| Category | Package | Started | Completed | Duration | Logs |
|---|---|---|---|---|---|
| FILE | generic | 2026-06-28 23:12:36 | 2026-06-28 23:13:29 | 53s |
|
2026-06-28 14:55:58,035 [root] INFO: Date set to: 20260628T23:12:43, timeout set to: 15 2026-06-28 23:12:43,099 [root] DEBUG: Starting analyzer from: C:\7d7wfxi0 2026-06-28 23:12:43,100 [root] DEBUG: Storing results at: C:\ulEbtvtLy 2026-06-28 23:12:43,100 [root] DEBUG: Pipe server name: \\.\PIPE\XzlyPm 2026-06-28 23:12:43,100 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314 2026-06-28 23:12:43,100 [root] INFO: analysis running as an admin 2026-06-28 23:12:43,101 [root] DEBUG: no analysis package configured, picking one for you 2026-06-28 23:12:46,211 [root] INFO: analysis package selected: "generic" 2026-06-28 23:12:46,212 [root] DEBUG: importing analysis package module: "modules.packages.generic"... 2026-06-28 23:12:46,224 [root] DEBUG: imported analysis package "generic" 2026-06-28 23:12:46,224 [root] DEBUG: initializing analysis package "generic"... 2026-06-28 23:12:46,224 [lib.common.common] INFO: no wrapping 2026-06-28 23:12:46,224 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-28 23:12:46,225 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\comany logo 2017.bmp 2026-06-28 23:12:46,225 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll option 2026-06-28 23:12:46,225 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll_64 option 2026-06-28 23:12:46,226 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader option 2026-06-28 23:12:46,226 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader_64 option 2026-06-28 23:12:46,277 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2026-06-28 23:12:46,288 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2026-06-28 23:12:46,372 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2026-06-28 23:12:46,417 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2026-06-28 23:12:46,431 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-06-28 23:12:46,434 [lib.api.screenshot] ERROR: No module named 'PIL' 2026-06-28 23:12:46,435 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots" 2026-06-28 23:12:46,454 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2026-06-28 23:12:46,456 [root] DEBUG: Initialized auxiliary module "Browser" 2026-06-28 23:12:46,456 [root] DEBUG: attempting to configure 'Browser' from data 2026-06-28 23:12:46,458 [root] DEBUG: module Browser does not support data configuration, ignoring 2026-06-28 23:12:46,459 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2026-06-28 23:12:46,462 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2026-06-28 23:12:46,462 [root] DEBUG: Initialized auxiliary module "DigiSig" 2026-06-28 23:12:46,462 [root] DEBUG: attempting to configure 'DigiSig' from data 2026-06-28 23:12:46,462 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2026-06-28 23:12:46,462 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2026-06-28 23:12:46,463 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature 2026-06-28 23:12:47,106 [modules.auxiliary.digisig] DEBUG: File has an invalid signature 2026-06-28 23:12:47,107 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json 2026-06-28 23:12:47,109 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2026-06-28 23:12:47,109 [root] DEBUG: Initialized auxiliary module "Disguise" 2026-06-28 23:12:47,109 [root] DEBUG: attempting to configure 'Disguise' from data 2026-06-28 23:12:47,110 [root] DEBUG: module Disguise does not support data configuration, ignoring 2026-06-28 23:12:47,110 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2026-06-28 23:12:47,123 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 3692) 2026-06-28 23:12:47,133 [modules.auxiliary.disguise] INFO: Disguising GUID to 1a98ac3a-16f4-4342-92b2-835bcbf61450 2026-06-28 23:12:47,134 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2026-06-28 23:12:47,134 [root] DEBUG: Initialized auxiliary module "Human" 2026-06-28 23:12:47,134 [root] DEBUG: attempting to configure 'Human' from data 2026-06-28 23:12:47,134 [root] DEBUG: module Human does not support data configuration, ignoring 2026-06-28 23:12:47,135 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2026-06-28 23:12:47,142 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2026-06-28 23:12:47,142 [root] DEBUG: Initialized auxiliary module "Screenshots" 2026-06-28 23:12:47,142 [root] DEBUG: attempting to configure 'Screenshots' from data 2026-06-28 23:12:47,142 [root] DEBUG: module Screenshots does not support data configuration, ignoring 2026-06-28 23:12:47,143 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"... 2026-06-28 23:12:47,162 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2026-06-28 23:12:47,162 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots 2026-06-28 23:12:47,163 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2026-06-28 23:12:47,163 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2026-06-28 23:12:47,163 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2026-06-28 23:12:47,163 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2026-06-28 23:12:47,172 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process 2026-06-28 23:12:47,173 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2026-06-28 23:12:53,212 [root] INFO: Restarting WMI Service 2026-06-28 23:12:55,359 [root] DEBUG: package modules.packages.generic does not support configure, ignoring 2026-06-28 23:12:55,364 [root] WARNING: configuration error for package modules.packages.generic: error importing data.packages.generic: No module named 'data.packages' 2026-06-28 23:12:55,365 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-28 23:12:55,382 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\comany logo 2017.bmp"" with pid 4340 2026-06-28 23:12:55,669 [lib.api.process] INFO: Monitor config for process 4340: C:\7d7wfxi0\dll\4340.ini 2026-06-28 23:12:55,689 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\zAfesvgf.dll, loader C:\7d7wfxi0\bin\eUKktRuI.exe 2026-06-28 23:12:55,715 [root] DEBUG: Loader: Injecting process 4340 (thread 4788) with C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:12:55,716 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-28 23:12:55,717 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:12:55,720 [lib.api.process] INFO: Injected into 64-bit <Process 4340 cmd.exe> 2026-06-28 23:12:57,759 [lib.api.process] INFO: Successfully resumed process with pid 4340 2026-06-28 23:12:57,974 [root] DEBUG: 4340: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-28 23:12:57,976 [root] DEBUG: 4340: Disabling sleep skipping. 2026-06-28 23:12:57,977 [root] DEBUG: 4340: Dropped file limit defaulting to 100. 2026-06-28 23:12:58,006 [root] DEBUG: 4340: YaraInit: Compiled 44 rule files 2026-06-28 23:12:58,010 [root] DEBUG: 4340: YaraInit: Compiled rules saved to file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-28 23:12:58,073 [root] DEBUG: 4340: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-28 23:12:58,074 [root] DEBUG: 4340: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-28 23:12:58,080 [root] DEBUG: 4340: YaraScan hit: FindFixAndRun 2026-06-28 23:12:58,082 [root] DEBUG: 4340: Monitor initialised: 64-bit capemon loaded in process 4340 at 0x00007FF9863D0000, thread 4788, image base 0x00007FF79A450000, stack from 0x00000058BD604000-0x00000058BD700000 2026-06-28 23:12:58,085 [root] DEBUG: 4340: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\comany logo 2017.bmp" 2026-06-28 23:12:58,104 [root] DEBUG: 4340: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-28 23:12:58,158 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-28 23:12:58,160 [root] DEBUG: 4340: set_hooks: Unable to hook LockResource 2026-06-28 23:12:58,179 [root] DEBUG: 4340: Hooked 630 out of 631 functions 2026-06-28 23:12:58,184 [root] DEBUG: 4340: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620 2026-06-28 23:12:58,187 [root] DEBUG: 4340: Syscall hook installed, syscall logging level 1 2026-06-28 23:12:58,209 [root] DEBUG: 4340: RestoreHeaders: Restored original import table. 2026-06-28 23:12:58,210 [root] INFO: Loaded monitor into process with pid 4340 2026-06-28 23:12:58,212 [root] DEBUG: 4340: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 4788). 2026-06-28 23:12:58,214 [root] DEBUG: 4340: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-28 23:12:58,222 [root] DEBUG: 4340: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00) 2026-06-28 23:12:58,246 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-28 23:12:58,248 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-28 23:12:58,253 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-28 23:12:58,268 [root] DEBUG: 4340: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes). 2026-06-28 23:12:58,272 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes). 2026-06-28 23:12:58,276 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-28 23:12:58,277 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes). 2026-06-28 23:12:58,281 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes). 2026-06-28 23:12:58,294 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-28 23:12:58,332 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-28 23:12:58,439 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-28 23:12:58,443 [root] DEBUG: 4340: DLL loaded at 0x00007FF993730000: C:\Windows\system32\edputil (0x24000 bytes). 2026-06-28 23:12:58,489 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-28 23:12:58,502 [root] DEBUG: 4340: DLL loaded at 0x00007FF9903B0000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes). 2026-06-28 23:12:58,637 [root] DEBUG: 4340: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes). 2026-06-28 23:12:58,688 [root] DEBUG: 4340: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes). 2026-06-28 23:12:58,690 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes). 2026-06-28 23:12:58,693 [root] DEBUG: 4340: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes). 2026-06-28 23:12:58,702 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A7200000: C:\Windows\system32\msvcp110_win (0x8a000 bytes). 2026-06-28 23:12:58,704 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes). 2026-06-28 23:12:58,737 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\System32\wintypes (0x154000 bytes). 2026-06-28 23:12:58,745 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A5A30000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes). 2026-06-28 23:12:58,753 [root] DEBUG: 4340: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes). 2026-06-28 23:12:58,755 [root] DEBUG: 4340: DLL loaded at 0x00007FF998E30000: C:\Windows\system32\PhotoMetadataHandler (0x81000 bytes). 2026-06-28 23:12:58,820 [root] DEBUG: 4340: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes). 2026-06-28 23:12:58,822 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A6C60000: C:\Windows\System32\sppc (0x25000 bytes). 2026-06-28 23:12:58,825 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A6C90000: C:\Windows\System32\SLC (0x29000 bytes). 2026-06-28 23:12:58,827 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A7F80000: C:\Windows\System32\USERENV (0x2e000 bytes). 2026-06-28 23:12:58,829 [root] DEBUG: 4340: DLL loaded at 0x00007FF9971F0000: C:\Windows\System32\appresolver (0x90000 bytes). 2026-06-28 23:12:58,849 [root] DEBUG: 4340: DLL loaded at 0x00007FF99D480000: C:\Windows\System32\OneCoreCommonProxyStub (0x7d000 bytes). 2026-06-28 23:12:58,868 [root] DEBUG: 4340: DLL loaded at 0x00007FF99EEA0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x798000 bytes). 2026-06-28 23:12:58,883 [lib.api.process] INFO: Monitor config for process 756: C:\7d7wfxi0\dll\756.ini 2026-06-28 23:12:58,889 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\zAfesvgf.dll, loader C:\7d7wfxi0\bin\eUKktRuI.exe 2026-06-28 23:12:58,936 [root] DEBUG: Loader: Injecting process 756 with C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:12:58,943 [root] DEBUG: 756: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-28 23:12:58,944 [root] DEBUG: 756: Disabling sleep skipping. 2026-06-28 23:12:58,945 [root] DEBUG: 756: Dropped file limit defaulting to 100. 2026-06-28 23:12:58,949 [root] DEBUG: 756: Services hook set enabled 2026-06-28 23:12:58,954 [root] DEBUG: 756: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-28 23:12:58,977 [root] DEBUG: 756: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-28 23:12:58,979 [root] DEBUG: 756: Monitor initialised: 64-bit capemon loaded in process 756 at 0x00007FF9863D0000, thread 1004, image base 0x00007FF69D480000, stack from 0x00000036AC3F5000-0x00000036AC400000 2026-06-28 23:12:58,981 [root] DEBUG: 756: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p 2026-06-28 23:12:59,005 [root] DEBUG: 756: Hooked 69 out of 69 functions 2026-06-28 23:12:59,007 [root] INFO: Loaded monitor into process with pid 756 2026-06-28 23:12:59,008 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-06-28 23:12:59,009 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:12:59,013 [lib.api.process] INFO: Injected into 64-bit <Process 756 svchost.exe> 2026-06-28 23:13:01,027 [root] DEBUG: 4340: CreateProcessHandler: Injection info set for new process 4448: C:\Windows\system32\mspaint.exe, ImageBase: 0x00007FF700FE0000 2026-06-28 23:13:01,029 [root] INFO: Announced 64-bit process name: mspaint.exe pid: 4448 2026-06-28 23:13:01,029 [lib.api.process] INFO: Monitor config for process 4448: C:\7d7wfxi0\dll\4448.ini 2026-06-28 23:13:01,034 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\zAfesvgf.dll, loader C:\7d7wfxi0\bin\eUKktRuI.exe 2026-06-28 23:13:01,047 [root] DEBUG: Loader: Injecting process 4448 (thread 4732) with C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:13:01,051 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-28 23:13:01,052 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:13:01,056 [lib.api.process] INFO: Injected into 64-bit <Process 4448 mspaint.exe> 2026-06-28 23:13:01,068 [root] INFO: Announced 64-bit process name: mspaint.exe pid: 4448 2026-06-28 23:13:01,068 [lib.api.process] INFO: Monitor config for process 4448: C:\7d7wfxi0\dll\4448.ini 2026-06-28 23:13:01,070 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\zAfesvgf.dll, loader C:\7d7wfxi0\bin\eUKktRuI.exe 2026-06-28 23:13:01,081 [root] DEBUG: Loader: Injecting process 4448 (thread 4732) with C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:13:01,083 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-28 23:13:01,084 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:13:01,087 [lib.api.process] INFO: Injected into 64-bit <Process 4448 mspaint.exe> 2026-06-28 23:13:01,091 [root] DEBUG: 4340: DLL loaded at 0x00007FF998030000: C:\Windows\system32\MPR (0x1d000 bytes). 2026-06-28 23:13:01,092 [root] DEBUG: 4340: DLL loaded at 0x00007FF9A31D0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes). 2026-06-28 23:13:01,186 [root] DEBUG: 4448: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-28 23:13:01,187 [root] DEBUG: 4448: Dropped file limit defaulting to 100. 2026-06-28 23:13:01,196 [root] DEBUG: 4448: Disabling sleep skipping. 2026-06-28 23:13:01,199 [root] DEBUG: 4448: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-28 23:13:01,222 [root] DEBUG: 4448: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-28 23:13:01,223 [root] DEBUG: 4448: YaraScan: Scanning 0x00007FF700FE0000, size 0xf8baa 2026-06-28 23:13:01,234 [root] DEBUG: 4448: Monitor initialised: 64-bit capemon loaded in process 4448 at 0x00007FF9863D0000, thread 4732, image base 0x00007FF700FE0000, stack from 0x00000053E3E74000-0x00000053E3E80000 2026-06-28 23:13:01,235 [root] DEBUG: 4448: Commandline: "C:\Windows\system32\mspaint.exe" "C:\Users\Rajesh\AppData\Local\Temp\comany logo 2017.bmp" 2026-06-28 23:13:01,252 [root] DEBUG: 4448: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-28 23:13:01,312 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-28 23:13:01,376 [root] DEBUG: 4448: set_hooks: Unable to hook LockResource 2026-06-28 23:13:01,391 [root] DEBUG: 4448: Hooked 630 out of 631 functions 2026-06-28 23:13:01,405 [root] DEBUG: 4448: Syscall hook installed, syscall logging level 1 2026-06-28 23:13:01,414 [root] DEBUG: 4448: RestoreHeaders: Restored original import table. 2026-06-28 23:13:01,415 [root] INFO: Loaded monitor into process with pid 4448 2026-06-28 23:13:01,421 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-28 23:13:01,443 [root] DEBUG: 4448: DLL loaded at 0x00007FF99DDA0000: C:\Windows\SYSTEM32\ninput (0x6a000 bytes). 2026-06-28 23:13:01,446 [root] DEBUG: 4448: caller_dispatch: Added region at 0x00007FF700FE0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF70107F9B1, thread 4732). 2026-06-28 23:13:01,448 [root] DEBUG: 4448: YaraScan: Scanning 0x00007FF700FE0000, size 0xf8baa 2026-06-28 23:13:01,466 [root] DEBUG: 4448: ProcessImageBase: Main module image at 0x00007FF700FE0000 unmodified (entropy change 0.000000e+00) 2026-06-28 23:13:01,473 [root] DEBUG: 4448: DLL loaded at 0x00007FF990180000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1288_none_91a663c8cc864906\gdiplus (0x1a9000 bytes). 2026-06-28 23:13:01,477 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-28 23:13:01,493 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes). 2026-06-28 23:13:01,565 [root] DEBUG: 4448: DLL loaded at 0x00007FF98DE00000: C:\Windows\system32\MSFTEDIT (0x348000 bytes). 2026-06-28 23:13:01,576 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-28 23:13:01,641 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-28 23:13:01,650 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A2820000: C:\Windows\system32\XmlLite (0x36000 bytes). 2026-06-28 23:13:01,651 [root] DEBUG: 4448: DLL loaded at 0x00007FF985FE0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes). 2026-06-28 23:13:01,661 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-28 23:13:01,662 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A6230000: C:\Windows\system32\windows.storage (0x790000 bytes). 2026-06-28 23:13:01,668 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes). 2026-06-28 23:13:01,670 [root] DEBUG: 4448: DLL loaded at 0x00007FF988A70000: C:\Windows\System32\efswrt (0xde000 bytes). 2026-06-28 23:13:01,677 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A10F0000: C:\Windows\System32\twinapi.appcore (0x201000 bytes). 2026-06-28 23:13:01,825 [root] INFO: Announced starting service "b'stisvc'" 2026-06-28 23:13:01,827 [lib.api.process] INFO: Monitor config for process 632: C:\7d7wfxi0\dll\632.ini 2026-06-28 23:13:01,830 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\zAfesvgf.dll, loader C:\7d7wfxi0\bin\eUKktRuI.exe 2026-06-28 23:13:01,842 [root] DEBUG: Loader: Injecting process 632 with C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:13:01,846 [root] DEBUG: Loader: Copied config file C:\7d7wfxi0\dll\632.ini to system path C:\632.ini 2026-06-28 23:13:01,851 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 632 C:\7d7wfxi0\dll\zAfesvgf.dll 2026-06-28 23:13:01,852 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\zAfesvgf.dll. 2026-06-28 23:13:01,855 [lib.api.process] INFO: Injected into 64-bit <Process 632 services.exe> 2026-06-28 23:13:05,004 [root] DEBUG: 4448: DLL loaded at 0x00007FF99DFF0000: C:\Windows\System32\sti (0x53000 bytes). 2026-06-28 23:13:05,034 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A4220000: C:\Windows\SYSTEM32\wiatrace (0xa000 bytes). 2026-06-28 23:13:05,150 [root] DEBUG: 4448: DLL loaded at 0x00007FF995FC0000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes). 2026-06-28 23:13:05,211 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A5F20000: C:\Windows\system32\dwmapi (0x2f000 bytes). 2026-06-28 23:13:05,274 [root] DEBUG: 4448: DLL loaded at 0x00007FF994E80000: C:\Windows\System32\msxml6 (0x25f000 bytes). 2026-06-28 23:13:05,296 [root] DEBUG: 4448: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\windowscodecs (0x1b4000 bytes). 2026-06-28 23:13:05,560 [root] DEBUG: 4448: DLL loaded at 0x00007FF998F00000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes). 2026-06-28 23:13:05,610 [root] DEBUG: 4448: DLL loaded at 0x00007FF992900000: C:\Windows\System32\oleacc (0x66000 bytes). 2026-06-28 23:13:05,672 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-28 23:13:05,732 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-28 23:13:06,221 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-28 23:13:06,237 [root] DEBUG: 4448: DLL loaded at 0x00007FF998E30000: C:\Windows\system32\PhotoMetadataHandler (0x81000 bytes). 2026-06-28 23:13:06,598 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A6E00000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-06-28 23:13:06,600 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A57F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-06-28 23:13:06,603 [root] DEBUG: 4448: DLL loaded at 0x00007FF9A5490000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes). 2026-06-28 23:13:06,605 [root] DEBUG: 4448: DLL loaded at 0x00007FF99BC00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-06-28 23:13:06,981 [root] DEBUG: 4448: DLL loaded at 0x00007FF9AA490000: C:\Windows\System32\coml2 (0x79000 bytes). 2026-06-28 23:13:12,940 [root] INFO: Analysis timeout hit, terminating analysis 2026-06-28 23:13:12,943 [lib.api.process] INFO: Terminate event set for process 4340 2026-06-28 23:13:12,944 [root] DEBUG: 4340: Terminate Event: Attempting to dump process 4340 2026-06-28 23:13:12,946 [root] DEBUG: 4340: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching 2026-06-28 23:13:12,947 [root] DEBUG: 4340: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000. 2026-06-28 23:13:12,948 [root] DEBUG: 4340: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2026-06-28 23:13:12,949 [root] DEBUG: 4340: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000. 2026-06-28 23:13:12,950 [root] DEBUG: 4340: DumpProcess: Module entry point VA is 0x00007FF79A468F50. 2026-06-28 23:13:12,968 [lib.common.results] INFO: Uploading file C:\ulEbtvtLy\CAPE\4340_391551213629162026 to procdump\596273a8b15eee0f0859d77756f42157bf16115f88ef2335be4f810d11885992; Size is 401920; Max size: 100000000 2026-06-28 23:13:12,981 [root] DEBUG: 4340: DumpProcess: Module image dump success - dump size 0x62200. 2026-06-28 23:13:12,995 [root] DEBUG: 4340: Terminate Event: Shutdown complete for process 4340 but failed to inform analyzer. 2026-06-28 23:13:17,947 [lib.api.process] INFO: Termination confirmed for process 4340 2026-06-28 23:13:17,948 [root] INFO: Terminate event set for process 4340 2026-06-28 23:13:17,950 [lib.api.process] INFO: Terminate event set for process 756 2026-06-28 23:13:17,950 [root] DEBUG: 756: Terminate Event: Attempting to dump process 756 2026-06-28 23:13:17,952 [root] DEBUG: 756: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-28 23:13:17,956 [lib.api.process] INFO: Termination confirmed for process 756 2026-06-28 23:13:17,958 [root] INFO: Terminate event set for process 756 2026-06-28 23:13:17,957 [root] DEBUG: 756: Terminate Event: monitor shutdown complete for process 756 2026-06-28 23:13:17,958 [lib.api.process] INFO: Terminate event set for process 4448 2026-06-28 23:13:17,960 [root] DEBUG: 4448: Terminate Event: Attempting to dump process 4448 2026-06-28 23:13:17,963 [root] DEBUG: 4448: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-28 23:13:17,981 [root] DEBUG: 4448: Terminate Event: Shutdown complete for process 4448 but failed to inform analyzer. 2026-06-28 23:13:22,185 [root] DEBUG: 4448: api-cap: GetCursorPos hook disabled due to count: 5000 2026-06-28 23:13:22,963 [lib.api.process] INFO: Termination confirmed for process 4448 2026-06-28 23:13:22,964 [root] INFO: Terminate event set for process 4448 2026-06-28 23:13:22,965 [root] INFO: Created shutdown mutex 2026-06-28 23:13:23,974 [root] INFO: Shutting down package 2026-06-28 23:13:23,975 [root] INFO: Stopping auxiliary modules 2026-06-28 23:13:23,976 [root] INFO: Stopping auxiliary module: Browser 2026-06-28 23:13:23,976 [root] INFO: Stopping auxiliary module: Human 2026-06-28 23:13:24,678 [root] INFO: Stopping auxiliary module: Screenshots 2026-06-28 23:13:24,679 [root] INFO: Finishing auxiliary modules 2026-06-28 23:13:24,679 [root] INFO: Shutting down pipe server and dumping dropped files 2026-06-28 23:13:24,679 [root] WARNING: Folder at path "C:\ulEbtvtLy\debugger" does not exist, skipping 2026-06-28 23:13:24,680 [root] WARNING: Folder at path "C:\ulEbtvtLy\tlsdump" does not exist, skipping 2026-06-28 23:13:24,681 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-28 23:12:36 | 2026-06-28 23:13:28 | none |
| File Name |
comany logo 2017.bmp
|
|---|---|
| File Type | data |
| File Size | 1089670 bytes |
| MD5 | eed9cbdb91b507bd01131e146d281a3d |
| SHA1 | 746cdf80fbc6a2cf225ae2d49e1abc3ff9b7033f |
| SHA256 | 6f6e9c8a8cd563c0548ff41979502c7e6ddff2b14c30aea22d05920f9f71c118 VT MWDB Bazaar |
| SHA3-384 | 54345ed4562b71f0cec41a8894369ca5070fca795f7ce7fa2d3801b7aa2b1b481ac2db252d7ec467c6466a7f4a841c24 |
| CRC32 | 988700C7 |
| TLSH | T13B35E3A9A5D09413F40EE0364A768CDD1A6A7D4ECCA7019F933B764790BDC24B7CA4CE |
| Ssdeep | 96:WfGhxDZVhLXOvfqs1zjf7pEHZKzjfd5GQhVLzjfY355ofvNSI5fa429QtGfwFpGh:p |
No results found.
No behavioral analysis data available.
No dropped files found.