| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| FILE | generic | 2026-06-29 19:26:00 | 2026-06-29 19:26:47 | 47s |
|
|||||
| Reports | JSON | |||||||||
vnc_port=5900
2026-06-29 14:58:58,620 [root] INFO: Date set to: 20260629T19:26:05, timeout set to: 15 2026-06-29 19:26:05,377 [root] DEBUG: Starting analyzer from: C:\2_6me6uj 2026-06-29 19:26:05,378 [root] DEBUG: Storing results at: C:\hHBMUz 2026-06-29 19:26:05,378 [root] DEBUG: Pipe server name: \\.\PIPE\Hwzptua 2026-06-29 19:26:05,378 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314 2026-06-29 19:26:05,378 [root] INFO: analysis running as an admin 2026-06-29 19:26:05,379 [root] DEBUG: no analysis package configured, picking one for you 2026-06-29 19:26:05,395 [root] INFO: analysis package selected: "generic" 2026-06-29 19:26:05,396 [root] DEBUG: importing analysis package module: "modules.packages.generic"... 2026-06-29 19:26:05,401 [root] DEBUG: imported analysis package "generic" 2026-06-29 19:26:05,401 [root] DEBUG: initializing analysis package "generic"... 2026-06-29 19:26:05,402 [lib.common.common] INFO: no wrapping 2026-06-29 19:26:05,403 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-29 19:26:05,403 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\0001.jpg 2026-06-29 19:26:05,404 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll option 2026-06-29 19:26:05,404 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll_64 option 2026-06-29 19:26:05,405 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader option 2026-06-29 19:26:05,405 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader_64 option 2026-06-29 19:26:05,423 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2026-06-29 19:26:05,430 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2026-06-29 19:26:05,460 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2026-06-29 19:26:05,514 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2026-06-29 19:26:05,520 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops' 2026-06-29 19:26:05,521 [lib.api.screenshot] ERROR: No module named 'PIL' 2026-06-29 19:26:05,522 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots" 2026-06-29 19:26:05,525 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2026-06-29 19:26:05,525 [root] DEBUG: Initialized auxiliary module "Browser" 2026-06-29 19:26:05,526 [root] DEBUG: attempting to configure 'Browser' from data 2026-06-29 19:26:05,527 [root] DEBUG: module Browser does not support data configuration, ignoring 2026-06-29 19:26:05,528 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2026-06-29 19:26:05,742 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2026-06-29 19:26:05,744 [root] DEBUG: Initialized auxiliary module "DigiSig" 2026-06-29 19:26:05,744 [root] DEBUG: attempting to configure 'DigiSig' from data 2026-06-29 19:26:05,744 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2026-06-29 19:26:05,744 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2026-06-29 19:26:05,745 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature 2026-06-29 19:26:06,234 [modules.auxiliary.digisig] DEBUG: File has an invalid signature 2026-06-29 19:26:06,236 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json 2026-06-29 19:26:06,239 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2026-06-29 19:26:06,239 [root] DEBUG: Initialized auxiliary module "Disguise" 2026-06-29 19:26:06,240 [root] DEBUG: attempting to configure 'Disguise' from data 2026-06-29 19:26:06,240 [root] DEBUG: module Disguise does not support data configuration, ignoring 2026-06-29 19:26:06,240 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2026-06-29 19:26:06,243 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 2848) 2026-06-29 19:26:06,248 [modules.auxiliary.disguise] INFO: Disguising GUID to 66c92be0-096a-4693-b2f4-39ea0ebbe16e 2026-06-29 19:26:06,248 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2026-06-29 19:26:06,249 [root] DEBUG: Initialized auxiliary module "Human" 2026-06-29 19:26:06,249 [root] DEBUG: attempting to configure 'Human' from data 2026-06-29 19:26:06,250 [root] DEBUG: module Human does not support data configuration, ignoring 2026-06-29 19:26:06,250 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2026-06-29 19:26:06,251 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2026-06-29 19:26:06,252 [root] DEBUG: Initialized auxiliary module "Screenshots" 2026-06-29 19:26:06,252 [root] DEBUG: attempting to configure 'Screenshots' from data 2026-06-29 19:26:06,253 [root] DEBUG: module Screenshots does not support data configuration, ignoring 2026-06-29 19:26:06,257 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"... 2026-06-29 19:26:06,264 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled 2026-06-29 19:26:06,265 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots 2026-06-29 19:26:06,265 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2026-06-29 19:26:06,265 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2026-06-29 19:26:06,266 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2026-06-29 19:26:06,266 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2026-06-29 19:26:06,268 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process 2026-06-29 19:26:06,268 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2026-06-29 19:26:12,024 [root] INFO: Restarting WMI Service 2026-06-29 19:26:14,152 [root] DEBUG: package modules.packages.generic does not support configure, ignoring 2026-06-29 19:26:14,154 [root] WARNING: configuration error for package modules.packages.generic: error importing data.packages.generic: No module named 'data.packages' 2026-06-29 19:26:14,155 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-29 19:26:14,157 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\0001.jpg"" with pid 3864 2026-06-29 19:26:14,487 [lib.api.process] INFO: Monitor config for process 3864: C:\2_6me6uj\dll\3864.ini 2026-06-29 19:26:14,501 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\fOTsOVfP.dll, loader C:\2_6me6uj\bin\oZDbrFhe.exe 2026-06-29 19:26:14,520 [root] DEBUG: Loader: Injecting process 3864 (thread 2716) with C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:14,522 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:26:14,523 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:14,526 [lib.api.process] INFO: Injected into 64-bit <Process 3864 cmd.exe> 2026-06-29 19:26:16,535 [lib.api.process] INFO: Successfully resumed process with pid 3864 2026-06-29 19:26:16,715 [root] DEBUG: 3864: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:26:16,717 [root] DEBUG: 3864: Disabling sleep skipping. 2026-06-29 19:26:16,718 [root] DEBUG: 3864: Dropped file limit defaulting to 100. 2026-06-29 19:26:16,768 [root] DEBUG: 3864: YaraInit: Compiled 44 rule files 2026-06-29 19:26:16,772 [root] DEBUG: 3864: YaraInit: Compiled rules saved to file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:26:16,836 [root] DEBUG: 3864: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:26:16,837 [root] DEBUG: 3864: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-29 19:26:16,842 [root] DEBUG: 3864: YaraScan hit: FindFixAndRun 2026-06-29 19:26:16,843 [root] DEBUG: 3864: Monitor initialised: 64-bit capemon loaded in process 3864 at 0x00007FF987A90000, thread 2716, image base 0x00007FF79A450000, stack from 0x00000082A0854000-0x00000082A0950000 2026-06-29 19:26:16,844 [root] DEBUG: 3864: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\0001.jpg" 2026-06-29 19:26:16,860 [root] DEBUG: 3864: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:26:16,929 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:26:16,931 [root] DEBUG: 3864: set_hooks: Unable to hook LockResource 2026-06-29 19:26:16,945 [root] DEBUG: 3864: Hooked 630 out of 631 functions 2026-06-29 19:26:16,950 [root] DEBUG: 3864: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620 2026-06-29 19:26:16,952 [root] DEBUG: 3864: Syscall hook installed, syscall logging level 1 2026-06-29 19:26:16,965 [root] DEBUG: 3864: RestoreHeaders: Restored original import table. 2026-06-29 19:26:16,967 [root] INFO: Loaded monitor into process with pid 3864 2026-06-29 19:26:16,969 [root] DEBUG: 3864: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 2716). 2026-06-29 19:26:16,971 [root] DEBUG: 3864: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-29 19:26:16,978 [root] DEBUG: 3864: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:26:17,005 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:26:17,008 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:26:17,012 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-29 19:26:17,031 [root] DEBUG: 3864: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes). 2026-06-29 19:26:17,090 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes). 2026-06-29 19:26:17,093 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-29 19:26:17,094 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes). 2026-06-29 19:26:17,098 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes). 2026-06-29 19:26:17,109 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:26:17,138 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-29 19:26:17,288 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-29 19:26:17,292 [root] DEBUG: 3864: DLL loaded at 0x00007FF993730000: C:\Windows\system32\edputil (0x24000 bytes). 2026-06-29 19:26:17,336 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-29 19:26:17,349 [root] DEBUG: 3864: DLL loaded at 0x00007FF9903B0000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes). 2026-06-29 19:26:17,447 [root] DEBUG: 3864: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes). 2026-06-29 19:26:17,448 [root] DEBUG: 3864: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes). 2026-06-29 19:26:17,450 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes). 2026-06-29 19:26:17,453 [root] DEBUG: 3864: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes). 2026-06-29 19:26:17,464 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A7200000: C:\Windows\system32\msvcp110_win (0x8a000 bytes). 2026-06-29 19:26:17,465 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes). 2026-06-29 19:26:17,502 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\System32\wintypes (0x154000 bytes). 2026-06-29 19:26:17,512 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A5A30000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes). 2026-06-29 19:26:17,522 [root] DEBUG: 3864: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes). 2026-06-29 19:26:17,524 [root] DEBUG: 3864: DLL loaded at 0x00007FF998E30000: C:\Windows\system32\PhotoMetadataHandler (0x81000 bytes). 2026-06-29 19:26:17,619 [root] DEBUG: 3864: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes). 2026-06-29 19:26:17,620 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A6C60000: C:\Windows\System32\sppc (0x25000 bytes). 2026-06-29 19:26:17,621 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A6C90000: C:\Windows\System32\SLC (0x29000 bytes). 2026-06-29 19:26:17,623 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A7F80000: C:\Windows\System32\USERENV (0x2e000 bytes). 2026-06-29 19:26:17,624 [root] DEBUG: 3864: DLL loaded at 0x00007FF9971F0000: C:\Windows\System32\appresolver (0x90000 bytes). 2026-06-29 19:26:17,640 [root] DEBUG: 3864: DLL loaded at 0x00007FF99D480000: C:\Windows\System32\OneCoreCommonProxyStub (0x7d000 bytes). 2026-06-29 19:26:17,658 [root] DEBUG: 3864: DLL loaded at 0x00007FF99EEA0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x798000 bytes). 2026-06-29 19:26:17,666 [lib.api.process] INFO: Monitor config for process 756: C:\2_6me6uj\dll\756.ini 2026-06-29 19:26:17,671 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\fOTsOVfP.dll, loader C:\2_6me6uj\bin\oZDbrFhe.exe 2026-06-29 19:26:17,681 [root] DEBUG: Loader: Injecting process 756 with C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:17,687 [root] DEBUG: 756: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:26:17,688 [root] DEBUG: 756: Disabling sleep skipping. 2026-06-29 19:26:17,690 [root] DEBUG: 756: Dropped file limit defaulting to 100. 2026-06-29 19:26:17,693 [root] DEBUG: 756: Services hook set enabled 2026-06-29 19:26:17,697 [root] DEBUG: 756: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:26:17,719 [root] DEBUG: 756: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:26:17,720 [root] DEBUG: 756: Monitor initialised: 64-bit capemon loaded in process 756 at 0x00007FF987A90000, thread 3120, image base 0x00007FF69D480000, stack from 0x00000036AC4F4000-0x00000036AC500000 2026-06-29 19:26:17,721 [root] DEBUG: 756: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p 2026-06-29 19:26:17,739 [root] DEBUG: 756: Hooked 69 out of 69 functions 2026-06-29 19:26:17,741 [root] INFO: Loaded monitor into process with pid 756 2026-06-29 19:26:17,743 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-06-29 19:26:17,743 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:17,747 [lib.api.process] INFO: Injected into 64-bit <Process 756 svchost.exe> 2026-06-29 19:26:19,769 [root] DEBUG: 3864: CreateProcessHandler: Injection info set for new process 4504: C:\Windows\system32\mspaint.exe, ImageBase: 0x00007FF700FE0000 2026-06-29 19:26:19,770 [root] INFO: Announced 64-bit process name: mspaint.exe pid: 4504 2026-06-29 19:26:19,771 [lib.api.process] INFO: Monitor config for process 4504: C:\2_6me6uj\dll\4504.ini 2026-06-29 19:26:19,778 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\fOTsOVfP.dll, loader C:\2_6me6uj\bin\oZDbrFhe.exe 2026-06-29 19:26:19,790 [root] DEBUG: Loader: Injecting process 4504 (thread 336) with C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:19,792 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:26:19,793 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:19,796 [lib.api.process] INFO: Injected into 64-bit <Process 4504 mspaint.exe> 2026-06-29 19:26:19,803 [root] INFO: Announced 64-bit process name: mspaint.exe pid: 4504 2026-06-29 19:26:19,803 [lib.api.process] INFO: Monitor config for process 4504: C:\2_6me6uj\dll\4504.ini 2026-06-29 19:26:19,806 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\fOTsOVfP.dll, loader C:\2_6me6uj\bin\oZDbrFhe.exe 2026-06-29 19:26:19,819 [root] DEBUG: Loader: Injecting process 4504 (thread 336) with C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:19,820 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:26:19,821 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:19,823 [lib.api.process] INFO: Injected into 64-bit <Process 4504 mspaint.exe> 2026-06-29 19:26:19,828 [root] DEBUG: 3864: DLL loaded at 0x00007FF998030000: C:\Windows\system32\MPR (0x1d000 bytes). 2026-06-29 19:26:19,829 [root] DEBUG: 3864: DLL loaded at 0x00007FF9A31D0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes). 2026-06-29 19:26:19,910 [root] DEBUG: 4504: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:26:19,911 [root] DEBUG: 4504: Dropped file limit defaulting to 100. 2026-06-29 19:26:19,919 [root] DEBUG: 4504: Disabling sleep skipping. 2026-06-29 19:26:19,922 [root] DEBUG: 4504: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:26:19,943 [root] DEBUG: 4504: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:26:19,945 [root] DEBUG: 4504: YaraScan: Scanning 0x00007FF700FE0000, size 0xf8baa 2026-06-29 19:26:19,956 [root] DEBUG: 4504: Monitor initialised: 64-bit capemon loaded in process 4504 at 0x00007FF987A90000, thread 336, image base 0x00007FF700FE0000, stack from 0x0000001E5EDE4000-0x0000001E5EDF0000 2026-06-29 19:26:19,957 [root] DEBUG: 4504: Commandline: "C:\Windows\system32\mspaint.exe" "C:\Users\Rajesh\AppData\Local\Temp\0001.jpg" 2026-06-29 19:26:19,974 [root] DEBUG: 4504: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:26:20,028 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:26:20,030 [root] DEBUG: 4504: set_hooks: Unable to hook LockResource 2026-06-29 19:26:20,044 [root] DEBUG: 4504: Hooked 630 out of 631 functions 2026-06-29 19:26:20,056 [root] DEBUG: 4504: Syscall hook installed, syscall logging level 1 2026-06-29 19:26:20,064 [root] DEBUG: 4504: RestoreHeaders: Restored original import table. 2026-06-29 19:26:20,070 [root] INFO: Loaded monitor into process with pid 4504 2026-06-29 19:26:20,107 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:26:20,147 [root] DEBUG: 4504: DLL loaded at 0x00007FF99DDA0000: C:\Windows\SYSTEM32\ninput (0x6a000 bytes). 2026-06-29 19:26:20,154 [root] DEBUG: 4504: caller_dispatch: Added region at 0x00007FF700FE0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF70107F9B1, thread 336). 2026-06-29 19:26:20,156 [root] DEBUG: 4504: YaraScan: Scanning 0x00007FF700FE0000, size 0xf8baa 2026-06-29 19:26:20,186 [root] DEBUG: 4504: ProcessImageBase: Main module image at 0x00007FF700FE0000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:26:20,200 [root] DEBUG: 4504: DLL loaded at 0x00007FF990180000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1288_none_91a663c8cc864906\gdiplus (0x1a9000 bytes). 2026-06-29 19:26:20,204 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-29 19:26:20,236 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes). 2026-06-29 19:26:20,289 [root] DEBUG: 4504: DLL loaded at 0x00007FF98DE00000: C:\Windows\system32\MSFTEDIT (0x348000 bytes). 2026-06-29 19:26:20,298 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:26:20,387 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:26:20,393 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A2820000: C:\Windows\system32\XmlLite (0x36000 bytes). 2026-06-29 19:26:20,395 [root] DEBUG: 4504: DLL loaded at 0x00007FF9870A0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes). 2026-06-29 19:26:20,406 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-29 19:26:20,407 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A6230000: C:\Windows\system32\windows.storage (0x790000 bytes). 2026-06-29 19:26:20,414 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes). 2026-06-29 19:26:20,415 [root] DEBUG: 4504: DLL loaded at 0x00007FF988F00000: C:\Windows\System32\efswrt (0xde000 bytes). 2026-06-29 19:26:20,420 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A10F0000: C:\Windows\System32\twinapi.appcore (0x201000 bytes). 2026-06-29 19:26:20,564 [root] INFO: Announced starting service "b'stisvc'" 2026-06-29 19:26:20,566 [lib.api.process] INFO: Monitor config for process 632: C:\2_6me6uj\dll\632.ini 2026-06-29 19:26:20,571 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\fOTsOVfP.dll, loader C:\2_6me6uj\bin\oZDbrFhe.exe 2026-06-29 19:26:20,584 [root] DEBUG: Loader: Injecting process 632 with C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:20,587 [root] DEBUG: Loader: Copied config file C:\2_6me6uj\dll\632.ini to system path C:\632.ini 2026-06-29 19:26:20,591 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 632 C:\2_6me6uj\dll\fOTsOVfP.dll 2026-06-29 19:26:20,593 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:20,597 [lib.api.process] INFO: Injected into 64-bit <Process 632 services.exe> 2026-06-29 19:26:23,692 [root] DEBUG: 4504: DLL loaded at 0x00007FF99DFF0000: C:\Windows\System32\sti (0x53000 bytes). 2026-06-29 19:26:23,696 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A4220000: C:\Windows\SYSTEM32\wiatrace (0xa000 bytes). 2026-06-29 19:26:23,866 [root] DEBUG: 4504: DLL loaded at 0x00007FF995FC0000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes). 2026-06-29 19:26:23,917 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A5F20000: C:\Windows\system32\dwmapi (0x2f000 bytes). 2026-06-29 19:26:23,974 [root] DEBUG: 4504: DLL loaded at 0x00007FF994E80000: C:\Windows\System32\msxml6 (0x25f000 bytes). 2026-06-29 19:26:23,995 [root] DEBUG: 4504: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\windowscodecs (0x1b4000 bytes). 2026-06-29 19:26:24,256 [root] DEBUG: 4504: DLL loaded at 0x00007FF998F00000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes). 2026-06-29 19:26:24,310 [root] DEBUG: 4504: DLL loaded at 0x00007FF992900000: C:\Windows\System32\oleacc (0x66000 bytes). 2026-06-29 19:26:24,396 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-29 19:26:24,464 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-29 19:26:24,937 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-29 19:26:24,951 [root] DEBUG: 4504: DLL loaded at 0x00007FF998E30000: C:\Windows\system32\PhotoMetadataHandler (0x81000 bytes). 2026-06-29 19:26:25,247 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A6E00000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-06-29 19:26:25,249 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A57F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-06-29 19:26:25,250 [root] DEBUG: 4504: DLL loaded at 0x00007FF9A5490000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes). 2026-06-29 19:26:25,259 [root] DEBUG: 4504: DLL loaded at 0x00007FF99BC00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-06-29 19:26:25,596 [root] DEBUG: 4504: DLL loaded at 0x00007FF9AA490000: C:\Windows\System32\coml2 (0x79000 bytes). 2026-06-29 19:26:31,433 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 2492: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF712FE0000 2026-06-29 19:26:31,435 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 2492 2026-06-29 19:26:31,435 [lib.api.process] INFO: Monitor config for process 2492: C:\2_6me6uj\dll\2492.ini 2026-06-29 19:26:31,690 [root] INFO: Analysis timeout hit, terminating analysis 2026-06-29 19:26:31,694 [lib.api.process] INFO: Terminate event set for process 3864 2026-06-29 19:26:31,695 [root] DEBUG: 3864: Terminate Event: Attempting to dump process 3864 2026-06-29 19:26:31,697 [root] DEBUG: 3864: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching 2026-06-29 19:26:31,698 [root] DEBUG: 3864: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000. 2026-06-29 19:26:31,699 [root] DEBUG: 3864: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2026-06-29 19:26:31,701 [root] DEBUG: 3864: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000. 2026-06-29 19:26:31,702 [root] DEBUG: 3864: DumpProcess: Module entry point VA is 0x00007FF79A468F50. 2026-06-29 19:26:31,719 [lib.common.results] INFO: Uploading file C:\hHBMUz\CAPE\3864_289873126230262026 to procdump\6fdb66c7cc6af48318ac063e472999e4271db238038017883c923ca46ee35795; Size is 401920; Max size: 100000000 2026-06-29 19:26:31,750 [root] DEBUG: 3864: DumpProcess: Module image dump success - dump size 0x62200. 2026-06-29 19:26:31,774 [root] DEBUG: 3864: Terminate Event: Shutdown complete for process 3864 but failed to inform analyzer. 2026-06-29 19:26:32,478 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\fOTsOVfP.dll, loader C:\2_6me6uj\bin\oZDbrFhe.exe 2026-06-29 19:26:32,490 [root] DEBUG: Loader: Injecting process 2492 (thread 1536) with C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:32,492 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:26:32,493 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\fOTsOVfP.dll. 2026-06-29 19:26:32,496 [lib.api.process] INFO: Injected into 64-bit <Process 2492 WmiPrvSE.exe> 2026-06-29 19:26:32,512 [root] DEBUG: 2492: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:26:32,514 [root] DEBUG: 2492: Dropped file limit defaulting to 100. 2026-06-29 19:26:32,522 [root] DEBUG: 2492: Disabling sleep skipping. 2026-06-29 19:26:32,524 [root] DEBUG: 2492: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:26:32,551 [root] DEBUG: 2492: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:26:32,552 [root] DEBUG: 2492: YaraScan: Scanning 0x00007FF712FE0000, size 0x7dcfe 2026-06-29 19:26:32,559 [root] DEBUG: 2492: Monitor initialised: 64-bit capemon loaded in process 2492 at 0x00007FF987A90000, thread 1536, image base 0x00007FF712FE0000, stack from 0x0000000E2AD20000-0x0000000E2AD30000 2026-06-29 19:26:32,560 [root] DEBUG: 2492: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -Embedding 2026-06-29 19:26:32,579 [root] DEBUG: 2492: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:26:32,636 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:26:32,638 [root] DEBUG: 2492: set_hooks: Unable to hook LockResource 2026-06-29 19:26:32,649 [root] DEBUG: 2492: Hooked 630 out of 631 functions 2026-06-29 19:26:32,656 [root] DEBUG: 2492: Syscall hook installed, syscall logging level 1 2026-06-29 19:26:32,667 [root] DEBUG: 2492: RestoreHeaders: Restored original import table. 2026-06-29 19:26:32,668 [root] INFO: Loaded monitor into process with pid 2492 2026-06-29 19:26:32,671 [root] DEBUG: 2492: caller_dispatch: Added region at 0x00007FF712FE0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF712FF2CD1, thread 1536). 2026-06-29 19:26:32,672 [root] DEBUG: 2492: YaraScan: Scanning 0x00007FF712FE0000, size 0x7dcfe 2026-06-29 19:26:32,682 [root] DEBUG: 2492: ProcessImageBase: Main module image at 0x00007FF712FE0000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:26:32,696 [root] DEBUG: 2492: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:26:32,699 [root] DEBUG: 2492: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:26:32,708 [root] DEBUG: 2492: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:26:32,718 [root] DEBUG: 2492: DLL loaded at 0x00007FF97FC40000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes). 2026-06-29 19:26:32,730 [root] DEBUG: 2492: DLL loaded at 0x00007FF97FC20000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes). 2026-06-29 19:26:32,788 [root] DEBUG: 2492: DLL loaded at 0x00007FF99E310000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes). 2026-06-29 19:26:36,701 [lib.api.process] INFO: Termination confirmed for process 3864 2026-06-29 19:26:36,702 [root] INFO: Terminate event set for process 3864 2026-06-29 19:26:36,702 [lib.api.process] INFO: Terminate event set for process 756 2026-06-29 19:26:36,703 [root] DEBUG: 756: Terminate Event: Attempting to dump process 756 2026-06-29 19:26:36,705 [root] DEBUG: 756: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:26:36,710 [lib.api.process] INFO: Termination confirmed for process 756 2026-06-29 19:26:36,711 [root] INFO: Terminate event set for process 756 2026-06-29 19:26:36,712 [lib.api.process] INFO: Terminate event set for process 4504 2026-06-29 19:26:36,711 [root] DEBUG: 756: Terminate Event: monitor shutdown complete for process 756 2026-06-29 19:26:36,713 [root] DEBUG: 4504: Terminate Event: Attempting to dump process 4504 2026-06-29 19:26:36,716 [root] DEBUG: 4504: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:26:36,738 [root] DEBUG: 4504: Terminate Event: Shutdown complete for process 4504 but failed to inform analyzer. 2026-06-29 19:26:41,721 [lib.api.process] INFO: Termination confirmed for process 4504 2026-06-29 19:26:41,722 [root] INFO: Terminate event set for process 4504 2026-06-29 19:26:41,722 [lib.api.process] INFO: Terminate event set for process 2492 2026-06-29 19:26:41,724 [root] DEBUG: 2492: Terminate Event: Attempting to dump process 2492 2026-06-29 19:26:41,725 [root] DEBUG: 2492: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:26:41,734 [lib.api.process] INFO: Termination confirmed for process 2492 2026-06-29 19:26:41,735 [root] INFO: Terminate event set for process 2492 2026-06-29 19:26:41,735 [root] INFO: Created shutdown mutex 2026-06-29 19:26:41,735 [root] DEBUG: 2492: Terminate Event: monitor shutdown complete for process 2492 2026-06-29 19:26:42,737 [root] INFO: Shutting down package 2026-06-29 19:26:42,738 [root] INFO: Stopping auxiliary modules 2026-06-29 19:26:42,738 [root] INFO: Stopping auxiliary module: Browser 2026-06-29 19:26:42,739 [root] INFO: Stopping auxiliary module: Human 2026-06-29 19:26:43,596 [root] INFO: Stopping auxiliary module: Screenshots 2026-06-29 19:26:43,597 [root] INFO: Finishing auxiliary modules 2026-06-29 19:26:43,598 [root] INFO: Shutting down pipe server and dumping dropped files 2026-06-29 19:26:43,599 [root] WARNING: Folder at path "C:\hHBMUz\debugger" does not exist, skipping 2026-06-29 19:26:43,599 [root] WARNING: Folder at path "C:\hHBMUz\tlsdump" does not exist, skipping 2026-06-29 19:26:43,601 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-29 19:26:00 | 2026-06-29 19:26:46 | internet |
| File Name |
0001.jpg
|
|---|---|
| File Type | JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1024x768, components 3 |
| File Size | 84157 bytes |
| MD5 | 55c6aa947b95384cf2be1fa2813ce1fd |
| SHA1 | 0ac6d75345699773cdd6743dc659aeb74263bcd7 |
| SHA256 | 39d6156aa04b687e55b7fde9df2abfc31d880b91863320f04d518b111b08d321 VT MWDB Bazaar |
| SHA3-384 | 0b7e0a113fb2c5df46a8a676a65d399d67160e3a6bd94255c2d79a9e944509229259dcc5cc38cf915658a6ef8e84da30 |
| CRC32 | E25D7393 |
| TLSH | T1CC83123F5A0AA992A3F90F9008CDD54D404AB985A24E70C9D3EBFFF5A150E7A7911385 |
| Ssdeep | 1536:Lq3NrbRa8Gm62Ef/K+IvNEeR1tFS+NtfvNC1P3dg1YRoSZtOoF8sgZ:CGmynVIvNEQndN5va3ObCOoeJZ |
&-&iy
-'H^Q
gU8uD
^!rlU9jz-
piuV2u
Yj2([
ubO@?*
Aomck=
TBmhSDv
U8_AX
O(m'vq
b09 ~4
0E{nj
%[HJ/,z
9oaRH
JUW<y
B9'=x
yj0A,
^G%qY
k)nn[w
xdi#A
kd|C1S"
F>k|cb
Y7}C`
j5#EE;;
vV+Cv
V lX[
[{-6[
$s<V>R
J3L.(4f
sX)Dr
!i4And
WQ\L$
3[5SS
HN($k
5t(nm[
C>*&~j
HE_{P:Uw
8@9cZ
?9,Ja
9RG*}
/|I}{yqpm!7
xoKo[8
%,ZK?
Gq4G(
J)qE1
cSH`I
)';On
P!))M
6N02x
BCy<Q
P!1E/
7P{DI
53v:Sa
U_>Lm
\QE-0
'AHkS
u&g%J
o2_'f
\~isL
Os;_Y
bO;sV
ynNpI
qy33JG
smiyh
HE%!9
Z2NM7
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
p4j?~
JQ]S<l
Zis8e
`B#bZBF
c'N*)ha<<f
fl1E.)
LbQKE
4s;X.;4f
3H.;4
J_2SY2
vss1f
,N9<z
wc|"<
u-n1w
Y-CZl
5Hz.*P1M
47d&P
T<4FQ
Jmmk;
ZJwjv
Fi,}_
t.isL
kJu:14;N
A$8ER
E=QPaT(
KiR-Z
M`Ie2Hw
mm3(I
?mX').
y6<#|
OJtQn=*
H]XS2
Beqgn
7S3Fk
Bm#lQ\
3*!f`
K+i=}
3Z^<lx
=Q1KK
_UxCC
p=k2I
RO-P3
RdRQ@
~4~4~
rv9
a%ebG"+UOju
jWfi?pd;7
veI]jIc.
$gh=>RI'
NMnYh
NHKc4
kqlB#
&-sM$
}i{)/
N-l5.
KvzTp
'x.'>rc1
XTSI#XR
0mByu
\QKHBb
PF_vX
u*w(>
be7c*
kyIEX
)zmmm
l1M$N
ZZZGl
KH.)=
Ejg%sj
mY`>Y
r'g TfJ
.i3IK
_28U_
.+-Y4t
Z)3Fh
FS~MF
QCB-q-
<Si{S
RB g
GNjX"[
SikhH
,pHbx
2m@I'
moc<l-
,GJ|wL
tF@^m
R;Up*
\678lq
M\4Wf2
<l5ia
wTSz!!URfn
n>bkF
Ouyww
VTjqEj
WoBX+aN7mlgi
Wo<!nW
k+}kuo
#I#uf95V
/-[t72
)3\W>Q
[pJ.a
O^~VE
mFO614S
Yn"0s
uXg*N8
,agVd
4IcpT
Tlhb#cQ
U{_K_m
8Z<_/
ii3Fh
,2Wd89
=EkNV2
=))11
cL6}J
'9=82<.342
_i%VPy
i$:\n
TsIt!
ItR3 y
C${e1}
vjw(#
FsIm'
wKHav
~J+S:
eUL7Q
,2sV'}
4F7`w
%N9=3Z]J
\-,5eZ*
j.]nr
S!y!a
E],v&I
J)qE0
iY/#X
]950}R
YkCG;/TV<
,{}+*
LW1ZF#
Q\sw2aE
.i3IHc
HS/pT
}sY:_
+}n}R
}kM;u
J)M%QbQKI
G!ys&4
B~Y^ERr8
(Rq$*#A
P!iGJAJx
:TR&j#&
O`+N[
ZJZZ.
&PB3s
kvxLm
I"GFE
X>"'h\
<S3Fi
(>Y+3d
cm%U$
'5i^`
7T5*o
q\visL
.Mf-3N
e&O3;G
Uo.XP(\
w[MB)
*_]$V
}+<MI
+"?U?
Ri)11)(4
6zV)1\
cL/5X
J}tGc
11oe2
{smjF
W.qm&2Nx
ZE:Hum9
\QE{G
},5|#;
a^EIsI
@{mpG
t*3"w
EhBW*[
}mf-c
1Uu,;
{~zsZ
KkM'O
.nnd2
YrCq1
!Y$P2
63[I&
q+Awk8
|mw1 i0
r4QEs
wwmwy7
/LfQm
a~b}iN
qmcu$
mR;[K
Elz9e
)Altt
Z)3Fi
u$0=A
A#1M+R
[YiG#f
r[[[kvk
[H|_n
XaIKE
Eii$*
2+I!f
Ekg+"
F5+Ur
^X33E
\visL
wjW3l
F9ZA:
,-.i(
R]CTN
5k)n\
!22222222222222222222222222222222222222222222222222
=pEkN
lZ3IHh
rN=k;O
Z3E%!
DGpql
bUJi_T|
p5B0a
/ncs3< (
&*\SH
3HAFi3Fh
}jI#*
O#-:Y
tkYi"
ZJ,!(
Ae&>S
) oB+
uqq$)
QFi)\.-%!
z$-%-
Y]\[ZX
SsFs@\vh
5*{9w
AK_Cc
4~4Rf
k4Yj)< Xi
-5;{K
aIKIH
#i#H"Y7
dn)1N
$.' ",#
'3!UeF`
HB(e*UAS
Mhajb
,851}
e:jVqEn.
vJvwG'
g=4*3
P{sW$
fq-[6^bn^j
H~L`n
9&f=j
LFkN-
HRAE&h
Jfi3E
H)i+U#E
CKMfTR
'<Oku{
e%frZ
$O1pT
-nPe&
i;IIu
(*0rz
wkiVH|)
A8<W{
nAtRe
EJ2kFU
Nkz={L
sE%.i
h2lQW,T5
q`ppp:r
~4~4sG4Xf
(mn!v]Z
Fb[g6
X3xcL
q,/4k
~'a|9
q_FxV
Y70QSNv
uk}KY
$@ $u
iqXKb
(7),01444
0\.T.[
pw+c#
KKXlm
5])s$
N6~^Z
cu#K*
qe88<
N2,o$
xR=#U11
d :HLx
cTHQc
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
zT7Oq
0*/aT
qus{<-i
=zVmn
j6jV5
1KGjv
\SHM!>
k{[O4HHv9
E.)1E
RyVY'PD
\.Gwk
h#{Y$d
!+L<PA
5%Amw
)i3Fi
)BvMm
uRQVL
8;QpN
3I#9'
@NHRq
*I[sZ
))i3@
<LZ{jZ5z
o#>DLFvp
W~lc=}+
VU@Hlc#
khSoV4
{QE-;
\yjAQ
8Gl5/
Tol;T
odLWS>
'V<MnB
_Qc;Z
lSPBv
No results found.
No behavioral analysis data available.
No dropped files found.