Analysis Log
2026-03-05 20:34:39,444 [root] INFO: Date set to: 20260428T00:04:27, timeout set to: 120
2026-04-28 00:04:27,166 [root] DEBUG: Starting analyzer from: C:\_g_ewr1x
2026-04-28 00:04:27,244 [root] DEBUG: Storing results at: C:\coVEjD
2026-04-28 00:04:27,275 [root] DEBUG: Pipe server name: \\.\PIPE\bEKvYdteFZ
2026-04-28 00:04:27,322 [root] DEBUG: Python path: C:\Python310
2026-04-28 00:04:27,369 [root] INFO: analysis running as an admin
2026-04-28 00:04:27,385 [root] INFO: analysis package specified: "exe"
2026-04-28 00:04:27,385 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2026-04-28 00:04:27,416 [root] DEBUG: imported analysis package "exe"
2026-04-28 00:04:27,431 [root] DEBUG: initializing analysis package "exe"...
2026-04-28 00:04:27,447 [lib.common.common] INFO: wrapping
2026-04-28 00:04:27,588 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-28 00:04:27,603 [root] DEBUG: New location of moved file: C:\Users\cape\AppData\Local\Temp\sex1.exe
2026-04-28 00:04:27,619 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2026-04-28 00:04:27,619 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2026-04-28 00:04:27,619 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2026-04-28 00:04:27,619 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2026-04-28 00:04:27,760 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-04-28 00:04:28,244 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-04-28 00:04:28,322 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-04-28 00:04:28,432 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-04-28 00:04:28,510 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-04-28 00:04:28,760 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-04-28 00:04:28,885 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-04-28 00:04:29,760 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance
2026-04-28 00:04:29,775 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-04-28 00:04:29,775 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-04-28 00:04:29,775 [root] DEBUG: Initialized auxiliary module "Browser"
2026-04-28 00:04:29,775 [root] DEBUG: attempting to configure 'Browser' from data
2026-04-28 00:04:29,791 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-04-28 00:04:29,791 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-04-28 00:04:29,791 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-04-28 00:04:29,791 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-04-28 00:04:29,791 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-04-28 00:04:29,807 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-04-28 00:04:29,807 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-04-28 00:04:29,807 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-04-28 00:04:58,182 [modules.auxiliary.digisig] DEBUG: File is not signed
2026-04-28 00:04:58,182 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-04-28 00:04:58,197 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-04-28 00:04:58,197 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-04-28 00:04:58,197 [root] DEBUG: attempting to configure 'Disguise' from data
2026-04-28 00:04:58,197 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-04-28 00:04:58,197 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-04-28 00:04:58,244 [modules.auxiliary.disguise] INFO: Disguising GUID to f3037635-6191-4c44-bd96-905f1b4feafd
2026-04-28 00:04:58,260 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-04-28 00:04:58,260 [root] DEBUG: Initialized auxiliary module "Human"
2026-04-28 00:04:58,260 [root] DEBUG: attempting to configure 'Human' from data
2026-04-28 00:04:58,260 [root] DEBUG: module Human does not support data configuration, ignoring
2026-04-28 00:04:58,260 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-04-28 00:04:58,275 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-04-28 00:04:58,275 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-04-28 00:04:58,275 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-04-28 00:04:58,275 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-04-28 00:04:58,275 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-04-28 00:04:58,325 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-04-28 00:04:58,338 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-04-28 00:04:58,432 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-04-28 00:04:58,432 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-04-28 00:04:58,432 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-04-28 00:04:58,447 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644
2026-04-28 00:04:58,619 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\_g_ewr1x\dll\644.ini
2026-04-28 00:04:58,619 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-04-28 00:04:58,744 [lib.api.process] INFO: 64-bit DLL to inject is C:\_g_ewr1x\dll\wIazzoy.dll, loader C:\_g_ewr1x\bin\fSDEQCOs.exe
2026-04-28 00:04:58,838 [root] DEBUG: Loader: Injecting process 644 with C:\_g_ewr1x\dll\wIazzoy.dll.
2026-04-28 00:04:59,713 [root] DEBUG: 644: Python path set to 'C:\Python310'.
2026-04-28 00:04:59,995 [root] DEBUG: 644: Disabling sleep skipping.
2026-04-28 00:05:00,057 [root] DEBUG: 644: TLS secret dump mode enabled.
2026-04-28 00:05:00,385 [root] DEBUG: 644: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 00:05:00,416 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABBA0000, thread 4908, image base 0x00007FF7C23E0000, stack from 0x0000008E4CA72000-0x0000008E4CA80000
2026-04-28 00:05:00,432 [root] DEBUG: 644: Commandline: C:\Windows\system32\lsass.exe
2026-04-28 00:05:00,494 [root] DEBUG: 644: Hooked 5 out of 5 functions
2026-04-28 00:05:00,557 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-28 00:05:00,682 [root] DEBUG: Successfully injected DLL C:\_g_ewr1x\dll\wIazzoy.dll.
2026-04-28 00:05:00,698 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>
2026-04-28 00:05:00,698 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-04-28 00:05:00,807 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\coVEjD\tlsdump\tlsdump.log
2026-04-28 00:05:08,494 [root] INFO: Restarting WMI Service
2026-04-28 00:05:10,744 [root] DEBUG: package modules.packages.exe does not support configure, ignoring
2026-04-28 00:05:10,775 [root] WARNING: configuration error for package modules.packages.exe: error importing data.packages.exe: No module named 'data.packages'
2026-04-28 00:05:10,775 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-28 00:05:10,932 [lib.api.process] INFO: Successfully executed process from path "C:\Users\cape\AppData\Local\Temp\sex1.exe" with arguments "" with pid 6648
2026-04-28 00:05:10,932 [lib.api.process] INFO: Monitor config for <Process 6648 sex1.exe>: C:\_g_ewr1x\dll\6648.ini
2026-04-28 00:05:10,947 [lib.api.process] INFO: 32-bit DLL to inject is C:\_g_ewr1x\dll\zbBXAj.dll, loader C:\_g_ewr1x\bin\oNunBip.exe
2026-04-28 00:05:11,135 [root] DEBUG: Loader: Injecting process 6648 (thread 6700) with C:\_g_ewr1x\dll\zbBXAj.dll.
2026-04-28 00:05:11,135 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2026-04-28 00:05:11,135 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2026-04-28 00:05:11,135 [root] DEBUG: Successfully injected DLL C:\_g_ewr1x\dll\zbBXAj.dll.
2026-04-28 00:05:11,150 [lib.api.process] INFO: Injected into 32-bit <Process 6648 sex1.exe>
2026-04-28 00:05:13,182 [lib.api.process] INFO: Successfully resumed <Process 6648 sex1.exe>
2026-04-28 00:05:13,619 [root] DEBUG: 6648: Python path set to 'C:\Python310'.
2026-04-28 00:05:13,697 [root] DEBUG: 6648: Disabling sleep skipping.
2026-04-28 00:05:13,697 [root] DEBUG: 6648: Dropped file limit defaulting to 100.
2026-04-28 00:05:13,728 [root] DEBUG: 6648: YaraInit: Compiled 44 rule files
2026-04-28 00:05:13,744 [root] DEBUG: 6648: YaraInit: Compiled rules saved to file C:\_g_ewr1x\data\yara\capemon.yac
2026-04-28 00:05:13,744 [root] DEBUG: 6648: YaraScan: Scanning 0x00610000, size 0x1f0
2026-04-28 00:05:13,744 [root] DEBUG: 6648: Monitor initialised: 32-bit capemon loaded in process 6648 at 0x73ea0000, thread 6700, image base 0x610000, stack from 0x7d2000-0x7e0000
2026-04-28 00:05:13,761 [root] DEBUG: 6648: Commandline: "C:\Users\cape\AppData\Local\Temp\sex1.exe"
2026-04-28 00:05:13,900 [root] DEBUG: 6648: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-04-28 00:05:14,010 [root] DEBUG: 6648: hook_api: Warning - SetWindowLongW export address 0x75D45420 differs from GetProcAddress -> 0x750E59E0 (apphelp.dll::0xff3d59e0)
2026-04-28 00:05:14,025 [root] DEBUG: 6648: hook_api: Warning - EnumDisplayDevicesA export address 0x75D395A0 differs from GetProcAddress -> 0x750E6780 (apphelp.dll::0xff3d6780)
2026-04-28 00:05:14,057 [root] DEBUG: 6648: hook_api: Warning - EnumDisplayDevicesW export address 0x75D4FB70 differs from GetProcAddress -> 0x7510E4D0 (apphelp.dll::0xff3fe4d0)
2026-04-28 00:05:14,072 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-28 00:05:14,072 [root] DEBUG: 6648: set_hooks: Unable to hook GetCommandLineA
2026-04-28 00:05:14,072 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-28 00:05:14,089 [root] DEBUG: 6648: set_hooks: Unable to hook GetCommandLineW
2026-04-28 00:05:14,166 [root] DEBUG: 6648: Hooked 630 out of 632 functions
2026-04-28 00:05:14,182 [root] DEBUG: 6648: Syscall hook installed, syscall logging level 1
2026-04-28 00:05:14,197 [root] INFO: Loaded monitor into process with pid 6648
2026-04-28 00:05:14,307 [root] DEBUG: 6648: DLL loaded at 0x73E10000: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei (0x8d000 bytes).
2026-04-28 00:05:14,447 [root] DEBUG: 6648: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-28 00:05:14,463 [root] DEBUG: 6648: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-28 00:05:14,463 [root] DEBUG: 6648: DLL loaded at 0x75460000: C:\Windows\SYSTEM32\VERSION (0x8000 bytes).
2026-04-28 00:05:16,010 [root] DEBUG: 6648: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 6700).
2026-04-28 00:05:16,010 [root] DEBUG: 6648: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-28 00:05:16,385 [root] DEBUG: 6648: DLL loaded at 0x73740000: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80 (0x9b000 bytes).
2026-04-28 00:05:16,400 [root] DEBUG: 6648: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-28 00:05:16,400 [root] DEBUG: 6648: DLL loaded at 0x737E0000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks (0x621000 bytes).
2026-04-28 00:05:17,698 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x0290A000, size: 0x1000.
2026-04-28 00:05:17,698 [root] DEBUG: 6648: GetEntropy: Error - Supplied address inaccessible: 0x02900000
2026-04-28 00:05:17,698 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:17,698 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02900000.
2026-04-28 00:05:17,744 [root] DEBUG: 6648: DLL loaded at 0x77590000: C:\Windows\System32\shell32 (0x5b5000 bytes).
2026-04-28 00:05:17,760 [root] DEBUG: 6648: DLL loaded at 0x756D0000: C:\Windows\SYSTEM32\Wldp (0x27000 bytes).
2026-04-28 00:05:17,775 [root] DEBUG: 6648: DLL loaded at 0x75700000: C:\Windows\SYSTEM32\windows.storage (0x60d000 bytes).
2026-04-28 00:05:17,775 [root] DEBUG: 6648: DLL loaded at 0x76F70000: C:\Windows\System32\SHCORE (0x87000 bytes).
2026-04-28 00:05:18,447 [root] DEBUG: 6648: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 6700).
2026-04-28 00:05:18,463 [root] DEBUG: 6648: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 00:05:18,494 [root] DEBUG: 6648: DLL loaded at 0x75260000: C:\Windows\SYSTEM32\profapi (0x18000 bytes).
2026-04-28 00:05:19,150 [root] DEBUG: 6648: DLL loaded at 0x72C40000: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\07fedecf3b964c4d26a6ec994226efe4\mscorlib.ni (0xb00000 bytes).
2026-04-28 00:05:19,385 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x02922000, size: 0x1000.
2026-04-28 00:05:19,385 [root] DEBUG: 6648: GetEntropy: Error - Supplied address inaccessible: 0x02920000
2026-04-28 00:05:19,400 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:19,807 [root] DEBUG: 6648: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-28 00:05:19,807 [root] DEBUG: 6648: DLL loaded at 0x745D0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-28 00:05:20,119 [root] DEBUG: 6648: caller_dispatch: Added region at 0x02910000 to tracked regions list (kernel32::SetErrorMode returns to 0x02910626, thread 6700).
2026-04-28 00:05:20,119 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x02910000 - 0x02910FFE.
2026-04-28 00:05:20,119 [root] DEBUG: 6648: ScanForDisguisedPE: No PE image located in range 0x02910000-0x02910FFE.
2026-04-28 00:05:20,183 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_12552922052127142026 to CAPE\67a4e4961f92079cfb03d908719e99c6c09b74279b0e37b9d7eea541659f3957; Size is 4094; Max size: 100000000
2026-04-28 00:05:20,183 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_12552922052127142026 (size 4094 bytes)
2026-04-28 00:05:20,199 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x02910000, size 4096 bytes.
2026-04-28 00:05:20,199 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x02910000.
2026-04-28 00:05:20,213 [root] DEBUG: 6648: YaraScan: Scanning 0x02910000, size 0xffe
2026-04-28 00:05:20,213 [root] DEBUG: 6648: ReverseScanForNonZero: Error - Supplied size zero.
2026-04-28 00:05:20,263 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_16854692052127142026 to CAPE\157b063a2a5ecda11353d506c46d65fac9350decc6f97df21fb48dc66a8a4c99; Size is 354; Max size: 100000000
2026-04-28 00:05:20,291 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_16854692052127142026 (size 354 bytes)
2026-04-28 00:05:20,291 [root] DEBUG: 6648: DumpRegion: Dumped region at 0x0290A000, size 4096 bytes.
2026-04-28 00:05:20,308 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x0290A000.
2026-04-28 00:05:20,308 [root] DEBUG: 6648: ReverseScanForNonZero: Error - Supplied address inaccessible: 0x02900FFF
2026-04-28 00:05:20,324 [root] DEBUG: 6648: YaraScan: Nothing to scan at 0x0290A000!
2026-04-28 00:05:20,588 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:20,713 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x0408B000, size: 0x1000.
2026-04-28 00:05:20,730 [root] DEBUG: 6648: GetEntropy: Error - Supplied address inaccessible: 0x04080000
2026-04-28 00:05:20,744 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:20,744 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x04080000.
2026-04-28 00:05:21,541 [root] DEBUG: 6648: DLL loaded at 0x72490000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c60dd1ee843ba8ff9ee7edcd6302393b\System.ni (0x7a8000 bytes).
2026-04-28 00:05:22,073 [root] DEBUG: 6648: DLL loaded at 0x72300000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\a03dd8871929955c680232682c9464a0\System.Drawing.ni (0x189000 bytes).
2026-04-28 00:05:22,338 [root] DEBUG: 6648: DLL loaded at 0x71720000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\194e1e92bfae5396086518c2ec0a0f74\System.Windows.Forms.ni (0xbe0000 bytes).
2026-04-28 00:05:22,557 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:22,666 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:22,697 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:22,697 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:22,807 [root] DEBUG: 6648: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-28 00:05:22,900 [root] DEBUG: 6648: DLL loaded at 0x716C0000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit (0x5b000 bytes).
2026-04-28 00:05:23,729 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:24,057 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x051E0000, size: 0x1000.
2026-04-28 00:05:24,072 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:24,916 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:25,510 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x051E0000 - 0x051E0564.
2026-04-28 00:05:25,541 [root] DEBUG: 6648: ScanForDisguisedPE: Size too small: 0x564 bytes
2026-04-28 00:05:25,588 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_83059732552127142026 to CAPE\7902243f3a376bfaa57345f4323c5ae18f5f180ad0fd75395f6a3344bab889d5; Size is 1380; Max size: 100000000
2026-04-28 00:05:25,619 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_83059732552127142026 (size 1380 bytes)
2026-04-28 00:05:25,650 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x051E0000, size 4096 bytes.
2026-04-28 00:05:25,713 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x051E0000.
2026-04-28 00:05:25,728 [root] DEBUG: 6648: YaraScan: Scanning 0x051E0000, size 0x564
2026-04-28 00:05:25,760 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x7F6C0000, size: 0x50000.
2026-04-28 00:05:25,760 [root] DEBUG: 6648: GetEntropy: Error - Supplied address inaccessible: 0x7F6C0000
2026-04-28 00:05:25,775 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:25,791 [root] DEBUG: 6648: AllocationHandler: Processing previous tracked region at: 0x051E0000.
2026-04-28 00:05:25,807 [root] DEBUG: 6648: ProcessTrackedRegion: Updated entropy for tracked region at 0x051E0000: 2.795399e+00 (from 0.000000e+00)
2026-04-28 00:05:25,838 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x051E0000 - 0x051E0564.
2026-04-28 00:05:25,854 [root] DEBUG: 6648: ScanForDisguisedPE: Size too small: 0x564 bytes
2026-04-28 00:05:25,869 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_253945442552127142026 to CAPE\7902243f3a376bfaa57345f4323c5ae18f5f180ad0fd75395f6a3344bab889d5; Size is 1380; Max size: 100000000
2026-04-28 00:05:25,916 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_253945442552127142026 (size 1380 bytes)
2026-04-28 00:05:26,119 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x051E0000, size 4096 bytes.
2026-04-28 00:05:26,135 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x051E0000.
2026-04-28 00:05:26,150 [root] DEBUG: 6648: YaraScan: Scanning 0x051E0000, size 0x564
2026-04-28 00:05:26,150 [root] DEBUG: 6648: AllocationHandler: Memory region (size 0x50000) reserved but not committed at 0x7F6C0000.
2026-04-28 00:05:26,166 [root] DEBUG: 6648: AllocationHandler: Previously reserved region at 0x7F6C0000, committing at: 0x7F6C0000.
2026-04-28 00:05:26,166 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x7F6C0000.
2026-04-28 00:05:26,182 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x7F6B0000, size: 0x10000.
2026-04-28 00:05:26,182 [root] DEBUG: 6648: GetEntropy: Error - Supplied address inaccessible: 0x7F6B0000
2026-04-28 00:05:26,260 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:26,322 [root] DEBUG: 6648: AllocationHandler: Processing previous tracked region at: 0x7F6C0000.
2026-04-28 00:05:26,338 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x7F6C0000 - 0x7F6C002C.
2026-04-28 00:05:26,369 [root] DEBUG: 6648: ScanForDisguisedPE: Size too small: 0x2c bytes
2026-04-28 00:05:26,525 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_36200322652127142026 to CAPE\6a4a38c4482e414c906feff2bcb47d46b8ed525c6b88eff38080f494a7163a1b; Size is 44; Max size: 100000000
2026-04-28 00:05:26,557 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_36200322652127142026 (size 44 bytes)
2026-04-28 00:05:26,557 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x7F6C0000, size 4096 bytes.
2026-04-28 00:05:26,572 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x7F6C0000.
2026-04-28 00:05:26,588 [root] DEBUG: 6648: YaraScan: Scanning 0x7F6C0000, size 0x2c
2026-04-28 00:05:26,603 [root] DEBUG: 6648: AllocationHandler: Memory region (size 0x10000) reserved but not committed at 0x7F6B0000.
2026-04-28 00:05:26,619 [root] DEBUG: 6648: AllocationHandler: Previously reserved region at 0x7F6B0000, committing at: 0x7F6B0000.
2026-04-28 00:05:28,182 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x0407A000, size: 0x1000.
2026-04-28 00:05:30,947 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x0293A000, size: 0x1000.
2026-04-28 00:05:30,963 [root] DEBUG: 6648: GetEntropy: Error - Supplied address inaccessible: 0x02930000
2026-04-28 00:05:30,994 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:31,010 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02930000.
2026-04-28 00:05:32,510 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02900000.
2026-04-28 00:05:33,369 [root] DEBUG: 6648: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-28 00:05:34,322 [root] DEBUG: 6648: DLL loaded at 0x76BA0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-04-28 00:05:35,229 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02930000.
2026-04-28 00:05:36,791 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:39,025 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:39,886 [root] DEBUG: 6648: DLL loaded at 0x75280000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-04-28 00:05:39,900 [root] DEBUG: 6648: DLL loaded at 0x74C10000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2026-04-28 00:05:39,900 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x077F0000, size: 0x1000.
2026-04-28 00:05:39,900 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:40,510 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:05:40,807 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x04080000.
2026-04-28 00:05:42,900 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:05:43,557 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x07800000, size: 0x1000.
2026-04-28 00:05:43,572 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:44,057 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x079B1000, size: 0x1000.
2026-04-28 00:05:45,057 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x079B0000.
2026-04-28 00:05:45,776 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x079B0000.
2026-04-28 00:05:45,791 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x079B0000.
2026-04-28 00:05:45,791 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x079B0000.
2026-04-28 00:05:45,807 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x07810000, size: 0x8000.
2026-04-28 00:05:45,807 [root] DEBUG: 6648: GetEntropy: Error - Supplied address inaccessible: 0x07810000
2026-04-28 00:05:45,807 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:45,822 [root] DEBUG: 6648: AllocationHandler: Processing previous tracked region at: 0x079B0000.
2026-04-28 00:05:45,822 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x079B0000 - 0x079B7FFE.
2026-04-28 00:05:45,822 [root] DEBUG: 6648: ScanForDisguisedPE: No PE image located in range 0x079B0000-0x079B7FFE.
2026-04-28 00:05:45,838 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_219745264552127142026 to CAPE\c53c9857218e56767da2dc2ef8fb81c512704e4023339b58d91ba52cdf903dca; Size is 32766; Max size: 100000000
2026-04-28 00:05:45,838 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_219745264552127142026 (size 32766 bytes)
2026-04-28 00:05:45,838 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x079B0000, size 32768 bytes.
2026-04-28 00:05:45,853 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x079B0000.
2026-04-28 00:05:45,853 [root] DEBUG: 6648: YaraScan: Scanning 0x079B0000, size 0x7ffe
2026-04-28 00:05:45,853 [root] DEBUG: 6648: AllocationHandler: Memory region (size 0x8000) reserved but not committed at 0x07810000.
2026-04-28 00:05:45,853 [root] DEBUG: 6648: AllocationHandler: Previously reserved region at 0x07810000, committing at: 0x07810000.
2026-04-28 00:05:46,166 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x079B0000.
2026-04-28 00:05:46,166 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x079B0000.
2026-04-28 00:05:47,338 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:05:48,525 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:05:48,853 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x077F0000 - 0x077F020C.
2026-04-28 00:05:48,853 [root] DEBUG: 6648: ScanForDisguisedPE: Size too small: 0x20c bytes
2026-04-28 00:05:48,869 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_187460684852127142026 to CAPE\5131cc93670f51e88960065f7bb8df32f8381db790c5a1ab3de61f19dec14c5f; Size is 524; Max size: 100000000
2026-04-28 00:05:48,885 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_187460684852127142026 (size 524 bytes)
2026-04-28 00:05:48,995 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x077F0000, size 4096 bytes.
2026-04-28 00:05:48,995 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x077F0000.
2026-04-28 00:05:48,995 [root] DEBUG: 6648: YaraScan: Scanning 0x077F0000, size 0x20c
2026-04-28 00:05:49,744 [root] DEBUG: 6648: DLL loaded at 0x71650000: C:\Windows\SYSTEM32\shfolder (0x6000 bytes).
2026-04-28 00:05:50,088 [root] INFO: Added new file to list with pid 6648 and path C:\Users\cape\AppData\Roaming\F3037635-6191-4C44-BD96-905F1B4FEAFD\run.dat
2026-04-28 00:05:50,104 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:05:50,104 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:05:50,510 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x04070000.
2026-04-28 00:05:50,525 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x04070000.
2026-04-28 00:05:50,572 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:05:50,838 [root] DEBUG: 6648: DLL loaded at 0x71620000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-28 00:05:50,838 [root] INFO: Added new file to list with pid 6648 and path C:\Program Files (x86)\WAN Manager\wanmgr.exe
2026-04-28 00:05:51,463 [root] DEBUG: 6648: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-28 00:05:51,463 [root] DEBUG: 6648: DLL loaded at 0x71610000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\culture (0x8000 bytes).
2026-04-28 00:05:52,244 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:05:52,276 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x07B00000, size: 0x100000.
2026-04-28 00:05:52,291 [root] DEBUG: 6648: GetEntropy: Error - Supplied address inaccessible: 0x07B00000
2026-04-28 00:05:52,307 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:05:52,307 [root] DEBUG: 6648: AllocationHandler: Processing previous tracked region at: 0x07810000.
2026-04-28 00:05:52,326 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x07810000 - 0x078108C9.
2026-04-28 00:05:52,326 [root] DEBUG: 6648: ScanForDisguisedPE: No PE image located in range 0x07810000-0x078108C9.
2026-04-28 00:05:52,340 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_77216365252127142026 to CAPE\93da0626e38b0f52be088e4e0960b629ba52a39a2ca07e32b131a24d489d513d; Size is 2249; Max size: 100000000
2026-04-28 00:05:52,340 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_77216365252127142026 (size 2249 bytes)
2026-04-28 00:05:52,340 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x07810000, size 4096 bytes.
2026-04-28 00:05:52,354 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x07810000.
2026-04-28 00:05:52,354 [root] DEBUG: 6648: YaraScan: Scanning 0x07810000, size 0x8c9
2026-04-28 00:05:52,354 [root] DEBUG: 6648: AllocationHandler: Memory region (size 0x100000) reserved but not committed at 0x07B00000.
2026-04-28 00:05:52,372 [root] DEBUG: 6648: AllocationHandler: Previously reserved region at 0x07B00000, committing at: 0x07B00000.
2026-04-28 00:05:52,994 [root] DEBUG: 6648: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-28 00:05:53,041 [root] DEBUG: 6648: DLL loaded at 0x71590000: C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader (0x8d000 bytes).
2026-04-28 00:05:54,510 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02900000.
2026-04-28 00:05:54,541 [root] INFO: Added new file to list with pid 6648 and path C:\Users\cape\AppData\Local\Temp\tmp16B1.tmp
2026-04-28 00:05:55,635 [root] DEBUG: 6648: CreateProcessHandler: Injection info set for new process 3884: C:\Windows\SYSTEM32\schtasks.exe, ImageBase: 0x009E0000
2026-04-28 00:05:55,635 [root] INFO: Announced 32-bit process name: schtasks.exe pid: 3884
2026-04-28 00:05:55,635 [lib.api.process] INFO: Monitor config for <Process 3884 schtasks.exe>: C:\_g_ewr1x\dll\3884.ini
2026-04-28 00:05:55,650 [lib.api.process] INFO: 32-bit DLL to inject is C:\_g_ewr1x\dll\zbBXAj.dll, loader C:\_g_ewr1x\bin\oNunBip.exe
2026-04-28 00:05:55,682 [root] DEBUG: Loader: Injecting process 3884 (thread 1828) with C:\_g_ewr1x\dll\zbBXAj.dll.
2026-04-28 00:05:55,760 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 00:05:55,775 [root] DEBUG: Successfully injected DLL C:\_g_ewr1x\dll\zbBXAj.dll.
2026-04-28 00:05:55,775 [lib.api.process] INFO: Injected into 32-bit <Process 3884 schtasks.exe>
2026-04-28 00:05:55,807 [root] DEBUG: 6648: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 00:05:56,197 [root] DEBUG: 3884: Python path set to 'C:\Python310'.
2026-04-28 00:05:56,197 [root] DEBUG: 3884: Disabling sleep skipping.
2026-04-28 00:05:56,197 [root] DEBUG: 3884: Dropped file limit defaulting to 100.
2026-04-28 00:05:56,244 [root] DEBUG: 3884: YaraInit: Compiled rules loaded from existing file C:\_g_ewr1x\data\yara\capemon.yac
2026-04-28 00:05:56,260 [root] DEBUG: 3884: YaraScan: Scanning 0x009E0000, size 0x3198c
2026-04-28 00:05:56,260 [root] DEBUG: 3884: Monitor initialised: 32-bit capemon loaded in process 3884 at 0x73ea0000, thread 1828, image base 0x9e0000, stack from 0x2ae4000-0x2af0000
2026-04-28 00:05:56,260 [root] DEBUG: 3884: Commandline: "schtasks.exe" /create /f /tn "WAN Manager" /xml "C:\Users\cape\AppData\Local\Temp\tmp16B1.tmp"
2026-04-28 00:05:56,369 [root] DEBUG: 3884: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-04-28 00:05:56,447 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-28 00:05:56,463 [root] DEBUG: 3884: set_hooks: Unable to hook GetCommandLineA
2026-04-28 00:05:56,482 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-28 00:05:56,482 [root] DEBUG: 3884: set_hooks: Unable to hook GetCommandLineW
2026-04-28 00:05:56,510 [root] DEBUG: 3884: Hooked 630 out of 632 functions
2026-04-28 00:05:56,510 [root] DEBUG: 3884: Syscall hook installed, syscall logging level 1
2026-04-28 00:05:56,526 [root] DEBUG: 3884: RestoreHeaders: Restored original import table.
2026-04-28 00:05:56,526 [root] INFO: Loaded monitor into process with pid 3884
2026-04-28 00:05:56,541 [root] DEBUG: 3884: caller_dispatch: Added region at 0x009E0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00A0022A, thread 1828).
2026-04-28 00:05:56,541 [root] DEBUG: 3884: YaraScan: Scanning 0x009E0000, size 0x3198c
2026-04-28 00:05:56,558 [root] DEBUG: 3884: ProcessImageBase: Main module image at 0x009E0000 unmodified (entropy change 0.000000e+00)
2026-04-28 00:05:56,650 [root] DEBUG: 3884: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 1828).
2026-04-28 00:05:56,666 [root] DEBUG: 3884: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 00:05:56,697 [root] DEBUG: 3884: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-28 00:05:56,713 [root] DEBUG: 3884: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-28 00:05:56,713 [root] DEBUG: 3884: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-28 00:05:56,730 [root] INFO: Stopping Task Scheduler Service
2026-04-28 00:05:56,808 [root] INFO: Stopped Task Scheduler Service
2026-04-28 00:05:56,838 [root] INFO: Starting Task Scheduler Service
2026-04-28 00:05:56,947 [root] INFO: Started Task Scheduler Service
2026-04-28 00:05:56,947 [lib.api.process] INFO: Monitor config for <Process 1052 svchost.exe>: C:\_g_ewr1x\dll\1052.ini
2026-04-28 00:05:57,010 [lib.api.process] INFO: 64-bit DLL to inject is C:\_g_ewr1x\dll\wIazzoy.dll, loader C:\_g_ewr1x\bin\fSDEQCOs.exe
2026-04-28 00:05:57,041 [root] DEBUG: Loader: Injecting process 1052 with C:\_g_ewr1x\dll\wIazzoy.dll.
2026-04-28 00:05:57,041 [root] DEBUG: 1052: Python path set to 'C:\Python310'.
2026-04-28 00:05:57,041 [root] DEBUG: 1052: Disabling sleep skipping.
2026-04-28 00:05:57,057 [root] DEBUG: 1052: Dropped file limit defaulting to 100.
2026-04-28 00:05:57,057 [root] DEBUG: 1052: Services hook set enabled
2026-04-28 00:05:57,057 [root] DEBUG: 1052: YaraInit: Compiled rules loaded from existing file C:\_g_ewr1x\data\yara\capemon.yac
2026-04-28 00:05:57,104 [root] DEBUG: 1052: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 00:05:57,104 [root] DEBUG: 1052: Monitor initialised: 64-bit capemon loaded in process 1052 at 0x00007FFEABBA0000, thread 852, image base 0x00007FF7AB6E0000, stack from 0x0000005367074000-0x0000005367080000
2026-04-28 00:05:57,104 [root] DEBUG: 1052: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
2026-04-28 00:05:57,182 [root] DEBUG: 1052: Hooked 69 out of 69 functions
2026-04-28 00:05:57,228 [root] INFO: Loaded monitor into process with pid 1052
2026-04-28 00:05:57,228 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-28 00:05:57,228 [root] DEBUG: Successfully injected DLL C:\_g_ewr1x\dll\wIazzoy.dll.
2026-04-28 00:05:57,244 [lib.api.process] INFO: Injected into 64-bit <Process 1052 svchost.exe>
2026-04-28 00:05:59,260 [root] DEBUG: 3884: DLL loaded at 0x77400000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-04-28 00:05:59,275 [root] DEBUG: 3884: DLL loaded at 0x75180000: C:\Windows\System32\taskschd (0x7d000 bytes).
2026-04-28 00:05:59,291 [root] DEBUG: 3884: DEBUG:Initialized 9 com hooks
2026-04-28 00:05:59,603 [root] DEBUG: 3884: NtTerminateProcess hook: Attempting to dump process 3884
2026-04-28 00:05:59,635 [root] DEBUG: 3884: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-28 00:05:59,697 [root] INFO: Process with pid 3884 has terminated
2026-04-28 00:05:59,791 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x077F0000.
2026-04-28 00:05:59,822 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\tmp16B1.tmp to files\4931757751d7c9d49e74bf11f86be68591998ab3608b8a0d8cca6b531f1451a6; Size is 1304; Max size: 100000000
2026-04-28 00:06:00,088 [root] INFO: Added new file to list with pid 6648 and path C:\Users\cape\AppData\Roaming\F3037635-6191-4C44-BD96-905F1B4FEAFD\task.dat
2026-04-28 00:06:00,385 [root] INFO: Added new file to list with pid 6648 and path C:\Users\cape\AppData\Local\Temp\tmp2CBA.tmp
2026-04-28 00:06:00,400 [root] DEBUG: 6648: CreateProcessHandler: Injection info set for new process 3200: C:\Windows\SYSTEM32\schtasks.exe, ImageBase: 0x009E0000
2026-04-28 00:06:00,432 [root] INFO: Announced 32-bit process name: schtasks.exe pid: 3200
2026-04-28 00:06:00,486 [lib.api.process] INFO: Monitor config for <Process 3200 schtasks.exe>: C:\_g_ewr1x\dll\3200.ini
2026-04-28 00:06:00,574 [lib.api.process] INFO: 32-bit DLL to inject is C:\_g_ewr1x\dll\zbBXAj.dll, loader C:\_g_ewr1x\bin\oNunBip.exe
2026-04-28 00:06:00,667 [root] DEBUG: Loader: Injecting process 3200 (thread 7412) with C:\_g_ewr1x\dll\zbBXAj.dll.
2026-04-28 00:06:00,701 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 00:06:00,802 [root] DEBUG: Successfully injected DLL C:\_g_ewr1x\dll\zbBXAj.dll.
2026-04-28 00:06:00,870 [lib.api.process] INFO: Injected into 32-bit <Process 3200 schtasks.exe>
2026-04-28 00:06:00,952 [root] DEBUG: 6648: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 00:06:01,101 [root] DEBUG: 3200: Python path set to 'C:\Python310'.
2026-04-28 00:06:01,121 [root] DEBUG: 3200: Dropped file limit defaulting to 100.
2026-04-28 00:06:01,155 [root] DEBUG: 3200: Disabling sleep skipping.
2026-04-28 00:06:01,180 [root] DEBUG: 3200: YaraInit: Compiled rules loaded from existing file C:\_g_ewr1x\data\yara\capemon.yac
2026-04-28 00:06:01,264 [root] DEBUG: 3200: YaraScan: Scanning 0x009E0000, size 0x3198c
2026-04-28 00:06:01,299 [root] DEBUG: 3200: Monitor initialised: 32-bit capemon loaded in process 3200 at 0x73ea0000, thread 7412, image base 0x9e0000, stack from 0x2f35000-0x2f40000
2026-04-28 00:06:01,320 [root] DEBUG: 3200: Commandline: "schtasks.exe" /create /f /tn "WAN Manager Task" /xml "C:\Users\cape\AppData\Local\Temp\tmp2CBA.tmp"
2026-04-28 00:06:01,550 [root] DEBUG: 3200: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-04-28 00:06:01,649 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-28 00:06:01,669 [root] DEBUG: 3200: set_hooks: Unable to hook GetCommandLineA
2026-04-28 00:06:01,683 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-28 00:06:01,694 [root] DEBUG: 3200: set_hooks: Unable to hook GetCommandLineW
2026-04-28 00:06:01,728 [root] DEBUG: 3200: Hooked 630 out of 632 functions
2026-04-28 00:06:01,751 [root] DEBUG: 3200: Syscall hook installed, syscall logging level 1
2026-04-28 00:06:01,772 [root] DEBUG: 3200: RestoreHeaders: Restored original import table.
2026-04-28 00:06:01,775 [root] INFO: Loaded monitor into process with pid 3200
2026-04-28 00:06:01,796 [root] DEBUG: 3200: caller_dispatch: Added region at 0x009E0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00A0022A, thread 7412).
2026-04-28 00:06:01,843 [root] DEBUG: 3200: YaraScan: Scanning 0x009E0000, size 0x3198c
2026-04-28 00:06:01,855 [root] DEBUG: 3200: ProcessImageBase: Main module image at 0x009E0000 unmodified (entropy change 0.000000e+00)
2026-04-28 00:06:01,936 [root] DEBUG: 3200: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 7412).
2026-04-28 00:06:01,938 [root] DEBUG: 3200: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 00:06:01,961 [root] DEBUG: 3200: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-28 00:06:01,970 [root] DEBUG: 3200: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-28 00:06:01,996 [root] DEBUG: 3200: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-28 00:06:02,042 [root] DEBUG: 3200: DLL loaded at 0x77400000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-04-28 00:06:02,062 [root] DEBUG: 3200: DLL loaded at 0x75180000: C:\Windows\System32\taskschd (0x7d000 bytes).
2026-04-28 00:06:02,065 [root] DEBUG: 3200: DEBUG:Initialized 9 com hooks
2026-04-28 00:06:02,192 [root] DEBUG: 3200: NtTerminateProcess hook: Attempting to dump process 3200
2026-04-28 00:06:02,206 [root] DEBUG: 3200: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-28 00:06:02,262 [root] INFO: Process with pid 3200 has terminated
2026-04-28 00:06:02,311 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\tmp2CBA.tmp to files\067d3f5167cab2ea4e76f59386df4eaf49c6008f6451e1971274a938ad7bcf44; Size is 1308; Max size: 100000000
2026-04-28 00:06:02,468 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:02,562 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:02,699 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:02,744 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:03,146 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:03,250 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:03,283 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:03,319 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:03,341 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:03,368 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:06:03,463 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07B00000.
2026-04-28 00:06:03,474 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07B00000.
2026-04-28 00:06:03,526 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07B00000.
2026-04-28 00:06:03,581 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:03,744 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:03,984 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:04,147 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:04,182 [root] DEBUG: 6648: DLL loaded at 0x76A70000: C:\Windows\System32\psapi (0x6000 bytes).
2026-04-28 00:06:04,211 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:04,414 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:04,640 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:04,780 [root] DEBUG: 6648: DLL loaded at 0x747C0000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-04-28 00:06:04,952 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:05,169 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:05,191 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:05,206 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:05,229 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02920000.
2026-04-28 00:06:05,323 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:05,351 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07800000.
2026-04-28 00:06:05,424 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x051E0000.
2026-04-28 00:06:05,460 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x08640000, size: 0x1000.
2026-04-28 00:06:05,484 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:06:05,530 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:05,876 [root] DEBUG: 6648: DLL loaded at 0x70900000: C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\bae24e9bcbc01bb2a0ed4fa751347041\System.Xml.ni (0x53c000 bytes).
2026-04-28 00:06:05,986 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x08630000, size: 0x1000.
2026-04-28 00:06:06,000 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:06:06,107 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:06,127 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x08640000 - 0x08642381.
2026-04-28 00:06:06,129 [root] DEBUG: 6648: ScanForDisguisedPE: No PE image located in range 0x08640000-0x08642381.
2026-04-28 00:06:06,259 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_4115020662127142026 to CAPE\b639220ba55e061b5ed03cb609435b06f2ca7eb4ded611f62778f43d345d4b25; Size is 9089; Max size: 100000000
2026-04-28 00:06:06,323 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_4115020662127142026 (size 9089 bytes)
2026-04-28 00:06:06,339 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x08640000, size 12288 bytes.
2026-04-28 00:06:06,375 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x08640000.
2026-04-28 00:06:06,442 [root] DEBUG: 6648: YaraScan: Scanning 0x08640000, size 0x2381
2026-04-28 00:06:06,712 [root] DEBUG: 6648: AllocationHandler: Previously reserved region at 0x02910000, committing at: 0x02911000.
2026-04-28 00:06:06,901 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:06,926 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08630000.
2026-04-28 00:06:07,014 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,150 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,156 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,188 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,235 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,273 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08630000.
2026-04-28 00:06:07,335 [root] DEBUG: 6648: AllocationHandler: Adding allocation to tracked region list: 0x08660000, size: 0x1000.
2026-04-28 00:06:07,351 [root] DEBUG: 6648: AddTrackedRegion: GetEntropy failed.
2026-04-28 00:06:07,357 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08630000.
2026-04-28 00:06:07,357 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,536 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,558 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08630000.
2026-04-28 00:06:07,621 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,723 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x077F0000.
2026-04-28 00:06:07,838 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:07,942 [root] DEBUG: 6648: DLL loaded at 0x71070000: C:\Windows\SYSTEM32\dnsapi (0x90000 bytes).
2026-04-28 00:06:07,954 [root] DEBUG: 6648: DLL loaded at 0x74BB0000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-04-28 00:06:07,974 [root] DEBUG: 6648: DLL loaded at 0x77E20000: C:\Windows\System32\NSI (0x7000 bytes).
2026-04-28 00:06:08,159 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:08,175 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08630000.
2026-04-28 00:06:08,321 [root] DEBUG: 6648: DumpRegion: Dump at 0x02920000 skipped due to dump limit 10
2026-04-28 00:06:08,346 [root] DEBUG: 6648: ProcessTrackedRegion: Failed to dump region at 0x02920000.
2026-04-28 00:06:08,357 [root] DEBUG: 6648: YaraScan: Scanning 0x02920000, size 0xad10
2026-04-28 00:06:08,926 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:08,958 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x08640000.
2026-04-28 00:06:08,991 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x077F0000.
2026-04-28 00:06:09,075 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x07B00000.
2026-04-28 00:06:13,225 [root] DEBUG: 6648: AllocationHandler: Allocation already in tracked region list: 0x02930000.
2026-04-28 00:06:18,257 [root] INFO: Process with pid 3556 has terminated
2026-04-28 00:06:34,522 [root] INFO: Process with pid 6016 has terminated
2026-04-28 00:07:14,179 [root] INFO: Analysis timeout hit, terminating analysis
2026-04-28 00:07:14,194 [lib.api.process] INFO: Terminate event set for <Process 6648 sex1.exe>
2026-04-28 00:07:14,257 [root] DEBUG: 6648: Terminate Event: Attempting to dump process 6648
2026-04-28 00:07:14,491 [root] DEBUG: 6648: VerifyCodeSection: Executable code does not match, 0x1c796 of 0x1c797 matching
2026-04-28 00:07:14,741 [root] DEBUG: 6648: DoProcessDump: Code modification detected, dumping Imagebase at 0x00610000.
2026-04-28 00:07:14,897 [root] DEBUG: 6648: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-28 00:07:15,041 [root] DEBUG: 6648: DumpProcess: Instantiating PeParser with address: 0x00610000.
2026-04-28 00:07:15,147 [root] DEBUG: 6648: DumpProcess: Module entry point VA is 0x0062E792.
2026-04-28 00:07:15,179 [root] DEBUG: 6648: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x00612000, section 1
2026-04-28 00:07:15,194 [root] DEBUG: 6648: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x00630000, section 2
2026-04-28 00:07:15,226 [root] DEBUG: 6648: reBasePEImage: Exception rebasing image from 0x00610000 to 0x00400000.
2026-04-28 00:07:15,241 [root] DEBUG: 6648: readPeSectionsFromProcess: Failed to relocate image back to header image base 0x00400000.
2026-04-28 00:07:15,350 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_111521572127142026 to procdump\e4dd7d882e7afe04c9b7bddfc0a6251193152d26b730d2625db3646f88c717b3; Size is 91136; Max size: 100000000
2026-04-28 00:07:15,366 [root] DEBUG: 6648: DumpProcess: Module image dump success - dump size 0x16400.
2026-04-28 00:07:15,397 [root] DEBUG: 6648: DumpInterestingRegions: Dumping .NET image at 0x08110000.
2026-04-28 00:07:15,413 [root] DEBUG: 6648: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image (process 6648)
2026-04-28 00:07:15,429 [root] DEBUG: 6648: DumpPE: Instantiating PeParser with address: 0x08110000.
2026-04-28 00:07:15,477 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_81993481572127142026 to CAPE\61e9d5c0727665e9ef3f328141397be47c65ed11ab621c644b5bbf1d67138403; Size is 19968; Max size: 100000000
2026-04-28 00:07:15,522 [root] DEBUG: 6648: DumpPE: PE file at 0x08110000 dumped successfully - dump size 0x4e00.
2026-04-28 00:07:15,539 [root] DEBUG: 6648: DumpInterestingRegions: Dumping .NET image at 0x083B0000.
2026-04-28 00:07:15,710 [root] DEBUG: 6648: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image (process 6648)
2026-04-28 00:07:15,741 [root] DEBUG: 6648: DumpPE: Instantiating PeParser with address: 0x083B0000.
2026-04-28 00:07:15,788 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_46934941572127142026 to CAPE\01e3b18bd63981decb384f558f0321346c3334bb6e6f97c31c6c95c4ab2fe354; Size is 100352; Max size: 100000000
2026-04-28 00:07:15,804 [root] DEBUG: 6648: DumpPE: PE file at 0x083B0000 dumped successfully - dump size 0x18800.
2026-04-28 00:07:15,835 [root] DEBUG: 6648: DumpInterestingRegions: Dumping .NET image at 0x08510000.
2026-04-28 00:07:15,882 [root] DEBUG: 6648: DumpImageInCurrentProcess: Attempting to dump 'raw' PE image (process 6648)
2026-04-28 00:07:15,882 [root] DEBUG: 6648: DumpPE: Instantiating PeParser with address: 0x08510000.
2026-04-28 00:07:15,945 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_241945001572127142026 to CAPE\f9b8c3f31375e9a1ec105f930f751869a804110d29d6b38e7298622eb74b2bec; Size is 12288; Max size: 100000000
2026-04-28 00:07:15,976 [root] DEBUG: 6648: DumpPE: PE file at 0x08510000 dumped successfully - dump size 0x3000.
2026-04-28 00:07:16,007 [root] DEBUG: 6648: DumpPEsInRange: Scanning range 0x08660000 - 0x086608CC.
2026-04-28 00:07:16,024 [root] DEBUG: 6648: ScanForDisguisedPE: No PE image located in range 0x08660000-0x086608CC.
2026-04-28 00:07:16,054 [lib.common.results] INFO: Uploading file C:\coVEjD\CAPE\6648_7284221672127142026 to CAPE\dc4a61046d5f6b52019eda5764ab099414471fc9e9fb50c828092a8db276c84d; Size is 2252; Max size: 100000000
2026-04-28 00:07:16,088 [root] DEBUG: 6648: DumpMemory: Payload successfully created: C:\coVEjD\CAPE\6648_7284221672127142026 (size 2252 bytes)
2026-04-28 00:07:16,101 [root] DEBUG: 6648: DumpRegion: Dumped entire allocation from 0x08660000, size 4096 bytes.
2026-04-28 00:07:16,132 [root] DEBUG: 6648: ProcessTrackedRegion: Dumped region at 0x08660000.
2026-04-28 00:07:16,132 [root] DEBUG: 6648: YaraScan: Scanning 0x08660000, size 0x8cc
2026-04-28 00:07:16,147 [lib.api.process] INFO: Termination confirmed for <Process 6648 sex1.exe>
2026-04-28 00:07:16,147 [root] INFO: Terminate event set for process 6648
2026-04-28 00:07:16,147 [root] DEBUG: 6648: Terminate Event: monitor shutdown complete for process 6648
2026-04-28 00:07:16,163 [lib.api.process] INFO: Terminate event set for <Process 1052 svchost.exe>
2026-04-28 00:07:16,179 [root] DEBUG: 1052: Terminate Event: Attempting to dump process 1052
2026-04-28 00:07:16,194 [root] DEBUG: 1052: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-28 00:07:16,429 [lib.api.process] INFO: Termination confirmed for <Process 1052 svchost.exe>
2026-04-28 00:07:16,429 [root] DEBUG: 1052: Terminate Event: monitor shutdown complete for process 1052
2026-04-28 00:07:16,444 [root] INFO: Terminate event set for process 1052
2026-04-28 00:07:16,475 [root] INFO: Created shutdown mutex
2026-04-28 00:07:17,554 [root] INFO: Shutting down package
2026-04-28 00:07:17,569 [root] INFO: Stopping auxiliary modules
2026-04-28 00:07:17,569 [root] INFO: Stopping auxiliary module: Browser
2026-04-28 00:07:17,585 [root] INFO: Stopping auxiliary module: Human
2026-04-28 00:07:19,397 [root] INFO: Stopping auxiliary module: Screenshots
2026-04-28 00:07:20,350 [root] INFO: Finishing auxiliary modules
2026-04-28 00:07:20,366 [root] INFO: Shutting down pipe server and dumping dropped files
2026-04-28 00:07:20,366 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Roaming\F3037635-6191-4C44-BD96-905F1B4FEAFD\run.dat to files\36bafa5002051a4b9b6881e5a98a99819e4d0b662428a35760be4ff269b74707; Size is 8; Max size: 100000000
2026-04-28 00:07:20,413 [lib.common.results] INFO: Uploading file C:\Program Files (x86)\WAN Manager\wanmgr.exe to files\2c14151d8f546aed480a7eda9be556bd37831020a3ab6d40eb993c260c9ee26b; Size is 207872; Max size: 100000000
2026-04-28 00:07:20,444 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Roaming\F3037635-6191-4C44-BD96-905F1B4FEAFD\task.dat to files\18dfaf9bd0867e40bf38b6f31369867a9d3ed42ac0a7a313753ad173556a4225; Size is 41; Max size: 100000000
2026-04-28 00:07:20,538 [root] WARNING: Folder at path "C:\coVEjD\debugger" does not exist, skipping
2026-04-28 00:07:20,632 [root] INFO: Uploading files at path "C:\coVEjD\tlsdump"
2026-04-28 00:07:20,772 [lib.common.results] INFO: Uploading file C:\coVEjD\tlsdump\tlsdump.log to tlsdump\tlsdump.log; Size is 14522; Max size: 100000000
2026-04-28 00:07:20,991 [root] INFO: Analysis completed