| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| FILE | batch | 2026-06-29 10:30:20 | 2026-06-29 10:34:32 | 252s |
|
|||||
| Reports | JSON | |||||||||
vnc_port=5900
2026-06-28 14:55:57,984 [root] INFO: Date set to: 20260629T10:30:24, timeout set to: 200
2026-06-29 10:30:24,412 [root] DEBUG: Starting analyzer from: C:\7d7wfxi0
2026-06-29 10:30:24,414 [root] DEBUG: Storing results at: C:\cUJPOo
2026-06-29 10:30:24,414 [root] DEBUG: Pipe server name: \\.\PIPE\pcWTWbc
2026-06-29 10:30:24,414 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314
2026-06-29 10:30:24,415 [root] INFO: analysis running as an admin
2026-06-29 10:30:24,415 [root] DEBUG: no analysis package configured, picking one for you
2026-06-29 10:30:24,420 [root] INFO: analysis package selected: "batch"
2026-06-29 10:30:24,421 [root] DEBUG: importing analysis package module: "modules.packages.batch"...
2026-06-29 10:30:24,439 [root] DEBUG: imported analysis package "batch"
2026-06-29 10:30:24,441 [root] DEBUG: initializing analysis package "batch"...
2026-06-29 10:30:24,441 [lib.common.common] INFO: no wrapping
2026-06-29 10:30:24,446 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-29 10:30:24,456 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\MEMZ.bat
2026-06-29 10:30:24,457 [root] INFO: Analyzer: Package modules.packages.batch does not specify a dll option
2026-06-29 10:30:24,457 [root] INFO: Analyzer: Package modules.packages.batch does not specify a dll_64 option
2026-06-29 10:30:24,458 [root] INFO: Analyzer: Package modules.packages.batch does not specify a loader option
2026-06-29 10:30:24,458 [root] INFO: Analyzer: Package modules.packages.batch does not specify a loader_64 option
2026-06-28 14:56:02,151 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-06-28 14:56:02,183 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-06-28 14:56:02,385 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-06-28 14:56:02,414 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-06-28 14:56:02,421 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-06-28 14:56:02,423 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-06-28 14:56:02,425 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-06-28 14:56:02,429 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-06-28 14:56:02,435 [root] DEBUG: Initialized auxiliary module "Browser"
2026-06-28 14:56:02,436 [root] DEBUG: attempting to configure 'Browser' from data
2026-06-28 14:56:02,437 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-06-28 14:56:02,438 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-06-28 14:56:02,504 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-06-28 14:56:02,505 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-06-28 14:56:02,505 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-06-28 14:56:02,505 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-06-28 14:56:02,505 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-06-28 14:56:02,506 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-06-28 14:56:03,152 [modules.auxiliary.digisig] DEBUG: File has an invalid signature
2026-06-28 14:56:03,153 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-06-28 14:56:03,156 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-06-28 14:56:03,156 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-06-28 14:56:03,156 [root] DEBUG: attempting to configure 'Disguise' from data
2026-06-28 14:56:03,157 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-06-28 14:56:03,158 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-06-28 14:56:03,163 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 2076)
2026-06-28 14:56:03,176 [modules.auxiliary.disguise] INFO: Disguising GUID to ea3bc399-0532-4a02-974e-f04172268c8e
2026-06-28 14:56:03,177 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-06-28 14:56:03,178 [root] DEBUG: Initialized auxiliary module "Human"
2026-06-28 14:56:03,178 [root] DEBUG: attempting to configure 'Human' from data
2026-06-28 14:56:03,178 [root] DEBUG: module Human does not support data configuration, ignoring
2026-06-28 14:56:03,179 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-06-28 14:56:03,181 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-06-28 14:56:03,181 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-06-28 14:56:03,182 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-06-28 14:56:03,182 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-06-28 14:56:03,183 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-06-28 14:56:03,197 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-06-28 14:56:03,197 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-06-28 14:56:03,199 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-06-28 14:56:03,199 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-06-28 14:56:03,200 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-06-28 14:56:03,201 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-06-28 14:56:03,205 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-06-28 14:56:03,207 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-06-28 14:56:09,885 [root] INFO: Restarting WMI Service
2026-06-28 14:56:12,058 [root] DEBUG: package modules.packages.batch does not support configure, ignoring
2026-06-28 14:56:12,060 [root] WARNING: configuration error for package modules.packages.batch: error importing data.packages.batch: No module named 'data.packages'
2026-06-28 14:56:12,062 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-28 14:56:12,065 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\cmd.exe" with arguments "/c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\MEMZ.bat"" with pid 4660
2026-06-28 14:56:12,679 [lib.api.process] INFO: Monitor config for process 4660: C:\7d7wfxi0\dll\4660.ini
2026-06-28 14:56:12,756 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-28 14:56:12,819 [root] DEBUG: Loader: Injecting process 4660 (thread 1468) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-28 14:56:12,826 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-28 14:56:12,827 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-28 14:56:12,831 [lib.api.process] INFO: Injected into 64-bit <Process 4660 cmd.exe>
2026-06-28 14:56:14,854 [lib.api.process] INFO: Successfully resumed process with pid 4660
2026-06-28 14:56:15,332 [root] DEBUG: 4660: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-28 14:56:15,366 [root] DEBUG: 4660: Disabling sleep skipping.
2026-06-28 14:56:15,383 [root] DEBUG: 4660: Dropped file limit defaulting to 100.
2026-06-28 14:56:15,413 [root] DEBUG: 4660: YaraInit: Compiled 44 rule files
2026-06-28 14:56:15,424 [root] DEBUG: 4660: YaraInit: Compiled rules saved to file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-28 14:56:15,488 [root] DEBUG: 4660: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-28 14:56:15,489 [root] DEBUG: 4660: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a
2026-06-28 14:56:15,495 [root] DEBUG: 4660: YaraScan hit: FindFixAndRun
2026-06-28 14:56:15,496 [root] DEBUG: 4660: Monitor initialised: 64-bit capemon loaded in process 4660 at 0x00007FF9840E0000, thread 1468, image base 0x00007FF79A450000, stack from 0x0000006CE1A04000-0x0000006CE1B00000
2026-06-28 14:56:15,497 [root] DEBUG: 4660: Commandline: "C:\Windows\system32\cmd.exe" /c start /wait "" "C:\Users\Rajesh\AppData\Local\Temp\MEMZ.bat"
2026-06-28 14:56:15,517 [root] DEBUG: 4660: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-28 14:56:15,584 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-28 14:56:15,586 [root] DEBUG: 4660: set_hooks: Unable to hook LockResource
2026-06-28 14:56:15,608 [root] DEBUG: 4660: Hooked 630 out of 631 functions
2026-06-28 14:56:15,613 [root] DEBUG: 4660: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620
2026-06-28 14:56:15,616 [root] DEBUG: 4660: Syscall hook installed, syscall logging level 1
2026-06-28 14:56:15,634 [root] DEBUG: 4660: RestoreHeaders: Restored original import table.
2026-06-28 14:56:15,636 [root] INFO: Loaded monitor into process with pid 4660
2026-06-28 14:56:15,638 [root] DEBUG: 4660: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 1468).
2026-06-28 14:56:15,640 [root] DEBUG: 4660: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a
2026-06-28 14:56:15,648 [root] DEBUG: 4660: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00)
2026-06-28 14:56:15,679 [root] DEBUG: 4660: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes).
2026-06-28 14:56:15,681 [root] DEBUG: 4660: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes).
2026-06-28 14:56:15,690 [root] DEBUG: 4660: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-06-28 14:56:15,695 [root] DEBUG: 4660: CreateProcessHandler: Injection info set for new process 3152: C:\Windows\system32\cmd.exe, ImageBase: 0x00007FF79A450000
2026-06-28 14:56:15,697 [root] INFO: Announced 64-bit process name: cmd.exe pid: 3152
2026-06-28 14:56:15,700 [lib.api.process] INFO: Monitor config for process 3152: C:\7d7wfxi0\dll\3152.ini
2026-06-28 14:56:15,705 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-28 14:56:15,719 [root] DEBUG: Loader: Injecting process 3152 (thread 3760) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-28 14:56:15,721 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-28 14:56:15,726 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-28 14:56:15,730 [lib.api.process] INFO: Injected into 64-bit <Process 3152 cmd.exe>
2026-06-28 14:56:15,739 [root] INFO: Announced 64-bit process name: cmd.exe pid: 3152
2026-06-28 14:56:15,743 [lib.api.process] INFO: Monitor config for process 3152: C:\7d7wfxi0\dll\3152.ini
2026-06-28 14:56:15,747 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-28 14:56:15,768 [root] DEBUG: Loader: Injecting process 3152 (thread 3760) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-28 14:56:15,770 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-28 14:56:15,771 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-28 14:56:15,775 [lib.api.process] INFO: Injected into 64-bit <Process 3152 cmd.exe>
2026-06-28 14:56:15,964 [root] DEBUG: 3152: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-28 14:56:15,970 [root] DEBUG: 3152: Dropped file limit defaulting to 100.
2026-06-28 14:56:15,976 [root] DEBUG: 3152: Disabling sleep skipping.
2026-06-28 14:56:15,983 [root] DEBUG: 3152: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-28 14:56:16,007 [root] DEBUG: 3152: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-28 14:56:16,009 [root] DEBUG: 3152: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a
2026-06-28 14:56:16,015 [root] DEBUG: 3152: YaraScan hit: FindFixAndRun
2026-06-28 14:56:16,017 [root] DEBUG: 3152: Monitor initialised: 64-bit capemon loaded in process 3152 at 0x00007FF9840E0000, thread 3760, image base 0x00007FF79A450000, stack from 0x000000DEE4C04000-0x000000DEE4D00000
2026-06-28 14:56:16,018 [root] DEBUG: 3152: Commandline: C:\Windows\system32\cmd.exe /K "C:\Users\Rajesh\AppData\Local\Temp\MEMZ.bat"
2026-06-28 14:56:16,038 [root] DEBUG: 3152: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-28 14:56:16,097 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-28 14:56:16,126 [root] DEBUG: 3152: set_hooks: Unable to hook LockResource
2026-06-28 14:56:16,139 [root] DEBUG: 3152: Hooked 630 out of 631 functions
2026-06-28 14:56:16,147 [root] DEBUG: 3152: set_hooks_exe: Hooked FindFixAndRun at 0x00007FF79A45C620
2026-06-28 14:56:16,151 [root] DEBUG: 3152: Syscall hook installed, syscall logging level 1
2026-06-28 14:56:16,163 [root] DEBUG: 3152: RestoreHeaders: Restored original import table.
2026-06-28 14:56:16,164 [root] INFO: Loaded monitor into process with pid 3152
2026-06-28 14:56:16,167 [root] DEBUG: 3152: caller_dispatch: Added region at 0x00007FF79A450000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF79A4693C1, thread 3760).
2026-06-28 14:56:16,179 [root] DEBUG: 3152: YaraScan: Scanning 0x00007FF79A450000, size 0x6630a
2026-06-28 14:56:16,195 [root] DEBUG: 3152: ProcessImageBase: Main module image at 0x00007FF79A450000 unmodified (entropy change 0.000000e+00)
2026-06-28 14:56:16,252 [root] DEBUG: 3152: DLL loaded at 0x00007FF99E300000: C:\Windows\SYSTEM32\cmdext (0xc000 bytes).
2026-06-28 14:56:16,318 [root] INFO: Added new file to list with pid 3152 and path C:\Users\Rajesh\AppData\Local\Temp\x
2026-06-29 03:30:48,855 [root] DEBUG: 3152: Dropped file limit reached.
2026-06-29 03:30:50,309 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A7A90000: C:\Windows\system32\Wldp (0x2c000 bytes).
2026-06-29 03:30:50,313 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A6230000: C:\Windows\SYSTEM32\windows.storage (0x790000 bytes).
2026-06-29 03:30:50,326 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-06-29 03:30:50,362 [root] DEBUG: 3152: CreateProcessHandler: Injection info set for new process 5364: C:\Windows\system32\cscript.exe, ImageBase: 0x00007FF68D880000
2026-06-29 03:30:50,405 [root] INFO: Announced 64-bit process name: cscript.exe pid: 5364
2026-06-29 03:30:50,407 [lib.api.process] INFO: Monitor config for process 5364: C:\7d7wfxi0\dll\5364.ini
2026-06-29 03:30:50,419 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:30:50,435 [root] DEBUG: Loader: Injecting process 5364 (thread 5368) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:30:50,437 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:30:50,439 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:30:50,443 [lib.api.process] INFO: Injected into 64-bit <Process 5364 cscript.exe>
2026-06-29 03:30:50,451 [root] INFO: Announced 64-bit process name: cscript.exe pid: 5364
2026-06-29 03:30:50,452 [lib.api.process] INFO: Monitor config for process 5364: C:\7d7wfxi0\dll\5364.ini
2026-06-29 03:30:50,462 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:30:50,497 [root] DEBUG: Loader: Injecting process 5364 (thread 5368) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:30:50,507 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:30:50,507 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:30:50,513 [lib.api.process] INFO: Injected into 64-bit <Process 5364 cscript.exe>
2026-06-29 03:30:50,540 [root] DEBUG: 5364: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:30:50,541 [root] DEBUG: 5364: Dropped file limit defaulting to 100.
2026-06-29 03:30:50,549 [root] DEBUG: 5364: Disabling sleep skipping.
2026-06-29 03:30:50,552 [root] DEBUG: 5364: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:30:50,578 [root] DEBUG: 5364: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 03:30:50,579 [root] DEBUG: 5364: YaraScan: Scanning 0x00007FF68D880000, size 0x2b9fc
2026-06-29 03:30:50,583 [root] DEBUG: 5364: Monitor initialised: 64-bit capemon loaded in process 5364 at 0x00007FF9840E0000, thread 5368, image base 0x00007FF68D880000, stack from 0x000000FE343B4000-0x000000FE343C0000
2026-06-29 03:30:50,584 [root] DEBUG: 5364: Commandline: cscript x.js
2026-06-29 03:30:50,603 [root] DEBUG: 5364: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 03:30:50,772 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 03:30:50,779 [root] DEBUG: 5364: set_hooks: Unable to hook LockResource
2026-06-29 03:30:50,808 [root] DEBUG: 5364: Hooked 630 out of 631 functions
2026-06-29 03:30:50,839 [root] DEBUG: 5364: Syscall hook installed, syscall logging level 1
2026-06-29 03:30:50,855 [root] DEBUG: 5364: RestoreHeaders: Restored original import table.
2026-06-29 03:30:50,856 [root] INFO: Loaded monitor into process with pid 5364
2026-06-29 03:30:50,861 [root] DEBUG: 5364: caller_dispatch: Added region at 0x00007FF68D880000 to tracked regions list (kernel32::GetUserDefaultLCID returns to 0x00007FF68D885B52, thread 5368).
2026-06-29 03:30:50,862 [root] DEBUG: 5364: YaraScan: Scanning 0x00007FF68D880000, size 0x2b9fc
2026-06-29 03:30:50,868 [root] DEBUG: 5364: ProcessImageBase: Main module image at 0x00007FF68D880000 unmodified (entropy change 0.000000e+00)
2026-06-29 03:30:50,887 [root] DEBUG: 5364: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 03:30:50,889 [root] DEBUG: 5364: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 03:30:50,894 [root] DEBUG: 5364: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 03:30:50,961 [root] DEBUG: 5364: DLL loaded at 0x00007FF9A7E50000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-06-29 03:30:50,974 [root] DEBUG: 5364: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes).
2026-06-29 03:30:51,027 [root] DEBUG: 5364: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 03:30:51,057 [root] DEBUG: 5364: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\shcore (0xad000 bytes).
2026-06-29 03:30:51,059 [root] DEBUG: 5364: DLL loaded at 0x00007FF99F680000: C:\Windows\System32\iertutil (0x2b0000 bytes).
2026-06-29 03:30:51,074 [root] DEBUG: 5364: DLL loaded at 0x00007FF9897E0000: C:\Windows\System32\jscript (0xd9000 bytes).
2026-06-29 03:30:51,092 [root] DEBUG: 5364: DLL loaded at 0x00007FF99E360000: C:\Windows\SYSTEM32\amsi (0x19000 bytes).
2026-06-29 03:30:51,099 [lib.api.process] INFO: Monitor config for process 756: C:\7d7wfxi0\dll\756.ini
2026-06-29 03:30:51,105 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:30:51,129 [root] DEBUG: Loader: Injecting process 756 with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:30:51,200 [root] DEBUG: 756: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:30:51,204 [root] DEBUG: 756: Disabling sleep skipping.
2026-06-29 03:30:51,205 [root] DEBUG: 756: Dropped file limit defaulting to 100.
2026-06-29 03:30:51,208 [root] DEBUG: 756: Services hook set enabled
2026-06-29 03:30:51,212 [root] DEBUG: 756: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:30:51,235 [root] DEBUG: 756: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 03:30:51,236 [root] DEBUG: 756: Monitor initialised: 64-bit capemon loaded in process 756 at 0x00007FF9840E0000, thread 5696, image base 0x00007FF69D480000, stack from 0x00000036AC474000-0x00000036AC480000
2026-06-29 03:30:51,237 [root] DEBUG: 756: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-06-29 03:30:51,255 [root] DEBUG: 756: Hooked 69 out of 69 functions
2026-06-29 03:30:51,257 [root] INFO: Loaded monitor into process with pid 756
2026-06-29 03:30:51,259 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-29 03:30:51,260 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:30:51,270 [lib.api.process] INFO: Injected into 64-bit <Process 756 svchost.exe>
2026-06-29 03:30:52,622 [modules.auxiliary.human] INFO: Found button "yes", clicking it
2026-06-29 03:30:53,290 [root] DEBUG: 5364: NtTerminateProcess hook: Attempting to dump process 5364
2026-06-29 03:30:53,291 [root] DEBUG: 5364: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:30:53,396 [root] INFO: Process with pid 5364 has terminated
2026-06-29 03:30:53,483 [root] DEBUG: 3152: CreateProcessHandler: Injection info set for new process 5896: C:\Users\Rajesh\AppData\Roaming\MEMZ.exe, ImageBase: 0x0000000000B30000
2026-06-29 03:30:53,485 [root] INFO: Announced 32-bit process name: MEMZ.exe pid: 5896
2026-06-29 03:30:53,486 [lib.api.process] INFO: Monitor config for process 5896: C:\7d7wfxi0\dll\5896.ini
2026-06-29 03:30:53,493 [lib.api.process] INFO: 32-bit DLL to inject is C:\7d7wfxi0\dll\hJaFnIOU.dll, loader C:\7d7wfxi0\bin\wdHkqEG.exe
2026-06-29 03:30:53,520 [root] DEBUG: Loader: Injecting process 5896 (thread 5900) with C:\7d7wfxi0\dll\hJaFnIOU.dll.
2026-06-29 03:30:53,521 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:30:53,522 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\hJaFnIOU.dll.
2026-06-29 03:30:53,530 [lib.api.process] INFO: Injected into 32-bit <Process 5896 MEMZ.exe>
2026-06-29 03:30:53,544 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 03:30:53,548 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 03:30:53,553 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 03:30:53,565 [root] DEBUG: 3152: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes).
2026-06-29 03:30:53,570 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\PROPSYS (0xf6000 bytes).
2026-06-29 03:30:53,578 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 03:30:53,600 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A8050000: C:\Windows\system32\profapi (0x1f000 bytes).
2026-06-29 03:30:53,808 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-06-29 03:30:53,875 [root] DEBUG: 3152: DLL loaded at 0x00007FF993730000: C:\Windows\system32\edputil (0x24000 bytes).
2026-06-29 03:30:53,971 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-06-29 03:30:53,987 [root] DEBUG: 3152: DLL loaded at 0x00007FF99F680000: C:\Windows\system32\iertutil (0x2b0000 bytes).
2026-06-29 03:30:53,989 [root] DEBUG: 3152: DLL loaded at 0x00007FF99F650000: C:\Windows\system32\srvcli (0x28000 bytes).
2026-06-29 03:30:53,990 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A75F0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-06-29 03:30:53,994 [root] DEBUG: 3152: DLL loaded at 0x00007FF99F930000: C:\Windows\system32\urlmon (0x1eb000 bytes).
2026-06-29 03:30:54,078 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\System32\wintypes (0x154000 bytes).
2026-06-29 03:30:54,094 [root] DEBUG: 3152: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes).
2026-06-29 03:30:54,096 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A6C60000: C:\Windows\System32\sppc (0x25000 bytes).
2026-06-29 03:30:54,097 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A6C90000: C:\Windows\System32\SLC (0x29000 bytes).
2026-06-29 03:30:54,098 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A7F80000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-06-29 03:30:54,100 [root] DEBUG: 3152: DLL loaded at 0x00007FF9971F0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-06-29 03:30:54,118 [root] DEBUG: 3152: DLL loaded at 0x00007FF99D480000: C:\Windows\System32\OneCoreCommonProxyStub (0x7d000 bytes).
2026-06-29 03:30:54,129 [root] DEBUG: 3152: DLL loaded at 0x00007FF99EEA0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x798000 bytes).
2026-06-29 03:30:54,145 [root] DEBUG: 3152: CreateProcessHandler: Injection info set for new process 6064: C:\Users\Rajesh\AppData\Roaming\MEMZ.exe, ImageBase: 0x0000000000B30000
2026-06-29 03:30:54,147 [root] INFO: Announced 32-bit process name: MEMZ.exe pid: 6064
2026-06-29 03:30:54,148 [lib.api.process] INFO: Monitor config for process 6064: C:\7d7wfxi0\dll\6064.ini
2026-06-29 03:30:54,155 [lib.api.process] INFO: 32-bit DLL to inject is C:\7d7wfxi0\dll\hJaFnIOU.dll, loader C:\7d7wfxi0\bin\wdHkqEG.exe
2026-06-29 03:30:54,171 [root] DEBUG: Loader: Injecting process 6064 (thread 6068) with C:\7d7wfxi0\dll\hJaFnIOU.dll.
2026-06-29 03:30:54,173 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:30:54,175 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\hJaFnIOU.dll.
2026-06-29 03:30:54,178 [lib.api.process] INFO: Injected into 32-bit <Process 6064 MEMZ.exe>
2026-06-29 03:30:54,185 [root] DEBUG: 3152: DLL loaded at 0x00007FF998030000: C:\Windows\system32\MPR (0x1d000 bytes).
2026-06-29 03:30:54,255 [root] DEBUG: 3152: DLL loaded at 0x00007FF9A31D0000: C:\Windows\SYSTEM32\pcacli (0x16000 bytes).
2026-06-29 03:30:56,497 [modules.auxiliary.human] INFO: Found button "yes", clicking it
2026-06-29 03:30:57,530 [modules.auxiliary.human] INFO: Found button "yes", clicking it
2026-06-29 03:31:05,503 [root] DEBUG: 3152: NtTerminateProcess hook: Attempting to dump process 3152
2026-06-29 03:31:05,504 [root] DEBUG: 3152: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching
2026-06-29 03:31:05,516 [root] DEBUG: 3152: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000.
2026-06-29 03:31:05,519 [root] DEBUG: 3152: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-06-29 03:31:05,521 [root] DEBUG: 3152: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000.
2026-06-29 03:31:05,564 [root] DEBUG: 3152: DumpProcess: Module entry point VA is 0x00007FF79A468F50.
2026-06-29 03:31:05,631 [lib.common.results] INFO: Uploading file C:\cUJPOo\CAPE\3152_234115311029162026 to procdump\921a1ee9ec0105a910cfca72352d4cef24a0fbcf55b66e58169a873a05445cdf; Size is 403456; Max size: 100000000
2026-06-29 03:31:05,654 [root] DEBUG: 3152: DumpProcess: Module image dump success - dump size 0x62800.
2026-06-29 03:31:05,697 [root] INFO: Process with pid 3152 has terminated
2026-06-29 03:31:05,825 [root] DEBUG: 4660: NtTerminateProcess hook: Attempting to dump process 4660
2026-06-29 03:31:05,827 [root] DEBUG: 4660: VerifyCodeSection: Executable code does not match, 0xb620 of 0x30ef9 matching
2026-06-29 03:31:05,828 [root] DEBUG: 4660: DoProcessDump: Code modification detected, dumping Imagebase at 0x00007FF79A450000.
2026-06-29 03:31:05,919 [root] DEBUG: 4660: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-06-29 03:31:05,920 [root] DEBUG: 4660: DumpProcess: Instantiating PeParser with address: 0x00007FF79A450000.
2026-06-29 03:31:05,921 [root] DEBUG: 4660: DumpProcess: Module entry point VA is 0x00007FF79A468F50.
2026-06-29 03:31:05,954 [lib.common.results] INFO: Uploading file C:\cUJPOo\CAPE\4660_47702255311029162026 to procdump\e3e8ce7a3a044a4eca3ba5b0eecc02041e9e1c8b5501640a49d4a5959e09be67; Size is 401920; Max size: 100000000
2026-06-29 03:31:06,073 [root] DEBUG: 4660: DumpProcess: Module image dump success - dump size 0x62200.
2026-06-29 03:31:06,140 [root] INFO: Process with pid 4660 has terminated
2026-06-29 03:32:22,900 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 3516: C:\Windows\explorer.exe, ImageBase: 0x00007FF66FFC0000
2026-06-29 03:32:22,907 [root] INFO: Announced 64-bit process name: explorer.exe pid: 3516
2026-06-29 03:32:22,909 [lib.api.process] INFO: Monitor config for process 3516: C:\7d7wfxi0\dll\3516.ini
2026-06-29 03:32:22,919 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:32:22,953 [root] DEBUG: Loader: Injecting process 3516 (thread 2852) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:22,956 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:32:22,958 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:22,986 [lib.api.process] INFO: Injected into 64-bit <Process 3516 explorer.exe>
2026-06-29 03:32:22,989 [root] INFO: Announced 64-bit process name: explorer.exe pid: 3516
2026-06-29 03:32:22,990 [lib.api.process] INFO: Monitor config for process 3516: C:\7d7wfxi0\dll\3516.ini
2026-06-29 03:32:22,996 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:32:23,081 [root] DEBUG: Loader: Injecting process 3516 (thread 2852) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:23,132 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:32:23,133 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:23,139 [lib.api.process] INFO: Injected into 64-bit <Process 3516 explorer.exe>
2026-06-29 03:32:23,216 [root] DEBUG: 3516: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:32:23,218 [root] DEBUG: 3516: Dropped file limit defaulting to 100.
2026-06-29 03:32:23,238 [root] DEBUG: 3516: Disabling sleep skipping.
2026-06-29 03:32:23,242 [root] DEBUG: 3516: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:32:23,273 [root] DEBUG: 3516: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 03:32:23,275 [root] DEBUG: 3516: YaraScan: Scanning 0x00007FF66FFC0000, size 0x49c0a4
2026-06-29 03:32:23,399 [root] DEBUG: 3516: Monitor initialised: 64-bit capemon loaded in process 3516 at 0x00007FF9840E0000, thread 2852, image base 0x00007FF66FFC0000, stack from 0x0000000000742000-0x0000000000750000
2026-06-29 03:32:23,409 [root] DEBUG: 3516: Commandline: C:\Windows\explorer.exe /factory,{5BD95610-9434-43C2-886C-57852CC8A120} -Embedding
2026-06-29 03:32:23,433 [root] DEBUG: 3516: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 03:32:23,486 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 03:32:23,497 [root] DEBUG: 3516: set_hooks: Unable to hook LockResource
2026-06-29 03:32:23,529 [root] DEBUG: 3516: Hooked 630 out of 631 functions
2026-06-29 03:32:23,590 [root] DEBUG: 3516: Syscall hook installed, syscall logging level 1
2026-06-29 03:32:23,616 [root] DEBUG: 3516: RestoreHeaders: Restored original import table.
2026-06-29 03:32:23,619 [root] INFO: Loaded monitor into process with pid 3516
2026-06-29 03:32:23,645 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 03:32:23,673 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A7F60000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-06-29 03:32:23,702 [root] DEBUG: 3516: caller_dispatch: Added region at 0x00007FF66FFC0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6700603B2, thread 2852).
2026-06-29 03:32:23,704 [root] DEBUG: 3516: YaraScan: Scanning 0x00007FF66FFC0000, size 0x49c0a4
2026-06-29 03:32:23,792 [root] DEBUG: 3516: ProcessImageBase: Main module image at 0x00007FF66FFC0000 unmodified (entropy change 0.000000e+00)
2026-06-29 03:32:23,875 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 03:32:23,915 [root] DEBUG: 3516: DLL loaded at 0x00007FF99DDA0000: C:\Windows\SYSTEM32\NInput (0x6a000 bytes).
2026-06-29 03:32:23,924 [root] DEBUG: 3516: DLL loaded at 0x00007FF992630000: C:\Windows\system32\explorerframe (0x220000 bytes).
2026-06-29 03:32:24,013 [root] DEBUG: 3516: DLL loaded at 0x00007FF99CC30000: C:\Windows\System32\ActXPrxy (0xa1000 bytes).
2026-06-29 03:32:24,022 [root] DEBUG: 3516: DLL loaded at 0x00007FF994050000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\comctl32 (0x29a000 bytes).
2026-06-29 03:32:24,055 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A9A10000: C:\Windows\System32\MSCTF (0x115000 bytes).
2026-06-29 03:32:24,078 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-29 03:32:24,088 [root] DEBUG: 3516: OpenProcessHandler: Injection info created for process 2892, handle 0x448: Error obtaining target process name
2026-06-29 03:32:24,125 [lib.api.process] INFO: Monitor config for process 2892: C:\7d7wfxi0\dll\2892.ini
2026-06-29 03:32:24,134 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:32:24,168 [root] DEBUG: Loader: Injecting process 2892 with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:24,172 [root] DEBUG: 2892: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:32:24,173 [root] DEBUG: 2892: Disabling sleep skipping.
2026-06-29 03:32:24,174 [root] DEBUG: 2892: Dropped file limit defaulting to 100.
2026-06-29 03:32:24,197 [root] DEBUG: 2892: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:32:24,236 [root] DEBUG: 2892: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 03:32:24,237 [root] DEBUG: 2892: YaraScan: Scanning 0x00007FF66FFC0000, size 0x49c0a4
2026-06-29 03:32:24,294 [root] DEBUG: 2892: Monitor initialised: 64-bit capemon loaded in process 2892 at 0x00007FF9840E0000, thread 2544, image base 0x00007FF66FFC0000, stack from 0x0000000008632000-0x0000000008640000
2026-06-29 03:32:24,296 [root] DEBUG: 2892: Commandline: C:\Windows\Explorer.EXE
2026-06-29 03:32:24,312 [root] DEBUG: 2892: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 03:32:24,372 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 03:32:24,374 [root] DEBUG: 2892: set_hooks: Unable to hook LockResource
2026-06-29 03:32:24,411 [root] DEBUG: 2892: Hooked 630 out of 631 functions
2026-06-29 03:32:24,547 [root] DEBUG: 2892: Syscall hook installed, syscall logging level 1
2026-06-29 03:32:24,572 [root] INFO: Loaded monitor into process with pid 2892
2026-06-29 03:32:24,587 [root] DEBUG: 2892: caller_dispatch: Added region at 0x00007FF66FFC0000 to tracked regions list (user32::GetSystemMetrics returns to 0x00007FF66FFE50CC, thread 2616).
2026-06-29 03:32:24,588 [root] DEBUG: 2892: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-06-29 03:32:24,590 [root] DEBUG: 2892: YaraScan: Scanning 0x00007FF66FFC0000, size 0x49c0a4
2026-06-29 03:32:24,684 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-29 03:32:24,694 [root] DEBUG: 2892: ProcessImageBase: Main module image at 0x00007FF66FFC0000 unmodified (entropy change 0.000000e+00)
2026-06-29 03:32:24,715 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:24,731 [lib.api.process] INFO: Injected into 64-bit <Process 2892 explorer.exe>
2026-06-29 03:32:26,385 [lib.api.process] INFO: Monitor config for process 2892: C:\7d7wfxi0\dll\2892.ini
2026-06-29 03:32:26,400 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:32:26,438 [root] DEBUG: Loader: Injecting process 2892 with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:26,458 [root] DEBUG: 2892: caller_dispatch: Added region at 0x00000000012F0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00000000012F0042, thread 444).
2026-06-29 03:32:26,460 [root] DEBUG: 2892: DumpPEsInRange: Scanning range 0x00000000012F0000 - 0x00000000012F0133.
2026-06-29 03:32:26,461 [root] DEBUG: 2892: ScanForDisguisedPE: Size too small: 0x133 bytes
2026-06-29 03:32:26,477 [lib.common.results] INFO: Uploading file C:\cUJPOo\CAPE\2892_1935226321029162026 to CAPE\59d24ea4d6de8e7d0f8c6979e8f93f9e5384426468785104909dc8a92a4dbac4; Size is 307; Max size: 100000000
2026-06-29 03:32:26,506 [root] DEBUG: 2892: DumpMemory: Payload successfully created: C:\cUJPOo\CAPE\2892_1935226321029162026 (size 307 bytes)
2026-06-29 03:32:26,507 [root] DEBUG: 2892: DumpRegion: Dumped entire allocation from 0x00000000012F0000, size 4096 bytes.
2026-06-29 03:32:26,508 [root] DEBUG: 2892: ProcessTrackedRegion: Dumped region at 0x00000000012F0000.
2026-06-29 03:32:26,509 [root] DEBUG: 2892: YaraScan: Scanning 0x00000000012F0000, size 0x133
2026-06-29 03:32:26,536 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-06-29 03:32:26,537 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:26,543 [lib.api.process] INFO: Injected into 64-bit <Process 2892 explorer.exe>
2026-06-29 03:32:26,760 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A7E50000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-06-29 03:32:26,882 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 3516, handle 0x24bc: C:\Windows\explorer.exe
2026-06-29 03:32:26,883 [root] DEBUG: 3516: DLL loaded at 0x00007FF988070000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-06-29 03:32:26,913 [root] DEBUG: 3516: DLL loaded at 0x00007FF987FD0000: C:\Windows\system32\DUser (0x95000 bytes).
2026-06-29 03:32:27,053 [root] DEBUG: 3516: DLL loaded at 0x00007FF99CF00000: C:\Windows\SYSTEM32\WindowsCodecs (0x1b4000 bytes).
2026-06-29 03:32:27,073 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A8050000: C:\Windows\SYSTEM32\profapi (0x1f000 bytes).
2026-06-29 03:32:27,106 [root] DEBUG: 3516: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2026-06-29 03:32:27,140 [root] DEBUG: 3516: api-rate-cap: NtReleaseMutant hook disabled due to rate
2026-06-29 03:32:27,255 [root] DEBUG: 3516: DLL loaded at 0x00007FF992850000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-06-29 03:32:27,307 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A7200000: C:\Windows\SYSTEM32\msvcp110_win (0x8a000 bytes).
2026-06-29 03:32:27,322 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A35E0000: C:\Windows\SYSTEM32\policymanager (0xa0000 bytes).
2026-06-29 03:32:27,432 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A43A0000: C:\Windows\system32\d3d11 (0x264000 bytes).
2026-06-29 03:32:27,434 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A4BD0000: C:\Windows\system32\dcomp (0x1e5000 bytes).
2026-06-29 03:32:27,449 [root] DEBUG: 3516: DLL loaded at 0x00007FF9928C0000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2026-06-29 03:32:27,532 [root] DEBUG: 3516: DLL loaded at 0x00007FF998F00000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2026-06-29 03:32:27,572 [root] DEBUG: 3516: DLL loaded at 0x00007FF98DE00000: C:\Windows\SYSTEM32\MsftEdit (0x348000 bytes).
2026-06-29 03:32:27,611 [root] DEBUG: 3516: DLL loaded at 0x00007FF99E080000: C:\Windows\System32\Bcp47Langs (0x5c000 bytes).
2026-06-29 03:32:27,614 [root] DEBUG: 3516: DLL loaded at 0x00007FF99C270000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2026-06-29 03:32:27,615 [root] DEBUG: 3516: DLL loaded at 0x00007FF99A3F0000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2026-06-29 03:32:27,620 [root] DEBUG: 3516: DLL loaded at 0x00007FF998CE0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-06-29 03:32:27,656 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A4DC0000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes).
2026-06-29 03:32:27,658 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A5490000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes).
2026-06-29 03:32:27,660 [root] DEBUG: 3516: DLL loaded at 0x00007FF99BC00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2026-06-29 03:32:27,724 [root] DEBUG: 3516: DLL loaded at 0x00007FF99D880000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-06-29 03:32:27,970 [root] DEBUG: 3516: DLL loaded at 0x00007FF993730000: C:\Windows\SYSTEM32\edputil (0x24000 bytes).
2026-06-29 03:32:28,069 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A5A30000: C:\Windows\system32\apphelp (0x90000 bytes).
2026-06-29 03:32:28,111 [root] DEBUG: 3516: DLL loaded at 0x00007FF9912D0000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x2c000 bytes).
2026-06-29 03:32:28,113 [root] DEBUG: 3516: DLL loaded at 0x00007FF997D30000: C:\Windows\SYSTEM32\VCRUNTIME140_1 (0xc000 bytes).
2026-06-29 03:32:28,115 [root] DEBUG: 3516: DLL loaded at 0x00007FF991230000: C:\Windows\SYSTEM32\MSVCP140 (0x9d000 bytes).
2026-06-29 03:32:28,116 [root] DEBUG: 3516: DLL loaded at 0x00007FF990B60000: C:\PROGRA~1\Microsoft Office\Office16\GROOVEEX (0x214000 bytes).
2026-06-29 03:32:28,140 [root] DEBUG: 3516: DLL loaded at 0x00007FF990830000: C:\Windows\SYSTEM32\msi (0x32d000 bytes).
2026-06-29 03:32:28,175 [root] DEBUG: 3516: DLL loaded at 0x00007FF995FC0000: C:\Windows\SYSTEM32\atlthunk (0xd000 bytes).
2026-06-29 03:32:28,219 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A2820000: C:\Windows\system32\xmllite (0x36000 bytes).
2026-06-29 03:32:28,939 [root] INFO: Added new file to list with pid 3516 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-06-29 03:32:28,977 [root] INFO: Added new file to list with pid 3516 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-06-29 03:32:29,173 [root] DEBUG: 2892: DLL loaded at 0x00007FF99E000000: C:\Windows\System32\Windows.UI.FileExplorer (0x49000 bytes).
2026-06-29 03:32:29,234 [root] INFO: Added new file to list with pid 3516 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-06-29 03:32:30,429 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-29 03:32:30,587 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A1300000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-06-29 03:32:30,609 [root] DEBUG: 2892: DLL loaded at 0x00007FF9870A0000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-06-29 03:32:31,119 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 2232, handle 0x23ec: Error obtaining target process name
2026-06-29 03:32:31,170 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-29 03:32:31,172 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A8110000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-06-29 03:32:31,194 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 2132, handle 0x23e0: Error obtaining target process name
2026-06-29 03:32:31,236 [root] DEBUG: 3516: DLL loaded at 0x00007FF999020000: C:\Windows\system32\DeviceCenter (0x3e000 bytes).
2026-06-29 03:32:31,237 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-06-29 03:32:31,361 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 2996, handle 0x2734: Error obtaining target process name
2026-06-29 03:32:31,403 [root] DEBUG: 3516: DLL loaded at 0x00007FF99CE50000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2026-06-29 03:32:31,404 [root] DEBUG: 3516: api-rate-cap: LoadLibraryExW hook disabled due to rate
2026-06-29 03:32:31,609 [root] DEBUG: 3516: DLL loaded at 0x00007FF99BAA0000: C:\Windows\System32\InputHost (0x152000 bytes).
2026-06-29 03:32:31,876 [root] DEBUG: 3516: api-rate-cap: LdrUnloadDll hook disabled due to rate
2026-06-29 03:32:31,973 [root] DEBUG: 3516: DLL loaded at 0x00007FF99BD00000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2026-06-29 03:32:32,118 [root] DEBUG: 3516: DLL loaded at 0x00007FF997F70000: C:\Windows\SYSTEM32\windows.staterepositoryclient (0x40000 bytes).
2026-06-29 03:32:32,624 [root] DEBUG: 3516: DLL loaded at 0x00007FF992900000: C:\Windows\system32\OLEACC (0x66000 bytes).
2026-06-29 03:32:32,772 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A3B20000: C:\Windows\System32\netprofm (0x3e000 bytes).
2026-06-29 03:32:33,315 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A18A0000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-06-29 03:32:33,409 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A7290000: C:\Windows\SYSTEM32\wkscli (0x17000 bytes).
2026-06-29 03:32:34,059 [root] DEBUG: 2892: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-06-29 03:32:34,347 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 5540: C:\Windows\SysWOW64\DllHost.exe, ImageBase: 0x0000000000EF0000
2026-06-29 03:32:34,423 [root] INFO: Announced 32-bit process name: dllhost.exe pid: 5540
2026-06-29 03:32:34,501 [lib.api.process] INFO: Monitor config for process 5540: C:\7d7wfxi0\dll\5540.ini
2026-06-29 03:32:34,561 [lib.api.process] INFO: 32-bit DLL to inject is C:\7d7wfxi0\dll\hJaFnIOU.dll, loader C:\7d7wfxi0\bin\wdHkqEG.exe
2026-06-29 03:32:34,772 [root] DEBUG: Loader: Injecting process 5540 (thread 2560) with C:\7d7wfxi0\dll\hJaFnIOU.dll.
2026-06-29 03:32:34,911 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:32:34,913 [root] DEBUG: 2892: DLL loaded at 0x00007FF989C20000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-06-29 03:32:35,008 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\hJaFnIOU.dll.
2026-06-29 03:32:35,102 [lib.api.process] INFO: Injected into 32-bit <Process 5540 dllhost.exe>
2026-06-29 03:32:35,193 [root] INFO: Announced 32-bit process name: dllhost.exe pid: 5540
2026-06-29 03:32:35,197 [lib.api.process] INFO: Monitor config for process 5540: C:\7d7wfxi0\dll\5540.ini
2026-06-29 03:32:35,245 [lib.api.process] INFO: 32-bit DLL to inject is C:\7d7wfxi0\dll\hJaFnIOU.dll, loader C:\7d7wfxi0\bin\wdHkqEG.exe
2026-06-29 03:32:35,368 [root] DEBUG: Loader: Injecting process 5540 (thread 2560) with C:\7d7wfxi0\dll\hJaFnIOU.dll.
2026-06-29 03:32:35,383 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-06-29 03:32:35,415 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\hJaFnIOU.dll.
2026-06-29 03:32:35,459 [lib.api.process] INFO: Injected into 32-bit <Process 5540 dllhost.exe>
2026-06-29 03:32:35,507 [root] DEBUG: 2892: DLL loaded at 0x00007FF989C20000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-06-29 03:32:35,579 [root] DEBUG: 5540: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:32:35,581 [root] DEBUG: 5540: Dropped file limit defaulting to 100.
2026-06-29 03:32:35,643 [root] DEBUG: 5540: Disabling sleep skipping.
2026-06-29 03:32:35,651 [root] DEBUG: 5540: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:32:35,678 [root] DEBUG: 5540: YaraScan: Scanning 0x00EF0000, size 0x6172
2026-06-29 03:32:35,706 [root] DEBUG: 5540: Monitor initialised: 32-bit capemon loaded in process 5540 at 0x728b0000, thread 2560, image base 0xef0000, stack from 0xe85000-0xe90000
2026-06-29 03:32:35,708 [root] DEBUG: 5540: Commandline: C:\Windows\SysWOW64\DllHost.exe /Processid:{06622D85-6856-4460-8DE1-A81921B41C4B}
2026-06-29 03:32:35,788 [root] DEBUG: 5540: hook_api: LdrpCallInitRoutine export address 0x76F72980 obtained via GetFunctionAddress
2026-06-29 03:32:35,837 [root] DEBUG: 5540: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-06-29 03:32:35,839 [root] DEBUG: 5540: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-06-29 03:32:35,944 [root] DEBUG: 5540: Hooked 635 out of 635 functions
2026-06-29 03:32:35,964 [root] DEBUG: 5540: Syscall hook installed, syscall logging level 1
2026-06-29 03:32:36,053 [root] DEBUG: 5540: RestoreHeaders: Restored original import table.
2026-06-29 03:32:36,079 [root] INFO: Loaded monitor into process with pid 5540
2026-06-29 03:32:36,111 [root] DEBUG: 5540: caller_dispatch: Added region at 0x00EF0000 to tracked regions list (ntdll::NtSetInformationProcess returns to 0x00EF14CF, thread 2560).
2026-06-29 03:32:36,117 [root] DEBUG: 5540: YaraScan: Scanning 0x00EF0000, size 0x6172
2026-06-29 03:32:36,138 [root] DEBUG: 5540: ProcessImageBase: Main module image at 0x00EF0000 unmodified (entropy change 0.000000e+00)
2026-06-29 03:32:36,147 [root] DEBUG: 5540: DLL loaded at 0x74CF0000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-06-29 03:32:36,174 [root] DEBUG: 5540: DLL loaded at 0x769D0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-06-29 03:32:36,205 [root] DEBUG: 5540: DLL loaded at 0x76A30000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-06-29 03:32:36,270 [root] DEBUG: 5540: DLL loaded at 0x74600000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-06-29 03:32:36,355 [root] DEBUG: 5540: DLL loaded at 0x72860000: C:\Windows\System32\ActXPrxy (0x4a000 bytes).
2026-06-29 03:32:36,466 [root] DEBUG: 5540: DLL loaded at 0x746B0000: C:\Windows\System32\Wldp (0x24000 bytes).
2026-06-29 03:32:36,501 [root] DEBUG: 5540: DLL loaded at 0x746E0000: C:\Windows\SYSTEM32\windows.storage (0x608000 bytes).
2026-06-29 03:32:36,548 [root] DEBUG: 5540: DLL loaded at 0x755E0000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-06-29 03:32:36,627 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A4F30000: C:\Windows\SYSTEM32\WSOCK32 (0x9000 bytes).
2026-06-29 03:32:36,644 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A4F40000: C:\Windows\system32\irprops.cpl (0xe000 bytes).
2026-06-29 03:32:36,698 [root] DEBUG: 3516: DLL loaded at 0x00007FF990180000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1288_none_91a663c8cc864906\gdiplus (0x1a9000 bytes).
2026-06-29 03:32:36,716 [root] DEBUG: 3516: DLL loaded at 0x00007FF989DB0000: C:\Windows\SYSTEM32\WSCAPI (0x4d000 bytes).
2026-06-29 03:32:36,742 [root] DEBUG: 3516: DLL loaded at 0x00007FF99BF30000: C:\Windows\system32\wscui.cpl (0x19000 bytes).
2026-06-29 03:32:36,817 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A4F30000: C:\PROGRA~1\Microsoft Office\Office16\MLCFG32.CPL (0x17000 bytes).
2026-06-29 03:32:36,996 [root] DEBUG: 3516: caller_dispatch: Added region at 0x00007FF9A4F30000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00007FF9A4F39579, thread 3428).
2026-06-29 03:32:37,049 [root] DEBUG: 3516: ProcessTrackedRegion: Region at 0x00007FF9A4F30000 mapped as \Device\HarddiskVolume2\PROGRA~1\Microsoft Office\Office16\MLCFG32.CPL is in known range, skipping
2026-06-29 03:32:37,101 [root] DEBUG: 3516: DLL loaded at 0x00007FF987B50000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso20win32client (0x304000 bytes).
2026-06-29 03:32:37,189 [root] DEBUG: 3516: DLL loaded at 0x00007FF9876D0000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso30win32client (0x478000 bytes).
2026-06-29 03:32:37,356 [root] DEBUG: 3516: DLL loaded at 0x00007FF990180000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1288_none_91a663c8cc864906\gdiplus (0x1a9000 bytes).
2026-06-29 03:32:37,431 [root] DEBUG: 3516: DLL loaded at 0x00007FF9837F0000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso40uiwin32client (0x8eb000 bytes).
2026-06-29 03:32:37,537 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A4300000: C:\Windows\SYSTEM32\MSIMG32 (0x7000 bytes).
2026-06-29 03:32:37,712 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A6C60000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-06-29 03:32:37,834 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A6C90000: C:\Windows\SYSTEM32\SLC (0x29000 bytes).
2026-06-29 03:32:37,835 [root] DEBUG: 3516: DLL loaded at 0x00007FF9868D0000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso99Lwin32client (0x7cc000 bytes).
2026-06-29 03:32:38,350 [root] DEBUG: 3516: DLL loaded at 0x00007FF982510000: C:\Program Files\Common Files\Microsoft Shared\Office16\mso (0x12dc000 bytes).
2026-06-29 03:32:38,432 [root] DEBUG: 3516: DLL loaded at 0x00007FF98F380000: C:\Windows\SYSTEM32\srpapi (0x2c000 bytes).
2026-06-29 03:32:38,681 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A4610000: C:\Windows\SYSTEM32\d2d1 (0x5c0000 bytes).
2026-06-29 03:32:38,802 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A7F00000: C:\Windows\SYSTEM32\WINSTA (0x5a000 bytes).
2026-06-29 03:32:38,842 [root] INFO: Added new file to list with pid 2892 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-06-29 03:32:38,871 [root] DEBUG: 3516: DLL loaded at 0x00007FF9A5C40000: C:\Windows\SYSTEM32\resourcepolicyclient (0x14000 bytes).
2026-06-29 03:32:39,050 [root] INFO: Added new file to list with pid 2892 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db
2026-06-29 03:32:39,051 [root] INFO: Added new file to list with pid 3516 and path C:\Users\Rajesh\AppData\Local\Temp\{B50518BB-416F-447C-97DB-B2ED0A6FDE17} - OProcSessId.dat
2026-06-29 03:32:39,078 [root] DEBUG: 3516: AllocationHandler: Adding allocation to tracked region list: 0x00007FF968300000, size: 0x10000.
2026-06-29 03:32:39,114 [root] DEBUG: 3516: ProcessTrackedRegion: Entropy for tracked region at 0x00007FF968300000: 6.197754e-01
2026-06-29 03:32:39,116 [root] DEBUG: 3516: DumpPEsInRange: Scanning range 0x00007FF968300000 - 0x00007FF96830FF4E.
2026-06-29 03:32:39,195 [root] DEBUG: 3516: ScanForDisguisedPE: No PE image located in range 0x00007FF968300000-0x00007FF96830FF4E.
2026-06-29 03:32:39,447 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 6668: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6F8BE0000
2026-06-29 03:32:39,530 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6668
2026-06-29 03:32:39,626 [lib.api.process] INFO: Monitor config for process 6668: C:\7d7wfxi0\dll\6668.ini
2026-06-29 03:32:39,642 [lib.common.results] INFO: Uploading file C:\cUJPOo\CAPE\3516_750339321029162026 to CAPE\b2f75198f26d9b6cdf2235e415d3e6430839f78a82ed902993f2d172af8545e2; Size is 65358; Max size: 100000000
2026-06-29 03:32:39,645 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:32:41,983 [root] DEBUG: 3516: DumpMemory: Payload successfully created: C:\cUJPOo\CAPE\3516_750339321029162026 (size 65358 bytes)
2026-06-29 03:32:41,985 [root] DEBUG: Loader: Injecting process 6668 (thread 6672) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:42,192 [root] INFO: Process with pid 5540 has terminated
2026-06-29 03:32:42,504 [root] DEBUG: 3516: DumpRegion: Dumped entire allocation from 0x00007FF968300000, size 65536 bytes.
2026-06-29 03:32:42,509 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:32:42,550 [root] DEBUG: 5540: NtTerminateProcess hook: Attempting to dump process 5540
2026-06-29 03:32:42,555 [root] DEBUG: 3516: api-cap: GetSystemMetrics hook disabled due to count: 5000
2026-06-29 03:32:42,896 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:42,902 [root] DEBUG: 5540: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:32:42,933 [lib.api.process] INFO: Injected into 64-bit <Process 6668 dllhost.exe>
2026-06-29 03:32:42,996 [root] DEBUG: 2892: api-cap: SystemParametersInfoW hook disabled due to count: 5000
2026-06-29 03:32:43,072 [root] DEBUG: 3516: ProcessTrackedRegion: Dumped region at 0x00007FF968300000.
2026-06-29 03:32:43,089 [root] DEBUG: 3516: YaraScan: Scanning 0x00007FF968300000, size 0xff4e
2026-06-29 03:32:43,127 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 6668
2026-06-29 03:32:43,129 [lib.api.process] INFO: Monitor config for process 6668: C:\7d7wfxi0\dll\6668.ini
2026-06-29 03:32:43,141 [root] DEBUG: 2892: api-cap: SystemParametersInfoW hook disabled due to count: 5001
2026-06-29 03:32:43,236 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:32:43,323 [root] DEBUG: 3516: DLL loaded at 0x0000000008FE0000: C:\PROGRA~1\Microsoft Office\Office16\1033\mapir (0x137000 bytes).
2026-06-29 03:32:43,383 [root] DEBUG: Loader: Injecting process 6668 (thread 6672) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:43,642 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:32:43,690 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:32:43,882 [lib.api.process] INFO: Injected into 64-bit <Process 6668 dllhost.exe>
2026-06-29 03:32:44,095 [root] DEBUG: 6668: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:32:44,098 [root] DEBUG: 6668: Dropped file limit defaulting to 100.
2026-06-29 03:32:44,340 [root] DEBUG: 6668: Disabling sleep skipping.
2026-06-29 03:32:44,364 [root] DEBUG: 6668: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:32:44,545 [root] DEBUG: 6668: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 03:32:44,685 [root] DEBUG: 6668: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 03:32:44,706 [root] DEBUG: 6668: Monitor initialised: 64-bit capemon loaded in process 6668 at 0x00007FF9840E0000, thread 6672, image base 0x00007FF6F8BE0000, stack from 0x000000E0B9AF4000-0x000000E0B9B00000
2026-06-29 03:32:44,746 [root] DEBUG: 6668: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-06-29 03:32:44,791 [root] DEBUG: 6668: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 03:32:44,932 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 03:32:45,034 [root] DEBUG: 6668: set_hooks: Unable to hook LockResource
2026-06-29 03:32:45,149 [root] DEBUG: 6668: Hooked 630 out of 631 functions
2026-06-29 03:32:45,200 [root] DEBUG: 6668: Syscall hook installed, syscall logging level 1
2026-06-29 03:32:45,253 [root] DEBUG: 6668: RestoreHeaders: Restored original import table.
2026-06-29 03:32:45,289 [root] INFO: Loaded monitor into process with pid 6668
2026-06-29 03:32:45,328 [root] DEBUG: 6668: caller_dispatch: Added region at 0x00007FF6F8BE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F8BE12F2, thread 6672).
2026-06-29 03:32:45,350 [root] DEBUG: 6668: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 03:32:45,371 [root] DEBUG: 6668: ProcessImageBase: Main module image at 0x00007FF6F8BE0000 unmodified (entropy change 0.000000e+00)
2026-06-29 03:32:45,463 [root] DEBUG: 6668: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 03:32:45,514 [root] DEBUG: 6668: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 03:32:45,606 [root] DEBUG: 6668: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 03:32:45,819 [root] DEBUG: 6668: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 03:32:46,032 [root] DEBUG: 6668: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\shcore (0xad000 bytes).
2026-06-29 03:32:46,095 [root] DEBUG: 6668: DLL loaded at 0x00007FF992850000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-06-29 03:32:48,333 [root] DEBUG: 6668: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-06-29 03:32:48,880 [root] INFO: Added new file to list with pid 2892 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
2026-06-29 03:32:50,472 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 6736, handle 0x13b4: C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2026-06-29 03:32:51,082 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 5368, handle 0x252c: C:\Windows\SysWOW64\notepad.exe
2026-06-29 03:32:51,406 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 5296, handle 0x251c: C:\Windows\SysWOW64\regedit.exe
2026-06-29 03:32:53,184 [root] DEBUG: 2892: api-cap: RegCloseKey hook disabled due to count: 5000
2026-06-29 03:32:53,401 [root] DEBUG: 2892: api-cap: RegCloseKey hook disabled due to count: 5002
2026-06-29 03:32:53,405 [root] DEBUG: 2892: api-cap: RegCloseKey hook disabled due to count: 5001
2026-06-29 03:32:53,431 [modules.auxiliary.human] INFO: Found button "save", clicking it
2026-06-29 03:32:53,495 [root] DEBUG: 2892: api-cap: RegCloseKey hook disabled due to count: 5003
2026-06-29 03:32:55,951 [root] DEBUG: 2892: DLL loaded at 0x00007FF9A4F30000: C:\Windows\SYSTEM32\VirtDisk (0x14000 bytes).
2026-06-29 03:32:55,997 [root] DEBUG: 2892: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-06-29 03:32:56,029 [root] DEBUG: 2892: api-cap: RegOpenKeyExW hook disabled due to count: 5001
2026-06-29 03:32:56,471 [root] DEBUG: 2892: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-06-29 03:32:58,567 [root] DEBUG: 2892: api-cap: NtClose hook disabled due to count: 5000
2026-06-29 03:33:01,477 [root] INFO: Process with pid 6668 has terminated
2026-06-29 03:33:01,550 [root] DEBUG: 6668: NtTerminateProcess hook: Attempting to dump process 6668
2026-06-29 03:33:01,638 [root] DEBUG: 6668: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:33:05,948 [root] DEBUG: 2892: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-06-29 03:33:05,978 [root] DEBUG: 2892: api-cap: RegQueryValueExW hook disabled due to count: 5001
2026-06-29 03:33:05,990 [root] DEBUG: 2892: api-cap: RegQueryValueExW hook disabled due to count: 5002
2026-06-29 03:33:06,234 [root] DEBUG: 2892: api-cap: RegQueryValueExW hook disabled due to count: 5003
2026-06-29 03:33:06,688 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 7700: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6F8BE0000
2026-06-29 03:33:06,699 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7700
2026-06-29 03:33:06,700 [lib.api.process] INFO: Monitor config for process 7700: C:\7d7wfxi0\dll\7700.ini
2026-06-29 03:33:06,707 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:06,758 [root] DEBUG: Loader: Injecting process 7700 (thread 7704) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:06,760 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:06,761 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:06,791 [lib.api.process] INFO: Injected into 64-bit <Process 7700 dllhost.exe>
2026-06-29 03:33:06,794 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7700
2026-06-29 03:33:06,795 [lib.api.process] INFO: Monitor config for process 7700: C:\7d7wfxi0\dll\7700.ini
2026-06-29 03:33:06,812 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:07,029 [root] DEBUG: Loader: Injecting process 7700 (thread 7704) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:07,095 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:07,187 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:07,193 [lib.api.process] INFO: Injected into 64-bit <Process 7700 dllhost.exe>
2026-06-29 03:33:07,237 [root] DEBUG: 7700: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:33:07,240 [root] DEBUG: 7700: Dropped file limit defaulting to 100.
2026-06-29 03:33:07,271 [root] DEBUG: 7700: Disabling sleep skipping.
2026-06-29 03:33:07,305 [root] DEBUG: 7700: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:33:07,352 [root] DEBUG: 7700: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 03:33:07,355 [root] DEBUG: 7700: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 03:33:07,357 [root] DEBUG: 7700: Monitor initialised: 64-bit capemon loaded in process 7700 at 0x00007FF9840E0000, thread 7704, image base 0x00007FF6F8BE0000, stack from 0x000000A9742F4000-0x000000A974300000
2026-06-29 03:33:07,380 [root] DEBUG: 7700: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-06-29 03:33:07,412 [root] DEBUG: 7700: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 03:33:07,473 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 03:33:07,500 [root] DEBUG: 7700: set_hooks: Unable to hook LockResource
2026-06-29 03:33:07,541 [root] DEBUG: 7700: Hooked 630 out of 631 functions
2026-06-29 03:33:07,545 [root] DEBUG: 7700: Syscall hook installed, syscall logging level 1
2026-06-29 03:33:07,572 [root] DEBUG: 7700: RestoreHeaders: Restored original import table.
2026-06-29 03:33:07,573 [root] INFO: Loaded monitor into process with pid 7700
2026-06-29 03:33:07,576 [root] DEBUG: 7700: caller_dispatch: Added region at 0x00007FF6F8BE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F8BE12F2, thread 7704).
2026-06-29 03:33:07,577 [root] DEBUG: 7700: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 03:33:07,603 [root] DEBUG: 7700: ProcessImageBase: Main module image at 0x00007FF6F8BE0000 unmodified (entropy change 0.000000e+00)
2026-06-29 03:33:07,609 [root] DEBUG: 7700: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 03:33:07,640 [root] DEBUG: 7700: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 03:33:07,661 [root] DEBUG: 7700: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 03:33:07,709 [root] DEBUG: 7700: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 03:33:07,758 [root] DEBUG: 7700: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\shcore (0xad000 bytes).
2026-06-29 03:33:07,759 [root] DEBUG: 7700: DLL loaded at 0x00007FF992850000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-06-29 03:33:07,805 [root] DEBUG: 7700: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-06-29 03:33:13,112 [root] INFO: Process with pid 7700 has terminated
2026-06-29 03:33:13,241 [root] DEBUG: 7700: NtTerminateProcess hook: Attempting to dump process 7700
2026-06-29 03:33:13,480 [root] DEBUG: 7700: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:33:13,539 [root] DEBUG: 2892: api-cap: NtQueryKey hook disabled due to count: 5000
2026-06-29 03:33:13,709 [root] DEBUG: 2892: api-cap: NtQueryKey hook disabled due to count: 5001
2026-06-29 03:33:14,781 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 7728, handle 0x21a8: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
2026-06-29 03:33:19,791 [root] DEBUG: 2892: api-cap: NtFindAtom hook disabled due to count: 5000
2026-06-29 03:33:21,104 [root] DEBUG: 2892: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-06-29 03:33:21,619 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 7924: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6F8BE0000
2026-06-29 03:33:21,669 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7924
2026-06-29 03:33:21,670 [lib.api.process] INFO: Monitor config for process 7924: C:\7d7wfxi0\dll\7924.ini
2026-06-29 03:33:21,904 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:22,132 [root] DEBUG: Loader: Injecting process 7924 (thread 5300) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:22,220 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:22,222 [root] DEBUG: 2892: CreateProcessHandler: Injection info set for new process 8144: C:\Windows\system32\taskmgr.exe, ImageBase: 0x00007FF6A55E0000
2026-06-29 03:33:22,238 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:22,314 [lib.api.process] INFO: Injected into 64-bit <Process 7924 dllhost.exe>
2026-06-29 03:33:22,884 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 8144
2026-06-29 03:33:22,886 [lib.api.process] INFO: Monitor config for process 8144: C:\7d7wfxi0\dll\8144.ini
2026-06-29 03:33:23,692 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:23,713 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 7924
2026-06-29 03:33:23,715 [lib.api.process] INFO: Monitor config for process 7924: C:\7d7wfxi0\dll\7924.ini
2026-06-29 03:33:23,729 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:23,749 [root] DEBUG: 2892: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-06-29 03:33:31,399 [root] DEBUG: 2892: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5001
2026-06-29 03:33:31,570 [root] DEBUG: Loader: Injecting process 7924 (thread 5300) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:31,572 [root] DEBUG: Loader: Injecting process 8144 (thread 7928) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:31,607 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:31,632 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:31,639 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:31,666 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:31,729 [lib.api.process] INFO: Injected into 64-bit <Process 7924 dllhost.exe>
2026-06-29 03:33:31,803 [lib.api.process] INFO: Injected into 64-bit <Process 8144 Taskmgr.exe>
2026-06-29 03:33:32,124 [root] DEBUG: 7924: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:33:32,156 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 8300
2026-06-29 03:33:32,157 [lib.api.process] INFO: Monitor config for process 8300: C:\7d7wfxi0\dll\8300.ini
2026-06-29 03:33:32,177 [root] DEBUG: 7924: Dropped file limit defaulting to 100.
2026-06-29 03:33:32,220 [root] DEBUG: 7924: Disabling sleep skipping.
2026-06-29 03:33:32,225 [root] DEBUG: 7924: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:33:32,273 [root] DEBUG: 7924: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 03:33:32,275 [root] DEBUG: 7924: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 03:33:32,276 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:32,345 [root] DEBUG: 7924: Monitor initialised: 64-bit capemon loaded in process 7924 at 0x00007FF9840E0000, thread 5300, image base 0x00007FF6F8BE0000, stack from 0x000000DEB6924000-0x000000DEB6930000
2026-06-29 03:33:32,357 [root] DEBUG: Loader: Injecting process 8300 with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:32,358 [root] DEBUG: 7924: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-06-29 03:33:32,389 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 8304, handle 0x10c
2026-06-29 03:33:32,392 [root] DEBUG: 7924: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 03:33:32,513 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:32,516 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 03:33:32,525 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:32,526 [root] DEBUG: 7924: set_hooks: Unable to hook LockResource
2026-06-29 03:33:32,562 [root] DEBUG: 7924: Hooked 630 out of 631 functions
2026-06-29 03:33:32,566 [lib.api.process] INFO: Injected into 64-bit <Process 8300 Taskmgr.exe>
2026-06-29 03:33:32,566 [root] DEBUG: 7924: Syscall hook installed, syscall logging level 1
2026-06-29 03:33:32,675 [root] DEBUG: 7924: RestoreHeaders: Restored original import table.
2026-06-29 03:33:32,677 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 8300, handle 0x1fcc: C:\Windows\System32\Taskmgr.exe
2026-06-29 03:33:32,680 [root] INFO: Loaded monitor into process with pid 7924
2026-06-29 03:33:32,682 [root] DEBUG: 7924: caller_dispatch: Added region at 0x00007FF6F8BE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F8BE12F2, thread 5300).
2026-06-29 03:33:32,756 [root] DEBUG: 7924: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 03:33:32,761 [root] DEBUG: 7924: ProcessImageBase: Main module image at 0x00007FF6F8BE0000 unmodified (entropy change 0.000000e+00)
2026-06-29 03:33:32,792 [root] DEBUG: 7924: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 03:33:32,796 [root] DEBUG: 7924: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 03:33:32,825 [root] DEBUG: 7924: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 03:33:32,918 [root] DEBUG: 7924: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 03:33:32,984 [root] DEBUG: 7924: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\shcore (0xad000 bytes).
2026-06-29 03:33:32,986 [root] DEBUG: 7924: DLL loaded at 0x00007FF992850000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-06-29 03:33:33,018 [root] DEBUG: 7924: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-06-29 03:33:33,767 [root] DEBUG: 2892: api-cap: NtSetInformationThread hook disabled due to count: 5000
2026-06-29 03:33:33,938 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 8608, handle 0x23dc: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
2026-06-29 03:33:34,585 [root] DEBUG: 2892: OpenProcessHandler: Image base for process 2996 (handle 0x233c): 0x00007FF619E70000.
2026-06-29 03:33:34,674 [root] INFO: Added new file to list with pid 3516 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
2026-06-29 03:33:41,743 [root] INFO: Process with pid 7924 has terminated
2026-06-29 03:33:41,778 [root] DEBUG: 7924: NtTerminateProcess hook: Attempting to dump process 7924
2026-06-29 03:33:41,837 [root] DEBUG: 7924: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:33:46,585 [root] DEBUG: 2892: CreateProcessHandler: Injection info set for new process 8896: C:\Windows\system32\taskmgr.exe, ImageBase: 0x00007FF6A55E0000
2026-06-29 03:33:46,592 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 8896
2026-06-29 03:33:46,634 [lib.api.process] INFO: Monitor config for process 8896: C:\7d7wfxi0\dll\8896.ini
2026-06-29 03:33:46,675 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:46,695 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 8912: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6F8BE0000
2026-06-29 03:33:46,698 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8912
2026-06-29 03:33:46,699 [lib.api.process] INFO: Monitor config for process 8912: C:\7d7wfxi0\dll\8912.ini
2026-06-29 03:33:46,760 [root] DEBUG: Loader: Injecting process 8896 (thread 8888) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:46,764 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:46,822 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:46,901 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:47,102 [lib.api.process] INFO: Injected into 64-bit <Process 8896 Taskmgr.exe>
2026-06-29 03:33:47,330 [root] DEBUG: Loader: Injecting process 8912 (thread 8908) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:47,358 [root] INFO: Announced 64-bit process name: Taskmgr.exe pid: 9056
2026-06-29 03:33:47,359 [lib.api.process] INFO: Monitor config for process 9056: C:\7d7wfxi0\dll\9056.ini
2026-06-29 03:33:47,384 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:47,415 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:47,480 [lib.api.process] INFO: Injected into 64-bit <Process 8912 dllhost.exe>
2026-06-29 03:33:47,484 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:47,697 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 8912
2026-06-29 03:33:47,699 [root] DEBUG: Loader: Injecting process 9056 with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:47,699 [lib.api.process] INFO: Monitor config for process 8912: C:\7d7wfxi0\dll\8912.ini
2026-06-29 03:33:47,889 [root] DEBUG: InjectDll: No thread ID supplied, initial thread ID 7504, handle 0x10c
2026-06-29 03:33:47,890 [lib.api.process] INFO: 64-bit DLL to inject is C:\7d7wfxi0\dll\HDJsPr.dll, loader C:\7d7wfxi0\bin\UFjmJKFL.exe
2026-06-29 03:33:47,994 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:48,527 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:48,528 [root] DEBUG: Loader: Injecting process 8912 (thread 8908) with C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:48,913 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-06-29 03:33:48,915 [lib.api.process] INFO: Injected into 64-bit <Process 9056 Taskmgr.exe>
2026-06-29 03:33:48,964 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\HDJsPr.dll.
2026-06-29 03:33:49,120 [lib.api.process] INFO: Injected into 64-bit <Process 8912 dllhost.exe>
2026-06-29 03:33:49,154 [root] DEBUG: 8912: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-29 03:33:49,156 [root] DEBUG: 8912: Dropped file limit defaulting to 100.
2026-06-29 03:33:49,344 [root] DEBUG: 8912: Disabling sleep skipping.
2026-06-29 03:33:49,363 [root] DEBUG: 8912: YaraInit: Compiled rules loaded from existing file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-29 03:33:49,434 [root] DEBUG: 8912: RtlInsertInvertedFunctionTable 0x00007FF9AAA0090E, LdrpInvertedFunctionTableSRWLock 0x00007FF9AAB5B4F0
2026-06-29 03:33:49,494 [root] DEBUG: 8912: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 03:33:49,522 [root] DEBUG: 8912: Monitor initialised: 64-bit capemon loaded in process 8912 at 0x00007FF9840E0000, thread 8908, image base 0x00007FF6F8BE0000, stack from 0x0000000FFDAF4000-0x0000000FFDB00000
2026-06-29 03:33:49,528 [root] DEBUG: 8912: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-06-29 03:33:50,206 [root] DEBUG: 8912: hook_api: LdrpCallInitRoutine export address 0x00007FF9AAA099BC obtained via GetFunctionAddress
2026-06-29 03:33:50,335 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-06-29 03:33:50,411 [root] DEBUG: 8912: set_hooks: Unable to hook LockResource
2026-06-29 03:33:50,447 [root] DEBUG: 756: CreateProcessHandler: Injection info set for new process 8808: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF620BA0000
2026-06-29 03:33:50,481 [root] DEBUG: 8912: Hooked 630 out of 631 functions
2026-06-29 03:33:50,484 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 8808
2026-06-29 03:33:50,504 [lib.api.process] INFO: Monitor config for process 8808: C:\7d7wfxi0\dll\8808.ini
2026-06-29 03:33:50,545 [root] DEBUG: 8912: Syscall hook installed, syscall logging level 1
2026-06-29 03:33:50,746 [root] DEBUG: 8912: RestoreHeaders: Restored original import table.
2026-06-29 03:33:50,809 [root] INFO: Loaded monitor into process with pid 8912
2026-06-29 03:33:50,813 [root] DEBUG: 8912: caller_dispatch: Added region at 0x00007FF6F8BE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F8BE12F2, thread 8908).
2026-06-29 03:33:50,820 [root] DEBUG: 8912: YaraScan: Scanning 0x00007FF6F8BE0000, size 0x8026
2026-06-29 03:33:50,842 [root] DEBUG: 8912: ProcessImageBase: Main module image at 0x00007FF6F8BE0000 unmodified (entropy change 0.000000e+00)
2026-06-29 03:33:50,894 [root] DEBUG: 8912: DLL loaded at 0x00007FF9A6030000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-06-29 03:33:50,896 [root] DEBUG: 8912: DLL loaded at 0x00007FF9A8700000: C:\Windows\System32\bcryptPrimitives (0x83000 bytes).
2026-06-29 03:33:50,929 [root] DEBUG: 8912: DLL loaded at 0x00007FF9A9600000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-06-29 03:33:51,018 [root] DEBUG: 8912: DLL loaded at 0x00007FF9A5B50000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-06-29 03:33:51,072 [root] DEBUG: 8912: DLL loaded at 0x00007FF9A9D30000: C:\Windows\System32\shcore (0xad000 bytes).
2026-06-29 03:33:51,076 [root] DEBUG: 8912: DLL loaded at 0x00007FF992850000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-06-29 03:33:51,117 [root] DEBUG: 8912: DLL loaded at 0x00007FF9A2720000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-06-29 03:33:58,390 [root] INFO: Process with pid 8912 has terminated
2026-06-29 03:33:58,782 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 1160, handle 0x2108: C:\Windows\System32\mmc.exe
2026-06-29 03:33:59,516 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 9288, handle 0x2608: C:\Windows\System32\conhost.exe
2026-06-29 03:33:59,557 [root] DEBUG: 2892: api-cap: NtQueryInformationThread hook disabled due to count: 5000
2026-06-29 03:34:00,195 [root] DEBUG: 8912: NtTerminateProcess hook: Attempting to dump process 8912
2026-06-29 03:34:00,626 [root] DEBUG: 2892: api-cap: NtQueryInformationThread hook disabled due to count: 5001
2026-06-29 03:34:01,224 [root] DEBUG: 8912: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:34:01,801 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 9268, handle 0x25d4: C:\Windows\SysWOW64\cmd.exe
2026-06-29 03:34:03,203 [root] DEBUG: 2892: api-cap: NtQueryValueKey hook disabled due to count: 5000
2026-06-29 03:34:03,543 [root] DEBUG: 2892: api-cap: NtQueryValueKey hook disabled due to count: 5001
2026-06-29 03:34:04,205 [root] DEBUG: 2892: api-cap: NtQueryValueKey hook disabled due to count: 5003
2026-06-29 03:34:04,336 [root] INFO: Analysis timeout hit, terminating analysis
2026-06-29 03:34:04,392 [lib.api.process] INFO: Terminate event set for process 756
2026-06-29 03:34:04,512 [root] DEBUG: 2892: api-cap: NtQueryValueKey hook disabled due to count: 5002
2026-06-29 03:34:04,737 [root] DEBUG: 756: Terminate Event: Attempting to dump process 756
2026-06-29 03:34:04,873 [root] DEBUG: 756: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:34:04,892 [lib.api.process] INFO: Termination confirmed for process 756
2026-06-29 03:34:04,893 [root] INFO: Terminate event set for process 756
2026-06-29 03:34:04,893 [lib.api.process] INFO: Terminate event set for process 3516
2026-06-29 03:34:05,140 [root] DEBUG: 3516: Terminate Event: Attempting to dump process 3516
2026-06-29 03:34:05,634 [root] DEBUG: 3516: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:34:05,686 [root] DEBUG: 756: Terminate Event: monitor shutdown complete for process 756
2026-06-29 03:34:07,745 [root] DEBUG: 3516: Terminate Event: Shutdown complete for process 3516 but failed to inform analyzer.
2026-06-29 03:34:09,921 [lib.api.process] INFO: Termination confirmed for process 3516
2026-06-29 03:34:09,921 [root] INFO: Terminate event set for process 3516
2026-06-29 03:34:09,922 [lib.api.process] INFO: Terminate event set for process 2892
2026-06-29 03:34:10,256 [root] DEBUG: 2892: Terminate Event: Attempting to dump process 2892
2026-06-29 03:34:10,340 [root] DEBUG: 2892: DoProcessDump: Skipping process dump as code is identical on disk.
2026-06-29 03:34:10,888 [root] INFO: Added new file to list with pid 2892 and path C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
2026-06-29 03:34:12,143 [root] DEBUG: 2892: Terminate Event: Shutdown complete for process 2892 but failed to inform analyzer.
2026-06-29 03:34:15,024 [lib.api.process] INFO: Termination confirmed for process 2892
2026-06-29 03:34:15,025 [root] INFO: Terminate event set for process 2892
2026-06-29 03:34:15,025 [root] INFO: Created shutdown mutex
2026-06-29 03:34:15,150 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 5552, handle 0x1738: C:\Users\Rajesh\AppData\Roaming\MEMZ.exe
2026-06-29 03:34:15,288 [root] DEBUG: 2892: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5000
2026-06-29 03:34:15,337 [root] DEBUG: 2892: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5001
2026-06-29 03:34:15,386 [root] DEBUG: 2892: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5002
2026-06-29 03:34:15,393 [root] DEBUG: 2892: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5004
2026-06-29 03:34:15,639 [root] DEBUG: 2892: api-cap: MsgWaitForMultipleObjectsEx hook disabled due to count: 5003
2026-06-29 03:34:16,035 [root] INFO: Shutting down package
2026-06-29 03:34:16,036 [root] INFO: Stopping auxiliary modules
2026-06-29 03:34:16,036 [root] INFO: Stopping auxiliary module: Browser
2026-06-29 03:34:16,036 [root] INFO: Stopping auxiliary module: Human
2026-06-29 03:34:16,248 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 5092, handle 0x10e8: C:\Users\Rajesh\AppData\Roaming\MEMZ.exe
2026-06-29 03:34:19,474 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 9712, handle 0x2280: C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2026-06-29 03:34:20,871 [root] DEBUG: 2892: OpenProcessHandler: Injection info created for process 8000, handle 0x10a0: C:\Windows\System32\mmc.exe
2026-06-29 03:34:21,300 [root] DEBUG: 2892: api-cap: NtOpenKey hook disabled due to count: 5000
2026-06-29 03:34:22,826 [modules.auxiliary.human] INFO: Found button "ok", clicking it
2026-06-29 03:34:24,128 [root] DEBUG: 2892: api-cap: NtQueryPerformanceCounter hook disabled due to count: 5000
2026-06-29 03:34:24,165 [modules.auxiliary.human] INFO: Found button "ok", clicking it
2026-06-29 03:34:26,260 [root] WARNING: Failed to join {aux} thread.
2026-06-29 03:34:26,260 [root] INFO: Stopping auxiliary module: Screenshots
2026-06-29 03:34:26,261 [root] INFO: Finishing auxiliary modules
2026-06-29 03:34:26,261 [root] INFO: Shutting down pipe server and dumping dropped files
2026-06-29 03:34:26,261 [root] WARNING: File at path c:\users\rajesh\appdata\local\temp\x does not exist, skipping
2026-06-29 03:34:26,264 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db to files\7c5b238422fbdff74c66945c20b51cd609dc0e023bfdc6a61dace27ac20a56c6; Size is 29232; Max size: 100000000
2026-06-29 03:34:26,589 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db to files\df904161e885b8f97fc35d85d76d81716f2f8f1aedd13d75457bffabfc745b0f; Size is 1048576; Max size: 100000000
2026-06-29 03:34:26,869 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db to files\4eef38accb6582fd140df5316eb7c11aa1b6266a0db129bc71ba0357dd787aae; Size is 1048576; Max size: 100000000
2026-06-29 03:34:26,906 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db to files\be782b95e1ddf9bca1525c2d0b7a7852cefe01fa55a4d69765288878d1e307c9; Size is 14688; Max size: 100000000
2026-06-29 03:34:27,152 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\thumbcache_48.db to files\fee17d50468d91404ae5621dd6413ecb1120be72daf2e64958df9404c6e3f8f4; Size is 1048576; Max size: 100000000
2026-06-29 03:34:27,257 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db to files\8c3de28a3961a814b7f9815df46f6a9cf6ffe8e9aabc349d83487200316075c2; Size is 1048576; Max size: 100000000
2026-06-29 03:34:27,300 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db to files\95c28934d5ffbb94ab8a595b8dc952d82a1233d15c476eac4e795f4661d14665; Size is 1048576; Max size: 100000000
2026-06-29 03:34:27,309 [lib.common.results] INFO: Uploading file C:\Users\Rajesh\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db to files\40d757bd473ea76f817d324b721c1e96fc34b1533dd67fef30b93fa9729bf3a5; Size is 1048576; Max size: 100000000
2026-06-29 03:34:27,318 [root] WARNING: Folder at path "C:\cUJPOo\debugger" does not exist, skipping
2026-06-29 03:34:27,318 [root] WARNING: Folder at path "C:\cUJPOo\tlsdump" does not exist, skipping
2026-06-29 03:34:27,445 [root] WARNING: Monitor injection attempted but failed for process 5896
2026-06-29 03:34:27,445 [root] WARNING: Monitor injection attempted but failed for process 6064
2026-06-29 03:34:27,446 [root] WARNING: Monitor injection attempted but failed for process 8144
2026-06-29 03:34:27,446 [root] WARNING: Monitor injection attempted but failed for process 8300
2026-06-29 03:34:27,447 [root] WARNING: Monitor injection attempted but failed for process 8896
2026-06-29 03:34:27,468 [root] WARNING: Monitor injection attempted but failed for process 9056
2026-06-29 03:34:27,469 [root] WARNING: Monitor injection attempted but failed for process 8808
2026-06-29 03:34:27,470 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| win10 | win10 | KVM | 2026-06-29 10:30:20 | 2026-06-29 10:34:31 | internet |
| File Name |
MEMZ.bat
|
|---|---|
| File Type | DOS batch file, ASCII text, with CRLF line terminators |
| File Size | 13782 bytes |
| MD5 | 4e2a7f369378a76d1df4d8c448f712af |
| SHA1 | 1192b4d01254a8704e6d6ae17dc2ec28a7ad5a49 |
| SHA256 | 5e2cd213ff47b7657abd9167c38ffd8b53c13261fe22adddea92b5a2d9e320ad VT MWDB Bazaar |
| SHA3-384 | a33a909ed2e3baed1be578d2a3fcbd6409db141bfa56745774ce1681bf74179e25151a92b86371b286cf3ff7b2de6da2 |
| CRC32 | 1ADFC544 |
| TLSH | T1BB528D3236754E13193326CB5C3AA256BCF4503F761A6E71A4138DFB90AAFD1319EB05 |
| Ssdeep | 192:AOyUySl0UaDz2gWsIzlmj+BxZ3yqueWQx0lZicyC8Sh31xcjBzyxwn7AVhllz3:AVODaDSHMql3yqlxy5L1xcjwrlz3 |
@echo off echo UEsDBBQAAAAIAHV36kiQ6IfZcyEAAAA6AAAIAAAATUVNWi5leGXtew10U8e17kg6soUtjACbGGzi>x echo AxgMyD9Hlm1sY4JkW2AH/wjLP5BgB9k6RhKSjqIfbKcJyBgaqw65tM1NIJckNE1705Tcpi3JJWma>>x echo OD830Da0TptFSQOpXx7NFSnhmYRbnIRw3jfnyMZpfmCt99b7WauzvM+c2TOz95699+zZIw71t+wl>>x echo KkIIAxBFQo4QuZjItctJQErWcynk8LTjC44o6o4vaHa6gqw/IGwJ2L1sl93nE0JsJ88Gwj7W5WOr>>x echo G22sV3Dw+dOnJ2XHaTxj9pZ/yKpcE/Dphr2uz6R3pet3qDdvT3BekurLro+kWuGkdZOry0nHf5Vs>>x echo VgshdQo1eXHNzrYJ3ChRKpIVKYRo0Vgu4/Jm4aEDsPFV03clIWqikPonahKJK0nqNu2WBtKxk/Vk>>x echo JZXDKwk5SF82ExJTfImAfogBPnvLCSm9Dl1PFsip+zJ68ZIf4ntDdHnJcYG0V+WeQmJzfsBhD9kJ>>x echo eXmBjCAL/24BRNKGKV8eRu6jPK1E0g0p/MK44fxAMNBF4mvdHB9X9CX0ArxH6JLXTnUgyVbyhXGV>>x echo X73Cf5T/naVl6NzAXVpdaDqec0KJ7eLiU6yJxBLQZRxuf1lHWtvcqR1Gsa2tzXlFZyJO6iRtYpoD>>x echo o9wOMc2EeuC8Ivzn2zrOTtA7l2lrbXPuKjMRMa0I/UPFEfocd94DVJt4wnmQ1kMnxRNGcWhs99uh>>x echo hbv/Frpxj0W0trkV7tniH/ZYLlrdCZQlvHJYPDHw6tI9lnGre6mY5gElq5hGUO2xxKzOwxLJNA3a>>x echo GL/Hcuao5Yzkqm1iePyoZYy6mZjGoNuZiK3sThDTRtG4rePWob+0v9Iqpm2mBN3E+cZcLEgNygsw>>x echo VIdFOitWQOixWME0qOL3l4pHlmM9Rf98zIpxIPk65mH6MVTG4Y6XGbry/nMV4GdrNb7dFm2/+Au6>>x echo B2xuk5jWi0E2a9QyFpc/9gRoOmMqKhpVoJu4lbFdwA2NH9396meimIuZe6Q3a1vsdtrRPmb8m/j0>>x echo 68BAVrppxDQ/XRTl4TZFLZdlLlLbKoYvRy3jsWpMhBZsYlouunYPhxVr0COmLUULeDEtRLU4wUaH>>x echo 0RjzYJs8YGX44l3q2BX0RcMX3Ulnm0RRlIzrsLUOFY/QZb/dZhNPuBXf37Ue9E58f3A9tcllWKdC>>x echo NtJe6ht3XVbMuPcvMIkzG/oU/YyYxknSzNg9CNvYbDbnzTOhHpvsU3ssjx+1PM6h54VSjD9qeYrA>>x echo 66zR8Ei0/VC0/XC0/Ui0/flo+3C0/dVo+7Fo++vR9jfFtJNUwyhuh9tB61aQe1Nyvct4/jV1j+Uk>>x echo BIpJDOjbGXm81Dixe3jHnzFVhT8nGA87HZLr3knnn4y2jw98KoY1bqWY5pQ0TN0oblTqv2WrYstM>>x echo ZFv6c+nwnKHf6k98i0laO6gwr5TwgQvGX5VNP0dHzPlWf81CExnclXIF6jCvlLCB992EurtEttU2>>x echo ND+bGucPMATjVv31HphpaJVkrz/C7hFI51bCW+Jy9l6Vc2zgihhOdDNnW0XqIpSkWPw6XNY5tow6>>x echo KqWY6FafXYHuVhBLMr5tk+Y7TxXK2t8HMmXzTwE19OnQfOqW25a+wFHTbmPEPxiHrdZWp34ebGGV>>x echo LbV24DXNylV0fOC0U5cDV/vDXy8NFdN98SLdOu6iNmcNavjIwHiCbG2KGy2dwIV7nTTWTyjTSc+h>>x echo oTFqulK6KdS3uZNskte0Uvnuo970PxTh9/dYDhy1HKigmzwaPgQP2VBGHeUgSJFo+2PR9sclP3n+>>x echo qOVIkrT7D1DiVHdiGK5STU1/tuCK5M7r17uToE8Sq1XLu1y3QNrlBLvcOVomb3WqmdhSDNj/7DFQ>>x echo ufRxtOXy25bLp9vHT1vG37Zo5JdTxRvKTeSUmqPPVRHp3YnnOy/FDmIuDTcSQ8RGGszEtKeo3Sza>>x echo Z/dpQPnSx3v8ytgrDH29MvRJ7Nn424exn+DNrdp/66VPb57xkz+qWi43xQ5InbR9QtUy3iSmHaL6>>x echo Um6IRzVpm+pasZEPS3EXL+ckH9ljGUNcTHtMYnzZ+Cu95aJTQ4xk/fpW65BlXI9uvIpp6TS2YeCr>>x echo UpAH2UnhqRtYnffNjR8EcVeIJVMZb9y/8atUM33pFNUMSu+bZdXsZmTVwLsr5lJvPizHjiOUdeGG>>x echo V3AgkNghlWycVNk4R6x0oAaN2HfQ406ljPcwM+WFZ9smV37SFm0fkxePCLnHcspqk1cfuwXzhurP>>x echo DLx0YD+V+WKsVkLEJhDjsdKpI4b+FFs6dQAMlK6i/rBBSf0BVpo2pelkyeukzTbUftnW1EoDbfii>>x echo TVaqTQyPyWqVdHPutOXcqeKaKbrxS++leMa2guJUg2bGT7bYwzTkL98IMdyZOPAGXuasbkV3tCUm>>x echo pl2ka9uupKLsVVBR9uzMVUz63sC59C91ithVp7g4VD8miW9dT7dF68DwAese8wGru9BdCMfInOIY>>x echo Uxz/iysw0RX8SElXMMk8deLgaHMniyf2618eGndr3xDl17E3rsRtL51lkmgnpSgm7ROnYgeR9uIw>>x echo HUJ99TU8L+qPDq0aoxib+MfYN7FSCDU0NqHYXgjxVuzUS6fVVupsH8Ld5kCkoWNDr0F5u38fXu5U>>x echo gWxTnGrMoqDbahU9x5pipXKDnm1NoG6TTs5X/36ftU5GsGb5HHe4lQhhUihzT8exIaaNS6ddKKM1>>x echo xoHkRnlMKyrtZDc0u0HKI0wd7S9ryFdlJRzNSmI0Zo9JkWkIvvT4l6QhA3dpVG1Dd+nCZbahrEtV>>x echo EMUUCeW2xnh4z9B0uiL9utT9kts2SahBCaWjnh/MjNrSO25F9kTFoxp/nqZL7S9rKWWkNn9rG3pn>>x echo 6MrQaw04ULRDFg1yAN3GjUNjVe6ktXI289d3aaj43j3rpZxjsRMKGnMrEDYoRkzTyrmIxq2QD1Rp>>x echo 4J76y+vdDIytk2PTYhxTOyaiTutQWIM1bqIHwLhiu9X4+xpb29A4HGXoT7vF7XO7h5jtM/5d29Ed>>x echo ZTqquqPa7Y0r/3zn+6Cye3j7AnfSbe7pG7vLKlrDuu6yulZleBqGtHZH72xVVq4cufMvt90quejb>>x echo m7IvD1VnX35FXFxDz9vFddLTKj0HWdP/iWT8/0I5bCLkGGAUMA7QmWX8d/B+wCS/n19FyCcAzU2E>>x echo pAJYAAdYA3gP+G7UdwDuBzwOeA5wDHACMIL+YcDPAA8D9gJ2AbYBNqDfsUrmcSDO14raBOAA3XGc>>x echo EnLMAlAjcAAToBlAPesOwN9WE/IYYCfAB9gEqAGUAJYAZgGugFcM9SnACOA5wBhwe1fLPHbFeeUD>>x echo 6O8hvxhNvPeVe98+wiifVZJnyC8IOT7bMBx9JfpS9OUXCHmRmA71X3k4MVhcEQmqzupI9o7Blw49>>x echo ceVXkY/F8KWz74qDrx6KvnIo+mH0nf7XiGmij4QvRU+cfVV86pn3qo6odD8nx3UvQpbhh54lR+59>>x echo 6Qghz44kfvTjFw48AuwZu1b1nv3niqbD33wWY8jm42m39F+JPXIXc+jw2I+v/CbyKQn/99boiSej>>x echo L0XOZL1XOTj6XuXwB+rhvygH/xr9sKP/k4sPhV95gZhA6ggWc/IIWAxf+c1Zljx16olDT/RfGX4o>>x echo VNkvHpwRUp09J1IuijgXzOj/5MAjYdVzFx+S+Rz/Ih+Jydmfi+Bw9iWRtDwxMBNFus9rpF8SWFKc>>x echo PHDhwswLhKwj9zMRkTQ2kkcayfu2nVkXshSVDaTBqpyVNaBDUVoZpVUT0SkNWQOpKMoIM1CNohxk>>x echo lJGUu00p589/gKJ8lFH+QL3z/PkU5eYblYOagTUoypOMciTlHnL+g9OnTqMcx5/yI2bg9AfnifLn>>x echo 8we6UVQso2I1qoUp/eS88lO1yswMjCQmjig/ZnadJ7rEROXP5g34UFR+ZuA8iqqXUfk1u0liIhk9>>x echo r7pJ808gSnp6ehJHRkZGE/GiUs5T9WoG3kdRHWNUw5rdScTfk0hU96qVnzD9p0ZUjzKRHtX7jOo8>>x echo o2qZN/AECqNjGJ2GmZNEx/ohyMeJqn3qyBhTykT8zEq16odzB76PwmxmBowojJNhNk8fUJHz7ygv>>x echo MKr7E/t7/MxqhrmHYdbMY5yau8tQPgYwT2kfLOMg6fl35JLih6hy6fErVP86d2A/ipow/fsfUTMJ>>x echo ajJtEG0syE8UqkFmQIGiXpCg1qtV6oyBb6OorYy6RqfexKhzGLVbrd6YqPYmKo7sI49cSNgfVB/6>>x echo buKOhMQd63ZemJml/rGoeeIXSuvHqhq1qkEdmamyZar86bvOj0Ig1R6tap+mf5SoHp2vGk5nqpn+>>x echo 0VHVO0mR06pYDjNz3oAfojL5ScyKpczmzIiKuSuZuXspMzyd+aUuUsb8Npk5maPWabUjWvUNGjWb>>x echo rF6+WN2ZELmgbktT356oDsxU71yuflJM+KmY+PS/9c+cqfhOIzn1dMrlA2Rdc9LGtFmLk3bpUlBm>>x echo mZhZJk1Sf1ZkZtKP0maFpw0QuJSWUUdOJT/NJB1XJ71h1io0O0+PjMzaz8z6HpNUkJFcq5utS0nu>>x echo 0Mx6kImQZA+jakxIDmck75+RvG/G7Hz1rAfV2rZE7U/VyaFMRjdv58GDB1WnmdkDCZHjs6PqyA6t>>x echo g5n9doLWmaXlZiYHGCZXPbswOdIz+9vqSGIqGrF0bTQttYUZVKEYIc87s95NjEzXOtT9fj+jh/9o>>x echo n56nTknRnp65K3EUJXWYuRsVnMfvT32dOs1fMvovZM38nVptvSFCUt9kdirQU5qYNludNjsJepnx>>x echo 7n/OeOu76kPinEUHb/gBo0mv16TeOosVZ2c92Z+YOPu3Nw8chIekZtbtUvn9KmOqtyj10cz+vYmp>>x echo LxrUtfPTUsT0B0RN2n2pY4kgNidPZHfVJVlv7K82zdNxSQfZeZtv6R8ZWViqTl7ALLiQkWyam1Gb>>x echo tLAoISMpsf/0+dR0RvVDQ/9ooirKJD+ZkPG9hIxblmTsSO9PSsp8lMl4KDnjRznaggUL30jOuJyt>>x echo 3XFjhMu8KSmzNidTyIzsXZSekPndfLU1A0Lo3hqPXFhirScPr9154ULWkkcb4HMJo+KCZ/6gqlUv>>x echo vFetshUnb0hZ9B8a1cPlyY8nL09Sq2Lm5I81i25PZipMi57XMfdwiy5nZt+g1v7bwkhWtml+pCe7>>x echo Q/vNUTnmay8yy7QZ2XvZ3G+oc7eqs388g5SKeXN35IoNOSv2LXnoQSx+8X/dkiWYklhu7tiNEV2S>>x echo YJhnYpVjkXmj6dMVTGTzvM+mqe5fnsGlR1JUb92dMZJuvFnN3GVMtc41/gvDHF/GfS9J+0aWOmvx>>x echo jdHZuZvT1J4czSyRM36W+IKYN0/Mn/tdQ0lyZMxQ8UHy3Jx5o3P7N2+e92lycvfywoPpyY8PGk2Z>>x echo 2roi4975EaP24azi0dnaEWt2dP70VfNnvCUmPC/OGBR1u8Qlzb9eMPzrec8tWfjUsoxpOctH0itv>>x echo Tpi9fafen56aXqofnrtrGkpZ5k2Nqb80qq2Z2T9Ki1xIWyjOWS/eYBXT68WSO39vJqJZfDLjQFHl>>x echo aHqEyzi7oopL3zXN759WVlVvzdxjrBqZX3VeS62Q/VzjmpY3blwpKm5dQZ1jmdjIReaO/Xrht5bM>>x echo G1228K2ccv8Ni26IrtSxi4Y5496s7Bn96/ZnrPslU61Qm3YlrHu9psA6svrdh0z9TIFCpHv4E9Ea>>x echo Obt8Y045u2T5D5eX+xct/+iupkiu0bMysropptPHcmxZcyIf36pkcpcX2wQIf6tFHbmQ+w2D5max>>x echo be8Dm95obF/YePf2nFk5dWuOVLcPq+9dciS7KPvFRUXZZPGR6ro17cOa9jfVB4GLLnpxURT4ujUP>>x echo WbbnbM/x147lOJf6l/ldzpqxte1XEu52Lt2eU7fkocUds5gOHdORwuz2L9u+tm5NxxztwBhmdCRp>>x echo +sfWdqRoOtYwHRXqXTX+WmdN+8Xu3f7a/bll+o7hhI4nEgb8y2bltB9L6PfXdrym6d+f2/Em0/EM>>x echo c/f+3E/zs/PRHE7peF1zG2E6/sZgLFl+mzah4/fafnJzx7DneWfNRiEcYLsErz8c4gOs0x5kO3ne>>x echo x4YC9qCTd7CdfWzIybP1lvpbgBPcdl8+2yD0sLzPLdz2fMK3GvrsPrbKHsrPzy/A3eNgIu4fjS1N>>x echo bFVjvbWl2dLE1phtbKXF0sCuaalaZ6lmKzeyzTUWmWBzU+PN5ob86UnTkz4vRo/gywmxnYIQYsN+>>x echo 1r7F7vLlTk8KCmw4yLOuEAspPYJvC637hDD9Z6AFlEh5NX02B/pc6AsJ7FaXxyNz6qFvXXY6vY9y>>x echo CvYFQ7yXjunkpyc5+CDW1oflunzBkN0X8vTlsuDmkMQIBfooz/Jq7OM/AeYBnKGQv7ygYIsgbPHw>>x echo +V1CftfWgiBvD3Q5V9++qhPk9D32Pn1I0FMR9JRlkPd0X2OeU+jRF+oDvFfYxuvt+m2uQDh4LV7e>>x echo Lns3z+u3BfU+IRASfNcaT3lArCDvc0ywoG1vn7474ALymvxcPr4rYO8O6Z32Xr1D6PF5BLsDzCfF>>x echo vS7+W/iQ3iv4+L5r6lLw3eHSd4Ydjr6r3LoDPH9duuwM9+l7eN5BrleuLsExqXq9y4eXYNju0Xfa>>x echo g66uifvM19Lpcdqpavx+3gcC3dT0egfv4UO8XvY5Y+E1aWwxhvQB49bQNXVjD3U547JO6OZac6TR>>x echo +XzvtfTn8mEf+mAlvtfvEQJ8QO+Cozh5veTcnQGhJ8gHrkMf3fYuHvt4K3TStRXbEkoWPJIBv+g8>>x echo +h4hII0p5Awl17MO2NflcUA2D7/FFfo81eu0d4C3wzR0g+oxUR+w+4KCt8ceuB7/wvz4ZvXy3jv0>>x echo cni8zn2ADTcR7ahmHQJddw/vCjigZbxDGaFu2iP7ElzR77kDDY//6+k67L6tkjjXJ/+kDeQp15hj>>x echo 93TrPa5uXm/Ewj28PQh1Q33XmodVIAqGETrsIRdm2j3X9hsEh5B9C6/32wMCtr7XLjlG/N/9ZQf5>>x echo 2vnUVSWrwJRxll87nob9rQgx0tNr78Nf8Hr2u1tw+vRdvM+u97ocrrgj+oQQrOvbxgdCiD3X8GMf>>x echo H7SHuyRpeczyePiukIsG8q+Xd2sAOuV79cEuHDQCji04ErzP5wKpoD/gCvFBSaRJOvDsHj4QzPe6>>x echo ugJCUOgOgaS3gPflhYMF0GsIbAu6hUDYO9G6TYASA3kTrSD92AJGKKBqzfPaPXSXSM6eJ3t+HnVo>>x echo Guk8f <truncated>
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| N | 74.125.133.138 [VT] | unknown | - |
| N | 64.233.184.105 [VT] | unknown | - |
| N | 50.63.8.124 [VT] | unknown | - |
| Y | 173.194.76.94 [VT] | unknown | - |
| Y | 40.126.31.131 [VT] | unknown | - |
| Y | 108.177.15.139 [VT] | unknown | - |
| N | 108.177.15.94 [VT] | unknown | - |
| Y | 74.125.206.84 [VT] | unknown | - |
| Y | 66.102.1.138 [VT] | unknown | - |
| Y | 74.125.206.138 [VT] | unknown | - |
| Y | 74.125.133.95 [VT] | unknown | - |
| Y | 142.251.150.119 [VT] | unknown | - |
| Y | 142.251.168.139 [VT] | unknown | - |
| Y | 142.251.168.100 [VT] | unknown | - |
| Y | 74.125.206.101 [VT] | unknown | - |
| Y | 74.125.71.94 [VT] | unknown | - |
| Y | 142.251.16.94 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| pcoptimizerpro.com [VT] | A 50.63.8.124 [VT] | 50.63.8.124 [VT] |
| google.co.ck [VT] |
A 64.233.184.99
[VT]
A 64.233.184.105 [VT] A 64.233.184.104 [VT] A 64.233.184.103 [VT] A 64.233.184.106 [VT] A 64.233.184.147 [VT] |
64.233.184.104 [VT] |
| www.google.co.ck [VT] | A 108.177.15.94 [VT] | 108.177.15.94 [VT] |
| consent.google.co.ck [VT] |
A 74.125.133.100
[VT]
A 74.125.133.102 [VT] A 74.125.133.139 [VT] A 74.125.133.101 [VT] A 74.125.133.113 [VT] A 74.125.133.138 [VT] |
74.125.133.113 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.