| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 21:02:59 | 2026-05-28 21:04:51 | 112s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 20:53:02,702 [root] INFO: Date set to: 20260528T21:03:05, timeout set to: 200
2026-05-28 21:03:05,006 [root] DEBUG: Starting analyzer from: C:\y_khzgei
2026-05-28 21:03:05,006 [root] DEBUG: Storing results at: C:\dVIjZkYRDm
2026-05-28 21:03:05,006 [root] DEBUG: Pipe server name: \\.\PIPE\ufQdZpWR
2026-05-28 21:03:05,006 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 21:03:05,007 [root] INFO: analysis running as an admin
2026-05-28 21:03:05,007 [root] INFO: analysis package specified: "edge"
2026-05-28 21:03:05,007 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 21:03:05,015 [root] DEBUG: imported analysis package "edge"
2026-05-28 21:03:05,015 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 21:03:05,016 [root] DEBUG: New location of moved file: d
2026-05-28 21:03:05,017 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 21:03:05,017 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 21:03:05,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 21:03:05,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 21:03:05,038 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 21:03:05,042 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 21:03:05,052 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 21:03:05,061 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 21:03:05,066 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 21:03:05,067 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 21:03:05,067 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 21:03:05,070 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 21:03:05,070 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 21:03:05,070 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 21:03:05,071 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 21:03:05,071 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 21:03:05,072 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 21:03:05,072 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 21:03:05,072 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 21:03:05,072 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 21:03:05,073 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 21:03:05,073 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 21:03:05,073 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 21:03:05,073 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 21:03:05,073 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 21:03:05,074 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 21:03:05,074 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 21:03:05,077 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 8928)
2026-05-28 21:03:05,077 [modules.auxiliary.disguise] INFO: Disguising GUID to 1152c13e-8906-4ca8-a50f-bb841ddf0cc0
2026-05-28 21:03:05,077 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 21:03:05,077 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 21:03:05,078 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 21:03:05,078 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 21:03:05,079 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 21:03:05,080 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 21:03:05,081 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 21:03:05,081 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 21:03:05,081 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 21:03:05,082 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 21:03:05,082 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 21:03:05,082 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 21:03:05,083 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 21:03:05,083 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 21:03:05,084 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 21:03:05,084 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 21:03:05,087 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 21:03:05,087 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 21:03:05,088 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 21:03:05,165 [lib.api.process] INFO: Monitor config for process 4484: C:\y_khzgei\dll\4484.ini
2026-05-28 21:03:05,167 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:05,170 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:05,231 [root] DEBUG: Loader: Injecting process 4484 with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:05,399 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:05,402 [root] DEBUG: 4484: Disabling sleep skipping.
2026-05-28 21:03:05,404 [root] DEBUG: 4484: Interactive desktop enabled.
2026-05-28 21:03:05,405 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-28 21:03:05,407 [root] DEBUG: 4484: Interactive desktop - injecting Explorer Shell
2026-05-28 21:03:05,417 [root] DEBUG: 4484: YaraInit: Compiled 44 rule files
2026-05-28 21:03:05,426 [root] DEBUG: 4484: YaraInit: Compiled rules saved to file C:\y_khzgei\data\yara\capemon.yac
2026-05-28 21:03:05,457 [root] DEBUG: 4484: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:05,458 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-28 21:03:05,502 [root] DEBUG: 4484: Monitor initialised: 64-bit capemon loaded in process 4484 at 0x00007FFF1A480000, thread 9052, image base 0x00007FF79BC10000, stack from 0x0000000010472000-0x0000000010480000
2026-05-28 21:03:05,503 [root] DEBUG: 4484: Commandline: C:\Windows\Explorer.EXE
2026-05-28 21:03:05,534 [root] DEBUG: 4484: Hooked 69 out of 69 functions
2026-05-28 21:03:05,567 [root] DEBUG: 4484: Syscall hook installed, syscall logging level 1
2026-05-28 21:03:05,574 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 21:03:05,574 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:05,576 [lib.api.process] INFO: Injected into 64-bit <Process 4484 explorer.exe>
2026-05-28 21:03:05,641 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00007FF79BC10000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF79BC7A06E, thread 4696).
2026-05-28 21:03:05,642 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-28 21:03:05,675 [root] DEBUG: 4484: ProcessImageBase: Main module image at 0x00007FF79BC10000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:07,648 [lib.api.process] INFO: Monitor config for process 832: C:\y_khzgei\dll\832.ini
2026-05-28 21:03:07,650 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:07,651 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:07,655 [root] DEBUG: Loader: Injecting process 832 with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:07,657 [root] DEBUG: 832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:07,657 [root] DEBUG: 832: Disabling sleep skipping.
2026-05-28 21:03:07,657 [root] DEBUG: 832: Interactive desktop enabled.
2026-05-28 21:03:07,658 [root] DEBUG: 832: Dropped file limit defaulting to 100.
2026-05-28 21:03:07,658 [root] DEBUG: 832: Services hook set enabled
2026-05-28 21:03:07,660 [root] DEBUG: 832: YaraInit: Compiled rules loaded from existing file C:\y_khzgei\data\yara\capemon.yac
2026-05-28 21:03:07,673 [root] DEBUG: 832: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:07,674 [root] DEBUG: 832: Monitor initialised: 64-bit capemon loaded in process 832 at 0x00007FFF1A480000, thread 8320, image base 0x00007FF7BF220000, stack from 0x000000CCA78F4000-0x000000CCA7900000
2026-05-28 21:03:07,674 [root] DEBUG: 832: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 21:03:07,686 [root] DEBUG: 832: Hooked 69 out of 69 functions
2026-05-28 21:03:07,687 [root] INFO: Loaded monitor into process with pid 832
2026-05-28 21:03:07,687 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 21:03:07,688 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:07,689 [lib.api.process] INFO: Injected into 64-bit <Process 832 svchost.exe>
2026-05-28 21:03:08,477 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 7380: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:03:08,479 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7380
2026-05-28 21:03:08,479 [lib.api.process] INFO: Monitor config for process 7380: C:\y_khzgei\dll\7380.ini
2026-05-28 21:03:08,480 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:08,481 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:08,486 [root] DEBUG: Loader: Injecting process 7380 (thread 7388) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:08,486 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:08,487 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:08,489 [lib.api.process] INFO: Injected into 64-bit <Process 7380 dllhost.exe>
2026-05-28 21:03:08,490 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7380
2026-05-28 21:03:08,490 [lib.api.process] INFO: Monitor config for process 7380: C:\y_khzgei\dll\7380.ini
2026-05-28 21:03:08,491 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:08,493 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:08,500 [root] DEBUG: Loader: Injecting process 7380 (thread 7388) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:08,501 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:08,503 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:08,506 [lib.api.process] INFO: Injected into 64-bit <Process 7380 dllhost.exe>
2026-05-28 21:03:08,518 [root] DEBUG: 7380: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:08,519 [root] DEBUG: 7380: Interactive desktop enabled.
2026-05-28 21:03:08,520 [root] DEBUG: 7380: Dropped file limit defaulting to 100.
2026-05-28 21:03:08,521 [root] DEBUG: 7380: Disabling sleep skipping.
2026-05-28 21:03:08,522 [root] DEBUG: 7380: YaraInit: Compiled rules loaded from existing file C:\y_khzgei\data\yara\capemon.yac
2026-05-28 21:03:08,529 [root] DEBUG: 4484: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 21:03:08,530 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54AE0000: C:\Windows\SYSTEM32\MLANG (0x42000 bytes).
2026-05-28 21:03:08,533 [root] DEBUG: 7380: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:08,534 [root] DEBUG: 7380: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:03:08,534 [root] DEBUG: 7380: Monitor initialised: 64-bit capemon loaded in process 7380 at 0x00007FFF1A480000, thread 7388, image base 0x00007FF6706B0000, stack from 0x000000E7022F4000-0x000000E702300000
2026-05-28 21:03:08,535 [root] DEBUG: 7380: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 21:03:08,545 [root] DEBUG: 7380: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:03:08,567 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:03:08,567 [root] DEBUG: 7380: set_hooks: Unable to hook LockResource
2026-05-28 21:03:08,571 [root] DEBUG: 7380: Hooked 627 out of 628 functions
2026-05-28 21:03:08,572 [root] DEBUG: 7380: Syscall hook installed, syscall logging level 1
2026-05-28 21:03:08,577 [root] DEBUG: 7380: RestoreHeaders: Restored original import table.
2026-05-28 21:03:08,577 [root] INFO: Loaded monitor into process with pid 7380
2026-05-28 21:03:08,578 [root] DEBUG: 7380: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 7388).
2026-05-28 21:03:08,578 [root] DEBUG: 7380: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:03:08,579 [root] DEBUG: 7380: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:08,581 [root] DEBUG: 7380: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:03:08,582 [root] DEBUG: 7380: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:03:08,584 [root] DEBUG: 7380: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:03:08,596 [root] DEBUG: 7380: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:03:08,610 [root] DEBUG: 7380: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:03:08,611 [root] DEBUG: 7380: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 21:03:08,616 [root] DEBUG: 7380: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 21:03:10,295 [root] DEBUG: 4484: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:03:11,626 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4E350000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 21:03:11,770 [lib.api.process] INFO: Monitor config for process 4484: C:\y_khzgei\dll\4484.ini
2026-05-28 21:03:11,771 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:11,772 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:11,777 [root] DEBUG: Loader: Injecting process 4484 with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:11,778 [root] DEBUG: 4484: caller_dispatch: Added region at 0x0000000003290000 to tracked regions list (ntdll::LdrLoadDll returns to 0x0000000003290044, thread 7748).
2026-05-28 21:03:11,778 [root] DEBUG: 4484: DumpPEsInRange: Scanning range 0x0000000003290000 - 0x0000000003290135.
2026-05-28 21:03:11,779 [root] DEBUG: 4484: ScanForDisguisedPE: Size too small: 0x135 bytes
2026-05-28 21:03:11,788 [lib.common.results] INFO: Uploading file C:\dVIjZkYRDm\CAPE\4484_31898113129552026 to CAPE\1dd9c46508da4d03227aa29ed6a24891de15515d636b053dc626399ea2b8faa5; Size is 309; Max size: 100000000
2026-05-28 21:03:11,789 [root] DEBUG: 4484: DumpMemory: Payload successfully created: C:\dVIjZkYRDm\CAPE\4484_31898113129552026 (size 309 bytes)
2026-05-28 21:03:11,791 [root] DEBUG: 4484: DumpRegion: Dumped entire allocation from 0x0000000003290000, size 4096 bytes.
2026-05-28 21:03:11,791 [root] DEBUG: 4484: ProcessTrackedRegion: Dumped region at 0x0000000003290000.
2026-05-28 21:03:11,791 [root] DEBUG: 4484: YaraScan: Scanning 0x0000000003290000, size 0x135
2026-05-28 21:03:11,792 [root] DEBUG: 4484: Monitor config - unrecognised key host-ip.
2026-05-28 21:03:11,792 [root] DEBUG: 4484: Monitor config - unrecognised key host-port.
2026-05-28 21:03:11,793 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:11,793 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-28 21:03:11,812 [root] DEBUG: 4484: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:03:11,857 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:03:11,857 [root] DEBUG: 4484: set_hooks: Unable to hook LockResource
2026-05-28 21:03:11,884 [root] DEBUG: 4484: Hooked 627 out of 628 functions
2026-05-28 21:03:11,913 [root] INFO: Loaded monitor into process with pid 4484
2026-05-28 21:03:11,922 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 21:03:11,922 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:12,074 [root] DEBUG: 4484: DLL loaded at 0x00007FFF49E50000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-28 21:03:12,075 [root] DEBUG: 4484: DLL loaded at 0x00007FFF49E50000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-28 21:03:12,084 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4E360000: C:\Windows\system32\WindowsInternal.ComposableShell.DesktopHosting (0x2e000 bytes).
2026-05-28 21:03:12,085 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4E360000: C:\Windows\system32\WindowsInternal.ComposableShell.DesktopHosting (0x2e000 bytes).
2026-05-28 21:03:12,091 [root] DEBUG: 4484: DLL loaded at 0x00007FFF19060000: C:\Windows\ShellComponents\WindowsInternal.ComposableShell.Experiences.Switcher (0x24d000 bytes).
2026-05-28 21:03:12,092 [root] DEBUG: 4484: DLL loaded at 0x00007FFF19060000: C:\Windows\ShellComponents\WindowsInternal.ComposableShell.Experiences.Switcher (0x24d000 bytes).
2026-05-28 21:03:12,160 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D2F0000: C:\Windows\ShellExperiences\TileControl (0x7d000 bytes).
2026-05-28 21:03:12,161 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D2F0000: C:\Windows\ShellExperiences\TileControl (0x7d000 bytes).
2026-05-28 21:03:12,184 [root] DEBUG: 4484: DLL loaded at 0x00007FFF18E40000: C:\Windows\ShellComponents\TaskFlowUI (0x215000 bytes).
2026-05-28 21:03:12,185 [root] DEBUG: 4484: DLL loaded at 0x00007FFF18E40000: C:\Windows\ShellComponents\TaskFlowUI (0x215000 bytes).
2026-05-28 21:03:12,224 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46660000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-28 21:03:12,225 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46660000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-28 21:03:12,240 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE181000, size: 0x1000.
2026-05-28 21:03:12,241 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
2026-05-28 21:03:12,915 [root] INFO: Restarting WMI Service
2026-05-28 21:03:13,696 [root] INFO: Process with pid 7380 has terminated
2026-05-28 21:03:13,697 [root] DEBUG: 7380: NtTerminateProcess hook: Attempting to dump process 7380
2026-05-28 21:03:13,697 [root] DEBUG: 7380: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:03:13,973 [root] DEBUG: 4484: DLL loaded at 0x0000000013270000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 21:03:13,974 [root] DEBUG: 4484: DLL loaded at 0x0000000013270000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 21:03:13,977 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FB00000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 21:03:13,978 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FB00000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 21:03:14,000 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 21:03:14,075 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 21:03:14,076 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 21:03:14,087 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C4B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 21:03:14,088 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C4B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 21:03:14,101 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F8A0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 21:03:14,101 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F8A0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 21:03:14,145 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F9A0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 21:03:14,146 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F9A0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 21:03:14,149 [root] DEBUG: 4484: DLL loaded at 0x0000000014C10000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 21:03:14,149 [root] DEBUG: 4484: DLL loaded at 0x0000000014C10000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 21:03:14,305 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 21:03:14,530 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3CE10000: C:\Windows\System32\uiautomationcore (0x2f5000 bytes).
2026-05-28 21:03:14,531 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3CE10000: C:\Windows\System32\uiautomationcore (0x2f5000 bytes).
2026-05-28 21:03:14,651 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3D570000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 21:03:14,652 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3D570000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 21:03:14,741 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:03:14,742 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5624, handle 0x26dc: Error obtaining target process name
2026-05-28 21:03:14,743 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:03:14,743 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6400, handle 0x26c0: Error obtaining target process name
2026-05-28 21:03:14,744 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:03:14,745 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5128, handle 0x2428: Error obtaining target process name
2026-05-28 21:03:14,764 [root] DEBUG: 4484: api-rate-cap: IsDebuggerPresent hook disabled due to rate
2026-05-28 21:03:14,822 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 21:03:14,831 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4E340000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 21:03:14,832 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4E340000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 21:03:14,862 [root] DEBUG: 4484: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 21:03:14,928 [root] DEBUG: 4484: DLL loaded at 0x00007FFF453C0000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 21:03:14,929 [root] DEBUG: 4484: DLL loaded at 0x00007FFF453C0000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 21:03:14,946 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 21:03:14,946 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 21:03:14,947 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 21:03:14,948 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""d"" with pid 5020
2026-05-28 21:03:14,948 [lib.api.process] INFO: Monitor config for process 5020: C:\y_khzgei\dll\5020.ini
2026-05-28 21:03:14,950 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:14,951 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:14,956 [root] DEBUG: Loader: Injecting process 5020 (thread 3420) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:14,957 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:14,957 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:14,959 [lib.api.process] INFO: Injected into 64-bit <Process 5020 msedge.exe>
2026-05-28 21:03:15,039 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9404: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:03:15,042 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9404
2026-05-28 21:03:15,043 [lib.api.process] INFO: Monitor config for process 9404: C:\y_khzgei\dll\9404.ini
2026-05-28 21:03:15,044 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:15,045 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:15,050 [root] DEBUG: Loader: Injecting process 9404 (thread 9408) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:15,051 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:15,051 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:15,053 [lib.api.process] INFO: Injected into 64-bit <Process 9404 dllhost.exe>
2026-05-28 21:03:15,053 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9404
2026-05-28 21:03:15,054 [lib.api.process] INFO: Monitor config for process 9404: C:\y_khzgei\dll\9404.ini
2026-05-28 21:03:15,054 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:15,055 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:15,060 [root] DEBUG: Loader: Injecting process 9404 (thread 9408) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:15,060 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:15,061 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:15,062 [lib.api.process] INFO: Injected into 64-bit <Process 9404 dllhost.exe>
2026-05-28 21:03:15,069 [root] DEBUG: 9404: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:15,070 [root] DEBUG: 9404: Interactive desktop enabled.
2026-05-28 21:03:15,074 [root] DEBUG: 9404: Dropped file limit defaulting to 100.
2026-05-28 21:03:15,076 [root] DEBUG: 9404: Disabling sleep skipping.
2026-05-28 21:03:15,077 [root] DEBUG: 9404: YaraInit: Compiled rules loaded from existing file C:\y_khzgei\data\yara\capemon.yac
2026-05-28 21:03:15,089 [root] DEBUG: 9404: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:15,090 [root] DEBUG: 9404: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:03:15,091 [root] DEBUG: 9404: Monitor initialised: 64-bit capemon loaded in process 9404 at 0x00007FFF1A480000, thread 9408, image base 0x00007FF6706B0000, stack from 0x000000B793384000-0x000000B793390000
2026-05-28 21:03:15,091 [root] DEBUG: 9404: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 21:03:15,106 [root] DEBUG: 9404: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:03:15,132 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:03:15,133 [root] DEBUG: 9404: set_hooks: Unable to hook LockResource
2026-05-28 21:03:15,141 [root] DEBUG: 9404: Hooked 627 out of 628 functions
2026-05-28 21:03:15,142 [root] DEBUG: 9404: Syscall hook installed, syscall logging level 1
2026-05-28 21:03:15,147 [root] DEBUG: 9404: RestoreHeaders: Restored original import table.
2026-05-28 21:03:15,147 [root] INFO: Loaded monitor into process with pid 9404
2026-05-28 21:03:15,148 [root] DEBUG: 9404: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 9408).
2026-05-28 21:03:15,148 [root] DEBUG: 9404: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:03:15,149 [root] DEBUG: 9404: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:15,151 [root] DEBUG: 9404: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:03:15,152 [root] DEBUG: 9404: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:03:15,154 [root] DEBUG: 9404: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:03:15,167 [root] DEBUG: 9404: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:03:15,182 [root] DEBUG: 9404: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:03:15,182 [root] DEBUG: 9404: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 21:03:15,187 [root] DEBUG: 9404: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 21:03:16,505 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 21:03:16,506 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 21:03:16,510 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D2E0000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 21:03:16,510 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D2E0000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 21:03:16,512 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D260000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 21:03:16,513 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D260000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 21:03:16,515 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D2D0000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 21:03:16,516 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D2D0000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 21:03:16,517 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D010000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 21:03:16,517 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D010000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 21:03:16,607 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46470000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 21:03:16,608 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46470000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 21:03:16,618 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46FD0000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 21:03:16,619 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46FD0000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 21:03:16,972 [lib.api.process] INFO: Successfully resumed process with pid 5020
2026-05-28 21:03:17,016 [root] DEBUG: 5020: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:17,017 [root] DEBUG: 5020: Interactive desktop enabled.
2026-05-28 21:03:17,017 [root] DEBUG: 5020: Dropped file limit defaulting to 100.
2026-05-28 21:03:17,024 [root] DEBUG: 5020: Edge-specific hook-set enabled.
2026-05-28 21:03:17,026 [root] DEBUG: 5020: Disabling sleep skipping.
2026-05-28 21:03:17,026 [root] DEBUG: 5020: YaraInit: Compiled rules loaded from existing file C:\y_khzgei\data\yara\capemon.yac
2026-05-28 21:03:17,038 [root] DEBUG: 5020: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:17,038 [root] DEBUG: 5020: Monitor initialised: 64-bit capemon loaded in process 5020 at 0x00007FFF1A480000, thread 3420, image base 0x00007FF7F5380000, stack from 0x0000005DABDF4000-0x0000005DABE00000
2026-05-28 21:03:17,039 [root] DEBUG: 5020: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "d"
2026-05-28 21:03:17,047 [root] DEBUG: 5020: Hooked 2 out of 2 functions
2026-05-28 21:03:17,082 [root] DEBUG: 5020: Syscall hook installed, syscall logging level 1
2026-05-28 21:03:17,087 [root] DEBUG: 5020: RestoreHeaders: Restored original import table.
2026-05-28 21:03:17,087 [root] INFO: Loaded monitor into process with pid 5020
2026-05-28 21:03:17,089 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:03:17,091 [root] DEBUG: 5020: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 21:03:17,092 [root] DEBUG: 5020: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:03:17,094 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 21:03:17,094 [root] DEBUG: 5020: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:03:17,095 [root] DEBUG: 5020: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 21:03:17,097 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 21:03:17,358 [root] DEBUG: 5020: DLL loaded at 0x00007FFF453C0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 21:03:17,359 [root] DEBUG: 5020: DLL loaded at 0x0000018AE6000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 21:03:17,364 [root] DEBUG: 5020: DLL loaded at 0x00007FFF45010000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 21:03:17,367 [root] DEBUG: 5020: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:03:17,371 [root] DEBUG: 5020: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:03:17,372 [root] DEBUG: 5020: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:03:17,373 [root] DEBUG: 5020: CreateProcessHandler: Injection info set for new process 11652: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:03:17,374 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4CFA0000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 21:03:17,374 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 11652
2026-05-28 21:03:17,375 [root] DEBUG: 5020: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:03:17,376 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 11652
2026-05-28 21:03:17,377 [root] DEBUG: 5020: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:03:17,387 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 21:03:17,387 [root] DEBUG: 5020: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 21:03:17,389 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 21:03:17,390 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 21:03:17,391 [root] DEBUG: 5020: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:03:17,391 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 11652, handle 0x2d84: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 21:03:17,392 [root] DEBUG: 5020: DLL loaded at 0x00007FFF46400000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 21:03:17,393 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 21:03:17,394 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 21:03:17,395 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 21:03:17,396 [root] DEBUG: 5020: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 21:03:17,396 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 21:03:17,398 [root] DEBUG: 5020: DLL loaded at 0x00007FFF42D90000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 21:03:17,398 [root] DEBUG: 5020: DLL loaded at 0x00007FFF435B0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 21:03:17,399 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 21:03:17,400 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 21:03:17,401 [root] DEBUG: 5020: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 21:03:17,402 [root] DEBUG: 5020: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:03:17,403 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 21:03:17,403 [root] DEBUG: 5020: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 21:03:17,405 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 21:03:17,414 [root] DEBUG: 5020: DLL loaded at 0x00007FFF46FB0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 21:03:17,415 [root] DEBUG: 5020: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 21:03:17,416 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 21:03:17,416 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5020, handle 0x2d7c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 21:03:17,417 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 21:03:17,418 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 21:03:17,421 [root] DEBUG: 5020: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 21:03:17,423 [root] DEBUG: 5020: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:03:17,424 [root] DEBUG: 5020: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 21:03:17,426 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:03:17,427 [root] DEBUG: 5020: DLL loaded at 0x00007FFF569F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 21:03:17,428 [root] DEBUG: 5020: DLL loaded at 0x00007FFF52960000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 21:03:17,429 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 21:03:17,430 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 21:03:17,430 [root] DEBUG: 5020: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 21:03:17,432 [root] DEBUG: 5020: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 21:03:17,433 [root] DEBUG: 5020: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 21:03:17,433 [root] DEBUG: 5020: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 21:03:17,434 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 21:03:17,436 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 21:03:17,442 [root] DEBUG: 5020: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 21:03:17,443 [root] DEBUG: 5020: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:03:17,443 [root] DEBUG: 5020: DLL loaded at 0x00007FFF54170000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 21:03:17,443 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4B680000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 21:03:17,444 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 21:03:17,447 [root] DEBUG: 5020: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 21:03:17,449 [root] DEBUG: 5020: DLL loaded at 0x00007FFF45580000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 21:03:17,450 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 21:03:17,453 [root] DEBUG: 5020: DLL loaded at 0x00007FFF52420000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 21:03:17,455 [root] DEBUG: 5020: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 21:03:17,459 [root] DEBUG: 5020: DLL loaded at 0x00007FFF51A60000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 21:03:17,459 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4AF10000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 21:03:17,460 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4BFB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 21:03:17,461 [root] DEBUG: 5020: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 21:03:17,462 [root] DEBUG: 5020: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 21:03:17,465 [root] DEBUG: 5020: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 21:03:17,466 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 21:03:17,468 [root] DEBUG: 5020: DLL loaded at 0x00007FFF515E0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 21:03:17,468 [root] DEBUG: 5020: DLL loaded at 0x00007FFF51600000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 21:03:17,478 [root] DEBUG: 5020: DLL loaded at 0x00007FFF52560000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 21:03:17,483 [root] DEBUG: 5020: DLL loaded at 0x00007FFF01470000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 21:03:17,485 [root] DEBUG: 5020: CreateProcessHandler: Injection info set for new process 12140: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:03:17,486 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12140
2026-05-28 21:03:17,486 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 21:03:17,487 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12140
2026-05-28 21:03:17,487 [lib.api.process] INFO: Monitor config for process 676: C:\y_khzgei\dll\676.ini
2026-05-28 21:03:17,489 [root] DEBUG: 5020: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 21:03:17,490 [root] DEBUG: 5020: caller_dispatch: Added region at 0x00007FF7F5380000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7F5477D66, thread 11848).
2026-05-28 21:03:17,494 [root] DEBUG: 5020: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:17,496 [root] DEBUG: 5020: CreateProcessHandler: Injection info set for new process 12176: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:03:17,497 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12176
2026-05-28 21:03:17,498 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12176
2026-05-28 21:03:17,500 [root] DEBUG: 5020: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 21:03:17,503 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:17,505 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:17,515 [root] DEBUG: Loader: Injecting process 676 with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:17,553 [root] DEBUG: Loader: Copied config file C:\y_khzgei\dll\676.ini to system path C:\676.ini
2026-05-28 21:03:17,578 [root] DEBUG: 5020: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 21:03:17,583 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 676 C:\y_khzgei\dll\ElpVTmeL.dll
2026-05-28 21:03:17,585 [root] DEBUG: 5020: CreateProcessHandler: Injection info set for new process 12292: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:03:17,586 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:17,586 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12292
2026-05-28 21:03:17,588 [lib.api.process] INFO: Injected into 64-bit <Process 676 services.exe>
2026-05-28 21:03:17,589 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12292
2026-05-28 21:03:17,655 [root] DEBUG: 5020: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 21:03:17,656 [root] DEBUG: 5020: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 21:03:17,657 [root] DEBUG: 5020: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 21:03:17,657 [root] DEBUG: 5020: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 21:03:17,698 [root] DEBUG: 5020: DLL loaded at 0x00007FFF46420000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 21:03:17,728 [root] DEBUG: 5020: DLL loaded at 0x00007FFF43990000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 21:03:17,728 [root] DEBUG: 5020: CreateProcessHandler: Injection info set for new process 12548: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:03:17,729 [root] DEBUG: 5020: CreateProcessHandler: Injection info set for new process 12556: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:03:17,729 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12548
2026-05-28 21:03:17,730 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12556
2026-05-28 21:03:17,730 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12548
2026-05-28 21:03:17,731 [root] DEBUG: 5020: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 21:03:17,731 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 12556
2026-05-28 21:03:17,816 [root] DEBUG: 5020: DLL loaded at 0x00007FFF3EA70000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 21:03:17,819 [root] DEBUG: 5020: DLL loaded at 0x00007FFF55220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 21:03:17,823 [root] DEBUG: 5020: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 21:03:17,871 [root] DEBUG: 5020: DLL loaded at 0x00007FFF46450000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1e000 bytes).
2026-05-28 21:03:17,872 [root] DEBUG: 5020: DLL loaded at 0x00007FFF46400000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Domain Actions\3.0.0.18\domain_actions (0x17000 bytes).
2026-05-28 21:03:17,878 [root] DEBUG: 5020: DLL loaded at 0x00007FFF3F700000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 21:03:17,888 [root] DEBUG: 5020: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 21:03:17,896 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 21:03:17,898 [root] DEBUG: 5020: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 21:03:17,899 [root] DEBUG: 5020: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 21:03:17,902 [root] DEBUG: 5020: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 21:03:17,904 [root] DEBUG: 5020: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 21:03:17,923 [root] DEBUG: 5020: DLL loaded at 0x00007FFF3E220000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 21:03:18,440 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 12872, handle 0x2da0: C:\Windows\System32\services.exe
2026-05-28 21:03:18,460 [root] DEBUG: 4484: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 21:03:18,558 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 13128: C:\Windows\System32\rundll32.exe, ImageBase: 0x00007FF6F3E20000
2026-05-28 21:03:18,561 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 13128
2026-05-28 21:03:18,561 [lib.api.process] INFO: Monitor config for process 13128: C:\y_khzgei\dll\13128.ini
2026-05-28 21:03:18,562 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:18,563 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:18,568 [root] DEBUG: Loader: Injecting process 13128 (thread 13132) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:18,569 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:18,570 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:18,571 [lib.api.process] INFO: Injected into 64-bit <Process 13128 rundll32.exe>
2026-05-28 21:03:18,573 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 13128
2026-05-28 21:03:18,573 [lib.api.process] INFO: Monitor config for process 13128: C:\y_khzgei\dll\13128.ini
2026-05-28 21:03:18,573 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:18,574 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:18,579 [root] DEBUG: Loader: Injecting process 13128 (thread 13132) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:18,580 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:03:18,580 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:18,581 [lib.api.process] INFO: Injected into 64-bit <Process 13128 rundll32.exe>
2026-05-28 21:03:18,594 [root] DEBUG: 13128: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:18,595 [root] DEBUG: 13128: Interactive desktop enabled.
2026-05-28 21:03:18,596 [root] DEBUG: 13128: Dropped file limit defaulting to 100.
2026-05-28 21:03:18,597 [root] DEBUG: 13128: Disabling sleep skipping.
2026-05-28 21:03:18,600 [root] DEBUG: 13128: YaraInit: Compiled rules loaded from existing file C:\y_khzgei\data\yara\capemon.yac
2026-05-28 21:03:18,612 [root] DEBUG: 13128: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:18,612 [root] DEBUG: 13128: YaraScan: Scanning 0x00007FF6F3E20000, size 0x16100
2026-05-28 21:03:18,613 [root] DEBUG: 13128: Monitor initialised: 64-bit capemon loaded in process 13128 at 0x00007FFF1A480000, thread 13132, image base 0x00007FF6F3E20000, stack from 0x0000009457E74000-0x0000009457E80000
2026-05-28 21:03:18,614 [root] DEBUG: 13128: Commandline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
2026-05-28 21:03:18,624 [root] DEBUG: 13128: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:03:18,647 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:03:18,647 [root] DEBUG: 13128: set_hooks: Unable to hook LockResource
2026-05-28 21:03:18,653 [root] DEBUG: 13128: Hooked 627 out of 628 functions
2026-05-28 21:03:18,654 [root] DEBUG: 13128: Syscall hook installed, syscall logging level 1
2026-05-28 21:03:18,658 [root] DEBUG: 13128: RestoreHeaders: Restored original import table.
2026-05-28 21:03:18,659 [root] INFO: Loaded monitor into process with pid 13128
2026-05-28 21:03:18,660 [root] DEBUG: 13128: caller_dispatch: Added region at 0x00007FF6F3E20000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6F3E26D01, thread 13132).
2026-05-28 21:03:18,661 [root] DEBUG: 13128: YaraScan: Scanning 0x00007FF6F3E20000, size 0x16100
2026-05-28 21:03:18,663 [root] DEBUG: 13128: ProcessImageBase: Main module image at 0x00007FF6F3E20000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:18,670 [root] DEBUG: 13128: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:03:18,672 [root] DEBUG: 13128: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 21:03:18,673 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 13128, handle 0x2dd8: C:\Windows\System32\rundll32.exe
2026-05-28 21:03:18,680 [root] DEBUG: 4484: DLL loaded at 0x0000000016A40000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 21:03:18,682 [root] DEBUG: 4484: DLL loaded at 0x0000000016A40000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 21:03:18,691 [root] DEBUG: 13128: NtTerminateProcess hook: Attempting to dump process 13128
2026-05-28 21:03:18,692 [root] DEBUG: 13128: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:03:18,700 [root] INFO: Process with pid 13128 has terminated
2026-05-28 21:03:19,010 [root] DEBUG: 676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:19,011 [root] DEBUG: 676: Disabling sleep skipping.
2026-05-28 21:03:19,012 [root] DEBUG: 676: Interactive desktop enabled.
2026-05-28 21:03:19,013 [root] DEBUG: 676: Dropped file limit defaulting to 100.
2026-05-28 21:03:19,016 [root] DEBUG: 676: Services hook set enabled
2026-05-28 21:03:19,034 [root] DEBUG: 676: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:19,034 [root] DEBUG: 676: Monitor initialised: 64-bit capemon loaded in process 676 at 0x00007FFF00530000, thread 13216, image base 0x00007FF7839A0000, stack from 0x000000F2F01F2000-0x000000F2F0200000
2026-05-28 21:03:19,035 [root] DEBUG: 676: Commandline: C:\Windows\system32\services.exe
2026-05-28 21:03:19,055 [root] DEBUG: 676: Hooked 69 out of 69 functions
2026-05-28 21:03:19,059 [root] INFO: Loaded monitor into process with pid 676
2026-05-28 21:03:19,423 [root] DEBUG: 5020: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:03:19,426 [root] DEBUG: 5020: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:03:19,760 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:03:19,760 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6136, handle 0x2e1c: Error obtaining target process name
2026-05-28 21:03:20,041 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 5020 (handle 0x2b8c): 0x00007FF7F5380000.
2026-05-28 21:03:20,059 [root] DEBUG: 4484: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 21:03:20,155 [root] DEBUG: 5020: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 21:03:20,156 [root] DEBUG: 5020: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 21:03:20,156 [root] DEBUG: 5020: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:03:20,616 [root] DEBUG: 676: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 21:03:20,617 [root] DEBUG: 676: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:03:20,619 [root] DEBUG: 676: DLL loaded at 0x00007FFF58070000: C:\Windows\system32\SHCORE (0xad000 bytes).
2026-05-28 21:03:20,620 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 13624: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe, ImageBase: 0x00007FF7E7840000
2026-05-28 21:03:20,622 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 13624
2026-05-28 21:03:20,622 [lib.api.process] INFO: Monitor config for process 13624: C:\y_khzgei\dll\13624.ini
2026-05-28 21:03:20,624 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:21,298 [root] DEBUG: 4484: api-rate-cap: NtQueryInformationToken hook disabled due to rate
2026-05-28 21:03:21,300 [root] DEBUG: 4484: api-rate-cap: NtQueryInformationToken hook disabled due to rate
2026-05-28 21:03:21,578 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 21:03:21,579 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 21:03:21,625 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:03:21,626 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:03:21,646 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:03:21,647 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:03:21,658 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:03:21,659 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:03:21,912 [root] INFO: Process with pid 9404 has terminated
2026-05-28 21:03:21,913 [root] DEBUG: 9404: NtTerminateProcess hook: Attempting to dump process 9404
2026-05-28 21:03:21,914 [root] DEBUG: 9404: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:03:22,035 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:03:22,036 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:03:22,036 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:03:22,037 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:03:22,037 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:03:22,037 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:03:22,037 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:03:22,037 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:03:22,045 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:22,057 [root] DEBUG: Loader: Injecting process 13624 (thread 13628) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:22,058 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:22,058 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:22,060 [lib.api.process] INFO: Injected into 64-bit <Process 13624 elevation_service.exe>
2026-05-28 21:03:22,064 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 13624
2026-05-28 21:03:22,064 [lib.api.process] INFO: Monitor config for process 13624: C:\y_khzgei\dll\13624.ini
2026-05-28 21:03:22,065 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:22,315 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:03:22,315 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:03:22,316 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:03:22,316 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:03:22,316 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:03:22,316 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:03:22,317 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:03:22,317 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:03:22,320 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:22,324 [root] DEBUG: Loader: Injecting process 13624 (thread 13628) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:22,325 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:22,326 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:22,327 [lib.api.process] INFO: Injected into 64-bit <Process 13624 elevation_service.exe>
2026-05-28 21:03:22,328 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 13624
2026-05-28 21:03:22,329 [lib.api.process] INFO: Monitor config for process 13624: C:\y_khzgei\dll\13624.ini
2026-05-28 21:03:22,329 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:22,571 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:03:22,571 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:03:22,572 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:03:22,572 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:03:22,572 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:03:22,572 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:03:22,572 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:03:22,573 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:03:22,576 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:22,581 [root] DEBUG: Loader: Injecting process 13624 with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:22,582 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 13628, handle 0x120
2026-05-28 21:03:22,583 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:03:22,583 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:22,584 [lib.api.process] INFO: Injected into 64-bit <Process 13624 elevation_service.exe>
2026-05-28 21:03:22,594 [root] DEBUG: 13624: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:22,594 [root] DEBUG: 13624: Interactive desktop enabled.
2026-05-28 21:03:22,595 [root] DEBUG: 13624: Dropped file limit defaulting to 100.
2026-05-28 21:03:22,602 [root] DEBUG: 13624: Disabling sleep skipping.
2026-05-28 21:03:22,604 [root] DEBUG: 13624: YaraInit: Compiled rules loaded from existing file C:\y_khzgei\data\yara\capemon.yac
2026-05-28 21:03:22,616 [root] DEBUG: 13624: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:22,617 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,640 [root] DEBUG: 13624: Monitor initialised: 64-bit capemon loaded in process 13624 at 0x00007FFF1A480000, thread 13628, image base 0x00007FF7E7840000, stack from 0x0000002F5F994000-0x0000002F5F9A0000
2026-05-28 21:03:22,641 [root] DEBUG: 13624: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe"
2026-05-28 21:03:22,652 [root] DEBUG: 13624: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:03:22,674 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:03:22,675 [root] DEBUG: 13624: set_hooks: Unable to hook LockResource
2026-05-28 21:03:22,681 [root] DEBUG: 13624: Hooked 627 out of 628 functions
2026-05-28 21:03:22,703 [root] DEBUG: 13624: Syscall hook installed, syscall logging level 1
2026-05-28 21:03:22,715 [root] DEBUG: 13624: RestoreHeaders: Restored original import table.
2026-05-28 21:03:22,716 [root] INFO: Loaded monitor into process with pid 13624
2026-05-28 21:03:22,718 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,740 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,761 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,784 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,806 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,828 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,850 [root] DEBUG: 13624: caller_dispatch: Scanning calling region at 0x00007FF7E7840000...
2026-05-28 21:03:22,851 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,852 [root] DEBUG: 13624: caller_dispatch: Added region at 0x00007FF7E7840000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7E797B9D6, thread 13628).
2026-05-28 21:03:22,852 [root] DEBUG: 13624: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:22,874 [root] DEBUG: 13624: ProcessImageBase: Main module image at 0x00007FF7E7840000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:22,874 [root] DEBUG: 13624: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:03:22,875 [root] DEBUG: 13624: ProcessImageBase: Main module image at 0x00007FF7E7840000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:22,879 [root] DEBUG: 13624: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:03:22,887 [root] DEBUG: 13624: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:03:22,895 [root] DEBUG: 13624: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:03:22,913 [root] DEBUG: 13624: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:03:22,917 [root] DEBUG: 5020: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:03:22,956 [root] DEBUG: 13624: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:03:22,961 [root] DEBUG: 13624: NtTerminateProcess hook: Attempting to dump process 13624
2026-05-28 21:03:22,963 [root] DEBUG: 13624: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:03:22,970 [root] DEBUG: 13624: caller_dispatch: Added region at 0x00007FFF56FD0000 to tracked regions list (ntdll::NtClose returns to 0x00007FFF56FD419B, thread 13628).
2026-05-28 21:03:22,971 [root] DEBUG: 13624: caller_dispatch: Scanning calling region at 0x00007FFF56FD0000...
2026-05-28 21:03:22,972 [root] DEBUG: 5020: CreateProcessHandler: Injection info set for new process 14056: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:03:22,974 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 14056
2026-05-28 21:03:22,975 [root] DEBUG: 5020: ProcessMessage: Skipping monitoring process 14056
2026-05-28 21:03:22,977 [root] INFO: Process with pid 13624 has terminated
2026-05-28 21:03:23,035 [root] INFO: Process with pid 5020 appears to have terminated
2026-05-28 21:03:23,134 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 14104, handle 0x2e18: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 21:03:23,148 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 14056, handle 0x2df4: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 21:03:23,345 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 21:03:23,488 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 12244, handle 0x1cc4: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 21:03:24,349 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 10036: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe, ImageBase: 0x00007FF7E7840000
2026-05-28 21:03:24,351 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 10036
2026-05-28 21:03:24,351 [lib.api.process] INFO: Monitor config for process 10036: C:\y_khzgei\dll\10036.ini
2026-05-28 21:03:24,352 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:25,093 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:03:25,093 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:03:25,094 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:03:25,094 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:03:25,095 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:03:25,095 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:03:25,095 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:03:25,095 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:03:25,105 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:25,109 [root] DEBUG: Loader: Injecting process 10036 (thread 9544) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:25,110 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:25,110 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:25,112 [lib.api.process] INFO: Injected into 64-bit <Process 10036 elevation_service.exe>
2026-05-28 21:03:25,114 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 10036
2026-05-28 21:03:25,115 [lib.api.process] INFO: Monitor config for process 10036: C:\y_khzgei\dll\10036.ini
2026-05-28 21:03:25,116 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:25,835 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:03:25,836 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:03:25,836 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:03:25,837 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:03:25,837 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:03:25,837 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:03:25,837 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:03:25,838 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:03:25,846 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:25,851 [root] DEBUG: Loader: Injecting process 10036 (thread 9544) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:25,851 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:03:25,852 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:25,853 [lib.api.process] INFO: Injected into 64-bit <Process 10036 elevation_service.exe>
2026-05-28 21:03:25,854 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 10036
2026-05-28 21:03:25,854 [lib.api.process] INFO: Monitor config for process 10036: C:\y_khzgei\dll\10036.ini
2026-05-28 21:03:25,855 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:03:26,552 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:03:26,553 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:03:26,553 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:03:26,554 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:03:26,554 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:03:26,554 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:03:26,554 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:03:26,554 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:03:26,569 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:03:26,574 [root] DEBUG: Loader: Injecting process 10036 with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:26,576 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9544, handle 0x124
2026-05-28 21:03:26,576 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:03:26,577 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:03:26,579 [lib.api.process] INFO: Injected into 64-bit <Process 10036 elevation_service.exe>
2026-05-28 21:03:26,586 [root] DEBUG: 10036: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:03:26,587 [root] DEBUG: 10036: Interactive desktop enabled.
2026-05-28 21:03:26,587 [root] DEBUG: 10036: Dropped file limit defaulting to 100.
2026-05-28 21:03:26,591 [root] DEBUG: 10036: Disabling sleep skipping.
2026-05-28 21:03:26,592 [root] DEBUG: 10036: YaraInit: Compiled rules loaded from existing file C:\y_khzgei\data\yara\capemon.yac
2026-05-28 21:03:26,604 [root] DEBUG: 10036: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:03:26,605 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,629 [root] DEBUG: 10036: Monitor initialised: 64-bit capemon loaded in process 10036 at 0x00007FFF1A480000, thread 9544, image base 0x00007FF7E7840000, stack from 0x00000016D0564000-0x00000016D0570000
2026-05-28 21:03:26,630 [root] DEBUG: 10036: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe"
2026-05-28 21:03:26,641 [root] DEBUG: 10036: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:03:26,662 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:03:26,664 [root] DEBUG: 10036: set_hooks: Unable to hook LockResource
2026-05-28 21:03:26,669 [root] DEBUG: 10036: Hooked 627 out of 628 functions
2026-05-28 21:03:26,690 [root] DEBUG: 10036: Syscall hook installed, syscall logging level 1
2026-05-28 21:03:26,695 [root] DEBUG: 10036: RestoreHeaders: Restored original import table.
2026-05-28 21:03:26,696 [root] INFO: Loaded monitor into process with pid 10036
2026-05-28 21:03:26,698 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,720 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,741 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,763 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,784 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,806 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,828 [root] DEBUG: 10036: caller_dispatch: Scanning calling region at 0x00007FF7E7840000...
2026-05-28 21:03:26,829 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,830 [root] DEBUG: 10036: caller_dispatch: Added region at 0x00007FF7E7840000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7E797B9D6, thread 9544).
2026-05-28 21:03:26,831 [root] DEBUG: 10036: YaraScan: Scanning 0x00007FF7E7840000, size 0x3bf4c0
2026-05-28 21:03:26,852 [root] DEBUG: 10036: ProcessImageBase: Main module image at 0x00007FF7E7840000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:26,854 [root] DEBUG: 10036: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:03:26,855 [root] DEBUG: 10036: ProcessImageBase: Main module image at 0x00007FF7E7840000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:03:26,859 [root] DEBUG: 10036: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:03:26,867 [root] DEBUG: 10036: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:03:26,873 [root] DEBUG: 10036: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:03:26,890 [root] DEBUG: 10036: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:03:26,925 [root] DEBUG: 10036: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:03:26,933 [root] DEBUG: 10036: NtTerminateProcess hook: Attempting to dump process 10036
2026-05-28 21:03:26,936 [root] DEBUG: 10036: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:03:26,944 [root] DEBUG: 10036: caller_dispatch: Added region at 0x00007FFF56FD0000 to tracked regions list (ntdll::NtClose returns to 0x00007FFF56FD419B, thread 9544).
2026-05-28 21:03:26,944 [root] DEBUG: 10036: caller_dispatch: Scanning calling region at 0x00007FFF56FD0000...
2026-05-28 21:03:26,949 [root] INFO: Process with pid 10036 has terminated
2026-05-28 21:03:29,968 [root] DEBUG: 4484: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 21:03:30,410 [root] DEBUG: 4484: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 21:04:08,855 [root] DEBUG: 4484: api-cap: NtQueryKey hook disabled due to count: 5000
2026-05-28 21:04:36,309 [root] DEBUG: 4484: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 21:04:36,378 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 6136 (handle 0x2744): 0x00007FF662BA0000.
2026-05-28 21:04:36,393 [root] DEBUG: 4484: api-rate-cap: NtOpenKeyEx hook disabled due to rate
2026-05-28 21:04:36,446 [root] DEBUG: 4484: api-cap: LdrpCallInitRoutine hook disabled due to count: 5000
2026-05-28 21:04:36,494 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 664: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe, ImageBase: 0x00007FF731E20000
2026-05-28 21:04:36,495 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 664
2026-05-28 21:04:36,496 [lib.api.process] INFO: Monitor config for process 664: C:\y_khzgei\dll\664.ini
2026-05-28 21:04:36,499 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:36,522 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 1108: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:04:36,526 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 1108
2026-05-28 21:04:36,527 [lib.api.process] INFO: Monitor config for process 1108: C:\y_khzgei\dll\1108.ini
2026-05-28 21:04:36,529 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:36,533 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:36,541 [root] DEBUG: Loader: Injecting process 1108 (thread 1120) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:36,543 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:36,543 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:36,545 [lib.api.process] INFO: Injected into 64-bit <Process 1108 dllhost.exe>
2026-05-28 21:04:36,547 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 1108
2026-05-28 21:04:36,548 [lib.api.process] INFO: Monitor config for process 1108: C:\y_khzgei\dll\1108.ini
2026-05-28 21:04:36,549 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:36,557 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:36,562 [root] DEBUG: Loader: Injecting process 1108 (thread 1120) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:36,563 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:36,564 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:36,565 [lib.api.process] INFO: Injected into 64-bit <Process 1108 dllhost.exe>
2026-05-28 21:04:36,573 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12728: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:04:36,576 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12728
2026-05-28 21:04:36,577 [lib.api.process] INFO: Monitor config for process 12728: C:\y_khzgei\dll\12728.ini
2026-05-28 21:04:36,579 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:36,584 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:36,590 [root] DEBUG: Loader: Injecting process 12728 (thread 2916) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:36,591 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:36,593 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:36,594 [lib.api.process] INFO: Injected into 64-bit <Process 12728 dllhost.exe>
2026-05-28 21:04:36,596 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12728
2026-05-28 21:04:36,598 [lib.api.process] INFO: Monitor config for process 12728: C:\y_khzgei\dll\12728.ini
2026-05-28 21:04:36,599 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:36,605 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:36,612 [root] DEBUG: Loader: Injecting process 12728 (thread 2916) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:36,615 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:36,616 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:36,618 [lib.api.process] INFO: Injected into 64-bit <Process 12728 dllhost.exe>
2026-05-28 21:04:36,624 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 3440: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:04:36,628 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3440
2026-05-28 21:04:36,629 [lib.api.process] INFO: Monitor config for process 3440: C:\y_khzgei\dll\3440.ini
2026-05-28 21:04:37,090 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 5624 (handle 0x20f8): 0x00007FF659080000.
2026-05-28 21:04:37,406 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,412 [root] DEBUG: Loader: Injecting process 664 (thread 4472) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,414 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,415 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,416 [lib.api.process] INFO: Injected into 64-bit <Process 664 TextInputHost.exe>
2026-05-28 21:04:37,418 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 664
2026-05-28 21:04:37,419 [lib.api.process] INFO: Monitor config for process 664: C:\y_khzgei\dll\664.ini
2026-05-28 21:04:37,419 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,645 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,649 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,653 [root] DEBUG: Loader: Injecting process 3440 (thread 3568) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,654 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,656 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,657 [lib.api.process] INFO: Injected into 64-bit <Process 3440 dllhost.exe>
2026-05-28 21:04:37,659 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3440
2026-05-28 21:04:37,660 [lib.api.process] INFO: Monitor config for process 3440: C:\y_khzgei\dll\3440.ini
2026-05-28 21:04:37,661 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,667 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,671 [root] DEBUG: Loader: Injecting process 3440 (thread 3568) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,672 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,673 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,674 [lib.api.process] INFO: Injected into 64-bit <Process 3440 dllhost.exe>
2026-05-28 21:04:37,679 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 5184: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:04:37,680 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5184
2026-05-28 21:04:37,680 [lib.api.process] INFO: Monitor config for process 5184: C:\y_khzgei\dll\5184.ini
2026-05-28 21:04:37,682 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,688 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,696 [root] DEBUG: Loader: Injecting process 5184 (thread 5164) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,698 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,699 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,701 [lib.api.process] INFO: Injected into 64-bit <Process 5184 dllhost.exe>
2026-05-28 21:04:37,703 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5184
2026-05-28 21:04:37,704 [lib.api.process] INFO: Monitor config for process 5184: C:\y_khzgei\dll\5184.ini
2026-05-28 21:04:37,705 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,712 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,717 [root] DEBUG: Loader: Injecting process 5184 (thread 5164) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,719 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,720 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,722 [lib.api.process] INFO: Injected into 64-bit <Process 5184 dllhost.exe>
2026-05-28 21:04:37,727 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 6036: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:04:37,728 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6036
2026-05-28 21:04:37,729 [lib.api.process] INFO: Monitor config for process 6036: C:\y_khzgei\dll\6036.ini
2026-05-28 21:04:37,731 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,736 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,742 [root] DEBUG: Loader: Injecting process 6036 (thread 6060) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,742 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,743 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,744 [lib.api.process] INFO: Injected into 64-bit <Process 6036 dllhost.exe>
2026-05-28 21:04:37,747 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6036
2026-05-28 21:04:37,749 [lib.api.process] INFO: Monitor config for process 6036: C:\y_khzgei\dll\6036.ini
2026-05-28 21:04:37,751 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,754 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,759 [root] DEBUG: Loader: Injecting process 6036 (thread 6060) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,760 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,761 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,763 [lib.api.process] INFO: Injected into 64-bit <Process 6036 dllhost.exe>
2026-05-28 21:04:37,767 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 1116: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:04:37,768 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 1116
2026-05-28 21:04:37,768 [lib.api.process] INFO: Monitor config for process 1116: C:\y_khzgei\dll\1116.ini
2026-05-28 21:04:37,771 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,775 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,779 [root] DEBUG: Loader: Injecting process 1116 (thread 2168) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,780 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,782 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,784 [lib.api.process] INFO: Injected into 64-bit <Process 1116 dllhost.exe>
2026-05-28 21:04:37,788 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 1116
2026-05-28 21:04:37,789 [lib.api.process] INFO: Monitor config for process 1116: C:\y_khzgei\dll\1116.ini
2026-05-28 21:04:37,789 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:04:37,795 [lib.api.process] INFO: 64-bit DLL to inject is C:\y_khzgei\dll\ElpVTmeL.dll, loader C:\y_khzgei\bin\pcWqBqLl.exe
2026-05-28 21:04:37,800 [root] DEBUG: Loader: Injecting process 1116 (thread 2168) with C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,800 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:04:37,802 [root] DEBUG: Successfully injected DLL C:\y_khzgei\dll\ElpVTmeL.dll.
2026-05-28 21:04:37,804 [lib.api.process] INFO: Injected into 64-bit <Process 1116 dllhost.exe>
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 21:02:59 | 2026-05-28 21:04:50 | none |
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 20.227.97.55 [VT] | unknown | - |
| Y | 150.171.109.25 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| N | 162.159.130.235 [VT] | unknown | - |
| Y | 149.135.84.160 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| N | 162.159.134.233 [VT] | unknown | - |
| N | 162.159.128.233 [VT] | unknown | - |
| N | 23.209.183.106 [VT] | unknown | - |
| N | 162.254.195.75 [VT] | unknown | - |
| N | 162.254.195.69 [VT] | unknown | - |
| N | 103.10.125.22 [VT] | unknown | - |
| N | 103.10.125.23 [VT] | unknown | - |
| N | 162.159.138.232 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 172.172.255.218 [VT] | unknown | - |
| Y | 20.190.167.19 [VT] | unknown | - |
| N | 162.159.133.233 [VT] | unknown | - |
| Y | 162.159.135.234 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.8.8 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| status.discord.com [VT] |
A 162.159.128.233
[VT]
A 162.159.138.232 [VT] A 162.159.137.232 [VT] A 162.159.135.232 [VT] A 162.159.136.232 [VT] |
162.159.136.232 [VT] |
| cmp2-syd1.steamserver.net [VT] | A 103.10.125.23 [VT] | 103.10.125.23 [VT] |
| cmp1-syd1.steamserver.net [VT] | A 103.10.125.22 [VT] | 103.10.125.22 [VT] |
| cmp1-lax1.steamserver.net [VT] | A 162.254.195.69 [VT] | 162.254.195.69 [VT] |
| cmp2-lax1.steamserver.net [VT] | A 162.254.195.75 [VT] | 162.254.195.75 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.24 [VT] |
| clientconfig.akamai.steamstatic.com [VT] |
A 23.209.183.106
[VT]
A 23.209.183.176 [VT] |
23.211.125.112 [VT] |
| cdn.discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.133.233 [VT] |
| steamcommunity.com [VT] | 23.216.106.59 [VT] | |
| discord.com [VT] | 162.159.136.232 [VT] | |
| latency.discord.media [VT] |
A 162.159.130.235
[VT]
A 162.159.129.235 [VT] A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.128.235 [VT] |
162.159.138.234 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.