Analysis Log
2026-03-05 20:34:41,788 [root] INFO: Date set to: 20260416T22:44:30, timeout set to: 200
2026-04-16 22:44:30,187 [root] DEBUG: Starting analyzer from: C:\ltb6yatm
2026-04-16 22:44:30,281 [root] DEBUG: Storing results at: C:\OHjuCIJf
2026-04-16 22:44:30,297 [root] DEBUG: Pipe server name: \\.\PIPE\THzYLz
2026-04-16 22:44:30,328 [root] DEBUG: Python path: C:\Python310
2026-04-16 22:44:30,343 [root] INFO: analysis running as an admin
2026-04-16 22:44:30,343 [root] INFO: analysis package specified: "dll"
2026-04-16 22:44:30,359 [root] DEBUG: importing analysis package module: "modules.packages.dll"...
2026-04-16 22:44:30,375 [root] DEBUG: imported analysis package "dll"
2026-04-16 22:44:30,375 [root] DEBUG: initializing analysis package "dll"...
2026-04-16 22:44:30,375 [lib.common.common] INFO: wrapping
2026-04-16 22:44:30,547 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-16 22:44:30,562 [root] DEBUG: New location of moved file: C:\Users\cape\AppData\Local\Temp\ClientPlugin.dll
2026-04-16 22:44:30,578 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL option
2026-04-16 22:44:30,578 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL_64 option
2026-04-16 22:44:30,578 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader option
2026-04-16 22:44:30,578 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader_64 option
2026-04-16 22:44:30,594 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-04-16 22:44:30,969 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-04-16 22:44:31,047 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-04-16 22:44:31,093 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-04-16 22:44:31,187 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-04-16 22:44:31,609 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-04-16 22:44:31,828 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-04-16 22:44:34,140 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance
2026-04-16 22:44:34,140 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-04-16 22:44:34,140 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-04-16 22:44:34,140 [root] DEBUG: Initialized auxiliary module "Browser"
2026-04-16 22:44:34,140 [root] DEBUG: attempting to configure 'Browser' from data
2026-04-16 22:44:34,156 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-04-16 22:44:34,156 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-04-16 22:44:34,156 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-04-16 22:44:34,156 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-04-16 22:44:34,156 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-04-16 22:44:34,172 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-04-16 22:44:34,172 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-04-16 22:44:34,172 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-04-16 22:44:57,734 [modules.auxiliary.digisig] DEBUG: File is not signed
2026-04-16 22:44:57,750 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-04-16 22:44:57,750 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-04-16 22:44:57,750 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-04-16 22:44:57,750 [root] DEBUG: attempting to configure 'Disguise' from data
2026-04-16 22:44:57,750 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-04-16 22:44:57,750 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-04-16 22:44:57,875 [modules.auxiliary.disguise] INFO: Disguising GUID to b891db33-606d-41e0-a0dd-e7dd26a578cf
2026-04-16 22:44:57,875 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-04-16 22:44:57,890 [root] DEBUG: Initialized auxiliary module "Human"
2026-04-16 22:44:57,890 [root] DEBUG: attempting to configure 'Human' from data
2026-04-16 22:44:57,890 [root] DEBUG: module Human does not support data configuration, ignoring
2026-04-16 22:44:57,890 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-04-16 22:44:57,906 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-04-16 22:44:57,906 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-04-16 22:44:57,906 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-04-16 22:44:57,906 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-04-16 22:44:57,906 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-04-16 22:44:58,250 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-04-16 22:44:58,250 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-04-16 22:44:58,469 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-04-16 22:44:58,484 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-04-16 22:44:58,484 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-04-16 22:44:58,500 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644
2026-04-16 22:45:00,218 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\ltb6yatm\dll\644.ini
2026-04-16 22:45:01,312 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-04-16 22:45:02,531 [lib.api.process] INFO: 64-bit DLL to inject is C:\ltb6yatm\dll\rXJCncX.dll, loader C:\ltb6yatm\bin\WBIUjUol.exe
2026-04-16 22:45:03,063 [root] DEBUG: Loader: Injecting process 644 with C:\ltb6yatm\dll\rXJCncX.dll.
2026-04-16 22:45:05,531 [root] DEBUG: 644: Python path set to 'C:\Python310'.
2026-04-16 22:45:05,547 [root] DEBUG: 644: Disabling sleep skipping.
2026-04-16 22:45:05,547 [root] DEBUG: 644: TLS secret dump mode enabled.
2026-04-16 22:45:06,766 [root] DEBUG: 644: Yara error: Scanning timed out
2026-04-16 22:45:06,766 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABC70000, thread 5740, image base 0x00007FF7C23E0000, stack from 0x0000008E4C471000-0x0000008E4C480000
2026-04-16 22:45:06,781 [root] DEBUG: 644: Commandline: C:\Windows\system32\lsass.exe
2026-04-16 22:45:06,812 [root] DEBUG: 644: Hooked 5 out of 5 functions
2026-04-16 22:45:06,828 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-16 22:45:06,828 [root] DEBUG: Successfully injected DLL C:\ltb6yatm\dll\rXJCncX.dll.
2026-04-16 22:45:06,844 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>
2026-04-16 22:45:06,844 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-04-16 22:45:08,547 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\OHjuCIJf\tlsdump\tlsdump.log
2026-04-16 22:46:01,875 [root] INFO: Restarting WMI Service
2026-04-16 22:46:04,000 [root] DEBUG: package modules.packages.dll does not support configure, ignoring
2026-04-16 22:46:04,000 [root] WARNING: configuration error for package modules.packages.dll: error importing data.packages.dll: No module named 'data.packages'
2026-04-16 22:46:04,125 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-16 22:46:04,641 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\System32\rundll32.exe" with arguments ""C:\Users\cape\AppData\Local\Temp\ClientPlugin.dll",#1" with pid 1568
2026-04-16 22:46:04,641 [lib.api.process] INFO: Monitor config for <Process 1568 rundll32.exe>: C:\ltb6yatm\dll\1568.ini
2026-04-16 22:46:04,656 [lib.api.process] INFO: 32-bit DLL to inject is C:\ltb6yatm\dll\iyMbcod.dll, loader C:\ltb6yatm\bin\QSOiFni.exe
2026-04-16 22:46:05,062 [root] DEBUG: Loader: Injecting process 1568 (thread 732) with C:\ltb6yatm\dll\iyMbcod.dll.
2026-04-16 22:46:05,167 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-16 22:46:05,167 [root] DEBUG: Successfully injected DLL C:\ltb6yatm\dll\iyMbcod.dll.
2026-04-16 22:46:05,177 [lib.api.process] INFO: Injected into 32-bit <Process 1568 rundll32.exe>
2026-04-16 22:46:07,253 [lib.api.process] INFO: Successfully resumed <Process 1568 rundll32.exe>
2026-04-16 22:46:09,567 [root] DEBUG: 1568: Python path set to 'C:\Python310'.
2026-04-16 22:46:09,722 [root] DEBUG: 1568: Disabling sleep skipping.
2026-04-16 22:46:09,722 [root] DEBUG: 1568: Dropped file limit defaulting to 100.
2026-04-16 22:46:09,769 [root] DEBUG: 1568: YaraInit: Compiled 44 rule files
2026-04-16 22:46:09,769 [root] DEBUG: 1568: YaraInit: Compiled rules saved to file C:\ltb6yatm\data\yara\capemon.yac
2026-04-16 22:46:09,769 [root] DEBUG: 1568: YaraScan: Scanning 0x00BC0000, size 0x136e8
2026-04-16 22:46:09,769 [root] DEBUG: 1568: Monitor initialised: 32-bit capemon loaded in process 1568 at 0x73ae0000, thread 732, image base 0xbc0000, stack from 0xa32000-0xa40000
2026-04-16 22:46:09,784 [root] DEBUG: 1568: Commandline: "C:\Windows\System32\rundll32.exe" "C:\Users\cape\AppData\Local\Temp\ClientPlugin.dll",#1
2026-04-16 22:46:10,945 [root] DEBUG: 1568: Yara error: Scanning timed out
2026-04-16 22:46:10,976 [root] DEBUG: 1568: hook_api: Warning - CreateProcessA export address 0x76AE2D90 differs from GetProcAddress -> 0x73E422A0 (AcLayers.DLL::0xfd3922a0)
2026-04-16 22:46:10,976 [root] DEBUG: 1568: hook_api: Warning - CreateProcessW export address 0x76AC88E0 differs from GetProcAddress -> 0x73E424E0 (AcLayers.DLL::0xfd3924e0)
2026-04-16 22:46:10,976 [root] DEBUG: 1568: hook_api: Warning - WinExec export address 0x76B0CF20 differs from GetProcAddress -> 0x73E427A0 (AcLayers.DLL::0xfd3927a0)
2026-04-16 22:46:11,536 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-16 22:46:11,536 [root] DEBUG: 1568: set_hooks: Unable to hook GetCommandLineA
2026-04-16 22:46:11,552 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-16 22:46:11,552 [root] DEBUG: 1568: set_hooks: Unable to hook GetCommandLineW
2026-04-16 22:46:12,305 [root] DEBUG: 1568: Hooked 630 out of 632 functions
2026-04-16 22:46:12,327 [root] DEBUG: 1568: Syscall hook installed, syscall logging level 1
2026-04-16 22:46:12,343 [root] DEBUG: 1568: RestoreHeaders: Restored original import table.
2026-04-16 22:46:12,343 [root] INFO: Loaded monitor into process with pid 1568
2026-04-16 22:46:12,343 [root] DEBUG: 1568: caller_dispatch: Added region at 0x00BC0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00BC5F1A, thread 732).
2026-04-16 22:46:12,343 [root] DEBUG: 1568: YaraScan: Scanning 0x00BC0000, size 0x136e8
2026-04-16 22:46:12,359 [root] DEBUG: 1568: ProcessImageBase: Main module image at 0x00BC0000 unmodified (entropy change 0.000000e+00)
2026-04-16 22:46:12,646 [root] DEBUG: 1568: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 732).
2026-04-16 22:46:12,662 [root] DEBUG: 1568: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-16 22:46:12,662 [root] DEBUG: 1568: Target DLL loaded at 0x05C10000: C:\Users\cape\AppData\Local\Temp\ClientPlugin (0xa000 bytes).
2026-04-16 22:46:12,678 [root] DEBUG: 1568: YaraScan: Scanning 0x05C10000, size 0x1f0
2026-04-16 22:46:14,946 [root] DEBUG: 1568: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 732).
2026-04-16 22:46:14,946 [root] DEBUG: 1568: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-16 22:46:15,349 [root] DEBUG: 1568: DLL loaded at 0x73A40000: C:\Windows\SYSTEM32\TextShaping (0x94000 bytes).
2026-04-16 22:46:15,948 [root] DEBUG: 1568: DLL loaded at 0x745D0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-16 22:46:16,026 [root] DEBUG: 1568: DLL loaded at 0x76BA0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-04-16 22:46:17,276 [root] DEBUG: 1568: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-16 22:46:17,308 [root] DEBUG: 1568: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-16 22:46:17,323 [root] DEBUG: 1568: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-16 22:46:21,761 [root] DEBUG: 1568: DLL loaded at 0x74190000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-16 22:46:21,776 [root] DEBUG: 1568: DLL loaded at 0x73660000: C:\Windows\System32\CoreMessaging (0x9b000 bytes).
2026-04-16 22:46:21,776 [root] DEBUG: 1568: DLL loaded at 0x73580000: C:\Windows\SYSTEM32\wintypes (0xdb000 bytes).
2026-04-16 22:46:21,776 [root] DEBUG: 1568: DLL loaded at 0x73700000: C:\Windows\System32\CoreUIComponents (0x27e000 bytes).
2026-04-16 22:46:21,776 [root] DEBUG: 1568: DLL loaded at 0x73980000: C:\Windows\SYSTEM32\textinputframework (0xb9000 bytes).
2026-04-16 22:49:27,557 [root] INFO: Analysis timeout hit, terminating analysis
2026-04-16 22:49:27,557 [lib.api.process] INFO: Terminate event set for <Process 1568 rundll32.exe>
2026-04-16 22:49:27,557 [root] DEBUG: 1568: Terminate Event: Attempting to dump process 1568
2026-04-16 22:49:27,557 [root] DEBUG: 1568: VerifyCodeSection: Executable code does not match, 0x18f2 of 0x18f3 matching
2026-04-16 22:49:27,573 [root] DEBUG: 1568: DoProcessDump: Code modification detected, dumping Imagebase at 0x05C10000.
2026-04-16 22:49:27,573 [root] DEBUG: 1568: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-16 22:49:27,573 [root] DEBUG: 1568: DumpProcess: Instantiating PeParser with address: 0x05C10000.
2026-04-16 22:49:27,573 [root] DEBUG: 1568: DumpProcess: Module entry point VA is 0x05C138EE.
2026-04-16 22:49:27,589 [root] DEBUG: 1568: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x05C14000, section 2
2026-04-16 22:49:27,589 [root] DEBUG: 1568: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x05C18000, section 3
2026-04-16 22:49:27,885 [lib.common.results] INFO: Uploading file C:\OHjuCIJf\CAPE\1568_3628527491916442026 to procdump\9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3; Size is 7680; Max size: 100000000
2026-04-16 22:49:27,979 [root] DEBUG: 1568: DumpProcess: Module image dump success - dump size 0x1e00.
2026-04-16 22:49:27,995 [lib.api.process] INFO: Termination confirmed for <Process 1568 rundll32.exe>
2026-04-16 22:49:27,995 [root] INFO: Terminate event set for process 1568
2026-04-16 22:49:27,995 [root] INFO: Created shutdown mutex
2026-04-16 22:49:28,010 [root] DEBUG: 1568: Terminate Event: monitor shutdown complete for process 1568
2026-04-16 22:49:29,042 [root] INFO: Shutting down package
2026-04-16 22:49:29,058 [root] INFO: Stopping auxiliary modules
2026-04-16 22:49:29,058 [root] INFO: Stopping auxiliary module: Browser
2026-04-16 22:49:29,073 [root] INFO: Stopping auxiliary module: Human
2026-04-16 22:49:29,495 [root] INFO: Stopping auxiliary module: Screenshots
2026-04-16 22:49:30,182 [root] INFO: Finishing auxiliary modules
2026-04-16 22:49:30,182 [root] INFO: Shutting down pipe server and dumping dropped files
2026-04-16 22:49:30,182 [root] WARNING: Folder at path "C:\OHjuCIJf\debugger" does not exist, skipping
2026-04-16 22:49:30,182 [root] INFO: Uploading files at path "C:\OHjuCIJf\tlsdump"
2026-04-16 22:49:30,182 [lib.common.results] INFO: Uploading file C:\OHjuCIJf\tlsdump\tlsdump.log to tlsdump\tlsdump.log; Size is 17536; Max size: 100000000
2026-04-16 22:49:30,213 [root] INFO: Analysis completed