| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| FILE | ie | 2026-06-29 16:59:59 | 2026-06-29 17:03:59 | 240s |
|
|||||
| Reports | JSON | |||||||||
vnc_port=5900
2026-06-29 14:58:59,799 [root] INFO: Date set to: 20260629T17:00:04, timeout set to: 200
2026-06-29 17:00:04,481 [root] DEBUG: Starting analyzer from: C:\2_6me6uj
2026-06-29 17:00:04,482 [root] DEBUG: Storing results at: C:\awPTaE
2026-06-29 17:00:04,482 [root] DEBUG: Pipe server name: \\.\PIPE\IHxHLw
2026-06-29 17:00:04,483 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314
2026-06-29 17:00:04,483 [root] INFO: analysis running as an admin
2026-06-29 17:00:04,483 [root] INFO: analysis package specified: "ie"
2026-06-29 17:00:04,483 [root] DEBUG: importing analysis package module: "modules.packages.ie"...
2026-06-29 17:00:04,489 [root] DEBUG: imported analysis package "ie"
2026-06-29 17:00:04,489 [root] DEBUG: initializing analysis package "ie"...
2026-06-29 17:00:04,489 [lib.common.common] INFO: no wrapping
2026-06-29 17:00:04,490 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-29 17:00:04,490 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\philip website fixed.html
2026-06-29 17:00:04,491 [root] INFO: Analyzer: Package modules.packages.ie does not specify a dll option
2026-06-29 17:00:04,491 [root] INFO: Analyzer: Package modules.packages.ie does not specify a dll_64 option
2026-06-29 17:00:04,491 [root] INFO: Analyzer: Package modules.packages.ie does not specify a loader option
2026-06-29 17:00:04,491 [root] INFO: Analyzer: Package modules.packages.ie does not specify a loader_64 option
2026-06-29 17:00:04,565 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-06-29 17:00:04,576 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-06-29 17:00:04,623 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-06-29 17:00:04,732 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-06-29 17:00:04,741 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-06-29 17:00:04,742 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-06-29 17:00:04,742 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-06-29 17:00:04,745 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-06-29 17:00:04,746 [root] DEBUG: Initialized auxiliary module "Browser"
2026-06-29 17:00:04,746 [root] DEBUG: attempting to configure 'Browser' from data
2026-06-29 17:00:04,747 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-06-29 17:00:04,747 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-06-29 17:00:05,046 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-06-29 17:00:05,049 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-06-29 17:00:05,050 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-06-29 17:00:05,051 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-06-29 17:00:05,052 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-06-29 17:00:05,052 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-06-29 17:00:06,150 [modules.auxiliary.digisig] DEBUG: File has an invalid signature
2026-06-29 17:00:06,153 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-06-29 17:00:06,155 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-06-29 17:00:06,156 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-06-29 17:00:06,157 [root] DEBUG: attempting to configure 'Disguise' from data
2026-06-29 17:00:06,158 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-06-29 17:00:06,158 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-06-29 17:00:06,209 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 2572)
2026-06-29 17:00:06,215 [modules.auxiliary.disguise] INFO: Disguising GUID to 2c8831e9-979c-4d9d-afc1-62a35d46c3e1
2026-06-29 17:00:06,216 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-06-29 17:00:06,216 [root] DEBUG: Initialized auxiliary module "Human"
2026-06-29 17:00:06,216 [root] DEBUG: attempting to configure 'Human' from data
2026-06-29 17:00:06,217 [root] DEBUG: module Human does not support data configuration, ignoring
2026-06-29 17:00:06,217 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-06-29 17:00:06,241 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-06-29 17:00:06,241 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-06-29 17:00:06,241 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-06-29 17:00:06,242 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-06-29 17:00:06,242 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-06-29 17:00:06,247 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-06-29 17:00:06,247 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-06-29 17:00:06,248 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-06-29 17:00:06,248 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-06-29 17:00:06,249 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-06-29 17:00:06,250 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-06-29 17:00:06,260 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-06-29 17:00:06,260 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-06-29 17:00:12,090 [root] INFO: Restarting WMI Service
2026-06-29 17:00:14,279 [root] DEBUG: package modules.packages.ie does not support configure, ignoring
2026-06-29 17:00:14,376 [root] WARNING: configuration error for package modules.packages.ie: error importing data.packages.ie: No module named 'data.packages'
2026-06-29 17:00:14,380 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-29 17:00:14,398 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files (x86)\Internet Explorer\iexplore.exe" with arguments ""C:\Users\Rajesh\AppData\Local\Temp\philip website fixed.html"" with pid 3864
2026-06-29 17:00:14,398 [lib.api.process] INFO: Monitor config for process 3864: C:\2_6me6uj\dll\3864.ini
2026-06-29 17:00:15,540 [lib.api.process] INFO: Potential dll side-loading detected in local directory: sqmapi.dll
2026-06-29 17:00:15,544 [lib.api.process] INFO: 32-bit DLL to inject is C:\2_6me6uj\dll\HGoNKVTL.dll, loader C:\2_6me6uj\bin\aRJrkFV.exe
2026-06-29 17:00:15,576 [root] DEBUG: Loader: Injecting process 3864 (thread 2716) with C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:00:15,579 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 17:00:15,581 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:00:15,584 [lib.api.process] INFO: Injected into 32-bit <Process 3864 iexplore.exe>
2026-06-29 17:00:17,596 [lib.api.process] INFO: Successfully resumed process with pid 3864
2026-06-29 17:00:17,636 [root] DEBUG: 3864: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 17:00:17,639 [root] DEBUG: 3864: Disabling sleep skipping.
2026-06-29 17:00:17,641 [root] DEBUG: 3864: Dropped file limit defaulting to 100.
2026-06-29 17:00:17,645 [root] DEBUG: 3864: Internet Explorer-specific hook-set enabled.
2026-06-29 17:00:17,657 [root] DEBUG: 3864: Monitor initialised: 32-bit capemon loaded in process 3864 at 0x74330000, thread 2716, image base 0x40000, stack from 0x2bb2000-0x2bc0000
2026-06-29 17:00:17,658 [root] DEBUG: 3864: Commandline: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" "C:\Users\Rajesh\AppData\Local\Temp\philip website fixed.html"
2026-06-29 17:00:17,683 [root] DEBUG: 3864: Hooked 64 out of 64 functions
2026-06-29 17:00:17,713 [root] DEBUG: 3864: Syscall hook installed, syscall logging level 1
2026-06-29 17:00:17,721 [root] DEBUG: 3864: RestoreHeaders: Restored original import table.
2026-06-29 17:00:17,722 [root] INFO: Loaded monitor into process with pid 3864
2026-06-29 17:00:17,725 [root] DEBUG: 3864: caller_dispatch: Added region at 0x00040000 to tracked regions list (ntdll::NtClose returns to 0x00043933, thread 2716).
2026-06-29 17:00:17,727 [root] DEBUG: 3864: ProcessImageBase: Main module image at 0x00040000 unmodified (entropy change 0.000000e+00)
2026-06-29 17:00:17,728 [root] DEBUG: 3864: DLL loaded at 0x769D0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-06-29 17:00:17,734 [root] DEBUG: 3864: DLL loaded at 0x74070000: C:\Windows\SYSTEM32\msIso (0x43000 bytes).
2026-06-29 17:00:17,742 [root] DEBUG: 3864: DLL loaded at 0x74CF0000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-06-29 17:00:17,753 [root] DEBUG: 3864: DLL loaded at 0x746B0000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-06-29 17:00:17,754 [root] DEBUG: 3864: DLL loaded at 0x746E0000: C:\Windows\SYSTEM32\windows.storage (0x608000 bytes).
2026-06-29 17:00:17,758 [root] DEBUG: 3864: CreateProcessHandler: Injection info set for new process 1812: C:\Program Files\Internet Explorer\IEXPLORE.EXE, ImageBase: 0x00000000
2026-06-29 17:00:17,987 [root] INFO: Announced 64-bit process name: iexplore.exe pid: 1812
2026-06-29 17:00:17,988 [lib.api.process] INFO: Monitor config for process 1812: C:\2_6me6uj\dll\1812.ini
2026-06-29 17:00:18,246 [lib.api.process] INFO: Potential dll side-loading detected in local directory: sqmapi.dll
2026-06-29 17:00:18,249 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\QbfJqv.dll, loader C:\2_6me6uj\bin\OTwbRAmw.exe
2026-06-29 17:00:18,266 [root] DEBUG: Loader: Injecting process 1812 (thread 3832) with C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:18,267 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 17:00:18,268 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:18,270 [lib.api.process] INFO: Injected into 64-bit <Process 1812 iexplore.exe>
2026-06-29 17:00:18,275 [root] INFO: Announced 64-bit process name: iexplore.exe pid: 1812
2026-06-29 17:00:18,276 [lib.api.process] INFO: Monitor config for process 1812: C:\2_6me6uj\dll\1812.ini
2026-06-29 17:00:18,531 [lib.api.process] INFO: Potential dll side-loading detected in local directory: sqmapi.dll
2026-06-29 17:00:18,565 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\QbfJqv.dll, loader C:\2_6me6uj\bin\OTwbRAmw.exe
2026-06-29 17:00:18,578 [root] DEBUG: Loader: Injecting process 1812 with C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:18,579 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 3832, handle 0x9c
2026-06-29 17:00:18,580 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 17:00:18,581 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:18,584 [lib.api.process] INFO: Injected into 64-bit <Process 1812 iexplore.exe>
2026-06-29 17:00:18,611 [root] DEBUG: 1812: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 17:00:18,612 [root] DEBUG: 1812: Dropped file limit defaulting to 100.
2026-06-29 17:00:18,618 [root] DEBUG: 1812: Internet Explorer-specific hook-set enabled.
2026-06-29 17:00:18,623 [root] DEBUG: 1812: Disabling sleep skipping.
2026-06-29 17:00:18,673 [root] DEBUG: 1812: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 17:00:18,674 [root] DEBUG: 1812: Monitor initialised: 64-bit capemon loaded in process 1812 at 0x00007FF987A90000, thread 3832, image base 0x00007FF6847E0000, stack from 0x000000CA144F1000-0x000000CA14500000
2026-06-29 17:00:18,675 [root] DEBUG: 1812: Commandline: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" "C:\Users\Rajesh\AppData\Local\Temp\philip website fixed.html"
2026-06-29 17:00:18,696 [root] DEBUG: 1812: Hooked 63 out of 63 functions
2026-06-29 17:00:18,728 [root] DEBUG: 1812: Syscall hook installed, syscall logging level 1
2026-06-29 17:00:18,742 [root] DEBUG: 1812: RestoreHeaders: Restored original import table.
2026-06-29 17:00:18,744 [root] INFO: Loaded monitor into process with pid 1812
2026-06-29 17:00:18,747 [root] DEBUG: 1812: caller_dispatch: Added region at 0x00007FF6847E0000 to tracked regions list (ntdll::NtClose returns to 0x00007FF6847E2177, thread 3832).
2026-06-29 17:00:18,749 [root] DEBUG: 1812: ProcessImageBase: Main module image at 0x00007FF6847E0000 unmodified (entropy change 0.000000e+00)
2026-06-29 17:00:18,750 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 17:00:18,753 [root] DEBUG: 1812: DLL loaded at 0x00007FF99E3A0000: C:\Windows\SYSTEM32\msIso (0x54000 bytes).
2026-06-29 17:00:18,759 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 17:00:18,777 [root] DEBUG: 1812: DLL loaded at 0x00007FF99E260000: C:\Windows\SYSTEM32\NETAPI32 (0x18000 bytes).
2026-06-29 17:00:18,778 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A3240000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2026-06-29 17:00:18,779 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7F80000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-06-29 17:00:18,780 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A1C10000: C:\Windows\SYSTEM32\WINHTTP (0x108000 bytes).
2026-06-29 17:00:18,781 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7290000: C:\Windows\SYSTEM32\WKSCLI (0x17000 bytes).
2026-06-29 17:00:18,783 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A75F0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2026-06-29 17:00:18,784 [root] DEBUG: 1812: DLL loaded at 0x00007FF986850000: C:\Windows\SYSTEM32\IEFRAME (0x757000 bytes).
2026-06-29 17:00:18,798 [root] DEBUG: 1812: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes).
2026-06-29 17:00:18,810 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 17:00:18,827 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 17:00:18,850 [root] DEBUG: 1812: DLL loaded at 0x00007FF99DFE0000: C:\Program Files\Internet Explorer\IEShims (0x6e000 bytes).
2026-06-29 17:00:18,867 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A9450000: C:\Windows\System32\comdlg32 (0xda000 bytes).
2026-06-29 17:00:18,885 [root] DEBUG: 1812: DLL loaded at 0x00007FF99F650000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-06-29 17:00:18,886 [root] DEBUG: 1812: DLL loaded at 0x00007FF99F930000: C:\Windows\SYSTEM32\urlmon (0x1eb000 bytes).
2026-06-29 17:00:18,894 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes).
2026-06-29 17:00:18,907 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A74E0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-06-29 17:00:18,911 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A9D20000: C:\Windows\System32\NSI (0x8000 bytes).
2026-06-29 17:00:18,914 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A32B0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-06-29 17:00:18,917 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A3290000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-06-29 17:00:18,946 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A77F0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-06-29 17:00:18,968 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7520000: C:\Windows\SYSTEM32\DNSAPI (0xcc000 bytes).
2026-06-29 17:00:18,977 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7200000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-06-29 17:00:18,979 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A79E0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-06-29 17:00:18,980 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A14B0000: C:\Windows\SYSTEM32\DSREG (0x13f000 bytes).
2026-06-29 17:00:18,982 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A1660000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-06-29 17:00:18,998 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A24D0000: C:\Windows\System32\fwpuclnt (0x7f000 bytes).
2026-06-29 17:00:19,002 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A8050000: C:\Windows\SYSTEM32\profapi (0x1f000 bytes).
2026-06-29 17:00:19,009 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C60000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-06-29 17:00:19,011 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C90000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-06-29 17:00:19,027 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7A90000: C:\Windows\SYSTEM32\Wldp (0x2c000 bytes).
2026-06-29 17:00:19,029 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes).
2026-06-29 17:00:19,049 [root] DEBUG: 1812: DLL loaded at 0x00007FF998780000: C:\Windows\SYSTEM32\WININET (0x4d0000 bytes).
2026-06-29 17:00:19,152 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A2820000: C:\Windows\SYSTEM32\XmlLite (0x36000 bytes).
2026-06-29 17:00:19,155 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6A00000: C:\Windows\SYSTEM32\DXGI (0xf4000 bytes).
2026-06-29 17:00:19,161 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A5C40000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-06-29 17:00:19,201 [root] DEBUG: 1812: DLL loaded at 0x00007FF988F00000: C:\Windows\SYSTEM32\ieapfltr (0xe0000 bytes).
2026-06-29 17:00:19,224 [root] DEBUG: 1812: DLL loaded at 0x00007FF989CD0000: C:\Windows\System32\ieproxy (0xde000 bytes).
2026-06-29 17:00:19,394 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C60000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-06-29 17:00:19,398 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C90000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-06-29 17:00:19,410 [root] DEBUG: 1812: DLL loaded at 0x00007FF994900000: C:\Windows\SYSTEM32\ondemandconnroutehelper (0x17000 bytes).
2026-06-29 17:00:19,448 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A3330000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-06-29 17:00:19,457 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-06-29 17:00:19,464 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-06-29 17:00:19,501 [root] DEBUG: 1812: CreateProcessHandler: Injection info set for new process 1428: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE, ImageBase: 0x0000000000040000
2026-06-29 17:00:19,502 [root] DEBUG: 1812: ProcessMessage: Skipping monitoring process 1428
2026-06-29 17:00:19,505 [root] DEBUG: 1812: ProcessMessage: Skipping monitoring process 1428
2026-06-29 17:00:19,508 [root] INFO: Announced 32-bit process name: iexplore.exe pid: 1428
2026-06-29 17:00:19,509 [lib.api.process] INFO: Monitor config for process 1428: C:\2_6me6uj\dll\1428.ini
2026-06-29 17:00:19,747 [lib.api.process] INFO: Potential dll side-loading detected in local directory: sqmapi.dll
2026-06-29 17:00:19,748 [lib.api.process] INFO: 32-bit DLL to inject is C:\2_6me6uj\dll\HGoNKVTL.dll, loader C:\2_6me6uj\bin\aRJrkFV.exe
2026-06-29 17:00:19,762 [root] DEBUG: Loader: Injecting process 1428 with C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:00:19,763 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed (SessionId=2).
2026-06-29 17:00:19,764 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:00:19,778 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7170000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-06-29 17:00:19,785 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C60000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-06-29 17:00:19,791 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C90000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-06-29 17:00:19,830 [root] DEBUG: 1812: DLL loaded at 0x00007FF989620000: C:\Windows\SYSTEM32\IEUI (0x91000 bytes).
2026-06-29 17:00:19,870 [root] DEBUG: 3864: NtTerminateProcess hook: Attempting to dump process 3864
2026-06-29 17:00:20,029 [root] INFO: Announced 64-bit process name: explorer.exe pid: 2892
2026-06-29 17:00:20,060 [lib.api.process] INFO: Monitor config for process 2892: C:\2_6me6uj\dll\2892.ini
2026-06-29 17:00:20,063 [root] DEBUG: 3864: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 17:00:20,143 [root] DEBUG: 1812: DLL loaded at 0x00007FF991890000: C:\Windows\system32\mssprxy (0x28000 bytes).
2026-06-29 17:00:20,190 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\QbfJqv.dll, loader C:\2_6me6uj\bin\OTwbRAmw.exe
2026-06-29 17:00:20,193 [root] INFO: Process with pid 3864 has terminated
2026-06-29 17:00:20,252 [root] DEBUG: 1812: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\windowscodecs (0x1b4000 bytes).
2026-06-29 17:00:20,317 [root] DEBUG: 1812: DLL loaded at 0x00007FF992900000: C:\Windows\System32\oleacc (0x66000 bytes).
2026-06-29 17:00:20,403 [root] DEBUG: Loader: Injecting process 2892 with C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:20,436 [root] DEBUG: 2892: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 17:00:20,453 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\Favorites\Bing.url
2026-06-29 17:00:20,487 [root] DEBUG: 2892: Dropped file limit defaulting to 100.
2026-06-29 17:00:20,543 [root] DEBUG: 2892: Disabling sleep skipping.
2026-06-29 17:00:20,584 [root] DEBUG: 2892: YaraInit: Compiled 44 rule files
2026-06-29 17:00:20,590 [root] DEBUG: 2892: YaraInit: Compiled rules saved to file C:\2_6me6uj\data\yara\capemon.yac
2026-06-29 17:00:20,616 [root] DEBUG: 2892: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 17:00:20,618 [root] DEBUG: 2892: YaraScan: Scanning 0x00007FF66FFC0000, size 0x49c0a4
2026-06-29 17:00:20,701 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6A00000: C:\Windows\system32\dxgi (0xf4000 bytes).
2026-06-29 17:00:20,714 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A43A0000: C:\Windows\system32\d3d11 (0x264000 bytes).
2026-06-29 17:00:20,718 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A4BD0000: C:\Windows\system32\dcomp (0x1e5000 bytes).
2026-06-29 17:00:20,723 [root] DEBUG: 1812: DLL loaded at 0x00007FF9928C0000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-06-29 17:00:20,733 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A10F0000: C:\Windows\system32\twinapi.appcore (0x201000 bytes).
2026-06-29 17:00:20,773 [root] DEBUG: 2892: Monitor initialised: 64-bit capemon loaded in process 2892 at 0x00007FF987A90000, thread 1396, image base 0x00007FF66FFC0000, stack from 0x0000000003591000-0x00000000035A0000
2026-06-29 17:00:20,775 [root] DEBUG: 2892: Commandline: C:\Windows\Explorer.EXE
2026-06-29 17:00:20,795 [root] DEBUG: 2892: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 17:00:20,855 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 17:00:20,858 [root] DEBUG: 2892: set_hooks: Unable to hook LockResource
2026-06-29 17:00:20,884 [root] DEBUG: 1812: DLL loaded at 0x00007FF998F00000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2026-06-29 17:00:20,929 [root] DEBUG: 2892: Hooked 630 out of 631 functions
2026-06-29 17:00:20,974 [root] DEBUG: 2892: Syscall hook installed, syscall logging level 1
2026-06-29 17:00:20,983 [root] INFO: Loaded monitor into process with pid 2892
2026-06-29 17:00:20,995 [root] DEBUG: 2892: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-06-29 17:00:20,998 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-29 17:00:21,001 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:21,005 [lib.api.process] INFO: Injected into 64-bit <Process 2892 explorer.exe>
2026-06-29 17:00:21,017 [root] DEBUG: 1812: DLL loaded at 0x00007FF9AA490000: C:\Windows\System32\coml2 (0x79000 bytes).
2026-06-29 17:00:21,051 [root] DEBUG: 2892: caller_dispatch: Added region at 0x00007FF66FFC0000 to tracked regions list (user32::GetSystemMetrics returns to 0x00007FF67002EB15, thread 1304).
2026-06-29 17:00:21,092 [root] DEBUG: 2892: YaraScan: Scanning 0x00007FF66FFC0000, size 0x49c0a4
2026-06-29 17:00:21,169 [root] DEBUG: 2892: ProcessImageBase: Main module image at 0x00007FF66FFC0000 unmodified (entropy change 0.000000e+00)
2026-06-29 17:00:21,268 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 1812, handle 0x10f0: C:\Program Files\Internet Explorer\iexplore.exe
2026-06-29 17:00:21,551 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A5F20000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2026-06-29 17:00:21,816 [root] DEBUG: 1812: DLL loaded at 0x00007FF992630000: C:\Windows\system32\explorerframe (0x220000 bytes).
2026-06-29 17:00:22,079 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6E00000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-06-29 17:00:22,081 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-29 17:00:22,088 [root] DEBUG: 2892: OpenProcessHandler: Image base for process 1812 (handle 0x1644): 0x00007FF6847E0000.
2026-06-29 17:00:22,096 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 2232, handle 0x245c: Error obtaining target process name
2026-06-29 17:00:22,097 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A57F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2026-06-29 17:00:22,103 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-29 17:00:22,104 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes).
2026-06-29 17:00:22,107 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 2132, handle 0x2484: Error obtaining target process name
2026-06-29 17:00:22,110 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A5490000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes).
2026-06-29 17:00:22,113 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-29 17:00:22,119 [root] DEBUG: 1812: DLL loaded at 0x00007FF99BC00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-06-29 17:00:22,175 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 2996, handle 0x23bc: Error obtaining target process name
2026-06-29 17:00:22,373 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A4300000: C:\Windows\SYSTEM32\MSIMG32 (0x7000 bytes).
2026-06-29 17:00:22,374 [lib.api.process] INFO: Monitor config for process 756: C:\2_6me6uj\dll\756.ini
2026-06-29 17:00:22,451 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 1428, handle 0x2848: C:\Program Files (x86)\Internet Explorer\iexplore.exe
2026-06-29 17:00:22,483 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\QbfJqv.dll, loader C:\2_6me6uj\bin\OTwbRAmw.exe
2026-06-29 17:00:22,576 [root] DEBUG: Loader: Injecting process 756 with C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:22,591 [root] DEBUG: 756: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 17:00:22,592 [root] DEBUG: 756: Disabling sleep skipping.
2026-06-29 17:00:22,594 [root] DEBUG: 756: Dropped file limit defaulting to 100.
2026-06-29 17:00:22,610 [root] DEBUG: 756: Services hook set enabled
2026-06-29 17:00:22,670 [root] DEBUG: 756: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac
2026-06-29 17:00:22,747 [root] DEBUG: 756: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 17:00:22,864 [lib.api.process] INFO: Monitor config for process 2892: C:\2_6me6uj\dll\2892.ini
2026-06-29 17:00:22,955 [root] DEBUG: 756: Monitor initialised: 64-bit capemon loaded in process 756 at 0x00007FF987A90000, thread 520, image base 0x00007FF69D480000, stack from 0x00000036AC4F4000-0x00000036AC500000
2026-06-29 17:00:22,957 [root] DEBUG: 756: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-06-29 17:00:23,000 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\QbfJqv.dll, loader C:\2_6me6uj\bin\OTwbRAmw.exe
2026-06-29 17:00:23,037 [root] DEBUG: 756: Hooked 69 out of 69 functions
2026-06-29 17:00:23,061 [root] INFO: Loaded monitor into process with pid 756
2026-06-29 17:00:23,068 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-29 17:00:23,069 [root] DEBUG: Loader: Injecting process 2892 with C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:23,077 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:23,079 [root] DEBUG: 2892: caller_dispatch: Added region at 0x0000000003230000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0000000003230042, thread 2432).
2026-06-29 17:00:23,101 [root] DEBUG: 2892: DumpPEsInRange: Scanning range 0x0000000003230000 - 0x0000000003230133.
2026-06-29 17:00:23,103 [root] DEBUG: 2892: ScanForDisguisedPE: Size too small: 0x133 bytes
2026-06-29 17:00:23,107 [lib.api.process] INFO: Injected into 64-bit <Process 756 svchost.exe>
2026-06-29 17:00:23,213 [lib.common.results] INFO: Uploading file C:\awPTaE\CAPE\2892_4018230030262026 to CAPE\0f34d970490a72e5892e413ff0447b76b728031ef23b3a9c973b79d54458ce1f; Size is 307; Max size: 100000000
2026-06-29 17:00:23,258 [root] DEBUG: 2892: DumpMemory: Payload successfully created: C:\awPTaE\CAPE\2892_4018230030262026 (size 307 bytes)
2026-06-29 17:00:23,488 [root] DEBUG: 2892: DumpRegion: Dumped entire allocation from 0x0000000003230000, size 4096 bytes.
2026-06-29 17:00:23,574 [root] DEBUG: 1812: DLL loaded at 0x00007FF99D480000: C:\Windows\System32\OneCoreCommonProxyStub (0x7d000 bytes).
2026-06-29 17:00:23,575 [root] DEBUG: 2892: DLL loaded at 0x00007FF99E260000: C:\Windows\System32\NETAPI32 (0x18000 bytes).
2026-06-29 17:00:23,583 [root] DEBUG: 2892: ProcessTrackedRegion: Dumped region at 0x0000000003230000.
2026-06-29 17:00:23,586 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 1492, handle 0x10f0: C:\Program Files (x86)\Internet Explorer\iexplore.exe
2026-06-29 17:00:23,588 [root] DEBUG: 2892: DLL loaded at 0x00007FF986850000: C:\Windows\System32\ieframe (0x757000 bytes).
2026-06-29 17:00:23,607 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:00:23,752 [root] DEBUG: 2892: YaraScan: Scanning 0x0000000003230000, size 0x133
2026-06-29 17:00:23,764 [root] DEBUG: 2892: OpenProcessHandler: Image base for process 1428 (handle 0x249c): 0x0000000000040000.
2026-06-29 17:00:23,790 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-29 17:00:23,795 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\QbfJqv.dll.
2026-06-29 17:00:23,809 [lib.api.process] INFO: Injected into 64-bit <Process 2892 explorer.exe>
2026-06-29 17:00:24,003 [root] DEBUG: 1812: DLL loaded at 0x00007FF997F60000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2026-06-29 17:00:24,005 [root] DEBUG: 1812: DLL loaded at 0x00007FF990130000: C:\Windows\SYSTEM32\MLANG (0x42000 bytes).
2026-06-29 17:00:24,014 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C60000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-06-29 17:00:24,016 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C90000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-06-29 17:00:24,022 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C60000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-06-29 17:00:24,024 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C90000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-06-29 17:00:24,792 [modules.auxiliary.human] INFO: Found button "ask me later", clicking it
2026-06-29 17:00:26,118 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:00:26,209 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7E50000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-06-29 17:00:26,349 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:00:30,085 [root] DEBUG: 2892: OpenProcessHandler: Image base for process 1492 (handle 0x249c): 0x0000000000040000.
2026-06-29 17:00:31,471 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C60000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-06-29 17:00:31,473 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C90000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-06-29 17:00:31,478 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7090000: C:\Windows\system32\schannel (0x91000 bytes).
2026-06-29 17:00:31,534 [root] DEBUG: 1812: DLL loaded at 0x00007FF99D360000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-06-29 17:00:31,556 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7AC0000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-06-29 17:00:31,571 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7B00000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-06-29 17:00:31,589 [root] DEBUG: 1812: DLL loaded at 0x00007FF99D410000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-06-29 17:00:31,596 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7C20000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-06-29 17:00:31,600 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7E40000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2026-06-29 17:00:31,653 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A82A0000: C:\Windows\System32\WINTRUST (0x60000 bytes).
2026-06-29 17:00:31,666 [root] DEBUG: 1812: DLL loaded at 0x00007FF99D2F0000: C:\Windows\System32\cryptnet (0x31000 bytes).
2026-06-29 17:00:31,748 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\YCJ22SLV\favicon[1].png
2026-06-29 17:00:31,847 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:00:31,899 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\imagestore\ptf03hl\imagestore.dat
2026-06-29 17:00:31,902 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A7F60000: C:\Windows\System32\UMPDC (0x12000 bytes).
2026-06-29 17:00:31,968 [root] DEBUG: 1812: DLL loaded at 0x00007FF997860000: C:\Windows\System32\cdp (0x4a1000 bytes).
2026-06-29 17:00:31,975 [root] DEBUG: 1812: DLL loaded at 0x00007FF9888B0000: C:\Windows\System32\cdprt (0x1bc000 bytes).
2026-06-29 17:00:32,055 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A1790000: C:\Windows\SYSTEM32\windows.staterepositorycore (0x11000 bytes).
2026-06-29 17:00:32,105 [root] DEBUG: 1812: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes).
2026-06-29 17:00:32,114 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C60000: C:\Windows\System32\sppc (0x25000 bytes).
2026-06-29 17:00:32,145 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A6C90000: C:\Windows\System32\SLC (0x29000 bytes).
2026-06-29 17:00:32,178 [root] DEBUG: 1812: DLL loaded at 0x00007FF9971F0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-06-29 17:00:32,194 [root] DEBUG: 1812: DLL loaded at 0x00007FF987280000: C:\Windows\System32\msxml3 (0x20c000 bytes).
2026-06-29 17:00:32,210 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A3BE0000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-06-29 17:00:32,391 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
2026-06-29 17:00:32,400 [root] DEBUG: 1812: DLL loaded at 0x00007FF994E80000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-06-29 17:00:32,454 [root] DEBUG: 1812: DLL loaded at 0x00007FF993730000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-06-29 17:00:32,657 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
2026-06-29 17:00:33,019 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\E2CXM875\favicon[1].ico
2026-06-29 17:00:33,083 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A01A0000: C:\Windows\SYSTEM32\webio (0x99000 bytes).
2026-06-29 17:00:33,122 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:00:33,224 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B76BE66D46C355931939D8CF818D03FD_68DC46933CF3DE41CC968E0784D43DC3
2026-06-29 17:00:33,239 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_68DC46933CF3DE41CC968E0784D43DC3
2026-06-29 17:00:33,301 [root] DEBUG: 1812: DLL loaded at 0x00007FF9912D0000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x2c000 bytes).
2026-06-29 17:00:33,314 [root] DEBUG: 1812: DLL loaded at 0x00007FF99E380000: C:\Program Files\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF (0x13000 bytes).
2026-06-29 17:00:33,325 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Temp\Kno6E40.tmp
2026-06-29 17:00:33,330 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\TGRORK47\known_providers_download_v1[1].xml
2026-06-29 17:00:33,362 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Temp\Kno6E40.tmp to files\1e2e25bf730ff20c89d57aa38f7f34be7690820e8279b20127d0014dd27b743f; Size is 90518; Max size: 100000000
2026-06-29 17:00:34,412 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:00:35,164 [root] DEBUG: 1812: DLL loaded at 0x00007FF995FC0000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes).
2026-06-29 17:00:58,292 [root] DEBUG: 1812: CreateProcessHandler: Injection info set for new process 5944: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE, ImageBase: 0x0000000000040000
2026-06-29 17:00:58,302 [root] DEBUG: 1812: ProcessMessage: Skipping monitoring process 5944
2026-06-29 17:00:58,306 [root] DEBUG: 1812: ProcessMessage: Skipping monitoring process 5944
2026-06-29 17:00:58,309 [root] INFO: Announced 32-bit process name: iexplore.exe pid: 5944
2026-06-29 17:00:58,311 [lib.api.process] INFO: Monitor config for process 5944: C:\2_6me6uj\dll\5944.ini
2026-06-29 17:00:59,139 [lib.api.process] INFO: Potential dll side-loading detected in local directory: sqmapi.dll
2026-06-29 17:00:59,142 [lib.api.process] INFO: 32-bit DLL to inject is C:\2_6me6uj\dll\HGoNKVTL.dll, loader C:\2_6me6uj\bin\aRJrkFV.exe
2026-06-29 17:00:59,158 [root] DEBUG: Loader: Injecting process 5944 with C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:00:59,159 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed (SessionId=2).
2026-06-29 17:00:59,160 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:00:59,297 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 5944, handle 0x113c: C:\Program Files (x86)\Internet Explorer\iexplore.exe
2026-06-29 17:00:59,474 [root] DEBUG: 1812: CreateProcessHandler: Injection info set for new process 6044: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE, ImageBase: 0x0000000000040000
2026-06-29 17:00:59,530 [root] DEBUG: 1812: ProcessMessage: Skipping monitoring process 6044
2026-06-29 17:00:59,534 [root] DEBUG: 1812: ProcessMessage: Skipping monitoring process 6044
2026-06-29 17:00:59,537 [root] INFO: Announced 32-bit process name: iexplore.exe pid: 6044
2026-06-29 17:00:59,538 [lib.api.process] INFO: Monitor config for process 6044: C:\2_6me6uj\dll\6044.ini
2026-06-29 17:01:00,133 [lib.api.process] INFO: Potential dll side-loading detected in local directory: sqmapi.dll
2026-06-29 17:01:00,135 [lib.api.process] INFO: 32-bit DLL to inject is C:\2_6me6uj\dll\HGoNKVTL.dll, loader C:\2_6me6uj\bin\aRJrkFV.exe
2026-06-29 17:01:00,146 [root] DEBUG: Loader: Injecting process 6044 with C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:01:00,148 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed (SessionId=2).
2026-06-29 17:01:00,149 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:01:00,343 [root] DEBUG: 1812: CreateProcessHandler: Injection info set for new process 6140: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE, ImageBase: 0x0000000000040000
2026-06-29 17:01:00,345 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 6044, handle 0x2130: C:\Program Files (x86)\Internet Explorer\iexplore.exe
2026-06-29 17:01:00,404 [root] DEBUG: 1812: ProcessMessage: Skipping monitoring process 6140
2026-06-29 17:01:00,423 [root] DEBUG: 1812: ProcessMessage: Skipping monitoring process 6140
2026-06-29 17:01:00,438 [root] INFO: Announced 32-bit process name: iexplore.exe pid: 6140
2026-06-29 17:01:00,439 [lib.api.process] INFO: Monitor config for process 6140: C:\2_6me6uj\dll\6140.ini
2026-06-29 17:01:00,980 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C02877841121CC45139CB51404116B25_637BBF2E4C2A4399F9FB16DDFF8700CC
2026-06-29 17:01:00,982 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C02877841121CC45139CB51404116B25_637BBF2E4C2A4399F9FB16DDFF8700CC
2026-06-29 17:01:01,007 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\9CPCQTWS\favicon[1].ico
2026-06-29 17:01:01,064 [lib.api.process] INFO: Potential dll side-loading detected in local directory: sqmapi.dll
2026-06-29 17:01:01,067 [lib.api.process] INFO: 32-bit DLL to inject is C:\2_6me6uj\dll\HGoNKVTL.dll, loader C:\2_6me6uj\bin\aRJrkFV.exe
2026-06-29 17:01:01,084 [root] DEBUG: Loader: Injecting process 6140 with C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:01:01,085 [root] DEBUG: InjectDll: No thread ID supplied, GetProcessInitialThreadId failed (SessionId=2).
2026-06-29 17:01:01,086 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\HGoNKVTL.dll.
2026-06-29 17:01:01,138 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:01,334 [root] DEBUG: 2892: OpenProcessHandler: Image base for process 5944 (handle 0x2460): 0x0000000000040000.
2026-06-29 17:01:01,336 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 6140, handle 0x278c: C:\Program Files (x86)\Internet Explorer\iexplore.exe
2026-06-29 17:01:01,733 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:02,083 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:02,593 [root] DEBUG: 2892: OpenProcessHandler: Image base for process 6044 (handle 0x232c): 0x0000000000040000.
2026-06-29 17:01:02,597 [root] DEBUG: 2892: OpenProcessHandler: Image base for process 6140 (handle 0x232c): 0x0000000000040000.
2026-06-29 17:01:08,866 [root] DEBUG: 2892: OpenProcessHandler: Image base for process 2996 (handle 0x494): 0x00007FF619E70000.
2026-06-29 17:01:10,036 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:10,148 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\YCJ22SLV\favicon_32x32[1].png
2026-06-29 17:01:11,598 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:12,237 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:13,001 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:15,502 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:15,564 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:01:27,304 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\E2CXM875\suggestions[1].en-US
2026-06-29 17:01:27,322 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\en-US.1
2026-06-29 17:01:27,330 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:02:08,660 [root] DEBUG: 1812: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 17:02:35,028 [root] DEBUG: 2892: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-06-29 17:03:38,306 [root] INFO: Analysis timeout hit, terminating analysis
2026-06-29 17:03:38,310 [lib.api.process] INFO: Terminate event set for process 1812
2026-06-29 17:03:38,314 [root] DEBUG: 1812: Terminate Event: Attempting to dump process 1812
2026-06-29 17:03:38,317 [root] DEBUG: 1812: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 17:03:38,337 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{CD227434-7416-11F1-9CDD-5254005B2305}.dat
2026-06-29 17:03:38,341 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{C54188B0-7416-11F1-9CDD-5254005B2305}.dat
2026-06-29 17:03:38,344 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{C54188AF-7416-11F1-9CDD-5254005B2305}.dat
2026-06-29 17:03:38,345 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{C54188AE-7416-11F1-9CDD-5254005B2305}.dat
2026-06-29 17:03:38,346 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{ADB144A5-7416-11F1-9CDD-5254005B2305}.dat
2026-06-29 17:03:38,348 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{ADB144A4-7416-11F1-9CDD-5254005B2305}.dat
2026-06-29 17:03:38,349 [root] INFO: Added new file to list with pid 1812 and path C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ADB144A2-7416-11F1-9CDD-5254005B2305}.dat
2026-06-29 17:03:38,350 [root] DEBUG: 1812: Terminate Event: Shutdown complete for process 1812 but failed to inform analyzer.
2026-06-29 17:03:43,307 [lib.api.process] INFO: Termination confirmed for process 1812
2026-06-29 17:03:43,308 [root] INFO: Terminate event set for process 1812
2026-06-29 17:03:43,309 [lib.api.process] INFO: Terminate event set for process 2892
2026-06-29 17:03:43,313 [root] DEBUG: 2892: Terminate Event: Attempting to dump process 2892
2026-06-29 17:03:43,329 [root] DEBUG: 2892: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 17:03:43,372 [root] DEBUG: 2892: Terminate Event: Shutdown complete for process 2892 but failed to inform analyzer.
2026-06-29 17:03:48,318 [lib.api.process] INFO: Termination confirmed for process 2892
2026-06-29 17:03:48,319 [root] INFO: Terminate event set for process 2892
2026-06-29 17:03:48,321 [lib.api.process] INFO: Terminate event set for process 756
2026-06-29 17:03:48,324 [root] DEBUG: 756: Terminate Event: Attempting to dump process 756
2026-06-29 17:03:48,327 [root] DEBUG: 756: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 17:03:48,333 [lib.api.process] INFO: Termination confirmed for process 756
2026-06-29 17:03:48,334 [root] DEBUG: 756: Terminate Event: monitor shutdown complete for process 756
2026-06-29 17:03:48,334 [root] INFO: Terminate event set for process 756
2026-06-29 17:03:48,336 [root] INFO: Created shutdown mutex
2026-06-29 17:03:49,341 [root] INFO: Shutting down package
2026-06-29 17:03:49,342 [root] INFO: Stopping auxiliary modules
2026-06-29 17:03:49,342 [root] INFO: Stopping auxiliary module: Browser
2026-06-29 17:03:49,343 [root] INFO: Stopping auxiliary module: Human
2026-06-29 17:03:53,790 [root] INFO: Stopping auxiliary module: Screenshots
2026-06-29 17:03:53,791 [root] INFO: Finishing auxiliary modules
2026-06-29 17:03:53,791 [root] INFO: Shutting down pipe server and dumping dropped files
2026-06-29 17:03:53,794 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\Favorites\Bing.url to files\e0c0a5a360482b5c5ded8fad5706c4c66f215f527851ad87b31380ef6060696e; Size is 208; Max size: 100000000
2026-06-29 17:03:53,801 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\YCJ22SLV\favicon[1].png to files\4d755ac02a070a1b4bb1b6f1c88ab493440109a8ac1e314aaced92f94cdc98e9; Size is 7904; Max size: 100000000
2026-06-29 17:03:53,807 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\imagestore\ptf03hl\imagestore.dat to files\74dfe822da407828bdabf6c8f4c6d034b656fafe852b772f50a081b62ee60a7f; Size is 18171; Max size: 100000000
2026-06-29 17:03:53,812 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml to files\2049fe84f772576d7da3dda49eff4de455ef9913e9b98540c494776ca1973813; Size is 377; Max size: 100000000
2026-06-29 17:03:53,818 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico to files\5b2c34b3c4e8dd898b664dba6c3786e2ff9869eff55d673aa48361f11325ed07; Size is 4286; Max size: 100000000
2026-06-29 17:03:53,824 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\E2CXM875\favicon[1].ico to files\5b2c34b3c4e8dd898b664dba6c3786e2ff9869eff55d673aa48361f11325ed07; Size is 4286; Max size: 100000000
2026-06-29 17:03:53,827 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B76BE66D46C355931939D8CF818D03FD_68DC46933CF3DE41CC968E0784D43DC3 to files\d42b05313ec0228ffcb30390c5af834f4570c08e18fb0d53a31535cc5bb90662; Size is 1761; Max size: 100000000
2026-06-29 17:03:53,833 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B76BE66D46C355931939D8CF818D03FD_68DC46933CF3DE41CC968E0784D43DC3 to files\2744b632889ce37dfc59afac9a9bff3e7bb6fa6b4a5c7464803f4e946be60717; Size is 422; Max size: 100000000
2026-06-29 17:03:53,839 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\TGRORK47\known_providers_download_v1[1].xml to files\1e2e25bf730ff20c89d57aa38f7f34be7690820e8279b20127d0014dd27b743f; Size is 90518; Max size: 100000000
2026-06-29 17:03:53,856 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C02877841121CC45139CB51404116B25_637BBF2E4C2A4399F9FB16DDFF8700CC to files\f437ad39236e15fc0764ce19c47f0e0424b9e54efa7d8a26461bea079d4432cc; Size is 472; Max size: 100000000
2026-06-29 17:03:53,861 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C02877841121CC45139CB51404116B25_637BBF2E4C2A4399F9FB16DDFF8700CC to files\4b1029d18f325eedc69851ac2dafeb1b292757182a03d5e791c5e04c396b20a6; Size is 398; Max size: 100000000
2026-06-29 17:03:53,866 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\9CPCQTWS\favicon[1].ico to files\6da5620880159634213e197fafca1dde0272153be3e4590818533fab8d040770; Size is 5430; Max size: 100000000
2026-06-29 17:03:53,872 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\YCJ22SLV\favicon_32x32[1].png to files\502b2fa1f09e4b9e4cab7b1e3d1bf8c921b2508c64e131481c221499158f9097; Size is 3214; Max size: 100000000
2026-06-29 17:03:53,877 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCache\IE\E2CXM875\suggestions[1].en-US to files\c6a5377cbc07eece33790cfc70572e12c7a48ad8296be25c0cc805a1f384dbad; Size is 18176; Max size: 100000000
2026-06-29 17:03:53,882 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\DomainSuggestions\en-US.1 to files\c6a5377cbc07eece33790cfc70572e12c7a48ad8296be25c0cc805a1f384dbad; Size is 18176; Max size: 100000000
2026-06-29 17:03:53,886 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{CD227434-7416-11F1-9CDD-5254005B2305}.dat to files\b034894502b383dcbe4d01a96ebbbdf1eb0ad3c3d3d926169771b264c1f0d43a; Size is 3584; Max size: 100000000
2026-06-29 17:03:53,890 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{C54188B0-7416-11F1-9CDD-5254005B2305}.dat to files\7ba62a9974a1698192f0f016f64eafb3ea6725053e62c3609e49f6bf5756df12; Size is 15872; Max size: 100000000
2026-06-29 17:03:53,896 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{C54188AF-7416-11F1-9CDD-5254005B2305}.dat to files\bcb2f3bf4bd7b725fe16664115040c3e673ae57d1a6fb89f21bbdfd91e1503ed; Size is 10752; Max size: 100000000
2026-06-29 17:03:53,902 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{C54188AE-7416-11F1-9CDD-5254005B2305}.dat to files\7d7062b7823fb658da934156929ea797671ac789141f39412bf2233a99f4cb81; Size is 10752; Max size: 100000000
2026-06-29 17:03:53,906 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{ADB144A5-7416-11F1-9CDD-5254005B2305}.dat to files\1281fdf92a2fd21a73bcb75184ac15667a76abfad09b9249398f9c0ed35d2970; Size is 3584; Max size: 100000000
2026-06-29 17:03:53,911 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{ADB144A4-7416-11F1-9CDD-5254005B2305}.dat to files\8785ba82169443bd42439a95ffcb6b9d4cb49de1d2dd5f328093d779dd636e43; Size is 4096; Max size: 100000000
2026-06-29 17:03:53,915 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ADB144A2-7416-11F1-9CDD-5254005B2305}.dat to files\4e82479bf79cafd6c8573a23738cb5a1df240744b1359816dd5a1dfda67e4c8d; Size is 6144; Max size: 100000000
2026-06-29 17:03:53,919 [root] WARNING: Folder at path "C:\awPTaE\debugger" does not exist, skipping
2026-06-29 17:03:53,919 [root] WARNING: Folder at path "C:\awPTaE\tlsdump" does not exist, skipping
2026-06-29 17:03:53,930 [root] WARNING: Monitor injection attempted but failed for process 1428
2026-06-29 17:03:53,930 [root] WARNING: Monitor injection attempted but failed for process 5944
2026-06-29 17:03:53,931 [root] WARNING: Monitor injection attempted but failed for process 6044
2026-06-29 17:03:53,931 [root] WARNING: Monitor injection attempted but failed for process 6140
2026-06-29 17:03:53,931 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-29 16:59:59 | 2026-06-29 17:03:58 | internet |
| File Name |
philip website fixed.html
|
|---|---|
| File Type | HTML document, ASCII text |
| File Size | 771 bytes |
| MD5 | 0332a12a029770f3118f9f346bf46dfe |
| SHA1 | c7efd61451c78ffd91b317cd325ccfb972675e5d |
| SHA256 | 076775d4cc29dcc6bfb09ffcfe5d423ebf13310c4aa17c9bf3ed8bd4f9eab0d2 VT MWDB Bazaar |
| SHA3-384 | 26749ffc9c66975cea7ab1994253035ca475698534ecdac0ca8a49b4042fe024fec7fbb200deb4073b97249375f09beb |
| CRC32 | FD52D484 |
| TLSH | T12F0120B7F094A5BB9E17F49EA807BAADC3817021A06655AC318C98C3F6C9F66C2420D1 |
| Ssdeep | 24:ZoEaGW3TgGeiVGnM8cBRdNQ8eAW9mCm8L:Zl9IWioM8AeAH8L |
<center><h1><u>The Philip Adams Website</u></h1> <p>Click the word <a href='https://www.youtube.com/osfirsttimer'>YouTube</a> to visit the best thing on the YouTube website</p> <h2><p>Check out this google logo</p></h2> <a href='https://www.google.com.au/'><img src='https://www.google.com.au/images/branding/googlelogo/2x/googlelogo_color_272x92dp.png'alt='Google'/> </a><p><i>Click on the google logo to visit google website</i></p> <table border="9> <td bgcolor="red">Windows 95</td><td bgcolor="rainbow">Windows 98</td><td bgcolor="lightblue">Windows 2000<td bgcolor="yellow">Windows XP</td><td bgcolor="pink">Windows 8</td> </table> <MARQUEE WIDTH=460 HEIGHT=50> Philip's silly website!!! </MARQUEE> <p><font size=9 face="Impact">Copyright Diana 2017</font></p>
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Process: iexplore.exe (1812) | ||||||||
| file | C:\Users\Rajesh\AppData\Local\Microsoft\Windows\INetCookies | |||||||
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| N | 74.125.206.84 [VT] | unknown | - |
| N | 74.125.71.119 [VT] | unknown | - |
| N | 142.251.173.101 [VT] | unknown | - |
| N | 74.125.206.91 [VT] | unknown | - |
| Y | 74.125.206.138 [VT] | unknown | - |
| Y | 74.125.71.95 [VT] | unknown | - |
| N | 108.177.15.94 [VT] | unknown | - |
| Y | 64.233.167.101 [VT] | unknown | - |
| N | 150.171.110.117 [VT] | unknown | - |
| N | 142.251.173.94 [VT] | unknown | - |
| Y | 142.251.16.94 [VT] | unknown | - |
| N | 64.233.184.94 [VT] | unknown | - |
| Y | 172.253.157.95 [VT] | unknown | - |
| Y | 151.101.206.172 [VT] | unknown | - |
| Y | 20.190.159.23 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| www.google.com.au [VT] | A 64.233.184.94 [VT] | 64.233.184.94 [VT] |
| c.pki.goog [VT] |
CNAME pki-goog.l.google.com
[VT]
A 64.233.167.94 [VT] |
74.125.71.94 [VT] |
| o.pki.goog [VT] | 64.233.167.94 [VT] | |
| beacons.gcp.gvt2.com [VT] |
CNAME beacons-handoff.gcp.gvt2.com
[VT]
A 142.251.173.94 [VT] |
142.251.173.94 [VT] |
| edgecdn-embza6g8cacagcbn.z01.azurefd.net [VT] |
CNAME mr-z01.tm-azurefd.net
[VT]
A 150.171.110.117 [VT] |
150.171.110.117 [VT] |
| www.youtube.com [VT] |
A 142.251.168.190
[VT]
A 142.251.173.91 [VT] A 142.251.168.93 [VT] A 142.250.110.93 [VT] A 142.250.110.190 [VT] A 142.251.173.93 [VT] A 142.251.168.91 [VT] A 74.125.206.136 [VT] A 74.125.206.91 [VT] A 74.125.206.93 [VT] CNAME youtube-ui.l.google.com [VT] A 142.251.168.136 [VT] A 64.233.167.93 [VT] A 64.233.167.190 [VT] A 74.125.206.190 [VT] A 142.250.110.136 [VT] A 142.251.173.190 [VT] |
74.125.206.91 [VT] |
| consent.youtube.com [VT] |
A 142.251.173.100
[VT]
A 142.251.173.102 [VT] A 142.251.173.113 [VT] A 142.251.173.138 [VT] A 142.251.173.139 [VT] A 142.251.173.101 [VT] |
142.251.173.138 [VT] |
| www.gstatic.com [VT] | A 108.177.15.94 [VT] | 108.177.15.94 [VT] |
| i.ytimg.com [VT] |
A 108.177.15.119
[VT]
A 74.125.133.119 [VT] A 64.233.167.119 [VT] A 64.233.166.119 [VT] A 142.251.168.119 [VT] A 74.125.206.119 [VT] A 74.125.71.119 [VT] A 66.102.1.119 [VT] A 172.253.157.119 [VT] A 64.233.184.119 [VT] A 173.194.76.119 [VT] A 142.250.110.119 [VT] |
74.125.206.119 [VT] |
| accounts.google.com [VT] | A 74.125.206.84 [VT] | 74.125.206.84 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.