| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 21:22:54 | 2026-05-28 21:24:45 | 111s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 20:55:30,764 [root] INFO: Date set to: 20260528T21:23:01, timeout set to: 200
2026-05-28 21:23:01,009 [root] DEBUG: Starting analyzer from: C:\lpw_albt
2026-05-28 21:23:01,009 [root] DEBUG: Storing results at: C:\NPOoaUZdpr
2026-05-28 21:23:01,010 [root] DEBUG: Pipe server name: \\.\PIPE\dlOvpdXk
2026-05-28 21:23:01,010 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 21:23:01,010 [root] INFO: analysis running as an admin
2026-05-28 21:23:01,010 [root] INFO: analysis package specified: "edge"
2026-05-28 21:23:01,010 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 21:23:01,013 [root] DEBUG: imported analysis package "edge"
2026-05-28 21:23:01,013 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 21:23:01,013 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-28 21:23:01,013 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 21:23:01,014 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 21:23:01,014 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 21:23:01,014 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 21:23:01,028 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 21:23:01,052 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 21:23:01,062 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 21:23:01,070 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 21:23:01,073 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 21:23:01,074 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 21:23:01,074 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 21:23:01,076 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 21:23:01,076 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 21:23:01,076 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 21:23:01,076 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 21:23:01,077 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 21:23:01,077 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 21:23:01,077 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 21:23:01,077 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 21:23:01,078 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 21:23:01,078 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 21:23:01,078 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 21:23:01,078 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 21:23:01,078 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 21:23:01,078 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 21:23:01,078 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 21:23:01,079 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 21:23:01,081 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 2976)
2026-05-28 21:23:01,081 [modules.auxiliary.disguise] INFO: Disguising GUID to c246259b-7e4d-4b40-aa1a-c88233d23ad0
2026-05-28 21:23:01,081 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 21:23:01,082 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 21:23:01,082 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 21:23:01,082 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 21:23:01,082 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 21:23:01,089 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 21:23:01,091 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 21:23:01,092 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 21:23:01,092 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 21:23:01,092 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 21:23:01,093 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 21:23:01,093 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 21:23:01,093 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 21:23:01,093 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 21:23:01,094 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 21:23:01,094 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 21:23:01,095 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 21:23:01,096 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 21:23:01,096 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 21:23:01,138 [lib.api.process] INFO: Monitor config for process 4484: C:\lpw_albt\dll\4484.ini
2026-05-28 21:23:01,140 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:01,142 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:01,261 [root] DEBUG: Loader: Injecting process 4484 with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:01,434 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:23:01,435 [root] DEBUG: 4484: Disabling sleep skipping.
2026-05-28 21:23:01,436 [root] DEBUG: 4484: Interactive desktop enabled.
2026-05-28 21:23:01,437 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-28 21:23:01,437 [root] DEBUG: 4484: Interactive desktop - injecting Explorer Shell
2026-05-28 21:23:01,445 [root] DEBUG: 4484: YaraInit: Compiled 44 rule files
2026-05-28 21:23:01,451 [root] DEBUG: 4484: YaraInit: Compiled rules saved to file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:23:01,488 [root] DEBUG: 4484: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:23:01,489 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-28 21:23:01,539 [root] DEBUG: 4484: Monitor initialised: 64-bit capemon loaded in process 4484 at 0x00007FFF177F0000, thread 2564, image base 0x00007FF79BC10000, stack from 0x0000000009002000-0x0000000009010000
2026-05-28 21:23:01,541 [root] DEBUG: 4484: Commandline: C:\Windows\Explorer.EXE
2026-05-28 21:23:01,554 [root] DEBUG: 4484: Hooked 69 out of 69 functions
2026-05-28 21:23:01,585 [root] DEBUG: 4484: Syscall hook installed, syscall logging level 1
2026-05-28 21:23:01,592 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 21:23:01,593 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:01,594 [lib.api.process] INFO: Injected into 64-bit <Process 4484 explorer.exe>
2026-05-28 21:23:08,364 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00007FF79BC10000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF79BC79D10, thread 6148).
2026-05-28 21:23:08,366 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-28 21:23:08,404 [root] DEBUG: 4484: ProcessImageBase: Main module image at 0x00007FF79BC10000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:23:08,683 [root] INFO: Restarting WMI Service
2026-05-28 21:23:10,721 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 21:23:10,723 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 21:23:10,725 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 21:23:10,729 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 5392
2026-05-28 21:23:10,730 [lib.api.process] INFO: Monitor config for process 5392: C:\lpw_albt\dll\5392.ini
2026-05-28 21:23:10,733 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:10,735 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:10,742 [root] DEBUG: Loader: Injecting process 5392 (thread 3256) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:10,742 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:10,742 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:10,744 [lib.api.process] INFO: Injected into 64-bit <Process 5392 msedge.exe>
2026-05-28 21:23:12,754 [lib.api.process] INFO: Successfully resumed process with pid 5392
2026-05-28 21:23:12,829 [root] DEBUG: 5392: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:23:12,830 [root] DEBUG: 5392: Disabling sleep skipping.
2026-05-28 21:23:12,830 [root] DEBUG: 5392: Interactive desktop enabled.
2026-05-28 21:23:12,831 [root] DEBUG: 5392: Dropped file limit defaulting to 100.
2026-05-28 21:23:12,839 [root] DEBUG: 5392: Edge-specific hook-set enabled.
2026-05-28 21:23:12,841 [root] DEBUG: 5392: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:23:12,852 [root] DEBUG: 5392: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:23:12,853 [root] DEBUG: 5392: Monitor initialised: 64-bit capemon loaded in process 5392 at 0x00007FFF177F0000, thread 3256, image base 0x00007FF7F5380000, stack from 0x00000027139F4000-0x0000002713A00000
2026-05-28 21:23:12,853 [root] DEBUG: 5392: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-28 21:23:12,862 [root] DEBUG: 5392: Hooked 2 out of 2 functions
2026-05-28 21:23:12,897 [root] DEBUG: 5392: Syscall hook installed, syscall logging level 1
2026-05-28 21:23:12,902 [root] DEBUG: 5392: RestoreHeaders: Restored original import table.
2026-05-28 21:23:12,902 [root] INFO: Loaded monitor into process with pid 5392
2026-05-28 21:23:12,906 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:23:12,912 [root] DEBUG: 5392: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 21:23:12,913 [root] DEBUG: 5392: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:23:12,914 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 21:23:12,914 [root] DEBUG: 5392: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:23:12,915 [root] DEBUG: 5392: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 21:23:12,916 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 21:23:13,051 [root] DEBUG: 5392: DLL loaded at 0x00007FFF453C0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-28 21:23:13,053 [root] DEBUG: 5392: DLL loaded at 0x00007FFEFE540000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 21:23:13,055 [root] DEBUG: 5392: DLL loaded at 0x00007FFF45010000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-28 21:23:13,057 [root] DEBUG: 5392: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:23:13,062 [root] DEBUG: 5392: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:23:13,063 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 5232: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:13,063 [root] DEBUG: 5392: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:23:13,064 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 5232
2026-05-28 21:23:13,065 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 5232
2026-05-28 21:23:13,065 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4D390000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-28 21:23:13,066 [root] DEBUG: 5392: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:23:13,067 [root] DEBUG: 5392: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:23:13,071 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-28 21:23:13,072 [root] DEBUG: 5392: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 21:23:13,073 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-28 21:23:13,074 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 21:23:13,075 [root] DEBUG: 5392: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:23:13,075 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4D320000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-28 21:23:13,076 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 21:23:13,077 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 21:23:13,077 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 21:23:13,077 [root] DEBUG: 5392: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 21:23:13,078 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 21:23:13,078 [root] DEBUG: 5392: DLL loaded at 0x00007FFF15300000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-28 21:23:13,078 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4D2E0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-28 21:23:13,079 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 21:23:13,080 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 21:23:13,081 [root] DEBUG: 5392: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-28 21:23:13,083 [root] DEBUG: 5392: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:23:13,083 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 21:23:13,084 [root] DEBUG: 5392: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-28 21:23:13,085 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-28 21:23:13,092 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4D370000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-28 21:23:13,093 [root] DEBUG: 5392: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 21:23:13,094 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-28 21:23:13,095 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 21:23:13,095 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 21:23:13,096 [root] DEBUG: 5392: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-28 21:23:13,099 [root] DEBUG: 5392: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-28 21:23:13,100 [root] DEBUG: 5392: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:23:13,101 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:23:13,102 [root] DEBUG: 5392: DLL loaded at 0x00007FFF569F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-28 21:23:13,102 [root] DEBUG: 5392: DLL loaded at 0x00007FFF52960000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-28 21:23:13,103 [root] DEBUG: 5392: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 21:23:13,104 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 21:23:13,105 [root] DEBUG: 5392: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 21:23:13,105 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-28 21:23:13,106 [root] DEBUG: 5392: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 21:23:13,107 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 21:23:13,107 [root] DEBUG: 5392: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-28 21:23:13,110 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 21:23:13,111 [root] DEBUG: 5392: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 21:23:13,112 [root] DEBUG: 5392: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:23:13,112 [root] DEBUG: 5392: DLL loaded at 0x00007FFF54170000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 21:23:13,113 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4B680000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 21:23:13,115 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-28 21:23:13,116 [root] DEBUG: 5392: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 21:23:13,118 [root] DEBUG: 5392: DLL loaded at 0x00007FFF45580000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-28 21:23:13,119 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 21:23:13,121 [root] DEBUG: 5392: DLL loaded at 0x00007FFF52420000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-28 21:23:13,124 [root] DEBUG: 5392: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-28 21:23:13,125 [root] DEBUG: 5392: DLL loaded at 0x00007FFF51A60000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 21:23:13,125 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4AF10000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 21:23:13,125 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4BFB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 21:23:13,127 [root] DEBUG: 5392: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-28 21:23:13,130 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-28 21:23:13,131 [root] DEBUG: 5392: DLL loaded at 0x00007FFF515E0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-28 21:23:13,131 [root] DEBUG: 5392: DLL loaded at 0x00007FFF51600000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-28 21:23:13,132 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 21:23:13,133 [root] DEBUG: 5392: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-28 21:23:13,149 [root] DEBUG: 5392: DLL loaded at 0x00007FFF52560000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-28 21:23:13,162 [root] DEBUG: 5392: DLL loaded at 0x00007FFF15A80000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-28 21:23:13,172 [root] DEBUG: 5392: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 21:23:13,172 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 2536: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:13,173 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 2536
2026-05-28 21:23:13,174 [root] DEBUG: 5392: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-28 21:23:13,175 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 2536
2026-05-28 21:23:13,177 [root] DEBUG: 5392: caller_dispatch: Added region at 0x00007FF7F5380000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7F5477D66, thread 400).
2026-05-28 21:23:13,182 [root] DEBUG: 5392: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:23:13,185 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 3776: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:13,186 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 3776
2026-05-28 21:23:13,187 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 3776
2026-05-28 21:23:13,190 [root] DEBUG: 5392: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:23:13,196 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 7240: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:13,196 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 7240
2026-05-28 21:23:13,197 [root] DEBUG: 5392: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 21:23:13,197 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 7240
2026-05-28 21:23:13,208 [root] DEBUG: 5392: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 21:23:13,216 [root] DEBUG: 5392: DLL loaded at 0x00007FFF409A0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-28 21:23:13,243 [root] DEBUG: 5392: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-28 21:23:13,245 [root] DEBUG: 5392: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-28 21:23:13,245 [root] DEBUG: 5392: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-28 21:23:13,246 [root] DEBUG: 5392: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-28 21:23:13,266 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4D250000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-28 21:23:13,280 [root] DEBUG: 5392: DLL loaded at 0x00007FFF55220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-28 21:23:13,287 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 8860: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:13,288 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 1112: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:13,288 [root] DEBUG: 5392: DLL loaded at 0x00007FFF43990000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-28 21:23:13,289 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 8860
2026-05-28 21:23:13,289 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 1112
2026-05-28 21:23:13,289 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 8860
2026-05-28 21:23:13,290 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 1112
2026-05-28 21:23:13,291 [root] DEBUG: 5392: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-28 21:23:13,356 [root] DEBUG: 5392: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-28 21:23:13,372 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4CFA0000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1e000 bytes).
2026-05-28 21:23:13,374 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4D010000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Domain Actions\3.0.0.18\domain_actions (0x17000 bytes).
2026-05-28 21:23:13,397 [root] DEBUG: 5392: DLL loaded at 0x00007FFF3F8B0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-28 21:23:13,411 [root] DEBUG: 5392: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 21:23:13,414 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 21:23:13,417 [root] DEBUG: 5392: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-28 21:23:13,422 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 21:23:13,424 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 21:23:13,451 [root] DEBUG: 5392: DLL loaded at 0x00007FFF3F7A0000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-28 21:23:14,637 [root] DEBUG: 5392: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 21:23:15,072 [root] DEBUG: 5392: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:23:15,077 [root] DEBUG: 5392: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:23:18,300 [root] DEBUG: 5392: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-28 21:23:18,302 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 3720: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:18,303 [root] DEBUG: 5392: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-28 21:23:18,304 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 1516: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:18,305 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 3720
2026-05-28 21:23:18,306 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 1516
2026-05-28 21:23:18,307 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 3720
2026-05-28 21:23:18,309 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 1516
2026-05-28 21:23:18,335 [root] DEBUG: 5392: DLL loaded at 0x00007FFEFC7E0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-28 21:23:18,359 [root] DEBUG: 5392: DLL loaded at 0x00007FFF572F0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-28 21:23:18,360 [root] DEBUG: 5392: DLL loaded at 0x00007FFF15610000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-28 21:23:18,361 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-28 21:23:18,363 [root] DEBUG: 5392: DLL loaded at 0x00007FFF12EA0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-28 21:23:18,366 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 21:23:18,366 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56250000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-28 21:23:18,367 [root] DEBUG: 5392: DLL loaded at 0x00007FFF561E0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-28 21:23:18,369 [root] DEBUG: 5392: DLL loaded at 0x00007FFF3F970000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-28 21:23:18,375 [root] DEBUG: 5392: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 21:23:18,376 [root] DEBUG: 5392: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 21:23:18,376 [root] DEBUG: 5392: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:23:18,390 [root] DEBUG: 5392: DLL loaded at 0x00007FFF46400000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-28 21:23:18,396 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 968: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF681070000
2026-05-28 21:23:18,396 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 968
2026-05-28 21:23:18,397 [lib.api.process] INFO: Monitor config for process 968: C:\lpw_albt\dll\968.ini
2026-05-28 21:23:18,397 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:18,765 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:23:18,766 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:23:18,766 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:23:18,767 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:23:18,767 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:23:18,767 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:23:18,767 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:23:18,767 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:23:18,771 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:18,775 [root] DEBUG: Loader: Injecting process 968 (thread 2060) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:18,775 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:18,776 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:18,777 [lib.api.process] INFO: Injected into 64-bit <Process 968 identity_helper.exe>
2026-05-28 21:23:18,781 [root] DEBUG: 5392: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 21:23:18,784 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4CBD0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 21:23:18,787 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 2412: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF681070000
2026-05-28 21:23:18,787 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 2412
2026-05-28 21:23:18,788 [lib.api.process] INFO: Monitor config for process 2412: C:\lpw_albt\dll\2412.ini
2026-05-28 21:23:18,789 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:18,790 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4F950000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-28 21:23:18,814 [root] DEBUG: 5392: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 21:23:18,815 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4F740000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-28 21:23:18,827 [root] DEBUG: 5392: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-28 21:23:18,850 [root] DEBUG: 5392: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-28 21:23:18,851 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-28 21:23:18,851 [root] DEBUG: 5392: DLL loaded at 0x00007FFF50370000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-28 21:23:18,852 [root] DEBUG: 5392: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 21:23:18,853 [root] DEBUG: 5392: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-28 21:23:18,854 [root] DEBUG: 5392: DLL loaded at 0x00007FFF45050000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-28 21:23:18,859 [root] DEBUG: 5392: DLL loaded at 0x00007FFF56D00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-28 21:23:18,869 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:23:18,869 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:23:18,869 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:23:18,869 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:23:18,869 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:23:18,869 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:23:18,870 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:23:18,870 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:23:18,871 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:18,875 [root] DEBUG: Loader: Injecting process 2412 (thread 5328) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:18,876 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:18,876 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:18,877 [lib.api.process] INFO: Injected into 64-bit <Process 2412 identity_helper.exe>
2026-05-28 21:23:18,879 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 2412
2026-05-28 21:23:18,879 [lib.api.process] INFO: Monitor config for process 2412: C:\lpw_albt\dll\2412.ini
2026-05-28 21:23:18,879 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:18,952 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:23:18,952 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:23:18,953 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:23:18,953 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:23:18,953 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:23:18,953 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:23:18,953 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:23:18,953 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:23:18,955 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:18,959 [root] DEBUG: Loader: Injecting process 2412 (thread 5328) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:18,960 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:23:18,960 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:18,963 [lib.api.process] INFO: Injected into 64-bit <Process 2412 identity_helper.exe>
2026-05-28 21:23:18,972 [root] DEBUG: 2412: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:23:18,973 [root] DEBUG: 2412: Interactive desktop enabled.
2026-05-28 21:23:18,973 [root] DEBUG: 2412: Dropped file limit defaulting to 100.
2026-05-28 21:23:18,979 [root] DEBUG: 2412: Disabling sleep skipping.
2026-05-28 21:23:18,981 [root] DEBUG: 2412: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:23:18,993 [root] DEBUG: 2412: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:23:18,994 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FF681070000, size 0x28b4d8
2026-05-28 21:23:19,013 [root] DEBUG: 2412: Monitor initialised: 64-bit capemon loaded in process 2412 at 0x00007FFF177F0000, thread 5328, image base 0x00007FF681070000, stack from 0x000000F2CDB64000-0x000000F2CDB70000
2026-05-28 21:23:19,014 [root] DEBUG: 2412: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5968,i,11133356123816338225,8401957050936449771,524288 --field-trial-handle=2396,i,5403840534169548923,5821839021258923942,262144 --variations-seed-version --pseudonymization-salt-handle=2400,i,5505900672474647929,207175341806969212
2026-05-28 21:23:19,014 [root] DEBUG: 2412: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-28 21:23:19,024 [root] DEBUG: 2412: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:23:19,048 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:23:19,048 [root] DEBUG: 2412: set_hooks: Unable to hook LockResource
2026-05-28 21:23:19,054 [root] DEBUG: 2412: Hooked 627 out of 628 functions
2026-05-28 21:23:19,068 [root] DEBUG: 2412: Syscall hook installed, syscall logging level 1
2026-05-28 21:23:19,073 [root] DEBUG: 2412: RestoreHeaders: Restored original import table.
2026-05-28 21:23:19,074 [root] INFO: Loaded monitor into process with pid 2412
2026-05-28 21:23:19,074 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FFF18100000, size 0x4b9994
2026-05-28 21:23:19,112 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FFF18100000, size 0x4b9994
2026-05-28 21:23:19,138 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FFF18100000, size 0x4b9994
2026-05-28 21:23:19,166 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FFF18100000, size 0x4b9994
2026-05-28 21:23:19,192 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FFF18100000, size 0x4b9994
2026-05-28 21:23:19,216 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FFF18100000, size 0x4b9994
2026-05-28 21:23:19,241 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FFF18100000, size 0x4b9994
2026-05-28 21:23:19,270 [root] DEBUG: 2412: caller_dispatch: Added region at 0x00007FFF18100000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF182FF156, thread 5328).
2026-05-28 21:23:19,271 [root] DEBUG: 2412: caller_dispatch: Scanning calling region at 0x00007FFF18100000...
2026-05-28 21:23:19,276 [root] DEBUG: 2412: ProcessTrackedRegion: Region at 0x00007FFF18100000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-28 21:23:19,278 [root] DEBUG: 2412: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:23:19,299 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FF681070000, size 0x28b4d8
2026-05-28 21:23:19,315 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FF681070000, size 0x28b4d8
2026-05-28 21:23:19,331 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FF681070000, size 0x28b4d8
2026-05-28 21:23:19,346 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FF681070000, size 0x28b4d8
2026-05-28 21:23:19,361 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FF681070000, size 0x28b4d8
2026-05-28 21:23:19,376 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FF681070000, size 0x28b4d8
2026-05-28 21:23:19,392 [root] DEBUG: 2412: caller_dispatch: Added region at 0x00007FF681070000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF681164096, thread 5328).
2026-05-28 21:23:19,393 [root] DEBUG: 2412: YaraScan: Scanning 0x00007FF681070000, size 0x28b4d8
2026-05-28 21:23:19,410 [root] DEBUG: 2412: ProcessImageBase: Main module image at 0x00007FF681070000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:23:19,415 [root] DEBUG: 2412: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:23:19,440 [root] DEBUG: 2412: DLL loaded at 0x0000023A8F000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-28 21:23:19,443 [root] DEBUG: 2412: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:23:19,446 [root] DEBUG: 2412: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 21:23:19,474 [root] DEBUG: 2412: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:23:19,480 [root] DEBUG: 2412: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:23:19,483 [root] DEBUG: 2412: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:23:19,484 [root] DEBUG: 2412: DLL loaded at 0x00007FFF52860000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-28 21:23:19,484 [root] DEBUG: 2412: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 21:23:19,484 [root] DEBUG: 2412: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-28 21:23:19,491 [root] DEBUG: 2412: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 21:23:19,493 [root] DEBUG: 2412: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 21:23:19,499 [root] DEBUG: 2412: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:23:19,500 [root] DEBUG: 2412: DLL loaded at 0x0000023AA4BD0000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-28 21:23:19,501 [root] DEBUG: 2412: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 21:23:19,506 [lib.api.process] INFO: Monitor config for process 832: C:\lpw_albt\dll\832.ini
2026-05-28 21:23:19,507 [root] DEBUG: 2412: DLL loaded at 0x00007FFF46AE0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-28 21:23:19,510 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:19,511 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:19,514 [root] DEBUG: 2412: DLL loaded at 0x00007FFF566C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-28 21:23:19,515 [root] DEBUG: 2412: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 21:23:19,516 [root] DEBUG: Loader: Injecting process 832 with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:19,518 [root] DEBUG: 832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:23:19,518 [root] DEBUG: 832: Disabling sleep skipping.
2026-05-28 21:23:19,518 [root] DEBUG: 832: Interactive desktop enabled.
2026-05-28 21:23:19,519 [root] DEBUG: 832: Dropped file limit defaulting to 100.
2026-05-28 21:23:19,520 [root] DEBUG: 832: Services hook set enabled
2026-05-28 21:23:19,521 [root] DEBUG: 832: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:23:19,528 [root] DEBUG: 2412: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 21:23:19,532 [root] DEBUG: 832: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:23:19,533 [root] DEBUG: 832: Monitor initialised: 64-bit capemon loaded in process 832 at 0x00007FFF177F0000, thread 1172, image base 0x00007FF7BF220000, stack from 0x000000CCA7AF4000-0x000000CCA7B00000
2026-05-28 21:23:19,533 [root] DEBUG: 832: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 21:23:19,537 [root] DEBUG: 2412: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-28 21:23:19,540 [root] DEBUG: 2412: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-28 21:23:19,542 [root] DEBUG: 2412: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-28 21:23:19,544 [root] DEBUG: 832: Hooked 69 out of 69 functions
2026-05-28 21:23:19,545 [root] INFO: Loaded monitor into process with pid 832
2026-05-28 21:23:19,545 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 21:23:19,546 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:19,547 [lib.api.process] INFO: Injected into 64-bit <Process 832 svchost.exe>
2026-05-28 21:23:21,571 [root] DEBUG: 2412: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 21:23:21,574 [root] DEBUG: 2412: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 21:23:21,578 [root] DEBUG: 2412: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:23:21,605 [root] DEBUG: 2412: DLL loaded at 0x00007FFF4B780000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 21:23:21,608 [root] DEBUG: 2412: DLL loaded at 0x00007FFF4B840000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 21:23:21,609 [root] DEBUG: 2412: DLL loaded at 0x00007FFF43150000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 21:23:21,614 [root] DEBUG: 2412: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 21:23:21,627 [root] DEBUG: 2412: DLL loaded at 0x00007FFF4F6E0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-28 21:23:21,637 [root] DEBUG: 2412: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:23:21,670 [root] DEBUG: 2412: DLL loaded at 0x00007FFF3D7B0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-28 21:23:21,689 [root] DEBUG: 2412: DLL loaded at 0x00007FFF55EF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-28 21:23:21,689 [root] DEBUG: 2412: DLL loaded at 0x00007FFF53070000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-28 21:23:21,694 [root] DEBUG: 2412: DLL loaded at 0x00007FFF48B40000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-28 21:23:21,694 [root] DEBUG: 2412: DLL loaded at 0x00007FFF3D6A0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 21:23:21,706 [root] DEBUG: 2412: DLL loaded at 0x00007FFF43060000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-28 21:23:21,737 [root] DEBUG: 2412: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 21:23:21,738 [root] DEBUG: 2412: DLL loaded at 0x00007FFF56FA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-28 21:23:21,739 [root] DEBUG: 2412: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:23:21,740 [root] DEBUG: 2412: DLL loaded at 0x00007FFF4C520000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 21:23:21,741 [root] DEBUG: 2412: DLL loaded at 0x00007FFF43DD0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-28 21:23:21,796 [root] DEBUG: 2412: DLL loaded at 0x00007FFF3D810000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-28 21:23:21,817 [root] DEBUG: 2412: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-28 21:23:21,844 [root] DEBUG: 2412: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 21:23:29,483 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2748: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-28 21:23:29,485 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2748
2026-05-28 21:23:29,485 [lib.api.process] INFO: Monitor config for process 2748: C:\lpw_albt\dll\2748.ini
2026-05-28 21:23:29,487 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:29,488 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:29,493 [root] DEBUG: Loader: Injecting process 2748 (thread 1228) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,493 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:29,493 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,495 [lib.api.process] INFO: Injected into 64-bit <Process 2748 backgroundTaskHost.exe>
2026-05-28 21:23:29,496 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2748
2026-05-28 21:23:29,496 [lib.api.process] INFO: Monitor config for process 2748: C:\lpw_albt\dll\2748.ini
2026-05-28 21:23:29,496 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:29,497 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:29,502 [root] DEBUG: Loader: Injecting process 2748 (thread 1228) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,502 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:23:29,502 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,503 [lib.api.process] INFO: Injected into 64-bit <Process 2748 backgroundTaskHost.exe>
2026-05-28 21:23:29,504 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2748
2026-05-28 21:23:29,504 [lib.api.process] INFO: Monitor config for process 2748: C:\lpw_albt\dll\2748.ini
2026-05-28 21:23:29,505 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:29,505 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:29,510 [root] DEBUG: Loader: Injecting process 2748 with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,510 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 1228, handle 0x120
2026-05-28 21:23:29,510 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:23:29,511 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,512 [lib.api.process] INFO: Injected into 64-bit <Process 2748 backgroundTaskHost.exe>
2026-05-28 21:23:29,517 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 1040: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-28 21:23:29,518 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 1040
2026-05-28 21:23:29,518 [lib.api.process] INFO: Monitor config for process 1040: C:\lpw_albt\dll\1040.ini
2026-05-28 21:23:29,519 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:29,520 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:29,524 [root] DEBUG: Loader: Injecting process 1040 (thread 2500) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,525 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:29,525 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,526 [lib.api.process] INFO: Injected into 64-bit <Process 1040 backgroundTaskHost.exe>
2026-05-28 21:23:29,527 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 1040
2026-05-28 21:23:29,527 [lib.api.process] INFO: Monitor config for process 1040: C:\lpw_albt\dll\1040.ini
2026-05-28 21:23:29,527 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:29,528 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:29,533 [root] DEBUG: Loader: Injecting process 1040 (thread 2500) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,533 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:23:29,534 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,536 [lib.api.process] INFO: Injected into 64-bit <Process 1040 backgroundTaskHost.exe>
2026-05-28 21:23:29,537 [root] INFO: Process with pid 1040 has terminated
2026-05-28 21:23:29,541 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 2148: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-28 21:23:29,541 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2148
2026-05-28 21:23:29,541 [lib.api.process] INFO: Monitor config for process 2148: C:\lpw_albt\dll\2148.ini
2026-05-28 21:23:29,542 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:29,543 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:29,547 [root] DEBUG: Loader: Injecting process 2148 (thread 4552) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,547 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:29,548 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,549 [lib.api.process] INFO: Injected into 64-bit <Process 2148 backgroundTaskHost.exe>
2026-05-28 21:23:29,550 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 2148
2026-05-28 21:23:29,550 [lib.api.process] INFO: Monitor config for process 2148: C:\lpw_albt\dll\2148.ini
2026-05-28 21:23:29,550 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:29,551 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:29,556 [root] DEBUG: Loader: Injecting process 2148 (thread 4552) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,556 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:23:29,557 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:29,558 [lib.api.process] INFO: Injected into 64-bit <Process 2148 backgroundTaskHost.exe>
2026-05-28 21:23:29,559 [root] INFO: Process with pid 2148 has terminated
2026-05-28 21:23:31,930 [root] INFO: Process with pid 2412 has terminated
2026-05-28 21:23:31,931 [root] DEBUG: 2412: NtTerminateProcess hook: Attempting to dump process 2412
2026-05-28 21:23:31,934 [root] DEBUG: 2412: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:23:40,073 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 9160: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:40,074 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 9160
2026-05-28 21:23:40,075 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 9160
2026-05-28 21:23:41,101 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 5812: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:41,103 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 5812
2026-05-28 21:23:41,103 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 5812
2026-05-28 21:23:43,074 [root] DEBUG: 5392: DLL loaded at 0x00007FFF3FB50000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-28 21:23:43,150 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 2636: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:23:43,151 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 2636
2026-05-28 21:23:43,152 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 2636
2026-05-28 21:23:45,376 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FB10000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 21:23:45,415 [lib.api.process] INFO: Monitor config for process 4484: C:\lpw_albt\dll\4484.ini
2026-05-28 21:23:45,416 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:45,416 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:45,421 [root] DEBUG: Loader: Injecting process 4484 with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:45,421 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00000000031B0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00000000031B0044, thread 6772).
2026-05-28 21:23:45,422 [root] DEBUG: 4484: DumpPEsInRange: Scanning range 0x00000000031B0000 - 0x00000000031B0135.
2026-05-28 21:23:45,423 [root] DEBUG: 4484: ScanForDisguisedPE: Size too small: 0x135 bytes
2026-05-28 21:23:45,425 [lib.common.results] INFO: Uploading file C:\NPOoaUZdpr\CAPE\4484_173434523129552026 to CAPE\3d0eeeb260cf5be84ae62fd0ac3ea073b00a3168cac0d4283713134d80924799; Size is 309; Max size: 100000000
2026-05-28 21:23:45,429 [root] DEBUG: 4484: DumpMemory: Payload successfully created: C:\NPOoaUZdpr\CAPE\4484_173434523129552026 (size 309 bytes)
2026-05-28 21:23:45,430 [root] DEBUG: 4484: DumpRegion: Dumped entire allocation from 0x00000000031B0000, size 4096 bytes.
2026-05-28 21:23:45,430 [root] DEBUG: 4484: ProcessTrackedRegion: Dumped region at 0x00000000031B0000.
2026-05-28 21:23:45,431 [root] DEBUG: 4484: YaraScan: Scanning 0x00000000031B0000, size 0x135
2026-05-28 21:23:45,432 [root] DEBUG: 4484: Monitor config - unrecognised key host-ip.
2026-05-28 21:23:45,432 [root] DEBUG: 4484: Monitor config - unrecognised key host-port.
2026-05-28 21:23:45,433 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:23:45,433 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-28 21:23:45,451 [root] DEBUG: 4484: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:23:45,498 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:23:45,499 [root] DEBUG: 4484: set_hooks: Unable to hook LockResource
2026-05-28 21:23:45,521 [root] DEBUG: 4484: Hooked 627 out of 628 functions
2026-05-28 21:23:45,549 [root] INFO: Loaded monitor into process with pid 4484
2026-05-28 21:23:45,552 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 21:23:45,552 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:47,590 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 21:23:47,618 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 21:23:47,619 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3BBD0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 21:23:47,631 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F6F0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 21:23:47,632 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F6F0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 21:23:47,664 [root] DEBUG: 4484: DLL loaded at 0x0000000012AE0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 21:23:47,666 [root] DEBUG: 4484: DLL loaded at 0x0000000012AE0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 21:23:47,907 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 21:23:48,177 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 21:23:48,188 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
2026-05-28 21:23:48,197 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9708: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:23:48,198 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9708
2026-05-28 21:23:48,198 [lib.api.process] INFO: Monitor config for process 9708: C:\lpw_albt\dll\9708.ini
2026-05-28 21:23:48,199 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:48,201 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:48,206 [root] DEBUG: Loader: Injecting process 9708 (thread 9712) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:48,207 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:48,209 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:48,211 [lib.api.process] INFO: Injected into 64-bit <Process 9708 dllhost.exe>
2026-05-28 21:23:48,212 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 9708
2026-05-28 21:23:48,212 [lib.api.process] INFO: Monitor config for process 9708: C:\lpw_albt\dll\9708.ini
2026-05-28 21:23:48,213 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:48,214 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:48,219 [root] DEBUG: Loader: Injecting process 9708 (thread 9712) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:48,220 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:48,223 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:48,226 [lib.api.process] INFO: Injected into 64-bit <Process 9708 dllhost.exe>
2026-05-28 21:23:48,236 [root] DEBUG: 9708: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:23:48,237 [root] DEBUG: 9708: Interactive desktop enabled.
2026-05-28 21:23:48,237 [root] DEBUG: 9708: Dropped file limit defaulting to 100.
2026-05-28 21:23:48,240 [root] DEBUG: 9708: Disabling sleep skipping.
2026-05-28 21:23:48,243 [root] DEBUG: 9708: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:23:48,257 [root] DEBUG: 9708: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:23:48,258 [root] DEBUG: 9708: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:23:48,260 [root] DEBUG: 9708: Monitor initialised: 64-bit capemon loaded in process 9708 at 0x00007FFF177F0000, thread 9712, image base 0x00007FF6706B0000, stack from 0x00000057BC5E4000-0x00000057BC5F0000
2026-05-28 21:23:48,261 [root] DEBUG: 9708: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 21:23:48,271 [root] DEBUG: 9708: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:23:48,300 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:23:48,301 [root] DEBUG: 9708: set_hooks: Unable to hook LockResource
2026-05-28 21:23:48,306 [root] DEBUG: 9708: Hooked 627 out of 628 functions
2026-05-28 21:23:48,309 [root] DEBUG: 9708: Syscall hook installed, syscall logging level 1
2026-05-28 21:23:48,313 [root] DEBUG: 9708: RestoreHeaders: Restored original import table.
2026-05-28 21:23:48,314 [root] INFO: Loaded monitor into process with pid 9708
2026-05-28 21:23:48,315 [root] DEBUG: 9708: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 9712).
2026-05-28 21:23:48,315 [root] DEBUG: 9708: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:23:48,317 [root] DEBUG: 9708: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:23:48,320 [root] DEBUG: 9708: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:23:48,321 [root] DEBUG: 9708: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:23:48,324 [root] DEBUG: 9708: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:23:48,341 [root] DEBUG: 9708: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:23:48,361 [root] DEBUG: 9708: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:23:48,361 [root] DEBUG: 9708: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 21:23:48,371 [root] DEBUG: 9708: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 21:23:48,393 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-28 21:23:50,427 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:23:50,428 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 8044, handle 0x1114: Error obtaining target process name
2026-05-28 21:23:50,428 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:23:50,429 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6136, handle 0x2724: Error obtaining target process name
2026-05-28 21:23:50,429 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:23:50,429 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5624, handle 0x1f80: Error obtaining target process name
2026-05-28 21:23:50,430 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:23:50,430 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5392, handle 0xff8: Error obtaining target process name
2026-05-28 21:23:50,431 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:23:50,431 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 5128, handle 0x242c: Error obtaining target process name
2026-05-28 21:23:50,432 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 21:23:50,432 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 6400, handle 0xea4: Error obtaining target process name
2026-05-28 21:23:51,438 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3E240000: C:\Windows\system32\SearchFolder (0x6a000 bytes).
2026-05-28 21:23:51,439 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3E240000: C:\Windows\system32\SearchFolder (0x6a000 bytes).
2026-05-28 21:23:51,469 [root] DEBUG: 4484: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 21:23:51,470 [root] DEBUG: 4484: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 21:23:51,882 [root] DEBUG: 4484: DLL loaded at 0x000000000DD20000: C:\Windows\system32\mssvp (0x63000 bytes).
2026-05-28 21:23:51,883 [root] DEBUG: 4484: DLL loaded at 0x000000000DD20000: C:\Windows\system32\mssvp (0x63000 bytes).
2026-05-28 21:23:51,930 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms
2026-05-28 21:23:51,938 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\SavedPictures.library-ms
2026-05-28 21:23:51,945 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
2026-05-28 21:23:51,952 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\CameraRoll.library-ms
2026-05-28 21:23:51,959 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
2026-05-28 21:23:51,966 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
2026-05-28 21:23:52,211 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 21:23:52,212 [root] DEBUG: 4484: DLL loaded at 0x00007FFF47720000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 21:23:52,215 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 21:23:52,215 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F530000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 21:23:52,216 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FB30000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 21:23:52,217 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FB30000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 21:23:52,218 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F430000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 21:23:52,219 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4F430000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 21:23:52,219 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FB10000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 21:23:52,220 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3FB10000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 21:23:52,267 [root] DEBUG: 4484: DLL loaded at 0x00000000119F0000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 21:23:52,268 [root] DEBUG: 4484: DLL loaded at 0x00000000119F0000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 21:23:52,281 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F6C0000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 21:23:52,282 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F6C0000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 21:23:53,459 [root] INFO: Process with pid 9708 has terminated
2026-05-28 21:23:53,460 [root] DEBUG: 9708: NtTerminateProcess hook: Attempting to dump process 9708
2026-05-28 21:23:53,460 [root] DEBUG: 9708: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:23:54,566 [root] INFO: Added new file to list with pid 4484 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 21:23:54,634 [root] DEBUG: 4484: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 21:23:54,737 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11712: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-28 21:23:54,738 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11712
2026-05-28 21:23:54,739 [lib.api.process] INFO: Monitor config for process 11712: C:\lpw_albt\dll\11712.ini
2026-05-28 21:23:54,741 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:54,743 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:54,748 [root] DEBUG: Loader: Injecting process 11712 (thread 11716) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:54,749 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:54,750 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:54,751 [lib.api.process] INFO: Injected into 64-bit <Process 11712 dllhost.exe>
2026-05-28 21:23:54,753 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11712
2026-05-28 21:23:54,753 [lib.api.process] INFO: Monitor config for process 11712: C:\lpw_albt\dll\11712.ini
2026-05-28 21:23:54,754 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:23:54,759 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:23:54,763 [root] DEBUG: Loader: Injecting process 11712 (thread 11716) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:54,764 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:23:54,765 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:23:54,767 [lib.api.process] INFO: Injected into 64-bit <Process 11712 dllhost.exe>
2026-05-28 21:23:54,773 [root] DEBUG: 11712: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:23:54,774 [root] DEBUG: 11712: Interactive desktop enabled.
2026-05-28 21:23:54,774 [root] DEBUG: 11712: Dropped file limit defaulting to 100.
2026-05-28 21:23:54,775 [root] DEBUG: 11712: Disabling sleep skipping.
2026-05-28 21:23:54,777 [root] DEBUG: 11712: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:23:54,788 [root] DEBUG: 11712: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:23:54,789 [root] DEBUG: 11712: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:23:54,790 [root] DEBUG: 11712: Monitor initialised: 64-bit capemon loaded in process 11712 at 0x00007FFF177F0000, thread 11716, image base 0x00007FF6706B0000, stack from 0x00000033965C4000-0x00000033965D0000
2026-05-28 21:23:54,790 [root] DEBUG: 11712: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 21:23:54,800 [root] DEBUG: 11712: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:23:54,822 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:23:54,823 [root] DEBUG: 11712: set_hooks: Unable to hook LockResource
2026-05-28 21:23:54,830 [root] DEBUG: 11712: Hooked 627 out of 628 functions
2026-05-28 21:23:54,831 [root] DEBUG: 11712: Syscall hook installed, syscall logging level 1
2026-05-28 21:23:54,837 [root] DEBUG: 11712: RestoreHeaders: Restored original import table.
2026-05-28 21:23:54,837 [root] INFO: Loaded monitor into process with pid 11712
2026-05-28 21:23:54,838 [root] DEBUG: 11712: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 11716).
2026-05-28 21:23:54,839 [root] DEBUG: 11712: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-28 21:23:54,840 [root] DEBUG: 11712: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:23:54,842 [root] DEBUG: 11712: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:23:54,843 [root] DEBUG: 11712: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:23:54,845 [root] DEBUG: 11712: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:23:54,859 [root] DEBUG: 11712: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 21:23:54,874 [root] DEBUG: 11712: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:23:54,875 [root] DEBUG: 11712: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 21:23:54,882 [root] DEBUG: 11712: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 21:23:54,893 [root] DEBUG: 11712: DLL loaded at 0x00007FFF51B20000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 21:23:54,894 [root] DEBUG: 11712: DLL loaded at 0x00007FFF47790000: C:\Windows\system32\PhotoMetadataHandler (0x84000 bytes).
2026-05-28 21:23:54,906 [root] DEBUG: 11712: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:23:56,836 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F2B0000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-28 21:23:56,837 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F2B0000: C:\Windows\SYSTEM32\CHARTV (0x25000 bytes).
2026-05-28 21:23:56,991 [root] DEBUG: 4484: api-cap: LdrpCallInitRoutine hook disabled due to count: 5000
2026-05-28 21:23:58,225 [root] DEBUG: 4484: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 21:23:58,330 [root] DEBUG: 4484: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 21:23:59,820 [root] DEBUG: 4484: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 21:23:59,977 [root] INFO: Process with pid 11712 has terminated
2026-05-28 21:23:59,978 [root] DEBUG: 11712: NtTerminateProcess hook: Attempting to dump process 11712
2026-05-28 21:23:59,979 [root] DEBUG: 11712: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:24:00,531 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 21:24:00,532 [root] DEBUG: 4484: DLL loaded at 0x00007FFF46F60000: C:\Windows\System32\Windows.Shell.ServiceHostBuilder (0x1d000 bytes).
2026-05-28 21:24:00,550 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE131000, size: 0x1000.
2026-05-28 21:24:00,556 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE121000, size: 0x1000.
2026-05-28 21:24:00,556 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE111000, size: 0x1000.
2026-05-28 21:24:00,558 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE101000, size: 0x1000.
2026-05-28 21:24:00,572 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE0F1000, size: 0x1000.
2026-05-28 21:24:00,581 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F290000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 21:24:00,582 [root] DEBUG: 4484: DLL loaded at 0x00007FFF3F290000: C:\Windows\system32\activationclient (0x12000 bytes).
2026-05-28 21:24:00,596 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 13528: C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe, ImageBase: 0x00007FF7A84D0000
2026-05-28 21:24:00,598 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 13528
2026-05-28 21:24:00,598 [lib.api.process] INFO: Monitor config for process 13528: C:\lpw_albt\dll\13528.ini
2026-05-28 21:24:00,600 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:00,602 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:00,607 [root] DEBUG: Loader: Injecting process 13528 (thread 13532) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:00,607 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:24:00,608 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:00,609 [lib.api.process] INFO: Injected into 64-bit <Process 13528 CHXSmartScreen.exe>
2026-05-28 21:24:00,610 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 13528
2026-05-28 21:24:00,611 [lib.api.process] INFO: Monitor config for process 13528: C:\lpw_albt\dll\13528.ini
2026-05-28 21:24:00,611 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:00,614 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:00,619 [root] DEBUG: Loader: Injecting process 13528 (thread 13532) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:00,620 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:24:00,620 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:00,621 [lib.api.process] INFO: Injected into 64-bit <Process 13528 CHXSmartScreen.exe>
2026-05-28 21:24:00,622 [root] INFO: Announced 64-bit process name: CHXSmartScreen.exe pid: 13528
2026-05-28 21:24:00,623 [lib.api.process] INFO: Monitor config for process 13528: C:\lpw_albt\dll\13528.ini
2026-05-28 21:24:00,623 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:00,625 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:00,629 [root] DEBUG: Loader: Injecting process 13528 with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:00,630 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 13532, handle 0xec
2026-05-28 21:24:00,631 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:24:00,631 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:00,633 [lib.api.process] INFO: Injected into 64-bit <Process 13528 CHXSmartScreen.exe>
2026-05-28 21:24:00,744 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 13724, handle 0x26f0: C:\Windows\System32\rundll32.exe
2026-05-28 21:24:01,066 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE0F0000.
2026-05-28 21:24:01,067 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:01,071 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-28 21:24:01,072 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:01,075 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE100000.
2026-05-28 21:24:01,077 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:01,078 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE110000.
2026-05-28 21:24:01,080 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:01,081 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-28 21:24:01,082 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:01,864 [root] DEBUG: 4484: api-cap: NtQueryKey hook disabled due to count: 5000
2026-05-28 21:24:01,881 [root] DEBUG: 4484: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 21:24:01,914 [root] DEBUG: 4484: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 21:24:01,946 [root] DEBUG: 4484: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-05-28 21:24:01,962 [root] DEBUG: 4484: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-28 21:24:02,273 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 5392 (handle 0x2ce8): 0x00007FF7F5380000.
2026-05-28 21:24:02,688 [root] DEBUG: 5392: CreateProcessHandler: Injection info set for new process 14276: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-28 21:24:02,689 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 14276
2026-05-28 21:24:02,690 [root] DEBUG: 5392: ProcessMessage: Skipping monitoring process 14276
2026-05-28 21:24:02,730 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 14328, handle 0x2894: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 21:24:02,735 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 14276, handle 0x2894: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 21:24:02,841 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 21:24:02,843 [lib.api.process] INFO: Monitor config for process 676: C:\lpw_albt\dll\676.ini
2026-05-28 21:24:02,845 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:02,847 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:02,857 [root] DEBUG: Loader: Injecting process 676 with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:02,878 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\676.ini to system path C:\676.ini
2026-05-28 21:24:02,880 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 676 C:\lpw_albt\dll\kgVUfOKq.dll
2026-05-28 21:24:02,882 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:02,884 [lib.api.process] INFO: Injected into 64-bit <Process 676 services.exe>
2026-05-28 21:24:02,912 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 2168, handle 0xe28: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 21:24:03,176 [root] INFO: Process with pid 5392 appears to have terminated
2026-05-28 21:24:03,429 [root] DEBUG: 4484: OpenProcessHandler: Injection info created for process 4936, handle 0x247c: C:\Windows\System32\services.exe
2026-05-28 21:24:04,082 [root] DEBUG: 676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:24:04,091 [root] DEBUG: 676: Disabling sleep skipping.
2026-05-28 21:24:04,091 [root] DEBUG: 676: Interactive desktop enabled.
2026-05-28 21:24:04,092 [root] DEBUG: 676: Dropped file limit defaulting to 100.
2026-05-28 21:24:04,096 [root] DEBUG: 676: Services hook set enabled
2026-05-28 21:24:04,115 [root] DEBUG: 676: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:24:04,116 [root] DEBUG: 676: Monitor initialised: 64-bit capemon loaded in process 676 at 0x00007FFF139A0000, thread 400, image base 0x00007FF7839A0000, stack from 0x000000F2F0071000-0x000000F2F0080000
2026-05-28 21:24:04,116 [root] DEBUG: 676: Commandline: C:\Windows\system32\services.exe
2026-05-28 21:24:04,143 [root] DEBUG: 676: Hooked 69 out of 69 functions
2026-05-28 21:24:04,149 [root] INFO: Loaded monitor into process with pid 676
2026-05-28 21:24:05,933 [root] DEBUG: 676: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 21:24:05,934 [root] DEBUG: 676: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 21:24:05,937 [root] DEBUG: 676: DLL loaded at 0x00007FFF58070000: C:\Windows\system32\SHCORE (0xad000 bytes).
2026-05-28 21:24:05,938 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 1416: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe, ImageBase: 0x00007FF7DDDF0000
2026-05-28 21:24:05,940 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 1416
2026-05-28 21:24:05,940 [lib.api.process] INFO: Monitor config for process 1416: C:\lpw_albt\dll\1416.ini
2026-05-28 21:24:05,942 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:07,405 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:24:07,406 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:24:07,407 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:24:07,407 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:24:07,407 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:24:07,408 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:24:07,408 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:24:07,408 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:24:07,417 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:07,434 [root] DEBUG: Loader: Injecting process 1416 (thread 4828) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:07,434 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:24:07,435 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:07,436 [lib.api.process] INFO: Injected into 64-bit <Process 1416 elevation_service.exe>
2026-05-28 21:24:07,439 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 1416
2026-05-28 21:24:07,439 [lib.api.process] INFO: Monitor config for process 1416: C:\lpw_albt\dll\1416.ini
2026-05-28 21:24:07,439 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:08,131 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:24:08,132 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:24:08,133 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:24:08,133 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:24:08,133 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:24:08,134 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:24:08,134 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:24:08,134 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:24:08,146 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:08,151 [root] DEBUG: Loader: Injecting process 1416 (thread 4828) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:08,151 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:24:08,152 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:08,153 [lib.api.process] INFO: Injected into 64-bit <Process 1416 elevation_service.exe>
2026-05-28 21:24:08,154 [root] INFO: Announced 64-bit process name: elevation_service.exe pid: 1416
2026-05-28 21:24:08,155 [lib.api.process] INFO: Monitor config for process 1416: C:\lpw_albt\dll\1416.ini
2026-05-28 21:24:08,157 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:08,715 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-28 21:24:08,716 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-28 21:24:08,716 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-28 21:24:08,717 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-28 21:24:08,717 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-28 21:24:08,718 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-28 21:24:08,718 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-28 21:24:08,718 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-28 21:24:08,725 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:08,730 [root] DEBUG: Loader: Injecting process 1416 with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:08,731 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 4828, handle 0x120
2026-05-28 21:24:08,732 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:24:08,732 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:08,735 [lib.api.process] INFO: Injected into 64-bit <Process 1416 elevation_service.exe>
2026-05-28 21:24:08,745 [root] DEBUG: 1416: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:24:08,746 [root] DEBUG: 1416: Interactive desktop enabled.
2026-05-28 21:24:08,747 [root] DEBUG: 1416: Dropped file limit defaulting to 100.
2026-05-28 21:24:08,755 [root] DEBUG: 1416: Disabling sleep skipping.
2026-05-28 21:24:08,757 [root] DEBUG: 1416: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:24:08,768 [root] DEBUG: 1416: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:24:08,770 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:08,795 [root] DEBUG: 1416: Monitor initialised: 64-bit capemon loaded in process 1416 at 0x00007FFF177F0000, thread 4828, image base 0x00007FF7DDDF0000, stack from 0x0000002E502F4000-0x0000002E50300000
2026-05-28 21:24:08,796 [root] DEBUG: 1416: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe"
2026-05-28 21:24:08,808 [root] DEBUG: 1416: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:24:08,831 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:24:08,832 [root] DEBUG: 1416: set_hooks: Unable to hook LockResource
2026-05-28 21:24:08,843 [root] DEBUG: 1416: Hooked 627 out of 628 functions
2026-05-28 21:24:08,866 [root] DEBUG: 1416: Syscall hook installed, syscall logging level 1
2026-05-28 21:24:08,880 [root] DEBUG: 1416: RestoreHeaders: Restored original import table.
2026-05-28 21:24:08,881 [root] INFO: Loaded monitor into process with pid 1416
2026-05-28 21:24:08,884 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:08,906 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:08,931 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:08,956 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:08,984 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:09,018 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:09,042 [root] DEBUG: 1416: caller_dispatch: Scanning calling region at 0x00007FF7DDDF0000...
2026-05-28 21:24:09,044 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:09,044 [root] DEBUG: 1416: caller_dispatch: Added region at 0x00007FF7DDDF0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF7DDF2B9D6, thread 4828).
2026-05-28 21:24:09,045 [root] DEBUG: 1416: YaraScan: Scanning 0x00007FF7DDDF0000, size 0x3bf4c0
2026-05-28 21:24:09,067 [root] DEBUG: 1416: ProcessImageBase: Main module image at 0x00007FF7DDDF0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:24:09,068 [root] DEBUG: 1416: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 21:24:09,070 [root] DEBUG: 1416: ProcessImageBase: Main module image at 0x00007FF7DDDF0000 unmodified (entropy change 8.288658e-06)
2026-05-28 21:24:09,075 [root] DEBUG: 1416: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:24:09,087 [root] DEBUG: 1416: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:24:09,099 [root] DEBUG: 1416: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:24:09,120 [root] DEBUG: 1416: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-28 21:24:09,173 [root] DEBUG: 1416: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-28 21:24:09,185 [root] DEBUG: 1416: NtTerminateProcess hook: Attempting to dump process 1416
2026-05-28 21:24:09,188 [root] DEBUG: 1416: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:24:09,232 [root] DEBUG: 1416: caller_dispatch: Added region at 0x00007FFF56FD0000 to tracked regions list (ntdll::NtClose returns to 0x00007FFF56FD419B, thread 4828).
2026-05-28 21:24:09,234 [root] DEBUG: 1416: caller_dispatch: Scanning calling region at 0x00007FFF56FD0000...
2026-05-28 21:24:09,251 [root] INFO: Process with pid 1416 has terminated
2026-05-28 21:24:10,306 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 21:24:10,307 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 21:24:10,315 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 14824: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF6A46D0000
2026-05-28 21:24:10,316 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 14824
2026-05-28 21:24:10,317 [lib.api.process] INFO: Monitor config for process 14824: C:\lpw_albt\dll\14824.ini
2026-05-28 21:24:10,318 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:10,321 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:10,326 [root] DEBUG: Loader: Injecting process 14824 (thread 14828) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:10,326 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:24:10,328 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:10,329 [lib.api.process] INFO: Injected into 64-bit <Process 14824 SecurityHealthHost.exe>
2026-05-28 21:24:10,331 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 14824
2026-05-28 21:24:10,331 [lib.api.process] INFO: Monitor config for process 14824: C:\lpw_albt\dll\14824.ini
2026-05-28 21:24:10,332 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:10,334 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:10,338 [root] DEBUG: Loader: Injecting process 14824 (thread 14828) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:10,339 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:24:10,340 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:10,341 [lib.api.process] INFO: Injected into 64-bit <Process 14824 SecurityHealthHost.exe>
2026-05-28 21:24:10,349 [root] DEBUG: 14824: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 21:24:10,350 [root] DEBUG: 14824: Interactive desktop enabled.
2026-05-28 21:24:10,351 [root] DEBUG: 14824: Dropped file limit defaulting to 100.
2026-05-28 21:24:10,353 [root] DEBUG: 14824: Disabling sleep skipping.
2026-05-28 21:24:10,354 [root] DEBUG: 14824: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-28 21:24:10,366 [root] DEBUG: 14824: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-28 21:24:10,367 [root] DEBUG: 14824: YaraScan: Scanning 0x00007FF6A46D0000, size 0x19174
2026-05-28 21:24:10,368 [root] DEBUG: 14824: Monitor initialised: 64-bit capemon loaded in process 14824 at 0x00007FFF177F0000, thread 14828, image base 0x00007FF6A46D0000, stack from 0x0000001071394000-0x00000010713A0000
2026-05-28 21:24:10,369 [root] DEBUG: 14824: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-28 21:24:10,379 [root] DEBUG: 14824: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-28 21:24:10,400 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 21:24:10,401 [root] DEBUG: 14824: set_hooks: Unable to hook LockResource
2026-05-28 21:24:10,407 [root] DEBUG: 14824: Hooked 627 out of 628 functions
2026-05-28 21:24:10,409 [root] DEBUG: 14824: Syscall hook installed, syscall logging level 1
2026-05-28 21:24:10,413 [root] DEBUG: 14824: RestoreHeaders: Restored original import table.
2026-05-28 21:24:10,415 [root] INFO: Loaded monitor into process with pid 14824
2026-05-28 21:24:10,416 [root] DEBUG: 14824: caller_dispatch: Added region at 0x00007FF6A46D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6A46DD3B2, thread 14828).
2026-05-28 21:24:10,417 [root] DEBUG: 14824: YaraScan: Scanning 0x00007FF6A46D0000, size 0x19174
2026-05-28 21:24:10,419 [root] DEBUG: 14824: ProcessImageBase: Main module image at 0x00007FF6A46D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 21:24:10,422 [root] DEBUG: 14824: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 21:24:10,423 [root] DEBUG: 14824: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 21:24:10,425 [root] DEBUG: 14824: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 21:24:10,441 [root] DEBUG: 14824: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 21:24:10,442 [root] DEBUG: 14824: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 21:24:10,443 [root] DEBUG: 14824: DLL loaded at 0x00007FFF15180000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-28 21:24:10,458 [root] DEBUG: 14824: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-28 21:24:10,463 [root] DEBUG: 14824: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-28 21:24:10,478 [root] DEBUG: 14824: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 21:24:10,479 [root] DEBUG: 14824: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 21:24:10,480 [root] DEBUG: 14824: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-28 21:24:10,481 [root] DEBUG: 14824: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-28 21:24:10,482 [root] DEBUG: 14824: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 21:24:10,483 [root] DEBUG: 14824: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-28 21:24:10,492 [root] DEBUG: 14824: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-28 21:24:10,503 [root] DEBUG: 14824: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-28 21:24:10,577 [root] DEBUG: 14824: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-28 21:24:10,615 [root] DEBUG: 14824: NtTerminateProcess hook: Attempting to dump process 14824
2026-05-28 21:24:10,618 [root] DEBUG: 14824: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 21:24:10,630 [root] INFO: Process with pid 14824 has terminated
2026-05-28 21:24:10,633 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE130000.
2026-05-28 21:24:10,661 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE120000.
2026-05-28 21:24:10,666 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-28 21:24:10,666 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:10,669 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-28 21:24:10,670 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:10,684 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE130000.
2026-05-28 21:24:10,687 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE120000.
2026-05-28 21:24:10,691 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE120000.
2026-05-28 21:24:10,692 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:10,696 [root] DEBUG: 4484: FreeHandler: Address: 0x00007DF4AE130000.
2026-05-28 21:24:10,699 [root] DEBUG: 4484: ScanForNonZero: Error - Supplied size zero.
2026-05-28 21:24:10,699 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 15228: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF653640000
2026-05-28 21:24:10,701 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 15228
2026-05-28 21:24:10,701 [lib.api.process] INFO: Monitor config for process 15228: C:\lpw_albt\dll\15228.ini
2026-05-28 21:24:10,709 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:11,579 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:11,583 [root] DEBUG: Loader: Injecting process 15228 (thread 15232) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:11,585 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:24:11,585 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:11,587 [lib.api.process] INFO: Injected into 64-bit <Process 15228 ShellExperienceHost.exe>
2026-05-28 21:24:11,588 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 15228
2026-05-28 21:24:11,589 [lib.api.process] INFO: Monitor config for process 15228: C:\lpw_albt\dll\15228.ini
2026-05-28 21:24:11,589 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:12,518 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:12,523 [root] DEBUG: Loader: Injecting process 15228 (thread 15232) with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:12,524 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 21:24:12,524 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:12,526 [lib.api.process] INFO: Injected into 64-bit <Process 15228 ShellExperienceHost.exe>
2026-05-28 21:24:12,527 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 15228
2026-05-28 21:24:12,528 [lib.api.process] INFO: Monitor config for process 15228: C:\lpw_albt\dll\15228.ini
2026-05-28 21:24:12,529 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 21:24:13,529 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\kgVUfOKq.dll, loader C:\lpw_albt\bin\qxBAOWzK.exe
2026-05-28 21:24:13,534 [root] DEBUG: Loader: Injecting process 15228 with C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:13,535 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 15232, handle 0x120
2026-05-28 21:24:13,536 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 21:24:13,537 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\kgVUfOKq.dll.
2026-05-28 21:24:13,538 [lib.api.process] INFO: Injected into 64-bit <Process 15228 ShellExperienceHost.exe>
2026-05-28 21:24:30,436 [root] DEBUG: 4484: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 21:24:30,502 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 6136 (handle 0x278c): 0x00007FF662BA0000.
2026-05-28 21:24:32,447 [root] DEBUG: 4484: OpenProcessHandler: Image base for process 5624 (handle 0x15dc): 0x00007FF659080000.
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 21:22:54 | 2026-05-28 21:24:45 | none |
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 104.115.81.8 [VT] | unknown | - |
| Y | 204.79.197.203 [VT] | unknown | - |
| Y | 149.135.84.50 [VT] | unknown | - |
| Y | 18.155.216.83 [VT] | unknown | - |
| Y | 172.64.154.167 [VT] | unknown | - |
| Y | 23.219.86.106 [VT] | unknown | - |
| Y | 150.171.27.10 [VT] | unknown | - |
| Y | 23.219.86.136 [VT] | unknown | - |
| Y | 20.227.97.55 [VT] | unknown | - |
| Y | 150.171.109.25 [VT] | unknown | - |
| N | 162.159.137.234 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 146.75.119.82 [VT] | unknown | - |
| N | 205.196.6.132 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 23.56.110.195 [VT] | unknown | - |
| N | 162.159.128.235 [VT] | unknown | - |
| N | 162.159.128.233 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| N | 162.159.137.232 [VT] | unknown | - |
| N | 162.159.134.233 [VT] | unknown | - |
| N | 162.159.133.233 [VT] | unknown | - |
| N | 162.159.136.234 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| N | 142.251.222.227 [VT] | unknown | - |
| N | 23.221.49.11 [VT] | unknown | - |
| Y | 172.172.255.218 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-udp.steamserver.net [VT] |
CNAME udp.ipv6check.akadns.net
[VT]
AAAA 2404:3fc0:1:102::670a:7d36 [VT] AAAA 2404:3fc0:1:102::670a:7d37 [VT] AAAA 2404:3fc0:1:100::670a:7d06 [VT] AAAA 2404:3fc0:1:100::42 [VT] AAAA 2404:3fc0:1:102::670a:7d38 [VT] CNAME syd.udp.ipv6check.akadns.net [VT] AAAA 2404:3fc0:1:100::670a:7d08 [VT] AAAA 2404:3fc0:1:102::670a:7d35 [VT] AAAA 2404:3fc0:1:100::32 [VT] |
|
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 23.221.49.11
[VT]
A 23.221.49.17 [VT] |
23.62.157.117 [VT] |
| c.pki.goog [VT] |
CNAME pki-goog.l.google.com
[VT]
A 142.251.222.227 [VT] |
142.250.195.163 [VT] |
| gateway-us-east1-c.discord.gg [VT] |
A 162.159.130.234
[VT]
A 162.159.134.234 [VT] A 162.159.135.234 [VT] A 162.159.133.234 [VT] A 162.159.136.234 [VT] |
162.159.136.234 [VT] |
| discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.129.233 [VT] |
| status.discord.com [VT] |
A 162.159.128.233
[VT]
A 162.159.138.232 [VT] A 162.159.137.232 [VT] A 162.159.135.232 [VT] A 162.159.136.232 [VT] |
162.159.136.232 [VT] |
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| cdn.discordapp.com [VT] | 162.159.135.233 [VT] | |
| updates.discord.com [VT] | 162.159.135.232 [VT] | |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.4.4 [VT] |
| cmp1-sea1.steamserver.net [VT] | A 205.196.6.132 [VT] | 205.196.6.132 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| latency.discord.media [VT] |
A 162.159.130.235
[VT]
A 162.159.129.235 [VT] A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.128.235 [VT] |
162.159.138.234 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.