Analysis Log
2026-03-05 20:34:41,335 [root] INFO: Date set to: 20260428T01:01:36, timeout set to: 120
2026-04-28 01:01:36,257 [root] DEBUG: Starting analyzer from: C:\ltb6yatm
2026-04-28 01:01:36,319 [root] DEBUG: Storing results at: C:\sQCNRNV
2026-04-28 01:01:36,335 [root] DEBUG: Pipe server name: \\.\PIPE\nBCsDBR
2026-04-28 01:01:36,335 [root] DEBUG: Python path: C:\Python310
2026-04-28 01:01:36,351 [root] INFO: analysis running as an admin
2026-04-28 01:01:36,351 [root] INFO: analysis package specified: "dll"
2026-04-28 01:01:36,351 [root] DEBUG: importing analysis package module: "modules.packages.dll"...
2026-04-28 01:01:36,366 [root] DEBUG: imported analysis package "dll"
2026-04-28 01:01:36,366 [root] DEBUG: initializing analysis package "dll"...
2026-04-28 01:01:36,366 [lib.common.common] INFO: wrapping
2026-04-28 01:01:37,210 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-28 01:01:37,226 [root] DEBUG: New location of moved file: C:\Users\cape\AppData\Local\Temp\61e9d5c0727665e9ef3f3281
2026-04-28 01:01:37,226 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL option
2026-04-28 01:01:37,226 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL_64 option
2026-04-28 01:01:37,226 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader option
2026-04-28 01:01:37,226 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader_64 option
2026-04-28 01:01:37,241 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-04-28 01:01:38,007 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-04-28 01:01:38,038 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-04-28 01:01:38,085 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-04-28 01:01:38,163 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-04-28 01:01:38,570 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-04-28 01:01:38,633 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-04-28 01:01:41,194 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance
2026-04-28 01:01:41,194 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-04-28 01:01:41,194 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-04-28 01:01:41,194 [root] DEBUG: Initialized auxiliary module "Browser"
2026-04-28 01:01:41,194 [root] DEBUG: attempting to configure 'Browser' from data
2026-04-28 01:01:41,210 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-04-28 01:01:41,210 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-04-28 01:01:41,210 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-04-28 01:01:41,210 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-04-28 01:01:41,210 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-04-28 01:01:41,210 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-04-28 01:01:41,210 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-04-28 01:01:41,210 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-04-28 01:01:42,195 [modules.auxiliary.digisig] DEBUG: File is not signed
2026-04-28 01:01:42,195 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-04-28 01:01:42,226 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-04-28 01:01:42,226 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-04-28 01:01:42,226 [root] DEBUG: attempting to configure 'Disguise' from data
2026-04-28 01:01:42,226 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-04-28 01:01:42,226 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-04-28 01:01:42,335 [modules.auxiliary.disguise] INFO: Disguising GUID to 80383195-5b8c-41eb-a60c-d69b37821b65
2026-04-28 01:01:42,335 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-04-28 01:01:42,351 [root] DEBUG: Initialized auxiliary module "Human"
2026-04-28 01:01:42,351 [root] DEBUG: attempting to configure 'Human' from data
2026-04-28 01:01:42,351 [root] DEBUG: module Human does not support data configuration, ignoring
2026-04-28 01:01:42,351 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-04-28 01:01:42,351 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-04-28 01:01:42,351 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-04-28 01:01:42,351 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-04-28 01:01:42,351 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-04-28 01:01:42,351 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-04-28 01:01:42,538 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-04-28 01:01:42,538 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-04-28 01:01:42,554 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-04-28 01:01:42,570 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-04-28 01:01:42,570 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-04-28 01:01:42,585 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644
2026-04-28 01:01:42,710 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\ltb6yatm\dll\644.ini
2026-04-28 01:01:42,710 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-04-28 01:01:42,741 [lib.api.process] INFO: 64-bit DLL to inject is C:\ltb6yatm\dll\Elzpnma.dll, loader C:\ltb6yatm\bin\tAVrvhgN.exe
2026-04-28 01:01:42,882 [root] DEBUG: Loader: Injecting process 644 with C:\ltb6yatm\dll\Elzpnma.dll.
2026-04-28 01:01:59,367 [root] DEBUG: 644: Python path set to 'C:\Python310'.
2026-04-28 01:01:59,367 [root] DEBUG: 644: Disabling sleep skipping.
2026-04-28 01:01:59,382 [root] DEBUG: 644: TLS secret dump mode enabled.
2026-04-28 01:02:01,429 [root] DEBUG: 644: Yara error: Scanning timed out
2026-04-28 01:02:01,429 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABE10000, thread 5048, image base 0x00007FF7C23E0000, stack from 0x0000008E4CA71000-0x0000008E4CA80000
2026-04-28 01:02:01,460 [root] DEBUG: 644: Commandline: C:\Windows\system32\lsass.exe
2026-04-28 01:02:01,523 [root] DEBUG: 644: Hooked 5 out of 5 functions
2026-04-28 01:02:01,523 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-28 01:02:01,538 [root] DEBUG: Successfully injected DLL C:\ltb6yatm\dll\Elzpnma.dll.
2026-04-28 01:02:01,538 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>
2026-04-28 01:02:01,538 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-04-28 01:02:06,382 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\sQCNRNV\tlsdump\tlsdump.log
2026-04-28 01:02:40,726 [root] INFO: Restarting WMI Service
2026-04-28 01:02:42,835 [root] DEBUG: package modules.packages.dll does not support configure, ignoring
2026-04-28 01:02:42,835 [root] WARNING: configuration error for package modules.packages.dll: error importing data.packages.dll: No module named 'data.packages'
2026-04-28 01:03:14,335 [lib.common.common] INFO: Submitted file is missing extension, adding .dll
2026-04-28 01:03:14,413 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-28 01:03:14,663 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\System32\rundll32.exe" with arguments ""C:\Users\cape\AppData\Local\Temp\61e9d5c0727665e9ef3f3281.dll",#1" with pid 2200
2026-04-28 01:03:14,663 [lib.api.process] INFO: Monitor config for <Process 2200 rundll32.exe>: C:\ltb6yatm\dll\2200.ini
2026-04-28 01:03:14,679 [lib.api.process] INFO: 32-bit DLL to inject is C:\ltb6yatm\dll\iteBJUYL.dll, loader C:\ltb6yatm\bin\njAvMNz.exe
2026-04-28 01:03:14,976 [root] DEBUG: Loader: Injecting process 2200 (thread 1416) with C:\ltb6yatm\dll\iteBJUYL.dll.
2026-04-28 01:03:15,022 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:03:15,022 [root] DEBUG: Successfully injected DLL C:\ltb6yatm\dll\iteBJUYL.dll.
2026-04-28 01:03:15,038 [lib.api.process] INFO: Injected into 32-bit <Process 2200 rundll32.exe>
2026-04-28 01:03:17,053 [lib.api.process] INFO: Successfully resumed <Process 2200 rundll32.exe>
2026-04-28 01:03:17,511 [root] DEBUG: 2200: Python path set to 'C:\Python310'.
2026-04-28 01:03:17,543 [root] DEBUG: 2200: Disabling sleep skipping.
2026-04-28 01:03:17,551 [root] DEBUG: 2200: Dropped file limit defaulting to 100.
2026-04-28 01:03:17,650 [root] DEBUG: 2200: YaraInit: Compiled 44 rule files
2026-04-28 01:03:17,672 [root] DEBUG: 2200: YaraInit: Compiled rules saved to file C:\ltb6yatm\data\yara\capemon.yac
2026-04-28 01:03:17,672 [root] DEBUG: 2200: YaraScan: Scanning 0x00080000, size 0x136e8
2026-04-28 01:03:17,683 [root] DEBUG: 2200: Monitor initialised: 32-bit capemon loaded in process 2200 at 0x73b60000, thread 1416, image base 0x80000, stack from 0x3072000-0x3080000
2026-04-28 01:03:17,693 [root] DEBUG: 2200: Commandline: "C:\Windows\System32\rundll32.exe" "C:\Users\cape\AppData\Local\Temp\61e9d5c0727665e9ef3f3281.dll",#1
2026-04-28 01:03:17,948 [root] DEBUG: 2200: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-04-28 01:03:18,017 [root] DEBUG: 2200: hook_api: Warning - CreateProcessA export address 0x76AE2D90 differs from GetProcAddress -> 0x73EF22A0 (AcLayers.DLL::0xfd4422a0)
2026-04-28 01:03:18,017 [root] DEBUG: 2200: hook_api: Warning - CreateProcessW export address 0x76AC88E0 differs from GetProcAddress -> 0x73EF24E0 (AcLayers.DLL::0xfd4424e0)
2026-04-28 01:03:18,017 [root] DEBUG: 2200: hook_api: Warning - WinExec export address 0x76B0CF20 differs from GetProcAddress -> 0x73EF27A0 (AcLayers.DLL::0xfd4427a0)
2026-04-28 01:03:18,134 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-28 01:03:18,166 [root] DEBUG: 2200: set_hooks: Unable to hook GetCommandLineA
2026-04-28 01:03:18,166 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-28 01:03:18,181 [root] DEBUG: 2200: set_hooks: Unable to hook GetCommandLineW
2026-04-28 01:03:18,336 [root] DEBUG: 2200: Hooked 630 out of 632 functions
2026-04-28 01:03:18,352 [root] DEBUG: 2200: Syscall hook installed, syscall logging level 1
2026-04-28 01:03:18,368 [root] DEBUG: 2200: RestoreHeaders: Restored original import table.
2026-04-28 01:03:18,368 [root] INFO: Loaded monitor into process with pid 2200
2026-04-28 01:03:18,383 [root] DEBUG: 2200: caller_dispatch: Added region at 0x00080000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00085F1A, thread 1416).
2026-04-28 01:03:18,383 [root] DEBUG: 2200: YaraScan: Scanning 0x00080000, size 0x136e8
2026-04-28 01:03:18,383 [root] DEBUG: 2200: ProcessImageBase: Main module image at 0x00080000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:03:18,601 [root] DEBUG: 2200: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 1416).
2026-04-28 01:03:18,616 [root] DEBUG: 2200: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-28 01:03:18,623 [root] DEBUG: 2200: Target DLL loaded at 0x03590000: C:\Users\cape\AppData\Local\Temp\61e9d5c0727665e9ef3f3281 (0xa000 bytes).
2026-04-28 01:03:18,623 [root] DEBUG: 2200: YaraScan: Scanning 0x03590000, size 0x1f0
2026-04-28 01:03:18,856 [root] DEBUG: 2200: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 1416).
2026-04-28 01:03:18,856 [root] DEBUG: 2200: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 01:03:18,871 [root] DEBUG: 2200: DLL loaded at 0x73AC0000: C:\Windows\SYSTEM32\TextShaping (0x94000 bytes).
2026-04-28 01:03:18,987 [root] DEBUG: 2200: DLL loaded at 0x745D0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-28 01:03:19,142 [root] DEBUG: 2200: DLL loaded at 0x76BA0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-04-28 01:03:19,259 [root] DEBUG: 2200: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-28 01:03:19,274 [root] DEBUG: 2200: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-28 01:03:19,290 [root] DEBUG: 2200: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-28 01:03:19,476 [root] DEBUG: 2200: DLL loaded at 0x736B0000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-28 01:03:19,476 [root] DEBUG: 2200: DLL loaded at 0x736E0000: C:\Windows\System32\CoreMessaging (0x9b000 bytes).
2026-04-28 01:03:19,492 [root] DEBUG: 2200: DLL loaded at 0x735D0000: C:\Windows\SYSTEM32\wintypes (0xdb000 bytes).
2026-04-28 01:03:19,492 [root] DEBUG: 2200: DLL loaded at 0x73780000: C:\Windows\System32\CoreUIComponents (0x27e000 bytes).
2026-04-28 01:03:19,492 [root] DEBUG: 2200: DLL loaded at 0x73A00000: C:\Windows\SYSTEM32\textinputframework (0xb9000 bytes).
2026-04-28 01:05:18,034 [root] INFO: Analysis timeout hit, terminating analysis
2026-04-28 01:05:18,034 [lib.api.process] INFO: Terminate event set for <Process 2200 rundll32.exe>
2026-04-28 01:05:18,034 [root] DEBUG: 2200: Terminate Event: Attempting to dump process 2200
2026-04-28 01:05:18,050 [root] DEBUG: 2200: VerifyCodeSection: Executable code does not match, 0x18f2 of 0x18f3 matching
2026-04-28 01:05:18,050 [root] DEBUG: 2200: DoProcessDump: Code modification detected, dumping Imagebase at 0x03590000.
2026-04-28 01:05:18,050 [root] DEBUG: 2200: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-28 01:05:18,050 [root] DEBUG: 2200: DumpProcess: Instantiating PeParser with address: 0x03590000.
2026-04-28 01:05:18,065 [root] DEBUG: 2200: DumpProcess: Module entry point VA is 0x035938EE.
2026-04-28 01:05:18,065 [root] DEBUG: 2200: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x03594000, section 2
2026-04-28 01:05:18,065 [root] DEBUG: 2200: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x03598000, section 3
2026-04-28 01:05:18,253 [lib.common.results] INFO: Uploading file C:\sQCNRNV\CAPE\2200_84461852227142026 to procdump\9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3; Size is 7680; Max size: 100000000
2026-04-28 01:05:18,268 [root] DEBUG: 2200: DumpProcess: Module image dump success - dump size 0x1e00.
2026-04-28 01:05:18,284 [lib.api.process] INFO: Termination confirmed for <Process 2200 rundll32.exe>
2026-04-28 01:05:18,284 [root] INFO: Terminate event set for process 2200
2026-04-28 01:05:18,284 [root] INFO: Created shutdown mutex
2026-04-28 01:05:18,299 [root] DEBUG: 2200: Terminate Event: monitor shutdown complete for process 2200
2026-04-28 01:05:19,300 [root] INFO: Shutting down package
2026-04-28 01:05:19,300 [root] INFO: Stopping auxiliary modules
2026-04-28 01:05:19,300 [root] INFO: Stopping auxiliary module: Browser
2026-04-28 01:05:19,300 [root] INFO: Stopping auxiliary module: Human
2026-04-28 01:05:24,612 [root] INFO: Stopping auxiliary module: Screenshots
2026-04-28 01:05:25,237 [root] INFO: Finishing auxiliary modules
2026-04-28 01:05:25,237 [root] INFO: Shutting down pipe server and dumping dropped files
2026-04-28 01:05:25,237 [root] WARNING: Folder at path "C:\sQCNRNV\debugger" does not exist, skipping
2026-04-28 01:05:25,237 [root] INFO: Uploading files at path "C:\sQCNRNV\tlsdump"
2026-04-28 01:05:25,252 [lib.common.results] INFO: Uploading file C:\sQCNRNV\tlsdump\tlsdump.log to tlsdump\tlsdump.log; Size is 24660; Max size: 100000000
2026-04-28 01:05:25,252 [root] INFO: Analysis completed