| Category | Package | Started | Completed | Duration | Logs |
|---|---|---|---|---|---|
| FILE | generic | 2026-06-28 23:08:35 | 2026-06-28 23:09:29 | 54s |
|
2026-06-28 14:55:58,665 [root] INFO: Date set to: 20260628T23:08:42, timeout set to: 15 2026-06-28 23:08:42,539 [root] DEBUG: Starting analyzer from: C:\7d7wfxi0 2026-06-28 23:08:42,540 [root] DEBUG: Storing results at: C:\SZitfqj 2026-06-28 23:08:42,541 [root] DEBUG: Pipe server name: \\.\PIPE\VqluDZZAmn 2026-06-28 23:08:42,541 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314 2026-06-28 23:08:42,542 [root] INFO: analysis running as an admin 2026-06-28 23:08:42,542 [root] DEBUG: no analysis package configured, picking one for you 2026-06-28 23:08:45,101 [root] INFO: analysis package selected: "generic" 2026-06-28 23:08:45,102 [root] DEBUG: importing analysis package module: "modules.packages.generic"... 2026-06-28 23:08:45,107 [root] DEBUG: imported analysis package "generic" 2026-06-28 23:08:45,107 [root] DEBUG: initializing analysis package "generic"... 2026-06-28 23:08:45,108 [lib.common.common] INFO: no wrapping 2026-06-28 23:08:45,108 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-28 23:08:45,109 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\comany logo 2017.bmp 2026-06-28 23:08:45,109 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll option 2026-06-28 23:08:45,110 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll_64 option 2026-06-28 23:08:45,110 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader option 2026-06-28 23:08:45,110 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader_64 option 2026-06-28 23:08:45,137 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2026-06-28 23:08:45,144 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2026-06-28 23:08:45,218 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2026-06-28 23:08:45,277 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2026-06-28 23:08:45,286 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-06-28 23:08:45,287 [lib.api.screenshot] ERROR: No module named 'PIL' 2026-06-28 23:08:45,288 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots" 2026-06-28 23:08:45,291 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2026-06-28 23:08:45,291 [root] DEBUG: Initialized auxiliary module "Browser" 2026-06-28 23:08:45,292 [root] DEBUG: attempting to configure 'Browser' from data 2026-06-28 23:08:45,293 [root] DEBUG: module Browser does not support data configuration, ignoring 2026-06-28 23:08:45,294 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2026-06-28 23:08:45,301 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2026-06-28 23:08:45,301 [root] DEBUG: Initialized auxiliary module "DigiSig" 2026-06-28 23:08:45,302 [root] DEBUG: attempting to configure 'DigiSig' from data 2026-06-28 23:08:45,302 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2026-06-28 23:08:45,303 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2026-06-28 23:08:45,303 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature 2026-06-28 23:08:45,875 [modules.auxiliary.digisig] DEBUG: File has an invalid signature 2026-06-28 23:08:45,877 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json 2026-06-28 23:08:45,880 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2026-06-28 23:08:45,882 [root] DEBUG: Initialized auxiliary module "Disguise" 2026-06-28 23:08:45,883 [root] DEBUG: attempting to configure 'Disguise' from data 2026-06-28 23:08:45,884 [root] DEBUG: module Disguise does not support data configuration, ignoring 2026-06-28 23:08:45,884 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2026-06-28 23:08:45,903 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 4468) 2026-06-28 23:08:45,913 [modules.auxiliary.disguise] INFO: Disguising GUID to 1a1c3eed-927b-46ed-96f8-95fcd45ef564 2026-06-28 23:08:45,914 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2026-06-28 23:08:45,915 [root] DEBUG: Initialized auxiliary module "Human" 2026-06-28 23:08:45,915 [root] DEBUG: attempting to configure 'Human' from data 2026-06-28 23:08:45,916 [root] DEBUG: module Human does not support data configuration, ignoring 2026-06-28 23:08:45,916 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2026-06-28 23:08:45,922 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2026-06-28 23:08:45,923 [root] DEBUG: Initialized auxiliary module "Screenshots" 2026-06-28 23:08:45,923 [root] DEBUG: attempting to configure 'Screenshots' from data 2026-06-28 23:08:45,924 [root] DEBUG: module Screenshots does not support data configuration, ignoring 2026-06-28 23:08:45,924 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"... 2026-06-28 23:08:45,935 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2026-06-28 23:08:45,935 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots 2026-06-28 23:08:45,936 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2026-06-28 23:08:45,936 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2026-06-28 23:08:45,936 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2026-06-28 23:08:45,936 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2026-06-28 23:08:45,939 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process 2026-06-28 23:08:45,939 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2026-06-28 23:08:51,893 [root] INFO: Restarting WMI Service 2026-06-28 23:08:54,150 [root] DEBUG: package modules.packages.generic does not support configure, ignoring 2026-06-28 23:08:54,151 [root] WARNING: configuration error for package modules.packages.generic: error importing data.packages.generic: No module named 'data.packages' 2026-06-28 23:08:54,152 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-28 23:08:54,154 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\comany logo 2017.bmp"" with pid 2924 2026-06-28 23:08:54,455 [lib.api.process] INFO: Monitor config for process 2924: C:\7d7wfxi0\dll\2924.ini 2026-06-28 23:08:54,471 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\uMqhHKoF.dll, loader C:\7d7wfxi0\bin\AAydvAme.exe 2026-06-28 23:08:54,493 [root] DEBUG: Loader: Injecting process 2924 (thread 4768) with C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:08:54,495 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-28 23:08:54,496 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:08:54,499 [lib.api.process] INFO: Injected into 64-bit <Process 2924 cmd.exe> 2026-06-28 23:08:56,524 [lib.api.process] INFO: Successfully resumed process with pid 2924 2026-06-28 23:08:56,716 [root] DEBUG: 2924: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-28 23:08:56,717 [root] DEBUG: 2924: Disabling sleep skipping. 2026-06-28 23:08:56,718 [root] DEBUG: 2924: Dropped file limit defaulting to 100. 2026-06-28 23:08:56,759 [root] DEBUG: 2924: YaraInit: Compiled 44 rule files 2026-06-28 23:08:56,765 [root] DEBUG: 2924: YaraInit: Compiled rules saved to file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-28 23:08:56,831 [root] DEBUG: 2924: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-28 23:08:56,835 [root] DEBUG: 2924: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-28 23:08:56,840 [root] DEBUG: 2924: YaraScan hit: FindFixAndRun 2026-06-28 23:08:56,841 [root] DEBUG: 2924: Monitor initialised: 64-bit capemon loaded in process 2924 at 0x00007FF9863A0000, thread 4768, image base 0x00007FF79A450000, stack from 0x00000090D8E04000-0x00000090D8F00000 2026-06-28 23:08:56,842 [root] DEBUG: 2924: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\comany logo 2017.bmp" 2026-06-28 23:08:56,859 [root] DEBUG: 2924: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-28 23:08:56,936 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-28 23:08:56,937 [root] DEBUG: 2924: set_hooks: Unable to hook LockResource 2026-06-28 23:08:56,952 [root] DEBUG: 2924: Hooked 630 out of 631 functions 2026-06-28 23:08:56,957 [root] DEBUG: 2924: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620 2026-06-28 23:08:56,960 [root] DEBUG: 2924: Syscall hook installed, syscall logging level 1 2026-06-28 23:08:56,979 [root] DEBUG: 2924: RestoreHeaders: Restored original import table. 2026-06-28 23:08:56,981 [root] INFO: Loaded monitor into process with pid 2924 2026-06-28 23:08:56,985 [root] DEBUG: 2924: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 4768). 2026-06-28 23:08:56,986 [root] DEBUG: 2924: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-28 23:08:56,995 [root] DEBUG: 2924: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00) 2026-06-28 23:08:57,017 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-28 23:08:57,020 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-28 23:08:57,026 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-28 23:08:57,041 [root] DEBUG: 2924: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes). 2026-06-28 23:08:57,046 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes). 2026-06-28 23:08:57,050 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-28 23:08:57,062 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes). 2026-06-28 23:08:57,068 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes). 2026-06-28 23:08:57,079 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-28 23:08:57,111 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-28 23:08:57,247 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-28 23:08:57,258 [root] DEBUG: 2924: DLL loaded at 0x00007FF993730000: C:\Windows\system32\edputil (0x24000 bytes). 2026-06-28 23:08:57,298 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-28 23:08:57,311 [root] DEBUG: 2924: DLL loaded at 0x00007FF9903B0000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes). 2026-06-28 23:08:57,452 [root] DEBUG: 2924: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes). 2026-06-28 23:08:57,453 [root] DEBUG: 2924: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes). 2026-06-28 23:08:57,455 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes). 2026-06-28 23:08:57,458 [root] DEBUG: 2924: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes). 2026-06-28 23:08:57,468 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A7200000: C:\Windows\system32\msvcp110_win (0x8a000 bytes). 2026-06-28 23:08:57,469 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes). 2026-06-28 23:08:57,569 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\System32\wintypes (0x154000 bytes). 2026-06-28 23:08:57,577 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A5A30000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes). 2026-06-28 23:08:57,586 [root] DEBUG: 2924: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes). 2026-06-28 23:08:57,589 [root] DEBUG: 2924: DLL loaded at 0x00007FF998E30000: C:\Windows\system32\PhotoMetadataHandler (0x81000 bytes). 2026-06-28 23:08:57,652 [root] DEBUG: 2924: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes). 2026-06-28 23:08:57,653 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A6C60000: C:\Windows\System32\sppc (0x25000 bytes). 2026-06-28 23:08:57,659 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A6C90000: C:\Windows\System32\SLC (0x29000 bytes). 2026-06-28 23:08:57,660 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A7F80000: C:\Windows\System32\USERENV (0x2e000 bytes). 2026-06-28 23:08:57,662 [root] DEBUG: 2924: DLL loaded at 0x00007FF9971F0000: C:\Windows\System32\appresolver (0x90000 bytes). 2026-06-28 23:08:57,680 [root] DEBUG: 2924: DLL loaded at 0x00007FF99D480000: C:\Windows\System32\OneCoreCommonProxyStub (0x7d000 bytes). 2026-06-28 23:08:57,700 [root] DEBUG: 2924: DLL loaded at 0x00007FF99EEA0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x798000 bytes). 2026-06-28 23:08:57,725 [lib.api.process] INFO: Monitor config for process 756: C:\7d7wfxi0\dll\756.ini 2026-06-28 23:08:57,730 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\uMqhHKoF.dll, loader C:\7d7wfxi0\bin\AAydvAme.exe 2026-06-28 23:08:57,746 [root] DEBUG: Loader: Injecting process 756 with C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:08:57,752 [root] DEBUG: 756: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-28 23:08:57,753 [root] DEBUG: 756: Disabling sleep skipping. 2026-06-28 23:08:57,754 [root] DEBUG: 756: Dropped file limit defaulting to 100. 2026-06-28 23:08:57,758 [root] DEBUG: 756: Services hook set enabled 2026-06-28 23:08:57,761 [root] DEBUG: 756: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-28 23:08:57,782 [root] DEBUG: 756: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-28 23:08:57,783 [root] DEBUG: 756: Monitor initialised: 64-bit capemon loaded in process 756 at 0x00007FF9863A0000, thread 404, image base 0x00007FF69D480000, stack from 0x00000036AC3F4000-0x00000036AC400000 2026-06-28 23:08:57,785 [root] DEBUG: 756: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p 2026-06-28 23:08:57,808 [root] DEBUG: 756: Hooked 69 out of 69 functions 2026-06-28 23:08:57,809 [root] INFO: Loaded monitor into process with pid 756 2026-06-28 23:08:57,811 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-06-28 23:08:57,812 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:08:57,816 [lib.api.process] INFO: Injected into 64-bit <Process 756 svchost.exe> 2026-06-28 23:08:59,826 [root] DEBUG: 2924: CreateProcessHandler: Injection info set for new process 2420: C:\Windows\system32\mspaint.exe, ImageBase: 0x00007FF700FE0000 2026-06-28 23:08:59,828 [root] INFO: Announced 64-bit process name: mspaint.exe pid: 2420 2026-06-28 23:08:59,828 [lib.api.process] INFO: Monitor config for process 2420: C:\7d7wfxi0\dll\2420.ini 2026-06-28 23:08:59,833 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\uMqhHKoF.dll, loader C:\7d7wfxi0\bin\AAydvAme.exe 2026-06-28 23:08:59,848 [root] DEBUG: Loader: Injecting process 2420 (thread 556) with C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:08:59,851 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-28 23:08:59,852 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:08:59,855 [lib.api.process] INFO: Injected into 64-bit <Process 2420 mspaint.exe> 2026-06-28 23:08:59,862 [root] INFO: Announced 64-bit process name: mspaint.exe pid: 2420 2026-06-28 23:08:59,863 [lib.api.process] INFO: Monitor config for process 2420: C:\7d7wfxi0\dll\2420.ini 2026-06-28 23:08:59,865 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\uMqhHKoF.dll, loader C:\7d7wfxi0\bin\AAydvAme.exe 2026-06-28 23:08:59,875 [root] DEBUG: Loader: Injecting process 2420 (thread 556) with C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:08:59,876 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-28 23:08:59,877 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:08:59,880 [lib.api.process] INFO: Injected into 64-bit <Process 2420 mspaint.exe> 2026-06-28 23:08:59,884 [root] DEBUG: 2924: DLL loaded at 0x00007FF998030000: C:\Windows\system32\MPR (0x1d000 bytes). 2026-06-28 23:08:59,885 [root] DEBUG: 2924: DLL loaded at 0x00007FF9A31D0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes). 2026-06-28 23:08:59,961 [root] DEBUG: 2420: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-28 23:08:59,962 [root] DEBUG: 2420: Dropped file limit defaulting to 100. 2026-06-28 23:08:59,971 [root] DEBUG: 2420: Disabling sleep skipping. 2026-06-28 23:08:59,973 [root] DEBUG: 2420: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-28 23:08:59,993 [root] DEBUG: 2420: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-28 23:08:59,994 [root] DEBUG: 2420: YaraScan: Scanning 0x00007FF700FE0000, size 0xf8baa 2026-06-28 23:09:00,005 [root] DEBUG: 2420: Monitor initialised: 64-bit capemon loaded in process 2420 at 0x00007FF9863A0000, thread 556, image base 0x00007FF700FE0000, stack from 0x0000001D07F44000-0x0000001D07F50000 2026-06-28 23:09:00,006 [root] DEBUG: 2420: Commandline: "C:\Windows\system32\mspaint.exe" "C:\Users\Rajesh\AppData\Local\Temp\comany logo 2017.bmp" 2026-06-28 23:09:00,021 [root] DEBUG: 2420: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-28 23:09:00,074 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-28 23:09:00,075 [root] DEBUG: 2420: set_hooks: Unable to hook LockResource 2026-06-28 23:09:00,090 [root] DEBUG: 2420: Hooked 630 out of 631 functions 2026-06-28 23:09:00,101 [root] DEBUG: 2420: Syscall hook installed, syscall logging level 1 2026-06-28 23:09:00,114 [root] DEBUG: 2420: RestoreHeaders: Restored original import table. 2026-06-28 23:09:00,116 [root] INFO: Loaded monitor into process with pid 2420 2026-06-28 23:09:00,122 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-28 23:09:00,137 [root] DEBUG: 2420: DLL loaded at 0x00007FF99DDA0000: C:\Windows\SYSTEM32\ninput (0x6a000 bytes). 2026-06-28 23:09:00,139 [root] DEBUG: 2420: caller_dispatch: Added region at 0x00007FF700FE0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF70107F9B1, thread 556). 2026-06-28 23:09:00,141 [root] DEBUG: 2420: YaraScan: Scanning 0x00007FF700FE0000, size 0xf8baa 2026-06-28 23:09:00,158 [root] DEBUG: 2420: ProcessImageBase: Main module image at 0x00007FF700FE0000 unmodified (entropy change 0.000000e+00) 2026-06-28 23:09:00,167 [root] DEBUG: 2420: DLL loaded at 0x00007FF990180000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1288_none_91a663c8cc864906\gdiplus (0x1a9000 bytes). 2026-06-28 23:09:00,230 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-28 23:09:00,244 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes). 2026-06-28 23:09:00,301 [root] DEBUG: 2420: DLL loaded at 0x00007FF98DE00000: C:\Windows\system32\MSFTEDIT (0x348000 bytes). 2026-06-28 23:09:00,311 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-28 23:09:00,394 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-28 23:09:00,401 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A2820000: C:\Windows\system32\XmlLite (0x36000 bytes). 2026-06-28 23:09:00,406 [root] DEBUG: 2420: DLL loaded at 0x00007FF985FB0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes). 2026-06-28 23:09:00,415 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-28 23:09:00,417 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A6230000: C:\Windows\system32\windows.storage (0x790000 bytes). 2026-06-28 23:09:00,425 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes). 2026-06-28 23:09:00,426 [root] DEBUG: 2420: DLL loaded at 0x00007FF987C00000: C:\Windows\System32\efswrt (0xde000 bytes). 2026-06-28 23:09:00,432 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A10F0000: C:\Windows\System32\twinapi.appcore (0x201000 bytes). 2026-06-28 23:09:00,565 [root] INFO: Announced starting service "b'stisvc'" 2026-06-28 23:09:00,566 [lib.api.process] INFO: Monitor config for process 632: C:\7d7wfxi0\dll\632.ini 2026-06-28 23:09:00,571 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\uMqhHKoF.dll, loader C:\7d7wfxi0\bin\AAydvAme.exe 2026-06-28 23:09:00,581 [root] DEBUG: Loader: Injecting process 632 with C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:09:00,587 [root] DEBUG: Loader: Copied config file C:\7d7wfxi0\dll\632.ini to system path C:\632.ini 2026-06-28 23:09:00,593 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 632 C:\7d7wfxi0\dll\uMqhHKoF.dll 2026-06-28 23:09:00,594 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\uMqhHKoF.dll. 2026-06-28 23:09:00,597 [lib.api.process] INFO: Injected into 64-bit <Process 632 services.exe> 2026-06-28 23:09:03,678 [root] DEBUG: 2420: DLL loaded at 0x00007FF99DFF0000: C:\Windows\System32\sti (0x53000 bytes). 2026-06-28 23:09:03,681 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A4220000: C:\Windows\SYSTEM32\wiatrace (0xa000 bytes). 2026-06-28 23:09:03,808 [root] DEBUG: 2420: DLL loaded at 0x00007FF995FC0000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes). 2026-06-28 23:09:03,855 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A5F20000: C:\Windows\system32\dwmapi (0x2f000 bytes). 2026-06-28 23:09:03,900 [root] DEBUG: 2420: DLL loaded at 0x00007FF994E80000: C:\Windows\System32\msxml6 (0x25f000 bytes). 2026-06-28 23:09:03,924 [root] DEBUG: 2420: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\windowscodecs (0x1b4000 bytes). 2026-06-28 23:09:04,168 [root] DEBUG: 2420: DLL loaded at 0x00007FF998F00000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes). 2026-06-28 23:09:04,281 [root] DEBUG: 2420: DLL loaded at 0x00007FF992900000: C:\Windows\System32\oleacc (0x66000 bytes). 2026-06-28 23:09:04,347 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-28 23:09:04,420 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-28 23:09:04,951 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-28 23:09:04,965 [root] DEBUG: 2420: DLL loaded at 0x00007FF998E30000: C:\Windows\system32\PhotoMetadataHandler (0x81000 bytes). 2026-06-28 23:09:05,229 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A6E00000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-06-28 23:09:05,231 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A57F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-06-28 23:09:05,236 [root] DEBUG: 2420: DLL loaded at 0x00007FF9A5490000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes). 2026-06-28 23:09:05,239 [root] DEBUG: 2420: DLL loaded at 0x00007FF99BC00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-06-28 23:09:05,602 [root] DEBUG: 2420: DLL loaded at 0x00007FF9AA490000: C:\Windows\System32\coml2 (0x79000 bytes). 2026-06-28 23:09:11,767 [root] INFO: Analysis timeout hit, terminating analysis 2026-06-28 23:09:11,769 [lib.api.process] INFO: Terminate event set for process 2924 2026-06-28 23:09:11,770 [root] DEBUG: 2924: Terminate Event: Attempting to dump process 2924 2026-06-28 23:09:11,771 [root] DEBUG: 2924: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching 2026-06-28 23:09:11,772 [root] DEBUG: 2924: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000. 2026-06-28 23:09:11,774 [root] DEBUG: 2924: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2026-06-28 23:09:11,775 [root] DEBUG: 2924: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000. 2026-06-28 23:09:11,776 [root] DEBUG: 2924: DumpProcess: Module entry point VA is 0x00007FF79A468F50. 2026-06-28 23:09:11,793 [lib.common.results] INFO: Uploading file C:\SZitfqj\CAPE\2924_32103119629162026 to procdump\97e4a5577948facb96f82247470bd9e2d744048cb2ddf277e6f377df4bd53b79; Size is 401920; Max size: 100000000 2026-06-28 23:09:11,829 [root] DEBUG: 2924: DumpProcess: Module image dump success - dump size 0x62200. 2026-06-28 23:09:11,843 [root] DEBUG: 2924: Terminate Event: Shutdown complete for process 2924 but failed to inform analyzer. 2026-06-28 23:09:16,782 [lib.api.process] INFO: Termination confirmed for process 2924 2026-06-28 23:09:16,783 [root] INFO: Terminate event set for process 2924 2026-06-28 23:09:16,784 [lib.api.process] INFO: Terminate event set for process 756 2026-06-28 23:09:16,785 [root] DEBUG: 756: Terminate Event: Attempting to dump process 756 2026-06-28 23:09:16,786 [root] DEBUG: 756: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-28 23:09:16,791 [lib.api.process] INFO: Termination confirmed for process 756 2026-06-28 23:09:16,791 [root] INFO: Terminate event set for process 756 2026-06-28 23:09:16,792 [root] DEBUG: 756: Terminate Event: monitor shutdown complete for process 756 2026-06-28 23:09:16,792 [lib.api.process] INFO: Terminate event set for process 2420 2026-06-28 23:09:16,794 [root] DEBUG: 2420: Terminate Event: Attempting to dump process 2420 2026-06-28 23:09:16,798 [root] DEBUG: 2420: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-28 23:09:16,821 [root] DEBUG: 2420: Terminate Event: Shutdown complete for process 2420 but failed to inform analyzer. 2026-06-28 23:09:21,800 [lib.api.process] INFO: Termination confirmed for process 2420 2026-06-28 23:09:21,801 [root] INFO: Terminate event set for process 2420 2026-06-28 23:09:21,802 [root] INFO: Created shutdown mutex 2026-06-28 23:09:22,816 [root] INFO: Shutting down package 2026-06-28 23:09:22,817 [root] INFO: Stopping auxiliary modules 2026-06-28 23:09:22,817 [root] INFO: Stopping auxiliary module: Browser 2026-06-28 23:09:22,818 [root] INFO: Stopping auxiliary module: Human 2026-06-28 23:09:23,223 [root] INFO: Stopping auxiliary module: Screenshots 2026-06-28 23:09:23,224 [root] INFO: Finishing auxiliary modules 2026-06-28 23:09:23,224 [root] INFO: Shutting down pipe server and dumping dropped files 2026-06-28 23:09:23,225 [root] WARNING: Folder at path "C:\SZitfqj\debugger" does not exist, skipping 2026-06-28 23:09:23,225 [root] WARNING: Folder at path "C:\SZitfqj\tlsdump" does not exist, skipping 2026-06-28 23:09:23,227 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-28 23:08:35 | 2026-06-28 23:09:28 | none |
| File Name |
comany logo 2017.bmp
|
|---|---|
| File Type | data |
| File Size | 1089670 bytes |
| MD5 | eed9cbdb91b507bd01131e146d281a3d |
| SHA1 | 746cdf80fbc6a2cf225ae2d49e1abc3ff9b7033f |
| SHA256 | 6f6e9c8a8cd563c0548ff41979502c7e6ddff2b14c30aea22d05920f9f71c118 VT MWDB Bazaar |
| SHA3-384 | 54345ed4562b71f0cec41a8894369ca5070fca795f7ce7fa2d3801b7aa2b1b481ac2db252d7ec467c6466a7f4a841c24 |
| CRC32 | 988700C7 |
| TLSH | T13B35E3A9A5D09413F40EE0364A768CDD1A6A7D4ECCA7019F933B764790BDC24B7CA4CE |
| Ssdeep | 96:WfGhxDZVhLXOvfqs1zjf7pEHZKzjfd5GQhVLzjfY355ofvNSI5fa429QtGfwFpGh:p |
No results found.
No behavioral analysis data available.
No dropped files found.