commandline: taskhostw.exe
2026-05-28 20:45:41,441 [root] DEBUG: 14808: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:45:41,462 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:45:41,463 [root] DEBUG: 14808: set_hooks: Unable to hook LockResource
2026-05-28 20:45:41,468 [root] DEBUG: 14808: Hooked 627 out of 628 functions
2026-05-28 20:45:41,470 [root] DEBUG: 14808: Syscall hook installed, syscall logging level 1
2026-05-28 20:45:41,474 [root] DEBUG: 14808: RestoreHeaders: Restored original import table.
2026-05-28 20:45:41,475 [root] INFO: Loaded monitor into process with pid 14808
2026-05-28 20:45:41,476 [root] DEBUG: 14808: caller_dispatch: Added region at 0x00007FF753750000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF753755CA1, thread 14812).
2026-05-28 20:45:41,477 [root] DEBUG: 14808: YaraScan: Scanning 0x00007FF753750000, size 0x192fc
2026-05-28 20:45:41,479 [root] DEBUG: 14808: ProcessImageBase: Main module image at 0x00007FF753750000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:45:41,480 [root] DEBUG: 14808: DLL loaded at 0x00007FFEF1540000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-05-28 20:45:41,483 [root] DEBUG: 14808: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:45:41,484 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:45:41,489 [root] DEBUG: 14808: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:45:41,493 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:45:41,493 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDFBE0000: C:\Windows\System32\wosc (0x4e000 bytes).
2026-05-28 20:45:41,497 [root] DEBUG: 14808: DLL loaded at 0x00007FFED8B50000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 20:45:41,500 [root] DEBUG: 14808: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:45:41,501 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDDEA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:45:41,508 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:45:41,513 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEB550000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 20:45:41,516 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\System32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:45:41,517 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE5860000: C:\Windows\System32\InstallServiceTasks (0x3e000 bytes).
2026-05-28 20:45:41,519 [root] DEBUG: 14808: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:45:41,522 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDD9D0000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-05-28 20:45:41,523 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEACF0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 20:45:41,526 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF640000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 20:45:41,526 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE4FE0000: C:\Windows\System32\Cabinet (0x29000 bytes).
2026-05-28 20:45:41,527 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:45:41,528 [root] DEBUG: 14808: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:45:41,529 [root] DEBUG: 14808: DLL loaded at 0x00007FFED49C0000: C:\Windows\System32\UpdatePolicy (0x43000 bytes).
2026-05-28 20:45:41,530 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF210000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 20:45:41,532 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:45:41,535 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:45:41,536 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:45:41,540 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:45:41,541 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDEB40000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:45:41,543 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:45:41,551 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:45:41,569 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:45:41,569 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDA3E0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:45:41,579 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:45:41,580 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:45:41,582 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:45:41,584 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:45:41,584 [root] DEBUG: 14808: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:45:41,585 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:45:41,589 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDAF20000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-28 20:45:41,591 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE8610000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 20:45:41,596 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDA390000: C:\Windows\system32\fcon (0x45000 bytes).
2026-05-28 20:45:41,603 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:45:41,622 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:45:41,623 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDA3E0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:45:41,630 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:45:41,631 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:45:41,632 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:45:41,632 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:45:41,633 [root] DEBUG: 14808: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:45:41,634 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:45:41,636 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDAF20000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-28 20:45:41,697 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:45:41,698 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDA3E0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:45:41,701 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:45:41,702 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:45:41,702 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:45:41,703 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:45:41,705 [root] DEBUG: 14808: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:45:41,705 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:45:41,713 [root] DEBUG: 14808: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:45:41,714 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE6C20000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-28 20:45:41,716 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\wldp (0x2d000 bytes).
2026-05-28 20:45:41,723 [root] DEBUG: 14808: DLL loaded at 0x00007FFED95A0000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-28 20:45:41,724 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\system32\WTSAPI32 (0x14000 bytes).
2026-05-28 20:45:41,725 [root] DEBUG: 14808: DLL loaded at 0x00007FFEB6C10000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-28 20:45:41,726 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-28 20:45:41,727 [root] DEBUG: 14808: DLL loaded at 0x00007FFED9040000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-28 20:45:41,727 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE0D0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-28 20:45:41,728 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:45:41,730 [root] DEBUG: 14808: DLL loaded at 0x00007FFEF0250000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 20:45:41,730 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE6180000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-28 20:45:41,731 [root] DEBUG: 14808: DLL loaded at 0x00007FFED50A0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-28 20:45:41,746 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 20:45:41,747 [root] DEBUG: 14808: DLL loaded at 0x00007FFED0400000: C:\Windows\System32\OneSettingsClient (0x32000 bytes).
2026-05-28 20:45:41,753 [root] DEBUG: 14808: DLL loaded at 0x00007FFED5E30000: C:\Windows\system32\OnDemandConnRouteHelper (0x17000 bytes).
2026-05-28 20:45:41,756 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEDE0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 20:45:41,759 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE8E20000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 20:45:41,762 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE8E40000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 20:45:41,763 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE8D30000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:45:41,767 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDB3D0000: C:\Windows\System32\webio (0x98000 bytes).
2026-05-28 20:45:41,778 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEB10000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 20:45:41,780 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE4F10000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-05-28 20:45:41,809 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE6D00000: C:\Windows\System32\fwpuclnt (0x80000 bytes).
2026-05-28 20:45:42,023 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE620000: C:\Windows\system32\schannel (0x97000 bytes).
2026-05-28 20:45:42,450 [root] DEBUG: 14808: DLL loaded at 0x00007FFED9520000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-05-28 20:45:42,451 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:45:42,454 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\system32\ncrypt (0x27000 bytes).
2026-05-28 20:45:42,455 [root] DEBUG: 14808: DLL loaded at 0x00007FFED9570000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-05-28 20:45:42,472 [root] DEBUG: 14808: DLL loaded at 0x00007FFED94B0000: C:\Windows\system32\cryptnet (0x31000 bytes).
2026-05-28 20:45:42,480 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF430000: C:\Windows\system32\DPAPI (0xa000 bytes).
2026-05-28 20:45:42,960 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:45:42,961 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDA3E0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:45:43,009 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:45:43,010 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:45:43,011 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:45:43,012 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:45:43,012 [root] DEBUG: 14808: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:45:43,014 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:45:43,016 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDA3E0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:45:43,043 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE220000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:45:43,044 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE250000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-05-28 20:45:43,289 [root] DEBUG: 14808: api-rate-cap: ReadProcessMemory hook disabled due to rate
2026-05-28 20:45:43,293 [root] DEBUG: 14808: api-rate-cap: NtReadVirtualMemory hook disabled due to rate
2026-05-28 20:45:43,368 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 20:45:43,369 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEB400000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 20:45:43,375 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:45:43,376 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF3D0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:45:43,377 [root] DEBUG: 14808: DLL loaded at 0x00007FFED4EE0000: C:\Windows\SYSTEM32\dmEnrollEngine (0xdf000 bytes).
2026-05-28 20:45:43,378 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDA370000: C:\Windows\SYSTEM32\enrollmentapi (0x11000 bytes).
2026-05-28 20:45:43,401 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:45:43,403 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:45:43,403 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:45:43,404 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:45:43,406 [root] DEBUG: 14808: DLL loaded at 0x00007FFED52C0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-28 20:45:43,407 [root] DEBUG: 14808: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:45:43,409 [root] DEBUG: 14808: DLL loaded at 0x00007FFEDA3E0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-28 20:45:43,430 [root] DEBUG: 14808: DLL loaded at 0x00007FFEE8690000: C:\Windows\SYSTEM32\dmiso8601utils (0x9000 bytes).
2026-05-28 20:45:43,457 [root] DEBUG: 14808: NtTerminateProcess hook: Attempting to dump process 14808
2026-05-28 20:45:43,458 [root] DEBUG: 14808: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:45:43,468 [root] INFO: Process with pid 14808 has terminated
2026-05-28 20:45:43,472 [root] INFO: Process with pid 14808 has terminated
2026-05-28 20:45:45,332 [root] INFO: Added new file to list with pid 10784 and path C:\ProgramData\USOPrivate\UpdateStore\store.db
2026-05-28 20:45:45,334 [root] INFO: Added new file to list with pid 10784 and path C:\ProgramData\USOShared\Logs\System\WuProvider.3b57a5a4-fe55-4ca3-ad4d-fdc2d3f1c248.1.etl
2026-05-28 20:45:45,335 [root] INFO: Added new file to list with pid 10784 and path C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.ab5c0e85-4d0b-4e4b-8a29-6857fa9d1f22.1.etl
2026-05-28 20:45:45,335 [root] DEBUG: 10784: NtTerminateProcess hook: Attempting to dump process 10784
2026-05-28 20:45:45,337 [root] DEBUG: 10784: CAPEExceptionFilter: Exception 0xc0000005 accessing 0xd051d004 caught at RVA 0x75419 in capemon (expected in memory scans), passing to next handler.
2026-05-28 20:45:45,337 [root] DEBUG: 10784: VerifyCodeSection: Exception rebasing image from 0x00007FF6D0370000 to 0x0000000140000000.
2026-05-28 20:45:45,339 [root] DEBUG: 10784: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:45:45,348 [root] INFO: Process with pid 10784 has terminated
2026-05-28 20:45:49,234 [root] DEBUG: 7356: CreateProcessHandler: Injection info set for new process 7660: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF60A060000
2026-05-28 20:45:49,236 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 7660
2026-05-28 20:45:49,236 [root] DEBUG: 7356: ProcessMessage: Skipping monitoring process 7660
2026-05-28 20:45:59,715 [root] DEBUG: 1212: CreateProcessHandler: Injection info set for new process 2668: C:\Windows\system32\wermgr.exe, ImageBase: 0x00007FF6845A0000
2026-05-28 20:45:59,724 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 2668
2026-05-28 20:45:59,725 [lib.api.process] INFO: Monitor config for process 2668: C:\6lreqs2g\dll\2668.ini
2026-05-28 20:45:59,733 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:45:59,735 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:45:59,745 [root] DEBUG: Loader: Injecting process 2668 (thread 2664) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,747 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:45:59,748 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,757 [lib.api.process] INFO: Injected into 64-bit <Process 2668 wermgr.exe>
2026-05-28 20:45:59,768 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 2668
2026-05-28 20:45:59,772 [lib.api.process] INFO: Monitor config for process 2668: C:\6lreqs2g\dll\2668.ini
2026-05-28 20:45:59,774 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:45:59,782 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:45:59,788 [root] DEBUG: Loader: Injecting process 2668 (thread 2664) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,796 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:45:59,798 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,800 [lib.api.process] INFO: Injected into 64-bit <Process 2668 wermgr.exe>
2026-05-28 20:45:59,802 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 2668
2026-05-28 20:45:59,804 [lib.api.process] INFO: Monitor config for process 2668: C:\6lreqs2g\dll\2668.ini
2026-05-28 20:45:59,805 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:45:59,809 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:45:59,832 [root] DEBUG: Loader: Injecting process 2668 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,833 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 2664, handle 0x128
2026-05-28 20:45:59,835 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:45:59,837 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,841 [lib.api.process] INFO: Injected into 64-bit <Process 2668 wermgr.exe>
2026-05-28 20:45:59,877 [root] DEBUG: 2668: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:45:59,879 [root] DEBUG: 2668: Interactive desktop enabled.
2026-05-28 20:45:59,882 [root] DEBUG: 2668: Dropped file limit defaulting to 100.
2026-05-28 20:45:59,898 [root] DEBUG: 2668: Disabling sleep skipping.
2026-05-28 20:45:59,907 [root] DEBUG: 2668: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:45:59,915 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 6696: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:45:59,919 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6696
2026-05-28 20:45:59,920 [lib.api.process] INFO: Monitor config for process 6696: C:\6lreqs2g\dll\6696.ini
2026-05-28 20:45:59,922 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:45:59,928 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:45:59,936 [root] DEBUG: Loader: Injecting process 6696 (thread 6716) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,937 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:45:59,939 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,942 [lib.api.process] INFO: Injected into 64-bit <Process 6696 dllhost.exe>
2026-05-28 20:45:59,943 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6696
2026-05-28 20:45:59,944 [lib.api.process] INFO: Monitor config for process 6696: C:\6lreqs2g\dll\6696.ini
2026-05-28 20:45:59,945 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:45:59,946 [root] DEBUG: 9844: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:45:59,947 [root] DEBUG: 2668: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:45:59,949 [root] DEBUG: 2668: YaraScan: Scanning 0x00007FF6845A0000, size 0x3f17e
2026-05-28 20:45:59,950 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:45:59,953 [root] DEBUG: 2668: Monitor initialised: 64-bit capemon loaded in process 2668 at 0x00007FFEAF1A0000, thread 2664, image base 0x00007FF6845A0000, stack from 0x0000008194274000-0x0000008194280000
2026-05-28 20:45:59,954 [root] DEBUG: 2668: Commandline: "C:\Windows\system32\wermgr.exe" -upload
2026-05-28 20:45:59,956 [root] DEBUG: Loader: Injecting process 6696 (thread 6716) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,957 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:45:59,960 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:45:59,963 [lib.api.process] INFO: Injected into 64-bit <Process 6696 dllhost.exe>
2026-05-28 20:45:59,973 [root] DEBUG: 6696: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:45:59,974 [root] DEBUG: 6696: Interactive desktop enabled.
2026-05-28 20:45:59,984 [root] DEBUG: 6696: Dropped file limit defaulting to 100.
2026-05-28 20:45:59,991 [root] DEBUG: 6696: Disabling sleep skipping.
2026-05-28 20:45:59,993 [root] DEBUG: 6696: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:46:00,000 [root] DEBUG: 2668: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:46:00,005 [root] DEBUG: 6696: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:46:00,011 [root] DEBUG: 6696: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:46:00,016 [root] DEBUG: 6696: Monitor initialised: 64-bit capemon loaded in process 6696 at 0x00007FFEAF1A0000, thread 6716, image base 0x00007FF6868D0000, stack from 0x00000044F90F4000-0x00000044F9100000
2026-05-28 20:46:00,025 [root] DEBUG: 6696: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:46:00,035 [root] DEBUG: 6696: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:46:00,057 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:46:00,068 [root] DEBUG: 6696: set_hooks: Unable to hook LockResource
2026-05-28 20:46:00,080 [root] DEBUG: 6696: Hooked 627 out of 628 functions
2026-05-28 20:46:00,081 [root] DEBUG: 6696: Syscall hook installed, syscall logging level 1
2026-05-28 20:46:00,086 [root] DEBUG: 6696: RestoreHeaders: Restored original import table.
2026-05-28 20:46:00,087 [root] INFO: Loaded monitor into process with pid 6696
2026-05-28 20:46:00,088 [root] DEBUG: 6696: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 6716).
2026-05-28 20:46:00,089 [root] DEBUG: 6696: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:46:00,091 [root] DEBUG: 6696: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:46:00,093 [root] DEBUG: 6696: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:46:00,095 [root] DEBUG: 6696: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:46:00,098 [root] DEBUG: 6696: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:46:00,115 [root] DEBUG: 6696: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:46:00,130 [root] DEBUG: 6696: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:46:00,132 [root] DEBUG: 6696: DLL loaded at 0x00007FFEE27A0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:46:00,138 [root] DEBUG: 6696: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:46:00,195 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:46:00,209 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12644: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe, ImageBase: 0x00007FF6174D0000
2026-05-28 20:46:00,211 [root] DEBUG: 2668: set_hooks: Unable to hook LockResource
2026-05-28 20:46:00,214 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 12644
2026-05-28 20:46:00,224 [lib.api.process] INFO: Monitor config for process 12644: C:\6lreqs2g\dll\12644.ini
2026-05-28 20:46:00,231 [root] DEBUG: 2668: Hooked 627 out of 628 functions
2026-05-28 20:46:00,233 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:00,234 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 8804: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe, ImageBase: 0x00007FF716380000
2026-05-28 20:46:00,236 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 8804
2026-05-28 20:46:00,236 [root] DEBUG: 2668: Syscall hook installed, syscall logging level 1
2026-05-28 20:46:00,237 [root] INFO: Announced starting service "b'TrustedInstaller'"
2026-05-28 20:46:00,239 [lib.api.process] INFO: Monitor config for process 8804: C:\6lreqs2g\dll\8804.ini
2026-05-28 20:46:00,244 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:00,247 [root] DEBUG: 2668: RestoreHeaders: Restored original import table.
2026-05-28 20:46:00,249 [root] INFO: Loaded monitor into process with pid 2668
2026-05-28 20:46:00,252 [root] DEBUG: 2668: caller_dispatch: Added region at 0x00007FF6845A0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6845B9181, thread 2664).
2026-05-28 20:46:00,252 [root] DEBUG: 2668: YaraScan: Scanning 0x00007FF6845A0000, size 0x3f17e
2026-05-28 20:46:00,274 [root] DEBUG: 2668: ProcessImageBase: Main module image at 0x00007FF6845A0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:46:00,280 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\Comctl32 (0x29a000 bytes).
2026-05-28 20:46:00,289 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,290 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,297 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,298 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,307 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,310 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,326 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:46:00,339 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,341 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,347 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,348 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,352 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,353 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,369 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,370 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,374 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,376 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,380 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,382 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,386 [root] DEBUG: 2668: DLL loaded at 0x00007FFEF1540000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-05-28 20:46:00,390 [root] DEBUG: 2668: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:46:00,392 [root] DEBUG: 2668: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:46:00,394 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEADC0000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:46:00,402 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:46:00,410 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,411 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,414 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,416 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,420 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,421 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,428 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,429 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,433 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,434 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,439 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,440 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,455 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,456 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,460 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,461 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,465 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,467 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,471 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDF9F0000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-28 20:46:00,474 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:00,477 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:46:00,478 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEB400000: C:\Windows\system32\DSREG (0x141000 bytes).
2026-05-28 20:46:00,485 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF640000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 20:46:00,492 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,496 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,499 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,503 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:46:00,506 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 20:46:00,508 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF440000: C:\Windows\system32\WINSTA (0x5b000 bytes).
2026-05-28 20:46:00,516 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,519 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,522 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,533 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,536 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,539 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,551 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,554 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,557 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,575 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,577 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,583 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,586 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,590 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,597 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,601 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,604 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,606 [root] INFO: Process with pid 4372 appears to have terminated
2026-05-28 20:46:00,612 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,615 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,619 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,625 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER2461.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER2461.tmp'
2026-05-28 20:46:00,626 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER2461.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER2461.tmp'
2026-05-28 20:46:00,641 [root] INFO: Added new file to list with pid 2668 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER2461.tmp.WERInternalMetadata.xml
2026-05-28 20:46:00,643 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF550000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:46:00,646 [root] DEBUG: 2668: DLL loaded at 0x00007FFEED4F0000: C:\Windows\SYSTEM32\rmclient (0x2a000 bytes).
2026-05-28 20:46:00,649 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDA250000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 20:46:00,654 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF430000: C:\Windows\system32\DPAPI (0xa000 bytes).
2026-05-28 20:46:00,655 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:46:00,934 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEB240000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 20:46:00,939 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,942 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,945 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:00,950 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE6360000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 20:46:00,953 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF080000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 20:46:00,954 [root] DEBUG: 2668: DLL loaded at 0x00007FFEED7F0000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-28 20:46:00,958 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:46:00,972 [root] DEBUG: 2668: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:46:00,973 [root] DEBUG: 2668: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:46:00,983 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:46:00,985 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE5AC0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 20:46:00,993 [root] DEBUG: 2668: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 20:46:01,003 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-05-28 20:46:01,009 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDF8A0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:46:01,023 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDF7D0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 20:46:01,031 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDF190000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 20:46:01,049 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDEC10000: C:\Windows\system32\edputil (0x24000 bytes).
2026-05-28 20:46:01,054 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEB550000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 20:46:01,064 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE4BE0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:46:01,065 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDEB40000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:46:01,072 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:46:01,075 [root] DEBUG: 2668: DLL loaded at 0x00007FFED5E30000: C:\Windows\system32\OnDemandConnRouteHelper (0x17000 bytes).
2026-05-28 20:46:01,078 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEEDE0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 20:46:01,079 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:46:01,081 [root] DEBUG: 2668: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:46:01,082 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE8E20000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 20:46:01,085 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE8E40000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 20:46:01,087 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE8D30000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:46:01,089 [root] DEBUG: 2668: DLL loaded at 0x00007FFEDB3D0000: C:\Windows\system32\webio (0x98000 bytes).
2026-05-28 20:46:01,096 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEEB10000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 20:46:01,099 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE4F10000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-05-28 20:46:01,123 [root] DEBUG: 2668: DLL loaded at 0x00007FFEE6D00000: C:\Windows\System32\fwpuclnt (0x80000 bytes).
2026-05-28 20:46:01,261 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 416: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe, ImageBase: 0x00007FF610CE0000
2026-05-28 20:46:01,264 [root] INFO: Announced 64-bit process name: TiWorker.exe pid: 416
2026-05-28 20:46:01,265 [lib.api.process] INFO: Monitor config for process 416: C:\6lreqs2g\dll\416.ini
2026-05-28 20:46:01,267 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:01,284 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE620000: C:\Windows\system32\schannel (0x97000 bytes).
2026-05-28 20:46:01,359 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:01,360 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:01,364 [root] DEBUG: Loader: Injecting process 8804 (thread 8816) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:01,366 [root] DEBUG: Loader: Injecting process 12644 (thread 12640) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:01,366 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:01,367 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:01,368 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:01,368 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:01,370 [lib.api.process] INFO: Injected into 64-bit <Process 8804 TextInputHost.exe>
2026-05-28 20:46:01,370 [lib.api.process] INFO: Injected into 64-bit <Process 12644 StartMenuExperienceHost.exe>
2026-05-28 20:46:01,372 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 8804
2026-05-28 20:46:01,373 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 12644
2026-05-28 20:46:01,373 [lib.api.process] INFO: Monitor config for process 8804: C:\6lreqs2g\dll\8804.ini
2026-05-28 20:46:01,374 [lib.api.process] INFO: Monitor config for process 12644: C:\6lreqs2g\dll\12644.ini
2026-05-28 20:46:01,375 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:01,375 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:01,607 [root] DEBUG: 2668: DLL loaded at 0x00007FFED9520000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-05-28 20:46:01,609 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF0B0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:46:01,611 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF0F0000: C:\Windows\system32\ncrypt (0x27000 bytes).
2026-05-28 20:46:01,613 [root] DEBUG: 2668: DLL loaded at 0x00007FFED9570000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-05-28 20:46:01,615 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEF210000: C:\Windows\system32\MSASN1 (0x12000 bytes).
2026-05-28 20:46:01,629 [root] DEBUG: 2668: DLL loaded at 0x00007FFED94B0000: C:\Windows\system32\cryptnet (0x31000 bytes).
2026-05-28 20:46:02,001 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,004 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,007 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,022 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:46:02,031 [root] INFO: Added new file to list with pid 2668 and path C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_b855eb9196200fa41fc81a6c944f6807b7a66_2d511a93_8ee50540-7341-488c-bae6-2b83d340ec48\Report.wer
2026-05-28 20:46:02,049 [root] DEBUG: 2668: api-rate-cap: NtWriteFile hook disabled due to rate
2026-05-28 20:46:02,086 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_b855eb9196200fa41fc81a6c944f6807b7a66_2d511a93_8ee50540-7341-488c-bae6-2b83d340ec48\Report.wer": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_Explorer.EXE_b855eb9196200fa41fc81a6c944f6807b7a66_2d511a93_8ee50540-7341-488c-bae6-2b83d340ec48\\Report.wer'
2026-05-28 20:46:02,087 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_b855eb9196200fa41fc81a6c944f6807b7a66_2d511a93_8ee50540-7341-488c-bae6-2b83d340ec48\Report.wer": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_Explorer.EXE_b855eb9196200fa41fc81a6c944f6807b7a66_2d511a93_8ee50540-7341-488c-bae6-2b83d340ec48\\Report.wer'
2026-05-28 20:46:02,092 [root] WARNING: File at path C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_b855eb9196200fa41fc81a6c944f6807b7a66_2d511a93_8ee50540-7341-488c-bae6-2b83d340ec48 does not exist, skipping
2026-05-28 20:46:02,094 [root] WARNING: File at path C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_b855eb9196200fa41fc81a6c944f6807b7a66_2d511a93_8ee50540-7341-488c-bae6-2b83d340ec48 does not exist, skipping
2026-05-28 20:46:02,101 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER2461.tmp.WERInternalMetadata.xml": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER2461.tmp.WERInternalMetadata.xml'
2026-05-28 20:46:02,102 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER2461.tmp.WERInternalMetadata.xml": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER2461.tmp.WERInternalMetadata.xml'
2026-05-28 20:46:02,107 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,110 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,113 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,120 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,123 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,126 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,140 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,143 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,145 [root] DEBUG: 2668: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:02,150 [root] DEBUG: 2668: NtTerminateProcess hook: Attempting to dump process 2668
2026-05-28 20:46:02,151 [root] DEBUG: 2668: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:46:02,164 [root] INFO: Process with pid 2668 has terminated
2026-05-28 20:46:02,170 [root] INFO: Process with pid 2668 has terminated
2026-05-28 20:46:02,744 [lib.api.process] INFO: Potential dll side-loading detected in local directory: mspatcha.dll
2026-05-28 20:46:02,748 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msdelta.dll
2026-05-28 20:46:02,749 [lib.api.process] INFO: Potential dll side-loading detected in local directory: wdscore.dll
2026-05-28 20:46:02,749 [lib.api.process] INFO: Potential dll side-loading detected in local directory: smiengine.dll
2026-05-28 20:46:02,750 [lib.api.process] INFO: Potential dll side-loading detected in local directory: drvstore.dll
2026-05-28 20:46:02,750 [lib.api.process] INFO: Potential dll side-loading detected in local directory: updateagent.dll
2026-05-28 20:46:02,754 [lib.api.process] INFO: Potential dll side-loading detected in local directory: dpx.dll
2026-05-28 20:46:02,763 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:02,767 [root] DEBUG: Loader: Injecting process 416 (thread 1396) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:02,769 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:02,772 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:02,773 [lib.api.process] INFO: Injected into 64-bit <Process 416 TiWorker.exe>
2026-05-28 20:46:02,776 [root] INFO: Announced 64-bit process name: TiWorker.exe pid: 416
2026-05-28 20:46:02,777 [lib.api.process] INFO: Monitor config for process 416: C:\6lreqs2g\dll\416.ini
2026-05-28 20:46:02,777 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:03,035 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:03,036 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:03,041 [root] DEBUG: Loader: Injecting process 12644 (thread 12640) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:03,041 [root] DEBUG: Loader: Injecting process 8804 (thread 8816) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:03,042 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:03,043 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:03,043 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:03,044 [lib.api.process] INFO: Injected into 64-bit <Process 12644 StartMenuExperienceHost.exe>
2026-05-28 20:46:03,045 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:03,046 [lib.api.process] INFO: Injected into 64-bit <Process 8804 TextInputHost.exe>
2026-05-28 20:46:03,047 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 12644
2026-05-28 20:46:03,048 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 8804
2026-05-28 20:46:03,048 [lib.api.process] INFO: Monitor config for process 12644: C:\6lreqs2g\dll\12644.ini
2026-05-28 20:46:03,049 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:03,049 [lib.api.process] INFO: Monitor config for process 8804: C:\6lreqs2g\dll\8804.ini
2026-05-28 20:46:03,050 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:04,421 [lib.api.process] INFO: Potential dll side-loading detected in local directory: mspatcha.dll
2026-05-28 20:46:04,422 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msdelta.dll
2026-05-28 20:46:04,422 [lib.api.process] INFO: Potential dll side-loading detected in local directory: wdscore.dll
2026-05-28 20:46:04,424 [lib.api.process] INFO: Potential dll side-loading detected in local directory: smiengine.dll
2026-05-28 20:46:04,424 [lib.api.process] INFO: Potential dll side-loading detected in local directory: drvstore.dll
2026-05-28 20:46:04,424 [lib.api.process] INFO: Potential dll side-loading detected in local directory: updateagent.dll
2026-05-28 20:46:04,425 [lib.api.process] INFO: Potential dll side-loading detected in local directory: dpx.dll
2026-05-28 20:46:04,433 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:04,438 [root] DEBUG: Loader: Injecting process 416 (thread 1396) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:04,439 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:04,440 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:04,441 [lib.api.process] INFO: Injected into 64-bit <Process 416 TiWorker.exe>
2026-05-28 20:46:04,449 [root] DEBUG: 416: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:46:04,450 [root] DEBUG: 416: Interactive desktop enabled.
2026-05-28 20:46:04,451 [root] DEBUG: 416: Dropped file limit defaulting to 100.
2026-05-28 20:46:04,454 [root] DEBUG: 416: Disabling sleep skipping.
2026-05-28 20:46:04,455 [root] DEBUG: 416: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:46:04,467 [root] DEBUG: 416: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:46:04,469 [root] DEBUG: 416: YaraScan: Scanning 0x00007FF610CE0000, size 0x43128
2026-05-28 20:46:04,472 [root] DEBUG: 416: Monitor initialised: 64-bit capemon loaded in process 416 at 0x00007FFEAF1A0000, thread 1396, image base 0x00007FF610CE0000, stack from 0x0000006ACD474000-0x0000006ACD480000
2026-05-28 20:46:04,473 [root] DEBUG: 416: Commandline: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe -Embedding
2026-05-28 20:46:04,483 [root] DEBUG: 416: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:46:04,503 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:46:04,504 [root] DEBUG: 416: set_hooks: Unable to hook LockResource
2026-05-28 20:46:04,509 [root] DEBUG: 416: Hooked 627 out of 628 functions
2026-05-28 20:46:04,511 [root] DEBUG: 416: Syscall hook installed, syscall logging level 1
2026-05-28 20:46:04,516 [root] DEBUG: 416: RestoreHeaders: Restored original import table.
2026-05-28 20:46:04,517 [root] INFO: Loaded monitor into process with pid 416
2026-05-28 20:46:04,518 [root] DEBUG: 416: caller_dispatch: Added region at 0x00007FF610CE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF610CFD4C2, thread 1396).
2026-05-28 20:46:04,520 [root] DEBUG: 416: YaraScan: Scanning 0x00007FF610CE0000, size 0x43128
2026-05-28 20:46:04,525 [root] DEBUG: 416: ProcessImageBase: Main module image at 0x00007FF610CE0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:46:04,526 [root] DEBUG: 416: DLL loaded at 0x00007FFED7220000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\wdscore (0x43000 bytes).
2026-05-28 20:46:04,530 [root] DEBUG: 416: DLL loaded at 0x00007FFEDE100000: C:\Windows\system32\dbghelp (0x1e4000 bytes).
2026-05-28 20:46:04,532 [root] DEBUG: 416: DLL loaded at 0x00007FFEDE0C0000: C:\Windows\SYSTEM32\dbgcore (0x34000 bytes).
2026-05-28 20:46:04,538 [root] DEBUG: 416: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:46:04,540 [root] DEBUG: 416: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:46:04,544 [root] DEBUG: 416: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:46:04,561 [root] DEBUG: 416: DLL loaded at 0x00007FFED5BB0000: C:\Windows\servicing\CbsApi (0x12000 bytes).
2026-05-28 20:46:04,566 [root] DEBUG: 416: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:46:04,569 [root] DEBUG: 416: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:46:04,570 [root] DEBUG: 416: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:46:04,572 [root] DEBUG: 416: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:46:04,573 [root] DEBUG: 416: DLL loaded at 0x00007FFED5910000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\cbscore (0x295000 bytes).
2026-05-28 20:46:04,575 [root] DEBUG: 416: DLL loaded at 0x00007FFEEF210000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:46:04,586 [root] DEBUG: 416: DLL loaded at 0x00007FFED7160000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\dpx (0xb9000 bytes).
2026-05-28 20:46:04,589 [root] DEBUG: 416: DLL loaded at 0x00007FFED5550000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\wcp (0x3be000 bytes).
2026-05-28 20:46:04,592 [root] DEBUG: 416: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:46:04,595 [root] DEBUG: 416: DLL loaded at 0x00007FFED70F0000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\DrUpdate (0x61000 bytes).
2026-05-28 20:46:04,597 [root] DEBUG: 416: DLL loaded at 0x00007FFEE61D0000: C:\Windows\SYSTEM32\VssTrace (0x18000 bytes).
2026-05-28 20:46:04,598 [root] DEBUG: 416: DLL loaded at 0x00007FFEE5F20000: C:\Windows\SYSTEM32\VSSAPI (0x19e000 bytes).
2026-05-28 20:46:04,599 [root] DEBUG: 416: DLL loaded at 0x00007FFED70A0000: C:\Windows\SYSTEM32\SPP (0x4b000 bytes).
2026-05-28 20:46:04,601 [root] DEBUG: 416: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\POWRPROF (0x4b000 bytes).
2026-05-28 20:46:04,603 [root] DEBUG: 416: DLL loaded at 0x00007FFEE2780000: C:\Windows\SYSTEM32\SrClient (0x17000 bytes).
2026-05-28 20:46:04,605 [root] DEBUG: 416: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:46:04,609 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:46:04,610 [root] DEBUG: 416: OpenProcessHandler: Injection info created for process 10960, handle 0x34c: Error obtaining target process name
2026-05-28 20:46:04,701 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:04,705 [root] DEBUG: Loader: Injecting process 12644 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:04,707 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12640, handle 0x124
2026-05-28 20:46:04,709 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:04,710 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:04,711 [lib.api.process] INFO: Injected into 64-bit <Process 12644 StartMenuExperienceHost.exe>
2026-05-28 20:46:04,808 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:04,814 [root] DEBUG: Loader: Injecting process 8804 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:04,816 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8816, handle 0x120
2026-05-28 20:46:04,817 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:04,818 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:04,821 [lib.api.process] INFO: Injected into 64-bit <Process 8804 TextInputHost.exe>
2026-05-28 20:46:05,066 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 6652: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:05,070 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6652
2026-05-28 20:46:05,071 [lib.api.process] INFO: Monitor config for process 6652: C:\6lreqs2g\dll\6652.ini
2026-05-28 20:46:05,074 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,185 [root] INFO: Process with pid 6696 has terminated
2026-05-28 20:46:05,186 [root] DEBUG: 6696: NtTerminateProcess hook: Attempting to dump process 6696
2026-05-28 20:46:05,188 [root] DEBUG: 6696: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:46:05,196 [root] DEBUG: 416: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 20:46:05,205 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 6488: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF6D0370000
2026-05-28 20:46:05,207 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 6488
2026-05-28 20:46:05,209 [lib.api.process] INFO: Monitor config for process 6488: C:\6lreqs2g\dll\6488.ini
2026-05-28 20:46:05,219 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,223 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,231 [root] DEBUG: Loader: Injecting process 6488 (thread 6392) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,234 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:05,235 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,247 [lib.api.process] INFO: Injected into 64-bit <Process 6488 MoUsoCoreWorker.exe>
2026-05-28 20:46:05,250 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 6488
2026-05-28 20:46:05,251 [lib.api.process] INFO: Monitor config for process 6488: C:\6lreqs2g\dll\6488.ini
2026-05-28 20:46:05,252 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,257 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,264 [root] DEBUG: Loader: Injecting process 6488 (thread 6392) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,266 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:05,268 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,280 [lib.api.process] INFO: Injected into 64-bit <Process 6488 MoUsoCoreWorker.exe>
2026-05-28 20:46:05,289 [root] DEBUG: 6488: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:46:05,290 [root] DEBUG: 6488: Interactive desktop enabled.
2026-05-28 20:46:05,292 [root] DEBUG: 6488: Dropped file limit defaulting to 100.
2026-05-28 20:46:05,293 [root] DEBUG: 6488: VerifyCodeSection: Exception rebasing image from 0x00007FF6D0370000 to 0x0000000140000000.
2026-05-28 20:46:05,295 [root] DEBUG: 6488: Disabling sleep skipping.
2026-05-28 20:46:05,297 [root] DEBUG: 6488: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:46:05,310 [root] DEBUG: 6488: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:46:05,311 [root] DEBUG: 6488: YaraScan: Scanning 0x00007FF6D0370000, size 0x1ad000
2026-05-28 20:46:05,321 [root] DEBUG: 6488: Monitor initialised: 64-bit capemon loaded in process 6488 at 0x00007FFEAF1A0000, thread 6392, image base 0x00007FF6D0370000, stack from 0x00000024D0704000-0x00000024D0710000
2026-05-28 20:46:05,321 [root] DEBUG: 6488: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-05-28 20:46:05,332 [root] DEBUG: 6488: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:46:05,335 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13336: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF6357C0000
2026-05-28 20:46:05,336 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13336
2026-05-28 20:46:05,337 [lib.api.process] INFO: Monitor config for process 13336: C:\6lreqs2g\dll\13336.ini
2026-05-28 20:46:05,340 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,341 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 1460: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF6357C0000
2026-05-28 20:46:05,342 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 1460
2026-05-28 20:46:05,343 [lib.api.process] INFO: Monitor config for process 1460: C:\6lreqs2g\dll\1460.ini
2026-05-28 20:46:05,345 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,345 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,349 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 2200: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF6357C0000
2026-05-28 20:46:05,350 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2200
2026-05-28 20:46:05,350 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,351 [lib.api.process] INFO: Monitor config for process 2200: C:\6lreqs2g\dll\2200.ini
2026-05-28 20:46:05,352 [root] DEBUG: Loader: Injecting process 13336 (thread 13400) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,353 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:46:05,354 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:05,354 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,356 [root] DEBUG: 6488: set_hooks: Unable to hook LockResource
2026-05-28 20:46:05,357 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,358 [root] DEBUG: Loader: Injecting process 1460 (thread 3792) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,359 [lib.api.process] INFO: Injected into 64-bit <Process 13336 backgroundTaskHost.exe>
2026-05-28 20:46:05,360 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:05,361 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13336
2026-05-28 20:46:05,362 [lib.api.process] INFO: Monitor config for process 13336: C:\6lreqs2g\dll\13336.ini
2026-05-28 20:46:05,362 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,363 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,364 [root] DEBUG: 6488: Hooked 627 out of 628 functions
2026-05-28 20:46:05,364 [lib.api.process] INFO: Injected into 64-bit <Process 1460 backgroundTaskHost.exe>
2026-05-28 20:46:05,364 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,366 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 1460
2026-05-28 20:46:05,367 [lib.api.process] INFO: Monitor config for process 1460: C:\6lreqs2g\dll\1460.ini
2026-05-28 20:46:05,368 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,370 [root] DEBUG: Loader: Injecting process 2200 (thread 12648) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,371 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:05,372 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,372 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,374 [lib.api.process] INFO: Injected into 64-bit <Process 2200 backgroundTaskHost.exe>
2026-05-28 20:46:05,374 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,374 [root] DEBUG: 6488: Syscall hook installed, syscall logging level 1
2026-05-28 20:46:05,376 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2200
2026-05-28 20:46:05,377 [root] DEBUG: Loader: Injecting process 13336 (thread 13400) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,378 [lib.api.process] INFO: Monitor config for process 2200: C:\6lreqs2g\dll\2200.ini
2026-05-28 20:46:05,379 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,379 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:05,381 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,382 [root] DEBUG: Loader: Injecting process 1460 (thread 3792) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,382 [root] DEBUG: 6488: RestoreHeaders: Restored original import table.
2026-05-28 20:46:05,383 [lib.api.process] INFO: Injected into 64-bit <Process 13336 backgroundTaskHost.exe>
2026-05-28 20:46:05,385 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:05,386 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,386 [root] INFO: Loaded monitor into process with pid 6488
2026-05-28 20:46:05,387 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,388 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13336
2026-05-28 20:46:05,389 [lib.api.process] INFO: Monitor config for process 13336: C:\6lreqs2g\dll\13336.ini
2026-05-28 20:46:05,390 [lib.api.process] INFO: Injected into 64-bit <Process 1460 backgroundTaskHost.exe>
2026-05-28 20:46:05,390 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,391 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 1460
2026-05-28 20:46:05,392 [lib.api.process] INFO: Monitor config for process 1460: C:\6lreqs2g\dll\1460.ini
2026-05-28 20:46:05,393 [root] DEBUG: Loader: Injecting process 2200 (thread 12648) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,393 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,396 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:05,399 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,399 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,400 [root] DEBUG: 6488: caller_dispatch: Added region at 0x00007FF6D0370000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6D048F712, thread 6392).
2026-05-28 20:46:05,401 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,401 [lib.api.process] INFO: Injected into 64-bit <Process 2200 backgroundTaskHost.exe>
2026-05-28 20:46:05,402 [root] DEBUG: 6488: YaraScan: Scanning 0x00007FF6D0370000, size 0x1ad000
2026-05-28 20:46:05,403 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2200
2026-05-28 20:46:05,405 [lib.api.process] INFO: Monitor config for process 2200: C:\6lreqs2g\dll\2200.ini
2026-05-28 20:46:05,405 [root] DEBUG: Loader: Injecting process 13336 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,405 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:05,406 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 13400, handle 0x120
2026-05-28 20:46:05,410 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:05,411 [root] DEBUG: Loader: Injecting process 1460 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,412 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,413 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 3792, handle 0x120
2026-05-28 20:46:05,413 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:05,414 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:05,415 [root] DEBUG: 6488: ProcessImageBase: Main module image at 0x00007FF6D0370000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:46:05,414 [lib.api.process] INFO: Injected into 64-bit <Process 13336 backgroundTaskHost.exe>
2026-05-28 20:46:05,417 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,418 [root] DEBUG: 6488: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:46:05,419 [lib.api.process] INFO: Injected into 64-bit <Process 1460 backgroundTaskHost.exe>
2026-05-28 20:46:05,421 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:46:05,423 [root] DEBUG: Loader: Injecting process 2200 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,425 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12648, handle 0x94
2026-05-28 20:46:05,426 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:05,427 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:05,429 [lib.api.process] INFO: Injected into 64-bit <Process 2200 backgroundTaskHost.exe>
2026-05-28 20:46:05,446 [root] DEBUG: 6488: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:46:05,463 [root] DEBUG: 6488: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:46:05,479 [root] DEBUG: 6488: DLL loaded at 0x00007FFED0B00000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-05-28 20:46:05,663 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 20:46:05,665 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEF430000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 20:46:05,665 [root] DEBUG: 6488: DLL loaded at 0x00007FFED48E0000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-05-28 20:46:05,671 [root] DEBUG: 6488: DLL loaded at 0x00007FFEDDB70000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 20:46:05,673 [root] DEBUG: 6488: DLL loaded at 0x00007FFED0890000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 20:46:05,676 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 20:46:05,678 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEF440000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-05-28 20:46:05,744 [root] DEBUG: 6488: api-rate-cap: NtReadFile hook disabled due to rate
2026-05-28 20:46:05,769 [root] DEBUG: 6488: DLL loaded at 0x00007FFED0890000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 20:46:05,824 [root] DEBUG: 6488: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 20:46:05,852 [root] DEBUG: 6488: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 20:46:06,511 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:06,516 [root] DEBUG: Loader: Injecting process 6652 (thread 6668) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:06,518 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:06,519 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:06,521 [lib.api.process] INFO: Injected into 64-bit <Process 6652 SearchApp.exe>
2026-05-28 20:46:06,524 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6652
2026-05-28 20:46:06,526 [lib.api.process] INFO: Monitor config for process 6652: C:\6lreqs2g\dll\6652.ini
2026-05-28 20:46:06,526 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:08,330 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:08,335 [root] DEBUG: Loader: Injecting process 6652 (thread 6668) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:08,336 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:08,336 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:08,338 [lib.api.process] INFO: Injected into 64-bit <Process 6652 SearchApp.exe>
2026-05-28 20:46:08,341 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6652
2026-05-28 20:46:08,341 [lib.api.process] INFO: Monitor config for process 6652: C:\6lreqs2g\dll\6652.ini
2026-05-28 20:46:08,342 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:09,627 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:46:09,627 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:46:09,632 [root] DEBUG: 6488: DLL loaded at 0x00007FFED47D0000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-05-28 20:46:09,634 [root] DEBUG: 6488: DLL loaded at 0x00007FFED8B50000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 20:46:09,637 [root] DEBUG: 6488: DLL loaded at 0x00007FFEDDEA0000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:46:09,640 [root] DEBUG: 6488: DLL loaded at 0x00007FFEE8E60000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:46:09,644 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEB550000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 20:46:09,650 [root] DEBUG: 6488: DLL loaded at 0x00007FFEE6100000: C:\Windows\SYSTEM32\productenumerator (0xe000 bytes).
2026-05-28 20:46:09,940 [root] DEBUG: 6488: DLL loaded at 0x00007FFEEACF0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 20:46:09,967 [root] INFO: Announced starting service "b'WaaSMedicSvc'"
2026-05-28 20:46:09,987 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:09,992 [root] DEBUG: Loader: Injecting process 6652 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:09,993 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 6668, handle 0x120
2026-05-28 20:46:09,994 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:09,996 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:09,997 [lib.api.process] INFO: Injected into 64-bit <Process 6652 SearchApp.exe>
2026-05-28 20:46:10,005 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 5280: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:10,005 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 5280
2026-05-28 20:46:10,006 [lib.api.process] INFO: Monitor config for process 5280: C:\6lreqs2g\dll\5280.ini
2026-05-28 20:46:10,008 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:10,993 [root] DEBUG: 6488: DLL loaded at 0x00007FFEE04A0000: C:\Windows\system32\WaaSMedicPS (0xc000 bytes).
2026-05-28 20:46:11,087 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\36fb459888775a4779c17df06b0270343f12a6dce043331aa4a900db71221952; Size is 8720; Max size: 100000000
2026-05-28 20:46:11,104 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\af7019942d9bc658e47e93ec01a57bbc1b8dbd43953878eadf05f257e7711c09; Size is 8720; Max size: 100000000
2026-05-28 20:46:11,128 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\449859e0f4386677c1fe40870804966c53a27284a57939ea6f6e78d4b9c82d71; Size is 8720; Max size: 100000000
2026-05-28 20:46:11,150 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\7c1d178c2e5a0782d0fb7914c90388a8ba5bb1364086220970d263ff3aba37b6; Size is 8720; Max size: 100000000
2026-05-28 20:46:11,167 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\3034b5cd3ccd0726341e632626b2b25d9220dea2f15aba0ef30b7c499cdb8b9c; Size is 8720; Max size: 100000000
2026-05-28 20:46:11,216 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\613cff5c4fcdad1028966a48c9ff47a21121fb2fece6a25d94447687c83712f2; Size is 12824; Max size: 100000000
2026-05-28 20:46:11,665 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:11,671 [root] DEBUG: Loader: Injecting process 5280 (thread 4684) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:11,673 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:11,674 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:11,675 [lib.api.process] INFO: Injected into 64-bit <Process 5280 SearchApp.exe>
2026-05-28 20:46:11,678 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 5280
2026-05-28 20:46:11,679 [lib.api.process] INFO: Monitor config for process 5280: C:\6lreqs2g\dll\5280.ini
2026-05-28 20:46:11,680 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:12,746 [root] DEBUG: 12844: NtTerminateProcess hook: Attempting to dump process 12844
2026-05-28 20:46:12,747 [root] DEBUG: 12844: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:46:12,749 [root] INFO: Process with pid 12844 has terminated
2026-05-28 20:46:13,491 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:13,496 [root] DEBUG: Loader: Injecting process 5280 (thread 4684) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:13,498 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:13,499 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:13,501 [lib.api.process] INFO: Injected into 64-bit <Process 5280 SearchApp.exe>
2026-05-28 20:46:13,503 [root] INFO: Process with pid 5280 has terminated
2026-05-28 20:46:13,722 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13976: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:13,729 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 13976
2026-05-28 20:46:13,730 [lib.api.process] INFO: Monitor config for process 13976: C:\6lreqs2g\dll\13976.ini
2026-05-28 20:46:13,733 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:15,148 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:15,154 [root] DEBUG: Loader: Injecting process 13976 (thread 11132) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:15,156 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:15,156 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:15,159 [lib.api.process] INFO: Injected into 64-bit <Process 13976 SearchApp.exe>
2026-05-28 20:46:15,162 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 13976
2026-05-28 20:46:15,163 [lib.api.process] INFO: Monitor config for process 13976: C:\6lreqs2g\dll\13976.ini
2026-05-28 20:46:15,163 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:16,747 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 2296: C:\Windows\System32\mobsync.exe, ImageBase: 0x00007FF669BF0000
2026-05-28 20:46:16,751 [root] INFO: Announced 64-bit process name: mobsync.exe pid: 2296
2026-05-28 20:46:16,752 [lib.api.process] INFO: Monitor config for process 2296: C:\6lreqs2g\dll\2296.ini
2026-05-28 20:46:16,754 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:16,760 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:16,765 [root] DEBUG: Loader: Injecting process 2296 (thread 5280) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:16,766 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:16,768 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:16,769 [lib.api.process] INFO: Injected into 64-bit <Process 2296 mobsync.exe>
2026-05-28 20:46:16,773 [root] INFO: Announced 64-bit process name: mobsync.exe pid: 2296
2026-05-28 20:46:16,774 [lib.api.process] INFO: Monitor config for process 2296: C:\6lreqs2g\dll\2296.ini
2026-05-28 20:46:16,775 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:16,785 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:16,791 [root] DEBUG: Loader: Injecting process 2296 (thread 5280) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:16,794 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:16,796 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:16,798 [lib.api.process] INFO: Injected into 64-bit <Process 2296 mobsync.exe>
2026-05-28 20:46:16,804 [root] DEBUG: 2296: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:46:16,806 [root] DEBUG: 2296: Interactive desktop enabled.
2026-05-28 20:46:16,807 [root] DEBUG: 2296: Dropped file limit defaulting to 100.
2026-05-28 20:46:16,811 [root] DEBUG: 2296: Disabling sleep skipping.
2026-05-28 20:46:16,812 [root] DEBUG: 2296: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:46:16,824 [root] DEBUG: 2296: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:46:16,826 [root] DEBUG: 2296: YaraScan: Scanning 0x00007FF669BF0000, size 0x1d056
2026-05-28 20:46:16,831 [root] DEBUG: 2296: Monitor initialised: 64-bit capemon loaded in process 2296 at 0x00007FFEAF1A0000, thread 5280, image base 0x00007FF669BF0000, stack from 0x000000DB317C4000-0x000000DB317D0000
2026-05-28 20:46:16,832 [root] DEBUG: 2296: Commandline: C:\Windows\System32\mobsync.exe -Embedding
2026-05-28 20:46:16,842 [root] DEBUG: 2296: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:46:16,863 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:46:16,864 [root] DEBUG: 2296: set_hooks: Unable to hook LockResource
2026-05-28 20:46:16,869 [root] DEBUG: 2296: Hooked 627 out of 628 functions
2026-05-28 20:46:16,872 [root] DEBUG: 2296: Syscall hook installed, syscall logging level 1
2026-05-28 20:46:16,877 [root] DEBUG: 2296: RestoreHeaders: Restored original import table.
2026-05-28 20:46:16,878 [root] INFO: Loaded monitor into process with pid 2296
2026-05-28 20:46:16,879 [root] DEBUG: 2296: caller_dispatch: Added region at 0x00007FF669BF0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF669BF4861, thread 5280).
2026-05-28 20:46:16,881 [root] DEBUG: 2296: YaraScan: Scanning 0x00007FF669BF0000, size 0x1d056
2026-05-28 20:46:16,883 [root] DEBUG: 2296: ProcessImageBase: Main module image at 0x00007FF669BF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:46:16,885 [root] DEBUG: 2296: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:46:16,889 [root] DEBUG: 2296: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:46:16,890 [root] DEBUG: 2296: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:46:16,892 [root] DEBUG: 2296: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:46:16,900 [root] DEBUG: 2296: DLL loaded at 0x00007FFED4BC0000: C:\Windows\System32\SyncCenter (0x83000 bytes).
2026-05-28 20:46:16,903 [root] DEBUG: 2296: DLL loaded at 0x00007FFEDB070000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32 (0x29a000 bytes).
2026-05-28 20:46:16,906 [root] DEBUG: 2296: DLL loaded at 0x00007FFEE88C0000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 20:46:16,915 [root] DEBUG: 2296: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:46:16,918 [root] DEBUG: 2296: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:46:16,920 [root] DEBUG: 2296: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:46:16,923 [root] DEBUG: 2296: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-05-28 20:46:16,924 [root] DEBUG: 2296: DLL loaded at 0x00007FFEEB3E0000: C:\Windows\system32\WTSAPI32 (0x14000 bytes).
2026-05-28 20:46:16,926 [root] DEBUG: 2296: DLL loaded at 0x00007FFED42A0000: C:\Windows\system32\SyncInfrastructure (0x6e000 bytes).
2026-05-28 20:46:16,929 [root] DEBUG: 2296: DLL loaded at 0x00007FFEEF440000: C:\Windows\system32\WINSTA (0x5b000 bytes).
2026-05-28 20:46:16,931 [root] DEBUG: 2296: DLL loaded at 0x00007FFED74D0000: C:\Windows\System32\cscui (0xcd000 bytes).
2026-05-28 20:46:16,937 [root] DEBUG: 2296: DLL loaded at 0x00007FFEDCD00000: C:\Windows\System32\CSCAPI (0x12000 bytes).
2026-05-28 20:46:17,173 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:17,178 [root] DEBUG: Loader: Injecting process 13976 (thread 11132) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:17,179 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:17,180 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:17,182 [lib.api.process] INFO: Injected into 64-bit <Process 13976 SearchApp.exe>
2026-05-28 20:46:17,184 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 13976
2026-05-28 20:46:17,185 [lib.api.process] INFO: Monitor config for process 13976: C:\6lreqs2g\dll\13976.ini
2026-05-28 20:46:17,185 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:19,106 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:19,111 [root] DEBUG: Loader: Injecting process 13976 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:19,113 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 11132, handle 0x120
2026-05-28 20:46:19,114 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:19,115 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:19,117 [lib.api.process] INFO: Injected into 64-bit <Process 13976 SearchApp.exe>
2026-05-28 20:46:19,123 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 15648: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:19,125 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 15648
2026-05-28 20:46:19,126 [lib.api.process] INFO: Monitor config for process 15648: C:\6lreqs2g\dll\15648.ini
2026-05-28 20:46:19,128 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:21,073 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:21,078 [root] DEBUG: Loader: Injecting process 15648 (thread 15652) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:21,078 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:21,080 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:21,081 [lib.api.process] INFO: Injected into 64-bit <Process 15648 SearchApp.exe>
2026-05-28 20:46:21,084 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 15648
2026-05-28 20:46:21,085 [lib.api.process] INFO: Monitor config for process 15648: C:\6lreqs2g\dll\15648.ini
2026-05-28 20:46:21,085 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:23,022 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:23,027 [root] DEBUG: Loader: Injecting process 15648 (thread 15652) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:23,030 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:23,031 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:23,032 [lib.api.process] INFO: Injected into 64-bit <Process 15648 SearchApp.exe>
2026-05-28 20:46:23,034 [root] INFO: Process with pid 15648 has terminated
2026-05-28 20:46:23,047 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 15792: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:23,049 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 15792
2026-05-28 20:46:23,050 [lib.api.process] INFO: Monitor config for process 15792: C:\6lreqs2g\dll\15792.ini
2026-05-28 20:46:23,052 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:25,045 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:25,052 [root] DEBUG: Loader: Injecting process 15792 (thread 15796) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:25,055 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:25,056 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:25,058 [lib.api.process] INFO: Injected into 64-bit <Process 15792 SearchApp.exe>
2026-05-28 20:46:25,061 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 15792
2026-05-28 20:46:25,063 [lib.api.process] INFO: Monitor config for process 15792: C:\6lreqs2g\dll\15792.ini
2026-05-28 20:46:25,064 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:26,855 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:26,860 [root] DEBUG: Loader: Injecting process 15792 (thread 15796) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:26,861 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:26,862 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:26,864 [lib.api.process] INFO: Injected into 64-bit <Process 15792 SearchApp.exe>
2026-05-28 20:46:26,866 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 15792
2026-05-28 20:46:26,866 [lib.api.process] INFO: Monitor config for process 15792: C:\6lreqs2g\dll\15792.ini
2026-05-28 20:46:26,868 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:27,044 [root] DEBUG: 2296: NtTerminateProcess hook: Attempting to dump process 2296
2026-05-28 20:46:27,046 [root] DEBUG: 2296: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:46:27,055 [root] INFO: Process with pid 2296 has terminated
2026-05-28 20:46:29,036 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:29,041 [root] DEBUG: Loader: Injecting process 15792 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:29,042 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15796, handle 0x120
2026-05-28 20:46:29,043 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:29,045 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:29,047 [lib.api.process] INFO: Injected into 64-bit <Process 15792 SearchApp.exe>
2026-05-28 20:46:31,053 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 16028: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:31,055 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16028
2026-05-28 20:46:31,056 [lib.api.process] INFO: Monitor config for process 16028: C:\6lreqs2g\dll\16028.ini
2026-05-28 20:46:31,058 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:32,879 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:32,884 [root] DEBUG: Loader: Injecting process 16028 (thread 16032) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:32,886 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:32,887 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:32,889 [lib.api.process] INFO: Injected into 64-bit <Process 16028 SearchApp.exe>
2026-05-28 20:46:32,891 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16028
2026-05-28 20:46:32,892 [lib.api.process] INFO: Monitor config for process 16028: C:\6lreqs2g\dll\16028.ini
2026-05-28 20:46:32,893 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:34,797 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:34,804 [root] DEBUG: Loader: Injecting process 16028 (thread 16032) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:34,805 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:34,807 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:34,809 [lib.api.process] INFO: Injected into 64-bit <Process 16028 SearchApp.exe>
2026-05-28 20:46:34,812 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16028
2026-05-28 20:46:34,813 [lib.api.process] INFO: Monitor config for process 16028: C:\6lreqs2g\dll\16028.ini
2026-05-28 20:46:34,814 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:36,605 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:36,611 [root] DEBUG: Loader: Injecting process 16028 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:36,612 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16032, handle 0x120
2026-05-28 20:46:36,613 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:36,614 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:36,615 [lib.api.process] INFO: Injected into 64-bit <Process 16028 SearchApp.exe>
2026-05-28 20:46:36,621 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 16224: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:36,622 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16224
2026-05-28 20:46:36,623 [lib.api.process] INFO: Monitor config for process 16224: C:\6lreqs2g\dll\16224.ini
2026-05-28 20:46:36,626 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:38,321 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:38,327 [root] DEBUG: Loader: Injecting process 16224 (thread 16228) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:38,328 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:38,331 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:38,332 [lib.api.process] INFO: Injected into 64-bit <Process 16224 SearchApp.exe>
2026-05-28 20:46:38,335 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16224
2026-05-28 20:46:38,335 [lib.api.process] INFO: Monitor config for process 16224: C:\6lreqs2g\dll\16224.ini
2026-05-28 20:46:38,337 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:40,202 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:40,208 [root] DEBUG: Loader: Injecting process 16224 (thread 16228) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:40,209 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:40,211 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:40,213 [lib.api.process] INFO: Injected into 64-bit <Process 16224 SearchApp.exe>
2026-05-28 20:46:40,215 [root] INFO: Process with pid 16224 has terminated
2026-05-28 20:46:40,392 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 16356: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:40,394 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16356
2026-05-28 20:46:40,395 [lib.api.process] INFO: Monitor config for process 16356: C:\6lreqs2g\dll\16356.ini
2026-05-28 20:46:40,398 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:42,379 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:42,386 [root] DEBUG: Loader: Injecting process 16356 (thread 16360) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:42,387 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:42,389 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:42,390 [lib.api.process] INFO: Injected into 64-bit <Process 16356 SearchApp.exe>
2026-05-28 20:46:42,393 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16356
2026-05-28 20:46:42,396 [lib.api.process] INFO: Monitor config for process 16356: C:\6lreqs2g\dll\16356.ini
2026-05-28 20:46:42,396 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:44,172 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:44,177 [root] DEBUG: Loader: Injecting process 16356 (thread 16360) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:44,179 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:44,179 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:44,181 [lib.api.process] INFO: Injected into 64-bit <Process 16356 SearchApp.exe>
2026-05-28 20:46:44,183 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 16356
2026-05-28 20:46:44,184 [lib.api.process] INFO: Monitor config for process 16356: C:\6lreqs2g\dll\16356.ini
2026-05-28 20:46:44,185 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:45,894 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:45,898 [root] DEBUG: Loader: Injecting process 16356 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:45,907 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16360, handle 0x120
2026-05-28 20:46:45,922 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:45,923 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:45,928 [lib.api.process] INFO: Injected into 64-bit <Process 16356 SearchApp.exe>
2026-05-28 20:46:45,938 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 9748: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:45,941 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 9748
2026-05-28 20:46:45,943 [lib.api.process] INFO: Monitor config for process 9748: C:\6lreqs2g\dll\9748.ini
2026-05-28 20:46:45,944 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:47,651 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:47,656 [root] DEBUG: Loader: Injecting process 9748 (thread 15728) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:47,658 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:47,659 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:47,660 [lib.api.process] INFO: Injected into 64-bit <Process 9748 SearchApp.exe>
2026-05-28 20:46:47,663 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 9748
2026-05-28 20:46:47,664 [lib.api.process] INFO: Monitor config for process 9748: C:\6lreqs2g\dll\9748.ini
2026-05-28 20:46:47,664 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:49,520 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:49,525 [root] DEBUG: Loader: Injecting process 9748 (thread 15728) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:49,526 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:49,528 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:49,530 [lib.api.process] INFO: Injected into 64-bit <Process 9748 SearchApp.exe>
2026-05-28 20:46:49,532 [root] INFO: Process with pid 9748 has terminated
2026-05-28 20:46:49,719 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 15888: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:49,720 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 15888
2026-05-28 20:46:49,721 [lib.api.process] INFO: Monitor config for process 15888: C:\6lreqs2g\dll\15888.ini
2026-05-28 20:46:49,724 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:51,493 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:51,498 [root] DEBUG: Loader: Injecting process 15888 (thread 15884) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:51,499 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:51,501 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:51,502 [lib.api.process] INFO: Injected into 64-bit <Process 15888 SearchApp.exe>
2026-05-28 20:46:51,504 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 15888
2026-05-28 20:46:51,505 [lib.api.process] INFO: Monitor config for process 15888: C:\6lreqs2g\dll\15888.ini
2026-05-28 20:46:51,506 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:53,346 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:53,351 [root] DEBUG: Loader: Injecting process 15888 (thread 15884) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:53,352 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:53,354 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:53,356 [lib.api.process] INFO: Injected into 64-bit <Process 15888 SearchApp.exe>
2026-05-28 20:46:53,358 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 15888
2026-05-28 20:46:53,359 [lib.api.process] INFO: Monitor config for process 15888: C:\6lreqs2g\dll\15888.ini
2026-05-28 20:46:53,360 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:55,372 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:55,377 [root] DEBUG: Loader: Injecting process 15888 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:55,378 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15884, handle 0x120
2026-05-28 20:46:55,379 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:55,380 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:55,382 [lib.api.process] INFO: Injected into 64-bit <Process 15888 SearchApp.exe>
2026-05-28 20:46:55,388 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 6480: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:46:55,390 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6480
2026-05-28 20:46:55,391 [lib.api.process] INFO: Monitor config for process 6480: C:\6lreqs2g\dll\6480.ini
2026-05-28 20:46:55,394 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:57,262 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:57,267 [root] DEBUG: Loader: Injecting process 6480 (thread 15976) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:57,268 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:46:57,269 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:57,270 [lib.api.process] INFO: Injected into 64-bit <Process 6480 SearchApp.exe>
2026-05-28 20:46:57,273 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 6480
2026-05-28 20:46:57,274 [lib.api.process] INFO: Monitor config for process 6480: C:\6lreqs2g\dll\6480.ini
2026-05-28 20:46:57,275 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:46:59,135 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:46:59,140 [root] DEBUG: Loader: Injecting process 6480 (thread 15976) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:59,143 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:46:59,144 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:46:59,145 [lib.api.process] INFO: Injected into 64-bit <Process 6480 SearchApp.exe>
2026-05-28 20:46:59,147 [root] INFO: Process with pid 6480 has terminated
2026-05-28 20:47:10,387 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 4784: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:47:10,390 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 4784
2026-05-28 20:47:10,392 [lib.api.process] INFO: Monitor config for process 4784: C:\6lreqs2g\dll\4784.ini
2026-05-28 20:47:10,395 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:12,247 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:12,252 [root] DEBUG: Loader: Injecting process 4784 (thread 9936) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:12,253 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:12,255 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:12,256 [lib.api.process] INFO: Injected into 64-bit <Process 4784 SearchApp.exe>
2026-05-28 20:47:12,259 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 4784
2026-05-28 20:47:12,260 [lib.api.process] INFO: Monitor config for process 4784: C:\6lreqs2g\dll\4784.ini
2026-05-28 20:47:12,261 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:12,860 [root] INFO: Added new file to list with pid 6488 and path C:\ProgramData\USOShared\Logs\System\WuProvider.b5e56581-e9b6-4595-a683-a4789100303e.1.etl
2026-05-28 20:47:12,862 [root] INFO: Added new file to list with pid 6488 and path C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.abb9326d-c835-4d41-ae0d-bb11604e02df.1.etl
2026-05-28 20:47:12,863 [root] DEBUG: 6488: NtTerminateProcess hook: Attempting to dump process 6488
2026-05-28 20:47:12,865 [root] DEBUG: 6488: CAPEExceptionFilter: Exception 0xc0000005 accessing 0xd051d004 caught at RVA 0x75419 in capemon (expected in memory scans), passing to next handler.
2026-05-28 20:47:12,866 [root] DEBUG: 6488: VerifyCodeSection: Exception rebasing image from 0x00007FF6D0370000 to 0x0000000140000000.
2026-05-28 20:47:12,868 [root] DEBUG: 6488: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:47:12,878 [root] INFO: Process with pid 6488 has terminated
2026-05-28 20:47:14,266 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:14,275 [root] DEBUG: Loader: Injecting process 4784 (thread 9936) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:14,276 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:47:14,280 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:14,282 [lib.api.process] INFO: Injected into 64-bit <Process 4784 SearchApp.exe>
2026-05-28 20:47:14,284 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 4784
2026-05-28 20:47:14,285 [lib.api.process] INFO: Monitor config for process 4784: C:\6lreqs2g\dll\4784.ini
2026-05-28 20:47:14,286 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:15,562 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 6204: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:47:15,567 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6204
2026-05-28 20:47:15,568 [lib.api.process] INFO: Monitor config for process 6204: C:\6lreqs2g\dll\6204.ini
2026-05-28 20:47:15,570 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:15,574 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:15,579 [root] DEBUG: Loader: Injecting process 6204 (thread 6208) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:15,580 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:15,582 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:15,583 [lib.api.process] INFO: Injected into 64-bit <Process 6204 dllhost.exe>
2026-05-28 20:47:15,584 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6204
2026-05-28 20:47:15,586 [lib.api.process] INFO: Monitor config for process 6204: C:\6lreqs2g\dll\6204.ini
2026-05-28 20:47:15,588 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:15,596 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:15,601 [root] DEBUG: Loader: Injecting process 6204 (thread 6208) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:15,603 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:15,604 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:15,606 [lib.api.process] INFO: Injected into 64-bit <Process 6204 dllhost.exe>
2026-05-28 20:47:15,612 [root] DEBUG: 6204: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:47:15,614 [root] DEBUG: 6204: Interactive desktop enabled.
2026-05-28 20:47:15,615 [root] DEBUG: 6204: Dropped file limit defaulting to 100.
2026-05-28 20:47:15,619 [root] DEBUG: 6204: Disabling sleep skipping.
2026-05-28 20:47:15,621 [root] DEBUG: 6204: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:47:15,632 [root] DEBUG: 6204: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:47:15,633 [root] DEBUG: 6204: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:47:15,635 [root] DEBUG: 6204: Monitor initialised: 64-bit capemon loaded in process 6204 at 0x00007FFEAF1A0000, thread 6208, image base 0x00007FF6868D0000, stack from 0x000000EAB10F4000-0x000000EAB1100000
2026-05-28 20:47:15,637 [root] DEBUG: 6204: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:47:15,646 [root] DEBUG: 6204: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:47:15,668 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:47:15,669 [root] DEBUG: 6204: set_hooks: Unable to hook LockResource
2026-05-28 20:47:15,674 [root] DEBUG: 6204: Hooked 627 out of 628 functions
2026-05-28 20:47:15,675 [root] DEBUG: 6204: Syscall hook installed, syscall logging level 1
2026-05-28 20:47:15,680 [root] DEBUG: 6204: RestoreHeaders: Restored original import table.
2026-05-28 20:47:15,682 [root] INFO: Loaded monitor into process with pid 6204
2026-05-28 20:47:15,685 [root] DEBUG: 6204: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 6208).
2026-05-28 20:47:15,688 [root] DEBUG: 6204: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:47:15,689 [root] DEBUG: 6204: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:47:15,692 [root] DEBUG: 6204: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:47:15,693 [root] DEBUG: 6204: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:47:15,696 [root] DEBUG: 6204: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:47:15,710 [root] DEBUG: 6204: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:47:15,724 [root] DEBUG: 6204: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:47:15,727 [root] DEBUG: 6204: DLL loaded at 0x00007FFEE27A0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:47:15,732 [root] DEBUG: 6204: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:47:16,303 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:16,309 [root] DEBUG: Loader: Injecting process 4784 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:16,310 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9936, handle 0x124
2026-05-28 20:47:16,311 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:47:16,312 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:16,313 [lib.api.process] INFO: Injected into 64-bit <Process 4784 SearchApp.exe>
2026-05-28 20:47:20,847 [root] INFO: Process with pid 6204 appears to have terminated
2026-05-28 20:47:42,922 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12372: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF6357C0000
2026-05-28 20:47:42,923 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12372
2026-05-28 20:47:42,924 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13644: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF6357C0000
2026-05-28 20:47:42,925 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13644
2026-05-28 20:47:42,925 [lib.api.process] INFO: Monitor config for process 12372: C:\6lreqs2g\dll\12372.ini
2026-05-28 20:47:42,927 [lib.api.process] INFO: Monitor config for process 13644: C:\6lreqs2g\dll\13644.ini
2026-05-28 20:47:42,928 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:42,930 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:42,934 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:42,937 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:42,939 [root] DEBUG: Loader: Injecting process 12372 (thread 10880) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,940 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:42,942 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,943 [root] DEBUG: Loader: Injecting process 13644 (thread 16060) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,944 [lib.api.process] INFO: Injected into 64-bit <Process 12372 backgroundTaskHost.exe>
2026-05-28 20:47:42,945 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:42,947 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,949 [lib.api.process] INFO: Injected into 64-bit <Process 13644 backgroundTaskHost.exe>
2026-05-28 20:47:42,950 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12372
2026-05-28 20:47:42,951 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13644
2026-05-28 20:47:42,951 [lib.api.process] INFO: Monitor config for process 12372: C:\6lreqs2g\dll\12372.ini
2026-05-28 20:47:42,954 [lib.api.process] INFO: Monitor config for process 13644: C:\6lreqs2g\dll\13644.ini
2026-05-28 20:47:42,954 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:42,954 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:42,964 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:42,965 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:42,971 [root] DEBUG: Loader: Injecting process 13644 (thread 16060) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,972 [root] DEBUG: Loader: Injecting process 12372 (thread 10880) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,975 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:47:42,977 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,980 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:47:42,980 [lib.api.process] INFO: Injected into 64-bit <Process 13644 backgroundTaskHost.exe>
2026-05-28 20:47:42,981 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,982 [lib.api.process] INFO: Injected into 64-bit <Process 12372 backgroundTaskHost.exe>
2026-05-28 20:47:42,983 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13644
2026-05-28 20:47:42,985 [lib.api.process] INFO: Monitor config for process 13644: C:\6lreqs2g\dll\13644.ini
2026-05-28 20:47:42,986 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:42,987 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12372
2026-05-28 20:47:42,988 [lib.api.process] INFO: Monitor config for process 12372: C:\6lreqs2g\dll\12372.ini
2026-05-28 20:47:42,990 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:42,994 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:42,999 [root] DEBUG: Loader: Injecting process 13644 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:42,999 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:43,001 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16060, handle 0x120
2026-05-28 20:47:43,003 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:47:43,004 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:43,006 [lib.api.process] INFO: Injected into 64-bit <Process 13644 backgroundTaskHost.exe>
2026-05-28 20:47:43,008 [root] DEBUG: Loader: Injecting process 12372 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:43,009 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10880, handle 0x120
2026-05-28 20:47:43,011 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:47:43,012 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:43,015 [lib.api.process] INFO: Injected into 64-bit <Process 12372 backgroundTaskHost.exe>
2026-05-28 20:47:43,020 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 6360: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF6357C0000
2026-05-28 20:47:43,023 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 6360
2026-05-28 20:47:43,024 [lib.api.process] INFO: Monitor config for process 6360: C:\6lreqs2g\dll\6360.ini
2026-05-28 20:47:43,026 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:43,034 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:43,039 [root] DEBUG: Loader: Injecting process 6360 (thread 5696) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:43,041 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:43,042 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:43,045 [lib.api.process] INFO: Injected into 64-bit <Process 6360 backgroundTaskHost.exe>
2026-05-28 20:47:43,047 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 6360
2026-05-28 20:47:43,048 [lib.api.process] INFO: Monitor config for process 6360: C:\6lreqs2g\dll\6360.ini
2026-05-28 20:47:43,050 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:43,060 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:43,065 [root] DEBUG: Loader: Injecting process 6360 (thread 5696) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:43,067 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:47:43,068 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:43,070 [lib.api.process] INFO: Injected into 64-bit <Process 6360 backgroundTaskHost.exe>
2026-05-28 20:47:43,073 [root] INFO: Process with pid 6360 has terminated
2026-05-28 20:47:44,788 [root] DEBUG: 9092: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:47:44,790 [root] DEBUG: 9092: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:47:44,792 [root] DEBUG: 9092: CreateProcessHandler: Injection info set for new process 16296: \\?\C:\Windows\system32\wbem\WMIADAP.EXE, ImageBase: 0x00007FF7097C0000
2026-05-28 20:47:44,794 [root] INFO: Announced 64-bit process name: WMIADAP.exe pid: 16296
2026-05-28 20:47:44,797 [lib.api.process] INFO: Monitor config for process 16296: C:\6lreqs2g\dll\16296.ini
2026-05-28 20:47:44,800 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:47,260 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:47,266 [root] DEBUG: Loader: Injecting process 16296 (thread 16300) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:47,270 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:47,272 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:47,274 [lib.api.process] INFO: Injected into 64-bit <Process 16296 WMIADAP.exe>
2026-05-28 20:47:47,277 [root] INFO: Announced 64-bit process name: WMIADAP.exe pid: 16296
2026-05-28 20:47:47,279 [lib.api.process] INFO: Monitor config for process 16296: C:\6lreqs2g\dll\16296.ini
2026-05-28 20:47:47,279 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:49,771 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:49,776 [root] DEBUG: Loader: Injecting process 16296 (thread 16300) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:49,777 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:49,779 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:49,781 [lib.api.process] INFO: Injected into 64-bit <Process 16296 WMIADAP.exe>
2026-05-28 20:47:49,788 [root] DEBUG: 16296: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:47:49,790 [root] DEBUG: 16296: Interactive desktop enabled.
2026-05-28 20:47:49,792 [root] DEBUG: 16296: Dropped file limit defaulting to 100.
2026-05-28 20:47:49,796 [root] DEBUG: 16296: Disabling sleep skipping.
2026-05-28 20:47:49,798 [root] DEBUG: 16296: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:47:49,810 [root] DEBUG: 16296: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:47:49,812 [root] DEBUG: 16296: YaraScan: Scanning 0x00007FF7097C0000, size 0x302f8
2026-05-28 20:47:49,815 [root] DEBUG: 16296: Monitor initialised: 64-bit capemon loaded in process 16296 at 0x00007FFEAF1A0000, thread 16300, image base 0x00007FF7097C0000, stack from 0x000000BC55070000-0x000000BC55080000
2026-05-28 20:47:49,817 [root] DEBUG: 16296: Commandline: wmiadap.exe /F /T /R
2026-05-28 20:47:49,826 [root] DEBUG: 16296: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:47:49,847 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:47:49,848 [root] DEBUG: 16296: set_hooks: Unable to hook LockResource
2026-05-28 20:47:49,853 [root] DEBUG: 16296: Hooked 627 out of 628 functions
2026-05-28 20:47:49,856 [root] DEBUG: 16296: Syscall hook installed, syscall logging level 1
2026-05-28 20:47:49,861 [root] DEBUG: 16296: RestoreHeaders: Restored original import table.
2026-05-28 20:47:49,863 [root] INFO: Loaded monitor into process with pid 16296
2026-05-28 20:47:49,867 [root] DEBUG: 16296: caller_dispatch: Added region at 0x00007FF7097C0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7097D62B1, thread 16300).
2026-05-28 20:47:49,868 [root] DEBUG: 16296: YaraScan: Scanning 0x00007FF7097C0000, size 0x302f8
2026-05-28 20:47:49,871 [root] DEBUG: 16296: ProcessImageBase: Main module image at 0x00007FF7097C0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:47:49,875 [root] DEBUG: 16296: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:47:49,877 [root] DEBUG: 16296: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:47:49,882 [root] DEBUG: 16296: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:47:49,886 [root] DEBUG: 16296: DLL loaded at 0x00007FFEDD9B0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:47:49,887 [root] DEBUG: 16296: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 20:47:49,894 [root] DEBUG: 16296: DLL loaded at 0x00007FFED9650000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:47:49,898 [root] DEBUG: 16296: DLL loaded at 0x00007FFED9750000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2026-05-28 20:47:49,904 [root] DEBUG: 16296: DLL loaded at 0x00007FFED90A0000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 20:47:49,906 [root] DEBUG: 16296: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:47:49,907 [root] DEBUG: 16296: DLL loaded at 0x00007FFEEF640000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 20:47:49,911 [root] DEBUG: 16296: DLL loaded at 0x00007FFED9050000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 20:47:49,914 [root] DEBUG: 16296: DLL loaded at 0x00007FFED9040000: C:\Windows\system32\version (0xa000 bytes).
2026-05-28 20:47:49,918 [root] DEBUG: 16296: Successfully installed hook on COM Object function IWbemServices_ExecQuery
2026-05-28 20:47:49,919 [root] DEBUG: 16296: Successfully installed hook on COM Object function IWbemServices_ExecQueryAsync
2026-05-28 20:47:49,920 [root] DEBUG: 16296: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnum
2026-05-28 20:47:49,923 [root] DEBUG: 16296: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnumAsync
2026-05-28 20:47:49,924 [root] DEBUG: 16296: Successfully installed hook on COM Object function IWbemServices_GetObjectW
2026-05-28 20:47:49,926 [root] DEBUG: 16296: Successfully installed hook on COM Object function IWbemServices_GetObjectAsync
2026-05-28 20:47:49,927 [root] DEBUG: 16296: Successfully installed hook on COM Object function IWbemServices_ExecMethod
2026-05-28 20:47:49,929 [root] DEBUG: 16296: Successfully installed hook on COM Object function IWbemServices_ExecMethodAsync
2026-05-28 20:47:49,967 [root] DEBUG: 16296: DLL loaded at 0x00007FFEF0240000: C:\Windows\System32\PSAPI (0x8000 bytes).
2026-05-28 20:47:49,970 [root] DEBUG: 16296: DLL loaded at 0x00007FFEDF110000: C:\Windows\SYSTEM32\loadperf (0x25000 bytes).
2026-05-28 20:47:50,015 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 1724: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7D5630000
2026-05-28 20:47:50,017 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 1724
2026-05-28 20:47:50,018 [lib.api.process] INFO: Monitor config for process 1724: C:\6lreqs2g\dll\1724.ini
2026-05-28 20:47:50,021 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:52,624 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:52,630 [root] DEBUG: Loader: Injecting process 1724 (thread 1532) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:52,631 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:47:52,632 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:52,634 [lib.api.process] INFO: Injected into 64-bit <Process 1724 WmiPrvSE.exe>
2026-05-28 20:47:52,637 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 1724
2026-05-28 20:47:52,639 [lib.api.process] INFO: Monitor config for process 1724: C:\6lreqs2g\dll\1724.ini
2026-05-28 20:47:52,640 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:47:55,268 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:47:55,273 [root] DEBUG: Loader: Injecting process 1724 (thread 1532) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:55,276 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:47:55,278 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:47:55,280 [lib.api.process] INFO: Injected into 64-bit <Process 1724 WmiPrvSE.exe>
2026-05-28 20:47:55,286 [root] DEBUG: 1724: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:47:55,287 [root] DEBUG: 1724: Interactive desktop enabled.
2026-05-28 20:47:55,289 [root] DEBUG: 1724: Dropped file limit defaulting to 100.
2026-05-28 20:47:55,292 [root] DEBUG: 1724: Disabling sleep skipping.
2026-05-28 20:47:55,294 [root] DEBUG: 1724: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:47:55,308 [root] DEBUG: 1724: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:47:55,309 [root] DEBUG: 1724: YaraScan: Scanning 0x00007FF7D5630000, size 0x7dcfe
2026-05-28 20:47:55,312 [root] DEBUG: 1724: Monitor initialised: 64-bit capemon loaded in process 1724 at 0x00007FFEAF1A0000, thread 1532, image base 0x00007FF7D5630000, stack from 0x0000005B3B2B0000-0x0000005B3B2C0000
2026-05-28 20:47:55,313 [root] DEBUG: 1724: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -Embedding
2026-05-28 20:47:55,326 [root] DEBUG: 1724: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:47:55,349 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:47:55,354 [root] DEBUG: 1724: set_hooks: Unable to hook LockResource
2026-05-28 20:47:55,361 [root] DEBUG: 1724: Hooked 627 out of 628 functions
2026-05-28 20:47:55,365 [root] DEBUG: 1724: Syscall hook installed, syscall logging level 1
2026-05-28 20:47:55,371 [root] DEBUG: 1724: RestoreHeaders: Restored original import table.
2026-05-28 20:47:55,373 [root] INFO: Loaded monitor into process with pid 1724
2026-05-28 20:47:55,375 [root] DEBUG: 1724: caller_dispatch: Added region at 0x00007FF7D5630000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7D563F292, thread 1532).
2026-05-28 20:47:55,376 [root] DEBUG: 1724: YaraScan: Scanning 0x00007FF7D5630000, size 0x7dcfe
2026-05-28 20:47:55,380 [root] DEBUG: 1724: ProcessImageBase: Main module image at 0x00007FF7D5630000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:47:55,388 [root] DEBUG: 1724: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:47:55,392 [root] DEBUG: 1724: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:47:55,396 [root] DEBUG: 1724: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:47:55,401 [root] DEBUG: 1724: DLL loaded at 0x00007FFEDD9B0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:47:55,408 [root] DEBUG: 1724: DLL loaded at 0x00007FFED9650000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:47:55,440 [root] DEBUG: 1724: DLL loaded at 0x00007FFED0440000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 20:47:55,467 [root] DEBUG: 1724: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:47:55,469 [root] DEBUG: 1724: DLL loaded at 0x00007FFE95F80000: C:\Windows\system32\wbem\esscli (0x7d000 bytes).
2026-05-28 20:47:55,471 [root] DEBUG: 1724: DLL loaded at 0x00007FFED6EB0000: C:\Windows\system32\wbem\wmiprov (0x3d000 bytes).
2026-05-28 20:47:55,476 [root] DEBUG: 1724: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 20:47:55,483 [root] DEBUG: 1724: DLL loaded at 0x00007FFEEA840000: C:\Windows\SYSTEM32\WMICLNT (0x11000 bytes).
2026-05-28 20:47:55,649 [root] DEBUG: 1724: api-rate-cap: ?Get@CWbemObject@@UEAAJPEBGJPEAUtagVARIANT@@PEAJ2@Z hook disabled due to rate
2026-05-28 20:47:55,725 [root] DEBUG: 16296: api-rate-cap: GetUserDefaultLCID hook disabled due to rate
2026-05-28 20:47:56,465 [root] DEBUG: 16296: api-rate-cap: RegQueryValueExW hook disabled due to rate
2026-05-28 20:47:56,635 [root] DEBUG: 16296: api-rate-cap: NtQueryValueKey hook disabled due to rate
2026-05-28 20:47:56,797 [root] DEBUG: 16296: api-rate-cap: GetLastInputInfo hook disabled due to rate
2026-05-28 20:48:05,622 [root] INFO: Added new file to list with pid 16296 and path C:\Windows\System32\wbem\Performance\WmiApRpl_new.h
2026-05-28 20:48:05,625 [lib.common.results] INFO: Uploading file C:\Windows\System32\wbem\Performance\WmiApRpl.h to files\ae2b6236d3eeb4822835714ae9444e5dcd21bc60f7a909f2962c43bc743c7b15; Size is 3444; Max size: 100000000
2026-05-28 20:48:09,472 [root] INFO: Added new file to list with pid 416 and path C:\Windows\Logs\CBS\CBS.log
2026-05-28 20:48:09,474 [root] DEBUG: 416: NtTerminateProcess hook: Attempting to dump process 416
2026-05-28 20:48:09,475 [root] DEBUG: 416: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:48:09,483 [root] INFO: Process with pid 416 has terminated
2026-05-28 20:48:13,738 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 16880: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF6CDF10000
2026-05-28 20:48:13,741 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 16880
2026-05-28 20:48:13,741 [lib.api.process] INFO: Monitor config for process 16880: C:\6lreqs2g\dll\16880.ini
2026-05-28 20:48:13,745 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:13,753 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:13,758 [root] DEBUG: Loader: Injecting process 16880 (thread 16884) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:13,760 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:13,761 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:13,762 [lib.api.process] INFO: Injected into 64-bit <Process 16880 SecurityHealthHost.exe>
2026-05-28 20:48:13,765 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 16880
2026-05-28 20:48:13,768 [lib.api.process] INFO: Monitor config for process 16880: C:\6lreqs2g\dll\16880.ini
2026-05-28 20:48:13,768 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:13,779 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:13,783 [root] DEBUG: Loader: Injecting process 16880 (thread 16884) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:13,785 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:48:13,786 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:13,789 [lib.api.process] INFO: Injected into 64-bit <Process 16880 SecurityHealthHost.exe>
2026-05-28 20:48:13,796 [root] DEBUG: 16880: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:48:13,798 [root] DEBUG: 16880: Interactive desktop enabled.
2026-05-28 20:48:13,800 [root] DEBUG: 16880: Dropped file limit defaulting to 100.
2026-05-28 20:48:13,804 [root] DEBUG: 16880: Disabling sleep skipping.
2026-05-28 20:48:13,806 [root] DEBUG: 16880: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:48:13,818 [root] DEBUG: 16880: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:48:13,819 [root] DEBUG: 16880: YaraScan: Scanning 0x00007FF6CDF10000, size 0x19174
2026-05-28 20:48:13,820 [root] DEBUG: 16880: Monitor initialised: 64-bit capemon loaded in process 16880 at 0x00007FFEAF1A0000, thread 16884, image base 0x00007FF6CDF10000, stack from 0x000000EA0F194000-0x000000EA0F1A0000
2026-05-28 20:48:13,822 [root] DEBUG: 16880: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-28 20:48:13,831 [root] DEBUG: 16880: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:48:13,852 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:48:13,855 [root] DEBUG: 16880: set_hooks: Unable to hook LockResource
2026-05-28 20:48:13,860 [root] DEBUG: 16880: Hooked 627 out of 628 functions
2026-05-28 20:48:13,862 [root] DEBUG: 16880: Syscall hook installed, syscall logging level 1
2026-05-28 20:48:13,867 [root] DEBUG: 16880: RestoreHeaders: Restored original import table.
2026-05-28 20:48:13,868 [root] INFO: Loaded monitor into process with pid 16880
2026-05-28 20:48:13,870 [root] DEBUG: 16880: caller_dispatch: Added region at 0x00007FF6CDF10000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6CDF1D3B2, thread 16884).
2026-05-28 20:48:13,871 [root] DEBUG: 16880: YaraScan: Scanning 0x00007FF6CDF10000, size 0x19174
2026-05-28 20:48:13,882 [root] DEBUG: 16880: ProcessImageBase: Main module image at 0x00007FF6CDF10000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:48:13,896 [root] DEBUG: 16880: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:48:13,897 [root] DEBUG: 16880: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:48:13,904 [root] DEBUG: 16880: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:48:13,919 [root] DEBUG: 16880: DLL loaded at 0x00007FFEEF080000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 20:48:13,920 [root] DEBUG: 16880: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:48:13,922 [root] DEBUG: 16880: DLL loaded at 0x00007FFED7200000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-28 20:48:13,936 [root] DEBUG: 16880: DLL loaded at 0x00007FFEEC890000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 20:48:13,939 [root] DEBUG: 16880: DLL loaded at 0x00007FFEEAA90000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 20:48:13,945 [root] DEBUG: 16880: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:48:13,947 [root] DEBUG: 16880: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:48:13,949 [root] DEBUG: 16880: DLL loaded at 0x00007FFEED4F0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:48:13,950 [root] DEBUG: 16880: DLL loaded at 0x00007FFEEB240000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:48:13,953 [root] DEBUG: 16880: DLL loaded at 0x00007FFEE94D0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:48:13,954 [root] DEBUG: 16880: DLL loaded at 0x00007FFEDA690000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:48:13,958 [root] DEBUG: 16880: DLL loaded at 0x00007FFEEADA0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:48:13,966 [root] DEBUG: 16880: DLL loaded at 0x00007FFEE7C90000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:48:13,974 [root] DEBUG: 16880: DLL loaded at 0x00007FFED5C90000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 20:48:14,001 [root] DEBUG: 16880: NtTerminateProcess hook: Attempting to dump process 16880
2026-05-28 20:48:14,005 [root] DEBUG: 16880: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:48:14,014 [root] INFO: Process with pid 16880 has terminated
2026-05-28 20:48:14,023 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 17268: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF648C80000
2026-05-28 20:48:14,026 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 17268
2026-05-28 20:48:14,027 [lib.api.process] INFO: Monitor config for process 17268: C:\6lreqs2g\dll\17268.ini
2026-05-28 20:48:14,030 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:16,673 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:16,679 [root] DEBUG: Loader: Injecting process 17268 (thread 17272) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:16,680 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:16,682 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:16,685 [lib.api.process] INFO: Injected into 64-bit <Process 17268 ShellExperienceHost.exe>
2026-05-28 20:48:16,689 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 17268
2026-05-28 20:48:16,690 [lib.api.process] INFO: Monitor config for process 17268: C:\6lreqs2g\dll\17268.ini
2026-05-28 20:48:16,690 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:19,334 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:19,339 [root] DEBUG: Loader: Injecting process 17268 (thread 17272) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:19,341 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:19,343 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:19,345 [lib.api.process] INFO: Injected into 64-bit <Process 17268 ShellExperienceHost.exe>
2026-05-28 20:48:19,349 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 17268
2026-05-28 20:48:19,351 [lib.api.process] INFO: Monitor config for process 17268: C:\6lreqs2g\dll\17268.ini
2026-05-28 20:48:19,352 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:22,262 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:22,267 [root] DEBUG: Loader: Injecting process 17268 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:22,268 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17272, handle 0x120
2026-05-28 20:48:22,271 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:48:22,274 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:22,277 [lib.api.process] INFO: Injected into 64-bit <Process 17268 ShellExperienceHost.exe>
2026-05-28 20:48:22,860 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 10700: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:48:22,866 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 10700
2026-05-28 20:48:22,868 [lib.api.process] INFO: Monitor config for process 10700: C:\6lreqs2g\dll\10700.ini
2026-05-28 20:48:22,871 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:25,558 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:25,563 [root] DEBUG: Loader: Injecting process 10700 (thread 10788) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:25,564 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:25,566 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:25,568 [lib.api.process] INFO: Injected into 64-bit <Process 10700 SearchApp.exe>
2026-05-28 20:48:25,573 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 10700
2026-05-28 20:48:25,574 [lib.api.process] INFO: Monitor config for process 10700: C:\6lreqs2g\dll\10700.ini
2026-05-28 20:48:25,575 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:27,910 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:27,915 [root] DEBUG: Loader: Injecting process 10700 (thread 10788) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:27,916 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:48:27,920 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:27,922 [lib.api.process] INFO: Injected into 64-bit <Process 10700 SearchApp.exe>
2026-05-28 20:48:27,925 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 10700
2026-05-28 20:48:27,927 [lib.api.process] INFO: Monitor config for process 10700: C:\6lreqs2g\dll\10700.ini
2026-05-28 20:48:27,928 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:30,313 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:30,318 [root] DEBUG: Loader: Injecting process 10700 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:30,320 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10788, handle 0x120
2026-05-28 20:48:30,322 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:48:30,325 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:30,326 [lib.api.process] INFO: Injected into 64-bit <Process 10700 SearchApp.exe>
2026-05-28 20:48:37,436 [root] INFO: Added new file to list with pid 16296 and path C:\Windows\System32\wbem\Performance\WmiApRpl_new.ini
2026-05-28 20:48:37,445 [lib.common.results] INFO: Uploading file C:\Windows\System32\wbem\Performance\WmiApRpl.ini to files\c20b11dff802aa472265f4e9f330244ec4aca81b0009f6efcb2cf8a36086f390; Size is 29736; Max size: 100000000
2026-05-28 20:48:37,489 [root] INFO: Added new file to list with pid 16296 and path C:\Windows\System32\perfc009.dat
2026-05-28 20:48:37,493 [root] INFO: Added new file to list with pid 16296 and path C:\Windows\System32\perfh009.dat
2026-05-28 20:48:37,499 [lib.common.results] INFO: Uploading file C:\Windows\INF\WmiApRpl\0009\WmiApRpl.ini to files\c20b11dff802aa472265f4e9f330244ec4aca81b0009f6efcb2cf8a36086f390; Size is 29736; Max size: 100000000
2026-05-28 20:48:37,505 [lib.common.results] INFO: Uploading file C:\Windows\INF\WmiApRpl\WmiApRpl.h to files\ae2b6236d3eeb4822835714ae9444e5dcd21bc60f7a909f2962c43bc743c7b15; Size is 3444; Max size: 100000000
2026-05-28 20:48:37,513 [lib.common.results] INFO: Uploading file C:\Windows\INF\WmiApRpl\WmiApRpl.ini to files\c20b11dff802aa472265f4e9f330244ec4aca81b0009f6efcb2cf8a36086f390; Size is 29736; Max size: 100000000
2026-05-28 20:48:37,520 [root] DEBUG: 16296: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:48:37,523 [root] INFO: Added new file to list with pid 16296 and path C:\Windows\INF\WmiApRpl\WmiApRpl.h
2026-05-28 20:48:37,533 [root] INFO: Added new file to list with pid 16296 and path C:\Windows\INF\WmiApRpl\WmiApRpl.ini
2026-05-28 20:48:37,626 [root] DEBUG: 16296: api-rate-cap: NtWriteFile hook disabled due to rate
2026-05-28 20:48:37,646 [root] INFO: Added new file to list with pid 16296 and path C:\Windows\System32\PerfStringBackup.TMP
2026-05-28 20:48:37,651 [root] INFO: Added new file to list with pid 16296 and path C:\Windows\System32\PerfStringBackup.INI
2026-05-28 20:48:37,654 [lib.common.results] INFO: Uploading file C:\Windows\System32\PerfStringBackup.TMP to files\dff86bc86785d4235c80408b73210f340d2d0cbc155113a79045b741359b8542; Size is 795738; Max size: 100000000
2026-05-28 20:48:42,031 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 17328: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe, ImageBase: 0x00007FF6174D0000
2026-05-28 20:48:42,033 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17328
2026-05-28 20:48:42,034 [lib.api.process] INFO: Monitor config for process 17328: C:\6lreqs2g\dll\17328.ini
2026-05-28 20:48:42,037 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:44,500 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:44,505 [root] DEBUG: Loader: Injecting process 17328 (thread 17324) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:44,507 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:44,510 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:44,512 [lib.api.process] INFO: Injected into 64-bit <Process 17328 StartMenuExperienceHost.exe>
2026-05-28 20:48:44,515 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17328
2026-05-28 20:48:44,517 [lib.api.process] INFO: Monitor config for process 17328: C:\6lreqs2g\dll\17328.ini
2026-05-28 20:48:44,517 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:46,942 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:46,947 [root] DEBUG: Loader: Injecting process 17328 (thread 17324) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:46,948 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:46,950 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:46,952 [lib.api.process] INFO: Injected into 64-bit <Process 17328 StartMenuExperienceHost.exe>
2026-05-28 20:48:46,953 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17328
2026-05-28 20:48:46,955 [lib.api.process] INFO: Monitor config for process 17328: C:\6lreqs2g\dll\17328.ini
2026-05-28 20:48:46,956 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:47,974 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 5892: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:48:47,980 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5892
2026-05-28 20:48:47,986 [lib.api.process] INFO: Monitor config for process 5892: C:\6lreqs2g\dll\5892.ini
2026-05-28 20:48:47,989 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:47,996 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:48,001 [root] DEBUG: Loader: Injecting process 5892 (thread 16484) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:48,004 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:48,006 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:48,008 [lib.api.process] INFO: Injected into 64-bit <Process 5892 dllhost.exe>
2026-05-28 20:48:48,010 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5892
2026-05-28 20:48:48,012 [lib.api.process] INFO: Monitor config for process 5892: C:\6lreqs2g\dll\5892.ini
2026-05-28 20:48:48,015 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:48,025 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:48,030 [root] DEBUG: Loader: Injecting process 5892 (thread 16484) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:48,031 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:48,033 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:48,035 [lib.api.process] INFO: Injected into 64-bit <Process 5892 dllhost.exe>
2026-05-28 20:48:48,041 [root] DEBUG: 5892: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:48:48,042 [root] DEBUG: 5892: Interactive desktop enabled.
2026-05-28 20:48:48,043 [root] DEBUG: 5892: Dropped file limit defaulting to 100.
2026-05-28 20:48:48,048 [root] DEBUG: 5892: Disabling sleep skipping.
2026-05-28 20:48:48,049 [root] DEBUG: 5892: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:48:48,063 [root] DEBUG: 5892: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:48:48,064 [root] DEBUG: 5892: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:48:48,066 [root] DEBUG: 5892: Monitor initialised: 64-bit capemon loaded in process 5892 at 0x00007FFEAF1A0000, thread 16484, image base 0x00007FF6868D0000, stack from 0x000000086B6F4000-0x000000086B700000
2026-05-28 20:48:48,068 [root] DEBUG: 5892: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:48:48,078 [root] DEBUG: 5892: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:48:48,100 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:48:48,101 [root] DEBUG: 5892: set_hooks: Unable to hook LockResource
2026-05-28 20:48:48,106 [root] DEBUG: 5892: Hooked 627 out of 628 functions
2026-05-28 20:48:48,108 [root] DEBUG: 5892: Syscall hook installed, syscall logging level 1
2026-05-28 20:48:48,112 [root] DEBUG: 5892: RestoreHeaders: Restored original import table.
2026-05-28 20:48:48,113 [root] INFO: Loaded monitor into process with pid 5892
2026-05-28 20:48:48,116 [root] DEBUG: 5892: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 16484).
2026-05-28 20:48:48,117 [root] DEBUG: 5892: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:48:48,119 [root] DEBUG: 5892: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:48:48,123 [root] DEBUG: 5892: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:48:48,125 [root] DEBUG: 5892: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:48:48,128 [root] DEBUG: 5892: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:48:48,142 [root] DEBUG: 5892: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:48:48,156 [root] DEBUG: 5892: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:48:48,158 [root] DEBUG: 5892: DLL loaded at 0x00007FFEE27A0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:48:48,164 [root] DEBUG: 5892: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:48:48,943 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:48,950 [root] DEBUG: Loader: Injecting process 17328 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:48,952 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17324, handle 0x120
2026-05-28 20:48:48,953 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:48:48,954 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:48,956 [lib.api.process] INFO: Injected into 64-bit <Process 17328 StartMenuExperienceHost.exe>
2026-05-28 20:48:49,200 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 17372: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:48:49,202 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17372
2026-05-28 20:48:49,204 [lib.api.process] INFO: Monitor config for process 17372: C:\6lreqs2g\dll\17372.ini
2026-05-28 20:48:49,209 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:51,733 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:51,741 [root] DEBUG: Loader: Injecting process 17372 (thread 17376) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:51,743 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:48:51,745 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:51,747 [lib.api.process] INFO: Injected into 64-bit <Process 17372 SearchApp.exe>
2026-05-28 20:48:51,752 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17372
2026-05-28 20:48:51,754 [lib.api.process] INFO: Monitor config for process 17372: C:\6lreqs2g\dll\17372.ini
2026-05-28 20:48:51,754 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:53,183 [root] INFO: Process with pid 5892 has terminated
2026-05-28 20:48:53,186 [root] DEBUG: 5892: NtTerminateProcess hook: Attempting to dump process 5892
2026-05-28 20:48:53,189 [root] DEBUG: 5892: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:48:54,340 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:54,344 [root] DEBUG: Loader: Injecting process 17372 (thread 17376) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:54,346 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:48:54,348 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:54,349 [lib.api.process] INFO: Injected into 64-bit <Process 17372 SearchApp.exe>
2026-05-28 20:48:54,353 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 17372
2026-05-28 20:48:54,355 [lib.api.process] INFO: Monitor config for process 17372: C:\6lreqs2g\dll\17372.ini
2026-05-28 20:48:54,356 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:48:55,422 [root] DEBUG: 16296: NtTerminateProcess hook: Attempting to dump process 16296
2026-05-28 20:48:55,423 [root] DEBUG: 16296: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:48:55,433 [root] INFO: Process with pid 16296 has terminated
2026-05-28 20:48:57,292 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:48:57,297 [root] DEBUG: Loader: Injecting process 17372 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:57,301 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17376, handle 0x120
2026-05-28 20:48:57,305 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:48:57,307 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:48:57,309 [lib.api.process] INFO: Injected into 64-bit <Process 17372 SearchApp.exe>
2026-05-28 20:48:57,315 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 4308: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:48:57,319 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 4308
2026-05-28 20:48:57,322 [lib.api.process] INFO: Monitor config for process 4308: C:\6lreqs2g\dll\4308.ini
2026-05-28 20:48:57,328 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:49:00,340 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:49:00,344 [root] DEBUG: Loader: Injecting process 4308 (thread 16224) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:00,347 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:49:00,348 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:00,351 [lib.api.process] INFO: Injected into 64-bit <Process 4308 SearchApp.exe>
2026-05-28 20:49:00,353 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 4308
2026-05-28 20:49:00,356 [lib.api.process] INFO: Monitor config for process 4308: C:\6lreqs2g\dll\4308.ini
2026-05-28 20:49:00,358 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:49:03,410 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:49:03,416 [root] DEBUG: Loader: Injecting process 4308 (thread 16224) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:03,417 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:49:03,418 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:03,420 [lib.api.process] INFO: Injected into 64-bit <Process 4308 SearchApp.exe>
2026-05-28 20:49:03,424 [root] INFO: Process with pid 4308 has terminated
2026-05-28 20:49:03,695 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 17116: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe, ImageBase: 0x00007FF6174D0000
2026-05-28 20:49:03,699 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17116
2026-05-28 20:49:03,701 [lib.api.process] INFO: Monitor config for process 17116: C:\6lreqs2g\dll\17116.ini
2026-05-28 20:49:03,704 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:49:06,753 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:49:06,760 [root] DEBUG: Loader: Injecting process 17116 (thread 1060) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:06,762 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:49:06,763 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:06,765 [lib.api.process] INFO: Injected into 64-bit <Process 17116 StartMenuExperienceHost.exe>
2026-05-28 20:49:06,767 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17116
2026-05-28 20:49:06,769 [lib.api.process] INFO: Monitor config for process 17116: C:\6lreqs2g\dll\17116.ini
2026-05-28 20:49:06,769 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:49:08,987 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:49:08,992 [root] DEBUG: Loader: Injecting process 17116 (thread 1060) with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:08,994 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:49:08,995 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:08,998 [lib.api.process] INFO: Injected into 64-bit <Process 17116 StartMenuExperienceHost.exe>
2026-05-28 20:49:09,001 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 17116
2026-05-28 20:49:09,003 [lib.api.process] INFO: Monitor config for process 17116: C:\6lreqs2g\dll\17116.ini
2026-05-28 20:49:09,004 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:49:11,821 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\TXUMxByw.dll, loader C:\6lreqs2g\bin\IPlyRjrp.exe
2026-05-28 20:49:11,826 [root] DEBUG: Loader: Injecting process 17116 with C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:11,830 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 1060, handle 0xb4
2026-05-28 20:49:11,833 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:49:11,834 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\TXUMxByw.dll.
2026-05-28 20:49:11,836 [lib.api.process] INFO: Injected into 64-bit <Process 17116 StartMenuExperienceHost.exe>
2026-05-28 20:49:12,045 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 5084: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF741AF0000
2026-05-28 20:49:12,047 [root] INFO: Announced 64-bit process name: SearchApp.exe pid: 5084
2026-05-28 20:49:12,049 [lib.api.process] INFO: Monitor config for process 5084: C:\6lreqs2g\dll\5084.ini
2026-05-28 20:49:12,052 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 20:43:30 | 2026-05-28 20:50:01 | none |
| Process: wermgr.exe (2668) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: wermgr.exe (2668) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: wermgr.exe (2668) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: wermgr.exe (2668) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: SystemSettings.exe (8992) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| N | 162.159.135.233 [VT] | unknown | - |
| N | 23.211.116.176 [VT] | unknown | - |
| Y | 140.82.114.21 [VT] | unknown | - |
| Y | 13.107.213.31 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 20.190.122.23 [VT] | unknown | - |
| Y | 150.171.109.17 [VT] | unknown | - |
| Y | 162.159.128.235 [VT] | unknown | - |
| Y | 23.209.40.114 [VT] | unknown | - |
| Y | 162.159.128.233 [VT] | unknown | - |
| N | 162.159.133.234 [VT] | unknown | - |
| N | 104.18.21.213 [VT] | unknown | - |
| N | 162.254.194.56 [VT] | unknown | - |
| N | 162.159.130.234 [VT] | unknown | - |
| Y | 140.82.113.21 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 23.202.165.41 [VT] | unknown | - |
| Y | 162.159.61.3 [VT] | unknown | - |
| N | 162.159.130.233 [VT] | unknown | - |
| N | 185.199.111.133 [VT] | unknown | - |
| N | 185.199.109.215 [VT] | unknown | - |
| N | 162.159.134.233 [VT] | unknown | - |
| Y | 4.237.22.34 [VT] | unknown | - |
| N | 4.237.22.38 [VT] | unknown | - |
| Y | 172.172.255.217 [VT] | unknown | - |
| Y | 20.190.167.20 [VT] | unknown | - |
| Y | 162.254.194.57 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.155
[VT]
A 149.135.84.160 [VT] |
23.56.110.24 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| github.com [VT] | A 4.237.22.38 [VT] | 4.237.22.38 [VT] |
| github.githubassets.com [VT] |
A 185.199.108.215
[VT]
A 185.199.109.215 [VT] A 185.199.110.215 [VT] A 185.199.111.215 [VT] |
185.199.108.215 [VT] |
| avatars.githubusercontent.com [VT] |
A 185.199.111.133
[VT]
A 185.199.109.133 [VT] A 185.199.110.133 [VT] A 185.199.108.133 [VT] |
185.199.111.133 [VT] |
| user-images.githubusercontent.com [VT] | 185.199.109.133 [VT] | |
| github-cloud.s3.amazonaws.com [VT] |
A 16.15.214.248
[VT]
A 52.217.140.201 [VT] A 16.182.98.161 [VT] A 16.182.65.161 [VT] A 16.15.246.233 [VT] A 54.231.161.89 [VT] A 52.217.137.153 [VT] A 52.217.200.185 [VT] CNAME s3-1-w.amazonaws.com [VT] CNAME s3-w.us-east-1.amazonaws.com [VT] |
52.216.214.57 [VT] |
| camo.githubusercontent.com [VT] | 185.199.111.133 [VT] | |
| raw.githubusercontent.com [VT] | 185.199.110.133 [VT] | |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.4.4 [VT] |
| cmp1-dfw2.steamserver.net [VT] | A 162.254.194.56 [VT] | 162.254.194.56 [VT] |
| e7.c.lencr.org [VT] |
A 104.18.20.213
[VT]
A 104.18.21.213 [VT] |
104.18.20.213 [VT] |
| gateway-us-east1-d.discord.gg [VT] |
A 162.159.130.234
[VT]
A 162.159.134.234 [VT] A 162.159.135.234 [VT] A 162.159.133.234 [VT] A 162.159.136.234 [VT] |
162.159.133.234 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| client-update.akamai.steamstatic.com [VT] |
A 23.211.116.162
[VT]
CNAME client-update.akamai.steamstatic.com.akamaized.net [VT] CNAME a78.dscw27.akamai.net [VT] A 23.211.116.176 [VT] |
23.62.157.77 [VT] |
| discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.133.233 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.