| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| URL | edge | 2026-05-28 17:48:21 | 2026-05-28 17:50:41 | 140s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 17:47:31,815 [root] INFO: Date set to: 20260528T17:48:26, timeout set to: 200
2026-05-28 17:48:26,014 [root] DEBUG: Starting analyzer from: C:\va9o_glt
2026-05-28 17:48:26,015 [root] DEBUG: Storing results at: C:\IacoYJNSd
2026-05-28 17:48:26,015 [root] DEBUG: Pipe server name: \\.\PIPE\jOZBvkR
2026-05-28 17:48:26,015 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 17:48:26,015 [root] INFO: analysis running as an admin
2026-05-28 17:48:26,015 [root] INFO: analysis package specified: "edge"
2026-05-28 17:48:26,015 [root] DEBUG: importing analysis package module: "modules.packages.edge"...
2026-05-28 17:48:26,017 [root] DEBUG: imported analysis package "edge"
2026-05-28 17:48:26,018 [root] DEBUG: initializing analysis package "edge"...
2026-05-28 17:48:26,018 [root] DEBUG: New location of moved file: https://sugarcraft.net/
2026-05-28 17:48:26,018 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll option
2026-05-28 17:48:26,019 [root] INFO: Analyzer: Package modules.packages.edge does not specify a dll_64 option
2026-05-28 17:48:26,019 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader option
2026-05-28 17:48:26,019 [root] INFO: Analyzer: Package modules.packages.edge does not specify a loader_64 option
2026-05-28 17:48:26,033 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 17:48:26,044 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 17:48:26,051 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 17:48:26,060 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 17:48:26,063 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 17:48:26,063 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 17:48:26,063 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 17:48:26,065 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 17:48:26,065 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 17:48:26,065 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 17:48:26,065 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 17:48:26,066 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 17:48:26,066 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 17:48:26,066 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 17:48:26,066 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 17:48:26,067 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 17:48:26,067 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 17:48:26,067 [modules.auxiliary.digisig] DEBUG: Skipping authenticode validation, analysis is not a file
2026-05-28 17:48:26,067 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 17:48:26,067 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 17:48:26,068 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 17:48:26,068 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 17:48:26,068 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 17:48:26,071 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 5360)
2026-05-28 17:48:26,074 [modules.auxiliary.disguise] INFO: Disguising GUID to f06fcdaa-6f56-4146-b59b-6a5f76919232
2026-05-28 17:48:26,075 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 17:48:26,075 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 17:48:26,075 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 17:48:26,076 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 17:48:26,076 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 17:48:26,076 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 17:48:26,077 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 17:48:26,077 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 17:48:26,077 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 17:48:26,078 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 17:48:26,081 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 17:48:26,081 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 17:48:26,082 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 17:48:26,083 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 17:48:26,083 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 17:48:26,083 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 17:48:26,086 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 17:48:26,091 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 17:48:26,091 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 17:48:26,132 [lib.api.process] INFO: Monitor config for process 4684: C:\va9o_glt\dll\4684.ini
2026-05-28 17:48:26,137 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:48:26,139 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:48:26,251 [root] DEBUG: Loader: Injecting process 4684 with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:48:26,419 [root] DEBUG: 4684: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:48:26,420 [root] DEBUG: 4684: Disabling sleep skipping.
2026-05-28 17:48:26,421 [root] DEBUG: 4684: Interactive desktop enabled.
2026-05-28 17:48:26,421 [root] DEBUG: 4684: Dropped file limit defaulting to 100.
2026-05-28 17:48:26,422 [root] DEBUG: 4684: Interactive desktop - injecting Explorer Shell
2026-05-28 17:48:26,426 [root] DEBUG: 4684: YaraInit: Compiled 44 rule files
2026-05-28 17:48:26,427 [root] DEBUG: 4684: YaraInit: Compiled rules saved to file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:48:26,474 [root] DEBUG: 4684: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:48:26,475 [root] DEBUG: 4684: YaraScan: Scanning 0x00007FF7C2E80000, size 0x545316
2026-05-28 17:48:26,536 [root] DEBUG: 4684: Monitor initialised: 64-bit capemon loaded in process 4684 at 0x00007FFF742B0000, thread 8360, image base 0x00007FF7C2E80000, stack from 0x0000000008212000-0x0000000008220000
2026-05-28 17:48:26,537 [root] DEBUG: 4684: Commandline: C:\Windows\Explorer.EXE
2026-05-28 17:48:26,552 [root] DEBUG: 4684: Hooked 69 out of 69 functions
2026-05-28 17:48:26,590 [root] DEBUG: 4684: Syscall hook installed, syscall logging level 1
2026-05-28 17:48:26,596 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:48:26,596 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:48:26,598 [lib.api.process] INFO: Injected into 64-bit <Process 4684 explorer.exe>
2026-05-28 17:48:33,825 [root] INFO: Restarting WMI Service
2026-05-28 17:48:35,395 [root] DEBUG: 4684: caller_dispatch: Added region at 0x00007FF7C2E80000 to tracked regions list (ntdll::NtCreateFile returns to 0x00007FF7C2F97BE7, thread 4772).
2026-05-28 17:48:35,401 [root] DEBUG: 4684: YaraScan: Scanning 0x00007FF7C2E80000, size 0x545316
2026-05-28 17:48:35,435 [root] DEBUG: 4684: ProcessImageBase: Main module image at 0x00007FF7C2E80000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:48:35,857 [root] DEBUG: package modules.packages.edge does not support configure, ignoring
2026-05-28 17:48:35,858 [root] WARNING: configuration error for package modules.packages.edge: error importing data.packages.edge: No module named 'data.packages'
2026-05-28 17:48:35,858 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 17:48:35,859 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" with arguments ""https://sugarcraft.net/"" with pid 2412
2026-05-28 17:48:35,859 [lib.api.process] INFO: Monitor config for process 2412: C:\va9o_glt\dll\2412.ini
2026-05-28 17:48:35,860 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:48:35,861 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:48:35,865 [root] DEBUG: Loader: Injecting process 2412 (thread 2404) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:48:35,871 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:48:35,872 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:48:35,874 [lib.api.process] INFO: Injected into 64-bit <Process 2412 msedge.exe>
2026-05-28 17:48:37,883 [lib.api.process] INFO: Successfully resumed process with pid 2412
2026-05-28 17:48:37,903 [root] DEBUG: 2412: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:48:37,903 [root] DEBUG: 2412: Disabling sleep skipping.
2026-05-28 17:48:37,904 [root] DEBUG: 2412: Interactive desktop enabled.
2026-05-28 17:48:37,904 [root] DEBUG: 2412: Dropped file limit defaulting to 100.
2026-05-28 17:48:37,911 [root] DEBUG: 2412: Edge-specific hook-set enabled.
2026-05-28 17:48:37,913 [root] DEBUG: 2412: YaraInit: Compiled rules loaded from existing file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:48:37,924 [root] DEBUG: 2412: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:48:37,925 [root] DEBUG: 2412: Monitor initialised: 64-bit capemon loaded in process 2412 at 0x00007FFF742B0000, thread 2404, image base 0x00007FF7660B0000, stack from 0x000000A0C3BF4000-0x000000A0C3C00000
2026-05-28 17:48:37,925 [root] DEBUG: 2412: Commandline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://sugarcraft.net/"
2026-05-28 17:48:37,935 [root] DEBUG: 2412: Hooked 2 out of 2 functions
2026-05-28 17:48:37,970 [root] DEBUG: 2412: Syscall hook installed, syscall logging level 1
2026-05-28 17:48:37,974 [root] DEBUG: 2412: RestoreHeaders: Restored original import table.
2026-05-28 17:48:37,975 [root] INFO: Loaded monitor into process with pid 2412
2026-05-28 17:48:37,976 [root] DEBUG: 2412: DLL loaded at 0x00007FFFD0710000: C:\Windows\System32\bcryptprimitives (0x82000 bytes).
2026-05-28 17:48:37,977 [root] DEBUG: 2412: DLL loaded at 0x00007FFFBAB60000: C:\Windows\SYSTEM32\version (0xa000 bytes).
2026-05-28 17:48:37,978 [root] DEBUG: 2412: DLL loaded at 0x00007FFFD1280000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 17:48:37,979 [root] DEBUG: 2412: DLL loaded at 0x00007FFFD0080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 17:48:37,980 [root] DEBUG: 2412: DLL loaded at 0x00007FFFCE7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 17:48:37,980 [root] DEBUG: 2412: DLL loaded at 0x00007FFFD1280000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 17:48:37,982 [root] DEBUG: 2412: DLL loaded at 0x00007FFFCE5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:48:38,903 [root] INFO: Process with pid 2412 appears to have terminated
2026-05-28 17:48:42,884 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC5B40000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 17:48:43,654 [lib.api.process] INFO: Monitor config for process 4684: C:\va9o_glt\dll\4684.ini
2026-05-28 17:48:43,884 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:48:43,977 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:48:44,424 [root] DEBUG: Loader: Injecting process 4684 with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:48:44,643 [root] DEBUG: 4684: caller_dispatch: Added region at 0x0000000002670000 to tracked regions list (ntdll::LdrLoadDll returns to 0x0000000002670043, thread 8328).
2026-05-28 17:48:44,865 [root] DEBUG: 4684: DumpPEsInRange: Scanning range 0x0000000002670000 - 0x0000000002670134.
2026-05-28 17:48:45,106 [root] DEBUG: 4684: ScanForDisguisedPE: Size too small: 0x134 bytes
2026-05-28 17:48:46,174 [lib.common.results] INFO: Uploading file C:\IacoYJNSd\CAPE\4684_131246482128452026 to CAPE\34209e97dec45c7fabf464a20da455ff65d200607c40b11c522cc66bc3f8cb29; Size is 308; Max size: 100000000
2026-05-28 17:48:46,425 [root] DEBUG: 4684: DumpMemory: Payload successfully created: C:\IacoYJNSd\CAPE\4684_131246482128452026 (size 308 bytes)
2026-05-28 17:48:46,859 [root] DEBUG: 4684: DumpRegion: Dumped entire allocation from 0x0000000002670000, size 4096 bytes.
2026-05-28 17:48:47,085 [root] DEBUG: 4684: ProcessTrackedRegion: Dumped region at 0x0000000002670000.
2026-05-28 17:48:47,317 [root] DEBUG: 4684: YaraScan: Scanning 0x0000000002670000, size 0x134
2026-05-28 17:48:47,444 [lib.api.process] INFO: Monitor config for process 788: C:\va9o_glt\dll\788.ini
2026-05-28 17:48:47,535 [root] DEBUG: 4684: Monitor config - unrecognised key host-ip.
2026-05-28 17:48:47,622 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:48:47,808 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:48:47,808 [root] DEBUG: 4684: Monitor config - unrecognised key host-port.
2026-05-28 17:48:48,127 [root] DEBUG: 4684: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:48:48,338 [root] DEBUG: Loader: Injecting process 788 with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:48:48,454 [root] DEBUG: 4684: Dropped file limit defaulting to 100.
2026-05-28 17:48:48,587 [root] DEBUG: 788: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:48:48,689 [root] DEBUG: 4684: hook_api: LdrpCallInitRoutine export address 0x00007FFFD30499BC obtained via GetFunctionAddress
2026-05-28 17:48:48,864 [root] DEBUG: 788: Disabling sleep skipping.
2026-05-28 17:48:48,981 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:48:49,111 [root] DEBUG: 788: Interactive desktop enabled.
2026-05-28 17:48:49,239 [root] DEBUG: 4684: set_hooks: Unable to hook LockResource
2026-05-28 17:48:49,421 [root] DEBUG: 788: Dropped file limit defaulting to 100.
2026-05-28 17:48:49,548 [root] DEBUG: 4684: Hooked 627 out of 628 functions
2026-05-28 17:48:49,772 [root] DEBUG: 788: Services hook set enabled
2026-05-28 17:48:49,899 [root] INFO: Loaded monitor into process with pid 4684
2026-05-28 17:48:50,183 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 17:48:50,306 [root] DEBUG: 788: YaraInit: Compiled rules loaded from existing file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:48:50,494 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:48:50,626 [root] DEBUG: 788: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:48:50,860 [root] DEBUG: 788: Monitor initialised: 64-bit capemon loaded in process 788 at 0x00007FFF742B0000, thread 6800, image base 0x00007FF69C310000, stack from 0x00000076CFC74000-0x00000076CFC80000
2026-05-28 17:48:50,991 [root] DEBUG: 4684: OpenProcessHandler: Image base for process 6780 (handle 0xc10): 0x00007FF7660B0000.
2026-05-28 17:48:51,118 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:48:51,289 [root] DEBUG: 788: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 17:48:51,524 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 6780, handle 0xc10: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:48:51,614 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 8688, handle 0xbe0: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:48:51,698 [root] DEBUG: 788: Hooked 69 out of 69 functions
2026-05-28 17:48:51,823 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:48:51,986 [root] INFO: Loaded monitor into process with pid 788
2026-05-28 17:48:52,074 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 5780, handle 0xc1c: Error obtaining target process name
2026-05-28 17:48:52,206 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:48:52,372 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:48:52,459 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:48:52,541 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 5300, handle 0xd10: Error obtaining target process name
2026-05-28 17:48:52,712 [lib.api.process] INFO: Injected into 64-bit <Process 788 svchost.exe>
2026-05-28 17:48:52,748 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:48:52,935 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB6600000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 17:48:53,015 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 7712, handle 0xdac: Error obtaining target process name
2026-05-28 17:48:53,138 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB6600000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 17:48:53,272 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:48:53,400 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBFB90000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 17:48:53,516 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 6264, handle 0x2040: Error obtaining target process name
2026-05-28 17:48:53,663 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBFB90000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 17:48:53,794 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:48:53,913 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC5AE0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 17:48:54,037 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 1588, handle 0x2328: Error obtaining target process name
2026-05-28 17:48:54,162 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC5AE0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 17:48:54,256 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 17:48:54,432 [root] INFO: Added new file to list with pid 4684 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 17:48:54,539 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 8960, handle 0x2344: Error obtaining target process name
2026-05-28 17:48:55,020 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC09F0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 17:48:55,315 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC09F0000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 17:48:55,591 [root] DEBUG: 4684: CreateProcessHandler: Injection info set for new process 3056: C:\Windows\system32\taskmgr.exe, ImageBase: 0x00007FF714B10000
2026-05-28 17:48:55,775 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC59A0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 17:48:55,886 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 3056
2026-05-28 17:48:56,050 [lib.api.process] INFO: Monitor config for process 3056: C:\va9o_glt\dll\3056.ini
2026-05-28 17:48:56,050 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC59A0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 17:48:56,219 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:48:56,325 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:48:56,415 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBBDA0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 17:48:56,637 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBBDA0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 17:48:56,925 [root] DEBUG: 4684: DLL loaded at 0x00007FFF73790000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 17:48:57,147 [root] DEBUG: 4684: DLL loaded at 0x00007FFF73790000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 17:48:57,484 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC2CA0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 17:48:57,678 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC2CA0000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 17:48:58,152 [root] INFO: Added new file to list with pid 4684 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 17:48:58,643 [root] DEBUG: 4684: CreateProcessHandler: Injection info set for new process 8464: C:\Windows\system32\taskmgr.exe, ImageBase: 0x00007FF714B10000
2026-05-28 17:48:58,915 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 8464
2026-05-28 17:48:58,995 [lib.api.process] INFO: Monitor config for process 8464: C:\va9o_glt\dll\8464.ini
2026-05-28 17:48:59,040 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC5AA0000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 17:48:59,180 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:48:59,277 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC5AA0000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 17:48:59,278 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:01,639 [root] DEBUG: Loader: Injecting process 3056 (thread 4000) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:02,124 [root] DEBUG: Loader: Injecting process 8464 (thread 8460) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:02,392 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:49:02,794 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:49:03,075 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:03,357 [lib.api.process] INFO: Injected into 64-bit <Process 3056 Taskmgr.exe>
2026-05-28 17:49:03,556 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:03,654 [lib.api.process] INFO: Injected into 64-bit <Process 8464 Taskmgr.exe>
2026-05-28 17:49:03,654 [root] DEBUG: 4684: OpenProcessHandler: Image base for process 5556 (handle 0x25c0): 0x00007FF7DA4A0000.
2026-05-28 17:49:03,661 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 3056
2026-05-28 17:49:03,662 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 8464
2026-05-28 17:49:03,686 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 5556, handle 0x25c0: C:\Windows\System32\conhost.exe
2026-05-28 17:49:03,662 [lib.api.process] INFO: Monitor config for process 3056: C:\va9o_glt\dll\3056.ini
2026-05-28 17:49:03,688 [lib.api.process] INFO: Monitor config for process 8464: C:\va9o_glt\dll\8464.ini
2026-05-28 17:49:03,699 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:03,721 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:03,722 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:03,722 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:03,756 [root] DEBUG: Loader: Injecting process 8464 (thread 8460) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:03,765 [root] DEBUG: Loader: Injecting process 3056 (thread 4000) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:03,792 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:49:03,793 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:49:03,795 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:03,795 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:03,799 [lib.api.process] INFO: Injected into 64-bit <Process 3056 Taskmgr.exe>
2026-05-28 17:49:03,858 [lib.api.process] INFO: Injected into 64-bit <Process 8464 Taskmgr.exe>
2026-05-28 17:49:03,904 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBF430000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 17:49:03,910 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBF430000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 17:49:03,918 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB1860000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 17:49:03,924 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB1860000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-05-28 17:49:03,929 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB8220000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 17:49:03,930 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB8220000: C:\Windows\System32\sfc_os (0x12000 bytes).
2026-05-28 17:49:03,965 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 8464
2026-05-28 17:49:03,966 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 3056
2026-05-28 17:49:03,967 [lib.api.process] INFO: Monitor config for process 3056: C:\va9o_glt\dll\3056.ini
2026-05-28 17:49:03,966 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB64D0000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 17:49:03,966 [lib.api.process] INFO: Monitor config for process 8464: C:\va9o_glt\dll\8464.ini
2026-05-28 17:49:03,968 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:03,976 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:03,977 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB64D0000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 17:49:03,977 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:03,979 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:04,011 [root] DEBUG: Loader: Injecting process 8464 with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:04,013 [root] DEBUG: Loader: Injecting process 3056 with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:04,043 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8460, handle 0x120
2026-05-28 17:49:04,044 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 4000, handle 0x124
2026-05-28 17:49:04,109 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:49:04,157 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:49:04,185 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:04,269 [lib.api.process] INFO: Injected into 64-bit <Process 8464 Taskmgr.exe>
2026-05-28 17:49:04,301 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:04,327 [root] INFO: Added new file to list with pid 4684 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 17:49:04,386 [lib.api.process] INFO: Injected into 64-bit <Process 3056 Taskmgr.exe>
2026-05-28 17:49:04,671 [root] DEBUG: 8464: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:49:04,674 [root] DEBUG: 3056: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:49:04,674 [root] DEBUG: 4684: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 17:49:04,676 [root] DEBUG: 4684: api-rate-cap: IsDebuggerPresent hook disabled due to rate
2026-05-28 17:49:04,692 [root] DEBUG: 8464: Interactive desktop enabled.
2026-05-28 17:49:04,703 [root] DEBUG: 3056: Interactive desktop enabled.
2026-05-28 17:49:04,716 [root] DEBUG: 8464: Dropped file limit defaulting to 100.
2026-05-28 17:49:04,722 [root] DEBUG: 3056: Dropped file limit defaulting to 100.
2026-05-28 17:49:04,747 [root] DEBUG: 8464: Disabling sleep skipping.
2026-05-28 17:49:04,759 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB7C80000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 17:49:04,760 [root] DEBUG: 3056: Disabling sleep skipping.
2026-05-28 17:49:04,761 [root] DEBUG: 8464: YaraInit: Compiled rules loaded from existing file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:49:04,784 [root] DEBUG: 4684: DLL loaded at 0x00007FFFB7C80000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 17:49:04,786 [root] DEBUG: 3056: YaraInit: Compiled rules loaded from existing file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:49:04,799 [root] DEBUG: 8464: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:49:04,803 [root] DEBUG: 3056: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:49:04,807 [root] DEBUG: 8464: YaraScan: Scanning 0x00007FF714B10000, size 0x12fcfe
2026-05-28 17:49:04,824 [root] DEBUG: 3056: YaraScan: Scanning 0x00007FF714B10000, size 0x12fcfe
2026-05-28 17:49:04,831 [root] DEBUG: 8464: Monitor initialised: 64-bit capemon loaded in process 8464 at 0x00007FFF742B0000, thread 8460, image base 0x00007FF714B10000, stack from 0x0000004C67874000-0x0000004C67880000
2026-05-28 17:49:04,843 [root] DEBUG: 3056: Monitor initialised: 64-bit capemon loaded in process 3056 at 0x00007FFF742B0000, thread 4000, image base 0x00007FF714B10000, stack from 0x00000026A50A4000-0x00000026A50B0000
2026-05-28 17:49:04,859 [root] DEBUG: 8464: Commandline: "C:\Windows\system32\taskmgr.exe" /4
2026-05-28 17:49:04,875 [root] DEBUG: 3056: Commandline: "C:\Windows\system32\taskmgr.exe" /4
2026-05-28 17:49:04,876 [root] DEBUG: 8464: hook_api: LdrpCallInitRoutine export address 0x00007FFFD30499BC obtained via GetFunctionAddress
2026-05-28 17:49:04,923 [root] DEBUG: 3056: hook_api: LdrpCallInitRoutine export address 0x00007FFFD30499BC obtained via GetFunctionAddress
2026-05-28 17:49:04,938 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:49:04,963 [root] DEBUG: 8464: set_hooks: Unable to hook LockResource
2026-05-28 17:49:04,966 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:49:04,988 [root] DEBUG: 3056: set_hooks: Unable to hook LockResource
2026-05-28 17:49:04,995 [root] DEBUG: 8464: Hooked 627 out of 628 functions
2026-05-28 17:49:05,017 [root] DEBUG: 3056: Hooked 627 out of 628 functions
2026-05-28 17:49:05,029 [root] DEBUG: 8464: Syscall hook installed, syscall logging level 1
2026-05-28 17:49:05,077 [root] DEBUG: 3056: Syscall hook installed, syscall logging level 1
2026-05-28 17:49:05,089 [root] DEBUG: 8464: RestoreHeaders: Restored original import table.
2026-05-28 17:49:05,103 [root] DEBUG: 3056: RestoreHeaders: Restored original import table.
2026-05-28 17:49:05,113 [root] INFO: Loaded monitor into process with pid 8464
2026-05-28 17:49:05,129 [root] INFO: Loaded monitor into process with pid 3056
2026-05-28 17:49:05,135 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD04A0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 17:49:05,196 [root] DEBUG: 8464: caller_dispatch: Added region at 0x00007FF714B10000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF714B3FF02, thread 8460).
2026-05-28 17:49:05,210 [root] DEBUG: 8464: YaraScan: Scanning 0x00007FF714B10000, size 0x12fcfe
2026-05-28 17:49:05,232 [root] DEBUG: 8464: ProcessImageBase: Main module image at 0x00007FF714B10000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:49:05,242 [root] DEBUG: 3056: DLL loaded at 0x00007FFFD04A0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-05-28 17:49:05,278 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD0710000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:49:05,282 [root] DEBUG: 3056: caller_dispatch: Added region at 0x00007FF714B10000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF714B3FF02, thread 4000).
2026-05-28 17:49:05,293 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD2C30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:49:05,293 [root] DEBUG: 3056: YaraScan: Scanning 0x00007FF714B10000, size 0x12fcfe
2026-05-28 17:49:05,322 [root] DEBUG: 3056: ProcessImageBase: Main module image at 0x00007FF714B10000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:49:05,336 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD2940000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 17:49:05,362 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC0E00000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-05-28 17:49:05,389 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCF830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:49:05,394 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCDD00000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-05-28 17:49:05,400 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCC640000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 17:49:05,404 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCD9A0000: C:\Windows\System32\CoreUIComponents (0x35b000 bytes).
2026-05-28 17:49:05,406 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC5140000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-05-28 17:49:05,422 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCF7A0000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 17:49:05,428 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCB160000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 17:49:05,498 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC2D30000: C:\Windows\System32\NetworkUXBroker (0x6d000 bytes).
2026-05-28 17:49:05,522 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC09A0000: C:\Windows\system32\srumapi (0x14000 bytes).
2026-05-28 17:49:05,525 [root] DEBUG: 8464: DLL loaded at 0x00007FFFBF590000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes).
2026-05-28 17:49:05,572 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCB850000: C:\Windows\system32\WTSAPI32 (0x14000 bytes).
2026-05-28 17:49:05,577 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD0080000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 17:49:05,587 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCE7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 17:49:05,668 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCC600000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 17:49:05,730 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCA730000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes).
2026-05-28 17:49:05,785 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD03D0000: C:\Windows\system32\WINSTA (0x5b000 bytes).
2026-05-28 17:49:05,808 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC9800000: C:\Windows\System32\ActXPrxy (0xa2000 bytes).
2026-05-28 17:49:05,830 [root] DEBUG: 8464: DLL loaded at 0x00007FFFBAC40000: C:\Windows\system32\OLEACC (0x66000 bytes).
2026-05-28 17:49:05,879 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD0640000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 17:49:05,993 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC3EF0000: C:\Windows\System32\Windows.UI.Immersive (0x139000 bytes).
2026-05-28 17:49:06,061 [root] DEBUG: 8464: DLL loaded at 0x00007FFFBA5C0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 17:49:06,084 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC7040000: C:\Windows\system32\samcli (0x19000 bytes).
2026-05-28 17:49:06,098 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCC350000: C:\Windows\system32\SAMLIB (0x28000 bytes).
2026-05-28 17:49:06,118 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCFB10000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 17:49:06,146 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 92, handle 0x61c:
2026-05-28 17:49:06,183 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCC250000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 17:49:06,183 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 452, handle 0x61c: C:\Windows\System32\csrss.exe
2026-05-28 17:49:06,326 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 540, handle 0x61c: C:\Windows\System32\csrss.exe
2026-05-28 17:49:06,348 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCA8F0000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-05-28 17:49:06,348 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 628, handle 0x61c: C:\Windows\System32\winlogon.exe
2026-05-28 17:49:06,348 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC5AA0000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 17:49:06,367 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 628 (handle 0x61c): 0x00007FF795140000.
2026-05-28 17:49:06,368 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC04E0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-05-28 17:49:06,372 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC5AA0000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 17:49:06,385 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 772, handle 0x61c: C:\Windows\System32\fontdrvhost.exe
2026-05-28 17:49:06,401 [root] INFO: Added new file to list with pid 4684 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 17:49:06,401 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC1A30000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-05-28 17:49:06,409 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 772 (handle 0x61c): 0x00007FF69CF60000.
2026-05-28 17:49:06,425 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 788, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,431 [root] INFO: Added new file to list with pid 4684 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
2026-05-28 17:49:06,447 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 788 (handle 0x6f4): 0x00007FF69C310000.
2026-05-28 17:49:06,452 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 940, handle 0x6f4: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,460 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 940 (handle 0x6f4): 0x00007FF69C310000.
2026-05-28 17:49:06,489 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 392, handle 0x6f4: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,494 [root] DEBUG: 788: CreateProcessHandler: Injection info set for new process 10308: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF67F380000
2026-05-28 17:49:06,504 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 884, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,516 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10308
2026-05-28 17:49:06,517 [lib.api.process] INFO: Monitor config for process 10308: C:\va9o_glt\dll\10308.ini
2026-05-28 17:49:06,520 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 884 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:06,521 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:06,535 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1132, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,551 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:06,562 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1132 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:06,572 [root] DEBUG: Loader: Injecting process 10308 (thread 10312) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:06,575 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1148, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,585 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:49:06,603 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:06,605 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1148 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:06,607 [lib.api.process] INFO: Injected into 64-bit <Process 10308 dllhost.exe>
2026-05-28 17:49:06,613 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1352, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,632 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 10308
2026-05-28 17:49:06,632 [root] INFO: Added new file to list with pid 4684 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
2026-05-28 17:49:06,637 [lib.api.process] INFO: Monitor config for process 10308: C:\va9o_glt\dll\10308.ini
2026-05-28 17:49:06,639 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:06,639 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1352 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:06,641 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:06,653 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1368, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,667 [root] DEBUG: Loader: Injecting process 10308 (thread 10312) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:06,677 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1368 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:06,685 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:49:06,702 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1384, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,707 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:06,712 [lib.api.process] INFO: Injected into 64-bit <Process 10308 dllhost.exe>
2026-05-28 17:49:06,732 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1384 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:06,741 [root] DEBUG: 10308: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:49:06,747 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1564, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,761 [root] DEBUG: 10308: Interactive desktop enabled.
2026-05-28 17:49:06,780 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1564 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:06,786 [root] DEBUG: 10308: Dropped file limit defaulting to 100.
2026-05-28 17:49:06,804 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1644, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,820 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1644 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:06,838 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1668, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,861 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1668 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:06,865 [root] DEBUG: 10308: Disabling sleep skipping.
2026-05-28 17:49:06,883 [root] DEBUG: 10308: YaraInit: Compiled rules loaded from existing file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:49:06,883 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1776, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,916 [root] DEBUG: 10308: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:49:06,918 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1776 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:06,963 [root] DEBUG: 10308: YaraScan: Scanning 0x00007FF67F380000, size 0x8026
2026-05-28 17:49:06,969 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1948, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,972 [root] DEBUG: 10308: Monitor initialised: 64-bit capemon loaded in process 10308 at 0x00007FFF742B0000, thread 10312, image base 0x00007FF67F380000, stack from 0x000000A59DD84000-0x000000A59DD90000
2026-05-28 17:49:06,974 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1948 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:06,978 [root] DEBUG: 10308: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 17:49:06,996 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1988, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:06,999 [root] DEBUG: 10308: hook_api: LdrpCallInitRoutine export address 0x00007FFFD30499BC obtained via GetFunctionAddress
2026-05-28 17:49:07,028 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:49:07,033 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1988 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:07,035 [root] DEBUG: 10308: set_hooks: Unable to hook LockResource
2026-05-28 17:49:07,048 [root] DEBUG: 10308: Hooked 627 out of 628 functions
2026-05-28 17:49:07,049 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2096, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,067 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2096 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:07,068 [root] DEBUG: 10308: Syscall hook installed, syscall logging level 1
2026-05-28 17:49:07,093 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2144, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,096 [root] DEBUG: 10308: RestoreHeaders: Restored original import table.
2026-05-28 17:49:07,101 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2144 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:07,104 [root] INFO: Loaded monitor into process with pid 10308
2026-05-28 17:49:07,111 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2264, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,115 [root] DEBUG: 10308: caller_dispatch: Added region at 0x00007FF67F380000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF67F3812F2, thread 10312).
2026-05-28 17:49:07,120 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2264 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:07,124 [root] DEBUG: 10308: YaraScan: Scanning 0x00007FF67F380000, size 0x8026
2026-05-28 17:49:07,126 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2548, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,129 [root] DEBUG: 10308: ProcessImageBase: Main module image at 0x00007FF67F380000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:49:07,133 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2548 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:07,137 [root] DEBUG: 10308: DLL loaded at 0x00007FFFCE5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:49:07,140 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2632, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,143 [root] DEBUG: 10308: DLL loaded at 0x00007FFFD0710000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:49:07,147 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2632 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:07,147 [root] DEBUG: 10308: DLL loaded at 0x00007FFFD2C30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:49:07,170 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2648, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,171 [root] DEBUG: 10308: DLL loaded at 0x00007FFFCE0D0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 17:49:07,178 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2648 (handle 0x6fc): 0x00007FF69C310000.
2026-05-28 17:49:07,194 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2776, handle 0x6fc: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,198 [root] DEBUG: 10308: DLL loaded at 0x00007FFFD1280000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 17:49:07,198 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2776 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:07,202 [root] DEBUG: 10308: DLL loaded at 0x00007FFFBA5C0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 17:49:07,202 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2912, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,213 [root] DEBUG: 10308: DLL loaded at 0x00007FFFCC250000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 17:49:07,213 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2912 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:07,224 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3396, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,245 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3396 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:07,245 [root] INFO: Added new file to list with pid 4684 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-05-28 17:49:07,249 [root] DEBUG: 4684: api-cap: NtClose hook disabled due to count: 5000
2026-05-28 17:49:07,253 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3216, handle 0x61c: C:\Windows\System32\sihost.exe
2026-05-28 17:49:07,253 [root] DEBUG: 4684: api-cap: NtClose hook disabled due to count: 5001
2026-05-28 17:49:07,262 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3216 (handle 0x61c): 0x00007FF6ED7A0000.
2026-05-28 17:49:07,277 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3152, handle 0x61c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,292 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3152 (handle 0x61c): 0x00007FF69C310000.
2026-05-28 17:49:07,305 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4112, handle 0x61c: C:\Windows\System32\taskhostw.exe
2026-05-28 17:49:07,321 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4112 (handle 0x61c): 0x00007FF73DDE0000.
2026-05-28 17:49:07,334 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4244, handle 0x66c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,342 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4244 (handle 0x66c): 0x00007FF69C310000.
2026-05-28 17:49:07,353 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4376, handle 0x66c: C:\Windows\System32\ctfmon.exe
2026-05-28 17:49:07,371 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4376 (handle 0x66c): 0x00007FF751700000.
2026-05-28 17:49:07,385 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4568, handle 0x66c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,394 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4568 (handle 0x66c): 0x00007FF69C310000.
2026-05-28 17:49:07,403 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4684, handle 0x66c: C:\Windows\explorer.exe
2026-05-28 17:49:07,418 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4684 (handle 0x66c): 0x00007FF7C2E80000.
2026-05-28 17:49:07,432 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5300, handle 0x66c: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
2026-05-28 17:49:07,449 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC5A40000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 17:49:07,456 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCF220000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 17:49:07,468 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCF250000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 17:49:07,477 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD0600000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 17:49:07,486 [root] DEBUG: 8464: DLL loaded at 0x00007FFFBC440000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 17:49:07,501 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCDF40000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes).
2026-05-28 17:49:07,510 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC66F0000: C:\Windows\System32\StateRepository.Core (0xb1000 bytes).
2026-05-28 17:49:07,519 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC5B80000: C:\Windows\System32\Windows.StateRepository (0x58e000 bytes).
2026-05-28 17:49:07,521 [root] DEBUG: 8464: DLL loaded at 0x00007FFFBC770000: C:\Windows\System32\TileDataRepository (0x99000 bytes).
2026-05-28 17:49:07,540 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC7B50000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-05-28 17:49:07,549 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC54F0000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2026-05-28 17:49:07,556 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCAB00000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-05-28 17:49:07,557 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC5240000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-05-28 17:49:07,560 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC53A0000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-05-28 17:49:07,566 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC50F0000: C:\Windows\SYSTEM32\languageoverlayutil (0x41000 bytes).
2026-05-28 17:49:07,573 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC59D0000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-05-28 17:49:07,576 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC6BA0000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-05-28 17:49:07,590 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5300 (handle 0x788): 0x00007FF6BE890000.
2026-05-28 17:49:07,597 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5348, handle 0x738: C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe
2026-05-28 17:49:07,602 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5348 (handle 0x790): 0x00007FF7C0620000.
2026-05-28 17:49:07,604 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5532, handle 0x790: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 17:49:07,611 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5532 (handle 0x738): 0x00007FF6D97F0000.
2026-05-28 17:49:07,615 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5856, handle 0x738: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 17:49:07,623 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5856 (handle 0x78c): 0x00007FF6D97F0000.
2026-05-28 17:49:07,633 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3364, handle 0x78c: C:\Windows\System32\smartscreen.exe
2026-05-28 17:49:07,641 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3364 (handle 0x78c): 0x00007FF771A60000.
2026-05-28 17:49:07,643 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5820, handle 0x78c: C:\Windows\System32\SecurityHealthService.exe
2026-05-28 17:49:07,645 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5556, handle 0x78c: C:\Windows\System32\conhost.exe
2026-05-28 17:49:07,648 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5556 (handle 0x78c): 0x00007FF7DA4A0000.
2026-05-28 17:49:07,650 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6040, handle 0x78c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,653 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6040 (handle 0x78c): 0x00007FF69C310000.
2026-05-28 17:49:07,655 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6264, handle 0x78c: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:49:07,660 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6264 (handle 0x750): 0x00007FF748BE0000.
2026-05-28 17:49:07,661 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6372, handle 0x750: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:49:07,664 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6372 (handle 0x750): 0x00007FF748BE0000.
2026-05-28 17:49:07,666 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6536, handle 0x750: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:49:07,668 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6536 (handle 0x750): 0x00007FF748BE0000.
2026-05-28 17:49:07,671 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6860, handle 0x750: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:07,675 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6860 (handle 0x750): 0x00007FF7660B0000.
2026-05-28 17:49:07,677 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7104, handle 0x750: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:07,679 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7104 (handle 0x750): 0x00007FF7660B0000.
2026-05-28 17:49:07,681 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7248, handle 0x750: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:49:07,690 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7248 (handle 0x750): 0x00007FF748BE0000.
2026-05-28 17:49:07,724 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7528, handle 0x750: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:07,743 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7528 (handle 0x750): 0x00007FF7660B0000.
2026-05-28 17:49:07,747 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7712, handle 0x750: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:49:07,749 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7712 (handle 0x750): 0x00007FF684880000.
2026-05-28 17:49:07,755 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7796, handle 0x750: C:\Program Files (x86)\Common Files\Steam\steamservice.exe
2026-05-28 17:49:07,757 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7796 (handle 0x750): 0x0000000000860000.
2026-05-28 17:49:07,760 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 8036, handle 0x750: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:49:07,763 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 8036 (handle 0x750): 0x00007FF684880000.
2026-05-28 17:49:07,765 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 8188, handle 0x750: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:49:07,776 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 8188 (handle 0x750): 0x00007FF684880000.
2026-05-28 17:49:07,782 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 8688, handle 0x750: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
2026-05-28 17:49:07,798 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 8688 (handle 0x79c): 0x00007FF7E7C80000.
2026-05-28 17:49:07,815 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 8320, handle 0x750: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,820 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 8320 (handle 0x750): 0x00007FF69C310000.
2026-05-28 17:49:07,823 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 8960, handle 0x750: C:\Windows\System32\ApplicationFrameHost.exe
2026-05-28 17:49:07,825 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 8960 (handle 0x750): 0x00007FF7A52A0000.
2026-05-28 17:49:07,827 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 9048, handle 0x750: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 17:49:07,833 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 9048 (handle 0x750): 0x00007FF6D97F0000.
2026-05-28 17:49:07,843 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5960, handle 0x78c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:07,846 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5960 (handle 0x78c): 0x00007FF69C310000.
2026-05-28 17:49:07,848 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1404, handle 0x78c: C:\Windows\System32\backgroundTaskHost.exe
2026-05-28 17:49:07,871 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1404 (handle 0x798): 0x00007FF64B390000.
2026-05-28 17:49:07,876 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2960, handle 0x738: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:07,879 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2960 (handle 0x738): 0x00007FF7660B0000.
2026-05-28 17:49:07,881 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3056, handle 0x738: C:\Windows\System32\Taskmgr.exe
2026-05-28 17:49:07,890 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3056 (handle 0x738): 0x00007FF714B10000.
2026-05-28 17:49:07,893 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2824, handle 0x738: C:\Windows\System32\SearchFilterHost.exe
2026-05-28 17:49:07,895 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2824 (handle 0x738): 0x00007FF7FAEB0000.
2026-05-28 17:49:08,220 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCFAD0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 17:49:08,220 [root] DEBUG: 3056: NtTerminateProcess hook: Attempting to dump process 3056
2026-05-28 17:49:08,226 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC9740000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-05-28 17:49:08,231 [root] DEBUG: 3056: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:49:08,468 [root] INFO: Process with pid 3056 has terminated
2026-05-28 17:49:08,602 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCE1B0000: C:\Windows\system32\dwmapi (0x2f000 bytes).
2026-05-28 17:49:08,671 [root] DEBUG: 8464: DLL loaded at 0x00007FFF7A4E0000: C:\Windows\system32\d3d9 (0x1cd000 bytes).
2026-05-28 17:49:08,727 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCE230000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-05-28 17:49:08,782 [root] DEBUG: 8464: DLL loaded at 0x00007FFFBA2F0000: C:\Windows\system32\D3D12Core (0x1cd000 bytes).
2026-05-28 17:49:08,803 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC8D20000: C:\Windows\system32\d3d10warp (0x6f6000 bytes).
2026-05-28 17:49:08,869 [root] DEBUG: 8464: DLL loaded at 0x00007FFFBBC60000: C:\Windows\system32\dxilconv (0x139000 bytes).
2026-05-28 17:49:08,905 [root] DEBUG: 8464: DLL loaded at 0x00007FFFBBB20000: C:\Windows\system32\D3DSCache (0x2a000 bytes).
2026-05-28 17:49:08,953 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC8D20000: C:\Windows\system32\d3d10warp (0x6f6000 bytes).
2026-05-28 17:49:08,990 [root] DEBUG: 8464: DLL loaded at 0x00007FFFD0430000: C:\Windows\system32\DEVOBJ (0x33000 bytes).
2026-05-28 17:49:09,033 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC8950000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-05-28 17:49:09,069 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 356, handle 0xaa8: C:\Windows\System32\smss.exe
2026-05-28 17:49:09,157 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC8930000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-05-28 17:49:09,183 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCFB20000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-05-28 17:49:09,345 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 528, handle 0xad0: C:\Windows\System32\wininit.exe
2026-05-28 17:49:09,357 [root] DEBUG: 8464: DLL loaded at 0x00007FFFCF870000: C:\Windows\system32\wkscli (0x19000 bytes).
2026-05-28 17:49:09,406 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 620, handle 0xae0: C:\Windows\System32\services.exe
2026-05-28 17:49:09,441 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 668, handle 0xad0: C:\Windows\System32\lsass.exe
2026-05-28 17:49:09,484 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 668 (handle 0x814): 0x00007FF64A9F0000.
2026-05-28 17:49:09,557 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 780, handle 0x814: C:\Windows\System32\fontdrvhost.exe
2026-05-28 17:49:09,613 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 892, handle 0x814: C:\Windows\System32\svchost.exe
2026-05-28 17:49:09,672 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 892 (handle 0x814): 0x00007FF69C310000.
2026-05-28 17:49:09,722 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 316, handle 0x814: C:\Windows\System32\dwm.exe
2026-05-28 17:49:09,755 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 316 (handle 0xa34): 0x00007FF6C5A00000.
2026-05-28 17:49:09,782 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 520, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:09,822 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 520 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:09,890 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1068, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:09,910 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1068 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:09,937 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1140, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:09,950 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1140 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:09,977 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1160, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,016 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1160 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,050 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1292, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,099 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1292 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,146 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1360, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,177 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1360 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,188 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1376, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,222 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1376 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,243 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1540, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,314 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1540 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,332 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1632, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,418 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1632 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,502 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1652, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,584 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1652 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,644 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1760, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,724 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1760 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,809 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1904, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,849 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1904 (handle 0xa34): 0x00007FF69C310000.
2026-05-28 17:49:10,891 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1956, handle 0xa34: C:\Windows\System32\svchost.exe
2026-05-28 17:49:10,930 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1956 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:11,008 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1996, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:11,048 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1996 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:11,077 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2104, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:11,126 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2104 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:11,180 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2236, handle 0xa74: C:\Windows\System32\spoolsv.exe
2026-05-28 17:49:11,250 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2236 (handle 0xad0): 0x00007FF6BC720000.
2026-05-28 17:49:11,286 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2372, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 17:49:11,393 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2372 (handle 0xad0): 0x00007FF69C310000.
2026-05-28 17:49:11,431 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2564, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 17:49:11,478 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2564 (handle 0xad0): 0x00007FF69C310000.
2026-05-28 17:49:11,540 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2640, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 17:49:11,581 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2640 (handle 0xad0): 0x00007FF69C310000.
2026-05-28 17:49:11,653 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2764, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 17:49:11,695 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2764 (handle 0xad0): 0x00007FF69C310000.
2026-05-28 17:49:11,735 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2784, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 17:49:11,787 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2784 (handle 0xad0): 0x00007FF69C310000.
2026-05-28 17:49:11,883 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2948, handle 0xad0: C:\Windows\System32\svchost.exe
2026-05-28 17:49:11,931 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2948 (handle 0xad0): 0x00007FF69C310000.
2026-05-28 17:49:11,975 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3604, handle 0xad0: C:\Windows\System32\SearchIndexer.exe
2026-05-28 17:49:11,985 [root] DEBUG: 4684: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 17:49:12,023 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3604 (handle 0xa74): 0x00007FF6AB580000.
2026-05-28 17:49:12,059 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3628, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:12,086 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3628 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:12,096 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2544, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:12,134 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2544 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:12,174 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4212, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:12,198 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4212 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:12,227 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4284, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:12,251 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4284 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:12,283 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4500, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:12,309 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4576, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:12,329 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4576 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:12,372 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4916, handle 0xa74: C:\Windows\System32\svchost.exe
2026-05-28 17:49:12,403 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4916 (handle 0xa74): 0x00007FF69C310000.
2026-05-28 17:49:12,438 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5308, handle 0xa74: C:\Windows\servicing\TrustedInstaller.exe
2026-05-28 17:49:12,465 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5308 (handle 0xa6c): 0x00007FF7918C0000.
2026-05-28 17:49:12,500 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5420, handle 0xa6c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:12,586 [root] INFO: Process with pid 10308 has terminated
2026-05-28 17:49:12,625 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5420 (handle 0xa6c): 0x00007FF69C310000.
2026-05-28 17:49:12,718 [root] DEBUG: 10308: NtTerminateProcess hook: Attempting to dump process 10308
2026-05-28 17:49:12,719 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5780, handle 0xa6c: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
2026-05-28 17:49:12,809 [root] DEBUG: 10308: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:49:12,829 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5780 (handle 0xa64): 0x00007FF64D970000.
2026-05-28 17:49:13,093 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3344, handle 0xa64: C:\Windows\System32\RuntimeBroker.exe
2026-05-28 17:49:13,140 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3344 (handle 0xa64): 0x00007FF6D97F0000.
2026-05-28 17:49:13,186 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6136, handle 0xa64: C:\Windows\System32\SecurityHealthSystray.exe
2026-05-28 17:49:13,204 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6136 (handle 0xa64): 0x00007FF67B3D0000.
2026-05-28 17:49:13,248 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6004, handle 0xa64: C:\Windows\System32\svchost.exe
2026-05-28 17:49:13,288 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6004 (handle 0xa64): 0x00007FF69C310000.
2026-05-28 17:49:13,323 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5068, handle 0xa64: C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
2026-05-28 17:49:13,370 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5068 (handle 0xa64): 0x00000000003D0000.
2026-05-28 17:49:13,417 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3964, handle 0xa64: C:\Windows\System32\svchost.exe
2026-05-28 17:49:13,494 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3964 (handle 0xa64): 0x00007FF69C310000.
2026-05-28 17:49:13,525 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6272, handle 0xa64: C:\Program Files (x86)\Steam\steam.exe
2026-05-28 17:49:13,545 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6272 (handle 0xa64): 0x00007FF74FDA0000.
2026-05-28 17:49:13,582 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6488, handle 0xa64: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:49:13,612 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6488 (handle 0xa64): 0x00007FF748BE0000.
2026-05-28 17:49:13,630 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6780, handle 0xa64: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:13,683 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6780 (handle 0xa64): 0x00007FF7660B0000.
2026-05-28 17:49:13,789 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7096, handle 0xa64: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:13,871 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7096 (handle 0xa64): 0x00007FF7660B0000.
2026-05-28 17:49:13,960 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7140, handle 0xa64: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:14,027 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7424, handle 0xa64: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:14,063 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7620, handle 0xa64: C:\Windows\System32\svchost.exe
2026-05-28 17:49:14,166 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7620 (handle 0xa64): 0x00007FF69C310000.
2026-05-28 17:49:14,237 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7760, handle 0xa64: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:49:14,314 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7760 (handle 0xa64): 0x00007FF684880000.
2026-05-28 17:49:14,423 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7812, handle 0xa64: C:\Users\admin\AppData\Local\Discord\app-1.0.9238\Discord.exe
2026-05-28 17:49:14,556 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7812 (handle 0xa64): 0x00007FF748BE0000.
2026-05-28 17:49:14,611 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 8180, handle 0xa64: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:49:14,689 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 8180 (handle 0xa64): 0x00007FF684880000.
2026-05-28 17:49:14,733 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 8676, handle 0xa64: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:49:14,828 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 8676 (handle 0xa64): 0x00007FF684880000.
2026-05-28 17:49:14,893 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 8356, handle 0xa64: C:\Windows\System32\svchost.exe
2026-05-28 17:49:14,953 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 8356 (handle 0xa64): 0x00007FF69C310000.
2026-05-28 17:49:15,028 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4828, handle 0xa64: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:49:15,083 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4828 (handle 0xa64): 0x00007FF684880000.
2026-05-28 17:49:15,091 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1588, handle 0xa64: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe
2026-05-28 17:49:15,177 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC81F0000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 17:49:15,223 [root] DEBUG: 8464: DLL loaded at 0x00007FFFC81F0000: C:\Windows\SYSTEM32\AppxDeploymentClient (0x102000 bytes).
2026-05-28 17:49:15,303 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1588 (handle 0xa5c): 0x00007FF6DB5C0000.
2026-05-28 17:49:15,563 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5360, handle 0xa50: C:\Windows\System32\notepad.exe
2026-05-28 17:49:15,621 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5360 (handle 0xa60): 0x00007FF6889E0000.
2026-05-28 17:49:15,676 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 640, handle 0xa60: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:15,719 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2848, handle 0xa60: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:15,783 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 4588, handle 0xa60: C:\Windows\System32\SearchProtocolHost.exe
2026-05-28 17:49:15,808 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 4588 (handle 0xa50): 0x00007FF719890000.
2026-05-28 17:49:15,880 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 10308, handle 0xa50: C:\Windows\System32\dllhost.exe
2026-05-28 17:49:20,283 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 14320, handle 0xa50: C:\Windows\System32\svchost.exe
2026-05-28 17:49:24,254 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 636, handle 0xa40: C:\Windows\System32\svchost.exe
2026-05-28 17:49:24,335 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 636 (handle 0xa40): 0x00007FF69C310000.
2026-05-28 17:49:25,187 [root] DEBUG: 788: CreateProcessHandler: Injection info set for new process 7428: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF67F380000
2026-05-28 17:49:25,281 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7440, handle 0xa0c: C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
2026-05-28 17:49:25,344 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7428
2026-05-28 17:49:25,432 [lib.api.process] INFO: Monitor config for process 7428: C:\va9o_glt\dll\7428.ini
2026-05-28 17:49:25,478 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7440 (handle 0xa40): 0x0000000000120000.
2026-05-28 17:49:25,537 [root] DEBUG: 788: CreateProcessHandler: Injection info set for new process 6216: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF6959E0000
2026-05-28 17:49:25,591 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:25,660 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7428, handle 0xa40: C:\Windows\System32\dllhost.exe
2026-05-28 17:49:25,662 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:25,707 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 6216
2026-05-28 17:49:25,746 [lib.api.process] INFO: Monitor config for process 6216: C:\va9o_glt\dll\6216.ini
2026-05-28 17:49:25,746 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 13648, handle 0xa40: C:\Windows\System32\wermgr.exe
2026-05-28 17:49:25,783 [root] DEBUG: Loader: Injecting process 7428 (thread 7472) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:25,825 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:25,893 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 13648 (handle 0xa44): 0x00007FF7512E0000.
2026-05-28 17:49:25,940 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:49:25,985 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 10720, handle 0xa44: C:\Windows\System32\taskhostw.exe
2026-05-28 17:49:26,032 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:26,114 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 10720 (handle 0xa44): 0x00007FF73DDE0000.
2026-05-28 17:49:26,146 [lib.api.process] INFO: Injected into 64-bit <Process 7428 dllhost.exe>
2026-05-28 17:49:26,265 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6216, handle 0xa0c: C:\Windows\System32\wbem\WmiPrvSE.exe
2026-05-28 17:49:26,267 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7428
2026-05-28 17:49:26,313 [lib.api.process] INFO: Monitor config for process 7428: C:\va9o_glt\dll\7428.ini
2026-05-28 17:49:26,321 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:26,344 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:26,343 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6216 (handle 0xa94): 0x00007FF6959E0000.
2026-05-28 17:49:26,495 [root] DEBUG: Loader: Injecting process 7428 (thread 7472) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:26,554 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:49:26,633 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:26,750 [lib.api.process] INFO: Injected into 64-bit <Process 7428 dllhost.exe>
2026-05-28 17:49:26,934 [root] DEBUG: 7428: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:49:27,013 [root] DEBUG: 7428: Interactive desktop enabled.
2026-05-28 17:49:27,041 [root] DEBUG: 7428: Dropped file limit defaulting to 100.
2026-05-28 17:49:27,098 [root] DEBUG: 7428: Disabling sleep skipping.
2026-05-28 17:49:27,118 [root] DEBUG: 7428: YaraInit: Compiled rules loaded from existing file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:49:27,187 [root] DEBUG: 7428: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:49:27,248 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7428 (handle 0xa94): 0x00007FF67F380000.
2026-05-28 17:49:27,286 [root] DEBUG: 7428: YaraScan: Scanning 0x00007FF67F380000, size 0x8026
2026-05-28 17:49:27,397 [root] DEBUG: 7428: Monitor initialised: 64-bit capemon loaded in process 7428 at 0x00007FFF742B0000, thread 7472, image base 0x00007FF67F380000, stack from 0x000000C0F7EF4000-0x000000C0F7F00000
2026-05-28 17:49:27,483 [root] DEBUG: 7428: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 17:49:27,562 [root] DEBUG: 7428: hook_api: LdrpCallInitRoutine export address 0x00007FFFD30499BC obtained via GetFunctionAddress
2026-05-28 17:49:27,659 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 17:49:27,736 [root] DEBUG: 7428: set_hooks: Unable to hook LockResource
2026-05-28 17:49:27,802 [root] DEBUG: 7428: Hooked 627 out of 628 functions
2026-05-28 17:49:27,871 [root] DEBUG: 7428: Syscall hook installed, syscall logging level 1
2026-05-28 17:49:27,967 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:27,967 [root] DEBUG: 7428: RestoreHeaders: Restored original import table.
2026-05-28 17:49:28,195 [root] INFO: Loaded monitor into process with pid 7428
2026-05-28 17:49:28,291 [root] DEBUG: Loader: Injecting process 6216 (thread 6232) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:28,353 [root] DEBUG: 7428: caller_dispatch: Added region at 0x00007FF67F380000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF67F381349, thread 7472).
2026-05-28 17:49:28,454 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 17:49:28,546 [root] DEBUG: 7428: YaraScan: Scanning 0x00007FF67F380000, size 0x8026
2026-05-28 17:49:28,608 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 7556, handle 0x14fc: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:28,712 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:28,777 [root] DEBUG: 7428: ProcessImageBase: Main module image at 0x00007FF67F380000 unmodified (entropy change 0.000000e+00)
2026-05-28 17:49:28,944 [lib.api.process] INFO: Injected into 64-bit <Process 6216 WmiPrvSE.exe>
2026-05-28 17:49:28,985 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7540, handle 0xa90: C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:29,085 [root] DEBUG: 4684: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 17:49:29,220 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCE5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:49:29,269 [root] INFO: Announced starting service "b'MicrosoftEdgeElevationService'"
2026-05-28 17:49:29,338 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7556, handle 0xa90: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:29,396 [lib.api.process] INFO: Monitor config for process 620: C:\va9o_glt\dll\620.ini
2026-05-28 17:49:29,449 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 2672, handle 0x14fc: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:29,491 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBA2B0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 17:49:29,539 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7556 (handle 0xa90): 0x00007FF7660B0000.
2026-05-28 17:49:29,582 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:29,630 [root] DEBUG: 7428: DLL loaded at 0x00007FFFD0710000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:49:29,748 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBA2B0000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 17:49:29,749 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:29,861 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2672, handle 0xa88: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:29,962 [root] DEBUG: 7428: DLL loaded at 0x00007FFFD2C30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:49:30,024 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC1F90000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 17:49:30,088 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2672 (handle 0xa88): 0x00007FF7660B0000.
2026-05-28 17:49:30,172 [root] DEBUG: Loader: Injecting process 620 with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:30,240 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 904, handle 0xa88: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:30,297 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC1F90000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 17:49:30,324 [root] DEBUG: Loader: Copied config file C:\va9o_glt\dll\620.ini to system path C:\620.ini
2026-05-28 17:49:30,396 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 904 (handle 0xa88): 0x00007FF7660B0000.
2026-05-28 17:49:30,505 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC0790000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 17:49:30,568 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCE0D0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 17:49:30,617 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 620 C:\va9o_glt\dll\nNyvMSQ.dll
2026-05-28 17:49:30,671 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 3824, handle 0xa88: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:30,725 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:30,786 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC0790000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 17:49:30,923 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 3824 (handle 0xa88): 0x00007FF7660B0000.
2026-05-28 17:49:30,946 [lib.api.process] INFO: Injected into 64-bit <Process 620 services.exe>
2026-05-28 17:49:30,952 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCFBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 17:49:31,009 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 7804, handle 0xa88: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:31,088 [root] DEBUG: 4684: DLL loaded at 0x00007FFF95F70000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 17:49:31,118 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCFB10000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 17:49:31,186 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 7804 (handle 0xa88): 0x00007FF7660B0000.
2026-05-28 17:49:31,269 [root] DEBUG: 7428: DLL loaded at 0x00007FFFC8930000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 17:49:31,336 [root] DEBUG: 4684: DLL loaded at 0x00007FFF95F70000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 17:49:31,381 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCB220000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 17:49:31,415 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 14552, handle 0xa88: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:31,417 [root] DEBUG: 4684: DLL loaded at 0x00007FFFCE410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 17:49:31,483 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCF830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 17:49:31,520 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 14552 (handle 0xa88): 0x00007FF7660B0000.
2026-05-28 17:49:31,571 [root] DEBUG: 4684: DLL loaded at 0x00007FFFCE410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 17:49:31,578 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 14604, handle 0xa88: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:31,581 [root] DEBUG: 7428: DLL loaded at 0x00007FFFD1280000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 17:49:31,629 [root] DEBUG: 4684: DLL loaded at 0x00007FFF95BA0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 17:49:31,637 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 6216
2026-05-28 17:49:31,678 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 14604 (handle 0xa88): 0x00007FF7660B0000.
2026-05-28 17:49:31,749 [lib.api.process] INFO: Monitor config for process 6216: C:\va9o_glt\dll\6216.ini
2026-05-28 17:49:31,749 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCFAD0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 17:49:31,881 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:31,884 [root] DEBUG: 4684: DLL loaded at 0x00007FFF95BA0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 17:49:31,958 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 14684, handle 0xa88: C:\va9o_glt\bin\PPLinject64.exe
2026-05-28 17:49:32,029 [root] DEBUG: 7428: DLL loaded at 0x00007FFFD0600000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 17:49:32,099 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBBAD0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 17:49:32,157 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:32,205 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 14684 (handle 0xa80): 0x00007FF7D4C70000.
2026-05-28 17:49:32,260 [root] DEBUG: 7428: DLL loaded at 0x00007FFFD0640000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 17:49:32,263 [root] DEBUG: Loader: Injecting process 6216 (thread 6232) with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:32,301 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 14692, handle 0xa80: C:\Windows\System32\conhost.exe
2026-05-28 17:49:32,344 [root] DEBUG: 4684: DLL loaded at 0x00007FFFBBAD0000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 17:49:32,407 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 17:49:32,476 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 14692 (handle 0xa80): 0x00007FF7DA4A0000.
2026-05-28 17:49:32,522 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCC600000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 17:49:32,689 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:32,754 [root] DEBUG: 7428: DLL loaded at 0x00007FFFCFB20000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 17:49:32,855 [lib.api.process] INFO: Injected into 64-bit <Process 6216 WmiPrvSE.exe>
2026-05-28 17:49:32,855 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 14872, handle 0xa90: C:\Windows\System32\svchost.exe
2026-05-28 17:49:32,900 [root] DEBUG: 7428: DLL loaded at 0x00007FFF95B10000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 17:49:32,946 [root] DEBUG: 6216: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:49:33,016 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 14872 (handle 0xa28): 0x00007FF69C310000.
2026-05-28 17:49:33,079 [root] DEBUG: 6216: Interactive desktop enabled.
2026-05-28 17:49:33,130 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC07B0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 17:49:33,199 [root] DEBUG: 6216: Dropped file limit defaulting to 100.
2026-05-28 17:49:33,255 [root] DEBUG: 4684: DLL loaded at 0x00007FFFC07B0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 17:49:33,319 [root] DEBUG: 7428: DLL loaded at 0x00007FFFD2D90000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 17:49:33,412 [root] DEBUG: 6216: Disabling sleep skipping.
2026-05-28 17:49:33,477 [root] DEBUG: 7428: DLL loaded at 0x00007FFFC1C80000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 17:49:33,538 [root] DEBUG: 6216: Services hook set enabled
2026-05-28 17:49:33,694 [root] DEBUG: 6216: YaraInit: Compiled rules loaded from existing file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:49:33,818 [root] DEBUG: 6216: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:49:33,979 [root] DEBUG: 6216: Monitor initialised: 64-bit capemon loaded in process 6216 at 0x00007FFF742B0000, thread 6232, image base 0x00007FF6959E0000, stack from 0x0000002273DD0000-0x0000002273DE0000
2026-05-28 17:49:34,131 [root] DEBUG: 6216: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 17:49:34,305 [root] DEBUG: 6216: Hooked 69 out of 69 functions
2026-05-28 17:49:34,412 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 15080, handle 0xa44: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\elevation_service.exe
2026-05-28 17:49:34,525 [root] DEBUG: 6216: RestoreHeaders: Restored original import table.
2026-05-28 17:49:34,629 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 15080 (handle 0xa0c): 0x00007FF6CA2C0000.
2026-05-28 17:49:34,735 [root] INFO: Loaded monitor into process with pid 6216
2026-05-28 17:49:34,794 [root] DEBUG: 6216: DLL loaded at 0x00007FFFCE5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 17:49:35,002 [root] DEBUG: 6216: DLL loaded at 0x00007FFFD0710000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 17:49:35,207 [root] DEBUG: 6216: DLL loaded at 0x00007FFFD2C30000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 17:49:35,354 [lib.api.process] INFO: Monitor config for process 5960: C:\va9o_glt\dll\5960.ini
2026-05-28 17:49:35,456 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 17:49:35,522 [lib.api.process] INFO: 64-bit DLL to inject is C:\va9o_glt\dll\nNyvMSQ.dll, loader C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:35,770 [root] DEBUG: Loader: Injecting process 5960 with C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:35,916 [root] DEBUG: 5960: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 17:49:36,011 [root] DEBUG: 5960: Disabling sleep skipping.
2026-05-28 17:49:36,116 [root] DEBUG: 5960: Interactive desktop enabled.
2026-05-28 17:49:36,254 [root] DEBUG: 5960: Dropped file limit defaulting to 100.
2026-05-28 17:49:36,270 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 15172, handle 0xa3c: C:\va9o_glt\bin\XBXPkqwc.exe
2026-05-28 17:49:36,314 [root] DEBUG: 5960: Services hook set enabled
2026-05-28 17:49:36,364 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 15172 (handle 0xa40): 0x00007FF76E800000.
2026-05-28 17:49:36,440 [root] DEBUG: 5960: YaraInit: Compiled rules loaded from existing file C:\va9o_glt\data\yara\capemon.yac
2026-05-28 17:49:36,528 [root] DEBUG: 5960: RtlInsertInvertedFunctionTable 0x00007FFFD304090E, LdrpInvertedFunctionTableSRWLock 0x00007FFFD319D4F0
2026-05-28 17:49:36,598 [root] DEBUG: 5960: Monitor initialised: 64-bit capemon loaded in process 5960 at 0x00007FFF742B0000, thread 15192, image base 0x00007FF69C310000, stack from 0x00000036521F4000-0x0000003652200000
2026-05-28 17:49:36,708 [root] DEBUG: 5960: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 17:49:36,786 [root] DEBUG: 5960: Hooked 69 out of 69 functions
2026-05-28 17:49:36,880 [root] INFO: Loaded monitor into process with pid 5960
2026-05-28 17:49:36,931 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 17:49:37,006 [root] DEBUG: Successfully injected DLL C:\va9o_glt\dll\nNyvMSQ.dll.
2026-05-28 17:49:37,115 [lib.api.process] INFO: Injected into 64-bit <Process 5960 svchost.exe>
2026-05-28 17:49:38,748 [root] INFO: Process with pid 7428 has terminated
2026-05-28 17:49:38,967 [root] DEBUG: 7428: NtTerminateProcess hook: Attempting to dump process 7428
2026-05-28 17:49:39,149 [root] DEBUG: 7428: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 17:49:39,320 [root] DEBUG: 6216: DLL loaded at 0x00007FFFBC3A0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 17:49:39,578 [root] DEBUG: 6216: DLL loaded at 0x00007FFFBBAB0000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 17:49:40,606 [root] DEBUG: 6216: DLL loaded at 0x00007FFFBBCF0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 17:49:41,659 [root] DEBUG: 6216: DLL loaded at 0x00007FFFD04C0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 17:49:41,827 [root] DEBUG: 6216: DLL loaded at 0x00007FFF95F70000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 17:49:41,881 [root] DEBUG: 4684: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-05-28 17:49:41,942 [root] DEBUG: 6216: DLL loaded at 0x00007FFFB7780000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 17:49:42,095 [root] DEBUG: 6216: DLL loaded at 0x00007FFFD04A0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 17:49:42,618 [root] DEBUG: 6216: DLL loaded at 0x00000185EAE40000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 17:49:42,761 [root] DEBUG: 6216: DLL loaded at 0x00007FFFCB610000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 17:49:42,853 [root] DEBUG: 6216: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 17:49:43,391 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 1500, handle 0xa7c: C:\Windows\System32\svchost.exe
2026-05-28 17:49:43,595 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 1500 (handle 0xa7c): 0x00007FF69C310000.
2026-05-28 17:49:46,281 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 6832, handle 0xa40: C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe
2026-05-28 17:49:46,483 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 6832 (handle 0xa40): 0x00007FF684880000.
2026-05-28 17:49:46,680 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2284, handle 0xa40: C:\Windows\System32\SgrmBroker.exe
2026-05-28 17:49:47,334 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5196, handle 0x7a0: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 17:49:47,531 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5196 (handle 0xa40): 0x00007FF6EB090000.
2026-05-28 17:49:48,372 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 2244, handle 0xa7c: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 17:49:48,573 [root] DEBUG: 4684: OpenProcessHandler: Injection info created for process 2244, handle 0x2fac: C:\Program Files (x86)\Microsoft\Edge\Application\148.0.3967.83\identity_helper.exe
2026-05-28 17:49:48,637 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 2244 (handle 0xa7c): 0x00007FF6EB090000.
2026-05-28 17:49:59,359 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5252, handle 0xa3c: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:49:59,493 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5252 (handle 0xa3c): 0x00007FF7660B0000.
2026-05-28 17:50:01,040 [root] DEBUG: 4684: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 17:50:09,946 [root] DEBUG: 4684: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 17:50:10,851 [root] DEBUG: 4684: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 17:50:11,258 [root] DEBUG: 4684: api-cap: NtReadFile hook disabled due to count: 5000
2026-05-28 17:50:21,344 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 14752, handle 0x7d4: C:\Windows\System32\sppsvc.exe
2026-05-28 17:50:24,836 [root] DEBUG: 4684: api-cap: NtSetInformationFile hook disabled due to count: 5000
2026-05-28 17:50:28,321 [root] DEBUG: 8464: OpenProcessHandler: Injection info created for process 5660, handle 0x6d8: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
2026-05-28 17:50:28,452 [root] DEBUG: 8464: OpenProcessHandler: Image base for process 5660 (handle 0x6d8): 0x00007FF7660B0000.
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 17:48:21 | 2026-05-28 17:50:41 | none |
Seek in progress...
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.