| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| FILE | generic | 2026-06-29 19:31:57 | 2026-06-29 19:35:55 | 238s |
|
|||||
| Reports | JSON | |||||||||
vnc_port=5900
2026-06-29 14:58:58,715 [root] INFO: Date set to: 20260629T19:32:02, timeout set to: 200 2026-06-29 19:32:02,169 [root] DEBUG: Starting analyzer from: C:\2_6me6uj 2026-06-29 19:32:02,170 [root] DEBUG: Storing results at: C:\QonFocsg 2026-06-29 19:32:02,170 [root] DEBUG: Pipe server name: \\.\PIPE\ZkVqIBDyaH 2026-06-29 19:32:02,171 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314 2026-06-29 19:32:02,171 [root] INFO: analysis running as an admin 2026-06-29 19:32:02,172 [root] DEBUG: no analysis package configured, picking one for you 2026-06-29 19:32:02,177 [root] INFO: analysis package selected: "generic" 2026-06-29 19:32:02,179 [root] DEBUG: importing analysis package module: "modules.packages.generic"... 2026-06-29 19:32:02,187 [root] DEBUG: imported analysis package "generic" 2026-06-29 19:32:02,187 [root] DEBUG: initializing analysis package "generic"... 2026-06-29 19:32:02,187 [lib.common.common] INFO: no wrapping 2026-06-29 19:32:02,188 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-29 19:32:02,188 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\0139.jpg 2026-06-29 19:32:02,188 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll option 2026-06-29 19:32:02,189 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll_64 option 2026-06-29 19:32:02,189 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader option 2026-06-29 19:32:02,189 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader_64 option 2026-06-29 19:32:02,212 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2026-06-29 19:32:02,223 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2026-06-29 19:32:02,243 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2026-06-29 19:32:02,449 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2026-06-29 19:32:02,452 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2026-06-29 19:32:02,452 [root] DEBUG: Initialized auxiliary module "Browser" 2026-06-29 19:32:02,452 [root] DEBUG: attempting to configure 'Browser' from data 2026-06-29 19:32:02,454 [root] DEBUG: module Browser does not support data configuration, ignoring 2026-06-29 19:32:02,454 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2026-06-29 19:32:02,566 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2026-06-29 19:32:02,567 [root] DEBUG: Initialized auxiliary module "DigiSig" 2026-06-29 19:32:02,567 [root] DEBUG: attempting to configure 'DigiSig' from data 2026-06-29 19:32:02,567 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2026-06-29 19:32:02,567 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2026-06-29 19:32:02,568 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature 2026-06-29 19:32:03,320 [modules.auxiliary.digisig] DEBUG: File has an invalid signature 2026-06-29 19:32:03,321 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json 2026-06-29 19:32:03,323 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2026-06-29 19:32:03,323 [root] DEBUG: Initialized auxiliary module "Disguise" 2026-06-29 19:32:03,323 [root] DEBUG: attempting to configure 'Disguise' from data 2026-06-29 19:32:03,324 [root] DEBUG: module Disguise does not support data configuration, ignoring 2026-06-29 19:32:03,324 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2026-06-29 19:32:03,329 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 236) 2026-06-29 19:32:03,334 [modules.auxiliary.disguise] INFO: Disguising GUID to fa0ac19c-b40c-4caf-91d3-7eb1460f4ffc 2026-06-29 19:32:03,337 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2026-06-29 19:32:03,337 [root] DEBUG: Initialized auxiliary module "Human" 2026-06-29 19:32:03,337 [root] DEBUG: attempting to configure 'Human' from data 2026-06-29 19:32:03,338 [root] DEBUG: module Human does not support data configuration, ignoring 2026-06-29 19:32:03,338 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2026-06-29 19:32:03,412 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2026-06-29 19:32:03,412 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2026-06-29 19:32:03,413 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2026-06-29 19:32:03,413 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2026-06-29 19:32:03,414 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2026-06-29 19:32:03,416 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process 2026-06-29 19:32:03,416 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2026-06-29 19:32:09,440 [root] INFO: Restarting WMI Service 2026-06-29 19:32:11,549 [root] DEBUG: package modules.packages.generic does not support configure, ignoring 2026-06-29 19:32:11,551 [root] WARNING: configuration error for package modules.packages.generic: error importing data.packages.generic: No module named 'data.packages' 2026-06-29 19:32:11,552 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-29 19:32:11,555 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\0139.jpg"" with pid 2248 2026-06-29 19:32:11,823 [lib.api.process] INFO: Monitor config for process 2248: C:\2_6me6uj\dll\2248.ini 2026-06-29 19:32:11,841 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\sssfxwQ.dll, loader C:\2_6me6uj\bin\fKGEvqpn.exe 2026-06-29 19:32:11,863 [root] DEBUG: Loader: Injecting process 2248 (thread 4352) with C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:11,865 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:32:11,866 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:11,871 [lib.api.process] INFO: Injected into 64-bit <Process 2248 cmd.exe> 2026-06-29 19:32:13,887 [lib.api.process] INFO: Successfully resumed process with pid 2248 2026-06-29 19:32:14,088 [root] DEBUG: 2248: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:32:14,105 [root] DEBUG: 2248: Disabling sleep skipping. 2026-06-29 19:32:14,107 [root] DEBUG: 2248: Dropped file limit defaulting to 100. 2026-06-29 19:32:14,133 [root] DEBUG: 2248: YaraInit: Compiled 44 rule files 2026-06-29 19:32:14,141 [root] DEBUG: 2248: YaraInit: Compiled rules saved to file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:32:14,208 [root] DEBUG: 2248: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:32:14,210 [root] DEBUG: 2248: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-29 19:32:14,216 [root] DEBUG: 2248: YaraScan hit: FindFixAndRun 2026-06-29 19:32:14,217 [root] DEBUG: 2248: Monitor initialised: 64-bit capemon loaded in process 2248 at 0x00007FF987A90000, thread 4352, image base 0x00007FF79A450000, stack from 0x0000008F00604000-0x0000008F00700000 2026-06-29 19:32:14,219 [root] DEBUG: 2248: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\0139.jpg" 2026-06-29 19:32:14,239 [root] DEBUG: 2248: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:32:14,297 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:32:14,298 [root] DEBUG: 2248: set_hooks: Unable to hook LockResource 2026-06-29 19:32:14,313 [root] DEBUG: 2248: Hooked 630 out of 631 functions 2026-06-29 19:32:14,319 [root] DEBUG: 2248: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620 2026-06-29 19:32:14,323 [root] DEBUG: 2248: Syscall hook installed, syscall logging level 1 2026-06-29 19:32:14,335 [root] DEBUG: 2248: RestoreHeaders: Restored original import table. 2026-06-29 19:32:14,337 [root] INFO: Loaded monitor into process with pid 2248 2026-06-29 19:32:14,342 [root] DEBUG: 2248: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 4352). 2026-06-29 19:32:14,344 [root] DEBUG: 2248: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-29 19:32:14,353 [root] DEBUG: 2248: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:32:14,377 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:32:14,381 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:32:14,386 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-29 19:32:14,399 [root] DEBUG: 2248: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes). 2026-06-29 19:32:14,404 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes). 2026-06-29 19:32:14,408 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-29 19:32:14,410 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes). 2026-06-29 19:32:14,415 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes). 2026-06-29 19:32:14,426 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:32:14,464 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-29 19:32:14,582 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-29 19:32:14,587 [root] DEBUG: 2248: DLL loaded at 0x00007FF993730000: C:\Windows\system32\edputil (0x24000 bytes). 2026-06-29 19:32:14,626 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-29 19:32:14,638 [root] DEBUG: 2248: DLL loaded at 0x00007FF9903B0000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes). 2026-06-29 19:32:14,717 [root] DEBUG: 2248: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes). 2026-06-29 19:32:14,719 [root] DEBUG: 2248: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes). 2026-06-29 19:32:14,720 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes). 2026-06-29 19:32:14,723 [root] DEBUG: 2248: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes). 2026-06-29 19:32:14,733 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A7200000: C:\Windows\system32\msvcp110_win (0x8a000 bytes). 2026-06-29 19:32:14,734 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes). 2026-06-29 19:32:14,767 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\System32\wintypes (0x154000 bytes). 2026-06-29 19:32:14,774 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A5A30000: C:\Windows\SYSTEM32\apphelp (0x90000 bytes). 2026-06-29 19:32:14,782 [root] DEBUG: 2248: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\WindowsCodecs (0x1b4000 bytes). 2026-06-29 19:32:14,783 [root] DEBUG: 2248: DLL loaded at 0x00007FF998E30000: C:\Windows\system32\PhotoMetadataHandler (0x81000 bytes). 2026-06-29 19:32:14,864 [root] DEBUG: 2248: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes). 2026-06-29 19:32:14,865 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A6C60000: C:\Windows\System32\sppc (0x25000 bytes). 2026-06-29 19:32:14,867 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A6C90000: C:\Windows\System32\SLC (0x29000 bytes). 2026-06-29 19:32:14,868 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A7F80000: C:\Windows\System32\USERENV (0x2e000 bytes). 2026-06-29 19:32:14,870 [root] DEBUG: 2248: DLL loaded at 0x00007FF9971F0000: C:\Windows\System32\appresolver (0x90000 bytes). 2026-06-29 19:32:14,887 [root] DEBUG: 2248: DLL loaded at 0x00007FF99D480000: C:\Windows\System32\OneCoreCommonProxyStub (0x7d000 bytes). 2026-06-29 19:32:14,903 [root] DEBUG: 2248: DLL loaded at 0x00007FF99EEA0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x798000 bytes). 2026-06-29 19:32:14,912 [lib.api.process] INFO: Monitor config for process 756: C:\2_6me6uj\dll\756.ini 2026-06-29 19:32:14,916 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\sssfxwQ.dll, loader C:\2_6me6uj\bin\fKGEvqpn.exe 2026-06-29 19:32:14,928 [root] DEBUG: Loader: Injecting process 756 with C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:14,933 [root] DEBUG: 756: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:32:14,934 [root] DEBUG: 756: Disabling sleep skipping. 2026-06-29 19:32:14,935 [root] DEBUG: 756: Dropped file limit defaulting to 100. 2026-06-29 19:32:14,939 [root] DEBUG: 756: Services hook set enabled 2026-06-29 19:32:14,942 [root] DEBUG: 756: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:32:14,964 [root] DEBUG: 756: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:32:14,965 [root] DEBUG: 756: Monitor initialised: 64-bit capemon loaded in process 756 at 0x00007FF987A90000, thread 348, image base 0x00007FF69D480000, stack from 0x00000036AC574000-0x00000036AC580000 2026-06-29 19:32:14,966 [root] DEBUG: 756: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p 2026-06-29 19:32:14,984 [root] DEBUG: 756: Hooked 69 out of 69 functions 2026-06-29 19:32:14,986 [root] INFO: Loaded monitor into process with pid 756 2026-06-29 19:32:14,987 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-06-29 19:32:14,988 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:14,991 [lib.api.process] INFO: Injected into 64-bit <Process 756 svchost.exe> 2026-06-29 19:32:17,008 [root] DEBUG: 2248: CreateProcessHandler: Injection info set for new process 4420: C:\Windows\system32\mspaint.exe, ImageBase: 0x00007FF700FE0000 2026-06-29 19:32:17,009 [root] INFO: Announced 64-bit process name: mspaint.exe pid: 4420 2026-06-29 19:32:17,010 [lib.api.process] INFO: Monitor config for process 4420: C:\2_6me6uj\dll\4420.ini 2026-06-29 19:32:17,015 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\sssfxwQ.dll, loader C:\2_6me6uj\bin\fKGEvqpn.exe 2026-06-29 19:32:17,027 [root] DEBUG: Loader: Injecting process 4420 (thread 1708) with C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:17,029 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:32:17,030 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:17,033 [lib.api.process] INFO: Injected into 64-bit <Process 4420 mspaint.exe> 2026-06-29 19:32:17,040 [root] INFO: Announced 64-bit process name: mspaint.exe pid: 4420 2026-06-29 19:32:17,041 [lib.api.process] INFO: Monitor config for process 4420: C:\2_6me6uj\dll\4420.ini 2026-06-29 19:32:17,043 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\sssfxwQ.dll, loader C:\2_6me6uj\bin\fKGEvqpn.exe 2026-06-29 19:32:17,054 [root] DEBUG: Loader: Injecting process 4420 (thread 1708) with C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:17,055 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:32:17,056 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:17,059 [lib.api.process] INFO: Injected into 64-bit <Process 4420 mspaint.exe> 2026-06-29 19:32:17,062 [root] DEBUG: 2248: DLL loaded at 0x00007FF998030000: C:\Windows\system32\MPR (0x1d000 bytes). 2026-06-29 19:32:17,063 [root] DEBUG: 2248: DLL loaded at 0x00007FF9A31D0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes). 2026-06-29 19:32:17,150 [root] DEBUG: 4420: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:32:17,151 [root] DEBUG: 4420: Dropped file limit defaulting to 100. 2026-06-29 19:32:17,159 [root] DEBUG: 4420: Disabling sleep skipping. 2026-06-29 19:32:17,161 [root] DEBUG: 4420: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:32:17,184 [root] DEBUG: 4420: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:32:17,185 [root] DEBUG: 4420: YaraScan: Scanning 0x00007FF700FE0000, size 0xf8baa 2026-06-29 19:32:17,196 [root] DEBUG: 4420: Monitor initialised: 64-bit capemon loaded in process 4420 at 0x00007FF987A90000, thread 1708, image base 0x00007FF700FE0000, stack from 0x000000B1DB5A4000-0x000000B1DB5B0000 2026-06-29 19:32:17,198 [root] DEBUG: 4420: Commandline: "C:\Windows\system32\mspaint.exe" "C:\Users\Rajesh\AppData\Local\Temp\0139.jpg" 2026-06-29 19:32:17,216 [root] DEBUG: 4420: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:32:17,269 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:32:17,271 [root] DEBUG: 4420: set_hooks: Unable to hook LockResource 2026-06-29 19:32:17,284 [root] DEBUG: 4420: Hooked 630 out of 631 functions 2026-06-29 19:32:17,295 [root] DEBUG: 4420: Syscall hook installed, syscall logging level 1 2026-06-29 19:32:17,302 [root] DEBUG: 4420: RestoreHeaders: Restored original import table. 2026-06-29 19:32:17,304 [root] INFO: Loaded monitor into process with pid 4420 2026-06-29 19:32:17,309 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:32:17,326 [root] DEBUG: 4420: DLL loaded at 0x00007FF99DDA0000: C:\Windows\SYSTEM32\ninput (0x6a000 bytes). 2026-06-29 19:32:17,330 [root] DEBUG: 4420: caller_dispatch: Added region at 0x00007FF700FE0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF70107F9B1, thread 1708). 2026-06-29 19:32:17,331 [root] DEBUG: 4420: YaraScan: Scanning 0x00007FF700FE0000, size 0xf8baa 2026-06-29 19:32:17,349 [root] DEBUG: 4420: ProcessImageBase: Main module image at 0x00007FF700FE0000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:32:17,358 [root] DEBUG: 4420: DLL loaded at 0x00007FF990180000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1288_none_91a663c8cc864906\gdiplus (0x1a9000 bytes). 2026-06-29 19:32:17,361 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-29 19:32:17,374 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes). 2026-06-29 19:32:17,429 [root] DEBUG: 4420: DLL loaded at 0x00007FF98DE00000: C:\Windows\system32\MSFTEDIT (0x348000 bytes). 2026-06-29 19:32:17,438 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:32:17,505 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:32:17,511 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A2820000: C:\Windows\system32\XmlLite (0x36000 bytes). 2026-06-29 19:32:17,512 [root] DEBUG: 4420: DLL loaded at 0x00007FF9870A0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes). 2026-06-29 19:32:17,520 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-29 19:32:17,521 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A6230000: C:\Windows\system32\windows.storage (0x790000 bytes). 2026-06-29 19:32:17,528 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes). 2026-06-29 19:32:17,529 [root] DEBUG: 4420: DLL loaded at 0x00007FF988F00000: C:\Windows\System32\efswrt (0xde000 bytes). 2026-06-29 19:32:17,533 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A10F0000: C:\Windows\System32\twinapi.appcore (0x201000 bytes). 2026-06-29 19:32:17,656 [root] INFO: Announced starting service "b'stisvc'" 2026-06-29 19:32:17,659 [lib.api.process] INFO: Monitor config for process 632: C:\2_6me6uj\dll\632.ini 2026-06-29 19:32:17,663 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\sssfxwQ.dll, loader C:\2_6me6uj\bin\fKGEvqpn.exe 2026-06-29 19:32:17,677 [root] DEBUG: Loader: Injecting process 632 with C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:17,681 [root] DEBUG: Loader: Copied config file C:\2_6me6uj\dll\632.ini to system path C:\632.ini 2026-06-29 19:32:17,685 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 632 C:\2_6me6uj\dll\sssfxwQ.dll 2026-06-29 19:32:17,686 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:17,695 [lib.api.process] INFO: Injected into 64-bit <Process 632 services.exe> 2026-06-29 19:32:20,864 [root] DEBUG: 4420: DLL loaded at 0x00007FF99DFF0000: C:\Windows\System32\sti (0x53000 bytes). 2026-06-29 19:32:20,868 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A4220000: C:\Windows\SYSTEM32\wiatrace (0xa000 bytes). 2026-06-29 19:32:21,026 [root] DEBUG: 4420: DLL loaded at 0x00007FF995FC0000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes). 2026-06-29 19:32:21,082 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A5F20000: C:\Windows\system32\dwmapi (0x2f000 bytes). 2026-06-29 19:32:21,132 [root] DEBUG: 4420: DLL loaded at 0x00007FF994E80000: C:\Windows\System32\msxml6 (0x25f000 bytes). 2026-06-29 19:32:21,155 [root] DEBUG: 4420: DLL loaded at 0x00007FF99CF00000: C:\Windows\system32\windowscodecs (0x1b4000 bytes). 2026-06-29 19:32:21,578 [root] DEBUG: 4420: DLL loaded at 0x00007FF998F00000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes). 2026-06-29 19:32:21,676 [root] DEBUG: 4420: DLL loaded at 0x00007FF992900000: C:\Windows\System32\oleacc (0x66000 bytes). 2026-06-29 19:32:21,763 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-29 19:32:21,834 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-29 19:32:22,397 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-29 19:32:22,413 [root] DEBUG: 4420: DLL loaded at 0x00007FF998E30000: C:\Windows\system32\PhotoMetadataHandler (0x81000 bytes). 2026-06-29 19:32:22,734 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A6E00000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-06-29 19:32:22,739 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A57F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-06-29 19:32:22,741 [root] DEBUG: 4420: DLL loaded at 0x00007FF9A5490000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes). 2026-06-29 19:32:22,762 [root] DEBUG: 4420: DLL loaded at 0x00007FF99BC00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-06-29 19:32:23,128 [root] DEBUG: 4420: DLL loaded at 0x00007FF9AA490000: C:\Windows\System32\coml2 (0x79000 bytes). 2026-06-29 19:32:28,993 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 4888: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF712FE0000 2026-06-29 19:32:28,995 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 4888 2026-06-29 19:32:28,996 [lib.api.process] INFO: Monitor config for process 4888: C:\2_6me6uj\dll\4888.ini 2026-06-29 19:32:30,103 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\sssfxwQ.dll, loader C:\2_6me6uj\bin\fKGEvqpn.exe 2026-06-29 19:32:30,125 [root] DEBUG: Loader: Injecting process 4888 (thread 4948) with C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:30,128 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:32:30,129 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:30,133 [lib.api.process] INFO: Injected into 64-bit <Process 4888 WmiPrvSE.exe> 2026-06-29 19:32:30,135 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 4888 2026-06-29 19:32:30,136 [lib.api.process] INFO: Monitor config for process 4888: C:\2_6me6uj\dll\4888.ini 2026-06-29 19:32:30,415 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\sssfxwQ.dll, loader C:\2_6me6uj\bin\fKGEvqpn.exe 2026-06-29 19:32:30,428 [root] DEBUG: Loader: Injecting process 4888 (thread 4948) with C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:30,430 [root] DEBUG: InjectDllViaIAT: This image has already been patched. 2026-06-29 19:32:30,431 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:30,433 [lib.api.process] INFO: Injected into 64-bit <Process 4888 WmiPrvSE.exe> 2026-06-29 19:32:30,450 [root] DEBUG: 4888: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:32:30,452 [root] DEBUG: 4888: Dropped file limit defaulting to 100. 2026-06-29 19:32:30,469 [root] DEBUG: 4888: Disabling sleep skipping. 2026-06-29 19:32:30,473 [root] DEBUG: 4888: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:32:30,508 [root] DEBUG: 4888: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:32:30,509 [root] DEBUG: 4888: YaraScan: Scanning 0x00007FF712FE0000, size 0x7dcfe 2026-06-29 19:32:30,516 [root] DEBUG: 4888: Monitor initialised: 64-bit capemon loaded in process 4888 at 0x00007FF987A90000, thread 4948, image base 0x00007FF712FE0000, stack from 0x0000004FADB60000-0x0000004FADB70000 2026-06-29 19:32:30,517 [root] DEBUG: 4888: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -Embedding 2026-06-29 19:32:30,533 [root] DEBUG: 4888: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:32:30,579 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:32:30,581 [root] DEBUG: 4888: set_hooks: Unable to hook LockResource 2026-06-29 19:32:30,590 [root] DEBUG: 4888: Hooked 630 out of 631 functions 2026-06-29 19:32:30,596 [root] DEBUG: 4888: Syscall hook installed, syscall logging level 1 2026-06-29 19:32:30,612 [root] DEBUG: 4888: RestoreHeaders: Restored original import table. 2026-06-29 19:32:30,614 [root] INFO: Loaded monitor into process with pid 4888 2026-06-29 19:32:30,616 [root] DEBUG: 4888: caller_dispatch: Added region at 0x00007FF712FE0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF712FF2CD1, thread 4948). 2026-06-29 19:32:30,617 [root] DEBUG: 4888: YaraScan: Scanning 0x00007FF712FE0000, size 0x7dcfe 2026-06-29 19:32:30,626 [root] DEBUG: 4888: ProcessImageBase: Main module image at 0x00007FF712FE0000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:32:30,644 [root] DEBUG: 4888: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:32:30,646 [root] DEBUG: 4888: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:32:30,658 [root] DEBUG: 4888: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:32:30,666 [lib.api.process] INFO: Monitor config for process 4628: C:\2_6me6uj\dll\4628.ini 2026-06-29 19:32:30,670 [lib.api.process] INFO: 64-bit DLL to inject is C:\2_6me6uj\dll\sssfxwQ.dll, loader C:\2_6me6uj\bin\fKGEvqpn.exe 2026-06-29 19:32:30,684 [root] DEBUG: Loader: Injecting process 4628 with C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:30,695 [root] DEBUG: 4628: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:32:30,696 [root] DEBUG: 4628: Disabling sleep skipping. 2026-06-29 19:32:30,697 [root] DEBUG: 4628: Dropped file limit defaulting to 100. 2026-06-29 19:32:30,698 [root] DEBUG: 4628: Services hook set enabled 2026-06-29 19:32:30,703 [root] DEBUG: 4628: YaraInit: Compiled rules loaded from existing file C:\2_6me6uj\data\yara\capemon.yac 2026-06-29 19:32:30,730 [root] DEBUG: 4628: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:32:30,732 [root] DEBUG: 4628: Monitor initialised: 64-bit capemon loaded in process 4628 at 0x00007FF987A90000, thread 4048, image base 0x00007FF69D480000, stack from 0x000000B9C8174000-0x000000B9C8180000 2026-06-29 19:32:30,734 [root] DEBUG: 4628: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p 2026-06-29 19:32:30,759 [root] DEBUG: 4628: Hooked 69 out of 69 functions 2026-06-29 19:32:30,762 [root] INFO: Loaded monitor into process with pid 4628 2026-06-29 19:32:30,764 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-06-29 19:32:30,765 [root] DEBUG: Successfully injected DLL C:\2_6me6uj\dll\sssfxwQ.dll. 2026-06-29 19:32:30,770 [lib.api.process] INFO: Injected into 64-bit <Process 4628 svchost.exe> 2026-06-29 19:32:32,781 [root] DEBUG: 4888: DLL loaded at 0x00007FF97FC40000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes). 2026-06-29 19:32:32,796 [root] DEBUG: 4888: DLL loaded at 0x00007FF97FC20000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes). 2026-06-29 19:32:32,857 [root] DEBUG: 4888: DLL loaded at 0x00007FF99E310000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes). 2026-06-29 19:33:32,926 [root] DEBUG: 4888: NtTerminateProcess hook: Attempting to dump process 4888 2026-06-29 19:33:32,928 [root] DEBUG: 4888: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:33:32,948 [root] INFO: Process with pid 4888 has terminated 2026-06-29 19:35:19,651 [root] DEBUG: 4420: api-cap: GetCursorPos hook disabled due to count: 5000 2026-06-29 19:35:34,763 [root] INFO: Analysis timeout hit, terminating analysis 2026-06-29 19:35:34,768 [lib.api.process] INFO: Terminate event set for process 2248 2026-06-29 19:35:34,769 [root] DEBUG: 2248: Terminate Event: Attempting to dump process 2248 2026-06-29 19:35:34,772 [root] DEBUG: 2248: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching 2026-06-29 19:35:34,773 [root] DEBUG: 2248: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000. 2026-06-29 19:35:34,774 [root] DEBUG: 2248: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2026-06-29 19:35:34,775 [root] DEBUG: 2248: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000. 2026-06-29 19:35:34,776 [root] DEBUG: 2248: DumpProcess: Module entry point VA is 0x00007FF79A468F50. 2026-06-29 19:35:34,795 [lib.common.results] INFO: Uploading file C:\QonFocsg\CAPE\2248_320213435230262026 to procdump\0fe2871d9d36d1d9941922e27a102aff8489ba7c19ed4d09722321e32b15c69c; Size is 401920; Max size: 100000000 2026-06-29 19:35:34,809 [root] DEBUG: 2248: DumpProcess: Module image dump success - dump size 0x62200. 2026-06-29 19:35:34,834 [root] DEBUG: 2248: Terminate Event: Shutdown complete for process 2248 but failed to inform analyzer. 2026-06-29 19:35:39,779 [lib.api.process] INFO: Termination confirmed for process 2248 2026-06-29 19:35:39,780 [root] INFO: Terminate event set for process 2248 2026-06-29 19:35:39,781 [lib.api.process] INFO: Terminate event set for process 756 2026-06-29 19:35:39,783 [root] DEBUG: 756: Terminate Event: Attempting to dump process 756 2026-06-29 19:35:39,784 [root] DEBUG: 756: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:35:39,790 [lib.api.process] INFO: Termination confirmed for process 756 2026-06-29 19:35:39,791 [root] INFO: Terminate event set for process 756 2026-06-29 19:35:39,791 [root] DEBUG: 756: Terminate Event: monitor shutdown complete for process 756 2026-06-29 19:35:39,795 [lib.api.process] INFO: Terminate event set for process 4420 2026-06-29 19:35:39,796 [root] DEBUG: 4420: Terminate Event: Attempting to dump process 4420 2026-06-29 19:35:39,801 [root] DEBUG: 4420: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:35:39,831 [root] DEBUG: 4420: Terminate Event: Shutdown complete for process 4420 but failed to inform analyzer. 2026-06-29 19:35:40,372 [root] DEBUG: 4420: api-cap: GetSystemMetrics hook disabled due to count: 5000 2026-06-29 19:35:44,810 [lib.api.process] INFO: Termination confirmed for process 4420 2026-06-29 19:35:44,811 [root] INFO: Terminate event set for process 4420 2026-06-29 19:35:44,812 [lib.api.process] INFO: Terminate event set for process 4628 2026-06-29 19:35:44,813 [root] DEBUG: 4628: Terminate Event: Attempting to dump process 4628 2026-06-29 19:35:44,814 [root] DEBUG: 4628: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:35:44,825 [lib.api.process] INFO: Termination confirmed for process 4628 2026-06-29 19:35:44,825 [root] INFO: Terminate event set for process 4628 2026-06-29 19:35:44,826 [root] INFO: Created shutdown mutex 2026-06-29 19:35:44,826 [root] DEBUG: 4628: Terminate Event: monitor shutdown complete for process 4628 2026-06-29 19:35:45,843 [root] INFO: Shutting down package 2026-06-29 19:35:45,843 [root] INFO: Stopping auxiliary modules 2026-06-29 19:35:45,844 [root] INFO: Stopping auxiliary module: Browser 2026-06-29 19:35:45,844 [root] INFO: Stopping auxiliary module: Human 2026-06-29 19:35:51,508 [root] INFO: Finishing auxiliary modules 2026-06-29 19:35:51,509 [root] INFO: Shutting down pipe server and dumping dropped files 2026-06-29 19:35:51,510 [root] WARNING: Folder at path "C:\QonFocsg\debugger" does not exist, skipping 2026-06-29 19:35:51,510 [root] WARNING: Folder at path "C:\QonFocsg\tlsdump" does not exist, skipping 2026-06-29 19:35:51,518 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-29 19:31:57 | 2026-06-29 19:35:55 | internet |
| File Name |
0139.jpg
|
|---|---|
| File Type | JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1024x768, components 3 |
| File Size | 51367 bytes |
| MD5 | e88d2299114c9cd7a20b4322cab82966 |
| SHA1 | 2225e0d5b77f88a411ce0e6fbf01ea7a91afd6f4 |
| SHA256 | acfad3a0b81705ec15e58c4ca1eb6cb5fc531871f8e81ee88f60a32631e011e9 VT MWDB Bazaar |
| SHA3-384 | 0bf33bbc3c98d7be2d5e36ec0dea9f78a4fd159c53d74a1c45d28ed122556e78b1ad8a7ef38784aff6e58da7682b632a |
| CRC32 | 299F338E |
| TLSH | T1DA3381134C19CB43562997E87F434FAD2F5B2E0CA9952AEF50260D8B3F346762C8E51E |
| Ssdeep | 768:LqS5A3+fLbK5Y5UWw3eUnxnuy9RUifwKuNZJ085g90zbJBTe8zMrkN2B:Lqj3x3OUZuuU5KuN/D5CdIN2B |
ix/,nI
#F;cT}
FT+v<
$.' ",#
&9&Dg
'lduS
.J:39(
rk-<@
5AZ3V
TQE`n
X1bB(
hPo@sKS
rrON1SM
_ZH|I
r?1]
V 2OS
I"GFE
ZIa<&S
mOL:{B
Gq[7>
:)o+q
Hx{[)
O{qgi|
Ov%2l
dU%S'
))E+\n2n
iDlI($+
4vr4;
G{4q[
?pzW,u
t|9xc
o. x^
imjn&[
RH~~`U
Dm$arDj
giuiy
kd|C1S"
2BdU@
` x.f
rtW_/
ZH/V6F
:y|Uo-
+]BYd)v
u95J:
[ie%A
4g|k"
V;]DJ
1m!{{
]gTKYmWR
X{$tV3
"8--o!
zsPQ@
,~XFc
#sg$dt
Y//b1
5~MQZ
hfIT)d`
Fq!W*
-no:Xa
4IVA;
VRr~c
EbFx$`
=0@<V
sXw>
F5TSN
m'Y\2
}mf-c
jQYtP
Mjgh6)euj
ZG"YY
Q9F(]
4c<B6
g]3Ps}
+E<!s
0ixcM
Fzs\-
tH#I|
PEsm#l2l1
m<omo
fH5kY_b)f!VB
(7),01444
FeVV,
Eg_dk_dXy#
wwmwy7
EKmo-
Eh%JQ
XH"W8
k^`_/
-bDo0a
MfIcok
24>[p
h%f91
,R4r#
tShZtz
Caokm:\
AR0C}@
ym>"iv
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
sTU{Yw'
cTHQc
;O U*
rC$%D
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Q[{o#
Wo>>Y
m5MB4TK
``c<q\
Rd9BX
5[/:Xe
IT^B|
&h_Mw
W$G!9'
ORFps
*" YY
]Ackff
4k9ne
`TqxR7
nV$p>h
F9ZA:
|g~9#
20Gnh
;XmoA
!22222222222222222222222222222222222222222222222222
@rFr2
.rtWY
XRdqo
'9=82<.342
]FXUo
m--.%
@$\pz
Y2/fR
vpk2)d
2[G#F
|[se7
[}A^H
Sqkq)'
QEIAE
VU@Hlc#
-&i-u_
O'?^F
V,<u=
d_$dg!
-&;{IV
|+scqg
bd3+<A
atfdw
IKk}+
0:rsJO
PeCc8
A%s\U
xR;}5
V7-4q
$u-:L
#!Et:
G=s\N
muq8y
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 142.251.155.119 [VT] | unknown | - |
| Y | 142.251.168.101 [VT] | unknown | - |
| Y | 74.125.71.95 [VT] | unknown | - |
| Y | 108.177.15.94 [VT] | unknown | - |
| Y | 64.233.167.101 [VT] | unknown | - |
| N | 142.251.14.94 [VT] | unknown | - |
| Y | 142.251.16.94 [VT] | unknown | - |
| Y | 142.251.168.139 [VT] | unknown | - |
| Y | 172.253.157.95 [VT] | unknown | - |
| Y | 151.101.206.172 [VT] | unknown | - |
| Y | 20.190.159.23 [VT] | unknown | - |
No results found.
No behavioral analysis data available.
No dropped files found.