| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 20:53:53 | 2026-05-28 21:01:57 | 484s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 20:53:02,778 [root] INFO: Date set to: 20260528T20:54:00, timeout set to: 1200
2026-05-28 20:54:00,008 [root] DEBUG: Starting analyzer from: C:\rl4cuydm
2026-05-28 20:54:00,009 [root] DEBUG: Storing results at: C:\ZRbPmMNO
2026-05-28 20:54:00,009 [root] DEBUG: Pipe server name: \\.\PIPE\HKwARusd
2026-05-28 20:54:00,009 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 20:54:00,009 [root] INFO: analysis running as an admin
2026-05-28 20:54:00,010 [root] INFO: analysis package specified: "edge"
2026-05-28 20:54:00,010 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 20:54:00,026 [root] DEBUG: imported analysis package "edge"
2026-05-28 20:54:00,026 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 20:54:00,026 [root] DEBUG: New location of moved file: https://github.com/ytisf/theZoo
2026-05-28 20:54:00,026 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 20:54:00,027 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 20:54:00,027 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 20:54:00,027 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 20:54:00,057 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 20:54:00,076 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 20:54:00,095 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 20:54:00,101 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 20:54:00,104 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 20:54:00,104 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 20:54:00,105 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 20:54:00,106 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 20:54:00,106 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 20:54:00,106 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 20:54:00,107 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 20:54:00,107 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 20:54:00,108 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 20:54:00,108 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 20:54:00,108 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 20:54:00,108 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 20:54:00,108 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 20:54:00,109 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 20:54:00,109 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 20:54:00,109 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 20:54:00,109 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 20:54:00,109 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 20:54:00,109 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 20:54:00,117 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 8860)
2026-05-28 20:54:00,117 [modules.auxiliary.disguise] INFO: Disguising GUID to f35de8ad-ec43-4b61-9d50-b6b8c2938924
2026-05-28 20:54:00,118 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 20:54:00,118 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 20:54:00,118 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 20:54:00,118 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 20:54:00,118 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 20:54:00,119 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 20:54:00,119 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 20:54:00,119 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 20:54:00,119 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 20:54:00,120 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 20:54:00,120 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 20:54:00,120 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 20:54:00,120 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 20:54:00,120 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 20:54:00,121 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 20:54:00,121 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 20:54:00,123 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 20:54:00,124 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 20:54:00,124 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 20:54:00,151 [lib.api.process] INFO: Monitor config for process 4484: C:\rl4cuydm\dll\4484.ini
2026-05-28 20:54:00,152 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:00,154 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:00,197 [root] DEBUG: Loader: Injecting process 4484 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:00,371 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:00,372 [root] DEBUG: 4484: Disabling sleep skipping.
2026-05-28 20:54:00,373 [root] DEBUG: 4484: Interactive desktop enabled.
2026-05-28 20:54:00,373 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-28 20:54:00,374 [root] DEBUG: 4484: Interactive desktop - injecting Explorer Shell
2026-05-28 20:54:00,380 [root] DEBUG: 4484: YaraInit: Compiled 44 rule files
2026-05-28 20:54:00,381 [root] DEBUG: 4484: YaraInit: Compiled rules saved to file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:00,399 [root] DEBUG: 4484: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:00,399 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-28 20:54:00,443 [root] DEBUG: 4484: Monitor initialised: 64-bit capemon loaded in process 4484 at 0x00007FFF1A580000, thread 8952, image base 0x00007FF79BC10000, stack from 0x00000000103F1000-0x0000000010400000
2026-05-28 20:54:00,444 [root] DEBUG: 4484: Commandline: C:\Windows\Explorer.EXE
2026-05-28 20:54:00,455 [root] DEBUG: 4484: Hooked 69 out of 69 functions
2026-05-28 20:54:00,484 [root] DEBUG: 4484: Syscall hook installed, syscall logging level 1
2026-05-28 20:54:00,491 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:54:00,492 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:00,493 [lib.api.process] INFO: Injected into 64-bit <Process 4484 explorer.exe>
2026-05-28 20:54:02,382 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00007FF79BC10000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF79BC7C21A, thread 4696).
2026-05-28 20:54:02,383 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-28 20:54:02,417 [root] DEBUG: 4484: ProcessImageBase: Main module image at 0x00007FF79BC10000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:54:02,421 [lib.api.process] INFO: Monitor config for process 832: C:\rl4cuydm\dll\832.ini
2026-05-28 20:54:02,422 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:02,423 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:02,427 [root] DEBUG: Loader: Injecting process 832 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:02,429 [root] DEBUG: 832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:02,430 [root] DEBUG: 832: Disabling sleep skipping.
2026-05-28 20:54:02,430 [root] DEBUG: 832: Interactive desktop enabled.
2026-05-28 20:54:02,430 [root] DEBUG: 832: Dropped file limit defaulting to 100.
2026-05-28 20:54:02,431 [root] DEBUG: 832: Services hook set enabled
2026-05-28 20:54:02,433 [root] DEBUG: 832: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:02,450 [root] DEBUG: 832: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:02,451 [root] DEBUG: 832: Monitor initialised: 64-bit capemon loaded in process 832 at 0x00007FFF1A580000, thread 8308, image base 0x00007FF7BF220000, stack from 0x000000CCA78F4000-0x000000CCA7900000
2026-05-28 20:54:02,451 [root] DEBUG: 832: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 20:54:02,468 [root] DEBUG: 832: Hooked 69 out of 69 functions
2026-05-28 20:54:02,469 [root] INFO: Loaded monitor into process with pid 832
2026-05-28 20:54:02,470 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:54:02,470 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:02,472 [lib.api.process] INFO: Injected into 64-bit <Process 832 svchost.exe>
2026-05-28 20:54:03,461 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8416: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 20:54:03,462 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8416
2026-05-28 20:54:03,462 [lib.api.process] INFO: Monitor config for process 8416: C:\rl4cuydm\dll\8416.ini
2026-05-28 20:54:03,463 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:03,464 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:03,469 [root] DEBUG: Loader: Injecting process 8416 (thread 8044) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:03,470 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:03,471 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:03,472 [lib.api.process] INFO: Injected into 64-bit <Process 8416 dllhost.exe>
2026-05-28 20:54:03,473 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8416
2026-05-28 20:54:03,474 [lib.api.process] INFO: Monitor config for process 8416: C:\rl4cuydm\dll\8416.ini
2026-05-28 20:54:03,474 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:03,475 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:03,480 [root] DEBUG: Loader: Injecting process 8416 (thread 8044) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:03,481 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:03,481 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:03,482 [lib.api.process] INFO: Injected into 64-bit <Process 8416 dllhost.exe>
2026-05-28 20:54:03,495 [root] DEBUG: 8416: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:03,495 [root] DEBUG: 8416: Interactive desktop enabled.
2026-05-28 20:54:03,496 [root] DEBUG: 8416: Dropped file limit defaulting to 100.
2026-05-28 20:54:03,498 [root] DEBUG: 8416: Disabling sleep skipping.
2026-05-28 20:54:03,499 [root] DEBUG: 8416: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:03,501 [root] DEBUG: 4484: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 20:54:03,502 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54AE0000: C:\Windows\SYSTEM32\MLANG (0x42000 bytes).
2026-05-28 20:54:03,512 [root] DEBUG: 8416: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:03,512 [root] DEBUG: 8416: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:54:03,513 [root] DEBUG: 8416: Monitor initialised: 64-bit capemon loaded in process 8416 at 0x00007FFF1A580000, thread 8044, image base 0x00007FF6706B0000, stack from 0x0000002E86384000-0x0000002E86390000
2026-05-28 20:54:03,513 [root] DEBUG: 8416: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:54:03,522 [root] DEBUG: 8416: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:54:03,544 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:54:03,545 [root] DEBUG: 8416: set_hooks: Unable to hook LockResource
2026-05-28 20:54:03,549 [root] DEBUG: 8416: Hooked 627 out of 628 functions
2026-05-28 20:54:03,551 [root] DEBUG: 8416: Syscall hook installed, syscall logging level 1
2026-05-28 20:54:03,556 [root] DEBUG: 8416: RestoreHeaders: Restored original import table.
2026-05-28 20:54:03,556 [root] INFO: Loaded monitor into process with pid 8416
2026-05-28 20:54:03,557 [root] DEBUG: 8416: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 8044).
2026-05-28 20:54:03,558 [root] DEBUG: 8416: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:54:03,560 [root] DEBUG: 8416: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:54:03,563 [root] DEBUG: 8416: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:54:03,564 [root] DEBUG: 8416: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:54:03,566 [root] DEBUG: 8416: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:54:03,581 [root] DEBUG: 8416: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:54:03,600 [root] DEBUG: 8416: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:54:03,601 [root] DEBUG: 8416: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:54:03,615 [root] DEBUG: 8416: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:54:05,261 [root] DEBUG: 4484: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:54:05,366 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 20:54:06,997 [root] DEBUG: 4484: DLL loaded at 0x00007FFF49E50000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-28 20:54:06,999 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4E360000: C:\Windows\system32\WindowsInternal.ComposableShell.DesktopHosting (0x2e000 bytes).
2026-05-28 20:54:07,006 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F230000: C:\Windows\ShellComponents\WindowsInternal.ComposableShell.Experiences.Switcher (0x24d000 bytes).
2026-05-28 20:54:07,010 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D330000: C:\Windows\ShellExperiences\TileControl (0x7d000 bytes).
2026-05-28 20:54:07,013 [root] DEBUG: 4484: DLL loaded at 0x00007FFF19CD0000: C:\Windows\ShellComponents\TaskFlowUI (0x215000 bytes).
2026-05-28 20:54:07,040 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46660000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-28 20:54:07,196 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE181000, size: 0x1000.
2026-05-28 20:54:08,093 [root] INFO: Restarting WMI Service
2026-05-28 20:54:08,719 [root] INFO: Process with pid 8416 has terminated
2026-05-28 20:54:08,722 [root] DEBUG: 8416: NtTerminateProcess hook: Attempting to dump process 8416
2026-05-28 20:54:08,723 [root] DEBUG: 8416: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:54:09,617 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FCB0000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 20:54:09,667 [lib.api.process] INFO: Monitor config for process 4484: C:\rl4cuydm\dll\4484.ini
2026-05-28 20:54:09,667 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:09,669 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:09,675 [root] DEBUG: Loader: Injecting process 4484 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:09,676 [root] DEBUG: 4484: caller_dispatch: Added region at 0x000000000B2C0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x000000000B2C0043, thread 7380).
2026-05-28 20:54:09,676 [root] DEBUG: 4484: DumpPEsInRange: Scanning range 0x000000000B2C0000 - 0x000000000B2C0134.
2026-05-28 20:54:09,676 [root] DEBUG: 4484: ScanForDisguisedPE: Size too small: 0x134 bytes
2026-05-28 20:54:09,683 [lib.common.results] INFO: Uploading file C:\ZRbPmMNO\CAPE\4484_27757954029552026 to CAPE\29f1024a8c27e135f9616a33c54b961361af4249a73fad60462f809a3ee67529; Size is 308; Max size: 100000000
2026-05-28 20:54:09,687 [root] DEBUG: 4484: DumpMemory: Payload successfully created: C:\ZRbPmMNO\CAPE\4484_27757954029552026 (size 308 bytes)
2026-05-28 20:54:09,687 [root] DEBUG: 4484: DumpRegion: Dumped entire allocation from 0x000000000B2C0000, size 4096 bytes.
2026-05-28 20:54:09,688 [root] DEBUG: 4484: ProcessTrackedRegion: Dumped region at 0x000000000B2C0000.
2026-05-28 20:54:09,689 [root] DEBUG: 4484: YaraScan: Scanning 0x000000000B2C0000, size 0x134
2026-05-28 20:54:09,690 [root] DEBUG: 4484: Monitor config - unrecognised key host-ip.
2026-05-28 20:54:09,690 [root] DEBUG: 4484: Monitor config - unrecognised key host-port.
2026-05-28 20:54:09,691 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:09,692 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-28 20:54:09,712 [root] DEBUG: 4484: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:54:09,755 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:54:09,755 [root] DEBUG: 4484: set_hooks: Unable to hook LockResource
2026-05-28 20:54:09,782 [root] DEBUG: 4484: Hooked 627 out of 628 functions
2026-05-28 20:54:09,811 [root] INFO: Loaded monitor into process with pid 4484
2026-05-28 20:54:09,815 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 20:54:09,815 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:10,132 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 20:54:10,133 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 20:54:10,133 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 20:54:10,134 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://github.com/ytisf/theZoo"" with pid 8060
2026-05-28 20:54:10,135 [lib.api.process] INFO: Monitor config for process 8060: C:\rl4cuydm\dll\8060.ini
2026-05-28 20:54:10,136 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:10,137 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:10,142 [root] DEBUG: Loader: Injecting process 8060 (thread 5396) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:10,142 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:10,143 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:10,145 [lib.api.process] INFO: Injected into 64-bit <Process 8060 msedge.exe>
2026-05-28 20:54:11,858 [root] DEBUG: 4484: DLL loaded at 0x00007FFF42C60000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 20:54:11,859 [root] DEBUG: 4484: DLL loaded at 0x00007FFF42C60000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 20:54:11,863 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46440000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 20:54:11,863 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46440000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 20:54:11,933 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 20:54:11,934 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 20:54:11,946 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C4B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 20:54:11,947 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C4B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 20:54:11,965 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FC40000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 20:54:11,967 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FC40000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 20:54:12,062 [root] DEBUG: 4484: DLL loaded at 0x0000000014A20000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 20:54:12,064 [root] DEBUG: 4484: DLL loaded at 0x0000000014A20000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 20:54:12,085 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46FB0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 20:54:12,086 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46FB0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 20:54:12,152 [lib.api.process] INFO: Successfully resumed process with pid 8060
2026-05-28 20:54:12,205 [root] DEBUG: 8060: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:12,206 [root] DEBUG: 8060: Interactive desktop enabled.
2026-05-28 20:54:12,206 [root] DEBUG: 8060: Dropped file limit defaulting to 100.
2026-05-28 20:54:12,218 [root] DEBUG: 8060: Edge-specific hook-set enabled.
2026-05-28 20:54:12,219 [root] DEBUG: 8060: Disabling sleep skipping.
2026-05-28 20:54:12,221 [root] DEBUG: 8060: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:12,225 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Discord\app.ico
2026-05-28 20:54:12,232 [root] DEBUG: 8060: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:12,233 [root] DEBUG: 8060: Monitor initialised: 64-bit capemon loaded in process 8060 at 0x00007FFF1A580000, thread 5396, image base 0x00007FF7F5380000, stack from 0x0000003E227F4000-0x0000003E22800000
2026-05-28 20:54:12,233 [root] DEBUG: 8060: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://github.com/ytisf/theZoo"
2026-05-28 20:54:12,242 [root] DEBUG: 8060: Hooked 2 out of 2 functions
2026-05-28 20:54:12,277 [root] DEBUG: 8060: Syscall hook installed, syscall logging level 1
2026-05-28 20:54:12,281 [root] DEBUG: 8060: RestoreHeaders: Restored original import table.
2026-05-28 20:54:12,281 [root] INFO: Loaded monitor into process with pid 8060
2026-05-28 20:54:12,283 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:54:12,286 [root] DEBUG: 8060: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 20:54:12,287 [root] DEBUG: 8060: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:54:12,290 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:54:12,291 [root] DEBUG: 8060: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:54:12,292 [root] DEBUG: 8060: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:54:12,294 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:54:12,612 [root] DEBUG: 8060: DLL loaded at 0x00007FFF453C0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 20:54:12,613 [root] DEBUG: 8060: DLL loaded at 0x000001BE80000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:54:12,619 [root] DEBUG: 8060: DLL loaded at 0x00007FFF45010000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 20:54:12,622 [root] DEBUG: 8060: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:54:12,629 [root] DEBUG: 8060: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:54:12,632 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 1788: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:12,632 [root] DEBUG: 8060: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:54:12,633 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 1788
2026-05-28 20:54:12,633 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4E340000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 20:54:12,634 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 1788
2026-05-28 20:54:12,635 [root] DEBUG: 8060: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:54:12,635 [root] DEBUG: 8060: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:54:12,642 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:54:12,643 [root] DEBUG: 8060: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:54:12,643 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 1788, handle 0x261c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 20:54:12,644 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 20:54:12,645 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 20:54:12,646 [root] DEBUG: 8060: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:54:12,647 [root] DEBUG: 8060: DLL loaded at 0x00007FFF42BF0000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 20:54:12,650 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:54:12,651 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:54:12,652 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 20:54:12,653 [root] DEBUG: 8060: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:54:12,653 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 20:54:12,654 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3FBC0000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 20:54:12,654 [root] DEBUG: 8060: DLL loaded at 0x00007FFF46400000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 20:54:12,655 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:54:12,656 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:54:12,658 [root] DEBUG: 8060: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 20:54:12,658 [root] DEBUG: 8060: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:54:12,659 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:54:12,659 [root] DEBUG: 8060: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 20:54:12,661 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 20:54:12,674 [root] DEBUG: 8060: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:54:12,676 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 8060, handle 0x261c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 20:54:12,677 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4D260000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 20:54:12,679 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:54:12,680 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:54:12,681 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 20:54:12,683 [root] DEBUG: 8060: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 20:54:12,686 [root] DEBUG: 8060: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 20:54:12,688 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 20:54:12,689 [root] DEBUG: 8060: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:54:12,690 [root] DEBUG: 8060: DLL loaded at 0x00007FFF569F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:54:12,690 [root] DEBUG: 8060: DLL loaded at 0x00007FFF52960000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 20:54:12,692 [root] DEBUG: 8060: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:54:12,693 [root] DEBUG: 8060: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 20:54:12,695 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:54:12,696 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 20:54:12,697 [root] DEBUG: 8060: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:54:12,698 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 20:54:12,699 [root] DEBUG: 8060: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 20:54:12,702 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:54:12,705 [root] DEBUG: 8060: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:54:12,705 [root] DEBUG: 8060: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:54:12,706 [root] DEBUG: 8060: DLL loaded at 0x00007FFF54170000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 20:54:12,706 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4B680000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 20:54:12,708 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 20:54:12,713 [root] DEBUG: 8060: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:54:12,715 [root] DEBUG: 8060: DLL loaded at 0x00007FFF45580000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 20:54:12,717 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 20:54:12,720 [root] DEBUG: 8060: DLL loaded at 0x00007FFF52420000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 20:54:12,724 [root] DEBUG: 8060: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 20:54:12,726 [root] DEBUG: 8060: DLL loaded at 0x00007FFF51A60000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 20:54:12,727 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4AF10000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 20:54:12,728 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4BFB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 20:54:12,736 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:54:12,737 [root] DEBUG: 8060: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:54:12,738 [root] DEBUG: 8060: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 20:54:12,743 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 20:54:12,754 [root] DEBUG: 8060: DLL loaded at 0x00007FFF515E0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 20:54:12,756 [root] DEBUG: 8060: DLL loaded at 0x00007FFF51600000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 20:54:12,757 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 20:54:12,757 [lib.api.process] INFO: Monitor config for process 676: C:\rl4cuydm\dll\676.ini
2026-05-28 20:54:12,758 [root] DEBUG: 8060: DLL loaded at 0x00007FFF52560000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 20:54:12,761 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 8376: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:12,762 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:12,762 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 8376
2026-05-28 20:54:12,764 [root] DEBUG: 8060: caller_dispatch: Added region at 0x00007FF7F5380000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7F5477D66, thread 2996).
2026-05-28 20:54:12,764 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 8376
2026-05-28 20:54:12,764 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:12,766 [root] DEBUG: 8060: DLL loaded at 0x00007FFF024B0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 20:54:12,769 [root] DEBUG: 8060: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:54:12,773 [root] DEBUG: 8060: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 20:54:12,775 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 6544: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:12,779 [root] DEBUG: 8060: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 20:54:12,780 [root] DEBUG: Loader: Injecting process 676 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:12,781 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 6544
2026-05-28 20:54:12,783 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\676.ini to system path C:\676.ini
2026-05-28 20:54:12,784 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 6544
2026-05-28 20:54:12,807 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 8508: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:12,815 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3D570000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 20:54:12,818 [root] DEBUG: 8060: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 20:54:12,828 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 8508
2026-05-28 20:54:12,829 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3D570000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 20:54:12,843 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 676 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:54:12,844 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 8508
2026-05-28 20:54:12,861 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:12,867 [lib.api.process] INFO: Injected into 64-bit <Process 676 services.exe>
2026-05-28 20:54:12,896 [root] DEBUG: 8060: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 20:54:12,899 [root] DEBUG: 8060: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 20:54:12,903 [root] DEBUG: 8060: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 20:54:12,906 [root] DEBUG: 8060: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 20:54:12,947 [root] DEBUG: 8060: DLL loaded at 0x00007FFF46410000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 20:54:12,979 [root] DEBUG: 8060: DLL loaded at 0x00007FFF43990000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 20:54:12,980 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 9408: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:12,981 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 9416: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:12,983 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 9408
2026-05-28 20:54:12,984 [root] DEBUG: 8060: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 20:54:12,985 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 9416
2026-05-28 20:54:12,986 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 9408
2026-05-28 20:54:12,986 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 9416
2026-05-28 20:54:13,077 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 8060 (handle 0x2734): 0x00007FF7F5380000.
2026-05-28 20:54:13,078 [root] DEBUG: 8060: DLL loaded at 0x00007FFF55220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 20:54:13,079 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:54:13,081 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5624, handle 0x273c: Error obtaining target process name
2026-05-28 20:54:13,125 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:54:13,153 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3F8B0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 20:54:13,172 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6400, handle 0x2734: Error obtaining target process name
2026-05-28 20:54:13,173 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4D010000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1e000 bytes).
2026-05-28 20:54:13,174 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:54:13,177 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4CFA0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Domain Actions\3.0.0.18\domain_actions (0x17000 bytes).
2026-05-28 20:54:13,192 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:54:13,193 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5128, handle 0x2740: Error obtaining target process name
2026-05-28 20:54:13,201 [root] DEBUG: 8060: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 20:54:13,205 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:54:13,208 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:54:13,210 [root] DEBUG: 8060: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:54:13,220 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 20:54:13,246 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3E220000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 20:54:13,291 [root] DEBUG: 4484: api-rate-cap: IsDebuggerPresent hook disabled due to rate
2026-05-28 20:54:13,347 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 20:54:13,387 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 20:54:13,389 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 20:54:13,457 [root] DEBUG: 4484: DLL loaded at 0x00007FFF453C0000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 20:54:13,459 [root] DEBUG: 4484: DLL loaded at 0x00007FFF453C0000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 20:54:13,536 [root] DEBUG: 4484: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 20:54:13,537 [root] DEBUG: 4484: api-cap: NtClose hook disabled due to count: 5001
2026-05-28 20:54:13,571 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 3780: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 20:54:13,573 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3780
2026-05-28 20:54:13,574 [lib.api.process] INFO: Monitor config for process 3780: C:\rl4cuydm\dll\3780.ini
2026-05-28 20:54:13,575 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:13,576 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:13,582 [root] DEBUG: Loader: Injecting process 3780 (thread 8488) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:13,583 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:13,584 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:13,588 [lib.api.process] INFO: Injected into 64-bit <Process 3780 dllhost.exe>
2026-05-28 20:54:13,590 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3780
2026-05-28 20:54:13,591 [lib.api.process] INFO: Monitor config for process 3780: C:\rl4cuydm\dll\3780.ini
2026-05-28 20:54:13,592 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:13,593 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:13,601 [root] DEBUG: Loader: Injecting process 3780 (thread 8488) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:13,603 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:13,604 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:13,605 [lib.api.process] INFO: Injected into 64-bit <Process 3780 dllhost.exe>
2026-05-28 20:54:13,612 [root] DEBUG: 3780: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:13,614 [root] DEBUG: 3780: Interactive desktop enabled.
2026-05-28 20:54:13,615 [root] DEBUG: 3780: Dropped file limit defaulting to 100.
2026-05-28 20:54:13,619 [root] DEBUG: 3780: Disabling sleep skipping.
2026-05-28 20:54:13,621 [root] DEBUG: 3780: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:13,635 [root] DEBUG: 3780: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:13,636 [root] DEBUG: 3780: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:54:13,638 [root] DEBUG: 3780: Monitor initialised: 64-bit capemon loaded in process 3780 at 0x00007FFF1A580000, thread 8488, image base 0x00007FF6706B0000, stack from 0x0000005044724000-0x0000005044730000
2026-05-28 20:54:13,638 [root] DEBUG: 3780: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:54:13,648 [root] DEBUG: 3780: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:54:13,672 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:54:13,673 [root] DEBUG: 3780: set_hooks: Unable to hook LockResource
2026-05-28 20:54:13,680 [root] DEBUG: 3780: Hooked 627 out of 628 functions
2026-05-28 20:54:13,682 [root] DEBUG: 3780: Syscall hook installed, syscall logging level 1
2026-05-28 20:54:13,686 [root] DEBUG: 3780: RestoreHeaders: Restored original import table.
2026-05-28 20:54:13,687 [root] INFO: Loaded monitor into process with pid 3780
2026-05-28 20:54:13,688 [root] DEBUG: 3780: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 8488).
2026-05-28 20:54:13,688 [root] DEBUG: 3780: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:54:13,690 [root] DEBUG: 3780: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:54:13,694 [root] DEBUG: 3780: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:54:13,696 [root] DEBUG: 3780: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:54:13,699 [root] DEBUG: 3780: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:54:13,714 [root] DEBUG: 3780: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:54:13,729 [root] DEBUG: 3780: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:54:13,730 [root] DEBUG: 3780: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:54:13,736 [root] DEBUG: 3780: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:54:13,877 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 10652, handle 0x2a60: C:\Windows\System32\services.exe
2026-05-28 20:54:14,432 [root] DEBUG: 676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:14,439 [root] DEBUG: 676: Disabling sleep skipping.
2026-05-28 20:54:14,440 [root] DEBUG: 676: Interactive desktop enabled.
2026-05-28 20:54:14,440 [root] DEBUG: 676: Dropped file limit defaulting to 100.
2026-05-28 20:54:14,443 [root] DEBUG: 676: Services hook set enabled
2026-05-28 20:54:14,460 [root] DEBUG: 676: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:14,462 [root] DEBUG: 676: Monitor initialised: 64-bit capemon loaded in process 676 at 0x00007FFF01570000, thread 10700, image base 0x00007FF7839A0000, stack from 0x000000F2F01F2000-0x000000F2F0200000
2026-05-28 20:54:14,462 [root] DEBUG: 676: Commandline: C:\Windows\system32\services.exe
2026-05-28 20:54:14,476 [root] DEBUG: 676: Hooked 69 out of 69 functions
2026-05-28 20:54:14,481 [root] INFO: Loaded monitor into process with pid 676
2026-05-28 20:54:14,824 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:54:14,826 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6136, handle 0x2a6c: Error obtaining target process name
2026-05-28 20:54:14,880 [root] DEBUG: 8060: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:54:14,883 [root] DEBUG: 8060: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:54:15,879 [root] DEBUG: 676: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 20:54:15,880 [root] DEBUG: 676: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:54:15,882 [root] DEBUG: 676: DLL loaded at 0x00007FFF58070000: C:\Windows\system32\SHCORE (0xad000 bytes).
2026-05-28 20:54:15,882 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 11284: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe, ImageBase: 0x00007FF691DA0000
2026-05-28 20:54:15,884 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 11284
2026-05-28 20:54:15,884 [lib.api.process] INFO: Monitor config for process 11284: C:\rl4cuydm\dll\11284.ini
2026-05-28 20:54:15,885 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:16,538 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 20:54:16,540 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 20:54:16,562 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435B0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:54:16,563 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435B0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:54:16,570 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 20:54:16,570 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:54:16,570 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:54:16,571 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 20:54:16,571 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 20:54:16,572 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 20:54:16,572 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 20:54:16,572 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 20:54:16,579 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:16,581 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435B0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:54:16,581 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435B0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:54:16,590 [root] DEBUG: Loader: Injecting process 11284 (thread 11288) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,590 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:16,591 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,592 [lib.api.process] INFO: Injected into 64-bit <Process 11284 elevation_service.exe>
2026-05-28 20:54:16,593 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435B0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:54:16,594 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435B0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 20:54:16,597 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 11284
2026-05-28 20:54:16,598 [lib.api.process] INFO: Monitor config for process 11284: C:\rl4cuydm\dll\11284.ini
2026-05-28 20:54:16,598 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:16,692 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 20:54:16,692 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:54:16,693 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:54:16,694 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 20:54:16,694 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 20:54:16,695 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 20:54:16,695 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 20:54:16,695 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 20:54:16,697 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:16,702 [root] DEBUG: Loader: Injecting process 11284 (thread 11288) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,703 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:16,703 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,704 [lib.api.process] INFO: Injected into 64-bit <Process 11284 elevation_service.exe>
2026-05-28 20:54:16,705 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 11284
2026-05-28 20:54:16,705 [lib.api.process] INFO: Monitor config for process 11284: C:\rl4cuydm\dll\11284.ini
2026-05-28 20:54:16,705 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:16,766 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11524: C:\Windows\System32\rundll32.exe, ImageBase: 0x00007FF7F6FC0000
2026-05-28 20:54:16,767 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 11524
2026-05-28 20:54:16,768 [lib.api.process] INFO: Monitor config for process 11524: C:\rl4cuydm\dll\11524.ini
2026-05-28 20:54:16,769 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:16,770 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:16,777 [root] DEBUG: Loader: Injecting process 11524 (thread 11528) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,778 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:16,779 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,780 [lib.api.process] INFO: Injected into 64-bit <Process 11524 rundll32.exe>
2026-05-28 20:54:16,781 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 11524
2026-05-28 20:54:16,782 [lib.api.process] INFO: Monitor config for process 11524: C:\rl4cuydm\dll\11524.ini
2026-05-28 20:54:16,782 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:16,784 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:16,789 [root] DEBUG: Loader: Injecting process 11524 (thread 11528) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,791 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:54:16,792 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,793 [lib.api.process] INFO: Injected into 64-bit <Process 11524 rundll32.exe>
2026-05-28 20:54:16,803 [root] DEBUG: 11524: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:16,803 [root] DEBUG: 11524: Interactive desktop enabled.
2026-05-28 20:54:16,804 [root] DEBUG: 11524: Dropped file limit defaulting to 100.
2026-05-28 20:54:16,807 [root] DEBUG: 11524: Disabling sleep skipping.
2026-05-28 20:54:16,808 [root] DEBUG: 11524: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:16,821 [root] DEBUG: 11524: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:16,822 [root] DEBUG: 11524: YaraScan: Scanning 0x00007FF7F6FC0000, size 0x16100
2026-05-28 20:54:16,823 [root] DEBUG: 11524: Monitor initialised: 64-bit capemon loaded in process 11524 at 0x00007FFF1A580000, thread 11528, image base 0x00007FF7F6FC0000, stack from 0x000000595CF34000-0x000000595CF40000
2026-05-28 20:54:16,824 [root] DEBUG: 11524: Commandline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
2026-05-28 20:54:16,825 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 20:54:16,826 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:54:16,827 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:54:16,827 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 20:54:16,827 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 20:54:16,828 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 20:54:16,828 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 20:54:16,828 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 20:54:16,831 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:16,835 [root] DEBUG: 11524: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:54:16,839 [root] DEBUG: Loader: Injecting process 11284 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,840 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 11288, handle 0x124
2026-05-28 20:54:16,840 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:54:16,841 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:16,842 [lib.api.process] INFO: Injected into 64-bit <Process 11284 elevation_service.exe>
2026-05-28 20:54:16,848 [root] DEBUG: 11284: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:16,849 [root] DEBUG: 11284: Interactive desktop enabled.
2026-05-28 20:54:16,849 [root] DEBUG: 11284: Dropped file limit defaulting to 100.
2026-05-28 20:54:16,860 [root] DEBUG: 11284: Disabling sleep skipping.
2026-05-28 20:54:16,861 [root] DEBUG: 11284: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:16,862 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:54:16,862 [root] DEBUG: 11524: set_hooks: Unable to hook LockResource
2026-05-28 20:54:16,867 [root] DEBUG: 11524: Hooked 627 out of 628 functions
2026-05-28 20:54:16,869 [root] DEBUG: 11524: Syscall hook installed, syscall logging level 1
2026-05-28 20:54:16,874 [root] DEBUG: 11284: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:16,875 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:16,881 [root] DEBUG: 11524: RestoreHeaders: Restored original import table.
2026-05-28 20:54:16,882 [root] INFO: Loaded monitor into process with pid 11524
2026-05-28 20:54:16,885 [root] DEBUG: 11524: caller_dispatch: Added region at 0x00007FF7F6FC0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7F6FC6D01, thread 11528).
2026-05-28 20:54:16,885 [root] DEBUG: 11524: YaraScan: Scanning 0x00007FF7F6FC0000, size 0x16100
2026-05-28 20:54:16,887 [root] DEBUG: 11524: ProcessImageBase: Main module image at 0x00007FF7F6FC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:54:16,891 [root] DEBUG: 11524: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:54:16,894 [root] DEBUG: 11524: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:54:16,896 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 11524, handle 0x2cac: C:\Windows\System32\rundll32.exe
2026-05-28 20:54:16,901 [root] DEBUG: 11284: Monitor initialised: 64-bit capemon loaded in process 11284 at 0x00007FFF1A580000, thread 11288, image base 0x00007FF691DA0000, stack from 0x0000002736134000-0x0000002736140000
2026-05-28 20:54:16,902 [root] DEBUG: 4484: DLL loaded at 0x00007FFF42C20000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 20:54:16,902 [root] DEBUG: 11284: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe"
2026-05-28 20:54:16,903 [root] DEBUG: 4484: DLL loaded at 0x00007FFF42C20000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 20:54:16,914 [root] DEBUG: 11284: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:54:16,919 [root] DEBUG: 11524: NtTerminateProcess hook: Attempting to dump process 11524
2026-05-28 20:54:16,920 [root] DEBUG: 11524: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:54:16,930 [root] INFO: Process with pid 11524 has terminated
2026-05-28 20:54:16,941 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:54:16,941 [root] DEBUG: 11284: set_hooks: Unable to hook LockResource
2026-05-28 20:54:16,948 [root] DEBUG: 11284: Hooked 627 out of 628 functions
2026-05-28 20:54:16,971 [root] DEBUG: 11284: Syscall hook installed, syscall logging level 1
2026-05-28 20:54:16,975 [root] DEBUG: 11284: RestoreHeaders: Restored original import table.
2026-05-28 20:54:16,977 [root] INFO: Loaded monitor into process with pid 11284
2026-05-28 20:54:16,981 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:17,003 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:17,024 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:17,046 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:17,070 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:17,091 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:17,112 [root] DEBUG: 11284: caller_dispatch: Scanning calling region at 0x00007FF691DA0000...
2026-05-28 20:54:17,113 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:17,114 [root] DEBUG: 11284: caller_dispatch: Added region at 0x00007FF691DA0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF691EDB9D6, thread 11288).
2026-05-28 20:54:17,116 [root] DEBUG: 11284: YaraScan: Scanning 0x00007FF691DA0000, size 0x3bf4c0
2026-05-28 20:54:17,137 [root] DEBUG: 11284: ProcessImageBase: Main module image at 0x00007FF691DA0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:54:17,138 [root] DEBUG: 11284: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:54:17,140 [root] DEBUG: 11284: ProcessImageBase: Main module image at 0x00007FF691DA0000 unmodified (entropy change 8.306301e-06)
2026-05-28 20:54:17,143 [root] DEBUG: 11284: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:54:17,152 [root] DEBUG: 11284: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:54:17,160 [root] DEBUG: 11284: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:54:17,178 [root] DEBUG: 11284: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 20:54:17,185 [root] DEBUG: 8060: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 20:54:17,221 [root] DEBUG: 11284: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 20:54:17,230 [root] DEBUG: 11284: NtTerminateProcess hook: Attempting to dump process 11284
2026-05-28 20:54:17,236 [root] DEBUG: 8060: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:54:17,237 [root] DEBUG: 11284: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:54:17,237 [root] DEBUG: 8060: DLL loaded at 0x00007FFF409A0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 20:54:17,245 [root] DEBUG: 11284: caller_dispatch: Added region at 0x00007FFF56FD0000 to tracked regions list (ntdll::NtClose returns to 0x00007FFF56FD419B, thread 11288).
2026-05-28 20:54:17,246 [root] DEBUG: 11284: caller_dispatch: Scanning calling region at 0x00007FFF56FD0000...
2026-05-28 20:54:17,258 [root] INFO: Process with pid 11284 has terminated
2026-05-28 20:54:18,045 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 12064: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:18,046 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 12064: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:18,046 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 12064
2026-05-28 20:54:18,047 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 12072
2026-05-28 20:54:18,047 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 12064
2026-05-28 20:54:18,048 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 12072
2026-05-28 20:54:18,056 [root] DEBUG: 8060: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 20:54:18,059 [root] DEBUG: 8060: DLL loaded at 0x00007FFF572F0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:54:18,061 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:54:18,065 [root] DEBUG: 8060: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:54:18,069 [root] DEBUG: 8060: DLL loaded at 0x00007FFF01180000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 20:54:18,077 [root] DEBUG: 8060: DLL loaded at 0x00007FFF04560000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 20:54:18,080 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:54:18,084 [root] DEBUG: 8060: DLL loaded at 0x00007FFF00B20000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 20:54:18,307 [root] DEBUG: 8060: DLL loaded at 0x00007FFF435B0000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 20:54:18,579 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 20:54:18,593 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56250000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 20:54:18,601 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 12236: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF6ACDF0000
2026-05-28 20:54:18,602 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12236
2026-05-28 20:54:18,604 [lib.api.process] INFO: Monitor config for process 12236: C:\rl4cuydm\dll\12236.ini
2026-05-28 20:54:18,604 [root] DEBUG: 8060: DLL loaded at 0x00007FFF561E0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 20:54:18,605 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:18,719 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3FBC0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 20:54:18,914 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 20:54:18,915 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:54:18,916 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:54:18,916 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 20:54:18,917 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 20:54:18,917 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 20:54:18,918 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 20:54:18,918 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 20:54:18,923 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:18,931 [root] DEBUG: Loader: Injecting process 12236 (thread 12240) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:18,932 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:18,932 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:18,934 [lib.api.process] INFO: Injected into 64-bit <Process 12236 identity_helper.exe>
2026-05-28 20:54:18,968 [root] DEBUG: 8060: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 20:54:18,970 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4CBD0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 20:54:18,971 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 11360: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF6ACDF0000
2026-05-28 20:54:18,972 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 11360
2026-05-28 20:54:18,973 [lib.api.process] INFO: Monitor config for process 11360: C:\rl4cuydm\dll\11360.ini
2026-05-28 20:54:18,977 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:18,983 [root] DEBUG: 8060: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:54:18,983 [root] DEBUG: 8060: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:54:18,996 [root] DEBUG: 8060: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:54:19,288 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 20:54:19,289 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:54:19,290 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:54:19,290 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 20:54:19,290 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 20:54:19,291 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 20:54:19,291 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 20:54:19,291 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 20:54:19,302 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:19,313 [root] DEBUG: Loader: Injecting process 11360 (thread 11348) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:19,314 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:19,315 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:19,316 [lib.api.process] INFO: Injected into 64-bit <Process 11360 identity_helper.exe>
2026-05-28 20:54:19,322 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 11360
2026-05-28 20:54:19,322 [lib.api.process] INFO: Monitor config for process 11360: C:\rl4cuydm\dll\11360.ini
2026-05-28 20:54:19,324 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:19,606 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4F950000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 20:54:19,610 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 20:54:19,611 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 20:54:19,611 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 20:54:19,611 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 20:54:19,612 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 20:54:19,612 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 20:54:19,612 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 20:54:19,612 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 20:54:19,618 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:19,623 [root] DEBUG: Loader: Injecting process 11360 (thread 11348) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:19,625 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:54:19,626 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:19,627 [lib.api.process] INFO: Injected into 64-bit <Process 11360 identity_helper.exe>
2026-05-28 20:54:19,637 [root] DEBUG: 11360: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:19,637 [root] DEBUG: 11360: Interactive desktop enabled.
2026-05-28 20:54:19,638 [root] DEBUG: 11360: Dropped file limit defaulting to 100.
2026-05-28 20:54:19,643 [root] DEBUG: 11360: Disabling sleep skipping.
2026-05-28 20:54:19,644 [root] DEBUG: 11360: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:19,656 [root] DEBUG: 11360: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:19,658 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6ACDF0000, size 0x28b4d8
2026-05-28 20:54:19,680 [root] DEBUG: 11360: Monitor initialised: 64-bit capemon loaded in process 11360 at 0x00007FFF1A580000, thread 11348, image base 0x00007FF6ACDF0000, stack from 0x0000009DBC7A4000-0x0000009DBC7B0000
2026-05-28 20:54:19,681 [root] DEBUG: 11360: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5928,i,2531656744226610878,12770878818328967517,524288 --field-trial-handle=2376,i,14328475659644198266,10791028425394596407,262144 --variations-seed-version --pseudonymization-salt-handle=2380,i,10276108160452854364,13253988876609
2026-05-28 20:54:19,681 [root] DEBUG: 11360: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 20:54:19,692 [root] DEBUG: 11360: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:54:19,714 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:54:19,715 [root] DEBUG: 11360: set_hooks: Unable to hook LockResource
2026-05-28 20:54:19,719 [root] DEBUG: 8060: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 20:54:19,721 [root] DEBUG: 11360: Hooked 627 out of 628 functions
2026-05-28 20:54:19,721 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4F740000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 20:54:19,737 [root] DEBUG: 11360: Syscall hook installed, syscall logging level 1
2026-05-28 20:54:19,742 [root] DEBUG: 11360: RestoreHeaders: Restored original import table.
2026-05-28 20:54:19,742 [root] INFO: Loaded monitor into process with pid 11360
2026-05-28 20:54:19,743 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FFF19420000, size 0x4b9994
2026-05-28 20:54:19,803 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FFF19420000, size 0x4b9994
2026-05-28 20:54:19,827 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FFF19420000, size 0x4b9994
2026-05-28 20:54:19,851 [root] DEBUG: 8060: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 20:54:19,852 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FFF19420000, size 0x4b9994
2026-05-28 20:54:19,868 [root] DEBUG: 8060: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 20:54:19,869 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 20:54:19,871 [root] DEBUG: 8060: DLL loaded at 0x00007FFF50370000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 20:54:19,874 [root] DEBUG: 8060: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:54:19,874 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 20:54:19,877 [root] DEBUG: 8060: DLL loaded at 0x00007FFF45050000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 20:54:19,880 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FFF19420000, size 0x4b9994
2026-05-28 20:54:19,905 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FFF19420000, size 0x4b9994
2026-05-28 20:54:19,917 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56D00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 20:54:19,930 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FFF19420000, size 0x4b9994
2026-05-28 20:54:19,957 [root] DEBUG: 11360: caller_dispatch: Added region at 0x00007FFF19420000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF1961F156, thread 11348).
2026-05-28 20:54:19,959 [root] DEBUG: 11360: caller_dispatch: Scanning calling region at 0x00007FFF19420000...
2026-05-28 20:54:19,970 [root] DEBUG: 11360: ProcessTrackedRegion: Region at 0x00007FFF19420000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 20:54:19,972 [root] DEBUG: 11360: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:54:19,993 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6ACDF0000, size 0x28b4d8
2026-05-28 20:54:20,008 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6ACDF0000, size 0x28b4d8
2026-05-28 20:54:20,023 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6ACDF0000, size 0x28b4d8
2026-05-28 20:54:20,038 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6ACDF0000, size 0x28b4d8
2026-05-28 20:54:20,052 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6ACDF0000, size 0x28b4d8
2026-05-28 20:54:20,067 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6ACDF0000, size 0x28b4d8
2026-05-28 20:54:20,084 [root] DEBUG: 11360: caller_dispatch: Added region at 0x00007FF6ACDF0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF6ACEE4096, thread 11348).
2026-05-28 20:54:20,085 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6ACDF0000, size 0x28b4d8
2026-05-28 20:54:20,101 [root] DEBUG: 11360: ProcessImageBase: Main module image at 0x00007FF6ACDF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:54:20,104 [root] DEBUG: 11360: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:54:20,226 [root] DEBUG: 11360: DLL loaded at 0x000002618F000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 20:54:20,228 [root] DEBUG: 11360: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:54:20,231 [root] DEBUG: 11360: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:54:20,232 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 11360, handle 0x2cd4: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 20:54:20,260 [root] DEBUG: 11360: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:54:20,266 [root] DEBUG: 11360: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:54:20,280 [root] DEBUG: 11360: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:54:20,281 [root] DEBUG: 11360: DLL loaded at 0x00007FFF52860000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 20:54:20,281 [root] DEBUG: 11360: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:54:20,282 [root] DEBUG: 11360: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 20:54:20,294 [root] DEBUG: 11360: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:54:20,295 [root] DEBUG: 11360: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:54:20,296 [root] DEBUG: 11360: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:54:20,296 [root] DEBUG: 11360: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:54:20,297 [root] DEBUG: 11360: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:54:20,319 [root] DEBUG: 11360: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:54:20,330 [root] DEBUG: 11360: DLL loaded at 0x00007FFF46AE0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 20:54:20,332 [root] DEBUG: 11360: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:54:20,340 [root] DEBUG: 11360: DLL loaded at 0x00007FFF566C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:54:20,341 [root] DEBUG: 11360: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:54:20,345 [root] DEBUG: 11360: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:54:20,353 [root] INFO: Process with pid 3780 has terminated
2026-05-28 20:54:20,354 [root] DEBUG: 3780: NtTerminateProcess hook: Attempting to dump process 3780
2026-05-28 20:54:20,355 [root] DEBUG: 3780: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:54:20,355 [root] DEBUG: 11360: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:54:20,364 [root] DEBUG: 11360: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:54:20,366 [root] DEBUG: 11360: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 20:54:20,378 [root] DEBUG: 11360: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 20:54:20,386 [root] DEBUG: 11360: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 20:54:20,406 [root] DEBUG: 11360: DLL loaded at 0x000002618DF60000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 20:54:20,424 [root] DEBUG: 11360: DLL loaded at 0x00007FFF4B780000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 20:54:20,425 [root] DEBUG: 11360: DLL loaded at 0x00007FFF4B840000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 20:54:20,426 [root] DEBUG: 11360: DLL loaded at 0x00007FFF43150000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 20:54:20,427 [root] DEBUG: 11360: DLL loaded at 0x00007FFF3D7B0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 20:54:20,436 [root] DEBUG: 11360: DLL loaded at 0x00007FFF4F6E0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 20:54:20,470 [root] DEBUG: 11360: DLL loaded at 0x00007FFF55EF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 20:54:20,471 [root] DEBUG: 11360: DLL loaded at 0x00007FFF53070000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 20:54:20,490 [root] DEBUG: 11360: DLL loaded at 0x00007FFF48B40000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 20:54:20,491 [root] DEBUG: 11360: DLL loaded at 0x00007FFF3D6A0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 20:54:20,530 [root] DEBUG: 11360: DLL loaded at 0x00007FFF43060000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 20:54:20,574 [root] DEBUG: 11360: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:54:20,575 [root] DEBUG: 11360: DLL loaded at 0x00007FFF56FA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 20:54:20,575 [root] DEBUG: 11360: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:54:20,576 [root] DEBUG: 11360: DLL loaded at 0x00007FFF4C520000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 20:54:20,577 [root] DEBUG: 11360: DLL loaded at 0x00007FFF43DD0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 20:54:20,609 [root] DEBUG: 11360: DLL loaded at 0x00007FFF3D810000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 20:54:20,626 [root] DEBUG: 11360: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 20:54:20,666 [root] DEBUG: 11360: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:54:22,487 [root] DEBUG: 4484: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 20:54:23,305 [root] DEBUG: 4484: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 20:54:24,166 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 7844, handle 0x2d20: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 20:54:24,247 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12700: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF787820000
2026-05-28 20:54:24,249 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 12700
2026-05-28 20:54:24,249 [lib.api.process] INFO: Monitor config for process 12700: C:\rl4cuydm\dll\12700.ini
2026-05-28 20:54:24,250 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:24,960 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:24,965 [root] DEBUG: Loader: Injecting process 12700 (thread 12704) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:24,966 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:54:24,967 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:24,968 [lib.api.process] INFO: Injected into 64-bit <Process 12700 WmiPrvSE.exe>
2026-05-28 20:54:25,000 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 12700
2026-05-28 20:54:25,000 [lib.api.process] INFO: Monitor config for process 12700: C:\rl4cuydm\dll\12700.ini
2026-05-28 20:54:25,001 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:25,497 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:25,502 [root] DEBUG: Loader: Injecting process 12700 (thread 12704) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:25,503 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:54:25,504 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:25,505 [lib.api.process] INFO: Injected into 64-bit <Process 12700 WmiPrvSE.exe>
2026-05-28 20:54:25,513 [root] DEBUG: 12700: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:25,514 [root] DEBUG: 12700: Interactive desktop enabled.
2026-05-28 20:54:25,516 [root] DEBUG: 12700: Dropped file limit defaulting to 100.
2026-05-28 20:54:25,521 [root] DEBUG: 12700: Disabling sleep skipping.
2026-05-28 20:54:25,521 [root] DEBUG: 12700: Services hook set enabled
2026-05-28 20:54:25,523 [root] DEBUG: 12700: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:25,534 [root] DEBUG: 12700: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:25,535 [root] DEBUG: 12700: Monitor initialised: 64-bit capemon loaded in process 12700 at 0x00007FFF1A580000, thread 12704, image base 0x00007FF787820000, stack from 0x000000E4C43B0000-0x000000E4C43C0000
2026-05-28 20:54:25,535 [root] DEBUG: 12700: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 20:54:25,547 [root] DEBUG: 12700: Hooked 69 out of 69 functions
2026-05-28 20:54:25,551 [root] DEBUG: 12700: RestoreHeaders: Restored original import table.
2026-05-28 20:54:25,552 [root] INFO: Loaded monitor into process with pid 12700
2026-05-28 20:54:25,555 [root] DEBUG: 12700: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:54:25,556 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:54:25,558 [root] DEBUG: 12700: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:54:25,559 [lib.api.process] INFO: Monitor config for process 8424: C:\rl4cuydm\dll\8424.ini
2026-05-28 20:54:25,561 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:54:25,563 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:54:25,568 [root] DEBUG: Loader: Injecting process 8424 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:25,570 [root] DEBUG: 8424: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:54:25,571 [root] DEBUG: 8424: Disabling sleep skipping.
2026-05-28 20:54:25,571 [root] DEBUG: 8424: Interactive desktop enabled.
2026-05-28 20:54:25,572 [root] DEBUG: 8424: Dropped file limit defaulting to 100.
2026-05-28 20:54:25,573 [root] DEBUG: 8424: Services hook set enabled
2026-05-28 20:54:25,574 [root] DEBUG: 8424: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:54:25,586 [root] DEBUG: 8424: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:54:25,587 [root] DEBUG: 8424: Monitor initialised: 64-bit capemon loaded in process 8424 at 0x00007FFF1A580000, thread 12920, image base 0x00007FF7BF220000, stack from 0x000000B2DC774000-0x000000B2DC780000
2026-05-28 20:54:25,588 [root] DEBUG: 8424: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 20:54:25,602 [root] DEBUG: 8424: Hooked 69 out of 69 functions
2026-05-28 20:54:25,603 [root] INFO: Loaded monitor into process with pid 8424
2026-05-28 20:54:25,604 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:54:25,604 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:54:25,606 [lib.api.process] INFO: Injected into 64-bit <Process 8424 svchost.exe>
2026-05-28 20:54:27,615 [root] DEBUG: 12700: DLL loaded at 0x00007FFF3FD20000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:54:27,622 [root] DEBUG: 12700: DLL loaded at 0x00007FFF3F950000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:54:27,633 [root] DEBUG: 12700: DLL loaded at 0x00007FFF42BF0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 20:54:27,645 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:54:27,646 [root] DEBUG: 12700: DLL loaded at 0x00007FFF4F490000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 20:54:27,647 [root] DEBUG: 12700: DLL loaded at 0x00007FFF00440000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 20:54:27,647 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:54:27,656 [root] DEBUG: 12700: DLL loaded at 0x000002CDBFAC0000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 20:54:27,657 [root] DEBUG: 12700: DLL loaded at 0x00007FFF520C0000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 20:54:27,658 [root] DEBUG: 12700: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:54:27,666 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:54:27,667 [root] DEBUG: 12700: DLL loaded at 0x00007FFF572F0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:54:27,670 [root] DEBUG: 12700: DLL loaded at 0x00007FFF55EF0000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 20:54:27,671 [root] DEBUG: 12700: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 20:54:27,674 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:54:27,675 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:54:27,677 [root] DEBUG: 12700: DLL loaded at 0x00007FFF55EF0000: C:\Windows\SYSTEM32\dxgi (0xf3000 bytes).
2026-05-28 20:54:27,678 [root] DEBUG: 12700: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 20:54:27,680 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:54:27,681 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:54:27,682 [root] DEBUG: 12700: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-28 20:54:27,683 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:54:27,685 [root] DEBUG: 12700: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:54:30,777 [root] INFO: Process with pid 11360 has terminated
2026-05-28 20:54:30,778 [root] DEBUG: 11360: NtTerminateProcess hook: Attempting to dump process 11360
2026-05-28 20:54:30,779 [root] DEBUG: 11360: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:54:40,624 [root] DEBUG: 8060: DLL loaded at 0x00007FFF42E10000: C:\Windows\system32\explorerframe (0x244000 bytes).
2026-05-28 20:54:40,628 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3EA70000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 20:54:41,205 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 12760: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:41,207 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 336: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:41,207 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 12760
2026-05-28 20:54:41,208 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 336
2026-05-28 20:54:41,208 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 12760
2026-05-28 20:54:41,210 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 336
2026-05-28 20:54:41,210 [root] DEBUG: 8060: DLL loaded at 0x00007FFF47420000: C:\Windows\System32\Windows.FileExplorer.Common (0x61000 bytes).
2026-05-28 20:54:41,245 [root] DEBUG: 8060: DLL loaded at 0x00007FFF594D0000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-05-28 20:54:41,249 [root] DEBUG: 8060: DLL loaded at 0x00007FFF51B20000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 20:54:41,251 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 8608: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:41,252 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 8608
2026-05-28 20:54:41,253 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 8608
2026-05-28 20:54:41,262 [root] DEBUG: 8060: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:54:41,279 [root] DEBUG: 8060: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:54:41,280 [root] DEBUG: 8060: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:54:41,291 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 10376: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:41,298 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 10376
2026-05-28 20:54:41,300 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 10376
2026-05-28 20:54:41,800 [root] DEBUG: 4484: DLL loaded at 0x00007FFF1C390000: C:\Windows\system32\zipfldr (0x4a000 bytes).
2026-05-28 20:54:41,801 [root] DEBUG: 4484: DLL loaded at 0x00007FFF1C390000: C:\Windows\system32\zipfldr (0x4a000 bytes).
2026-05-28 20:54:42,630 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4F540000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 20:54:42,740 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 568: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:54:42,741 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 568
2026-05-28 20:54:42,742 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 568
2026-05-28 20:54:44,620 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F390000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 20:54:44,621 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F390000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 20:54:44,625 [root] DEBUG: 4484: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 20:54:44,763 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F210000: C:\Windows\System32\shacct (0x29000 bytes).
2026-05-28 20:54:44,764 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F210000: C:\Windows\System32\shacct (0x29000 bytes).
2026-05-28 20:54:44,830 [root] DEBUG: 4484: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 20:54:44,889 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF670000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 20:54:44,890 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF670000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 20:54:44,912 [root] DEBUG: 4484: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 20:54:44,940 [root] DEBUG: 4484: api-rate-cap: NtQueryKey hook disabled due to rate
2026-05-28 20:54:45,027 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3EF90000: C:\Windows\System32\sendmail (0x2b000 bytes).
2026-05-28 20:54:45,028 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3EF90000: C:\Windows\System32\sendmail (0x2b000 bytes).
2026-05-28 20:54:45,049 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\mydocs (0x11000 bytes).
2026-05-28 20:54:45,050 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F470000: C:\Windows\system32\mydocs (0x11000 bytes).
2026-05-28 20:54:45,138 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 20:54:45,139 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 20:54:45,142 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54E10000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 20:54:45,143 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54E10000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 20:54:45,144 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F430000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 20:54:45,145 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F430000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 20:54:45,147 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54A50000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 20:54:45,148 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54A50000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 20:54:45,148 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F210000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 20:54:45,149 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F210000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 20:54:45,207 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF600000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 20:54:45,208 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF600000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 20:54:45,224 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF5D0000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 20:54:45,225 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF5D0000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 20:54:46,050 [root] DEBUG: 4484: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 20:54:47,342 [root] DEBUG: 4484: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-28 20:54:47,347 [root] DEBUG: 4484: api-rate-cap: RtlSetCurrentTransaction hook disabled due to rate
2026-05-28 20:54:47,401 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3EF90000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-28 20:54:47,402 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3EF90000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-28 20:54:47,473 [root] DEBUG: 4484: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 20:54:47,527 [root] DEBUG: 4484: DLL loaded at 0x00007FFF589D0000: C:\Windows\System32\comdlg32 (0xda000 bytes).
2026-05-28 20:54:47,529 [root] DEBUG: 4484: DLL loaded at 0x00007FFF589D0000: C:\Windows\System32\comdlg32 (0xda000 bytes).
2026-05-28 20:54:53,581 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:53,583 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:53,584 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:53,585 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:53,604 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F830000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 20:54:53,605 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F830000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 20:54:53,612 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:53,613 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:53,623 [root] DEBUG: 4484: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:54:53,624 [root] DEBUG: 4484: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:54:53,692 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:53,695 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:53,699 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:53,699 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:53,710 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:53,712 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:53,773 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:53,776 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:53,777 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:53,777 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:53,788 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:53,789 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:53,850 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:53,851 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:53,852 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:53,852 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:53,862 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:53,863 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:54,131 [root] DEBUG: 4484: api-cap: RegEnumKeyExW hook disabled due to count: 5000
2026-05-28 20:54:54,159 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:54,160 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\SYSTEM32\WDSCORE (0x43000 bytes).
2026-05-28 20:54:54,161 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:54,162 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\system32\winshfhc (0xa000 bytes).
2026-05-28 20:54:54,172 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:54,172 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47F70000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:54:54,528 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3CE10000: C:\Windows\System32\uiautomationcore (0x2f5000 bytes).
2026-05-28 20:54:54,529 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3CE10000: C:\Windows\System32\uiautomationcore (0x2f5000 bytes).
2026-05-28 20:54:54,568 [root] DEBUG: 4484: api-cap: NtQueryValueKey hook disabled due to count: 5000
2026-05-28 20:54:54,571 [root] DEBUG: 4484: api-cap: NtQueryValueKey hook disabled due to count: 5001
2026-05-28 20:54:58,936 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes).
2026-05-28 20:54:58,937 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF580000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes).
2026-05-28 20:54:58,992 [root] DEBUG: 4484: api-cap: GetSystemTimeAsFileTime hook disabled due to count: 5000
2026-05-28 20:54:59,046 [root] DEBUG: 4484: DLL loaded at 0x00007FFF467E0000: C:\Windows\System32\Windows.System.Launcher (0xbd000 bytes).
2026-05-28 20:54:59,048 [root] DEBUG: 4484: DLL loaded at 0x00007FFF467E0000: C:\Windows\System32\Windows.System.Launcher (0xbd000 bytes).
2026-05-28 20:55:03,086 [root] DEBUG: 4484: DLL loaded at 0x00007FFF1C370000: C:\Windows\System32\HelpPaneProxy (0x13000 bytes).
2026-05-28 20:55:03,087 [root] DEBUG: 4484: DLL loaded at 0x00007FFF1C370000: C:\Windows\System32\HelpPaneProxy (0x13000 bytes).
2026-05-28 20:55:03,094 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 14888: C:\Windows\helppane.exe, ImageBase: 0x00007FF7791D0000
2026-05-28 20:55:03,094 [root] INFO: Announced 64-bit process name: HelpPane.exe pid: 14888
2026-05-28 20:55:03,095 [lib.api.process] INFO: Monitor config for process 14888: C:\rl4cuydm\dll\14888.ini
2026-05-28 20:55:03,096 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:03,099 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:03,103 [root] DEBUG: Loader: Injecting process 14888 (thread 14892) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:03,104 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:03,105 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:03,106 [lib.api.process] INFO: Injected into 64-bit <Process 14888 HelpPane.exe>
2026-05-28 20:55:03,109 [root] INFO: Announced 64-bit process name: HelpPane.exe pid: 14888
2026-05-28 20:55:03,110 [lib.api.process] INFO: Monitor config for process 14888: C:\rl4cuydm\dll\14888.ini
2026-05-28 20:55:03,110 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:03,113 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:03,117 [root] DEBUG: Loader: Injecting process 14888 (thread 14892) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:03,118 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:03,119 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:03,121 [lib.api.process] INFO: Injected into 64-bit <Process 14888 HelpPane.exe>
2026-05-28 20:55:03,130 [root] DEBUG: 14888: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:03,131 [root] DEBUG: 14888: Interactive desktop enabled.
2026-05-28 20:55:03,132 [root] DEBUG: 14888: Dropped file limit defaulting to 100.
2026-05-28 20:55:03,134 [root] DEBUG: 14888: Disabling sleep skipping.
2026-05-28 20:55:03,135 [root] DEBUG: 14888: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:03,146 [root] DEBUG: 14888: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:03,147 [root] DEBUG: 14888: YaraScan: Scanning 0x00007FF7791D0000, size 0x107b6c
2026-05-28 20:55:03,157 [root] DEBUG: 14888: Monitor initialised: 64-bit capemon loaded in process 14888 at 0x00007FFF1A580000, thread 14892, image base 0x00007FF7791D0000, stack from 0x000000ACFCFC4000-0x000000ACFCFD0000
2026-05-28 20:55:03,157 [root] DEBUG: 14888: Commandline: C:\Windows\helppane.exe -Embedding
2026-05-28 20:55:03,168 [root] DEBUG: 14888: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:03,189 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:03,190 [root] DEBUG: 14888: set_hooks: Unable to hook LockResource
2026-05-28 20:55:03,194 [root] DEBUG: 14888: Hooked 627 out of 628 functions
2026-05-28 20:55:03,199 [root] DEBUG: 14888: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:03,204 [root] DEBUG: 14888: RestoreHeaders: Restored original import table.
2026-05-28 20:55:03,204 [root] INFO: Loaded monitor into process with pid 14888
2026-05-28 20:55:03,211 [root] DEBUG: 14888: caller_dispatch: Added region at 0x00007FF7791D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF779228A32, thread 14892).
2026-05-28 20:55:03,211 [root] DEBUG: 14888: YaraScan: Scanning 0x00007FF7791D0000, size 0x107b6c
2026-05-28 20:55:03,217 [root] DEBUG: 14888: ProcessImageBase: Main module image at 0x00007FF7791D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:03,220 [root] DEBUG: 14888: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:03,221 [root] DEBUG: 14888: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:03,222 [root] DEBUG: 14888: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:55:03,227 [root] DEBUG: 14888: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:55:03,236 [root] DEBUG: 14888: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:55:03,237 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 14888, handle 0x3164: C:\Windows\HelpPane.exe
2026-05-28 20:55:03,241 [root] DEBUG: 14888: DLL loaded at 0x00007FFF3B650000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes).
2026-05-28 20:55:03,268 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4F590000: C:\Windows\SYSTEM32\Cabinet (0x29000 bytes).
2026-05-28 20:55:03,269 [root] DEBUG: 14888: DLL loaded at 0x00007FFEFF530000: C:\Windows\SYSTEM32\APDS (0x42000 bytes).
2026-05-28 20:55:03,287 [root] DEBUG: 14888: DLL loaded at 0x00007FFF48B40000: C:\Windows\SYSTEM32\WININET (0x4d6000 bytes).
2026-05-28 20:55:03,289 [root] DEBUG: 14888: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:55:03,295 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:55:03,296 [root] DEBUG: 14888: DLL loaded at 0x00007FFF43550000: C:\Windows\System32\NETAPI32 (0x19000 bytes).
2026-05-28 20:55:03,296 [root] DEBUG: 14888: DLL loaded at 0x00007FFF43500000: C:\Windows\System32\VERSION (0xa000 bytes).
2026-05-28 20:55:03,297 [root] DEBUG: 14888: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:55:03,299 [root] DEBUG: 14888: DLL loaded at 0x00007FFF52560000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-05-28 20:55:03,300 [root] DEBUG: 14888: DLL loaded at 0x00007FFF56A30000: C:\Windows\System32\NETUTILS (0xc000 bytes).
2026-05-28 20:55:03,300 [root] DEBUG: 14888: DLL loaded at 0x00007FFF56750000: C:\Windows\System32\WKSCLI (0x19000 bytes).
2026-05-28 20:55:03,301 [root] DEBUG: 14888: DLL loaded at 0x00007FFF41280000: C:\Windows\System32\ieframe (0x76c000 bytes).
2026-05-28 20:55:03,317 [root] DEBUG: 14888: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 20:55:03,318 [root] DEBUG: 14888: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 20:55:03,319 [root] DEBUG: 14888: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 20:55:03,319 [root] DEBUG: 14888: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 20:55:03,324 [root] DEBUG: 14888: DLL loaded at 0x00007FFF517C0000: C:\Windows\system32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:55:03,334 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4D670000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 20:55:03,335 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4DA40000: C:\Windows\SYSTEM32\urlmon (0x1ed000 bytes).
2026-05-28 20:55:03,353 [root] DEBUG: 14888: DLL loaded at 0x00007FFF49830000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2026-05-28 20:55:03,361 [root] DEBUG: 14888: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:55:03,362 [root] DEBUG: 14888: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:55:03,366 [root] DEBUG: 14888: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 20:55:03,369 [root] DEBUG: 14888: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:55:03,374 [root] DEBUG: 14888: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 20:55:03,379 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 14888 (handle 0x308c): 0x00007FF7791D0000.
2026-05-28 20:55:03,416 [root] DEBUG: 14888: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:55:03,421 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:55:03,431 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4C520000: C:\Windows\system32\Bcp47Langs (0x5b000 bytes).
2026-05-28 20:55:03,432 [root] DEBUG: 14888: DLL loaded at 0x00007FFF54850000: C:\Windows\system32\CoreMessaging (0xf2000 bytes).
2026-05-28 20:55:03,433 [root] DEBUG: 14888: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:55:03,433 [root] DEBUG: 14888: DLL loaded at 0x00007FFF54170000: C:\Windows\system32\CoreUIComponents (0x35b000 bytes).
2026-05-28 20:55:03,436 [root] DEBUG: 14888: DLL loaded at 0x00007FFF403A0000: C:\Windows\system32\DictationManager (0x80000 bytes).
2026-05-28 20:55:03,437 [root] DEBUG: 14888: DLL loaded at 0x00007FFF40420000: C:\Windows\system32\windowsudk.shellcommon (0x2b3000 bytes).
2026-05-28 20:55:03,445 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 20:55:03,452 [root] DEBUG: 14888: DLL loaded at 0x00007FFF57560000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 20:55:03,478 [root] DEBUG: 14888: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:55:03,488 [root] DEBUG: 14888: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:55:03,493 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 20:55:03,507 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 20:55:03,572 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 20:55:03,587 [root] DEBUG: 14888: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 20:55:03,647 [root] DEBUG: 14888: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 20:55:03,670 [root] DEBUG: 14888: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:55:03,770 [root] DEBUG: 14888: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 20:55:03,799 [root] DEBUG: 14888: DLL loaded at 0x00007FFF54AE0000: C:\Windows\SYSTEM32\MLANG (0x42000 bytes).
2026-05-28 20:55:03,824 [root] DEBUG: 14888: DLL loaded at 0x00007FFEFF580000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes).
2026-05-28 20:55:03,828 [root] DEBUG: 14888: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:55:03,830 [root] DEBUG: 14888: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:55:03,856 [root] DEBUG: 14888: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:55:03,858 [root] DEBUG: 14888: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:55:03,874 [root] DEBUG: 14888: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:55:03,941 [root] DEBUG: 14888: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:55:03,966 [root] DEBUG: 14888: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:03,967 [root] DEBUG: 14888: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:03,981 [root] DEBUG: 14888: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:55:03,986 [root] DEBUG: 14888: CreateProcessHandler: Injection info set for new process 14916: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:55:03,987 [root] INFO: Announced 64-bit process name: msedge.exe pid: 14916
2026-05-28 20:55:03,988 [lib.api.process] INFO: Monitor config for process 14916: C:\rl4cuydm\dll\14916.ini
2026-05-28 20:55:03,989 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:03,993 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:03,997 [root] DEBUG: Loader: Injecting process 14916 (thread 14912) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:03,997 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:03,998 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:03,999 [lib.api.process] INFO: Injected into 64-bit <Process 14916 msedge.exe>
2026-05-28 20:55:04,001 [root] INFO: Announced 64-bit process name: msedge.exe pid: 14916
2026-05-28 20:55:04,002 [lib.api.process] INFO: Monitor config for process 14916: C:\rl4cuydm\dll\14916.ini
2026-05-28 20:55:04,002 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:04,008 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:04,012 [root] DEBUG: Loader: Injecting process 14916 (thread 14912) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:04,013 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:04,014 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:04,015 [lib.api.process] INFO: Injected into 64-bit <Process 14916 msedge.exe>
2026-05-28 20:55:04,016 [root] INFO: Announced 64-bit process name: msedge.exe pid: 14916
2026-05-28 20:55:04,017 [lib.api.process] INFO: Monitor config for process 14916: C:\rl4cuydm\dll\14916.ini
2026-05-28 20:55:04,018 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:04,021 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:04,026 [root] DEBUG: Loader: Injecting process 14916 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:04,026 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 14912, handle 0x124
2026-05-28 20:55:04,028 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:04,028 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:04,030 [lib.api.process] INFO: Injected into 64-bit <Process 14916 msedge.exe>
2026-05-28 20:55:04,046 [root] DEBUG: 14916: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:04,047 [root] DEBUG: 14916: Interactive desktop enabled.
2026-05-28 20:55:04,047 [root] DEBUG: 14916: Dropped file limit defaulting to 100.
2026-05-28 20:55:04,052 [root] DEBUG: 14916: Edge-specific hook-set enabled.
2026-05-28 20:55:04,054 [root] DEBUG: 14916: Disabling sleep skipping.
2026-05-28 20:55:04,055 [root] DEBUG: 14916: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:04,067 [root] DEBUG: 14916: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:04,073 [root] DEBUG: 14916: Monitor initialised: 64-bit capemon loaded in process 14916 at 0x00007FFF1A580000, thread 14912, image base 0x00007FF7F5380000, stack from 0x000000E23BFF4000-0x000000E23C000000
2026-05-28 20:55:04,075 [root] DEBUG: 14916: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument microsoft-edge:https://go.microsoft.com/fwlink/?LinkId=528884
2026-05-28 20:55:04,087 [root] DEBUG: 14916: Hooked 2 out of 2 functions
2026-05-28 20:55:04,120 [root] DEBUG: 14916: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:04,126 [root] DEBUG: 14916: RestoreHeaders: Restored original import table.
2026-05-28 20:55:04,129 [root] INFO: Loaded monitor into process with pid 14916
2026-05-28 20:55:04,130 [root] DEBUG: 14916: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 20:55:04,133 [root] DEBUG: 14916: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 20:55:04,135 [root] DEBUG: 14916: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:55:04,136 [root] DEBUG: 14916: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:55:04,138 [root] DEBUG: 14916: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:55:04,139 [root] DEBUG: 14916: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:55:04,143 [root] DEBUG: 14916: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:04,173 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 15656: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:55:04,176 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15656
2026-05-28 20:55:04,178 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15656
2026-05-28 20:55:04,723 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 15748: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:55:04,733 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15748
2026-05-28 20:55:04,739 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15748
2026-05-28 20:55:04,807 [root] INFO: Process with pid 14916 appears to have terminated
2026-05-28 20:55:05,045 [root] DEBUG: 8060: DLL loaded at 0x00007FFF48630000: C:\Windows\System32\Windows.Devices.Enumeration (0x87000 bytes).
2026-05-28 20:55:05,052 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3E560000: C:\Windows\System32\CapabilityAccessManagerClient (0x3f000 bytes).
2026-05-28 20:55:05,084 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3D7B0000: C:\Windows\System32\BiWinrt (0x53000 bytes).
2026-05-28 20:55:05,085 [root] DEBUG: 8060: DLL loaded at 0x00007FFEFF4B0000: C:\Windows\System32\Geolocation (0x7d000 bytes).
2026-05-28 20:55:05,093 [root] DEBUG: 8060: DLL loaded at 0x00007FFF3D1A0000: C:\Windows\System32\LocationFrameworkPS (0xd000 bytes).
2026-05-28 20:55:12,725 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56140000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 20:55:12,727 [root] DEBUG: 8060: DLL loaded at 0x00007FFF56170000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-28 20:55:12,728 [root] DEBUG: 8060: DLL loaded at 0x00007FFF1A950000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-28 20:55:12,746 [root] DEBUG: 8060: DLL loaded at 0x00007FFF4F3B0000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 20:55:12,820 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 15952: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:55:12,821 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15952
2026-05-28 20:55:12,822 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15952
2026-05-28 20:55:12,901 [root] DEBUG: 8060: DLL loaded at 0x00007FFEFF290000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-28 20:55:32,670 [root] DEBUG: 8424: DLL loaded at 0x00007FFEFF6A0000: C:\Windows\system32\wbem\ncprov (0x21000 bytes).
2026-05-28 20:55:35,992 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 14908: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:55:35,993 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 15388
2026-05-28 20:55:35,993 [root] INFO: Announced 64-bit process name: svchost.exe pid: 14908
2026-05-28 20:55:35,994 [lib.api.process] INFO: Monitor config for process 14908: C:\rl4cuydm\dll\14908.ini
2026-05-28 20:55:35,995 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:35,998 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,002 [root] DEBUG: Loader: Injecting process 14908 (thread 15388) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,004 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\14908.ini to system path C:\14908.ini
2026-05-28 20:55:36,005 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 14908 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:55:36,006 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,007 [lib.api.process] INFO: Injected into 64-bit <Process 14908 svchost.exe>
2026-05-28 20:55:36,009 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 15388
2026-05-28 20:55:36,009 [root] INFO: Announced 64-bit process name: svchost.exe pid: 14908
2026-05-28 20:55:36,010 [lib.api.process] INFO: Monitor config for process 14908: C:\rl4cuydm\dll\14908.ini
2026-05-28 20:55:36,014 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,019 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,024 [root] DEBUG: Loader: Injecting process 14908 (thread 15388) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,026 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\14908.ini to system path C:\14908.ini
2026-05-28 20:55:36,027 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 14908 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:55:36,028 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,030 [lib.api.process] INFO: Injected into 64-bit <Process 14908 svchost.exe>
2026-05-28 20:55:36,032 [root] INFO: Announced 64-bit process name: svchost.exe pid: 14908
2026-05-28 20:55:36,033 [lib.api.process] INFO: Monitor config for process 14908: C:\rl4cuydm\dll\14908.ini
2026-05-28 20:55:36,034 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,038 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,046 [lib.api.process] INFO: Injected into 64-bit <Process 14908 svchost.exe>
2026-05-28 20:55:36,061 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 6632: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:55:36,063 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6632
2026-05-28 20:55:36,064 [lib.api.process] INFO: Monitor config for process 6632: C:\rl4cuydm\dll\6632.ini
2026-05-28 20:55:36,065 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,070 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,075 [root] DEBUG: Loader: Injecting process 6632 (thread 15896) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,076 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:36,077 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,078 [lib.api.process] INFO: Injected into 64-bit <Process 6632 svchost.exe>
2026-05-28 20:55:36,080 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6632
2026-05-28 20:55:36,080 [lib.api.process] INFO: Monitor config for process 6632: C:\rl4cuydm\dll\6632.ini
2026-05-28 20:55:36,081 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,085 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,089 [root] DEBUG: Loader: Injecting process 6632 (thread 15896) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,090 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,091 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,093 [lib.api.process] INFO: Injected into 64-bit <Process 6632 svchost.exe>
2026-05-28 20:55:36,094 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 16152: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 20:55:36,096 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 16152
2026-05-28 20:55:36,097 [root] INFO: Announced 64-bit process name: svchost.exe pid: 6632
2026-05-28 20:55:36,097 [lib.api.process] INFO: Monitor config for process 16152: C:\rl4cuydm\dll\16152.ini
2026-05-28 20:55:36,098 [lib.api.process] INFO: Monitor config for process 6632: C:\rl4cuydm\dll\6632.ini
2026-05-28 20:55:36,098 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,100 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,104 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,106 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,109 [root] DEBUG: Loader: Injecting process 16152 (thread 8636) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,109 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:36,110 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,111 [root] DEBUG: Loader: Injecting process 6632 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,111 [lib.api.process] INFO: Injected into 64-bit <Process 16152 dllhost.exe>
2026-05-28 20:55:36,113 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15896, handle 0x128
2026-05-28 20:55:36,115 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 16152
2026-05-28 20:55:36,115 [lib.api.process] INFO: Monitor config for process 16152: C:\rl4cuydm\dll\16152.ini
2026-05-28 20:55:36,116 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,117 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,118 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,120 [lib.api.process] INFO: Injected into 64-bit <Process 6632 svchost.exe>
2026-05-28 20:55:36,121 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,126 [root] DEBUG: Loader: Injecting process 16152 (thread 8636) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,127 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:36,128 [root] DEBUG: 6632: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:36,129 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,131 [root] DEBUG: 6632: Interactive desktop enabled.
2026-05-28 20:55:36,131 [root] DEBUG: 6632: Dropped file limit defaulting to 100.
2026-05-28 20:55:36,131 [lib.api.process] INFO: Injected into 64-bit <Process 16152 dllhost.exe>
2026-05-28 20:55:36,134 [root] DEBUG: 6632: Disabling sleep skipping.
2026-05-28 20:55:36,136 [root] DEBUG: 6632: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:36,138 [root] DEBUG: 16152: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:36,139 [root] DEBUG: 16152: Interactive desktop enabled.
2026-05-28 20:55:36,139 [root] DEBUG: 16152: Dropped file limit defaulting to 100.
2026-05-28 20:55:36,141 [root] DEBUG: 16152: Disabling sleep skipping.
2026-05-28 20:55:36,142 [root] DEBUG: 16152: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:36,147 [root] DEBUG: 6632: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:36,148 [root] DEBUG: 6632: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:55:36,150 [root] DEBUG: 6632: Monitor initialised: 64-bit capemon loaded in process 6632 at 0x00007FFF1A580000, thread 15896, image base 0x00007FF7BF220000, stack from 0x000000C1E2794000-0x000000C1E27A0000
2026-05-28 20:55:36,151 [root] DEBUG: 6632: Commandline: C:\Windows\System32\svchost.exe -k WerSvcGroup
2026-05-28 20:55:36,155 [root] DEBUG: 16152: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:36,156 [root] DEBUG: 16152: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:55:36,157 [root] DEBUG: 16152: Monitor initialised: 64-bit capemon loaded in process 16152 at 0x00007FFF1A580000, thread 8636, image base 0x00007FF6706B0000, stack from 0x00000016C9914000-0x00000016C9920000
2026-05-28 20:55:36,158 [root] DEBUG: 16152: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 20:55:36,161 [root] DEBUG: 6632: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:36,168 [root] DEBUG: 16152: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:36,181 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 12904: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:55:36,182 [root] INFO: Announced 64-bit process name: svchost.exe pid: 12904
2026-05-28 20:55:36,182 [lib.api.process] INFO: Monitor config for process 12904: C:\rl4cuydm\dll\12904.ini
2026-05-28 20:55:36,184 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,184 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:36,185 [root] DEBUG: 6632: set_hooks: Unable to hook LockResource
2026-05-28 20:55:36,188 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,190 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:36,190 [root] DEBUG: 6632: Hooked 627 out of 628 functions
2026-05-28 20:55:36,190 [root] DEBUG: 16152: set_hooks: Unable to hook LockResource
2026-05-28 20:55:36,191 [root] DEBUG: 6632: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:36,193 [root] DEBUG: Loader: Injecting process 12904 (thread 16388) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,194 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:36,194 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 16456: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x0000000000CD0000
2026-05-28 20:55:36,195 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,196 [root] DEBUG: 16152: Hooked 627 out of 628 functions
2026-05-28 20:55:36,196 [root] DEBUG: 6632: RestoreHeaders: Restored original import table.
2026-05-28 20:55:36,196 [lib.api.process] INFO: Injected into 64-bit <Process 12904 svchost.exe>
2026-05-28 20:55:36,197 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 16456
2026-05-28 20:55:36,198 [lib.api.process] INFO: Monitor config for process 16456: C:\rl4cuydm\dll\16456.ini
2026-05-28 20:55:36,198 [root] INFO: Announced 64-bit process name: svchost.exe pid: 12904
2026-05-28 20:55:36,198 [root] INFO: Loaded monitor into process with pid 6632
2026-05-28 20:55:36,199 [lib.api.process] INFO: Monitor config for process 12904: C:\rl4cuydm\dll\12904.ini
2026-05-28 20:55:36,199 [root] DEBUG: 16152: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:36,200 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,200 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,201 [root] DEBUG: 6632: caller_dispatch: Added region at 0x00007FF7BF220000 to tracked regions list (kernel32::GetCommandLineW returns to 0x00007FF7BF2250EA, thread 15896).
2026-05-28 20:55:36,202 [root] DEBUG: 6632: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:55:36,203 [root] DEBUG: 6632: ProcessImageBase: Main module image at 0x00007FF7BF220000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:36,204 [root] DEBUG: 16152: RestoreHeaders: Restored original import table.
2026-05-28 20:55:36,205 [root] INFO: Loaded monitor into process with pid 16152
2026-05-28 20:55:36,205 [lib.api.process] INFO: 32-bit DLL to inject is C:\rl4cuydm\dll\hRrVGCVJ.dll, loader C:\rl4cuydm\bin\GepINqp.exe
2026-05-28 20:55:36,206 [root] DEBUG: 16152: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6706B1349, thread 8636).
2026-05-28 20:55:36,205 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,207 [root] DEBUG: 16152: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:55:36,209 [root] DEBUG: 16152: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:36,211 [root] DEBUG: 16152: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:36,212 [root] DEBUG: 16152: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:36,213 [root] DEBUG: 6632: DLL loaded at 0x00007FFF523E0000: c:\windows\system32\XmlLite (0x36000 bytes).
2026-05-28 20:55:36,214 [root] DEBUG: Loader: Injecting process 12904 (thread 16388) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,214 [root] DEBUG: 6632: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:55:36,216 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,217 [root] DEBUG: 6632: DLL loaded at 0x00007FFF3E0F0000: c:\windows\system32\WindowsPerformanceRecorderControl (0x12d000 bytes).
2026-05-28 20:55:36,218 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,218 [root] DEBUG: 16152: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:55:36,219 [root] DEBUG: 6632: DLL loaded at 0x00007FFEFEF80000: c:\windows\system32\WerEtw (0x3f000 bytes).
2026-05-28 20:55:36,219 [lib.api.process] INFO: Injected into 64-bit <Process 12904 svchost.exe>
2026-05-28 20:55:36,220 [root] DEBUG: 6632: DLL loaded at 0x00007FFEFEFC0000: c:\windows\system32\wersvc (0x45000 bytes).
2026-05-28 20:55:36,221 [root] INFO: Announced 64-bit process name: svchost.exe pid: 12904
2026-05-28 20:55:36,222 [lib.api.process] INFO: Monitor config for process 12904: C:\rl4cuydm\dll\12904.ini
2026-05-28 20:55:36,223 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,225 [root] DEBUG: 6632: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-28 20:55:36,226 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,232 [root] DEBUG: 6632: DLL loaded at 0x00007FFF55330000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:55:36,234 [root] DEBUG: Loader: Injecting process 12904 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,235 [root] DEBUG: 16152: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:55:36,236 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 16388, handle 0x120
2026-05-28 20:55:36,236 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,237 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,240 [root] DEBUG: Loader: Injecting process 16456 (thread 16460) with C:\rl4cuydm\dll\hRrVGCVJ.dll.
2026-05-28 20:55:36,241 [lib.api.process] INFO: Injected into 64-bit <Process 12904 svchost.exe>
2026-05-28 20:55:36,241 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,242 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:36,242 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,243 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\hRrVGCVJ.dll.
2026-05-28 20:55:36,247 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,248 [lib.api.process] INFO: Injected into 32-bit <Process 16456 MicrosoftEdgeUpdate.exe>
2026-05-28 20:55:36,248 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,250 [root] DEBUG: 12904: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:36,250 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 16456
2026-05-28 20:55:36,251 [lib.api.process] INFO: Monitor config for process 16456: C:\rl4cuydm\dll\16456.ini
2026-05-28 20:55:36,251 [root] DEBUG: 12904: Interactive desktop enabled.
2026-05-28 20:55:36,252 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,252 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,253 [root] DEBUG: 12904: Dropped file limit defaulting to 100.
2026-05-28 20:55:36,254 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,256 [root] DEBUG: 16152: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:55:36,257 [root] DEBUG: 16152: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:55:36,258 [root] DEBUG: 12904: Disabling sleep skipping.
2026-05-28 20:55:36,258 [lib.api.process] INFO: 32-bit DLL to inject is C:\rl4cuydm\dll\hRrVGCVJ.dll, loader C:\rl4cuydm\bin\GepINqp.exe
2026-05-28 20:55:36,259 [root] DEBUG: 16152: DLL loaded at 0x00007FFF515A0000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:55:36,260 [root] DEBUG: 12904: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:36,261 [root] DEBUG: 16152: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:55:36,263 [root] DEBUG: 16152: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:55:36,264 [root] DEBUG: 16152: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:55:36,265 [root] DEBUG: 16152: DLL loaded at 0x00007FFF569F0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:55:36,266 [root] DEBUG: 6632: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:36,267 [root] DEBUG: 16152: DLL loaded at 0x00007FFF57520000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:55:36,268 [root] DEBUG: 16152: DLL loaded at 0x00007FFF57560000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 20:55:36,269 [root] DEBUG: Loader: Injecting process 16456 (thread 16460) with C:\rl4cuydm\dll\hRrVGCVJ.dll.
2026-05-28 20:55:36,269 [root] DEBUG: 16152: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 20:55:36,271 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,272 [root] DEBUG: 16152: DLL loaded at 0x00007FFF56A40000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 20:55:36,273 [root] DEBUG: 12904: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:36,273 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\hRrVGCVJ.dll.
2026-05-28 20:55:36,274 [root] DEBUG: 12904: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:55:36,275 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,276 [root] DEBUG: 12904: Monitor initialised: 64-bit capemon loaded in process 12904 at 0x00007FFF1A580000, thread 16388, image base 0x00007FF7BF220000, stack from 0x00000091B9FD4000-0x00000091B9FE0000
2026-05-28 20:55:36,276 [lib.api.process] INFO: Injected into 32-bit <Process 16456 MicrosoftEdgeUpdate.exe>
2026-05-28 20:55:36,277 [root] DEBUG: 16152: DLL loaded at 0x00007FFEFEEF0000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 20:55:36,278 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 16456
2026-05-28 20:55:36,278 [lib.api.process] INFO: Monitor config for process 16456: C:\rl4cuydm\dll\16456.ini
2026-05-28 20:55:36,279 [root] DEBUG: 12904: Commandline: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
2026-05-28 20:55:36,279 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,280 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,281 [root] DEBUG: 16152: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:55:36,284 [lib.api.process] INFO: 32-bit DLL to inject is C:\rl4cuydm\dll\hRrVGCVJ.dll, loader C:\rl4cuydm\bin\GepINqp.exe
2026-05-28 20:55:36,284 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,286 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,288 [root] DEBUG: 16152: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:55:36,290 [root] DEBUG: 12904: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:36,292 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,292 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,304 [root] DEBUG: Loader: Injecting process 16456 with C:\rl4cuydm\dll\hRrVGCVJ.dll.
2026-05-28 20:55:36,305 [root] DEBUG: 6632: OpenProcessHandler: Injection info created for process 11788, handle 0x250: C:\rl4cuydm\bin\PPLinject64.exe
2026-05-28 20:55:36,305 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed, falling back to thread injection.
2026-05-28 20:55:36,306 [root] DEBUG: 6632: OpenProcessHandler: Image base for process 11788 (handle 0x250): 0x00007FF7521A0000.
2026-05-28 20:55:36,312 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:36,313 [root] DEBUG: 6632: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:55:36,314 [root] DEBUG: 12904: set_hooks: Unable to hook LockResource
2026-05-28 20:55:36,315 [root] DEBUG: 6632: CreateProcessHandler: Injection info set for new process 16992: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:55:36,316 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 16992
2026-05-28 20:55:36,318 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 16992
2026-05-28 20:55:36,319 [root] DEBUG: 12904: Hooked 627 out of 628 functions
2026-05-28 20:55:36,321 [root] DEBUG: 12904: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:36,325 [root] DEBUG: 12904: RestoreHeaders: Restored original import table.
2026-05-28 20:55:36,326 [root] INFO: Loaded monitor into process with pid 12904
2026-05-28 20:55:36,328 [root] DEBUG: 12904: caller_dispatch: Added region at 0x00007FF7BF220000 to tracked regions list (kernel32::GetCommandLineW returns to 0x00007FF7BF2250EA, thread 16388).
2026-05-28 20:55:36,329 [root] DEBUG: 12904: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:55:36,330 [root] DEBUG: 12904: ProcessImageBase: Main module image at 0x00007FF7BF220000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:36,332 [root] DEBUG: 16456: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:36,334 [root] DEBUG: 16456: Interactive desktop enabled.
2026-05-28 20:55:36,335 [root] DEBUG: 16456: Dropped file limit defaulting to 100.
2026-05-28 20:55:36,338 [root] DEBUG: 12904: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:36,340 [root] DEBUG: 12904: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:36,342 [root] DEBUG: 16456: Disabling sleep skipping.
2026-05-28 20:55:36,344 [root] DEBUG: 16456: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:36,345 [root] DEBUG: 16456: YaraScan: Scanning 0x00CD0000, size 0x34220
2026-05-28 20:55:36,347 [root] DEBUG: 16456: Monitor initialised: 32-bit capemon loaded in process 16456 at 0x6ae20000, thread 16988, image base 0xcd0000, stack from 0x33f4000-0x3400000
2026-05-28 20:55:36,349 [root] DEBUG: 16456: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
2026-05-28 20:55:36,351 [root] DEBUG: 12904: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:55:36,379 [root] DEBUG: 16456: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-28 20:55:36,381 [root] DEBUG: 12904: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:55:36,383 [root] DEBUG: 12904: DLL loaded at 0x00007FFF572F0000: c:\windows\system32\DEVOBJ (0x33000 bytes).
2026-05-28 20:55:36,383 [root] DEBUG: 12904: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:55:36,385 [root] DEBUG: 12904: DLL loaded at 0x00007FFF47900000: c:\windows\system32\FLTLIB (0xb000 bytes).
2026-05-28 20:55:36,386 [root] DEBUG: 12904: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:55:36,387 [root] DEBUG: 12904: DLL loaded at 0x00007FFEFE7F0000: c:\windows\system32\bcd (0x22000 bytes).
2026-05-28 20:55:36,388 [root] DEBUG: 12904: DLL loaded at 0x00007FFF55330000: c:\windows\system32\wer (0xde000 bytes).
2026-05-28 20:55:36,390 [root] DEBUG: 12904: DLL loaded at 0x00007FFF52560000: c:\windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:55:36,391 [root] DEBUG: 12904: DLL loaded at 0x00007FFF4F590000: c:\windows\system32\Cabinet (0x29000 bytes).
2026-05-28 20:55:36,391 [root] DEBUG: 12904: DLL loaded at 0x00007FFEFE820000: c:\windows\system32\storsvc (0x10b000 bytes).
2026-05-28 20:55:36,396 [root] DEBUG: 16456: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-28 20:55:36,397 [root] DEBUG: 16456: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-28 20:55:36,398 [root] DEBUG: 12904: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-28 20:55:36,401 [root] DEBUG: 6632: DLL loaded at 0x00007FFF47530000: c:\windows\system32\dbghelp (0x1e4000 bytes).
2026-05-28 20:55:36,402 [root] DEBUG: 12904: DLL loaded at 0x00007FFF55710000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-28 20:55:36,402 [root] DEBUG: 6632: DLL loaded at 0x00007FFF474F0000: c:\windows\system32\dbgcore (0x34000 bytes).
2026-05-28 20:55:36,404 [root] DEBUG: 6632: DLL loaded at 0x00007FFF46350000: c:\windows\system32\faultrep (0x7b000 bytes).
2026-05-28 20:55:36,404 [root] DEBUG: 16456: Hooked 632 out of 632 functions
2026-05-28 20:55:36,406 [root] DEBUG: 16456: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:36,406 [root] DEBUG: 6632: DLL loaded at 0x00007FFF55330000: c:\windows\system32\wer (0xde000 bytes).
2026-05-28 20:55:36,413 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,414 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,415 [root] DEBUG: 12904: DLL loaded at 0x00007FFF4F740000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 20:55:36,418 [root] DEBUG: 16456: RestoreHeaders: Restored original import table.
2026-05-28 20:55:36,418 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,419 [root] DEBUG: 12904: DLL loaded at 0x00007FFEFF670000: C:\Windows\SYSTEM32\storageusage (0x2f000 bytes).
2026-05-28 20:55:36,419 [root] INFO: Loaded monitor into process with pid 16456
2026-05-28 20:55:36,420 [root] DEBUG: 16456: caller_dispatch: Added region at 0x02F80000 to tracked regions list (ntdll::LdrLoadDll returns to 0x02F80037, thread 16988).
2026-05-28 20:55:36,421 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,421 [root] DEBUG: 16456: DumpPEsInRange: Scanning range 0x02F80000 - 0x02F80129.
2026-05-28 20:55:36,422 [root] DEBUG: 16456: ScanForDisguisedPE: Size too small: 0x129 bytes
2026-05-28 20:55:36,425 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,426 [lib.common.results] INFO: Uploading file C:\ZRbPmMNO\CAPE\16456_129211503655029552026 to CAPE\1b54ceaf1408e58bac20171c5eb6b2e6d8afc5cd43bd52d5ab93281ce6a6a15a; Size is 297; Max size: 100000000
2026-05-28 20:55:36,428 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,429 [root] DEBUG: 12904: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:55:36,431 [root] DEBUG: 16456: DumpMemory: Payload successfully created: C:\ZRbPmMNO\CAPE\16456_129211503655029552026 (size 297 bytes)
2026-05-28 20:55:36,432 [root] DEBUG: 12904: DLL loaded at 0x00007FFF57560000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 20:55:36,432 [root] DEBUG: 16456: DumpRegion: Dumped entire allocation from 0x02F80000, size 4096 bytes.
2026-05-28 20:55:36,433 [root] DEBUG: 16456: ProcessTrackedRegion: Dumped region at 0x02F80000.
2026-05-28 20:55:36,434 [root] DEBUG: 16456: YaraScan: Scanning 0x02F80000, size 0x129
2026-05-28 20:55:36,435 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:55:36,436 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\hRrVGCVJ.dll.
2026-05-28 20:55:36,443 [lib.api.process] INFO: Injected into 32-bit <Process 16456 MicrosoftEdgeUpdate.exe>
2026-05-28 20:55:36,444 [root] DEBUG: 12904: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:55:36,444 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,445 [root] DEBUG: 16456: caller_dispatch: Added region at 0x00CD0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00CDD98E, thread 16460).
2026-05-28 20:55:36,445 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,446 [root] DEBUG: 16456: YaraScan: Scanning 0x00CD0000, size 0x34220
2026-05-28 20:55:36,448 [root] DEBUG: 16456: ProcessImageBase: Main module image at 0x00CD0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:36,449 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,450 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,454 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,455 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,456 [root] DEBUG: 16456: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-28 20:55:36,458 [root] DEBUG: 16456: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-28 20:55:36,463 [root] DEBUG: 16456: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-28 20:55:36,468 [root] DEBUG: 6632: DLL loaded at 0x00007FFF57520000: c:\windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:55:36,469 [root] DEBUG: 6632: DLL loaded at 0x00007FFF57560000: c:\windows\system32\profapi (0x25000 bytes).
2026-05-28 20:55:36,470 [root] DEBUG: 16456: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-28 20:55:36,471 [root] DEBUG: 16456: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-28 20:55:36,472 [root] DEBUG: 16456: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-28 20:55:36,473 [root] DEBUG: 16456: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-28 20:55:36,474 [root] DEBUG: 16456: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-28 20:55:36,475 [root] DEBUG: 16456: DLL loaded at 0x6ABE0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\msedgeupdate (0x23d000 bytes).
2026-05-28 20:55:36,479 [root] DEBUG: 6632: CreateProcessHandler: Injection info set for new process 16564: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:55:36,480 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 16564
2026-05-28 20:55:36,481 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 16564
2026-05-28 20:55:36,489 [root] DEBUG: 16456: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-28 20:55:36,491 [root] DEBUG: 16456: DLL loaded at 0x755E0000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-28 20:55:36,492 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 16564, handle 0x1f7c: C:\Windows\System32\WerFault.exe
2026-05-28 20:55:36,504 [root] DEBUG: 16456: DLL loaded at 0x6F2A0000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-28 20:55:36,505 [root] DEBUG: 16456: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-28 20:55:36,506 [root] DEBUG: 16456: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-28 20:55:36,507 [root] DEBUG: 16456: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-28 20:55:36,509 [root] DEBUG: 16456: DLL loaded at 0x75520000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-28 20:55:36,509 [root] DEBUG: 16456: DLL loaded at 0x75540000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-28 20:55:36,510 [root] DEBUG: 16456: DLL loaded at 0x755B0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-28 20:55:36,512 [root] DEBUG: 16456: DLL loaded at 0x6F290000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-28 20:55:36,514 [root] DEBUG: 16456: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-28 20:55:36,520 [root] DEBUG: 16456: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-28 20:55:36,521 [root] DEBUG: 16456: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-28 20:55:36,523 [root] DEBUG: 16456: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-28 20:55:36,530 [root] DEBUG: 16456: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-28 20:55:36,571 [root] DEBUG: 16456: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-28 20:55:36,574 [root] DEBUG: 16456: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-28 20:55:36,578 [root] DEBUG: 16456: CreateProcessHandler: Injection info set for new process 17436: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x00CD0000
2026-05-28 20:55:36,580 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 17436
2026-05-28 20:55:36,581 [lib.api.process] INFO: Monitor config for process 17436: C:\rl4cuydm\dll\17436.ini
2026-05-28 20:55:36,582 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,587 [lib.api.process] INFO: 32-bit DLL to inject is C:\rl4cuydm\dll\hRrVGCVJ.dll, loader C:\rl4cuydm\bin\GepINqp.exe
2026-05-28 20:55:36,594 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,595 [root] DEBUG: Loader: Injecting process 17436 (thread 17440) with C:\rl4cuydm\dll\hRrVGCVJ.dll.
2026-05-28 20:55:36,596 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,599 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:36,600 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 17492: C:\Windows\system32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:55:36,601 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\hRrVGCVJ.dll.
2026-05-28 20:55:36,601 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,603 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,603 [lib.api.process] INFO: Injected into 32-bit <Process 17436 MicrosoftEdgeUpdate.exe>
2026-05-28 20:55:36,603 [root] INFO: Announced 64-bit process name: svchost.exe pid: 17492
2026-05-28 20:55:36,605 [root] DEBUG: 16456: DLL loaded at 0x74960000: C:\Windows\system32\apphelp (0x9f000 bytes).
2026-05-28 20:55:36,605 [lib.api.process] INFO: Monitor config for process 17492: C:\rl4cuydm\dll\17492.ini
2026-05-28 20:55:36,607 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,607 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,609 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,610 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,617 [root] INFO: Added new file to list with pid 16456 and path C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log
2026-05-28 20:55:36,618 [root] DEBUG: 17436: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:36,620 [root] DEBUG: 17436: Interactive desktop enabled.
2026-05-28 20:55:36,621 [root] DEBUG: 16456: NtTerminateProcess hook: Attempting to dump process 16456
2026-05-28 20:55:36,622 [root] DEBUG: 17436: Dropped file limit defaulting to 100.
2026-05-28 20:55:36,622 [root] DEBUG: 16456: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:55:36,623 [root] DEBUG: Loader: Injecting process 17492 (thread 17496) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,625 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERE46F.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERE46F.tmp'
2026-05-28 20:55:36,625 [root] DEBUG: 17436: Disabling sleep skipping.
2026-05-28 20:55:36,625 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:36,627 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERE46F.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERE46F.tmp'
2026-05-28 20:55:36,628 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,629 [root] DEBUG: 17436: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:36,631 [root] INFO: Process with pid 16456 has terminated
2026-05-28 20:55:36,632 [root] DEBUG: 17436: YaraScan: Scanning 0x00CD0000, size 0x34220
2026-05-28 20:55:36,631 [lib.api.process] INFO: Injected into 64-bit <Process 17492 svchost.exe>
2026-05-28 20:55:36,634 [root] DEBUG: 17436: Monitor initialised: 32-bit capemon loaded in process 17436 at 0x6ae20000, thread 17440, image base 0xcd0000, stack from 0x734000-0x740000
2026-05-28 20:55:36,635 [root] DEBUG: 17436: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /c
2026-05-28 20:55:36,642 [root] INFO: Announced 64-bit process name: svchost.exe pid: 17492
2026-05-28 20:55:36,643 [lib.api.process] INFO: Monitor config for process 17492: C:\rl4cuydm\dll\17492.ini
2026-05-28 20:55:36,644 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,648 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,656 [root] DEBUG: 6632: api-rate-cap: NtWriteFile hook disabled due to rate
2026-05-28 20:55:36,658 [root] DEBUG: 17436: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-28 20:55:36,673 [root] DEBUG: 17436: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-28 20:55:36,674 [root] DEBUG: Loader: Injecting process 17492 (thread 17496) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,674 [root] DEBUG: 17436: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-28 20:55:36,676 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,678 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WERE46F.tmp.csv
2026-05-28 20:55:36,679 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,679 [root] DEBUG: 17436: Hooked 632 out of 632 functions
2026-05-28 20:55:36,683 [root] DEBUG: 17436: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:36,683 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,684 [lib.api.process] INFO: Injected into 64-bit <Process 17492 svchost.exe>
2026-05-28 20:55:36,686 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,687 [root] DEBUG: 17436: RestoreHeaders: Restored original import table.
2026-05-28 20:55:36,687 [root] INFO: Announced 64-bit process name: svchost.exe pid: 17492
2026-05-28 20:55:36,688 [lib.api.process] INFO: Monitor config for process 17492: C:\rl4cuydm\dll\17492.ini
2026-05-28 20:55:36,688 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,688 [root] INFO: Loaded monitor into process with pid 17436
2026-05-28 20:55:36,690 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,691 [root] DEBUG: 17436: caller_dispatch: Added region at 0x00CD0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00CDD98E, thread 17440).
2026-05-28 20:55:36,691 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,693 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,694 [root] DEBUG: 17436: YaraScan: Scanning 0x00CD0000, size 0x34220
2026-05-28 20:55:36,695 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,696 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 17760: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:55:36,697 [root] DEBUG: 17436: ProcessImageBase: Main module image at 0x00CD0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:36,697 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,701 [root] INFO: Announced 64-bit process name: svchost.exe pid: 17760
2026-05-28 20:55:36,701 [root] DEBUG: 17436: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-28 20:55:36,701 [root] DEBUG: Loader: Injecting process 17492 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,702 [lib.api.process] INFO: Monitor config for process 17760: C:\rl4cuydm\dll\17760.ini
2026-05-28 20:55:36,702 [root] DEBUG: 17436: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-28 20:55:36,703 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17496, handle 0x124
2026-05-28 20:55:36,703 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,704 [root] DEBUG: 17436: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-28 20:55:36,704 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,705 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,706 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERE4BE.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERE4BE.tmp'
2026-05-28 20:55:36,707 [root] DEBUG: 17436: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-28 20:55:36,707 [lib.api.process] INFO: Injected into 64-bit <Process 17492 svchost.exe>
2026-05-28 20:55:36,708 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERE4BE.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERE4BE.tmp'
2026-05-28 20:55:36,709 [root] DEBUG: 17436: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-28 20:55:36,710 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,710 [root] DEBUG: 17436: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-28 20:55:36,711 [root] DEBUG: 17436: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-28 20:55:36,712 [root] DEBUG: 17436: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-28 20:55:36,713 [root] DEBUG: 17436: DLL loaded at 0x6ABE0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\msedgeupdate (0x23d000 bytes).
2026-05-28 20:55:36,718 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WERE4BE.tmp.txt
2026-05-28 20:55:36,718 [root] DEBUG: Loader: Injecting process 17760 (thread 17764) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,720 [root] DEBUG: 17436: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-28 20:55:36,720 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:36,721 [root] DEBUG: 17492: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:36,722 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,722 [root] DEBUG: 17492: Interactive desktop enabled.
2026-05-28 20:55:36,723 [root] DEBUG: 17436: DLL loaded at 0x755E0000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-28 20:55:36,724 [lib.api.process] INFO: Injected into 64-bit <Process 17760 svchost.exe>
2026-05-28 20:55:36,725 [root] DEBUG: 17492: Dropped file limit defaulting to 100.
2026-05-28 20:55:36,727 [root] INFO: Announced 64-bit process name: svchost.exe pid: 17760
2026-05-28 20:55:36,728 [lib.api.process] INFO: Monitor config for process 17760: C:\rl4cuydm\dll\17760.ini
2026-05-28 20:55:36,729 [root] DEBUG: 17492: Disabling sleep skipping.
2026-05-28 20:55:36,729 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,730 [root] DEBUG: 17492: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:36,732 [root] DEBUG: 17436: DLL loaded at 0x6F2A0000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-28 20:55:36,733 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,734 [root] DEBUG: 17436: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-28 20:55:36,735 [root] DEBUG: 17436: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-28 20:55:36,737 [root] DEBUG: 17436: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-28 20:55:36,737 [root] DEBUG: 17436: DLL loaded at 0x75520000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-28 20:55:36,742 [root] DEBUG: 17436: DLL loaded at 0x75540000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-28 20:55:36,743 [root] DEBUG: Loader: Injecting process 17760 (thread 17764) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,743 [root] DEBUG: 17492: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:36,744 [root] DEBUG: 17436: DLL loaded at 0x755B0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-28 20:55:36,745 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,745 [root] DEBUG: 17492: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:55:36,746 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,747 [root] DEBUG: 17492: Monitor initialised: 64-bit capemon loaded in process 17492 at 0x00007FFF1A580000, thread 17496, image base 0x00007FF7BF220000, stack from 0x0000002E8DA74000-0x0000002E8DA80000
2026-05-28 20:55:36,748 [root] DEBUG: 17436: DLL loaded at 0x6F290000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-28 20:55:36,748 [lib.api.process] INFO: Injected into 64-bit <Process 17760 svchost.exe>
2026-05-28 20:55:36,749 [root] DEBUG: 17492: Commandline: C:\Windows\system32\svchost.exe -k UnistackSvcGroup
2026-05-28 20:55:36,750 [root] INFO: Announced 64-bit process name: svchost.exe pid: 17760
2026-05-28 20:55:36,751 [root] DEBUG: 17436: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-28 20:55:36,752 [lib.api.process] INFO: Monitor config for process 17760: C:\rl4cuydm\dll\17760.ini
2026-05-28 20:55:36,753 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,756 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,757 [root] DEBUG: 17436: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-28 20:55:36,758 [root] DEBUG: 17436: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-28 20:55:36,759 [root] DEBUG: 17436: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-28 20:55:36,760 [root] DEBUG: 17492: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:36,767 [root] DEBUG: Loader: Injecting process 17760 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,767 [root] DEBUG: 17436: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-28 20:55:36,768 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17764, handle 0x124
2026-05-28 20:55:36,777 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:36,778 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,780 [lib.api.process] INFO: Injected into 64-bit <Process 17760 svchost.exe>
2026-05-28 20:55:36,782 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:36,783 [root] DEBUG: 17492: set_hooks: Unable to hook LockResource
2026-05-28 20:55:36,789 [root] DEBUG: 17492: Hooked 627 out of 628 functions
2026-05-28 20:55:36,789 [root] DEBUG: 17760: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:36,790 [root] DEBUG: 17492: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:36,790 [root] DEBUG: 17760: Interactive desktop enabled.
2026-05-28 20:55:36,792 [root] DEBUG: 17760: Dropped file limit defaulting to 100.
2026-05-28 20:55:36,792 [root] DEBUG: 17436: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2026-05-28 20:55:36,793 [root] DEBUG: 17760: parent_has_path: unable to open parent process 676
2026-05-28 20:55:36,794 [root] DEBUG: 17436: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-28 20:55:36,795 [root] DEBUG: 17760: Disabling sleep skipping.
2026-05-28 20:55:36,796 [root] DEBUG: 17760: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:36,796 [root] DEBUG: 17492: RestoreHeaders: Restored original import table.
2026-05-28 20:55:36,797 [root] DEBUG: 17436: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-28 20:55:36,798 [root] INFO: Loaded monitor into process with pid 17492
2026-05-28 20:55:36,799 [root] DEBUG: 17436: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-28 20:55:36,799 [root] DEBUG: 17492: caller_dispatch: Added region at 0x00007FF7BF220000 to tracked regions list (kernel32::GetCommandLineW returns to 0x00007FF7BF2250EA, thread 17496).
2026-05-28 20:55:36,800 [root] DEBUG: 17492: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:55:36,803 [root] DEBUG: 17492: ProcessImageBase: Main module image at 0x00007FF7BF220000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:36,804 [root] DEBUG: 17436: DLL loaded at 0x755F0000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-05-28 20:55:36,807 [root] DEBUG: 17492: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:36,808 [root] DEBUG: 17760: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:36,809 [root] DEBUG: 17492: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:36,809 [root] DEBUG: 17760: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:55:36,811 [root] DEBUG: 17760: Monitor initialised: 64-bit capemon loaded in process 17760 at 0x00007FFF1A580000, thread 17764, image base 0x00007FF7BF220000, stack from 0x000000820D274000-0x000000820D280000
2026-05-28 20:55:36,812 [root] DEBUG: 17760: Commandline: C:\Windows\System32\svchost.exe -k NetworkService -p
2026-05-28 20:55:36,812 [root] DEBUG: 17492: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:55:36,823 [root] DEBUG: 17760: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:36,827 [root] INFO: Stopping Task Scheduler Service
2026-05-28 20:55:36,843 [root] INFO: Stopped Task Scheduler Service
2026-05-28 20:55:36,845 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:36,847 [root] DEBUG: 17760: set_hooks: Unable to hook LockResource
2026-05-28 20:55:36,847 [root] INFO: Starting Task Scheduler Service
2026-05-28 20:55:36,851 [root] DEBUG: 17760: Hooked 627 out of 628 functions
2026-05-28 20:55:36,853 [root] DEBUG: 17760: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:36,857 [root] DEBUG: 17760: RestoreHeaders: Restored original import table.
2026-05-28 20:55:36,858 [root] INFO: Started Task Scheduler Service
2026-05-28 20:55:36,858 [root] INFO: Loaded monitor into process with pid 17760
2026-05-28 20:55:36,860 [root] DEBUG: 17760: caller_dispatch: Added region at 0x00007FF7BF220000 to tracked regions list (kernel32::GetCommandLineW returns to 0x00007FF7BF2250EA, thread 17764).
2026-05-28 20:55:36,860 [lib.api.process] INFO: Monitor config for process 1292: C:\rl4cuydm\dll\1292.ini
2026-05-28 20:55:36,861 [root] DEBUG: 17492: DLL loaded at 0x00007FFF57470000: c:\windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:55:36,862 [root] DEBUG: 17760: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:55:36,862 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:36,863 [root] DEBUG: 17492: DLL loaded at 0x00007FFF510D0000: c:\windows\system32\MCCSPal (0xd000 bytes).
2026-05-28 20:55:36,864 [root] DEBUG: 17760: ProcessImageBase: Main module image at 0x00007FF7BF220000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:36,865 [root] DEBUG: 17492: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:55:36,866 [root] DEBUG: 17492: DLL loaded at 0x00007FFF3E730000: c:\windows\system32\VAULTCLI (0x51000 bytes).
2026-05-28 20:55:36,867 [root] DEBUG: 17492: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:55:36,868 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:36,868 [root] DEBUG: 17492: DLL loaded at 0x00007FFF566C0000: c:\windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:36,869 [root] DEBUG: 17760: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:36,871 [root] DEBUG: 17760: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:36,872 [root] DEBUG: 17492: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:55:36,873 [root] DEBUG: Loader: Injecting process 1292 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,873 [root] DEBUG: 17492: DLL loaded at 0x00007FFF57010000: c:\windows\system32\ncrypt (0x27000 bytes).
2026-05-28 20:55:36,874 [root] DEBUG: 17492: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:55:36,875 [root] DEBUG: 17760: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:55:36,876 [root] DEBUG: 1292: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:36,876 [root] DEBUG: 1292: Disabling sleep skipping.
2026-05-28 20:55:36,877 [root] DEBUG: 1292: Interactive desktop enabled.
2026-05-28 20:55:36,878 [root] DEBUG: 17492: DLL loaded at 0x00007FFF4FA10000: c:\windows\system32\tbs (0x1b000 bytes).
2026-05-28 20:55:36,878 [root] DEBUG: 1292: Dropped file limit defaulting to 100.
2026-05-28 20:55:36,881 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFED70000: c:\windows\system32\DMCmnUtils (0x7c000 bytes).
2026-05-28 20:55:36,881 [root] DEBUG: 1292: Services hook set enabled
2026-05-28 20:55:36,883 [root] DEBUG: 17492: DLL loaded at 0x00007FFF523E0000: c:\windows\system32\XmlLite (0x36000 bytes).
2026-05-28 20:55:36,884 [root] DEBUG: 17492: DLL loaded at 0x00007FFF1C370000: c:\windows\system32\dmxmlhelputils (0x1f000 bytes).
2026-05-28 20:55:36,885 [root] DEBUG: 1292: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:36,886 [root] DEBUG: 17492: DLL loaded at 0x00007FFF522D0000: c:\windows\system32\policymanager (0xa1000 bytes).
2026-05-28 20:55:36,886 [root] DEBUG: 17760: DLL loaded at 0x00007FFF510C0000: c:\windows\system32\ZTrace_Maps (0xb000 bytes).
2026-05-28 20:55:36,887 [root] DEBUG: 17492: DLL loaded at 0x00007FFF4F390000: c:\windows\system32\DMCfgUtils (0x20000 bytes).
2026-05-28 20:55:36,887 [root] DEBUG: 17760: DLL loaded at 0x00007FFEFED20000: c:\windows\system32\mapsbtsvc (0x24000 bytes).
2026-05-28 20:55:36,888 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEDF0000: c:\windows\system32\SYNCUTIL (0x65000 bytes).
2026-05-28 20:55:36,889 [root] DEBUG: 17760: DLL loaded at 0x00007FFF4C520000: c:\windows\system32\Bcp47Langs (0x5b000 bytes).
2026-05-28 20:55:36,889 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEE60000: c:\windows\system32\NetworkHelper (0x26000 bytes).
2026-05-28 20:55:36,890 [root] DEBUG: 17492: DLL loaded at 0x00007FFF51580000: c:\windows\system32\UserDataPlatformHelperUtil (0x15000 bytes).
2026-05-28 20:55:36,892 [root] DEBUG: 17760: DLL loaded at 0x00007FFF52560000: c:\windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:55:36,892 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEE90000: c:\windows\system32\aphostservice (0x5c000 bytes).
2026-05-28 20:55:36,893 [root] DEBUG: 17760: DLL loaded at 0x00007FFEFEC70000: c:\windows\system32\MapConfiguration (0x8a000 bytes).
2026-05-28 20:55:36,894 [root] DEBUG: 17760: DLL loaded at 0x00007FFEFED00000: c:\windows\system32\MosStorage (0x1c000 bytes).
2026-05-28 20:55:36,894 [root] DEBUG: 17492: DLL loaded at 0x00007FFF56FD0000: c:\windows\system32\NTASN1 (0x3b000 bytes).
2026-05-28 20:55:36,895 [root] DEBUG: 17760: DLL loaded at 0x00007FFEFED50000: c:\windows\system32\moshost (0x1b000 bytes).
2026-05-28 20:55:36,896 [root] DEBUG: 1292: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:36,898 [root] DEBUG: 1292: Monitor initialised: 64-bit capemon loaded in process 1292 at 0x00007FFF1A580000, thread 17572, image base 0x00007FF7BF220000, stack from 0x000000250E8F4000-0x000000250E900000
2026-05-28 20:55:36,898 [root] DEBUG: 1292: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-05-28 20:55:36,900 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEC50000: c:\windows\system32\InprocLogger (0x14000 bytes).
2026-05-28 20:55:36,903 [root] DEBUG: 17492: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-28 20:55:36,905 [root] DEBUG: 17760: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-28 20:55:36,908 [root] DEBUG: 17492: DLL loaded at 0x00007FFF57560000: c:\windows\system32\profapi (0x25000 bytes).
2026-05-28 20:55:36,913 [root] DEBUG: 1292: Hooked 69 out of 69 functions
2026-05-28 20:55:36,914 [root] INFO: Loaded monitor into process with pid 1292
2026-05-28 20:55:36,915 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:55:36,916 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:36,919 [lib.api.process] INFO: Injected into 64-bit <Process 1292 svchost.exe>
2026-05-28 20:55:36,919 [root] DEBUG: 17760: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:55:36,922 [root] DEBUG: 17760: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:55:36,926 [root] DEBUG: 17760: DLL loaded at 0x00007FFF57560000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 20:55:36,943 [root] DEBUG: 17492: DLL loaded at 0x00007FFF40A10000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 20:55:36,949 [root] DEBUG: 17492: DLL loaded at 0x00007FFF42490000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:55:36,959 [root] DEBUG: 17492: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:55:36,968 [root] DEBUG: 17492: DLL loaded at 0x00007FFF4D6A0000: c:\windows\system32\iertutil (0x2bc000 bytes).
2026-05-28 20:55:36,977 [root] DEBUG: 17492: DLL loaded at 0x00007FFF56D70000: C:\Windows\system32\cryptdll (0x15000 bytes).
2026-05-28 20:55:36,978 [root] DEBUG: 17492: DLL loaded at 0x00007FFF56C50000: C:\Windows\system32\NtlmShared (0x14000 bytes).
2026-05-28 20:55:36,979 [root] DEBUG: 17492: DLL loaded at 0x00007FFF56C70000: C:\Windows\system32\msv1_0 (0x8c000 bytes).
2026-05-28 20:55:36,991 [root] DEBUG: 17492: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:55:36,991 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEAB0000: C:\Windows\System32\PIMSTORE (0xf5000 bytes).
2026-05-28 20:55:36,992 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEA90000: C:\Windows\System32\APHostClient (0x17000 bytes).
2026-05-28 20:55:36,993 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFE9C0000: C:\Windows\System32\CEMAPI (0x44000 bytes).
2026-05-28 20:55:36,994 [root] DEBUG: 17492: DLL loaded at 0x00007FFF4D250000: C:\Windows\System32\UserDataLanguageUtil (0x10000 bytes).
2026-05-28 20:55:36,996 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFE9A0000: C:\Windows\System32\UserDataTypeHelperUtil (0x11000 bytes).
2026-05-28 20:55:36,997 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFE940000: C:\Windows\System32\PhoneUtil (0x5e000 bytes).
2026-05-28 20:55:36,997 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEA10000: C:\Windows\System32\MCCSEngineShared (0x30000 bytes).
2026-05-28 20:55:36,998 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEA40000: C:\Windows\System32\AccountAccessor (0x47000 bytes).
2026-05-28 20:55:36,999 [root] DEBUG: 17492: DLL loaded at 0x00007FFF4D2D0000: C:\Windows\System32\dsclient (0xf000 bytes).
2026-05-28 20:55:37,000 [root] DEBUG: 17492: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:55:37,001 [root] DEBUG: 17492: DLL loaded at 0x00007FFF52220000: C:\Windows\System32\SystemEventsBrokerClient (0xd000 bytes).
2026-05-28 20:55:37,002 [root] DEBUG: 17492: DLL loaded at 0x00007FFEFEBB0000: C:\Windows\System32\SyncController (0x9c000 bytes).
2026-05-28 20:55:37,007 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 18488: C:\Windows\system32\SgrmBroker.exe, ImageBase: 0x0000000000000000
2026-05-28 20:55:37,008 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 18492
2026-05-28 20:55:37,008 [root] INFO: Announced 64-bit process name: SgrmBroker.exe pid: 18488
2026-05-28 20:55:37,009 [lib.api.process] INFO: Monitor config for process 18488: C:\rl4cuydm\dll\18488.ini
2026-05-28 20:55:37,011 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:37,015 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:37,019 [root] DEBUG: Loader: Injecting process 18488 (thread 18492) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:37,021 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\18488.ini to system path C:\18488.ini
2026-05-28 20:55:37,022 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 18488 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:55:37,023 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:37,025 [lib.api.process] INFO: Injected into 64-bit <Process 18488 SgrmBroker.exe>
2026-05-28 20:55:37,027 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 18492
2026-05-28 20:55:37,027 [root] INFO: Announced 64-bit process name: SgrmBroker.exe pid: 18488
2026-05-28 20:55:37,029 [lib.api.process] INFO: Monitor config for process 18488: C:\rl4cuydm\dll\18488.ini
2026-05-28 20:55:37,029 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:37,030 [root] DEBUG: 17492: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:55:37,032 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:37,038 [root] DEBUG: Loader: Injecting process 18488 (thread 18492) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:37,039 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\18488.ini to system path C:\18488.ini
2026-05-28 20:55:37,041 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 18488 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:55:37,042 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:37,043 [root] DEBUG: 17492: DLL loaded at 0x00007FFF46AE0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 20:55:37,044 [lib.api.process] INFO: Injected into 64-bit <Process 18488 SgrmBroker.exe>
2026-05-28 20:55:37,045 [root] INFO: Announced 64-bit process name: SgrmBroker.exe pid: 18488
2026-05-28 20:55:37,046 [lib.api.process] INFO: Monitor config for process 18488: C:\rl4cuydm\dll\18488.ini
2026-05-28 20:55:37,046 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:37,050 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:37,054 [root] DEBUG: 17492: DLL loaded at 0x00007FFF55410000: C:\Windows\SYSTEM32\rmclient (0x2a000 bytes).
2026-05-28 20:55:37,056 [root] DEBUG: Loader: Injecting process 18488 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:37,058 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\18488.ini to system path C:\18488.ini
2026-05-28 20:55:37,059 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 18488 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:55:37,060 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:37,061 [lib.api.process] INFO: Injected into 64-bit <Process 18488 SgrmBroker.exe>
2026-05-28 20:55:37,061 [root] INFO: Announced starting service "b'VaultSvc'"
2026-05-28 20:55:37,196 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 18868: C:\Windows\system32\sppsvc.exe, ImageBase: 0x0000000000000000
2026-05-28 20:55:37,198 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 18872
2026-05-28 20:55:37,198 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 18868
2026-05-28 20:55:37,199 [lib.api.process] INFO: Monitor config for process 18868: C:\rl4cuydm\dll\18868.ini
2026-05-28 20:55:38,068 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 18936: C:\Windows\system32\lsass.exe, ImageBase: 0x00007FF6AE920000
2026-05-28 20:55:38,070 [root] INFO: Announced 64-bit process name: lsass.exe pid: 18936
2026-05-28 20:55:38,070 [lib.api.process] INFO: Monitor config for process 18936: C:\rl4cuydm\dll\18936.ini
2026-05-28 20:55:38,071 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,076 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,081 [root] DEBUG: Loader: Injecting process 18936 (thread 18940) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,081 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:38,082 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,084 [lib.api.process] INFO: Injected into 64-bit <Process 18936 lsass.exe>
2026-05-28 20:55:38,086 [root] INFO: Announced 64-bit process name: lsass.exe pid: 18936
2026-05-28 20:55:38,086 [lib.api.process] INFO: Monitor config for process 18936: C:\rl4cuydm\dll\18936.ini
2026-05-28 20:55:38,087 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,091 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,097 [root] DEBUG: Loader: Injecting process 18936 (thread 18940) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,098 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:38,099 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,100 [lib.api.process] INFO: Injected into 64-bit <Process 18936 lsass.exe>
2026-05-28 20:55:38,102 [root] INFO: Announced 64-bit process name: lsass.exe pid: 18936
2026-05-28 20:55:38,103 [lib.api.process] INFO: Monitor config for process 18936: C:\rl4cuydm\dll\18936.ini
2026-05-28 20:55:38,103 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,108 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,112 [root] DEBUG: Loader: Injecting process 18936 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,113 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 18940, handle 0x120
2026-05-28 20:55:38,114 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:38,115 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,116 [lib.api.process] INFO: Injected into 64-bit <Process 18936 lsass.exe>
2026-05-28 20:55:38,123 [root] DEBUG: 18936: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:38,124 [root] DEBUG: 18936: Interactive desktop enabled.
2026-05-28 20:55:38,124 [root] DEBUG: 18936: Dropped file limit defaulting to 100.
2026-05-28 20:55:38,126 [root] DEBUG: 18936: Disabling sleep skipping.
2026-05-28 20:55:38,127 [root] DEBUG: 18936: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:38,139 [root] DEBUG: 18936: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:38,140 [root] DEBUG: 18936: YaraScan: Scanning 0x00007FF6AE920000, size 0x111fe
2026-05-28 20:55:38,141 [root] DEBUG: 18936: Monitor initialised: 64-bit capemon loaded in process 18936 at 0x00007FFF1A580000, thread 18940, image base 0x00007FF6AE920000, stack from 0x0000000A09E74000-0x0000000A09E80000
2026-05-28 20:55:38,142 [root] DEBUG: 18936: Commandline: C:\Windows\system32\lsass.exe
2026-05-28 20:55:38,153 [root] DEBUG: 18936: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:38,175 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:38,176 [root] DEBUG: 18936: set_hooks: Unable to hook LockResource
2026-05-28 20:55:38,181 [root] DEBUG: 18936: Hooked 627 out of 628 functions
2026-05-28 20:55:38,182 [root] DEBUG: 18936: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:38,187 [root] DEBUG: 18936: RestoreHeaders: Restored original import table.
2026-05-28 20:55:38,188 [root] INFO: Loaded monitor into process with pid 18936
2026-05-28 20:55:38,188 [root] DEBUG: 18936: caller_dispatch: Added region at 0x00007FF6AE920000 to tracked regions list (kernel32::SetErrorMode returns to 0x00007FF6AE9221F4, thread 18940).
2026-05-28 20:55:38,189 [root] DEBUG: 18936: YaraScan: Scanning 0x00007FF6AE920000, size 0x111fe
2026-05-28 20:55:38,191 [root] DEBUG: 18936: ProcessImageBase: Main module image at 0x00007FF6AE920000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:38,208 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,210 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF1E0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 20:55:38,211 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF1E0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 20:55:38,213 [root] DEBUG: 4484: DLL loaded at 0x00007FFF48A40000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 20:55:38,213 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,214 [root] DEBUG: 4484: DLL loaded at 0x00007FFF48A40000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 20:55:38,218 [root] DEBUG: Loader: Injecting process 18868 (thread 18872) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,219 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\18868.ini to system path C:\18868.ini
2026-05-28 20:55:38,221 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF1C0000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 20:55:38,221 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 18868 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:55:38,222 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF1C0000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 20:55:38,223 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,226 [lib.api.process] INFO: Injected into 64-bit <Process 18868 sppsvc.exe>
2026-05-28 20:55:38,228 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 18872
2026-05-28 20:55:38,228 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 18868
2026-05-28 20:55:38,228 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F490000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 20:55:38,228 [lib.api.process] INFO: Monitor config for process 18868: C:\rl4cuydm\dll\18868.ini
2026-05-28 20:55:38,229 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F490000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 20:55:38,229 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,230 [root] DEBUG: 4484: DLL loaded at 0x00007FFF55330000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:55:38,231 [root] DEBUG: 4484: DLL loaded at 0x00007FFF55330000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:55:38,233 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFE680000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 20:55:38,234 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFE680000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 20:55:38,236 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,241 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF1A0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 20:55:38,242 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF1A0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 20:55:38,242 [root] DEBUG: Loader: Injecting process 18868 (thread 18872) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,244 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\18868.ini to system path C:\18868.ini
2026-05-28 20:55:38,246 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 18868 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:55:38,247 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,250 [root] DEBUG: 6632: OpenProcessHandler: Injection info created for process 19216, handle 0x314: C:\rl4cuydm\bin\PPLinject64.exe
2026-05-28 20:55:38,251 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF3C0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 20:55:38,251 [lib.api.process] INFO: Injected into 64-bit <Process 18868 sppsvc.exe>
2026-05-28 20:55:38,252 [root] DEBUG: 6632: OpenProcessHandler: Image base for process 19216 (handle 0x314): 0x00007FF7521A0000.
2026-05-28 20:55:38,253 [root] DEBUG: 4484: DLL loaded at 0x00007FFEFF3C0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 20:55:38,256 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 18868
2026-05-28 20:55:38,257 [root] DEBUG: 6632: CreateProcessHandler: Injection info set for new process 19416: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:55:38,257 [lib.api.process] INFO: Monitor config for process 18868: C:\rl4cuydm\dll\18868.ini
2026-05-28 20:55:38,258 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 19416
2026-05-28 20:55:38,258 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,259 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 19416
2026-05-28 20:55:38,261 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,269 [root] DEBUG: Loader: Injecting process 18868 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,272 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\18868.ini to system path C:\18868.ini
2026-05-28 20:55:38,275 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 18868 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:55:38,278 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,279 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,280 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,287 [lib.api.process] INFO: Injected into 64-bit <Process 18868 sppsvc.exe>
2026-05-28 20:55:38,287 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,289 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,293 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,294 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,310 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,311 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,315 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,316 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,320 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,322 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,342 [root] DEBUG: 6632: CreateProcessHandler: Injection info set for new process 18712: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:55:38,343 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 18712
2026-05-28 20:55:38,344 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 18712
2026-05-28 20:55:38,355 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 18712, handle 0x1120: C:\Windows\System32\WerFault.exe
2026-05-28 20:55:38,444 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 18776: C:\Windows\system32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:55:38,445 [root] INFO: Announced 64-bit process name: svchost.exe pid: 18776
2026-05-28 20:55:38,446 [lib.api.process] INFO: Monitor config for process 18776: C:\rl4cuydm\dll\18776.ini
2026-05-28 20:55:38,447 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,451 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,457 [root] DEBUG: Loader: Injecting process 18776 (thread 18824) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,459 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:38,459 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,460 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,461 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,463 [lib.api.process] INFO: Injected into 64-bit <Process 18776 svchost.exe>
2026-05-28 20:55:38,464 [root] INFO: Announced 64-bit process name: svchost.exe pid: 18776
2026-05-28 20:55:38,465 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,466 [lib.api.process] INFO: Monitor config for process 18776: C:\rl4cuydm\dll\18776.ini
2026-05-28 20:55:38,466 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,467 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,470 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,471 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,473 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,479 [root] DEBUG: Loader: Injecting process 18776 (thread 18824) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,480 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WEREBB5.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WEREBB5.tmp'
2026-05-28 20:55:38,481 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:38,482 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,483 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WEREBB5.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WEREBB5.tmp'
2026-05-28 20:55:38,483 [lib.api.process] INFO: Injected into 64-bit <Process 18776 svchost.exe>
2026-05-28 20:55:38,484 [root] INFO: Announced 64-bit process name: svchost.exe pid: 18776
2026-05-28 20:55:38,485 [lib.api.process] INFO: Monitor config for process 18776: C:\rl4cuydm\dll\18776.ini
2026-05-28 20:55:38,486 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,493 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,498 [root] DEBUG: Loader: Injecting process 18776 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,499 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 18824, handle 0xe8
2026-05-28 20:55:38,500 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:38,500 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,502 [lib.api.process] INFO: Injected into 64-bit <Process 18776 svchost.exe>
2026-05-28 20:55:38,514 [root] DEBUG: 18776: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:38,515 [root] DEBUG: 18776: Interactive desktop enabled.
2026-05-28 20:55:38,516 [root] DEBUG: 18776: Dropped file limit defaulting to 100.
2026-05-28 20:55:38,517 [root] DEBUG: 18776: Disabling sleep skipping.
2026-05-28 20:55:38,519 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WEREBB5.tmp.csv
2026-05-28 20:55:38,520 [root] DEBUG: 18776: Services hook set enabled
2026-05-28 20:55:38,523 [root] DEBUG: 18776: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:38,525 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,526 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,530 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,531 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,534 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,535 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,535 [root] DEBUG: 18776: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:38,536 [root] DEBUG: 18776: Monitor initialised: 64-bit capemon loaded in process 18776 at 0x00007FFF1A580000, thread 18824, image base 0x00007FF7BF220000, stack from 0x000000B2F04D4000-0x000000B2F04E0000
2026-05-28 20:55:38,537 [root] DEBUG: 18776: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s UsoSvc
2026-05-28 20:55:38,543 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WEREBF4.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WEREBF4.tmp'
2026-05-28 20:55:38,544 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WEREBF4.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WEREBF4.tmp'
2026-05-28 20:55:38,550 [root] DEBUG: 18776: Hooked 69 out of 69 functions
2026-05-28 20:55:38,552 [root] DEBUG: 18776: RestoreHeaders: Restored original import table.
2026-05-28 20:55:38,552 [root] INFO: Loaded monitor into process with pid 18776
2026-05-28 20:55:38,554 [root] DEBUG: 18776: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:38,555 [root] DEBUG: 18776: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:38,557 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WEREBF4.tmp.txt
2026-05-28 20:55:38,557 [root] DEBUG: 18776: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:55:38,562 [root] DEBUG: 18776: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:55:38,564 [root] DEBUG: 18776: DLL loaded at 0x00007FFF57470000: c:\windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:55:38,566 [root] DEBUG: 18776: DLL loaded at 0x00007FFF57560000: c:\windows\system32\profapi (0x25000 bytes).
2026-05-28 20:55:38,569 [root] DEBUG: 18776: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:55:38,570 [root] DEBUG: 18776: DLL loaded at 0x00007FFF4F590000: c:\windows\system32\Cabinet (0x29000 bytes).
2026-05-28 20:55:38,571 [root] DEBUG: 18776: DLL loaded at 0x00007FFF57520000: c:\windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:55:38,573 [root] DEBUG: 18776: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:55:38,574 [root] DEBUG: 18776: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:55:38,575 [root] DEBUG: 18776: DLL loaded at 0x00007FFF3EE40000: c:\windows\system32\UpdatePolicy (0x43000 bytes).
2026-05-28 20:55:38,575 [root] DEBUG: 18776: DLL loaded at 0x00007FFEFE250000: c:\windows\system32\usosvc (0x91000 bytes).
2026-05-28 20:55:38,576 [root] DEBUG: 18776: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 20:55:38,579 [root] DEBUG: 18776: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-28 20:55:38,608 [root] DEBUG: 6632: OpenProcessHandler: Injection info created for process 18776, handle 0x338: C:\Windows\System32\svchost.exe
2026-05-28 20:55:38,609 [root] DEBUG: 6632: OpenProcessHandler: Image base for process 18776 (handle 0x338): 0x00007FF7BF220000.
2026-05-28 20:55:38,610 [root] DEBUG: 6632: CreateProcessHandler: Injection info set for new process 1580: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:55:38,612 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 1580
2026-05-28 20:55:38,613 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 1580
2026-05-28 20:55:38,636 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,638 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,642 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,643 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,646 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,647 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,661 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,663 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,666 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,667 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,672 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,674 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,692 [root] DEBUG: 6632: CreateProcessHandler: Injection info set for new process 2596: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:55:38,693 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 2596
2026-05-28 20:55:38,694 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 2596
2026-05-28 20:55:38,822 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,824 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,827 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,828 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,832 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,833 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,840 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERED1E.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERED1E.tmp'
2026-05-28 20:55:38,841 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERED1E.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERED1E.tmp'
2026-05-28 20:55:38,865 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WERED1E.tmp.csv
2026-05-28 20:55:38,871 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,872 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,876 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,877 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,881 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:38,883 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:38,895 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERED4E.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERED4E.tmp'
2026-05-28 20:55:38,896 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERED4E.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERED4E.tmp'
2026-05-28 20:55:38,902 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WERED4E.tmp.txt
2026-05-28 20:55:38,928 [root] DEBUG: 17436: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-28 20:55:38,931 [root] DEBUG: 17436: DLL loaded at 0x6ED50000: C:\Windows\System32\taskschd (0x7d000 bytes).
2026-05-28 20:55:38,946 [root] DEBUG: 1292: CreateProcessHandler: Injection info set for new process 19592: C:\Windows\system32\taskhostw.exe, ImageBase: 0x00007FF688270000
2026-05-28 20:55:38,946 [root] DEBUG: 1292: CreateProcessHandler: Injection info set for new process 19604: C:\Windows\system32\wermgr.exe, ImageBase: 0x00007FF75CBF0000
2026-05-28 20:55:38,948 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 19592
2026-05-28 20:55:38,949 [lib.api.process] INFO: Monitor config for process 19592: C:\rl4cuydm\dll\19592.ini
2026-05-28 20:55:38,949 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 19604
2026-05-28 20:55:38,950 [lib.api.process] INFO: Monitor config for process 19604: C:\rl4cuydm\dll\19604.ini
2026-05-28 20:55:38,951 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,953 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,955 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,957 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,959 [root] DEBUG: 17436: NtTerminateProcess hook: Attempting to dump process 17436
2026-05-28 20:55:38,960 [root] DEBUG: 17436: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:55:38,960 [root] DEBUG: Loader: Injecting process 19604 (thread 19608) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,961 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:38,962 [root] DEBUG: Loader: Injecting process 19592 (thread 19596) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,962 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,963 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:38,964 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,964 [lib.api.process] INFO: Injected into 64-bit <Process 19604 wermgr.exe>
2026-05-28 20:55:38,964 [root] INFO: Process with pid 17436 has terminated
2026-05-28 20:55:38,965 [lib.api.process] INFO: Injected into 64-bit <Process 19592 taskhostw.exe>
2026-05-28 20:55:38,966 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 19604
2026-05-28 20:55:38,967 [lib.api.process] INFO: Monitor config for process 19604: C:\rl4cuydm\dll\19604.ini
2026-05-28 20:55:38,967 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,968 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 19592
2026-05-28 20:55:38,969 [lib.api.process] INFO: Monitor config for process 19592: C:\rl4cuydm\dll\19592.ini
2026-05-28 20:55:38,969 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,973 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,974 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,977 [root] DEBUG: Loader: Injecting process 19604 (thread 19608) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,978 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:38,980 [root] DEBUG: Loader: Injecting process 19592 (thread 19596) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,980 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,981 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:55:38,982 [lib.api.process] INFO: Injected into 64-bit <Process 19604 wermgr.exe>
2026-05-28 20:55:38,982 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:38,984 [root] INFO: Announced 64-bit process name: wermgr.exe pid: 19604
2026-05-28 20:55:38,984 [lib.api.process] INFO: Injected into 64-bit <Process 19592 taskhostw.exe>
2026-05-28 20:55:38,984 [lib.api.process] INFO: Monitor config for process 19604: C:\rl4cuydm\dll\19604.ini
2026-05-28 20:55:38,986 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,986 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 19592
2026-05-28 20:55:38,989 [lib.api.process] INFO: Monitor config for process 19592: C:\rl4cuydm\dll\19592.ini
2026-05-28 20:55:38,990 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:55:38,994 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,995 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:55:38,999 [root] DEBUG: Loader: Injecting process 19604 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:39,000 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 19608, handle 0xfc
2026-05-28 20:55:39,000 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:39,001 [root] DEBUG: Loader: Injecting process 19592 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:39,002 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:39,002 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 19596, handle 0x124
2026-05-28 20:55:39,003 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:55:39,003 [lib.api.process] INFO: Injected into 64-bit <Process 19604 wermgr.exe>
2026-05-28 20:55:39,004 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:55:39,006 [lib.api.process] INFO: Injected into 64-bit <Process 19592 taskhostw.exe>
2026-05-28 20:55:39,011 [root] DEBUG: 19604: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:39,012 [root] DEBUG: 19604: Interactive desktop enabled.
2026-05-28 20:55:39,013 [root] DEBUG: 19604: Dropped file limit defaulting to 100.
2026-05-28 20:55:39,015 [root] DEBUG: 19592: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:55:39,016 [root] DEBUG: 19592: Interactive desktop enabled.
2026-05-28 20:55:39,017 [root] DEBUG: 19592: Dropped file limit defaulting to 100.
2026-05-28 20:55:39,019 [root] DEBUG: 19592: Disabling sleep skipping.
2026-05-28 20:55:39,021 [root] DEBUG: 19592: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:39,023 [root] DEBUG: 19604: Disabling sleep skipping.
2026-05-28 20:55:39,024 [root] DEBUG: 19604: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:55:39,034 [root] DEBUG: 19592: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:39,035 [root] DEBUG: 19592: YaraScan: Scanning 0x00007FF688270000, size 0x192fc
2026-05-28 20:55:39,037 [root] DEBUG: 19592: Monitor initialised: 64-bit capemon loaded in process 19592 at 0x00007FFF1A580000, thread 19596, image base 0x00007FF688270000, stack from 0x000000A6DD6C4000-0x000000A6DD6D0000
2026-05-28 20:55:39,038 [root] DEBUG: 19604: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:55:39,039 [root] DEBUG: 19592: Commandline: taskhostw.exe
2026-05-28 20:55:39,040 [root] DEBUG: 19604: YaraScan: Scanning 0x00007FF75CBF0000, size 0x3f17e
2026-05-28 20:55:39,043 [root] DEBUG: 19604: Monitor initialised: 64-bit capemon loaded in process 19604 at 0x00007FFF1A580000, thread 19608, image base 0x00007FF75CBF0000, stack from 0x0000004CB7474000-0x0000004CB7480000
2026-05-28 20:55:39,043 [root] DEBUG: 19604: Commandline: "C:\Windows\system32\wermgr.exe" -upload
2026-05-28 20:55:39,054 [root] DEBUG: 19592: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:39,056 [root] DEBUG: 19604: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:55:39,078 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:39,079 [root] DEBUG: 19592: set_hooks: Unable to hook LockResource
2026-05-28 20:55:39,081 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:55:39,082 [root] DEBUG: 19604: set_hooks: Unable to hook LockResource
2026-05-28 20:55:39,084 [root] DEBUG: 19592: Hooked 627 out of 628 functions
2026-05-28 20:55:39,085 [root] DEBUG: 19592: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:39,087 [root] DEBUG: 19604: Hooked 627 out of 628 functions
2026-05-28 20:55:39,090 [root] DEBUG: 19604: Syscall hook installed, syscall logging level 1
2026-05-28 20:55:39,090 [root] DEBUG: 19592: RestoreHeaders: Restored original import table.
2026-05-28 20:55:39,091 [root] INFO: Loaded monitor into process with pid 19592
2026-05-28 20:55:39,092 [root] DEBUG: 19592: caller_dispatch: Added region at 0x00007FF688270000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF688275CA1, thread 19596).
2026-05-28 20:55:39,093 [root] DEBUG: 19592: YaraScan: Scanning 0x00007FF688270000, size 0x192fc
2026-05-28 20:55:39,094 [root] DEBUG: 19604: RestoreHeaders: Restored original import table.
2026-05-28 20:55:39,095 [root] DEBUG: 19592: ProcessImageBase: Main module image at 0x00007FF688270000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:39,096 [root] INFO: Loaded monitor into process with pid 19604
2026-05-28 20:55:39,097 [root] DEBUG: 19592: DLL loaded at 0x00007FFF58180000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-05-28 20:55:39,098 [root] DEBUG: 19604: caller_dispatch: Added region at 0x00007FF75CBF0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF75CC09181, thread 19608).
2026-05-28 20:55:39,100 [root] DEBUG: 19604: YaraScan: Scanning 0x00007FF75CBF0000, size 0x3f17e
2026-05-28 20:55:39,101 [root] DEBUG: 19592: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:39,102 [root] DEBUG: 19592: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:39,103 [root] DEBUG: 19604: ProcessImageBase: Main module image at 0x00007FF75CBF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:55:39,106 [root] DEBUG: 19604: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\Comctl32 (0x29a000 bytes).
2026-05-28 20:55:39,108 [root] DEBUG: 19592: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:55:39,111 [root] DEBUG: 19592: DLL loaded at 0x00007FFEFE200000: C:\Windows\System32\fcon (0x45000 bytes).
2026-05-28 20:55:39,114 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,115 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,118 [root] DEBUG: 19592: DLL loaded at 0x00007FFF566C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,119 [root] DEBUG: 19592: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,120 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,121 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,125 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,126 [root] DEBUG: 19592: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:55:39,127 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,128 [root] DEBUG: 19592: DLL loaded at 0x00007FFEFE1B0000: C:\Windows\System32\wosc (0x4e000 bytes).
2026-05-28 20:55:39,133 [root] DEBUG: 19592: DLL loaded at 0x00007FFF40A10000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-05-28 20:55:39,135 [root] DEBUG: 19592: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:55:39,137 [root] DEBUG: 19592: DLL loaded at 0x00007FFF42490000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-28 20:55:39,138 [root] DEBUG: 19604: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:55:39,145 [root] DEBUG: 19592: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:55:39,147 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,148 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,152 [root] DEBUG: 19592: DLL loaded at 0x00007FFF52DC0000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-28 20:55:39,152 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,153 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,155 [root] DEBUG: 19592: DLL loaded at 0x00007FFF569F0000: C:\Windows\System32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:55:39,156 [root] DEBUG: 19592: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:55:39,158 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,158 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,161 [root] DEBUG: 19592: DLL loaded at 0x00007FFF40900000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-05-28 20:55:39,166 [root] DEBUG: 19592: DLL loaded at 0x00007FFF57560000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-28 20:55:39,167 [root] DEBUG: 19592: DLL loaded at 0x00007FFF4F590000: C:\Windows\System32\Cabinet (0x29000 bytes).
2026-05-28 20:55:39,168 [root] DEBUG: 19592: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:55:39,170 [root] DEBUG: 19592: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:55:39,171 [root] DEBUG: 19592: DLL loaded at 0x00007FFF3EE40000: C:\Windows\System32\UpdatePolicy (0x43000 bytes).
2026-05-28 20:55:39,172 [root] DEBUG: 19592: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 20:55:39,180 [root] DEBUG: 19592: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:55:39,181 [root] DEBUG: 19592: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:55:39,184 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,186 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,189 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,190 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,196 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,198 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,202 [root] DEBUG: 19604: DLL loaded at 0x00007FFF58180000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-05-28 20:55:39,206 [root] DEBUG: 19604: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:55:39,207 [root] DEBUG: 19604: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:55:39,210 [root] DEBUG: 19604: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 20:55:39,214 [root] DEBUG: 19592: NtTerminateProcess hook: Attempting to dump process 19592
2026-05-28 20:55:39,215 [root] DEBUG: 19592: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:55:39,218 [root] DEBUG: 19604: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 20:55:39,225 [root] INFO: Process with pid 19592 has terminated
2026-05-28 20:55:39,229 [root] INFO: Process with pid 19592 has terminated
2026-05-28 20:55:39,229 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,230 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,234 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,235 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,240 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,241 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,249 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,251 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,255 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,256 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,260 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,260 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,271 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,273 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,278 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,279 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,283 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,284 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,293 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,294 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,297 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,299 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,303 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,305 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,324 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,327 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,331 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,332 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,336 [root] DEBUG: 19604: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:55:39,337 [root] DEBUG: 19604: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:55:39,345 [root] DEBUG: 19604: NtTerminateProcess hook: Attempting to dump process 19604
2026-05-28 20:55:39,346 [root] DEBUG: 19604: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:55:39,354 [root] INFO: Process with pid 19604 has terminated
2026-05-28 20:55:39,358 [root] INFO: Process with pid 19604 has terminated
2026-05-28 20:55:39,986 [root] INFO: Added new file to list with pid 18776 and path C:\ProgramData\USOShared\Logs\System\UpdateSessionOrchestration.765a23ad-7bf1-41a6-82e7-fa68c970a3a3.1.etl
2026-05-28 20:55:39,988 [root] INFO: Process with pid 18776 has terminated
2026-05-28 20:55:39,990 [root] DEBUG: 18776: NtTerminateProcess hook: Attempting to dump process 18776
2026-05-28 20:55:39,992 [root] DEBUG: 18776: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:55:40,790 [root] DEBUG: 4484: api-cap: NtSetInformationThread hook disabled due to count: 5000
2026-05-28 20:55:41,291 [root] INFO: Process with pid 16152 has terminated
2026-05-28 20:55:41,292 [root] DEBUG: 16152: NtTerminateProcess hook: Attempting to dump process 16152
2026-05-28 20:55:41,293 [root] DEBUG: 16152: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:55:46,918 [root] INFO: Process with pid 17760 has terminated
2026-05-28 20:55:46,920 [root] DEBUG: 17760: NtTerminateProcess hook: Attempting to dump process 17760
2026-05-28 20:55:46,921 [root] DEBUG: 17760: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:56:08,115 [root] INFO: Process with pid 18936 has terminated
2026-05-28 20:56:08,196 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 19216: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:56:08,198 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 19288
2026-05-28 20:56:08,199 [root] INFO: Announced 64-bit process name: svchost.exe pid: 19216
2026-05-28 20:56:08,199 [lib.api.process] INFO: Monitor config for process 19216: C:\rl4cuydm\dll\19216.ini
2026-05-28 20:56:08,202 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:08,209 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:08,214 [root] DEBUG: Loader: Injecting process 19216 (thread 19288) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:08,216 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\19216.ini to system path C:\19216.ini
2026-05-28 20:56:08,218 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 19216 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:56:08,219 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:08,221 [lib.api.process] INFO: Injected into 64-bit <Process 19216 svchost.exe>
2026-05-28 20:56:08,222 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 19288
2026-05-28 20:56:08,223 [root] INFO: Announced 64-bit process name: svchost.exe pid: 19216
2026-05-28 20:56:08,224 [lib.api.process] INFO: Monitor config for process 19216: C:\rl4cuydm\dll\19216.ini
2026-05-28 20:56:08,225 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:08,232 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:08,237 [root] DEBUG: Loader: Injecting process 19216 (thread 19288) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:08,239 [root] DEBUG: 6632: OpenProcessHandler: Injection info created for process 19488, handle 0x304: C:\rl4cuydm\bin\PPLinject64.exe
2026-05-28 20:56:08,240 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\19216.ini to system path C:\19216.ini
2026-05-28 20:56:08,242 [root] DEBUG: 6632: OpenProcessHandler: Image base for process 19488 (handle 0x304): 0x00007FF7521A0000.
2026-05-28 20:56:08,243 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 19216 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:56:08,244 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:08,244 [root] DEBUG: 6632: CreateProcessHandler: Injection info set for new process 8636: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:56:08,246 [lib.api.process] INFO: Injected into 64-bit <Process 19216 svchost.exe>
2026-05-28 20:56:08,247 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 8636
2026-05-28 20:56:08,248 [root] INFO: Announced 64-bit process name: svchost.exe pid: 19216
2026-05-28 20:56:08,250 [lib.api.process] INFO: Monitor config for process 19216: C:\rl4cuydm\dll\19216.ini
2026-05-28 20:56:08,250 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 8636
2026-05-28 20:56:08,250 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:08,257 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:08,267 [root] DEBUG: Loader: Injecting process 19216 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:08,269 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,270 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\19216.ini to system path C:\19216.ini
2026-05-28 20:56:08,272 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,272 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 19216 C:\rl4cuydm\dll\FRqkFpQ.dll
2026-05-28 20:56:08,274 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:08,275 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,277 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,277 [lib.api.process] INFO: Injected into 64-bit <Process 19216 svchost.exe>
2026-05-28 20:56:08,281 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,282 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,300 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,302 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,305 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,306 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,310 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,312 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,332 [root] DEBUG: 6632: CreateProcessHandler: Injection info set for new process 1732: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:56:08,334 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 1732
2026-05-28 20:56:08,336 [root] DEBUG: 6632: ProcessMessage: Skipping monitoring process 1732
2026-05-28 20:56:08,344 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 1732, handle 0x2794: C:\Windows\System32\WerFault.exe
2026-05-28 20:56:08,426 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,427 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,432 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,434 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,438 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,439 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,447 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER60C9.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER60C9.tmp'
2026-05-28 20:56:08,449 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER60C9.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER60C9.tmp'
2026-05-28 20:56:08,472 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER60C9.tmp.csv
2026-05-28 20:56:08,478 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,480 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,484 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,485 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,489 [root] DEBUG: 6632: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:56:08,492 [root] DEBUG: 6632: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:56:08,500 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER60F9.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER60F9.tmp'
2026-05-28 20:56:08,502 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER60F9.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER60F9.tmp'
2026-05-28 20:56:08,507 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER60F9.tmp.txt
2026-05-28 20:56:09,869 [root] DEBUG: 4484: api-cap: NtReadFile hook disabled due to count: 5000
2026-05-28 20:56:12,742 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 6800: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:56:12,743 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 6800
2026-05-28 20:56:12,745 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 6800
2026-05-28 20:56:46,711 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 5244: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:56:46,712 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 5244
2026-05-28 20:56:46,713 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 5244
2026-05-28 20:56:47,547 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 5776: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe, ImageBase: 0x00007FF6C0120000
2026-05-28 20:56:47,549 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 5776
2026-05-28 20:56:47,552 [lib.api.process] INFO: Monitor config for process 5776: C:\rl4cuydm\dll\5776.ini
2026-05-28 20:56:47,555 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:47,704 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 19784: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:56:47,709 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 19784
2026-05-28 20:56:47,735 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 19784
2026-05-28 20:56:48,928 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:48,933 [root] DEBUG: Loader: Injecting process 5776 (thread 5860) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:48,936 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:56:48,941 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:48,944 [lib.api.process] INFO: Injected into 64-bit <Process 5776 TextInputHost.exe>
2026-05-28 20:56:48,947 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 5776
2026-05-28 20:56:48,948 [lib.api.process] INFO: Monitor config for process 5776: C:\rl4cuydm\dll\5776.ini
2026-05-28 20:56:48,949 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:50,052 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:50,062 [root] DEBUG: Loader: Injecting process 5776 (thread 5860) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:50,071 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:56:50,072 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:50,075 [lib.api.process] INFO: Injected into 64-bit <Process 5776 TextInputHost.exe>
2026-05-28 20:56:50,077 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 5776
2026-05-28 20:56:50,078 [lib.api.process] INFO: Monitor config for process 5776: C:\rl4cuydm\dll\5776.ini
2026-05-28 20:56:50,079 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:51,773 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:51,778 [root] DEBUG: Loader: Injecting process 5776 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:51,779 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 5860, handle 0x120
2026-05-28 20:56:51,781 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:56:51,783 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:51,784 [lib.api.process] INFO: Injected into 64-bit <Process 5776 TextInputHost.exe>
2026-05-28 20:56:51,942 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 18756, handle 0x1aa8: C:\Windows\System32\rundll32.exe
2026-05-28 20:56:52,653 [root] DEBUG: 8060: DLL loaded at 0x00007FFF01060000: C:\Windows\System32\MicrosoftAccountTokenProvider (0x51000 bytes).
2026-05-28 20:56:52,829 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8328: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:56:52,831 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8328: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:56:52,833 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8328: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:56:52,836 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 19632
2026-05-28 20:56:52,838 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 16624
2026-05-28 20:56:52,838 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8328
2026-05-28 20:56:52,839 [lib.api.process] INFO: Monitor config for process 19632: C:\rl4cuydm\dll\19632.ini
2026-05-28 20:56:52,840 [lib.api.process] INFO: Monitor config for process 16624: C:\rl4cuydm\dll\16624.ini
2026-05-28 20:56:52,841 [lib.api.process] INFO: Monitor config for process 8328: C:\rl4cuydm\dll\8328.ini
2026-05-28 20:56:52,843 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,844 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,847 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,852 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,854 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,856 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,861 [root] DEBUG: Loader: Injecting process 16624 (thread 8636) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,862 [root] DEBUG: Loader: Injecting process 8328 (thread 19644) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,866 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:56:52,866 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:56:52,868 [root] DEBUG: Loader: Injecting process 19632 (thread 10692) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,868 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,870 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,870 [lib.api.process] INFO: Injected into 64-bit <Process 16624 backgroundTaskHost.exe>
2026-05-28 20:56:52,872 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:56:52,873 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,872 [lib.api.process] INFO: Injected into 64-bit <Process 8328 backgroundTaskHost.exe>
2026-05-28 20:56:52,875 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 16624
2026-05-28 20:56:52,876 [lib.api.process] INFO: Injected into 64-bit <Process 19632 backgroundTaskHost.exe>
2026-05-28 20:56:52,876 [lib.api.process] INFO: Monitor config for process 16624: C:\rl4cuydm\dll\16624.ini
2026-05-28 20:56:52,877 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,878 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8328
2026-05-28 20:56:52,879 [lib.api.process] INFO: Monitor config for process 8328: C:\rl4cuydm\dll\8328.ini
2026-05-28 20:56:52,880 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 19632
2026-05-28 20:56:52,880 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,884 [lib.api.process] INFO: Monitor config for process 19632: C:\rl4cuydm\dll\19632.ini
2026-05-28 20:56:52,885 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,887 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,892 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,895 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,897 [root] DEBUG: Loader: Injecting process 16624 (thread 8636) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,899 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:56:52,900 [root] DEBUG: Loader: Injecting process 8328 (thread 19644) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,901 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,904 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:56:52,904 [lib.api.process] INFO: Injected into 64-bit <Process 16624 backgroundTaskHost.exe>
2026-05-28 20:56:52,907 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,906 [root] DEBUG: Loader: Injecting process 19632 (thread 10692) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,910 [lib.api.process] INFO: Injected into 64-bit <Process 8328 backgroundTaskHost.exe>
2026-05-28 20:56:52,910 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 16624
2026-05-28 20:56:52,912 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:56:52,912 [lib.api.process] INFO: Monitor config for process 16624: C:\rl4cuydm\dll\16624.ini
2026-05-28 20:56:52,913 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,914 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8328
2026-05-28 20:56:52,915 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,916 [lib.api.process] INFO: Monitor config for process 8328: C:\rl4cuydm\dll\8328.ini
2026-05-28 20:56:52,919 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,920 [lib.api.process] INFO: Injected into 64-bit <Process 19632 backgroundTaskHost.exe>
2026-05-28 20:56:52,923 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 19632
2026-05-28 20:56:52,926 [lib.api.process] INFO: Monitor config for process 19632: C:\rl4cuydm\dll\19632.ini
2026-05-28 20:56:52,926 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,927 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:56:52,929 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,932 [root] DEBUG: Loader: Injecting process 16624 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,933 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8636, handle 0x128
2026-05-28 20:56:52,935 [root] DEBUG: Loader: Injecting process 8328 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,937 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:56:52,938 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:56:52,939 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 19644, handle 0x120
2026-05-28 20:56:52,941 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,943 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:56:52,944 [lib.api.process] INFO: Injected into 64-bit <Process 16624 backgroundTaskHost.exe>
2026-05-28 20:56:52,944 [root] DEBUG: Loader: Injecting process 19632 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,945 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,946 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10692, handle 0x84
2026-05-28 20:56:52,947 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:56:52,948 [lib.api.process] INFO: Injected into 64-bit <Process 8328 backgroundTaskHost.exe>
2026-05-28 20:56:52,949 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:56:52,954 [lib.api.process] INFO: Injected into 64-bit <Process 19632 backgroundTaskHost.exe>
2026-05-28 20:56:53,174 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 20:56:53,185 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 3672: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:56:53,187 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 3672
2026-05-28 20:56:53,188 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 3672
2026-05-28 20:56:53,732 [root] DEBUG: 4484: api-cap: NtSetInformationFile hook disabled due to count: 5000
2026-05-28 20:56:53,770 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 13020: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:56:53,772 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 13020
2026-05-28 20:56:53,775 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 13020
2026-05-28 20:56:53,801 [root] DEBUG: 4484: api-cap: NtOpenProcessToken hook disabled due to count: 5000
2026-05-28 20:56:53,802 [root] DEBUG: 4484: api-cap: NtOpenProcessToken hook disabled due to count: 5001
2026-05-28 20:56:53,997 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 19736: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:56:53,999 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 19736
2026-05-28 20:56:54,000 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 19736
2026-05-28 20:56:55,132 [root] DEBUG: 4484: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5000
2026-05-28 20:57:04,075 [root] DEBUG: 4484: api-cap: NtWaitForSingleObject hook disabled due to count: 5000
2026-05-28 20:57:08,372 [root] DEBUG: 12700: NtTerminateProcess hook: Attempting to dump process 12700
2026-05-28 20:57:08,373 [root] DEBUG: 12700: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:57:08,376 [root] INFO: Process with pid 12700 has terminated
2026-05-28 20:57:13,951 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 15744: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:57:13,954 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15744
2026-05-28 20:57:13,968 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15744
2026-05-28 20:57:14,115 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 16616: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:57:14,118 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 16616
2026-05-28 20:57:14,120 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 16616
2026-05-28 20:57:17,031 [root] DEBUG: 4484: api-cap: CoCreateInstance hook disabled due to count: 5000
2026-05-28 20:57:17,616 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 4340: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 20:57:17,617 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4340
2026-05-28 20:57:17,619 [lib.api.process] INFO: Monitor config for process 4340: C:\rl4cuydm\dll\4340.ini
2026-05-28 20:57:17,622 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:17,625 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:17,633 [root] DEBUG: Loader: Injecting process 4340 (thread 5100) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:17,635 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:17,636 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:17,638 [lib.api.process] INFO: Injected into 64-bit <Process 4340 dllhost.exe>
2026-05-28 20:57:17,640 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4340
2026-05-28 20:57:17,642 [lib.api.process] INFO: Monitor config for process 4340: C:\rl4cuydm\dll\4340.ini
2026-05-28 20:57:17,644 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:17,655 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:17,662 [root] DEBUG: Loader: Injecting process 4340 (thread 5100) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:17,665 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:17,666 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:17,668 [lib.api.process] INFO: Injected into 64-bit <Process 4340 dllhost.exe>
2026-05-28 20:57:17,678 [root] DEBUG: 4340: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:57:17,680 [root] DEBUG: 4340: Interactive desktop enabled.
2026-05-28 20:57:17,682 [root] DEBUG: 4340: Dropped file limit defaulting to 100.
2026-05-28 20:57:17,685 [root] DEBUG: 4340: Disabling sleep skipping.
2026-05-28 20:57:17,687 [root] DEBUG: 4340: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:57:17,700 [root] DEBUG: 4340: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:57:17,702 [root] DEBUG: 4340: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:57:17,703 [root] DEBUG: 4340: Monitor initialised: 64-bit capemon loaded in process 4340 at 0x00007FFF1A580000, thread 5100, image base 0x00007FF6706B0000, stack from 0x00000076026F4000-0x0000007602700000
2026-05-28 20:57:17,704 [root] DEBUG: 4340: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:57:17,716 [root] DEBUG: 4340: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:57:17,737 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:57:17,741 [root] DEBUG: 4340: set_hooks: Unable to hook LockResource
2026-05-28 20:57:17,746 [root] DEBUG: 4340: Hooked 627 out of 628 functions
2026-05-28 20:57:17,747 [root] DEBUG: 4340: Syscall hook installed, syscall logging level 1
2026-05-28 20:57:17,753 [root] DEBUG: 4340: RestoreHeaders: Restored original import table.
2026-05-28 20:57:17,755 [root] INFO: Loaded monitor into process with pid 4340
2026-05-28 20:57:17,757 [root] DEBUG: 4340: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 5100).
2026-05-28 20:57:17,758 [root] DEBUG: 4340: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:57:17,761 [root] DEBUG: 4340: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:57:17,767 [root] DEBUG: 4340: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:57:17,769 [root] DEBUG: 4340: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:57:17,774 [root] DEBUG: 4340: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:57:17,789 [root] DEBUG: 4340: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:57:17,806 [root] DEBUG: 4340: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:57:17,808 [root] DEBUG: 4340: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:57:17,814 [root] DEBUG: 4340: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:57:17,906 [root] DEBUG: 4484: api-cap: NtReleaseMutant hook disabled due to count: 5000
2026-05-28 20:57:20,073 [root] DEBUG: 8060: CreateProcessHandler: Injection info set for new process 15884: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 20:57:20,076 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15884
2026-05-28 20:57:20,079 [root] DEBUG: 8060: ProcessMessage: Skipping monitoring process 15884
2026-05-28 20:57:20,087 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-28 20:57:20,601 [root] DEBUG: 4484: api-cap: NtOpenProcess hook disabled due to count: 5000
2026-05-28 20:57:22,479 [root] DEBUG: 4484: api-cap: NtQueryInformationThread hook disabled due to count: 5001
2026-05-28 20:57:22,479 [root] DEBUG: 4484: api-cap: NtQueryInformationThread hook disabled due to count: 5001
2026-05-28 20:57:22,930 [root] INFO: Process with pid 4340 has terminated
2026-05-28 20:57:22,932 [root] DEBUG: 4340: NtTerminateProcess hook: Attempting to dump process 4340
2026-05-28 20:57:22,935 [root] DEBUG: 4484: api-cap: NtCreateMutant hook disabled due to count: 5000
2026-05-28 20:57:22,938 [root] DEBUG: 4340: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:57:24,557 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 15456: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 20:57:24,559 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15456
2026-05-28 20:57:24,560 [lib.api.process] INFO: Monitor config for process 15456: C:\rl4cuydm\dll\15456.ini
2026-05-28 20:57:25,568 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:25,577 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:25,582 [root] DEBUG: Loader: Injecting process 15456 (thread 2564) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:25,584 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:25,586 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:25,588 [lib.api.process] INFO: Injected into 64-bit <Process 15456 dllhost.exe>
2026-05-28 20:57:25,591 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15456
2026-05-28 20:57:25,593 [lib.api.process] INFO: Monitor config for process 15456: C:\rl4cuydm\dll\15456.ini
2026-05-28 20:57:25,594 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:25,602 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:25,607 [root] DEBUG: Loader: Injecting process 15456 (thread 2564) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:25,608 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:25,610 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:25,612 [lib.api.process] INFO: Injected into 64-bit <Process 15456 dllhost.exe>
2026-05-28 20:57:25,618 [root] DEBUG: 15456: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:57:25,620 [root] DEBUG: 15456: Interactive desktop enabled.
2026-05-28 20:57:25,623 [root] DEBUG: 15456: Dropped file limit defaulting to 100.
2026-05-28 20:57:25,626 [root] DEBUG: 15456: Disabling sleep skipping.
2026-05-28 20:57:25,628 [root] DEBUG: 15456: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:57:25,643 [root] DEBUG: 15456: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:57:25,643 [root] DEBUG: 15456: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:57:25,645 [root] DEBUG: 15456: Monitor initialised: 64-bit capemon loaded in process 15456 at 0x00007FFF1A580000, thread 2564, image base 0x00007FF6706B0000, stack from 0x000000F02F8F4000-0x000000F02F900000
2026-05-28 20:57:25,646 [root] DEBUG: 15456: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:57:25,656 [root] DEBUG: 15456: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:57:25,679 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:57:25,681 [root] DEBUG: 15456: set_hooks: Unable to hook LockResource
2026-05-28 20:57:25,685 [root] DEBUG: 15456: Hooked 627 out of 628 functions
2026-05-28 20:57:25,687 [root] DEBUG: 15456: Syscall hook installed, syscall logging level 1
2026-05-28 20:57:25,693 [root] DEBUG: 15456: RestoreHeaders: Restored original import table.
2026-05-28 20:57:25,694 [root] INFO: Loaded monitor into process with pid 15456
2026-05-28 20:57:25,695 [root] DEBUG: 15456: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 2564).
2026-05-28 20:57:25,698 [root] DEBUG: 15456: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:57:25,700 [root] DEBUG: 15456: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:57:25,702 [root] DEBUG: 15456: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:57:25,704 [root] DEBUG: 15456: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:57:25,708 [root] DEBUG: 15456: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:57:25,721 [root] DEBUG: 15456: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:57:25,734 [root] DEBUG: 15456: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:57:25,736 [root] DEBUG: 15456: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:57:25,743 [root] DEBUG: 15456: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:57:28,040 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 20:57:28,043 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 20:57:28,064 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE171000, size: 0x1000.
2026-05-28 20:57:28,071 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE161000, size: 0x1000.
2026-05-28 20:57:28,072 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE151000, size: 0x1000.
2026-05-28 20:57:28,076 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE141000, size: 0x1000.
2026-05-28 20:57:28,094 [root] DEBUG: 4484: DLL loaded at 0x0000000009FA0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 20:57:28,096 [root] DEBUG: 4484: DLL loaded at 0x0000000009FA0000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 20:57:28,114 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 20564: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF679750000
2026-05-28 20:57:28,115 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 20564
2026-05-28 20:57:28,117 [lib.api.process] INFO: Monitor config for process 20564: C:\rl4cuydm\dll\20564.ini
2026-05-28 20:57:28,120 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:28,130 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:28,135 [root] DEBUG: Loader: Injecting process 20564 (thread 20568) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:28,138 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:28,140 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:28,142 [lib.api.process] INFO: Injected into 64-bit <Process 20564 CHXSmartScreen.exe>
2026-05-28 20:57:28,144 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 20564
2026-05-28 20:57:28,145 [lib.api.process] INFO: Monitor config for process 20564: C:\rl4cuydm\dll\20564.ini
2026-05-28 20:57:28,147 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:28,159 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:28,165 [root] DEBUG: Loader: Injecting process 20564 (thread 20568) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:28,166 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:28,167 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:28,168 [lib.api.process] INFO: Injected into 64-bit <Process 20564 CHXSmartScreen.exe>
2026-05-28 20:57:28,170 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 20564
2026-05-28 20:57:28,172 [lib.api.process] INFO: Monitor config for process 20564: C:\rl4cuydm\dll\20564.ini
2026-05-28 20:57:28,174 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:28,182 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:28,186 [root] DEBUG: Loader: Injecting process 20564 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:28,189 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 20568, handle 0x98
2026-05-28 20:57:28,191 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:57:28,193 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:28,194 [lib.api.process] INFO: Injected into 64-bit <Process 20564 CHXSmartScreen.exe>
2026-05-28 20:57:28,453 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE150000.
2026-05-28 20:57:28,457 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:57:28,459 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE140000.
2026-05-28 20:57:28,460 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:57:28,461 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE160000.
2026-05-28 20:57:28,463 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:57:28,466 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE170000.
2026-05-28 20:57:28,467 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:57:30,787 [root] INFO: Process with pid 15456 has terminated
2026-05-28 20:57:30,789 [root] DEBUG: 15456: NtTerminateProcess hook: Attempting to dump process 15456
2026-05-28 20:57:30,791 [root] DEBUG: 15456: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:57:35,664 [root] DEBUG: 1292: CreateProcessHandler: Injection info set for new process 20896: C:\Windows\system32\sc.exe, ImageBase: 0x00007FF6DC2A0000
2026-05-28 20:57:35,667 [root] INFO: Announced 64-bit process name: sc.exe pid: 20896
2026-05-28 20:57:35,669 [lib.api.process] INFO: Monitor config for process 20896: C:\rl4cuydm\dll\20896.ini
2026-05-28 20:57:35,671 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:35,681 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:35,686 [root] DEBUG: Loader: Injecting process 20896 (thread 20900) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:35,687 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:35,689 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:35,691 [lib.api.process] INFO: Injected into 64-bit <Process 20896 sc.exe>
2026-05-28 20:57:35,694 [root] INFO: Announced 64-bit process name: sc.exe pid: 20896
2026-05-28 20:57:35,695 [lib.api.process] INFO: Monitor config for process 20896: C:\rl4cuydm\dll\20896.ini
2026-05-28 20:57:35,696 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:35,704 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:35,711 [root] DEBUG: Loader: Injecting process 20896 (thread 20900) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:35,712 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:57:35,715 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:35,717 [lib.api.process] INFO: Injected into 64-bit <Process 20896 sc.exe>
2026-05-28 20:57:35,719 [root] INFO: Announced 64-bit process name: sc.exe pid: 20896
2026-05-28 20:57:35,720 [lib.api.process] INFO: Monitor config for process 20896: C:\rl4cuydm\dll\20896.ini
2026-05-28 20:57:35,721 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:35,730 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:35,734 [root] DEBUG: Loader: Injecting process 20896 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:35,738 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 20900, handle 0x120
2026-05-28 20:57:35,740 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:57:35,743 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:35,745 [lib.api.process] INFO: Injected into 64-bit <Process 20896 sc.exe>
2026-05-28 20:57:35,779 [root] DEBUG: 20896: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:57:35,782 [root] DEBUG: 20896: Interactive desktop enabled.
2026-05-28 20:57:35,783 [root] DEBUG: 20896: Dropped file limit defaulting to 100.
2026-05-28 20:57:35,787 [root] DEBUG: 20896: Disabling sleep skipping.
2026-05-28 20:57:35,789 [root] DEBUG: 20896: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:57:35,803 [root] DEBUG: 20896: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:57:35,805 [root] DEBUG: 20896: YaraScan: Scanning 0x00007FF6DC2A0000, size 0x1607c
2026-05-28 20:57:35,806 [root] DEBUG: 20896: Monitor initialised: 64-bit capemon loaded in process 20896 at 0x00007FFF1A580000, thread 20900, image base 0x00007FF6DC2A0000, stack from 0x000000BE05114000-0x000000BE05120000
2026-05-28 20:57:35,808 [root] DEBUG: 20896: Commandline: "C:\Windows\system32\sc.exe" start pushtoinstall registration
2026-05-28 20:57:35,819 [root] DEBUG: 20896: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:57:35,843 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:57:35,846 [root] DEBUG: 20896: set_hooks: Unable to hook LockResource
2026-05-28 20:57:35,852 [root] DEBUG: 20896: Hooked 627 out of 628 functions
2026-05-28 20:57:35,854 [root] DEBUG: 20896: Syscall hook installed, syscall logging level 1
2026-05-28 20:57:35,862 [root] DEBUG: 20896: RestoreHeaders: Restored original import table.
2026-05-28 20:57:35,866 [root] INFO: Loaded monitor into process with pid 20896
2026-05-28 20:57:35,869 [root] DEBUG: 20896: caller_dispatch: Added region at 0x00007FF6DC2A0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6DC2A24F1, thread 20900).
2026-05-28 20:57:35,872 [root] DEBUG: 20896: YaraScan: Scanning 0x00007FF6DC2A0000, size 0x1607c
2026-05-28 20:57:35,875 [root] DEBUG: 20896: ProcessImageBase: Main module image at 0x00007FF6DC2A0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:57:35,884 [root] INFO: Announced starting service "b'PushToInstall'"
2026-05-28 20:57:36,898 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 21208: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:57:36,900 [root] INFO: Announced 64-bit process name: svchost.exe pid: 21208
2026-05-28 20:57:36,902 [lib.api.process] INFO: Monitor config for process 21208: C:\rl4cuydm\dll\21208.ini
2026-05-28 20:57:36,904 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:36,914 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:36,919 [root] DEBUG: Loader: Injecting process 21208 (thread 21212) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:36,920 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:36,922 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:36,924 [lib.api.process] INFO: Injected into 64-bit <Process 21208 svchost.exe>
2026-05-28 20:57:36,928 [root] INFO: Announced 64-bit process name: svchost.exe pid: 21208
2026-05-28 20:57:36,929 [lib.api.process] INFO: Monitor config for process 21208: C:\rl4cuydm\dll\21208.ini
2026-05-28 20:57:36,930 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:36,938 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:36,944 [root] DEBUG: Loader: Injecting process 21208 (thread 21212) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:36,947 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:57:36,951 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:36,953 [lib.api.process] INFO: Injected into 64-bit <Process 21208 svchost.exe>
2026-05-28 20:57:36,955 [root] INFO: Announced 64-bit process name: svchost.exe pid: 21208
2026-05-28 20:57:36,957 [lib.api.process] INFO: Monitor config for process 21208: C:\rl4cuydm\dll\21208.ini
2026-05-28 20:57:36,958 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:36,967 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:36,973 [root] DEBUG: Loader: Injecting process 21208 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:36,974 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 21212, handle 0x134
2026-05-28 20:57:36,975 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:57:36,976 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:36,978 [lib.api.process] INFO: Injected into 64-bit <Process 21208 svchost.exe>
2026-05-28 20:57:36,991 [root] DEBUG: 21208: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:57:36,999 [root] DEBUG: 21208: Interactive desktop enabled.
2026-05-28 20:57:37,000 [root] DEBUG: 21208: Dropped file limit defaulting to 100.
2026-05-28 20:57:37,002 [root] DEBUG: 21208: Disabling sleep skipping.
2026-05-28 20:57:37,005 [root] DEBUG: 21208: Services hook set enabled
2026-05-28 20:57:37,011 [root] DEBUG: 21208: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:57:37,024 [root] DEBUG: 21208: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:57:37,025 [root] DEBUG: 21208: Monitor initialised: 64-bit capemon loaded in process 21208 at 0x00007FFF1A580000, thread 21212, image base 0x00007FF7BF220000, stack from 0x000000FA1BF34000-0x000000FA1BF40000
2026-05-28 20:57:37,026 [root] DEBUG: 21208: Commandline: C:\Windows\System32\svchost.exe -k netsvcs -p
2026-05-28 20:57:37,044 [root] DEBUG: 21208: Hooked 69 out of 69 functions
2026-05-28 20:57:37,047 [root] DEBUG: 21208: RestoreHeaders: Restored original import table.
2026-05-28 20:57:37,052 [root] INFO: Loaded monitor into process with pid 21208
2026-05-28 20:57:37,056 [root] DEBUG: 21208: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:57:37,058 [root] DEBUG: 21208: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:57:37,065 [root] DEBUG: 21208: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:57:37,071 [root] DEBUG: 21208: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:57:37,071 [root] DEBUG: 21208: DLL loaded at 0x00007FFF52560000: c:\windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:57:37,072 [root] DEBUG: 20896: NtTerminateProcess hook: Attempting to dump process 20896
2026-05-28 20:57:37,074 [root] DEBUG: 21208: DLL loaded at 0x00007FFF00F20000: c:\windows\system32\pushtoinstall (0x70000 bytes).
2026-05-28 20:57:37,075 [root] DEBUG: 20896: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:57:37,078 [root] DEBUG: 21208: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-28 20:57:37,083 [root] DEBUG: 21208: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:57:37,084 [root] INFO: Process with pid 20896 has terminated
2026-05-28 20:57:37,089 [root] INFO: Process with pid 20896 has terminated
2026-05-28 20:57:37,137 [root] DEBUG: 21208: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:57:37,138 [root] DEBUG: 21208: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:57:37,141 [root] DEBUG: 21208: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:57:37,142 [root] DEBUG: 21208: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:57:37,144 [root] DEBUG: 21208: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:57:37,152 [root] DEBUG: 21208: DLL loaded at 0x00007FFF40190000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-05-28 20:57:37,161 [root] DEBUG: 21208: DLL loaded at 0x00007FFF3EE90000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-05-28 20:57:37,173 [root] DEBUG: 21208: DLL loaded at 0x00007FFF3EE90000: C:\Windows\System32\wups (0x1a000 bytes).
2026-05-28 20:57:37,226 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2564: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF787820000
2026-05-28 20:57:37,228 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 2564
2026-05-28 20:57:37,229 [lib.api.process] INFO: Monitor config for process 2564: C:\rl4cuydm\dll\2564.ini
2026-05-28 20:57:38,240 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:41,385 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:41,391 [root] DEBUG: Loader: Injecting process 2564 (thread 15792) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:41,394 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:41,394 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:41,397 [lib.api.process] INFO: Injected into 64-bit <Process 2564 WmiPrvSE.exe>
2026-05-28 20:57:41,400 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 2564
2026-05-28 20:57:41,401 [lib.api.process] INFO: Monitor config for process 2564: C:\rl4cuydm\dll\2564.ini
2026-05-28 20:57:41,402 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:44,337 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:44,343 [root] DEBUG: Loader: Injecting process 2564 (thread 15792) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:44,346 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:57:44,348 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:44,350 [lib.api.process] INFO: Injected into 64-bit <Process 2564 WmiPrvSE.exe>
2026-05-28 20:57:44,357 [root] DEBUG: 2564: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:57:44,359 [root] DEBUG: 2564: Interactive desktop enabled.
2026-05-28 20:57:44,362 [root] DEBUG: 2564: Dropped file limit defaulting to 100.
2026-05-28 20:57:44,365 [root] DEBUG: 2564: Disabling sleep skipping.
2026-05-28 20:57:44,368 [root] DEBUG: 2564: Services hook set enabled
2026-05-28 20:57:44,374 [root] DEBUG: 2564: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:57:44,386 [root] DEBUG: 2564: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:57:44,389 [root] DEBUG: 2564: Monitor initialised: 64-bit capemon loaded in process 2564 at 0x00007FFF1A580000, thread 15792, image base 0x00007FF787820000, stack from 0x0000006BA04C0000-0x0000006BA04D0000
2026-05-28 20:57:44,391 [root] DEBUG: 2564: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 20:57:44,404 [root] DEBUG: 2564: Hooked 69 out of 69 functions
2026-05-28 20:57:44,409 [root] DEBUG: 2564: RestoreHeaders: Restored original import table.
2026-05-28 20:57:44,411 [root] INFO: Loaded monitor into process with pid 2564
2026-05-28 20:57:44,415 [root] DEBUG: 2564: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:57:44,417 [root] DEBUG: 2564: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:57:44,420 [root] DEBUG: 2564: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:57:44,427 [root] DEBUG: 2564: DLL loaded at 0x00007FFF3FD20000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:57:44,432 [root] DEBUG: 2564: DLL loaded at 0x00007FFF3F950000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:57:44,448 [root] DEBUG: 2564: DLL loaded at 0x00007FFF42BF0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 20:57:44,474 [root] DEBUG: 2564: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:57:44,476 [root] DEBUG: 2564: DLL loaded at 0x00007FFF4F490000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 20:57:44,481 [root] DEBUG: 2564: DLL loaded at 0x00007FFF54BE0000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 20:57:44,482 [root] DEBUG: 2564: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:57:44,494 [root] DEBUG: 2564: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-28 20:57:44,498 [root] DEBUG: 2564: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 20:57:44,501 [root] DEBUG: 2564: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-28 20:57:44,503 [root] DEBUG: 2564: DLL loaded at 0x00007FFF572F0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 20:57:44,505 [root] DEBUG: 2564: DLL loaded at 0x00000227CDE90000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 20:57:44,506 [root] DEBUG: 2564: DLL loaded at 0x00007FFF520C0000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 20:57:44,510 [root] DEBUG: 2564: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 20:57:44,511 [root] DEBUG: 2564: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\SYSTEM32\SAMCLI (0x19000 bytes).
2026-05-28 20:57:44,513 [root] DEBUG: 2564: DLL loaded at 0x00007FFF4D670000: C:\Windows\SYSTEM32\SRVCLI (0x28000 bytes).
2026-05-28 20:57:44,517 [root] DEBUG: 2564: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-05-28 20:57:44,522 [root] DEBUG: 2564: DLL loaded at 0x00007FFF56B10000: C:\Windows\SYSTEM32\LOGONCLI (0x43000 bytes).
2026-05-28 20:57:44,525 [root] DEBUG: 2564: DLL loaded at 0x00007FFF510C0000: C:\Windows\SYSTEM32\SCHEDCLI (0xc000 bytes).
2026-05-28 20:57:44,528 [root] DEBUG: 2564: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2026-05-28 20:57:44,532 [root] DEBUG: 2564: DLL loaded at 0x00007FFF52850000: C:\Windows\SYSTEM32\DSROLE (0xa000 bytes).
2026-05-28 20:57:44,573 [root] DEBUG: 21208: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 20:57:44,577 [root] DEBUG: 21208: DLL loaded at 0x00007FFF3EA70000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 20:57:44,601 [root] DEBUG: 21208: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 20:57:44,603 [root] DEBUG: 21208: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 20:57:44,605 [root] DEBUG: 21208: DLL loaded at 0x00007FFF57350000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-05-28 20:57:44,608 [root] DEBUG: 21208: DLL loaded at 0x00007FFF569F0000: c:\windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:57:44,610 [root] DEBUG: 21208: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:57:44,612 [root] DEBUG: 21208: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 20:57:44,615 [root] DEBUG: 21208: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:57:44,618 [root] DEBUG: 21208: DLL loaded at 0x00007FFF43570000: C:\Windows\system32\OnDemandConnRouteHelper (0x17000 bytes).
2026-05-28 20:57:44,622 [root] DEBUG: 21208: DLL loaded at 0x00007FFF3E610000: c:\windows\system32\webio (0x98000 bytes).
2026-05-28 20:57:44,631 [root] DEBUG: 21208: DLL loaded at 0x00007FFF56D00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 20:57:44,632 [root] DEBUG: 21208: DLL loaded at 0x00007FFF51770000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 20:57:44,636 [root] DEBUG: 21208: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 20:57:44,640 [root] DEBUG: 21208: DLL loaded at 0x00007FFF4F200000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-05-28 20:57:44,666 [root] DEBUG: 21208: DLL loaded at 0x00007FFF524B0000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-05-28 20:57:49,693 [root] DEBUG: 21208: NtTerminateProcess hook: Attempting to dump process 21208
2026-05-28 20:57:49,695 [root] DEBUG: 21208: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:57:49,698 [root] INFO: Process with pid 21208 has terminated
2026-05-28 20:57:53,922 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 21668: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 20:57:53,925 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 21668
2026-05-28 20:57:53,930 [lib.api.process] INFO: Monitor config for process 21668: C:\rl4cuydm\dll\21668.ini
2026-05-28 20:57:54,944 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:54,951 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:54,956 [root] DEBUG: Loader: Injecting process 21668 (thread 21672) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:54,957 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:54,961 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:54,963 [lib.api.process] INFO: Injected into 64-bit <Process 21668 dllhost.exe>
2026-05-28 20:57:54,966 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 21668
2026-05-28 20:57:54,969 [lib.api.process] INFO: Monitor config for process 21668: C:\rl4cuydm\dll\21668.ini
2026-05-28 20:57:54,970 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:57:54,983 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:57:54,988 [root] DEBUG: Loader: Injecting process 21668 (thread 21672) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:54,990 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:57:54,993 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:57:54,996 [lib.api.process] INFO: Injected into 64-bit <Process 21668 dllhost.exe>
2026-05-28 20:57:55,002 [root] DEBUG: 21668: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:57:55,004 [root] DEBUG: 21668: Interactive desktop enabled.
2026-05-28 20:57:55,005 [root] DEBUG: 21668: Dropped file limit defaulting to 100.
2026-05-28 20:57:55,008 [root] DEBUG: 21668: Disabling sleep skipping.
2026-05-28 20:57:55,010 [root] DEBUG: 21668: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:57:55,022 [root] DEBUG: 21668: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:57:55,026 [root] DEBUG: 21668: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:57:55,027 [root] DEBUG: 21668: Monitor initialised: 64-bit capemon loaded in process 21668 at 0x00007FFF1A580000, thread 21672, image base 0x00007FF6706B0000, stack from 0x0000009B445F4000-0x0000009B44600000
2026-05-28 20:57:55,028 [root] DEBUG: 21668: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:57:55,040 [root] DEBUG: 21668: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:57:55,064 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:57:55,066 [root] DEBUG: 21668: set_hooks: Unable to hook LockResource
2026-05-28 20:57:55,076 [root] DEBUG: 21668: Hooked 627 out of 628 functions
2026-05-28 20:57:55,079 [root] DEBUG: 21668: Syscall hook installed, syscall logging level 1
2026-05-28 20:57:55,085 [root] DEBUG: 21668: RestoreHeaders: Restored original import table.
2026-05-28 20:57:55,087 [root] INFO: Loaded monitor into process with pid 21668
2026-05-28 20:57:55,090 [root] DEBUG: 21668: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 21672).
2026-05-28 20:57:55,099 [root] DEBUG: 21668: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:57:55,102 [root] DEBUG: 21668: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:57:55,109 [root] DEBUG: 21668: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:57:55,116 [root] DEBUG: 21668: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:57:55,123 [root] DEBUG: 21668: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:57:55,139 [root] DEBUG: 21668: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:57:55,152 [root] DEBUG: 21668: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:57:55,155 [root] DEBUG: 21668: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:57:55,165 [root] DEBUG: 21668: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:58:00,306 [root] INFO: Process with pid 21668 has terminated
2026-05-28 20:58:00,310 [root] DEBUG: 21668: NtTerminateProcess hook: Attempting to dump process 21668
2026-05-28 20:58:00,311 [root] DEBUG: 21668: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:58:08,131 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 22012: C:\Windows\system32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:58:08,137 [root] INFO: Announced 64-bit process name: svchost.exe pid: 22012
2026-05-28 20:58:08,138 [lib.api.process] INFO: Monitor config for process 22012: C:\rl4cuydm\dll\22012.ini
2026-05-28 20:58:08,141 [root] DEBUG: 8424: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:58:08,143 [root] DEBUG: 8424: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:58:08,145 [root] DEBUG: 8424: CreateProcessHandler: Injection info set for new process 22028: \\?\C:\Windows\system32\wbem\WMIADAP.EXE, ImageBase: 0x00007FF69C390000
2026-05-28 20:58:08,148 [root] INFO: Announced 64-bit process name: WMIADAP.exe pid: 22028
2026-05-28 20:58:08,150 [lib.api.process] INFO: Monitor config for process 22028: C:\rl4cuydm\dll\22028.ini
2026-05-28 20:58:08,467 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 20:58:08,469 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 20:58:08,478 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 22060: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF7DFCC0000
2026-05-28 20:58:08,482 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 22060
2026-05-28 20:58:08,485 [lib.api.process] INFO: Monitor config for process 22060: C:\rl4cuydm\dll\22060.ini
2026-05-28 20:58:08,488 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:08,498 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:08,502 [root] DEBUG: Loader: Injecting process 22060 (thread 22064) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:08,505 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:08,507 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:08,510 [lib.api.process] INFO: Injected into 64-bit <Process 22060 SecurityHealthHost.exe>
2026-05-28 20:58:08,512 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 22060
2026-05-28 20:58:08,513 [lib.api.process] INFO: Monitor config for process 22060: C:\rl4cuydm\dll\22060.ini
2026-05-28 20:58:08,514 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:08,524 [root] INFO: Added new file to list with pid 6632 and path C:\ProgramData\Microsoft\Windows\WER\Temp\dfdefffc-82d8-4439-b2b9-ed8034845336
2026-05-28 20:58:08,526 [root] DEBUG: 6632: NtTerminateProcess hook: Attempting to dump process 6632
2026-05-28 20:58:08,528 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:08,529 [root] DEBUG: 6632: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:58:08,534 [root] DEBUG: Loader: Injecting process 22060 (thread 22064) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:08,535 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:08,539 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:08,541 [lib.api.process] INFO: Injected into 64-bit <Process 22060 SecurityHealthHost.exe>
2026-05-28 20:58:08,544 [root] INFO: Process with pid 6632 has terminated
2026-05-28 20:58:08,552 [root] DEBUG: 22060: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:58:08,554 [root] DEBUG: 22060: Interactive desktop enabled.
2026-05-28 20:58:08,556 [root] DEBUG: 22060: Dropped file limit defaulting to 100.
2026-05-28 20:58:08,562 [root] DEBUG: 22060: Disabling sleep skipping.
2026-05-28 20:58:08,564 [root] DEBUG: 22060: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:58:08,576 [root] DEBUG: 22060: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:58:08,577 [root] DEBUG: 22060: YaraScan: Scanning 0x00007FF7DFCC0000, size 0x19174
2026-05-28 20:58:08,582 [root] DEBUG: 22060: Monitor initialised: 64-bit capemon loaded in process 22060 at 0x00007FFF1A580000, thread 22064, image base 0x00007FF7DFCC0000, stack from 0x0000001509C74000-0x0000001509C80000
2026-05-28 20:58:08,584 [root] DEBUG: 22060: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-28 20:58:08,595 [root] DEBUG: 22060: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:58:08,618 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:58:08,620 [root] DEBUG: 22060: set_hooks: Unable to hook LockResource
2026-05-28 20:58:08,626 [root] DEBUG: 22060: Hooked 627 out of 628 functions
2026-05-28 20:58:08,628 [root] DEBUG: 22060: Syscall hook installed, syscall logging level 1
2026-05-28 20:58:08,633 [root] DEBUG: 22060: RestoreHeaders: Restored original import table.
2026-05-28 20:58:08,635 [root] INFO: Loaded monitor into process with pid 22060
2026-05-28 20:58:08,637 [root] DEBUG: 22060: caller_dispatch: Added region at 0x00007FF7DFCC0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7DFCCD3B2, thread 22064).
2026-05-28 20:58:08,639 [root] DEBUG: 22060: YaraScan: Scanning 0x00007FF7DFCC0000, size 0x19174
2026-05-28 20:58:08,647 [root] DEBUG: 22060: ProcessImageBase: Main module image at 0x00007FF7DFCC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:58:08,651 [root] DEBUG: 22060: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:58:08,652 [root] DEBUG: 22060: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:58:08,656 [root] DEBUG: 22060: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:58:08,677 [root] DEBUG: 22060: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 20:58:08,679 [root] DEBUG: 22060: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:58:08,684 [root] DEBUG: 22060: DLL loaded at 0x00007FFF00F70000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-28 20:58:08,709 [root] DEBUG: 22060: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 20:58:08,714 [root] DEBUG: 22060: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 20:58:08,720 [root] DEBUG: 22060: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:58:08,722 [root] DEBUG: 22060: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:58:08,724 [root] DEBUG: 22060: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 20:58:08,727 [root] DEBUG: 22060: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 20:58:08,729 [root] DEBUG: 22060: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 20:58:08,733 [root] DEBUG: 22060: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 20:58:08,738 [root] DEBUG: 22060: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 20:58:08,746 [root] DEBUG: 22060: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 20:58:08,755 [root] DEBUG: 22060: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 20:58:08,779 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE170000.
2026-05-28 20:58:08,784 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE160000.
2026-05-28 20:58:08,789 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE160000.
2026-05-28 20:58:08,790 [root] DEBUG: 22060: NtTerminateProcess hook: Attempting to dump process 22060
2026-05-28 20:58:08,792 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:58:08,793 [root] DEBUG: 22060: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:58:08,797 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE170000.
2026-05-28 20:58:08,800 [root] INFO: Process with pid 22060 appears to have terminated
2026-05-28 20:58:08,801 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:58:08,810 [root] INFO: Process with pid 22060 has terminated
2026-05-28 20:58:08,812 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE170000.
2026-05-28 20:58:08,814 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE160000.
2026-05-28 20:58:08,817 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE160000.
2026-05-28 20:58:08,821 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:58:08,824 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE170000.
2026-05-28 20:58:08,827 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 20:58:08,838 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 22508: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF6E2310000
2026-05-28 20:58:08,841 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 22508
2026-05-28 20:58:08,842 [lib.api.process] INFO: Monitor config for process 22508: C:\rl4cuydm\dll\22508.ini
2026-05-28 20:58:08,844 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:09,147 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:09,148 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:09,163 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:09,168 [root] DEBUG: Loader: Injecting process 22012 (thread 22016) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:09,170 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:09,173 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:09,175 [lib.api.process] INFO: Injected into 64-bit <Process 22012 svchost.exe>
2026-05-28 20:58:09,178 [root] INFO: Announced 64-bit process name: svchost.exe pid: 22012
2026-05-28 20:58:09,180 [lib.api.process] INFO: Monitor config for process 22012: C:\rl4cuydm\dll\22012.ini
2026-05-28 20:58:09,181 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:09,196 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:09,201 [root] DEBUG: Loader: Injecting process 22012 (thread 22016) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:09,202 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:09,205 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:09,208 [lib.api.process] INFO: Injected into 64-bit <Process 22012 svchost.exe>
2026-05-28 20:58:09,212 [root] INFO: Announced 64-bit process name: svchost.exe pid: 22012
2026-05-28 20:58:09,213 [lib.api.process] INFO: Monitor config for process 22012: C:\rl4cuydm\dll\22012.ini
2026-05-28 20:58:09,214 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:09,227 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:09,232 [root] DEBUG: Loader: Injecting process 22012 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:09,234 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 22016, handle 0x12c
2026-05-28 20:58:09,241 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:09,244 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:09,248 [lib.api.process] INFO: Injected into 64-bit <Process 22012 svchost.exe>
2026-05-28 20:58:09,258 [root] DEBUG: 22012: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:58:09,260 [root] DEBUG: 22012: Interactive desktop enabled.
2026-05-28 20:58:09,263 [root] DEBUG: 22012: Dropped file limit defaulting to 100.
2026-05-28 20:58:09,264 [root] DEBUG: 22012: Disabling sleep skipping.
2026-05-28 20:58:09,266 [root] DEBUG: 22012: Services hook set enabled
2026-05-28 20:58:09,270 [root] DEBUG: 22012: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:58:09,283 [root] DEBUG: 22012: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:58:09,285 [root] DEBUG: 22012: Monitor initialised: 64-bit capemon loaded in process 22012 at 0x00007FFF1A580000, thread 22016, image base 0x00007FF7BF220000, stack from 0x000000E3FC734000-0x000000E3FC740000
2026-05-28 20:58:09,287 [root] DEBUG: 22012: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s UsoSvc
2026-05-28 20:58:09,304 [root] DEBUG: 22012: Hooked 69 out of 69 functions
2026-05-28 20:58:09,307 [root] DEBUG: 22012: RestoreHeaders: Restored original import table.
2026-05-28 20:58:09,309 [root] INFO: Loaded monitor into process with pid 22012
2026-05-28 20:58:09,311 [root] DEBUG: 22012: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:58:09,316 [root] DEBUG: 22012: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:58:09,319 [root] DEBUG: 22012: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:58:09,325 [root] DEBUG: 22012: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:58:09,327 [root] DEBUG: 22012: DLL loaded at 0x00007FFF57470000: c:\windows\system32\UMPDC (0x12000 bytes).
2026-05-28 20:58:09,329 [root] DEBUG: 22012: DLL loaded at 0x00007FFF57560000: c:\windows\system32\profapi (0x25000 bytes).
2026-05-28 20:58:09,331 [root] DEBUG: 22012: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:58:09,332 [root] DEBUG: 22012: DLL loaded at 0x00007FFF4F590000: c:\windows\system32\Cabinet (0x29000 bytes).
2026-05-28 20:58:09,335 [root] DEBUG: 22012: DLL loaded at 0x00007FFF57520000: c:\windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:58:09,339 [root] DEBUG: 22012: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 20:58:09,340 [root] DEBUG: 22012: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:58:09,346 [root] DEBUG: 22012: DLL loaded at 0x00007FFF3EE40000: c:\windows\system32\UpdatePolicy (0x43000 bytes).
2026-05-28 20:58:09,348 [root] DEBUG: 22012: DLL loaded at 0x00007FFF00ED0000: c:\windows\system32\usosvc (0x91000 bytes).
2026-05-28 20:58:09,350 [root] DEBUG: 22012: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 20:58:09,357 [root] DEBUG: 22012: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-28 20:58:09,368 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 20720: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-28 20:58:09,375 [root] INFO: Announced 64-bit process name: svchost.exe pid: 20720
2026-05-28 20:58:09,376 [lib.api.process] INFO: Monitor config for process 20720: C:\rl4cuydm\dll\20720.ini
2026-05-28 20:58:10,382 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:10,391 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:10,399 [root] DEBUG: Loader: Injecting process 20720 (thread 20724) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:10,401 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:10,403 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:10,405 [lib.api.process] INFO: Injected into 64-bit <Process 20720 svchost.exe>
2026-05-28 20:58:10,408 [root] INFO: Announced 64-bit process name: svchost.exe pid: 20720
2026-05-28 20:58:10,410 [lib.api.process] INFO: Monitor config for process 20720: C:\rl4cuydm\dll\20720.ini
2026-05-28 20:58:10,412 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:10,424 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:10,429 [root] DEBUG: Loader: Injecting process 20720 (thread 20724) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:10,431 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:10,432 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:10,434 [lib.api.process] INFO: Injected into 64-bit <Process 20720 svchost.exe>
2026-05-28 20:58:10,438 [root] INFO: Announced 64-bit process name: svchost.exe pid: 20720
2026-05-28 20:58:10,439 [lib.api.process] INFO: Monitor config for process 20720: C:\rl4cuydm\dll\20720.ini
2026-05-28 20:58:10,441 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:10,456 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:10,464 [root] DEBUG: Loader: Injecting process 20720 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:10,468 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 20724, handle 0x120
2026-05-28 20:58:10,471 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:10,474 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:10,476 [lib.api.process] INFO: Injected into 64-bit <Process 20720 svchost.exe>
2026-05-28 20:58:10,486 [root] DEBUG: 20720: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:58:10,487 [root] DEBUG: 20720: Interactive desktop enabled.
2026-05-28 20:58:10,490 [root] DEBUG: 20720: Dropped file limit defaulting to 100.
2026-05-28 20:58:10,495 [root] DEBUG: 20720: Disabling sleep skipping.
2026-05-28 20:58:10,498 [root] DEBUG: 20720: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:58:10,510 [root] DEBUG: 20720: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:58:10,513 [root] DEBUG: 20720: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:58:10,516 [root] DEBUG: 20720: Monitor initialised: 64-bit capemon loaded in process 20720 at 0x00007FFF1A580000, thread 20724, image base 0x00007FF7BF220000, stack from 0x0000009B4A094000-0x0000009B4A0A0000
2026-05-28 20:58:10,521 [root] DEBUG: 20720: Commandline: C:\Windows\System32\svchost.exe -k WerSvcGroup
2026-05-28 20:58:10,534 [root] DEBUG: 20720: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:58:10,560 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:58:10,563 [root] DEBUG: 20720: set_hooks: Unable to hook LockResource
2026-05-28 20:58:10,571 [root] DEBUG: 20720: Hooked 627 out of 628 functions
2026-05-28 20:58:10,573 [root] DEBUG: 20720: Syscall hook installed, syscall logging level 1
2026-05-28 20:58:10,579 [root] DEBUG: 20720: RestoreHeaders: Restored original import table.
2026-05-28 20:58:10,583 [root] INFO: Loaded monitor into process with pid 20720
2026-05-28 20:58:10,586 [root] DEBUG: 20720: caller_dispatch: Added region at 0x00007FF7BF220000 to tracked regions list (kernel32::GetCommandLineW returns to 0x00007FF7BF2250EA, thread 20724).
2026-05-28 20:58:10,590 [root] DEBUG: 20720: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-28 20:58:10,596 [root] DEBUG: 20720: ProcessImageBase: Main module image at 0x00007FF7BF220000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:58:10,603 [root] DEBUG: 20720: DLL loaded at 0x00007FFF523E0000: c:\windows\system32\XmlLite (0x36000 bytes).
2026-05-28 20:58:10,605 [root] DEBUG: 20720: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:58:10,609 [root] DEBUG: 20720: DLL loaded at 0x00007FFF3E0F0000: c:\windows\system32\WindowsPerformanceRecorderControl (0x12d000 bytes).
2026-05-28 20:58:10,613 [root] DEBUG: 20720: DLL loaded at 0x00007FFF00610000: c:\windows\system32\WerEtw (0x3f000 bytes).
2026-05-28 20:58:10,617 [root] DEBUG: 20720: DLL loaded at 0x00007FFF00E80000: c:\windows\system32\wersvc (0x45000 bytes).
2026-05-28 20:58:10,624 [root] DEBUG: 20720: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-28 20:58:10,633 [root] DEBUG: 20720: DLL loaded at 0x00007FFF55330000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:58:10,641 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,646 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,654 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,658 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,662 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,666 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,682 [root] DEBUG: 20720: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:58:10,690 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,693 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,699 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,700 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,704 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,709 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,725 [root] DEBUG: 20720: OpenProcessHandler: Injection info created for process 22012, handle 0x290: C:\Windows\System32\svchost.exe
2026-05-28 20:58:10,727 [root] DEBUG: 20720: OpenProcessHandler: Image base for process 22012 (handle 0x290): 0x00007FF7BF220000.
2026-05-28 20:58:10,732 [root] DEBUG: 20720: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:58:10,736 [root] DEBUG: 20720: CreateProcessHandler: Injection info set for new process 8436: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:58:10,741 [root] DEBUG: 20720: ProcessMessage: Skipping monitoring process 8436
2026-05-28 20:58:10,743 [root] DEBUG: 20720: ProcessMessage: Skipping monitoring process 8436
2026-05-28 20:58:10,765 [root] DEBUG: 20720: DLL loaded at 0x00007FFF47530000: c:\windows\system32\dbghelp (0x1e4000 bytes).
2026-05-28 20:58:10,773 [root] DEBUG: 20720: DLL loaded at 0x00007FFF474F0000: c:\windows\system32\dbgcore (0x34000 bytes).
2026-05-28 20:58:10,775 [root] DEBUG: 20720: DLL loaded at 0x00007FFF46350000: c:\windows\system32\faultrep (0x7b000 bytes).
2026-05-28 20:58:10,778 [root] DEBUG: 20720: DLL loaded at 0x00007FFF55330000: c:\windows\system32\wer (0xde000 bytes).
2026-05-28 20:58:10,784 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,787 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,793 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,794 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,801 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,802 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,821 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,823 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,828 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,830 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,836 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,839 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,852 [root] DEBUG: 20720: DLL loaded at 0x00007FFF57520000: c:\windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:58:10,857 [root] DEBUG: 20720: DLL loaded at 0x00007FFF57560000: c:\windows\system32\profapi (0x25000 bytes).
2026-05-28 20:58:10,865 [root] DEBUG: 20720: CreateProcessHandler: Injection info set for new process 21568: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF7365D0000
2026-05-28 20:58:10,866 [root] DEBUG: 20720: ProcessMessage: Skipping monitoring process 21568
2026-05-28 20:58:10,870 [root] DEBUG: 20720: ProcessMessage: Skipping monitoring process 21568
2026-05-28 20:58:10,988 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,992 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:10,996 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:10,999 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:11,006 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:11,009 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:11,017 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER3F86.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER3F86.tmp'
2026-05-28 20:58:11,020 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER3F86.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER3F86.tmp'
2026-05-28 20:58:11,049 [root] DEBUG: 20720: api-rate-cap: NtWriteFile hook disabled due to rate
2026-05-28 20:58:11,069 [root] INFO: Added new file to list with pid 20720 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER3F86.tmp.csv
2026-05-28 20:58:11,077 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:11,079 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:11,085 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:11,086 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:11,092 [root] DEBUG: 20720: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:58:11,102 [root] DEBUG: 20720: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:58:11,111 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER3FE5.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER3FE5.tmp'
2026-05-28 20:58:11,115 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WER3FE5.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WER3FE5.tmp'
2026-05-28 20:58:11,121 [root] INFO: Added new file to list with pid 20720 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WER3FE5.tmp.txt
2026-05-28 20:58:12,233 [root] INFO: Added new file to list with pid 22012 and path C:\ProgramData\USOShared\Logs\System\UpdateSessionOrchestration.1b383405-3825-4fb0-9c97-4a5ada73563b.1.etl
2026-05-28 20:58:12,237 [root] INFO: Process with pid 22012 has terminated
2026-05-28 20:58:12,238 [root] DEBUG: 22012: NtTerminateProcess hook: Attempting to dump process 22012
2026-05-28 20:58:12,242 [root] DEBUG: 22012: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:58:12,705 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:12,711 [root] DEBUG: Loader: Injecting process 22508 (thread 22512) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:12,713 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:12,715 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:12,717 [lib.api.process] INFO: Injected into 64-bit <Process 22508 ShellExperienceHost.exe>
2026-05-28 20:58:12,722 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 22508
2026-05-28 20:58:12,724 [lib.api.process] INFO: Monitor config for process 22508: C:\rl4cuydm\dll\22508.ini
2026-05-28 20:58:12,726 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:12,935 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:12,942 [root] DEBUG: Loader: Injecting process 22028 (thread 22032) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:12,946 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:12,948 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:12,950 [lib.api.process] INFO: Injected into 64-bit <Process 22028 WMIADAP.exe>
2026-05-28 20:58:12,957 [root] INFO: Announced 64-bit process name: WMIADAP.exe pid: 22028
2026-05-28 20:58:12,959 [lib.api.process] INFO: Monitor config for process 22028: C:\rl4cuydm\dll\22028.ini
2026-05-28 20:58:12,961 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:16,801 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:16,806 [root] DEBUG: Loader: Injecting process 22508 (thread 22512) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:16,808 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:16,811 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:16,812 [lib.api.process] INFO: Injected into 64-bit <Process 22508 ShellExperienceHost.exe>
2026-05-28 20:58:16,814 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 22508
2026-05-28 20:58:16,816 [lib.api.process] INFO: Monitor config for process 22508: C:\rl4cuydm\dll\22508.ini
2026-05-28 20:58:16,817 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:17,041 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:17,048 [root] DEBUG: Loader: Injecting process 22028 (thread 22032) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:17,049 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:17,052 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:17,054 [lib.api.process] INFO: Injected into 64-bit <Process 22028 WMIADAP.exe>
2026-05-28 20:58:17,065 [root] DEBUG: 22028: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:58:17,068 [root] DEBUG: 22028: Interactive desktop enabled.
2026-05-28 20:58:17,073 [root] DEBUG: 22028: Dropped file limit defaulting to 100.
2026-05-28 20:58:17,077 [root] DEBUG: 22028: Disabling sleep skipping.
2026-05-28 20:58:17,079 [root] DEBUG: 22028: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:58:17,092 [root] DEBUG: 22028: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:58:17,095 [root] DEBUG: 22028: YaraScan: Scanning 0x00007FF69C390000, size 0x302f8
2026-05-28 20:58:17,097 [root] DEBUG: 22028: Monitor initialised: 64-bit capemon loaded in process 22028 at 0x00007FFF1A580000, thread 22032, image base 0x00007FF69C390000, stack from 0x0000006ABE5E0000-0x0000006ABE5F0000
2026-05-28 20:58:17,100 [root] DEBUG: 22028: Commandline: wmiadap.exe /F /T /R
2026-05-28 20:58:17,110 [root] DEBUG: 22028: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:58:17,133 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:58:17,135 [root] DEBUG: 22028: set_hooks: Unable to hook LockResource
2026-05-28 20:58:17,141 [root] DEBUG: 22028: Hooked 627 out of 628 functions
2026-05-28 20:58:17,147 [root] DEBUG: 22028: Syscall hook installed, syscall logging level 1
2026-05-28 20:58:17,154 [root] DEBUG: 22028: RestoreHeaders: Restored original import table.
2026-05-28 20:58:17,157 [root] INFO: Loaded monitor into process with pid 22028
2026-05-28 20:58:17,161 [root] DEBUG: 22028: caller_dispatch: Added region at 0x00007FF69C390000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF69C3A62B1, thread 22032).
2026-05-28 20:58:17,164 [root] DEBUG: 22028: YaraScan: Scanning 0x00007FF69C390000, size 0x302f8
2026-05-28 20:58:17,171 [root] DEBUG: 22028: ProcessImageBase: Main module image at 0x00007FF69C390000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:58:17,176 [root] DEBUG: 22028: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:58:17,179 [root] DEBUG: 22028: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:58:17,187 [root] DEBUG: 22028: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:58:17,189 [root] DEBUG: 22028: DLL loaded at 0x00007FFF3FD20000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:58:17,191 [root] DEBUG: 22028: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 20:58:17,197 [root] DEBUG: 22028: DLL loaded at 0x00007FFF3F950000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:58:17,207 [root] DEBUG: 22028: DLL loaded at 0x00007FFF3F9F0000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2026-05-28 20:58:17,212 [root] DEBUG: 22028: DLL loaded at 0x00007FFF3F880000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 20:58:17,215 [root] DEBUG: 22028: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 20:58:17,217 [root] DEBUG: 22028: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 20:58:17,220 [root] DEBUG: 22028: DLL loaded at 0x00007FFF3F830000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 20:58:17,222 [root] DEBUG: 22028: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\version (0xa000 bytes).
2026-05-28 20:58:17,228 [root] DEBUG: 22028: Successfully installed hook on COM Object function IWbemServices_ExecQuery
2026-05-28 20:58:17,230 [root] DEBUG: 22028: Successfully installed hook on COM Object function IWbemServices_ExecQueryAsync
2026-05-28 20:58:17,233 [root] DEBUG: 22028: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnum
2026-05-28 20:58:17,237 [root] DEBUG: 22028: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnumAsync
2026-05-28 20:58:17,242 [root] DEBUG: 22028: Successfully installed hook on COM Object function IWbemServices_GetObjectW
2026-05-28 20:58:17,249 [root] DEBUG: 22028: Successfully installed hook on COM Object function IWbemServices_GetObjectAsync
2026-05-28 20:58:17,251 [root] DEBUG: 22028: Successfully installed hook on COM Object function IWbemServices_ExecMethod
2026-05-28 20:58:17,255 [root] DEBUG: 22028: Successfully installed hook on COM Object function IWbemServices_ExecMethodAsync
2026-05-28 20:58:17,290 [root] DEBUG: 22028: DLL loaded at 0x00007FFF59A70000: C:\Windows\System32\PSAPI (0x8000 bytes).
2026-05-28 20:58:17,293 [root] DEBUG: 22028: DLL loaded at 0x000001A3868E0000: C:\Windows\SYSTEM32\loadperf (0x25000 bytes).
2026-05-28 20:58:17,362 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 23120: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF787820000
2026-05-28 20:58:17,365 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 23120
2026-05-28 20:58:17,366 [lib.api.process] INFO: Monitor config for process 23120: C:\rl4cuydm\dll\23120.ini
2026-05-28 20:58:17,368 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:20,492 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:20,497 [root] DEBUG: Loader: Injecting process 22508 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:20,499 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 22512, handle 0x124
2026-05-28 20:58:20,502 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:20,504 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:20,506 [lib.api.process] INFO: Injected into 64-bit <Process 22508 ShellExperienceHost.exe>
2026-05-28 20:58:21,329 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:21,335 [root] DEBUG: Loader: Injecting process 23120 (thread 23124) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:21,337 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:21,349 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:21,350 [lib.api.process] INFO: Injected into 64-bit <Process 23120 WmiPrvSE.exe>
2026-05-28 20:58:21,357 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 23120
2026-05-28 20:58:21,357 [lib.api.process] INFO: Monitor config for process 23120: C:\rl4cuydm\dll\23120.ini
2026-05-28 20:58:21,360 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:25,150 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:25,155 [root] DEBUG: Loader: Injecting process 23120 (thread 23124) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:25,157 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:25,159 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:25,160 [lib.api.process] INFO: Injected into 64-bit <Process 23120 WmiPrvSE.exe>
2026-05-28 20:58:25,167 [root] DEBUG: 23120: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:58:25,169 [root] DEBUG: 23120: Interactive desktop enabled.
2026-05-28 20:58:25,173 [root] DEBUG: 23120: Dropped file limit defaulting to 100.
2026-05-28 20:58:25,179 [root] DEBUG: 23120: Disabling sleep skipping.
2026-05-28 20:58:25,181 [root] DEBUG: 23120: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:58:25,193 [root] DEBUG: 23120: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:58:25,196 [root] DEBUG: 23120: YaraScan: Scanning 0x00007FF787820000, size 0x7dcfe
2026-05-28 20:58:25,200 [root] DEBUG: 23120: Monitor initialised: 64-bit capemon loaded in process 23120 at 0x00007FFF1A580000, thread 23124, image base 0x00007FF787820000, stack from 0x000000F8028D0000-0x000000F8028E0000
2026-05-28 20:58:25,203 [root] DEBUG: 23120: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -Embedding
2026-05-28 20:58:25,213 [root] DEBUG: 23120: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:58:25,243 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:58:25,245 [root] DEBUG: 23120: set_hooks: Unable to hook LockResource
2026-05-28 20:58:25,250 [root] DEBUG: 23120: Hooked 627 out of 628 functions
2026-05-28 20:58:25,254 [root] DEBUG: 23120: Syscall hook installed, syscall logging level 1
2026-05-28 20:58:25,261 [root] DEBUG: 23120: RestoreHeaders: Restored original import table.
2026-05-28 20:58:25,264 [root] INFO: Loaded monitor into process with pid 23120
2026-05-28 20:58:25,266 [root] DEBUG: 23120: caller_dispatch: Added region at 0x00007FF787820000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF787832CD1, thread 23124).
2026-05-28 20:58:25,268 [root] DEBUG: 23120: YaraScan: Scanning 0x00007FF787820000, size 0x7dcfe
2026-05-28 20:58:25,273 [root] DEBUG: 23120: ProcessImageBase: Main module image at 0x00007FF787820000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:58:25,278 [root] DEBUG: 23120: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:58:25,281 [root] DEBUG: 23120: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:58:25,285 [root] DEBUG: 23120: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:58:25,292 [root] DEBUG: 23120: DLL loaded at 0x00007FFF3FD20000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:58:25,301 [root] DEBUG: 23120: DLL loaded at 0x00007FFF3F950000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:58:25,333 [root] DEBUG: 23120: DLL loaded at 0x00007FFF42BF0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 20:58:25,375 [root] DEBUG: 23120: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:58:25,378 [root] DEBUG: 23120: DLL loaded at 0x00007FFF3F970000: C:\Windows\system32\wbem\esscli (0x7d000 bytes).
2026-05-28 20:58:25,384 [root] DEBUG: 23120: DLL loaded at 0x00007FFF005D0000: C:\Windows\system32\wbem\wmiprov (0x3d000 bytes).
2026-05-28 20:58:25,388 [root] DEBUG: 23120: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-05-28 20:58:25,393 [root] DEBUG: 23120: DLL loaded at 0x00007FFF520C0000: C:\Windows\SYSTEM32\WMICLNT (0x11000 bytes).
2026-05-28 20:58:25,551 [root] DEBUG: 23120: api-rate-cap: ?Get@CWbemObject@@UEAAJPEBGJPEAUtagVARIANT@@PEAJ2@Z hook disabled due to rate
2026-05-28 20:58:25,615 [root] DEBUG: 22028: api-rate-cap: GetUserDefaultLCID hook disabled due to rate
2026-05-28 20:58:26,636 [root] DEBUG: 22028: api-rate-cap: RegQueryValueExW hook disabled due to rate
2026-05-28 20:58:26,817 [root] DEBUG: 22028: api-rate-cap: NtQueryValueKey hook disabled due to rate
2026-05-28 20:58:26,978 [root] DEBUG: 22028: api-rate-cap: GetLastInputInfo hook disabled due to rate
2026-05-28 20:58:28,002 [root] INFO: Added new file to list with pid 22028 and path C:\Windows\System32\wbem\Performance\WmiApRpl_new.h
2026-05-28 20:58:28,010 [lib.common.results] INFO: Uploading file C:\Windows\System32\wbem\Performance\WmiApRpl.h to files\ae2b6236d3eeb4822835714ae9444e5dcd21bc60f7a909f2962c43bc743c7b15; Size is 3444; Max size: 100000000
2026-05-28 20:58:36,101 [root] INFO: Added new file to list with pid 22028 and path C:\Windows\System32\wbem\Performance\WmiApRpl_new.ini
2026-05-28 20:58:36,111 [lib.common.results] INFO: Uploading file C:\Windows\System32\wbem\Performance\WmiApRpl.ini to files\c20b11dff802aa472265f4e9f330244ec4aca81b0009f6efcb2cf8a36086f390; Size is 29736; Max size: 100000000
2026-05-28 20:58:36,147 [root] INFO: Added new file to list with pid 22028 and path C:\Windows\System32\perfc009.dat
2026-05-28 20:58:36,149 [root] INFO: Added new file to list with pid 22028 and path C:\Windows\System32\perfh009.dat
2026-05-28 20:58:36,156 [lib.common.results] INFO: Uploading file C:\Windows\INF\WmiApRpl\0009\WmiApRpl.ini to files\c20b11dff802aa472265f4e9f330244ec4aca81b0009f6efcb2cf8a36086f390; Size is 29736; Max size: 100000000
2026-05-28 20:58:36,167 [lib.common.results] INFO: Uploading file C:\Windows\INF\WmiApRpl\WmiApRpl.h to files\ae2b6236d3eeb4822835714ae9444e5dcd21bc60f7a909f2962c43bc743c7b15; Size is 3444; Max size: 100000000
2026-05-28 20:58:36,176 [lib.common.results] INFO: Uploading file C:\Windows\INF\WmiApRpl\WmiApRpl.ini to files\c20b11dff802aa472265f4e9f330244ec4aca81b0009f6efcb2cf8a36086f390; Size is 29736; Max size: 100000000
2026-05-28 20:58:36,398 [root] DEBUG: 22028: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:58:36,400 [root] INFO: Added new file to list with pid 22028 and path C:\Windows\INF\WmiApRpl\WmiApRpl.h
2026-05-28 20:58:36,413 [root] INFO: Added new file to list with pid 22028 and path C:\Windows\INF\WmiApRpl\WmiApRpl.ini
2026-05-28 20:58:36,477 [root] DEBUG: 22028: api-rate-cap: RegEnumKeyExW hook disabled due to rate
2026-05-28 20:58:36,502 [root] DEBUG: 22028: api-rate-cap: RegOpenKeyExW hook disabled due to rate
2026-05-28 20:58:36,522 [root] DEBUG: 22028: api-rate-cap: NtWriteFile hook disabled due to rate
2026-05-28 20:58:36,542 [root] INFO: Added new file to list with pid 22028 and path C:\Windows\System32\PerfStringBackup.TMP
2026-05-28 20:58:36,551 [root] INFO: Added new file to list with pid 22028 and path C:\Windows\System32\PerfStringBackup.INI
2026-05-28 20:58:36,566 [lib.common.results] INFO: Uploading file C:\Windows\System32\PerfStringBackup.TMP to files\dff86bc86785d4235c80408b73210f340d2d0cbc155113a79045b741359b8542; Size is 795738; Max size: 100000000
2026-05-28 20:58:36,677 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 23620: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:58:36,679 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23620
2026-05-28 20:58:36,683 [lib.api.process] INFO: Monitor config for process 23620: C:\rl4cuydm\dll\23620.ini
2026-05-28 20:58:36,689 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 23664: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:58:36,692 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23664
2026-05-28 20:58:36,702 [lib.api.process] INFO: Monitor config for process 23664: C:\rl4cuydm\dll\23664.ini
2026-05-28 20:58:36,715 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 23708: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:58:36,716 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23708
2026-05-28 20:58:36,717 [lib.api.process] INFO: Monitor config for process 23708: C:\rl4cuydm\dll\23708.ini
2026-05-28 20:58:37,692 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,701 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,708 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,709 [root] DEBUG: Loader: Injecting process 23620 (thread 23624) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,712 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:37,717 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,718 [lib.api.process] INFO: Injected into 64-bit <Process 23620 backgroundTaskHost.exe>
2026-05-28 20:58:37,720 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,723 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,724 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23620
2026-05-28 20:58:37,727 [lib.api.process] INFO: Monitor config for process 23620: C:\rl4cuydm\dll\23620.ini
2026-05-28 20:58:37,727 [root] DEBUG: Loader: Injecting process 23664 (thread 23668) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,728 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,729 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:37,733 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,734 [lib.api.process] INFO: Injected into 64-bit <Process 23664 backgroundTaskHost.exe>
2026-05-28 20:58:37,735 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,738 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23664
2026-05-28 20:58:37,741 [lib.api.process] INFO: Monitor config for process 23664: C:\rl4cuydm\dll\23664.ini
2026-05-28 20:58:37,741 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,743 [root] DEBUG: Loader: Injecting process 23708 (thread 23712) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,744 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:37,746 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,748 [lib.api.process] INFO: Injected into 64-bit <Process 23708 backgroundTaskHost.exe>
2026-05-28 20:58:37,749 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,751 [root] DEBUG: 832: DLL loaded at 0x00007FFF54E60000: C:\Windows\system32\apphelp (0x90000 bytes).
2026-05-28 20:58:37,755 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23708
2026-05-28 20:58:37,755 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,756 [root] DEBUG: Loader: Injecting process 23620 (thread 23624) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,756 [lib.api.process] INFO: Monitor config for process 23708: C:\rl4cuydm\dll\23708.ini
2026-05-28 20:58:37,759 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,758 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:37,760 [root] DEBUG: Loader: Injecting process 23664 (thread 23668) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,764 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:37,765 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,767 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,769 [lib.api.process] INFO: Injected into 64-bit <Process 23620 backgroundTaskHost.exe>
2026-05-28 20:58:37,770 [lib.api.process] INFO: Injected into 64-bit <Process 23664 backgroundTaskHost.exe>
2026-05-28 20:58:37,776 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23620
2026-05-28 20:58:37,777 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23664
2026-05-28 20:58:37,776 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,778 [lib.api.process] INFO: Monitor config for process 23620: C:\rl4cuydm\dll\23620.ini
2026-05-28 20:58:37,779 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,780 [lib.api.process] INFO: Monitor config for process 23664: C:\rl4cuydm\dll\23664.ini
2026-05-28 20:58:37,782 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,784 [root] DEBUG: Loader: Injecting process 23708 (thread 23712) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,786 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:37,791 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,793 [lib.api.process] INFO: Injected into 64-bit <Process 23708 backgroundTaskHost.exe>
2026-05-28 20:58:37,797 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,798 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 23708
2026-05-28 20:58:37,801 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,802 [lib.api.process] INFO: Monitor config for process 23708: C:\rl4cuydm\dll\23708.ini
2026-05-28 20:58:37,803 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,806 [root] DEBUG: Loader: Injecting process 23620 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,810 [root] DEBUG: Loader: Injecting process 23664 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,811 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 23624, handle 0x120
2026-05-28 20:58:37,814 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 23668, handle 0x120
2026-05-28 20:58:37,818 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:37,823 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:37,825 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,827 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,827 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,828 [lib.api.process] INFO: Injected into 64-bit <Process 23664 backgroundTaskHost.exe>
2026-05-28 20:58:37,830 [lib.api.process] INFO: Injected into 64-bit <Process 23620 backgroundTaskHost.exe>
2026-05-28 20:58:37,833 [root] DEBUG: Loader: Injecting process 23708 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,834 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 23712, handle 0x138
2026-05-28 20:58:37,838 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:37,840 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,840 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24144: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:58:37,843 [lib.api.process] INFO: Injected into 64-bit <Process 23708 backgroundTaskHost.exe>
2026-05-28 20:58:37,845 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24144
2026-05-28 20:58:37,848 [lib.api.process] INFO: Monitor config for process 24144: C:\rl4cuydm\dll\24144.ini
2026-05-28 20:58:37,869 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24188: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:58:37,874 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24188
2026-05-28 20:58:37,875 [lib.api.process] INFO: Monitor config for process 24188: C:\rl4cuydm\dll\24188.ini
2026-05-28 20:58:37,878 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,895 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,901 [root] DEBUG: Loader: Injecting process 24188 (thread 24192) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,906 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:37,908 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,911 [lib.api.process] INFO: Injected into 64-bit <Process 24188 backgroundTaskHost.exe>
2026-05-28 20:58:37,920 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24188
2026-05-28 20:58:37,923 [lib.api.process] INFO: Monitor config for process 24188: C:\rl4cuydm\dll\24188.ini
2026-05-28 20:58:37,924 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:37,938 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:37,945 [root] DEBUG: Loader: Injecting process 24188 (thread 24192) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,947 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:37,948 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:37,949 [lib.api.process] INFO: Injected into 64-bit <Process 24188 backgroundTaskHost.exe>
2026-05-28 20:58:37,959 [root] INFO: Process with pid 24188 has terminated
2026-05-28 20:58:38,863 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:38,875 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:38,881 [root] DEBUG: Loader: Injecting process 24144 (thread 24148) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:38,884 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:38,885 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:38,889 [lib.api.process] INFO: Injected into 64-bit <Process 24144 backgroundTaskHost.exe>
2026-05-28 20:58:38,893 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24144
2026-05-28 20:58:38,895 [lib.api.process] INFO: Monitor config for process 24144: C:\rl4cuydm\dll\24144.ini
2026-05-28 20:58:38,896 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:38,907 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:38,915 [root] DEBUG: Loader: Injecting process 24144 (thread 24148) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:38,919 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:38,920 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:38,923 [lib.api.process] INFO: Injected into 64-bit <Process 24144 backgroundTaskHost.exe>
2026-05-28 20:58:38,925 [root] INFO: Process with pid 24144 has terminated
2026-05-28 20:58:38,929 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24392: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 20:58:38,931 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24392
2026-05-28 20:58:38,933 [lib.api.process] INFO: Monitor config for process 24392: C:\rl4cuydm\dll\24392.ini
2026-05-28 20:58:39,941 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:39,950 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:39,955 [root] DEBUG: Loader: Injecting process 24392 (thread 24396) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:39,959 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:39,961 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:39,963 [lib.api.process] INFO: Injected into 64-bit <Process 24392 backgroundTaskHost.exe>
2026-05-28 20:58:39,966 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24392
2026-05-28 20:58:39,968 [lib.api.process] INFO: Monitor config for process 24392: C:\rl4cuydm\dll\24392.ini
2026-05-28 20:58:39,969 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:39,981 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:39,985 [root] DEBUG: Loader: Injecting process 24392 (thread 24396) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:39,989 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:58:39,992 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:39,994 [lib.api.process] INFO: Injected into 64-bit <Process 24392 backgroundTaskHost.exe>
2026-05-28 20:58:39,998 [root] INFO: Process with pid 24392 has terminated
2026-05-28 20:58:41,804 [root] DEBUG: 22028: NtTerminateProcess hook: Attempting to dump process 22028
2026-05-28 20:58:41,806 [root] DEBUG: 22028: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:58:41,815 [root] INFO: Process with pid 22028 has terminated
2026-05-28 20:58:46,216 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24572: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 20:58:46,234 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 24572
2026-05-28 20:58:46,239 [lib.api.process] INFO: Monitor config for process 24572: C:\rl4cuydm\dll\24572.ini
2026-05-28 20:58:47,254 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:47,264 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:47,271 [root] DEBUG: Loader: Injecting process 24572 (thread 23192) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:47,274 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:47,279 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:47,281 [lib.api.process] INFO: Injected into 64-bit <Process 24572 dllhost.exe>
2026-05-28 20:58:47,286 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 24572
2026-05-28 20:58:47,288 [lib.api.process] INFO: Monitor config for process 24572: C:\rl4cuydm\dll\24572.ini
2026-05-28 20:58:47,289 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:58:47,299 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 20:58:47,304 [root] DEBUG: Loader: Injecting process 24572 (thread 23192) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:47,307 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:58:47,311 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 20:58:47,313 [lib.api.process] INFO: Injected into 64-bit <Process 24572 dllhost.exe>
2026-05-28 20:58:47,320 [root] DEBUG: 24572: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:58:47,324 [root] DEBUG: 24572: Interactive desktop enabled.
2026-05-28 20:58:47,326 [root] DEBUG: 24572: Dropped file limit defaulting to 100.
2026-05-28 20:58:47,333 [root] DEBUG: 24572: Disabling sleep skipping.
2026-05-28 20:58:47,336 [root] DEBUG: 24572: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 20:58:47,349 [root] DEBUG: 24572: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 20:58:47,353 [root] DEBUG: 24572: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:58:47,358 [root] DEBUG: 24572: Monitor initialised: 64-bit capemon loaded in process 24572 at 0x00007FFF1A580000, thread 23192, image base 0x00007FF6706B0000, stack from 0x000000B33BCF4000-0x000000B33BD00000
2026-05-28 20:58:47,363 [root] DEBUG: 24572: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:58:47,374 [root] DEBUG: 24572: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 20:58:47,400 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:58:47,402 [root] DEBUG: 24572: set_hooks: Unable to hook LockResource
2026-05-28 20:58:47,408 [root] DEBUG: 24572: Hooked 627 out of 628 functions
2026-05-28 20:58:47,414 [root] DEBUG: 24572: Syscall hook installed, syscall logging level 1
2026-05-28 20:58:47,421 [root] DEBUG: 24572: RestoreHeaders: Restored original import table.
2026-05-28 20:58:47,424 [root] INFO: Loaded monitor into process with pid 24572
2026-05-28 20:58:47,426 [root] DEBUG: 24572: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6706B1349, thread 23192).
2026-05-28 20:58:47,428 [root] DEBUG: 24572: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 20:58:47,432 [root] DEBUG: 24572: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:58:47,437 [root] DEBUG: 24572: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:58:47,439 [root] DEBUG: 24572: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:58:47,444 [root] DEBUG: 24572: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:58:47,460 [root] DEBUG: 24572: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:58:47,475 [root] DEBUG: 24572: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:58:47,477 [root] DEBUG: 24572: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:58:47,485 [root] DEBUG: 24572: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:58:52,601 [root] INFO: Process with pid 24572 has terminated
2026-05-28 20:58:52,602 [root] DEBUG: 24572: NtTerminateProcess hook: Attempting to dump process 24572
2026-05-28 20:58:52,606 [root] DEBUG: 24572: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:59:25,617 [root] DEBUG: 2564: NtTerminateProcess hook: Attempting to dump process 2564
2026-05-28 20:59:25,618 [root] DEBUG: 2564: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:59:25,620 [root] INFO: Process with pid 2564 has terminated
2026-05-28 21:00:09,883 [root] DEBUG: 4484: api-cap: NtQueryInformationFile hook disabled due to count: 5000
2026-05-28 21:00:11,148 [root] INFO: Added new file to list with pid 20720 and path C:\ProgramData\Microsoft\Windows\WER\Temp\29cbc21b-3f43-4c4f-a8d5-4ba946606d05
2026-05-28 21:00:11,150 [root] DEBUG: 20720: NtTerminateProcess hook: Attempting to dump process 20720
2026-05-28 21:00:11,152 [root] DEBUG: 20720: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:00:11,165 [root] INFO: Process with pid 20720 has terminated
2026-05-28 21:00:22,250 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54D70000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 21:00:22,255 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54D70000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 21:00:22,300 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54D10000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 21:00:22,303 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54D10000: C:\Program Files\Windows Defender\shellext (0x55000 bytes).
2026-05-28 21:00:22,328 [root] DEBUG: 4484: DLL loaded at 0x0000000002FE0000: C:\Windows\system32\sfc (0x3000 bytes).
2026-05-28 21:00:22,332 [root] DEBUG: 4484: DLL loaded at 0x0000000002FE0000: C:\Windows\system32\sfc (0x3000 bytes).
2026-05-28 21:00:22,335 [root] DEBUG: 4484: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\msi (0x337000 bytes).
2026-05-28 21:00:22,338 [root] DEBUG: 4484: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\msi (0x337000 bytes).
2026-05-28 21:00:22,340 [root] DEBUG: 4484: DLL loaded at 0x00007FFF453F0000: C:\Windows\system32\sfc_os (0x12000 bytes).
2026-05-28 21:00:22,342 [root] DEBUG: 4484: DLL loaded at 0x00007FFF453F0000: C:\Windows\system32\sfc_os (0x12000 bytes).
2026-05-28 21:00:22,344 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54CF0000: C:\Windows\system32\acppage (0x19000 bytes).
2026-05-28 21:00:22,347 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54CF0000: C:\Windows\system32\acppage (0x19000 bytes).
2026-05-28 21:00:22,392 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54CC0000: C:\Windows\System32\sendmail (0x2b000 bytes).
2026-05-28 21:00:22,397 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54CC0000: C:\Windows\System32\sendmail (0x2b000 bytes).
2026-05-28 21:00:22,415 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54CA0000: C:\Windows\system32\mydocs (0x11000 bytes).
2026-05-28 21:00:22,417 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54CA0000: C:\Windows\system32\mydocs (0x11000 bytes).
2026-05-28 21:00:23,593 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C240000: C:\Windows\System32\smartscreenps (0x52000 bytes).
2026-05-28 21:00:23,597 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C240000: C:\Windows\System32\smartscreenps (0x52000 bytes).
2026-05-28 21:00:23,787 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 21:00:23,790 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 21:00:23,801 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE170000.
2026-05-28 21:00:23,802 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE160000.
2026-05-28 21:00:23,807 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE150000.
2026-05-28 21:00:23,813 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE131000, size: 0x1000.
2026-05-28 21:00:23,830 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 23772: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF679750000
2026-05-28 21:00:23,835 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 23772
2026-05-28 21:00:23,836 [lib.api.process] INFO: Monitor config for process 23772: C:\rl4cuydm\dll\23772.ini
2026-05-28 21:00:23,841 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:00:23,876 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:00:23,881 [root] DEBUG: Loader: Injecting process 23772 (thread 3192) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:23,884 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:00:23,888 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:23,891 [lib.api.process] INFO: Injected into 64-bit <Process 23772 CHXSmartScreen.exe>
2026-05-28 21:00:23,895 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 23772
2026-05-28 21:00:23,903 [lib.api.process] INFO: Monitor config for process 23772: C:\rl4cuydm\dll\23772.ini
2026-05-28 21:00:23,905 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:00:23,929 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:00:23,934 [root] DEBUG: Loader: Injecting process 23772 (thread 3192) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:23,937 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:00:23,940 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:23,943 [lib.api.process] INFO: Injected into 64-bit <Process 23772 CHXSmartScreen.exe>
2026-05-28 21:00:23,958 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 23772
2026-05-28 21:00:23,966 [lib.api.process] INFO: Monitor config for process 23772: C:\rl4cuydm\dll\23772.ini
2026-05-28 21:00:23,967 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:00:23,992 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:00:24,000 [root] DEBUG: Loader: Injecting process 23772 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:24,002 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 3192, handle 0x120
2026-05-28 21:00:24,006 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:00:24,012 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:24,013 [lib.api.process] INFO: Injected into 64-bit <Process 23772 CHXSmartScreen.exe>
2026-05-28 21:00:24,248 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-28 21:00:24,253 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:00:24,256 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE150000.
2026-05-28 21:00:24,258 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:00:24,260 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE140000.
2026-05-28 21:00:24,263 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:00:24,265 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE160000.
2026-05-28 21:00:24,267 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:00:24,269 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE170000.
2026-05-28 21:00:24,271 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:00:24,498 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
2026-05-28 21:00:49,689 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 23392: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:00:49,698 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 23392
2026-05-28 21:00:49,723 [lib.api.process] INFO: Monitor config for process 23392: C:\rl4cuydm\dll\23392.ini
2026-05-28 21:00:49,741 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:00:49,752 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:00:49,766 [root] DEBUG: Loader: Injecting process 23392 (thread 23388) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:49,767 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:00:49,769 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:49,771 [lib.api.process] INFO: Injected into 64-bit <Process 23392 dllhost.exe>
2026-05-28 21:00:49,775 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 23392
2026-05-28 21:00:49,778 [lib.api.process] INFO: Monitor config for process 23392: C:\rl4cuydm\dll\23392.ini
2026-05-28 21:00:49,781 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:00:49,790 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:00:49,796 [root] DEBUG: Loader: Injecting process 23392 (thread 23388) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:49,806 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:00:49,823 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:00:49,827 [lib.api.process] INFO: Injected into 64-bit <Process 23392 dllhost.exe>
2026-05-28 21:00:49,839 [root] DEBUG: 23392: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:00:49,842 [root] DEBUG: 23392: Interactive desktop enabled.
2026-05-28 21:00:49,846 [root] DEBUG: 23392: Dropped file limit defaulting to 100.
2026-05-28 21:00:49,849 [root] DEBUG: 23392: Disabling sleep skipping.
2026-05-28 21:00:49,853 [root] DEBUG: 23392: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:00:49,866 [root] DEBUG: 23392: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:00:49,868 [root] DEBUG: 23392: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:00:49,869 [root] DEBUG: 23392: Monitor initialised: 64-bit capemon loaded in process 23392 at 0x00007FFF1A580000, thread 23388, image base 0x00007FF6706B0000, stack from 0x0000008F1B0F4000-0x0000008F1B100000
2026-05-28 21:00:49,873 [root] DEBUG: 23392: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 21:00:49,888 [root] DEBUG: 23392: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:00:49,912 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:00:49,915 [root] DEBUG: 23392: set_hooks: Unable to hook LockResource
2026-05-28 21:00:49,920 [root] DEBUG: 23392: Hooked 627 out of 628 functions
2026-05-28 21:00:49,923 [root] DEBUG: 23392: Syscall hook installed, syscall logging level 1
2026-05-28 21:00:49,928 [root] DEBUG: 23392: RestoreHeaders: Restored original import table.
2026-05-28 21:00:49,929 [root] INFO: Loaded monitor into process with pid 23392
2026-05-28 21:00:49,932 [root] DEBUG: 23392: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 23388).
2026-05-28 21:00:49,935 [root] DEBUG: 23392: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:00:49,940 [root] DEBUG: 23392: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:00:49,945 [root] DEBUG: 23392: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:00:49,949 [root] DEBUG: 23392: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:00:49,954 [root] DEBUG: 23392: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:00:49,976 [root] DEBUG: 23392: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:00:49,994 [root] DEBUG: 23392: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:00:49,997 [root] DEBUG: 23392: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 21:00:50,004 [root] DEBUG: 23392: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 21:00:55,103 [root] INFO: Process with pid 23392 has terminated
2026-05-28 21:00:55,105 [root] DEBUG: 23392: NtTerminateProcess hook: Attempting to dump process 23392
2026-05-28 21:00:55,109 [root] DEBUG: 23392: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:01:24,373 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47070000: C:\Windows\System32\Windows.StateRepositoryBroker (0x20000 bytes).
2026-05-28 21:01:24,375 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47070000: C:\Windows\System32\Windows.StateRepositoryBroker (0x20000 bytes).
2026-05-28 21:01:24,413 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24180: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe, ImageBase: 0x00007FF6C0120000
2026-05-28 21:01:24,419 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 24180
2026-05-28 21:01:24,422 [lib.api.process] INFO: Monitor config for process 24180: C:\rl4cuydm\dll\24180.ini
2026-05-28 21:01:24,425 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:24,458 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24316: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:01:24,463 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 24316
2026-05-28 21:01:24,466 [lib.api.process] INFO: Monitor config for process 24316: C:\rl4cuydm\dll\24316.ini
2026-05-28 21:01:24,472 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:24,497 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:24,508 [root] DEBUG: Loader: Injecting process 24316 (thread 23316) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,514 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:24,516 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,518 [lib.api.process] INFO: Injected into 64-bit <Process 24316 dllhost.exe>
2026-05-28 21:01:24,528 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 24316
2026-05-28 21:01:24,531 [lib.api.process] INFO: Monitor config for process 24316: C:\rl4cuydm\dll\24316.ini
2026-05-28 21:01:24,534 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:24,557 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:24,562 [root] DEBUG: Loader: Injecting process 24316 (thread 23316) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,564 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:24,567 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,576 [lib.api.process] INFO: Injected into 64-bit <Process 24316 dllhost.exe>
2026-05-28 21:01:24,587 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24480: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:01:24,598 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 24480
2026-05-28 21:01:24,603 [lib.api.process] INFO: Monitor config for process 24480: C:\rl4cuydm\dll\24480.ini
2026-05-28 21:01:24,608 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:24,626 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:24,637 [root] DEBUG: Loader: Injecting process 24480 (thread 23344) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,640 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:24,641 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,644 [lib.api.process] INFO: Injected into 64-bit <Process 24480 dllhost.exe>
2026-05-28 21:01:24,659 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 24480
2026-05-28 21:01:24,660 [lib.api.process] INFO: Monitor config for process 24480: C:\rl4cuydm\dll\24480.ini
2026-05-28 21:01:24,661 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:24,683 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:24,689 [root] DEBUG: Loader: Injecting process 24480 (thread 23344) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,691 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:24,695 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,700 [lib.api.process] INFO: Injected into 64-bit <Process 24480 dllhost.exe>
2026-05-28 21:01:24,709 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 23384: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:01:24,716 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 23384
2026-05-28 21:01:24,719 [lib.api.process] INFO: Monitor config for process 23384: C:\rl4cuydm\dll\23384.ini
2026-05-28 21:01:24,725 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:24,733 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:24,739 [root] DEBUG: Loader: Injecting process 23384 (thread 20244) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,740 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:24,744 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,745 [lib.api.process] INFO: Injected into 64-bit <Process 23384 dllhost.exe>
2026-05-28 21:01:24,748 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 23384
2026-05-28 21:01:24,752 [lib.api.process] INFO: Monitor config for process 23384: C:\rl4cuydm\dll\23384.ini
2026-05-28 21:01:24,753 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:24,778 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:24,786 [root] DEBUG: Loader: Injecting process 23384 (thread 20244) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,788 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:24,794 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:24,800 [lib.api.process] INFO: Injected into 64-bit <Process 23384 dllhost.exe>
2026-05-28 21:01:24,809 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 22764: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:01:24,814 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 22764
2026-05-28 21:01:24,815 [lib.api.process] INFO: Monitor config for process 22764: C:\rl4cuydm\dll\22764.ini
2026-05-28 21:01:25,820 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:25,842 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:25,848 [root] DEBUG: Loader: Injecting process 22764 (thread 22796) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:25,851 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:25,856 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:25,858 [lib.api.process] INFO: Injected into 64-bit <Process 22764 dllhost.exe>
2026-05-28 21:01:25,871 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 22764
2026-05-28 21:01:25,875 [lib.api.process] INFO: Monitor config for process 22764: C:\rl4cuydm\dll\22764.ini
2026-05-28 21:01:25,877 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:25,895 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:25,903 [root] DEBUG: Loader: Injecting process 22764 (thread 22796) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:25,909 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:25,911 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:25,914 [lib.api.process] INFO: Injected into 64-bit <Process 22764 dllhost.exe>
2026-05-28 21:01:25,922 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 15508: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:01:25,929 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15508
2026-05-28 21:01:25,930 [lib.api.process] INFO: Monitor config for process 15508: C:\rl4cuydm\dll\15508.ini
2026-05-28 21:01:26,944 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:26,961 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:26,967 [root] DEBUG: Loader: Injecting process 15508 (thread 352) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:26,969 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:26,973 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:26,975 [lib.api.process] INFO: Injected into 64-bit <Process 15508 dllhost.exe>
2026-05-28 21:01:26,985 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 15508
2026-05-28 21:01:26,986 [lib.api.process] INFO: Monitor config for process 15508: C:\rl4cuydm\dll\15508.ini
2026-05-28 21:01:26,991 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:27,008 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:27,013 [root] DEBUG: Loader: Injecting process 15508 (thread 352) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:27,018 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:27,021 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:27,026 [lib.api.process] INFO: Injected into 64-bit <Process 15508 dllhost.exe>
2026-05-28 21:01:27,036 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 3880: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:01:27,039 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3880
2026-05-28 21:01:27,040 [lib.api.process] INFO: Monitor config for process 3880: C:\rl4cuydm\dll\3880.ini
2026-05-28 21:01:27,043 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:27,062 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:27,067 [root] DEBUG: Loader: Injecting process 3880 (thread 22484) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:27,070 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:27,072 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:27,074 [lib.api.process] INFO: Injected into 64-bit <Process 3880 dllhost.exe>
2026-05-28 21:01:27,081 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3880
2026-05-28 21:01:27,086 [lib.api.process] INFO: Monitor config for process 3880: C:\rl4cuydm\dll\3880.ini
2026-05-28 21:01:27,089 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:27,106 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:27,113 [root] DEBUG: Loader: Injecting process 3880 (thread 22484) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:27,117 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:27,122 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:27,127 [lib.api.process] INFO: Injected into 64-bit <Process 3880 dllhost.exe>
2026-05-28 21:01:27,815 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:27,822 [root] DEBUG: Loader: Injecting process 24180 (thread 24176) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:27,824 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:27,825 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:27,827 [lib.api.process] INFO: Injected into 64-bit <Process 24180 TextInputHost.exe>
2026-05-28 21:01:27,831 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 24180
2026-05-28 21:01:27,834 [lib.api.process] INFO: Monitor config for process 24180: C:\rl4cuydm\dll\24180.ini
2026-05-28 21:01:27,836 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:32,565 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:32,572 [root] DEBUG: Loader: Injecting process 24180 (thread 24176) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:32,575 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:32,579 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:32,581 [lib.api.process] INFO: Injected into 64-bit <Process 24180 TextInputHost.exe>
2026-05-28 21:01:32,585 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 24180
2026-05-28 21:01:32,587 [lib.api.process] INFO: Monitor config for process 24180: C:\rl4cuydm\dll\24180.ini
2026-05-28 21:01:32,588 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,202 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,207 [root] DEBUG: Loader: Injecting process 24180 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,210 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 24176, handle 0x120
2026-05-28 21:01:37,214 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:01:37,217 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,220 [lib.api.process] INFO: Injected into 64-bit <Process 24180 TextInputHost.exe>
2026-05-28 21:01:37,662 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 17248: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 21:01:37,665 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17248
2026-05-28 21:01:37,667 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24396: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 21:01:37,669 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24396
2026-05-28 21:01:37,669 [lib.api.process] INFO: Monitor config for process 17248: C:\rl4cuydm\dll\17248.ini
2026-05-28 21:01:37,672 [lib.api.process] INFO: Monitor config for process 24396: C:\rl4cuydm\dll\24396.ini
2026-05-28 21:01:37,675 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 24176: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF679C00000
2026-05-28 21:01:37,675 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,678 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,680 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24176
2026-05-28 21:01:37,682 [lib.api.process] INFO: Monitor config for process 24176: C:\rl4cuydm\dll\24176.ini
2026-05-28 21:01:37,683 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,684 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,692 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,699 [root] DEBUG: Loader: Injecting process 24396 (thread 21636) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,700 [root] DEBUG: Loader: Injecting process 17248 (thread 17232) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,701 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,702 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:37,705 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:37,707 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,707 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,711 [lib.api.process] INFO: Injected into 64-bit <Process 17248 backgroundTaskHost.exe>
2026-05-28 21:01:37,712 [root] DEBUG: Loader: Injecting process 24176 (thread 24180) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,712 [lib.api.process] INFO: Injected into 64-bit <Process 24396 backgroundTaskHost.exe>
2026-05-28 21:01:37,714 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:01:37,716 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24396
2026-05-28 21:01:37,718 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,719 [lib.api.process] INFO: Monitor config for process 24396: C:\rl4cuydm\dll\24396.ini
2026-05-28 21:01:37,720 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17248
2026-05-28 21:01:37,720 [lib.api.process] INFO: Injected into 64-bit <Process 24176 backgroundTaskHost.exe>
2026-05-28 21:01:37,721 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,723 [lib.api.process] INFO: Monitor config for process 17248: C:\rl4cuydm\dll\17248.ini
2026-05-28 21:01:37,726 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24176
2026-05-28 21:01:37,727 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,731 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,729 [lib.api.process] INFO: Monitor config for process 24176: C:\rl4cuydm\dll\24176.ini
2026-05-28 21:01:37,734 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,739 [root] DEBUG: Loader: Injecting process 24396 (thread 21636) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,742 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:01:37,744 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,746 [lib.api.process] INFO: Injected into 64-bit <Process 24396 backgroundTaskHost.exe>
2026-05-28 21:01:37,747 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,751 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24396
2026-05-28 21:01:37,753 [root] DEBUG: Loader: Injecting process 17248 (thread 17232) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,754 [lib.api.process] INFO: Monitor config for process 24396: C:\rl4cuydm\dll\24396.ini
2026-05-28 21:01:37,753 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,758 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,760 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:01:37,764 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,766 [lib.api.process] INFO: Injected into 64-bit <Process 17248 backgroundTaskHost.exe>
2026-05-28 21:01:37,767 [root] DEBUG: Loader: Injecting process 24176 (thread 24180) with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,769 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:01:37,773 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 17248
2026-05-28 21:01:37,773 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,774 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,777 [lib.api.process] INFO: Monitor config for process 17248: C:\rl4cuydm\dll\17248.ini
2026-05-28 21:01:37,780 [lib.api.process] INFO: Injected into 64-bit <Process 24176 backgroundTaskHost.exe>
2026-05-28 21:01:37,782 [root] DEBUG: Loader: Injecting process 24396 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,782 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,787 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 21636, handle 0x120
2026-05-28 21:01:37,790 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 24176
2026-05-28 21:01:37,792 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:01:37,794 [lib.api.process] INFO: Monitor config for process 24176: C:\rl4cuydm\dll\24176.ini
2026-05-28 21:01:37,796 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:01:37,798 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,800 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,804 [lib.api.process] INFO: Injected into 64-bit <Process 24396 backgroundTaskHost.exe>
2026-05-28 21:01:37,807 [root] DEBUG: Loader: Injecting process 17248 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,811 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 17232, handle 0x124
2026-05-28 21:01:37,811 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\FRqkFpQ.dll, loader C:\rl4cuydm\bin\OsTKfuJq.exe
2026-05-28 21:01:37,814 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:01:37,817 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,819 [lib.api.process] INFO: Injected into 64-bit <Process 17248 backgroundTaskHost.exe>
2026-05-28 21:01:37,820 [root] DEBUG: Loader: Injecting process 24176 with C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,829 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 24180, handle 0x120
2026-05-28 21:01:37,830 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:01:37,834 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\FRqkFpQ.dll.
2026-05-28 21:01:37,835 [lib.api.process] INFO: Injected into 64-bit <Process 24176 backgroundTaskHost.exe>
2026-05-28 21:01:37,888 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 20:53:53 | 2026-05-28 21:01:56 | none |
| Process: HelpPane.exe (14888) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: HelpPane.exe (14888) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: HelpPane.exe (14888) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: HelpPane.exe (14888) | ||||||||
| file | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCookies | |||||||
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| N | 162.159.129.235 [VT] | unknown | - |
| N | 162.159.135.233 [VT] | unknown | - |
| Y | 4.237.153.9 [VT] | unknown | - |
| Y | 40.126.14.162 [VT] | unknown | - |
| Y | 40.126.14.163 [VT] | unknown | - |
| Y | 150.171.28.10 [VT] | unknown | - |
| Y | 204.79.197.203 [VT] | unknown | - |
| Y | 20.44.10.123 [VT] | unknown | - |
| Y | 150.171.27.12 [VT] | unknown | - |
| Y | 149.135.84.50 [VT] | unknown | - |
| Y | 18.155.216.46 [VT] | unknown | - |
| Y | 23.219.86.120 [VT] | unknown | - |
| Y | 150.171.109.25 [VT] | unknown | - |
| Y | 150.171.27.10 [VT] | unknown | - |
| Y | 23.219.86.136 [VT] | unknown | - |
| Y | 149.135.84.41 [VT] | unknown | - |
| N | 146.75.119.82 [VT] | unknown | - |
| Y | 20.227.97.55 [VT] | unknown | - |
| Y | 172.64.154.167 [VT] | unknown | - |
| Y | 104.18.33.89 [VT] | unknown | - |
| Y | 23.202.166.58 [VT] | unknown | - |
| Y | 150.171.109.19 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| N | 162.159.137.234 [VT] | unknown | - |
| Y | 4.200.105.68 [VT] | unknown | - |
| Y | 185.199.110.133 [VT] | unknown | - |
| N | 162.159.134.233 [VT] | unknown | - |
| Y | 149.135.84.160 [VT] | unknown | - |
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 4.237.22.34 [VT] | unknown | - |
| Y | 140.82.113.21 [VT] | unknown | - |
| Y | 185.199.108.133 [VT] | unknown | - |
| Y | 185.199.111.133 [VT] | unknown | - |
| Y | 185.199.111.215 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| N | 4.237.22.38 [VT] | unknown | - |
| N | 162.159.128.233 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| N | 162.254.195.69 [VT] | unknown | - |
| N | 103.10.125.22 [VT] | unknown | - |
| N | 103.10.125.23 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 172.172.255.218 [VT] | unknown | - |
| N | 162.159.133.233 [VT] | unknown | - |
| Y | 162.159.135.234 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.8.8 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| cmp2-syd1.steamserver.net [VT] | A 103.10.125.23 [VT] | 103.10.125.23 [VT] |
| cmp1-syd1.steamserver.net [VT] | A 103.10.125.22 [VT] | 103.10.125.22 [VT] |
| cmp1-lax1.steamserver.net [VT] | A 162.254.195.69 [VT] | 162.254.195.69 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.24 [VT] |
| steamcommunity.com [VT] | 23.216.106.59 [VT] | |
| status.discord.com [VT] |
A 162.159.128.233
[VT]
A 162.159.138.232 [VT] A 162.159.137.232 [VT] A 162.159.135.232 [VT] A 162.159.136.232 [VT] |
162.159.135.232 [VT] |
| github.com [VT] | A 4.237.22.38 [VT] | 4.237.22.38 [VT] |
| cdn.discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.134.233 [VT] |
| discord.com [VT] | 162.159.128.233 [VT] | |
| latency.discord.media [VT] |
A 162.159.130.235
[VT]
A 162.159.129.235 [VT] A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.128.235 [VT] |
162.159.129.235 [VT] |
| client-update.fastly.steamstatic.com [VT] |
A 146.75.119.82
[VT]
CNAME valve.map.fastly.net [VT] |
199.232.211.82 [VT] |
| discordapp.com [VT] | 162.159.129.233 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.