| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 21:18:45 | 2026-05-28 21:20:05 | 80s |
|
|||||
| Reports | JSON | |||||||||
vnc_port=5910
2026-05-28 20:55:30,758 [root] INFO: Date set to: 20260528T21:18:52, timeout set to: 60
2026-05-28 21:18:52,011 [root] DEBUG: Starting analyzer from: C:\lpw_albt
2026-05-28 21:18:52,011 [root] DEBUG: Storing results at: C:\wRMOqlspU
2026-05-28 21:18:52,012 [root] DEBUG: Pipe server name: \\.\PIPE\gsdfIGV
2026-05-28 21:18:52,012 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 21:18:52,012 [root] INFO: analysis running as an admin
2026-05-28 21:18:52,012 [root] INFO: analysis package specified: "edge"
2026-05-28 21:18:52,012 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 21:18:52,016 [root] DEBUG: imported analysis package "edge"
2026-05-28 21:18:52,017 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 21:18:52,017 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-28 21:18:52,017 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 21:18:52,017 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 21:18:52,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 21:18:52,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 21:18:52,032 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 21:18:52,045 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 21:18:52,052 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 21:18:52,057 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 21:18:52,062 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 21:18:52,062 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 21:18:52,063 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 21:18:52,064 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 21:18:52,065 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 21:18:52,065 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 21:18:52,066 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 21:18:52,066 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 21:18:52,066 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 21:18:52,067 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 21:18:52,067 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 21:18:52,067 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 21:18:52,067 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 21:18:52,068 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 21:18:52,068 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 21:18:52,068 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 21:18:52,068 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 21:18:52,068 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 21:18:52,069 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 21:18:52,073 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 712)
2026-05-28 21:18:52,074 [modules.auxiliary.disguise] INFO: Disguising GUID to 06aa6ba2-d493-411a-8692-fe35a6c3fb7b
2026-05-28 21:18:52,076 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 21:18:52,078 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 21:18:52,078 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 21:18:52,079 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 21:18:52,079 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 21:18:52,080 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 21:18:52,081 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 21:18:52,081 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 21:18:52,081 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 21:18:52,081 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 21:18:52,082 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 21:18:52,082 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 21:18:52,083 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 21:18:52,083 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 21:18:52,083 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 21:18:52,084 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 21:18:52,086 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 21:18:52,086 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 21:18:57,145 [root] INFO: Restarting WMI Service
2026-05-28 21:18:59,170 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 21:18:59,171 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 21:18:59,172 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 21:18:59,173 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 4132
2026-05-28 21:18:59,283 [lib.api.process] INFO: Monitor config for process 4132: C:\lpw_albt\dll\4132.ini
2026-05-28 21:18:59,298 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:18:59,370 [root] DEBUG: Loader: Injecting process 4132 (thread 2012) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:18:59,371 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:18:59,371 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:18:59,373 [lib.api.process] INFO: Injected into 64-bit <Process 4132 msedge.exe>
2026-05-28 21:19:01,389 [lib.api.process] INFO: Successfully resumed process with pid 4132
2026-05-28 21:19:01,483 [root] DEBUG: 4132: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:19:01,484 [root] DEBUG: 4132: Disabling sleep skipping.
2026-05-28 21:19:01,485 [root] DEBUG: 4132: Dropped file limit defaulting to 100.
2026-05-28 21:19:01,492 [root] DEBUG: 4132: Edge-specific hook-set enabled.
2026-05-28 21:19:01,503 [root] DEBUG: 4132: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:19:01,503 [root] DEBUG: 4132: Monitor initialised: 64-bit capemon loaded in process 4132 at 0x00007FFF17AD0000, thread 2012, image base 0x00007FF7F5380000, stack from 0x0000001B11DF1000-0x0000001B11E00000
2026-05-28 21:19:01,504 [root] DEBUG: 4132: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-28 21:19:01,515 [root] DEBUG: 4132: Hooked 2 out of 2 functions
2026-05-28 21:19:01,536 [root] DEBUG: 4132: Syscall hook installed, syscall logging level 1
2026-05-28 21:19:01,541 [root] DEBUG: 4132: RestoreHeaders: Restored original import table.
2026-05-28 21:19:01,542 [root] INFO: Loaded monitor into process with pid 4132
2026-05-28 21:19:01,544 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:19:01,549 [root] DEBUG: 4132: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 21:19:01,550 [root] DEBUG: 4132: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:19:01,551 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 21:19:01,551 [root] DEBUG: 4132: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:19:01,552 [root] DEBUG: 4132: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 21:19:01,553 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 21:19:01,683 [root] DEBUG: 4132: DLL loaded at 0x00007FFF453C0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 21:19:01,684 [root] DEBUG: 4132: DLL loaded at 0x00007FFEFE540000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 21:19:01,687 [root] DEBUG: 4132: DLL loaded at 0x00007FFF45010000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 21:19:01,689 [root] DEBUG: 4132: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:19:01,694 [root] DEBUG: 4132: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:19:01,694 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 4748: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:01,695 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 4748
2026-05-28 21:19:01,695 [root] DEBUG: 4132: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:19:01,695 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 4748
2026-05-28 21:19:01,696 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4D260000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 21:19:01,697 [root] DEBUG: 4132: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:19:01,697 [root] DEBUG: 4132: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:19:01,701 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 21:19:01,701 [root] DEBUG: 4132: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 21:19:01,702 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 21:19:01,703 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 21:19:01,704 [root] DEBUG: 4132: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:19:01,704 [root] DEBUG: 4132: DLL loaded at 0x00007FFF19B60000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 21:19:01,706 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 21:19:01,707 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 21:19:01,707 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 21:19:01,708 [root] DEBUG: 4132: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 21:19:01,708 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 21:19:01,709 [root] DEBUG: 4132: DLL loaded at 0x00007FFF15300000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 21:19:01,709 [root] DEBUG: 4132: DLL loaded at 0x00007FFF19B20000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 21:19:01,710 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 21:19:01,710 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 21:19:01,711 [root] DEBUG: 4132: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 21:19:01,712 [root] DEBUG: 4132: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:19:01,713 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 21:19:01,713 [root] DEBUG: 4132: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 21:19:01,714 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 21:19:01,721 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4D010000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 21:19:01,721 [root] DEBUG: 4132: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 21:19:01,722 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 21:19:01,723 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 21:19:01,723 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 21:19:01,724 [root] DEBUG: 4132: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 21:19:01,727 [root] DEBUG: 4132: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 21:19:01,729 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:19:01,729 [root] DEBUG: 4132: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:19:01,730 [root] DEBUG: 4132: DLL loaded at 0x00007FFF569F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 21:19:01,731 [root] DEBUG: 4132: DLL loaded at 0x00007FFF52960000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 21:19:01,732 [root] DEBUG: 4132: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 21:19:01,733 [root] DEBUG: 4132: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 21:19:01,733 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 21:19:01,734 [root] DEBUG: 4132: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 21:19:01,735 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 21:19:01,735 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 21:19:01,736 [root] DEBUG: 4132: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 21:19:01,739 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 21:19:01,740 [root] DEBUG: 4132: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 21:19:01,741 [root] DEBUG: 4132: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:19:01,741 [root] DEBUG: 4132: DLL loaded at 0x00007FFF54170000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 21:19:01,742 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4B680000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 21:19:01,744 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 21:19:01,745 [root] DEBUG: 4132: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 21:19:01,746 [root] DEBUG: 4132: DLL loaded at 0x00007FFF45580000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 21:19:01,748 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 21:19:01,749 [root] DEBUG: 4132: DLL loaded at 0x00007FFF52420000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 21:19:01,752 [root] DEBUG: 4132: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 21:19:01,753 [root] DEBUG: 4132: DLL loaded at 0x00007FFF51A60000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 21:19:01,753 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4AF10000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 21:19:01,754 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4BFB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 21:19:01,756 [root] DEBUG: 4132: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 21:19:01,758 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 21:19:01,758 [root] DEBUG: 4132: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 21:19:01,759 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 21:19:01,760 [root] DEBUG: 4132: DLL loaded at 0x00007FFF515E0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 21:19:01,761 [root] DEBUG: 4132: DLL loaded at 0x00007FFF51600000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 21:19:01,768 [root] DEBUG: 4132: DLL loaded at 0x00007FFF52560000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 21:19:01,772 [root] DEBUG: 4132: DLL loaded at 0x00007FFF17040000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 21:19:01,787 [root] DEBUG: 4132: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 21:19:01,788 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 2916: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:01,789 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 2916
2026-05-28 21:19:01,790 [root] DEBUG: 4132: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 21:19:01,790 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 2916
2026-05-28 21:19:01,791 [root] DEBUG: 4132: caller_dispatch: Added region at 0x00007FF7F5380000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7F5477D66, thread 5708).
2026-05-28 21:19:01,795 [root] DEBUG: 4132: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:19:01,796 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 5704: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:01,797 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 5704
2026-05-28 21:19:01,797 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 5704
2026-05-28 21:19:01,800 [root] DEBUG: 4132: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:19:01,809 [root] DEBUG: 4132: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 21:19:01,811 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 4388: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:01,811 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 4388
2026-05-28 21:19:01,812 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 4388
2026-05-28 21:19:01,813 [root] DEBUG: 4132: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 21:19:01,813 [root] DEBUG: 4132: DLL loaded at 0x00007FFF409A0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 21:19:01,844 [root] DEBUG: 4132: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 21:19:01,844 [root] DEBUG: 4132: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 21:19:01,845 [root] DEBUG: 4132: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 21:19:01,845 [root] DEBUG: 4132: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 21:19:01,867 [root] DEBUG: 4132: DLL loaded at 0x00007FFF3F8A0000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 21:19:01,880 [root] DEBUG: 4132: DLL loaded at 0x00007FFF55220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 21:19:01,887 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 7928: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:01,888 [root] DEBUG: 4132: DLL loaded at 0x00007FFF43990000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 21:19:01,889 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 7928
2026-05-28 21:19:01,889 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 7460: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:01,889 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 7460
2026-05-28 21:19:01,890 [root] DEBUG: 4132: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 21:19:01,890 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 7928
2026-05-28 21:19:01,890 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 7460
2026-05-28 21:19:01,939 [root] DEBUG: 4132: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 21:19:01,945 [root] DEBUG: 4132: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 21:19:01,967 [root] DEBUG: 4132: DLL loaded at 0x00007FFF181E0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 21:19:01,975 [root] DEBUG: 4132: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 21:19:01,979 [root] DEBUG: 4132: DLL loaded at 0x00007FFF42BF0000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1e000 bytes).
2026-05-28 21:19:01,983 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4CFA0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Domain Actions\3.0.0.18\domain_actions (0x17000 bytes).
2026-05-28 21:19:02,012 [root] DEBUG: 4132: DLL loaded at 0x00007FFF18150000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 21:19:02,021 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 21:19:02,023 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 21:19:02,024 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 21:19:03,255 [root] DEBUG: 4132: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 21:19:03,700 [root] DEBUG: 4132: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:19:03,701 [root] DEBUG: 4132: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:19:06,895 [root] DEBUG: 4132: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 21:19:06,897 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 1252: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:06,897 [root] DEBUG: 4132: DLL loaded at 0x00007FFF572F0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 21:19:06,897 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 1252
2026-05-28 21:19:06,898 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 972: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:06,898 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 1252
2026-05-28 21:19:06,898 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 972
2026-05-28 21:19:06,899 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 972
2026-05-28 21:19:06,918 [root] DEBUG: 4132: DLL loaded at 0x00007FFF140B0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 21:19:06,938 [root] DEBUG: 4132: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 21:19:06,939 [root] DEBUG: 4132: DLL loaded at 0x00007FFF16BD0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 21:19:06,942 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 21:19:06,947 [root] DEBUG: 4132: DLL loaded at 0x00007FFF13A50000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 21:19:06,951 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 21:19:06,953 [root] DEBUG: 4132: DLL loaded at 0x00007FFF3F6A0000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 21:19:06,955 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 5384: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7DA540000
2026-05-28 21:19:06,955 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56250000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 21:19:06,956 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 5384
2026-05-28 21:19:06,956 [root] DEBUG: 4132: DLL loaded at 0x00007FFF561E0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 21:19:06,956 [lib.api.process] INFO: Monitor config for process 5384: C:\lpw_albt\dll\5384.ini
2026-05-28 21:19:06,958 [root] DEBUG: 4132: DLL loaded at 0x00007FFF180D0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 21:19:06,963 [root] DEBUG: 4132: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 21:19:06,964 [root] DEBUG: 4132: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 21:19:06,964 [root] DEBUG: 4132: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:19:07,276 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:19:07,276 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:19:07,278 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:19:07,278 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:19:07,278 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:19:07,279 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:19:07,279 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:19:07,279 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:19:07,282 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:07,286 [root] DEBUG: Loader: Injecting process 5384 (thread 2800) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:07,286 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:19:07,287 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:07,288 [lib.api.process] INFO: Injected into 64-bit <Process 5384 identity_helper.exe>
2026-05-28 21:19:07,293 [root] DEBUG: 4132: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 21:19:07,294 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4CBD0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 21:19:07,295 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 8972: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7DA540000
2026-05-28 21:19:07,296 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8972
2026-05-28 21:19:07,296 [lib.api.process] INFO: Monitor config for process 8972: C:\lpw_albt\dll\8972.ini
2026-05-28 21:19:07,350 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4F950000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 21:19:07,352 [root] DEBUG: 4132: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 21:19:07,353 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4F740000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 21:19:07,367 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:19:07,368 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:19:07,368 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:19:07,368 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:19:07,368 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:19:07,368 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:19:07,368 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:19:07,369 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:19:07,370 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:07,375 [root] DEBUG: Loader: Injecting process 8972 (thread 8608) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:07,376 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:19:07,376 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:07,377 [lib.api.process] INFO: Injected into 64-bit <Process 8972 identity_helper.exe>
2026-05-28 21:19:07,379 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 8972
2026-05-28 21:19:07,379 [lib.api.process] INFO: Monitor config for process 8972: C:\lpw_albt\dll\8972.ini
2026-05-28 21:19:07,386 [root] DEBUG: 4132: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 21:19:07,400 [root] DEBUG: 4132: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 21:19:07,401 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 21:19:07,402 [root] DEBUG: 4132: DLL loaded at 0x00007FFF50370000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 21:19:07,403 [root] DEBUG: 4132: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 21:19:07,404 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 21:19:07,404 [root] DEBUG: 4132: DLL loaded at 0x00007FFF45050000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 21:19:07,457 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:19:07,457 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:19:07,458 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:19:07,458 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:19:07,458 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:19:07,458 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:19:07,458 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:19:07,458 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:19:07,460 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:07,464 [root] DEBUG: Loader: Injecting process 8972 (thread 8608) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:07,465 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:19:07,465 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:07,466 [lib.api.process] INFO: Injected into 64-bit <Process 8972 identity_helper.exe>
2026-05-28 21:19:07,489 [root] DEBUG: 8972: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:19:07,489 [root] DEBUG: 8972: Dropped file limit defaulting to 100.
2026-05-28 21:19:07,496 [root] DEBUG: 8972: Disabling sleep skipping.
2026-05-28 21:19:07,502 [root] DEBUG: 8972: YaraInit: Compiled 44 rule files
2026-05-28 21:19:07,503 [root] DEBUG: 8972: YaraInit: Compiled rules saved to file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:19:07,517 [root] DEBUG: 8972: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:19:07,517 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56D00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 21:19:07,518 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FF7DA540000, size 0x28b4d8
2026-05-28 21:19:07,536 [root] DEBUG: 8972: Monitor initialised: 64-bit capemon loaded in process 8972 at 0x00007FFF17AD0000, thread 8608, image base 0x00007FF7DA540000, stack from 0x0000007121AF1000-0x0000007121B00000
2026-05-28 21:19:07,537 [root] DEBUG: 8972: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5484,i,16682385157051867027,9882385662020069020,524288 --field-trial-handle=2332,i,7160788429019893685,10299558798743960205,262144 --variations-seed-version --pseudonymization-salt-handle=2336,i,11924026469095214904,2916500198826238
2026-05-28 21:19:07,537 [root] DEBUG: 8972: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 21:19:07,547 [root] DEBUG: 8972: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:19:07,570 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:19:07,571 [root] DEBUG: 8972: set_hooks: Unable to hook LockResource
2026-05-28 21:19:07,578 [root] DEBUG: 8972: Hooked 627 out of 628 functions
2026-05-28 21:19:07,594 [root] DEBUG: 8972: Syscall hook installed, syscall logging level 1
2026-05-28 21:19:07,599 [root] DEBUG: 8972: RestoreHeaders: Restored original import table.
2026-05-28 21:19:07,599 [root] INFO: Loaded monitor into process with pid 8972
2026-05-28 21:19:07,600 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FFF17610000, size 0x4b9994
2026-05-28 21:19:07,650 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FFF17610000, size 0x4b9994
2026-05-28 21:19:07,681 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FFF17610000, size 0x4b9994
2026-05-28 21:19:07,705 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FFF17610000, size 0x4b9994
2026-05-28 21:19:07,728 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FFF17610000, size 0x4b9994
2026-05-28 21:19:07,753 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FFF17610000, size 0x4b9994
2026-05-28 21:19:07,778 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FFF17610000, size 0x4b9994
2026-05-28 21:19:07,805 [root] DEBUG: 8972: caller_dispatch: Added region at 0x00007FFF17610000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF1780F156, thread 8608).
2026-05-28 21:19:07,806 [root] DEBUG: 8972: caller_dispatch: Scanning calling region at 0x00007FFF17610000...
2026-05-28 21:19:07,810 [root] DEBUG: 8972: ProcessTrackedRegion: Region at 0x00007FFF17610000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 21:19:07,814 [root] DEBUG: 8972: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:19:07,835 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FF7DA540000, size 0x28b4d8
2026-05-28 21:19:07,850 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FF7DA540000, size 0x28b4d8
2026-05-28 21:19:07,865 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FF7DA540000, size 0x28b4d8
2026-05-28 21:19:07,881 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FF7DA540000, size 0x28b4d8
2026-05-28 21:19:07,896 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FF7DA540000, size 0x28b4d8
2026-05-28 21:19:07,911 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FF7DA540000, size 0x28b4d8
2026-05-28 21:19:07,928 [root] DEBUG: 8972: caller_dispatch: Added region at 0x00007FF7DA540000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7DA634096, thread 8608).
2026-05-28 21:19:07,928 [root] DEBUG: 8972: YaraScan: Scanning 0x00007FF7DA540000, size 0x28b4d8
2026-05-28 21:19:07,944 [root] DEBUG: 8972: ProcessImageBase: Main module image at 0x00007FF7DA540000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:19:07,947 [root] DEBUG: 8972: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:19:07,972 [root] DEBUG: 8972: DLL loaded at 0x0000024647000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 21:19:07,974 [root] DEBUG: 8972: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:19:07,976 [root] DEBUG: 8972: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 21:19:08,006 [root] DEBUG: 8972: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:19:08,010 [root] DEBUG: 8972: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:19:08,014 [root] DEBUG: 8972: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:19:08,015 [root] DEBUG: 8972: DLL loaded at 0x00007FFF52860000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 21:19:08,015 [root] DEBUG: 8972: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 21:19:08,016 [root] DEBUG: 8972: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 21:19:08,024 [root] DEBUG: 8972: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:19:08,024 [root] DEBUG: 8972: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 21:19:08,025 [root] DEBUG: 8972: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 21:19:08,025 [root] DEBUG: 8972: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 21:19:08,026 [root] DEBUG: 8972: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:19:08,038 [root] DEBUG: 8972: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 21:19:08,046 [root] DEBUG: 8972: DLL loaded at 0x00007FFF46AE0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 21:19:08,051 [root] DEBUG: 8972: DLL loaded at 0x00007FFF566C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:19:08,051 [root] DEBUG: 8972: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:19:08,054 [root] DEBUG: 8972: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 21:19:08,065 [root] DEBUG: 8972: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:19:08,065 [root] DEBUG: 8972: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 21:19:08,075 [root] DEBUG: 8972: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 21:19:08,076 [root] DEBUG: 8972: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 21:19:08,080 [root] DEBUG: 8972: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 21:19:08,088 [root] DEBUG: 8972: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 21:19:08,094 [root] DEBUG: 8972: DLL loaded at 0x000002465D490000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 21:19:08,099 [lib.api.process] INFO: Monitor config for process 832: C:\lpw_albt\dll\832.ini
2026-05-28 21:19:08,101 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:08,105 [root] DEBUG: Loader: Injecting process 832 with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:08,107 [root] DEBUG: 832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:19:08,107 [root] DEBUG: 832: Disabling sleep skipping.
2026-05-28 21:19:08,108 [root] DEBUG: 832: Dropped file limit defaulting to 100.
2026-05-28 21:19:08,109 [root] DEBUG: 832: Services hook set enabled
2026-05-28 21:19:08,110 [root] DEBUG: 832: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:19:08,122 [root] DEBUG: 832: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:19:08,122 [root] DEBUG: 832: Monitor initialised: 64-bit capemon loaded in process 832 at 0x00007FFF17AD0000, thread 3532, image base 0x00007FF7BF220000, stack from 0x000000CCA7AF5000-0x000000CCA7B00000
2026-05-28 21:19:08,122 [root] DEBUG: 832: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 21:19:08,133 [root] DEBUG: 832: Hooked 69 out of 69 functions
2026-05-28 21:19:08,134 [root] INFO: Loaded monitor into process with pid 832
2026-05-28 21:19:08,134 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 21:19:08,135 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:08,136 [lib.api.process] INFO: Injected into 64-bit <Process 832 svchost.exe>
2026-05-28 21:19:10,192 [root] DEBUG: 8972: DLL loaded at 0x00007FFF4B780000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 21:19:10,194 [root] DEBUG: 8972: DLL loaded at 0x00007FFF4B840000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 21:19:10,195 [root] DEBUG: 8972: DLL loaded at 0x00007FFF43150000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 21:19:10,197 [root] DEBUG: 8972: DLL loaded at 0x00007FFF3D7B0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 21:19:10,210 [root] DEBUG: 8972: DLL loaded at 0x00007FFF4F6E0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 21:19:10,230 [root] DEBUG: 8972: DLL loaded at 0x00007FFF55EF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 21:19:10,231 [root] DEBUG: 8972: DLL loaded at 0x00007FFF53070000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 21:19:10,237 [root] DEBUG: 8972: DLL loaded at 0x00007FFF48B40000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 21:19:10,237 [root] DEBUG: 8972: DLL loaded at 0x00007FFF3D6A0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 21:19:10,250 [root] DEBUG: 8972: DLL loaded at 0x00007FFF43060000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 21:19:10,271 [root] DEBUG: 8972: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 21:19:10,272 [root] DEBUG: 8972: DLL loaded at 0x00007FFF56FA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 21:19:10,272 [root] DEBUG: 8972: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:19:10,272 [root] DEBUG: 8972: DLL loaded at 0x00007FFF4C520000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 21:19:10,273 [root] DEBUG: 8972: DLL loaded at 0x00007FFF43DD0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 21:19:10,282 [root] DEBUG: 8972: DLL loaded at 0x00007FFF3D810000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 21:19:10,299 [root] DEBUG: 8972: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 21:19:10,333 [root] DEBUG: 8972: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 21:19:17,563 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8504: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-28 21:19:17,564 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8504
2026-05-28 21:19:17,564 [lib.api.process] INFO: Monitor config for process 8504: C:\lpw_albt\dll\8504.ini
2026-05-28 21:19:17,566 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:17,570 [root] DEBUG: Loader: Injecting process 8504 (thread 7064) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,570 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:19:17,570 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,572 [lib.api.process] INFO: Injected into 64-bit <Process 8504 backgroundTaskHost.exe>
2026-05-28 21:19:17,573 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8504
2026-05-28 21:19:17,573 [lib.api.process] INFO: Monitor config for process 8504: C:\lpw_albt\dll\8504.ini
2026-05-28 21:19:17,574 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:17,578 [root] DEBUG: Loader: Injecting process 8504 (thread 7064) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,579 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:19:17,579 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,580 [lib.api.process] INFO: Injected into 64-bit <Process 8504 backgroundTaskHost.exe>
2026-05-28 21:19:17,581 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8504
2026-05-28 21:19:17,581 [lib.api.process] INFO: Monitor config for process 8504: C:\lpw_albt\dll\8504.ini
2026-05-28 21:19:17,582 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:17,586 [root] DEBUG: Loader: Injecting process 8504 with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,586 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 7064, handle 0x120
2026-05-28 21:19:17,586 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:19:17,587 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,588 [lib.api.process] INFO: Injected into 64-bit <Process 8504 backgroundTaskHost.exe>
2026-05-28 21:19:17,596 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2076: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-28 21:19:17,597 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2076
2026-05-28 21:19:17,597 [lib.api.process] INFO: Monitor config for process 2076: C:\lpw_albt\dll\2076.ini
2026-05-28 21:19:17,598 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:17,602 [root] DEBUG: Loader: Injecting process 2076 (thread 2560) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,602 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:19:17,603 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,604 [lib.api.process] INFO: Injected into 64-bit <Process 2076 backgroundTaskHost.exe>
2026-05-28 21:19:17,606 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2076
2026-05-28 21:19:17,606 [lib.api.process] INFO: Monitor config for process 2076: C:\lpw_albt\dll\2076.ini
2026-05-28 21:19:17,608 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:19:17,611 [root] DEBUG: Loader: Injecting process 2076 (thread 2560) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,612 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:19:17,612 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:19:17,613 [lib.api.process] INFO: Injected into 64-bit <Process 2076 backgroundTaskHost.exe>
2026-05-28 21:19:17,615 [root] INFO: Process with pid 2076 has terminated
2026-05-28 21:19:20,407 [root] INFO: Process with pid 8972 has terminated
2026-05-28 21:19:20,409 [root] DEBUG: 8972: NtTerminateProcess hook: Attempting to dump process 8972
2026-05-28 21:19:20,410 [root] DEBUG: 8972: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:19:29,736 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 8828: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:29,737 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 8828
2026-05-28 21:19:29,738 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 8828
2026-05-28 21:19:30,764 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 9124: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:30,766 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 9124
2026-05-28 21:19:30,768 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 9124
2026-05-28 21:19:31,694 [root] DEBUG: 4132: DLL loaded at 0x00007FFF3EFA0000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 21:19:31,771 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 6148: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:31,772 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 6148
2026-05-28 21:19:31,773 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 6148
2026-05-28 21:19:57,141 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 3348: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:19:57,143 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 3348
2026-05-28 21:19:57,143 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 3348
2026-05-28 21:20:01,298 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 5232: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF71C070000
2026-05-28 21:20:01,300 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 5232
2026-05-28 21:20:01,300 [lib.api.process] INFO: Monitor config for process 5232: C:\lpw_albt\dll\5232.ini
2026-05-28 21:20:01,302 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:20:01,305 [root] DEBUG: Loader: Injecting process 5232 (thread 6740) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:20:01,306 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:20:01,306 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:20:01,307 [lib.api.process] INFO: Injected into 64-bit <Process 5232 SecurityHealthHost.exe>
2026-05-28 21:20:01,309 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 5232
2026-05-28 21:20:01,309 [lib.api.process] INFO: Monitor config for process 5232: C:\lpw_albt\dll\5232.ini
2026-05-28 21:20:01,310 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:20:01,314 [root] DEBUG: Loader: Injecting process 5232 (thread 6740) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:20:01,314 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:20:01,315 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:20:01,316 [lib.api.process] INFO: Injected into 64-bit <Process 5232 SecurityHealthHost.exe>
2026-05-28 21:20:01,322 [root] DEBUG: 5232: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:20:01,322 [root] DEBUG: 5232: Dropped file limit defaulting to 100.
2026-05-28 21:20:01,325 [root] DEBUG: 5232: Disabling sleep skipping.
2026-05-28 21:20:01,325 [root] DEBUG: 5232: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:20:01,337 [root] DEBUG: 5232: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:20:01,337 [root] DEBUG: 5232: YaraScan: Scanning 0x00007FF71C070000, size 0x19174
2026-05-28 21:20:01,339 [root] DEBUG: 5232: Monitor initialised: 64-bit capemon loaded in process 5232 at 0x00007FFF17AD0000, thread 6740, image base 0x00007FF71C070000, stack from 0x00000098A50D4000-0x00000098A50E0000
2026-05-28 21:20:01,339 [root] DEBUG: 5232: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-28 21:20:01,347 [root] DEBUG: 5232: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:20:01,368 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:20:01,370 [root] DEBUG: 5232: set_hooks: Unable to hook LockResource
2026-05-28 21:20:01,374 [root] DEBUG: 5232: Hooked 627 out of 628 functions
2026-05-28 21:20:01,376 [root] DEBUG: 5232: Syscall hook installed, syscall logging level 1
2026-05-28 21:20:01,380 [root] DEBUG: 5232: RestoreHeaders: Restored original import table.
2026-05-28 21:20:01,380 [root] INFO: Loaded monitor into process with pid 5232
2026-05-28 21:20:01,381 [root] DEBUG: 5232: caller_dispatch: Added region at 0x00007FF71C070000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF71C07D3B2, thread 6740).
2026-05-28 21:20:01,381 [root] DEBUG: 5232: YaraScan: Scanning 0x00007FF71C070000, size 0x19174
2026-05-28 21:20:01,383 [root] DEBUG: 5232: ProcessImageBase: Main module image at 0x00007FF71C070000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:20:01,385 [root] DEBUG: 5232: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:20:01,386 [root] DEBUG: 5232: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:20:01,388 [root] DEBUG: 5232: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:20:01,403 [root] DEBUG: 5232: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 21:20:01,404 [root] DEBUG: 5232: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 21:20:01,404 [root] DEBUG: 5232: DLL loaded at 0x000001A258BB0000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-28 21:20:01,420 [root] DEBUG: 5232: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 21:20:01,423 [root] DEBUG: 5232: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 21:20:01,428 [root] DEBUG: 5232: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:20:01,429 [root] DEBUG: 5232: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:20:01,429 [root] DEBUG: 5232: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 21:20:01,430 [root] DEBUG: 5232: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 21:20:01,431 [root] DEBUG: 5232: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 21:20:01,431 [root] DEBUG: 5232: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:20:01,435 [root] DEBUG: 5232: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 21:20:01,446 [root] DEBUG: 5232: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:20:01,455 [root] DEBUG: 5232: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 21:20:01,479 [root] DEBUG: 5232: NtTerminateProcess hook: Attempting to dump process 5232
2026-05-28 21:20:01,480 [root] DEBUG: 5232: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:20:01,488 [root] INFO: Process with pid 5232 has terminated
2026-05-28 21:20:01,504 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2436: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF645A20000
2026-05-28 21:20:01,505 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 2436
2026-05-28 21:20:01,505 [lib.api.process] INFO: Monitor config for process 2436: C:\lpw_albt\dll\2436.ini
2026-05-28 21:20:01,761 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56140000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-28 21:20:01,762 [root] DEBUG: 4132: DLL loaded at 0x00007FFF56170000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-28 21:20:01,763 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4F220000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-28 21:20:01,778 [root] DEBUG: 4132: DLL loaded at 0x00007FFF4D360000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-28 21:20:01,823 [root] DEBUG: 4132: CreateProcessHandler: Injection info set for new process 6460: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:20:01,824 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 6460
2026-05-28 21:20:01,825 [root] DEBUG: 4132: ProcessMessage: Skipping monitoring process 6460
2026-05-28 21:20:01,902 [root] DEBUG: 4132: DLL loaded at 0x00007FFF17EF0000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-28 21:20:01,942 [root] INFO: Analysis timeout hit, terminating analysis
2026-05-28 21:20:01,943 [lib.api.process] INFO: Terminate event set for process 4132
2026-05-28 21:20:01,944 [root] DEBUG: 4132: Terminate Event: Attempting to dump process 4132
2026-05-28 21:20:01,947 [root] DEBUG: 4132: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:20:01,960 [lib.api.process] INFO: Termination confirmed for process 4132
2026-05-28 21:20:01,960 [root] DEBUG: 4132: Terminate Event: monitor shutdown complete for process 4132
2026-05-28 21:20:01,960 [root] INFO: Terminate event set for process 4132
2026-05-28 21:20:01,961 [lib.api.process] INFO: Terminate event set for process 832
2026-05-28 21:20:01,961 [root] DEBUG: 832: Terminate Event: Attempting to dump process 832
2026-05-28 21:20:01,962 [root] DEBUG: 832: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:20:01,964 [lib.api.process] INFO: Termination confirmed for process 832
2026-05-28 21:20:01,964 [root] INFO: Terminate event set for process 832
2026-05-28 21:20:01,965 [root] INFO: Created shutdown mutex
2026-05-28 21:20:01,964 [root] DEBUG: 832: Terminate Event: monitor shutdown complete for process 832
2026-05-28 21:20:02,200 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\SlxjJjW.dll, loader C:\lpw_albt\bin\eXPvwUns.exe
2026-05-28 21:20:02,205 [root] DEBUG: Loader: Injecting process 2436 (thread 5812) with C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:20:02,206 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:20:02,207 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\SlxjJjW.dll.
2026-05-28 21:20:02,208 [lib.api.process] INFO: Injected into 64-bit <Process 2436 ShellExperienceHost.exe>
2026-05-28 21:20:02,978 [root] INFO: Shutting down package
2026-05-28 21:20:02,978 [root] INFO: Stopping auxiliary modules
2026-05-28 21:20:02,979 [root] INFO: Stopping auxiliary module: Browser
2026-05-28 21:20:02,979 [root] INFO: Stopping auxiliary module: Human
2026-05-28 21:20:03,938 [root] INFO: Stopping auxiliary module: Screenshots
2026-05-28 21:20:03,938 [root] INFO: Finishing auxiliary modules
2026-05-28 21:20:03,939 [root] INFO: Shutting down pipe server and dumping dropped files
2026-05-28 21:20:03,939 [root] WARNING: Folder at path "C:\wRMOqlspU\debugger" does not exist, skipping
2026-05-28 21:20:03,939 [root] WARNING: Folder at path "C:\wRMOqlspU\tlsdump" does not exist, skipping
2026-05-28 21:20:03,971 [root] WARNING: Monitor injection attempted but failed for process 5384
2026-05-28 21:20:03,971 [root] WARNING: Monitor injection attempted but failed for process 8504
2026-05-28 21:20:03,972 [root] WARNING: Monitor injection attempted but failed for process 2076
2026-05-28 21:20:03,973 [root] WARNING: Monitor injection attempted but failed for process 2436
2026-05-28 21:20:03,973 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 21:18:45 | 2026-05-28 21:20:05 | none |
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 150.171.109.19 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 146.75.119.82 [VT] | unknown | - |
| N | 205.196.6.132 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 23.56.110.169 [VT] | unknown | - |
| N | 162.159.128.235 [VT] | unknown | - |
| N | 162.159.138.232 [VT] | unknown | - |
| N | 162.159.135.232 [VT] | unknown | - |
| N | 162.159.133.234 [VT] | unknown | - |
| N | 162.159.135.233 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| N | 162.159.133.233 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| N | 142.250.195.131 [VT] | unknown | - |
| N | 23.221.49.11 [VT] | unknown | - |
| Y | 172.172.255.218 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-udp.steamserver.net [VT] |
CNAME udp.ipv6check.akadns.net
[VT]
AAAA 2404:3fc0:1:102::670a:7d36 [VT] AAAA 2404:3fc0:1:102::670a:7d37 [VT] AAAA 2404:3fc0:1:100::670a:7d06 [VT] AAAA 2404:3fc0:1:100::42 [VT] AAAA 2404:3fc0:1:102::670a:7d38 [VT] CNAME syd.udp.ipv6check.akadns.net [VT] AAAA 2404:3fc0:1:100::670a:7d08 [VT] AAAA 2404:3fc0:1:102::670a:7d35 [VT] AAAA 2404:3fc0:1:100::32 [VT] |
|
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 23.221.49.11
[VT]
A 23.221.49.17 [VT] |
23.56.110.51 [VT] |
| c.pki.goog [VT] |
CNAME pki-goog.l.google.com
[VT]
A 142.250.195.131 [VT] |
142.250.207.3 [VT] |
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.129.233 [VT] |
| gateway-us-east1-c.discord.gg [VT] |
A 162.159.130.234
[VT]
A 162.159.134.234 [VT] A 162.159.135.234 [VT] A 162.159.133.234 [VT] A 162.159.136.234 [VT] |
162.159.135.234 [VT] |
| status.discord.com [VT] |
A 162.159.128.233
[VT]
A 162.159.138.232 [VT] A 162.159.137.232 [VT] A 162.159.135.232 [VT] A 162.159.136.232 [VT] |
162.159.137.232 [VT] |
| cdn.discordapp.com [VT] | 162.159.134.233 [VT] | |
| updates.discord.com [VT] | 162.159.137.232 [VT] | |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.4.4 [VT] |
| cmp1-sea1.steamserver.net [VT] | A 205.196.6.132 [VT] | 205.196.6.132 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.24 [VT] |
| latency.discord.media [VT] |
A 162.159.130.235
[VT]
A 162.159.129.235 [VT] A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.128.235 [VT] |
162.159.138.234 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.