| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| FILE | batch | 2026-06-29 12:43:43 | 2026-06-29 12:47:36 | 233s |
|
|||||
| Reports | JSON | |||||||||
vnc_port=5900
2026-06-28 14:55:57,985 [root] INFO: Date set to: 20260629T12:43:48, timeout set to: 200
2026-06-29 12:43:49,624 [root] DEBUG: Starting analyzer from: C:\2_6me6uj
2026-06-29 12:43:49,625 [root] DEBUG: Storing results at: C:\ngIpjVKr
2026-06-29 12:43:49,627 [root] DEBUG: Pipe server name: \\.\PIPE\CWnexHVb
2026-06-29 12:43:49,632 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314
2026-06-29 12:43:49,637 [root] INFO: analysis running as an admin
2026-06-29 12:43:49,640 [root] DEBUG: no analysis package configured, picking one for you
2026-06-29 12:43:49,663 [root] INFO: analysis package selected: "batch"
2026-06-29 12:43:49,669 [root] DEBUG: importing analysis package module: "modules.packages.batch"...
2026-06-29 12:43:50,274 [root] DEBUG: imported analysis package "batch"
2026-06-29 12:43:50,275 [root] DEBUG: initializing analysis package "batch"...
2026-06-29 12:43:50,276 [lib.common.common] INFO: no wrapping
2026-06-29 12:43:50,276 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-29 12:43:50,283 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\test.bat
2026-06-29 12:43:50,283 [root] INFO: Analyzer: Package modules.packages.batch does not specify a dll option
2026-06-29 12:43:50,284 [root] INFO: Analyzer: Package modules.packages.batch does not specify a dll_64 option
2026-06-29 12:43:50,284 [root] INFO: Analyzer: Package modules.packages.batch does not specify a loader option
2026-06-29 12:43:50,286 [root] INFO: Analyzer: Package modules.packages.batch does not specify a loader_64 option
2026-06-28 14:56:02,044 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-06-28 14:56:02,063 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-06-28 14:56:02,110 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-06-28 14:56:02,278 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-06-28 14:56:02,289 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-06-28 14:56:02,290 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-06-28 14:56:02,290 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-06-28 14:56:02,295 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-06-28 14:56:02,296 [root] DEBUG: Initialized auxiliary module "Browser"
2026-06-28 14:56:02,296 [root] DEBUG: attempting to configure 'Browser' from data
2026-06-28 14:56:02,298 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-06-28 14:56:02,298 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-06-28 14:56:02,308 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-06-28 14:56:02,308 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-06-28 14:56:02,308 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-06-28 14:56:02,309 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-06-28 14:56:02,309 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-06-28 14:56:02,309 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-06-28 14:56:02,939 [modules.auxiliary.digisig] DEBUG: File has an invalid signature
2026-06-28 14:56:02,940 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-06-28 14:56:02,943 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-06-28 14:56:02,943 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-06-28 14:56:02,944 [root] DEBUG: attempting to configure 'Disguise' from data
2026-06-28 14:56:02,945 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-06-28 14:56:02,945 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-06-28 14:56:02,949 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 4688)
2026-06-28 14:56:02,959 [modules.auxiliary.disguise] INFO: Disguising GUID to 783034a4-7eca-4edd-ac9e-1e8027d53a55
2026-06-28 14:56:02,959 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-06-28 14:56:02,960 [root] DEBUG: Initialized auxiliary module "Human"
2026-06-28 14:56:02,960 [root] DEBUG: attempting to configure 'Human' from data
2026-06-28 14:56:02,960 [root] DEBUG: module Human does not support data configuration, ignoring
2026-06-28 14:56:02,961 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-06-28 14:56:02,961 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-06-28 14:56:02,962 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-06-28 14:56:02,962 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-06-28 14:56:02,963 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-06-28 14:56:02,964 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-06-28 14:56:02,969 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-06-28 14:56:02,969 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-06-28 14:56:02,969 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-06-28 14:56:02,970 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-06-28 14:56:02,970 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-06-28 14:56:02,971 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-06-28 14:56:02,973 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-06-28 14:56:02,974 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-06-28 14:56:09,002 [root] INFO: Restarting WMI Service
2026-06-28 14:56:11,286 [root] DEBUG: package modules.packages.batch does not support configure, ignoring
2026-06-28 14:56:11,289 [root] WARNING: configuration error for package modules.packages.batch: error importing data.packages.batch: No module named 'data.packages'
2026-06-28 14:56:11,291 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-28 14:56:11,300 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\test.bat"" with pid 3636
2026-06-28 14:56:11,777 [lib.api.process] INFO: Monitor config for process 3636: C:\2_6me6uj\dll\3636.ini
2026-06-28 14:56:11,801 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-28 14:56:11,829 [root] DEBUG: Loader: Injecting process 3636 (thread 3868) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:11,833 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-28 14:56:11,835 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:11,839 [lib.api.process] INFO: Injected into 64-bit <Process 3636 cmd.exe>
2026-06-28 14:56:13,860 [lib.api.process] INFO: Successfully resumed process with pid 3636
2026-06-28 14:56:14,096 [root] DEBUG: 3636: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-28 14:56:14,097 [root] DEBUG: 3636: Disabling sleep skipping.
2026-06-28 14:56:14,098 [root] DEBUG: 3636: Dropped file limit defaulting to 100.
2026-06-28 14:56:14,132 [root] DEBUG: 3636: YaraInit: Compiled 44 rule files
2026-06-28 14:56:14,135 [root] DEBUG: 3636: YaraInit: Compiled rules saved to file C:\2_6me6uj\data\yara\capemon.yac
2026-06-28 14:56:14,200 [root] DEBUG: 3636: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-28 14:56:14,201 [root] DEBUG: 3636: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a
2026-06-28 14:56:14,206 [root] DEBUG: 3636: YaraScan hit: FindFixAndRun
2026-06-28 14:56:14,207 [root] DEBUG: 3636: Monitor initialised: 64-bit capemon loaded in process 3636 at 0x00007FF986960000, thread 3868, image base 0x00007FF79A450000, stack from 0x000000A0D6604000-0x000000A0D6700000
2026-06-28 14:56:14,208 [root] DEBUG: 3636: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\test.bat"
2026-06-28 14:56:14,228 [root] DEBUG: 3636: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-28 14:56:14,289 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-28 14:56:14,290 [root] DEBUG: 3636: set_hooks: Unable to hook LockResource
2026-06-28 14:56:14,307 [root] DEBUG: 3636: Hooked 630 out of 631 functions
2026-06-28 14:56:14,314 [root] DEBUG: 3636: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620
2026-06-28 14:56:14,317 [root] DEBUG: 3636: Syscall hook installed, syscall logging level 1
2026-06-28 14:56:14,345 [root] DEBUG: 3636: RestoreHeaders: Restored original import table.
2026-06-28 14:56:14,346 [root] INFO: Loaded monitor into process with pid 3636
2026-06-28 14:56:14,348 [root] DEBUG: 3636: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 3868).
2026-06-28 14:56:14,350 [root] DEBUG: 3636: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a
2026-06-28 14:56:14,360 [root] DEBUG: 3636: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00)
2026-06-28 14:56:14,386 [root] DEBUG: 3636: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes).
2026-06-28 14:56:14,391 [root] DEBUG: 3636: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes).
2026-06-28 14:56:14,396 [root] DEBUG: 3636: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-06-28 14:56:14,400 [root] DEBUG: 3636: CreateProcessHandler: Injection info set for new process 2108: C:\Windows\system32\cmd.exe, ImageBase: 0x00007FF79A450000
2026-06-28 14:56:14,401 [root] INFO: Announced 64-bit process name: cmd.exe pid: 2108
2026-06-28 14:56:14,402 [lib.api.process] INFO: Monitor config for process 2108: C:\2_6me6uj\dll\2108.ini
2026-06-28 14:56:14,408 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-28 14:56:14,426 [root] DEBUG: Loader: Injecting process 2108 (thread 4448) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:14,428 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-28 14:56:14,429 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:14,432 [lib.api.process] INFO: Injected into 64-bit <Process 2108 cmd.exe>
2026-06-28 14:56:14,436 [root] INFO: Announced 64-bit process name: cmd.exe pid: 2108
2026-06-28 14:56:14,436 [lib.api.process] INFO: Monitor config for process 2108: C:\2_6me6uj\dll\2108.ini
2026-06-28 14:56:14,441 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-28 14:56:14,452 [root] DEBUG: Loader: Injecting process 2108 (thread 4448) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:14,453 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-28 14:56:14,455 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:14,459 [lib.api.process] INFO: Injected into 64-bit <Process 2108 cmd.exe>
2026-06-28 14:56:14,626 [root] DEBUG: 2108: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-28 14:56:14,628 [root] DEBUG: 2108: Dropped file limit defaulting to 100.
2026-06-28 14:56:14,632 [root] DEBUG: 2108: Disabling sleep skipping.
2026-06-28 14:56:14,635 [root] DEBUG: 2108: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-28 14:56:14,665 [root] DEBUG: 2108: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-28 14:56:14,666 [root] DEBUG: 2108: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a
2026-06-28 14:56:14,671 [root] DEBUG: 2108: YaraScan hit: FindFixAndRun
2026-06-28 14:56:14,672 [root] DEBUG: 2108: Monitor initialised: 64-bit capemon loaded in process 2108 at 0x00007FF986960000, thread 4448, image base 0x00007FF79A450000, stack from 0x000000AE2B404000-0x000000AE2B500000
2026-06-28 14:56:14,673 [root] DEBUG: 2108: Commandline: C:\Windows\system32\cmd.exe /K "C:\Users\Rajesh\AppData\Local\Temp\test.bat"
2026-06-28 14:56:14,690 [root] DEBUG: 2108: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-28 14:56:14,743 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-28 14:56:14,746 [root] DEBUG: 2108: set_hooks: Unable to hook LockResource
2026-06-28 14:56:14,761 [root] DEBUG: 2108: Hooked 630 out of 631 functions
2026-06-28 14:56:14,824 [root] DEBUG: 2108: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620
2026-06-28 14:56:14,825 [root] DEBUG: 2108: Syscall hook installed, syscall logging level 1
2026-06-28 14:56:14,834 [root] DEBUG: 2108: RestoreHeaders: Restored original import table.
2026-06-28 14:56:14,835 [root] INFO: Loaded monitor into process with pid 2108
2026-06-28 14:56:14,837 [root] DEBUG: 2108: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 4448).
2026-06-28 14:56:14,839 [root] DEBUG: 2108: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a
2026-06-28 14:56:14,851 [root] DEBUG: 2108: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00)
2026-06-28 14:56:14,882 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A4220000: C:\Windows\SYSTEM32\cmdext (0xc000 bytes).
2026-06-28 14:56:14,942 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes).
2026-06-28 14:56:14,947 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes).
2026-06-28 14:56:14,951 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-06-28 14:56:14,954 [root] DEBUG: 2108: CreateProcessHandler: Injection info set for new process 4468: C:\Windows\system32\systeminfo.exe, ImageBase: 0x00007FF6573D0000
2026-06-28 14:56:14,955 [root] INFO: Announced 64-bit process name: systeminfo.exe pid: 4468
2026-06-28 14:56:14,956 [lib.api.process] INFO: Monitor config for process 4468: C:\2_6me6uj\dll\4468.ini
2026-06-28 14:56:14,960 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-28 14:56:14,975 [root] DEBUG: Loader: Injecting process 4468 (thread 1140) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:14,976 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-28 14:56:14,977 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:14,982 [lib.api.process] INFO: Injected into 64-bit <Process 4468 systeminfo.exe>
2026-06-28 14:56:14,984 [root] INFO: Announced 64-bit process name: systeminfo.exe pid: 4468
2026-06-28 14:56:14,985 [lib.api.process] INFO: Monitor config for process 4468: C:\2_6me6uj\dll\4468.ini
2026-06-28 14:56:14,987 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-28 14:56:14,998 [root] DEBUG: Loader: Injecting process 4468 (thread 1140) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:15,000 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-28 14:56:15,001 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:15,005 [lib.api.process] INFO: Injected into 64-bit <Process 4468 systeminfo.exe>
2026-06-28 14:56:15,025 [root] DEBUG: 4468: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-28 14:56:15,026 [root] DEBUG: 4468: Dropped file limit defaulting to 100.
2026-06-28 14:56:15,031 [root] DEBUG: 4468: Disabling sleep skipping.
2026-06-28 14:56:15,037 [root] DEBUG: 4468: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-28 14:56:15,060 [root] DEBUG: 4468: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-28 14:56:15,061 [root] DEBUG: 4468: YaraScan: Scanning 0x00007FF6573D0000, size 0x1e030
2026-06-28 14:56:15,065 [root] DEBUG: 4468: Monitor initialised: 64-bit capemon loaded in process 4468 at 0x00007FF986960000, thread 1140, image base 0x00007FF6573D0000, stack from 0x0000003381ED4000-0x0000003381EE0000
2026-06-28 14:56:15,066 [root] DEBUG: 4468: Commandline: systeminfo
2026-06-28 14:56:15,085 [root] DEBUG: 4468: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-28 14:56:15,141 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-28 14:56:15,143 [root] DEBUG: 4468: set_hooks: Unable to hook LockResource
2026-06-28 14:56:15,156 [root] DEBUG: 4468: Hooked 630 out of 631 functions
2026-06-28 14:56:15,160 [root] DEBUG: 4468: Syscall hook installed, syscall logging level 1
2026-06-28 14:56:15,170 [root] DEBUG: 4468: RestoreHeaders: Restored original import table.
2026-06-28 14:56:15,171 [root] INFO: Loaded monitor into process with pid 4468
2026-06-28 14:56:15,177 [root] DEBUG: 4468: caller_dispatch: Added region at 0x00007FF6573D0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6573E1EA1, thread 1140).
2026-06-28 14:56:15,181 [root] DEBUG: 4468: YaraScan: Scanning 0x00007FF6573D0000, size 0x1e030
2026-06-28 14:56:15,185 [root] DEBUG: 4468: ProcessImageBase: Main module image at 0x00007FF6573D0000 unmodified (entropy change 0.000000e+00)
2026-06-28 14:56:15,191 [root] DEBUG: 4468: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-28 14:56:15,192 [root] DEBUG: 4468: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-28 14:56:15,204 [lib.api.process] INFO: Monitor config for process 756: C:\2_6me6uj\dll\756.ini
2026-06-28 14:56:15,207 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-28 14:56:15,225 [root] DEBUG: Loader: Injecting process 756 with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:15,231 [root] DEBUG: 756: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-28 14:56:15,232 [root] DEBUG: 756: Disabling sleep skipping.
2026-06-28 14:56:15,232 [root] DEBUG: 756: Dropped file limit defaulting to 100.
2026-06-28 14:56:15,236 [root] DEBUG: 756: Services hook set enabled
2026-06-28 14:56:15,243 [root] DEBUG: 756: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-28 14:56:15,263 [root] DEBUG: 756: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-28 14:56:15,264 [root] DEBUG: 756: Monitor initialised: 64-bit capemon loaded in process 756 at 0x00007FF986960000, thread 5016, image base 0x00007FF69D480000, stack from 0x00000036AC3F4000-0x00000036AC400000
2026-06-28 14:56:15,266 [root] DEBUG: 756: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-06-28 14:56:15,286 [root] DEBUG: 756: Hooked 69 out of 69 functions
2026-06-28 14:56:15,288 [root] INFO: Loaded monitor into process with pid 756
2026-06-28 14:56:15,289 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-28 14:56:15,290 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:15,293 [lib.api.process] INFO: Injected into 64-bit <Process 756 svchost.exe>
2026-06-28 14:56:17,306 [lib.api.process] INFO: Monitor config for process 3036: C:\2_6me6uj\dll\3036.ini
2026-06-28 14:56:17,311 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-28 14:56:17,326 [root] DEBUG: Loader: Injecting process 3036 with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:17,332 [root] DEBUG: 3036: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-28 14:56:17,334 [root] DEBUG: 3036: Disabling sleep skipping.
2026-06-28 14:56:17,335 [root] DEBUG: 3036: Dropped file limit defaulting to 100.
2026-06-28 14:56:17,337 [root] DEBUG: 3036: Services hook set enabled
2026-06-28 14:56:17,341 [root] DEBUG: 3036: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-28 14:56:17,365 [root] DEBUG: 3036: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-28 14:56:17,366 [root] DEBUG: 3036: Monitor initialised: 64-bit capemon loaded in process 3036 at 0x00007FF986960000, thread 3952, image base 0x00007FF69D480000, stack from 0x000000A3D10F5000-0x000000A3D1100000
2026-06-28 14:56:17,370 [root] DEBUG: 3036: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-06-28 14:56:17,392 [root] DEBUG: 3036: Hooked 69 out of 69 functions
2026-06-28 14:56:17,395 [root] INFO: Loaded monitor into process with pid 3036
2026-06-28 14:56:17,398 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-28 14:56:17,404 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-28 14:56:17,408 [lib.api.process] INFO: Injected into 64-bit <Process 3036 svchost.exe>
2026-06-29 05:44:12,738 [root] DEBUG: 4468: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 05:44:12,746 [root] DEBUG: 4468: DLL loaded at 0x00007FF9A0F30000: C:\Windows\SYSTEM32\wbemcomn (0x92000 bytes).
2026-06-29 05:44:12,747 [root] DEBUG: 4468: DLL loaded at 0x00007FF97FC40000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-06-29 05:44:12,750 [root] DEBUG: 4468: Successfully installed hook on COM Object function WbemLocator_ConnectServer
2026-06-29 05:44:12,779 [root] DEBUG: 4468: DLL loaded at 0x00007FF97FC20000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-06-29 05:44:12,793 [root] DEBUG: 4468: DLL loaded at 0x00007FF99DC10000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2026-06-29 05:44:12,803 [root] DEBUG: 4468: DLL loaded at 0x00007FF99E360000: C:\Windows\SYSTEM32\amsi (0x19000 bytes).
2026-06-29 05:44:12,809 [root] DEBUG: 4468: Successfully installed hook on COM Object function IWbemServices_ExecQuery
2026-06-29 05:44:12,810 [root] DEBUG: 4468: Successfully installed hook on COM Object function IWbemServices_ExecQueryAsync
2026-06-29 05:44:12,812 [root] DEBUG: 4468: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnum
2026-06-29 05:44:12,815 [root] DEBUG: 4468: Successfully installed hook on COM Object function IWbemServices_CreateInstanceEnumAsync
2026-06-29 05:44:12,817 [root] DEBUG: 4468: Successfully installed hook on COM Object function IWbemServices_GetObjectW
2026-06-29 05:44:12,818 [root] DEBUG: 4468: Successfully installed hook on COM Object function IWbemServices_GetObjectAsync
2026-06-29 05:44:12,819 [root] DEBUG: 4468: Successfully installed hook on COM Object function IWbemServices_ExecMethod
2026-06-29 05:44:12,821 [root] DEBUG: 4468: Successfully installed hook on COM Object function IWbemServices_ExecMethodAsync
2026-06-29 05:44:14,360 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 2868: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF712FE0000
2026-06-29 05:44:14,361 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 2868
2026-06-29 05:44:14,362 [lib.api.process] INFO: Monitor config for process 2868: C:\2_6me6uj\dll\2868.ini
2026-06-29 05:44:15,644 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:44:15,661 [root] DEBUG: Loader: Injecting process 2868 (thread 3472) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:15,663 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:44:15,664 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:15,666 [lib.api.process] INFO: Injected into 64-bit <Process 2868 WmiPrvSE.exe>
2026-06-29 05:44:15,668 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 2868
2026-06-29 05:44:15,669 [lib.api.process] INFO: Monitor config for process 2868: C:\2_6me6uj\dll\2868.ini
2026-06-29 05:44:15,930 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:44:15,941 [root] DEBUG: Loader: Injecting process 2868 (thread 3472) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:15,942 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-06-29 05:44:15,943 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:15,946 [lib.api.process] INFO: Injected into 64-bit <Process 2868 WmiPrvSE.exe>
2026-06-29 05:44:15,962 [root] DEBUG: 2868: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 05:44:15,963 [root] DEBUG: 2868: Dropped file limit defaulting to 100.
2026-06-29 05:44:15,968 [root] DEBUG: 2868: Disabling sleep skipping.
2026-06-29 05:44:15,969 [root] DEBUG: 2868: Services hook set enabled
2026-06-29 05:44:15,975 [root] DEBUG: 2868: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-29 05:44:15,996 [root] DEBUG: 2868: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 05:44:15,997 [root] DEBUG: 2868: Monitor initialised: 64-bit capemon loaded in process 2868 at 0x00007FF986960000, thread 3472, image base 0x00007FF712FE0000, stack from 0x0000001D40890000-0x0000001D408A0000
2026-06-29 05:44:15,998 [root] DEBUG: 2868: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-06-29 05:44:16,021 [root] DEBUG: 2868: Hooked 69 out of 69 functions
2026-06-29 05:44:16,031 [root] DEBUG: 2868: RestoreHeaders: Restored original import table.
2026-06-29 05:44:16,032 [root] INFO: Loaded monitor into process with pid 2868
2026-06-29 05:44:16,041 [root] DEBUG: 2868: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 05:44:16,045 [root] DEBUG: 2868: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 05:44:16,050 [root] DEBUG: 2868: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 05:44:16,055 [root] DEBUG: 2868: DLL loaded at 0x00007FF97FC40000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-06-29 05:44:16,063 [root] DEBUG: 2868: DLL loaded at 0x00007FF97FC20000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-06-29 05:44:16,084 [root] DEBUG: 2868: DLL loaded at 0x00007FF99E310000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-06-29 05:44:16,110 [root] DEBUG: 2868: DLL loaded at 0x00007FF9A7F80000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-06-29 05:44:16,111 [root] DEBUG: 2868: DLL loaded at 0x00007FF9A6E00000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-06-29 05:44:16,112 [root] DEBUG: 2868: DLL loaded at 0x00007FF9A0DA0000: C:\Windows\system32\wbem\esscli (0x7d000 bytes).
2026-06-29 05:44:16,113 [root] DEBUG: 2868: DLL loaded at 0x00007FF99E3D0000: C:\Windows\system32\wbem\stdprov (0x28000 bytes).
2026-06-29 05:44:17,049 [root] DEBUG: 4468: NtTerminateProcess hook: Attempting to dump process 4468
2026-06-29 05:44:17,050 [root] DEBUG: 4468: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 05:44:17,161 [root] INFO: Process with pid 4468 has terminated
2026-06-29 05:44:17,212 [root] INFO: Added new file to list with pid 2108 and path C:\Users\Rajesh\AppData\Local\Temp\information.txt
2026-06-29 05:44:17,294 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 05:44:17,334 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 05:44:17,387 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 05:44:17,495 [root] DEBUG: 2108: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes).
2026-06-29 05:44:17,598 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-06-29 05:44:17,611 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 05:44:17,662 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes).
2026-06-29 05:44:17,791 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-06-29 05:44:17,795 [root] DEBUG: 2108: DLL loaded at 0x00007FF993730000: C:\Windows\system32\edputil (0x24000 bytes).
2026-06-29 05:44:17,836 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-06-29 05:44:17,853 [root] DEBUG: 2108: DLL loaded at 0x00007FF9903B0000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes).
2026-06-29 05:44:17,933 [root] DEBUG: 2108: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes).
2026-06-29 05:44:17,935 [root] DEBUG: 2108: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes).
2026-06-29 05:44:17,938 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-06-29 05:44:17,941 [root] DEBUG: 2108: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes).
2026-06-29 05:44:17,951 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A7200000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-06-29 05:44:17,954 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 05:44:17,987 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\System32\wintypes (0x154000 bytes).
2026-06-29 05:44:18,002 [root] DEBUG: 2108: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes).
2026-06-29 05:44:18,003 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A6C60000: C:\Windows\System32\sppc (0x25000 bytes).
2026-06-29 05:44:18,005 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A6C90000: C:\Windows\System32\SLC (0x29000 bytes).
2026-06-29 05:44:18,008 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A7F80000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-06-29 05:44:18,009 [root] DEBUG: 2108: DLL loaded at 0x00007FF9971F0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-06-29 05:44:18,027 [root] DEBUG: 2108: DLL loaded at 0x00007FF99D480000: C:\Windows\System32\OneCoreCommonProxyStub (0x7d000 bytes).
2026-06-29 05:44:18,045 [root] DEBUG: 2108: DLL loaded at 0x00007FF99EEA0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x798000 bytes).
2026-06-29 05:44:18,075 [root] DEBUG: 2108: CreateProcessHandler: Injection info set for new process 5432: C:\Windows\system32\NOTEPAD.EXE, ImageBase: 0x00007FF737DC0000
2026-06-29 05:44:18,076 [root] INFO: Announced 64-bit process name: notepad.exe pid: 5432
2026-06-29 05:44:18,077 [lib.api.process] INFO: Monitor config for process 5432: C:\2_6me6uj\dll\5432.ini
2026-06-29 05:44:18,083 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:44:18,096 [root] DEBUG: Loader: Injecting process 5432 (thread 5436) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:18,097 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:44:18,098 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:18,101 [lib.api.process] INFO: Injected into 64-bit <Process 5432 notepad.exe>
2026-06-29 05:44:18,104 [root] INFO: Announced 64-bit process name: notepad.exe pid: 5432
2026-06-29 05:44:18,105 [lib.api.process] INFO: Monitor config for process 5432: C:\2_6me6uj\dll\5432.ini
2026-06-29 05:44:18,109 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:44:18,118 [root] DEBUG: Loader: Injecting process 5432 (thread 5436) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:18,121 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:44:18,122 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:18,124 [lib.api.process] INFO: Injected into 64-bit <Process 5432 notepad.exe>
2026-06-29 05:44:18,127 [root] DEBUG: 2108: DLL loaded at 0x00007FF998030000: C:\Windows\system32\MPR (0x1d000 bytes).
2026-06-29 05:44:18,130 [root] DEBUG: 2108: DLL loaded at 0x00007FF9A31D0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-06-29 05:44:18,167 [root] DEBUG: 5432: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 05:44:18,168 [root] DEBUG: 5432: Dropped file limit defaulting to 100.
2026-06-29 05:44:18,176 [root] DEBUG: 5432: Disabling sleep skipping.
2026-06-29 05:44:18,178 [root] DEBUG: 5432: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-29 05:44:18,198 [root] DEBUG: 5432: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 05:44:18,202 [root] DEBUG: 5432: YaraScan: Scanning 0x00007FF737DC0000, size 0x392ee
2026-06-29 05:44:18,207 [root] DEBUG: 5432: Monitor initialised: 64-bit capemon loaded in process 5432 at 0x00007FF986960000, thread 5436, image base 0x00007FF737DC0000, stack from 0x0000002E2B59F000-0x0000002E2B5B0000
2026-06-29 05:44:18,208 [root] DEBUG: 5432: Commandline: "C:\Windows\system32\NOTEPAD.EXE" C:\Users\Rajesh\AppData\Local\Temp\information.txt
2026-06-29 05:44:18,229 [root] DEBUG: 5432: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 05:44:18,279 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 05:44:18,281 [root] DEBUG: 5432: set_hooks: Unable to hook LockResource
2026-06-29 05:44:18,294 [root] DEBUG: 5432: Hooked 630 out of 631 functions
2026-06-29 05:44:18,299 [root] DEBUG: 5432: Syscall hook installed, syscall logging level 1
2026-06-29 05:44:18,307 [root] DEBUG: 5432: RestoreHeaders: Restored original import table.
2026-06-29 05:44:18,309 [root] INFO: Loaded monitor into process with pid 5432
2026-06-29 05:44:18,318 [root] DEBUG: 5432: caller_dispatch: Added region at 0x00007FF737DC0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF737DE5842, thread 5436).
2026-06-29 05:44:18,319 [root] DEBUG: 5432: YaraScan: Scanning 0x00007FF737DC0000, size 0x392ee
2026-06-29 05:44:18,325 [root] DEBUG: 5432: ProcessImageBase: Main module image at 0x00007FF737DC0000 unmodified (entropy change 0.000000e+00)
2026-06-29 05:44:18,328 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 05:44:18,334 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 05:44:18,339 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 05:44:18,345 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 05:44:18,352 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A06E0000: C:\Windows\System32\MrmCoreR (0xf5000 bytes).
2026-06-29 05:44:18,378 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes).
2026-06-29 05:44:18,379 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes).
2026-06-29 05:44:18,388 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes).
2026-06-29 05:44:18,424 [root] DEBUG: 5432: DLL loaded at 0x00007FF998F00000: C:\Windows\system32\TextShaping (0xac000 bytes).
2026-06-29 05:44:18,444 [root] DEBUG: 5432: DLL loaded at 0x00007FF998030000: C:\Windows\System32\MPR (0x1d000 bytes).
2026-06-29 05:44:18,446 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes).
2026-06-29 05:44:18,448 [root] DEBUG: 5432: DLL loaded at 0x00007FF987D80000: C:\Windows\System32\efswrt (0xde000 bytes).
2026-06-29 05:44:18,457 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A10F0000: C:\Windows\System32\twinapi.appcore (0x201000 bytes).
2026-06-29 05:44:18,552 [root] DEBUG: 5432: DLL loaded at 0x00007FF992900000: C:\Windows\System32\oleacc (0x66000 bytes).
2026-06-29 05:44:18,621 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A6E00000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-06-29 05:44:18,622 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A57F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-06-29 05:44:18,626 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A5490000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes).
2026-06-29 05:44:18,647 [root] DEBUG: 5432: DLL loaded at 0x00007FF99BC00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-06-29 05:44:18,686 [root] DEBUG: 5432: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes).
2026-06-29 05:44:18,689 [root] DEBUG: 5432: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes).
2026-06-29 05:44:18,690 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-06-29 05:44:18,698 [root] DEBUG: 5432: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes).
2026-06-29 05:44:18,720 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A9450000: C:\Windows\System32\COMDLG32 (0xda000 bytes).
2026-06-29 05:44:18,728 [root] DEBUG: 5432: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-06-29 05:44:23,230 [root] DEBUG: 2108: NtTerminateProcess hook: Attempting to dump process 2108
2026-06-29 05:44:23,234 [root] DEBUG: 2108: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching
2026-06-29 05:44:23,248 [root] DEBUG: 2108: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000.
2026-06-29 05:44:23,250 [root] DEBUG: 2108: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-06-29 05:44:23,251 [root] DEBUG: 2108: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000.
2026-06-29 05:44:23,254 [root] DEBUG: 2108: DumpProcess: Module entry point VA is 0x00007FF79A468F50.
2026-06-29 05:44:23,275 [lib.common.results] INFO: Uploading file C:\ngIpjVKr\CAPE\2108_1053723441229162026 to procdump\238cf97018bf3c257a80f8509fc1efce6ac4a8bf5ff3a07dfbbdff994135f05f; Size is 403456; Max size: 100000000
2026-06-29 05:44:23,287 [root] DEBUG: 2108: DumpProcess: Module image dump success - dump size 0x62800.
2026-06-29 05:44:23,310 [root] INFO: Process with pid 2108 has terminated
2026-06-29 05:44:23,392 [root] DEBUG: 3636: NtTerminateProcess hook: Attempting to dump process 3636
2026-06-29 05:44:23,394 [root] DEBUG: 3636: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching
2026-06-29 05:44:23,396 [root] DEBUG: 3636: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000.
2026-06-29 05:44:23,397 [root] DEBUG: 3636: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-06-29 05:44:23,400 [root] DEBUG: 3636: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000.
2026-06-29 05:44:23,402 [root] DEBUG: 3636: DumpProcess: Module entry point VA is 0x00007FF79A468F50.
2026-06-29 05:44:23,411 [lib.common.results] INFO: Uploading file C:\ngIpjVKr\CAPE\3636_48993823441229162026 to procdump\87fc8ef8bc1a66ad7ebff4fa1fda65a6e8a58b6776da2bc87d16a0b8e29b097a; Size is 401920; Max size: 100000000
2026-06-29 05:44:23,421 [root] DEBUG: 3636: DumpProcess: Module image dump success - dump size 0x62200.
2026-06-29 05:44:23,440 [root] INFO: Process with pid 3636 has terminated
2026-06-29 05:44:46,391 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 5760: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6F8BE0000
2026-06-29 05:44:46,394 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5760
2026-06-29 05:44:46,397 [lib.api.process] INFO: Monitor config for process 5760: C:\2_6me6uj\dll\5760.ini
2026-06-29 05:44:46,421 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:44:46,440 [root] DEBUG: Loader: Injecting process 5760 (thread 4664) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:46,442 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:44:46,445 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:46,451 [lib.api.process] INFO: Injected into 64-bit <Process 5760 dllhost.exe>
2026-06-29 05:44:46,454 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5760
2026-06-29 05:44:46,455 [lib.api.process] INFO: Monitor config for process 5760: C:\2_6me6uj\dll\5760.ini
2026-06-29 05:44:46,467 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:44:46,485 [root] DEBUG: Loader: Injecting process 5760 (thread 4664) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:46,487 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:44:46,488 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:44:46,500 [lib.api.process] INFO: Injected into 64-bit <Process 5760 dllhost.exe>
2026-06-29 05:44:46,516 [root] DEBUG: 5760: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 05:44:46,517 [root] DEBUG: 5760: Dropped file limit defaulting to 100.
2026-06-29 05:44:46,535 [root] DEBUG: 5760: Disabling sleep skipping.
2026-06-29 05:44:46,546 [root] DEBUG: 5760: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-29 05:44:46,571 [root] DEBUG: 5760: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 05:44:46,576 [root] DEBUG: 5760: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 05:44:46,578 [root] DEBUG: 5760: Monitor initialised: 64-bit capemon loaded in process 5760 at 0x00007FF986960000, thread 4664, image base 0x00007FF6F8BE0000, stack from 0x000000AE04D44000-0x000000AE04D50000
2026-06-29 05:44:46,580 [root] DEBUG: 5760: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-06-29 05:44:46,702 [root] DEBUG: 5760: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 05:44:47,008 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 05:44:47,231 [root] DEBUG: 5760: set_hooks: Unable to hook LockResource
2026-06-29 05:44:47,278 [root] DEBUG: 5760: Hooked 630 out of 631 functions
2026-06-29 05:44:47,296 [root] DEBUG: 5760: Syscall hook installed, syscall logging level 1
2026-06-29 05:44:47,314 [root] DEBUG: 5760: RestoreHeaders: Restored original import table.
2026-06-29 05:44:47,315 [root] INFO: Loaded monitor into process with pid 5760
2026-06-29 05:44:47,317 [root] DEBUG: 5760: caller_dispatch: Added region at 0x00007FF6F8BE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F8BE12F2, thread 4664).
2026-06-29 05:44:47,329 [root] DEBUG: 5760: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 05:44:47,332 [root] DEBUG: 5760: ProcessImageBase: Main module image at 0x00007FF6F8BE0000 unmodified (entropy change 0.000000e+00)
2026-06-29 05:44:47,344 [root] DEBUG: 5760: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 05:44:47,348 [root] DEBUG: 5760: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 05:44:47,362 [root] DEBUG: 5760: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 05:44:47,395 [root] DEBUG: 5760: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 05:44:47,438 [root] DEBUG: 5760: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\shcore (0xad000 bytes).
2026-06-29 05:44:47,442 [root] DEBUG: 5760: DLL loaded at 0x00007FF992850000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-06-29 05:44:47,457 [root] DEBUG: 5760: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-06-29 05:44:52,532 [root] INFO: Process with pid 5760 has terminated
2026-06-29 05:44:52,534 [root] DEBUG: 5760: NtTerminateProcess hook: Attempting to dump process 5760
2026-06-29 05:44:52,536 [root] DEBUG: 5760: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 05:45:15,890 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 4440: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF620BA0000
2026-06-29 05:45:15,894 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 4440
2026-06-29 05:45:15,896 [lib.api.process] INFO: Monitor config for process 4440: C:\2_6me6uj\dll\4440.ini
2026-06-29 05:45:17,954 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:45:17,973 [root] DEBUG: Loader: Injecting process 4440 (thread 4536) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:17,975 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:45:17,976 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:17,982 [lib.api.process] INFO: Injected into 64-bit <Process 4440 ShellExperienceHost.exe>
2026-06-29 05:45:17,986 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 4440
2026-06-29 05:45:17,988 [lib.api.process] INFO: Monitor config for process 4440: C:\2_6me6uj\dll\4440.ini
2026-06-29 05:45:19,501 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:45:19,520 [root] DEBUG: Loader: Injecting process 4440 (thread 4536) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:19,522 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:45:19,523 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:19,530 [lib.api.process] INFO: Injected into 64-bit <Process 4440 ShellExperienceHost.exe>
2026-06-29 05:45:19,534 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 4440
2026-06-29 05:45:19,535 [lib.api.process] INFO: Monitor config for process 4440: C:\2_6me6uj\dll\4440.ini
2026-06-29 05:45:21,339 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:45:21,358 [root] DEBUG: Loader: Injecting process 4440 with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:21,376 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 4536, handle 0x10c
2026-06-29 05:45:21,378 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-06-29 05:45:21,379 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:21,388 [lib.api.process] INFO: Injected into 64-bit <Process 4440 ShellExperienceHost.exe>
2026-06-29 05:45:44,366 [root] DEBUG: 2868: NtTerminateProcess hook: Attempting to dump process 2868
2026-06-29 05:45:44,368 [root] DEBUG: 2868: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 05:45:44,374 [root] INFO: Process with pid 2868 has terminated
2026-06-29 05:45:47,998 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 3904: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6F8BE0000
2026-06-29 05:45:48,179 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3904
2026-06-29 05:45:48,195 [lib.api.process] INFO: Monitor config for process 3904: C:\2_6me6uj\dll\3904.ini
2026-06-29 05:45:48,205 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:45:48,220 [root] DEBUG: Loader: Injecting process 3904 (thread 4108) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:48,223 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:45:48,224 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:48,230 [lib.api.process] INFO: Injected into 64-bit <Process 3904 dllhost.exe>
2026-06-29 05:45:48,234 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3904
2026-06-29 05:45:48,237 [lib.api.process] INFO: Monitor config for process 3904: C:\2_6me6uj\dll\3904.ini
2026-06-29 05:45:48,244 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\pKwfPInu.dll, loader C:\2_6me6uj\bin\QfFFmdso.exe
2026-06-29 05:45:48,258 [root] DEBUG: Loader: Injecting process 3904 (thread 4108) with C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:48,260 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 05:45:48,261 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\pKwfPInu.dll.
2026-06-29 05:45:48,266 [lib.api.process] INFO: Injected into 64-bit <Process 3904 dllhost.exe>
2026-06-29 05:45:48,282 [root] DEBUG: 3904: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 05:45:48,284 [root] DEBUG: 3904: Dropped file limit defaulting to 100.
2026-06-29 05:45:48,289 [root] DEBUG: 3904: Disabling sleep skipping.
2026-06-29 05:45:48,295 [root] DEBUG: 3904: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-29 05:45:48,318 [root] DEBUG: 3904: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 05:45:48,321 [root] DEBUG: 3904: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 05:45:48,324 [root] DEBUG: 3904: Monitor initialised: 64-bit capemon loaded in process 3904 at 0x00007FF986960000, thread 4108, image base 0x00007FF6F8BE0000, stack from 0x0000009DE78F4000-0x0000009DE7900000
2026-06-29 05:45:48,327 [root] DEBUG: 3904: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-06-29 05:45:48,343 [root] DEBUG: 3904: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 05:45:48,394 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 05:45:48,395 [root] DEBUG: 3904: set_hooks: Unable to hook LockResource
2026-06-29 05:45:48,409 [root] DEBUG: 3904: Hooked 630 out of 631 functions
2026-06-29 05:45:48,412 [root] DEBUG: 3904: Syscall hook installed, syscall logging level 1
2026-06-29 05:45:48,423 [root] DEBUG: 3904: RestoreHeaders: Restored original import table.
2026-06-29 05:45:48,424 [root] INFO: Loaded monitor into process with pid 3904
2026-06-29 05:45:48,428 [root] DEBUG: 3904: caller_dispatch: Added region at 0x00007FF6F8BE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F8BE12F2, thread 4108).
2026-06-29 05:45:48,429 [root] DEBUG: 3904: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 05:45:48,433 [root] DEBUG: 3904: ProcessImageBase: Main module image at 0x00007FF6F8BE0000 unmodified (entropy change 0.000000e+00)
2026-06-29 05:45:48,439 [root] DEBUG: 3904: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 05:45:48,443 [root] DEBUG: 3904: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 05:45:48,450 [root] DEBUG: 3904: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 05:45:48,482 [root] DEBUG: 3904: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 05:45:48,515 [root] DEBUG: 3904: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\shcore (0xad000 bytes).
2026-06-29 05:45:48,517 [root] DEBUG: 3904: DLL loaded at 0x00007FF992850000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-06-29 05:45:48,582 [root] DEBUG: 3904: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-06-29 05:45:53,882 [root] INFO: Process with pid 3904 has terminated
2026-06-29 05:45:53,885 [root] DEBUG: 3904: NtTerminateProcess hook: Attempting to dump process 3904
2026-06-29 05:45:53,887 [root] DEBUG: 3904: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 05:47:27,753 [root] INFO: Analysis timeout hit, terminating analysis
2026-06-29 05:47:27,757 [lib.api.process] INFO: Terminate event set for process 756
2026-06-29 05:47:27,758 [root] DEBUG: 756: Terminate Event: Attempting to dump process 756
2026-06-29 05:47:27,760 [root] DEBUG: 756: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 05:47:27,766 [lib.api.process] INFO: Termination confirmed for process 756
2026-06-29 05:47:27,766 [root] INFO: Terminate event set for process 756
2026-06-29 05:47:27,767 [root] DEBUG: 756: Terminate Event: monitor shutdown complete for process 756
2026-06-29 05:47:27,769 [lib.api.process] INFO: Terminate event set for process 3036
2026-06-29 05:47:27,770 [root] DEBUG: 3036: Terminate Event: Attempting to dump process 3036
2026-06-29 05:47:27,772 [root] DEBUG: 3036: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 05:47:27,776 [lib.api.process] INFO: Termination confirmed for process 3036
2026-06-29 05:47:27,777 [root] INFO: Terminate event set for process 3036
2026-06-29 05:47:27,777 [lib.api.process] INFO: Terminate event set for process 5432
2026-06-29 05:47:27,779 [root] DEBUG: 3036: Terminate Event: monitor shutdown complete for process 3036
2026-06-29 05:47:27,783 [root] DEBUG: 5432: Terminate Event: Attempting to dump process 5432
2026-06-29 05:47:27,788 [root] DEBUG: 5432: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 05:47:27,802 [root] DEBUG: 5432: Terminate Event: Shutdown complete for process 5432 but failed to inform analyzer.
2026-06-29 05:47:32,783 [lib.api.process] INFO: Termination confirmed for process 5432
2026-06-29 05:47:32,784 [root] INFO: Terminate event set for process 5432
2026-06-29 05:47:32,786 [root] INFO: Created shutdown mutex
2026-06-29 05:47:33,787 [root] INFO: Shutting down package
2026-06-29 05:47:33,788 [root] INFO: Stopping auxiliary modules
2026-06-29 05:47:33,789 [root] INFO: Stopping auxiliary module: Browser
2026-06-29 05:47:33,790 [root] INFO: Stopping auxiliary module: Human
2026-06-29 05:47:34,820 [root] INFO: Stopping auxiliary module: Screenshots
2026-06-29 05:47:34,821 [root] INFO: Finishing auxiliary modules
2026-06-29 05:47:34,822 [root] INFO: Shutting down pipe server and dumping dropped files
2026-06-29 05:47:34,828 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Temp\information.txt to files\1579f6235bdcda8ced8fb6c161a9cfa55c8dddca53970f9683236c9ceca581c3; Size is 2365; Max size: 100000000
2026-06-29 05:47:34,835 [root] WARNING: Folder at path "C:\ngIpjVKr\debugger" does not exist, skipping
2026-06-29 05:47:34,836 [root] WARNING: Folder at path "C:\ngIpjVKr\tlsdump" does not exist, skipping
2026-06-29 05:47:34,909 [root] WARNING: Monitor injection attempted but failed for process 4440
2026-06-29 05:47:34,910 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-29 12:43:43 | 2026-06-29 12:47:36 | internet |
| File Name |
test.bat
|
|---|---|
| File Type | ASCII text, with CRLF line terminators |
| File Size | 51 bytes |
| MD5 | 3c81be5e67ce4c4974231d6a8dd5746e |
| SHA1 | ad8f07c8528442ce0a9f4fce436ed795fdd0f924 |
| SHA256 | d5adc813fc59eb3112da0876d52643faf3b0ed8c54ae2ef70048269e683ce21e VT MWDB Bazaar |
| SHA3-384 | 9935c3f25f3cb57d9c15241ab33c52cd863acb88f465121be1f5c5c9ef6546685924b394179aeac5992d524098fa7e83 |
| CRC32 | 5565FD64 |
| TLSH | T1D8900293DD014A473C121B02928311014A2110063008E43A0C418481540EC012317A14 |
| Ssdeep | 3:gh2Z4MKLL7zYXI4MKLL7R:gh26MKjzGPMKjR |
systeminfo > information.txt start information.txt
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 173.194.76.94 [VT] | unknown | - |
| Y | 108.177.15.139 [VT] | unknown | - |
| Y | 40.126.31.131 [VT] | unknown | - |
| Y | 108.177.15.94 [VT] | unknown | - |
| Y | 74.125.206.84 [VT] | unknown | - |
| Y | 66.102.1.138 [VT] | unknown | - |
| Y | 74.125.206.138 [VT] | unknown | - |
| Y | 74.125.133.95 [VT] | unknown | - |
| Y | 142.251.150.119 [VT] | unknown | - |
| Y | 142.251.168.139 [VT] | unknown | - |
| Y | 142.251.168.100 [VT] | unknown | - |
| Y | 74.125.206.101 [VT] | unknown | - |
| Y | 74.125.71.94 [VT] | unknown | - |
| Y | 142.251.16.94 [VT] | unknown | - |
No results found.
No behavioral analysis data available.
No dropped files found.