| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 17:41:27 | 2026-05-28 17:44:40 | 193s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 20:40:10,002 [root] INFO: Date set to: 20260528T17:41:32, timeout set to: 600 2026-05-28 17:41:32,006 [root] DEBUG: Starting analyzer from: C:\q61py415 2026-05-28 17:41:32,006 [root] DEBUG: Storing results at: C:\BzuLYXQUrs 2026-05-28 17:41:32,015 [root] DEBUG: Pipe server name: \\.\PIPE\IkRdYsEaKU 2026-05-28 17:41:32,016 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64 2026-05-28 17:41:32,016 [root] INFO: analysis running as an admin 2026-05-28 17:41:32,016 [root] INFO: analysis package specified: "edge" 2026-05-28 17:41:32,016 [root] DEBUG: importing analysis package module: "modules.packages.edge"... 2026-05-28 17:41:32,021 [root] DEBUG: imported analysis package "edge" 2026-05-28 17:41:32,023 [root] DEBUG: initializing analysis package "edge"... 2026-05-28 17:41:32,023 [root] DEBUG: New location of moved file: https://sugarcraft(dot)net/ 2026-05-28 17:41:32,023 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option 2026-05-28 17:41:32,024 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option 2026-05-28 17:41:32,024 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option 2026-05-28 17:41:32,024 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option 2026-05-28 17:41:32,076 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2026-05-28 17:41:32,079 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2026-05-28 17:41:32,090 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2026-05-28 17:41:32,096 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2026-05-28 17:41:32,100 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-05-28 17:41:32,100 [lib.api.screenshot] ERROR: No module named 'PIL' 2026-05-28 17:41:32,100 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots" 2026-05-28 17:41:32,102 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2026-05-28 17:41:32,102 [root] DEBUG: Initialized auxiliary module "Browser" 2026-05-28 17:41:32,102 [root] DEBUG: attempting to configure 'Browser' from data 2026-05-28 17:41:32,103 [root] DEBUG: module Browser does not support data configuration, ignoring 2026-05-28 17:41:32,103 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2026-05-28 17:41:32,103 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2026-05-28 17:41:32,103 [root] DEBUG: Initialized auxiliary module "DigiSig" 2026-05-28 17:41:32,103 [root] DEBUG: attempting to configure 'DigiSig' from data 2026-05-28 17:41:32,104 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2026-05-28 17:41:32,104 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2026-05-28 17:41:32,104 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file 2026-05-28 17:41:32,104 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2026-05-28 17:41:32,104 [root] DEBUG: Initialized auxiliary module "Disguise" 2026-05-28 17:41:32,105 [root] DEBUG: attempting to configure 'Disguise' from data 2026-05-28 17:41:32,105 [root] DEBUG: module Disguise does not support data configuration, ignoring 2026-05-28 17:41:32,105 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2026-05-28 17:41:32,107 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 2672) 2026-05-28 17:41:32,110 [modules.auxiliary.disguise] INFO: Disguising GUID to 6575d657-0ae1-4491-884c-aa1cccdd08f8 2026-05-28 17:41:32,110 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2026-05-28 17:41:32,110 [root] DEBUG: Initialized auxiliary module "Human" 2026-05-28 17:41:32,111 [root] DEBUG: attempting to configure 'Human' from data 2026-05-28 17:41:32,111 [root] DEBUG: module Human does not support data configuration, ignoring 2026-05-28 17:41:32,111 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2026-05-28 17:41:32,113 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2026-05-28 17:41:32,113 [root] DEBUG: Initialized auxiliary module "Screenshots" 2026-05-28 17:41:32,113 [root] DEBUG: attempting to configure 'Screenshots' from data 2026-05-28 17:41:32,114 [root] DEBUG: module Screenshots does not support data configuration, ignoring 2026-05-28 17:41:32,114 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"... 2026-05-28 17:41:32,118 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2026-05-28 17:41:32,119 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots 2026-05-28 17:41:32,119 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2026-05-28 17:41:32,120 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2026-05-28 17:41:32,120 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2026-05-28 17:41:32,120 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2026-05-28 17:41:32,122 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process 2026-05-28 17:41:32,123 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2026-05-28 17:41:32,124 [root] INFO: Interactive mode enabled - injecting into explorer shell 2026-05-28 17:41:32,184 [lib.api.process] INFO: Monitor config for process 4248: C:\q61py415\dll\4248.ini 2026-05-28 17:41:32,185 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:41:32,188 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:41:32,233 [root] DEBUG: Loader: Injecting process 4248 with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:32,404 [root] DEBUG: 4248: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 17:41:32,405 [root] DEBUG: 4248: Disabling sleep skipping. 2026-05-28 17:41:32,405 [root] DEBUG: 4248: Interactive desktop enabled. 2026-05-28 17:41:32,406 [root] DEBUG: 4248: Dropped file limit defaulting to 100. 2026-05-28 17:41:32,406 [root] DEBUG: 4248: Interactive desktop - injecting Explorer Shell 2026-05-28 17:41:32,414 [root] DEBUG: 4248: YaraInit: Compiled 44 rule files 2026-05-28 17:41:32,416 [root] DEBUG: 4248: YaraInit: Compiled rules saved to file C:\q61py415\data\yara\capemon.yac 2026-05-28 17:41:32,438 [root] DEBUG: 4248: RtlInsertInvertedFunctionTable 0x00007FFC2D10090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC2D25D4F0 2026-05-28 17:41:32,439 [root] DEBUG: 4248: YaraScan: Scanning 0x00007FF651080000, size 0x545316 2026-05-28 17:41:32,496 [root] DEBUG: 4248: Monitor initialised: 64-bit capemon loaded in process 4248 at 0x00007FFC14380000, thread 964, image base 0x00007FF651080000, stack from 0x0000000002AC1000-0x0000000002AD0000 2026-05-28 17:41:32,497 [root] DEBUG: 4248: Commandline: C:\Windows\Explorer.EXE 2026-05-28 17:41:32,509 [root] DEBUG: 4248: Hooked 69 out of 69 functions 2026-05-28 17:41:32,540 [root] DEBUG: 4248: Syscall hook installed, syscall logging level 1 2026-05-28 17:41:32,546 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-05-28 17:41:32,546 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:32,548 [lib.api.process] INFO: Injected into 64-bit <Process 4248 explorer.exe> 2026-05-28 17:41:36,492 [root] DEBUG: 4248: caller_dispatch: Added region at 0x00007FF651080000 to tracked regions list (ntdll::NtDuplicateObject returns to 0x00007FF65125D17E, thread 4908). 2026-05-28 17:41:36,493 [root] DEBUG: 4248: YaraScan: Scanning 0x00007FF651080000, size 0x545316 2026-05-28 17:41:36,528 [root] DEBUG: 4248: ProcessImageBase: Main module image at 0x00007FF651080000 unmodified (entropy change 0.000000e+00) 2026-05-28 17:41:39,791 [root] INFO: Restarting WMI Service 2026-05-28 17:41:40,842 [root] DEBUG: 4248: CreateProcessHandler: Injection info set for new process 2072: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:40,844 [root] INFO: Announced 64-bit process name: chrome.exe pid: 2072 2026-05-28 17:41:40,845 [lib.api.process] INFO: Monitor config for process 2072: C:\q61py415\dll\2072.ini 2026-05-28 17:41:40,846 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:41:40,847 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:41:40,851 [root] DEBUG: Loader: Injecting process 2072 (thread 1884) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:40,852 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 17:41:40,852 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:40,853 [lib.api.process] INFO: Injected into 64-bit <Process 2072 chrome.exe> 2026-05-28 17:41:40,854 [root] INFO: Announced 64-bit process name: chrome.exe pid: 2072 2026-05-28 17:41:40,854 [lib.api.process] INFO: Monitor config for process 2072: C:\q61py415\dll\2072.ini 2026-05-28 17:41:40,855 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:41:40,855 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:41:40,859 [root] DEBUG: Loader: Injecting process 2072 (thread 1884) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:40,859 [root] DEBUG: InjectDllViaIAT: This image has already been patched. 2026-05-28 17:41:40,860 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:40,861 [lib.api.process] INFO: Injected into 64-bit <Process 2072 chrome.exe> 2026-05-28 17:41:40,950 [root] DEBUG: 2072: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 17:41:40,951 [root] DEBUG: 2072: Interactive desktop enabled. 2026-05-28 17:41:40,952 [root] DEBUG: 2072: Dropped file limit defaulting to 100. 2026-05-28 17:41:40,956 [root] DEBUG: 2072: Chrome-specific hook-set enabled. 2026-05-28 17:41:40,958 [root] DEBUG: 2072: Disabling sleep skipping. 2026-05-28 17:41:40,960 [root] DEBUG: 2072: YaraInit: Compiled rules loaded from existing file C:\q61py415\data\yara\capemon.yac 2026-05-28 17:41:40,972 [root] DEBUG: 2072: RtlInsertInvertedFunctionTable 0x00007FFC2D10090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC2D25D4F0 2026-05-28 17:41:40,973 [root] DEBUG: 2072: Monitor initialised: 64-bit capemon loaded in process 2072 at 0x00007FFC14380000, thread 1884, image base 0x00007FF78CD00000, stack from 0x00000036489F4000-0x0000003648A00000 2026-05-28 17:41:40,973 [root] DEBUG: 2072: Commandline: "C:\Program Files\Google\Chrome\Application\chrome.exe" 2026-05-28 17:41:40,980 [root] DEBUG: 2072: Hooked 2 out of 2 functions 2026-05-28 17:41:41,008 [root] DEBUG: 2072: Syscall hook installed, syscall logging level 1 2026-05-28 17:41:41,012 [root] DEBUG: 2072: RestoreHeaders: Restored original import table. 2026-05-28 17:41:41,013 [root] INFO: Loaded monitor into process with pid 2072 2026-05-28 17:41:41,014 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2B0C0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes). 2026-05-28 17:41:41,032 [root] DEBUG: 2072: InstrumentationCallback: Added region at 0x00007FFC136D0014 (base 0x00007FFC13420000) to tracked regions list (thread 1884). 2026-05-28 17:41:41,034 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,035 [root] DEBUG: 2072: DLL loaded at 0x00007FFC298F0000: C:\Windows\system32\ntmarta (0x33000 bytes). 2026-05-28 17:41:41,039 [root] DEBUG: 2072: caller_dispatch: Added region at 0x00007FF78CD00000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF78CD372AF, thread 1884). 2026-05-28 17:41:41,042 [root] DEBUG: 2072: ProcessImageBase: Main module image at 0x00007FF78CD00000 unmodified (entropy change 0.000000e+00) 2026-05-28 17:41:41,046 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270666e+00 (from 6.270496e+00) 2026-05-28 17:41:41,047 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,051 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270666e+00 (from 6.270496e+00) 2026-05-28 17:41:41,051 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,052 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A140000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes). 2026-05-28 17:41:41,055 [root] DEBUG: 2072: DLL loaded at 0x00007FFC288B0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes). 2026-05-28 17:41:41,061 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270666e+00 (from 6.270496e+00) 2026-05-28 17:41:41,061 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,062 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 1264: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:41,063 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 1264 2026-05-28 17:41:41,067 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270666e+00 (from 6.270496e+00) 2026-05-28 17:41:41,068 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,070 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 1264 2026-05-28 17:41:41,123 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,124 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,228 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,229 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,235 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,235 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,240 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270913e+00 (from 6.270496e+00) 2026-05-28 17:41:41,242 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,247 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,247 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,248 [root] DEBUG: 2072: DLL loaded at 0x00007FFC15250000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes). 2026-05-28 17:41:41,249 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1E180000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes). 2026-05-28 17:41:41,249 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A4F0000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes). 2026-05-28 17:41:41,250 [root] DEBUG: 2072: DLL loaded at 0x00007FFBD4D10000: C:\Program Files\Google\Chrome\Application\148.0.7778.217\chrome (0x10fdc000 bytes). 2026-05-28 17:41:41,258 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270913e+00 (from 6.270496e+00) 2026-05-28 17:41:41,259 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,263 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270913e+00 (from 6.270496e+00) 2026-05-28 17:41:41,263 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,264 [root] DEBUG: 2072: DLL loaded at 0x00007FFC17FD0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes). 2026-05-28 17:41:41,268 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,269 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,274 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,275 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,275 [root] DEBUG: 2072: DLL loaded at 0x00007FFC28160000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-05-28 17:41:41,281 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270913e+00 (from 6.270496e+00) 2026-05-28 17:41:41,282 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,283 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A6C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes). 2026-05-28 17:41:41,286 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,288 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,289 [root] DEBUG: 2072: DLL loaded at 0x00007FFC29060000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes). 2026-05-28 17:41:41,293 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,293 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,294 [root] DEBUG: 2072: DLL loaded at 0x00007FFC29930000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes). 2026-05-28 17:41:41,298 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,298 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,299 [root] DEBUG: 2072: DLL loaded at 0x00007FFC29CA0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes). 2026-05-28 17:41:41,310 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270913e+00 (from 6.270496e+00) 2026-05-28 17:41:41,311 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,314 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270913e+00 (from 6.270496e+00) 2026-05-28 17:41:41,315 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,315 [root] DEBUG: 2072: DLL loaded at 0x00007FFC17770000: C:\Windows\system32\netapi32 (0x19000 bytes). 2026-05-28 17:41:41,320 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,320 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,326 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270914e+00 (from 6.270496e+00) 2026-05-28 17:41:41,326 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,330 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270890e+00 (from 6.270496e+00) 2026-05-28 17:41:41,331 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,333 [root] DEBUG: 2072: DLL loaded at 0x00007FFC29860000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 17:41:41,334 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A090000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes). 2026-05-28 17:41:41,336 [root] DEBUG: 2072: DLL loaded at 0x00007FFC27830000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes). 2026-05-28 17:41:41,341 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,341 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,342 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A700000: C:\Windows\SYSTEM32\profapi (0x25000 bytes). 2026-05-28 17:41:41,361 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,364 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,370 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,371 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,375 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,375 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,380 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,380 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,386 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270890e+00 (from 6.270496e+00) 2026-05-28 17:41:41,386 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,387 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2B280000: C:\Windows\System32\MSCTF (0x114000 bytes). 2026-05-28 17:41:41,392 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270892e+00 (from 6.270496e+00) 2026-05-28 17:41:41,392 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270892e+00 (from 6.270496e+00) 2026-05-28 17:41:41,393 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,396 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,397 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A630000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes). 2026-05-28 17:41:41,398 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270892e+00 (from 6.270496e+00) 2026-05-28 17:41:41,399 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,402 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270892e+00 (from 6.270496e+00) 2026-05-28 17:41:41,403 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,403 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A560000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes). 2026-05-28 17:41:41,407 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270890e+00 (from 6.270496e+00) 2026-05-28 17:41:41,408 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,409 [root] DEBUG: 2072: DLL loaded at 0x00007FFC286B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-05-28 17:41:41,415 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,415 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,419 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,419 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,423 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,424 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,429 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,430 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,435 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270891e+00 (from 6.270496e+00) 2026-05-28 17:41:41,435 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,436 [root] DEBUG: 2072: DLL loaded at 0x00007FFC171F0000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes). 2026-05-28 17:41:41,440 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270893e+00 (from 6.270496e+00) 2026-05-28 17:41:41,440 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,446 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270893e+00 (from 6.270496e+00) 2026-05-28 17:41:41,446 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,451 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270893e+00 (from 6.270496e+00) 2026-05-28 17:41:41,451 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,452 [root] DEBUG: 2072: DLL loaded at 0x00007FFC29B90000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes). 2026-05-28 17:41:41,452 [root] DEBUG: 2072: DLL loaded at 0x00007FFC26180000: C:\Windows\system32\NLAapi (0x1d000 bytes). 2026-05-28 17:41:41,457 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270893e+00 (from 6.270496e+00) 2026-05-28 17:41:41,458 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,461 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2C7B0000: C:\Windows\System32\NSI (0x8000 bytes). 2026-05-28 17:41:41,465 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270893e+00 (from 6.270496e+00) 2026-05-28 17:41:41,466 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,466 [root] DEBUG: 2072: DLL loaded at 0x00007FFC232D0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes). 2026-05-28 17:41:41,470 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270892e+00 (from 6.270496e+00) 2026-05-28 17:41:41,471 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,471 [root] DEBUG: 2072: DLL loaded at 0x00007FFC232B0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes). 2026-05-28 17:41:41,476 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270897e+00 (from 6.270496e+00) 2026-05-28 17:41:41,477 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,477 [root] DEBUG: 2072: DLL loaded at 0x00007FFC29BD0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes). 2026-05-28 17:41:41,482 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270898e+00 (from 6.270496e+00) 2026-05-28 17:41:41,483 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,488 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270898e+00 (from 6.270496e+00) 2026-05-28 17:41:41,489 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,493 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270898e+00 (from 6.270496e+00) 2026-05-28 17:41:41,494 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,499 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270898e+00 (from 6.270496e+00) 2026-05-28 17:41:41,500 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,503 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270898e+00 (from 6.270496e+00) 2026-05-28 17:41:41,504 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,504 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2C9C0000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-05-28 17:41:41,510 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270897e+00 (from 6.270496e+00) 2026-05-28 17:41:41,511 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,515 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270897e+00 (from 6.270496e+00) 2026-05-28 17:41:41,516 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,521 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270897e+00 (from 6.270496e+00) 2026-05-28 17:41:41,523 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,527 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270897e+00 (from 6.270496e+00) 2026-05-28 17:41:41,528 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,532 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270895e+00 (from 6.270496e+00) 2026-05-28 17:41:41,532 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,536 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270895e+00 (from 6.270496e+00) 2026-05-28 17:41:41,536 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,538 [root] DEBUG: 2072: DLL loaded at 0x00007FFC27DC0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-05-28 17:41:41,539 [root] DEBUG: 2072: DLL loaded at 0x00007FFC26FE0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes). 2026-05-28 17:41:41,539 [root] DEBUG: 2072: DLL loaded at 0x00007FFC27980000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes). 2026-05-28 17:41:41,540 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1FA90000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-05-28 17:41:41,546 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270895e+00 (from 6.270496e+00) 2026-05-28 17:41:41,547 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,547 [root] DEBUG: 2072: DLL loaded at 0x00007FFC25980000: C:\Windows\System32\twinapi.appcore (0x203000 bytes). 2026-05-28 17:41:41,552 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270895e+00 (from 6.270496e+00) 2026-05-28 17:41:41,555 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,556 [root] DEBUG: 2072: DLL loaded at 0x00007FFC17530000: C:\Windows\system32\twinapi (0xa9000 bytes). 2026-05-28 17:41:41,561 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270896e+00 (from 6.270496e+00) 2026-05-28 17:41:41,561 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,567 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270894e+00 (from 6.270496e+00) 2026-05-28 17:41:41,568 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,573 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270894e+00 (from 6.270496e+00) 2026-05-28 17:41:41,573 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,577 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270894e+00 (from 6.270496e+00) 2026-05-28 17:41:41,578 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,583 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270894e+00 (from 6.270496e+00) 2026-05-28 17:41:41,584 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,591 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270894e+00 (from 6.270496e+00) 2026-05-28 17:41:41,591 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,595 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270895e+00 (from 6.270496e+00) 2026-05-28 17:41:41,595 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,599 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270909e+00 (from 6.270496e+00) 2026-05-28 17:41:41,600 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,604 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270907e+00 (from 6.270496e+00) 2026-05-28 17:41:41,605 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,606 [root] DEBUG: 2072: DLL loaded at 0x00007FFC25B90000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes). 2026-05-28 17:41:41,606 [root] DEBUG: 2072: DLL loaded at 0x00007FFC27140000: C:\Windows\System32\PROPSYS (0xf6000 bytes). 2026-05-28 17:41:41,607 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1F650000: C:\Windows\System32\InputHost (0x152000 bytes). 2026-05-28 17:41:41,607 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1FB90000: C:\Windows\System32\Windows.UI (0x141000 bytes). 2026-05-28 17:41:41,614 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270909e+00 (from 6.270496e+00) 2026-05-28 17:41:41,615 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270909e+00 (from 6.270496e+00) 2026-05-28 17:41:41,615 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,617 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,622 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270909e+00 (from 6.270496e+00) 2026-05-28 17:41:41,623 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,623 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270909e+00 (from 6.270496e+00) 2026-05-28 17:41:41,624 [root] DEBUG: 2072: DLL loaded at 0x00007FFC29860000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 17:41:41,624 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,625 [root] DEBUG: 2072: DLL loaded at 0x00007FFC20270000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes). 2026-05-28 17:41:41,629 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270909e+00 (from 6.270496e+00) 2026-05-28 17:41:41,630 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,630 [root] DEBUG: 2072: DLL loaded at 0x00007FFC27460000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes). 2026-05-28 17:41:41,635 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270907e+00 (from 6.270496e+00) 2026-05-28 17:41:41,635 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,636 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A500000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes). 2026-05-28 17:41:41,642 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270910e+00 (from 6.270496e+00) 2026-05-28 17:41:41,642 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,660 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270910e+00 (from 6.270496e+00) 2026-05-28 17:41:41,660 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,661 [root] DEBUG: 2072: DLL loaded at 0x00007FFC257D0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes). 2026-05-28 17:41:41,662 [root] DEBUG: 2072: DLL loaded at 0x00007FFC257F0000: C:\Windows\SYSTEM32\mscms (0xae000 bytes). 2026-05-28 17:41:41,671 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270909e+00 (from 6.270496e+00) 2026-05-28 17:41:41,672 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270911e+00 (from 6.270496e+00) 2026-05-28 17:41:41,673 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270910e+00 (from 6.270496e+00) 2026-05-28 17:41:41,676 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,677 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,681 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270911e+00 (from 6.270496e+00) 2026-05-28 17:41:41,681 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,682 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270911e+00 (from 6.270496e+00) 2026-05-28 17:41:41,682 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,686 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,687 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270911e+00 (from 6.270496e+00) 2026-05-28 17:41:41,689 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270911e+00 (from 6.270496e+00) 2026-05-28 17:41:41,689 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,690 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,690 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270911e+00 (from 6.270496e+00) 2026-05-28 17:41:41,691 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,692 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2ACD0000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes). 2026-05-28 17:41:41,693 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A490000: C:\Windows\System32\DEVOBJ (0x33000 bytes). 2026-05-28 17:41:41,695 [root] DEBUG: 2072: DLL loaded at 0x00007FFC23860000: C:\Windows\System32\MMDevApi (0x85000 bytes). 2026-05-28 17:41:41,696 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270909e+00 (from 6.270496e+00) 2026-05-28 17:41:41,701 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270922e+00 (from 6.270496e+00) 2026-05-28 17:41:41,702 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,702 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,708 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270922e+00 (from 6.270496e+00) 2026-05-28 17:41:41,711 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,712 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,712 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,725 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,726 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,730 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,731 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 4360: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:41,732 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 3136: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:41,733 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,733 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,734 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,735 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 4360 2026-05-28 17:41:41,744 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 3136 2026-05-28 17:41:41,744 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,744 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,749 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,749 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270923e+00 (from 6.270496e+00) 2026-05-28 17:41:41,750 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270923e+00 (from 6.270496e+00) 2026-05-28 17:41:41,750 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,751 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,751 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,752 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 4360 2026-05-28 17:41:41,758 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 3136 2026-05-28 17:41:41,759 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270922e+00 (from 6.270496e+00) 2026-05-28 17:41:41,760 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270922e+00 (from 6.270496e+00) 2026-05-28 17:41:41,761 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,764 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,778 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,779 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,787 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,794 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,799 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A090000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes). 2026-05-28 17:41:41,813 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,814 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A1B0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes). 2026-05-28 17:41:41,819 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,821 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2B260000: C:\Windows\System32\imagehlp (0x1d000 bytes). 2026-05-28 17:41:41,825 [root] DEBUG: 2072: DLL loaded at 0x00007FFC236C0000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes). 2026-05-28 17:41:41,829 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1AF70000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes). 2026-05-28 17:41:41,842 [root] DEBUG: 2072: DLL loaded at 0x00007FFC20230000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes). 2026-05-28 17:41:41,844 [root] DEBUG: package modules.packages.edge does not support configure, ignoring 2026-05-28 17:41:41,845 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages' 2026-05-28 17:41:41,847 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation 2026-05-28 17:41:41,852 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://sugarcraft(dot)net/"" with pid 2208 2026-05-28 17:41:41,853 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,853 [lib.api.process] INFO: Monitor config for process 2208: C:\q61py415\dll\2208.ini 2026-05-28 17:41:41,854 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,855 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:41:41,856 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A170000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes). 2026-05-28 17:41:41,857 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:41:41,866 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270922e+00 (from 6.270496e+00) 2026-05-28 17:41:41,869 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,871 [root] DEBUG: Loader: Injecting process 2208 (thread 5180) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:41,872 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1E400000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes). 2026-05-28 17:41:41,886 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,887 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,888 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,888 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 17:41:41,892 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,899 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:41,900 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,901 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A580000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes). 2026-05-28 17:41:41,902 [lib.api.process] INFO: Injected into 64-bit <Process 2208 msedge.exe> 2026-05-28 17:41:41,906 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,914 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270925e+00 (from 6.270496e+00) 2026-05-28 17:41:41,915 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270925e+00 (from 6.270496e+00) 2026-05-28 17:41:41,915 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270925e+00 (from 6.270496e+00) 2026-05-28 17:41:41,915 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,916 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 5756: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:41,934 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270925e+00 (from 6.270496e+00) 2026-05-28 17:41:41,935 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,940 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,955 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270925e+00 (from 6.270496e+00) 2026-05-28 17:41:41,955 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 5756 2026-05-28 17:41:41,964 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,965 [root] DEBUG: 2072: DLL loaded at 0x00007FFC22A50000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes). 2026-05-28 17:41:41,972 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,978 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,979 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,979 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,980 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,981 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,989 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,995 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:41,996 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:41,997 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,000 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,001 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,006 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,007 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,009 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,020 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,024 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,026 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 5756 2026-05-28 17:41:42,032 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,033 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,034 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,040 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,048 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,049 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,058 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,059 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,060 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,063 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,065 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,065 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,066 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,073 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,074 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,075 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,093 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,095 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,100 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,101 [root] DEBUG: 2072: DLL loaded at 0x00007FFC284D0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes). 2026-05-28 17:41:42,102 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,103 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,105 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,106 [root] DEBUG: 2072: DLL loaded at 0x00007FFC26310000: C:\Windows\System32\XmlLite (0x36000 bytes). 2026-05-28 17:41:42,107 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,107 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,109 [root] DEBUG: 2072: DLL loaded at 0x00007FFC16860000: C:\Windows\System32\wpnapps (0x15b000 bytes). 2026-05-28 17:41:42,112 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,115 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270924e+00 (from 6.270496e+00) 2026-05-28 17:41:42,117 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,118 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,119 [root] DEBUG: 2072: DLL loaded at 0x00007FFC25960000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes). 2026-05-28 17:41:42,124 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270923e+00 (from 6.270496e+00) 2026-05-28 17:41:42,124 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270923e+00 (from 6.270496e+00) 2026-05-28 17:41:42,125 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,125 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,126 [root] DEBUG: 2072: DLL loaded at 0x00007FFC0C8D0000: C:\Windows\System32\CryptoWinRT (0x61000 bytes). 2026-05-28 17:41:42,129 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,130 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,135 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,135 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,135 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,136 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,140 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,140 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,140 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,141 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,142 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A1B0000: C:\Windows\System32\ncrypt (0x27000 bytes). 2026-05-28 17:41:42,142 [root] DEBUG: 2072: DLL loaded at 0x00007FFC23C70000: C:\Windows\System32\cryptngc (0x77000 bytes). 2026-05-28 17:41:42,149 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,149 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,149 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,150 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,151 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A170000: C:\Windows\System32\NTASN1 (0x3b000 bytes). 2026-05-28 17:41:42,154 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,154 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,155 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,156 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,157 [root] DEBUG: 2072: DLL loaded at 0x00007FFC0C8A0000: C:\Windows\system32\ngcksp (0x27000 bytes). 2026-05-28 17:41:42,161 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270950e+00 (from 6.270496e+00) 2026-05-28 17:41:42,162 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,164 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,165 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,165 [root] DEBUG: 2072: DLL loaded at 0x00007FFC0D0A0000: C:\Windows\System32\CapabilityAccessManagerClient (0x3f000 bytes). 2026-05-28 17:41:42,171 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,171 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,177 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,182 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,188 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270951e+00 (from 6.270496e+00) 2026-05-28 17:41:42,188 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,194 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,195 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,196 [root] DEBUG: 2072: DLL loaded at 0x00007FFC29090000: C:\Windows\system32\dxgi (0xf3000 bytes). 2026-05-28 17:41:42,197 [root] DEBUG: 2072: DLL loaded at 0x00007FFC26D70000: C:\Windows\system32\d3d11 (0x263000 bytes). 2026-05-28 17:41:42,198 [root] DEBUG: 2072: DLL loaded at 0x00007FFC27240000: C:\Windows\system32\dcomp (0x1e3000 bytes). 2026-05-28 17:41:42,198 [root] DEBUG: 2072: DLL loaded at 0x00007FFC14FC0000: C:\Windows\system32\dataexchange (0x3e000 bytes). 2026-05-28 17:41:42,203 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,203 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,204 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,204 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,206 [root] DEBUG: 2072: DLL loaded at 0x00007FFC24D40000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes). 2026-05-28 17:41:42,216 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,217 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,218 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,219 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,220 [root] DEBUG: 2072: DLL loaded at 0x00007FFC293F0000: C:\Windows\System32\FirewallAPI (0x96000 bytes). 2026-05-28 17:41:42,223 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,228 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,230 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,234 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,235 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,236 [root] DEBUG: 2072: DLL loaded at 0x00007FFC293B0000: C:\Windows\System32\fwbase (0x36000 bytes). 2026-05-28 17:41:42,248 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,257 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,259 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,260 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,260 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,261 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,264 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,266 [root] DEBUG: 2072: DLL loaded at 0x00007FFC23800000: C:\Windows\System32\usermgrproxy (0x54000 bytes). 2026-05-28 17:41:42,269 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,272 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,274 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,276 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,277 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,278 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,279 [root] DEBUG: 2072: DLL loaded at 0x00007FFC06820000: C:\Windows\System32\Windows.Media (0x726000 bytes). 2026-05-28 17:41:42,282 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,284 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,284 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,285 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,285 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,288 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,290 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,292 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,293 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,295 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,300 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,301 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,301 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270952e+00 (from 6.270496e+00) 2026-05-28 17:41:42,303 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,305 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,307 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,309 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 4648: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:42,310 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,311 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1BE00000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes). 2026-05-28 17:41:42,315 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,316 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 4648 2026-05-28 17:41:42,319 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,320 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,321 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,322 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 5668: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:42,322 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,323 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,327 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,328 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 5668 2026-05-28 17:41:42,328 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,329 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,331 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,332 [root] DEBUG: 2072: DLL loaded at 0x00007FFC283C0000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes). 2026-05-28 17:41:42,333 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,337 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,340 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,341 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,341 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,341 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 4648 2026-05-28 17:41:42,342 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,342 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,343 [root] DEBUG: 2072: DLL loaded at 0x00007FFC15030000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes). 2026-05-28 17:41:42,347 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,347 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,348 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,348 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,351 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,353 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,355 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,356 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 5668 2026-05-28 17:41:42,356 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,357 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,357 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,363 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,369 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,370 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,370 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1D050000: C:\Windows\system32\directmanipulation (0x9d000 bytes). 2026-05-28 17:41:42,371 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,379 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,384 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,385 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,390 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,410 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,463 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,465 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,465 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,465 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,466 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,467 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,467 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,470 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,472 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,479 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,480 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,485 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,485 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,486 [root] DEBUG: 2072: DLL loaded at 0x00007FFC14D70000: C:\Windows\system32\explorerframe (0x244000 bytes). 2026-05-28 17:41:42,491 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270954e+00 (from 6.270496e+00) 2026-05-28 17:41:42,492 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,493 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,497 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,497 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,498 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270953e+00 (from 6.270496e+00) 2026-05-28 17:41:42,499 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,501 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,502 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,539 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,550 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 8428: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:42,551 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,552 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,555 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,555 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,556 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,556 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,557 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,557 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,558 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,573 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 8428 2026-05-28 17:41:42,578 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,579 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,605 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,622 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,623 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,624 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,625 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,627 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,628 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,629 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,629 [root] DEBUG: 2072: DLL loaded at 0x00007FFC22E90000: C:\Windows\system32\wlanapi (0x74000 bytes). 2026-05-28 17:41:42,635 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,636 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,637 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,640 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,641 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,641 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,642 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,642 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,642 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,643 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 8428 2026-05-28 17:41:42,643 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,647 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,650 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,651 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,659 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,660 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,662 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,663 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,665 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,666 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A2D0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes). 2026-05-28 17:41:42,672 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,673 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,674 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,682 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,683 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,689 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,694 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,697 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,698 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,698 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,699 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,700 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,704 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,705 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,706 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,706 [root] DEBUG: 2072: DLL loaded at 0x00007FFC2A090000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes). 2026-05-28 17:41:42,713 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,714 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,716 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,723 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,724 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,724 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,727 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,729 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:41:42,729 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,730 [root] DEBUG: 2072: DLL loaded at 0x00007FFC297D0000: C:\Windows\system32\rsaenh (0x34000 bytes). 2026-05-28 17:41:42,734 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,735 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,736 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,746 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,747 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,748 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,757 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,759 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,762 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,763 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,763 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,764 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,767 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,769 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,770 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,770 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,776 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,781 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,785 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,786 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,788 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,813 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,813 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,814 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,816 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,818 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,819 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,820 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,821 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,826 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,826 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,826 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,827 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,831 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,832 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,832 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,833 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,836 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,837 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,838 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,838 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,842 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,843 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,843 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,844 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,848 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,849 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,850 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,850 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,852 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,853 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,855 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,855 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,859 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,860 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,865 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,866 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,870 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,871 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,875 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,876 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,881 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,881 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,885 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,886 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,890 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,890 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,896 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,897 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,901 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,901 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,906 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,906 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,912 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,913 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,917 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,919 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,923 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,924 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,928 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,928 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,933 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,933 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,937 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,938 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,943 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,943 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,947 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,948 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,953 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,954 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,972 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,973 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,974 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,974 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,975 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,976 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,978 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,979 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,980 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,981 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,981 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,986 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,987 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,988 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:42,988 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,989 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:42,999 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,000 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,000 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,000 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,004 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,006 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,008 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,008 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,012 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,013 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,017 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,017 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,022 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,022 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,028 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,028 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,029 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,032 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,036 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,036 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,044 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,046 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,046 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,053 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,058 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,059 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,063 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,064 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,069 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,070 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,078 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,079 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,087 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,088 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,093 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,093 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,098 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,106 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,115 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,120 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,133 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,136 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,137 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,138 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,143 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,146 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,148 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,156 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,159 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 9436: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:41:43,160 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,161 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 9436 2026-05-28 17:41:43,166 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,169 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,170 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,171 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,173 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,174 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,175 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 9436 2026-05-28 17:41:43,176 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,188 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,189 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,189 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,190 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,190 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,196 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,196 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,197 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,204 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,205 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,206 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,210 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,215 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,215 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,216 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,220 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,221 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,221 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,226 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,227 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,231 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,232 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,232 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,233 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,238 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,239 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,242 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,243 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,247 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,247 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,251 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,252 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,256 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,256 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,261 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,261 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,266 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,267 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,268 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,268 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,295 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,297 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,301 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,302 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,306 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,307 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,314 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,315 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,328 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,328 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,333 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,333 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,352 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,353 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,361 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,361 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,362 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,362 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,367 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,368 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,368 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,369 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,374 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,375 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,385 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,385 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,389 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,390 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,396 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,396 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,417 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,418 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,424 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,424 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,441 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,442 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,447 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,448 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,487 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,488 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,496 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,497 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,502 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,503 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,524 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,525 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,530 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,531 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,536 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,536 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,549 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,550 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,550 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,551 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,556 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,556 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,563 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,564 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,570 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,571 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,573 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,573 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,580 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,581 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,587 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,589 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,593 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,594 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,598 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,598 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,758 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,759 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,912 [lib.api.process] INFO: Successfully resumed process with pid 2208 2026-05-28 17:41:43,928 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:43,929 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:43,950 [root] DEBUG: 2208: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 17:41:43,951 [root] DEBUG: 2208: Interactive desktop enabled. 2026-05-28 17:41:43,951 [root] DEBUG: 2208: Dropped file limit defaulting to 100. 2026-05-28 17:41:43,959 [root] DEBUG: 2208: Edge-specific hook-set enabled. 2026-05-28 17:41:43,961 [root] DEBUG: 2208: Disabling sleep skipping. 2026-05-28 17:41:43,962 [root] DEBUG: 2208: YaraInit: Compiled rules loaded from existing file C:\q61py415\data\yara\capemon.yac 2026-05-28 17:41:43,973 [root] DEBUG: 2208: RtlInsertInvertedFunctionTable 0x00007FFC2D10090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC2D25D4F0 2026-05-28 17:41:43,974 [root] DEBUG: 2208: Monitor initialised: 64-bit capemon loaded in process 2208 at 0x00007FFC14380000, thread 5180, image base 0x00007FF7B5F00000, stack from 0x000000A0977F4000-0x000000A097800000 2026-05-28 17:41:43,974 [root] DEBUG: 2208: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://sugarcraft(dot)net/" 2026-05-28 17:41:43,982 [root] DEBUG: 2208: Hooked 2 out of 2 functions 2026-05-28 17:41:44,018 [root] DEBUG: 2208: Syscall hook installed, syscall logging level 1 2026-05-28 17:41:44,022 [root] DEBUG: 2208: RestoreHeaders: Restored original import table. 2026-05-28 17:41:44,023 [root] INFO: Loaded monitor into process with pid 2208 2026-05-28 17:41:44,023 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2B0C0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes). 2026-05-28 17:41:44,025 [root] DEBUG: 2208: DLL loaded at 0x00007FFC19C80000: C:\Windows\SYSTEM32\version (0xa000 bytes). 2026-05-28 17:41:44,026 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2B150000: C:\Windows\System32\shcore (0xad000 bytes). 2026-05-28 17:41:44,027 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A140000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes). 2026-05-28 17:41:44,027 [root] DEBUG: 2208: DLL loaded at 0x00007FFC288B0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes). 2026-05-28 17:41:44,028 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2B150000: C:\Windows\System32\SHCORE (0xad000 bytes). 2026-05-28 17:41:44,029 [root] DEBUG: 2208: DLL loaded at 0x00007FFC298F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-05-28 17:41:44,072 [root] DEBUG: 2208: DLL loaded at 0x00007FFC15250000: C:\Windows\SYSTEM32\WINMM (0x27000 bytes). 2026-05-28 17:41:44,073 [root] DEBUG: 2208: DLL loaded at 0x00007FFBBE9A0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes). 2026-05-28 17:41:44,075 [root] DEBUG: 2208: DLL loaded at 0x00007FFC17FD0000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes). 2026-05-28 17:41:44,077 [root] DEBUG: 2208: DLL loaded at 0x00007FFC28160000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-05-28 17:41:44,080 [root] DEBUG: 2208: DLL loaded at 0x00007FFC286B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-05-28 17:41:44,081 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2C9C0000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-05-28 17:41:44,081 [root] DEBUG: 2208: DLL loaded at 0x00007FFC20250000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes). 2026-05-28 17:41:44,083 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29860000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 17:41:44,083 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 10176: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:44,084 [root] DEBUG: 2208: DLL loaded at 0x00007FFC23B90000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 17:41:44,085 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10176 2026-05-28 17:41:44,086 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10176 2026-05-28 17:41:44,088 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A6C0000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes). 2026-05-28 17:41:44,089 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29060000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes). 2026-05-28 17:41:44,089 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29930000: C:\Windows\SYSTEM32\wkscli (0x19000 bytes). 2026-05-28 17:41:44,090 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29CA0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes). 2026-05-28 17:41:44,091 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29860000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 17:41:44,092 [root] DEBUG: 2208: DLL loaded at 0x00007FFC17910000: C:\Windows\SYSTEM32\MDMRegistration (0x68000 bytes). 2026-05-28 17:41:44,093 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A630000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes). 2026-05-28 17:41:44,094 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A090000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes). 2026-05-28 17:41:44,095 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A1B0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes). 2026-05-28 17:41:44,095 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2B260000: C:\Windows\System32\imagehlp (0x1d000 bytes). 2026-05-28 17:41:44,096 [root] DEBUG: 2208: DLL loaded at 0x00007FFC236C0000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes). 2026-05-28 17:41:44,096 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1AF70000: C:\Windows\SYSTEM32\DMCmnUtils (0x7c000 bytes). 2026-05-28 17:41:44,097 [root] DEBUG: 2208: DLL loaded at 0x00007FFC15500000: C:\Windows\SYSTEM32\omadmapi (0x3a000 bytes). 2026-05-28 17:41:44,098 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A560000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes). 2026-05-28 17:41:44,099 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A170000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes). 2026-05-28 17:41:44,100 [root] DEBUG: 2208: DLL loaded at 0x00007FFC17770000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes). 2026-05-28 17:41:44,101 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29860000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 17:41:44,102 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A090000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes). 2026-05-28 17:41:44,103 [root] DEBUG: 2208: DLL loaded at 0x00007FFC27830000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes). 2026-05-28 17:41:44,104 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A700000: C:\Windows\SYSTEM32\profapi (0x25000 bytes). 2026-05-28 17:41:44,111 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2B280000: C:\Windows\System32\MSCTF (0x114000 bytes). 2026-05-28 17:41:44,112 [root] DEBUG: 2208: DLL loaded at 0x00007FFC20230000: C:\Windows\System32\AssignedAccessRuntime (0x14000 bytes). 2026-05-28 17:41:44,112 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A630000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes). 2026-05-28 17:41:44,113 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A560000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes). 2026-05-28 17:41:44,116 [root] DEBUG: 2208: DLL loaded at 0x00007FFC21B30000: C:\Windows\System32\SystemSettings.DataModel (0x74000 bytes). 2026-05-28 17:41:44,118 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1E180000: C:\Windows\SYSTEM32\DWrite (0x27f000 bytes). 2026-05-28 17:41:44,120 [root] DEBUG: 2208: DLL loaded at 0x00007FFC171F0000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\COMCTL32 (0x29a000 bytes). 2026-05-28 17:41:44,122 [root] DEBUG: 2208: DLL loaded at 0x00007FFC24D40000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes). 2026-05-28 17:41:44,122 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A4F0000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes). 2026-05-28 17:41:44,124 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29B90000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes). 2026-05-28 17:41:44,124 [root] DEBUG: 2208: DLL loaded at 0x00007FFC26180000: C:\Windows\system32\NLAapi (0x1d000 bytes). 2026-05-28 17:41:44,126 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2C7B0000: C:\Windows\System32\NSI (0x8000 bytes). 2026-05-28 17:41:44,127 [root] DEBUG: 2208: DLL loaded at 0x00007FFC232D0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes). 2026-05-28 17:41:44,127 [root] DEBUG: 2208: DLL loaded at 0x00007FFC216E0000: C:\Windows\System32\StructuredQuery (0xa6000 bytes). 2026-05-28 17:41:44,128 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2ACD0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-05-28 17:41:44,129 [root] DEBUG: 2208: DLL loaded at 0x00007FFC232B0000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes). 2026-05-28 17:41:44,130 [root] DEBUG: 2208: DLL loaded at 0x00007FFC27140000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes). 2026-05-28 17:41:44,132 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29BD0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes). 2026-05-28 17:41:44,134 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1BEB0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-05-28 17:41:44,136 [root] DEBUG: 2208: DLL loaded at 0x00007FFC27DC0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-05-28 17:41:44,137 [root] DEBUG: 2208: DLL loaded at 0x00007FFC26FE0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes). 2026-05-28 17:41:44,137 [root] DEBUG: 2208: DLL loaded at 0x00007FFC27980000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes). 2026-05-28 17:41:44,138 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1FA90000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-05-28 17:41:44,140 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1BCF0000: C:\Windows\system32\Windows.Storage.Search (0xc6000 bytes). 2026-05-28 17:41:44,141 [root] DEBUG: 2208: DLL loaded at 0x00007FFC25980000: C:\Windows\System32\twinapi.appcore (0x203000 bytes). 2026-05-28 17:41:44,143 [root] DEBUG: 2208: DLL loaded at 0x00007FFC17530000: C:\Windows\system32\twinapi (0xa9000 bytes). 2026-05-28 17:41:44,144 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1AD10000: C:\Windows\system32\mssprxy (0x28000 bytes). 2026-05-28 17:41:44,148 [root] DEBUG: 2208: DLL loaded at 0x00007FFC25B90000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes). 2026-05-28 17:41:44,148 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1F650000: C:\Windows\System32\InputHost (0x152000 bytes). 2026-05-28 17:41:44,149 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1FB90000: C:\Windows\System32\Windows.UI (0x141000 bytes). 2026-05-28 17:41:44,150 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1ACE0000: C:\Windows\SYSTEM32\edputil (0x24000 bytes). 2026-05-28 17:41:44,158 [root] DEBUG: 2208: DLL loaded at 0x00007FFC27460000: C:\Windows\SYSTEM32\WTSAPI32 (0x14000 bytes). 2026-05-28 17:41:44,163 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A500000: C:\Windows\SYSTEM32\WINSTA (0x5b000 bytes). 2026-05-28 17:41:44,166 [root] DEBUG: 2208: DLL loaded at 0x00007FFC20C50000: C:\Windows\System32\iertutil (0x2bc000 bytes). 2026-05-28 17:41:44,167 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1AC10000: C:\Windows\System32\Windows.Web (0xc3000 bytes). 2026-05-28 17:41:44,169 [root] DEBUG: 2208: DLL loaded at 0x00007FFBBE3D0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneauth (0x5c4000 bytes). 2026-05-28 17:41:44,171 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1CBA0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes). 2026-05-28 17:41:44,173 [root] DEBUG: 2208: DLL loaded at 0x00007FFC22A50000: C:\Windows\SYSTEM32\WINHTTP (0x10a000 bytes). 2026-05-28 17:41:44,174 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1E400000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes). 2026-05-28 17:41:44,175 [root] DEBUG: 2208: DLL loaded at 0x00007FFC257D0000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes). 2026-05-28 17:41:44,176 [root] DEBUG: 2208: DLL loaded at 0x00007FFC257F0000: C:\Windows\SYSTEM32\mscms (0xae000 bytes). 2026-05-28 17:41:44,202 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1BE00000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes). 2026-05-28 17:41:44,229 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 10688: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:44,230 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29090000: C:\Windows\system32\dxgi (0xf3000 bytes). 2026-05-28 17:41:44,231 [root] DEBUG: 2208: caller_dispatch: Added region at 0x00007FF7B5F00000 to tracked regions list (kernel32::CreateProcessInternalW returns to 0x00007FF7B5FF7D66, thread 10372). 2026-05-28 17:41:44,231 [root] DEBUG: 2208: DLL loaded at 0x00007FFC26D70000: C:\Windows\system32\d3d11 (0x263000 bytes). 2026-05-28 17:41:44,232 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10688 2026-05-28 17:41:44,233 [root] DEBUG: 2208: DLL loaded at 0x00007FFC27240000: C:\Windows\system32\dcomp (0x1e3000 bytes). 2026-05-28 17:41:44,233 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10688 2026-05-28 17:41:44,235 [root] DEBUG: 2208: DLL loaded at 0x00007FFC14FC0000: C:\Windows\system32\dataexchange (0x3e000 bytes). 2026-05-28 17:41:44,236 [root] DEBUG: 2208: ProcessImageBase: Main module image at 0x00007FF7B5F00000 unmodified (entropy change 0.000000e+00) 2026-05-28 17:41:44,258 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 10748: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:44,275 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A580000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes). 2026-05-28 17:41:44,281 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 10760: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:44,282 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10748 2026-05-28 17:41:44,285 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 10828: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:44,286 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 10836: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:44,291 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10760 2026-05-28 17:41:44,292 [root] DEBUG: 2208: DLL loaded at 0x00007FFC17950000: C:\Windows\System32\Windows.System.Profile.RetailInfo (0x28000 bytes). 2026-05-28 17:41:44,293 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10828 2026-05-28 17:41:44,294 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10836 2026-05-28 17:41:44,295 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10748 2026-05-28 17:41:44,296 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10828 2026-05-28 17:41:44,297 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10760 2026-05-28 17:41:44,297 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 10836 2026-05-28 17:41:44,308 [root] DEBUG: 2208: DLL loaded at 0x00007FFC15030000: C:\Windows\SYSTEM32\OLEACC (0x66000 bytes). 2026-05-28 17:41:44,342 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1D050000: C:\Windows\system32\directmanipulation (0x9d000 bytes). 2026-05-28 17:41:44,374 [root] DEBUG: 2208: DLL loaded at 0x00007FFC25960000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes). 2026-05-28 17:41:44,382 [root] DEBUG: 2208: DLL loaded at 0x00007FFC12AB0000: C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager (0x6d000 bytes). 2026-05-28 17:41:44,383 [root] DEBUG: 2208: DLL loaded at 0x00007FFC283C0000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes). 2026-05-28 17:41:44,513 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,548 [root] DEBUG: 2208: DLL loaded at 0x00007FFC198A0000: C:\Windows\System32\Windows.Security.Authentication.Web.Core (0x11d000 bytes). 2026-05-28 17:41:44,591 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,597 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,603 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 11252: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:44,605 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A2D0000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes). 2026-05-28 17:41:44,606 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,621 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,623 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 11252 2026-05-28 17:41:44,624 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,624 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1C0A0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes). 2026-05-28 17:41:44,625 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,626 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 11252 2026-05-28 17:41:44,628 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,633 [root] DEBUG: 2208: DLL loaded at 0x00007FFBED5F0000: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Well Known Domains\1.2.0.0\well_known_domains (0x9e000 bytes). 2026-05-28 17:41:44,636 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,636 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,638 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,639 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,644 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A090000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes). 2026-05-28 17:41:44,646 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,647 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1CFE0000: C:\Windows\System32\vaultcli (0x51000 bytes). 2026-05-28 17:41:44,650 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,653 [root] DEBUG: 2208: DLL loaded at 0x00007FFC297D0000: C:\Windows\system32\rsaenh (0x34000 bytes). 2026-05-28 17:41:44,665 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,666 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,667 [root] DEBUG: 2208: DLL loaded at 0x00007FFC17910000: C:\Windows\System32\aadWamExtension (0x36000 bytes). 2026-05-28 17:41:44,668 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,672 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,681 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,683 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,684 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,684 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,686 [root] DEBUG: 2208: DLL loaded at 0x00007FFBED560000: C:\Windows\System32\MicrosoftAccountWAMExtension (0x8c000 bytes). 2026-05-28 17:41:44,688 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,689 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,694 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,695 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,700 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,702 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:44,706 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:44,709 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,079 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,080 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,364 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,365 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,369 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,370 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,374 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,375 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,379 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,380 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,381 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,381 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,385 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,385 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,399 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,400 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,400 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,400 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,404 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,404 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,405 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,405 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,411 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,411 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,418 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,418 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,425 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,426 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,430 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,430 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,444 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,444 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,449 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,449 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,461 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,461 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,467 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,467 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,486 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,486 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,491 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,491 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,498 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,499 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,504 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,504 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,519 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,520 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,524 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,524 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,534 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,535 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,539 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,539 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,550 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,551 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,555 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,555 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,580 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 11928: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:45,581 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 11940: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:45,582 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 11928 2026-05-28 17:41:45,582 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 11940 2026-05-28 17:41:45,583 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 11928 2026-05-28 17:41:45,583 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 11940 2026-05-28 17:41:45,593 [root] DEBUG: 2208: DLL loaded at 0x00007FFC24C20000: C:\Windows\System32\netprofm (0x3f000 bytes). 2026-05-28 17:41:45,620 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,621 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,626 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,626 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,637 [root] DEBUG: 2208: DLL loaded at 0x00007FFBB9DC0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\telclient (0x3ed000 bytes). 2026-05-28 17:41:45,657 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2C0D0000: C:\Windows\System32\SETUPAPI (0x46e000 bytes). 2026-05-28 17:41:45,658 [root] DEBUG: 2208: DLL loaded at 0x00007FFC225B0000: C:\Windows\System32\npmproxy (0x10000 bytes). 2026-05-28 17:41:45,660 [root] DEBUG: 2208: DLL loaded at 0x00007FFBB9A80000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\oneds (0x33f000 bytes). 2026-05-28 17:41:45,664 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A490000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes). 2026-05-28 17:41:45,665 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2B050000: C:\Windows\System32\WINTRUST (0x67000 bytes). 2026-05-28 17:41:45,679 [root] DEBUG: 2208: DLL loaded at 0x00007FFC293F0000: C:\Windows\System32\FirewallAPI (0x96000 bytes). 2026-05-28 17:41:45,680 [root] DEBUG: 2208: DLL loaded at 0x00007FFC293B0000: C:\Windows\System32\fwbase (0x36000 bytes). 2026-05-28 17:41:45,689 [root] DEBUG: 2208: DLL loaded at 0x00007FFC11D50000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\microsoft_shell_integration (0x78000 bytes). 2026-05-28 17:41:45,699 [root] DEBUG: 2208: DLL loaded at 0x00007FFBBCBD0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\ffmpeg (0x467000 bytes). 2026-05-28 17:41:45,701 [root] DEBUG: 2208: DLL loaded at 0x00007FFC284D0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes). 2026-05-28 17:41:45,702 [root] DEBUG: 2208: DLL loaded at 0x00007FFC26310000: C:\Windows\System32\XmlLite (0x36000 bytes). 2026-05-28 17:41:45,702 [root] DEBUG: 2208: DLL loaded at 0x00007FFC16860000: C:\Windows\System32\wpnapps (0x15b000 bytes). 2026-05-28 17:41:45,722 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,723 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,727 [root] DEBUG: 2208: DLL loaded at 0x00007FFC11B00000: C:\Windows\System32\ShellCommonCommonProxyStub (0xe4000 bytes). 2026-05-28 17:41:45,727 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,728 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,752 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,753 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,759 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,759 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,775 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,776 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,780 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,780 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,787 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,788 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,792 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,792 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,796 [root] DEBUG: 2208: DLL loaded at 0x00007FFC20180000: C:\Windows\system32\TenantRestrictionsPlugin (0x1b000 bytes). 2026-05-28 17:41:45,801 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,803 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,806 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,807 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,816 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,817 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,821 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,821 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,830 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,831 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,835 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,835 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,847 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,847 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,851 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,852 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,863 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,864 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,869 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,869 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,886 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,887 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,890 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,891 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,898 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,899 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,903 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,903 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,917 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,917 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,921 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,922 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,929 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,929 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,933 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,934 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:45,960 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 10964: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7809A0000 2026-05-28 17:41:45,961 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 10964 2026-05-28 17:41:45,961 [lib.api.process] INFO: Monitor config for process 10964: C:\q61py415\dll\10964.ini 2026-05-28 17:41:45,962 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:41:45,997 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:45,998 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,003 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,004 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,059 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,060 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,064 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,065 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,079 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,079 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,084 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,085 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,091 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,092 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,096 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,097 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,100 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29860000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes). 2026-05-28 17:41:46,101 [root] DEBUG: 2208: DLL loaded at 0x00007FFC23B90000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 17:41:46,108 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,108 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,113 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,114 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,122 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,123 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,128 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,128 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,135 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,136 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,140 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,141 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,147 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,148 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,151 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,152 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,161 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,162 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,166 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:46,167 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:46,468 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 17:41:46,468 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 17:41:46,471 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:41:46,475 [root] DEBUG: Loader: Injecting process 10964 (thread 10984) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:46,476 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 17:41:46,476 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:46,478 [lib.api.process] INFO: Injected into 64-bit <Process 10964 identity_helper.exe> 2026-05-28 17:41:46,483 [root] DEBUG: 2208: DLL loaded at 0x00007FFC23660000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes). 2026-05-28 17:41:46,484 [root] DEBUG: 2208: DLL loaded at 0x00007FFC204E0000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes). 2026-05-28 17:41:46,486 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 12320: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe, ImageBase: 0x00007FF7809A0000 2026-05-28 17:41:46,488 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12320 2026-05-28 17:41:46,488 [lib.api.process] INFO: Monitor config for process 12320: C:\q61py415\dll\12320.ini 2026-05-28 17:41:46,489 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:41:46,557 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 17:41:46,557 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 17:41:46,559 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:41:46,563 [root] DEBUG: Loader: Injecting process 12320 (thread 12324) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:46,563 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 17:41:46,564 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:46,565 [lib.api.process] INFO: Injected into 64-bit <Process 12320 identity_helper.exe> 2026-05-28 17:41:46,567 [root] INFO: Announced 64-bit process name: identity_helper.exe pid: 12320 2026-05-28 17:41:46,567 [lib.api.process] INFO: Monitor config for process 12320: C:\q61py415\dll\12320.ini 2026-05-28 17:41:46,568 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:41:46,636 [lib.api.process] INFO: Potential dll side-loading detected in local directory: d3dcompiler_47.dll 2026-05-28 17:41:46,636 [lib.api.process] INFO: Potential dll side-loading detected in local directory: onnxruntime.dll 2026-05-28 17:41:46,638 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:41:46,642 [root] DEBUG: Loader: Injecting process 12320 (thread 12324) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:46,642 [root] DEBUG: InjectDllViaIAT: This image has already been patched. 2026-05-28 17:41:46,643 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:46,644 [lib.api.process] INFO: Injected into 64-bit <Process 12320 identity_helper.exe> 2026-05-28 17:41:46,658 [root] DEBUG: 12320: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 17:41:46,658 [root] DEBUG: 12320: Interactive desktop enabled. 2026-05-28 17:41:46,659 [root] DEBUG: 12320: Dropped file limit defaulting to 100. 2026-05-28 17:41:46,664 [root] DEBUG: 12320: Disabling sleep skipping. 2026-05-28 17:41:46,665 [root] DEBUG: 12320: YaraInit: Compiled rules loaded from existing file C:\q61py415\data\yara\capemon.yac 2026-05-28 17:41:46,677 [root] DEBUG: 12320: RtlInsertInvertedFunctionTable 0x00007FFC2D10090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC2D25D4F0 2026-05-28 17:41:46,677 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FF7809A0000, size 0x28b4d8 2026-05-28 17:41:46,695 [root] DEBUG: 12320: Monitor initialised: 64-bit capemon loaded in process 12320 at 0x00007FFC14380000, thread 12324, image base 0x00007FF7809A0000, stack from 0x0000005093D94000-0x0000005093DA0000 2026-05-28 17:41:46,696 [root] DEBUG: 12320: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=windows_package_identity --skip-read-main-dll --metrics-shmem-handle=5004,i,10041185329265187298,11074568154246322711,524288 --field-trial-handle=2364,i,10929924703418574237,15321897610074055618,262144 --variations-seed-version --pseudonymization-salt-handle=2368,i,15205487911583646568,1435369039403 2026-05-28 17:41:46,696 [root] DEBUG: 12320: add_all_dlls_to_dll_ranges: skipping C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll 2026-05-28 17:41:46,705 [root] DEBUG: 12320: hook_api: LdrpCallInitRoutine export address 0x00007FFC2D1099BC obtained via GetFunctionAddress 2026-05-28 17:41:46,732 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-05-28 17:41:46,733 [root] DEBUG: 12320: set_hooks: Unable to hook LockResource 2026-05-28 17:41:46,740 [root] DEBUG: 12320: Hooked 627 out of 628 functions 2026-05-28 17:41:46,746 [root] DEBUG: 2208: DLL loaded at 0x00007FFC19AE0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes). 2026-05-28 17:41:46,747 [root] DEBUG: 2208: DLL loaded at 0x00007FFC23A80000: C:\Windows\System32\AppXDeploymentClient (0x102000 bytes). 2026-05-28 17:41:46,750 [root] DEBUG: 2208: DLL loaded at 0x00007FFC22E90000: C:\Windows\system32\wlanapi (0x74000 bytes). 2026-05-28 17:41:46,755 [root] DEBUG: 12320: Syscall hook installed, syscall logging level 1 2026-05-28 17:41:46,760 [root] DEBUG: 12320: RestoreHeaders: Restored original import table. 2026-05-28 17:41:46,760 [root] INFO: Loaded monitor into process with pid 12320 2026-05-28 17:41:46,761 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FFBD2060000, size 0x4b9994 2026-05-28 17:41:46,845 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FFBD2060000, size 0x4b9994 2026-05-28 17:41:46,867 [root] DEBUG: 2208: DLL loaded at 0x00007FFC17770000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes). 2026-05-28 17:41:46,870 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A1B0000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes). 2026-05-28 17:41:46,871 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2A170000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes). 2026-05-28 17:41:46,872 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FFBD2060000, size 0x4b9994 2026-05-28 17:41:46,873 [root] DEBUG: 2208: DLL loaded at 0x00007FFC236E0000: C:\Windows\system32\PCPKsp (0x118000 bytes). 2026-05-28 17:41:46,879 [root] DEBUG: 2208: DLL loaded at 0x00007FFC2B260000: C:\Windows\System32\imagehlp (0x1d000 bytes). 2026-05-28 17:41:46,880 [root] DEBUG: 2208: DLL loaded at 0x00007FFC236C0000: C:\Windows\SYSTEM32\tbs (0x1b000 bytes). 2026-05-28 17:41:46,889 [root] DEBUG: 2208: DLL loaded at 0x00007FFC17800000: C:\Windows\system32\ncryptprov (0x5a000 bytes). 2026-05-28 17:41:46,901 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FFBD2060000, size 0x4b9994 2026-05-28 17:41:46,926 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FFBD2060000, size 0x4b9994 2026-05-28 17:41:46,952 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FFBD2060000, size 0x4b9994 2026-05-28 17:41:46,977 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FFBD2060000, size 0x4b9994 2026-05-28 17:41:47,004 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29EA0000: C:\Windows\system32\mswsock (0x6a000 bytes). 2026-05-28 17:41:47,006 [root] DEBUG: 12320: caller_dispatch: Added region at 0x00007FFBD2060000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FFBD225F156, thread 12324). 2026-05-28 17:41:47,006 [root] DEBUG: 12320: caller_dispatch: Scanning calling region at 0x00007FFBD2060000... 2026-05-28 17:41:47,010 [root] DEBUG: 12320: ProcessTrackedRegion: Region at 0x00007FFBD2060000 mapped as \Device\HarddiskVolume2\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge_elf.dll appears unmodified, skipping 2026-05-28 17:41:47,012 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2B0C0000: C:\Windows\System32\bcryptprimitives (0x82000 bytes). 2026-05-28 17:41:47,043 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FF7809A0000, size 0x28b4d8 2026-05-28 17:41:47,059 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FF7809A0000, size 0x28b4d8 2026-05-28 17:41:47,075 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FF7809A0000, size 0x28b4d8 2026-05-28 17:41:47,091 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FF7809A0000, size 0x28b4d8 2026-05-28 17:41:47,107 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FF7809A0000, size 0x28b4d8 2026-05-28 17:41:47,124 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FF7809A0000, size 0x28b4d8 2026-05-28 17:41:47,141 [root] DEBUG: 12320: caller_dispatch: Added region at 0x00007FF7809A0000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007FF780A94096, thread 12324). 2026-05-28 17:41:47,142 [root] DEBUG: 12320: YaraScan: Scanning 0x00007FF7809A0000, size 0x28b4d8 2026-05-28 17:41:47,159 [root] DEBUG: 12320: ProcessImageBase: Main module image at 0x00007FF7809A0000 unmodified (entropy change 0.000000e+00) 2026-05-28 17:41:47,163 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2B150000: C:\Windows\System32\shcore (0xad000 bytes). 2026-05-28 17:41:47,186 [root] DEBUG: 12320: DLL loaded at 0x00007FFBBE9A0000: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\msedge (0x136be000 bytes). 2026-05-28 17:41:47,190 [root] DEBUG: 12320: DLL loaded at 0x00007FFC28160000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-05-28 17:41:47,193 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2B280000: C:\Windows\System32\MSCTF (0x114000 bytes). 2026-05-28 17:41:47,222 [root] DEBUG: 12320: DLL loaded at 0x00007FFC286B0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-05-28 17:41:47,271 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2C9C0000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-05-28 17:41:47,282 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2B150000: C:\Windows\System32\shcore (0xad000 bytes). 2026-05-28 17:41:47,283 [root] DEBUG: 12320: DLL loaded at 0x00007FFC27140000: C:\Windows\System32\PROPSYS (0xf6000 bytes). 2026-05-28 17:41:47,284 [root] DEBUG: 12320: DLL loaded at 0x00007FFC27DC0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-05-28 17:41:47,284 [root] DEBUG: 12320: DLL loaded at 0x00007FFC19830000: C:\Windows\System32\execmodelclient (0x63000 bytes). 2026-05-28 17:41:47,292 [root] DEBUG: 12320: DLL loaded at 0x00007FFC25980000: C:\Windows\System32\twinapi.appcore (0x203000 bytes). 2026-05-28 17:41:47,294 [root] DEBUG: 12320: DLL loaded at 0x00007FFC26FE0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes). 2026-05-28 17:41:47,296 [root] DEBUG: 12320: DLL loaded at 0x00007FFC284D0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes). 2026-05-28 17:41:47,297 [root] DEBUG: 12320: DLL loaded at 0x00007FFC26310000: C:\Windows\System32\XmlLite (0x36000 bytes). 2026-05-28 17:41:47,297 [root] DEBUG: 12320: DLL loaded at 0x00007FFC16860000: C:\Windows\System32\wpnapps (0x15b000 bytes). 2026-05-28 17:41:47,305 [root] DEBUG: 12320: DLL loaded at 0x00007FFC1C0A0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes). 2026-05-28 17:41:47,313 [root] DEBUG: 12320: DLL loaded at 0x00007FFC178B0000: C:\Windows\system32\execmodelproxy (0x18000 bytes). 2026-05-28 17:41:47,319 [root] DEBUG: 12320: DLL loaded at 0x00007FFC29860000: C:\Windows\System32\msvcp110_win (0x8a000 bytes). 2026-05-28 17:41:47,320 [root] DEBUG: 12320: DLL loaded at 0x00007FFC23B90000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 17:41:47,323 [root] DEBUG: 12320: DLL loaded at 0x00007FFC25960000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes). 2026-05-28 17:41:47,331 [root] DEBUG: 12320: DLL loaded at 0x00007FFC24D40000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7d0000 bytes). 2026-05-28 17:41:47,335 [root] DEBUG: 12320: DLL loaded at 0x00007FFC1BEB0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-05-28 17:41:47,342 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2B050000: C:\Windows\System32\WINTRUST (0x67000 bytes). 2026-05-28 17:41:47,343 [root] DEBUG: 12320: DLL loaded at 0x00007FFC23660000: C:\Windows\SYSTEM32\capauthz (0x51000 bytes). 2026-05-28 17:41:47,351 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2A2D0000: C:\Windows\System32\MSASN1 (0x12000 bytes). 2026-05-28 17:41:47,401 [root] DEBUG: 12320: DLL loaded at 0x00007FFC19AE0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes). 2026-05-28 17:41:47,407 [root] DEBUG: 12320: DLL loaded at 0x00007FFC0C8D0000: C:\Windows\System32\CryptoWinRT (0x61000 bytes). 2026-05-28 17:41:47,420 [lib.api.process] INFO: Monitor config for process 760: C:\q61py415\dll\760.ini 2026-05-28 17:41:47,421 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:41:47,422 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:41:47,427 [root] DEBUG: Loader: Injecting process 760 with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:47,430 [root] DEBUG: 760: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 17:41:47,430 [root] DEBUG: 760: Disabling sleep skipping. 2026-05-28 17:41:47,430 [root] DEBUG: 760: Interactive desktop enabled. 2026-05-28 17:41:47,431 [root] DEBUG: 760: Dropped file limit defaulting to 100. 2026-05-28 17:41:47,434 [root] DEBUG: 760: Services hook set enabled 2026-05-28 17:41:47,435 [root] DEBUG: 760: YaraInit: Compiled rules loaded from existing file C:\q61py415\data\yara\capemon.yac 2026-05-28 17:41:47,449 [root] DEBUG: 760: RtlInsertInvertedFunctionTable 0x00007FFC2D10090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC2D25D4F0 2026-05-28 17:41:47,450 [root] DEBUG: 760: Monitor initialised: 64-bit capemon loaded in process 760 at 0x00007FFC14380000, thread 12848, image base 0x00007FF7B7570000, stack from 0x000000946FBF4000-0x000000946FC00000 2026-05-28 17:41:47,450 [root] DEBUG: 760: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p 2026-05-28 17:41:47,463 [root] DEBUG: 760: Hooked 69 out of 69 functions 2026-05-28 17:41:47,464 [root] INFO: Loaded monitor into process with pid 760 2026-05-28 17:41:47,464 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-05-28 17:41:47,465 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:41:47,466 [lib.api.process] INFO: Injected into 64-bit <Process 760 svchost.exe> 2026-05-28 17:41:47,595 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:47,596 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:47,600 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:47,600 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:47,795 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:47,796 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:47,800 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:47,801 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:48,409 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:48,410 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:49,488 [root] DEBUG: 12320: DLL loaded at 0x00007FFC200C0000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes). 2026-05-28 17:41:49,489 [root] DEBUG: 12320: DLL loaded at 0x00007FFC20500000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes). 2026-05-28 17:41:49,489 [root] DEBUG: 12320: DLL loaded at 0x00007FFC17000000: C:\Windows\System32\TileDataRepository (0x99000 bytes). 2026-05-28 17:41:49,490 [root] DEBUG: 12320: DLL loaded at 0x00007FFC10950000: C:\Windows\System32\biwinrt (0x53000 bytes). 2026-05-28 17:41:49,505 [root] DEBUG: 12320: DLL loaded at 0x00007FFC23800000: C:\Windows\System32\usermgrproxy (0x54000 bytes). 2026-05-28 17:41:49,550 [root] DEBUG: 12320: DLL loaded at 0x00007FFC29090000: C:\Windows\System32\dxgi (0xf3000 bytes). 2026-05-28 17:41:49,551 [root] DEBUG: 12320: DLL loaded at 0x00007FFC26D70000: C:\Windows\System32\d3d11 (0x263000 bytes). 2026-05-28 17:41:49,558 [root] DEBUG: 12320: DLL loaded at 0x00007FFC1D2B0000: C:\Windows\System32\WININET (0x4d6000 bytes). 2026-05-28 17:41:49,558 [root] DEBUG: 12320: DLL loaded at 0x00007FFC10840000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes). 2026-05-28 17:41:49,572 [root] DEBUG: 12320: DLL loaded at 0x00007FFC11C60000: C:\Windows\System32\PCShellCommonProxyStub (0x13000 bytes). 2026-05-28 17:41:49,593 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2A6C0000: C:\Windows\System32\USERENV (0x2e000 bytes). 2026-05-28 17:41:49,594 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2A140000: C:\Windows\System32\Wldp (0x2d000 bytes). 2026-05-28 17:41:49,594 [root] DEBUG: 12320: DLL loaded at 0x00007FFC288B0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes). 2026-05-28 17:41:49,595 [root] DEBUG: 12320: DLL loaded at 0x00007FFC20480000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes). 2026-05-28 17:41:49,595 [root] DEBUG: 12320: DLL loaded at 0x00007FFC16A70000: C:\Windows\System32\StartTileData (0x58a000 bytes). 2026-05-28 17:41:49,625 [root] DEBUG: 12320: DLL loaded at 0x00007FFC10BF0000: C:\Windows\System32\Windows.Storage.ApplicationData (0x66000 bytes). 2026-05-28 17:41:49,654 [root] DEBUG: 12320: DLL loaded at 0x00007FFC1AD10000: C:\Windows\system32\mssprxy (0x28000 bytes). 2026-05-28 17:41:49,690 [root] DEBUG: 12320: DLL loaded at 0x00007FFC2ACD0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-05-28 17:41:50,612 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 13100: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:41:50,613 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13100 2026-05-28 17:41:50,614 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13100 2026-05-28 17:41:52,237 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:41:52,238 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:41:59,769 [root] INFO: Process with pid 12320 has terminated 2026-05-28 17:41:59,770 [root] DEBUG: 12320: NtTerminateProcess hook: Attempting to dump process 12320 2026-05-28 17:41:59,773 [root] DEBUG: 12320: DoProcessDump: Skipping process dump as code is identical on disk. 2026-05-28 17:42:00,449 [root] INFO: Announced starting service "b'GoogleUpdaterService149.0.7814.0'" 2026-05-28 17:42:00,450 [lib.api.process] INFO: Monitor config for process 624: C:\q61py415\dll\624.ini 2026-05-28 17:42:00,451 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:42:00,452 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:42:00,456 [root] DEBUG: Loader: Injecting process 624 with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:42:00,458 [root] DEBUG: Loader: Copied config file C:\q61py415\dll\624.ini to system path C:\624.ini 2026-05-28 17:42:00,462 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 624 C:\q61py415\dll\wXsOlW.dll 2026-05-28 17:42:00,467 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:42:00,479 [lib.api.process] INFO: Injected into 64-bit <Process 624 services.exe> 2026-05-28 17:42:03,601 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:42:03,603 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:03,610 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270955e+00 (from 6.270496e+00) 2026-05-28 17:42:03,611 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:03,612 [root] DEBUG: 2072: DLL loaded at 0x00007FFC25E00000: C:\Windows\System32\taskschd (0xac000 bytes). 2026-05-28 17:42:03,617 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:03,617 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:03,618 [root] DEBUG: 2072: DLL loaded at 0x00007FFC1CBA0000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes). 2026-05-28 17:42:05,615 [root] DEBUG: 2208: DLL loaded at 0x00007FFC23E60000: C:\Windows\SYSTEM32\wevtapi (0x65000 bytes). 2026-05-28 17:42:11,711 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,712 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,718 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,718 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 12764: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:42:11,719 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,719 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 12764 2026-05-28 17:42:11,728 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,728 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,729 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,730 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,730 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 12764 2026-05-28 17:42:11,755 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,764 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,773 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 8160: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:42:11,773 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,774 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 8160 2026-05-28 17:42:11,779 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,781 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,781 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,782 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 8160 2026-05-28 17:42:11,815 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,819 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,827 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 7824: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:42:11,827 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,829 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 7824 2026-05-28 17:42:11,830 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,836 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,837 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,838 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 7824 2026-05-28 17:42:11,864 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,874 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:11,884 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:11,885 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:14,084 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1FE60000: C:\Windows\System32\Windows.System.UserProfile.DiagnosticsSettings (0x15000 bytes). 2026-05-28 17:42:14,162 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 13388: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:42:14,163 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13388 2026-05-28 17:42:14,164 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13388 2026-05-28 17:42:20,632 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 13500: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:42:20,633 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13500 2026-05-28 17:42:20,634 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13500 2026-05-28 17:42:42,099 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:42,100 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:42,743 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:42:42,744 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:42:44,150 [root] DEBUG: 2208: DLL loaded at 0x00007FFC292E0000: C:\Windows\SYSTEM32\sppc (0x25000 bytes). 2026-05-28 17:42:44,151 [root] DEBUG: 2208: DLL loaded at 0x00007FFC29310000: C:\Windows\system32\slc (0x29000 bytes). 2026-05-28 17:42:44,153 [root] DEBUG: 2208: DLL loaded at 0x00007FFC1CF10000: C:\Windows\system32\slwga (0x19000 bytes). 2026-05-28 17:42:44,185 [root] DEBUG: 2208: DLL loaded at 0x00007FFC14880000: C:\Windows\System32\Windows.System.Diagnostics.Telemetry.PlatformTelemetryClient (0x12000 bytes). 2026-05-28 17:42:44,197 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 13868: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:42:44,198 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13868 2026-05-28 17:42:44,199 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13868 2026-05-28 17:42:44,306 [root] DEBUG: 2208: DLL loaded at 0x00007FFBE85B0000: C:\Windows\System32\CloudExperienceHostCommon (0x128000 bytes). 2026-05-28 17:42:48,899 [root] DEBUG: 4248: DLL loaded at 0x00007FFC14310000: C:\Windows\SYSTEM32\storageusage (0x2f000 bytes). 2026-05-28 17:43:20,654 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 13416: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:43:20,656 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13416 2026-05-28 17:43:20,657 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13416 2026-05-28 17:43:24,436 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 12064: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:43:24,437 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 12064 2026-05-28 17:43:24,438 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 12064 2026-05-28 17:43:24,781 [root] DEBUG: 2208: DLL loaded at 0x00007FFC15280000: C:\Windows\System32\Windows.Security.Authentication.OnlineId (0xf4000 bytes). 2026-05-28 17:43:30,171 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 13596: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:43:30,433 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13596 2026-05-28 17:43:30,719 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 13596 2026-05-28 17:43:42,259 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:43:43,575 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:43:44,801 [root] DEBUG: 2208: CreateProcessHandler: Injection info set for new process 5932: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe, ImageBase: 0x00007FF7B5F00000 2026-05-28 17:43:45,162 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:43:45,578 [root] DEBUG: 2072: CreateProcessHandler: Injection info set for new process 13828: C:\Program Files\Google\Chrome\Application\chrome.exe, ImageBase: 0x00007FF78CD00000 2026-05-28 17:43:45,801 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 5932 2026-05-28 17:43:45,893 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:43:46,025 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 13828 2026-05-28 17:43:46,120 [root] DEBUG: 2208: ProcessMessage: Skipping monitoring process 5932 2026-05-28 17:43:46,255 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:43:46,344 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:43:46,484 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:43:46,619 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:43:46,705 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:43:46,800 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:43:46,999 [root] DEBUG: 2072: ProcessMessage: Skipping monitoring process 13828 2026-05-28 17:43:47,216 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:43:47,420 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:43:47,629 [root] DEBUG: 2072: ProcessTrackedRegion: Updated entropy for tracked region at 0x00007FFC13420000: 6.270956e+00 (from 6.270496e+00) 2026-05-28 17:43:47,821 [root] DEBUG: 2072: ProcessTrackedRegion: Region at 0x00007FFC13420000 mapped as \Device\HarddiskVolume2\Program Files\Google\Chrome\Application\148.0.7778.217\chrome_elf.dll is in known range, skipping 2026-05-28 17:43:50,542 [root] DEBUG: 4248: CreateProcessHandler: Injection info set for new process 14276: C:\Windows\system32\taskmgr.exe, ImageBase: 0x00007FF7299E0000 2026-05-28 17:43:50,790 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 14276 2026-05-28 17:43:50,871 [lib.api.process] INFO: Monitor config for process 14276: C:\q61py415\dll\14276.ini 2026-05-28 17:43:51,070 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:43:51,152 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:43:51,462 [root] DEBUG: Loader: Injecting process 14276 (thread 14212) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:43:51,700 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 17:43:51,904 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:43:52,182 [lib.api.process] INFO: Injected into 64-bit <Process 14276 Taskmgr.exe> 2026-05-28 17:43:52,392 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 14276 2026-05-28 17:43:52,469 [lib.api.process] INFO: Monitor config for process 14276: C:\q61py415\dll\14276.ini 2026-05-28 17:43:52,553 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:43:52,639 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:43:53,056 [root] DEBUG: Loader: Injecting process 14276 (thread 14212) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:43:53,259 [root] DEBUG: InjectDllViaIAT: This image has already been patched. 2026-05-28 17:43:53,467 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:43:53,706 [lib.api.process] INFO: Injected into 64-bit <Process 14276 Taskmgr.exe> 2026-05-28 17:43:53,909 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 14276 2026-05-28 17:43:53,993 [lib.api.process] INFO: Monitor config for process 14276: C:\q61py415\dll\14276.ini 2026-05-28 17:43:54,071 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:43:54,147 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:43:54,450 [root] DEBUG: Loader: Injecting process 14276 with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:43:54,655 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 14212, handle 0x120 2026-05-28 17:43:54,846 [root] DEBUG: InjectDllViaIAT: This image has already been patched. 2026-05-28 17:43:55,050 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:43:55,291 [lib.api.process] INFO: Injected into 64-bit <Process 14276 Taskmgr.exe> 2026-05-28 17:43:55,668 [root] DEBUG: 14276: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'. 2026-05-28 17:43:55,853 [root] DEBUG: 14276: Interactive desktop enabled. 2026-05-28 17:43:56,080 [root] DEBUG: 14276: Dropped file limit defaulting to 100. 2026-05-28 17:43:56,422 [root] DEBUG: 14276: Disabling sleep skipping. 2026-05-28 17:43:56,613 [root] DEBUG: 14276: YaraInit: Compiled rules loaded from existing file C:\q61py415\data\yara\capemon.yac 2026-05-28 17:43:56,820 [root] DEBUG: 14276: RtlInsertInvertedFunctionTable 0x00007FFC2D10090E, LdrpInvertedFunctionTableSRWLock 0x00007FFC2D25D4F0 2026-05-28 17:43:57,053 [root] DEBUG: 14276: YaraScan: Scanning 0x00007FF7299E0000, size 0x12fcfe 2026-05-28 17:43:57,294 [root] DEBUG: 14276: Monitor initialised: 64-bit capemon loaded in process 14276 at 0x00007FFC14380000, thread 14212, image base 0x00007FF7299E0000, stack from 0x000000ED18D94000-0x000000ED18DA0000 2026-05-28 17:43:57,520 [root] DEBUG: 14276: Commandline: "C:\Windows\system32\taskmgr.exe" /4 2026-05-28 17:43:57,725 [root] DEBUG: 14276: hook_api: LdrpCallInitRoutine export address 0x00007FFC2D1099BC obtained via GetFunctionAddress 2026-05-28 17:43:57,901 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-05-28 17:43:58,100 [root] DEBUG: 14276: set_hooks: Unable to hook LockResource 2026-05-28 17:43:58,288 [root] DEBUG: 14276: Hooked 627 out of 628 functions 2026-05-28 17:43:58,491 [root] DEBUG: 14276: Syscall hook installed, syscall logging level 1 2026-05-28 17:43:58,685 [root] DEBUG: 14276: RestoreHeaders: Restored original import table. 2026-05-28 17:43:58,865 [root] INFO: Loaded monitor into process with pid 14276 2026-05-28 17:43:59,115 [root] DEBUG: 14276: DLL loaded at 0x00007FFC2A560000: C:\Windows\system32\UMPDC (0x12000 bytes). 2026-05-28 17:43:59,294 [root] DEBUG: 14276: caller_dispatch: Added region at 0x00007FF7299E0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF729A0FF02, thread 14212). 2026-05-28 17:43:59,479 [root] DEBUG: 14276: YaraScan: Scanning 0x00007FF7299E0000, size 0x12fcfe 2026-05-28 17:43:59,682 [root] DEBUG: 14276: ProcessImageBase: Main module image at 0x00007FF7299E0000 unmodified (entropy change 0.000000e+00) 2026-05-28 17:44:00,015 [root] DEBUG: 14276: DLL loaded at 0x00007FFC2B0C0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes). 2026-05-28 17:44:00,216 [root] DEBUG: 14276: DLL loaded at 0x00007FFC2C9C0000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-05-28 17:44:00,416 [root] DEBUG: 14276: DLL loaded at 0x00007FFC2B280000: C:\Windows\System32\MSCTF (0x114000 bytes). 2026-05-28 17:44:00,615 [root] DEBUG: 14276: DLL loaded at 0x00007FFC1C2E0000: C:\Windows\system32\TextShaping (0xac000 bytes). 2026-05-28 17:44:00,941 [root] DEBUG: 14276: DLL loaded at 0x00007FFC298F0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-05-28 17:44:01,194 [root] DEBUG: 14276: DLL loaded at 0x00007FFC27DC0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-05-28 17:44:01,411 [root] DEBUG: 14276: DLL loaded at 0x00007FFC26FE0000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes). 2026-05-28 17:44:01,575 [root] DEBUG: 14276: DLL loaded at 0x00007FFC27980000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes). 2026-05-28 17:44:01,784 [root] DEBUG: 14276: DLL loaded at 0x00007FFC1FA90000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-05-28 17:44:02,010 [root] DEBUG: 14276: DLL loaded at 0x00007FFC29860000: C:\Windows\system32\msvcp110_win (0x8a000 bytes). 2026-05-28 17:44:02,257 [root] DEBUG: 14276: DLL loaded at 0x00007FFC23B90000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes). 2026-05-28 17:44:02,501 [root] DEBUG: 14276: DLL loaded at 0x00007FFC1D240000: C:\Windows\System32\NetworkUXBroker (0x6d000 bytes). 2026-05-28 17:44:02,784 [root] DEBUG: 14276: DLL loaded at 0x00007FFC0D2A0000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes). 2026-05-28 17:44:03,216 [root] DEBUG: 4248: DLL loaded at 0x00007FFC0D0A0000: C:\Windows\System32\CapabilityAccessManagerClient (0x3f000 bytes). 2026-05-28 17:44:03,389 [root] DEBUG: 14276: DLL loaded at 0x00007FFC27460000: C:\Windows\system32\WTSAPI32 (0x14000 bytes). 2026-05-28 17:44:06,907 [root] DEBUG: 14276: DLL loaded at 0x00007FFC2A500000: C:\Windows\system32\WINSTA (0x5b000 bytes). 2026-05-28 17:44:08,042 [root] DEBUG: 14276: DLL loaded at 0x00007FFC25C40000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes). 2026-05-28 17:44:09,884 [root] DEBUG: 760: CreateProcessHandler: Injection info set for new process 12736: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6ABE30000 2026-05-28 17:44:11,582 [root] DEBUG: 14276: DLL loaded at 0x00007FFC26310000: C:\Windows\system32\XmlLite (0x36000 bytes). 2026-05-28 17:44:12,106 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12736 2026-05-28 17:44:12,455 [lib.api.process] INFO: Monitor config for process 12736: C:\q61py415\dll\12736.ini 2026-05-28 17:44:12,625 [root] DEBUG: 14276: DLL loaded at 0x00007FFC2A700000: C:\Windows\System32\profapi (0x25000 bytes). 2026-05-28 17:44:13,146 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:44:13,492 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:44:13,492 [root] DEBUG: 14276: DLL loaded at 0x00007FFC1E400000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes). 2026-05-28 17:44:14,782 [root] DEBUG: 14276: DLL loaded at 0x00007FFC15030000: C:\Windows\system32\OLEACC (0x66000 bytes). 2026-05-28 17:44:15,333 [root] DEBUG: Loader: Injecting process 12736 (thread 14316) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:44:16,087 [root] DEBUG: 14276: DLL loaded at 0x00007FFC19C60000: C:\Windows\system32\srumapi (0x14000 bytes). 2026-05-28 17:44:16,639 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 17:44:17,211 [root] DEBUG: 14276: DLL loaded at 0x00007FFC2A140000: C:\Windows\system32\Wldp (0x2d000 bytes). 2026-05-28 17:44:17,986 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:44:20,843 [root] DEBUG: 14276: DLL loaded at 0x00007FFC288B0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes). 2026-05-28 17:44:21,410 [lib.api.process] INFO: Injected into 64-bit <Process 12736 dllhost.exe> 2026-05-28 17:44:21,750 [root] DEBUG: 14276: DLL loaded at 0x00007FFC213D0000: C:\Windows\system32\samcli (0x19000 bytes). 2026-05-28 17:44:21,913 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 12736 2026-05-28 17:44:22,034 [lib.api.process] INFO: Monitor config for process 12736: C:\q61py415\dll\12736.ini 2026-05-28 17:44:22,033 [root] DEBUG: 14276: DLL loaded at 0x00007FFC27430000: C:\Windows\system32\SAMLIB (0x28000 bytes). 2026-05-28 17:44:22,152 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:44:22,402 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:44:22,402 [root] DEBUG: 14276: DLL loaded at 0x00007FFC29CA0000: C:\Windows\system32\netutils (0xc000 bytes). 2026-05-28 17:44:22,744 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 92, handle 0x5cc: 2026-05-28 17:44:22,869 [root] DEBUG: 14276: DLL loaded at 0x00007FFC24B40000: C:\Windows\System32\ActXPrxy (0xa2000 bytes). 2026-05-28 17:44:22,950 [root] DEBUG: Loader: Injecting process 12736 (thread 14316) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:44:23,037 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 436, handle 0x5cc: C:\Windows\System32\csrss.exe 2026-05-28 17:44:23,168 [root] DEBUG: 14276: DLL loaded at 0x00007FFC14D00000: C:\Windows\System32\thumbcache (0x66000 bytes). 2026-05-28 17:44:23,325 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 17:44:23,405 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 524, handle 0x5cc: C:\Windows\System32\csrss.exe 2026-05-28 17:44:23,492 [root] DEBUG: 14276: DLL loaded at 0x00007FFC27140000: C:\Windows\system32\propsys (0xf6000 bytes). 2026-05-28 17:44:23,621 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:44:23,853 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 624, handle 0x5cc: C:\Windows\System32\services.exe 2026-05-28 17:44:23,994 [root] DEBUG: 14276: DLL loaded at 0x00007FFC25980000: C:\Windows\System32\twinapi.appcore (0x203000 bytes). 2026-05-28 17:44:24,035 [lib.api.process] INFO: Injected into 64-bit <Process 12736 dllhost.exe> 2026-05-28 17:44:24,091 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 760, handle 0x5cc: C:\Windows\System32\svchost.exe 2026-05-28 17:44:24,227 [root] DEBUG: 14276: DLL loaded at 0x00007FFC19AE0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes). 2026-05-28 17:44:24,362 [root] DEBUG: 760: CreateProcessHandler: Injection info set for new process 2700: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6ABE30000 2026-05-28 17:44:24,463 [root] DEBUG: 14276: OpenProcessHandler: Image base for process 760 (handle 0x5cc): 0x00007FF7B7570000. 2026-05-28 17:44:24,593 [root] DEBUG: 14276: DLL loaded at 0x00007FFC1BEB0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-05-28 17:44:24,757 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2700 2026-05-28 17:44:24,849 [lib.api.process] INFO: Monitor config for process 2700: C:\q61py415\dll\2700.ini 2026-05-28 17:44:24,887 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 780, handle 0x5cc: C:\Windows\System32\fontdrvhost.exe 2026-05-28 17:44:25,077 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:44:25,151 [lib.api.process] INFO: 64-bit DLL to inject is C:\q61py415\dll\wXsOlW.dll, loader C:\q61py415\bin\OCVwDwZX.exe 2026-05-28 17:44:25,150 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 928, handle 0x5cc: C:\Windows\System32\svchost.exe 2026-05-28 17:44:25,470 [root] DEBUG: 14276: OpenProcessHandler: Image base for process 928 (handle 0x5cc): 0x00007FF7B7570000. 2026-05-28 17:44:25,603 [root] DEBUG: Loader: Injecting process 2700 (thread 3912) with C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:44:25,690 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 420, handle 0x5cc: C:\Windows\System32\svchost.exe 2026-05-28 17:44:25,816 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-05-28 17:44:25,893 [root] DEBUG: 14276: OpenProcessHandler: Image base for process 420 (handle 0x5cc): 0x00007FF7B7570000. 2026-05-28 17:44:25,978 [root] DEBUG: Successfully injected DLL C:\q61py415\dll\wXsOlW.dll. 2026-05-28 17:44:26,066 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 688, handle 0x5cc: C:\Windows\System32\svchost.exe 2026-05-28 17:44:26,194 [lib.api.process] INFO: Injected into 64-bit <Process 2700 dllhost.exe> 2026-05-28 17:44:26,286 [root] DEBUG: 14276: OpenProcessHandler: Image base for process 688 (handle 0x5cc): 0x00007FF7B7570000. 2026-05-28 17:44:26,410 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2700 2026-05-28 17:44:26,508 [lib.api.process] INFO: Monitor config for process 2700: C:\q61py415\dll\2700.ini 2026-05-28 17:44:26,574 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor 2026-05-28 17:44:26,574 [root] DEBUG: 14276: OpenProcessHandler: Injection info created for process 1108, handle 0x5cc: C:\Windows\System32\svchost.exe
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 17:41:27 | 2026-05-28 17:44:39 | none |
Seek in progress...
No results found.
No behavioral analysis data available.
No dropped files found.