| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| FILE | generic | 2026-06-29 19:35:56 | 2026-06-29 19:36:45 | 49s |
|
|||||
| Reports | JSON | |||||||||
vnc_port=5900
2026-06-29 14:58:59,948 [root] INFO: Date set to: 20260629T19:36:00, timeout set to: 15 2026-06-29 19:36:00,470 [root] DEBUG: Starting analyzer from: C:\7d7wfxi0 2026-06-29 19:36:00,471 [root] DEBUG: Storing results at: C:\BxeBJc 2026-06-29 19:36:00,471 [root] DEBUG: Pipe server name: \\.\PIPE\QYkbIs 2026-06-29 19:36:00,471 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314 2026-06-29 19:36:00,472 [root] INFO: analysis running as an admin 2026-06-29 19:36:00,472 [root] DEBUG: no analysis package configured, picking one for you 2026-06-29 19:36:00,473 [root] INFO: analysis package selected: "generic" 2026-06-29 19:36:00,473 [root] DEBUG: importing analysis package module: "modules.packages.generic"... 2026-06-29 19:36:00,478 [root] DEBUG: imported analysis package "generic" 2026-06-29 19:36:00,479 [root] DEBUG: initializing analysis package "generic"... 2026-06-29 19:36:00,479 [lib.common.common] INFO: no wrapping 2026-06-29 19:36:00,480 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-29 19:36:00,480 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\rufus.ini 2026-06-29 19:36:00,481 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll option 2026-06-29 19:36:00,481 [root] INFO: Analyzer: Package modules.packages.generic does not specify a dll_64 option 2026-06-29 19:36:00,482 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader option 2026-06-29 19:36:00,482 [root] INFO: Analyzer: Package modules.packages.generic does not specify a loader_64 option 2026-06-29 19:36:00,733 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser" 2026-06-29 19:36:00,745 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig" 2026-06-29 19:36:00,785 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise" 2026-06-29 19:36:01,132 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human" 2026-06-29 19:36:01,139 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump" 2026-06-29 19:36:01,139 [root] DEBUG: Initialized auxiliary module "Browser" 2026-06-29 19:36:01,140 [root] DEBUG: attempting to configure 'Browser' from data 2026-06-29 19:36:01,143 [root] DEBUG: module Browser does not support data configuration, ignoring 2026-06-29 19:36:01,144 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"... 2026-06-29 19:36:01,159 [root] DEBUG: Started auxiliary module modules.auxiliary.browser 2026-06-29 19:36:01,159 [root] DEBUG: Initialized auxiliary module "DigiSig" 2026-06-29 19:36:01,160 [root] DEBUG: attempting to configure 'DigiSig' from data 2026-06-29 19:36:01,161 [root] DEBUG: module DigiSig does not support data configuration, ignoring 2026-06-29 19:36:01,162 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"... 2026-06-29 19:36:01,162 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature 2026-06-29 19:36:01,861 [modules.auxiliary.digisig] DEBUG: File has an invalid signature 2026-06-29 19:36:01,861 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json 2026-06-29 19:36:01,867 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig 2026-06-29 19:36:01,868 [root] DEBUG: Initialized auxiliary module "Disguise" 2026-06-29 19:36:01,868 [root] DEBUG: attempting to configure 'Disguise' from data 2026-06-29 19:36:01,868 [root] DEBUG: module Disguise does not support data configuration, ignoring 2026-06-29 19:36:01,869 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"... 2026-06-29 19:36:01,881 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 2624) 2026-06-29 19:36:01,886 [modules.auxiliary.disguise] INFO: Disguising GUID to aaf550a6-7a62-4bb8-9d95-1e7652f2d63b 2026-06-29 19:36:01,886 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise 2026-06-29 19:36:01,886 [root] DEBUG: Initialized auxiliary module "Human" 2026-06-29 19:36:01,887 [root] DEBUG: attempting to configure 'Human' from data 2026-06-29 19:36:01,887 [root] DEBUG: module Human does not support data configuration, ignoring 2026-06-29 19:36:01,887 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"... 2026-06-29 19:36:01,903 [root] DEBUG: Started auxiliary module modules.auxiliary.human 2026-06-29 19:36:01,903 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets" 2026-06-29 19:36:01,903 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data 2026-06-29 19:36:01,904 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring 2026-06-29 19:36:01,904 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"... 2026-06-29 19:36:01,906 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process 2026-06-29 19:36:01,906 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump 2026-06-29 19:36:08,392 [root] INFO: Restarting WMI Service 2026-06-29 19:36:10,567 [root] DEBUG: package modules.packages.generic does not support configure, ignoring 2026-06-29 19:36:10,569 [root] WARNING: configuration error for package modules.packages.generic: error importing data.packages.generic: No module named 'data.packages' 2026-06-29 19:36:10,570 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation 2026-06-29 19:36:10,573 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\rufus.ini"" with pid 3792 2026-06-29 19:36:10,830 [lib.api.process] INFO: Monitor config for process 3792: C:\7d7wfxi0\dll\3792.ini 2026-06-29 19:36:10,847 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\XVaHDaL.dll, loader C:\7d7wfxi0\bin\OzgDrRsD.exe 2026-06-29 19:36:10,875 [root] DEBUG: Loader: Injecting process 3792 (thread 2248) with C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:10,999 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:36:11,001 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:11,008 [lib.api.process] INFO: Injected into 64-bit <Process 3792 cmd.exe> 2026-06-29 19:36:13,028 [lib.api.process] INFO: Successfully resumed process with pid 3792 2026-06-29 19:36:13,310 [root] DEBUG: 3792: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:36:13,317 [root] DEBUG: 3792: Disabling sleep skipping. 2026-06-29 19:36:13,318 [root] DEBUG: 3792: Dropped file limit defaulting to 100. 2026-06-29 19:36:13,352 [root] DEBUG: 3792: YaraInit: Compiled 44 rule files 2026-06-29 19:36:13,357 [root] DEBUG: 3792: YaraInit: Compiled rules saved to file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-29 19:36:13,428 [root] DEBUG: 3792: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:36:13,430 [root] DEBUG: 3792: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-29 19:36:13,437 [root] DEBUG: 3792: YaraScan hit: FindFixAndRun 2026-06-29 19:36:13,439 [root] DEBUG: 3792: Monitor initialised: 64-bit capemon loaded in process 3792 at 0x00007FF9870C0000, thread 2248, image base 0x00007FF79A450000, stack from 0x000000F098A04000-0x000000F098B00000 2026-06-29 19:36:13,440 [root] DEBUG: 3792: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\rufus.ini" 2026-06-29 19:36:13,466 [root] DEBUG: 3792: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:36:13,535 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:36:13,536 [root] DEBUG: 3792: set_hooks: Unable to hook LockResource 2026-06-29 19:36:13,554 [root] DEBUG: 3792: Hooked 630 out of 631 functions 2026-06-29 19:36:13,561 [root] DEBUG: 3792: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620 2026-06-29 19:36:13,565 [root] DEBUG: 3792: Syscall hook installed, syscall logging level 1 2026-06-29 19:36:13,585 [root] DEBUG: 3792: RestoreHeaders: Restored original import table. 2026-06-29 19:36:13,586 [root] INFO: Loaded monitor into process with pid 3792 2026-06-29 19:36:13,588 [root] DEBUG: 3792: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 2248). 2026-06-29 19:36:13,591 [root] DEBUG: 3792: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a 2026-06-29 19:36:13,604 [root] DEBUG: 3792: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:36:13,634 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:36:13,637 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:36:13,657 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-29 19:36:13,676 [root] DEBUG: 3792: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes). 2026-06-29 19:36:13,681 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes). 2026-06-29 19:36:13,686 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-29 19:36:13,688 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes). 2026-06-29 19:36:13,694 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes). 2026-06-29 19:36:13,717 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:36:13,752 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes). 2026-06-29 19:36:13,922 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes). 2026-06-29 19:36:13,940 [root] DEBUG: 3792: DLL loaded at 0x00007FF993730000: C:\Windows\system32\edputil (0x24000 bytes). 2026-06-29 19:36:13,994 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes). 2026-06-29 19:36:14,016 [root] DEBUG: 3792: DLL loaded at 0x00007FF9903B0000: C:\Windows\System32\Windows.UI.AppDefaults (0x4c000 bytes). 2026-06-29 19:36:14,093 [root] DEBUG: 3792: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes). 2026-06-29 19:36:14,095 [root] DEBUG: 3792: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes). 2026-06-29 19:36:14,096 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes). 2026-06-29 19:36:14,099 [root] DEBUG: 3792: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes). 2026-06-29 19:36:14,111 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A7200000: C:\Windows\system32\msvcp110_win (0x8a000 bytes). 2026-06-29 19:36:14,113 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes). 2026-06-29 19:36:14,148 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\System32\wintypes (0x154000 bytes). 2026-06-29 19:36:14,163 [root] DEBUG: 3792: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes). 2026-06-29 19:36:14,164 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A6C60000: C:\Windows\System32\sppc (0x25000 bytes). 2026-06-29 19:36:14,166 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A6C90000: C:\Windows\System32\SLC (0x29000 bytes). 2026-06-29 19:36:14,167 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A7F80000: C:\Windows\System32\USERENV (0x2e000 bytes). 2026-06-29 19:36:14,168 [root] DEBUG: 3792: DLL loaded at 0x00007FF9971F0000: C:\Windows\System32\appresolver (0x90000 bytes). 2026-06-29 19:36:14,187 [root] DEBUG: 3792: DLL loaded at 0x00007FF99D480000: C:\Windows\System32\OneCoreCommonProxyStub (0x7d000 bytes). 2026-06-29 19:36:14,209 [root] DEBUG: 3792: DLL loaded at 0x00007FF99EEA0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x798000 bytes). 2026-06-29 19:36:14,222 [lib.api.process] INFO: Monitor config for process 756: C:\7d7wfxi0\dll\756.ini 2026-06-29 19:36:14,227 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\XVaHDaL.dll, loader C:\7d7wfxi0\bin\OzgDrRsD.exe 2026-06-29 19:36:14,241 [root] DEBUG: Loader: Injecting process 756 with C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:14,250 [root] DEBUG: 756: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:36:14,251 [root] DEBUG: 756: Disabling sleep skipping. 2026-06-29 19:36:14,252 [root] DEBUG: 756: Dropped file limit defaulting to 100. 2026-06-29 19:36:14,256 [root] DEBUG: 756: Services hook set enabled 2026-06-29 19:36:14,262 [root] DEBUG: 756: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-29 19:36:14,285 [root] DEBUG: 756: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:36:14,286 [root] DEBUG: 756: Monitor initialised: 64-bit capemon loaded in process 756 at 0x00007FF9870C0000, thread 1140, image base 0x00007FF69D480000, stack from 0x00000036AC4F4000-0x00000036AC500000 2026-06-29 19:36:14,288 [root] DEBUG: 756: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p 2026-06-29 19:36:14,313 [root] DEBUG: 756: Hooked 69 out of 69 functions 2026-06-29 19:36:14,316 [root] INFO: Loaded monitor into process with pid 756 2026-06-29 19:36:14,319 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread. 2026-06-29 19:36:14,321 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:14,324 [lib.api.process] INFO: Injected into 64-bit <Process 756 svchost.exe> 2026-06-29 19:36:16,359 [root] DEBUG: 3792: CreateProcessHandler: Injection info set for new process 5060: C:\Windows\system32\NOTEPAD.EXE, ImageBase: 0x00007FF737DC0000 2026-06-29 19:36:16,361 [root] INFO: Announced 64-bit process name: notepad.exe pid: 5060 2026-06-29 19:36:16,361 [lib.api.process] INFO: Monitor config for process 5060: C:\7d7wfxi0\dll\5060.ini 2026-06-29 19:36:16,366 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\XVaHDaL.dll, loader C:\7d7wfxi0\bin\OzgDrRsD.exe 2026-06-29 19:36:16,378 [root] DEBUG: Loader: Injecting process 5060 (thread 3940) with C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:16,379 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:36:16,382 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:16,385 [lib.api.process] INFO: Injected into 64-bit <Process 5060 notepad.exe> 2026-06-29 19:36:16,388 [root] INFO: Announced 64-bit process name: notepad.exe pid: 5060 2026-06-29 19:36:16,389 [lib.api.process] INFO: Monitor config for process 5060: C:\7d7wfxi0\dll\5060.ini 2026-06-29 19:36:16,391 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\XVaHDaL.dll, loader C:\7d7wfxi0\bin\OzgDrRsD.exe 2026-06-29 19:36:16,402 [root] DEBUG: Loader: Injecting process 5060 (thread 3940) with C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:16,403 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:36:16,404 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:16,407 [lib.api.process] INFO: Injected into 64-bit <Process 5060 notepad.exe> 2026-06-29 19:36:16,411 [root] DEBUG: 3792: DLL loaded at 0x00007FF998030000: C:\Windows\system32\MPR (0x1d000 bytes). 2026-06-29 19:36:16,412 [root] DEBUG: 3792: DLL loaded at 0x00007FF9A31D0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes). 2026-06-29 19:36:16,436 [root] DEBUG: 5060: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:36:16,437 [root] DEBUG: 5060: Dropped file limit defaulting to 100. 2026-06-29 19:36:16,450 [root] DEBUG: 5060: Disabling sleep skipping. 2026-06-29 19:36:16,453 [root] DEBUG: 5060: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-29 19:36:16,538 [root] DEBUG: 5060: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:36:16,540 [root] DEBUG: 5060: YaraScan: Scanning 0x00007FF737DC0000, size 0x392ee 2026-06-29 19:36:16,545 [root] DEBUG: 5060: Monitor initialised: 64-bit capemon loaded in process 5060 at 0x00007FF9870C0000, thread 3940, image base 0x00007FF737DC0000, stack from 0x00000097E611F000-0x00000097E6130000 2026-06-29 19:36:16,546 [root] DEBUG: 5060: Commandline: "C:\Windows\system32\NOTEPAD.EXE" C:\Users\Rajesh\AppData\Local\Temp\rufus.ini 2026-06-29 19:36:16,568 [root] DEBUG: 5060: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:36:16,633 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:36:16,635 [root] DEBUG: 5060: set_hooks: Unable to hook LockResource 2026-06-29 19:36:16,650 [root] DEBUG: 5060: Hooked 630 out of 631 functions 2026-06-29 19:36:16,656 [root] DEBUG: 5060: Syscall hook installed, syscall logging level 1 2026-06-29 19:36:16,667 [root] DEBUG: 5060: RestoreHeaders: Restored original import table. 2026-06-29 19:36:16,668 [root] INFO: Loaded monitor into process with pid 5060 2026-06-29 19:36:16,679 [root] DEBUG: 5060: caller_dispatch: Added region at 0x00007FF737DC0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF737DE5842, thread 3940). 2026-06-29 19:36:16,681 [root] DEBUG: 5060: YaraScan: Scanning 0x00007FF737DC0000, size 0x392ee 2026-06-29 19:36:16,690 [root] DEBUG: 5060: ProcessImageBase: Main module image at 0x00007FF737DC0000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:36:16,695 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:36:16,703 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:36:16,707 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes). 2026-06-29 19:36:16,714 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:36:16,725 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A06E0000: C:\Windows\System32\MrmCoreR (0xf5000 bytes). 2026-06-29 19:36:16,764 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes). 2026-06-29 19:36:16,765 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes). 2026-06-29 19:36:16,776 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes). 2026-06-29 19:36:16,830 [root] DEBUG: 5060: DLL loaded at 0x00007FF998F00000: C:\Windows\system32\TextShaping (0xac000 bytes). 2026-06-29 19:36:16,854 [root] DEBUG: 5060: DLL loaded at 0x00007FF998030000: C:\Windows\System32\MPR (0x1d000 bytes). 2026-06-29 19:36:16,856 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes). 2026-06-29 19:36:16,857 [root] DEBUG: 5060: DLL loaded at 0x00007FF987B80000: C:\Windows\System32\efswrt (0xde000 bytes). 2026-06-29 19:36:16,867 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A10F0000: C:\Windows\System32\twinapi.appcore (0x201000 bytes). 2026-06-29 19:36:16,982 [root] DEBUG: 5060: DLL loaded at 0x00007FF992900000: C:\Windows\System32\oleacc (0x66000 bytes). 2026-06-29 19:36:17,099 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A6E00000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes). 2026-06-29 19:36:17,102 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A57F0000: C:\Windows\System32\CoreMessaging (0xf2000 bytes). 2026-06-29 19:36:17,103 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A5490000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes). 2026-06-29 19:36:17,104 [root] DEBUG: 5060: DLL loaded at 0x00007FF99BC00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes). 2026-06-29 19:36:17,191 [root] DEBUG: 5060: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes). 2026-06-29 19:36:17,193 [root] DEBUG: 5060: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes). 2026-06-29 19:36:17,196 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes). 2026-06-29 19:36:17,200 [root] DEBUG: 5060: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes). 2026-06-29 19:36:17,237 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A9450000: C:\Windows\System32\COMDLG32 (0xda000 bytes). 2026-06-29 19:36:17,244 [root] DEBUG: 5060: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes). 2026-06-29 19:36:27,999 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 1820: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF712FE0000 2026-06-29 19:36:28,001 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 1820 2026-06-29 19:36:28,002 [lib.api.process] INFO: Monitor config for process 1820: C:\7d7wfxi0\dll\1820.ini 2026-06-29 19:36:28,251 [root] INFO: Analysis timeout hit, terminating analysis 2026-06-29 19:36:28,253 [lib.api.process] INFO: Terminate event set for process 3792 2026-06-29 19:36:28,254 [root] DEBUG: 3792: Terminate Event: Attempting to dump process 3792 2026-06-29 19:36:28,258 [root] DEBUG: 3792: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching 2026-06-29 19:36:28,259 [root] DEBUG: 3792: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000. 2026-06-29 19:36:28,261 [root] DEBUG: 3792: DumpImageInCurrentProcess: Attempting to dump virtual PE image. 2026-06-29 19:36:28,262 [root] DEBUG: 3792: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000. 2026-06-29 19:36:28,263 [root] DEBUG: 3792: DumpProcess: Module entry point VA is 0x00007FF79A468F50. 2026-06-29 19:36:28,286 [lib.common.results] INFO: Uploading file C:\BxeBJc\CAPE\3792_108242836230262026 to procdump\f4dd0d951a26f0fe9d8ea0afcbfb650ce05b3e9e3d31cfdc394da2f1fe8dc80d; Size is 401920; Max size: 100000000 2026-06-29 19:36:28,324 [root] DEBUG: 3792: DumpProcess: Module image dump success - dump size 0x62200. 2026-06-29 19:36:28,340 [root] DEBUG: 3792: Terminate Event: Shutdown complete for process 3792 but failed to inform analyzer. 2026-06-29 19:36:29,500 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\XVaHDaL.dll, loader C:\7d7wfxi0\bin\OzgDrRsD.exe 2026-06-29 19:36:29,524 [root] DEBUG: Loader: Injecting process 1820 (thread 3596) with C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:29,527 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT. 2026-06-29 19:36:29,530 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\XVaHDaL.dll. 2026-06-29 19:36:29,535 [lib.api.process] INFO: Injected into 64-bit <Process 1820 WmiPrvSE.exe> 2026-06-29 19:36:29,561 [root] DEBUG: 1820: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'. 2026-06-29 19:36:29,562 [root] DEBUG: 1820: Dropped file limit defaulting to 100. 2026-06-29 19:36:29,575 [root] DEBUG: 1820: Disabling sleep skipping. 2026-06-29 19:36:29,577 [root] DEBUG: 1820: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac 2026-06-29 19:36:29,608 [root] DEBUG: 1820: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0 2026-06-29 19:36:29,614 [root] DEBUG: 1820: YaraScan: Scanning 0x00007FF712FE0000, size 0x7dcfe 2026-06-29 19:36:29,624 [root] DEBUG: 1820: Monitor initialised: 64-bit capemon loaded in process 1820 at 0x00007FF9870C0000, thread 3596, image base 0x00007FF712FE0000, stack from 0x0000002D0E470000-0x0000002D0E480000 2026-06-29 19:36:29,626 [root] DEBUG: 1820: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -Embedding 2026-06-29 19:36:29,653 [root] DEBUG: 1820: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress 2026-06-29 19:36:29,751 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2' 2026-06-29 19:36:29,754 [root] DEBUG: 1820: set_hooks: Unable to hook LockResource 2026-06-29 19:36:29,769 [root] DEBUG: 1820: Hooked 630 out of 631 functions 2026-06-29 19:36:29,777 [root] DEBUG: 1820: Syscall hook installed, syscall logging level 1 2026-06-29 19:36:29,789 [root] DEBUG: 1820: RestoreHeaders: Restored original import table. 2026-06-29 19:36:29,790 [root] INFO: Loaded monitor into process with pid 1820 2026-06-29 19:36:29,793 [root] DEBUG: 1820: caller_dispatch: Added region at 0x00007FF712FE0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF712FF2CD1, thread 3596). 2026-06-29 19:36:29,795 [root] DEBUG: 1820: YaraScan: Scanning 0x00007FF712FE0000, size 0x7dcfe 2026-06-29 19:36:29,808 [root] DEBUG: 1820: ProcessImageBase: Main module image at 0x00007FF712FE0000 unmodified (entropy change 0.000000e+00) 2026-06-29 19:36:29,830 [root] DEBUG: 1820: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes). 2026-06-29 19:36:29,833 [root] DEBUG: 1820: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes). 2026-06-29 19:36:29,855 [root] DEBUG: 1820: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes). 2026-06-29 19:36:29,867 [root] DEBUG: 1820: DLL loaded at 0x00007FF97FC40000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes). 2026-06-29 19:36:29,890 [root] DEBUG: 1820: DLL loaded at 0x00007FF97FC20000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes). 2026-06-29 19:36:29,955 [root] DEBUG: 1820: DLL loaded at 0x00007FF99E310000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes). 2026-06-29 19:36:33,251 [lib.api.process] INFO: Termination confirmed for process 3792 2026-06-29 19:36:33,252 [root] INFO: Terminate event set for process 3792 2026-06-29 19:36:33,252 [lib.api.process] INFO: Terminate event set for process 756 2026-06-29 19:36:33,253 [root] DEBUG: 756: Terminate Event: Attempting to dump process 756 2026-06-29 19:36:33,255 [root] DEBUG: 756: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:36:33,260 [lib.api.process] INFO: Termination confirmed for process 756 2026-06-29 19:36:33,260 [root] DEBUG: 756: Terminate Event: monitor shutdown complete for process 756 2026-06-29 19:36:33,260 [root] INFO: Terminate event set for process 756 2026-06-29 19:36:33,261 [lib.api.process] INFO: Terminate event set for process 5060 2026-06-29 19:36:33,262 [root] DEBUG: 5060: Terminate Event: Attempting to dump process 5060 2026-06-29 19:36:33,264 [root] DEBUG: 5060: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:36:33,277 [root] DEBUG: 5060: Terminate Event: Shutdown complete for process 5060 but failed to inform analyzer. 2026-06-29 19:36:38,252 [lib.api.process] INFO: Termination confirmed for process 5060 2026-06-29 19:36:38,253 [root] INFO: Terminate event set for process 5060 2026-06-29 19:36:38,253 [lib.api.process] INFO: Terminate event set for process 1820 2026-06-29 19:36:38,254 [root] DEBUG: 1820: Terminate Event: Attempting to dump process 1820 2026-06-29 19:36:38,256 [root] DEBUG: 1820: DoProcessDump: Skipping process dump as code is identical on disk. 2026-06-29 19:36:38,265 [lib.api.process] INFO: Termination confirmed for process 1820 2026-06-29 19:36:38,266 [root] INFO: Terminate event set for process 1820 2026-06-29 19:36:38,266 [root] DEBUG: 1820: Terminate Event: monitor shutdown complete for process 1820 2026-06-29 19:36:38,266 [root] INFO: Created shutdown mutex 2026-06-29 19:36:39,276 [root] INFO: Shutting down package 2026-06-29 19:36:39,277 [root] INFO: Stopping auxiliary modules 2026-06-29 19:36:39,277 [root] INFO: Stopping auxiliary module: Browser 2026-06-29 19:36:39,278 [root] INFO: Stopping auxiliary module: Human 2026-06-29 19:36:39,699 [root] INFO: Finishing auxiliary modules 2026-06-29 19:36:39,700 [root] INFO: Shutting down pipe server and dumping dropped files 2026-06-29 19:36:39,705 [root] WARNING: Folder at path "C:\BxeBJc\debugger" does not exist, skipping 2026-06-29 19:36:39,709 [root] WARNING: Folder at path "C:\BxeBJc\tlsdump" does not exist, skipping 2026-06-29 19:36:39,711 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-29 19:35:56 | 2026-06-29 19:36:44 | internet |
| File Name |
rufus.ini
|
|---|---|
| File Type | ASCII text, with CRLF line terminators |
| File Size | 107 bytes |
| MD5 | 8a78a90f6c9c3b0da292006dd16b4cd1 |
| SHA1 | 82c2a11d4ccba12662a05e3f60741338eba051a3 |
| SHA256 | eb5be587219b06d6b089f104095b98c119c73495a3e09c584b10d29defb112bd VT MWDB Bazaar |
| SHA3-384 | b618a4c8b3a2dc0e9a983ff4171e854ce27f17a95e5409fb73874cb28eabcca7304d2feb1cf36e3c61f2253474e0830d |
| CRC32 | 324E6668 |
| TLSH | T1F4B012183F062CB736F7121C7D4208813DEE8D274B0BA421A6CAAC82010EC07C35A904 |
| Ssdeep | 3:5HQAFoSzWx1jXDJiFIvJmyFMu67MKii8p6cv:5BlzWx1jlm8myF967MKEp6e |
Locale = en-US CommCheck64 = 7277031 UpdateCheckInterval = -1 WindowsUserExperienceOptions = 385810517
No results found.
No behavioral analysis data available.
No dropped files found.