Analysis Log
2026-03-05 20:34:43,241 [root] INFO: Date set to: 20260416T22:53:20, timeout set to: 200
2026-04-16 22:53:20,344 [root] DEBUG: Starting analyzer from: C:\ltb6yatm
2026-04-16 22:53:20,422 [root] DEBUG: Storing results at: C:\ErkGjXZSW
2026-04-16 22:53:20,453 [root] DEBUG: Pipe server name: \\.\PIPE\pyNDmeTCC
2026-04-16 22:53:20,469 [root] DEBUG: Python path: C:\Python310
2026-04-16 22:53:20,469 [root] INFO: analysis running as an admin
2026-04-16 22:53:20,484 [root] INFO: analysis package specified: "dll"
2026-04-16 22:53:20,484 [root] DEBUG: importing analysis package module: "modules.packages.dll"...
2026-04-16 22:53:20,500 [root] DEBUG: imported analysis package "dll"
2026-04-16 22:53:20,500 [root] DEBUG: initializing analysis package "dll"...
2026-04-16 22:53:20,500 [lib.common.common] INFO: wrapping
2026-04-16 22:53:20,718 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-16 22:53:20,734 [root] DEBUG: New location of moved file: C:\Users\cape\AppData\Local\Temp\ServerPlugin.dll
2026-04-16 22:53:20,734 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL option
2026-04-16 22:53:20,734 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL_64 option
2026-04-16 22:53:20,734 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader option
2026-04-16 22:53:20,734 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader_64 option
2026-04-16 22:53:20,906 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-04-16 22:53:21,562 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-04-16 22:53:21,625 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-04-16 22:53:21,640 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-04-16 22:53:21,703 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-04-16 22:53:21,718 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-04-16 22:53:21,922 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-04-16 22:53:23,453 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance
2026-04-16 22:53:23,453 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-04-16 22:53:23,469 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-04-16 22:53:23,469 [root] DEBUG: Initialized auxiliary module "Browser"
2026-04-16 22:53:23,469 [root] DEBUG: attempting to configure 'Browser' from data
2026-04-16 22:53:23,469 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-04-16 22:53:23,469 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-04-16 22:53:23,469 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-04-16 22:53:23,469 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-04-16 22:53:23,469 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-04-16 22:53:23,484 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-04-16 22:53:23,484 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-04-16 22:53:23,484 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-04-16 22:54:19,859 [modules.auxiliary.digisig] DEBUG: File is not signed
2026-04-16 22:54:19,875 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-04-16 22:54:19,875 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-04-16 22:54:19,875 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-04-16 22:54:19,875 [root] DEBUG: attempting to configure 'Disguise' from data
2026-04-16 22:54:19,890 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-04-16 22:54:19,890 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-04-16 22:54:19,953 [modules.auxiliary.disguise] INFO: Disguising GUID to 3edd1f36-5c52-4bb2-8439-a3ed6ce40e23
2026-04-16 22:54:19,953 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-04-16 22:54:19,969 [root] DEBUG: Initialized auxiliary module "Human"
2026-04-16 22:54:19,969 [root] DEBUG: attempting to configure 'Human' from data
2026-04-16 22:54:19,969 [root] DEBUG: module Human does not support data configuration, ignoring
2026-04-16 22:54:19,969 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-04-16 22:54:19,969 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-04-16 22:54:19,969 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-04-16 22:54:19,984 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-04-16 22:54:19,984 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-04-16 22:54:19,984 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-04-16 22:54:20,000 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-04-16 22:54:20,000 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-04-16 22:54:20,078 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-04-16 22:54:20,078 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-04-16 22:54:20,078 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-04-16 22:54:20,093 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644
2026-04-16 22:54:20,250 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\ltb6yatm\dll\644.ini
2026-04-16 22:54:20,250 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-04-16 22:54:20,281 [lib.api.process] INFO: 64-bit DLL to inject is C:\ltb6yatm\dll\vlsdJF.dll, loader C:\ltb6yatm\bin\xwjOEbSl.exe
2026-04-16 22:54:20,609 [root] DEBUG: Loader: Injecting process 644 with C:\ltb6yatm\dll\vlsdJF.dll.
2026-04-16 22:54:21,515 [root] DEBUG: 644: Python path set to 'C:\Python310'.
2026-04-16 22:54:21,593 [root] DEBUG: 644: Disabling sleep skipping.
2026-04-16 22:54:21,593 [root] DEBUG: 644: TLS secret dump mode enabled.
2026-04-16 22:54:22,344 [root] DEBUG: 644: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-16 22:54:22,359 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABB00000, thread 6084, image base 0x00007FF7C23E0000, stack from 0x0000008E4C9F2000-0x0000008E4CA00000
2026-04-16 22:54:22,359 [root] DEBUG: 644: Commandline: C:\Windows\system32\lsass.exe
2026-04-16 22:54:22,406 [root] DEBUG: 644: Hooked 5 out of 5 functions
2026-04-16 22:54:22,406 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-16 22:54:22,406 [root] DEBUG: Successfully injected DLL C:\ltb6yatm\dll\vlsdJF.dll.
2026-04-16 22:54:22,406 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>
2026-04-16 22:54:22,406 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-04-16 22:54:22,547 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\ErkGjXZSW\tlsdump\tlsdump.log
2026-04-16 22:54:31,172 [root] INFO: Restarting WMI Service
2026-04-16 22:54:31,281 [root] DEBUG: package modules.packages.dll does not support configure, ignoring
2026-04-16 22:54:31,281 [root] WARNING: configuration error for package modules.packages.dll: error importing data.packages.dll: No module named 'data.packages'
2026-04-16 22:54:31,281 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-16 22:54:31,297 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\System32\rundll32.exe" with arguments ""C:\Users\cape\AppData\Local\Temp\ServerPlugin.dll",#1" with pid 4344
2026-04-16 22:54:31,297 [lib.api.process] INFO: Monitor config for <Process 4344 rundll32.exe>: C:\ltb6yatm\dll\4344.ini
2026-04-16 22:54:31,312 [lib.api.process] INFO: 32-bit DLL to inject is C:\ltb6yatm\dll\bNmKpkjG.dll, loader C:\ltb6yatm\bin\NvwgoPM.exe
2026-04-16 22:54:31,687 [root] DEBUG: Loader: Injecting process 4344 (thread 6616) with C:\ltb6yatm\dll\bNmKpkjG.dll.
2026-04-16 22:54:31,828 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-16 22:54:31,843 [root] DEBUG: Successfully injected DLL C:\ltb6yatm\dll\bNmKpkjG.dll.
2026-04-16 22:54:31,843 [lib.api.process] INFO: Injected into 32-bit <Process 4344 rundll32.exe>
2026-04-16 22:54:33,875 [lib.api.process] INFO: Successfully resumed <Process 4344 rundll32.exe>
2026-04-16 22:54:36,203 [root] DEBUG: 4344: Python path set to 'C:\Python310'.
2026-04-16 22:54:36,203 [root] DEBUG: 4344: Disabling sleep skipping.
2026-04-16 22:54:36,218 [root] DEBUG: 4344: Dropped file limit defaulting to 100.
2026-04-16 22:54:36,484 [root] DEBUG: 4344: YaraInit: Compiled 44 rule files
2026-04-16 22:54:36,484 [root] DEBUG: 4344: YaraInit: Compiled rules saved to file C:\ltb6yatm\data\yara\capemon.yac
2026-04-16 22:54:36,484 [root] DEBUG: 4344: YaraScan: Scanning 0x001A0000, size 0x136e8
2026-04-16 22:54:36,500 [root] DEBUG: 4344: Monitor initialised: 32-bit capemon loaded in process 4344 at 0x73b90000, thread 6616, image base 0x1a0000, stack from 0x2762000-0x2770000
2026-04-16 22:54:36,500 [root] DEBUG: 4344: Commandline: "C:\Windows\System32\rundll32.exe" "C:\Users\cape\AppData\Local\Temp\ServerPlugin.dll",#1
2026-04-16 22:54:36,687 [root] DEBUG: 4344: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-04-16 22:54:36,687 [root] DEBUG: 4344: hook_api: Warning - CreateProcessA export address 0x76AE2D90 differs from GetProcAddress -> 0x73EF22A0 (AcLayers.DLL::0xfd4422a0)
2026-04-16 22:54:36,687 [root] DEBUG: 4344: hook_api: Warning - CreateProcessW export address 0x76AC88E0 differs from GetProcAddress -> 0x73EF24E0 (AcLayers.DLL::0xfd4424e0)
2026-04-16 22:54:36,703 [root] DEBUG: 4344: hook_api: Warning - WinExec export address 0x76B0CF20 differs from GetProcAddress -> 0x73EF27A0 (AcLayers.DLL::0xfd4427a0)
2026-04-16 22:54:36,828 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-16 22:54:36,828 [root] DEBUG: 4344: set_hooks: Unable to hook GetCommandLineA
2026-04-16 22:54:36,843 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-16 22:54:36,843 [root] DEBUG: 4344: set_hooks: Unable to hook GetCommandLineW
2026-04-16 22:54:36,906 [root] DEBUG: 4344: Hooked 630 out of 632 functions
2026-04-16 22:54:36,906 [root] DEBUG: 4344: Syscall hook installed, syscall logging level 1
2026-04-16 22:54:36,922 [root] DEBUG: 4344: RestoreHeaders: Restored original import table.
2026-04-16 22:54:36,922 [root] INFO: Loaded monitor into process with pid 4344
2026-04-16 22:54:36,937 [root] DEBUG: 4344: caller_dispatch: Added region at 0x001A0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x001A5F1A, thread 6616).
2026-04-16 22:54:36,937 [root] DEBUG: 4344: YaraScan: Scanning 0x001A0000, size 0x136e8
2026-04-16 22:54:36,937 [root] DEBUG: 4344: ProcessImageBase: Main module image at 0x001A0000 unmodified (entropy change 0.000000e+00)
2026-04-16 22:54:37,297 [root] DEBUG: 4344: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 6616).
2026-04-16 22:54:37,312 [root] DEBUG: 4344: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-16 22:54:37,312 [root] DEBUG: 4344: Target DLL loaded at 0x05B20000: C:\Users\cape\AppData\Local\Temp\ServerPlugin (0xc000 bytes).
2026-04-16 22:54:37,312 [root] DEBUG: 4344: YaraScan: Scanning 0x05B20000, size 0x1f0
2026-04-16 22:54:37,531 [root] DEBUG: 4344: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 6616).
2026-04-16 22:54:37,531 [root] DEBUG: 4344: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-16 22:54:38,610 [root] DEBUG: 4344: DLL loaded at 0x73AF0000: C:\Windows\SYSTEM32\TextShaping (0x94000 bytes).
2026-04-16 22:54:39,781 [root] DEBUG: 4344: DLL loaded at 0x745D0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-16 22:54:40,109 [root] DEBUG: 4344: DLL loaded at 0x76BA0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-04-16 22:54:41,453 [root] DEBUG: 4344: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-16 22:54:41,468 [root] DEBUG: 4344: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-16 22:54:41,468 [root] DEBUG: 4344: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-16 22:55:23,406 [root] DEBUG: 4344: DLL loaded at 0x74190000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-16 22:55:23,406 [root] DEBUG: 4344: DLL loaded at 0x73710000: C:\Windows\System32\CoreMessaging (0x9b000 bytes).
2026-04-16 22:55:23,422 [root] DEBUG: 4344: DLL loaded at 0x73630000: C:\Windows\SYSTEM32\wintypes (0xdb000 bytes).
2026-04-16 22:55:23,437 [root] DEBUG: 4344: DLL loaded at 0x737B0000: C:\Windows\System32\CoreUIComponents (0x27e000 bytes).
2026-04-16 22:55:23,437 [root] DEBUG: 4344: DLL loaded at 0x73A30000: C:\Windows\SYSTEM32\textinputframework (0xb9000 bytes).
2026-04-16 22:57:54,825 [root] INFO: Analysis timeout hit, terminating analysis
2026-04-16 22:57:54,825 [lib.api.process] INFO: Terminate event set for <Process 4344 rundll32.exe>
2026-04-16 22:57:54,825 [root] DEBUG: 4344: Terminate Event: Attempting to dump process 4344
2026-04-16 22:57:54,825 [root] DEBUG: 4344: VerifyCodeSection: Executable code does not match, 0x3d42 of 0x3d43 matching
2026-04-16 22:57:54,841 [root] DEBUG: 4344: DoProcessDump: Code modification detected, dumping Imagebase at 0x05B20000.
2026-04-16 22:57:54,841 [root] DEBUG: 4344: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-16 22:57:54,841 [root] DEBUG: 4344: DumpProcess: Instantiating PeParser with address: 0x05B20000.
2026-04-16 22:57:54,856 [root] DEBUG: 4344: DumpProcess: Module entry point VA is 0x05B25D3E.
2026-04-16 22:57:54,856 [root] DEBUG: 4344: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x05B26000, section 2
2026-04-16 22:57:54,872 [root] DEBUG: 4344: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x05B2A000, section 3
2026-04-16 22:57:55,200 [lib.common.results] INFO: Uploading file C:\ErkGjXZSW\CAPE\4344_820055571916442026 to procdump\c2800550f928a910a9337cd2013e97a03b2da584b8522843804197fc2aa23634; Size is 16896; Max size: 100000000
2026-04-16 22:57:55,200 [root] DEBUG: 4344: DumpProcess: Module image dump success - dump size 0x4200.
2026-04-16 22:57:55,215 [lib.api.process] INFO: Termination confirmed for <Process 4344 rundll32.exe>
2026-04-16 22:57:55,215 [root] INFO: Terminate event set for process 4344
2026-04-16 22:57:55,215 [root] INFO: Created shutdown mutex
2026-04-16 22:57:55,215 [root] DEBUG: 4344: Terminate Event: monitor shutdown complete for process 4344
2026-04-16 22:57:56,231 [root] INFO: Shutting down package
2026-04-16 22:57:56,231 [root] INFO: Stopping auxiliary modules
2026-04-16 22:57:56,231 [root] INFO: Stopping auxiliary module: Browser
2026-04-16 22:57:56,231 [root] INFO: Stopping auxiliary module: Human
2026-04-16 22:57:58,090 [root] INFO: Stopping auxiliary module: Screenshots
2026-04-16 22:57:58,872 [root] INFO: Finishing auxiliary modules
2026-04-16 22:57:58,872 [root] INFO: Shutting down pipe server and dumping dropped files
2026-04-16 22:57:58,872 [root] WARNING: Folder at path "C:\ErkGjXZSW\debugger" does not exist, skipping
2026-04-16 22:57:58,872 [root] INFO: Uploading files at path "C:\ErkGjXZSW\tlsdump"
2026-04-16 22:57:58,887 [lib.common.results] INFO: Uploading file C:\ErkGjXZSW\tlsdump\tlsdump.log to tlsdump\tlsdump.log; Size is 18358; Max size: 100000000
2026-04-16 22:57:58,903 [root] INFO: Analysis completed