| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-29 06:44:05 | 2026-05-29 06:47:47 | 222s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 20:55:31,182 [root] INFO: Date set to: 20260529T06:44:12, timeout set to: 200
2026-05-29 06:44:12,055 [root] DEBUG: Starting analyzer from: C:\lpw_albt
2026-05-29 06:44:12,057 [root] DEBUG: Storing results at: C:\gZRInK
2026-05-29 06:44:12,058 [root] DEBUG: Pipe server name: \\.\PIPE\AMUWJCJPH
2026-05-29 06:44:12,058 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-29 06:44:12,058 [root] INFO: analysis running as an admin
2026-05-29 06:44:12,059 [root] INFO: analysis package specified: "edge"
2026-05-29 06:44:12,059 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-29 06:44:12,065 [root] DEBUG: imported analysis package "edge"
2026-05-29 06:44:12,066 [root] DEBUG: initializing analysis package "edge"...
2026-05-29 06:44:12,066 [root] DEBUG: New location of moved file: https://badoomovies.com/download/BadooMovies.exe
2026-05-29 06:44:12,070 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-29 06:44:12,072 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-29 06:44:12,072 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-29 06:44:12,074 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-29 06:44:12,133 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-29 06:44:12,201 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-29 06:44:12,216 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-29 06:44:12,225 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-29 06:44:12,231 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-29 06:44:12,232 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-29 06:44:12,233 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-29 06:44:12,242 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-29 06:44:12,243 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-29 06:44:12,244 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-29 06:44:12,245 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-29 06:44:12,245 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-29 06:44:12,246 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-29 06:44:12,246 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-29 06:44:12,246 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-29 06:44:12,247 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-29 06:44:12,247 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-29 06:44:12,247 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-29 06:44:12,247 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-29 06:44:12,248 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-29 06:44:12,248 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-29 06:44:12,248 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-29 06:44:12,248 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-29 06:44:12,261 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 1028)
2026-05-29 06:44:12,261 [modules.auxiliary.disguise] INFO: Disguising GUID to 1fe1aae4-9186-4225-a287-b753d9a30a59
2026-05-29 06:44:12,262 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-29 06:44:12,262 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-29 06:44:12,262 [root] DEBUG: attempting to configure 'Human' from data
2026-05-29 06:44:12,262 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-29 06:44:12,263 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-29 06:44:12,263 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-29 06:44:12,263 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-29 06:44:12,264 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-29 06:44:12,264 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-29 06:44:12,264 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-29 06:44:12,264 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-29 06:44:12,264 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-29 06:44:12,265 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-29 06:44:12,265 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-29 06:44:12,265 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-29 06:44:12,265 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-29 06:44:12,267 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-29 06:44:12,267 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-29 06:44:12,267 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-29 06:44:12,358 [lib.api.process] INFO: Monitor config for process 4484: C:\lpw_albt\dll\4484.ini
2026-05-29 06:44:12,359 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:12,362 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:12,412 [root] DEBUG: Loader: Injecting process 4484 with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:12,584 [root] DEBUG: 4484: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:44:12,586 [root] DEBUG: 4484: Disabling sleep skipping.
2026-05-29 06:44:12,588 [root] DEBUG: 4484: Interactive desktop enabled.
2026-05-29 06:44:12,589 [root] DEBUG: 4484: Dropped file limit defaulting to 100.
2026-05-29 06:44:12,591 [root] DEBUG: 4484: Interactive desktop - injecting Explorer Shell
2026-05-29 06:44:12,612 [root] DEBUG: 4484: YaraInit: Compiled 44 rule files
2026-05-29 06:44:12,615 [root] DEBUG: 4484: YaraInit: Compiled rules saved to file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:44:12,666 [root] DEBUG: 4484: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:44:12,668 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-29 06:44:12,723 [root] DEBUG: 4484: Monitor initialised: 64-bit capemon loaded in process 4484 at 0x00007FFF18240000, thread 1276, image base 0x00007FF79BC10000, stack from 0x0000000009051000-0x0000000009060000
2026-05-29 06:44:12,724 [root] DEBUG: 4484: Commandline: C:\Windows\Explorer.EXE
2026-05-29 06:44:12,740 [root] DEBUG: 4484: Hooked 69 out of 69 functions
2026-05-29 06:44:12,773 [root] DEBUG: 4484: Syscall hook installed, syscall logging level 1
2026-05-29 06:44:12,781 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-29 06:44:12,782 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:12,783 [lib.api.process] INFO: Injected into 64-bit <Process 4484 explorer.exe>
2026-05-29 06:44:13,366 [root] DEBUG: 4484: caller_dispatch: Added region at 0x00007FF79BC10000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF79BD27BE7, thread 4696).
2026-05-29 06:44:13,367 [root] DEBUG: 4484: YaraScan: Scanning 0x00007FF79BC10000, size 0x545316
2026-05-29 06:44:13,401 [root] DEBUG: 4484: ProcessImageBase: Main module image at 0x00007FF79BC10000 unmodified (entropy change 0.000000e+00)
2026-05-29 06:44:19,933 [root] INFO: Restarting WMI Service
2026-05-29 06:44:19,952 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-29 06:44:19,953 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-29 06:44:19,953 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-29 06:44:19,954 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://badoomovies.com/download/BadooMovies.exe"" with pid 4104
2026-05-29 06:44:19,955 [lib.api.process] INFO: Monitor config for process 4104: C:\lpw_albt\dll\4104.ini
2026-05-29 06:44:19,957 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:19,958 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:19,965 [root] DEBUG: Loader: Injecting process 4104 (thread 4828) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:19,965 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:19,966 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:19,967 [lib.api.process] INFO: Injected into 64-bit <Process 4104 msedge.exe>
2026-05-29 06:44:21,971 [lib.api.process] INFO: Successfully resumed process with pid 4104
2026-05-29 06:44:22,017 [root] DEBUG: 4104: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:44:22,019 [root] DEBUG: 4104: Disabling sleep skipping.
2026-05-29 06:44:22,019 [root] DEBUG: 4104: Interactive desktop enabled.
2026-05-29 06:44:22,020 [root] DEBUG: 4104: Dropped file limit defaulting to 100.
2026-05-29 06:44:22,027 [root] DEBUG: 4104: Edge-specific hook-set enabled.
2026-05-29 06:44:22,030 [root] DEBUG: 4104: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:44:22,041 [root] DEBUG: 4104: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:44:22,041 [root] DEBUG: 4104: Monitor initialised: 64-bit capemon loaded in process 4104 at 0x00007FFF18240000, thread 4828, image base 0x00007FF7F5380000, stack from 0x000000F49FFF4000-0x000000F4A0000000
2026-05-29 06:44:22,041 [root] DEBUG: 4104: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://badoomovies.com/download/BadooMovies.exe"
2026-05-29 06:44:22,052 [root] DEBUG: 4104: Hooked 2 out of 2 functions
2026-05-29 06:44:22,087 [root] DEBUG: 4104: Syscall hook installed, syscall logging level 1
2026-05-29 06:44:22,093 [root] DEBUG: 4104: RestoreHeaders: Restored original import table.
2026-05-29 06:44:22,094 [root] INFO: Loaded monitor into process with pid 4104
2026-05-29 06:44:22,097 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-29 06:44:22,102 [root] DEBUG: 4104: DLL loaded at 0x00007FFF43500000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-29 06:44:22,103 [root] DEBUG: 4104: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 06:44:22,104 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-29 06:44:22,104 [root] DEBUG: 4104: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-29 06:44:22,105 [root] DEBUG: 4104: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-29 06:44:22,106 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:44:22,277 [root] DEBUG: 4104: DLL loaded at 0x00007FFF453C0000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes).
2026-05-29 06:44:22,278 [root] DEBUG: 4104: DLL loaded at 0x00007FFEFE540000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-29 06:44:22,281 [root] DEBUG: 4104: DLL loaded at 0x00007FFF45010000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2026-05-29 06:44:22,284 [root] DEBUG: 4104: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 06:44:22,289 [root] DEBUG: 4104: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 06:44:22,290 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 1204: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:22,290 [root] DEBUG: 4104: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 06:44:22,290 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 1204
2026-05-29 06:44:22,291 [root] DEBUG: 4104: DLL loaded at 0x00007FFF3E220000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-29 06:44:22,291 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 1204
2026-05-29 06:44:22,292 [root] DEBUG: 4104: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:44:22,292 [root] DEBUG: 4104: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:44:22,296 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57520000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-05-29 06:44:22,297 [root] DEBUG: 4104: DLL loaded at 0x00007FFF55EC0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-29 06:44:22,297 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56750000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes).
2026-05-29 06:44:22,298 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56A30000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-29 06:44:22,299 [root] DEBUG: 4104: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:44:22,301 [root] DEBUG: 4104: DLL loaded at 0x00007FFF16A40000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes).
2026-05-29 06:44:22,302 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:44:22,303 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-29 06:44:22,303 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-29 06:44:22,304 [root] DEBUG: 4104: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:44:22,304 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-29 06:44:22,304 [root] DEBUG: 4104: DLL loaded at 0x00007FFF15300000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes).
2026-05-29 06:44:22,305 [root] DEBUG: 4104: DLL loaded at 0x00007FFF3F6A0000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes).
2026-05-29 06:44:22,305 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-29 06:44:22,306 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-29 06:44:22,308 [root] DEBUG: 4104: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-05-29 06:44:22,309 [root] DEBUG: 4104: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:44:22,309 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-29 06:44:22,309 [root] DEBUG: 4104: DLL loaded at 0x00007FFF52F20000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-05-29 06:44:22,311 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57560000: C:\Windows\SYSTEM32\profapi (0x25000 bytes).
2026-05-29 06:44:22,319 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4CFA0000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes).
2026-05-29 06:44:22,321 [root] DEBUG: 4104: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-29 06:44:22,321 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4D3D0000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes).
2026-05-29 06:44:22,322 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:44:22,323 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57470000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-29 06:44:22,324 [root] DEBUG: 4104: DLL loaded at 0x00007FFF49A90000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes).
2026-05-29 06:44:22,327 [root] DEBUG: 4104: DLL loaded at 0x00007FFF44D50000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes).
2026-05-29 06:44:22,328 [root] DEBUG: 4104: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 06:44:22,328 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57350000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-05-29 06:44:22,330 [root] DEBUG: 4104: DLL loaded at 0x00007FFF569F0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-05-29 06:44:22,330 [root] DEBUG: 4104: DLL loaded at 0x00007FFF52960000: C:\Windows\system32\NLAapi (0x1d000 bytes).
2026-05-29 06:44:22,332 [root] DEBUG: 4104: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-29 06:44:22,333 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-29 06:44:22,334 [root] DEBUG: 4104: DLL loaded at 0x00007FFF515C0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-29 06:44:22,334 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4B070000: C:\Windows\System32\StructuredQuery (0xa6000 bytes).
2026-05-29 06:44:22,335 [root] DEBUG: 4104: DLL loaded at 0x00007FFF515A0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-29 06:44:22,336 [root] DEBUG: 4104: DLL loaded at 0x00007FFF52860000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2026-05-29 06:44:22,337 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56A40000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-29 06:44:22,339 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-29 06:44:22,342 [root] DEBUG: 4104: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-29 06:44:22,342 [root] DEBUG: 4104: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-29 06:44:22,342 [root] DEBUG: 4104: DLL loaded at 0x00007FFF54170000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-29 06:44:22,343 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4B680000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-29 06:44:22,345 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4CD70000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes).
2026-05-29 06:44:22,348 [root] DEBUG: 4104: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-29 06:44:22,349 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-29 06:44:22,350 [root] DEBUG: 4104: DLL loaded at 0x00007FFF45580000: C:\Windows\system32\twinapi (0xa9000 bytes).
2026-05-29 06:44:22,353 [root] DEBUG: 4104: DLL loaded at 0x00007FFF52420000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes).
2026-05-29 06:44:22,353 [root] DEBUG: 4104: DLL loaded at 0x00007FFF47AB0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-05-29 06:44:22,357 [root] DEBUG: 4104: DLL loaded at 0x00007FFF51A60000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-29 06:44:22,357 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4AF10000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-29 06:44:22,357 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4BFB0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-29 06:44:22,358 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-29 06:44:22,359 [root] DEBUG: 4104: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-29 06:44:22,360 [root] DEBUG: 4104: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes).
2026-05-29 06:44:22,368 [root] DEBUG: 4104: DLL loaded at 0x00007FFF515E0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2026-05-29 06:44:22,369 [root] DEBUG: 4104: DLL loaded at 0x00007FFF51600000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2026-05-29 06:44:22,370 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-29 06:44:22,373 [root] DEBUG: 4104: DLL loaded at 0x00007FFF52560000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes).
2026-05-29 06:44:22,385 [root] DEBUG: 4104: DLL loaded at 0x00007FFF15A80000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes).
2026-05-29 06:44:22,389 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 2168: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:22,390 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 2168
2026-05-29 06:44:22,391 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 2168
2026-05-29 06:44:22,393 [root] DEBUG: 4104: caller_dispatch: Added region at 0x00007FF7F5380000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7F5477D66, thread 8576).
2026-05-29 06:44:22,394 [root] DEBUG: 4104: DLL loaded at 0x00007FFF48330000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-05-29 06:44:22,396 [root] DEBUG: 4104: DLL loaded at 0x00007FFF49D10000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-29 06:44:22,398 [root] DEBUG: 4104: ProcessImageBase: Main module image at 0x00007FF7F5380000 unmodified (entropy change 0.000000e+00)
2026-05-29 06:44:22,400 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 1332: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:22,400 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 1332
2026-05-29 06:44:22,401 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 1332
2026-05-29 06:44:22,405 [root] DEBUG: 4104: DLL loaded at 0x00007FFF573C0000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-05-29 06:44:22,411 [root] DEBUG: 4104: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-29 06:44:22,412 [root] DEBUG: 4104: DLL loaded at 0x00007FFF409A0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes).
2026-05-29 06:44:22,421 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 4760: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:22,421 [root] DEBUG: 4104: DLL loaded at 0x00007FFF43590000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-29 06:44:22,423 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 4760
2026-05-29 06:44:22,426 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 4760
2026-05-29 06:44:22,470 [root] DEBUG: 4104: DLL loaded at 0x00007FFF55EF0000: C:\Windows\system32\dxgi (0xf3000 bytes).
2026-05-29 06:44:22,471 [root] DEBUG: 4104: DLL loaded at 0x00007FFF53070000: C:\Windows\system32\d3d11 (0x263000 bytes).
2026-05-29 06:44:22,471 [root] DEBUG: 4104: DLL loaded at 0x00007FFF538A0000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2026-05-29 06:44:22,472 [root] DEBUG: 4104: DLL loaded at 0x00007FFF43630000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-05-29 06:44:22,498 [root] DEBUG: 4104: DLL loaded at 0x00007FFF18950000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes).
2026-05-29 06:44:22,514 [root] DEBUG: 4104: DLL loaded at 0x00007FFF55220000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-05-29 06:44:22,521 [root] DEBUG: 4104: DLL loaded at 0x00007FFF43990000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes).
2026-05-29 06:44:22,522 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 4108: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:22,523 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 5820: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:22,523 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 4108
2026-05-29 06:44:22,523 [root] DEBUG: 4104: DLL loaded at 0x00007FFF488B0000: C:\Windows\system32\directmanipulation (0x9d000 bytes).
2026-05-29 06:44:22,524 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 5820
2026-05-29 06:44:22,524 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 4108
2026-05-29 06:44:22,525 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 5820
2026-05-29 06:44:22,598 [root] DEBUG: 4104: DLL loaded at 0x00007FFF456D0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes).
2026-05-29 06:44:22,603 [root] DEBUG: 4104: DLL loaded at 0x00007FFF3F8A0000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1e000 bytes).
2026-05-29 06:44:22,604 [root] DEBUG: 4104: DLL loaded at 0x00007FFF42BF0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Domain Actions\3.0.0.18\domain_actions (0x17000 bytes).
2026-05-29 06:44:22,606 [root] DEBUG: 4104: DLL loaded at 0x00007FFF16390000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes).
2026-05-29 06:44:22,617 [root] DEBUG: 4104: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-29 06:44:22,620 [root] DEBUG: 4104: DLL loaded at 0x00007FFF3E730000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-05-29 06:44:22,627 [root] DEBUG: 4104: DLL loaded at 0x00007FFF16350000: C:\Windows\System32\aadWamExtension (0x36000 bytes).
2026-05-29 06:44:22,635 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57130000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-29 06:44:22,637 [root] DEBUG: 4104: DLL loaded at 0x00007FFF162C0000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes).
2026-05-29 06:44:22,639 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-29 06:44:22,641 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-29 06:44:23,883 [root] DEBUG: 4104: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-29 06:44:24,304 [root] DEBUG: 4104: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:44:24,306 [root] DEBUG: 4104: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:44:27,545 [root] DEBUG: 4104: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\SETUPAPI (0x46e000 bytes).
2026-05-29 06:44:27,551 [root] DEBUG: 4104: DLL loaded at 0x00007FFF572F0000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-05-29 06:44:27,556 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 9328: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:27,558 [root] DEBUG: 4104: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-29 06:44:27,562 [root] DEBUG: 4104: DLL loaded at 0x00007FFF54B30000: C:\Windows\System32\netprofm (0x3f000 bytes).
2026-05-29 06:44:27,566 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-29 06:44:27,574 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 9344: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:27,582 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 9328
2026-05-29 06:44:27,588 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 9344
2026-05-29 06:44:27,590 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 9344
2026-05-29 06:44:27,653 [root] DEBUG: 4104: DLL loaded at 0x00007FFEFB560000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes).
2026-05-29 06:44:27,865 [root] DEBUG: 4104: DLL loaded at 0x00007FFF164C0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes).
2026-05-29 06:44:27,866 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-29 06:44:27,903 [root] DEBUG: 4104: DLL loaded at 0x00007FFEFAF00000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes).
2026-05-29 06:44:28,069 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56250000: C:\Windows\System32\FirewallAPI (0x96000 bytes).
2026-05-29 06:44:28,070 [root] DEBUG: 4104: DLL loaded at 0x00007FFF561E0000: C:\Windows\System32\fwbase (0x36000 bytes).
2026-05-29 06:44:28,077 [root] DEBUG: 4104: DLL loaded at 0x00007FFF12EB0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes).
2026-05-29 06:44:28,113 [root] DEBUG: 4104: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-29 06:44:28,114 [root] DEBUG: 4104: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-29 06:44:28,115 [root] DEBUG: 4104: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-29 06:44:28,681 [root] DEBUG: 4104: DLL loaded at 0x00007FFF150C0000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes).
2026-05-29 06:44:28,719 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 9528: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF6C7670000
2026-05-29 06:44:28,721 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9528
2026-05-29 06:44:28,722 [lib.api.process] INFO: Monitor config for process 9528: C:\lpw_albt\dll\9528.ini
2026-05-29 06:44:28,725 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:30,107 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 06:44:30,107 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 06:44:30,108 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 06:44:30,108 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 06:44:30,108 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 06:44:30,108 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 06:44:30,108 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 06:44:30,108 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 06:44:30,112 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:30,116 [root] DEBUG: Loader: Injecting process 9528 (thread 9532) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:30,117 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:30,117 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:30,120 [lib.api.process] INFO: Injected into 64-bit <Process 9528 identity_helper.exe>
2026-05-29 06:44:30,139 [root] DEBUG: 4104: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-29 06:44:30,140 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4CBD0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-29 06:44:30,141 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 9656: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF6C7670000
2026-05-29 06:44:30,142 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9656
2026-05-29 06:44:30,142 [lib.api.process] INFO: Monitor config for process 9656: C:\lpw_albt\dll\9656.ini
2026-05-29 06:44:30,143 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:30,231 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 06:44:30,231 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 06:44:30,232 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 06:44:30,232 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 06:44:30,233 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 06:44:30,233 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 06:44:30,233 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 06:44:30,233 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 06:44:30,235 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:30,241 [root] DEBUG: Loader: Injecting process 9656 (thread 9660) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:30,241 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:30,242 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:30,243 [lib.api.process] INFO: Injected into 64-bit <Process 9656 identity_helper.exe>
2026-05-29 06:44:30,247 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 9656
2026-05-29 06:44:30,247 [lib.api.process] INFO: Monitor config for process 9656: C:\lpw_albt\dll\9656.ini
2026-05-29 06:44:30,248 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:30,325 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll
2026-05-29 06:44:30,325 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140_1.dll
2026-05-29 06:44:30,326 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4F950000: C:\Windows\system32\wlanapi (0x74000 bytes).
2026-05-29 06:44:30,326 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vccorlib140.dll
2026-05-29 06:44:30,326 [lib.api.process] INFO: Potential dll side-loading detected in local directory: concrt140.dll
2026-05-29 06:44:30,326 [lib.api.process] INFO: Potential dll side-loading detected in local directory: vcruntime140.dll
2026-05-29 06:44:30,327 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140.dll
2026-05-29 06:44:30,327 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll
2026-05-29 06:44:30,327 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msvcp140_codecvt_ids.dll
2026-05-29 06:44:30,328 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:30,332 [root] DEBUG: Loader: Injecting process 9656 (thread 9660) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:30,334 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:44:30,334 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:30,337 [lib.api.process] INFO: Injected into 64-bit <Process 9656 identity_helper.exe>
2026-05-29 06:44:30,351 [root] DEBUG: 9656: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:44:30,351 [root] DEBUG: 9656: Interactive desktop enabled.
2026-05-29 06:44:30,352 [root] DEBUG: 9656: Dropped file limit defaulting to 100.
2026-05-29 06:44:30,362 [root] DEBUG: 9656: Disabling sleep skipping.
2026-05-29 06:44:30,364 [root] DEBUG: 9656: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:44:30,376 [root] DEBUG: 9656: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:44:30,377 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FF6C7670000, size 0x28b4d8
2026-05-29 06:44:30,406 [root] DEBUG: 9656: Monitor initialised: 64-bit capemon loaded in process 9656 at 0x00007FFF18240000, thread 9660, image base 0x00007FF6C7670000, stack from 0x000000FC372F4000-0x000000FC37300000
2026-05-29 06:44:30,407 [root] DEBUG: 9656: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=6048,i,2971723425194365174,16206758529383860314,524288 --field-trial-handle=2456,i,5241159451444011597,10090642637214373156,262144 --variations-seed-version --pseudonymization-salt-handle=2460,i,13440712079067794296,1199331602286409
2026-05-29 06:44:30,407 [root] DEBUG: 9656: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll
2026-05-29 06:44:30,419 [root] DEBUG: 9656: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 06:44:30,445 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 06:44:30,446 [root] DEBUG: 9656: set_hooks: Unable to hook LockResource
2026-05-29 06:44:30,451 [root] DEBUG: 9656: Hooked 627 out of 628 functions
2026-05-29 06:44:30,467 [root] DEBUG: 9656: Syscall hook installed, syscall logging level 1
2026-05-29 06:44:30,473 [root] DEBUG: 9656: RestoreHeaders: Restored original import table.
2026-05-29 06:44:30,474 [root] INFO: Loaded monitor into process with pid 9656
2026-05-29 06:44:30,475 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FFF16AB0000, size 0x4b9994
2026-05-29 06:44:30,549 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FFF16AB0000, size 0x4b9994
2026-05-29 06:44:30,578 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FFF16AB0000, size 0x4b9994
2026-05-29 06:44:30,584 [root] DEBUG: 4104: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-29 06:44:30,586 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4F740000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes).
2026-05-29 06:44:30,608 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FFF16AB0000, size 0x4b9994
2026-05-29 06:44:30,635 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FFF16AB0000, size 0x4b9994
2026-05-29 06:44:30,659 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FFF16AB0000, size 0x4b9994
2026-05-29 06:44:30,688 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FFF16AB0000, size 0x4b9994
2026-05-29 06:44:30,691 [root] DEBUG: 4104: DLL loaded at 0x00007FFF43550000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2026-05-29 06:44:30,693 [root] DEBUG: 4104: DLL loaded at 0x00007FFF57010000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-05-29 06:44:30,694 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56FD0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-05-29 06:44:30,694 [root] DEBUG: 4104: DLL loaded at 0x00007FFF50370000: C:\Windows\system32\PCPKsp (0x118000 bytes).
2026-05-29 06:44:30,695 [root] DEBUG: 4104: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:44:30,696 [root] DEBUG: 4104: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes).
2026-05-29 06:44:30,697 [root] DEBUG: 4104: DLL loaded at 0x00007FFF45050000: C:\Windows\system32\ncryptprov (0x5a000 bytes).
2026-05-29 06:44:30,718 [root] DEBUG: 9656: caller_dispatch: Added region at 0x00007FFF16AB0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFF16CAF156, thread 9660).
2026-05-29 06:44:30,720 [root] DEBUG: 9656: caller_dispatch: Scanning calling region at 0x00007FFF16AB0000...
2026-05-29 06:44:30,731 [root] DEBUG: 9656: ProcessTrackedRegion: Region at 0x00007FFF16AB0000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping
2026-05-29 06:44:30,733 [root] DEBUG: 9656: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-29 06:44:30,772 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FF6C7670000, size 0x28b4d8
2026-05-29 06:44:30,788 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FF6C7670000, size 0x28b4d8
2026-05-29 06:44:30,803 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FF6C7670000, size 0x28b4d8
2026-05-29 06:44:30,819 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FF6C7670000, size 0x28b4d8
2026-05-29 06:44:30,838 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FF6C7670000, size 0x28b4d8
2026-05-29 06:44:30,853 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FF6C7670000, size 0x28b4d8
2026-05-29 06:44:30,871 [root] DEBUG: 9656: caller_dispatch: Added region at 0x00007FF6C7670000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF6C7764096, thread 9660).
2026-05-29 06:44:30,871 [root] DEBUG: 9656: YaraScan: Scanning 0x00007FF6C7670000, size 0x28b4d8
2026-05-29 06:44:30,875 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56D00000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-05-29 06:44:30,890 [root] DEBUG: 9656: ProcessImageBase: Main module image at 0x00007FF6C7670000 unmodified (entropy change 0.000000e+00)
2026-05-29 06:44:30,893 [root] DEBUG: 9656: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 06:44:30,923 [root] DEBUG: 9656: DLL loaded at 0x0000025931000000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes).
2026-05-29 06:44:30,926 [root] DEBUG: 9656: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 06:44:30,930 [root] DEBUG: 9656: DLL loaded at 0x00007FFF58380000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-29 06:44:30,970 [root] DEBUG: 9656: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 06:44:31,140 [root] DEBUG: 9656: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 06:44:31,146 [root] DEBUG: 9656: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 06:44:31,147 [root] DEBUG: 9656: DLL loaded at 0x00007FFF52860000: C:\Windows\System32\PROPSYS (0xf6000 bytes).
2026-05-29 06:44:31,148 [root] DEBUG: 9656: DLL loaded at 0x00007FFF54850000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-29 06:44:31,148 [root] DEBUG: 9656: DLL loaded at 0x00007FFF46D30000: C:\Windows\System32\execmodelclient (0x63000 bytes).
2026-05-29 06:44:31,159 [root] DEBUG: 9656: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-29 06:44:31,162 [root] DEBUG: 9656: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-29 06:44:31,162 [root] DEBUG: 9656: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-29 06:44:31,163 [root] DEBUG: 9656: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-29 06:44:31,163 [root] DEBUG: 9656: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-29 06:44:31,172 [root] DEBUG: 9656: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-29 06:44:31,184 [root] DEBUG: 9656: DLL loaded at 0x00007FFF46AE0000: C:\Windows\system32\execmodelproxy (0x18000 bytes).
2026-05-29 06:44:31,196 [root] DEBUG: 9656: DLL loaded at 0x00007FFF566C0000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:44:31,197 [root] DEBUG: 9656: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:44:31,202 [root] DEBUG: 9656: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-29 06:44:31,216 [root] DEBUG: 9656: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 06:44:31,228 [root] DEBUG: 9656: DLL loaded at 0x00007FFF4CBF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-29 06:44:31,243 [root] DEBUG: 9656: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-29 06:44:31,244 [root] DEBUG: 9656: DLL loaded at 0x00007FFF501A0000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes).
2026-05-29 06:44:31,247 [root] DEBUG: 9656: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-29 06:44:31,254 [root] DEBUG: 9656: DLL loaded at 0x00007FFF457F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-29 06:44:31,271 [root] DEBUG: 9656: DLL loaded at 0x000002592FF50000: C:\Windows\System32\CryptoWinRT (0x61000 bytes).
2026-05-29 06:44:31,282 [lib.api.process] INFO: Monitor config for process 832: C:\lpw_albt\dll\832.ini
2026-05-29 06:44:31,283 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:31,285 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:31,292 [root] DEBUG: Loader: Injecting process 832 with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:31,297 [root] DEBUG: 832: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:44:31,297 [root] DEBUG: 832: Disabling sleep skipping.
2026-05-29 06:44:31,298 [root] DEBUG: 832: Interactive desktop enabled.
2026-05-29 06:44:31,298 [root] DEBUG: 832: Dropped file limit defaulting to 100.
2026-05-29 06:44:31,300 [root] DEBUG: 832: Services hook set enabled
2026-05-29 06:44:31,302 [root] DEBUG: 832: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:44:31,313 [root] DEBUG: 832: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:44:31,314 [root] DEBUG: 832: Monitor initialised: 64-bit capemon loaded in process 832 at 0x00007FFF18240000, thread 10180, image base 0x00007FF7BF220000, stack from 0x000000CCA7AF4000-0x000000CCA7B00000
2026-05-29 06:44:31,316 [root] DEBUG: 832: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-29 06:44:31,331 [root] DEBUG: 832: Hooked 69 out of 69 functions
2026-05-29 06:44:31,332 [root] INFO: Loaded monitor into process with pid 832
2026-05-29 06:44:31,333 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-29 06:44:31,333 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:31,335 [lib.api.process] INFO: Injected into 64-bit <Process 832 svchost.exe>
2026-05-29 06:44:33,355 [root] DEBUG: 9656: DLL loaded at 0x00007FFF4B780000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-29 06:44:33,356 [root] DEBUG: 9656: DLL loaded at 0x00007FFF4B840000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-29 06:44:33,358 [root] DEBUG: 9656: DLL loaded at 0x00007FFF43150000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-29 06:44:33,359 [root] DEBUG: 9656: DLL loaded at 0x00007FFF3D7B0000: C:\Windows\System32\biwinrt (0x53000 bytes).
2026-05-29 06:44:33,368 [root] DEBUG: 9656: DLL loaded at 0x00007FFF4F6E0000: C:\Windows\System32\usermgrproxy (0x54000 bytes).
2026-05-29 06:44:33,396 [root] DEBUG: 9656: DLL loaded at 0x00007FFF55EF0000: C:\Windows\System32\dxgi (0xf3000 bytes).
2026-05-29 06:44:33,397 [root] DEBUG: 9656: DLL loaded at 0x00007FFF53070000: C:\Windows\System32\d3d11 (0x263000 bytes).
2026-05-29 06:44:33,404 [root] DEBUG: 9656: DLL loaded at 0x00007FFF48B40000: C:\Windows\System32\WININET (0x4d6000 bytes).
2026-05-29 06:44:33,405 [root] DEBUG: 9656: DLL loaded at 0x00007FFF3D6A0000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-29 06:44:33,425 [root] DEBUG: 9656: DLL loaded at 0x00007FFF43060000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes).
2026-05-29 06:44:33,455 [root] DEBUG: 9656: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-29 06:44:33,456 [root] DEBUG: 9656: DLL loaded at 0x00007FFF56FA0000: C:\Windows\System32\Wldp (0x2d000 bytes).
2026-05-29 06:44:33,457 [root] DEBUG: 9656: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-29 06:44:33,458 [root] DEBUG: 9656: DLL loaded at 0x00007FFF4C520000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-29 06:44:33,458 [root] DEBUG: 9656: DLL loaded at 0x00007FFF43DD0000: C:\Windows\System32\StartTileData (0x58a000 bytes).
2026-05-29 06:44:33,489 [root] DEBUG: 9656: DLL loaded at 0x00007FFF3D810000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes).
2026-05-29 06:44:33,579 [root] DEBUG: 9656: DLL loaded at 0x00007FFF4CD40000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-05-29 06:44:33,622 [root] DEBUG: 9656: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-29 06:44:40,168 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9452: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 06:44:40,170 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9452
2026-05-29 06:44:40,170 [lib.api.process] INFO: Monitor config for process 9452: C:\lpw_albt\dll\9452.ini
2026-05-29 06:44:40,171 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,172 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,177 [root] DEBUG: Loader: Injecting process 9452 (thread 9428) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,178 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:40,179 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,180 [lib.api.process] INFO: Injected into 64-bit <Process 9452 backgroundTaskHost.exe>
2026-05-29 06:44:40,182 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9452
2026-05-29 06:44:40,182 [lib.api.process] INFO: Monitor config for process 9452: C:\lpw_albt\dll\9452.ini
2026-05-29 06:44:40,182 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,183 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,188 [root] DEBUG: Loader: Injecting process 9452 (thread 9428) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,188 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:44:40,189 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,190 [lib.api.process] INFO: Injected into 64-bit <Process 9452 backgroundTaskHost.exe>
2026-05-29 06:44:40,192 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9452
2026-05-29 06:44:40,192 [lib.api.process] INFO: Monitor config for process 9452: C:\lpw_albt\dll\9452.ini
2026-05-29 06:44:40,200 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,201 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,214 [root] DEBUG: Loader: Injecting process 9452 with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,215 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9428, handle 0x120
2026-05-29 06:44:40,216 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:44:40,217 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,219 [lib.api.process] INFO: Injected into 64-bit <Process 9452 backgroundTaskHost.exe>
2026-05-29 06:44:40,228 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 10160: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 06:44:40,228 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10160
2026-05-29 06:44:40,229 [lib.api.process] INFO: Monitor config for process 10160: C:\lpw_albt\dll\10160.ini
2026-05-29 06:44:40,229 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,230 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,235 [root] DEBUG: Loader: Injecting process 10160 (thread 10156) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,235 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:40,237 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,247 [lib.api.process] INFO: Injected into 64-bit <Process 10160 backgroundTaskHost.exe>
2026-05-29 06:44:40,250 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 10160
2026-05-29 06:44:40,251 [lib.api.process] INFO: Monitor config for process 10160: C:\lpw_albt\dll\10160.ini
2026-05-29 06:44:40,251 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,252 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,261 [root] DEBUG: Loader: Injecting process 10160 (thread 10156) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,262 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:44:40,263 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,268 [lib.api.process] INFO: Injected into 64-bit <Process 10160 backgroundTaskHost.exe>
2026-05-29 06:44:40,273 [root] INFO: Process with pid 10160 has terminated
2026-05-29 06:44:40,279 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 8272: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 06:44:40,280 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8272
2026-05-29 06:44:40,280 [lib.api.process] INFO: Monitor config for process 8272: C:\lpw_albt\dll\8272.ini
2026-05-29 06:44:40,281 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,282 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,289 [root] DEBUG: Loader: Injecting process 8272 (thread 1152) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,289 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:40,290 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,292 [lib.api.process] INFO: Injected into 64-bit <Process 8272 backgroundTaskHost.exe>
2026-05-29 06:44:40,293 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 8272
2026-05-29 06:44:40,293 [lib.api.process] INFO: Monitor config for process 8272: C:\lpw_albt\dll\8272.ini
2026-05-29 06:44:40,293 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,294 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,298 [root] DEBUG: Loader: Injecting process 8272 (thread 1152) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,299 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:44:40,301 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,302 [lib.api.process] INFO: Injected into 64-bit <Process 8272 backgroundTaskHost.exe>
2026-05-29 06:44:40,303 [root] INFO: Process with pid 8272 has terminated
2026-05-29 06:44:40,307 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 9120: C:\Windows\system32\backgroundTaskHost.exe, ImageBase: 0x00007FF62C670000
2026-05-29 06:44:40,308 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9120
2026-05-29 06:44:40,308 [lib.api.process] INFO: Monitor config for process 9120: C:\lpw_albt\dll\9120.ini
2026-05-29 06:44:40,309 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,310 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,316 [root] DEBUG: Loader: Injecting process 9120 (thread 1880) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,317 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:40,317 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,319 [lib.api.process] INFO: Injected into 64-bit <Process 9120 backgroundTaskHost.exe>
2026-05-29 06:44:40,320 [root] INFO: Announced 64-bit process name: backgroundTaskHost.exe pid: 9120
2026-05-29 06:44:40,320 [lib.api.process] INFO: Monitor config for process 9120: C:\lpw_albt\dll\9120.ini
2026-05-29 06:44:40,321 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:40,322 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:40,326 [root] DEBUG: Loader: Injecting process 9120 (thread 1880) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,326 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:44:40,328 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:40,330 [lib.api.process] INFO: Injected into 64-bit <Process 9120 backgroundTaskHost.exe>
2026-05-29 06:44:40,332 [root] INFO: Process with pid 9120 has terminated
2026-05-29 06:44:43,727 [root] INFO: Process with pid 9656 has terminated
2026-05-29 06:44:43,728 [root] DEBUG: 9656: NtTerminateProcess hook: Attempting to dump process 9656
2026-05-29 06:44:43,730 [root] DEBUG: 9656: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:44:46,682 [root] INFO: Announced starting service "b'edgeupdate'"
2026-05-29 06:44:46,682 [lib.api.process] INFO: Monitor config for process 676: C:\lpw_albt\dll\676.ini
2026-05-29 06:44:46,683 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:46,684 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:44:46,688 [root] DEBUG: Loader: Injecting process 676 with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:46,689 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\676.ini to system path C:\676.ini
2026-05-29 06:44:46,692 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 676 C:\lpw_albt\dll\yCvZHFYF.dll
2026-05-29 06:44:46,692 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:44:46,693 [lib.api.process] INFO: Injected into 64-bit <Process 676 services.exe>
2026-05-29 06:44:47,916 [root] DEBUG: 676: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:44:47,924 [root] DEBUG: 676: Disabling sleep skipping.
2026-05-29 06:44:47,925 [root] DEBUG: 676: Interactive desktop enabled.
2026-05-29 06:44:47,926 [root] DEBUG: 676: Dropped file limit defaulting to 100.
2026-05-29 06:44:47,929 [root] DEBUG: 676: Services hook set enabled
2026-05-29 06:44:47,945 [root] DEBUG: 676: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:44:47,945 [root] DEBUG: 676: Monitor initialised: 64-bit capemon loaded in process 676 at 0x00007FFEFAB30000, thread 6500, image base 0x00007FF7839A0000, stack from 0x000000F2F01F2000-0x000000F2F0200000
2026-05-29 06:44:47,945 [root] DEBUG: 676: Commandline: C:\Windows\system32\services.exe
2026-05-29 06:44:47,960 [root] DEBUG: 676: Hooked 69 out of 69 functions
2026-05-29 06:44:47,963 [root] INFO: Loaded monitor into process with pid 676
2026-05-29 06:44:49,812 [root] DEBUG: 676: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-29 06:44:49,819 [root] DEBUG: 676: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-29 06:44:49,831 [root] DEBUG: 676: DLL loaded at 0x00007FFF58070000: C:\Windows\system32\SHCORE (0xad000 bytes).
2026-05-29 06:44:49,848 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 5932: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x0000000000150000
2026-05-29 06:44:49,864 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 5932
2026-05-29 06:44:49,872 [lib.api.process] INFO: Monitor config for process 5932: C:\lpw_albt\dll\5932.ini
2026-05-29 06:44:49,873 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:49,906 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\nxatNo.dll, loader C:\lpw_albt\bin\pNxCcCJ.exe
2026-05-29 06:44:49,990 [root] DEBUG: Loader: Injecting process 5932 (thread 5888) with C:\lpw_albt\dll\nxatNo.dll.
2026-05-29 06:44:49,992 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:49,992 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\nxatNo.dll.
2026-05-29 06:44:49,996 [lib.api.process] INFO: Injected into 32-bit <Process 5932 MicrosoftEdgeUpdate.exe>
2026-05-29 06:44:49,998 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 5932
2026-05-29 06:44:49,998 [lib.api.process] INFO: Monitor config for process 5932: C:\lpw_albt\dll\5932.ini
2026-05-29 06:44:49,999 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:50,000 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\nxatNo.dll, loader C:\lpw_albt\bin\pNxCcCJ.exe
2026-05-29 06:44:50,006 [root] DEBUG: Loader: Injecting process 5932 (thread 5888) with C:\lpw_albt\dll\nxatNo.dll.
2026-05-29 06:44:50,007 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:44:50,007 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\nxatNo.dll.
2026-05-29 06:44:50,009 [lib.api.process] INFO: Injected into 32-bit <Process 5932 MicrosoftEdgeUpdate.exe>
2026-05-29 06:44:50,009 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 5932
2026-05-29 06:44:50,010 [lib.api.process] INFO: Monitor config for process 5932: C:\lpw_albt\dll\5932.ini
2026-05-29 06:44:50,010 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:50,011 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\nxatNo.dll, loader C:\lpw_albt\bin\pNxCcCJ.exe
2026-05-29 06:44:50,016 [root] DEBUG: Loader: Injecting process 5932 with C:\lpw_albt\dll\nxatNo.dll.
2026-05-29 06:44:50,017 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed, falling back to thread injection.
2026-05-29 06:44:50,074 [root] DEBUG: 5932: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:44:50,075 [root] DEBUG: 5932: Interactive desktop enabled.
2026-05-29 06:44:50,076 [root] DEBUG: 5932: Dropped file limit defaulting to 100.
2026-05-29 06:44:50,080 [root] DEBUG: 5932: Disabling sleep skipping.
2026-05-29 06:44:50,091 [root] DEBUG: 5932: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:44:50,091 [root] DEBUG: 5932: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-29 06:44:50,093 [root] DEBUG: 5932: Monitor initialised: 32-bit capemon loaded in process 5932 at 0x6ab90000, thread 9680, image base 0x150000, stack from 0x2734000-0x2740000
2026-05-29 06:44:50,094 [root] DEBUG: 5932: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc
2026-05-29 06:44:50,128 [root] DEBUG: 5932: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-29 06:44:50,153 [root] DEBUG: 5932: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-29 06:44:50,153 [root] DEBUG: 5932: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-29 06:44:50,159 [root] DEBUG: 5932: Hooked 632 out of 632 functions
2026-05-29 06:44:50,162 [root] DEBUG: 5932: Syscall hook installed, syscall logging level 1
2026-05-29 06:44:50,170 [root] DEBUG: 5932: RestoreHeaders: Restored original import table.
2026-05-29 06:44:50,172 [root] INFO: Loaded monitor into process with pid 5932
2026-05-29 06:44:50,172 [root] DEBUG: 5932: caller_dispatch: Added region at 0x023D0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x023D0035, thread 9680).
2026-05-29 06:44:50,173 [root] DEBUG: 5932: DumpPEsInRange: Scanning range 0x023D0000 - 0x023D0127.
2026-05-29 06:44:50,173 [root] DEBUG: 5932: ScanForDisguisedPE: Size too small: 0x127 bytes
2026-05-29 06:44:50,186 [lib.common.results] INFO: Uploading file C:\gZRInK\CAPE\5932_284721350441029552026 to CAPE\760e3c46aa0d294ae0c9528bdd5ad0e57b0e0a20301b2e3a7ca6bd400b7ee76a; Size is 295; Max size: 100000000
2026-05-29 06:44:50,194 [root] DEBUG: 5932: DumpMemory: Payload successfully created: C:\gZRInK\CAPE\5932_284721350441029552026 (size 295 bytes)
2026-05-29 06:44:50,194 [root] DEBUG: 5932: DumpRegion: Dumped entire allocation from 0x023D0000, size 4096 bytes.
2026-05-29 06:44:50,195 [root] DEBUG: 5932: ProcessTrackedRegion: Dumped region at 0x023D0000.
2026-05-29 06:44:50,195 [root] DEBUG: 5932: YaraScan: Scanning 0x023D0000, size 0x127
2026-05-29 06:44:50,196 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-29 06:44:50,197 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\nxatNo.dll.
2026-05-29 06:44:50,199 [lib.api.process] INFO: Injected into 32-bit <Process 5932 MicrosoftEdgeUpdate.exe>
2026-05-29 06:44:50,200 [root] DEBUG: 5932: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 5888).
2026-05-29 06:44:50,200 [root] DEBUG: 5932: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-29 06:44:50,203 [root] DEBUG: 5932: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-29 06:44:50,210 [root] DEBUG: 5932: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-29 06:44:50,210 [root] DEBUG: 5932: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-29 06:44:50,220 [root] DEBUG: 5932: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-29 06:44:50,233 [root] DEBUG: 5932: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-29 06:44:50,234 [root] DEBUG: 5932: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-29 06:44:50,235 [root] DEBUG: 5932: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-29 06:44:50,235 [root] DEBUG: 5932: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-29 06:44:50,236 [root] DEBUG: 5932: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-29 06:44:50,237 [root] DEBUG: 5932: DLL loaded at 0x6AEB0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\msedgeupdate (0x23d000 bytes).
2026-05-29 06:44:50,252 [root] DEBUG: 5932: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-29 06:44:50,253 [root] DEBUG: 5932: DLL loaded at 0x755E0000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-29 06:44:50,269 [root] DEBUG: 5932: DLL loaded at 0x6F2A0000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-29 06:44:50,270 [root] DEBUG: 5932: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-29 06:44:50,271 [root] DEBUG: 5932: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-29 06:44:50,271 [root] DEBUG: 5932: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-29 06:44:50,271 [root] DEBUG: 5932: DLL loaded at 0x75520000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-29 06:44:50,272 [root] DEBUG: 5932: DLL loaded at 0x75540000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-29 06:44:50,272 [root] DEBUG: 5932: DLL loaded at 0x755B0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-29 06:44:50,274 [root] DEBUG: 5932: DLL loaded at 0x6F290000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-29 06:44:50,276 [root] DEBUG: 5932: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-29 06:44:50,283 [root] DEBUG: 5932: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-29 06:44:50,284 [root] DEBUG: 5932: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-29 06:44:50,287 [root] DEBUG: 5932: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-29 06:44:50,302 [root] DEBUG: 5932: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-29 06:44:50,339 [root] DEBUG: 5932: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-05-29 06:44:50,346 [root] DEBUG: 5932: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-29 06:44:50,358 [root] DEBUG: 5932: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-29 06:44:50,365 [root] DEBUG: 5932: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-29 06:44:50,382 [root] DEBUG: 5932: DLL loaded at 0x755E0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\psmachine (0x58000 bytes).
2026-05-29 06:44:50,681 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-29 06:44:50,682 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6408, handle 0x3c4: Error obtaining target process name
2026-05-29 06:44:50,871 [root] DEBUG: 5932: DLL loaded at 0x75580000: C:\Windows\System32\SystemSettings.DataModel (0x57000 bytes).
2026-05-29 06:44:50,873 [root] DEBUG: 5932: caller_dispatch: Added region at 0x75580000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x755AB711, thread 10280).
2026-05-29 06:44:50,874 [root] DEBUG: 5932: ProcessTrackedRegion: Region at 0x75580000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\SystemSettings.DataModel.dll is in known range, skipping
2026-05-29 06:44:50,882 [root] DEBUG: 5932: DLL loaded at 0x75410000: C:\Windows\SYSTEM32\USERENV (0x25000 bytes).
2026-05-29 06:44:50,895 [root] DEBUG: 5932: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-29 06:44:50,896 [root] DEBUG: 5932: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-29 06:44:50,906 [root] DEBUG: 5932: DLL loaded at 0x6FCF0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x3ba000 bytes).
2026-05-29 06:44:50,941 [root] DEBUG: 5932: DLL loaded at 0x77270000: C:\Windows\System32\CFGMGR32 (0x3b000 bytes).
2026-05-29 06:44:50,951 [root] DEBUG: 5932: DLL loaded at 0x754F0000: C:\Windows\System32\StructuredQuery (0x81000 bytes).
2026-05-29 06:44:50,967 [root] DEBUG: 5932: DLL loaded at 0x70910000: C:\Windows\SYSTEM32\PROPSYS (0xc2000 bytes).
2026-05-29 06:44:50,980 [root] DEBUG: 5932: DLL loaded at 0x6AAF0000: C:\Windows\System32\Windows.StateRepositoryPS (0x93000 bytes).
2026-05-29 06:44:51,018 [root] DEBUG: 5932: DLL loaded at 0x6AA50000: C:\Windows\system32\Windows.Storage.Search (0x9d000 bytes).
2026-05-29 06:44:51,060 [root] DEBUG: 5932: DLL loaded at 0x754E0000: C:\Windows\SYSTEM32\LINKINFO (0xb000 bytes).
2026-05-29 06:44:51,123 [root] DEBUG: 5932: DLL loaded at 0x6F0B0000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2026-05-29 06:44:51,136 [root] DEBUG: 5932: DLL loaded at 0x6AE60000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-05-29 06:44:51,156 [root] DEBUG: 5932: DLL loaded at 0x75340000: C:\Windows\system32\winhttp (0xca000 bytes).
2026-05-29 06:44:51,161 [root] DEBUG: 5932: DLL loaded at 0x6E3B0000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2026-05-29 06:44:51,165 [root] DEBUG: 5932: DLL loaded at 0x73FA0000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-05-29 06:44:51,166 [root] DEBUG: 5932: DLL loaded at 0x76290000: C:\Windows\System32\NSI (0x7000 bytes).
2026-05-29 06:44:51,170 [root] DEBUG: 5932: DLL loaded at 0x6BC10000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-05-29 06:44:51,173 [root] DEBUG: 5932: DLL loaded at 0x73F80000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-05-29 06:44:51,185 [root] DEBUG: 5932: DLL loaded at 0x6A9D0000: C:\Windows\SYSTEM32\webio (0x73000 bytes).
2026-05-29 06:44:51,190 [root] DEBUG: 5932: DLL loaded at 0x6E350000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-05-29 06:44:51,200 [root] DEBUG: 5932: DLL loaded at 0x6E2F0000: C:\Windows\SYSTEM32\WINNSI (0x8000 bytes).
2026-05-29 06:44:51,207 [root] DEBUG: 5932: DLL loaded at 0x702C0000: C:\Windows\SYSTEM32\DNSAPI (0x90000 bytes).
2026-05-29 06:44:51,212 [root] DEBUG: 5932: DLL loaded at 0x6D030000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2026-05-29 06:44:51,256 [root] DEBUG: 5932: DLL loaded at 0x6CFD0000: C:\Windows\System32\fwpuclnt (0x58000 bytes).
2026-05-29 06:44:51,629 [root] DEBUG: 5932: DLL loaded at 0x6CF50000: C:\Windows\System32\schannel (0x7c000 bytes).
2026-05-29 06:44:52,290 [root] DEBUG: 4104: DLL loaded at 0x00007FFF18180000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes).
2026-05-29 06:44:52,291 [root] DEBUG: 5932: DLL loaded at 0x6CF40000: C:\Windows\SYSTEM32\mskeyprotect (0x10000 bytes).
2026-05-29 06:44:52,292 [root] DEBUG: 5932: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-29 06:44:52,293 [root] DEBUG: 5932: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-29 06:44:52,295 [root] DEBUG: 5932: DLL loaded at 0x6CEF0000: C:\Windows\system32\ncryptsslp (0x1f000 bytes).
2026-05-29 06:44:52,297 [root] DEBUG: 5932: DLL loaded at 0x701B0000: C:\Windows\SYSTEM32\MSASN1 (0xe000 bytes).
2026-05-29 06:44:52,386 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 10500: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:52,387 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 10500
2026-05-29 06:44:52,388 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 10500
2026-05-29 06:44:52,645 [root] DEBUG: Error 87 (0x57) - OpenProcessHandler: Error obtaining target process name: The parameter is incorrect.
2026-05-29 06:44:52,647 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4, handle 0x73c: Error obtaining target process name
2026-05-29 06:44:52,647 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 124, handle 0x73c:
2026-05-29 06:44:52,648 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 384, handle 0x73c: C:\Windows\System32\smss.exe
2026-05-29 06:44:52,648 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 480, handle 0x73c: C:\Windows\System32\csrss.exe
2026-05-29 06:44:52,648 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 556, handle 0x73c: C:\Windows\System32\wininit.exe
2026-05-29 06:44:52,649 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 576, handle 0x73c: C:\Windows\System32\csrss.exe
2026-05-29 06:44:52,650 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 656, handle 0x73c: C:\Windows\System32\winlogon.exe
2026-05-29 06:44:52,650 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 676, handle 0x73c: C:\Windows\System32\services.exe
2026-05-29 06:44:52,650 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 724, handle 0x73c: C:\Windows\System32\lsass.exe
2026-05-29 06:44:52,651 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 832, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,651 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 860, handle 0x73c: C:\Windows\System32\fontdrvhost.exe
2026-05-29 06:44:52,652 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 868, handle 0x73c: C:\Windows\System32\fontdrvhost.exe
2026-05-29 06:44:52,652 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 948, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,653 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1004, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,653 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 472, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,654 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 772, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,654 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1048, handle 0x73c: C:\Windows\System32\dwm.exe
2026-05-29 06:44:52,655 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1096, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,655 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1136, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,656 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1164, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,656 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1268, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,657 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1284, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,657 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1292, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,658 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1308, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,658 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1352, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,658 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1444, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,659 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1596, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,661 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1632, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,661 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1644, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,662 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1664, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,662 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1828, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,663 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1852, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,663 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1860, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,664 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1868, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,664 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1992, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,665 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2020, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,665 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2036, handle 0x73c:
2026-05-29 06:44:52,666 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2124, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,666 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2224, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,666 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2240, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,667 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2296, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,667 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2344, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,668 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2456, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,668 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2472, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,669 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2520, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,669 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2696, handle 0x73c: C:\Windows\System32\spoolsv.exe
2026-05-29 06:44:52,669 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2724, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,670 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2772, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,670 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2876, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,671 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2896, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,671 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3012, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,672 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3020, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,672 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3040, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,673 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3048, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,673 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3056, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,674 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2292, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,674 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2820, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,675 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3396, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,676 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3892, handle 0x73c: C:\Windows\System32\SearchIndexer.exe
2026-05-29 06:44:52,677 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3992, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,677 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3500, handle 0x73c: C:\Windows\System32\sihost.exe
2026-05-29 06:44:52,678 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3416, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,678 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4148, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,679 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4240, handle 0x73c: C:\Windows\System32\taskhostw.exe
2026-05-29 06:44:52,679 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4300, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,680 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4380, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,680 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4484, handle 0x73c: C:\Windows\explorer.exe
2026-05-29 06:44:52,681 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4524, handle 0x73c: C:\Windows\System32\ctfmon.exe
2026-05-29 06:44:52,681 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4592, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,681 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4788, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,682 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4916, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,682 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5200, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,683 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5260, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,683 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5544, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,683 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5624, handle 0x73c: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2026-05-29 06:44:52,684 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5688, handle 0x73c: C:\Windows\System32\RuntimeBroker.exe
2026-05-29 06:44:52,684 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5800, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,685 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5892, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,685 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6008, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,686 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6136, handle 0x73c: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
2026-05-29 06:44:52,686 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5948, handle 0x73c: C:\Windows\System32\RuntimeBroker.exe
2026-05-29 06:44:52,687 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6436, handle 0x73c: C:\Windows\System32\RuntimeBroker.exe
2026-05-29 06:44:52,687 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6616, handle 0x73c: C:\Windows\System32\taskhostw.exe
2026-05-29 06:44:52,687 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6996, handle 0x73c: C:\Windows\System32\smartscreen.exe
2026-05-29 06:44:52,688 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 7052, handle 0x73c: C:\Windows\System32\SecurityHealthSystray.exe
2026-05-29 06:44:52,688 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 7088, handle 0x73c: C:\Windows\System32\SecurityHealthService.exe
2026-05-29 06:44:52,689 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6284, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,689 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3976, handle 0x73c: C:\Windows\System32\conhost.exe
2026-05-29 06:44:52,690 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1104, handle 0x73c: C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2026-05-29 06:44:52,690 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5128, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 06:44:52,691 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6768, handle 0x73c: C:\Program Files (x86)\Steam\steam.exe
2026-05-29 06:44:52,692 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6400, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 06:44:52,693 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6356, handle 0x73c: C:\Program Files (x86)\Common Files\Steam\steamservice.exe
2026-05-29 06:44:52,693 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6360, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 06:44:52,694 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6392, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 06:44:52,694 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2160, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 06:44:52,694 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6512, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 06:44:52,695 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6504, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 06:44:52,695 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 7444, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 06:44:52,696 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 7544, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 06:44:52,696 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 7844, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 06:44:52,697 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 8100, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 06:44:52,697 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 8340, handle 0x73c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-29 06:44:52,698 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 8108, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,698 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3820, handle 0x73c: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-29 06:44:52,699 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 8044, handle 0x73c: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
2026-05-29 06:44:52,699 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1740, handle 0x73c: C:\Windows\System32\dllhost.exe
2026-05-29 06:44:52,700 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1316, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,700 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 3404, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,701 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5364, handle 0x73c: C:\Windows\System32\SgrmBroker.exe
2026-05-29 06:44:52,701 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6640, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,702 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2580, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,702 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6028, handle 0x73c: C:\Windows\System32\MoUsoCoreWorker.exe
2026-05-29 06:44:52,702 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6188, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,703 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5116, handle 0x73c: C:\Windows\System32\backgroundTaskHost.exe
2026-05-29 06:44:52,703 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 8828, handle 0x73c: C:\Windows\System32\CompatTelRunner.exe
2026-05-29 06:44:52,704 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6280, handle 0x73c: C:\Windows\servicing\TrustedInstaller.exe
2026-05-29 06:44:52,704 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1028, handle 0x73c: C:\Windows\System32\notepad.exe
2026-05-29 06:44:52,705 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4932, handle 0x73c: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe
2026-05-29 06:44:52,706 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1016, handle 0x73c: C:\Windows\System32\RuntimeBroker.exe
2026-05-29 06:44:52,708 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2016, handle 0x73c: C:\Windows\System32\conhost.exe
2026-05-29 06:44:52,709 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2672, handle 0x73c: C:\Windows\System32\RuntimeBroker.exe
2026-05-29 06:44:52,709 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 6568, handle 0x73c: C:\Windows\System32\CompatTelRunner.exe
2026-05-29 06:44:52,710 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5040, handle 0x73c: C:\Windows\System32\sppsvc.exe
2026-05-29 06:44:52,710 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2916, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,711 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 8700, handle 0x73c: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-29 06:44:52,712 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4104, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,712 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1204, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,713 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2168, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,713 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 1332, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,714 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4760, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,714 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 4108, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,715 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 5820, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,715 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 8604, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,716 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 8504, handle 0x73c: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-29 06:44:52,716 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 7080, handle 0x73c: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-29 06:44:52,716 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 9328, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,717 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 9344, handle 0x73c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-29 06:44:52,717 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 9568, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,718 [root] DEBUG: 5932: OpenProcessHandler: Injection info created for process 2464, handle 0x73c: C:\Windows\System32\svchost.exe
2026-05-29 06:44:52,732 [root] DEBUG: 5932: DLL loaded at 0x6E2E0000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2026-05-29 06:44:52,733 [root] DEBUG: 5932: CreateProcessHandler: Injection info set for new process 11132: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe, ImageBase: 0x00150000
2026-05-29 06:44:52,734 [root] INFO: Announced 32-bit process name: MicrosoftEdgeUpdate.exe pid: 11132
2026-05-29 06:44:52,734 [lib.api.process] INFO: Monitor config for process 11132: C:\lpw_albt\dll\11132.ini
2026-05-29 06:44:52,735 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:44:52,736 [lib.api.process] INFO: 32-bit DLL to inject is C:\lpw_albt\dll\nxatNo.dll, loader C:\lpw_albt\bin\pNxCcCJ.exe
2026-05-29 06:44:52,743 [root] DEBUG: Loader: Injecting process 11132 (thread 11136) with C:\lpw_albt\dll\nxatNo.dll.
2026-05-29 06:44:52,744 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:44:52,744 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\nxatNo.dll.
2026-05-29 06:44:52,745 [lib.api.process] INFO: Injected into 32-bit <Process 11132 MicrosoftEdgeUpdate.exe>
2026-05-29 06:44:52,747 [root] DEBUG: 5932: DLL loaded at 0x74960000: C:\Windows\system32\apphelp (0x9f000 bytes).
2026-05-29 06:44:52,754 [root] DEBUG: 11132: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:44:52,755 [root] DEBUG: 11132: Interactive desktop enabled.
2026-05-29 06:44:52,755 [root] DEBUG: 11132: Dropped file limit defaulting to 100.
2026-05-29 06:44:52,757 [root] DEBUG: 11132: Disabling sleep skipping.
2026-05-29 06:44:52,759 [root] DEBUG: 11132: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:44:52,760 [root] DEBUG: 11132: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-29 06:44:52,761 [root] DEBUG: 11132: Monitor initialised: 32-bit capemon loaded in process 11132 at 0x6ab90000, thread 11136, image base 0x150000, stack from 0x2cf5000-0x2d00000
2026-05-29 06:44:52,762 [root] DEBUG: 11132: Commandline: "C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4yMzMuMyIgc2hlbGxfdmVyc2lvbj0iMS4zLjIzMy4zIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0iezkxRDY1M0YwLTc4OEItNDM2OS04M0ExLTRCMkJEM0U2OTdDOX0iIHVzZXJpZD0ie0JFRkJDQjc3LTYzRjgtNDI5RS04ODYzLUYwREM4MjE0REVFNn0iIGluc3RhbGxzb3VyY2U9InNjaGVkdWxlciIgcmVxdWVzdGlkPSJ7NzUzRDU2OEQtQ0EyOS00OTU2LUFBNEMtRDJGNkI4M
2026-05-29 06:44:52,784 [root] DEBUG: 11132: hook_api: LdrpCallInitRoutine export address 0x77812B50 obtained via GetFunctionAddress
2026-05-29 06:44:52,802 [root] DEBUG: 11132: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-05-29 06:44:52,803 [root] DEBUG: 11132: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-05-29 06:44:52,807 [root] DEBUG: 11132: Hooked 632 out of 632 functions
2026-05-29 06:44:52,808 [root] DEBUG: 11132: Syscall hook installed, syscall logging level 1
2026-05-29 06:44:52,812 [root] DEBUG: 11132: RestoreHeaders: Restored original import table.
2026-05-29 06:44:52,812 [root] INFO: Loaded monitor into process with pid 11132
2026-05-29 06:44:52,813 [root] DEBUG: 11132: caller_dispatch: Added region at 0x00150000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0015D98E, thread 11136).
2026-05-29 06:44:52,814 [root] DEBUG: 11132: YaraScan: Scanning 0x00150000, size 0x34220
2026-05-29 06:44:52,815 [root] DEBUG: 11132: ProcessImageBase: Main module image at 0x00150000 unmodified (entropy change 0.000000e+00)
2026-05-29 06:44:52,818 [root] DEBUG: 11132: DLL loaded at 0x74A30000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-05-29 06:44:52,819 [root] DEBUG: 11132: DLL loaded at 0x74A60000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-05-29 06:44:52,820 [root] DEBUG: 11132: DLL loaded at 0x75F00000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-05-29 06:44:52,823 [root] DEBUG: 11132: DLL loaded at 0x70670000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-05-29 06:44:52,824 [root] DEBUG: 11132: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-05-29 06:44:52,824 [root] DEBUG: 11132: DLL loaded at 0x75450000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-05-29 06:44:52,825 [root] DEBUG: 11132: DLL loaded at 0x74890000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-05-29 06:44:52,825 [root] DEBUG: 11132: DLL loaded at 0x748A0000: C:\Windows\SYSTEM32\WKSCLI (0x11000 bytes).
2026-05-29 06:44:52,826 [root] DEBUG: 11132: DLL loaded at 0x6AEB0000: C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.233.3\msedgeupdate (0x23d000 bytes).
2026-05-29 06:44:52,832 [root] DEBUG: 11132: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-29 06:44:52,833 [root] DEBUG: 11132: DLL loaded at 0x6A970000: C:\Windows\system32\MDMRegistration (0x53000 bytes).
2026-05-29 06:44:52,839 [root] DEBUG: 11132: DLL loaded at 0x6F2A0000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-05-29 06:44:52,840 [root] DEBUG: 11132: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-05-29 06:44:52,841 [root] DEBUG: 11132: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-29 06:44:52,841 [root] DEBUG: 11132: DLL loaded at 0x76790000: C:\Windows\System32\imagehlp (0x19000 bytes).
2026-05-29 06:44:52,842 [root] DEBUG: 11132: DLL loaded at 0x6A8E0000: C:\Windows\SYSTEM32\tbs (0x13000 bytes).
2026-05-29 06:44:52,842 [root] DEBUG: 11132: DLL loaded at 0x6A900000: C:\Windows\SYSTEM32\DMCmnUtils (0x63000 bytes).
2026-05-29 06:44:52,843 [root] DEBUG: 11132: DLL loaded at 0x754B0000: C:\Windows\SYSTEM32\omadmapi (0x2c000 bytes).
2026-05-29 06:44:52,849 [root] DEBUG: 11132: DLL loaded at 0x6F290000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-05-29 06:44:52,851 [root] DEBUG: 11132: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-29 06:44:52,854 [root] DEBUG: 11132: DLL loaded at 0x6EBD0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-05-29 06:44:52,854 [root] DEBUG: 11132: DLL loaded at 0x741D0000: C:\Windows\SYSTEM32\cryptsp (0x13000 bytes).
2026-05-29 06:44:52,855 [root] DEBUG: 11132: DLL loaded at 0x6EC40000: C:\Windows\SYSTEM32\DSREG (0x107000 bytes).
2026-05-29 06:44:52,859 [root] DEBUG: 11132: DLL loaded at 0x74180000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-05-29 06:44:52,880 [root] DEBUG: 11132: DLL loaded at 0x74950000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-05-29 06:44:52,881 [root] DEBUG: 11132: DLL loaded at 0x75DF0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-05-29 06:44:52,884 [root] DEBUG: 11132: DLL loaded at 0x6AE60000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-05-29 06:44:52,890 [root] DEBUG: 11132: DLL loaded at 0x73FA0000: C:\Windows\SYSTEM32\Iphlpapi (0x32000 bytes).
2026-05-29 06:44:52,891 [root] DEBUG: 11132: DLL loaded at 0x76290000: C:\Windows\System32\NSI (0x7000 bytes).
2026-05-29 06:44:52,893 [root] DEBUG: 11132: DLL loaded at 0x73F80000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-05-29 06:44:52,895 [root] DEBUG: 11132: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-29 06:44:52,895 [root] DEBUG: 11132: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-29 06:44:52,898 [root] DEBUG: 11132: DLL loaded at 0x73E90000: C:\Windows\SYSTEM32\diagnosticdataquery (0xc000 bytes).
2026-05-29 06:44:52,899 [root] DEBUG: 11132: DLL loaded at 0x76650000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-05-29 06:44:52,900 [root] DEBUG: 11132: DLL loaded at 0x6F0B0000: C:\Windows\System32\msxml6 (0x1dd000 bytes).
2026-05-29 06:44:52,906 [root] DEBUG: 11132: DLL loaded at 0x73EB0000: C:\Windows\System32\netprofm (0x32000 bytes).
2026-05-29 06:44:52,916 [root] DEBUG: 11132: DLL loaded at 0x73EA0000: C:\Windows\System32\npmproxy (0xa000 bytes).
2026-05-29 06:44:52,932 [root] DEBUG: 11132: DLL loaded at 0x75340000: C:\Windows\system32\winhttp (0xca000 bytes).
2026-05-29 06:44:52,934 [root] DEBUG: 11132: DLL loaded at 0x6E3B0000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2026-05-29 06:44:52,938 [root] DEBUG: 11132: DLL loaded at 0x6BC10000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-05-29 06:44:52,950 [root] DEBUG: 11132: DLL loaded at 0x6A9D0000: C:\Windows\SYSTEM32\webio (0x73000 bytes).
2026-05-29 06:44:52,951 [root] DEBUG: 11132: DLL loaded at 0x6E350000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-05-29 06:44:52,952 [root] DEBUG: 11132: DLL loaded at 0x6E2F0000: C:\Windows\SYSTEM32\WINNSI (0x8000 bytes).
2026-05-29 06:44:52,957 [root] DEBUG: 11132: DLL loaded at 0x702C0000: C:\Windows\SYSTEM32\DNSAPI (0x90000 bytes).
2026-05-29 06:44:52,958 [root] DEBUG: 11132: DLL loaded at 0x6D030000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2026-05-29 06:44:52,983 [root] DEBUG: 11132: DLL loaded at 0x6CFD0000: C:\Windows\System32\fwpuclnt (0x58000 bytes).
2026-05-29 06:44:53,005 [root] DEBUG: 11132: DLL loaded at 0x6CF50000: C:\Windows\System32\schannel (0x7c000 bytes).
2026-05-29 06:44:53,029 [root] DEBUG: 11132: DLL loaded at 0x6CF40000: C:\Windows\SYSTEM32\mskeyprotect (0x10000 bytes).
2026-05-29 06:44:53,029 [root] DEBUG: 11132: DLL loaded at 0x70200000: C:\Windows\SYSTEM32\NTASN1 (0x28000 bytes).
2026-05-29 06:44:53,030 [root] DEBUG: 11132: DLL loaded at 0x70D00000: C:\Windows\SYSTEM32\ncrypt (0x21000 bytes).
2026-05-29 06:44:53,031 [root] DEBUG: 11132: DLL loaded at 0x6CEF0000: C:\Windows\system32\ncryptsslp (0x1f000 bytes).
2026-05-29 06:44:53,033 [root] DEBUG: 11132: DLL loaded at 0x701B0000: C:\Windows\SYSTEM32\MSASN1 (0xe000 bytes).
2026-05-29 06:44:53,263 [root] DEBUG: 11132: DLL loaded at 0x6E2E0000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2026-05-29 06:44:53,269 [root] INFO: Added new file to list with pid 11132 and path C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log
2026-05-29 06:44:53,270 [root] DEBUG: 11132: NtTerminateProcess hook: Attempting to dump process 11132
2026-05-29 06:44:53,271 [root] DEBUG: 11132: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:44:53,276 [root] INFO: Process with pid 11132 has terminated
2026-05-29 06:44:53,285 [root] DEBUG: 5932: NtTerminateProcess hook: Attempting to dump process 5932
2026-05-29 06:44:53,285 [root] DEBUG: 5932: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:44:53,293 [root] INFO: Process with pid 5932 has terminated
2026-05-29 06:44:55,897 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 11408: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:44:55,899 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 11408
2026-05-29 06:44:55,900 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 11408
2026-05-29 06:45:20,815 [root] DEBUG: 4484: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-29 06:45:20,823 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 11836: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF652CF0000
2026-05-29 06:45:20,824 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 11836
2026-05-29 06:45:20,824 [lib.api.process] INFO: Monitor config for process 11836: C:\lpw_albt\dll\11836.ini
2026-05-29 06:45:20,826 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:20,828 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:20,835 [root] DEBUG: Loader: Injecting process 11836 (thread 11840) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:20,836 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:45:20,836 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:20,838 [lib.api.process] INFO: Injected into 64-bit <Process 11836 SecurityHealthHost.exe>
2026-05-29 06:45:20,840 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 11836
2026-05-29 06:45:20,840 [lib.api.process] INFO: Monitor config for process 11836: C:\lpw_albt\dll\11836.ini
2026-05-29 06:45:20,840 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:20,842 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:20,846 [root] DEBUG: Loader: Injecting process 11836 (thread 11840) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:20,846 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:45:20,847 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:20,848 [lib.api.process] INFO: Injected into 64-bit <Process 11836 SecurityHealthHost.exe>
2026-05-29 06:45:20,858 [root] DEBUG: 11836: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:45:20,859 [root] DEBUG: 11836: Interactive desktop enabled.
2026-05-29 06:45:20,859 [root] DEBUG: 11836: Dropped file limit defaulting to 100.
2026-05-29 06:45:20,862 [root] DEBUG: 11836: Disabling sleep skipping.
2026-05-29 06:45:20,864 [root] DEBUG: 11836: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:45:20,876 [root] DEBUG: 11836: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:45:20,876 [root] DEBUG: 11836: YaraScan: Scanning 0x00007FF652CF0000, size 0x19174
2026-05-29 06:45:20,877 [root] DEBUG: 11836: Monitor initialised: 64-bit capemon loaded in process 11836 at 0x00007FFF18240000, thread 11840, image base 0x00007FF652CF0000, stack from 0x000000E02A964000-0x000000E02A970000
2026-05-29 06:45:20,878 [root] DEBUG: 11836: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-05-29 06:45:20,890 [root] DEBUG: 11836: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 06:45:20,913 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 06:45:20,914 [root] DEBUG: 11836: set_hooks: Unable to hook LockResource
2026-05-29 06:45:20,920 [root] DEBUG: 11836: Hooked 627 out of 628 functions
2026-05-29 06:45:20,922 [root] DEBUG: 11836: Syscall hook installed, syscall logging level 1
2026-05-29 06:45:20,933 [root] DEBUG: 11836: RestoreHeaders: Restored original import table.
2026-05-29 06:45:20,933 [root] INFO: Loaded monitor into process with pid 11836
2026-05-29 06:45:20,934 [root] DEBUG: 11836: caller_dispatch: Added region at 0x00007FF652CF0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF652CFD3B2, thread 11840).
2026-05-29 06:45:20,935 [root] DEBUG: 11836: YaraScan: Scanning 0x00007FF652CF0000, size 0x19174
2026-05-29 06:45:20,937 [root] DEBUG: 11836: ProcessImageBase: Main module image at 0x00007FF652CF0000 unmodified (entropy change 0.000000e+00)
2026-05-29 06:45:20,940 [root] DEBUG: 11836: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 06:45:20,941 [root] DEBUG: 11836: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 06:45:20,943 [root] DEBUG: 11836: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 06:45:20,961 [root] DEBUG: 11836: DLL loaded at 0x00007FFF56FA0000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-29 06:45:20,962 [root] DEBUG: 11836: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:20,962 [root] DEBUG: 11836: DLL loaded at 0x00007FFF18110000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-05-29 06:45:20,977 [root] DEBUG: 11836: DLL loaded at 0x00007FFF4C1E0000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-05-29 06:45:20,984 [root] DEBUG: 11836: DLL loaded at 0x00007FFF52B60000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-05-29 06:45:20,995 [root] DEBUG: 11836: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 06:45:20,996 [root] DEBUG: 11836: DLL loaded at 0x00007FFF52DC0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-29 06:45:20,997 [root] DEBUG: 11836: DLL loaded at 0x00007FFF55410000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-05-29 06:45:20,998 [root] DEBUG: 11836: DLL loaded at 0x00007FFF523E0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-05-29 06:45:20,999 [root] DEBUG: 11836: DLL loaded at 0x00007FFF517C0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-29 06:45:20,999 [root] DEBUG: 11836: DLL loaded at 0x00007FFF40FB0000: C:\Windows\System32\wpnapps (0x15b000 bytes).
2026-05-29 06:45:21,008 [root] DEBUG: 11836: DLL loaded at 0x00007FFF52490000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-05-29 06:45:21,019 [root] DEBUG: 11836: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 06:45:21,031 [root] DEBUG: 11836: DLL loaded at 0x00007FFF3FD40000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes).
2026-05-29 06:45:21,064 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE131000, size: 0x1000.
2026-05-29 06:45:21,065 [root] DEBUG: 11836: NtTerminateProcess hook: Attempting to dump process 11836
2026-05-29 06:45:21,066 [root] DEBUG: 11836: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:45:21,072 [root] DEBUG: 4484: AllocationHandler: Adding allocation to tracked region list: 0x00007DF4AE121000, size: 0x1000.
2026-05-29 06:45:21,078 [root] INFO: Process with pid 11836 has terminated
2026-05-29 06:45:21,079 [root] DEBUG: 4484: AllocationHandler: Allocation already in tracked region list: 0x00007DF4AE130000.
2026-05-29 06:45:21,129 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 12232: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF65DCB0000
2026-05-29 06:45:21,130 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 12232
2026-05-29 06:45:21,131 [lib.api.process] INFO: Monitor config for process 12232: C:\lpw_albt\dll\12232.ini
2026-05-29 06:45:21,133 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:21,857 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:21,862 [root] DEBUG: Loader: Injecting process 12232 (thread 12236) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:21,863 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:45:21,864 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:21,865 [lib.api.process] INFO: Injected into 64-bit <Process 12232 ShellExperienceHost.exe>
2026-05-29 06:45:21,867 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 12232
2026-05-29 06:45:21,867 [lib.api.process] INFO: Monitor config for process 12232: C:\lpw_albt\dll\12232.ini
2026-05-29 06:45:21,868 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:22,234 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 10244: C:\Windows\system32\sppsvc.exe, ImageBase: 0x0000000000000000
2026-05-29 06:45:22,235 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 10272
2026-05-29 06:45:22,235 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 10244
2026-05-29 06:45:22,236 [lib.api.process] INFO: Monitor config for process 10244: C:\lpw_albt\dll\10244.ini
2026-05-29 06:45:22,237 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:22,240 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:22,245 [root] DEBUG: Loader: Injecting process 10244 (thread 10272) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,247 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\10244.ini to system path C:\10244.ini
2026-05-29 06:45:22,248 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 10244 C:\lpw_albt\dll\yCvZHFYF.dll
2026-05-29 06:45:22,249 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,251 [lib.api.process] INFO: Injected into 64-bit <Process 10244 sppsvc.exe>
2026-05-29 06:45:22,252 [lib.api.process] WARNING: OpenThread(THREAD_ALL_ACCESS, ...) failed for thread 10272
2026-05-29 06:45:22,252 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 10244
2026-05-29 06:45:22,253 [lib.api.process] INFO: Monitor config for process 10244: C:\lpw_albt\dll\10244.ini
2026-05-29 06:45:22,254 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:22,257 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:22,262 [root] DEBUG: Loader: Injecting process 10244 (thread 10272) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,264 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\10244.ini to system path C:\10244.ini
2026-05-29 06:45:22,266 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 10244 C:\lpw_albt\dll\yCvZHFYF.dll
2026-05-29 06:45:22,267 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,268 [lib.api.process] INFO: Injected into 64-bit <Process 10244 sppsvc.exe>
2026-05-29 06:45:22,270 [root] INFO: Announced 64-bit process name: sppsvc.exe pid: 10244
2026-05-29 06:45:22,270 [lib.api.process] INFO: Monitor config for process 10244: C:\lpw_albt\dll\10244.ini
2026-05-29 06:45:22,271 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:22,274 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:22,281 [root] DEBUG: Loader: Injecting process 10244 with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,282 [root] DEBUG: Loader: Copied config file C:\lpw_albt\dll\10244.ini to system path C:\10244.ini
2026-05-29 06:45:22,284 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 10244 C:\lpw_albt\dll\yCvZHFYF.dll
2026-05-29 06:45:22,285 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,286 [lib.api.process] INFO: Injected into 64-bit <Process 10244 sppsvc.exe>
2026-05-29 06:45:22,294 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 9388: C:\Windows\System32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-29 06:45:22,295 [root] INFO: Announced 64-bit process name: svchost.exe pid: 9388
2026-05-29 06:45:22,295 [lib.api.process] INFO: Monitor config for process 9388: C:\lpw_albt\dll\9388.ini
2026-05-29 06:45:22,296 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:22,300 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:22,305 [root] DEBUG: Loader: Injecting process 9388 (thread 9348) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,306 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:45:22,307 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,310 [lib.api.process] INFO: Injected into 64-bit <Process 9388 svchost.exe>
2026-05-29 06:45:22,312 [root] INFO: Announced 64-bit process name: svchost.exe pid: 9388
2026-05-29 06:45:22,312 [lib.api.process] INFO: Monitor config for process 9388: C:\lpw_albt\dll\9388.ini
2026-05-29 06:45:22,313 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:22,317 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:22,324 [root] DEBUG: Loader: Injecting process 9388 (thread 9348) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,325 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:45:22,326 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,328 [lib.api.process] INFO: Injected into 64-bit <Process 9388 svchost.exe>
2026-05-29 06:45:22,329 [root] INFO: Announced 64-bit process name: svchost.exe pid: 9388
2026-05-29 06:45:22,330 [lib.api.process] INFO: Monitor config for process 9388: C:\lpw_albt\dll\9388.ini
2026-05-29 06:45:22,331 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:22,335 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:22,340 [root] DEBUG: Loader: Injecting process 9388 with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,341 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 9348, handle 0x120
2026-05-29 06:45:22,341 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:45:22,342 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,344 [lib.api.process] INFO: Injected into 64-bit <Process 9388 svchost.exe>
2026-05-29 06:45:22,352 [root] DEBUG: 9388: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:45:22,353 [root] DEBUG: 9388: Interactive desktop enabled.
2026-05-29 06:45:22,355 [root] DEBUG: 9388: Dropped file limit defaulting to 100.
2026-05-29 06:45:22,355 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56140000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-05-29 06:45:22,356 [root] DEBUG: 4104: DLL loaded at 0x00007FFF56170000: C:\Windows\system32\slc (0x29000 bytes).
2026-05-29 06:45:22,358 [root] DEBUG: 9388: Disabling sleep skipping.
2026-05-29 06:45:22,359 [root] DEBUG: 4104: DLL loaded at 0x00007FFF17400000: C:\Windows\system32\slwga (0x19000 bytes).
2026-05-29 06:45:22,360 [root] DEBUG: 9388: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:45:22,373 [root] DEBUG: 9388: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:45:22,374 [root] DEBUG: 9388: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-29 06:45:22,375 [root] DEBUG: 9388: Monitor initialised: 64-bit capemon loaded in process 9388 at 0x00007FFF18240000, thread 9348, image base 0x00007FF7BF220000, stack from 0x000000EA5B274000-0x000000EA5B280000
2026-05-29 06:45:22,376 [root] DEBUG: 9388: Commandline: C:\Windows\System32\svchost.exe -k WerSvcGroup
2026-05-29 06:45:22,387 [root] DEBUG: 4104: DLL loaded at 0x00007FFF17220000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes).
2026-05-29 06:45:22,388 [root] DEBUG: 9388: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 06:45:22,410 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 06:45:22,411 [root] DEBUG: 9388: set_hooks: Unable to hook LockResource
2026-05-29 06:45:22,415 [root] DEBUG: 9388: Hooked 627 out of 628 functions
2026-05-29 06:45:22,417 [root] DEBUG: 9388: Syscall hook installed, syscall logging level 1
2026-05-29 06:45:22,421 [root] DEBUG: 9388: RestoreHeaders: Restored original import table.
2026-05-29 06:45:22,422 [root] INFO: Loaded monitor into process with pid 9388
2026-05-29 06:45:22,423 [root] DEBUG: 9388: caller_dispatch: Added region at 0x00007FF7BF220000 to tracked regions list (kernel32::GetCommandLineW returns to 0x00007FF7BF2250EA, thread 9348).
2026-05-29 06:45:22,423 [root] DEBUG: 9388: YaraScan: Scanning 0x00007FF7BF220000, size 0xf06a
2026-05-29 06:45:22,424 [root] DEBUG: 9388: ProcessImageBase: Main module image at 0x00007FF7BF220000 unmodified (entropy change 0.000000e+00)
2026-05-29 06:45:22,433 [root] DEBUG: 9388: DLL loaded at 0x00007FFF523E0000: c:\windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:22,434 [root] DEBUG: 9388: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 06:45:22,435 [root] DEBUG: 9388: DLL loaded at 0x00007FFF3E0F0000: c:\windows\system32\WindowsPerformanceRecorderControl (0x12d000 bytes).
2026-05-29 06:45:22,436 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 1196: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:45:22,436 [root] DEBUG: 9388: DLL loaded at 0x00007FFF17190000: c:\windows\system32\WerEtw (0x3f000 bytes).
2026-05-29 06:45:22,437 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 1196
2026-05-29 06:45:22,438 [root] DEBUG: 9388: DLL loaded at 0x00007FFF171D0000: c:\windows\system32\wersvc (0x45000 bytes).
2026-05-29 06:45:22,438 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 1196
2026-05-29 06:45:22,442 [root] DEBUG: 9388: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-29 06:45:22,447 [root] DEBUG: 9388: DLL loaded at 0x00007FFF55330000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-29 06:45:22,455 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,456 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,461 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,462 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,466 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,467 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,479 [root] DEBUG: 9388: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 06:45:22,488 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,489 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,494 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,494 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:22,495 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,499 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,500 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,500 [root] DEBUG: Loader: Injecting process 12232 (thread 12236) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,501 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:45:22,502 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:22,505 [lib.api.process] INFO: Injected into 64-bit <Process 12232 ShellExperienceHost.exe>
2026-05-29 06:45:22,506 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 12232
2026-05-29 06:45:22,506 [lib.api.process] INFO: Monitor config for process 12232: C:\lpw_albt\dll\12232.ini
2026-05-29 06:45:22,507 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:22,512 [root] DEBUG: 9388: OpenProcessHandler: Injection info created for process 8756, handle 0x2a4: C:\lpw_albt\bin\PPLinject64.exe
2026-05-29 06:45:22,513 [root] DEBUG: 9388: OpenProcessHandler: Image base for process 8756 (handle 0x2a4): 0x00007FF68CAE0000.
2026-05-29 06:45:22,517 [root] DEBUG: 9388: DLL loaded at 0x00007FFF55710000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-29 06:45:22,519 [root] DEBUG: 9388: CreateProcessHandler: Injection info set for new process 2104: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF78EB10000
2026-05-29 06:45:22,520 [root] DEBUG: 9388: ProcessMessage: Skipping monitoring process 2104
2026-05-29 06:45:22,525 [root] DEBUG: 9388: ProcessMessage: Skipping monitoring process 2104
2026-05-29 06:45:22,609 [root] DEBUG: 9388: DLL loaded at 0x00007FFF47530000: c:\windows\system32\dbghelp (0x1e4000 bytes).
2026-05-29 06:45:22,610 [root] DEBUG: 9388: DLL loaded at 0x00007FFF474F0000: c:\windows\system32\dbgcore (0x34000 bytes).
2026-05-29 06:45:22,611 [root] DEBUG: 9388: DLL loaded at 0x00007FFF46350000: c:\windows\system32\faultrep (0x7b000 bytes).
2026-05-29 06:45:22,615 [root] DEBUG: 9388: DLL loaded at 0x00007FFF55330000: c:\windows\system32\wer (0xde000 bytes).
2026-05-29 06:45:22,622 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,623 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,630 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,631 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,634 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,636 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,641 [root] DEBUG: 4104: DLL loaded at 0x00007FFEFBAE0000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes).
2026-05-29 06:45:22,652 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,653 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,658 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,658 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,663 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,664 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,677 [root] DEBUG: 9388: DLL loaded at 0x00007FFF57520000: c:\windows\system32\USERENV (0x2e000 bytes).
2026-05-29 06:45:22,679 [root] DEBUG: 9388: DLL loaded at 0x00007FFF57560000: c:\windows\system32\profapi (0x25000 bytes).
2026-05-29 06:45:22,690 [root] DEBUG: 9388: CreateProcessHandler: Injection info set for new process 7024: C:\Windows\system32\WerFault.exe, ImageBase: 0x00007FF78EB10000
2026-05-29 06:45:22,692 [root] DEBUG: 9388: ProcessMessage: Skipping monitoring process 7024
2026-05-29 06:45:22,694 [root] DEBUG: 9388: ProcessMessage: Skipping monitoring process 7024
2026-05-29 06:45:22,880 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,881 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,884 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,885 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,888 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,889 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,897 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERC3DE.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERC3DE.tmp'
2026-05-29 06:45:22,898 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERC3DE.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERC3DE.tmp'
2026-05-29 06:45:22,918 [root] DEBUG: 9388: api-rate-cap: NtWriteFile hook disabled due to rate
2026-05-29 06:45:22,936 [root] INFO: Added new file to list with pid 9388 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WERC3DE.tmp.csv
2026-05-29 06:45:22,942 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,943 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,947 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,948 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,953 [root] DEBUG: 9388: DLL loaded at 0x00007FFF566C0000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:22,954 [root] DEBUG: 9388: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:22,961 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERC41D.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERC41D.tmp'
2026-05-29 06:45:22,963 [root] INFO: Error dumping file from path "C:\ProgramData\Microsoft\Windows\WER\Temp\WERC41D.tmp": [Errno 13] Permission denied: 'C:\\ProgramData\\Microsoft\\Windows\\WER\\Temp\\WERC41D.tmp'
2026-05-29 06:45:22,968 [root] INFO: Added new file to list with pid 9388 and path C:\ProgramData\Microsoft\Windows\WER\Temp\WERC41D.tmp.txt
2026-05-29 06:45:23,086 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:23,092 [root] DEBUG: Loader: Injecting process 12232 with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:23,093 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12236, handle 0x120
2026-05-29 06:45:23,094 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:45:23,094 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:23,096 [lib.api.process] INFO: Injected into 64-bit <Process 12232 ShellExperienceHost.exe>
2026-05-29 06:45:42,448 [root] INFO: Announced starting service "b'wisvc'"
2026-05-29 06:45:43,465 [root] DEBUG: 676: CreateProcessHandler: Injection info set for new process 12224: C:\Windows\system32\svchost.exe, ImageBase: 0x00007FF7BF220000
2026-05-29 06:45:43,466 [root] INFO: Announced 64-bit process name: svchost.exe pid: 12224
2026-05-29 06:45:43,467 [lib.api.process] INFO: Monitor config for process 12224: C:\lpw_albt\dll\12224.ini
2026-05-29 06:45:43,468 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:43,471 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:43,476 [root] DEBUG: Loader: Injecting process 12224 (thread 12228) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:43,477 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:45:43,478 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:43,479 [lib.api.process] INFO: Injected into 64-bit <Process 12224 svchost.exe>
2026-05-29 06:45:43,481 [root] INFO: Announced 64-bit process name: svchost.exe pid: 12224
2026-05-29 06:45:43,481 [lib.api.process] INFO: Monitor config for process 12224: C:\lpw_albt\dll\12224.ini
2026-05-29 06:45:43,482 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:43,485 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:43,489 [root] DEBUG: Loader: Injecting process 12224 (thread 12228) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:43,490 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:45:43,491 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:43,492 [lib.api.process] INFO: Injected into 64-bit <Process 12224 svchost.exe>
2026-05-29 06:45:43,493 [root] INFO: Announced 64-bit process name: svchost.exe pid: 12224
2026-05-29 06:45:43,494 [lib.api.process] INFO: Monitor config for process 12224: C:\lpw_albt\dll\12224.ini
2026-05-29 06:45:43,495 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:43,499 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:43,503 [root] DEBUG: Loader: Injecting process 12224 with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:43,504 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 12228, handle 0x120
2026-05-29 06:45:43,505 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-29 06:45:43,505 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:43,507 [lib.api.process] INFO: Injected into 64-bit <Process 12224 svchost.exe>
2026-05-29 06:45:43,520 [root] DEBUG: 12224: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:45:43,521 [root] DEBUG: 12224: Interactive desktop enabled.
2026-05-29 06:45:43,522 [root] DEBUG: 12224: Dropped file limit defaulting to 100.
2026-05-29 06:45:43,522 [root] DEBUG: 12224: Disabling sleep skipping.
2026-05-29 06:45:43,523 [root] DEBUG: 12224: Services hook set enabled
2026-05-29 06:45:43,526 [root] DEBUG: 12224: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:45:43,537 [root] DEBUG: 12224: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:45:43,538 [root] DEBUG: 12224: Monitor initialised: 64-bit capemon loaded in process 12224 at 0x00007FFF18240000, thread 12228, image base 0x00007FF7BF220000, stack from 0x00000081BD184000-0x00000081BD190000
2026-05-29 06:45:43,539 [root] DEBUG: 12224: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-29 06:45:43,555 [root] DEBUG: 12224: Hooked 69 out of 69 functions
2026-05-29 06:45:43,557 [root] DEBUG: 12224: RestoreHeaders: Restored original import table.
2026-05-29 06:45:43,558 [root] INFO: Loaded monitor into process with pid 12224
2026-05-29 06:45:43,559 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 06:45:43,560 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 06:45:43,561 [root] DEBUG: 12224: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 06:45:43,564 [root] DEBUG: 12224: DLL loaded at 0x00007FFF40A10000: c:\windows\system32\flightsettings (0xe6000 bytes).
2026-05-29 06:45:43,564 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56FA0000: C:\Windows\SYSTEM32\WLDP (0x2d000 bytes).
2026-05-29 06:45:43,568 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52B00000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-05-29 06:45:43,570 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57360000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes).
2026-05-29 06:45:43,571 [root] DEBUG: 12224: DLL loaded at 0x00007FFF50870000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes).
2026-05-29 06:45:43,573 [root] DEBUG: 12224: DLL loaded at 0x00007FFF48780000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-29 06:45:43,576 [root] DEBUG: 12224: DLL loaded at 0x00007FFF566C0000: c:\windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-29 06:45:43,576 [root] DEBUG: 12224: DLL loaded at 0x00007FFF522D0000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-29 06:45:43,578 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56EF0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-29 06:45:43,578 [root] DEBUG: 12224: DLL loaded at 0x00007FFF188A0000: C:\Windows\System32\wosc (0x4e000 bytes).
2026-05-29 06:45:43,585 [root] DEBUG: 12224: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 06:45:43,585 [root] DEBUG: 12224: DLL loaded at 0x00007FFF42490000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-05-29 06:45:43,587 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4F560000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-05-29 06:45:43,590 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52DC0000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-05-29 06:45:43,591 [root] DEBUG: 12224: DLL loaded at 0x00007FFF569F0000: C:\Windows\System32\IPHLPAPI (0x3b000 bytes).
2026-05-29 06:45:43,592 [root] DEBUG: 12224: DLL loaded at 0x00007FFF58B20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-29 06:45:43,594 [root] DEBUG: 12224: DLL loaded at 0x00007FFF40900000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-05-29 06:45:43,596 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57560000: C:\Windows\System32\profapi (0x25000 bytes).
2026-05-29 06:45:43,596 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4F590000: C:\Windows\System32\Cabinet (0x29000 bytes).
2026-05-29 06:45:43,597 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57520000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-29 06:45:43,597 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57AA0000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-05-29 06:45:43,598 [root] DEBUG: 12224: DLL loaded at 0x00007FFF3EE40000: C:\Windows\System32\UpdatePolicy (0x43000 bytes).
2026-05-29 06:45:43,599 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57130000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-05-29 06:45:43,601 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D6A0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-29 06:45:43,601 [root] DEBUG: 12224: DLL loaded at 0x00007FFF47980000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-05-29 06:45:43,617 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,617 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,619 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,620 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,620 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,621 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,622 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,623 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,627 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:43,630 [root] DEBUG: 12224: DLL loaded at 0x00007FFF3E220000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-05-29 06:45:43,637 [root] DEBUG: 12224: DLL loaded at 0x00007FFF42C10000: C:\Windows\system32\fcon (0x45000 bytes).
2026-05-29 06:45:43,642 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56630000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-29 06:45:43,660 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,661 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,662 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,663 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,664 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,665 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,665 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,667 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,669 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:43,670 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:43,675 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:43,675 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:43,676 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:43,677 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:43,677 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:43,678 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:43,679 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:43,680 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:43,681 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:43,682 [root] DEBUG: 12224: DLL loaded at 0x00007FFF17420000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:43,718 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,719 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,722 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,722 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,723 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,724 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,725 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,726 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,728 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:43,756 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,758 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,760 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,761 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,762 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,763 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,764 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,766 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,769 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:43,770 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:43,772 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:43,774 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:43,774 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:43,775 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:43,777 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:43,778 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:43,779 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:43,780 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:43,781 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:43,781 [root] DEBUG: 12224: DLL loaded at 0x00007FFF17420000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:43,808 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,809 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,812 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,813 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,814 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,814 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,815 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,816 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,817 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:43,841 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,842 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,843 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,844 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,845 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,845 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,846 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,846 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,848 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:43,849 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:43,852 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:43,852 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:43,853 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:43,854 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:43,855 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:43,856 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:43,856 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:43,857 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:43,858 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:43,859 [root] DEBUG: 12224: DLL loaded at 0x00007FFF17420000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:43,887 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,888 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,890 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,891 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,891 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,892 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,893 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,893 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,895 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:43,922 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,922 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,924 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,924 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,925 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,926 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,927 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,927 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,929 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:43,930 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:43,933 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:43,934 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:43,934 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:43,935 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:43,936 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:43,937 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:43,937 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:43,938 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:43,938 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:43,939 [root] DEBUG: 12224: DLL loaded at 0x00007FFF17420000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:43,962 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,963 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,965 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,966 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,966 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,967 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,968 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,969 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:43,970 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:43,992 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:43,992 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:43,994 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:43,995 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:43,996 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:43,996 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:43,997 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:43,998 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,000 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:44,000 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:44,003 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:44,004 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:44,005 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:44,006 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:44,006 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:44,007 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:44,008 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:44,010 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:44,012 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:44,013 [root] DEBUG: 12224: DLL loaded at 0x00007FFF17420000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:44,080 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,081 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,083 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,085 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,086 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,087 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,087 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,089 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,090 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:44,112 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,113 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,114 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,115 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,115 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,116 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,117 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,117 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,119 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:44,120 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:44,123 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:44,124 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:44,124 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:44,125 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:44,126 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:44,126 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:44,127 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:44,127 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:44,128 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:44,129 [root] DEBUG: 12224: DLL loaded at 0x00007FFF12FC0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:44,152 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,153 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,155 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,156 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,157 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,157 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,158 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,159 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,160 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:44,182 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,183 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,184 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,185 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,186 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,187 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,187 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,188 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,190 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:44,190 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:44,193 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:44,193 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:44,194 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:44,195 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:44,196 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:44,197 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:44,198 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:44,199 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:44,200 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:44,202 [root] DEBUG: 12224: DLL loaded at 0x00007FFF12FC0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:44,226 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,227 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,229 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,231 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,233 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,233 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,234 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,235 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,237 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:44,260 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,261 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,263 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,264 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,264 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,265 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,266 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,266 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,268 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:44,269 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:44,272 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:44,273 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:44,274 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:44,275 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:44,276 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:44,277 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:44,278 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:44,279 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:44,280 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:44,280 [root] DEBUG: 12224: DLL loaded at 0x00007FFF12FC0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:44,303 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,304 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,306 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,306 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,308 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,309 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,310 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,310 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,311 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:44,333 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,333 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,335 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,335 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,336 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,337 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,337 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,339 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,341 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:44,341 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:44,344 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:44,344 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:44,345 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:44,346 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:44,346 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:44,347 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:44,348 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:44,348 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:44,349 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:44,351 [root] DEBUG: 12224: DLL loaded at 0x00007FFF12FC0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:44,380 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,381 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,383 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,384 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,384 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,385 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,386 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,387 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,388 [root] DEBUG: 12224: DLL loaded at 0x00007FFF45630000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-05-29 06:45:44,408 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56B10000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-29 06:45:44,409 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C380000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-05-29 06:45:44,411 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57490000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-29 06:45:44,412 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56A30000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-29 06:45:44,412 [root] DEBUG: 12224: DLL loaded at 0x00007FFF52560000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-29 06:45:44,413 [root] DEBUG: 12224: DLL loaded at 0x00007FFF56770000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-29 06:45:44,414 [root] DEBUG: 12224: DLL loaded at 0x00007FFF19B10000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-05-29 06:45:44,414 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57470000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-29 06:45:44,417 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59EF0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-29 06:45:44,417 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4FA10000: C:\Windows\SYSTEM32\Tbs (0x1b000 bytes).
2026-05-29 06:45:44,420 [root] DEBUG: 12224: DLL loaded at 0x0000018F1F120000: C:\Windows\system32\WDSCORE (0x43000 bytes).
2026-05-29 06:45:44,421 [root] DEBUG: 12224: DLL loaded at 0x00007FFF1C620000: C:\Windows\system32\MSI (0x337000 bytes).
2026-05-29 06:45:44,421 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43550000: C:\Windows\system32\NETAPI32 (0x19000 bytes).
2026-05-29 06:45:44,422 [root] DEBUG: 12224: DLL loaded at 0x00007FFF523E0000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-29 06:45:44,422 [root] DEBUG: 12224: DLL loaded at 0x00007FFF43500000: C:\Windows\system32\VERSION (0xa000 bytes).
2026-05-29 06:45:44,423 [root] DEBUG: 12224: DLL loaded at 0x00007FFF55FF0000: C:\Windows\system32\tdh (0x11b000 bytes).
2026-05-29 06:45:44,424 [root] DEBUG: 12224: DLL loaded at 0x00007FFF57750000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-05-29 06:45:44,424 [root] DEBUG: 12224: DLL loaded at 0x00007FFF59A80000: C:\Windows\System32\setupapi (0x46e000 bytes).
2026-05-29 06:45:44,425 [root] DEBUG: 12224: DLL loaded at 0x00007FFF4D3B0000: C:\Windows\system32\SAMCLI (0x19000 bytes).
2026-05-29 06:45:44,426 [root] DEBUG: 12224: DLL loaded at 0x00007FFF12FC0000: C:\Windows\system32\appraiser (0x212000 bytes).
2026-05-29 06:45:48,832 [root] DEBUG: 832: CreateProcessHandler: Injection info set for new process 13492: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6706B0000
2026-05-29 06:45:48,837 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13492
2026-05-29 06:45:48,838 [lib.api.process] INFO: Monitor config for process 13492: C:\lpw_albt\dll\13492.ini
2026-05-29 06:45:48,841 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:48,844 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:48,851 [root] DEBUG: Loader: Injecting process 13492 (thread 13496) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:48,853 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:45:48,858 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:48,860 [lib.api.process] INFO: Injected into 64-bit <Process 13492 dllhost.exe>
2026-05-29 06:45:48,861 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13492
2026-05-29 06:45:48,861 [lib.api.process] INFO: Monitor config for process 13492: C:\lpw_albt\dll\13492.ini
2026-05-29 06:45:48,862 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-29 06:45:48,865 [lib.api.process] INFO: 64-bit DLL to inject is C:\lpw_albt\dll\yCvZHFYF.dll, loader C:\lpw_albt\bin\ibkiRcbt.exe
2026-05-29 06:45:48,870 [root] DEBUG: Loader: Injecting process 13492 (thread 13496) with C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:48,871 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-29 06:45:48,871 [root] DEBUG: Successfully injected DLL C:\lpw_albt\dll\yCvZHFYF.dll.
2026-05-29 06:45:48,873 [lib.api.process] INFO: Injected into 64-bit <Process 13492 dllhost.exe>
2026-05-29 06:45:48,881 [root] DEBUG: 13492: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-29 06:45:48,882 [root] DEBUG: 13492: Interactive desktop enabled.
2026-05-29 06:45:48,882 [root] DEBUG: 13492: Dropped file limit defaulting to 100.
2026-05-29 06:45:48,884 [root] DEBUG: 13492: Disabling sleep skipping.
2026-05-29 06:45:48,886 [root] DEBUG: 13492: YaraInit: Compiled rules loaded from existing file C:\lpw_albt\data\yara\capemon.yac
2026-05-29 06:45:48,897 [root] DEBUG: 13492: RtlInsertInvertedFunctionTable 0x00007FFF59F6090E, LdrpInvertedFunctionTableSRWLock 0x00007FFF5A0BD4F0
2026-05-29 06:45:48,898 [root] DEBUG: 13492: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 06:45:48,899 [root] DEBUG: 13492: Monitor initialised: 64-bit capemon loaded in process 13492 at 0x00007FFF18240000, thread 13496, image base 0x00007FF6706B0000, stack from 0x00000099FF124000-0x00000099FF130000
2026-05-29 06:45:48,900 [root] DEBUG: 13492: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-29 06:45:48,911 [root] DEBUG: 13492: hook_api: LdrpCallInitRoutine export address 0x00007FFF59F699BC obtained via GetFunctionAddress
2026-05-29 06:45:48,933 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-29 06:45:48,934 [root] DEBUG: 13492: set_hooks: Unable to hook LockResource
2026-05-29 06:45:48,938 [root] DEBUG: 13492: Hooked 627 out of 628 functions
2026-05-29 06:45:48,940 [root] DEBUG: 13492: Syscall hook installed, syscall logging level 1
2026-05-29 06:45:48,945 [root] DEBUG: 13492: RestoreHeaders: Restored original import table.
2026-05-29 06:45:48,945 [root] INFO: Loaded monitor into process with pid 13492
2026-05-29 06:45:48,946 [root] DEBUG: 13492: caller_dispatch: Added region at 0x00007FF6706B0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6706B12F2, thread 13496).
2026-05-29 06:45:48,947 [root] DEBUG: 13492: YaraScan: Scanning 0x00007FF6706B0000, size 0x8026
2026-05-29 06:45:48,949 [root] DEBUG: 13492: ProcessImageBase: Main module image at 0x00007FF6706B0000 unmodified (entropy change 0.000000e+00)
2026-05-29 06:45:48,951 [root] DEBUG: 13492: DLL loaded at 0x00007FFF55510000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-29 06:45:48,952 [root] DEBUG: 13492: DLL loaded at 0x00007FFF57EF0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-29 06:45:48,955 [root] DEBUG: 13492: DLL loaded at 0x00007FFF58B30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-29 06:45:48,968 [root] DEBUG: 13492: DLL loaded at 0x00007FFF54FC0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-29 06:45:48,982 [root] DEBUG: 13492: DLL loaded at 0x00007FFF58070000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-29 06:45:48,982 [root] DEBUG: 13492: DLL loaded at 0x00007FFF432B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-29 06:45:48,988 [root] DEBUG: 13492: DLL loaded at 0x00007FFF52860000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-29 06:45:54,043 [root] INFO: Process with pid 13492 has terminated
2026-05-29 06:45:54,044 [root] DEBUG: 13492: NtTerminateProcess hook: Attempting to dump process 13492
2026-05-29 06:45:54,045 [root] DEBUG: 13492: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:46:22,371 [root] DEBUG: 4104: CreateProcessHandler: Injection info set for new process 14232: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7F5380000
2026-05-29 06:46:22,372 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 14232
2026-05-29 06:46:22,373 [root] DEBUG: 4104: ProcessMessage: Skipping monitoring process 14232
2026-05-29 06:46:44,435 [root] DEBUG: 12224: NtTerminateProcess hook: Attempting to dump process 12224
2026-05-29 06:46:44,436 [root] DEBUG: 12224: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:46:44,438 [root] INFO: Process with pid 12224 has terminated
2026-05-29 06:47:22,988 [root] INFO: Added new file to list with pid 9388 and path C:\ProgramData\Microsoft\Windows\WER\Temp\a6e4fa08-0880-4e40-b09b-bb389c339c38
2026-05-29 06:47:22,989 [root] DEBUG: 9388: NtTerminateProcess hook: Attempting to dump process 9388
2026-05-29 06:47:22,990 [root] DEBUG: 9388: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:47:22,999 [root] INFO: Process with pid 9388 has terminated
2026-05-29 06:47:42,838 [root] INFO: Analysis timeout hit, terminating analysis
2026-05-29 06:47:42,839 [lib.api.process] INFO: Terminate event set for process 4104
2026-05-29 06:47:42,840 [root] DEBUG: 4104: Terminate Event: Attempting to dump process 4104
2026-05-29 06:47:42,844 [root] DEBUG: 4104: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:47:42,866 [lib.api.process] INFO: Termination confirmed for process 4104
2026-05-29 06:47:42,867 [root] INFO: Terminate event set for process 4104
2026-05-29 06:47:42,866 [root] DEBUG: 4104: Terminate Event: monitor shutdown complete for process 4104
2026-05-29 06:47:42,868 [lib.api.process] INFO: Terminate event set for process 832
2026-05-29 06:47:42,868 [root] DEBUG: 832: Terminate Event: Attempting to dump process 832
2026-05-29 06:47:42,870 [root] DEBUG: 832: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:47:42,872 [lib.api.process] INFO: Termination confirmed for process 832
2026-05-29 06:47:42,872 [root] INFO: Terminate event set for process 832
2026-05-29 06:47:42,873 [root] DEBUG: 832: Terminate Event: monitor shutdown complete for process 832
2026-05-29 06:47:42,874 [lib.api.process] INFO: Terminate event set for process 676
2026-05-29 06:47:42,875 [root] DEBUG: 676: Terminate Event: Attempting to dump process 676
2026-05-29 06:47:42,877 [root] DEBUG: 676: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-29 06:47:42,879 [lib.api.process] INFO: Termination confirmed for process 676
2026-05-29 06:47:42,880 [root] INFO: Terminate event set for process 676
2026-05-29 06:47:42,880 [root] DEBUG: 676: Terminate Event: monitor shutdown complete for process 676
2026-05-29 06:47:42,880 [root] INFO: Created shutdown mutex
2026-05-29 06:47:43,884 [root] INFO: Shutting down package
2026-05-29 06:47:43,885 [root] INFO: Stopping auxiliary modules
2026-05-29 06:47:43,886 [root] INFO: Stopping auxiliary module: Browser
2026-05-29 06:47:43,886 [root] INFO: Stopping auxiliary module: Human
2026-05-29 06:47:43,887 [root] INFO: Stopping auxiliary module: Screenshots
2026-05-29 06:47:43,887 [root] INFO: Finishing auxiliary modules
2026-05-29 06:47:43,887 [root] INFO: Shutting down pipe server and dumping dropped files
2026-05-29 06:47:43,896 [lib.common.results] INFO: Uploading file C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log to files\a9dce6cfa04718d830d0b771fec562178730bed2ef59c79fede912a7dd96fef7; Size is 692816; Max size: 100000000
2026-05-29 06:47:43,900 [root] WARNING: File at path c:\programdata\microsoft\windows\wer\temp\werc3de.tmp.csv does not exist, skipping
2026-05-29 06:47:43,901 [root] WARNING: File at path c:\programdata\microsoft\windows\wer\temp\werc41d.tmp.txt does not exist, skipping
2026-05-29 06:47:43,901 [root] WARNING: File at path c:\programdata\microsoft\windows\wer\temp\a6e4fa08-0880-4e40-b09b-bb389c339c38 does not exist, skipping
2026-05-29 06:47:43,901 [root] WARNING: Folder at path "C:\gZRInK\debugger" does not exist, skipping
2026-05-29 06:47:43,902 [root] WARNING: Folder at path "C:\gZRInK\tlsdump" does not exist, skipping
2026-05-29 06:47:44,062 [root] WARNING: Monitor injection attempted but failed for process 9528
2026-05-29 06:47:44,062 [root] WARNING: Monitor injection attempted but failed for process 9452
2026-05-29 06:47:44,063 [root] WARNING: Monitor injection attempted but failed for process 10160
2026-05-29 06:47:44,063 [root] WARNING: Monitor injection attempted but failed for process 8272
2026-05-29 06:47:44,064 [root] WARNING: Monitor injection attempted but failed for process 9120
2026-05-29 06:47:44,064 [root] WARNING: Monitor injection attempted but failed for process 12232
2026-05-29 06:47:44,065 [root] WARNING: Monitor injection attempted but failed for process 10244
2026-05-29 06:47:44,065 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-29 06:44:05 | 2026-05-29 06:47:46 | none |
| Process: MicrosoftEdgeUpdate.exe (5932) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (5932) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (5932) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (5932) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (5932) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (5932) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (5932) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (5932) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
| Process: MicrosoftEdgeUpdate.exe (11132) | ||||||||
| registry | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer | |||||||
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 72.153.5.62 [VT] | unknown | - |
| Y | 72.153.5.96 [VT] | unknown | - |
| Y | 72.153.5.141 [VT] | unknown | - |
| Y | 23.202.166.56 [VT] | unknown | - |
| Y | 150.171.109.19 [VT] | unknown | - |
| Y | 104.29.148.135 [VT] | unknown | - |
| Y | 104.29.138.227 [VT] | unknown | - |
| Y | 104.29.138.199 [VT] | unknown | - |
| Y | 104.29.139.137 [VT] | unknown | - |
| Y | 104.29.139.152 [VT] | unknown | - |
| Y | 104.29.143.150 [VT] | unknown | - |
| Y | 104.29.140.158 [VT] | unknown | - |
| Y | 104.29.140.174 [VT] | unknown | - |
| Y | 104.29.140.170 [VT] | unknown | - |
| Y | 104.29.141.15 [VT] | unknown | - |
| Y | 104.29.132.82 [VT] | unknown | - |
| Y | 104.29.132.119 [VT] | unknown | - |
| Y | 104.29.157.219 [VT] | unknown | - |
| Y | 104.29.136.163 [VT] | unknown | - |
| Y | 104.29.132.178 [VT] | unknown | - |
| Y | 104.29.140.188 [VT] | unknown | - |
| Y | 104.29.141.148 [VT] | unknown | - |
| Y | 104.29.142.90 [VT] | unknown | - |
| Y | 104.29.142.1 [VT] | unknown | - |
| Y | 104.29.141.192 [VT] | unknown | - |
| Y | 104.29.149.132 [VT] | unknown | - |
| Y | 104.29.149.149 [VT] | unknown | - |
| Y | 104.29.149.134 [VT] | unknown | - |
| Y | 104.29.149.152 [VT] | unknown | - |
| Y | 104.29.149.137 [VT] | unknown | - |
| N | 162.159.130.235 [VT] | unknown | - |
| Y | 23.211.129.205 [VT] | unknown | - |
| Y | 146.75.119.82 [VT] | unknown | - |
| N | 199.232.211.52 [VT] | unknown | - |
| N | 23.209.183.106 [VT] | unknown | - |
| N | 205.196.6.133 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| Y | 23.56.110.169 [VT] | unknown | - |
| N | 162.159.128.235 [VT] | unknown | - |
| N | 185.247.139.200 [VT] | unknown | - |
| N | 162.159.136.232 [VT] | unknown | - |
| N | 162.159.135.234 [VT] | unknown | - |
| N | 162.159.135.233 [VT] | unknown | - |
| N | 162.159.133.233 [VT] | unknown | - |
| N | 142.250.195.227 [VT] | unknown | - |
| Y | 40.126.14.161 [VT] | unknown | - |
| Y | 104.115.81.8 [VT] | unknown | - |
| Y | 172.172.255.218 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| N | 199.232.215.52 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-udp.steamserver.net [VT] |
CNAME udp.ipv6check.akadns.net
[VT]
AAAA 2404:3fc0:1:102::670a:7d36 [VT] AAAA 2404:3fc0:1:102::670a:7d37 [VT] AAAA 2404:3fc0:1:100::670a:7d06 [VT] AAAA 2404:3fc0:1:100::42 [VT] AAAA 2404:3fc0:1:102::670a:7d38 [VT] CNAME syd.udp.ipv6check.akadns.net [VT] AAAA 2404:3fc0:1:100::670a:7d08 [VT] AAAA 2404:3fc0:1:102::670a:7d35 [VT] AAAA 2404:3fc0:1:100::32 [VT] |
|
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.155
[VT]
A 149.135.84.160 [VT] |
23.56.110.24 [VT] |
| c.pki.goog [VT] |
A 142.250.195.227
[VT]
CNAME pki-goog.l.google.com [VT] |
142.250.195.163 [VT] |
| discordapp.com [VT] |
A 162.159.135.233
[VT]
A 162.159.134.233 [VT] A 162.159.133.233 [VT] A 162.159.129.233 [VT] A 162.159.130.233 [VT] |
162.159.129.233 [VT] |
| gateway-us-east1-c.discord.gg [VT] |
A 162.159.130.234
[VT]
A 162.159.134.234 [VT] A 162.159.135.234 [VT] A 162.159.133.234 [VT] A 162.159.136.234 [VT] |
162.159.130.234 [VT] |
| badoomovies.com [VT] | A 185.247.139.200 [VT] | 185.247.139.200 [VT] |
| status.discord.com [VT] |
A 162.159.128.233
[VT]
A 162.159.138.232 [VT] A 162.159.137.232 [VT] A 162.159.135.232 [VT] A 162.159.136.232 [VT] |
162.159.136.232 [VT] |
| cdn.discordapp.com [VT] | 162.159.133.233 [VT] | |
| updates.discord.com [VT] | 162.159.138.232 [VT] | |
| dns.google [VT] |
A 8.8.4.4
[VT]
A 8.8.8.8 [VT] |
8.8.4.4 [VT] |
| cmp2-sea1.steamserver.net [VT] | A 205.196.6.133 [VT] | 205.196.6.133 [VT] |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.42 [VT] |
| clientconfig.akamai.steamstatic.com [VT] |
A 23.209.183.106
[VT]
A 23.209.183.176 [VT] |
23.211.125.112 [VT] |
| shared.steamstatic.com [VT] |
A 199.232.215.52
[VT]
A 199.232.211.52 [VT] CNAME shared.valve.map.fastly.net [VT] |
199.232.211.52 [VT] |
| latency.discord.media [VT] |
A 162.159.130.235
[VT]
A 162.159.129.235 [VT] A 162.159.138.234 [VT] A 162.159.137.234 [VT] A 162.159.128.235 [VT] |
162.159.137.234 [VT] |
| disabled.invalid [VT] | NXDOMAIN |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.