Analysis Log
2026-03-05 20:34:39,179 [root] INFO: Date set to: 20260428T01:14:10, timeout set to: 300
2026-04-28 01:14:10,126 [root] DEBUG: Starting analyzer from: C:\vdyc7mjt
2026-04-28 01:14:10,157 [root] DEBUG: Storing results at: C:\XJKAvEz
2026-04-28 01:14:10,172 [root] DEBUG: Pipe server name: \\.\PIPE\bRdEiig
2026-04-28 01:14:10,172 [root] DEBUG: Python path: C:\Python310
2026-04-28 01:14:10,172 [root] INFO: analysis running as an admin
2026-04-28 01:14:10,172 [root] INFO: analysis package specified: "exe"
2026-04-28 01:14:10,219 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2026-04-28 01:14:10,250 [root] DEBUG: imported analysis package "exe"
2026-04-28 01:14:10,282 [root] DEBUG: initializing analysis package "exe"...
2026-04-28 01:14:10,282 [lib.common.common] INFO: wrapping
2026-04-28 01:14:10,297 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-28 01:14:10,313 [root] DEBUG: New location of moved file: C:\Users\cape\AppData\Local\Temp\xcd2b41bdfa49d6668e6.exe
2026-04-28 01:14:10,313 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2026-04-28 01:14:10,313 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2026-04-28 01:14:10,328 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2026-04-28 01:14:10,344 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2026-04-28 01:14:10,563 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-04-28 01:14:10,578 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-04-28 01:14:10,610 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-04-28 01:14:10,657 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-04-28 01:14:10,735 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-04-28 01:14:10,750 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-04-28 01:14:10,828 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-04-28 01:14:11,688 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance
2026-04-28 01:14:11,704 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-04-28 01:14:11,719 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-04-28 01:14:11,719 [root] DEBUG: Initialized auxiliary module "Browser"
2026-04-28 01:14:11,719 [root] DEBUG: attempting to configure 'Browser' from data
2026-04-28 01:14:11,750 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-04-28 01:14:11,750 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-04-28 01:14:11,750 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-04-28 01:14:11,750 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-04-28 01:14:11,750 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-04-28 01:14:11,766 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-04-28 01:14:11,766 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-04-28 01:14:11,766 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-04-28 01:14:12,938 [modules.auxiliary.digisig] DEBUG: File is not signed
2026-04-28 01:14:12,938 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-04-28 01:14:12,954 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-04-28 01:14:12,954 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-04-28 01:14:12,954 [root] DEBUG: attempting to configure 'Disguise' from data
2026-04-28 01:14:12,954 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-04-28 01:14:12,954 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-04-28 01:14:12,969 [modules.auxiliary.disguise] INFO: Disguising GUID to e89d11b0-a4f8-4f8d-8a97-aa81b8d07205
2026-04-28 01:14:12,969 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-04-28 01:14:12,969 [root] DEBUG: Initialized auxiliary module "Human"
2026-04-28 01:14:12,969 [root] DEBUG: attempting to configure 'Human' from data
2026-04-28 01:14:12,985 [root] DEBUG: module Human does not support data configuration, ignoring
2026-04-28 01:14:12,985 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-04-28 01:14:12,985 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-04-28 01:14:12,985 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-04-28 01:14:13,000 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-04-28 01:14:13,000 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-04-28 01:14:13,000 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-04-28 01:14:13,035 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-04-28 01:14:13,035 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-04-28 01:14:13,035 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-04-28 01:14:13,047 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-04-28 01:14:13,047 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-04-28 01:14:13,047 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644
2026-04-28 01:14:13,094 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\vdyc7mjt\dll\644.ini
2026-04-28 01:14:13,110 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-04-28 01:14:13,282 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:14:41,000 [root] DEBUG: Loader: Injecting process 644 with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:42,063 [root] DEBUG: 644: Python path set to 'C:\Python310'.
2026-04-28 01:14:42,079 [root] DEBUG: 644: Disabling sleep skipping.
2026-04-28 01:14:42,079 [root] DEBUG: 644: TLS secret dump mode enabled.
2026-04-28 01:14:43,016 [root] DEBUG: 644: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:14:43,032 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABC40000, thread 6296, image base 0x00007FF7C23E0000, stack from 0x0000008E4C472000-0x0000008E4C480000
2026-04-28 01:14:43,032 [root] DEBUG: 644: Commandline: C:\Windows\system32\lsass.exe
2026-04-28 01:14:43,063 [root] DEBUG: 644: Hooked 5 out of 5 functions
2026-04-28 01:14:43,078 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-28 01:14:43,078 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:43,078 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>
2026-04-28 01:14:43,078 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-04-28 01:14:43,391 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\XJKAvEz\tlsdump\tlsdump.log
2026-04-28 01:14:50,891 [root] INFO: Restarting WMI Service
2026-04-28 01:14:50,938 [root] DEBUG: package modules.packages.exe does not support configure, ignoring
2026-04-28 01:14:50,938 [root] WARNING: configuration error for package modules.packages.exe: error importing data.packages.exe: No module named 'data.packages'
2026-04-28 01:14:50,938 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-04-28 01:14:51,188 [lib.api.process] INFO: Successfully executed process from path "C:\Users\cape\AppData\Local\Temp\xcd2b41bdfa49d6668e6.exe" with arguments "" with pid 5852
2026-04-28 01:14:51,188 [lib.api.process] INFO: Monitor config for <Process 5852 xcd2b41bdfa49d6668e6.exe>: C:\vdyc7mjt\dll\5852.ini
2026-04-28 01:14:51,204 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:14:51,220 [root] DEBUG: Loader: Injecting process 5852 (thread 5964) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:51,235 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:14:51,235 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:51,235 [lib.api.process] INFO: Injected into 64-bit <Process 5852 xcd2b41bdfa49d6668e6.exe>
2026-04-28 01:14:53,251 [lib.api.process] INFO: Successfully resumed <Process 5852 xcd2b41bdfa49d6668e6.exe>
2026-04-28 01:14:53,282 [root] DEBUG: 5852: Python path set to 'C:\Python310'.
2026-04-28 01:14:53,313 [root] DEBUG: 5852: Disabling sleep skipping.
2026-04-28 01:14:53,329 [root] DEBUG: 5852: Dropped file limit defaulting to 100.
2026-04-28 01:14:53,375 [root] DEBUG: 5852: YaraInit: Compiled 44 rule files
2026-04-28 01:14:53,375 [root] DEBUG: 5852: YaraInit: Compiled rules saved to file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:14:53,407 [root] DEBUG: 5852: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:14:53,422 [root] DEBUG: 5852: YaraScan: Scanning 0x0000000140000000, size 0xd1a2e
2026-04-28 01:14:53,438 [root] DEBUG: 5852: Monitor initialised: 64-bit capemon loaded in process 5852 at 0x00007FFEABC40000, thread 5964, image base 0x0000000140000000, stack from 0x0000000000141000-0x0000000000150000
2026-04-28 01:14:53,438 [root] DEBUG: 5852: Commandline: "C:\Users\cape\AppData\Local\Temp\xcd2b41bdfa49d6668e6.exe"
2026-04-28 01:14:53,469 [root] DEBUG: 5852: hook_api: LdrpCallInitRoutine export address 0x00007FFEFE8699BC obtained via GetFunctionAddress
2026-04-28 01:14:53,548 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-28 01:14:53,563 [root] DEBUG: 5852: set_hooks: Unable to hook LockResource
2026-04-28 01:14:53,579 [root] DEBUG: 5852: Hooked 627 out of 628 functions
2026-04-28 01:14:53,579 [root] DEBUG: 5852: Syscall hook installed, syscall logging level 1
2026-04-28 01:14:53,688 [root] DEBUG: 5852: RestoreHeaders: Restored original import table.
2026-04-28 01:14:53,688 [root] INFO: Loaded monitor into process with pid 5852
2026-04-28 01:14:53,704 [root] DEBUG: 5852: caller_dispatch: Added region at 0x0000000140000000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0000000140096A27, thread 5964).
2026-04-28 01:14:53,719 [root] DEBUG: 5852: YaraScan: Scanning 0x0000000140000000, size 0xd1a2e
2026-04-28 01:14:53,735 [root] DEBUG: 5852: ProcessImageBase: Main module image at 0x0000000140000000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:14:54,282 [root] DEBUG: 5852: DLL loaded at 0x00007FFEFB900000: C:\Windows\SYSTEM32\Wldp (0x30000 bytes).
2026-04-28 01:14:54,297 [root] DEBUG: 5852: DLL loaded at 0x00007FFEFA080000: C:\Windows\SYSTEM32\windows.storage (0x795000 bytes).
2026-04-28 01:14:54,360 [root] DEBUG: 5852: DLL loaded at 0x00007FFEFE330000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-04-28 01:14:54,407 [root] INFO: Added new file to list with pid 5852 and path C:\Users\cape\Documents\diagnostics\audiodg.exe
2026-04-28 01:14:54,485 [root] DEBUG: 5852: CreateProcessHandler: Injection info set for new process 3688: C:\Users\cape\Documents\diagnostics\audiodg.exe, ImageBase: 0x0000000000440000
2026-04-28 01:14:54,501 [root] INFO: Announced 64-bit process name: audiodg.exe pid: 3688
2026-04-28 01:14:54,501 [lib.api.process] INFO: Monitor config for <Process 3688 audiodg.exe>: C:\vdyc7mjt\dll\3688.ini
2026-04-28 01:14:54,516 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:14:54,532 [root] DEBUG: Loader: Injecting process 3688 (thread 3684) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:54,532 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2026-04-28 01:14:54,547 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2026-04-28 01:14:54,547 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:54,547 [lib.api.process] INFO: Injected into 64-bit <Process 3688 audiodg.exe>
2026-04-28 01:14:54,563 [root] INFO: Announced 64-bit process name: audiodg.exe pid: 3688
2026-04-28 01:14:54,563 [lib.api.process] INFO: Monitor config for <Process 3688 audiodg.exe>: C:\vdyc7mjt\dll\3688.ini
2026-04-28 01:14:54,579 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:14:54,594 [root] DEBUG: Loader: Injecting process 3688 (thread 3684) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:54,594 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2026-04-28 01:14:54,610 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2026-04-28 01:14:54,610 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:54,610 [lib.api.process] INFO: Injected into 64-bit <Process 3688 audiodg.exe>
2026-04-28 01:14:54,672 [root] DEBUG: 3688: Python path set to 'C:\Python310'.
2026-04-28 01:14:54,672 [root] DEBUG: 3688: Dropped file limit defaulting to 100.
2026-04-28 01:14:54,672 [root] DEBUG: 3688: Disabling sleep skipping.
2026-04-28 01:14:54,688 [root] DEBUG: 3688: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:14:54,719 [root] DEBUG: 3688: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:14:54,719 [root] DEBUG: 3688: YaraScan: Scanning 0x0000000000440000, size 0x200
2026-04-28 01:14:54,719 [root] DEBUG: 3688: Monitor initialised: 64-bit capemon loaded in process 3688 at 0x00007FFEABC40000, thread 3684, image base 0x0000000000440000, stack from 0x0000000000594000-0x00000000005A0000
2026-04-28 01:14:54,719 [root] DEBUG: 3688: Commandline: "C:\Users\cape\Documents\diagnostics\audiodg.exe"
2026-04-28 01:14:54,766 [root] DEBUG: 3688: hook_api: LdrpCallInitRoutine export address 0x00007FFEFE8699BC obtained via GetFunctionAddress
2026-04-28 01:14:54,813 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-28 01:14:54,828 [root] DEBUG: 3688: set_hooks: Unable to hook LockResource
2026-04-28 01:14:54,860 [root] DEBUG: 3688: Hooked 627 out of 628 functions
2026-04-28 01:14:54,875 [root] DEBUG: 3688: Syscall hook installed, syscall logging level 1
2026-04-28 01:14:54,875 [root] INFO: Loaded monitor into process with pid 3688
2026-04-28 01:14:54,891 [root] DEBUG: 3688: caller_dispatch: Added region at 0x00000000005E0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00000000005E0047, thread 3684).
2026-04-28 01:14:54,891 [root] DEBUG: 3688: DumpPEsInRange: Scanning range 0x00000000005E0000 - 0x00000000005E0138.
2026-04-28 01:14:54,891 [root] DEBUG: 3688: ScanForDisguisedPE: Size too small: 0x138 bytes
2026-04-28 01:14:54,907 [lib.common.results] INFO: Uploading file C:\XJKAvEz\CAPE\3688_900801054142227142026 to CAPE\1c9e3a77226328fb5f03e9ea8c4b18e97e78e8fd808e9632c3ee02d3bb81284d; Size is 312; Max size: 100000000
2026-04-28 01:14:54,922 [root] DEBUG: 3688: DumpMemory: Payload successfully created: C:\XJKAvEz\CAPE\3688_900801054142227142026 (size 312 bytes)
2026-04-28 01:14:54,922 [root] DEBUG: 5852: DLL loaded at 0x00007FFEF9980000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-04-28 01:14:54,922 [root] DEBUG: 3688: DumpRegion: Dumped entire allocation from 0x00000000005E0000, size 4096 bytes.
2026-04-28 01:14:54,922 [root] DEBUG: 3688: ProcessTrackedRegion: Dumped region at 0x00000000005E0000.
2026-04-28 01:14:54,922 [root] DEBUG: 3688: YaraScan: Scanning 0x00000000005E0000, size 0x138
2026-04-28 01:14:54,938 [root] DEBUG: 3688: DLL loaded at 0x00007FFEEF710000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei (0xaa000 bytes).
2026-04-28 01:14:55,016 [root] INFO: Added new file to list with pid 5852 and path C:\Users\cape\AppData\Local\Temp\xcd2b41bdfa49d6668e6..exe
2026-04-28 01:14:55,047 [root] INFO: Added new file to list with pid 5852 and path C:\Users\cape\Documents\diagnostics\shost.exe
2026-04-28 01:14:55,047 [root] DEBUG: 3688: set_hooks_by_export_directory: Hooked 0 out of 628 functions
2026-04-28 01:14:55,047 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF9E80000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-04-28 01:14:55,063 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF5730000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2026-04-28 01:14:55,078 [root] DEBUG: 3688: DLL loaded at 0x00007FFEEF330000: C:\Windows\SYSTEM32\ucrtbase_clr0400 (0xbd000 bytes).
2026-04-28 01:14:55,078 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF2100000: C:\Windows\SYSTEM32\VCRUNTIME140_CLR0400 (0x16000 bytes).
2026-04-28 01:14:55,078 [root] DEBUG: 3688: DLL loaded at 0x00007FFEAB100000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr (0xb35000 bytes).
2026-04-28 01:14:55,266 [root] DEBUG: 3688: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2026-04-28 01:14:55,266 [root] DEBUG: 3688: DLL loaded at 0x00007FFEA9B00000: C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\b8493bec853ac702d2188091d76ccffa\mscorlib.ni (0x1600000 bytes).
2026-04-28 01:14:55,282 [root] INFO: Added new file to list with pid 5852 and path C:\Users\cape\Documents\diagnostics\RCX6FE2.tmp
2026-04-28 01:14:55,297 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFC380000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-04-28 01:14:55,297 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF9980000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-04-28 01:14:55,313 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FF46F9A0000, size: 0xa0000.
2026-04-28 01:14:55,313 [root] DEBUG: 3688: GetEntropy: Error - Supplied address inaccessible: 0x00007FF46F9A0000
2026-04-28 01:14:55,313 [root] DEBUG: 3688: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:14:55,313 [root] DEBUG: 3688: AllocationHandler: Memory region (size 0xa0000) reserved but not committed at 0x00007FF46F9A0000.
2026-04-28 01:14:55,313 [root] DEBUG: 3688: AllocationHandler: Previously reserved region at 0x00007FF46F9A0000, committing at: 0x00007FF46F9A0000.
2026-04-28 01:14:55,313 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FF46F9A0000.
2026-04-28 01:14:55,313 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FF46F9A0000.
2026-04-28 01:14:55,328 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FF46F990000, size: 0x10000.
2026-04-28 01:14:55,328 [root] DEBUG: 3688: GetEntropy: Error - Supplied address inaccessible: 0x00007FF46F990000
2026-04-28 01:14:55,328 [root] DEBUG: 3688: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:14:55,328 [root] DEBUG: 3688: AllocationHandler: Processing previous tracked region at: 0x00007FF46F9A0000.
2026-04-28 01:14:55,328 [root] DEBUG: 3688: DumpPEsInRange: Scanning range 0x00007FF46F9A0000 - 0x00007FF46F9A0066.
2026-04-28 01:14:55,328 [root] DEBUG: 3688: ScanForDisguisedPE: Size too small: 0x66 bytes
2026-04-28 01:14:55,375 [lib.common.results] INFO: Uploading file C:\XJKAvEz\CAPE\3688_418820055142227142026 to CAPE\fa605e4ccb5a4dfdb17df05a25617972f7c0d0a791277e6ed7c31b00fb428d41; Size is 102; Max size: 100000000
2026-04-28 01:14:55,391 [root] DEBUG: 3688: DumpMemory: Payload successfully created: C:\XJKAvEz\CAPE\3688_418820055142227142026 (size 102 bytes)
2026-04-28 01:14:55,391 [root] DEBUG: 3688: DumpRegion: Dumped entire allocation from 0x00007FF46F9A0000, size 4096 bytes.
2026-04-28 01:14:55,391 [root] DEBUG: 3688: ProcessTrackedRegion: Dumped region at 0x00007FF46F9A0000.
2026-04-28 01:14:55,391 [root] DEBUG: 3688: YaraScan: Scanning 0x00007FF46F9A0000, size 0x66
2026-04-28 01:14:55,391 [root] DEBUG: 3688: AllocationHandler: Memory region (size 0x10000) reserved but not committed at 0x00007FF46F990000.
2026-04-28 01:14:55,391 [root] DEBUG: 3688: AllocationHandler: Previously reserved region at 0x00007FF46F990000, committing at: 0x00007FF46F990000.
2026-04-28 01:14:55,407 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BB2D000, size: 0x1000.
2026-04-28 01:14:55,407 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BC40000, size: 0x1000.
2026-04-28 01:14:55,407 [root] DEBUG: 3688: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:14:55,532 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BBDC000, size: 0x1000.
2026-04-28 01:14:55,547 [root] DEBUG: 3688: GetEntropy: Error - Supplied address inaccessible: 0x00007FFE4BBD0000
2026-04-28 01:14:55,547 [root] DEBUG: 3688: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:14:55,547 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BBD0000.
2026-04-28 01:14:55,563 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BBD0000.
2026-04-28 01:14:55,563 [root] DEBUG: 3688: hook_api: clrjit::compileMethod export address 0x00007FFEE8675FF0 obtained via GetFunctionAddress
2026-04-28 01:14:55,579 [root] DEBUG: 3688: DLL loaded at 0x00007FFEE8670000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit (0x14f000 bytes).
2026-04-28 01:14:55,704 [root] DEBUG: 5852: CreateProcessHandler: Injection info set for new process 2484: C:\Users\cape\Documents\diagnostics\shost.exe, ImageBase: 0x0000000140000000
2026-04-28 01:14:55,719 [root] INFO: Announced 64-bit process name: shost.exe pid: 2484
2026-04-28 01:14:55,719 [lib.api.process] INFO: Monitor config for <Process 2484 shost.exe>: C:\vdyc7mjt\dll\2484.ini
2026-04-28 01:14:55,735 [root] DEBUG: 3688: .NET JIT native cache at 0x00007FFE4BC40000: scans and dumps active.
2026-04-28 01:14:55,751 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:14:55,782 [root] DEBUG: Loader: Injecting process 2484 (thread 2832) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:55,797 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:14:55,797 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:55,814 [root] DEBUG: 3688: DLL loaded at 0x00007FFEA8E80000: C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni (0xc71000 bytes).
2026-04-28 01:14:55,814 [lib.api.process] INFO: Injected into 64-bit <Process 2484 shost.exe>
2026-04-28 01:14:55,829 [root] DEBUG: 3688: DLL loaded at 0x000000001CB70000: C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\31326613607f69254f3284ec964796c8\System.Core.ni (0xa75000 bytes).
2026-04-28 01:14:55,829 [root] INFO: Announced 64-bit process name: shost.exe pid: 2484
2026-04-28 01:14:55,829 [lib.api.process] INFO: Monitor config for <Process 2484 shost.exe>: C:\vdyc7mjt\dll\2484.ini
2026-04-28 01:14:55,845 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:14:55,860 [root] DEBUG: Loader: Injecting process 2484 (thread 2832) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:55,860 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:14:55,860 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:55,878 [lib.api.process] INFO: Injected into 64-bit <Process 2484 shost.exe>
2026-04-28 01:14:55,891 [root] DEBUG: 2484: Python path set to 'C:\Python310'.
2026-04-28 01:14:55,908 [root] DEBUG: 2484: Dropped file limit defaulting to 100.
2026-04-28 01:14:55,908 [root] DEBUG: 2484: Disabling sleep skipping.
2026-04-28 01:14:55,908 [root] DEBUG: 2484: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:14:55,940 [root] DEBUG: 2484: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:14:55,940 [root] DEBUG: 2484: YaraScan: Scanning 0x0000000140000000, size 0xd1a2e
2026-04-28 01:14:55,954 [root] DEBUG: 2484: Monitor initialised: 64-bit capemon loaded in process 2484 at 0x00007FFEABC40000, thread 2832, image base 0x0000000140000000, stack from 0x0000000000144000-0x0000000000150000
2026-04-28 01:14:55,954 [root] DEBUG: 2484: Commandline: "C:\Users\cape\Documents\diagnostics\shost.exe"
2026-04-28 01:14:55,985 [root] DEBUG: 2484: hook_api: LdrpCallInitRoutine export address 0x00007FFEFE8699BC obtained via GetFunctionAddress
2026-04-28 01:14:56,000 [root] DEBUG: 5852: CreateProcessHandler: Injection info set for new process 3368: C:\Users\cape\AppData\Local\Temp\xcd2b41bdfa49d6668e6..exe, ImageBase: 0x0000000000400000
2026-04-28 01:14:56,000 [root] DEBUG: 3688: DLL loaded at 0x00007FFEAD090000: C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.V9921e851#\04de61553901f06e2f763b6f03a6f65a\Microsoft.VisualBasic.ni (0x225000 bytes).
2026-04-28 01:14:56,016 [root] INFO: Announced 32-bit process name: xcd2b41bdfa49d6668e6..exe pid: 3368
2026-04-28 01:14:56,078 [lib.api.process] INFO: Monitor config for <Process 3368 xcd2b41bdfa49d6668e6..exe>: C:\vdyc7mjt\dll\3368.ini
2026-04-28 01:14:56,094 [root] DEBUG: 3688: ProcessTrackedRegion: .NET cache region at 0x00007FFE4BC40000 skipped
2026-04-28 01:14:56,094 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-28 01:14:56,110 [root] DEBUG: 2484: set_hooks: Unable to hook LockResource
2026-04-28 01:14:56,125 [lib.api.process] INFO: 32-bit DLL to inject is C:\vdyc7mjt\dll\bcxciCVv.dll, loader C:\vdyc7mjt\bin\SuLiCON.exe
2026-04-28 01:14:56,141 [root] DEBUG: 2484: Hooked 627 out of 628 functions
2026-04-28 01:14:56,141 [root] DEBUG: 2484: Syscall hook installed, syscall logging level 1
2026-04-28 01:14:56,157 [root] DEBUG: 2484: RestoreHeaders: Restored original import table.
2026-04-28 01:14:56,157 [root] INFO: Loaded monitor into process with pid 2484
2026-04-28 01:14:56,172 [root] DEBUG: 2484: caller_dispatch: Added region at 0x0000000140000000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0000000140096A27, thread 2832).
2026-04-28 01:14:56,172 [root] DEBUG: 2484: YaraScan: Scanning 0x0000000140000000, size 0xd1a2e
2026-04-28 01:14:56,188 [root] DEBUG: 2484: ProcessImageBase: Main module image at 0x0000000140000000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:14:56,266 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFB850000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-04-28 01:14:56,266 [root] DEBUG: Loader: Injecting process 3368 (thread 2372) with C:\vdyc7mjt\dll\bcxciCVv.dll.
2026-04-28 01:14:56,266 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFAFE0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-04-28 01:14:56,282 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:14:56,282 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\bcxciCVv.dll.
2026-04-28 01:14:56,282 [lib.api.process] INFO: Injected into 32-bit <Process 3368 xcd2b41bdfa49d6668e6..exe>
2026-04-28 01:14:56,297 [root] INFO: Announced 32-bit process name: xcd2b41bdfa49d6668e6..exe pid: 3368
2026-04-28 01:14:56,313 [lib.api.process] INFO: Monitor config for <Process 3368 xcd2b41bdfa49d6668e6..exe>: C:\vdyc7mjt\dll\3368.ini
2026-04-28 01:14:56,313 [lib.api.process] INFO: 32-bit DLL to inject is C:\vdyc7mjt\dll\bcxciCVv.dll, loader C:\vdyc7mjt\bin\SuLiCON.exe
2026-04-28 01:14:56,328 [root] DEBUG: Loader: Injecting process 3368 (thread 2372) with C:\vdyc7mjt\dll\bcxciCVv.dll.
2026-04-28 01:14:56,344 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-04-28 01:14:56,344 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\bcxciCVv.dll.
2026-04-28 01:14:56,344 [lib.api.process] INFO: Injected into 32-bit <Process 3368 xcd2b41bdfa49d6668e6..exe>
2026-04-28 01:14:56,375 [root] DEBUG: 5852: set_hooks_by_export_directory: Hooked 0 out of 628 functions
2026-04-28 01:14:56,375 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFD100000: C:\Windows\System32\psapi (0x8000 bytes).
2026-04-28 01:14:56,375 [root] DEBUG: 5852: DLL loaded at 0x00007FFEF9E80000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-04-28 01:14:56,391 [root] DEBUG: 5852: NtTerminateProcess hook: Attempting to dump process 5852
2026-04-28 01:14:56,391 [root] DEBUG: 5852: CAPEExceptionFilter: Exception 0xc0000005 accessing 0x400d2000 caught at RVA 0x752f0 in capemon (expected in memory scans), passing to next handler.
2026-04-28 01:14:56,391 [root] DEBUG: 5852: VerifyCodeSection: Exception rebasing image from 0x0000000140000000 to 0x0000000140000000.
2026-04-28 01:14:56,391 [root] DEBUG: 5852: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-28 01:14:56,672 [root] DEBUG: 2484: DLL loaded at 0x00007FFEFB900000: C:\Windows\SYSTEM32\Wldp (0x30000 bytes).
2026-04-28 01:14:56,813 [root] INFO: Process with pid 5852 has terminated
2026-04-28 01:14:56,891 [root] DEBUG: 2484: DLL loaded at 0x00007FFEFA080000: C:\Windows\SYSTEM32\windows.storage (0x795000 bytes).
2026-04-28 01:14:56,985 [root] DEBUG: 3368: Python path set to 'C:\Python310'.
2026-04-28 01:14:57,047 [root] DEBUG: 2484: DLL loaded at 0x00007FFEFE330000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-04-28 01:14:57,125 [root] DEBUG: 3368: Dropped file limit defaulting to 100.
2026-04-28 01:14:57,203 [root] DEBUG: 2484: CreateProcessHandler: Injection info set for new process 2884: C:\Users\cape\Documents\diagnostics\audiodg.exe, ImageBase: 0x0000000000DD0000
2026-04-28 01:14:57,266 [root] INFO: Announced 64-bit process name: audiodg.exe pid: 2884
2026-04-28 01:14:57,266 [lib.api.process] INFO: Monitor config for <Process 2884 audiodg.exe>: C:\vdyc7mjt\dll\2884.ini
2026-04-28 01:14:57,282 [root] DEBUG: 3368: Disabling sleep skipping.
2026-04-28 01:14:57,297 [root] DEBUG: 3368: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:14:57,297 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:14:57,313 [root] DEBUG: 3368: YaraScan: Scanning 0x00400000, size 0x3257e
2026-04-28 01:14:57,329 [root] DEBUG: 3368: YaraScan hit: NSIS
2026-04-28 01:14:57,344 [root] DEBUG: Loader: Injecting process 2884 (thread 7752) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:57,344 [root] DEBUG: 3368: YaraScan match: $check (0x2d36)
2026-04-28 01:14:57,344 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2026-04-28 01:14:57,360 [root] DEBUG: 3368: Monitor initialised: 32-bit capemon loaded in process 3368 at 0x73f00000, thread 2372, image base 0x400000, stack from 0x195000-0x1a0000
2026-04-28 01:14:57,360 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2026-04-28 01:14:57,360 [root] DEBUG: 3368: Commandline: "C:\Users\cape\AppData\Local\Temp\xcd2b41bdfa49d6668e6..exe"
2026-04-28 01:14:57,407 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:57,438 [lib.api.process] INFO: Injected into 64-bit <Process 2884 audiodg.exe>
2026-04-28 01:14:57,453 [root] INFO: Announced 64-bit process name: audiodg.exe pid: 2884
2026-04-28 01:14:57,453 [lib.api.process] INFO: Monitor config for <Process 2884 audiodg.exe>: C:\vdyc7mjt\dll\2884.ini
2026-04-28 01:14:57,469 [root] DEBUG: 3368: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-04-28 01:14:57,485 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:14:57,532 [root] DEBUG: 3368: hook_api: Warning - SetWindowLongW export address 0x75D45420 differs from GetProcAddress -> 0x750E59E0 (apphelp.dll::0xff3d59e0)
2026-04-28 01:14:57,532 [root] DEBUG: Loader: Injecting process 2884 (thread 7752) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:57,532 [root] DEBUG: 3368: hook_api: Warning - EnumDisplayDevicesA export address 0x75D395A0 differs from GetProcAddress -> 0x750E6780 (apphelp.dll::0xff3d6780)
2026-04-28 01:14:57,547 [root] DEBUG: InjectDllViaIAT: Executable is .NET, injecting via queued APC.
2026-04-28 01:14:57,547 [root] DEBUG: 3368: hook_api: Warning - EnumDisplayDevicesW export address 0x75D4FB70 differs from GetProcAddress -> 0x7510E4D0 (apphelp.dll::0xff3fe4d0)
2026-04-28 01:14:57,547 [root] DEBUG: InjectDllViaQueuedAPC: APC injection queued.
2026-04-28 01:14:57,547 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:14:57,563 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-28 01:14:57,563 [lib.api.process] INFO: Injected into 64-bit <Process 2884 audiodg.exe>
2026-04-28 01:14:57,563 [root] DEBUG: 3368: set_hooks: Unable to hook GetCommandLineA
2026-04-28 01:14:57,672 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-28 01:14:57,688 [root] DEBUG: 2884: Python path set to 'C:\Python310'.
2026-04-28 01:14:57,688 [root] DEBUG: 3368: set_hooks: Unable to hook GetCommandLineW
2026-04-28 01:14:57,703 [root] DEBUG: 2884: Dropped file limit defaulting to 100.
2026-04-28 01:14:57,719 [root] DEBUG: 2884: Disabling sleep skipping.
2026-04-28 01:14:57,735 [root] DEBUG: 3368: Hooked 630 out of 632 functions
2026-04-28 01:14:57,735 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\Documents\logs.txt
2026-04-28 01:14:57,750 [root] DEBUG: 2884: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:14:57,782 [root] DEBUG: 3368: Syscall hook installed, syscall logging level 1
2026-04-28 01:14:57,797 [root] DEBUG: 2484: DLL loaded at 0x00007FFEFC380000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-04-28 01:14:57,797 [root] DEBUG: 2884: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:14:57,797 [root] DEBUG: 3368: RestoreHeaders: Restored original import table.
2026-04-28 01:14:57,813 [root] DEBUG: 2484: DLL loaded at 0x00007FFEFAC70000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-28 01:14:57,813 [root] DEBUG: 2884: YaraScan: Scanning 0x0000000000DD0000, size 0x200
2026-04-28 01:14:57,829 [root] INFO: Loaded monitor into process with pid 3368
2026-04-28 01:14:57,829 [root] DEBUG: 2884: Monitor initialised: 64-bit capemon loaded in process 2884 at 0x00007FFEABC40000, thread 7752, image base 0x0000000000DD0000, stack from 0x0000000001133000-0x0000000001140000
2026-04-28 01:14:57,829 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\405899223012.exe
2026-04-28 01:14:57,829 [root] DEBUG: 2884: Commandline: "C:\Users\cape\Documents\diagnostics\audiodg.exe"
2026-04-28 01:14:57,891 [root] DEBUG: 2884: hook_api: LdrpCallInitRoutine export address 0x00007FFEFE8699BC obtained via GetFunctionAddress
2026-04-28 01:14:57,891 [root] DEBUG: 3368: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 2372).
2026-04-28 01:14:57,953 [root] DEBUG: 2484: DLL loaded at 0x00007FFEF9980000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-04-28 01:14:58,000 [root] DEBUG: 3368: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-28 01:14:58,094 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-28 01:14:58,110 [root] DEBUG: 3368: caller_dispatch: Added region at 0x00400000 to tracked regions list (kernel32::SetErrorMode returns to 0x0040326C, thread 2372).
2026-04-28 01:14:58,110 [root] DEBUG: 2884: set_hooks: Unable to hook LockResource
2026-04-28 01:14:58,125 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\aqmslpGj.exe
2026-04-28 01:14:58,157 [root] DEBUG: 2884: Hooked 627 out of 628 functions
2026-04-28 01:14:58,157 [root] DEBUG: 3368: YaraScan: Scanning 0x00400000, size 0x3257e
2026-04-28 01:14:58,172 [root] DEBUG: 2884: Syscall hook installed, syscall logging level 1
2026-04-28 01:14:58,188 [root] DEBUG: 3368: YaraScan hit: NSIS
2026-04-28 01:14:58,188 [root] INFO: Loaded monitor into process with pid 2884
2026-04-28 01:14:58,188 [root] DEBUG: 3368: YaraScan match: $check (0x2d36)
2026-04-28 01:14:58,203 [root] DEBUG: 2884: caller_dispatch: Added region at 0x0000000001170000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0000000001170047, thread 7752).
2026-04-28 01:14:58,235 [root] DEBUG: 3368: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:14:58,360 [root] DEBUG: 2884: DumpPEsInRange: Scanning range 0x0000000001170000 - 0x0000000001170138.
2026-04-28 01:14:58,391 [root] DEBUG: 3368: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-28 01:14:58,391 [root] DEBUG: 2884: ScanForDisguisedPE: Size too small: 0x138 bytes
2026-04-28 01:14:58,407 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\RCX7BD8.tmp
2026-04-28 01:14:58,407 [root] DEBUG: 3368: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-28 01:14:58,407 [root] DEBUG: 3368: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-28 01:14:58,438 [root] DEBUG: 3368: DLL loaded at 0x745D0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-28 01:14:58,438 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\716242802584-theThing.exe
2026-04-28 01:14:58,469 [lib.common.results] INFO: Uploading file C:\5o722xtn\bin\aqmslpGj.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:14:58,485 [lib.common.results] INFO: Uploading file C:\XJKAvEz\CAPE\2884_337199558142227142026 to CAPE\19c99239cb5ddf8ac8dbebd35b6738eaf4566491ab0faca9c18e5d760304b063; Size is 312; Max size: 100000000
2026-04-28 01:14:58,485 [root] DEBUG: 3368: DLL loaded at 0x73CE0000: C:\Windows\SYSTEM32\SHFOLDER (0x6000 bytes).
2026-04-28 01:14:58,610 [root] DEBUG: 2884: DumpMemory: Payload successfully created: C:\XJKAvEz\CAPE\2884_337199558142227142026 (size 312 bytes)
2026-04-28 01:14:58,672 [root] DEBUG: 3368: DLL loaded at 0x76F70000: C:\Windows\System32\shcore (0x87000 bytes).
2026-04-28 01:14:58,672 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\aqmslpGj.exe
2026-04-28 01:14:58,672 [root] DEBUG: 2884: DumpRegion: Dumped entire allocation from 0x0000000001170000, size 4096 bytes.
2026-04-28 01:14:58,688 [root] DEBUG: 2884: ProcessTrackedRegion: Dumped region at 0x0000000001170000.
2026-04-28 01:14:58,703 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\405899223012.exe to files\0977acb95b52d5fee4573755cb83edf7e2ab4500c7f6fb4b149d59850e9ef47c; Size is 171008; Max size: 100000000
2026-04-28 01:14:58,703 [root] DEBUG: 3368: DLL loaded at 0x756D0000: C:\Windows\SYSTEM32\Wldp (0x27000 bytes).
2026-04-28 01:14:58,703 [root] DEBUG: 2884: YaraScan: Scanning 0x0000000001170000, size 0x138
2026-04-28 01:14:58,719 [root] DEBUG: 3368: DLL loaded at 0x75700000: C:\Windows\SYSTEM32\windows.storage (0x60d000 bytes).
2026-04-28 01:14:58,750 [root] DEBUG: 2884: DLL loaded at 0x00007FFEEF710000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei (0xaa000 bytes).
2026-04-28 01:14:58,782 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\716242802584-theThing.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:14:58,782 [root] DEBUG: 2884: set_hooks_by_export_directory: Hooked 0 out of 628 functions
2026-04-28 01:14:58,828 [root] DEBUG: 2884: DLL loaded at 0x00007FFEF9E80000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-04-28 01:14:58,844 [root] DEBUG: 3368: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 2372).
2026-04-28 01:14:58,844 [root] DEBUG: 2884: DLL loaded at 0x00007FFEF5730000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2026-04-28 01:14:58,860 [root] DEBUG: 3368: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 01:14:58,875 [root] DEBUG: 2884: DLL loaded at 0x00007FFEEF330000: C:\Windows\SYSTEM32\ucrtbase_clr0400 (0xbd000 bytes).
2026-04-28 01:14:58,875 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\197183996254.exe
2026-04-28 01:14:58,875 [root] DEBUG: 2884: DLL loaded at 0x00007FFEF2100000: C:\Windows\SYSTEM32\VCRUNTIME140_CLR0400 (0x16000 bytes).
2026-04-28 01:14:58,907 [root] DEBUG: 2884: DLL loaded at 0x00007FFEAB100000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr (0xb35000 bytes).
2026-04-28 01:14:59,000 [root] DEBUG: 3368: DLL loaded at 0x77400000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-04-28 01:14:59,016 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\197183996254.ico
2026-04-28 01:14:59,016 [root] DEBUG: 2884: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2026-04-28 01:14:59,016 [root] DEBUG: 2884: DLL loaded at 0x00007FFEA9B00000: C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\b8493bec853ac702d2188091d76ccffa\mscorlib.ni (0x1600000 bytes).
2026-04-28 01:14:59,047 [root] DEBUG: 2884: DLL loaded at 0x00007FFEFC380000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-04-28 01:14:59,172 [root] DEBUG: 2884: DLL loaded at 0x00007FFEF9980000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-04-28 01:14:59,203 [root] DEBUG: 3368: DLL loaded at 0x73C10000: C:\Windows\system32\propsys (0xc2000 bytes).
2026-04-28 01:14:59,203 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\autoit3.exe
2026-04-28 01:14:59,235 [root] DEBUG: 2884: AllocationHandler: Adding allocation to tracked region list: 0x00007FF48CE90000, size: 0xa0000.
2026-04-28 01:14:59,235 [root] DEBUG: 3368: DEBUG:Initialized 9 com hooks
2026-04-28 01:14:59,235 [root] DEBUG: 2884: GetEntropy: Error - Supplied address inaccessible: 0x00007FF48CE90000
2026-04-28 01:14:59,250 [root] DEBUG: 3368: DLL loaded at 0x77480000: C:\Windows\System32\CFGMGR32 (0x3b000 bytes).
2026-04-28 01:14:59,250 [root] DEBUG: 2884: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:14:59,266 [root] DEBUG: 2884: AllocationHandler: Memory region (size 0xa0000) reserved but not committed at 0x00007FF48CE90000.
2026-04-28 01:14:59,266 [root] DEBUG: 2884: AllocationHandler: Previously reserved region at 0x00007FF48CE90000, committing at: 0x00007FF48CE90000.
2026-04-28 01:14:59,344 [root] DEBUG: 2884: AllocationHandler: Allocation already in tracked region list: 0x00007FF48CE90000.
2026-04-28 01:14:59,516 [root] DEBUG: 3368: DLL loaded at 0x75260000: C:\Windows\SYSTEM32\profapi (0x18000 bytes).
2026-04-28 01:14:59,610 [root] DEBUG: 2884: AllocationHandler: Allocation already in tracked region list: 0x00007FF48CE90000.
2026-04-28 01:14:59,626 [root] DEBUG: 2884: AllocationHandler: Adding allocation to tracked region list: 0x00007FF48CE80000, size: 0x10000.
2026-04-28 01:14:59,641 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\RCX800F.tmp
2026-04-28 01:14:59,657 [root] DEBUG: 2884: GetEntropy: Error - Supplied address inaccessible: 0x00007FF48CE80000
2026-04-28 01:14:59,719 [root] DEBUG: 2884: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:14:59,766 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\197183996254.ico to files\0408d3291204a0715cdc90469f0cd3ab02fb0070c1c68177608818fa7f14cae1; Size is 1150; Max size: 100000000
2026-04-28 01:14:59,813 [root] DEBUG: 2884: AllocationHandler: Processing previous tracked region at: 0x00007FF48CE90000.
2026-04-28 01:14:59,891 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\850016649643-theThing.exe
2026-04-28 01:14:59,969 [root] DEBUG: 2884: DumpPEsInRange: Scanning range 0x00007FF48CE90000 - 0x00007FF48CE90066.
2026-04-28 01:15:00,094 [root] DEBUG: 3688: YaraScan hit: XWorm
2026-04-28 01:15:00,157 [root] DEBUG: 2884: ScanForDisguisedPE: Size too small: 0x66 bytes
2026-04-28 01:15:00,172 [root] DEBUG: 3688: YaraScan match: $decrypt (0x101)
2026-04-28 01:15:00,204 [lib.common.results] INFO: Uploading file C:\XJKAvEz\CAPE\2884_37000640152227142026 to CAPE\5ef272c8c97ab2f5381ee23a242051c619f7d435d016c5639362b0f3269fd76c; Size is 102; Max size: 100000000
2026-04-28 01:15:00,219 [lib.common.results] INFO: Uploading file C:\5o722xtn\bin\autoit3.exe to files\c9320142f0c71207ff11b52332dcbe2c4cf689adda0b8a1d2caf8fdeccb8d79e; Size is 838656; Max size: 100000000
2026-04-28 01:15:00,219 [root] DEBUG: 3688: Config: bp0 set to 0x000000000000010C.
2026-04-28 01:15:00,375 [root] DEBUG: 2884: DumpMemory: Payload successfully created: C:\XJKAvEz\CAPE\2884_37000640152227142026 (size 102 bytes)
2026-04-28 01:15:00,516 [root] DEBUG: 3688: Config: Action0 set to string:r10.
2026-04-28 01:15:00,625 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\autoit3.exe
2026-04-28 01:15:00,641 [root] DEBUG: 2884: DumpRegion: Dumped entire allocation from 0x00007FF48CE90000, size 4096 bytes.
2026-04-28 01:15:00,641 [root] DEBUG: 3368: DLL loaded at 0x73BE0000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-28 01:15:00,657 [root] DEBUG: 2884: ProcessTrackedRegion: Dumped region at 0x00007FF48CE90000.
2026-04-28 01:15:00,672 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\197183996254.exe to files\237d1bca6e056df5bb16a1216a434634109478f882d3b1d58344c801d184f95d; Size is 893608; Max size: 100000000
2026-04-28 01:15:00,672 [root] DEBUG: 3688: Config: Trace instruction count set to 0x1
2026-04-28 01:15:00,672 [root] INFO: Added new file to list with pid 3368 and path C:\Users\cape\AppData\Local\Temp\~nsu.tmp\Au_.exe
2026-04-28 01:15:00,688 [root] DEBUG: 2884: YaraScan: Scanning 0x00007FF48CE90000, size 0x66
2026-04-28 01:15:00,704 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\850016649643-theThing.exe to files\c9320142f0c71207ff11b52332dcbe2c4cf689adda0b8a1d2caf8fdeccb8d79e; Size is 838656; Max size: 100000000
2026-04-28 01:15:00,704 [root] DEBUG: 3688: Config: typestring set to XWorm Config
2026-04-28 01:15:00,704 [root] DEBUG: 2884: AllocationHandler: Memory region (size 0x10000) reserved but not committed at 0x00007FF48CE80000.
2026-04-28 01:15:00,719 [root] DEBUG: 3688: SetInitialBreakpoints: Breakpoint 0 set on address 0x00007FFE4BC41BDC (RVA 0x10c, type 0, hit count 0, thread 3684)
2026-04-28 01:15:00,719 [root] DEBUG: 2884: AllocationHandler: Previously reserved region at 0x00007FF48CE80000, committing at: 0x00007FF48CE80000.
2026-04-28 01:15:00,719 [root] DEBUG: 2884: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BB2D000, size: 0x1000.
2026-04-28 01:15:00,735 [root] DEBUG: 2884: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BC40000, size: 0x1000.
2026-04-28 01:15:00,735 [root] DEBUG: 2884: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:15:00,735 [root] DEBUG: 2884: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BBDC000, size: 0x1000.
2026-04-28 01:15:00,750 [root] DEBUG: 2884: GetEntropy: Error - Supplied address inaccessible: 0x00007FFE4BBD0000
2026-04-28 01:15:00,750 [root] DEBUG: 2884: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:15:00,750 [root] DEBUG: 2884: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BBD0000.
2026-04-28 01:15:00,766 [root] DEBUG: 2884: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BBD0000.
2026-04-28 01:15:00,798 [root] DEBUG: 2884: hook_api: clrjit::compileMethod export address 0x00007FFEE8675FF0 obtained via GetFunctionAddress
2026-04-28 01:15:00,798 [root] DEBUG: 2884: DLL loaded at 0x00007FFEE8670000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit (0x14f000 bytes).
2026-04-28 01:15:00,813 [root] DEBUG: 2884: .NET JIT native cache at 0x00007FFE4BC40000: scans and dumps active.
2026-04-28 01:15:00,829 [root] DEBUG: 2884: DLL loaded at 0x00007FFEA8E80000: C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni (0xc71000 bytes).
2026-04-28 01:15:00,844 [root] DEBUG: 2884: DLL loaded at 0x000000001D4D0000: C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\31326613607f69254f3284ec964796c8\System.Core.ni (0xa75000 bytes).
2026-04-28 01:15:00,844 [root] DEBUG: 2884: DLL loaded at 0x00007FFEAD090000: C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.V9921e851#\04de61553901f06e2f763b6f03a6f65a\Microsoft.VisualBasic.ni (0x225000 bytes).
2026-04-28 01:15:00,875 [root] DEBUG: 2884: ProcessTrackedRegion: .NET cache region at 0x00007FFE4BC40000 skipped
2026-04-28 01:15:00,893 [root] DEBUG: 2884: DLL loaded at 0x00007FFEFB850000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-04-28 01:15:00,907 [root] DEBUG: 2884: DLL loaded at 0x00007FFEFAFE0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-04-28 01:15:00,907 [root] DEBUG: 2884: DLL loaded at 0x00007FFEFD100000: C:\Windows\System32\psapi (0x8000 bytes).
2026-04-28 01:15:00,907 [root] DEBUG: 3368: CreateProcessHandler: Injection info set for new process 6252: C:\Users\cape\AppData\Local\Temp\~nsu.tmp\Au_.exe, ImageBase: 0x00400000
2026-04-28 01:15:00,938 [root] INFO: Announced 32-bit process name: Au_.exe pid: 6252
2026-04-28 01:15:00,938 [lib.api.process] INFO: Monitor config for <Process 6252 Au_.exe>: C:\vdyc7mjt\dll\6252.ini
2026-04-28 01:15:00,954 [lib.api.process] INFO: 32-bit DLL to inject is C:\vdyc7mjt\dll\bcxciCVv.dll, loader C:\vdyc7mjt\bin\SuLiCON.exe
2026-04-28 01:15:00,969 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\592438782002.exe
2026-04-28 01:15:00,969 [root] DEBUG: Loader: Injecting process 6252 (thread 816) with C:\vdyc7mjt\dll\bcxciCVv.dll.
2026-04-28 01:15:01,110 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:15:01,125 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\geckodriver.exe
2026-04-28 01:15:01,143 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\bcxciCVv.dll.
2026-04-28 01:15:01,157 [lib.api.process] INFO: Injected into 32-bit <Process 6252 Au_.exe>
2026-04-28 01:15:01,175 [root] DEBUG: 3368: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 01:15:01,313 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BB7C000, size: 0x1000.
2026-04-28 01:15:01,360 [root] DEBUG: 6252: Python path set to 'C:\Python310'.
2026-04-28 01:15:01,360 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\RCX8782.tmp
2026-04-28 01:15:01,360 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BB40000.
2026-04-28 01:15:01,360 [root] DEBUG: 6252: Dropped file limit defaulting to 100.
2026-04-28 01:15:01,375 [root] DEBUG: 3688: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 3684)
2026-04-28 01:15:01,391 [root] DEBUG: 6252: Disabling sleep skipping.
2026-04-28 01:15:01,391 [root] DEBUG: 6252: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:15:01,407 [root] DEBUG: 6252: YaraScan: Scanning 0x00400000, size 0x3257e
2026-04-28 01:15:01,422 [root] DEBUG: 6252: YaraScan hit: NSIS
2026-04-28 01:15:01,422 [root] DEBUG: 6252: YaraScan match: $check (0x2d36)
2026-04-28 01:15:01,422 [root] DEBUG: 6252: Monitor initialised: 32-bit capemon loaded in process 6252 at 0x73f00000, thread 816, image base 0x400000, stack from 0x195000-0x1a0000
2026-04-28 01:15:01,438 [root] DEBUG: 6252: Commandline: "C:\Users\cape\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=C:\Users\cape\AppData\Local\Temp\
2026-04-28 01:15:01,485 [root] DEBUG: 6252: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-04-28 01:15:01,547 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\770937141164-theThing.exe
2026-04-28 01:15:01,547 [root] DEBUG: 6252: hook_api: Warning - SetWindowLongW export address 0x75D45420 differs from GetProcAddress -> 0x750E59E0 (apphelp.dll::0xff3d59e0)
2026-04-28 01:15:01,563 [root] DEBUG: 3688: DebuggerOutput: Debugger logfile C:\XJKAvEz\debugger\3688.log.
2026-04-28 01:15:01,563 [root] DEBUG: 6252: hook_api: Warning - EnumDisplayDevicesA export address 0x75D395A0 differs from GetProcAddress -> 0x750E6780 (apphelp.dll::0xff3d6780)
2026-04-28 01:15:01,579 [root] DEBUG: 6252: hook_api: Warning - EnumDisplayDevicesW export address 0x75D4FB70 differs from GetProcAddress -> 0x7510E4D0 (apphelp.dll::0xff3fe4d0)
2026-04-28 01:15:01,579 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-28 01:15:01,594 [lib.common.results] INFO: Uploading file C:\5o722xtn\bin\geckodriver.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:01,657 [root] DEBUG: 6252: set_hooks: Unable to hook GetCommandLineA
2026-04-28 01:15:01,860 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-28 01:15:01,985 [root] DEBUG: 3688: StringsOutput: Output file C:\XJKAvEz\CAPE\3688.txt.
2026-04-28 01:15:02,235 [root] DEBUG: 6252: set_hooks: Unable to hook GetCommandLineW
2026-04-28 01:15:02,344 [root] DEBUG: 3688: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 3684)
2026-04-28 01:15:02,344 [root] DEBUG: 6252: Hooked 630 out of 632 functions
2026-04-28 01:15:02,360 [root] DEBUG: 3688: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 3684)
2026-04-28 01:15:02,391 [root] DEBUG: 6252: Syscall hook installed, syscall logging level 1
2026-04-28 01:15:02,391 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\geckodriver.exe
2026-04-28 01:15:02,407 [root] DEBUG: 3688: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 3684)
2026-04-28 01:15:02,407 [root] DEBUG: 6252: RestoreHeaders: Restored original import table.
2026-04-28 01:15:02,422 [root] DEBUG: 3368: NtTerminateProcess hook: Attempting to dump process 3368
2026-04-28 01:15:02,469 [root] INFO: Loaded monitor into process with pid 6252
2026-04-28 01:15:02,469 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\592438782002.exe to files\0827dc1b074d2cc32909629cd399c33bedeae82f3ca37b049655065781c318b3; Size is 3300792; Max size: 100000000
2026-04-28 01:15:02,469 [root] DEBUG: 3688: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 3684)
2026-04-28 01:15:02,485 [root] DEBUG: 3368: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-28 01:15:02,516 [root] INFO: Process with pid 3368 appears to have terminated
2026-04-28 01:15:02,532 [root] DEBUG: 6252: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 816).
2026-04-28 01:15:02,532 [root] DEBUG: 3688: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 3684)
2026-04-28 01:15:02,563 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\770937141164-theThing.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:02,563 [root] INFO: Process with pid 3368 has terminated
2026-04-28 01:15:02,610 [root] DEBUG: 6252: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-28 01:15:02,641 [root] DEBUG: 3688: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 3684)
2026-04-28 01:15:02,641 [root] DEBUG: 6252: caller_dispatch: Added region at 0x00400000 to tracked regions list (kernel32::SetErrorMode returns to 0x0040326C, thread 816).
2026-04-28 01:15:02,657 [root] DEBUG: 6252: YaraScan: Scanning 0x00400000, size 0x3257e
2026-04-28 01:15:02,672 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\306192873875.exe
2026-04-28 01:15:02,672 [root] DEBUG: 6252: YaraScan hit: NSIS
2026-04-28 01:15:02,688 [root] DEBUG: 6252: YaraScan match: $check (0x2d36)
2026-04-28 01:15:02,688 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\loader.exe
2026-04-28 01:15:02,688 [root] DEBUG: 6252: ProcessImageBase: Main module image at 0x00400000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:15:02,844 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BB20000.
2026-04-28 01:15:02,860 [root] DEBUG: 6252: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-28 01:15:02,907 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BC40000.
2026-04-28 01:15:02,907 [root] DEBUG: 6252: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-28 01:15:02,953 [root] DEBUG: 6252: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-28 01:15:02,969 [root] DEBUG: 6252: DLL loaded at 0x745D0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-28 01:15:02,985 [root] DEBUG: 6252: DLL loaded at 0x73CE0000: C:\Windows\SYSTEM32\SHFOLDER (0x6000 bytes).
2026-04-28 01:15:03,000 [root] DEBUG: 6252: DLL loaded at 0x76F70000: C:\Windows\System32\shcore (0x87000 bytes).
2026-04-28 01:15:03,016 [root] DEBUG: 6252: DLL loaded at 0x756D0000: C:\Windows\SYSTEM32\Wldp (0x27000 bytes).
2026-04-28 01:15:03,032 [root] DEBUG: 6252: DLL loaded at 0x75700000: C:\Windows\SYSTEM32\windows.storage (0x60d000 bytes).
2026-04-28 01:15:03,063 [root] DEBUG: 6252: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 816).
2026-04-28 01:15:03,063 [root] DEBUG: 6252: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 01:15:03,094 [root] DEBUG: 6252: DLL loaded at 0x77400000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-04-28 01:15:03,110 [root] DEBUG: 6252: DLL loaded at 0x73C10000: C:\Windows\system32\propsys (0xc2000 bytes).
2026-04-28 01:15:03,250 [root] DEBUG: 6252: DEBUG:Initialized 9 com hooks
2026-04-28 01:15:03,360 [root] DEBUG: 6252: DLL loaded at 0x77480000: C:\Windows\System32\CFGMGR32 (0x3b000 bytes).
2026-04-28 01:15:03,485 [root] DEBUG: 6252: DLL loaded at 0x75260000: C:\Windows\SYSTEM32\profapi (0x18000 bytes).
2026-04-28 01:15:03,500 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\RCX8E69.tmp
2026-04-28 01:15:03,875 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\212133528077-theThing.exe
2026-04-28 01:15:04,110 [root] DEBUG: 2884: YaraScan hit: XWorm
2026-04-28 01:15:04,297 [root] DEBUG: 2884: YaraScan match: $decrypt (0x101)
2026-04-28 01:15:04,375 [root] INFO: Added new file to list with pid 3688 and path C:\Users\cape\AppData\Local\winlogon
2026-04-28 01:15:04,391 [root] DEBUG: 2884: Config: bp0 set to 0x000000000000010C.
2026-04-28 01:15:04,407 [lib.common.results] INFO: Uploading file C:\5o722xtn\bin\loader.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:04,438 [root] DEBUG: 2884: Config: Action0 set to string:r10.
2026-04-28 01:15:04,610 [root] DEBUG: 2884: Config: Trace instruction count set to 0x1
2026-04-28 01:15:04,750 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFDBE0000: C:\Windows\System32\shell32 (0x743000 bytes).
2026-04-28 01:15:04,797 [root] DEBUG: 2884: Config: typestring set to XWorm Config
2026-04-28 01:15:04,797 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\loader.exe
2026-04-28 01:15:04,813 [root] DEBUG: 2884: SetInitialBreakpoints: Breakpoint 0 set on address 0x00007FFE4BC41BDC (RVA 0x10c, type 0, hit count 0, thread 7752)
2026-04-28 01:15:04,813 [root] DEBUG: 2884: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BB7C000, size: 0x1000.
2026-04-28 01:15:04,829 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\306192873875.exe to files\b840d32315a14a89e9e2dd7ae721b4f37181be64c48890a86501f9c087937823; Size is 145920; Max size: 100000000
2026-04-28 01:15:04,829 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFB900000: C:\Windows\SYSTEM32\Wldp (0x30000 bytes).
2026-04-28 01:15:04,844 [root] DEBUG: 2884: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BB40000.
2026-04-28 01:15:04,844 [root] DEBUG: 2884: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 7752)
2026-04-28 01:15:04,844 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFA080000: C:\Windows\SYSTEM32\windows.storage (0x795000 bytes).
2026-04-28 01:15:04,860 [root] DEBUG: 2884: DebuggerOutput: Debugger logfile C:\XJKAvEz\debugger\2884.log.
2026-04-28 01:15:04,875 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\212133528077-theThing.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:04,875 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFE330000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-04-28 01:15:04,907 [root] DEBUG: 2884: StringsOutput: Output file C:\XJKAvEz\CAPE\2884.txt.
2026-04-28 01:15:04,938 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\890833420823.exe
2026-04-28 01:15:04,953 [root] DEBUG: 2884: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 7752)
2026-04-28 01:15:04,969 [root] DEBUG: 2884: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 7752)
2026-04-28 01:15:04,969 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\loader_x64.exe
2026-04-28 01:15:05,049 [root] DEBUG: 2884: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 7752)
2026-04-28 01:15:05,203 [root] DEBUG: 2884: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 7752)
2026-04-28 01:15:05,219 [root] DEBUG: 2884: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 7752)
2026-04-28 01:15:05,235 [root] DEBUG: 2884: CAPEExceptionFilter: breakpoint 0 hit by instruction at 0x00007FFE4BC41BDC (thread 7752)
2026-04-28 01:15:05,547 [root] DEBUG: 2884: InitNewThreadBreakpoints: Breakpoints set for thread 7444 (handle 0x348).
2026-04-28 01:15:05,719 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFCC00000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-04-28 01:15:05,719 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\RCX9782.tmp
2026-04-28 01:15:05,735 [root] DEBUG: 2884: InitNewThreadBreakpoints: Breakpoints set for thread 5804 (handle 0x378).
2026-04-28 01:15:05,782 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\608436310720-theThing.exe
2026-04-28 01:15:05,828 [lib.common.results] INFO: Uploading file C:\5o722xtn\bin\loader_x64.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:06,016 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\loader_x64.exe
2026-04-28 01:15:06,032 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\890833420823.exe to files\a84a62144dd642dd8b7c94db6145a0855d3ea494415d6d3bc8cc8c10dd09b4ed; Size is 171008; Max size: 100000000
2026-04-28 01:15:06,047 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\608436310720-theThing.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:06,125 [root] DEBUG: 6252: DLL loaded at 0x73B70000: C:\Windows\SYSTEM32\USP10 (0x17000 bytes).
2026-04-28 01:15:06,125 [root] DEBUG: 6252: DLL loaded at 0x73B30000: C:\Windows\SYSTEM32\msls31 (0x31000 bytes).
2026-04-28 01:15:06,125 [root] DEBUG: 6252: DLL loaded at 0x73B90000: C:\Windows\SYSTEM32\RichEd20 (0x7a000 bytes).
2026-04-28 01:15:06,297 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFBD10000: C:\Windows\SYSTEM32\sxs (0xa2000 bytes).
2026-04-28 01:15:06,313 [root] INFO: Added new file to list with pid 2884 and path C:\Users\cape\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\audiodg.exe.log
2026-04-28 01:15:06,328 [root] DEBUG: 2884: DumpStrings: Uploading captured strings at C:\XJKAvEz\CAPE\2884.txt
2026-04-28 01:15:06,344 [lib.common.results] INFO: Uploading file C:\XJKAvEz\CAPE\2884.txt to CAPE\f8a2e1f4fe2ff845b2054496b039f623c95ef5ab22a049f3923c164484e99d39; Size is 96; Max size: 100000000
2026-04-28 01:15:06,344 [root] DEBUG: 2884: NtTerminateProcess hook: Attempting to dump process 2884
2026-04-28 01:15:06,360 [root] DEBUG: 2884: VerifyCodeSection: SizeOfRawData zero.
2026-04-28 01:15:06,360 [root] DEBUG: 2884: DoProcessDump: Code modification detected, dumping Imagebase at 0x0000000000DD0000.
2026-04-28 01:15:06,360 [root] DEBUG: 2884: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-28 01:15:06,375 [root] DEBUG: 2884: DumpProcess: Instantiating PeParser with address: 0x0000000000DD0000.
2026-04-28 01:15:06,375 [root] DEBUG: 2884: DumpProcess: Module entry point VA is 0x0000000000DE0F6E.
2026-04-28 01:15:06,391 [root] DEBUG: 2884: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x0000000000DD2000, section 1
2026-04-28 01:15:06,391 [root] DEBUG: 2884: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x0000000000DE2000, section 2
2026-04-28 01:15:06,391 [root] DEBUG: 2884: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x0000000000DE4000, section 3
2026-04-28 01:15:06,391 [root] DEBUG: 2884: CAPEExceptionFilter: Exception 0xc0000005 accessing 0xef70 caught at RVA 0x876e6 in capemon (expected in memory scans), passing to next handler.
2026-04-28 01:15:06,407 [root] DEBUG: 2884: reBasePEImage: Exception rebasing image from 0x0000000000DD0000 to 0x0000000000400000.
2026-04-28 01:15:06,407 [root] DEBUG: 2884: readPeSectionsFromProcess: Failed to relocate image back to header image base 0x0000000000400000.
2026-04-28 01:15:06,438 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\611488267921.exe
2026-04-28 01:15:06,563 [root] DEBUG: 2884: DumpProcess: Failed to dump image at 0x0000000000DD0000.
2026-04-28 01:15:06,563 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\PPLinject.exe
2026-04-28 01:15:06,578 [root] DEBUG: 2884: DumpImageInCurrentProcess: Failed to dump virtual PE image from 0x0000000000DD0000, dumping memory region.
2026-04-28 01:15:06,578 [root] DEBUG: 2884: DoProcessDump: Attempting raw dump of Imagebase at 0x0000000000DD0000.
2026-04-28 01:15:06,657 [lib.common.results] INFO: Uploading file C:\XJKAvEz\CAPE\2884_67730046152227142026 to procdump\4dab2988b659a4b16cb7cd640dfb8c54226855cd27dc76a7a52ed6f11b626935; Size is 512; Max size: 100000000
2026-04-28 01:15:06,672 [root] DEBUG: 2884: DumpMemory: Payload successfully created: C:\XJKAvEz\CAPE\2884_67730046152227142026 (size 512 bytes)
2026-04-28 01:15:06,688 [root] DEBUG: 2884: DumpInterestingRegions: Skipping .NET JIT native cache at 0x00007FFE4BC40000 (jit-dumps=0)
2026-04-28 01:15:06,703 [root] DEBUG: 2884: DumpPEsInRange: Scanning range 0x00007FFE4BB40000 - 0x00007FFE4BB40116.
2026-04-28 01:15:06,703 [root] DEBUG: 2884: ScanForDisguisedPE: Size too small: 0x116 bytes
2026-04-28 01:15:06,703 [lib.common.results] INFO: Uploading file C:\XJKAvEz\CAPE\2884_69625126152227142026 to CAPE\2d7b2343e2949ae1bba6ed1942642257fe0209f3e8867f7927b0c47cc6bbd0b8; Size is 278; Max size: 100000000
2026-04-28 01:15:06,735 [root] DEBUG: 2884: DumpMemory: Payload successfully created: C:\XJKAvEz\CAPE\2884_69625126152227142026 (size 278 bytes)
2026-04-28 01:15:06,735 [root] DEBUG: 2884: DumpRegion: Dumped entire allocation from 0x00007FFE4BB40000, size 4096 bytes.
2026-04-28 01:15:06,750 [root] DEBUG: 2884: ProcessTrackedRegion: Dumped region at 0x00007FFE4BB40000.
2026-04-28 01:15:06,750 [root] DEBUG: 2884: YaraScan: Scanning 0x00007FFE4BB40000, size 0x116
2026-04-28 01:15:07,032 [root] DEBUG: 6252: DLL loaded at 0x76BA0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-04-28 01:15:07,063 [root] INFO: Process with pid 2884 has terminated
2026-04-28 01:15:07,157 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\RCX9CD3.tmp
2026-04-28 01:15:07,219 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\276682945835-theThing.exe
2026-04-28 01:15:07,235 [lib.common.results] INFO: Uploading file C:\5o722xtn\bin\PPLinject.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:07,344 [root] DEBUG: 2484: api-cap: NtReadFile hook disabled due to count: 5000
2026-04-28 01:15:07,360 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\PPLinject.exe
2026-04-28 01:15:07,375 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\611488267921.exe to files\aefc987f3057b2d26e024c08fdc6607532c1bc28d89a3c5bef92117ef6bb1a9d; Size is 140800; Max size: 100000000
2026-04-28 01:15:07,407 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\276682945835-theThing.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:07,875 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\254065630230.exe
2026-04-28 01:15:08,032 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\PPLinject64.exe
2026-04-28 01:15:08,282 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF00C0000: C:\Windows\System32\MPR (0x1d000 bytes).
2026-04-28 01:15:08,328 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\RCXA290.tmp
2026-04-28 01:15:08,344 [root] DEBUG: 3688: DLL loaded at 0x00007FFEEFF10000: C:\Windows\System32\ScrRun (0x3b000 bytes).
2026-04-28 01:15:08,391 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF0800000: C:\Windows\System32\wshom.ocx (0x29000 bytes).
2026-04-28 01:15:08,469 [root] INFO: Added new file to list with pid 2484 and path C:\Users\cape\AppData\Local\Temp\PROGRA~~1\777159489083-theThing.exe
2026-04-28 01:15:08,500 [lib.common.results] INFO: Uploading file C:\5o722xtn\bin\PPLinject64.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:08,532 [root] INFO: Added new file to list with pid 2484 and path C:\5o722xtn\bin\PPLinject64.exe
2026-04-28 01:15:08,547 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\ioSpecial.ini
2026-04-28 01:15:08,547 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\254065630230.exe to files\a8e8ce929a145a0c6ba7e537da571e0f78a11b3e46820fe22ffae4c55ef26ee1; Size is 165376; Max size: 100000000
2026-04-28 01:15:08,578 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\modern-wizard.bmp
2026-04-28 01:15:08,594 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\PROGRA~~1\777159489083-theThing.exe to files\a3ff37d55acfbaebd09ae893460551583c9e16c05fedd01e3f046ee52bb3db01; Size is 837120; Max size: 100000000
2026-04-28 01:15:08,610 [root] DEBUG: 2484: Dropped file limit reached.
2026-04-28 01:15:08,735 [root] DEBUG: 3688: DEBUG:Initialized 9 com hooks
2026-04-28 01:15:09,485 [root] DEBUG: 3688: InitNewThreadBreakpoints: Breakpoints set for thread 1572 (handle 0x474).
2026-04-28 01:15:10,875 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF6F00000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-04-28 01:15:13,860 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFBFA0000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-04-28 01:15:13,985 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFBEB0000: C:\Windows\SYSTEM32\profapi (0x1f000 bytes).
2026-04-28 01:15:14,875 [root] DEBUG: 6252: DLL loaded at 0x736C0000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-28 01:15:14,938 [root] DEBUG: 6252: DLL loaded at 0x736F0000: C:\Windows\System32\CoreMessaging (0x9b000 bytes).
2026-04-28 01:15:14,985 [root] DEBUG: 6252: DLL loaded at 0x735E0000: C:\Windows\SYSTEM32\wintypes (0xdb000 bytes).
2026-04-28 01:15:15,032 [root] DEBUG: 6252: DLL loaded at 0x737F0000: C:\Windows\System32\CoreUIComponents (0x27e000 bytes).
2026-04-28 01:15:15,141 [root] DEBUG: 6252: DLL loaded at 0x73A70000: C:\Windows\SYSTEM32\textinputframework (0xb9000 bytes).
2026-04-28 01:15:16,328 [root] DEBUG: 3688: DLL loaded at 0x00007FFEEA630000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-04-28 01:15:16,344 [root] DEBUG: 3688: DLL loaded at 0x00007FFEE1D20000: C:\Windows\SYSTEM32\ntshrui (0x7d000 bytes).
2026-04-28 01:15:16,578 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF15D0000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-04-28 01:15:16,688 [root] DEBUG: 3688: DLL loaded at 0x00007FFEE7F80000: C:\Windows\SYSTEM32\cscapi (0x12000 bytes).
2026-04-28 01:15:16,750 [root] INFO: Added new file to list with pid 3688 and path C:\Users\cape\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winlogon.lnk
2026-04-28 01:15:16,813 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ๏ฟ๏ฟฒ๏ฟช๏ฟ ๏ฟง๏ฟ ๏ฟญ๏ฟฎ ๏ฟข ๏ฟค๏ฟฎ๏ฟฑ๏ฟฒ๏ฟณ๏ฟฏ๏ฟฅ.
2026-04-28 01:15:16,813 [root] DEBUG: 3688: OpenProcessHandler: Injection info created for process 5000, handle 0x580: Error obtaining target process name
2026-04-28 01:15:16,828 [root] INFO: Announced 64-bit process name: explorer.exe pid: 5000
2026-04-28 01:15:16,844 [lib.api.process] INFO: Monitor config for <Process 5000 explorer.exe>: C:\vdyc7mjt\dll\5000.ini
2026-04-28 01:15:16,860 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:15:16,875 [root] DEBUG: Loader: Injecting process 5000 with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:16,875 [root] DEBUG: 5000: Python path set to 'C:\Python310'.
2026-04-28 01:15:16,891 [root] DEBUG: 5000: Dropped file limit defaulting to 100.
2026-04-28 01:15:16,891 [root] DEBUG: 5000: Disabling sleep skipping.
2026-04-28 01:15:16,891 [root] DEBUG: 5000: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:15:16,922 [root] DEBUG: 5000: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:15:16,922 [root] DEBUG: 5000: YaraScan: Scanning 0x00007FF768FF0000, size 0x4e1114
2026-04-28 01:15:17,938 [root] DEBUG: 5000: Yara error: Scanning timed out
2026-04-28 01:15:17,953 [root] DEBUG: 5000: Monitor initialised: 64-bit capemon loaded in process 5000 at 0x00007FFEABC40000, thread 2468, image base 0x00007FF768FF0000, stack from 0x0000000002B52000-0x0000000002B60000
2026-04-28 01:15:17,953 [root] DEBUG: 5000: Commandline: C:\Windows\Explorer.EXE
2026-04-28 01:15:17,985 [root] DEBUG: 5000: hook_api: LdrpCallInitRoutine export address 0x00007FFEFE8699BC obtained via GetFunctionAddress
2026-04-28 01:15:18,156 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-28 01:15:18,156 [root] DEBUG: 5000: set_hooks: Unable to hook LockResource
2026-04-28 01:15:18,266 [root] DEBUG: 5000: Hooked 627 out of 628 functions
2026-04-28 01:15:19,297 [root] DEBUG: 5000: Yara error: Scanning timed out
2026-04-28 01:15:19,313 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\InstallOptions.dll
2026-04-28 01:15:19,313 [root] DEBUG: 5000: Syscall hook installed, syscall logging level 1
2026-04-28 01:15:19,313 [root] INFO: Loaded monitor into process with pid 5000
2026-04-28 01:15:19,328 [root] DEBUG: 5000: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-04-28 01:15:19,344 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-28 01:15:19,344 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:19,360 [lib.api.process] INFO: Injected into 64-bit <Process 5000 explorer.exe>
2026-04-28 01:15:19,453 [root] DEBUG: 5000: OpenProcessHandler: Injection info created for process 6252, handle 0xea8: C:\Users\cape\AppData\Local\Temp\~nsu.tmp\Au_.exe
2026-04-28 01:15:19,469 [root] DEBUG: 6252: DLL loaded at 0x769C0000: C:\Windows\System32\comdlg32 (0xaf000 bytes).
2026-04-28 01:15:19,469 [root] DEBUG: 5000: caller_dispatch: Added region at 0x00007FF768FF0000 to tracked regions list (ntdll::NtQueryInformationThread returns to 0x00007FF7690147C9, thread 5004).
2026-04-28 01:15:19,469 [root] DEBUG: 6252: ProtectionHandler: Adding region at 0x10003000 to tracked regions.
2026-04-28 01:15:19,485 [root] DEBUG: 5000: YaraScan: Scanning 0x00007FF768FF0000, size 0x4e1114
2026-04-28 01:15:19,485 [root] DEBUG: 6252: DLL loaded at 0x10000000: C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\InstallOptions (0x9000 bytes).
2026-04-28 01:15:19,578 [root] DEBUG: 5000: ProcessImageBase: Main module image at 0x00007FF768FF0000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:15:20,172 [root] INFO: Added new file to list with pid 5000 and path C:\Users\cape\AppData\Local\Microsoft\Windows\Caches\cversions.3.db
2026-04-28 01:15:20,438 [root] DEBUG: 3688: DLL loaded at 0x00007FFEACC40000: C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\915c1ee906bd8dfc15398a4bab4acb48\System.Configuration.ni (0x133000 bytes).
2026-04-28 01:15:20,453 [root] DEBUG: 2484: api-cap: NtWriteFile hook disabled due to count: 5000
2026-04-28 01:15:20,594 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BB20000.
2026-04-28 01:15:20,703 [root] DEBUG: 3688: DLL loaded at 0x00007FFEA7B50000: C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\db3df155ec9c0595b0198c4487f36ca1\System.Xml.ni (0x8ab000 bytes).
2026-04-28 01:15:20,719 [root] DEBUG: 5000: DEBUG:Initialized 9 com hooks
2026-04-28 01:15:20,813 [root] DEBUG: 5000: OpenProcessHandler: Image base for process 6252 (handle 0xdd8): 0x0000000000400000.
2026-04-28 01:15:21,157 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BB40000.
2026-04-28 01:15:21,188 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001d.db to files\fd2dfe41298319309d3953067073d60a37c120d83599b564bf914d3752c8f34f; Size is 83240; Max size: 100000000
2026-04-28 01:15:21,203 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001e.db to files\e1ba3f65ac9ce41c1d71a46fec6a3e72d37542db86bdc8c9f8c0995fe1e093bc; Size is 81024; Max size: 100000000
2026-04-28 01:15:21,219 [root] INFO: Added new file to list with pid 5000 and path C:\Users\cape\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001e.db
2026-04-28 01:15:22,219 [root] DEBUG: 6252: DLL loaded at 0x73540000: C:\Windows\SYSTEM32\TextShaping (0x94000 bytes).
2026-04-28 01:15:22,453 [root] DEBUG: 3688: DLL loaded at 0x00007FFEEF6D0000: C:\Windows\SYSTEM32\rasman (0x34000 bytes).
2026-04-28 01:15:22,703 [root] DEBUG: 3688: DLL loaded at 0x00007FFEE7DC0000: C:\Windows\SYSTEM32\rasapi32 (0xff000 bytes).
2026-04-28 01:15:22,797 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001d.db to files\fd2dfe41298319309d3953067073d60a37c120d83599b564bf914d3752c8f34f; Size is 83240; Max size: 100000000
2026-04-28 01:15:23,703 [root] DEBUG: 3688: DLL loaded at 0x00007FFEEFF70000: C:\Windows\SYSTEM32\rtutils (0x16000 bytes).
2026-04-28 01:15:24,063 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFB660000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-04-28 01:15:24,281 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BC40000.
2026-04-28 01:15:24,688 [root] DEBUG: 3688: InitNewThreadBreakpoints: Breakpoints set for thread 4304 (handle 0x5fc).
2026-04-28 01:15:24,797 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF5C20000: C:\Windows\SYSTEM32\winhttp (0x10a000 bytes).
2026-04-28 01:15:25,219 [root] DEBUG: 3688: DLL loaded at 0x00007FFEE1150000: C:\Windows\system32\OnDemandConnRouteHelper (0x17000 bytes).
2026-04-28 01:15:25,219 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFB350000: C:\Windows\SYSTEM32\IPHLPAPI (0x3b000 bytes).
2026-04-28 01:15:25,375 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFE580000: C:\Windows\System32\NSI (0x8000 bytes).
2026-04-28 01:15:25,438 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF5F30000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-04-28 01:15:25,485 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF5F10000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-04-28 01:15:25,563 [root] DEBUG: 3688: InitNewThreadBreakpoints: Breakpoints set for thread 3972 (handle 0x678).
2026-04-28 01:15:25,735 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BB3E000, size: 0x1000.
2026-04-28 01:15:25,797 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ๏ฟ๏ฟฒ๏ฟช๏ฟ ๏ฟง๏ฟ ๏ฟญ๏ฟฎ ๏ฟข ๏ฟค๏ฟฎ๏ฟฑ๏ฟฒ๏ฟณ๏ฟฏ๏ฟฅ.
2026-04-28 01:15:25,828 [root] DEBUG: 5000: OpenProcessHandler: Injection info created for process 5904, handle 0xf70: Error obtaining target process name
2026-04-28 01:15:25,828 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ๏ฟ๏ฟฒ๏ฟช๏ฟ ๏ฟง๏ฟ ๏ฟญ๏ฟฎ ๏ฟข ๏ฟค๏ฟฎ๏ฟฑ๏ฟฒ๏ฟณ๏ฟฏ๏ฟฅ.
2026-04-28 01:15:25,844 [root] DEBUG: 5000: OpenProcessHandler: Injection info created for process 5728, handle 0xdfc: Error obtaining target process name
2026-04-28 01:15:26,031 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFB3A0000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-04-28 01:15:26,250 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF52E0000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-04-28 01:15:26,297 [modules.auxiliary.human] INFO: Found button "uninstall", clicking it
2026-04-28 01:15:26,297 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF5D30000: C:\Windows\System32\fwpuclnt (0x80000 bytes).
2026-04-28 01:15:26,531 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BB30000.
2026-04-28 01:15:26,750 [root] DEBUG: 3688: DLL loaded at 0x00007FFEF5250000: C:\Windows\SYSTEM32\secur32 (0xc000 bytes).
2026-04-28 01:15:27,235 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFAF00000: C:\Windows\system32\schannel (0x98000 bytes).
2026-04-28 01:15:27,344 [root] DEBUG: 3688: DLL loaded at 0x00007FFEE8180000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-04-28 01:15:27,469 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFB930000: C:\Windows\SYSTEM32\NTASN1 (0x3b000 bytes).
2026-04-28 01:15:27,485 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFB970000: C:\Windows\SYSTEM32\ncrypt (0x27000 bytes).
2026-04-28 01:15:27,657 [root] DEBUG: 3688: DLL loaded at 0x00007FFEE84C0000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-04-28 01:15:27,906 [root] DEBUG: 3688: DLL loaded at 0x00007FFEFBA90000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-04-28 01:15:28,016 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BCD0000, size: 0x1000.
2026-04-28 01:15:28,032 [root] DEBUG: 3688: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:15:28,157 [root] DEBUG: 3688: AllocationHandler: Adding allocation to tracked region list: 0x00007FFE4BCE0000, size: 0x1000.
2026-04-28 01:15:28,235 [root] DEBUG: 5000: DLL loaded at 0x00007FFEACA80000: C:\Windows\System32\cdprt (0x1bb000 bytes).
2026-04-28 01:15:28,313 [root] DEBUG: 3688: AddTrackedRegion: GetEntropy failed.
2026-04-28 01:15:28,360 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\nsExec.dll
2026-04-28 01:15:28,656 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BCE0000.
2026-04-28 01:15:28,672 [root] DEBUG: 6252: ProtectionHandler: Adding region at 0x04D01000 to tracked regions.
2026-04-28 01:15:28,688 [root] DEBUG: 6252: DLL loaded at 0x04D00000: C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\nsExec (0x5000 bytes).
2026-04-28 01:15:28,797 [root] DEBUG: 6252: CreateProcessHandler: Injection info set for new process 6028: C:\Windows\system32\taskkill.exe, ImageBase: 0x00D80000
2026-04-28 01:15:28,797 [root] INFO: Announced 32-bit process name: taskkill.exe pid: 6028
2026-04-28 01:15:28,797 [lib.api.process] INFO: Monitor config for <Process 6028 taskkill.exe>: C:\vdyc7mjt\dll\6028.ini
2026-04-28 01:15:29,047 [lib.api.process] INFO: 32-bit DLL to inject is C:\vdyc7mjt\dll\bcxciCVv.dll, loader C:\vdyc7mjt\bin\SuLiCON.exe
2026-04-28 01:15:29,344 [root] DEBUG: Loader: Injecting process 6028 (thread 4488) with C:\vdyc7mjt\dll\bcxciCVv.dll.
2026-04-28 01:15:29,360 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:15:29,391 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\bcxciCVv.dll.
2026-04-28 01:15:29,407 [lib.api.process] INFO: Injected into 32-bit <Process 6028 taskkill.exe>
2026-04-28 01:15:29,422 [root] DEBUG: 6252: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 01:15:29,469 [root] DEBUG: 5000: OpenProcessHandler: Injection info created for process 4800, handle 0x121c: C:\Windows\System32\conhost.exe
2026-04-28 01:15:29,953 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BCE0000.
2026-04-28 01:15:30,078 [root] DEBUG: 6028: Python path set to 'C:\Python310'.
2026-04-28 01:15:30,157 [root] DEBUG: 5000: DLL loaded at 0x00007FFEDC910000: C:\Windows\System32\icu (0x22e000 bytes).
2026-04-28 01:15:30,297 [root] DEBUG: 6028: Dropped file limit defaulting to 100.
2026-04-28 01:15:30,938 [root] DEBUG: 6028: Disabling sleep skipping.
2026-04-28 01:15:31,031 [root] DEBUG: 6028: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:15:31,031 [root] DEBUG: 6028: YaraScan: Scanning 0x00D80000, size 0x14e4e
2026-04-28 01:15:31,047 [root] DEBUG: 6028: Monitor initialised: 32-bit capemon loaded in process 6028 at 0x73f00000, thread 4488, image base 0xd80000, stack from 0x3235000-0x3240000
2026-04-28 01:15:31,125 [root] DEBUG: 6028: Commandline: "C:\Windows\system32\taskkill.exe" /im loopBeAudio.exe /f /t
2026-04-28 01:15:31,281 [root] DEBUG: 6028: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-04-28 01:15:31,453 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-28 01:15:31,563 [root] DEBUG: 6028: set_hooks: Unable to hook GetCommandLineA
2026-04-28 01:15:31,610 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-28 01:15:31,657 [root] DEBUG: 6028: set_hooks: Unable to hook GetCommandLineW
2026-04-28 01:15:31,797 [root] DEBUG: 6028: Hooked 630 out of 632 functions
2026-04-28 01:15:31,844 [root] DEBUG: 6028: Syscall hook installed, syscall logging level 1
2026-04-28 01:15:31,922 [root] DEBUG: 6028: RestoreHeaders: Restored original import table.
2026-04-28 01:15:32,000 [root] INFO: Loaded monitor into process with pid 6028
2026-04-28 01:15:32,297 [root] DEBUG: 6028: caller_dispatch: Added region at 0x00D80000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00D8DCBB, thread 4488).
2026-04-28 01:15:32,578 [root] DEBUG: 6028: YaraScan: Scanning 0x00D80000, size 0x14e4e
2026-04-28 01:15:32,657 [root] DEBUG: 6028: ProcessImageBase: Main module image at 0x00D80000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:15:32,657 [root] DEBUG: 6028: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-04-28 01:15:32,672 [root] DEBUG: 6028: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-28 01:15:32,672 [root] DEBUG: 6028: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-28 01:15:32,688 [lib.api.process] INFO: Monitor config for <Process 752 svchost.exe>: C:\vdyc7mjt\dll\752.ini
2026-04-28 01:15:32,703 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:15:32,860 [root] DEBUG: Loader: Injecting process 752 with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:32,891 [root] DEBUG: 752: Python path set to 'C:\Python310'.
2026-04-28 01:15:32,906 [root] DEBUG: 752: Disabling sleep skipping.
2026-04-28 01:15:32,906 [root] DEBUG: 752: Dropped file limit defaulting to 100.
2026-04-28 01:15:33,032 [root] DEBUG: 752: Services hook set enabled
2026-04-28 01:15:33,063 [root] DEBUG: 752: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:15:33,094 [root] DEBUG: 752: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:15:33,110 [root] DEBUG: 752: Monitor initialised: 64-bit capemon loaded in process 752 at 0x00007FFEABC40000, thread 496, image base 0x00007FF7AB6E0000, stack from 0x000000AE373F4000-0x000000AE37400000
2026-04-28 01:15:33,110 [root] DEBUG: 3688: InitNewThreadBreakpoints: Breakpoints set for thread 1952 (handle 0x7f0).
2026-04-28 01:15:33,110 [root] DEBUG: 752: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-04-28 01:15:33,172 [root] DEBUG: 752: Hooked 69 out of 69 functions
2026-04-28 01:15:33,250 [root] DEBUG: 3688: AllocationHandler: Allocation already in tracked region list: 0x00007FFE4BCE0000.
2026-04-28 01:15:33,282 [root] INFO: Loaded monitor into process with pid 752
2026-04-28 01:15:33,406 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-28 01:15:33,406 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:33,422 [lib.api.process] INFO: Injected into 64-bit <Process 752 svchost.exe>
2026-04-28 01:15:34,563 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,578 [root] DEBUG: 6252: ProcessTrackedRegion: Region at 0x04D00000 mapped as \Device\HarddiskVolume1\Users\cape\AppData\Local\Temp\nscA3F4.tmp\nsExec.dll is in known range, skipping
2026-04-28 01:15:34,610 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,625 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,625 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,641 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,641 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,641 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,657 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,657 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,657 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,657 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,719 [root] INFO: Process with pid 6028 has terminated
2026-04-28 01:15:34,719 [root] INFO: Process lock is locked
2026-04-28 01:15:34,891 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\System.dll
2026-04-28 01:15:35,282 [root] DEBUG: 6252: DLL loaded at 0x04D00000: C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\System (0x6000 bytes).
2026-04-28 01:15:35,422 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\loopBeAu.sys
2026-04-28 01:15:35,500 [lib.api.process] INFO: Monitor config for <Process 5940 svchost.exe>: C:\vdyc7mjt\dll\5940.ini
2026-04-28 01:15:35,516 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\loopBeAu.inf
2026-04-28 01:15:35,610 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:15:35,750 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\loopbeau.cat
2026-04-28 01:15:35,953 [root] DEBUG: Loader: Injecting process 5940 with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:35,969 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\difxapi.dll
2026-04-28 01:15:35,969 [root] DEBUG: 5940: Python path set to 'C:\Python310'.
2026-04-28 01:15:35,985 [root] DEBUG: 5940: Disabling sleep skipping.
2026-04-28 01:15:35,985 [root] DEBUG: 5940: Dropped file limit defaulting to 100.
2026-04-28 01:15:36,000 [root] DEBUG: 5940: Services hook set enabled
2026-04-28 01:15:36,000 [root] DEBUG: 5940: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:15:36,110 [root] DEBUG: 5940: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:15:36,125 [root] INFO: Added new file to list with pid 6252 and path C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\drvinst.exe
2026-04-28 01:15:36,141 [root] DEBUG: 5940: Monitor initialised: 64-bit capemon loaded in process 5940 at 0x00007FFEABC40000, thread 2760, image base 0x00007FF7AB6E0000, stack from 0x0000008DECD75000-0x0000008DECD80000
2026-04-28 01:15:36,141 [root] DEBUG: 6252: ProtectionHandler: Adding region at 0x04D11000 to tracked regions.
2026-04-28 01:15:36,141 [root] DEBUG: 5940: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-04-28 01:15:36,141 [root] DEBUG: 6252: DLL loaded at 0x04D10000: C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\nsExec (0x5000 bytes).
2026-04-28 01:15:36,172 [root] DEBUG: 5940: Hooked 69 out of 69 functions
2026-04-28 01:15:36,188 [root] INFO: Loaded monitor into process with pid 5940
2026-04-28 01:15:36,188 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-28 01:15:36,188 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:36,219 [lib.api.process] INFO: Injected into 64-bit <Process 5940 svchost.exe>
2026-04-28 01:15:36,813 [root] DEBUG: 6252: CreateProcessHandler: Injection info set for new process 3388: C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\drvinst.exe, ImageBase: 0x00000000
2026-04-28 01:15:36,953 [root] INFO: Announced 64-bit process name: drvinst.exe pid: 3388
2026-04-28 01:15:36,953 [lib.api.process] INFO: Monitor config for <Process 3388 drvinst.exe>: C:\vdyc7mjt\dll\3388.ini
2026-04-28 01:15:40,578 [lib.api.process] INFO: Potential dll side-loading detected in local directory: difxapi.dll
2026-04-28 01:15:40,594 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:15:40,782 [root] DEBUG: Loader: Injecting process 3388 (thread 3860) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:40,907 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:15:41,094 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:41,125 [lib.api.process] INFO: Injected into 64-bit <Process 3388 drvinst.exe>
2026-04-28 01:15:41,141 [root] DEBUG: 6252: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-28 01:15:41,235 [root] DEBUG: 5000: OpenProcessHandler: Injection info created for process 8144, handle 0x1274: C:\Windows\System32\conhost.exe
2026-04-28 01:15:41,703 [root] DEBUG: 3388: Python path set to 'C:\Python310'.
2026-04-28 01:15:41,719 [root] DEBUG: 3388: Dropped file limit defaulting to 100.
2026-04-28 01:15:41,719 [root] DEBUG: 3388: Disabling sleep skipping.
2026-04-28 01:15:41,719 [root] DEBUG: 3388: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:15:41,875 [root] DEBUG: 3388: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:15:41,907 [root] DEBUG: 3388: YaraScan: Scanning 0x00007FF708830000, size 0x39a86
2026-04-28 01:15:42,032 [root] DEBUG: 3388: Monitor initialised: 64-bit capemon loaded in process 3388 at 0x00007FFEABC40000, thread 3860, image base 0x00007FF708830000, stack from 0x0000005CF76F4000-0x0000005CF7700000
2026-04-28 01:15:42,281 [root] DEBUG: 3388: Commandline: "C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\drvinst.exe" "C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\loopBeAu.inf" *LoopBeAu uninstall
2026-04-28 01:15:42,344 [root] DEBUG: 5000: DLL loaded at 0x00007FFEECE40000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-04-28 01:15:42,391 [root] DEBUG: 3388: hook_api: LdrpCallInitRoutine export address 0x00007FFEFE8699BC obtained via GetFunctionAddress
2026-04-28 01:15:42,516 [root] DEBUG: 752: CreateProcessHandler: Injection info set for new process 6348: C:\Windows\System32\SecurityHealthHost.exe, ImageBase: 0x00007FF7B2120000
2026-04-28 01:15:42,641 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-28 01:15:42,782 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 6348
2026-04-28 01:15:42,907 [lib.api.process] INFO: Monitor config for <Process 6348 SecurityHealthHost.exe>: C:\vdyc7mjt\dll\6348.ini
2026-04-28 01:15:43,000 [root] DEBUG: 3388: set_hooks: Unable to hook LockResource
2026-04-28 01:15:43,016 [root] DEBUG: 3388: Hooked 627 out of 628 functions
2026-04-28 01:15:43,016 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:15:43,016 [root] DEBUG: 3388: Syscall hook installed, syscall logging level 1
2026-04-28 01:15:43,047 [root] DEBUG: 3388: RestoreHeaders: Restored original import table.
2026-04-28 01:15:43,047 [root] DEBUG: Loader: Injecting process 6348 (thread 4568) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:43,047 [root] INFO: Loaded monitor into process with pid 3388
2026-04-28 01:15:43,063 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:15:43,063 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:43,078 [lib.api.process] INFO: Injected into 64-bit <Process 6348 SecurityHealthHost.exe>
2026-04-28 01:15:43,094 [root] INFO: Announced 64-bit process name: SecurityHealthHost.exe pid: 6348
2026-04-28 01:15:43,110 [lib.api.process] INFO: Monitor config for <Process 6348 SecurityHealthHost.exe>: C:\vdyc7mjt\dll\6348.ini
2026-04-28 01:15:43,125 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:15:43,156 [root] DEBUG: 3388: caller_dispatch: Added region at 0x00007FF708830000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x00007FF708840D97, thread 3860).
2026-04-28 01:15:43,172 [root] DEBUG: Loader: Injecting process 6348 (thread 4568) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:43,172 [root] DEBUG: 3388: YaraScan: Scanning 0x00007FF708830000, size 0x39a86
2026-04-28 01:15:43,188 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-04-28 01:15:43,266 [root] DEBUG: 3388: ProcessImageBase: Main module image at 0x00007FF708830000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:15:43,297 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:43,313 [lib.api.process] INFO: Injected into 64-bit <Process 6348 SecurityHealthHost.exe>
2026-04-28 01:15:43,453 [root] DEBUG: 3388: NtTerminateProcess hook: Attempting to dump process 3388
2026-04-28 01:15:43,469 [root] DEBUG: 6348: Python path set to 'C:\Python310'.
2026-04-28 01:15:43,469 [root] DEBUG: 3388: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-28 01:15:43,485 [root] DEBUG: 6348: Dropped file limit defaulting to 100.
2026-04-28 01:15:43,500 [root] INFO: Process with pid 3388 has terminated
2026-04-28 01:15:43,594 [root] DEBUG: 6348: Disabling sleep skipping.
2026-04-28 01:15:43,610 [root] DEBUG: 6348: YaraInit: Compiled rules loaded from existing file C:\vdyc7mjt\data\yara\capemon.yac
2026-04-28 01:15:43,672 [root] DEBUG: 6348: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500
2026-04-28 01:15:43,797 [root] DEBUG: 6348: YaraScan: Scanning 0x00007FF7B2120000, size 0x19174
2026-04-28 01:15:43,953 [root] DEBUG: 6348: Monitor initialised: 64-bit capemon loaded in process 6348 at 0x00007FFEABC40000, thread 4568, image base 0x00007FF7B2120000, stack from 0x000000044FB64000-0x000000044FB70000
2026-04-28 01:15:44,110 [root] DEBUG: 6348: Commandline: C:\Windows\System32\SecurityHealthHost.exe {08728914-3F57-4D52-9E31-49DAECA5A80A} -Embedding
2026-04-28 01:15:44,188 [root] DEBUG: 6348: hook_api: LdrpCallInitRoutine export address 0x00007FFEFE8699BC obtained via GetFunctionAddress
2026-04-28 01:15:44,250 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-28 01:15:44,266 [root] DEBUG: 6348: set_hooks: Unable to hook LockResource
2026-04-28 01:15:44,313 [root] DEBUG: 6348: Hooked 627 out of 628 functions
2026-04-28 01:15:44,313 [root] DEBUG: 6348: Syscall hook installed, syscall logging level 1
2026-04-28 01:15:44,328 [root] DEBUG: 6348: RestoreHeaders: Restored original import table.
2026-04-28 01:15:44,328 [root] INFO: Loaded monitor into process with pid 6348
2026-04-28 01:15:44,328 [root] DEBUG: 6348: caller_dispatch: Added region at 0x00007FF7B2120000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7B212D3B2, thread 4568).
2026-04-28 01:15:44,344 [root] DEBUG: 6348: YaraScan: Scanning 0x00007FF7B2120000, size 0x19174
2026-04-28 01:15:44,344 [root] DEBUG: 6348: ProcessImageBase: Main module image at 0x00007FF7B2120000 unmodified (entropy change 0.000000e+00)
2026-04-28 01:15:44,360 [root] DEBUG: 6348: set_hooks_by_export_directory: Hooked 0 out of 628 functions
2026-04-28 01:15:44,360 [root] DEBUG: 6348: DLL loaded at 0x00007FFEF9E80000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-04-28 01:15:44,375 [root] DEBUG: 6348: DLL loaded at 0x00007FFEFC380000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-04-28 01:15:44,391 [root] DEBUG: 6348: DEBUG:Initialized 9 com hooks
2026-04-28 01:15:44,407 [root] DEBUG: 6348: DLL loaded at 0x00007FFEFCC00000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-04-28 01:15:44,547 [root] DEBUG: 6348: DLL loaded at 0x00007FFEFDBE0000: C:\Windows\System32\SHELL32 (0x743000 bytes).
2026-04-28 01:15:44,563 [root] DEBUG: 6348: DLL loaded at 0x00007FFEFB900000: C:\Windows\system32\Wldp (0x30000 bytes).
2026-04-28 01:15:44,563 [root] DEBUG: 6348: DLL loaded at 0x00007FFEFAC70000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-28 01:15:44,594 [root] DEBUG: 6348: DLL loaded at 0x00007FFEEF060000: C:\Windows\system32\SecurityHealthAgent (0x6d000 bytes).
2026-04-28 01:15:44,672 [root] DEBUG: 6348: DLL loaded at 0x00007FFEECE40000: C:\Windows\system32\SecurityHealthProxyStub (0x1f000 bytes).
2026-04-28 01:15:44,750 [root] DEBUG: 6348: DLL loaded at 0x00007FFEE7170000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2026-04-28 01:15:44,860 [root] DEBUG: 6348: DLL loaded at 0x00007FFEFE330000: C:\Windows\System32\shcore (0xad000 bytes).
2026-04-28 01:15:45,094 [root] DEBUG: 6348: DLL loaded at 0x00007FFEF8C40000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes).
2026-04-28 01:15:45,220 [root] DEBUG: 2484: api-rate-cap: FindNextFileW hook disabled due to rate
2026-04-28 01:15:45,266 [root] DEBUG: 6348: DLL loaded at 0x00007FFEF9CA0000: C:\Windows\System32\RMCLIENT (0x2a000 bytes).
2026-04-28 01:15:45,281 [root] DEBUG: 6348: DLL loaded at 0x00007FFEF60C0000: C:\Windows\System32\XmlLite (0x36000 bytes).
2026-04-28 01:15:45,360 [root] DEBUG: 6348: DLL loaded at 0x00007FFEEF4B0000: C:\Windows\System32\twinapi.appcore (0x200000 bytes).
2026-04-28 01:15:45,406 [root] DEBUG: 6348: DLL loaded at 0x00007FFEE32A0000: C:\Windows\System32\wpnapps (0x156000 bytes).
2026-04-28 01:15:45,422 [root] DEBUG: 6348: DLL loaded at 0x00007FFEF7A20000: C:\Windows\SYSTEM32\usermgrcli (0x16000 bytes).
2026-04-28 01:15:45,469 [root] DEBUG: 6348: DLL loaded at 0x00007FFEF09F0000: C:\Windows\System32\OneCoreUAPCommonProxyStub (0x7c9000 bytes).
2026-04-28 01:15:45,531 [root] DEBUG: 6348: DLL loaded at 0x00007FFEE1060000: C:\Windows\System32\ShellCommonCommonProxyStub (0xd0000 bytes).
2026-04-28 01:15:46,110 [root] DEBUG: 6348: DLL loaded at 0x00007FFEFA080000: C:\Windows\SYSTEM32\windows.storage (0x795000 bytes).
2026-04-28 01:15:46,203 [root] DEBUG: 5000: AllocationHandler: Adding allocation to tracked region list: 0x00007DF442EB1000, size: 0x1000.
2026-04-28 01:15:46,282 [root] DEBUG: 6348: NtTerminateProcess hook: Attempting to dump process 6348
2026-04-28 01:15:46,406 [root] DEBUG: 5000: AllocationHandler: Adding allocation to tracked region list: 0x00007DF442EA1000, size: 0x1000.
2026-04-28 01:15:46,422 [root] DEBUG: 752: CreateProcessHandler: Injection info set for new process 5372: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe, ImageBase: 0x00007FF76BCF0000
2026-04-28 01:15:46,438 [root] DEBUG: 6348: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-28 01:15:46,453 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 5372
2026-04-28 01:15:46,516 [lib.api.process] INFO: Monitor config for <Process 5372 ShellExperienceHost.exe>: C:\vdyc7mjt\dll\5372.ini
2026-04-28 01:15:46,610 [root] INFO: Process with pid 6348 has terminated
2026-04-28 01:15:46,766 [root] DEBUG: 5000: AllocationHandler: Adding allocation to tracked region list: 0x00007DF442E91000, size: 0x1000.
2026-04-28 01:15:46,938 [root] DEBUG: 5000: AllocationHandler: Adding allocation to tracked region list: 0x00007DF442E81000, size: 0x1000.
2026-04-28 01:15:47,157 [root] DEBUG: 5000: FreeHandler: Address: 0x00007DF442EA0000.
2026-04-28 01:15:47,157 [root] DEBUG: 5000: ScanForNonZero: Error - Supplied size zero.
2026-04-28 01:15:47,172 [root] DEBUG: 5000: DropTrackedRegion: removed region at 0x00007DF442EA0000 from tracked region list.
2026-04-28 01:15:47,188 [root] DEBUG: 5000: FreeHandler: Address: 0x00007DF442E80000.
2026-04-28 01:15:47,188 [root] DEBUG: 5000: ScanForNonZero: Error - Supplied size zero.
2026-04-28 01:15:47,188 [root] DEBUG: 5000: DropTrackedRegion: removed region at 0x00007DF442E80000 from the end of the tracked region list.
2026-04-28 01:15:47,219 [root] DEBUG: 5000: FreeHandler: Address: 0x00007DF442E90000.
2026-04-28 01:15:47,219 [root] DEBUG: 5000: ScanForNonZero: Error - Supplied size zero.
2026-04-28 01:15:47,235 [root] DEBUG: 5000: DropTrackedRegion: removed region at 0x00007DF442E90000 from the end of the tracked region list.
2026-04-28 01:15:47,250 [root] DEBUG: 5000: FreeHandler: Address: 0x00007DF442EB0000.
2026-04-28 01:15:47,282 [root] DEBUG: 5000: ScanForNonZero: Error - Supplied size zero.
2026-04-28 01:15:47,282 [root] DEBUG: 5000: DropTrackedRegion: removed region at 0x00007DF442EB0000 from the end of the tracked region list.
2026-04-28 01:15:47,297 [root] DEBUG: 5000: AllocationHandler: Adding allocation to tracked region list: 0x00007DF442EB1000, size: 0x1000.
2026-04-28 01:15:47,313 [root] DEBUG: 5000: AllocationHandler: Adding allocation to tracked region list: 0x00007DF442EA1000, size: 0x1000.
2026-04-28 01:15:47,344 [root] DEBUG: 5000: FreeHandler: Address: 0x00007DF442EA0000.
2026-04-28 01:15:47,360 [root] DEBUG: 5000: ScanForNonZero: Error - Supplied size zero.
2026-04-28 01:15:47,360 [root] DEBUG: 5000: DropTrackedRegion: removed region at 0x00007DF442EA0000 from the end of the tracked region list.
2026-04-28 01:15:47,547 [root] DEBUG: 5000: FreeHandler: Address: 0x00007DF442EB0000.
2026-04-28 01:15:47,641 [root] DEBUG: 5000: ScanForNonZero: Error - Supplied size zero.
2026-04-28 01:15:47,657 [root] DEBUG: 5000: DropTrackedRegion: removed region at 0x00007DF442EB0000 from the end of the tracked region list.
2026-04-28 01:15:48,266 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:15:48,500 [root] DEBUG: Loader: Injecting process 5372 (thread 5816) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:48,625 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:15:48,625 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:48,657 [lib.api.process] INFO: Injected into 64-bit <Process 5372 ShellExperienceHost.exe>
2026-04-28 01:15:48,688 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 5372
2026-04-28 01:15:48,688 [lib.api.process] INFO: Monitor config for <Process 5372 ShellExperienceHost.exe>: C:\vdyc7mjt\dll\5372.ini
2026-04-28 01:15:49,188 [modules.auxiliary.human] INFO: Found button "finish", clicking it
2026-04-28 01:15:50,422 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\EoqgWis.dll, loader C:\vdyc7mjt\bin\jbmtltnx.exe
2026-04-28 01:15:50,828 [root] DEBUG: Loader: Injecting process 5372 (thread 5816) with C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:50,891 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-28 01:15:51,188 [root] DEBUG: 5940: DEBUG:Initialized 9 com hooks
2026-04-28 01:15:51,282 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\EoqgWis.dll.
2026-04-28 01:15:51,391 [lib.api.process] INFO: Injected into 64-bit <Process 5372 ShellExperienceHost.exe>
2026-04-28 01:15:51,391 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\difxapi.dll to files\7a1f158bbab2c3616464891bd90a94318877c976c0177b34ec8d9b59b5253114; Size is 383600; Max size: 100000000
2026-04-28 01:15:51,813 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 5372
2026-04-28 01:15:51,828 [lib.api.process] INFO: Monitor config for <Process 5372 ShellExperienceHost.exe>: C:\vdyc7mjt\dll\5372.ini
2026-04-28 01:15:51,922 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\drvinst.exe to files\9f8e20e94add395570dc2178d755e131ce47dff7f7dab2a899e7f06609fec847; Size is 214016; Max size: 100000000
2026-04-28 01:15:51,953 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\InstallOptions.dll to files\c9cd5c9609e70005926ae5171726a4142ffbcccc771d307efcd195dafc1e6b4b; Size is 14848; Max size: 100000000
2026-04-28 01:15:51,969 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\ioSpecial.ini to files\052b9e95aed0a1c13552d6299719502b858a7f066956c65a117bb55d80d46aa1; Size is 873; Max size: 100000000
2026-04-28 01:15:52,000 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\loopbeau.cat to files\d35545bf0b0c441eaeea6f7f3ff501035b45453592f4fbaf3e9ee75d46911b5a; Size is 7987; Max size: 100000000
2026-04-28 01:15:52,016 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\loopBeAu.inf to files\333d44917ef712a3ad87de11e06fdc34c4dd257bcdbf33e90ee98532baa7ccf1; Size is 4261; Max size: 100000000
2026-04-28 01:15:52,047 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\loopBeAu.sys to files\1d8645d64220a990447a786f84bbb4dbcb044135fe2b0ad47cf3d767e1d4e788; Size is 22528; Max size: 100000000
2026-04-28 01:15:52,078 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\modern-wizard.bmp to files\3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2; Size is 26494; Max size: 100000000
2026-04-28 01:15:52,110 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\nsExec.dll to files\168a974eaa3f588d759db3f47c1a9fdc3494ba1fa1a73a84e5e3b2a4d58abd7e; Size is 6656; Max size: 100000000
2026-04-28 01:15:52,125 [lib.common.results] INFO: Uploading file C:\Users\cape\AppData\Local\Temp\nscA3F4.tmp\System.dll to files\dc58d8ad81cacb0c1ed72e33bff8f23ea40b5252b5bb55d393a0903e6819ae2f; Size is 11264; Max size: 100000000
2026-04-28 01:15:52,203 [root] INFO: Received shutdown request
2026-04-28 01:15:52,203 [root] DEBUG: 5000: OpenProcessHandler: Image base for process 6832 (handle 0x41c): 0x00007FF7568A0000.
2026-04-28 01:15:52,235 [root] DEBUG: 5000: OpenProcessHandler: Injection info created for process 6832, handle 0x41c: C:\Windows\System32\conhost.exe
2026-04-28 01:15:52,297 [root] DEBUG: 6252: DLL loaded at 0x75200000: C:\Windows\SYSTEM32\WINSTA (0x47000 bytes).
2026-04-28 01:15:52,328 [root] DEBUG: 6252: NtTerminateProcess hook: Attempting to dump process 6252
2026-04-28 01:15:52,344 [root] DEBUG: 6252: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-28 01:15:52,344 [root] DEBUG: 6252: DumpPEsInRange: Scanning range 0x04D10000 - 0x04D12FFF.
2026-04-28 01:15:52,344 [root] DEBUG: 6252: ScanForDisguisedPE: No PE image located in range 0x04D10000-0x04D12FFF.
2026-04-28 01:15:52,453 [lib.common.results] INFO: Uploading file C:\XJKAvEz\CAPE\6252_930960052152227142026 to CAPE\834fff42a6a1800c89156b5bbdd75cff207c13c2cbf0b90a44f117e7a0d8f3a3; Size is 12287; Max size: 100000000
2026-04-28 01:15:52,594 [root] DEBUG: 6252: DumpMemory: Payload successfully created: C:\XJKAvEz\CAPE\6252_930960052152227142026 (size 12287 bytes)
2026-04-28 01:15:52,610 [root] DEBUG: 6252: DumpRegion: Dumped entire allocation from 0x04D10000, size 12288 bytes.
2026-04-28 01:15:52,625 [root] DEBUG: 6252: ProcessTrackedRegion: Dumped region at 0x04D10000.
2026-04-28 01:15:52,703 [root] DEBUG: 6252: YaraScan: Scanning 0x04D10000, size 0x2fff