Analysis Log
2026-06-28 14:55:57,564 [root] INFO: Date set to: 20260629T10:54:37, timeout set to: 25
2026-06-29 10:54:37,554 [root] DEBUG: Starting analyzer from: C:\7d7wfxi0
2026-06-29 10:54:37,555 [root] DEBUG: Storing results at: C:\jXRqFQqtn
2026-06-29 10:54:37,690 [root] DEBUG: Pipe server name: \\.\PIPE\SRwXNL
2026-06-29 10:54:37,693 [root] DEBUG: Python path: C:\Users\Rajesh\AppData\Local\Programs\Python\Python314
2026-06-29 10:54:37,693 [root] INFO: analysis running as an admin
2026-06-29 10:54:37,693 [root] INFO: analysis package specified: "exe"
2026-06-29 10:54:37,693 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2026-06-29 10:54:37,706 [root] DEBUG: imported analysis package "exe"
2026-06-29 10:54:37,706 [root] DEBUG: initializing analysis package "exe"...
2026-06-29 10:54:37,706 [lib.common.common] INFO: no wrapping
2026-06-29 10:54:37,706 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-29 10:54:37,707 [root] DEBUG: New location of moved file: C:\Users\Rajesh\AppData\Local\Temp\HTMLive.exe
2026-06-29 10:54:37,707 [root] INFO: Analyzer: Package modules.packages.exe does not specify a dll option
2026-06-29 10:54:37,707 [root] INFO: Analyzer: Package modules.packages.exe does not specify a dll_64 option
2026-06-29 10:54:37,708 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2026-06-29 10:54:37,708 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2026-06-29 10:54:39,834 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-06-29 10:54:39,844 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-06-29 10:54:39,944 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-06-28 14:56:01,645 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-06-28 14:56:01,651 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-06-28 14:56:01,652 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-06-28 14:56:01,653 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-06-28 14:56:01,660 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-06-28 14:56:01,660 [root] DEBUG: Initialized auxiliary module "Browser"
2026-06-28 14:56:01,661 [root] DEBUG: attempting to configure 'Browser' from data
2026-06-28 14:56:01,663 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-06-28 14:56:01,664 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-06-28 14:56:01,670 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-06-28 14:56:01,672 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-06-28 14:56:01,673 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-06-28 14:56:01,674 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-06-28 14:56:01,675 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-06-28 14:56:01,675 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-06-28 14:56:02,351 [modules.auxiliary.digisig] DEBUG: File has an invalid signature
2026-06-28 14:56:02,352 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-06-28 14:56:02,360 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-06-28 14:56:02,361 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-06-28 14:56:02,361 [root] DEBUG: attempting to configure 'Disguise' from data
2026-06-28 14:56:02,361 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-06-28 14:56:02,362 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-06-28 14:56:02,364 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 836)
2026-06-28 14:56:02,370 [modules.auxiliary.disguise] INFO: Disguising GUID to e06ee56f-3f97-4fb9-8eff-130f7e2f067f
2026-06-28 14:56:02,370 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-06-28 14:56:02,370 [root] DEBUG: Initialized auxiliary module "Human"
2026-06-28 14:56:02,371 [root] DEBUG: attempting to configure 'Human' from data
2026-06-28 14:56:02,371 [root] DEBUG: module Human does not support data configuration, ignoring
2026-06-28 14:56:02,372 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-06-28 14:56:02,373 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-06-28 14:56:02,373 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-06-28 14:56:02,374 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-06-28 14:56:02,375 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-06-28 14:56:02,375 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-06-28 14:56:02,384 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-06-28 14:56:02,384 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-06-28 14:56:02,385 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-06-28 14:56:02,385 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-06-28 14:56:02,385 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-06-28 14:56:02,385 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-06-28 14:56:02,389 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-06-28 14:56:02,389 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-06-28 14:56:08,369 [root] INFO: Restarting WMI Service
2026-06-28 14:56:10,571 [root] DEBUG: package modules.packages.exe does not support configure, ignoring
2026-06-28 14:56:10,574 [root] WARNING: configuration error for package modules.packages.exe: error importing data.packages.exe: No module named 'data.packages'
2026-06-28 14:56:10,575 [lib.core.compound] INFO: C:\Users\Rajesh\AppData\Local\Temp already exists, skipping creation
2026-06-28 14:56:10,585 [lib.api.process] INFO: Successfully executed process from path "C:\Users\Rajesh\AppData\Local\Temp\HTMLive.exe" with arguments "" with pid 4500
2026-06-28 14:56:10,586 [lib.api.process] INFO: Monitor config for process 4500: C:\7d7wfxi0\dll\4500.ini
2026-06-28 14:56:10,604 [lib.api.process] INFO: 32-bit DLL to inject is C:\7d7wfxi0\dll\KYwIXTPC.dll, loader C:\7d7wfxi0\bin\cyFsYoS.exe
2026-06-28 14:56:10,630 [root] DEBUG: Loader: Injecting process 4500 (thread 2784) with C:\7d7wfxi0\dll\KYwIXTPC.dll.
2026-06-28 14:56:10,631 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2026-06-28 14:56:10,632 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2026-06-28 14:56:10,633 [root] DEBUG: Successfully injected DLL C:\7d7wfxi0\dll\KYwIXTPC.dll.
2026-06-28 14:56:10,637 [lib.api.process] INFO: Injected into 32-bit <Process 4500 HTMLive.exe>
2026-06-28 14:56:12,652 [lib.api.process] INFO: Successfully resumed process with pid 4500
2026-06-28 14:56:12,710 [root] DEBUG: 4500: Python path set to 'C:\Users\Rajesh\AppData\Local\Programs\Python\Python314'.
2026-06-28 14:56:12,715 [root] DEBUG: 4500: Disabling sleep skipping.
2026-06-28 14:56:12,716 [root] DEBUG: 4500: Dropped file limit defaulting to 100.
2026-06-28 14:56:12,745 [root] DEBUG: 4500: YaraInit: Compiled 44 rule files
2026-06-28 14:56:12,749 [root] DEBUG: 4500: YaraInit: Compiled rules saved to file C:\7d7wfxi0\data\yara\capemon.yac
2026-06-28 14:56:12,750 [root] DEBUG: 4500: YaraScan: Scanning 0x00B60000, size 0x218
2026-06-28 14:56:12,755 [root] DEBUG: 4500: Monitor initialised: 32-bit capemon loaded in process 4500 at 0x742d0000, thread 2784, image base 0xb60000, stack from 0xf32000-0xf40000
2026-06-28 14:56:12,756 [root] DEBUG: 4500: Commandline: "C:\Users\Rajesh\AppData\Local\Temp\HTMLive.exe"
2026-06-28 14:56:12,825 [root] DEBUG: 4500: hook_api: LdrpCallInitRoutine export address 0x76F72980 obtained via GetFunctionAddress
2026-06-28 14:56:12,853 [root] DEBUG: 4500: hook_api: Warning - SetWindowLongW export address 0x75D57CC0 differs from GetProcAddress -> 0x745E5820 (apphelp.dll::0xfe8c5820)
2026-06-28 14:56:12,855 [root] DEBUG: 4500: hook_api: Warning - EnumDisplayDevicesA export address 0x75D4BE40 differs from GetProcAddress -> 0x745E65C0 (apphelp.dll::0xfe8c65c0)
2026-06-28 14:56:12,856 [root] DEBUG: 4500: hook_api: Warning - EnumDisplayDevicesW export address 0x75D62430 differs from GetProcAddress -> 0x7460E230 (apphelp.dll::0xfe8ee230)
2026-06-28 14:56:12,859 [root] DEBUG: 4500: hook_api: Trampoline creation failed for GetCommandLineA, retrying with HOOK_SAFEST
2026-06-28 14:56:12,860 [root] DEBUG: 4500: hook_api: Trampoline creation failed for GetCommandLineW, retrying with HOOK_SAFEST
2026-06-28 14:56:12,875 [root] DEBUG: 4500: Hooked 635 out of 635 functions
2026-06-28 14:56:12,876 [root] DEBUG: 4500: Syscall hook installed, syscall logging level 1
2026-06-28 14:56:12,886 [root] INFO: Loaded monitor into process with pid 4500
2026-06-28 14:56:12,908 [root] DEBUG: 4500: DLL loaded at 0x74200000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes).
2026-06-28 14:56:12,936 [root] DEBUG: 4500: DLL loaded at 0x74CF0000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-06-28 14:56:12,939 [root] DEBUG: 4500: DLL loaded at 0x741F0000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-06-28 14:56:12,999 [root] DEBUG: 4500: DLL loaded at 0x73960000: C:\Windows\SYSTEM32\ucrtbase_clr0400 (0xab000 bytes).
2026-06-28 14:56:13,001 [root] DEBUG: 4500: DLL loaded at 0x73A10000: C:\Windows\SYSTEM32\VCRUNTIME140_CLR0400 (0x14000 bytes).
2026-06-28 14:56:13,003 [root] DEBUG: 4500: DLL loaded at 0x73A30000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr (0x7b1000 bytes).
2026-06-28 14:56:13,152 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x01293000, size: 0x1000.
2026-06-28 14:56:13,153 [root] DEBUG: 4500: GetEntropy: Error - Supplied address inaccessible: 0x01290000
2026-06-28 14:56:13,183 [root] DEBUG: 4500: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2026-06-28 14:56:13,195 [root] DEBUG: 4500: DLL loaded at 0x73950000: C:\Windows\SYSTEM32\WTSAPI32 (0xf000 bytes).
2026-06-28 14:56:13,209 [root] DEBUG: 4500: DLL loaded at 0x73900000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-06-28 14:56:13,338 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x07B20000, size: 0x1000.
2026-06-28 14:56:13,372 [root] DEBUG: 4500: DLL loaded at 0x769D0000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-06-28 14:56:13,379 [root] DEBUG: 4500: DLL loaded at 0x73880000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-06-28 14:56:13,397 [root] DEBUG: 4500: hook_api: clrjit::compileMethod export address 0x737F3700 obtained via GetFunctionAddress
2026-06-28 14:56:13,401 [root] DEBUG: 4500: DLL loaded at 0x737F0000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit (0x8a000 bytes).
2026-06-28 14:56:13,420 [root] DEBUG: 4500: .NET JIT native cache at 0x07B20000: scans and dumps active.
2026-06-28 14:56:13,433 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07B20000 skipped
2026-06-28 14:56:13,495 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x04645000, size: 0x1000.
2026-06-28 14:56:13,497 [root] DEBUG: 4500: GetEntropy: Error - Supplied address inaccessible: 0x04640000
2026-06-28 14:56:13,508 [root] DEBUG: 4500: AllocationHandler: Allocation already in tracked region list: 0x07B20000.
2026-06-28 14:56:13,684 [root] DEBUG: 4500: .NET JIT native cache at 0x07CF0000: scans and dumps active.
2026-06-28 14:56:13,691 [root] DEBUG: 4500: caller_dispatch: Added region at 0x07CF0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x07CF2F53, thread 2784).
2026-06-28 14:56:13,692 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07CF0000 skipped
2026-06-28 14:56:13,693 [root] DEBUG: 4500: AllocationHandler: Allocation already in tracked region list: 0x01290000.
2026-06-28 14:56:13,731 [root] DEBUG: 4500: AllocationHandler: Previously reserved region at 0x07CF0000, committing at: 0x07CF9000.
2026-06-28 14:56:13,785 [root] DEBUG: 4500: .NET JIT native cache at 0x07D40000: scans and dumps active.
2026-06-28 14:56:13,792 [root] DEBUG: 4500: caller_dispatch: Added region at 0x07D40000 to tracked regions list (ntdll::NtQueryInformationThread returns to 0x07D41341, thread 2784).
2026-06-28 14:56:13,793 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07D40000 skipped
2026-06-28 14:56:14,059 [root] DEBUG: 4500: .NET JIT native cache at 0x07E40000: scans and dumps active.
2026-06-28 14:56:14,062 [root] DEBUG: 4500: caller_dispatch: Added region at 0x07E40000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x07E40A1A, thread 2784).
2026-06-28 14:56:14,063 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07E40000 skipped
2026-06-28 14:56:14,104 [root] DEBUG: 4500: DLL loaded at 0x737D0000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-06-28 14:56:14,107 [root] DEBUG: 4500: DLL loaded at 0x737A0000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2026-06-28 14:56:14,128 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x0463A000, size: 0x1000.
2026-06-28 14:56:14,207 [root] DEBUG: 4500: .NET JIT native cache at 0x07E70000: scans and dumps active.
2026-06-28 14:56:14,209 [root] DEBUG: 4500: caller_dispatch: Added region at 0x07E70000 to tracked regions list (ntdll::NtCreateFile returns to 0x07E700F3, thread 2784).
2026-06-28 14:56:14,209 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07E70000 skipped
2026-06-28 14:56:14,241 [root] DEBUG: 4500: DLL loaded at 0x746B0000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-06-28 14:56:14,244 [root] DEBUG: 4500: DLL loaded at 0x746E0000: C:\Windows\SYSTEM32\windows.storage (0x608000 bytes).
2026-06-28 14:56:14,247 [root] DEBUG: 4500: DLL loaded at 0x755E0000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-06-28 14:56:14,253 [root] DEBUG: 4500: DLL loaded at 0x73780000: C:\Windows\SYSTEM32\profapi (0x18000 bytes).
2026-06-28 14:56:14,370 [root] DEBUG: 4500: .NET JIT native cache at 0x07F70000: scans and dumps active.
2026-06-28 14:56:14,380 [root] DEBUG: 4500: caller_dispatch: Added region at 0x07F70000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x07F70422, thread 2784).
2026-06-28 14:56:14,381 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07F70000 skipped
2026-06-28 14:56:14,491 [root] DEBUG: 4500: .NET JIT native cache at 0x07F30000: scans and dumps active.
2026-06-28 14:56:14,498 [root] DEBUG: 4500: caller_dispatch: Added region at 0x07F30000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x07F30778, thread 2784).
2026-06-28 14:56:14,499 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07F30000 skipped
2026-06-28 14:56:14,591 [root] DEBUG: 4500: DLL loaded at 0x736F0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.19041.1110_none_c0da534e38c01f4d\comctl32 (0x8d000 bytes).
2026-06-28 14:56:14,608 [root] DEBUG: 4500: AllocationHandler: Previously reserved region at 0x07F30000, committing at: 0x07F3E000.
2026-06-28 14:56:14,610 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x012AD000, size: 0x1000.
2026-06-28 14:56:14,625 [root] DEBUG: 4500: .NET JIT native cache at 0x07FA0000: scans and dumps active.
2026-06-28 14:56:14,627 [root] DEBUG: 4500: caller_dispatch: Added region at 0x07FA0000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x07FA0689, thread 2784).
2026-06-28 14:56:14,628 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07FA0000 skipped
2026-06-28 14:56:14,706 [root] DEBUG: 4500: InstrumentationCallback: Added region at 0x751524AC (base 0x75130000) to tracked regions list (thread 2784).
2026-06-28 14:56:14,707 [root] DEBUG: 4500: ProcessTrackedRegion: Region at 0x75130000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-06-28 14:56:14,709 [root] DEBUG: 4500: AllocationHandler: Previously reserved region at 0x07FA0000, committing at: 0x07FA8000.
2026-06-28 14:56:14,723 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x7FCF0000, size: 0x50000.
2026-06-28 14:56:14,724 [root] DEBUG: 4500: GetEntropy: Error - Supplied address inaccessible: 0x7FCF0000
2026-06-28 14:56:14,725 [root] DEBUG: 4500: AllocationHandler: Processing previous tracked region at: 0x07FA0000.
2026-06-28 14:56:14,726 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07FA0000 skipped
2026-06-28 14:56:14,727 [root] DEBUG: 4500: AllocationHandler: Memory region (size 0x50000) reserved but not committed at 0x7FCF0000.
2026-06-28 14:56:14,728 [root] DEBUG: 4500: AllocationHandler: Previously reserved region at 0x7FCF0000, committing at: 0x7FCF0000.
2026-06-28 14:56:14,729 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x7FCE0000, size: 0x10000.
2026-06-28 14:56:14,730 [root] DEBUG: 4500: GetEntropy: Error - Supplied address inaccessible: 0x7FCE0000
2026-06-28 14:56:14,731 [root] DEBUG: 4500: AllocationHandler: Processing previous tracked region at: 0x7FCF0000.
2026-06-28 14:56:14,732 [root] DEBUG: 4500: ProcessTrackedRegion: Entropy for tracked region at 0x7FCF0000: 1.341173e-01
2026-06-28 14:56:14,733 [root] DEBUG: 4500: DumpPEsInRange: Scanning range 0x7FCF0000 - 0x7FCF003C.
2026-06-28 14:56:14,734 [root] DEBUG: 4500: ScanForDisguisedPE: Size too small: 0x3c bytes
2026-06-28 14:56:14,742 [lib.common.results] INFO: Uploading file C:\jXRqFQqtn\CAPE\4500_1415353514562128062026 to CAPE\31224ad4f6c7504ce6f7e40fa315803be21124a78eac135ddd82b8eaba18535b; Size is 60; Max size: 100000000
2026-06-28 14:56:14,747 [root] DEBUG: 4500: DumpMemory: Payload successfully created: C:\jXRqFQqtn\CAPE\4500_1415353514562128062026 (size 60 bytes)
2026-06-28 14:56:14,748 [root] DEBUG: 4500: DumpRegion: Dumped entire allocation from 0x7FCF0000, size 4096 bytes.
2026-06-28 14:56:14,749 [root] DEBUG: 4500: ProcessTrackedRegion: Dumped region at 0x7FCF0000.
2026-06-28 14:56:14,749 [root] DEBUG: 4500: YaraScan: Scanning 0x7FCF0000, size 0x3c
2026-06-28 14:56:14,750 [root] DEBUG: 4500: AllocationHandler: Memory region (size 0x10000) reserved but not committed at 0x7FCE0000.
2026-06-28 14:56:14,751 [root] DEBUG: 4500: AllocationHandler: Previously reserved region at 0x7FCE0000, committing at: 0x7FCE0000.
2026-06-28 14:56:14,830 [root] DEBUG: 4500: .NET JIT native cache at 0x07FE0000: scans and dumps active.
2026-06-28 14:56:14,841 [root] DEBUG: 4500: caller_dispatch: Added region at 0x07FE0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x07FE6E67, thread 2784).
2026-06-28 14:56:14,842 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x07FE0000 skipped
2026-06-28 14:56:14,904 [root] DEBUG: 4500: .NET JIT native cache at 0x08030000: scans and dumps active.
2026-06-28 14:56:14,915 [root] DEBUG: 4500: caller_dispatch: Added region at 0x08030000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x08031174, thread 2784).
2026-06-28 14:56:14,916 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x08030000 skipped
2026-06-28 14:56:14,969 [root] DEBUG: 4500: DLL loaded at 0x73650000: C:\Windows\SYSTEM32\USP10 (0x17000 bytes).
2026-06-28 14:56:14,970 [root] DEBUG: 4500: DLL loaded at 0x73610000: C:\Windows\SYSTEM32\msls31 (0x31000 bytes).
2026-06-28 14:56:14,971 [root] DEBUG: 4500: DLL loaded at 0x73670000: C:\Windows\SYSTEM32\RichEd20 (0x7a000 bytes).
2026-06-28 14:56:15,038 [root] DEBUG: 4500: DLL loaded at 0x734A0000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1288_none_d9539a9fe102720c\gdiplus (0x169000 bytes).
2026-06-28 14:56:15,065 [root] DEBUG: 4500: DLL loaded at 0x73290000: C:\Windows\SYSTEM32\DWrite (0x210000 bytes).
2026-06-28 14:56:15,069 [root] DEBUG: 4500: DLL loaded at 0x768E0000: C:\Windows\System32\MSCTF (0xd3000 bytes).
2026-06-29 03:55:00,531 [root] DEBUG: 4500: .NET JIT native cache at 0x08B80000: scans and dumps active.
2026-06-29 03:55:00,534 [root] DEBUG: 4500: caller_dispatch: Added region at 0x08B80000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x08B80105, thread 2784).
2026-06-29 03:55:00,535 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x08B80000 skipped
2026-06-29 03:55:00,627 [root] DEBUG: 4500: ProcessTrackedRegion: Updated entropy for tracked region at 0x012A0000: 3.425831e+00 (from 3.129104e+00)
2026-06-29 03:55:00,629 [root] DEBUG: 4500: DumpPEsInRange: Scanning range 0x012A0000 - 0x012AB54A.
2026-06-29 03:55:00,630 [root] DEBUG: 4500: ScanForDisguisedPE: No PE image located in range 0x012A0000-0x012AB54A.
2026-06-29 03:55:00,633 [lib.common.results] INFO: Uploading file C:\jXRqFQqtn\CAPE\4500_99875000551029162026 to CAPE\ee5f16dc47945cae528752f9a1c59316cfb9d941272eb7a2f00ebe0d074f2720; Size is 46410; Max size: 100000000
2026-06-29 03:55:00,638 [root] DEBUG: 4500: DumpMemory: Payload successfully created: C:\jXRqFQqtn\CAPE\4500_99875000551029162026 (size 46410 bytes)
2026-06-29 03:55:00,639 [root] DEBUG: 4500: DumpRegion: Dumped entire allocation from 0x012A0000, size 49152 bytes.
2026-06-29 03:55:00,640 [root] DEBUG: 4500: ProcessTrackedRegion: Dumped region at 0x012A0000.
2026-06-29 03:55:00,640 [root] DEBUG: 4500: YaraScan: Scanning 0x012A0000, size 0xb54a
2026-06-29 03:55:00,698 [root] DEBUG: 4500: .NET JIT native cache at 0x09300000: scans and dumps active.
2026-06-29 03:55:00,707 [root] DEBUG: 4500: caller_dispatch: Added region at 0x09300000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x0930165B, thread 2784).
2026-06-29 03:55:00,708 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x09300000 skipped
2026-06-29 03:55:00,849 [root] DEBUG: 4500: DLL loaded at 0x76A30000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-06-29 03:55:00,868 [root] DEBUG: 4500: DLL loaded at 0x72A30000: C:\Windows\System32\iertutil (0x22b000 bytes).
2026-06-29 03:55:00,869 [root] DEBUG: 4500: DLL loaded at 0x72A10000: C:\Windows\System32\NETAPI32 (0x13000 bytes).
2026-06-29 03:55:00,870 [root] DEBUG: 4500: DLL loaded at 0x729E0000: C:\Windows\System32\USERENV (0x25000 bytes).
2026-06-29 03:55:00,872 [root] DEBUG: 4500: DLL loaded at 0x72910000: C:\Windows\System32\WINHTTP (0xc8000 bytes).
2026-06-29 03:55:00,873 [root] DEBUG: 4500: DLL loaded at 0x72900000: C:\Windows\System32\WKSCLI (0x10000 bytes).
2026-06-29 03:55:00,874 [root] DEBUG: 4500: DLL loaded at 0x728F0000: C:\Windows\System32\NETUTILS (0xb000 bytes).
2026-06-29 03:55:00,875 [root] DEBUG: 4500: DLL loaded at 0x72C60000: C:\Windows\System32\ieframe (0x62f000 bytes).
2026-06-29 03:55:00,884 [root] DEBUG: 4500: ProcessTrackedRegion: Region at 0x75130000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-06-29 03:55:00,887 [root] DEBUG: 4500: DLL loaded at 0x726E0000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984\comctl32 (0x210000 bytes).
2026-06-29 03:55:00,896 [root] DEBUG: 4500: ProcessTrackedRegion: Region at 0x75130000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-06-29 03:55:00,908 [root] DEBUG: 4500: DLL loaded at 0x72650000: C:\Windows\SYSTEM32\sxs (0x88000 bytes).
2026-06-29 03:55:00,996 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x08001000, size: 0x1000.
2026-06-29 03:55:01,008 [root] DEBUG: 4500: .NET JIT native cache at 0x09380000: scans and dumps active.
2026-06-29 03:55:01,011 [root] DEBUG: 4500: caller_dispatch: Added region at 0x09380000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x09380B87, thread 2784).
2026-06-29 03:55:01,012 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x09380000 skipped
2026-06-29 03:55:01,055 [root] DEBUG: 4500: DLL loaded at 0x721F0000: C:\Windows\system32\dxgi (0xc3000 bytes).
2026-06-29 03:55:01,057 [root] DEBUG: 4500: DLL loaded at 0x72430000: C:\Windows\system32\d3d11 (0x1e0000 bytes).
2026-06-29 03:55:01,058 [root] DEBUG: 4500: DLL loaded at 0x722C0000: C:\Windows\system32\dcomp (0x165000 bytes).
2026-06-29 03:55:01,059 [root] DEBUG: 4500: DLL loaded at 0x72610000: C:\Windows\system32\dataexchange (0x32000 bytes).
2026-06-29 03:55:01,068 [root] DEBUG: 4500: DLL loaded at 0x72060000: C:\Windows\system32\twinapi.appcore (0x18f000 bytes).
2026-06-29 03:55:01,104 [root] DEBUG: 4500: AllocationHandler: Allocation already in tracked region list: 0x04630000.
2026-06-29 03:55:01,133 [root] DEBUG: 4500: DLL loaded at 0x71F90000: C:\Windows\SYSTEM32\PROPSYS (0xc2000 bytes).
2026-06-29 03:55:01,147 [root] DEBUG: 4500: DLL loaded at 0x71F40000: C:\Windows\SYSTEM32\msIso (0x43000 bytes).
2026-06-29 03:55:01,184 [root] DEBUG: 4500: DLL loaded at 0x71D70000: C:\Windows\SYSTEM32\srvcli (0x1d000 bytes).
2026-06-29 03:55:01,191 [root] DEBUG: 4500: DLL loaded at 0x71D90000: C:\Windows\SYSTEM32\urlmon (0x1a8000 bytes).
2026-06-29 03:55:01,252 [root] DEBUG: 4500: DLL loaded at 0x70AC0000: C:\Windows\SYSTEM32\powrprof (0x44000 bytes).
2026-06-29 03:55:01,315 [root] DEBUG: 4500: DLL loaded at 0x70B10000: C:\Windows\System32\mshtml (0x1254000 bytes).
2026-06-29 03:55:01,317 [root] DEBUG: 4500: DLL loaded at 0x70AB0000: C:\Windows\SYSTEM32\UMPDC (0xd000 bytes).
2026-06-29 03:55:01,385 [root] DEBUG: 4500: ProcessTrackedRegion: Region at 0x75130000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-06-29 03:55:01,438 [root] DEBUG: 4500: ProcessTrackedRegion: Region at 0x75130000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-06-29 03:55:01,468 [root] DEBUG: 4500: DLL loaded at 0x70A80000: C:\Windows\System32\srpapi (0x25000 bytes).
2026-06-29 03:55:01,603 [root] DEBUG: 4500: .NET JIT native cache at 0x0B260000: scans and dumps active.
2026-06-29 03:55:01,606 [root] DEBUG: 4500: caller_dispatch: Added region at 0x0B260000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x0B26011F, thread 2784).
2026-06-29 03:55:01,607 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x0B260000 skipped
2026-06-29 03:55:01,683 [root] DEBUG: 4500: DLL loaded at 0x709E0000: C:\Windows\SYSTEM32\TextShaping (0x94000 bytes).
2026-06-29 03:55:01,779 [root] DEBUG: 4500: DLL loaded at 0x70860000: C:\Windows\SYSTEM32\WindowsCodecs (0x171000 bytes).
2026-06-29 03:55:02,033 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x0B200000, size: 0x8000.
2026-06-29 03:55:02,035 [root] DEBUG: 4500: GetEntropy: Error - Supplied address inaccessible: 0x0B200000
2026-06-29 03:55:02,039 [root] DEBUG: 4500: AllocationHandler: Processing previous tracked region at: 0x08000000.
2026-06-29 03:55:02,041 [root] DEBUG: 4500: ProcessTrackedRegion: Updated entropy for tracked region at 0x08000000: 1.764103e+00 (from 1.163484e+00)
2026-06-29 03:55:02,042 [root] DEBUG: 4500: DumpPEsInRange: Scanning range 0x08000000 - 0x08006FFE.
2026-06-29 03:55:02,043 [root] DEBUG: 4500: ScanForDisguisedPE: No PE image located in range 0x08000000-0x08006FFE.
2026-06-29 03:55:02,046 [lib.common.results] INFO: Uploading file C:\jXRqFQqtn\CAPE\4500_5895722551029162026 to CAPE\7415bbbf4690ce7e9491f81bbc414968aed014b33adeb1889801131d86ebee63; Size is 28670; Max size: 100000000
2026-06-29 03:55:02,051 [root] DEBUG: 4500: DumpMemory: Payload successfully created: C:\jXRqFQqtn\CAPE\4500_5895722551029162026 (size 28670 bytes)
2026-06-29 03:55:02,052 [root] DEBUG: 4500: DumpRegion: Dumped entire allocation from 0x08000000, size 28672 bytes.
2026-06-29 03:55:02,053 [root] DEBUG: 4500: ProcessTrackedRegion: Dumped region at 0x08000000.
2026-06-29 03:55:02,054 [root] DEBUG: 4500: YaraScan: Scanning 0x08000000, size 0x6ffe
2026-06-29 03:55:02,056 [root] DEBUG: 4500: AllocationHandler: Memory region (size 0x8000) reserved but not committed at 0x0B200000.
2026-06-29 03:55:02,058 [root] DEBUG: 4500: AllocationHandler: Previously reserved region at 0x0B200000, committing at: 0x0B200000.
2026-06-29 03:55:02,242 [root] DEBUG: 4500: .NET JIT native cache at 0x0B210000: scans and dumps active.
2026-06-29 03:55:02,252 [root] DEBUG: 4500: caller_dispatch: Added region at 0x0B210000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x0B210E75, thread 2784).
2026-06-29 03:55:02,253 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x0B210000 skipped
2026-06-29 03:55:02,398 [root] DEBUG: 4500: .NET JIT native cache at 0x0B230000: scans and dumps active.
2026-06-29 03:55:02,441 [root] DEBUG: 4500: caller_dispatch: Added region at 0x0B230000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x0B235734, thread 2784).
2026-06-29 03:55:02,443 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x0B230000 skipped
2026-06-29 03:55:02,546 [root] DEBUG: 4500: .NET JIT native cache at 0x0C560000: scans and dumps active.
2026-06-29 03:55:02,553 [root] DEBUG: 4500: caller_dispatch: Added region at 0x0C560000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x0C560769, thread 2784).
2026-06-29 03:55:02,554 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x0C560000 skipped
2026-06-29 03:55:02,629 [root] DEBUG: 4500: ProcessTrackedRegion: Region at 0x75130000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-06-29 03:55:02,767 [root] DEBUG: 4500: DLL loaded at 0x70450000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-06-29 03:55:02,771 [root] DEBUG: 4500: DLL loaded at 0x70480000: C:\Windows\System32\CoreMessaging (0x9b000 bytes).
2026-06-29 03:55:02,775 [root] DEBUG: 4500: DLL loaded at 0x70370000: C:\Windows\SYSTEM32\wintypes (0xdb000 bytes).
2026-06-29 03:55:02,780 [root] DEBUG: 4500: DLL loaded at 0x70520000: C:\Windows\System32\CoreUIComponents (0x27e000 bytes).
2026-06-29 03:55:02,784 [root] DEBUG: 4500: DLL loaded at 0x707A0000: C:\Windows\SYSTEM32\textinputframework (0xb9000 bytes).
2026-06-29 03:55:02,962 [root] DEBUG: 4500: DLL loaded at 0x70360000: C:\Windows\system32\msimtf (0xe000 bytes).
2026-06-29 03:55:02,987 [root] DEBUG: 4500: DLL loaded at 0x6FE40000: C:\Windows\System32\d2d1 (0x515000 bytes).
2026-06-29 03:55:02,996 [root] DEBUG: 4500: DLL loaded at 0x6FE30000: C:\Windows\SYSTEM32\resourcepolicyclient (0xf000 bytes).
2026-06-29 03:55:03,035 [root] DEBUG: 4500: DLL loaded at 0x6F870000: C:\Windows\SYSTEM32\d3d10warp (0x5c2000 bytes).
2026-06-29 03:55:03,050 [root] DEBUG: 4500: DLL loaded at 0x75720000: C:\Windows\System32\cfgmgr32 (0x3b000 bytes).
2026-06-29 03:55:03,052 [root] DEBUG: 4500: DLL loaded at 0x6F840000: C:\Windows\SYSTEM32\dxcore (0x2c000 bytes).
2026-06-29 03:55:03,203 [root] DEBUG: 4500: AllocationHandler: Previously reserved region at 0x0C560000, committing at: 0x0C56F000.
2026-06-29 03:55:03,207 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x0F850000, size: 0x1000.
2026-06-29 03:55:03,240 [root] DEBUG: 4500: .NET JIT native cache at 0x0F850000: scans and dumps active.
2026-06-29 03:55:03,249 [root] DEBUG: 4500: DLL loaded at 0x6F830000: C:\Windows\SYSTEM32\Secur32 (0xa000 bytes).
2026-06-29 03:55:03,254 [root] DEBUG: 4500: DLL loaded at 0x6F7F0000: C:\Windows\SYSTEM32\MLANG (0x34000 bytes).
2026-06-29 03:55:03,265 [root] DEBUG: 4500: DLL loaded at 0x6F3A0000: C:\Windows\SYSTEM32\WININET (0x450000 bytes).
2026-06-29 03:55:03,369 [root] DEBUG: 4500: AllocationHandler: Adding allocation to tracked region list: 0x7FCD0000, size: 0x1000.
2026-06-29 03:55:03,410 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x0F850000 skipped
2026-06-29 03:55:03,482 [root] DEBUG: 4500: .NET JIT native cache at 0x0FC50000: scans and dumps active.
2026-06-29 03:55:03,485 [root] DEBUG: 4500: caller_dispatch: Added region at 0x0FC50000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x0FC50929, thread 2784).
2026-06-29 03:55:03,486 [root] DEBUG: 4500: ProcessTrackedRegion: .NET cache region at 0x0FC50000 skipped
2026-06-29 03:55:20,153 [root] INFO: Analysis timeout hit, terminating analysis
2026-06-29 03:55:20,155 [lib.api.process] INFO: Terminate event set for process 4500
2026-06-29 03:55:20,157 [root] DEBUG: 4500: Terminate Event: Attempting to dump process 4500
2026-06-29 03:55:20,158 [root] DEBUG: 4500: VerifyCodeSection: Executable code does not match, 0x204f2 of 0x204f3 matching
2026-06-29 03:55:20,160 [root] DEBUG: 4500: DoProcessDump: Code modification detected, dumping Imagebase at 0x00B60000.
2026-06-29 03:55:20,161 [root] DEBUG: 4500: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-06-29 03:55:20,162 [root] DEBUG: 4500: DumpProcess: Instantiating PeParser with address: 0x00B60000.
2026-06-29 03:55:20,163 [root] DEBUG: 4500: DumpProcess: Module entry point VA is 0x00B824EE.
2026-06-29 03:55:20,163 [root] DEBUG: 4500: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x00B62000, section 1
2026-06-29 03:55:20,164 [root] DEBUG: 4500: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x00B84000, section 2
2026-06-29 03:55:20,165 [root] DEBUG: 4500: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x00B8A000, section 4
2026-06-29 03:55:20,166 [root] DEBUG: 4500: reBasePEImage: Exception rebasing image from 0x00B60000 to 0x00400000.
2026-06-29 03:55:20,167 [root] DEBUG: 4500: readPeSectionsFromProcess: Failed to relocate image back to header image base 0x00400000.
2026-06-29 03:55:20,172 [lib.common.results] INFO: Uploading file C:\jXRqFQqtn\CAPE\4500_684720551029162026 to procdump\f6b3577e43911312e7ab3c479b13215e856a3ce268d071e250a391b84ff632d8; Size is 17408; Max size: 100000000
2026-06-29 03:55:20,187 [root] DEBUG: 4500: DumpProcess: Module image dump success - dump size 0x4400.
2026-06-29 03:55:20,191 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07B20000 (jit-dumps=0)
2026-06-29 03:55:20,192 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07CF0000 (jit-dumps=0)
2026-06-29 03:55:20,194 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07D40000 (jit-dumps=0)
2026-06-29 03:55:20,195 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07E40000 (jit-dumps=0)
2026-06-29 03:55:20,195 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07E70000 (jit-dumps=0)
2026-06-29 03:55:20,197 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07F30000 (jit-dumps=0)
2026-06-29 03:55:20,198 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07F70000 (jit-dumps=0)
2026-06-29 03:55:20,199 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07FA0000 (jit-dumps=0)
2026-06-29 03:55:20,200 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x07FE0000 (jit-dumps=0)
2026-06-29 03:55:20,202 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x08030000 (jit-dumps=0)
2026-06-29 03:55:20,205 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x08B80000 (jit-dumps=0)
2026-06-29 03:55:20,207 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x09300000 (jit-dumps=0)
2026-06-29 03:55:20,210 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x09380000 (jit-dumps=0)
2026-06-29 03:55:20,212 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x0B210000 (jit-dumps=0)
2026-06-29 03:55:20,213 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x0B230000 (jit-dumps=0)
2026-06-29 03:55:20,214 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x0B260000 (jit-dumps=0)
2026-06-29 03:55:20,215 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x0C560000 (jit-dumps=0)
2026-06-29 03:55:20,217 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x0F850000 (jit-dumps=0)
2026-06-29 03:55:20,218 [root] DEBUG: 4500: DumpInterestingRegions: Skipping .NET JIT native cache at 0x0FC50000 (jit-dumps=0)
2026-06-29 03:55:20,223 [root] DEBUG: 4500: ProcessTrackedRegion: Updated entropy for tracked region at 0x7FCD0000: 6.939652e-01 (from 6.939653e-01)
2026-06-29 03:55:20,224 [root] DEBUG: 4500: DumpPEsInRange: Scanning range 0x7FCD0000 - 0x7FCD010B.
2026-06-29 03:55:20,225 [root] DEBUG: 4500: ScanForDisguisedPE: Size too small: 0x10b bytes
2026-06-29 03:55:20,228 [lib.common.results] INFO: Uploading file C:\jXRqFQqtn\CAPE\4500_411814120551029162026 to CAPE\ca517a62cc4bd322c4afb74599b3f4a6f414d0fb6f750eae56a0d9c95d997f49; Size is 267; Max size: 100000000
2026-06-29 03:55:20,252 [root] DEBUG: 4500: DumpMemory: Payload successfully created: C:\jXRqFQqtn\CAPE\4500_411814120551029162026 (size 267 bytes)
2026-06-29 03:55:20,253 [root] DEBUG: 4500: DumpRegion: Dumped entire allocation from 0x7FCD0000, size 4096 bytes.
2026-06-29 03:55:20,254 [root] DEBUG: 4500: ProcessTrackedRegion: Dumped region at 0x7FCD0000.
2026-06-29 03:55:20,255 [root] DEBUG: 4500: YaraScan: Scanning 0x7FCD0000, size 0x10b
2026-06-29 03:55:20,256 [root] DEBUG: 4500: Terminate Event: Shutdown complete for process 4500 but failed to inform analyzer.
2026-06-29 03:55:25,169 [lib.api.process] INFO: Termination confirmed for process 4500
2026-06-29 03:55:25,170 [root] INFO: Terminate event set for process 4500
2026-06-29 03:55:25,170 [root] INFO: Created shutdown mutex
2026-06-29 03:55:26,187 [root] INFO: Shutting down package
2026-06-29 03:55:26,188 [root] INFO: Stopping auxiliary modules
2026-06-29 03:55:26,188 [root] INFO: Stopping auxiliary module: Browser
2026-06-29 03:55:26,189 [root] INFO: Stopping auxiliary module: Human
2026-06-29 03:55:31,766 [root] INFO: Stopping auxiliary module: Screenshots
2026-06-29 03:55:31,767 [root] INFO: Finishing auxiliary modules
2026-06-29 03:55:31,768 [root] INFO: Shutting down pipe server and dumping dropped files
2026-06-29 03:55:31,769 [root] WARNING: Folder at path "C:\jXRqFQqtn\debugger" does not exist, skipping
2026-06-29 03:55:31,769 [root] WARNING: Folder at path "C:\jXRqFQqtn\tlsdump" does not exist, skipping
2026-06-29 03:55:31,771 [root] INFO: Analysis completed