| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 21:04:54 | 2026-05-28 21:06:27 | 93s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 20:53:02,790 [root] INFO: Date set to: 20260528T21:05:01, timeout set to: 1200
2026-05-28 21:05:01,006 [root] DEBUG: Starting analyzer from: C:\rl4cuydm
2026-05-28 21:05:01,006 [root] DEBUG: Storing results at: C:\SnQADZPxRF
2026-05-28 21:05:01,007 [root] DEBUG: Pipe server name: \\.\PIPE\ZKqbPx
2026-05-28 21:05:01,007 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 21:05:01,008 [root] INFO: analysis running as an admin
2026-05-28 21:05:01,008 [root] INFO: analysis package specified: "edge"
2026-05-28 21:05:01,008 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 21:05:01,029 [root] DEBUG: imported analysis package "edge"
2026-05-28 21:05:01,030 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 21:05:01,030 [root] DEBUG: New location of moved file: d
2026-05-28 21:05:01,030 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 21:05:01,030 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 21:05:01,030 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 21:05:01,030 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 21:05:01,097 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 21:05:01,116 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 21:05:01,122 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 21:05:01,132 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 21:05:01,140 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 21:05:01,141 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 21:05:01,141 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 21:05:01,143 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 21:05:01,143 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 21:05:01,143 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 21:05:01,144 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 21:05:01,144 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 21:05:01,144 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 21:05:01,144 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 21:05:01,144 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 21:05:01,145 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 21:05:01,145 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 21:05:01,145 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 21:05:01,145 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 21:05:01,145 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 21:05:01,146 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 21:05:01,146 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 21:05:01,146 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 21:05:01,148 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 8924)
2026-05-28 21:05:01,149 [modules.auxiliary.disguise] INFO: Disguising GUID to c668a5b7-31de-43f1-93c5-91b18aa48b35
2026-05-28 21:05:01,149 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 21:05:01,149 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 21:05:01,149 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 21:05:01,150 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 21:05:01,150 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 21:05:01,150 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 21:05:01,150 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 21:05:01,151 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 21:05:01,151 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 21:05:01,151 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 21:05:01,152 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 21:05:01,152 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 21:05:01,152 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 21:05:01,153 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 21:05:01,153 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 21:05:01,153 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 21:05:01,155 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 21:05:01,157 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 21:05:01,157 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 21:05:01,221 [lib.api.process] INFO: Monitor config for process 4484: C:\rl4cuydm\dll\4484.ini
2026-05-28 21:05:01,222 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:01,224 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:01,243 [root] DEBUG: Loader: Injecting process 4484 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:01,395 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:01,397 [root] DEBUG: 4484: Disabling sleep skipping.
2026-05-28 21:05:01,397 [root] DEBUG: 4484: Interactive desktop enabled.
2026-05-28 21:05:01,398 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-28 21:05:01,399 [root] DEBUG: 4484: Interactive desktop - injecting Explorer Shell
2026-05-28 21:05:01,405 [root] DEBUG: 4484: YaraInit: Compiled 44 rule files
2026-05-28 21:05:01,407 [root] DEBUG: 4484: YaraInit: Compiled rules saved to file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:05:01,438 [root] DEBUG: 4484: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:01,449 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-28 21:05:01,489 [root] DEBUG: 4484: Monitor initialised: 64-bit capemon loaded in process 4484 at 0x00007FFF1A4F0000, thread 9024, image base 0x00007FF79BC10000, stack from 0x0000000010472000-0x0000000010480000
2026-05-28 21:05:01,490 [root] DEBUG: 4484: Commandline: C:\Windows\Explorer.EXE
2026-05-28 21:05:01,502 [root] DEBUG: 4484: Hooked 69 out of 69 functions
2026-05-28 21:05:01,532 [root] DEBUG: 4484: Syscall hook installed, syscall logging level 1
2026-05-28 21:05:01,542 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 21:05:01,542 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:01,544 [lib.api.process] INFO: Injected into 64-bit <Process 4484 explorer.exe>
2026-05-28 21:05:01,669 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00007FF79BC10000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF79BC7A06E, thread 4696).
2026-05-28 21:05:01,670 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-28 21:05:01,709 [root] DEBUG: 4484: ProcessImageBase: Main module image at 0x00007FF79BC10000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:03,347 [lib.api.process] INFO: Monitor config for process 832: C:\rl4cuydm\dll\832.ini
2026-05-28 21:05:03,349 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:03,350 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:03,355 [root] DEBUG: Loader: Injecting process 832 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:03,358 [root] DEBUG: 832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:03,359 [root] DEBUG: 832: Disabling sleep skipping.
2026-05-28 21:05:03,359 [root] DEBUG: 832: Interactive desktop enabled.
2026-05-28 21:05:03,360 [root] DEBUG: 832: Dropped file limit defaulting to 100.
2026-05-28 21:05:03,361 [root] DEBUG: 832: Services hook set enabled
2026-05-28 21:05:03,362 [root] DEBUG: 832: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:05:03,374 [root] DEBUG: 832: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:03,375 [root] DEBUG: 832: Monitor initialised: 64-bit capemon loaded in process 832 at 0x00007FFF1A4F0000, thread 7528, image base 0x00007FF7BF220000, stack from 0x000000CCA78F4000-0x000000CCA7900000
2026-05-28 21:05:03,375 [root] DEBUG: 832: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 21:05:03,388 [root] DEBUG: 832: Hooked 69 out of 69 functions
2026-05-28 21:05:03,389 [root] INFO: Loaded monitor into process with pid 832
2026-05-28 21:05:03,390 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 21:05:03,391 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:03,392 [lib.api.process] INFO: Injected into 64-bit <Process 832 svchost.exe>
2026-05-28 21:05:04,424 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8636: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:04,425 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8636
2026-05-28 21:05:04,426 [lib.api.process] INFO: Monitor config for process 8636: C:\rl4cuydm\dll\8636.ini
2026-05-28 21:05:04,426 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:04,427 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:04,431 [root] DEBUG: Loader: Injecting process 8636 (thread 8632) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:04,432 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:04,432 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:04,433 [lib.api.process] INFO: Injected into 64-bit <Process 8636 dllhost.exe>
2026-05-28 21:05:04,434 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8636
2026-05-28 21:05:04,434 [lib.api.process] INFO: Monitor config for process 8636: C:\rl4cuydm\dll\8636.ini
2026-05-28 21:05:04,435 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:04,435 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:04,439 [root] DEBUG: Loader: Injecting process 8636 (thread 8632) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:04,439 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:04,440 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:04,441 [lib.api.process] INFO: Injected into 64-bit <Process 8636 dllhost.exe>
2026-05-28 21:05:04,455 [root] DEBUG: 8636: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:04,455 [root] DEBUG: 8636: Interactive desktop enabled.
2026-05-28 21:05:04,456 [root] DEBUG: 8636: Dropped file limit defaulting to 100.
2026-05-28 21:05:04,457 [root] DEBUG: 8636: Disabling sleep skipping.
2026-05-28 21:05:04,458 [root] DEBUG: 8636: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:05:04,470 [root] DEBUG: 8636: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:04,470 [root] DEBUG: 8636: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:05:04,471 [root] DEBUG: 8636: Monitor initialised: 64-bit capemon loaded in process 8636 at 0x00007FFF1A4F0000, thread 8632, image base 0x00007FF6706B0000, stack from 0x000000B4DC0F4000-0x000000B4DC100000
2026-05-28 21:05:04,472 [root] DEBUG: 8636: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 21:05:04,479 [root] DEBUG: 4484: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 21:05:04,481 [root] DEBUG: 4484: DLL loaded at 0x00007FFF54AE0000: C:\Windows\SYSTEM32\MLANG (0x42000 bytes).
2026-05-28 21:05:04,482 [root] DEBUG: 8636: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:05:04,503 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:05:04,504 [root] DEBUG: 8636: set_hooks: Unable to hook LockResource
2026-05-28 21:05:04,509 [root] DEBUG: 8636: Hooked 627 out of 628 functions
2026-05-28 21:05:04,510 [root] DEBUG: 8636: Syscall hook installed, syscall logging level 1
2026-05-28 21:05:04,515 [root] DEBUG: 8636: RestoreHeaders: Restored original import table.
2026-05-28 21:05:04,516 [root] INFO: Loaded monitor into process with pid 8636
2026-05-28 21:05:04,516 [root] DEBUG: 8636: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 8632).
2026-05-28 21:05:04,517 [root] DEBUG: 8636: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:05:04,518 [root] DEBUG: 8636: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:04,520 [root] DEBUG: 8636: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:05:04,521 [root] DEBUG: 8636: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:05:04,524 [root] DEBUG: 8636: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:05:04,538 [root] DEBUG: 8636: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:05:04,556 [root] DEBUG: 8636: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:05:04,557 [root] DEBUG: 8636: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 21:05:04,564 [root] DEBUG: 8636: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 21:05:06,315 [root] DEBUG: 4484: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:05:07,981 [root] DEBUG: 4484: DLL loaded at 0x00007FFF49E50000: C:\Windows\System32\Windows.UI.Xaml (0x10c0000 bytes).
2026-05-28 21:05:07,984 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D380000: C:\Windows\system32\WindowsInternal.ComposableShell.DesktopHosting (0x2e000 bytes).
2026-05-28 21:05:07,992 [root] DEBUG: 4484: DLL loaded at 0x00007FFF19080000: C:\Windows\ShellComponents\WindowsInternal.ComposableShell.Experiences.Switcher (0x24d000 bytes).
2026-05-28 21:05:07,997 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4D300000: C:\Windows\ShellExperiences\TileControl (0x7d000 bytes).
2026-05-28 21:05:08,000 [root] DEBUG: 4484: DLL loaded at 0x00007FFF18E60000: C:\Windows\ShellComponents\TaskFlowUI (0x215000 bytes).
2026-05-28 21:05:08,019 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46660000: C:\Windows\System32\UiaManager (0xa1000 bytes).
2026-05-28 21:05:08,139 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE181000, size: 0x1000.
2026-05-28 21:05:09,171 [root] INFO: Restarting WMI Service
2026-05-28 21:05:09,628 [root] INFO: Process with pid 8636 has terminated
2026-05-28 21:05:09,629 [root] DEBUG: 8636: NtTerminateProcess hook: Attempting to dump process 8636
2026-05-28 21:05:09,630 [root] DEBUG: 8636: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:05:10,297 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 5356: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe, ImageBase: 0x00007FF741E00000
2026-05-28 21:05:10,298 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 5356
2026-05-28 21:05:10,298 [lib.api.process] INFO: Monitor config for process 5356: C:\rl4cuydm\dll\5356.ini
2026-05-28 21:05:10,299 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,311 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2800: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:10,313 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2800
2026-05-28 21:05:10,313 [lib.api.process] INFO: Monitor config for process 2800: C:\rl4cuydm\dll\2800.ini
2026-05-28 21:05:10,314 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,315 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,320 [root] DEBUG: Loader: Injecting process 2800 (thread 5324) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,321 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,322 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,323 [lib.api.process] INFO: Injected into 64-bit <Process 2800 dllhost.exe>
2026-05-28 21:05:10,324 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2800
2026-05-28 21:05:10,325 [lib.api.process] INFO: Monitor config for process 2800: C:\rl4cuydm\dll\2800.ini
2026-05-28 21:05:10,325 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,327 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,331 [root] DEBUG: Loader: Injecting process 2800 (thread 5324) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,332 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,333 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,334 [lib.api.process] INFO: Injected into 64-bit <Process 2800 dllhost.exe>
2026-05-28 21:05:10,340 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2496: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:10,341 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2496
2026-05-28 21:05:10,342 [lib.api.process] INFO: Monitor config for process 2496: C:\rl4cuydm\dll\2496.ini
2026-05-28 21:05:10,355 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,372 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,376 [root] DEBUG: Loader: Injecting process 2496 (thread 3712) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,377 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,377 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,378 [lib.api.process] INFO: Injected into 64-bit <Process 2496 dllhost.exe>
2026-05-28 21:05:10,379 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2496
2026-05-28 21:05:10,379 [lib.api.process] INFO: Monitor config for process 2496: C:\rl4cuydm\dll\2496.ini
2026-05-28 21:05:10,380 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,382 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,388 [root] DEBUG: Loader: Injecting process 2496 (thread 3712) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,389 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,390 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,391 [lib.api.process] INFO: Injected into 64-bit <Process 2496 dllhost.exe>
2026-05-28 21:05:10,395 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 812: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:10,396 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 812
2026-05-28 21:05:10,396 [lib.api.process] INFO: Monitor config for process 812: C:\rl4cuydm\dll\812.ini
2026-05-28 21:05:10,397 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,414 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,430 [root] DEBUG: Loader: Injecting process 812 (thread 444) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,431 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,435 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,440 [lib.api.process] INFO: Injected into 64-bit <Process 812 dllhost.exe>
2026-05-28 21:05:10,442 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 812
2026-05-28 21:05:10,445 [lib.api.process] INFO: Monitor config for process 812: C:\rl4cuydm\dll\812.ini
2026-05-28 21:05:10,446 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,449 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,456 [root] DEBUG: Loader: Injecting process 812 (thread 444) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,456 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,457 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,459 [lib.api.process] INFO: Injected into 64-bit <Process 812 dllhost.exe>
2026-05-28 21:05:10,463 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 4388: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:10,464 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4388
2026-05-28 21:05:10,464 [lib.api.process] INFO: Monitor config for process 4388: C:\rl4cuydm\dll\4388.ini
2026-05-28 21:05:10,465 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,468 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,476 [root] DEBUG: Loader: Injecting process 4388 (thread 5584) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,477 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,478 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,480 [lib.api.process] INFO: Injected into 64-bit <Process 4388 dllhost.exe>
2026-05-28 21:05:10,481 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4388
2026-05-28 21:05:10,481 [lib.api.process] INFO: Monitor config for process 4388: C:\rl4cuydm\dll\4388.ini
2026-05-28 21:05:10,482 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,483 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,488 [root] DEBUG: Loader: Injecting process 4388 (thread 5584) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,489 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,490 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,491 [lib.api.process] INFO: Injected into 64-bit <Process 4388 dllhost.exe>
2026-05-28 21:05:10,497 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8276: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:10,498 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8276
2026-05-28 21:05:10,499 [lib.api.process] INFO: Monitor config for process 8276: C:\rl4cuydm\dll\8276.ini
2026-05-28 21:05:10,500 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,501 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,507 [root] DEBUG: Loader: Injecting process 8276 (thread 8280) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,508 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,509 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,510 [lib.api.process] INFO: Injected into 64-bit <Process 8276 dllhost.exe>
2026-05-28 21:05:10,511 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8276
2026-05-28 21:05:10,512 [lib.api.process] INFO: Monitor config for process 8276: C:\rl4cuydm\dll\8276.ini
2026-05-28 21:05:10,512 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,514 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,519 [root] DEBUG: Loader: Injecting process 8276 (thread 8280) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,520 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,520 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,522 [lib.api.process] INFO: Injected into 64-bit <Process 8276 dllhost.exe>
2026-05-28 21:05:10,527 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 3284: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:10,529 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3284
2026-05-28 21:05:10,529 [lib.api.process] INFO: Monitor config for process 3284: C:\rl4cuydm\dll\3284.ini
2026-05-28 21:05:10,531 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,532 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,538 [root] DEBUG: Loader: Injecting process 3284 (thread 3368) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,539 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,540 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,541 [lib.api.process] INFO: Injected into 64-bit <Process 3284 dllhost.exe>
2026-05-28 21:05:10,544 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3284
2026-05-28 21:05:10,544 [lib.api.process] INFO: Monitor config for process 3284: C:\rl4cuydm\dll\3284.ini
2026-05-28 21:05:10,545 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:10,546 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,550 [root] DEBUG: Loader: Injecting process 3284 (thread 3368) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,551 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,551 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,553 [lib.api.process] INFO: Injected into 64-bit <Process 3284 dllhost.exe>
2026-05-28 21:05:10,941 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:10,948 [root] DEBUG: Loader: Injecting process 5356 (thread 5376) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,950 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:10,950 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:10,952 [lib.api.process] INFO: Injected into 64-bit <Process 5356 TextInputHost.exe>
2026-05-28 21:05:10,953 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 5356
2026-05-28 21:05:10,953 [lib.api.process] INFO: Monitor config for process 5356: C:\rl4cuydm\dll\5356.ini
2026-05-28 21:05:10,954 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,039 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,045 [root] DEBUG: Loader: Injecting process 5356 (thread 5376) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,046 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:11,047 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,048 [lib.api.process] INFO: Injected into 64-bit <Process 5356 TextInputHost.exe>
2026-05-28 21:05:11,049 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 5356
2026-05-28 21:05:11,049 [lib.api.process] INFO: Monitor config for process 5356: C:\rl4cuydm\dll\5356.ini
2026-05-28 21:05:11,050 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,140 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,145 [root] DEBUG: Loader: Injecting process 5356 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,146 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 5376, handle 0x120
2026-05-28 21:05:11,146 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:11,147 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,148 [lib.api.process] INFO: Injected into 64-bit <Process 5356 TextInputHost.exe>
2026-05-28 21:05:11,201 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 21:05:11,202 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 21:05:11,202 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 21:05:11,204 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""d"" with pid 2912
2026-05-28 21:05:11,204 [lib.api.process] INFO: Monitor config for process 2912: C:\rl4cuydm\dll\2912.ini
2026-05-28 21:05:11,205 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,206 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,210 [root] DEBUG: Loader: Injecting process 2912 (thread 2780) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,211 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:11,211 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,213 [lib.api.process] INFO: Injected into 64-bit <Process 2912 msedge.exe>
2026-05-28 21:05:11,818 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 7348: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF7E2EF0000
2026-05-28 21:05:11,820 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 7348
2026-05-28 21:05:11,820 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 1204: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF7E2EF0000
2026-05-28 21:05:11,820 [lib.api.process] INFO: Monitor config for process 7348: C:\rl4cuydm\dll\7348.ini
2026-05-28 21:05:11,822 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 1204
2026-05-28 21:05:11,823 [lib.api.process] INFO: Monitor config for process 1204: C:\rl4cuydm\dll\1204.ini
2026-05-28 21:05:11,824 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,826 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,826 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 3280: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF7E2EF0000
2026-05-28 21:05:11,827 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 3280
2026-05-28 21:05:11,828 [lib.api.process] INFO: Monitor config for process 3280: C:\rl4cuydm\dll\3280.ini
2026-05-28 21:05:11,828 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,828 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,830 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,831 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,833 [root] DEBUG: Loader: Injecting process 1204 (thread 1132) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,834 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:11,834 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,835 [root] DEBUG: Loader: Injecting process 7348 (thread 8596) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,835 [root] DEBUG: Loader: Injecting process 3280 (thread 8652) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,836 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:11,836 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:11,836 [lib.api.process] INFO: Injected into 64-bit <Process 1204 backgroundTaskHost.exe>
2026-05-28 21:05:11,836 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,837 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,838 [lib.api.process] INFO: Injected into 64-bit <Process 7348 backgroundTaskHost.exe>
2026-05-28 21:05:11,837 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 1204
2026-05-28 21:05:11,838 [lib.api.process] INFO: Monitor config for process 1204: C:\rl4cuydm\dll\1204.ini
2026-05-28 21:05:11,839 [lib.api.process] INFO: Injected into 64-bit <Process 3280 backgroundTaskHost.exe>
2026-05-28 21:05:11,840 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,839 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 7348
2026-05-28 21:05:11,840 [lib.api.process] INFO: Monitor config for process 7348: C:\rl4cuydm\dll\7348.ini
2026-05-28 21:05:11,841 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 3280
2026-05-28 21:05:11,841 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,841 [lib.api.process] INFO: Monitor config for process 3280: C:\rl4cuydm\dll\3280.ini
2026-05-28 21:05:11,842 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,842 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,843 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,843 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,846 [root] DEBUG: Loader: Injecting process 1204 (thread 1132) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,847 [root] DEBUG: Loader: Injecting process 7348 (thread 8596) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,848 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:11,848 [root] DEBUG: Loader: Injecting process 3280 (thread 8652) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,848 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:11,849 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,849 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:11,849 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,850 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,850 [lib.api.process] INFO: Injected into 64-bit <Process 1204 backgroundTaskHost.exe>
2026-05-28 21:05:11,851 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 1204
2026-05-28 21:05:11,851 [lib.api.process] INFO: Injected into 64-bit <Process 7348 backgroundTaskHost.exe>
2026-05-28 21:05:11,851 [lib.api.process] INFO: Monitor config for process 1204: C:\rl4cuydm\dll\1204.ini
2026-05-28 21:05:11,851 [lib.api.process] INFO: Injected into 64-bit <Process 3280 backgroundTaskHost.exe>
2026-05-28 21:05:11,853 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,853 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 7348
2026-05-28 21:05:11,853 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 3280
2026-05-28 21:05:11,854 [lib.api.process] INFO: Monitor config for process 7348: C:\rl4cuydm\dll\7348.ini
2026-05-28 21:05:11,855 [lib.api.process] INFO: Monitor config for process 3280: C:\rl4cuydm\dll\3280.ini
2026-05-28 21:05:11,854 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,855 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,855 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:11,857 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,858 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:11,860 [root] DEBUG: Loader: Injecting process 1204 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,861 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 1132, handle 0x120
2026-05-28 21:05:11,861 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:11,862 [root] DEBUG: Loader: Injecting process 3280 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,862 [root] DEBUG: Loader: Injecting process 7348 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,862 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8652, handle 0x124
2026-05-28 21:05:11,863 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8596, handle 0x124
2026-05-28 21:05:11,863 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,863 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:11,864 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:11,864 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,864 [lib.api.process] INFO: Injected into 64-bit <Process 1204 backgroundTaskHost.exe>
2026-05-28 21:05:11,865 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:11,865 [lib.api.process] INFO: Injected into 64-bit <Process 3280 backgroundTaskHost.exe>
2026-05-28 21:05:11,866 [lib.api.process] INFO: Injected into 64-bit <Process 7348 backgroundTaskHost.exe>
2026-05-28 21:05:13,228 [lib.api.process] INFO: Successfully resumed process with pid 2912
2026-05-28 21:05:13,276 [root] DEBUG: 2912: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:13,277 [root] DEBUG: 2912: Interactive desktop enabled.
2026-05-28 21:05:13,277 [root] DEBUG: 2912: Dropped file limit defaulting to 100.
2026-05-28 21:05:13,285 [root] DEBUG: 2912: Edge-specific hook-set enabled.
2026-05-28 21:05:13,287 [root] DEBUG: 2912: Disabling sleep skipping.
2026-05-28 21:05:13,287 [root] DEBUG: 2912: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:05:13,298 [root] DEBUG: 2912: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:13,299 [root] DEBUG: 2912: Monitor initialised: 64-bit capemon loaded in process 2912 at 0x00007FFF1A4F0000, thread 2780, image base 0x00007FF7F5380000, stack from 0x00000047DB9F4000-0x00000047DBA00000
2026-05-28 21:05:13,299 [root] DEBUG: 2912: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "d"
2026-05-28 21:05:13,308 [root] DEBUG: 2912: Hooked 2 out of 2 functions
2026-05-28 21:05:13,341 [root] DEBUG: 2912: Syscall hook installed, syscall logging level 1
2026-05-28 21:05:13,346 [root] DEBUG: 2912: RestoreHeaders: Restored original import table.
2026-05-28 21:05:13,346 [root] INFO: Loaded monitor into process with pid 2912
2026-05-28 21:05:13,347 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:05:13,350 [root] DEBUG: 2912: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 21:05:13,351 [root] DEBUG: 2912: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:05:13,352 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 21:05:13,353 [root] DEBUG: 2912: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:05:13,353 [root] DEBUG: 2912: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 21:05:13,355 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 21:05:13,595 [root] DEBUG: 2912: DLL loaded at 0x00007FFF453C0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 21:05:13,596 [root] DEBUG: 2912: DLL loaded at 0x000001E76A000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 21:05:13,599 [root] DEBUG: 2912: DLL loaded at 0x00007FFF45010000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 21:05:13,602 [root] DEBUG: 2912: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:05:13,604 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3D6A0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 21:05:13,606 [root] DEBUG: 2912: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:05:13,608 [root] DEBUG: 2912: CreateProcessHandler: Injection info set for new process 4408: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:05:13,608 [root] DEBUG: 2912: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:05:13,608 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 4408
2026-05-28 21:05:13,609 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4D010000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 21:05:13,610 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 4408
2026-05-28 21:05:13,611 [root] DEBUG: 2912: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:05:13,611 [root] DEBUG: 2912: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:05:13,620 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 21:05:13,621 [root] DEBUG: 2912: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 21:05:13,622 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 21:05:13,623 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 21:05:13,624 [root] DEBUG: 2912: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:05:13,624 [root] DEBUG: 2912: DLL loaded at 0x00007FFF46470000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 21:05:13,626 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 21:05:13,627 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 21:05:13,627 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 21:05:13,628 [root] DEBUG: 2912: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 21:05:13,628 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 21:05:13,629 [root] DEBUG: 2912: DLL loaded at 0x00007FFF42D90000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 21:05:13,629 [root] DEBUG: 2912: DLL loaded at 0x00007FFF46FC0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 21:05:13,630 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 21:05:13,630 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 21:05:13,632 [root] DEBUG: 2912: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 21:05:13,633 [root] DEBUG: 2912: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:05:13,633 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 21:05:13,634 [root] DEBUG: 2912: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 21:05:13,636 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 21:05:13,645 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4CFA0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 21:05:13,646 [root] DEBUG: 2912: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 21:05:13,647 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 21:05:13,648 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 21:05:13,648 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 21:05:13,651 [root] DEBUG: 2912: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 21:05:13,654 [root] DEBUG: 2912: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:05:13,655 [root] DEBUG: 2912: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 21:05:13,657 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:05:13,658 [root] DEBUG: 2912: DLL loaded at 0x00007FFF569F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 21:05:13,659 [root] DEBUG: 2912: DLL loaded at 0x00007FFF52960000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 21:05:13,660 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 21:05:13,660 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 21:05:13,662 [root] DEBUG: 2912: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 21:05:13,663 [root] DEBUG: 2912: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 21:05:13,664 [root] DEBUG: 2912: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 21:05:13,664 [root] DEBUG: 2912: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 21:05:13,665 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 21:05:13,667 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 21:05:13,672 [root] DEBUG: 2912: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 21:05:13,673 [root] DEBUG: 2912: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:05:13,673 [root] DEBUG: 2912: DLL loaded at 0x00007FFF54170000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 21:05:13,674 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4B680000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 21:05:13,675 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 21:05:13,678 [root] DEBUG: 2912: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 21:05:13,679 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 21:05:13,680 [root] DEBUG: 2912: DLL loaded at 0x00007FFF45580000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 21:05:13,685 [root] DEBUG: 2912: DLL loaded at 0x00007FFF52420000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 21:05:13,686 [root] DEBUG: 2912: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 21:05:13,691 [root] DEBUG: 2912: DLL loaded at 0x00007FFF51A60000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 21:05:13,692 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4AF10000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 21:05:13,692 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4BFB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 21:05:13,694 [root] DEBUG: 2912: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 21:05:13,695 [root] DEBUG: 2912: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 21:05:13,696 [root] DEBUG: 2912: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 21:05:13,698 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 21:05:13,700 [root] DEBUG: 2912: DLL loaded at 0x00007FFF515E0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 21:05:13,701 [root] DEBUG: 2912: DLL loaded at 0x00007FFF51600000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 21:05:13,711 [root] DEBUG: 2912: DLL loaded at 0x00007FFF52560000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 21:05:13,715 [root] DEBUG: 2912: CreateProcessHandler: Injection info set for new process 9648: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:05:13,716 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 9648
2026-05-28 21:05:13,717 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 9648
2026-05-28 21:05:13,718 [root] DEBUG: 2912: DLL loaded at 0x00007FFF01A30000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 21:05:13,718 [root] DEBUG: 2912: caller_dispatch: Added region at 0x00007FF7F5380000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7F5477D66, thread 9380).
2026-05-28 21:05:13,718 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 21:05:13,719 [lib.api.process] INFO: Monitor config for process 676: C:\rl4cuydm\dll\676.ini
2026-05-28 21:05:13,721 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:13,723 [root] DEBUG: 2912: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:13,724 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:13,725 [root] DEBUG: 2912: CreateProcessHandler: Injection info set for new process 9704: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:05:13,726 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 9704
2026-05-28 21:05:13,727 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 9704
2026-05-28 21:05:13,731 [root] DEBUG: 2912: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 21:05:13,733 [root] DEBUG: Loader: Injecting process 676 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:13,735 [root] DEBUG: Loader: Copied config file C:\rl4cuydm\dll\676.ini to system path C:\676.ini
2026-05-28 21:05:13,736 [root] DEBUG: 2912: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 21:05:13,783 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 676 C:\rl4cuydm\dll\ELAodRE.dll
2026-05-28 21:05:13,784 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:13,785 [lib.api.process] INFO: Injected into 64-bit <Process 676 services.exe>
2026-05-28 21:05:13,811 [root] DEBUG: 2912: CreateProcessHandler: Injection info set for new process 9904: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:05:13,812 [root] DEBUG: 2912: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 21:05:13,813 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 9904
2026-05-28 21:05:13,814 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 9904
2026-05-28 21:05:13,886 [root] DEBUG: 2912: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 21:05:13,887 [root] DEBUG: 2912: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 21:05:13,888 [root] DEBUG: 2912: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 21:05:13,889 [root] DEBUG: 2912: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 21:05:13,930 [root] DEBUG: 2912: DLL loaded at 0x00007FFF46FB0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 21:05:13,951 [root] DEBUG: 2912: DLL loaded at 0x00007FFF43990000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 21:05:13,954 [root] DEBUG: 2912: CreateProcessHandler: Injection info set for new process 10100: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:05:13,954 [root] DEBUG: 2912: CreateProcessHandler: Injection info set for new process 10116: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:05:13,955 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 10100
2026-05-28 21:05:13,955 [root] DEBUG: 2912: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 21:05:13,956 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 10116
2026-05-28 21:05:13,956 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 10100
2026-05-28 21:05:13,957 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 10116
2026-05-28 21:05:13,986 [root] DEBUG: 2912: DLL loaded at 0x00007FFF3EA70000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes).
2026-05-28 21:05:13,990 [root] DEBUG: 2912: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 21:05:14,045 [root] DEBUG: 2912: DLL loaded at 0x00007FFF55220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 21:05:14,071 [root] DEBUG: 2912: DLL loaded at 0x00007FFF3F8B0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 21:05:14,081 [root] DEBUG: 2912: DLL loaded at 0x00007FFF46FE0000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1e000 bytes).
2026-05-28 21:05:14,082 [root] DEBUG: 2912: DLL loaded at 0x00007FFF46430000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Domain Actions\3.0.0.18\domain_actions (0x17000 bytes).
2026-05-28 21:05:14,084 [root] DEBUG: 2912: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 21:05:14,091 [root] DEBUG: 2912: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 21:05:14,094 [root] DEBUG: 2912: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 21:05:14,106 [root] DEBUG: 2912: DLL loaded at 0x00007FFF3F7A0000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 21:05:14,115 [root] DEBUG: 2912: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 21:05:14,126 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 21:05:14,127 [root] DEBUG: 2912: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 21:05:14,805 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10372: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:14,817 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10372
2026-05-28 21:05:14,819 [lib.api.process] INFO: Monitor config for process 10372: C:\rl4cuydm\dll\10372.ini
2026-05-28 21:05:14,824 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:14,828 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:14,850 [root] DEBUG: Loader: Injecting process 10372 (thread 10376) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,851 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:14,852 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,859 [lib.api.process] INFO: Injected into 64-bit <Process 10372 dllhost.exe>
2026-05-28 21:05:14,863 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10372
2026-05-28 21:05:14,864 [lib.api.process] INFO: Monitor config for process 10372: C:\rl4cuydm\dll\10372.ini
2026-05-28 21:05:14,865 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:14,866 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:14,872 [root] DEBUG: Loader: Injecting process 10372 (thread 10376) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,873 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:14,874 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,875 [lib.api.process] INFO: Injected into 64-bit <Process 10372 dllhost.exe>
2026-05-28 21:05:14,884 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10488: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:14,885 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10488
2026-05-28 21:05:14,885 [lib.api.process] INFO: Monitor config for process 10488: C:\rl4cuydm\dll\10488.ini
2026-05-28 21:05:14,886 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:14,888 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:14,893 [root] DEBUG: Loader: Injecting process 10488 (thread 10492) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,894 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:14,895 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,896 [lib.api.process] INFO: Injected into 64-bit <Process 10488 dllhost.exe>
2026-05-28 21:05:14,897 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10488
2026-05-28 21:05:14,897 [lib.api.process] INFO: Monitor config for process 10488: C:\rl4cuydm\dll\10488.ini
2026-05-28 21:05:14,898 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:14,899 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:14,905 [root] DEBUG: Loader: Injecting process 10488 (thread 10492) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,907 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:14,909 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,911 [lib.api.process] INFO: Injected into 64-bit <Process 10488 dllhost.exe>
2026-05-28 21:05:14,916 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10572: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:14,918 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10572
2026-05-28 21:05:14,919 [lib.api.process] INFO: Monitor config for process 10572: C:\rl4cuydm\dll\10572.ini
2026-05-28 21:05:14,920 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:14,921 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:14,926 [root] DEBUG: Loader: Injecting process 10572 (thread 10576) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,926 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:14,926 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,928 [lib.api.process] INFO: Injected into 64-bit <Process 10572 dllhost.exe>
2026-05-28 21:05:14,929 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10572
2026-05-28 21:05:14,929 [lib.api.process] INFO: Monitor config for process 10572: C:\rl4cuydm\dll\10572.ini
2026-05-28 21:05:14,929 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:14,930 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:14,935 [root] DEBUG: Loader: Injecting process 10572 (thread 10576) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,938 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:14,939 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:14,941 [lib.api.process] INFO: Injected into 64-bit <Process 10572 dllhost.exe>
2026-05-28 21:05:14,947 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10656: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:14,947 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10656
2026-05-28 21:05:14,948 [lib.api.process] INFO: Monitor config for process 10656: C:\rl4cuydm\dll\10656.ini
2026-05-28 21:05:14,952 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:14,954 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:15,025 [root] DEBUG: Loader: Injecting process 10656 (thread 10660) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,026 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:15,027 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,035 [lib.api.process] INFO: Injected into 64-bit <Process 10656 dllhost.exe>
2026-05-28 21:05:15,036 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10656
2026-05-28 21:05:15,037 [lib.api.process] INFO: Monitor config for process 10656: C:\rl4cuydm\dll\10656.ini
2026-05-28 21:05:15,037 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:15,038 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:15,061 [root] DEBUG: Loader: Injecting process 10656 (thread 10660) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,063 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:15,063 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,065 [lib.api.process] INFO: Injected into 64-bit <Process 10656 dllhost.exe>
2026-05-28 21:05:15,067 [root] DEBUG: 676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:15,067 [root] DEBUG: 676: Disabling sleep skipping.
2026-05-28 21:05:15,068 [root] DEBUG: 676: Interactive desktop enabled.
2026-05-28 21:05:15,068 [root] DEBUG: 676: Dropped file limit defaulting to 100.
2026-05-28 21:05:15,071 [root] DEBUG: 676: Services hook set enabled
2026-05-28 21:05:15,089 [root] DEBUG: 676: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:15,090 [root] DEBUG: 676: Monitor initialised: 64-bit capemon loaded in process 676 at 0x00007FFF00AF0000, thread 10736, image base 0x00007FF7839A0000, stack from 0x000000F2F01F1000-0x000000F2F0200000
2026-05-28 21:05:15,091 [root] DEBUG: 676: Commandline: C:\Windows\system32\services.exe
2026-05-28 21:05:15,105 [root] DEBUG: 676: Hooked 69 out of 69 functions
2026-05-28 21:05:15,109 [root] INFO: Loaded monitor into process with pid 676
2026-05-28 21:05:15,659 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10852: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:15,663 [root] DEBUG: 2912: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:05:15,664 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10852
2026-05-28 21:05:15,665 [lib.api.process] INFO: Monitor config for process 10852: C:\rl4cuydm\dll\10852.ini
2026-05-28 21:05:15,666 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:15,667 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:15,673 [root] DEBUG: Loader: Injecting process 10852 (thread 10856) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,675 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:15,675 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,677 [lib.api.process] INFO: Injected into 64-bit <Process 10852 dllhost.exe>
2026-05-28 21:05:15,677 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10852
2026-05-28 21:05:15,678 [lib.api.process] INFO: Monitor config for process 10852: C:\rl4cuydm\dll\10852.ini
2026-05-28 21:05:15,678 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:15,680 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:15,684 [root] DEBUG: Loader: Injecting process 10852 (thread 10856) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,685 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:15,685 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,687 [lib.api.process] INFO: Injected into 64-bit <Process 10852 dllhost.exe>
2026-05-28 21:05:15,692 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10944: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:15,692 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10944
2026-05-28 21:05:15,693 [lib.api.process] INFO: Monitor config for process 10944: C:\rl4cuydm\dll\10944.ini
2026-05-28 21:05:15,694 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:15,694 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:15,699 [root] DEBUG: Loader: Injecting process 10944 (thread 10948) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,701 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:15,701 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,703 [lib.api.process] INFO: Injected into 64-bit <Process 10944 dllhost.exe>
2026-05-28 21:05:15,703 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10944
2026-05-28 21:05:15,705 [lib.api.process] INFO: Monitor config for process 10944: C:\rl4cuydm\dll\10944.ini
2026-05-28 21:05:15,706 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:15,707 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:15,707 [root] DEBUG: 2912: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:05:15,712 [root] DEBUG: Loader: Injecting process 10944 (thread 10948) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,713 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:15,713 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:15,716 [lib.api.process] INFO: Injected into 64-bit <Process 10944 dllhost.exe>
2026-05-28 21:05:16,584 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11076: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:16,585 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11076
2026-05-28 21:05:16,586 [lib.api.process] INFO: Monitor config for process 11076: C:\rl4cuydm\dll\11076.ini
2026-05-28 21:05:16,586 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:16,588 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:16,593 [root] DEBUG: Loader: Injecting process 11076 (thread 11080) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,594 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:16,595 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,597 [lib.api.process] INFO: Injected into 64-bit <Process 11076 dllhost.exe>
2026-05-28 21:05:16,598 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11076
2026-05-28 21:05:16,598 [lib.api.process] INFO: Monitor config for process 11076: C:\rl4cuydm\dll\11076.ini
2026-05-28 21:05:16,598 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:16,599 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:16,607 [root] DEBUG: Loader: Injecting process 11076 (thread 11080) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,609 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:16,610 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,612 [lib.api.process] INFO: Injected into 64-bit <Process 11076 dllhost.exe>
2026-05-28 21:05:16,616 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11172: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:16,617 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11172
2026-05-28 21:05:16,617 [lib.api.process] INFO: Monitor config for process 11172: C:\rl4cuydm\dll\11172.ini
2026-05-28 21:05:16,618 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:16,619 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:16,626 [root] DEBUG: Loader: Injecting process 11172 (thread 11176) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,627 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:16,627 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,629 [lib.api.process] INFO: Injected into 64-bit <Process 11172 dllhost.exe>
2026-05-28 21:05:16,630 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11172
2026-05-28 21:05:16,630 [lib.api.process] INFO: Monitor config for process 11172: C:\rl4cuydm\dll\11172.ini
2026-05-28 21:05:16,631 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:16,631 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:16,637 [root] DEBUG: Loader: Injecting process 11172 (thread 11176) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,640 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:16,640 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,643 [lib.api.process] INFO: Injected into 64-bit <Process 11172 dllhost.exe>
2026-05-28 21:05:16,661 [root] DEBUG: 4484: CreateProcessHandler: Injection info set for new process 11260: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ImageBase: 0x00007FF7E4150000
2026-05-28 21:05:16,662 [root] INFO: Announced 64-bit process name: powershell.exe pid: 11260
2026-05-28 21:05:16,662 [lib.api.process] INFO: Monitor config for process 11260: C:\rl4cuydm\dll\11260.ini
2026-05-28 21:05:16,663 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:16,836 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:16,841 [root] DEBUG: Loader: Injecting process 11260 (thread 9696) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,844 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:16,844 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,845 [root] DEBUG: 676: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 21:05:16,846 [root] DEBUG: 676: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:05:16,846 [lib.api.process] INFO: Injected into 64-bit <Process 11260 powershell.exe>
2026-05-28 21:05:16,849 [root] DEBUG: 676: DLL loaded at 0x00007FFF58070000: C:\Windows\system32\SHCORE (0xad000 bytes).
2026-05-28 21:05:16,850 [root] INFO: Announced 64-bit process name: powershell.exe pid: 11260
2026-05-28 21:05:16,850 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 10432: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe, ImageBase: 0x00007FF7C5F80000
2026-05-28 21:05:16,850 [lib.api.process] INFO: Monitor config for process 11260: C:\rl4cuydm\dll\11260.ini
2026-05-28 21:05:16,851 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:16,851 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 10432
2026-05-28 21:05:16,852 [lib.api.process] INFO: Monitor config for process 10432: C:\rl4cuydm\dll\10432.ini
2026-05-28 21:05:16,853 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:16,988 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:16,993 [root] DEBUG: Loader: Injecting process 11260 (thread 9696) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,994 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:16,995 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:16,996 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:05:16,996 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:05:16,997 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:05:16,997 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:05:16,997 [lib.api.process] INFO: Injected into 64-bit <Process 11260 powershell.exe>
2026-05-28 21:05:16,997 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:05:16,998 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:05:16,998 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:05:16,998 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:05:17,006 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:17,009 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 21:05:17,011 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3D4A0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 21:05:17,014 [root] DEBUG: Loader: Injecting process 10432 (thread 10428) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:17,017 [root] DEBUG: 4484: DLL loaded at 0x00007FFF453F0000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 21:05:17,018 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:17,019 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:17,021 [root] INFO: Announced 64-bit process name: powershell.exe pid: 11260
2026-05-28 21:05:17,021 [lib.api.process] INFO: Injected into 64-bit <Process 10432 elevation_service.exe>
2026-05-28 21:05:17,022 [lib.api.process] INFO: Monitor config for process 11260: C:\rl4cuydm\dll\11260.ini
2026-05-28 21:05:17,025 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:17,033 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 10432
2026-05-28 21:05:17,033 [lib.api.process] INFO: Monitor config for process 10432: C:\rl4cuydm\dll\10432.ini
2026-05-28 21:05:17,034 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:17,174 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:17,180 [root] DEBUG: Loader: Injecting process 11260 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:17,181 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9696, handle 0xe8
2026-05-28 21:05:17,181 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:17,182 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:17,182 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:05:17,182 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:05:17,182 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:05:17,183 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:05:17,183 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:05:17,183 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:05:17,183 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:05:17,183 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:05:17,184 [lib.api.process] INFO: Injected into 64-bit <Process 11260 powershell.exe>
2026-05-28 21:05:17,186 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:17,190 [root] DEBUG: Loader: Injecting process 10432 (thread 10428) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:17,191 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:17,191 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:17,196 [lib.api.process] INFO: Injected into 64-bit <Process 10432 elevation_service.exe>
2026-05-28 21:05:17,197 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 10432
2026-05-28 21:05:17,197 [lib.api.process] INFO: Monitor config for process 10432: C:\rl4cuydm\dll\10432.ini
2026-05-28 21:05:17,197 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:17,317 [root] DEBUG: 11260: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:17,319 [root] DEBUG: 11260: Interactive desktop enabled.
2026-05-28 21:05:17,319 [root] DEBUG: 11260: Dropped file limit defaulting to 100.
2026-05-28 21:05:17,323 [root] DEBUG: 11260: Disabling sleep skipping.
2026-05-28 21:05:17,326 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:05:17,327 [root] DEBUG: 11260: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:05:17,328 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:05:17,329 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:05:17,329 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:05:17,329 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:05:17,329 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:05:17,330 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:05:17,330 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:05:17,332 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:17,341 [root] DEBUG: 11260: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:17,342 [root] DEBUG: Loader: Injecting process 10432 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:17,343 [root] DEBUG: 11260: YaraScan: Scanning 0x00007FF7E4150000, size 0x7caba
2026-05-28 21:05:17,343 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 10428, handle 0x128
2026-05-28 21:05:17,344 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:17,344 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:17,346 [lib.api.process] INFO: Injected into 64-bit <Process 10432 elevation_service.exe>
2026-05-28 21:05:17,346 [root] DEBUG: 11260: Monitor initialised: 64-bit capemon loaded in process 11260 at 0x00007FFF1A4F0000, thread 9696, image base 0x00007FF7E4150000, stack from 0x0000006C11EC4000-0x0000006C11ED0000
2026-05-28 21:05:17,347 [root] DEBUG: 11260: Commandline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
2026-05-28 21:05:17,353 [root] DEBUG: 10432: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:17,356 [root] DEBUG: 10432: Interactive desktop enabled.
2026-05-28 21:05:17,357 [root] DEBUG: 10432: Dropped file limit defaulting to 100.
2026-05-28 21:05:17,361 [root] DEBUG: 11260: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:05:17,364 [root] DEBUG: 10432: Disabling sleep skipping.
2026-05-28 21:05:17,365 [root] DEBUG: 10432: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:05:17,380 [root] DEBUG: 10432: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:17,381 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,386 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:05:17,387 [root] DEBUG: 11260: set_hooks: Unable to hook LockResource
2026-05-28 21:05:17,392 [root] DEBUG: 11260: Hooked 627 out of 628 functions
2026-05-28 21:05:17,395 [root] DEBUG: 11260: Syscall hook installed, syscall logging level 1
2026-05-28 21:05:17,407 [root] DEBUG: 10432: Monitor initialised: 64-bit capemon loaded in process 10432 at 0x00007FFF1A4F0000, thread 10428, image base 0x00007FF7C5F80000, stack from 0x0000003C1D554000-0x0000003C1D560000
2026-05-28 21:05:17,408 [root] DEBUG: 11260: RestoreHeaders: Restored original import table.
2026-05-28 21:05:17,408 [root] DEBUG: 10432: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe"
2026-05-28 21:05:17,408 [root] INFO: Loaded monitor into process with pid 11260
2026-05-28 21:05:17,413 [root] DEBUG: 11260: caller_dispatch: Added region at 0x00007FF7E4150000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7E4154D21, thread 9696).
2026-05-28 21:05:17,413 [root] DEBUG: 11260: YaraScan: Scanning 0x00007FF7E4150000, size 0x7caba
2026-05-28 21:05:17,419 [root] DEBUG: 11260: ProcessImageBase: Main module image at 0x00007FF7E4150000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:17,421 [root] DEBUG: 10432: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:05:17,424 [root] DEBUG: 11260: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:05:17,425 [root] DEBUG: 11260: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:05:17,427 [root] DEBUG: 11260: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:05:17,429 [root] DEBUG: 11260: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:05:17,448 [root] DEBUG: 11260: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 21:05:17,449 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:05:17,450 [root] DEBUG: 11260: DLL loaded at 0x00007FFF55710000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-28 21:05:17,450 [root] DEBUG: 10432: set_hooks: Unable to hook LockResource
2026-05-28 21:05:17,459 [root] DEBUG: 10432: Hooked 627 out of 628 functions
2026-05-28 21:05:17,459 [root] DEBUG: 11260: DLL loaded at 0x00007FFF4C520000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 21:05:17,460 [root] DEBUG: 11260: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 21:05:17,461 [root] DEBUG: 11260: DLL loaded at 0x00007FFF56140000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 21:05:17,461 [root] DEBUG: 11260: DLL loaded at 0x00007FFF56170000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 21:05:17,462 [root] DEBUG: 11260: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 21:05:17,462 [root] DEBUG: 11260: DLL loaded at 0x00007FFF44BB0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 21:05:17,485 [root] DEBUG: 10432: Syscall hook installed, syscall logging level 1
2026-05-28 21:05:17,489 [root] DEBUG: 10432: RestoreHeaders: Restored original import table.
2026-05-28 21:05:17,490 [root] INFO: Loaded monitor into process with pid 10432
2026-05-28 21:05:17,492 [root] DEBUG: 11260: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-05-28 21:05:17,493 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,505 [root] DEBUG: 11260: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 21:05:17,514 [root] DEBUG: 11260: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 21:05:17,516 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,522 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 21:05:17,538 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:05:17,539 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,549 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:05:17,551 [root] DEBUG: 11260: DLL loaded at 0x00007FFF57560000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 21:05:17,556 [root] DEBUG: 4484: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\ploptin (0x13000 bytes).
2026-05-28 21:05:17,561 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,585 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,596 [root] INFO: Added new file to list with pid 11260 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk
2026-05-28 21:05:17,608 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,630 [root] DEBUG: 10432: caller_dispatch: Scanning calling region at 0x00007FF7C5F80000...
2026-05-28 21:05:17,631 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,632 [root] DEBUG: 10432: caller_dispatch: Added region at 0x00007FF7C5F80000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7C60BB9D6, thread 10428).
2026-05-28 21:05:17,632 [root] DEBUG: 10432: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:17,656 [root] DEBUG: 10432: ProcessImageBase: Main module image at 0x00007FF7C5F80000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:17,657 [root] DEBUG: 10432: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:05:17,658 [root] DEBUG: 10432: ProcessImageBase: Main module image at 0x00007FF7C5F80000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:17,662 [root] DEBUG: 10432: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:05:17,674 [root] DEBUG: 10432: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:05:17,683 [root] DEBUG: 10432: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:05:17,718 [root] DEBUG: 10432: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:05:17,728 [root] DEBUG: 2912: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:05:17,759 [root] DEBUG: 2912: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 21:05:17,760 [root] DEBUG: 2912: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 21:05:17,761 [root] DEBUG: 2912: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:05:17,773 [root] DEBUG: 10432: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:05:17,787 [root] DEBUG: 2912: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 21:05:17,788 [root] DEBUG: 2912: DLL loaded at 0x00007FFF409A0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 21:05:17,855 [root] DEBUG: 10432: NtTerminateProcess hook: Attempting to dump process 10432
2026-05-28 21:05:17,861 [root] DEBUG: 11260: DLL loaded at 0x00007FFF41C10000: C:\Windows\SYSTEM32\ntshrui (0x7d000 bytes).
2026-05-28 21:05:17,864 [root] DEBUG: 10432: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:05:17,865 [root] DEBUG: 11260: DLL loaded at 0x00007FFF4D670000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 21:05:17,883 [root] DEBUG: 10432: caller_dispatch: Added region at 0x00007FFF56FD0000 to tracked regions list (ntdll::NtClose returns to 0x00007FFF56FD419B, thread 10428).
2026-05-28 21:05:17,883 [root] DEBUG: 11260: DLL loaded at 0x00007FFF434D0000: C:\Windows\SYSTEM32\cscapi (0x12000 bytes).
2026-05-28 21:05:17,884 [root] DEBUG: 10432: caller_dispatch: Scanning calling region at 0x00007FFF56FD0000...
2026-05-28 21:05:17,909 [root] DEBUG: 11260: DLL loaded at 0x00007FFF566C0000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:05:17,911 [root] DEBUG: 11260: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:05:17,914 [root] INFO: Process with pid 10432 has terminated
2026-05-28 21:05:17,953 [root] INFO: Added new file to list with pid 11260 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VHST5SNBKLGDHAI8GQ3C.temp
2026-05-28 21:05:17,959 [root] DEBUG: 11260: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 21:05:17,961 [root] INFO: Added new file to list with pid 11260 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms
2026-05-28 21:05:17,984 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RFad57.TMP to files\e5a7743b9b7971160418116c3b989d4d02ca253c83e36875441637d943df3af4; Size is 5441; Max size: 100000000
2026-05-28 21:05:18,023 [root] DEBUG: 11260: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:05:18,024 [root] DEBUG: 11260: DLL loaded at 0x00007FFF57470000: C:\Windows\System32\UMPDC (0x12000 bytes).
2026-05-28 21:05:18,027 [root] DEBUG: 11260: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 21:05:18,028 [root] DEBUG: 11260: DLL loaded at 0x00007FFF52F20000: C:\Windows\System32\dsreg (0x141000 bytes).
2026-05-28 21:05:18,029 [root] DEBUG: 11260: DLL loaded at 0x00007FFF45DC0000: C:\Windows\System32\cdp (0x4d4000 bytes).
2026-05-28 21:05:18,029 [root] DEBUG: 11260: DLL loaded at 0x00007FFF40B90000: C:\Windows\System32\TaskFlowDataEngine (0x17e000 bytes).
2026-05-28 21:05:18,041 [root] DEBUG: 11260: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 21:05:18,051 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:05:18,051 [root] DEBUG: 11260: OpenProcessHandler: Injection info created for process 4484, handle 0x49c: Error obtaining target process name
2026-05-28 21:05:18,053 [root] INFO: Announced 64-bit process name: explorer.exe pid: 4484
2026-05-28 21:05:18,054 [lib.api.process] INFO: Monitor config for process 4484: C:\rl4cuydm\dll\4484.ini
2026-05-28 21:05:18,054 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:18,056 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:18,061 [root] DEBUG: Loader: Injecting process 4484 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:18,061 [root] DEBUG: 4484: caller_dispatch: Added region at 0x000000000D430000 to tracked regions list (ntdll::LdrLoadDll returns to 0x000000000D430043, thread 11660).
2026-05-28 21:05:18,062 [root] DEBUG: 4484: DumpPEsInRange: Scanning range 0x000000000D430000 - 0x000000000D430134.
2026-05-28 21:05:18,063 [root] DEBUG: 4484: ScanForDisguisedPE: Size too small: 0x134 bytes
2026-05-28 21:05:18,064 [lib.common.results] INFO: Uploading file C:\SnQADZPxRF\CAPE\4484_2296185129552026 to CAPE\44c97b92a962d051064603a8c8bf865cab4a4bdae213d74bef863b14048fbc7f; Size is 308; Max size: 100000000
2026-05-28 21:05:18,066 [root] DEBUG: 4484: DumpMemory: Payload successfully created: C:\SnQADZPxRF\CAPE\4484_2296185129552026 (size 308 bytes)
2026-05-28 21:05:18,066 [root] DEBUG: 4484: DumpRegion: Dumped entire allocation from 0x000000000D430000, size 4096 bytes.
2026-05-28 21:05:18,067 [root] DEBUG: 4484: ProcessTrackedRegion: Dumped region at 0x000000000D430000.
2026-05-28 21:05:18,067 [root] DEBUG: 4484: YaraScan: Scanning 0x000000000D430000, size 0x134
2026-05-28 21:05:18,069 [root] DEBUG: 4484: Monitor config - unrecognised key host-ip.
2026-05-28 21:05:18,071 [root] DEBUG: 4484: Monitor config - unrecognised key host-port.
2026-05-28 21:05:18,072 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:18,077 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-28 21:05:18,100 [root] DEBUG: 4484: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:05:18,166 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:05:18,167 [root] DEBUG: 4484: set_hooks: Unable to hook LockResource
2026-05-28 21:05:18,220 [root] DEBUG: 4484: Hooked 627 out of 628 functions
2026-05-28 21:05:18,359 [root] INFO: Loaded monitor into process with pid 4484
2026-05-28 21:05:18,368 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 21:05:18,369 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:18,388 [root] DEBUG: 11260: DLL loaded at 0x00007FFF1C3E0000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei (0xaa000 bytes).
2026-05-28 21:05:18,407 [root] DEBUG: 11260: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2026-05-28 21:05:18,415 [root] DEBUG: 11260: DLL loaded at 0x00007FFEFFD40000: C:\Windows\SYSTEM32\ucrtbase_clr0400 (0xbd000 bytes).
2026-05-28 21:05:18,416 [root] DEBUG: 11260: DLL loaded at 0x00007FFF435D0000: C:\Windows\SYSTEM32\VCRUNTIME140_CLR0400 (0x16000 bytes).
2026-05-28 21:05:18,417 [root] DEBUG: 11260: DLL loaded at 0x00007FFEFFE00000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr (0xb34000 bytes).
2026-05-28 21:05:18,419 [root] DEBUG: 2912: CreateProcessHandler: Injection info set for new process 11768: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:05:18,420 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 11768
2026-05-28 21:05:18,421 [root] DEBUG: 2912: ProcessMessage: Skipping monitoring process 11768
2026-05-28 21:05:18,502 [root] DEBUG: 11260: AllocationHandler: Adding allocation to tracked region list: 0x00007FFEA09D0000, size: 0x1000.
2026-05-28 21:05:18,525 [root] DEBUG: 11260: hook_api: clrjit::compileMethod export address 0x00007FFEFFBF5FF0 obtained via GetFunctionAddress
2026-05-28 21:05:18,527 [root] DEBUG: 11260: DLL loaded at 0x00007FFEFFBF0000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit (0x14f000 bytes).
2026-05-28 21:05:18,542 [root] DEBUG: 11260: .NET JIT native cache at 0x00007FFEA09D0000: scans and dumps active.
2026-05-28 21:05:18,545 [root] DEBUG: 11260: AllocationHandler: Adding allocation to tracked region list: 0x00007DF413CD0000, size: 0xa0000.
2026-05-28 21:05:18,546 [root] DEBUG: 11260: GetEntropy: Error - Supplied address inaccessible: 0x00007DF413CD0000
2026-05-28 21:05:18,547 [root] DEBUG: 11260: AllocationHandler: Processing previous tracked region at: 0x00007FFEA09D0000.
2026-05-28 21:05:18,548 [root] DEBUG: 11260: ProcessTrackedRegion: Entropy for tracked region at 0x00007FFEA09D0000: 5.806183e+00
2026-05-28 21:05:18,550 [root] DEBUG: 11260: DumpPEsInRange: Scanning range 0x00007FFEA09D0000 - 0x00007FFEA09D741D.
2026-05-28 21:05:18,551 [root] DEBUG: 11260: ScanForDisguisedPE: No PE image located in range 0x00007FFEA09D0000-0x00007FFEA09D741D.
2026-05-28 21:05:18,554 [lib.common.results] INFO: Uploading file C:\SnQADZPxRF\CAPE\11260_14323245185129552026 to CAPE\233b38664af7b56a54577c36e6ab454deb635e8a6b147d1b87383b6ba8a1ab22; Size is 29725; Max size: 100000000
2026-05-28 21:05:18,557 [root] DEBUG: 11260: DumpMemory: Payload successfully created: C:\SnQADZPxRF\CAPE\11260_14323245185129552026 (size 29725 bytes)
2026-05-28 21:05:18,557 [root] DEBUG: 11260: DumpRegion: Dumped entire allocation from 0x00007FFEA09D0000, size 32768 bytes.
2026-05-28 21:05:18,558 [root] DEBUG: 11260: ProcessTrackedRegion: Dumped region at 0x00007FFEA09D0000.
2026-05-28 21:05:18,559 [root] DEBUG: 11260: YaraScan: Scanning 0x00007FFEA09D0000, size 0x741d
2026-05-28 21:05:18,560 [root] DEBUG: 11260: AllocationHandler: Memory region (size 0xa0000) reserved but not committed at 0x00007DF413CD0000.
2026-05-28 21:05:18,560 [root] DEBUG: 11260: AllocationHandler: Previously reserved region at 0x00007DF413CD0000, committing at: 0x00007DF413CD0000.
2026-05-28 21:05:18,561 [root] DEBUG: 11260: AllocationHandler: Adding allocation to tracked region list: 0x00007DF413CC0000, size: 0x10000.
2026-05-28 21:05:18,561 [root] DEBUG: 11260: GetEntropy: Error - Supplied address inaccessible: 0x00007DF413CC0000
2026-05-28 21:05:18,562 [root] DEBUG: 11260: AllocationHandler: Processing previous tracked region at: 0x00007DF413CD0000.
2026-05-28 21:05:18,562 [root] DEBUG: 11260: ProcessTrackedRegion: Entropy for tracked region at 0x00007DF413CD0000: 1.759065e-01
2026-05-28 21:05:18,563 [root] DEBUG: 11260: DumpPEsInRange: Scanning range 0x00007DF413CD0000 - 0x00007DF413CD0066.
2026-05-28 21:05:18,564 [root] DEBUG: 11260: ScanForDisguisedPE: Size too small: 0x66 bytes
2026-05-28 21:05:18,574 [lib.common.results] INFO: Uploading file C:\SnQADZPxRF\CAPE\11260_13334548185129552026 to CAPE\9d733ac0b4917a48b31154ee4cec9e5d22deab4c217f17b5d0f5cf0ee34fec95; Size is 102; Max size: 100000000
2026-05-28 21:05:18,589 [root] DEBUG: 11260: DumpMemory: Payload successfully created: C:\SnQADZPxRF\CAPE\11260_13334548185129552026 (size 102 bytes)
2026-05-28 21:05:18,591 [root] DEBUG: 11260: DumpRegion: Dumped entire allocation from 0x00007DF413CD0000, size 4096 bytes.
2026-05-28 21:05:18,592 [root] DEBUG: 11260: ProcessTrackedRegion: Dumped region at 0x00007DF413CD0000.
2026-05-28 21:05:18,592 [root] DEBUG: 11260: YaraScan: Scanning 0x00007DF413CD0000, size 0x66
2026-05-28 21:05:18,595 [root] DEBUG: 11260: AllocationHandler: Memory region (size 0x10000) reserved but not committed at 0x00007DF413CC0000.
2026-05-28 21:05:18,595 [root] DEBUG: 11260: AllocationHandler: Previously reserved region at 0x00007DF413CC0000, committing at: 0x00007DF413CC0000.
2026-05-28 21:05:18,596 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 11916, handle 0x256c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 21:05:18,601 [root] DEBUG: 11260: AllocationHandler: Adding allocation to tracked region list: 0x00007FFEA080D000, size: 0x1000.
2026-05-28 21:05:18,613 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 11768, handle 0x2568: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 21:05:18,659 [root] DEBUG: 11260: AllocationHandler: Adding allocation to tracked region list: 0x000001F5C3CF2000, size: 0x1000.
2026-05-28 21:05:18,663 [root] DEBUG: 11260: AllocationHandler: Allocation already in tracked region list: 0x00007FFEA09D0000.
2026-05-28 21:05:18,731 [root] DEBUG: 11260: AllocationHandler: Allocation already in tracked region list: 0x00007FFEA09D0000.
2026-05-28 21:05:18,764 [root] DEBUG: 11260: AllocationHandler: Allocation already in tracked region list: 0x00007FFEA09D0000.
2026-05-28 21:05:18,778 [root] DEBUG: 11260: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 21:05:18,811 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 21:05:18,870 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:05:18,871 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6136, handle 0x2570: Error obtaining target process name
2026-05-28 21:05:18,872 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:05:18,873 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5624, handle 0x2564: Error obtaining target process name
2026-05-28 21:05:18,874 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:05:18,875 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6400, handle 0x2560: Error obtaining target process name
2026-05-28 21:05:18,875 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:05:18,876 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5128, handle 0x255c: Error obtaining target process name
2026-05-28 21:05:18,915 [root] DEBUG: 11260: AllocationHandler: Adding allocation to tracked region list: 0x00007FFEA08E6000, size: 0x1000.
2026-05-28 21:05:18,955 [root] DEBUG: 11260: NtTerminateProcess hook: Attempting to dump process 11260
2026-05-28 21:05:18,956 [root] DEBUG: 11260: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:05:18,959 [root] DEBUG: 11260: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFEA09D0000 (jit-dumps=0)
2026-05-28 21:05:18,964 [root] DEBUG: 11260: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFEA08B0000: 4.153035e-01 (from 4.139015e-01)
2026-05-28 21:05:18,965 [root] DEBUG: 11260: DumpPEsInRange: Scanning range 0x00007FFEA08B0000 - 0x00007FFEA08B0116.
2026-05-28 21:05:18,966 [root] DEBUG: 11260: ScanForDisguisedPE: Size too small: 0x116 bytes
2026-05-28 21:05:18,968 [lib.common.results] INFO: Uploading file C:\SnQADZPxRF\CAPE\11260_39442185129552026 to CAPE\0cb520fbce075cd66beb3dfad3f410d9feed059a22b68b8769e17c87e1b27711; Size is 278; Max size: 100000000
2026-05-28 21:05:18,971 [root] DEBUG: 11260: DumpMemory: Payload successfully created: C:\SnQADZPxRF\CAPE\11260_39442185129552026 (size 278 bytes)
2026-05-28 21:05:18,971 [root] DEBUG: 11260: DumpRegion: Dumped entire allocation from 0x00007FFEA08B0000, size 4096 bytes.
2026-05-28 21:05:18,972 [root] DEBUG: 11260: ProcessTrackedRegion: Dumped region at 0x00007FFEA08B0000.
2026-05-28 21:05:18,973 [root] DEBUG: 11260: YaraScan: Scanning 0x00007FFEA08B0000, size 0x116
2026-05-28 21:05:18,977 [root] DEBUG: 11260: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 21:05:18,982 [root] INFO: Process with pid 11260 has terminated
2026-05-28 21:05:18,987 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 5128 (handle 0x252c): 0x00007FF6FFE40000.
2026-05-28 21:05:19,299 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 11652, handle 0x2544: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 21:05:19,306 [root] INFO: Process with pid 2912 appears to have terminated
2026-05-28 21:05:19,824 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 11628: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe, ImageBase: 0x00007FF7C5F80000
2026-05-28 21:05:19,826 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 11628
2026-05-28 21:05:19,827 [lib.api.process] INFO: Monitor config for process 11628: C:\rl4cuydm\dll\11628.ini
2026-05-28 21:05:19,829 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:20,395 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:05:20,396 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:05:20,396 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:05:20,396 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:05:20,397 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:05:20,397 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:05:20,397 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:05:20,397 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:05:20,406 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:20,411 [root] DEBUG: Loader: Injecting process 11628 (thread 9840) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:20,412 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:20,412 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:20,414 [lib.api.process] INFO: Injected into 64-bit <Process 11628 elevation_service.exe>
2026-05-28 21:05:20,416 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 11628
2026-05-28 21:05:20,416 [lib.api.process] INFO: Monitor config for process 11628: C:\rl4cuydm\dll\11628.ini
2026-05-28 21:05:20,418 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:20,956 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:05:20,957 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:05:20,957 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:05:20,958 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:05:20,958 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:05:20,958 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:05:20,958 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:05:20,959 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:05:20,968 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:20,973 [root] DEBUG: Loader: Injecting process 11628 (thread 9840) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:20,975 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:20,975 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:20,977 [lib.api.process] INFO: Injected into 64-bit <Process 11628 elevation_service.exe>
2026-05-28 21:05:20,978 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 11628
2026-05-28 21:05:20,978 [lib.api.process] INFO: Monitor config for process 11628: C:\rl4cuydm\dll\11628.ini
2026-05-28 21:05:20,979 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,552 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:05:21,552 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:05:21,553 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:05:21,554 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:05:21,554 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:05:21,555 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:05:21,556 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:05:21,556 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:05:21,566 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,570 [root] DEBUG: Loader: Injecting process 11628 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,571 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9840, handle 0x120
2026-05-28 21:05:21,572 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:21,573 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,575 [lib.api.process] INFO: Injected into 64-bit <Process 11628 elevation_service.exe>
2026-05-28 21:05:21,582 [root] DEBUG: 11628: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:21,582 [root] DEBUG: 11628: Interactive desktop enabled.
2026-05-28 21:05:21,583 [root] DEBUG: 11628: Dropped file limit defaulting to 100.
2026-05-28 21:05:21,587 [root] DEBUG: 11628: Disabling sleep skipping.
2026-05-28 21:05:21,588 [root] DEBUG: 11628: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:05:21,602 [root] DEBUG: 11628: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:21,602 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,625 [root] DEBUG: 11628: Monitor initialised: 64-bit capemon loaded in process 11628 at 0x00007FFF1A4F0000, thread 9840, image base 0x00007FF7C5F80000, stack from 0x000000BFD1BA4000-0x000000BFD1BB0000
2026-05-28 21:05:21,626 [root] DEBUG: 11628: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe"
2026-05-28 21:05:21,641 [root] DEBUG: 11628: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:05:21,666 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:05:21,668 [root] DEBUG: 11628: set_hooks: Unable to hook LockResource
2026-05-28 21:05:21,676 [root] DEBUG: 11628: Hooked 627 out of 628 functions
2026-05-28 21:05:21,692 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 6136 (handle 0x2438): 0x00007FF662BA0000.
2026-05-28 21:05:21,700 [root] DEBUG: 11628: Syscall hook installed, syscall logging level 1
2026-05-28 21:05:21,705 [root] DEBUG: 11628: RestoreHeaders: Restored original import table.
2026-05-28 21:05:21,707 [root] INFO: Loaded monitor into process with pid 11628
2026-05-28 21:05:21,708 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,733 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,767 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,771 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9916: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe, ImageBase: 0x00007FF73E3F0000
2026-05-28 21:05:21,773 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 9916
2026-05-28 21:05:21,773 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9980: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:21,773 [lib.api.process] INFO: Monitor config for process 9916: C:\rl4cuydm\dll\9916.ini
2026-05-28 21:05:21,774 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9980
2026-05-28 21:05:21,775 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,775 [lib.api.process] INFO: Monitor config for process 9980: C:\rl4cuydm\dll\9980.ini
2026-05-28 21:05:21,778 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,780 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,785 [root] DEBUG: Loader: Injecting process 9980 (thread 9924) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,786 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:21,786 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,788 [lib.api.process] INFO: Injected into 64-bit <Process 9980 dllhost.exe>
2026-05-28 21:05:21,788 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,789 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9980
2026-05-28 21:05:21,790 [lib.api.process] INFO: Monitor config for process 9980: C:\rl4cuydm\dll\9980.ini
2026-05-28 21:05:21,790 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,798 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,803 [root] DEBUG: Loader: Injecting process 9980 (thread 9924) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,804 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:21,805 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,808 [lib.api.process] INFO: Injected into 64-bit <Process 9980 dllhost.exe>
2026-05-28 21:05:21,813 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9952: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:21,815 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9952
2026-05-28 21:05:21,815 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,815 [lib.api.process] INFO: Monitor config for process 9952: C:\rl4cuydm\dll\9952.ini
2026-05-28 21:05:21,817 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,819 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,825 [root] DEBUG: Loader: Injecting process 9952 (thread 9964) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,826 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:21,827 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,829 [lib.api.process] INFO: Injected into 64-bit <Process 9952 dllhost.exe>
2026-05-28 21:05:21,830 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9952
2026-05-28 21:05:21,830 [lib.api.process] INFO: Monitor config for process 9952: C:\rl4cuydm\dll\9952.ini
2026-05-28 21:05:21,831 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,835 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,837 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,845 [root] DEBUG: Loader: Injecting process 9952 (thread 9964) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,846 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:21,847 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,849 [lib.api.process] INFO: Injected into 64-bit <Process 9952 dllhost.exe>
2026-05-28 21:05:21,854 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10168: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:21,855 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10168
2026-05-28 21:05:21,855 [lib.api.process] INFO: Monitor config for process 10168: C:\rl4cuydm\dll\10168.ini
2026-05-28 21:05:21,858 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,862 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,863 [root] DEBUG: 11628: caller_dispatch: Scanning calling region at 0x00007FF7C5F80000...
2026-05-28 21:05:21,864 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,865 [root] DEBUG: 11628: caller_dispatch: Added region at 0x00007FF7C5F80000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7C60BB9D6, thread 9840).
2026-05-28 21:05:21,866 [root] DEBUG: 11628: YaraScan: Scanning 0x00007FF7C5F80000, size 0x3bf4c0
2026-05-28 21:05:21,867 [root] DEBUG: Loader: Injecting process 10168 (thread 12264) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,868 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:21,869 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,872 [lib.api.process] INFO: Injected into 64-bit <Process 10168 dllhost.exe>
2026-05-28 21:05:21,876 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10168
2026-05-28 21:05:21,877 [lib.api.process] INFO: Monitor config for process 10168: C:\rl4cuydm\dll\10168.ini
2026-05-28 21:05:21,877 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,880 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,886 [root] DEBUG: Loader: Injecting process 10168 (thread 12264) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,886 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:21,887 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,890 [root] DEBUG: 11628: ProcessImageBase: Main module image at 0x00007FF7C5F80000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:21,892 [root] DEBUG: 11628: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:05:21,892 [lib.api.process] INFO: Injected into 64-bit <Process 10168 dllhost.exe>
2026-05-28 21:05:21,892 [root] DEBUG: 11628: ProcessImageBase: Main module image at 0x00007FF7C5F80000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:21,896 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11660: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:21,898 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11660
2026-05-28 21:05:21,899 [root] DEBUG: 11628: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:05:21,900 [lib.api.process] INFO: Monitor config for process 11660: C:\rl4cuydm\dll\11660.ini
2026-05-28 21:05:21,901 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,906 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,908 [root] DEBUG: 11628: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:05:21,913 [root] DEBUG: Loader: Injecting process 11660 (thread 9652) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,914 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:21,915 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,917 [lib.api.process] INFO: Injected into 64-bit <Process 11660 dllhost.exe>
2026-05-28 21:05:21,919 [root] DEBUG: 11628: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:05:21,920 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11660
2026-05-28 21:05:21,921 [lib.api.process] INFO: Monitor config for process 11660: C:\rl4cuydm\dll\11660.ini
2026-05-28 21:05:21,921 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:21,925 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:21,930 [root] DEBUG: Loader: Injecting process 11660 (thread 9652) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,932 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:21,934 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:21,936 [lib.api.process] INFO: Injected into 64-bit <Process 11660 dllhost.exe>
2026-05-28 21:05:21,937 [root] DEBUG: 11628: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:05:21,982 [root] DEBUG: 11628: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:05:21,988 [root] DEBUG: 11628: NtTerminateProcess hook: Attempting to dump process 11628
2026-05-28 21:05:21,990 [root] DEBUG: 11628: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:05:21,999 [root] DEBUG: 11628: caller_dispatch: Added region at 0x00007FFF56FD0000 to tracked regions list (ntdll::NtClose returns to 0x00007FFF56FD419B, thread 9840).
2026-05-28 21:05:22,000 [root] DEBUG: 11628: caller_dispatch: Scanning calling region at 0x00007FFF56FD0000...
2026-05-28 21:05:22,006 [root] INFO: Process with pid 11628 has terminated
2026-05-28 21:05:22,382 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10384: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:22,383 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10384
2026-05-28 21:05:22,384 [lib.api.process] INFO: Monitor config for process 10384: C:\rl4cuydm\dll\10384.ini
2026-05-28 21:05:22,386 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,388 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,407 [root] DEBUG: Loader: Injecting process 10384 (thread 9812) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,408 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,410 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,411 [lib.api.process] INFO: Injected into 64-bit <Process 10384 dllhost.exe>
2026-05-28 21:05:22,413 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10384
2026-05-28 21:05:22,413 [lib.api.process] INFO: Monitor config for process 10384: C:\rl4cuydm\dll\10384.ini
2026-05-28 21:05:22,414 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,417 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,424 [root] DEBUG: Loader: Injecting process 10384 (thread 9812) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,425 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,427 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,429 [lib.api.process] INFO: Injected into 64-bit <Process 10384 dllhost.exe>
2026-05-28 21:05:22,436 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11016: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:22,439 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11016
2026-05-28 21:05:22,439 [lib.api.process] INFO: Monitor config for process 11016: C:\rl4cuydm\dll\11016.ini
2026-05-28 21:05:22,441 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,445 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,447 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,450 [root] DEBUG: Loader: Injecting process 11016 (thread 11004) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,451 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,452 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,454 [lib.api.process] INFO: Injected into 64-bit <Process 11016 dllhost.exe>
2026-05-28 21:05:22,455 [root] DEBUG: Loader: Injecting process 9916 (thread 9920) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,456 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,458 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11016
2026-05-28 21:05:22,459 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,459 [lib.api.process] INFO: Monitor config for process 11016: C:\rl4cuydm\dll\11016.ini
2026-05-28 21:05:22,460 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,460 [lib.api.process] INFO: Injected into 64-bit <Process 9916 TextInputHost.exe>
2026-05-28 21:05:22,463 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 9916
2026-05-28 21:05:22,465 [lib.api.process] INFO: Monitor config for process 9916: C:\rl4cuydm\dll\9916.ini
2026-05-28 21:05:22,465 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,466 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,471 [root] DEBUG: Loader: Injecting process 11016 (thread 11004) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,472 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,473 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,474 [lib.api.process] INFO: Injected into 64-bit <Process 11016 dllhost.exe>
2026-05-28 21:05:22,479 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 964: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:22,483 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 964
2026-05-28 21:05:22,483 [lib.api.process] INFO: Monitor config for process 964: C:\rl4cuydm\dll\964.ini
2026-05-28 21:05:22,485 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,488 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,493 [root] DEBUG: Loader: Injecting process 964 (thread 9840) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,496 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,496 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,498 [lib.api.process] INFO: Injected into 64-bit <Process 964 dllhost.exe>
2026-05-28 21:05:22,501 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 964
2026-05-28 21:05:22,502 [lib.api.process] INFO: Monitor config for process 964: C:\rl4cuydm\dll\964.ini
2026-05-28 21:05:22,502 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,505 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,511 [root] DEBUG: Loader: Injecting process 964 (thread 9840) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,513 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,513 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,515 [lib.api.process] INFO: Injected into 64-bit <Process 964 dllhost.exe>
2026-05-28 21:05:22,521 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9376: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:22,527 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9376
2026-05-28 21:05:22,529 [lib.api.process] INFO: Monitor config for process 9376: C:\rl4cuydm\dll\9376.ini
2026-05-28 21:05:22,532 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,534 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,539 [root] DEBUG: Loader: Injecting process 9376 (thread 5672) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,539 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,540 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,545 [lib.api.process] INFO: Injected into 64-bit <Process 9376 dllhost.exe>
2026-05-28 21:05:22,547 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9376
2026-05-28 21:05:22,548 [lib.api.process] INFO: Monitor config for process 9376: C:\rl4cuydm\dll\9376.ini
2026-05-28 21:05:22,548 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,552 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,558 [root] DEBUG: Loader: Injecting process 9376 (thread 5672) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,559 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,560 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,563 [lib.api.process] INFO: Injected into 64-bit <Process 9376 dllhost.exe>
2026-05-28 21:05:22,667 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 5112: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:22,669 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5112
2026-05-28 21:05:22,670 [lib.api.process] INFO: Monitor config for process 5112: C:\rl4cuydm\dll\5112.ini
2026-05-28 21:05:22,671 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,675 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,681 [root] DEBUG: Loader: Injecting process 5112 (thread 10920) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,682 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,683 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,686 [lib.api.process] INFO: Injected into 64-bit <Process 5112 dllhost.exe>
2026-05-28 21:05:22,687 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5112
2026-05-28 21:05:22,688 [lib.api.process] INFO: Monitor config for process 5112: C:\rl4cuydm\dll\5112.ini
2026-05-28 21:05:22,689 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,693 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,697 [root] DEBUG: Loader: Injecting process 5112 (thread 10920) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,698 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,699 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,700 [lib.api.process] INFO: Injected into 64-bit <Process 5112 dllhost.exe>
2026-05-28 21:05:22,704 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12304: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:22,705 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12304
2026-05-28 21:05:22,706 [lib.api.process] INFO: Monitor config for process 12304: C:\rl4cuydm\dll\12304.ini
2026-05-28 21:05:22,714 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,718 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,724 [root] DEBUG: Loader: Injecting process 12304 (thread 12308) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,724 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,725 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,726 [lib.api.process] INFO: Injected into 64-bit <Process 12304 dllhost.exe>
2026-05-28 21:05:22,727 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12304
2026-05-28 21:05:22,728 [lib.api.process] INFO: Monitor config for process 12304: C:\rl4cuydm\dll\12304.ini
2026-05-28 21:05:22,729 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,732 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,737 [root] DEBUG: Loader: Injecting process 12304 (thread 12308) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,737 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,740 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,742 [lib.api.process] INFO: Injected into 64-bit <Process 12304 dllhost.exe>
2026-05-28 21:05:22,789 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12396: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:22,791 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12396
2026-05-28 21:05:22,792 [lib.api.process] INFO: Monitor config for process 12396: C:\rl4cuydm\dll\12396.ini
2026-05-28 21:05:22,793 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,797 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,803 [root] DEBUG: Loader: Injecting process 12396 (thread 12400) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,804 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,805 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,808 [lib.api.process] INFO: Injected into 64-bit <Process 12396 dllhost.exe>
2026-05-28 21:05:22,810 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12396
2026-05-28 21:05:22,811 [lib.api.process] INFO: Monitor config for process 12396: C:\rl4cuydm\dll\12396.ini
2026-05-28 21:05:22,811 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,815 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,820 [root] DEBUG: Loader: Injecting process 12396 (thread 12400) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,820 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,821 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,823 [lib.api.process] INFO: Injected into 64-bit <Process 12396 dllhost.exe>
2026-05-28 21:05:22,826 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12488: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:22,827 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12488
2026-05-28 21:05:22,828 [lib.api.process] INFO: Monitor config for process 12488: C:\rl4cuydm\dll\12488.ini
2026-05-28 21:05:22,830 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,833 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,837 [root] DEBUG: Loader: Injecting process 12488 (thread 12492) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,838 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,839 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,841 [lib.api.process] INFO: Injected into 64-bit <Process 12488 dllhost.exe>
2026-05-28 21:05:22,842 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12488
2026-05-28 21:05:22,842 [lib.api.process] INFO: Monitor config for process 12488: C:\rl4cuydm\dll\12488.ini
2026-05-28 21:05:22,843 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:22,847 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:22,852 [root] DEBUG: Loader: Injecting process 12488 (thread 12492) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,853 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:22,854 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:22,856 [lib.api.process] INFO: Injected into 64-bit <Process 12488 dllhost.exe>
2026-05-28 21:05:23,054 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:23,060 [root] DEBUG: Loader: Injecting process 9916 (thread 9920) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:23,061 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:23,061 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:23,063 [lib.api.process] INFO: Injected into 64-bit <Process 9916 TextInputHost.exe>
2026-05-28 21:05:23,064 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 9916
2026-05-28 21:05:23,065 [lib.api.process] INFO: Monitor config for process 9916: C:\rl4cuydm\dll\9916.ini
2026-05-28 21:05:23,066 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:23,729 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:23,733 [root] DEBUG: Loader: Injecting process 9916 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:23,734 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9920, handle 0x120
2026-05-28 21:05:23,735 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:23,735 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:23,737 [lib.api.process] INFO: Injected into 64-bit <Process 9916 TextInputHost.exe>
2026-05-28 21:05:24,138 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12668: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:24,141 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12668
2026-05-28 21:05:24,142 [lib.api.process] INFO: Monitor config for process 12668: C:\rl4cuydm\dll\12668.ini
2026-05-28 21:05:24,147 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,151 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,162 [root] DEBUG: Loader: Injecting process 12668 (thread 12672) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,169 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:24,171 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,180 [lib.api.process] INFO: Injected into 64-bit <Process 12668 dllhost.exe>
2026-05-28 21:05:24,181 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12668
2026-05-28 21:05:24,182 [lib.api.process] INFO: Monitor config for process 12668: C:\rl4cuydm\dll\12668.ini
2026-05-28 21:05:24,184 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,188 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,194 [root] DEBUG: Loader: Injecting process 12668 (thread 12672) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,195 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:24,196 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,198 [lib.api.process] INFO: Injected into 64-bit <Process 12668 dllhost.exe>
2026-05-28 21:05:24,203 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12756: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:24,204 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12756
2026-05-28 21:05:24,205 [lib.api.process] INFO: Monitor config for process 12756: C:\rl4cuydm\dll\12756.ini
2026-05-28 21:05:24,206 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,208 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,213 [root] DEBUG: Loader: Injecting process 12756 (thread 12760) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,214 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:24,216 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,218 [lib.api.process] INFO: Injected into 64-bit <Process 12756 dllhost.exe>
2026-05-28 21:05:24,220 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12756
2026-05-28 21:05:24,220 [lib.api.process] INFO: Monitor config for process 12756: C:\rl4cuydm\dll\12756.ini
2026-05-28 21:05:24,221 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,229 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,259 [root] DEBUG: Loader: Injecting process 12756 (thread 12760) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,264 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:24,267 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,274 [lib.api.process] INFO: Injected into 64-bit <Process 12756 dllhost.exe>
2026-05-28 21:05:24,409 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12928: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF644350000
2026-05-28 21:05:24,414 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 12860, handle 0x1aa8: C:\Windows\System32\conhost.exe
2026-05-28 21:05:24,418 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12928
2026-05-28 21:05:24,418 [lib.api.process] INFO: Monitor config for process 12928: C:\rl4cuydm\dll\12928.ini
2026-05-28 21:05:24,420 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 12844, handle 0x1aa8: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
2026-05-28 21:05:24,423 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12960: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF644350000
2026-05-28 21:05:24,423 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,424 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 12860 (handle 0x2290): 0x00007FF7BF860000.
2026-05-28 21:05:24,425 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 13004: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF644350000
2026-05-28 21:05:24,426 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12960
2026-05-28 21:05:24,428 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13004
2026-05-28 21:05:24,428 [lib.api.process] INFO: Monitor config for process 13004: C:\rl4cuydm\dll\13004.ini
2026-05-28 21:05:24,429 [lib.api.process] INFO: Monitor config for process 12960: C:\rl4cuydm\dll\12960.ini
2026-05-28 21:05:24,430 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,431 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,441 [root] DEBUG: Loader: Injecting process 12928 (thread 12932) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,443 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:24,445 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,446 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,450 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,481 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,490 [root] DEBUG: Loader: Injecting process 13004 (thread 13008) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,494 [root] DEBUG: Loader: Injecting process 12960 (thread 12964) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,494 [lib.api.process] INFO: Injected into 64-bit <Process 12928 backgroundTaskHost.exe>
2026-05-28 21:05:24,495 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:24,496 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:24,497 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12928
2026-05-28 21:05:24,498 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,498 [lib.api.process] INFO: Monitor config for process 12928: C:\rl4cuydm\dll\12928.ini
2026-05-28 21:05:24,500 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,500 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,501 [lib.api.process] INFO: Injected into 64-bit <Process 13004 backgroundTaskHost.exe>
2026-05-28 21:05:24,504 [lib.api.process] INFO: Injected into 64-bit <Process 12960 backgroundTaskHost.exe>
2026-05-28 21:05:24,504 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13004
2026-05-28 21:05:24,505 [lib.api.process] INFO: Monitor config for process 13004: C:\rl4cuydm\dll\13004.ini
2026-05-28 21:05:24,506 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,509 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12960
2026-05-28 21:05:24,509 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,511 [lib.api.process] INFO: Monitor config for process 12960: C:\rl4cuydm\dll\12960.ini
2026-05-28 21:05:24,511 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,514 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,516 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,516 [root] DEBUG: Loader: Injecting process 12928 (thread 12932) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,518 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:24,519 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,520 [root] DEBUG: Loader: Injecting process 13004 (thread 13008) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,521 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:24,522 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,522 [lib.api.process] INFO: Injected into 64-bit <Process 12928 backgroundTaskHost.exe>
2026-05-28 21:05:24,524 [root] DEBUG: Loader: Injecting process 12960 (thread 12964) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,529 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:24,530 [lib.api.process] INFO: Injected into 64-bit <Process 13004 backgroundTaskHost.exe>
2026-05-28 21:05:24,531 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12928
2026-05-28 21:05:24,532 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,532 [lib.api.process] INFO: Monitor config for process 12928: C:\rl4cuydm\dll\12928.ini
2026-05-28 21:05:24,533 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 13004
2026-05-28 21:05:24,534 [lib.api.process] INFO: Monitor config for process 13004: C:\rl4cuydm\dll\13004.ini
2026-05-28 21:05:24,534 [lib.api.process] INFO: Injected into 64-bit <Process 12960 backgroundTaskHost.exe>
2026-05-28 21:05:24,535 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,535 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,537 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,539 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 12960
2026-05-28 21:05:24,540 [lib.api.process] INFO: Monitor config for process 12960: C:\rl4cuydm\dll\12960.ini
2026-05-28 21:05:24,541 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:24,542 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,548 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:24,555 [root] DEBUG: Loader: Injecting process 12928 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,560 [root] DEBUG: Loader: Injecting process 13004 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,562 [root] DEBUG: Loader: Injecting process 12960 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,564 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12932, handle 0x124
2026-05-28 21:05:24,565 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 13008, handle 0x12c
2026-05-28 21:05:24,565 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12964, handle 0x120
2026-05-28 21:05:24,577 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:24,579 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:24,580 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:05:24,580 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,581 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,582 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:24,584 [lib.api.process] INFO: Injected into 64-bit <Process 13004 backgroundTaskHost.exe>
2026-05-28 21:05:24,584 [lib.api.process] INFO: Injected into 64-bit <Process 12960 backgroundTaskHost.exe>
2026-05-28 21:05:24,586 [lib.api.process] INFO: Injected into 64-bit <Process 12928 backgroundTaskHost.exe>
2026-05-28 21:05:24,808 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 21:05:36,105 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 21:05:45,714 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
2026-05-28 21:05:51,880 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 21:05:51,902 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
2026-05-28 21:05:51,906 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Discord\app.ico
2026-05-28 21:05:51,941 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9212: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:05:51,944 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9212
2026-05-28 21:05:51,944 [lib.api.process] INFO: Monitor config for process 9212: C:\rl4cuydm\dll\9212.ini
2026-05-28 21:05:51,946 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:51,947 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:51,971 [root] DEBUG: Loader: Injecting process 9212 (thread 8308) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:51,972 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:51,973 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:51,976 [lib.api.process] INFO: Injected into 64-bit <Process 9212 dllhost.exe>
2026-05-28 21:05:51,977 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9212
2026-05-28 21:05:51,978 [lib.api.process] INFO: Monitor config for process 9212: C:\rl4cuydm\dll\9212.ini
2026-05-28 21:05:51,979 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:05:51,982 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:05:51,988 [root] DEBUG: Loader: Injecting process 9212 (thread 8308) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:51,992 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:05:51,996 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:05:52,001 [lib.api.process] INFO: Injected into 64-bit <Process 9212 dllhost.exe>
2026-05-28 21:05:52,017 [root] DEBUG: 9212: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:05:52,020 [root] DEBUG: 9212: Interactive desktop enabled.
2026-05-28 21:05:52,023 [root] DEBUG: 9212: Dropped file limit defaulting to 100.
2026-05-28 21:05:52,032 [root] DEBUG: 9212: Disabling sleep skipping.
2026-05-28 21:05:52,033 [root] DEBUG: 9212: YaraInit: Compiled rules loaded from existing file C:\rl4cuydm\data\yara\capemon.yac
2026-05-28 21:05:52,062 [root] DEBUG: 9212: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:05:52,064 [root] DEBUG: 9212: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:05:52,065 [root] DEBUG: 9212: Monitor initialised: 64-bit capemon loaded in process 9212 at 0x00007FFF1A4F0000, thread 8308, image base 0x00007FF6706B0000, stack from 0x00000065022F4000-0x0000006502300000
2026-05-28 21:05:52,068 [root] DEBUG: 9212: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 21:05:52,078 [root] DEBUG: 9212: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:05:52,101 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:05:52,102 [root] DEBUG: 9212: set_hooks: Unable to hook LockResource
2026-05-28 21:05:52,106 [root] DEBUG: 9212: Hooked 627 out of 628 functions
2026-05-28 21:05:52,108 [root] DEBUG: 9212: Syscall hook installed, syscall logging level 1
2026-05-28 21:05:52,114 [root] DEBUG: 9212: RestoreHeaders: Restored original import table.
2026-05-28 21:05:52,115 [root] INFO: Loaded monitor into process with pid 9212
2026-05-28 21:05:52,117 [root] DEBUG: 9212: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 8308).
2026-05-28 21:05:52,117 [root] DEBUG: 9212: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:05:52,119 [root] DEBUG: 9212: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:05:52,122 [root] DEBUG: 9212: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:05:52,123 [root] DEBUG: 9212: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:05:52,126 [root] DEBUG: 9212: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:05:52,139 [root] DEBUG: 9212: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:05:52,152 [root] DEBUG: 9212: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:05:52,153 [root] DEBUG: 9212: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 21:05:52,159 [root] DEBUG: 9212: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 21:05:54,497 [root] DEBUG: 4484: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 21:05:54,497 [root] DEBUG: 4484: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 21:05:57,339 [root] INFO: Process with pid 9212 has terminated
2026-05-28 21:05:57,340 [root] DEBUG: 9212: NtTerminateProcess hook: Attempting to dump process 9212
2026-05-28 21:05:57,341 [root] DEBUG: 9212: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:06:12,599 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 4040: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:06:12,601 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4040
2026-05-28 21:06:12,602 [lib.api.process] INFO: Monitor config for process 4040: C:\rl4cuydm\dll\4040.ini
2026-05-28 21:06:12,603 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 1112: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe, ImageBase: 0x00007FF73E3F0000
2026-05-28 21:06:12,606 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 1112
2026-05-28 21:06:12,606 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,607 [lib.api.process] INFO: Monitor config for process 1112: C:\rl4cuydm\dll\1112.ini
2026-05-28 21:06:12,609 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,613 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:12,618 [root] DEBUG: Loader: Injecting process 4040 (thread 4048) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,621 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:12,622 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,624 [lib.api.process] INFO: Injected into 64-bit <Process 4040 dllhost.exe>
2026-05-28 21:06:12,625 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4040
2026-05-28 21:06:12,626 [lib.api.process] INFO: Monitor config for process 4040: C:\rl4cuydm\dll\4040.ini
2026-05-28 21:06:12,627 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,630 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:12,636 [root] DEBUG: Loader: Injecting process 4040 (thread 4048) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,637 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:12,638 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,639 [lib.api.process] INFO: Injected into 64-bit <Process 4040 dllhost.exe>
2026-05-28 21:06:12,643 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 7004: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:06:12,644 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7004
2026-05-28 21:06:12,645 [lib.api.process] INFO: Monitor config for process 7004: C:\rl4cuydm\dll\7004.ini
2026-05-28 21:06:12,647 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,650 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:12,655 [root] DEBUG: Loader: Injecting process 7004 (thread 7012) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,657 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:12,658 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,660 [lib.api.process] INFO: Injected into 64-bit <Process 7004 dllhost.exe>
2026-05-28 21:06:12,662 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7004
2026-05-28 21:06:12,663 [lib.api.process] INFO: Monitor config for process 7004: C:\rl4cuydm\dll\7004.ini
2026-05-28 21:06:12,663 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,667 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:12,673 [root] DEBUG: Loader: Injecting process 7004 (thread 7012) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,673 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:12,674 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,676 [lib.api.process] INFO: Injected into 64-bit <Process 7004 dllhost.exe>
2026-05-28 21:06:12,679 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8460: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:06:12,684 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8460
2026-05-28 21:06:12,685 [lib.api.process] INFO: Monitor config for process 8460: C:\rl4cuydm\dll\8460.ini
2026-05-28 21:06:12,686 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,692 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:12,698 [root] DEBUG: Loader: Injecting process 8460 (thread 1084) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,698 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:12,699 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,701 [lib.api.process] INFO: Injected into 64-bit <Process 8460 dllhost.exe>
2026-05-28 21:06:12,703 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8460
2026-05-28 21:06:12,704 [lib.api.process] INFO: Monitor config for process 8460: C:\rl4cuydm\dll\8460.ini
2026-05-28 21:06:12,704 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,710 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:12,715 [root] DEBUG: Loader: Injecting process 8460 (thread 1084) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,717 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:12,718 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,721 [lib.api.process] INFO: Injected into 64-bit <Process 8460 dllhost.exe>
2026-05-28 21:06:12,730 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 6404: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:06:12,733 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6404
2026-05-28 21:06:12,735 [lib.api.process] INFO: Monitor config for process 6404: C:\rl4cuydm\dll\6404.ini
2026-05-28 21:06:12,737 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,740 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:12,747 [root] DEBUG: Loader: Injecting process 6404 (thread 6376) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,748 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:12,749 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,751 [lib.api.process] INFO: Injected into 64-bit <Process 6404 dllhost.exe>
2026-05-28 21:06:12,752 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6404
2026-05-28 21:06:12,753 [lib.api.process] INFO: Monitor config for process 6404: C:\rl4cuydm\dll\6404.ini
2026-05-28 21:06:12,757 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:12,762 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:12,767 [root] DEBUG: Loader: Injecting process 6404 (thread 6376) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,768 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:12,768 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:12,770 [lib.api.process] INFO: Injected into 64-bit <Process 6404 dllhost.exe>
2026-05-28 21:06:13,650 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:13,655 [root] DEBUG: Loader: Injecting process 1112 (thread 9768) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:13,656 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:13,657 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:13,658 [lib.api.process] INFO: Injected into 64-bit <Process 1112 TextInputHost.exe>
2026-05-28 21:06:13,660 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 1112
2026-05-28 21:06:13,661 [lib.api.process] INFO: Monitor config for process 1112: C:\rl4cuydm\dll\1112.ini
2026-05-28 21:06:13,662 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:13,866 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 5624 (handle 0x25d8): 0x00007FF659080000.
2026-05-28 21:06:14,540 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:14,545 [root] DEBUG: Loader: Injecting process 1112 (thread 9768) with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:14,546 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:06:14,547 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:14,550 [lib.api.process] INFO: Injected into 64-bit <Process 1112 TextInputHost.exe>
2026-05-28 21:06:14,551 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 1112
2026-05-28 21:06:14,553 [lib.api.process] INFO: Monitor config for process 1112: C:\rl4cuydm\dll\1112.ini
2026-05-28 21:06:14,553 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:06:15,432 [lib.api.process] INFO: 64-bit DLL to inject is C:\rl4cuydm\dll\ELAodRE.dll, loader C:\rl4cuydm\bin\jaEGukfU.exe
2026-05-28 21:06:15,436 [root] DEBUG: Loader: Injecting process 1112 with C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:15,437 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9768, handle 0x128
2026-05-28 21:06:15,438 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:06:15,439 [root] DEBUG: Successfully injected DLL C:\rl4cuydm\dll\ELAodRE.dll.
2026-05-28 21:06:15,441 [lib.api.process] INFO: Injected into 64-bit <Process 1112 TextInputHost.exe>
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 21:04:54 | 2026-05-28 21:06:27 | none |
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 13.107.246.31 [VT] | unknown | - |
| Y | 20.227.97.55 [VT] | unknown | - |
| Y | 150.171.109.25 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| N | 162.159.128.235 [VT] | unknown | - |
| Y | 204.79.197.203 [VT] | unknown | - |
| Y | 150.171.28.12 [VT] | unknown | - |
| Y | 149.135.84.11 [VT] | unknown | - |
| Y | 18.155.216.83 [VT] | unknown | - |
| Y | 104.18.33.89 [VT] | unknown | - |
| Y | 23.219.86.120 [VT] | unknown | - |
| Y | 150.171.109.17 [VT] | unknown | - |
| Y | 150.171.27.10 [VT] | unknown | - |
| Y | 23.219.86.114 [VT] | unknown | - |
| Y | 149.135.84.160 [VT] | unknown | - |
| Y | 172.64.154.167 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| N | 162.159.134.233 [VT] | unknown | - |
| N | 162.159.128.233 [VT] | unknown | - |
| N | 23.209.183.106 [VT] | unknown | - |
| Y | 172.172.255.218 [VT] | unknown | - |
| N | 103.28.54.101 [VT] | unknown | - |
| N | 162.254.195.69 [VT] | unknown | - |
| N | 162.254.195.75 [VT] | unknown | - |
| N | 103.10.125.22 [VT] | unknown | - |
| N | 103.10.125.23 [VT] | unknown | - |
| N | 162.159.135.232 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 20.190.167.19 [VT] | unknown | - |
| N | 162.159.133.233 [VT] | unknown | - |
| Y | 162.159.135.234 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.8.8 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| status.discord.com [VT] |
A 162.159.128.233
[VT]
A 162.159.138.232 [VT] A 162.159.137.232 [VT] A 162.159.135.232 [VT] A 162.159.136.232 [VT] |
162.159.135.232 [VT] |
| cmp1-syd1.steamserver.net [VT] | A 103.10.125.22 [VT] | 103.10.125.22 [VT] |
| cmp2-syd1.steamserver.net [VT] | A 103.10.125.23 [VT] | 103.10.125.23 [VT] |
| cmp2-lax1.steamserver.net [VT] | A 162.254.195.75 [VT] | 162.254.195.75 [VT] |
| cmp1-lax1.steamserver.net [VT] | A 162.254.195.69 [VT] | 162.254.195.69 [VT] |
| cmp2-hkg1.steamserver.net [VT] | A 103.28.54.101 [VT] | 103.28.54.101 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.24 [VT] |
| clientconfig.akamai.steamstatic.com [VT] |
A 23.209.183.106
[VT]
A 23.209.183.176 [VT] |
23.211.125.112 [VT] |
| cdn.discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.129.233 [VT] |
| steamcommunity.com [VT] | 23.216.106.59 [VT] | |
| discord.com [VT] | 162.159.138.232 [VT] | |
| latency.discord.media [VT] |
A 162.159.130.235
[VT]
A 162.159.129.235 [VT] A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.128.235 [VT] |
162.159.128.235 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.