{
  "statistics": {
    "processing": [
      {
        "name": "CAPE",
        "time": 5.361
      },
      {
        "name": "AnalysisInfo",
        "time": 0.065
      },
      {
        "name": "BehaviorAnalysis",
        "time": 0.017
      },
      {
        "name": "Debug",
        "time": 0.002
      },
      {
        "name": "NetworkAnalysis",
        "time": 10.221
      },
      {
        "name": "Suricata",
        "time": 11.136
      },
      {
        "name": "UrlAnalysis",
        "time": 0.0
      },
      {
        "name": "script_log_processing",
        "time": 0.0
      },
      {
        "name": "ProcessMemory",
        "time": 0.0
      }
    ],
    "signatures": [
      {
        "name": "packer_themida",
        "time": 0.0
      },
      {
        "name": "stealth_network",
        "time": 0.0
      },
      {
        "name": "disable_driver_via_blocklist",
        "time": 0.0
      },
      {
        "name": "disable_driver_via_hvcidisallowedimages",
        "time": 0.0
      },
      {
        "name": "disable_hypervisor_protected_code_integrity",
        "time": 0.0
      },
      {
        "name": "pendingfilerenameoperations_Operations",
        "time": 0.0
      },
      {
        "name": "anomalous_deletefile",
        "time": 0.0
      },
      {
        "name": "antiav_360_libs",
        "time": 0.0
      },
      {
        "name": "antiav_ahnlab_libs",
        "time": 0.0
      },
      {
        "name": "antiav_avast_libs",
        "time": 0.0
      },
      {
        "name": "antiav_bitdefender_libs",
        "time": 0.0
      },
      {
        "name": "antiav_bullguard_libs",
        "time": 0.0
      },
      {
        "name": "antiav_emsisoft_libs",
        "time": 0.0
      },
      {
        "name": "antiav_qurb_libs",
        "time": 0.0
      },
      {
        "name": "antiav_servicestop",
        "time": 0.0
      },
      {
        "name": "antiav_apioverride_libs",
        "time": 0.0
      },
      {
        "name": "antidebug_guardpages",
        "time": 0.0
      },
      {
        "name": "antiav_nthookengine_libs",
        "time": 0.0
      },
      {
        "name": "antidebug_outputdebugstring",
        "time": 0.0
      },
      {
        "name": "antidebug_windows",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoo",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoocrash",
        "time": 0.0
      },
      {
        "name": "antisandbox_foregroundwindows",
        "time": 0.0
      },
      {
        "name": "mouse_movement_detect",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_libs",
        "time": 0.0
      },
      {
        "name": "antisandbox_script_timer",
        "time": 0.0
      },
      {
        "name": "antisandbox_sleep",
        "time": 0.0
      },
      {
        "name": "antisandbox_sunbelt_libs",
        "time": 0.0
      },
      {
        "name": "antisandbox_unhook",
        "time": 0.0
      },
      {
        "name": "antivm_directory_objects",
        "time": 0.0
      },
      {
        "name": "antivm_display",
        "time": 0.0
      },
      {
        "name": "antivm_generic_disk",
        "time": 0.0
      },
      {
        "name": "antivm_generic_system",
        "time": 0.0
      },
      {
        "name": "antivm_checks_available_memory",
        "time": 0.0
      },
      {
        "name": "detect_virtualization_via_recent_files",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_libs",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_events",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_libs",
        "time": 0.0
      },
      {
        "name": "antivm_wmi",
        "time": 0.0
      },
      {
        "name": "api_spamming",
        "time": 0.0
      },
      {
        "name": "api_uuidfromstringa",
        "time": 0.0
      },
      {
        "name": "bcdedit_command",
        "time": 0.0
      },
      {
        "name": "bootkit",
        "time": 0.0
      },
      {
        "name": "direct_hdd_access",
        "time": 0.0
      },
      {
        "name": "physical_drive_access",
        "time": 0.0
      },
      {
        "name": "potential_overwrite_mbr",
        "time": 0.0
      },
      {
        "name": "read_file_raw_disk_access",
        "time": 0.0
      },
      {
        "name": "suspicious_iocontrol_codes",
        "time": 0.0
      },
      {
        "name": "browser_needed",
        "time": 0.0
      },
      {
        "name": "regsvr32_squiblydoo_dll_load",
        "time": 0.0
      },
      {
        "name": "uac_bypass_cmstp",
        "time": 0.0
      },
      {
        "name": "uac_bypass_eventvwr",
        "time": 0.0
      },
      {
        "name": "uac_bypass_windows_Backup",
        "time": 0.0
      },
      {
        "name": "dotnet_code_compile",
        "time": 0.0
      },
      {
        "name": "queries_computer_name",
        "time": 0.0
      },
      {
        "name": "queries_user_name",
        "time": 0.0
      },
      {
        "name": "creates_largekey",
        "time": 0.0
      },
      {
        "name": "creates_nullvalue",
        "time": 0.0
      },
      {
        "name": "access_windows_passwords_vault",
        "time": 0.0
      },
      {
        "name": "lsass_credential_dumping",
        "time": 0.0
      },
      {
        "name": "critical_process",
        "time": 0.0
      },
      {
        "name": "cryptopool_domains",
        "time": 0.0
      },
      {
        "name": "dead_connect",
        "time": 0.0
      },
      {
        "name": "dead_link",
        "time": 0.0
      },
      {
        "name": "decoy_document",
        "time": 0.0
      },
      {
        "name": "decoy_image",
        "time": 0.0
      },
      {
        "name": "deletes_consolehost_history",
        "time": 0.0
      },
      {
        "name": "dep_bypass",
        "time": 0.0
      },
      {
        "name": "dep_disable",
        "time": 0.0
      },
      {
        "name": "disables_wfp",
        "time": 0.0
      },
      {
        "name": "add_windows_defender_exclusions",
        "time": 0.0
      },
      {
        "name": "mountpoints_volume_discovery",
        "time": 0.0
      },
      {
        "name": "dll_load_uncommon_file_types",
        "time": 0.0
      },
      {
        "name": "document_script_exe_drop",
        "time": 0.0
      },
      {
        "name": "guloader_apis",
        "time": 0.0
      },
      {
        "name": "driver_load",
        "time": 0.0
      },
      {
        "name": "dynamic_function_loading",
        "time": 0.0
      },
      {
        "name": "encrypted_ioc",
        "time": 0.0
      },
      {
        "name": "exec_crash",
        "time": 0.0
      },
      {
        "name": "process_creation_suspicious_location",
        "time": 0.0
      },
      {
        "name": "exploit_getbasekerneladdress",
        "time": 0.0
      },
      {
        "name": "exploit_gethaldispatchtable",
        "time": 0.0
      },
      {
        "name": "exploit_heapspray",
        "time": 0.0
      },
      {
        "name": "koadic_apis",
        "time": 0.0
      },
      {
        "name": "koadic_network_activity",
        "time": 0.0
      },
      {
        "name": "downloads_from_filehosting",
        "time": 0.0
      },
      {
        "name": "generic_phish",
        "time": 0.0
      },
      {
        "name": "http_request",
        "time": 0.0
      },
      {
        "name": "infostealer_browser",
        "time": 0.0
      },
      {
        "name": "infostealer_browser_password",
        "time": 0.0
      },
      {
        "name": "infostealer_cookies",
        "time": 0.0
      },
      {
        "name": "cryptbot_network",
        "time": 0.0
      },
      {
        "name": "purplewave_network_activity",
        "time": 0.0
      },
      {
        "name": "quilclipper_behavior",
        "time": 0.0
      },
      {
        "name": "raccoon_behavior",
        "time": 0.0
      },
      {
        "name": "captures_screenshot",
        "time": 0.0
      },
      {
        "name": "vidar_behavior",
        "time": 0.0
      },
      {
        "name": "injection_createremotethread",
        "time": 0.0
      },
      {
        "name": "creates_suspended_process",
        "time": 0.0
      },
      {
        "name": "injection_explorer",
        "time": 0.0
      },
      {
        "name": "injection_network_traffic",
        "time": 0.0
      },
      {
        "name": "injection_runpe",
        "time": 0.0
      },
      {
        "name": "injection_rwx",
        "time": 0.0
      },
      {
        "name": "injection_themeinitapihook",
        "time": 0.0
      },
      {
        "name": "resumethread_remote_process",
        "time": 0.0
      },
      {
        "name": "injection_write_exe_process",
        "time": 0.0
      },
      {
        "name": "injection_write_process",
        "time": 0.0
      },
      {
        "name": "internet_dropper",
        "time": 0.0
      },
      {
        "name": "escalate_privilege_via_named_pipe",
        "time": 0.0
      },
      {
        "name": "ipc_namedpipe",
        "time": 0.0
      },
      {
        "name": "js_phish",
        "time": 0.0
      },
      {
        "name": "js_suspicious_redirect",
        "time": 0.0
      },
      {
        "name": "loader_alien",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_internet_explorer_exporter",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_run_exe_helper_utility",
        "time": 0.0
      },
      {
        "name": "execute_ps_via_syncappvpublishingserver",
        "time": 0.0
      },
      {
        "name": "malicious_dynamic_function_loading",
        "time": 0.0
      },
      {
        "name": "encrypt_pcinfo",
        "time": 0.0
      },
      {
        "name": "encrypt_data_agenttesla_http",
        "time": 0.0
      },
      {
        "name": "encrypt_data_agentteslat2_http",
        "time": 0.0
      },
      {
        "name": "encrypt_data_nanocore",
        "time": 0.0
      },
      {
        "name": "reads_memory_remote_process",
        "time": 0.0
      },
      {
        "name": "mimics_filetime",
        "time": 0.0
      },
      {
        "name": "amsi_bypass_via_com_registry",
        "time": 0.0
      },
      {
        "name": "access_auto_logons_via_registry",
        "time": 0.0
      },
      {
        "name": "access_boot_key_via_registry",
        "time": 0.0
      },
      {
        "name": "create_suspicious_lnk_files",
        "time": 0.0
      },
      {
        "name": "credential_access_via_windows_credential_history",
        "time": 0.0
      },
      {
        "name": "dll_hijacking_via_microsoft_exchange",
        "time": 0.0
      },
      {
        "name": "dll_hijacking_via_waas_medic_svc_com_typelib",
        "time": 0.0
      },
      {
        "name": "execute_file_downloaded_via_openssh",
        "time": 0.0
      },
      {
        "name": "execute_safe_mode_from_suspicious_process",
        "time": 0.0
      },
      {
        "name": "execute_scripts_via_microsoft_management_console",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_processes_via_windows_mssql_service",
        "time": 0.0
      },
      {
        "name": "execution_from_self_extracting_archive",
        "time": 0.0
      },
      {
        "name": "ip_address_discovery_via_trusted_program",
        "time": 0.0
      },
      {
        "name": "load_dll_via_control_panel",
        "time": 0.0
      },
      {
        "name": "network_connection_via_suspicious_process",
        "time": 0.0
      },
      {
        "name": "potential_location_discovery_via_unusual_process",
        "time": 0.0
      },
      {
        "name": "store_executable_registry",
        "time": 0.0
      },
      {
        "name": "Suspicious_Execution_Via_MicrosoftExchangeTransportAgent",
        "time": 0.0
      },
      {
        "name": "suspicious_java_execution_via_win_scripts",
        "time": 0.0
      },
      {
        "name": "Suspicious_Scheduled_Task_Creation_Via_Masqueraded_XML_File",
        "time": 0.0
      },
      {
        "name": "uses_restart_manager_for_suspicious_activities",
        "time": 0.0
      },
      {
        "name": "modify_desktop_wallpaper",
        "time": 0.0
      },
      {
        "name": "move_file_on_reboot",
        "time": 0.0
      },
      {
        "name": "multiple_useragents",
        "time": 0.0
      },
      {
        "name": "network_anomaly",
        "time": 0.0
      },
      {
        "name": "network_bind",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_archive",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_free_webhosting",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_generic",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_interactsh",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_opensource",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_pastesite",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_payload",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_serviceinterface",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_socialmedia",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_telegram",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_tempstorage",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_temp_urldns",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_urlshortener",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_useragent",
        "time": 0.0
      },
      {
        "name": "network_cnc_smtps_exfil",
        "time": 0.0
      },
      {
        "name": "network_cnc_smtps_generic",
        "time": 0.0
      },
      {
        "name": "network_dns_idn",
        "time": 0.0
      },
      {
        "name": "network_dns_suspicious_querytype",
        "time": 0.0
      },
      {
        "name": "network_dns_tunneling_request",
        "time": 0.0
      },
      {
        "name": "network_document_http",
        "time": 0.0
      },
      {
        "name": "explorer_http",
        "time": 0.0
      },
      {
        "name": "network_fake_useragent",
        "time": 0.0
      },
      {
        "name": "legitimate_domain_abuse",
        "time": 0.0
      },
      {
        "name": "suspicious_communication_trusted_site",
        "time": 0.0
      },
      {
        "name": "network_tor",
        "time": 0.0
      },
      {
        "name": "office_com_load",
        "time": 0.0
      },
      {
        "name": "office_dotnet_load",
        "time": 0.0
      },
      {
        "name": "office_mshtml_load",
        "time": 0.0
      },
      {
        "name": "office_vb_load",
        "time": 0.0
      },
      {
        "name": "office_wmi_load",
        "time": 0.0
      },
      {
        "name": "office_cve2017_11882",
        "time": 0.0
      },
      {
        "name": "office_cve2017_11882_network",
        "time": 0.0
      },
      {
        "name": "office_cve_2021_40444",
        "time": 0.0
      },
      {
        "name": "office_cve_2021_40444_m2",
        "time": 0.0
      },
      {
        "name": "office_flash_load",
        "time": 0.0
      },
      {
        "name": "office_postscript",
        "time": 0.0
      },
      {
        "name": "office_suspicious_processes",
        "time": 0.0
      },
      {
        "name": "office_write_exe",
        "time": 0.0
      },
      {
        "name": "persistence_via_autodial_dll_registry",
        "time": 0.0
      },
      {
        "name": "persistence_autorun",
        "time": 0.0
      },
      {
        "name": "persistence_autorun_tasks",
        "time": 0.0
      },
      {
        "name": "persistence_bootexecute",
        "time": 0.0
      },
      {
        "name": "persistence_registry_script",
        "time": 0.0
      },
      {
        "name": "powershell_network_connection",
        "time": 0.0
      },
      {
        "name": "powershell_download",
        "time": 0.0
      },
      {
        "name": "powershell_request",
        "time": 0.0
      },
      {
        "name": "createtoolhelp32snapshot_module_enumeration",
        "time": 0.0
      },
      {
        "name": "enumerates_running_processes",
        "time": 0.0
      },
      {
        "name": "process_interest",
        "time": 0.0
      },
      {
        "name": "process_needed",
        "time": 0.0
      },
      {
        "name": "mass_data_encryption",
        "time": 0.0
      },
      {
        "name": "ransomware_file_modifications",
        "time": 0.0
      },
      {
        "name": "ransomware_message",
        "time": 0.0
      },
      {
        "name": "nemty_network_activity",
        "time": 0.0
      },
      {
        "name": "nemty_note",
        "time": 0.0
      },
      {
        "name": "sodinokibi_behavior",
        "time": 0.0
      },
      {
        "name": "stop_ransomware_registry",
        "time": 0.0
      },
      {
        "name": "blackrat_apis",
        "time": 0.0
      },
      {
        "name": "blackrat_network_activity",
        "time": 0.0
      },
      {
        "name": "blackrat_registry_keys",
        "time": 0.0
      },
      {
        "name": "dcrat_behavior",
        "time": 0.0
      },
      {
        "name": "karagany_system_event_objects",
        "time": 0.0
      },
      {
        "name": "rat_luminosity",
        "time": 0.0
      },
      {
        "name": "rat_nanocore",
        "time": 0.0
      },
      {
        "name": "netwire_behavior",
        "time": 0.0
      },
      {
        "name": "obliquerat_network_activity",
        "time": 0.0
      },
      {
        "name": "orcusrat_behavior",
        "time": 0.0
      },
      {
        "name": "trochilusrat_apis",
        "time": 0.0
      },
      {
        "name": "reads_self",
        "time": 0.0
      },
      {
        "name": "recon_beacon",
        "time": 0.0
      },
      {
        "name": "recon_programs",
        "time": 0.0
      },
      {
        "name": "recon_systeminfo",
        "time": 0.0
      },
      {
        "name": "accesses_recyclebin",
        "time": 0.0
      },
      {
        "name": "remcos_shell_code_dynamic_wrapper_x",
        "time": 0.0
      },
      {
        "name": "script_created_process",
        "time": 0.0
      },
      {
        "name": "script_network_activity",
        "time": 0.0
      },
      {
        "name": "suspicious_js_script",
        "time": 0.0
      },
      {
        "name": "javascript_timer",
        "time": 0.0
      },
      {
        "name": "secure_login_phishing",
        "time": 0.0
      },
      {
        "name": "securityxploded_modules",
        "time": 0.0
      },
      {
        "name": "get_clipboard_data",
        "time": 0.0
      },
      {
        "name": "sets_autoconfig_url",
        "time": 0.0
      },
      {
        "name": "spoofs_procname",
        "time": 0.0
      },
      {
        "name": "stack_pivot",
        "time": 0.0
      },
      {
        "name": "stack_pivot_file_created",
        "time": 0.0
      },
      {
        "name": "stack_pivot_process_create",
        "time": 0.0
      },
      {
        "name": "set_clipboard_data",
        "time": 0.0
      },
      {
        "name": "stealth_childproc",
        "time": 0.0
      },
      {
        "name": "stealth_file",
        "time": 0.0
      },
      {
        "name": "stealth_timeout",
        "time": 0.0
      },
      {
        "name": "stealth_window",
        "time": 0.0
      },
      {
        "name": "queries_keyboard_layout",
        "time": 0.0
      },
      {
        "name": "queries_locale_api",
        "time": 0.0
      },
      {
        "name": "terminates_remote_process",
        "time": 0.0
      },
      {
        "name": "uiautomationcore_load",
        "time": 0.0
      },
      {
        "name": "user_enum",
        "time": 0.0
      },
      {
        "name": "mmc_dll_script_load",
        "time": 0.0
      },
      {
        "name": "mmc_dotnet_load",
        "time": 0.0
      },
      {
        "name": "virus",
        "time": 0.0
      },
      {
        "name": "neshta_files",
        "time": 0.0
      },
      {
        "name": "neshta_regkeys",
        "time": 0.0
      },
      {
        "name": "webmail_phish",
        "time": 0.0
      },
      {
        "name": "persists_dev_util",
        "time": 0.0
      },
      {
        "name": "spawns_dev_util",
        "time": 0.0
      },
      {
        "name": "alters_windows_utility",
        "time": 0.0
      },
      {
        "name": "overwrites_accessibility_utility",
        "time": 0.0
      },
      {
        "name": "Potential_Lateral_Movement_Via_SMBEXEC",
        "time": 0.0
      },
      {
        "name": "potential_WebShell_Via_ScreenConnectServer",
        "time": 0.0
      },
      {
        "name": "uses_Microsoft_HTML_Help_Executable",
        "time": 0.0
      },
      {
        "name": "wiper_zeroedbytes",
        "time": 0.0
      },
      {
        "name": "wmi_create_process",
        "time": 0.0
      },
      {
        "name": "wmi_script_process",
        "time": 0.0
      },
      {
        "name": "antianalysis_tls_section",
        "time": 0.0
      },
      {
        "name": "antivirus_clamav",
        "time": 0.0
      },
      {
        "name": "antivirus_virustotal",
        "time": 0.0
      },
      {
        "name": "bad_certs",
        "time": 0.0
      },
      {
        "name": "bad_ssl_certs",
        "time": 0.0
      },
      {
        "name": "banker_zeus_p2p",
        "time": 0.0
      },
      {
        "name": "banker_zeus_url",
        "time": 0.0
      },
      {
        "name": "binary_yara",
        "time": 0.0
      },
      {
        "name": "bot_athenahttp",
        "time": 0.0
      },
      {
        "name": "bot_dirtjumper",
        "time": 0.0
      },
      {
        "name": "bot_drive",
        "time": 0.0
      },
      {
        "name": "bot_drive2",
        "time": 0.0
      },
      {
        "name": "bot_madness",
        "time": 0.0
      },
      {
        "name": "phishing_kit_detected",
        "time": 0.0
      },
      {
        "name": "family_proxyback",
        "time": 0.0
      },
      {
        "name": "flare_capa_antianalysis",
        "time": 0.0
      },
      {
        "name": "flare_capa_collection",
        "time": 0.0
      },
      {
        "name": "flare_capa_communication",
        "time": 0.0
      },
      {
        "name": "flare_capa_compiler",
        "time": 0.0
      },
      {
        "name": "flare_capa_datamanipulation",
        "time": 0.0
      },
      {
        "name": "flare_capa_executable",
        "time": 0.0
      },
      {
        "name": "flare_capa_hostinteraction",
        "time": 0.0
      },
      {
        "name": "flare_capa_impact",
        "time": 0.0
      },
      {
        "name": "flare_capa_lib",
        "time": 0.0
      },
      {
        "name": "flare_capa_linking",
        "time": 0.0
      },
      {
        "name": "flare_capa_loadcode",
        "time": 0.0
      },
      {
        "name": "flare_capa_malwarefamily",
        "time": 0.0
      },
      {
        "name": "flare_capa_nursery",
        "time": 0.0
      },
      {
        "name": "flare_capa_persistence",
        "time": 0.0
      },
      {
        "name": "flare_capa_runtime",
        "time": 0.0
      },
      {
        "name": "flare_capa_targeting",
        "time": 0.0
      },
      {
        "name": "threatfox",
        "time": 0.0
      },
      {
        "name": "log4shell",
        "time": 0.0
      },
      {
        "name": "mimics_extension",
        "time": 0.0
      },
      {
        "name": "network_country_distribution",
        "time": 0.0
      },
      {
        "name": "network_cnc_http",
        "time": 0.004
      },
      {
        "name": "network_ip_exe",
        "time": 0.0
      },
      {
        "name": "network_dga",
        "time": 0.0
      },
      {
        "name": "network_dga_fraunhofer",
        "time": 0.0
      },
      {
        "name": "network_dyndns",
        "time": 0.003
      },
      {
        "name": "network_excessive_udp",
        "time": 0.0
      },
      {
        "name": "network_http",
        "time": 0.002
      },
      {
        "name": "network_icmp",
        "time": 0.0
      },
      {
        "name": "network_irc",
        "time": 0.0
      },
      {
        "name": "network_open_proxy",
        "time": 0.001
      },
      {
        "name": "network_questionable_http_path",
        "time": 0.0
      },
      {
        "name": "network_questionable_https_path",
        "time": 0.0
      },
      {
        "name": "network_smtp",
        "time": 0.0
      },
      {
        "name": "network_torgateway",
        "time": 0.001
      },
      {
        "name": "origin_langid",
        "time": 0.0
      },
      {
        "name": "origin_resource_langid",
        "time": 0.0
      },
      {
        "name": "overlay",
        "time": 0.0
      },
      {
        "name": "packer_unknown_pe_section_name",
        "time": 0.0
      },
      {
        "name": "packer_aspack",
        "time": 0.0
      },
      {
        "name": "packer_aspirecrypt",
        "time": 0.0
      },
      {
        "name": "packer_bedsprotector",
        "time": 0.0
      },
      {
        "name": "packer_confuser",
        "time": 0.0
      },
      {
        "name": "packer_enigma",
        "time": 0.0
      },
      {
        "name": "packer_entropy",
        "time": 0.0
      },
      {
        "name": "packer_mpress",
        "time": 0.0
      },
      {
        "name": "packer_nate",
        "time": 0.0
      },
      {
        "name": "packer_nspack",
        "time": 0.0
      },
      {
        "name": "packer_smartassembly",
        "time": 0.0
      },
      {
        "name": "packer_spices",
        "time": 0.0
      },
      {
        "name": "packer_themida",
        "time": 0.0
      },
      {
        "name": "packer_titan",
        "time": 0.0
      },
      {
        "name": "packer_upx",
        "time": 0.0
      },
      {
        "name": "packer_vmprotect",
        "time": 0.0
      },
      {
        "name": "packer_yoda",
        "time": 0.0
      },
      {
        "name": "pdf_annot_urls_checker",
        "time": 0.0
      },
      {
        "name": "polymorphic",
        "time": 0.0
      },
      {
        "name": "punch_plus_plus_pcres",
        "time": 0.0
      },
      {
        "name": "procmem_yara",
        "time": 0.0
      },
      {
        "name": "recon_checkip",
        "time": 0.0
      },
      {
        "name": "static_authenticode",
        "time": 0.0
      },
      {
        "name": "invalid_authenticode_signature",
        "time": 0.0
      },
      {
        "name": "static_dotnet_anomaly",
        "time": 0.0
      },
      {
        "name": "static_java",
        "time": 0.0
      },
      {
        "name": "static_pdf",
        "time": 0.0
      },
      {
        "name": "contains_pe_overlay",
        "time": 0.0
      },
      {
        "name": "static_pe_anomaly",
        "time": 0.0
      },
      {
        "name": "pe_compile_timestomping",
        "time": 0.0
      },
      {
        "name": "static_pe_pdbpath",
        "time": 0.0
      },
      {
        "name": "static_rat_config",
        "time": 0.0
      },
      {
        "name": "static_versioninfo_anomaly",
        "time": 0.0
      },
      {
        "name": "suricata_alert",
        "time": 0.0
      },
      {
        "name": "suspicious_html_body",
        "time": 0.0
      },
      {
        "name": "suspicious_html_name",
        "time": 0.0
      },
      {
        "name": "suspicious_html_title",
        "time": 0.0
      },
      {
        "name": "volatility_devicetree_1",
        "time": 0.0
      },
      {
        "name": "volatility_handles_1",
        "time": 0.0
      },
      {
        "name": "volatility_ldrmodules_1",
        "time": 0.0
      },
      {
        "name": "volatility_ldrmodules_2",
        "time": 0.0
      },
      {
        "name": "volatility_malfind_1",
        "time": 0.0
      },
      {
        "name": "volatility_malfind_2",
        "time": 0.0
      },
      {
        "name": "volatility_modscan_1",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_1",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_2",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_3",
        "time": 0.0
      },
      {
        "name": "whois_create",
        "time": 0.0
      },
      {
        "name": "accesses_mailslot",
        "time": 0.0
      },
      {
        "name": "accesses_netlogon_regkey",
        "time": 0.0
      },
      {
        "name": "accesses_public_folder",
        "time": 0.0
      },
      {
        "name": "accesses_sysvol",
        "time": 0.0
      },
      {
        "name": "writes_sysvol",
        "time": 0.0
      },
      {
        "name": "adds_admin_user",
        "time": 0.0
      },
      {
        "name": "adds_user",
        "time": 0.0
      },
      {
        "name": "overwrites_admin_password",
        "time": 0.0
      },
      {
        "name": "antianalysis_detectfile",
        "time": 0.002
      },
      {
        "name": "antianalysis_detectreg",
        "time": 0.001
      },
      {
        "name": "modify_attachment_manager",
        "time": 0.0
      },
      {
        "name": "antiav_detectfile",
        "time": 0.004
      },
      {
        "name": "antiav_detectreg",
        "time": 0.005
      },
      {
        "name": "antiav_srp",
        "time": 0.0
      },
      {
        "name": "antiav_whitespace",
        "time": 0.0
      },
      {
        "name": "antidebug_devices",
        "time": 0.001
      },
      {
        "name": "antiemu_windefend",
        "time": 0.0
      },
      {
        "name": "antiemu_wine_reg",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoo_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_fortinet_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_joe_anubis_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_mutex",
        "time": 0.0
      },
      {
        "name": "antisandbox_sunbelt_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_threattrack_files",
        "time": 0.0
      },
      {
        "name": "antivm_bochs_keys",
        "time": 0.0
      },
      {
        "name": "antivm_generic_bios",
        "time": 0.0
      },
      {
        "name": "antivm_generic_diskreg",
        "time": 0.0
      },
      {
        "name": "antivm_hyperv_keys",
        "time": 0.0
      },
      {
        "name": "antivm_parallels_keys",
        "time": 0.0
      },
      {
        "name": "antivm_recentdocs",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_devices",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_files",
        "time": 0.002
      },
      {
        "name": "antivm_vbox_keys",
        "time": 0.001
      },
      {
        "name": "antivm_vmware_devices",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_files",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_keys",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_mutexes",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_files",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_keys",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_mutex",
        "time": 0.0
      },
      {
        "name": "antivm_xen_keys",
        "time": 0.0
      },
      {
        "name": "asyncrat_mutex",
        "time": 0.0
      },
      {
        "name": "gulpix_behavior",
        "time": 0.0
      },
      {
        "name": "ketrican_regkeys",
        "time": 0.0
      },
      {
        "name": "okrum_mutexes",
        "time": 0.0
      },
      {
        "name": "banker_cridex",
        "time": 0.0
      },
      {
        "name": "geodo_banking_trojan",
        "time": 0.001
      },
      {
        "name": "banker_spyeye_mutexes",
        "time": 0.0
      },
      {
        "name": "banker_zeus_mutex",
        "time": 0.0
      },
      {
        "name": "bitcoin_opencl",
        "time": 0.0
      },
      {
        "name": "enumerates_physical_drives",
        "time": 0.0
      },
      {
        "name": "bot_russkill",
        "time": 0.0
      },
      {
        "name": "browser_addon",
        "time": 0.0
      },
      {
        "name": "chromium_browser_extension_directory",
        "time": 0.0
      },
      {
        "name": "browser_helper_object",
        "time": 0.0
      },
      {
        "name": "browser_security",
        "time": 0.001
      },
      {
        "name": "browser_startpage",
        "time": 0.0
      },
      {
        "name": "ie_disables_process_tab",
        "time": 0.0
      },
      {
        "name": "odbcconf_bypass",
        "time": 0.0
      },
      {
        "name": "squiblydoo_bypass",
        "time": 0.0
      },
      {
        "name": "squiblytwo_bypass",
        "time": 0.0
      },
      {
        "name": "bypass_chromium_protection",
        "time": 0.0
      },
      {
        "name": "bypass_firewall",
        "time": 0.0
      },
      {
        "name": "checks_uac_status",
        "time": 0.0
      },
      {
        "name": "uac_bypass_cmstpcom",
        "time": 0.0
      },
      {
        "name": "uac_bypass_delegateexecute_sdclt",
        "time": 0.0
      },
      {
        "name": "uac_bypass_fodhelper",
        "time": 0.0
      },
      {
        "name": "cape_extracted_content",
        "time": 0.0
      },
      {
        "name": "carberp_mutex",
        "time": 0.0
      },
      {
        "name": "clears_logs",
        "time": 0.0
      },
      {
        "name": "cmdline_obfuscation",
        "time": 0.0
      },
      {
        "name": "cmdline_switches",
        "time": 0.0
      },
      {
        "name": "cmdline_terminate",
        "time": 0.0
      },
      {
        "name": "cmdline_forfiles_wildcard",
        "time": 0.0
      },
      {
        "name": "cmdline_http_link",
        "time": 0.0
      },
      {
        "name": "cmdline_long_string",
        "time": 0.0
      },
      {
        "name": "cmdline_reversed_http_link",
        "time": 0.0
      },
      {
        "name": "long_commandline",
        "time": 0.0
      },
      {
        "name": "powershell_renamed_commandline",
        "time": 0.0
      },
      {
        "name": "copies_self",
        "time": 0.0
      },
      {
        "name": "credwiz_credentialaccess",
        "time": 0.0
      },
      {
        "name": "enables_wdigest",
        "time": 0.0
      },
      {
        "name": "vaultcmd_credentialaccess",
        "time": 0.0
      },
      {
        "name": "file_credential_store_access",
        "time": 0.0
      },
      {
        "name": "file_credential_store_write",
        "time": 0.0
      },
      {
        "name": "kerberos_credential_access_via_rubeus",
        "time": 0.0
      },
      {
        "name": "registry_credential_dumping",
        "time": 0.0
      },
      {
        "name": "registry_credential_store_access",
        "time": 0.0
      },
      {
        "name": "registry_lsa_secrets_access",
        "time": 0.0
      },
      {
        "name": "comsvcs_credentialdump",
        "time": 0.0
      },
      {
        "name": "cryptomining_stratum_command",
        "time": 0.0
      },
      {
        "name": "cypherit_mutexes",
        "time": 0.0
      },
      {
        "name": "darkcomet_regkeys",
        "time": 0.0
      },
      {
        "name": "datop_loader",
        "time": 0.0
      },
      {
        "name": "deepfreeze_mutex",
        "time": 0.0
      },
      {
        "name": "deletes_executed_files",
        "time": 0.0
      },
      {
        "name": "disables_app_launch",
        "time": 0.0
      },
      {
        "name": "disables_auto_app_termination",
        "time": 0.0
      },
      {
        "name": "disables_appv_virtualization",
        "time": 0.0
      },
      {
        "name": "disables_backups",
        "time": 0.001
      },
      {
        "name": "disables_browser_warn",
        "time": 0.001
      },
      {
        "name": "disables_context_menus",
        "time": 0.0
      },
      {
        "name": "disables_cpl_disable",
        "time": 0.0
      },
      {
        "name": "disables_crashdumps",
        "time": 0.0
      },
      {
        "name": "disables_event_logging",
        "time": 0.0
      },
      {
        "name": "disables_folder_options",
        "time": 0.0
      },
      {
        "name": "disables_notificationcenter",
        "time": 0.0
      },
      {
        "name": "disables_power_options",
        "time": 0.001
      },
      {
        "name": "disables_restore_default_state",
        "time": 0.0
      },
      {
        "name": "disables_run_command",
        "time": 0.0
      },
      {
        "name": "disables_smartscreen",
        "time": 0.0
      },
      {
        "name": "disables_startmenu_search",
        "time": 0.0
      },
      {
        "name": "disables_system_restore",
        "time": 0.0
      },
      {
        "name": "disables_uac",
        "time": 0.0
      },
      {
        "name": "disables_wer",
        "time": 0.0
      },
      {
        "name": "disables_windows_defender",
        "time": 0.0
      },
      {
        "name": "disables_windows_defender_logging",
        "time": 0.0
      },
      {
        "name": "removes_windows_defender_contextmenu",
        "time": 0.0
      },
      {
        "name": "removes_windows_defender_updates",
        "time": 0.0
      },
      {
        "name": "windows_defender_powershell",
        "time": 0.0
      },
      {
        "name": "disables_windows_file_protection",
        "time": 0.0
      },
      {
        "name": "disables_windowsupdate",
        "time": 0.0
      },
      {
        "name": "disables_winfirewall",
        "time": 0.0
      },
      {
        "name": "discover_registry_mount_points",
        "time": 0.0
      },
      {
        "name": "adfind_domain_enumeration",
        "time": 0.0
      },
      {
        "name": "domain_enumeration_commands",
        "time": 0.0
      },
      {
        "name": "andromut_mutexes",
        "time": 0.0
      },
      {
        "name": "downloader_cabby",
        "time": 0.0
      },
      {
        "name": "phorpiex_mutexes",
        "time": 0.0
      },
      {
        "name": "protonbot_mutexes",
        "time": 0.0
      },
      {
        "name": "driver_filtermanager",
        "time": 0.0
      },
      {
        "name": "dropper",
        "time": 0.0
      },
      {
        "name": "dll_archive_execution",
        "time": 0.0
      },
      {
        "name": "lnk_archive_execution",
        "time": 0.0
      },
      {
        "name": "script_archive_execution",
        "time": 0.0
      },
      {
        "name": "excel4_macro_urls",
        "time": 0.0
      },
      {
        "name": "escalate_privilege_via_ntlm_relay",
        "time": 0.0
      },
      {
        "name": "spooler_access",
        "time": 0.0
      },
      {
        "name": "spooler_svc_start",
        "time": 0.0
      },
      {
        "name": "mapped_drives_uac",
        "time": 0.0
      },
      {
        "name": "hides_recycle_bin_icon",
        "time": 0.0
      },
      {
        "name": "apocalypse_stealer_file_behavior",
        "time": 0.0
      },
      {
        "name": "arkei_files",
        "time": 0.0
      },
      {
        "name": "azorult_mutexes",
        "time": 0.001
      },
      {
        "name": "infostealer_bitcoin",
        "time": 0.002
      },
      {
        "name": "cryptbot_files",
        "time": 0.0
      },
      {
        "name": "echelon_files",
        "time": 0.001
      },
      {
        "name": "infostealer_ftp",
        "time": 0.003
      },
      {
        "name": "infostealer_im",
        "time": 0.002
      },
      {
        "name": "infostealer_mail",
        "time": 0.002
      },
      {
        "name": "masslogger_files",
        "time": 0.0
      },
      {
        "name": "poullight_files",
        "time": 0.001
      },
      {
        "name": "purplewave_mutexes",
        "time": 0.0
      },
      {
        "name": "quilclipper_mutexes",
        "time": 0.0
      },
      {
        "name": "qulab_files",
        "time": 0.001
      },
      {
        "name": "qulab_mutexes",
        "time": 0.0
      },
      {
        "name": "asyncrat_mutex",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_ASPNet_Compiler",
        "time": 0.0
      },
      {
        "name": "Evade_Execute_Via_DeviceCredentialDeployment",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_Filter_Manager_Control",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_Intel_GFXDownloadWrapper",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_appvlp",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_pcalua",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_OpenSSH",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_pcalua",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_PesterPSModule",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_ScriptRunner",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_ttdinject",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_VisualStudioLiveShare",
        "time": 0.0
      },
      {
        "name": "Execute_Msiexec_Via_Explorer",
        "time": 0.0
      },
      {
        "name": "execute_remote_msi",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_powershell_via_runscripthelper",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_powershell_via_sqlps",
        "time": 0.0
      },
      {
        "name": "Indirect_Command_Execution_Via_ConsoleWindowHost",
        "time": 0.0
      },
      {
        "name": "Perform_Malicious_Activities_Via_Headless_Browser",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_CertOC",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_MSIEXEC",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_Odbcconf",
        "time": 0.0
      },
      {
        "name": "Scriptlet_Proxy_Execution_Via_Pubprn",
        "time": 0.0
      },
      {
        "name": "ie_martian_children",
        "time": 0.0
      },
      {
        "name": "office_martian_children",
        "time": 0.0
      },
      {
        "name": "mimics_icon",
        "time": 0.0
      },
      {
        "name": "masquerade_process_name",
        "time": 0.002
      },
      {
        "name": "mimikatz_modules",
        "time": 0.0
      },
      {
        "name": "ms_office_cmd_rce",
        "time": 0.0
      },
      {
        "name": "mount_copy_to_webdav_share",
        "time": 0.0
      },
      {
        "name": "potential_protocol_tunneling_via_legit_utilities",
        "time": 0.0
      },
      {
        "name": "potential_protocol_tunneling_via_qemu",
        "time": 0.0
      },
      {
        "name": "suspicious_execution_via_dotnet_remoting",
        "time": 0.0
      },
      {
        "name": "modify_certs",
        "time": 0.0
      },
      {
        "name": "dotnet_clr_usagelog_regkeys",
        "time": 0.0
      },
      {
        "name": "modify_hostfile",
        "time": 0.0
      },
      {
        "name": "modify_oem_information",
        "time": 0.0
      },
      {
        "name": "modify_security_center_warnings",
        "time": 0.0
      },
      {
        "name": "modify_uac_prompt",
        "time": 0.0
      },
      {
        "name": "network_dns_blockchain",
        "time": 0.0
      },
      {
        "name": "network_dns_opennic",
        "time": 0.001
      },
      {
        "name": "network_dns_paste_site",
        "time": 0.001
      },
      {
        "name": "network_dns_reverse_proxy",
        "time": 0.0
      },
      {
        "name": "network_dns_temp_file_storage",
        "time": 0.001
      },
      {
        "name": "network_dns_temp_urldns",
        "time": 0.0
      },
      {
        "name": "network_dns_url_shortener",
        "time": 0.008
      },
      {
        "name": "network_dns_doh_tls",
        "time": 0.0
      },
      {
        "name": "suspicious_tld",
        "time": 0.006
      },
      {
        "name": "network_tor_service",
        "time": 0.0
      },
      {
        "name": "office_code_page",
        "time": 0.0
      },
      {
        "name": "office_addinloading",
        "time": 0.0
      },
      {
        "name": "office_perfkey",
        "time": 0.0
      },
      {
        "name": "office_macro",
        "time": 0.0
      },
      {
        "name": "changes_trust_center_settings",
        "time": 0.0
      },
      {
        "name": "disables_vba_trust_access",
        "time": 0.0
      },
      {
        "name": "office_macro_autoexecution",
        "time": 0.0
      },
      {
        "name": "office_macro_ioc",
        "time": 0.0
      },
      {
        "name": "office_macro_malicious_prediction",
        "time": 0.0
      },
      {
        "name": "office_macro_suspicious",
        "time": 0.0
      },
      {
        "name": "rtf_aslr_bypass",
        "time": 0.0
      },
      {
        "name": "rtf_anomaly_characterset",
        "time": 0.0
      },
      {
        "name": "rtf_anomaly_version",
        "time": 0.0
      },
      {
        "name": "rtf_embedded_content",
        "time": 0.0
      },
      {
        "name": "rtf_embedded_office_file",
        "time": 0.0
      },
      {
        "name": "rtf_exploit_static",
        "time": 0.0
      },
      {
        "name": "office_security",
        "time": 0.0
      },
      {
        "name": "accesses_office_username",
        "time": 0.0
      },
      {
        "name": "office_anomalous_feature",
        "time": 0.0
      },
      {
        "name": "office_dde_command",
        "time": 0.0
      },
      {
        "name": "packer_armadillo_mutex",
        "time": 0.0
      },
      {
        "name": "packer_armadillo_regkey",
        "time": 0.0
      },
      {
        "name": "persistence_ads",
        "time": 0.0
      },
      {
        "name": "persistence_safeboot",
        "time": 0.0
      },
      {
        "name": "persistence_ifeo",
        "time": 0.0
      },
      {
        "name": "persistence_silent_process_exit",
        "time": 0.0
      },
      {
        "name": "persistence_rdp_registry",
        "time": 0.0
      },
      {
        "name": "persistence_rdp_shadowing",
        "time": 0.0
      },
      {
        "name": "persistence_service",
        "time": 0.0
      },
      {
        "name": "persistence_shim_database",
        "time": 0.0
      },
      {
        "name": "powerpool_mutexes",
        "time": 0.0
      },
      {
        "name": "powershell_scriptblock_logging",
        "time": 0.0
      },
      {
        "name": "powershell_command_suspicious",
        "time": 0.0
      },
      {
        "name": "powershell_history_save_mod",
        "time": 0.0
      },
      {
        "name": "powershell_renamed",
        "time": 0.0
      },
      {
        "name": "powershell_reversed",
        "time": 0.0
      },
      {
        "name": "powershell_variable_obfuscation",
        "time": 0.0
      },
      {
        "name": "prevents_safeboot",
        "time": 0.0
      },
      {
        "name": "cmdline_process_discovery",
        "time": 0.0
      },
      {
        "name": "cryptomix_mutexes",
        "time": 0.0
      },
      {
        "name": "dharma_mutexes",
        "time": 0.0
      },
      {
        "name": "ransomware_extensions_generic",
        "time": 0.0
      },
      {
        "name": "ransomware_extensions_known",
        "time": 0.004
      },
      {
        "name": "ransomware_files",
        "time": 0.006
      },
      {
        "name": "fonix_mutexes",
        "time": 0.0
      },
      {
        "name": "gandcrab_mutexes",
        "time": 0.0
      },
      {
        "name": "germanwiper_mutexes",
        "time": 0.0
      },
      {
        "name": "medusalocker_mutexes",
        "time": 0.0
      },
      {
        "name": "medusalocker_regkeys",
        "time": 0.0
      },
      {
        "name": "nemty_mutexes",
        "time": 0.0
      },
      {
        "name": "nemty_regkeys",
        "time": 0.0
      },
      {
        "name": "pysa_mutexes",
        "time": 0.0
      },
      {
        "name": "ransomware_radamant",
        "time": 0.0
      },
      {
        "name": "ransomware_recyclebin",
        "time": 0.0
      },
      {
        "name": "revil_mutexes",
        "time": 0.001
      },
      {
        "name": "ransomware_revil_regkey",
        "time": 0.0
      },
      {
        "name": "satan_mutexes",
        "time": 0.0
      },
      {
        "name": "snake_ransom_mutexes",
        "time": 0.0
      },
      {
        "name": "stop_ransom_mutexes",
        "time": 0.0
      },
      {
        "name": "stop_ransomware_cmd",
        "time": 0.0
      },
      {
        "name": "ransomware_stopdjvu",
        "time": 0.0
      },
      {
        "name": "rat_beebus_mutexes",
        "time": 0.0
      },
      {
        "name": "blacknet_mutexes",
        "time": 0.0
      },
      {
        "name": "blackrat_mutexes",
        "time": 0.0
      },
      {
        "name": "crat_mutexes",
        "time": 0.0
      },
      {
        "name": "dcrat_files",
        "time": 0.0
      },
      {
        "name": "dcrat_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_fynloski_mutexes",
        "time": 0.0
      },
      {
        "name": "limerat_mutexes",
        "time": 0.0
      },
      {
        "name": "limerat_regkeys",
        "time": 0.0
      },
      {
        "name": "lodarat_file_behavior",
        "time": 0.0
      },
      {
        "name": "modirat_behavior",
        "time": 0.0
      },
      {
        "name": "njrat_regkeys",
        "time": 0.0
      },
      {
        "name": "obliquerat_files",
        "time": 0.0
      },
      {
        "name": "obliquerat_mutexes",
        "time": 0.0
      },
      {
        "name": "parallax_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_pcclient",
        "time": 0.0
      },
      {
        "name": "rat_plugx_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_poisonivy_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_quasar_mutexes",
        "time": 0.0
      },
      {
        "name": "ratsnif_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_spynet",
        "time": 0.0
      },
      {
        "name": "venomrat_mutexes",
        "time": 0.0
      },
      {
        "name": "warzonerat_files",
        "time": 0.0
      },
      {
        "name": "warzonerat_regkeys",
        "time": 0.0
      },
      {
        "name": "xpertrat_files",
        "time": 0.0
      },
      {
        "name": "xpertrat_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_xtreme_mutexes",
        "time": 0.0
      },
      {
        "name": "reads_password_database",
        "time": 0.0
      },
      {
        "name": "recon_fingerprint",
        "time": 0.0
      },
      {
        "name": "remcos_files",
        "time": 0.0
      },
      {
        "name": "remcos_mutexes",
        "time": 0.0
      },
      {
        "name": "remcos_regkeys",
        "time": 0.0
      },
      {
        "name": "rdptcp_key",
        "time": 0.0
      },
      {
        "name": "uses_rdp_clip",
        "time": 0.0
      },
      {
        "name": "uses_remote_desktop_session",
        "time": 0.0
      },
      {
        "name": "removes_networking_icon",
        "time": 0.0
      },
      {
        "name": "removes_pinned_programs",
        "time": 0.0
      },
      {
        "name": "removes_security_maintenance_icon",
        "time": 0.0
      },
      {
        "name": "removes_startmenu_defaults",
        "time": 0.0
      },
      {
        "name": "removes_username_startmenu",
        "time": 0.0
      },
      {
        "name": "spicyhotpot_behavior",
        "time": 0.0
      },
      {
        "name": "sniffer_winpcap",
        "time": 0.0
      },
      {
        "name": "spreading_autoruninf",
        "time": 0.0
      },
      {
        "name": "stealth_hidden_extension",
        "time": 0.0
      },
      {
        "name": "stealth_hiddenreg",
        "time": 0.0
      },
      {
        "name": "stealth_hide_notifications",
        "time": 0.0
      },
      {
        "name": "stealth_webhistory",
        "time": 0.0
      },
      {
        "name": "sysinternals_psexec",
        "time": 0.0
      },
      {
        "name": "sysinternals_tools",
        "time": 0.0
      },
      {
        "name": "language_check_registry",
        "time": 0.0
      },
      {
        "name": "tampers_etw",
        "time": 0.0
      },
      {
        "name": "lsa_tampering",
        "time": 0.0
      },
      {
        "name": "tampers_powershell_logging",
        "time": 0.0
      },
      {
        "name": "targeted_flame",
        "time": 0.0
      },
      {
        "name": "territorial_disputes_sigs",
        "time": 0.002
      },
      {
        "name": "trickbot_mutex",
        "time": 0.0
      },
      {
        "name": "fleercivet_mutex",
        "time": 0.0
      },
      {
        "name": "lokibot_mutexes",
        "time": 0.0
      },
      {
        "name": "ursnif_behavior",
        "time": 0.001
      },
      {
        "name": "uses_adfind",
        "time": 0.0
      },
      {
        "name": "uses_ms_protocol",
        "time": 0.0
      },
      {
        "name": "neshta_mutexes",
        "time": 0.0
      },
      {
        "name": "renamer_mutexes",
        "time": 0.0
      },
      {
        "name": "owa_web_shell_files",
        "time": 0.0
      },
      {
        "name": "web_shell_files",
        "time": 0.0
      },
      {
        "name": "web_shell_processes",
        "time": 0.0
      },
      {
        "name": "dotnet_csc_build",
        "time": 0.0
      },
      {
        "name": "mavinject_lolbin",
        "time": 0.0
      },
      {
        "name": "multiple_explorer_instances",
        "time": 0.0
      },
      {
        "name": "script_tool_executed",
        "time": 0.0
      },
      {
        "name": "suspicious_certutil_use",
        "time": 0.0
      },
      {
        "name": "suspicious_command_tools",
        "time": 0.0
      },
      {
        "name": "suspicious_mpcmdrun_use",
        "time": 0.0
      },
      {
        "name": "suspicious_ping_use",
        "time": 0.0
      },
      {
        "name": "uses_powershell_copyitem",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_appcmd",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_csvde_ldifde",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_cipher",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_clickonce",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_curl",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_dsquery",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_esentutl",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_finger",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_mode",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_ntdsutil",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_nltest",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_setx",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_xcopy",
        "time": 0.0
      },
      {
        "name": "wmic_command_suspicious",
        "time": 0.0
      },
      {
        "name": "scrcons_wmi_script_consumer",
        "time": 0.0
      },
      {
        "name": "allaple_mutexes",
        "time": 0.0
      }
    ],
    "reporting": [
      {
        "name": "BinGraph",
        "time": 0.0
      }
    ]
  },
  "target": {
    "category": "file",
    "file": {
      "name": "ClientPlugin.dll",
      "path": "/opt/CAPEv2/storage/binaries/61e9d5c0727665e9ef3f328141397be47c65ed11ab621c644b5bbf1d67138403",
      "guest_paths": "",
      "size": 19968,
      "crc32": "BE3B83AB",
      "md5": "bdc8945f1d799c845408522e372d1dbd",
      "sha1": "874b7c3c97cc5b13b9dd172fec5a54bc1f258005",
      "sha256": "61e9d5c0727665e9ef3f328141397be47c65ed11ab621c644b5bbf1d67138403",
      "sha512": "4fa0ed4ef66e4c442f5fc628e8bfc8a4f84cb213210643996d9387027edb619c054f6104ac889ae77cece09f0304f95d5f20e14d66847e2d382ef51eecec0962",
      "rh_hash": null,
      "ssdeep": "192:VYLQui6h6p5WW3tZVTnlYJL/eLYLTr2/C8:VYLQu/6/fKqLYLTR",
      "type": "PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows",
      "yara": [
        {
          "name": "DITEKSHEN_MALWARE_Win_Nanocore",
          "meta": {
            "description": "Detects NanoCore",
            "author": "ditekSHen",
            "id": "931b98f6-df2b-538b-bc49-ecbbd24334da",
            "date": "2020-11-06",
            "modified": "2024-11-01",
            "reference": "https://github.com/ditekshen/detection",
            "source_url": "https://github.com/ditekshen/detection/blob/e76c93dcdedff04076380ffc60ea54e45b313635/yara/malware.yar#L7654-L7681",
            "license_url": "https://github.com/ditekshen/detection/blob/e76c93dcdedff04076380ffc60ea54e45b313635/LICENSE.txt",
            "logic_hash": "6336260e0af2b4b51338ee066f41b7c58aa134a6c03ca110db7e088edf2b65a7",
            "score": 75,
            "quality": 75,
            "tags": "FILE"
          },
          "strings": [
            "NanoCore.ClientPlugin",
            "NanoCore.ClientPluginHost",
            "IClientApp",
            "IClientData",
            "IClientNetwork",
            "IClientAppHost",
            "IClientDataHost",
            "IClientLoggingHost",
            "IClientNetworkHost",
            "IClientUIHost",
            "IClientNameObjectCollection",
            "IClientReadOnlyNameObjectCollection",
            "ClientPlugin",
            "get_ClientSettings",
            "get_Connected"
          ],
          "addresses": {
            "x2": 3640,
            "x3": 3701,
            "i1": 3674,
            "i2": 3662,
            "i3": 3625,
            "i4": 3779,
            "i5": 3685,
            "i6": 3760,
            "i7": 3727,
            "i8": 3746,
            "i9": 3794,
            "i10": 3831,
            "s1": 6025,
            "s6": 4601,
            "s7": 4681
          }
        },
        {
          "name": "Windows_Trojan_Nanocore_d8c4e3c5",
          "meta": {
            "author": "Elastic Security",
            "id": "d8c4e3c5-8bcc-43d2-9104-fa3774282da5",
            "fingerprint": "e5c284f14c1c650ef8ddd7caf314f5318e46a811addc2af5e70890390c7307d4",
            "creation_date": "2021-06-13",
            "last_modified": "2021-08-23",
            "threat_name": "Windows.Trojan.Nanocore",
            "reference_sample": "b2262126a955e306dc68487333394dc08c4fbd708a19afeb531f58916ddb1cfd",
            "severity": 100,
            "arch_context": "x86, arm64",
            "scan_context": "file, memory",
            "license": "Elastic License v2",
            "os": "windows"
          },
          "strings": [
            "NanoCore.ClientPluginHost",
            "NanoCore.ClientPlugin",
            "get_BuilderSettings",
            "IClientAppHost",
            "AddHostEntry",
            "LogClientException",
            "PipeExists",
            "IClientLoggingHost"
          ],
          "addresses": {
            "a1": 3701,
            "a2": 3640,
            "b1": 4620,
            "b4": 3779,
            "b6": 4733,
            "b7": 4844,
            "b8": 4705,
            "b9": 3760
          }
        },
        {
          "name": "Nanocore_RAT_Gen_2",
          "meta": {
            "description": "Detetcs the Nanocore RAT",
            "author": "Florian Roth",
            "score": 100,
            "reference": "https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/",
            "date": "2016-04-22",
            "hash1": "755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050"
          },
          "strings": [
            "NanoCore.ClientPluginHost",
            "IClientNetworkHost"
          ],
          "addresses": {
            "x1": 3701,
            "x2": 3727
          }
        },
        {
          "name": "NETDLLMicrosoft",
          "meta": {
            "author": "malware-lu"
          },
          "strings": [
            "{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }"
          ],
          "addresses": {
            "a0": 6858
          }
        },
        {
          "name": "IsPE32",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsNET_DLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsDLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsWindowsGUI",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "Microsoft_Visual_Studio_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 6894
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 6894
          }
        },
        {
          "name": "Microsoft_Visual_C_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 6894
          }
        },
        {
          "name": "Microsoft_Visual_Studio_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 6894
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 6894
          }
        },
        {
          "name": "NET_executable_",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 6894
          }
        },
        {
          "name": "NET_executable",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 6894
          }
        }
      ],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T1CA924D1362CE7DE6E5B916303B3387C1C72DDE041653DA2E16D87629E97E2833A523D8",
      "sha3_384": "34e76812c5bbcc4e39114f9560b049a9e8ac0f74800b55f33641134edf5dfb32ff8a420a55be3ca4c294e8d1f69db255",
      "yara_hash": "b833150b13e1662cfeb7589959edd288cf4e73710395ec5c5f2123f39a668f4d",
      "options_hash": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
      "pe": {
        "guest_signers": {
          "aux_sha1": null,
          "aux_timestamp": null,
          "aux_valid": false,
          "aux_error": true,
          "aux_error_desc": "No signature found.",
          "aux_signers": []
        },
        "digital_signers": [],
        "imagebase": "0x00400000",
        "entrypoint": "0x000038ee",
        "ep_bytes": "ff250020400000000000000000000000",
        "peid_signatures": null,
        "reported_checksum": "0x00000000",
        "actual_checksum": "0x0000721e",
        "osversion": "4.0",
        "machine_type": "IMAGE_FILE_MACHINE_I386",
        "pdbpath": null,
        "imports": {
          "mscoree": {
            "dll": "mscoree.dll",
            "imports": [
              {
                "address": "0x402000",
                "name": "_CorDllMain"
              }
            ]
          }
        },
        "exported_dll_name": null,
        "exports": [],
        "dirents": [
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
            "virtual_address": "0x0000389c",
            "size": "0x0000004f"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
            "virtual_address": "0x00004000",
            "size": "0x00002f58"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
            "virtual_address": "0x00008000",
            "size": "0x0000000c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_TLS",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IAT",
            "virtual_address": "0x00002000",
            "size": "0x00000008"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
            "virtual_address": "0x00002008",
            "size": "0x00000048"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          }
        ],
        "sections": [
          {
            "name": ".text",
            "raw_address": "0x00000200",
            "virtual_address": "0x00002000",
            "virtual_size": "0x000018f4",
            "size_of_data": "0x00001a00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x60000020",
            "entropy": "5.26"
          },
          {
            "name": ".rsrc",
            "raw_address": "0x00001c00",
            "virtual_address": "0x00004000",
            "virtual_size": "0x00002f58",
            "size_of_data": "0x00003000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x40000040",
            "entropy": "3.31"
          },
          {
            "name": ".reloc",
            "raw_address": "0x00004c00",
            "virtual_address": "0x00008000",
            "virtual_size": "0x0000000c",
            "size_of_data": "0x00000200",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "0.08"
          }
        ],
        "overlay": null,
        "resources": [
          {
            "name": "RT_ICON",
            "offset": "0x00004468",
            "size": "0x000002e8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.71"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00004750",
            "size": "0x00000128",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.08"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00004878",
            "size": "0x000008a8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.72"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00005120",
            "size": "0x00000568",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.05"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00005688",
            "size": "0x00000353",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "4.05"
          },
          {
            "name": "RT_ICON",
            "offset": "0x000059e0",
            "size": "0x000010a8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.72"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00006a88",
            "size": "0x00000468",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.76"
          },
          {
            "name": "RT_GROUP_ICON",
            "offset": "0x00006ef0",
            "size": "0x00000068",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.69"
          },
          {
            "name": "RT_VERSION",
            "offset": "0x00004208",
            "size": "0x0000025c",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "3.23"
          }
        ],
        "versioninfo": [
          {
            "name": "Translation",
            "value": "0x0000 0x04b0"
          },
          {
            "name": "FileDescription",
            "value": " "
          },
          {
            "name": "FileVersion",
            "value": "1.2.0.0"
          },
          {
            "name": "InternalName",
            "value": "ClientPlugin.dll"
          },
          {
            "name": "LegalCopyright",
            "value": " "
          },
          {
            "name": "OriginalFilename",
            "value": "ClientPlugin.dll"
          },
          {
            "name": "ProductVersion",
            "value": "1.2.0.0"
          },
          {
            "name": "Assembly Version",
            "value": "1.2.0.0"
          }
        ],
        "imphash": "dae02f32a21e03ce65412f6e56942daa",
        "timestamp": "2014-11-23 01:09:01",
        "icon": "iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAY0lEQVR4nO3XIQ6AMBBE0YH0eGuAcwKmZ1sLCkHRZUj4o9qaeVmzqfT3DJl5OAGjs1ySynWIiFeLa62SPjABAABK+7Cte9fCeZlud/sEAAAAAAAAADvgsY7bddk79gnwMSH2nLDUDvNx5OJLAAAAAElFTkSuQmCC",
        "icon_hash": "f66c7c86e9ab59ef3f289acd613a3738",
        "icon_fuzzy": "c3ca946d749a15ad18efd3e5d7b0d8f5",
        "icon_dhash": "454545d4d4d44503",
        "imported_dll_count": 1
      },
      "data": null,
      "strings": [
        "System.CodeDom.Compiler",
        "get_ClientSettings",
        "RestoreProtection",
        "mscoree.dll",
        "EntryExists",
        "params",
        "Assembly Version",
        "ClientPlugin.dll",
        "SendToServer",
        "RebuildHostCache",
        "m_Context",
        "KeyValuePair`2",
        "GetObjectValue",
        "set_Value",
        "TargetMethod",
        "My.Application",
        "1.2.0.0",
        "NanoCore.My",
        "IDATx",
        "Microsoft.VisualBasic.CompilerServices",
        "InternalName",
        "message",
        "System",
        "#Blob",
        "_CorDllMain",
        "System.Diagnostics",
        "MulticastDelegate",
        "ClientPlugin",
        "ComVisibleAttribute",
        "MyApplication",
        "IClientNameObjectCollection",
        "MyGroupCollectionAttribute",
        "EditorBrowsableAttribute",
        "pipeName",
        "AddHostEntry",
        "ParamArrayAttribute",
        "MyComputer",
        "BeginInvoke",
        ".ctor",
        "MyProject",
        "compress",
        "ThreadSafeObjectProvider`1",
        "LogClientException",
        "ConnectionStateChanged",
        "DebuggerHiddenAttribute",
        "System.ComponentModel",
        "ToString",
        "DelegateCallback",
        "instance",
        "wwwwwwwwwwwwww",
        "VarFileInfo",
        "LegalCopyright",
        "My.Computer",
        "get_Connected",
        "GetEntries",
        "AsyncCallback",
        "MyTemplate",
        "m_AppObjectProvider",
        "Restart",
        "System.Runtime.CompilerServices",
        "<Module>",
        "GetInstance",
        "Uninstall",
        "get_GetInstance",
        "Equals",
        "IAsyncResult",
        "wwwwww",
        "ClientSettingChanged",
        "EndInvoke",
        "My.User",
        "FileVersion",
        "ClientInvokeDelegate",
        "ContextValue`1",
        "SetValue",
        "IClientNetwork",
        "get_WebServices",
        "PipeCreated",
        "`.rsrc",
        ".text",
        "AssemblyFileVersionAttribute",
        "WebServices",
        "Invoke",
        "StringFileInfo",
        "LogClientMessage",
        "GuidAttribute",
        "NanoCore",
        "AssemblyTrademarkAttribute",
        "DelegateAsyncState",
        "v2.0.50727",
        "ProductVersion",
        "#Strings",
        "System.Collections.Generic",
        "System.ComponentModel.Design",
        "Microsoft.VisualBasic",
        "AssemblyProductAttribute",
        "ClientSettings",
        "FileDescription",
        "@.reloc",
        "ConnectionFailed",
        "IClientUIHost",
        "$d6e3c4d8-8560-4021-a765-fad7362f3388",
        "VariableChanged",
        "MyWebServices",
        "!This program cannot be run in DOS mode.",
        "ClosePipe",
        "My.WebServices",
        "Variables",
        "IClientLoggingHost",
        "GetHashCode",
        "IClientNetworkHost",
        "TargetObject",
        "AssemblyCompanyAttribute",
        "BuildingHostCache",
        "GetValue",
        "m_UserObjectProvider",
        "Connected",
        "IClientApp",
        "RuntimeCompatibilityAttribute",
        "Dispose__Instance__",
        "8.0.0.0",
        "CompilationRelaxationsAttribute",
        "get_Application",
        "IClientData",
        "Activator",
        "000004b0",
        "PipeExists",
        "state",
        "PluginUninstalling",
        "Application",
        "Translation",
        "mscorlib",
        "OriginalFilename",
        "RuntimeHelpers",
        "RemoveValue",
        "IClientReadOnlyNameObjectCollection",
        "get_User",
        "CreateInstance",
        "IClientAppHost",
        "HideModuleNameAttribute",
        "connected",
        "ReadPacket",
        "System.Runtime.InteropServices",
        "value",
        "VS_VERSION_INFO",
        "HelpKeywordAttribute",
        "get_Variables",
        "Create__Instance__",
        "Computer",
        "Disconnect",
        "Exception",
        "AssemblyTitleAttribute",
        "defaultValue",
        "ApplicationBase",
        "#GUID",
        "ClientUninstalling",
        "AssemblyDescriptionAttribute",
        "NanoCore.ClientPlugin",
        "IClientDataHost",
        "Object",
        "get_BuilderSettings",
        "method",
        "System.Reflection",
        "AssemblyCopyrightAttribute",
        "DisableProtection",
        "get_Value",
        "Microsoft.VisualBasic.Devices",
        "4System.Web.Services.Protocols.SoapHttpClientProtocol",
        "m_MyWebServicesObjectProvider",
        "m_ComputerObjectProvider",
        "BuilderSettings",
        "GeneratedCodeAttribute",
        "NanoCore.ClientPluginHost",
        "Shutdown",
        "DelegateAsyncResult",
        "RuntimeTypeHandle",
        "WrapNonExceptionThrows",
        "get_Computer",
        ".cctor",
        "GetType",
        "StandardModuleAttribute",
        "GetTypeFromHandle",
        "PipeClosed",
        "EditorBrowsableState",
        "Microsoft.VisualBasic.ApplicationServices",
        "Microsoft.VisualBasic.MyServices.Internal"
      ],
      "virustotal": {
        "error": true,
        "msg": "VT File lookup disabled in processing.conf"
      },
      "executed_tools": [
        "overlay",
        "msi_extract",
        "kixtart_extract",
        "vbe_extract",
        "batch_extract",
        "UnAutoIt_extract",
        "UPX_unpack",
        "RarSFX_extract",
        "Inno_extract",
        "SevenZip_unpack",
        "de4dot_deobfuscate",
        "eziriz_deobfuscate",
        "office_one"
      ],
      "cape_type_code": 0,
      "cape_type": ""
    }
  },
  "procdump": [
    {
      "name": "9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3",
      "path": "/opt/CAPEv2/storage/analyses/39/procdump/9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3",
      "guest_paths": "1;?C:\\Windows\\SysWOW64\\rundll32.exe;?C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll;?",
      "size": 7680,
      "crc32": "A45BF1B0",
      "md5": "08586ab761ab859d6860a2c7de3bebd2",
      "sha1": "8cea2f8166202b243f70ded0b9dfb7fce1518365",
      "sha256": "9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3",
      "sha512": "7ab3fd442e35dd3140aef27abe78bd2374623b9d4794c6325977ad4c35943861ff79a7d8e0dd361660d2bed1a8618379cbfa8aa7254b16021a934071a6560ba0",
      "rh_hash": null,
      "ssdeep": "96:QYLIkUui+Nqih6pe+WWLTtZE2F6lYlnlYJnLEM/m3bViL0KfrneR1P7ZXmrI:QYLQui6h6p5WW3tZVTnlYJL/eLYLTr2",
      "type": "PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows",
      "yara": [
        {
          "name": "DITEKSHEN_MALWARE_Win_Nanocore",
          "meta": {
            "description": "Detects NanoCore",
            "author": "ditekSHen",
            "id": "931b98f6-df2b-538b-bc49-ecbbd24334da",
            "date": "2020-11-06",
            "modified": "2024-11-01",
            "reference": "https://github.com/ditekshen/detection",
            "source_url": "https://github.com/ditekshen/detection/blob/e76c93dcdedff04076380ffc60ea54e45b313635/yara/malware.yar#L7654-L7681",
            "license_url": "https://github.com/ditekshen/detection/blob/e76c93dcdedff04076380ffc60ea54e45b313635/LICENSE.txt",
            "logic_hash": "6336260e0af2b4b51338ee066f41b7c58aa134a6c03ca110db7e088edf2b65a7",
            "score": 75,
            "quality": 75,
            "tags": "FILE"
          },
          "strings": [
            "NanoCore.ClientPlugin",
            "NanoCore.ClientPluginHost",
            "IClientApp",
            "IClientData",
            "IClientNetwork",
            "IClientAppHost",
            "IClientDataHost",
            "IClientLoggingHost",
            "IClientNetworkHost",
            "IClientUIHost",
            "IClientNameObjectCollection",
            "IClientReadOnlyNameObjectCollection",
            "ClientPlugin",
            "get_ClientSettings",
            "get_Connected"
          ],
          "addresses": {
            "x2": 4152,
            "x3": 4213,
            "i1": 4186,
            "i2": 4174,
            "i3": 4137,
            "i4": 4291,
            "i5": 4197,
            "i6": 4272,
            "i7": 4239,
            "i8": 4258,
            "i9": 4306,
            "i10": 4343,
            "s1": 6537,
            "s6": 5113,
            "s7": 5193
          }
        },
        {
          "name": "Windows_Trojan_Nanocore_d8c4e3c5",
          "meta": {
            "author": "Elastic Security",
            "id": "d8c4e3c5-8bcc-43d2-9104-fa3774282da5",
            "fingerprint": "e5c284f14c1c650ef8ddd7caf314f5318e46a811addc2af5e70890390c7307d4",
            "creation_date": "2021-06-13",
            "last_modified": "2021-08-23",
            "threat_name": "Windows.Trojan.Nanocore",
            "reference_sample": "b2262126a955e306dc68487333394dc08c4fbd708a19afeb531f58916ddb1cfd",
            "severity": 100,
            "arch_context": "x86, arm64",
            "scan_context": "file, memory",
            "license": "Elastic License v2",
            "os": "windows"
          },
          "strings": [
            "NanoCore.ClientPluginHost",
            "NanoCore.ClientPlugin",
            "get_BuilderSettings",
            "IClientAppHost",
            "AddHostEntry",
            "LogClientException",
            "PipeExists",
            "IClientLoggingHost"
          ],
          "addresses": {
            "a1": 4213,
            "a2": 4152,
            "b1": 5132,
            "b4": 4291,
            "b6": 5245,
            "b7": 5356,
            "b8": 5217,
            "b9": 4272
          }
        },
        {
          "name": "Nanocore_RAT_Gen_2",
          "meta": {
            "description": "Detetcs the Nanocore RAT",
            "author": "Florian Roth",
            "score": 100,
            "reference": "https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/",
            "date": "2016-04-22",
            "hash1": "755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050"
          },
          "strings": [
            "NanoCore.ClientPluginHost",
            "IClientNetworkHost"
          ],
          "addresses": {
            "x1": 4213,
            "x2": 4239
          }
        },
        {
          "name": "NETDLLMicrosoft",
          "meta": {
            "author": "malware-lu"
          },
          "strings": [
            "{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }"
          ],
          "addresses": {
            "a0": 7370
          }
        },
        {
          "name": "IsPE32",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsNET_DLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsDLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsWindowsGUI",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "Microsoft_Visual_Studio_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 7406
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 7406
          }
        },
        {
          "name": "Microsoft_Visual_C_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 7406
          }
        },
        {
          "name": "Microsoft_Visual_Studio_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 7406
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 7406
          }
        },
        {
          "name": "NET_executable_",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 7406
          }
        },
        {
          "name": "NET_executable",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 7406
          }
        }
      ],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T1F5F1D71AE3C0D2B6CF6A2372490399405BB2CB0932CBEF57159C9376C8D6B990B67167",
      "sha3_384": "db7d891351ab061a15580b9b986a987f3ad831454033bbe28ee8a1054c75e623a25d3c90c295d68347270bb4ff07ebee",
      "yara_hash": "b833150b13e1662cfeb7589959edd288cf4e73710395ec5c5f2123f39a668f4d",
      "options_hash": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
      "pe": {
        "guest_signers": {
          "aux_sha1": null,
          "aux_timestamp": null,
          "aux_valid": false,
          "aux_error": true,
          "aux_error_desc": "No signature found.",
          "aux_signers": []
        },
        "digital_signers": [],
        "imagebase": "0x00400000",
        "entrypoint": "0x000038ee",
        "ep_bytes": "ff250020400000000000000000000000",
        "peid_signatures": null,
        "reported_checksum": "0x00000000",
        "actual_checksum": "0x000069a1",
        "osversion": "4.0",
        "machine_type": "IMAGE_FILE_MACHINE_I386",
        "pdbpath": null,
        "imports": {
          "mscoree": {
            "dll": "mscoree.dll",
            "imports": [
              {
                "address": "0x402000",
                "name": "_CorDllMain"
              }
            ]
          }
        },
        "exported_dll_name": null,
        "exports": [],
        "dirents": [
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
            "virtual_address": "0x0000389c",
            "size": "0x0000004f"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
            "virtual_address": "0x00004000",
            "size": "0x00002f58"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
            "virtual_address": "0x00008000",
            "size": "0x0000000c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_TLS",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IAT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
            "virtual_address": "0x00002008",
            "size": "0x00000048"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          }
        ],
        "sections": [
          {
            "name": ".text",
            "raw_address": "0x00000400",
            "virtual_address": "0x00002000",
            "virtual_size": "0x00002000",
            "size_of_data": "0x00001a00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
            "characteristics_raw": "0xe0000020",
            "entropy": "5.26"
          },
          {
            "name": ".rsrc",
            "raw_address": "0x00001e00",
            "virtual_address": "0x00004000",
            "virtual_size": "0x00004000",
            "size_of_data": "0x00000000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x40000040",
            "entropy": "0.00"
          },
          {
            "name": ".reloc",
            "raw_address": "0x00001e00",
            "virtual_address": "0x00008000",
            "virtual_size": "0x00002000",
            "size_of_data": "0x00000000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "0.00"
          }
        ],
        "overlay": null,
        "resources": [],
        "versioninfo": [],
        "imphash": "dae02f32a21e03ce65412f6e56942daa",
        "timestamp": "2014-11-23 01:09:01",
        "icon": null,
        "icon_hash": null,
        "icon_fuzzy": null,
        "icon_dhash": null,
        "imported_dll_count": 1
      },
      "data": null,
      "strings": [
        "System.CodeDom.Compiler",
        "get_ClientSettings",
        "RestoreProtection",
        "mscoree.dll",
        "EntryExists",
        "params",
        "ClientPlugin.dll",
        "SendToServer",
        "RebuildHostCache",
        "m_Context",
        "KeyValuePair`2",
        "GetObjectValue",
        "set_Value",
        "TargetMethod",
        "My.Application",
        "1.2.0.0",
        "NanoCore.My",
        "Microsoft.VisualBasic.CompilerServices",
        "message",
        "System",
        "#Blob",
        "_CorDllMain",
        "System.Diagnostics",
        "MulticastDelegate",
        "ClientPlugin",
        "ComVisibleAttribute",
        "MyApplication",
        "IClientNameObjectCollection",
        "MyGroupCollectionAttribute",
        "EditorBrowsableAttribute",
        "pipeName",
        "AddHostEntry",
        "ParamArrayAttribute",
        "MyComputer",
        "BeginInvoke",
        ".ctor",
        "MyProject",
        "compress",
        "ThreadSafeObjectProvider`1",
        "LogClientException",
        "ConnectionStateChanged",
        "DebuggerHiddenAttribute",
        "System.ComponentModel",
        "ToString",
        "DelegateCallback",
        "instance",
        "My.Computer",
        "get_Connected",
        "GetEntries",
        "AsyncCallback",
        "MyTemplate",
        "m_AppObjectProvider",
        "Restart",
        "System.Runtime.CompilerServices",
        "<Module>",
        "GetInstance",
        "Uninstall",
        "get_GetInstance",
        "Equals",
        "IAsyncResult",
        "ClientSettingChanged",
        "EndInvoke",
        "My.User",
        "ClientInvokeDelegate",
        "ContextValue`1",
        "SetValue",
        "IClientNetwork",
        "get_WebServices",
        "PipeCreated",
        ".text",
        "AssemblyFileVersionAttribute",
        "WebServices",
        "Invoke",
        "LogClientMessage",
        "GuidAttribute",
        "NanoCore",
        "AssemblyTrademarkAttribute",
        "DelegateAsyncState",
        "v2.0.50727",
        "#Strings",
        "System.Collections.Generic",
        "System.ComponentModel.Design",
        "Microsoft.VisualBasic",
        "AssemblyProductAttribute",
        "ClientSettings",
        "@.reloc",
        "ConnectionFailed",
        "IClientUIHost",
        "$d6e3c4d8-8560-4021-a765-fad7362f3388",
        ".rsrc",
        "VariableChanged",
        "MyWebServices",
        "!This program cannot be run in DOS mode.",
        "ClosePipe",
        "My.WebServices",
        "Variables",
        "IClientLoggingHost",
        "GetHashCode",
        "IClientNetworkHost",
        "TargetObject",
        "AssemblyCompanyAttribute",
        "BuildingHostCache",
        "GetValue",
        "m_UserObjectProvider",
        "Connected",
        "IClientApp",
        "RuntimeCompatibilityAttribute",
        "Dispose__Instance__",
        "8.0.0.0",
        "CompilationRelaxationsAttribute",
        "get_Application",
        "IClientData",
        "Activator",
        "PipeExists",
        "state",
        "Application",
        "PluginUninstalling",
        "mscorlib",
        "RuntimeHelpers",
        "RemoveValue",
        "IClientReadOnlyNameObjectCollection",
        "get_User",
        "CreateInstance",
        "IClientAppHost",
        "HideModuleNameAttribute",
        "connected",
        "ReadPacket",
        "System.Runtime.InteropServices",
        "value",
        "HelpKeywordAttribute",
        "get_Variables",
        "Create__Instance__",
        "Computer",
        "Disconnect",
        "Exception",
        "AssemblyTitleAttribute",
        "defaultValue",
        "ApplicationBase",
        "#GUID",
        "ClientUninstalling",
        "AssemblyDescriptionAttribute",
        "NanoCore.ClientPlugin",
        "IClientDataHost",
        "Object",
        "get_BuilderSettings",
        "method",
        "System.Reflection",
        "AssemblyCopyrightAttribute",
        "DisableProtection",
        "get_Value",
        "Microsoft.VisualBasic.Devices",
        "4System.Web.Services.Protocols.SoapHttpClientProtocol",
        "m_MyWebServicesObjectProvider",
        "m_ComputerObjectProvider",
        "BuilderSettings",
        "GeneratedCodeAttribute",
        "NanoCore.ClientPluginHost",
        "Shutdown",
        "DelegateAsyncResult",
        "RuntimeTypeHandle",
        "WrapNonExceptionThrows",
        "get_Computer",
        ".cctor",
        "GetType",
        "StandardModuleAttribute",
        "GetTypeFromHandle",
        "PipeClosed",
        "EditorBrowsableState",
        "Microsoft.VisualBasic.ApplicationServices",
        "Microsoft.VisualBasic.MyServices.Internal"
      ],
      "virustotal": {
        "error": true,
        "msg": "VT File lookup disabled in processing.conf"
      },
      "executed_tools": [
        "overlay",
        "msi_extract",
        "kixtart_extract",
        "vbe_extract",
        "batch_extract",
        "UnAutoIt_extract",
        "UPX_unpack",
        "RarSFX_extract",
        "Inno_extract",
        "SevenZip_unpack",
        "de4dot_deobfuscate",
        "eziriz_deobfuscate",
        "office_one"
      ],
      "cape_type_code": 1,
      "cape_type": "",
      "process_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
      "process_name": "rundll32.exe",
      "module_path": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll",
      "pid": 1568
    }
  ],
  "CAPE": {
    "payloads": [],
    "configs": []
  },
  "info": {
    "version": "2.5",
    "started": "2026-04-16 22:43:33",
    "ended": "2026-04-16 22:49:40",
    "duration": 367,
    "id": 39,
    "category": "file",
    "custom": "",
    "machine": {
      "id": 32,
      "status": "stopping",
      "name": "win10x64",
      "label": "win10x64",
      "platform": "windows",
      "manager": "KVM",
      "started_on": "2026-04-16 22:43:33",
      "shutdown_on": "2026-04-16 22:49:39"
    },
    "package": "dll",
    "timeout": true,
    "tlp": null,
    "parent_sample": {
      "id": 23,
      "file_size": 13850813,
      "file_type": "7-zip archive data, version 0.3",
      "md5": "a17189d956c6d1975717256a6e6418cb",
      "crc32": "97AFA081",
      "sha1": "970e16de1d07a90dd285e84b59c0a77e8992ed9f",
      "sha256": "f9cef6944196d5d27ca99a9c6287d9718b658add797e9cb770789a0c4dbf2bcd",
      "sha512": "3105fa5d4d6914fe69f4d4ab9e517eab55d225bbdfa199f37f3c9f103805b1b5c587fe5e985a87ea60e2e7d511a0f872619343014233791ef63859130065e9f1",
      "ssdeep": null,
      "source_url": null
    },
    "options": {},
    "source_url": null,
    "route": "",
    "user_id": 0,
    "CAPE_current_commit": "a9a0887dab232f52c59e955b9984dd494c47ce6b"
  },
  "behavior": {
    "processes": [
      {
        "process_id": 1568,
        "process_name": "rundll32.exe",
        "parent_id": 3592,
        "module_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
        "first_seen": "2026-04-16 19:46:09,737",
        "calls": [
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x77274faa",
            "parentcaller": "0x77514cce",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetThreadContext"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ae38d0"
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetThreadTimes"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad1f70"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "IsProcessorFeaturePresent"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0b70"
              }
            ],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "OpenThread"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76acf5b0"
              }
            ],
            "repeated": 0,
            "id": 4
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "ProcessIdToSessionId"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0b90"
              }
            ],
            "repeated": 0,
            "id": 5
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "SetProcessShutdownParameters"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ac9540"
              }
            ],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "SetThreadContext"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ae4d20"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetProcessId"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0c20"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x77274faa",
            "parentcaller": "0x77514d2f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x77274faa",
            "parentcaller": "0x77514cce",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x77274faa",
            "parentcaller": "0x77514d2f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x77e7007d",
            "parentcaller": "0x7726648d",
            "category": "system",
            "api": "NtQueryLicenseValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Name",
                "value": "TerminalServices-RemoteConnectionManager-AllowAppServerMode"
              },
              {
                "name": "Type",
                "value": "0x00000004"
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "732",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "1696",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "1696",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "6244",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "6244",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-04-16 19:46:12,331",
            "thread_id": "2692",
            "caller": "0x77e91c0e",
            "parentcaller": "0x77e8dbb1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000007c"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 1,
            "id": 19
          },
          {
            "timestamp": "2026-04-16 19:46:12,346",
            "thread_id": "732",
            "caller": "0x00bc5f1a",
            "parentcaller": "0x00bc5fdd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02f53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-04-16 19:46:12,346",
            "thread_id": "732",
            "caller": "0x00bc5f1a",
            "parentcaller": "0x00bc5fdd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02f54000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-04-16 19:46:12,346",
            "thread_id": "732",
            "caller": "0x00bc4168",
            "parentcaller": "0x00bc6078",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "34",
                "pretty_value": "ProcessExecuteFlags"
              },
              {
                "name": "ProcessInformation",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-04-16 19:46:12,346",
            "thread_id": "732",
            "caller": "0x00bc40d8",
            "parentcaller": "0x00bc41fe",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-04-16 19:46:12,346",
            "thread_id": "732",
            "caller": "0x00bc4290",
            "parentcaller": "0x00bc6078",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-04-16 19:46:12,346",
            "thread_id": "732",
            "caller": "0x00bc59c5",
            "parentcaller": "0x00bc42a3",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll.manifest"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-04-16 19:46:12,346",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-04-16 19:46:12,565",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c8"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-04-16 19:46:12,565",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02f40000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000a000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-04-16 19:46:12,565",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-04-16 19:46:12,565",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b8"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-04-16 19:46:12,565",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll.123.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a1d",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02f40000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02f40000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000a000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b8"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll.124.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-04-16 19:46:12,581",
            "thread_id": "732",
            "caller": "0x00bc5a3e",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02f40000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c8"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02f40000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000a000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll.2.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5a5f",
            "parentcaller": "0x00bc42a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02f40000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-04-16 19:46:12,596",
            "thread_id": "732",
            "caller": "0x00bc5abb",
            "parentcaller": "0x00bc42a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-04-16 19:46:12,612",
            "thread_id": "732",
            "caller": "0x00bc5abb",
            "parentcaller": "0x00bc42a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002cc"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-04-16 19:46:12,612",
            "thread_id": "732",
            "caller": "0x00bc5abb",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-04-16 19:46:12,612",
            "thread_id": "732",
            "caller": "0x00bc5abb",
            "parentcaller": "0x00bc42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00120089",
                "pretty_value": "FILE_GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\rundll32.exe"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-04-16 19:46:12,643",
            "thread_id": "732",
            "caller": "0x00bc5abb",
            "parentcaller": "0x00bc42a3",
            "category": "__notification__",
            "api": "sysenter",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadIdentifier",
                "value": "732"
              },
              {
                "name": "Module",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "Return Address",
                "value": "0x76ad24ac"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-04-16 19:46:12,659",
            "thread_id": "732",
            "caller": "0x00bc5abb",
            "parentcaller": "0x00bc42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-04-16 19:46:12,659",
            "thread_id": "732",
            "caller": "0x00bc5d94",
            "parentcaller": "0x00bc42ae",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-04-16 19:46:12,659",
            "thread_id": "732",
            "caller": "0x00bc5d1d",
            "parentcaller": "0x00bc5db9",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "18"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-04-16 19:46:12,659",
            "thread_id": "732",
            "caller": "0x00bc5d42",
            "parentcaller": "0x00bc5db9",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "20"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-04-16 19:46:12,659",
            "thread_id": "732",
            "caller": "0x00bc5dc4",
            "parentcaller": "0x00bc42ae",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-04-16 19:46:12,659",
            "thread_id": "732",
            "caller": "0x00bc3c8d",
            "parentcaller": "0x00bc3e97",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin"
              },
              {
                "name": "DllBase",
                "value": "0x05c10000"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3c8d",
            "parentcaller": "0x00bc3e97",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x05c10000"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3d51",
            "parentcaller": "0x00bc3e97",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "34",
                "pretty_value": "ProcessExecuteFlags"
              },
              {
                "name": "ProcessInformation",
                "value": "13"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3da6",
            "parentcaller": "0x00bc3eb2",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": false,
            "return": "0xffffffffc0000138",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ClientPlugin.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x05c10000"
              },
              {
                "name": "FunctionName",
                "value": ""
              },
              {
                "name": "Ordinal",
                "value": "1"
              },
              {
                "name": "FunctionAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02be0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e8"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000e8"
              },
              {
                "name": "ValueName",
                "value": "Latest"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e8"
              }
            ],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-04-16 19:46:12,690",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000000e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-04-16 19:46:12,706",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000000e8"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-04-16 19:46:12,706",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002d8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02be0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00a3e6b8"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-04-16 19:46:12,706",
            "thread_id": "732",
            "caller": "0x00bc3924",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-04-16 19:46:12,706",
            "thread_id": "732",
            "caller": "0x00bc5e77",
            "parentcaller": "0x00bc69af",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x00bcb000"
              },
              {
                "name": "ModuleName",
                "value": "rundll32.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-04-16 19:46:12,706",
            "thread_id": "732",
            "caller": "0x00bc5e77",
            "parentcaller": "0x00bc69af",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x00bcb000"
              },
              {
                "name": "ModuleName",
                "value": "rundll32.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-04-16 19:46:12,846",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "__notification__",
            "api": "sysenter",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadIdentifier",
                "value": "732"
              },
              {
                "name": "Module",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "Return Address",
                "value": "0x772833ec"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-04-16 19:46:15,331",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\TextShaping"
              },
              {
                "name": "DllBase",
                "value": "0x73a40000"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-04-16 19:46:15,940",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\uxtheme"
              },
              {
                "name": "DllBase",
                "value": "0x745d0000"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-04-16 19:46:15,940",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\uxtheme.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x745d0000"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-04-16 19:46:16,018",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\MSCTF"
              },
              {
                "name": "DllBase",
                "value": "0x76ba0000"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-04-16 19:46:17,221",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\kernel.appcore"
              },
              {
                "name": "DllBase",
                "value": "0x75250000"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-04-16 19:46:17,299",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\bcryptPrimitives"
              },
              {
                "name": "DllBase",
                "value": "0x76d80000"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-04-16 19:46:21,752",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\ntmarta"
              },
              {
                "name": "DllBase",
                "value": "0x74190000"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-04-16 19:46:21,752",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\CoreMessaging"
              },
              {
                "name": "DllBase",
                "value": "0x73660000"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-04-16 19:46:21,768",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\wintypes"
              },
              {
                "name": "DllBase",
                "value": "0x73580000"
              }
            ],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-04-16 19:46:21,768",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\CoreUIComponents"
              },
              {
                "name": "DllBase",
                "value": "0x73700000"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-04-16 19:46:21,768",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\textinputframework"
              },
              {
                "name": "DllBase",
                "value": "0x73980000"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-04-16 19:46:26,252",
            "thread_id": "732",
            "caller": "0x00bc3a40",
            "parentcaller": "0x00bc3f58",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76ab0000"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-04-16 19:46:47,706",
            "thread_id": "4584",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-04-16 19:46:47,706",
            "thread_id": "4584",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-04-16 19:46:47,706",
            "thread_id": "4584",
            "caller": "0x77271454",
            "parentcaller": "0x7693b5fa",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x0000034c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-04-16 19:46:47,706",
            "thread_id": "4584",
            "caller": "0x76938f18",
            "parentcaller": "0x76938dcd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-04-16 19:46:47,706",
            "thread_id": "4736",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-04-16 19:46:47,706",
            "thread_id": "4736",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-04-16 19:47:08,893",
            "thread_id": "6020",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "6020"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-04-16 19:47:08,893",
            "thread_id": "6020",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-04-16 19:47:08,893",
            "thread_id": "5148",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "5148"
              }
            ],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-04-16 19:47:08,893",
            "thread_id": "5148",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-04-16 19:48:21,268",
            "thread_id": "4736",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "4736"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-04-16 19:48:21,268",
            "thread_id": "4736",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-04-16 19:48:21,268",
            "thread_id": "4584",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "4584"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-04-16 19:48:21,268",
            "thread_id": "4584",
            "caller": "0x7726269a",
            "parentcaller": "0x7693c192",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-04-16 19:48:21,268",
            "thread_id": "4584",
            "caller": "0x7726269a",
            "parentcaller": "0x7693c214",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-04-16 19:48:21,268",
            "thread_id": "4584",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 109
          }
        ],
        "threads": [
          "732",
          "1696",
          "6244",
          "2692",
          "4584",
          "4736",
          "6020",
          "5148"
        ],
        "environ": {
          "UserName": "cape",
          "ComputerName": "DESKTOP-PC01",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Users\\cape\\AppData\\Local\\Temp\\",
          "CommandLine": "\"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll\",#1",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "7c6d-8d48",
          "SystemVolumeGUID": "c48439d1-0000-0000-0000-100000000000",
          "MachineGUID": "",
          "MainExeBase": "0x00bc0000",
          "MainExeSize": "0x00014000",
          "Bitness": "32-bit",
          "DllBase": "0x05c10000"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      }
    ],
    "anomaly": [],
    "processtree": [
      {
        "name": "rundll32.exe",
        "pid": 1568,
        "parent_id": 3592,
        "module_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
        "children": [],
        "threads": [
          "732",
          "1696",
          "6244",
          "2692",
          "4584",
          "4736",
          "6020",
          "5148"
        ],
        "environ": {
          "UserName": "cape",
          "ComputerName": "DESKTOP-PC01",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Users\\cape\\AppData\\Local\\Temp\\",
          "CommandLine": "\"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll\",#1",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "7c6d-8d48",
          "SystemVolumeGUID": "c48439d1-0000-0000-0000-100000000000",
          "MachineGUID": "",
          "MainExeBase": "0x00bc0000",
          "MainExeSize": "0x00014000",
          "Bitness": "32-bit",
          "DllBase": "0x05c10000"
        }
      }
    ],
    "summary": {
      "files": [
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll.manifest",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll.123.Manifest",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll.124.Manifest",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll.2.Manifest",
        "C:\\Windows\\SysWOW64\\rundll32.exe",
        "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
      ],
      "read_files": [],
      "write_files": [],
      "delete_files": [],
      "keys": [
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
      ],
      "read_keys": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
      ],
      "write_keys": [],
      "delete_keys": [],
      "executed_commands": [],
      "resolved_apis": [],
      "mutexes": [],
      "created_services": [],
      "started_services": []
    },
    "enhanced": [
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:46:12,565",
        "eid": 1,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:46:12,581",
        "eid": 2,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:46:12,596",
        "eid": 3,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:46:12,612",
        "eid": 4,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-16 19:46:12,690",
        "eid": 5,
        "data": {
          "file": "C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll",
          "pathtofile": null,
          "moduleaddress": "0x05c10000"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:46:12,690",
        "eid": 6,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest",
          "content": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-16 19:46:15,940",
        "eid": 7,
        "data": {
          "file": "C:\\Windows\\System32\\uxtheme.dll",
          "pathtofile": null,
          "moduleaddress": "0x745d0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-16 19:46:26,252",
        "eid": 8,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76ab0000"
        }
      }
    ],
    "encryptedbuffers": [],
    "network_map": {
      "endpoint_map": {},
      "http_host_map": {},
      "dns_intents": {},
      "http_requests": [],
      "winhttp_sessions": []
    }
  },
  "debug": {
    "log": "2026-03-05 20:34:41,788 [root] INFO: Date set to: 20260416T22:44:30, timeout set to: 200\n2026-04-16 22:44:30,187 [root] DEBUG: Starting analyzer from: C:\\ltb6yatm\n2026-04-16 22:44:30,281 [root] DEBUG: Storing results at: C:\\OHjuCIJf\n2026-04-16 22:44:30,297 [root] DEBUG: Pipe server name: \\\\.\\PIPE\\THzYLz\n2026-04-16 22:44:30,328 [root] DEBUG: Python path: C:\\Python310\n2026-04-16 22:44:30,343 [root] INFO: analysis running as an admin\n2026-04-16 22:44:30,343 [root] INFO: analysis package specified: \"dll\"\n2026-04-16 22:44:30,359 [root] DEBUG: importing analysis package module: \"modules.packages.dll\"...\n2026-04-16 22:44:30,375 [root] DEBUG: imported analysis package \"dll\"\n2026-04-16 22:44:30,375 [root] DEBUG: initializing analysis package \"dll\"...\n2026-04-16 22:44:30,375 [lib.common.common] INFO: wrapping\n2026-04-16 22:44:30,547 [lib.core.compound] INFO: C:\\Users\\cape\\AppData\\Local\\Temp already exists, skipping creation\n2026-04-16 22:44:30,562 [root] DEBUG: New location of moved file: C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll\n2026-04-16 22:44:30,578 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL option\n2026-04-16 22:44:30,578 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL_64 option\n2026-04-16 22:44:30,578 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader option\n2026-04-16 22:44:30,578 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader_64 option\n2026-04-16 22:44:30,594 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.browser\"\n2026-04-16 22:44:30,969 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.digisig\"\n2026-04-16 22:44:31,047 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.disguise\"\n2026-04-16 22:44:31,093 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.human\"\n2026-04-16 22:44:31,187 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'\n2026-04-16 22:44:31,609 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'\n2026-04-16 22:44:31,828 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'\n2026-04-16 22:44:34,140 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance\n2026-04-16 22:44:34,140 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.screenshots\"\n2026-04-16 22:44:34,140 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.tlsdump\"\n2026-04-16 22:44:34,140 [root] DEBUG: Initialized auxiliary module \"Browser\"\n2026-04-16 22:44:34,140 [root] DEBUG: attempting to configure 'Browser' from data\n2026-04-16 22:44:34,156 [root] DEBUG: module Browser does not support data configuration, ignoring\n2026-04-16 22:44:34,156 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.browser\"...\n2026-04-16 22:44:34,156 [root] DEBUG: Started auxiliary module modules.auxiliary.browser\n2026-04-16 22:44:34,156 [root] DEBUG: Initialized auxiliary module \"DigiSig\"\n2026-04-16 22:44:34,156 [root] DEBUG: attempting to configure 'DigiSig' from data\n2026-04-16 22:44:34,172 [root] DEBUG: module DigiSig does not support data configuration, ignoring\n2026-04-16 22:44:34,172 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.digisig\"...\n2026-04-16 22:44:34,172 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature\n2026-04-16 22:44:57,734 [modules.auxiliary.digisig] DEBUG: File is not signed\n2026-04-16 22:44:57,750 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json\n2026-04-16 22:44:57,750 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig\n2026-04-16 22:44:57,750 [root] DEBUG: Initialized auxiliary module \"Disguise\"\n2026-04-16 22:44:57,750 [root] DEBUG: attempting to configure 'Disguise' from data\n2026-04-16 22:44:57,750 [root] DEBUG: module Disguise does not support data configuration, ignoring\n2026-04-16 22:44:57,750 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.disguise\"...\n2026-04-16 22:44:57,875 [modules.auxiliary.disguise] INFO: Disguising GUID to b891db33-606d-41e0-a0dd-e7dd26a578cf\n2026-04-16 22:44:57,875 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise\n2026-04-16 22:44:57,890 [root] DEBUG: Initialized auxiliary module \"Human\"\n2026-04-16 22:44:57,890 [root] DEBUG: attempting to configure 'Human' from data\n2026-04-16 22:44:57,890 [root] DEBUG: module Human does not support data configuration, ignoring\n2026-04-16 22:44:57,890 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.human\"...\n2026-04-16 22:44:57,906 [root] DEBUG: Started auxiliary module modules.auxiliary.human\n2026-04-16 22:44:57,906 [root] DEBUG: Initialized auxiliary module \"Screenshots\"\n2026-04-16 22:44:57,906 [root] DEBUG: attempting to configure 'Screenshots' from data\n2026-04-16 22:44:57,906 [root] DEBUG: module Screenshots does not support data configuration, ignoring\n2026-04-16 22:44:57,906 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.screenshots\"...\n2026-04-16 22:44:58,250 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots\n2026-04-16 22:44:58,250 [root] DEBUG: Initialized auxiliary module \"TLSDumpMasterSecrets\"\n2026-04-16 22:44:58,469 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data\n2026-04-16 22:44:58,484 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring\n2026-04-16 22:44:58,484 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.tlsdump\"...\n2026-04-16 22:44:58,500 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644\n2026-04-16 22:45:00,218 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\\ltb6yatm\\dll\\644.ini\n2026-04-16 22:45:01,312 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor\n2026-04-16 22:45:02,531 [lib.api.process] INFO: 64-bit DLL to inject is C:\\ltb6yatm\\dll\\rXJCncX.dll, loader C:\\ltb6yatm\\bin\\WBIUjUol.exe\n2026-04-16 22:45:03,063 [root] DEBUG: Loader: Injecting process 644 with C:\\ltb6yatm\\dll\\rXJCncX.dll.\n2026-04-16 22:45:05,531 [root] DEBUG: 644: Python path set to 'C:\\Python310'.\n2026-04-16 22:45:05,547 [root] DEBUG: 644: Disabling sleep skipping.\n2026-04-16 22:45:05,547 [root] DEBUG: 644: TLS secret dump mode enabled.\n2026-04-16 22:45:06,766 [root] DEBUG: 644: Yara error: Scanning timed out\n2026-04-16 22:45:06,766 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABC70000, thread 5740, image base 0x00007FF7C23E0000, stack from 0x0000008E4C471000-0x0000008E4C480000\n2026-04-16 22:45:06,781 [root] DEBUG: 644: Commandline: C:\\Windows\\system32\\lsass.exe\n2026-04-16 22:45:06,812 [root] DEBUG: 644: Hooked 5 out of 5 functions\n2026-04-16 22:45:06,828 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.\n2026-04-16 22:45:06,828 [root] DEBUG: Successfully injected DLL C:\\ltb6yatm\\dll\\rXJCncX.dll.\n2026-04-16 22:45:06,844 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>\n2026-04-16 22:45:06,844 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump\n2026-04-16 22:45:08,547 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\\OHjuCIJf\\tlsdump\\tlsdump.log\n2026-04-16 22:46:01,875 [root] INFO: Restarting WMI Service\n2026-04-16 22:46:04,000 [root] DEBUG: package modules.packages.dll does not support configure, ignoring\n2026-04-16 22:46:04,000 [root] WARNING: configuration error for package modules.packages.dll: error importing data.packages.dll: No module named 'data.packages'\n2026-04-16 22:46:04,125 [lib.core.compound] INFO: C:\\Users\\cape\\AppData\\Local\\Temp already exists, skipping creation\n2026-04-16 22:46:04,641 [lib.api.process] INFO: Successfully executed process from path \"C:\\Windows\\System32\\rundll32.exe\" with arguments \"\"C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll\",#1\" with pid 1568\n2026-04-16 22:46:04,641 [lib.api.process] INFO: Monitor config for <Process 1568 rundll32.exe>: C:\\ltb6yatm\\dll\\1568.ini\n2026-04-16 22:46:04,656 [lib.api.process] INFO: 32-bit DLL to inject is C:\\ltb6yatm\\dll\\iyMbcod.dll, loader C:\\ltb6yatm\\bin\\QSOiFni.exe\n2026-04-16 22:46:05,062 [root] DEBUG: Loader: Injecting process 1568 (thread 732) with C:\\ltb6yatm\\dll\\iyMbcod.dll.\n2026-04-16 22:46:05,167 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-04-16 22:46:05,167 [root] DEBUG: Successfully injected DLL C:\\ltb6yatm\\dll\\iyMbcod.dll.\n2026-04-16 22:46:05,177 [lib.api.process] INFO: Injected into 32-bit <Process 1568 rundll32.exe>\n2026-04-16 22:46:07,253 [lib.api.process] INFO: Successfully resumed <Process 1568 rundll32.exe>\n2026-04-16 22:46:09,567 [root] DEBUG: 1568: Python path set to 'C:\\Python310'.\n2026-04-16 22:46:09,722 [root] DEBUG: 1568: Disabling sleep skipping.\n2026-04-16 22:46:09,722 [root] DEBUG: 1568: Dropped file limit defaulting to 100.\n2026-04-16 22:46:09,769 [root] DEBUG: 1568: YaraInit: Compiled 44 rule files\n2026-04-16 22:46:09,769 [root] DEBUG: 1568: YaraInit: Compiled rules saved to file C:\\ltb6yatm\\data\\yara\\capemon.yac\n2026-04-16 22:46:09,769 [root] DEBUG: 1568: YaraScan: Scanning 0x00BC0000, size 0x136e8\n2026-04-16 22:46:09,769 [root] DEBUG: 1568: Monitor initialised: 32-bit capemon loaded in process 1568 at 0x73ae0000, thread 732, image base 0xbc0000, stack from 0xa32000-0xa40000\n2026-04-16 22:46:09,784 [root] DEBUG: 1568: Commandline: \"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin.dll\",#1\n2026-04-16 22:46:10,945 [root] DEBUG: 1568: Yara error: Scanning timed out\n2026-04-16 22:46:10,976 [root] DEBUG: 1568: hook_api: Warning - CreateProcessA export address 0x76AE2D90 differs from GetProcAddress -> 0x73E422A0 (AcLayers.DLL::0xfd3922a0)\n2026-04-16 22:46:10,976 [root] DEBUG: 1568: hook_api: Warning - CreateProcessW export address 0x76AC88E0 differs from GetProcAddress -> 0x73E424E0 (AcLayers.DLL::0xfd3924e0)\n2026-04-16 22:46:10,976 [root] DEBUG: 1568: hook_api: Warning - WinExec export address 0x76B0CF20 differs from GetProcAddress -> 0x73E427A0 (AcLayers.DLL::0xfd3927a0)\n2026-04-16 22:46:11,536 [root] WARNING: b'Unable to place hook on GetCommandLineA'\n2026-04-16 22:46:11,536 [root] DEBUG: 1568: set_hooks: Unable to hook GetCommandLineA\n2026-04-16 22:46:11,552 [root] WARNING: b'Unable to place hook on GetCommandLineW'\n2026-04-16 22:46:11,552 [root] DEBUG: 1568: set_hooks: Unable to hook GetCommandLineW\n2026-04-16 22:46:12,305 [root] DEBUG: 1568: Hooked 630 out of 632 functions\n2026-04-16 22:46:12,327 [root] DEBUG: 1568: Syscall hook installed, syscall logging level 1\n2026-04-16 22:46:12,343 [root] DEBUG: 1568: RestoreHeaders: Restored original import table.\n2026-04-16 22:46:12,343 [root] INFO: Loaded monitor into process with pid 1568\n2026-04-16 22:46:12,343 [root] DEBUG: 1568: caller_dispatch: Added region at 0x00BC0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00BC5F1A, thread 732).\n2026-04-16 22:46:12,343 [root] DEBUG: 1568: YaraScan: Scanning 0x00BC0000, size 0x136e8\n2026-04-16 22:46:12,359 [root] DEBUG: 1568: ProcessImageBase: Main module image at 0x00BC0000 unmodified (entropy change 0.000000e+00)\n2026-04-16 22:46:12,646 [root] DEBUG: 1568: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 732).\n2026-04-16 22:46:12,662 [root] DEBUG: 1568: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \\Device\\HarddiskVolume1\\Windows\\SysWOW64\\kernel32.dll is in known range, skipping\n2026-04-16 22:46:12,662 [root] DEBUG: 1568: Target DLL loaded at 0x05C10000: C:\\Users\\cape\\AppData\\Local\\Temp\\ClientPlugin (0xa000 bytes).\n2026-04-16 22:46:12,678 [root] DEBUG: 1568: YaraScan: Scanning 0x05C10000, size 0x1f0\n2026-04-16 22:46:14,946 [root] DEBUG: 1568: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 732).\n2026-04-16 22:46:14,946 [root] DEBUG: 1568: ProcessTrackedRegion: Region at 0x77150000 mapped as \\Device\\HarddiskVolume1\\Windows\\SysWOW64\\KernelBase.dll is in known range, skipping\n2026-04-16 22:46:15,349 [root] DEBUG: 1568: DLL loaded at 0x73A40000: C:\\Windows\\SYSTEM32\\TextShaping (0x94000 bytes).\n2026-04-16 22:46:15,948 [root] DEBUG: 1568: DLL loaded at 0x745D0000: C:\\Windows\\system32\\uxtheme (0x74000 bytes).\n2026-04-16 22:46:16,026 [root] DEBUG: 1568: DLL loaded at 0x76BA0000: C:\\Windows\\System32\\MSCTF (0xd4000 bytes).\n2026-04-16 22:46:17,276 [root] DEBUG: 1568: set_hooks_by_export_directory: Hooked 0 out of 632 functions\n2026-04-16 22:46:17,308 [root] DEBUG: 1568: DLL loaded at 0x75250000: C:\\Windows\\SYSTEM32\\kernel.appcore (0xf000 bytes).\n2026-04-16 22:46:17,323 [root] DEBUG: 1568: DLL loaded at 0x76D80000: C:\\Windows\\System32\\bcryptPrimitives (0x5f000 bytes).\n2026-04-16 22:46:21,761 [root] DEBUG: 1568: DLL loaded at 0x74190000: C:\\Windows\\SYSTEM32\\ntmarta (0x29000 bytes).\n2026-04-16 22:46:21,776 [root] DEBUG: 1568: DLL loaded at 0x73660000: C:\\Windows\\System32\\CoreMessaging (0x9b000 bytes).\n2026-04-16 22:46:21,776 [root] DEBUG: 1568: DLL loaded at 0x73580000: C:\\Windows\\SYSTEM32\\wintypes (0xdb000 bytes).\n2026-04-16 22:46:21,776 [root] DEBUG: 1568: DLL loaded at 0x73700000: C:\\Windows\\System32\\CoreUIComponents (0x27e000 bytes).\n2026-04-16 22:46:21,776 [root] DEBUG: 1568: DLL loaded at 0x73980000: C:\\Windows\\SYSTEM32\\textinputframework (0xb9000 bytes).\n2026-04-16 22:49:27,557 [root] INFO: Analysis timeout hit, terminating analysis\n2026-04-16 22:49:27,557 [lib.api.process] INFO: Terminate event set for <Process 1568 rundll32.exe>\n2026-04-16 22:49:27,557 [root] DEBUG: 1568: Terminate Event: Attempting to dump process 1568\n2026-04-16 22:49:27,557 [root] DEBUG: 1568: VerifyCodeSection: Executable code does not match, 0x18f2 of 0x18f3 matching\n2026-04-16 22:49:27,573 [root] DEBUG: 1568: DoProcessDump: Code modification detected, dumping Imagebase at 0x05C10000.\n2026-04-16 22:49:27,573 [root] DEBUG: 1568: DumpImageInCurrentProcess: Attempting to dump virtual PE image.\n2026-04-16 22:49:27,573 [root] DEBUG: 1568: DumpProcess: Instantiating PeParser with address: 0x05C10000.\n2026-04-16 22:49:27,573 [root] DEBUG: 1568: DumpProcess: Module entry point VA is 0x05C138EE.\n2026-04-16 22:49:27,589 [root] DEBUG: 1568: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x05C14000, section 2\n2026-04-16 22:49:27,589 [root] DEBUG: 1568: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x05C18000, section 3\n2026-04-16 22:49:27,885 [lib.common.results] INFO: Uploading file C:\\OHjuCIJf\\CAPE\\1568_3628527491916442026 to procdump\\9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3; Size is 7680; Max size: 100000000\n2026-04-16 22:49:27,979 [root] DEBUG: 1568: DumpProcess: Module image dump success - dump size 0x1e00.\n2026-04-16 22:49:27,995 [lib.api.process] INFO: Termination confirmed for <Process 1568 rundll32.exe>\n2026-04-16 22:49:27,995 [root] INFO: Terminate event set for process 1568\n2026-04-16 22:49:27,995 [root] INFO: Created shutdown mutex\n2026-04-16 22:49:28,010 [root] DEBUG: 1568: Terminate Event: monitor shutdown complete for process 1568\n2026-04-16 22:49:29,042 [root] INFO: Shutting down package\n2026-04-16 22:49:29,058 [root] INFO: Stopping auxiliary modules\n2026-04-16 22:49:29,058 [root] INFO: Stopping auxiliary module: Browser\n2026-04-16 22:49:29,073 [root] INFO: Stopping auxiliary module: Human\n2026-04-16 22:49:29,495 [root] INFO: Stopping auxiliary module: Screenshots\n2026-04-16 22:49:30,182 [root] INFO: Finishing auxiliary modules\n2026-04-16 22:49:30,182 [root] INFO: Shutting down pipe server and dumping dropped files\n2026-04-16 22:49:30,182 [root] WARNING: Folder at path \"C:\\OHjuCIJf\\debugger\" does not exist, skipping\n2026-04-16 22:49:30,182 [root] INFO: Uploading files at path \"C:\\OHjuCIJf\\tlsdump\"\n2026-04-16 22:49:30,182 [lib.common.results] INFO: Uploading file C:\\OHjuCIJf\\tlsdump\\tlsdump.log to tlsdump\\tlsdump.log; Size is 17536; Max size: 100000000\n2026-04-16 22:49:30,213 [root] INFO: Analysis completed\n",
    "errors": []
  },
  "network": {
    "pcap_sha256": "ed5e33f14591759878c79b58ca78dfb8699b3644aff4d8ff8545fb74546b4244",
    "hosts": [
      {
        "ip": "20.93.72.182",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "46.149.110.67",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          80
        ]
      },
      {
        "ip": "72.154.7.16",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.108",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.100",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.105",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.102",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.98",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.101",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.107",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.109",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.165.94.54",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "13.107.6.156",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "84.47.178.41",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "150.171.27.11",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "173.194.73.94",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "i.pki.goog",
        "inaddrarpa": "",
        "ports": [
          80
        ]
      },
      {
        "ip": "84.47.178.49",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "52.123.242.97",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "40.126.53.14",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.42.65.93",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "4.207.247.139",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "84.47.178.56",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.189.173.2",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      }
    ],
    "domains": [
      {
        "domain": "i.pki.goog",
        "ip": "64.233.162.94"
      }
    ],
    "tcp": [
      {
        "src": "192.168.1.100",
        "sport": 49723,
        "dst": "20.189.173.2",
        "dport": 443,
        "offset": 24,
        "time": 0.0
      },
      {
        "src": "192.168.1.100",
        "sport": 49724,
        "dst": "20.189.173.2",
        "dport": 443,
        "offset": 95,
        "time": 0.9216852188110352
      },
      {
        "src": "192.168.1.100",
        "sport": 49718,
        "dst": "84.47.178.56",
        "dport": 443,
        "offset": 166,
        "time": 4.828071117401123
      },
      {
        "src": "192.168.1.100",
        "sport": 49806,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 682,
        "time": 5.2516350746154785
      },
      {
        "src": "192.168.1.100",
        "sport": 49784,
        "dst": "40.126.53.14",
        "dport": 443,
        "offset": 8587,
        "time": 7.677495002746582
      },
      {
        "src": "192.168.1.100",
        "sport": 49810,
        "dst": "13.107.253.44",
        "dport": 443,
        "offset": 26796,
        "time": 8.231582164764404
      },
      {
        "src": "192.168.1.100",
        "sport": 49813,
        "dst": "84.47.178.49",
        "dport": 443,
        "offset": 53334,
        "time": 8.36952805519104
      },
      {
        "src": "192.168.1.100",
        "sport": 49814,
        "dst": "84.47.178.49",
        "dport": 443,
        "offset": 58063,
        "time": 8.371561050415039
      },
      {
        "src": "192.168.1.100",
        "sport": 49815,
        "dst": "150.171.109.51",
        "dport": 443,
        "offset": 82700,
        "time": 8.722498178482056
      },
      {
        "src": "192.168.1.100",
        "sport": 49817,
        "dst": "23.11.40.157",
        "dport": 80,
        "offset": 324237,
        "time": 9.619777202606201
      },
      {
        "src": "192.168.1.100",
        "sport": 49820,
        "dst": "40.126.53.14",
        "dport": 443,
        "offset": 330025,
        "time": 10.039916038513184
      },
      {
        "src": "192.168.1.100",
        "sport": 49819,
        "dst": "52.185.211.133",
        "dport": 443,
        "offset": 344277,
        "time": 10.103654146194458
      },
      {
        "src": "192.168.1.100",
        "sport": 49823,
        "dst": "8.8.8.8",
        "dport": 443,
        "offset": 386257,
        "time": 10.284924983978271
      },
      {
        "src": "192.168.1.100",
        "sport": 49824,
        "dst": "173.194.73.94",
        "dport": 80,
        "offset": 388199,
        "time": 10.3021080493927
      },
      {
        "src": "192.168.1.100",
        "sport": 49826,
        "dst": "62.74.30.154",
        "dport": 80,
        "offset": 433701,
        "time": 10.672446012496948
      },
      {
        "src": "192.168.1.100",
        "sport": 49728,
        "dst": "150.171.27.11",
        "dport": 443,
        "offset": 435991,
        "time": 10.751543998718262
      },
      {
        "src": "192.168.1.100",
        "sport": 49827,
        "dst": "40.126.53.14",
        "dport": 443,
        "offset": 438639,
        "time": 10.782604217529297
      },
      {
        "src": "192.168.1.100",
        "sport": 49828,
        "dst": "150.171.27.11",
        "dport": 443,
        "offset": 439092,
        "time": 10.793625116348267
      },
      {
        "src": "192.168.1.100",
        "sport": 49831,
        "dst": "20.42.65.93",
        "dport": 443,
        "offset": 489493,
        "time": 11.934559106826782
      },
      {
        "src": "192.168.1.100",
        "sport": 49829,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 505136,
        "time": 14.672043085098267
      },
      {
        "src": "192.168.1.100",
        "sport": 49834,
        "dst": "188.43.78.74",
        "dport": 80,
        "offset": 529809,
        "time": 16.617967128753662
      },
      {
        "src": "192.168.1.100",
        "sport": 49837,
        "dst": "135.233.95.144",
        "dport": 443,
        "offset": 1124483,
        "time": 18.71474599838257
      },
      {
        "src": "192.168.1.100",
        "sport": 49839,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 1180581,
        "time": 22.99627709388733
      },
      {
        "src": "192.168.1.100",
        "sport": 49841,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 1236142,
        "time": 24.325780153274536
      },
      {
        "src": "192.168.1.100",
        "sport": 49843,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 1266924,
        "time": 25.704861164093018
      },
      {
        "src": "192.168.1.100",
        "sport": 49845,
        "dst": "40.126.53.14",
        "dport": 443,
        "offset": 1279073,
        "time": 28.172266006469727
      },
      {
        "src": "192.168.1.100",
        "sport": 49847,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 1296096,
        "time": 28.414132118225098
      },
      {
        "src": "192.168.1.100",
        "sport": 49849,
        "dst": "40.74.98.195",
        "dport": 443,
        "offset": 1355539,
        "time": 29.48596715927124
      },
      {
        "src": "192.168.1.100",
        "sport": 49851,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 1361320,
        "time": 29.958550214767456
      },
      {
        "src": "192.168.1.100",
        "sport": 49856,
        "dst": "199.232.214.172",
        "dport": 80,
        "offset": 2349201,
        "time": 38.1322979927063
      },
      {
        "src": "192.168.1.100",
        "sport": 49710,
        "dst": "84.47.178.41",
        "dport": 443,
        "offset": 2365900,
        "time": 39.715800046920776
      },
      {
        "src": "192.168.1.100",
        "sport": 49716,
        "dst": "84.47.178.56",
        "dport": 443,
        "offset": 2366041,
        "time": 39.79370307922363
      },
      {
        "src": "192.168.1.100",
        "sport": 49720,
        "dst": "8.8.4.4",
        "dport": 443,
        "offset": 2366323,
        "time": 40.98126006126404
      },
      {
        "src": "192.168.1.100",
        "sport": 49708,
        "dst": "13.107.6.156",
        "dport": 443,
        "offset": 2366464,
        "time": 41.012402057647705
      },
      {
        "src": "192.168.1.100",
        "sport": 49712,
        "dst": "84.47.178.41",
        "dport": 443,
        "offset": 2366769,
        "time": 42.19987416267395
      },
      {
        "src": "192.168.1.100",
        "sport": 49861,
        "dst": "135.233.95.144",
        "dport": 443,
        "offset": 2383819,
        "time": 45.020529985427856
      },
      {
        "src": "192.168.1.100",
        "sport": 49866,
        "dst": "51.11.168.232",
        "dport": 443,
        "offset": 2390361,
        "time": 48.63370609283447
      },
      {
        "src": "192.168.1.100",
        "sport": 49867,
        "dst": "20.165.94.54",
        "dport": 443,
        "offset": 2406467,
        "time": 49.075719118118286
      },
      {
        "src": "192.168.1.100",
        "sport": 49869,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 2419657,
        "time": 50.22336220741272
      },
      {
        "src": "192.168.1.100",
        "sport": 49870,
        "dst": "23.46.118.69",
        "dport": 443,
        "offset": 2431532,
        "time": 55.46841216087341
      },
      {
        "src": "192.168.1.100",
        "sport": 49872,
        "dst": "135.233.95.144",
        "dport": 443,
        "offset": 2476419,
        "time": 58.5285120010376
      },
      {
        "src": "192.168.1.100",
        "sport": 49874,
        "dst": "52.185.211.133",
        "dport": 443,
        "offset": 2775805,
        "time": 61.255245208740234
      },
      {
        "src": "192.168.1.100",
        "sport": 49876,
        "dst": "52.185.211.133",
        "dport": 443,
        "offset": 2794130,
        "time": 64.78270602226257
      },
      {
        "src": "192.168.1.100",
        "sport": 49878,
        "dst": "20.71.22.186",
        "dport": 443,
        "offset": 2809304,
        "time": 66.53502917289734
      },
      {
        "src": "192.168.1.100",
        "sport": 49880,
        "dst": "52.185.211.133",
        "dport": 443,
        "offset": 2817223,
        "time": 66.96833419799805
      },
      {
        "src": "192.168.1.100",
        "sport": 49881,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 2825608,
        "time": 73.91817116737366
      },
      {
        "src": "4.207.247.139",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49899,
        "offset": 2836188,
        "time": 75.53879404067993
      },
      {
        "src": "192.168.1.100",
        "sport": 49883,
        "dst": "51.11.168.232",
        "dport": 443,
        "offset": 2841042,
        "time": 75.71029019355774
      },
      {
        "src": "192.168.1.100",
        "sport": 49885,
        "dst": "204.79.197.203",
        "dport": 80,
        "offset": 2850895,
        "time": 76.250244140625
      },
      {
        "src": "192.168.1.100",
        "sport": 49887,
        "dst": "51.11.168.232",
        "dport": 443,
        "offset": 2868298,
        "time": 77.53445410728455
      },
      {
        "src": "192.168.1.100",
        "sport": 49889,
        "dst": "199.232.214.172",
        "dport": 80,
        "offset": 2880710,
        "time": 77.76675200462341
      },
      {
        "src": "192.168.1.100",
        "sport": 49892,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 3642791,
        "time": 85.66664099693298
      },
      {
        "src": "192.168.1.100",
        "sport": 49904,
        "dst": "52.123.245.100",
        "dport": 443,
        "offset": 3676246,
        "time": 111.52972507476807
      },
      {
        "src": "192.168.1.100",
        "sport": 49910,
        "dst": "204.79.197.203",
        "dport": 80,
        "offset": 3694403,
        "time": 122.80199313163757
      },
      {
        "src": "192.168.1.100",
        "sport": 49913,
        "dst": "2.23.89.205",
        "dport": 443,
        "offset": 4002604,
        "time": 135.42738604545593
      },
      {
        "src": "192.168.1.100",
        "sport": 49915,
        "dst": "46.149.110.67",
        "dport": 80,
        "offset": 4026124,
        "time": 136.00152206420898
      },
      {
        "src": "192.168.1.100",
        "sport": 49916,
        "dst": "46.149.110.67",
        "dport": 80,
        "offset": 4038026,
        "time": 137.73136806488037
      },
      {
        "src": "192.168.1.100",
        "sport": 49918,
        "dst": "46.149.110.67",
        "dport": 80,
        "offset": 4056307,
        "time": 137.86988019943237
      },
      {
        "src": "192.168.1.100",
        "sport": 49920,
        "dst": "72.154.7.107",
        "dport": 443,
        "offset": 5870049,
        "time": 142.30218720436096
      },
      {
        "src": "192.168.1.100",
        "sport": 49922,
        "dst": "72.154.7.106",
        "dport": 443,
        "offset": 5870937,
        "time": 142.34104108810425
      },
      {
        "src": "192.168.1.100",
        "sport": 49924,
        "dst": "2.23.90.38",
        "dport": 443,
        "offset": 5894304,
        "time": 143.18134212493896
      },
      {
        "src": "192.168.1.100",
        "sport": 49926,
        "dst": "2.23.90.38",
        "dport": 443,
        "offset": 5919161,
        "time": 143.48004817962646
      },
      {
        "src": "192.168.1.100",
        "sport": 49928,
        "dst": "52.123.245.96",
        "dport": 443,
        "offset": 5934954,
        "time": 148.15693616867065
      },
      {
        "src": "128.75.237.145",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49862,
        "offset": 6040501,
        "time": 150.19310307502747
      },
      {
        "src": "23.46.118.69",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49883,
        "offset": 6444231,
        "time": 157.74421906471252
      },
      {
        "src": "192.168.1.100",
        "sport": 49931,
        "dst": "199.232.214.172",
        "dport": 80,
        "offset": 6446686,
        "time": 170.05976605415344
      },
      {
        "src": "192.168.1.100",
        "sport": 49933,
        "dst": "13.107.226.44",
        "dport": 443,
        "offset": 6482660,
        "time": 189.24102902412415
      },
      {
        "src": "192.168.1.100",
        "sport": 49935,
        "dst": "188.43.72.25",
        "dport": 443,
        "offset": 6494186,
        "time": 189.5117790699005
      },
      {
        "src": "192.168.1.100",
        "sport": 49937,
        "dst": "52.123.243.46",
        "dport": 443,
        "offset": 7016622,
        "time": 192.1138551235199
      },
      {
        "src": "192.168.1.100",
        "sport": 49939,
        "dst": "23.11.40.157",
        "dport": 80,
        "offset": 116543744,
        "time": 247.75961899757385
      },
      {
        "src": "192.168.1.100",
        "sport": 49941,
        "dst": "13.107.226.44",
        "dport": 443,
        "offset": 117417250,
        "time": 288.22814202308655
      },
      {
        "src": "192.168.1.100",
        "sport": 49943,
        "dst": "52.123.245.109",
        "dport": 443,
        "offset": 117927745,
        "time": 289.35010719299316
      },
      {
        "src": "192.168.1.100",
        "sport": 49945,
        "dst": "150.171.22.17",
        "dport": 443,
        "offset": 117955665,
        "time": 294.9355661869049
      }
    ],
    "udp": [
      {
        "src": "192.168.1.100",
        "sport": 64198,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 81068,
        "time": 8.619002103805542
      },
      {
        "src": "192.168.1.100",
        "sport": 64629,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 323592,
        "time": 9.533440113067627
      },
      {
        "src": "192.168.1.100",
        "sport": 64008,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 329711,
        "time": 10.021758079528809
      },
      {
        "src": "192.168.1.100",
        "sport": 62931,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 384899,
        "time": 10.259932041168213
      },
      {
        "src": "192.168.1.100",
        "sport": 53260,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 426895,
        "time": 10.527546167373657
      },
      {
        "src": "192.168.1.100",
        "sport": 50914,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 438298,
        "time": 10.772236108779907
      },
      {
        "src": "192.168.1.100",
        "sport": 50041,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 833588,
        "time": 16.791956186294556
      },
      {
        "src": "192.168.1.100",
        "sport": 59742,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1124904,
        "time": 18.729048013687134
      },
      {
        "src": "192.168.1.100",
        "sport": 63003,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1273636,
        "time": 28.018578052520752
      },
      {
        "src": "192.168.1.100",
        "sport": 64104,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1354745,
        "time": 29.21305513381958
      },
      {
        "src": "192.168.1.100",
        "sport": 138,
        "dst": "192.168.1.255",
        "dport": 138,
        "offset": 1398713,
        "time": 31.651660203933716
      },
      {
        "src": "192.168.1.100",
        "sport": 53255,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2388037,
        "time": 48.4785270690918
      },
      {
        "src": "192.168.1.100",
        "sport": 56532,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2402006,
        "time": 48.8843560218811
      },
      {
        "src": "192.168.1.100",
        "sport": 63053,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2430903,
        "time": 55.35902214050293
      },
      {
        "src": "192.168.1.100",
        "sport": 52139,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2775219,
        "time": 61.075536012649536
      },
      {
        "src": "192.168.1.100",
        "sport": 50648,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2808622,
        "time": 66.45126605033875
      },
      {
        "src": "192.168.1.100",
        "sport": 54240,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2836768,
        "time": 75.60008716583252
      },
      {
        "src": "192.168.1.100",
        "sport": 54943,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2845366,
        "time": 75.76450514793396
      },
      {
        "src": "192.168.1.100",
        "sport": 58676,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2873761,
        "time": 77.67727303504944
      },
      {
        "src": "192.168.1.100",
        "sport": 53559,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 3666374,
        "time": 107.70315217971802
      },
      {
        "src": "192.168.1.100",
        "sport": 52958,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 3693890,
        "time": 122.76284408569336
      },
      {
        "src": "192.168.1.100",
        "sport": 60076,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 4002037,
        "time": 135.379967212677
      },
      {
        "src": "192.168.1.100",
        "sport": 52129,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 4013510,
        "time": 135.76617002487183
      },
      {
        "src": "192.168.1.100",
        "sport": 61472,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 4027865,
        "time": 136.62558102607727
      },
      {
        "src": "192.168.1.100",
        "sport": 57845,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 5868399,
        "time": 142.08054304122925
      },
      {
        "src": "192.168.1.100",
        "sport": 62667,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 5869129,
        "time": 142.13284921646118
      },
      {
        "src": "192.168.1.100",
        "sport": 56355,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 5886473,
        "time": 142.8129141330719
      },
      {
        "src": "192.168.1.100",
        "sport": 62615,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 5893890,
        "time": 143.15784621238708
      },
      {
        "src": "192.168.1.100",
        "sport": 49739,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 6445584,
        "time": 169.79040217399597
      },
      {
        "src": "192.168.1.100",
        "sport": 50343,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 6462290,
        "time": 174.41894507408142
      },
      {
        "src": "192.168.1.100",
        "sport": 57944,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 6481484,
        "time": 189.19979310035706
      },
      {
        "src": "192.168.1.100",
        "sport": 51401,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 6484776,
        "time": 189.35574507713318
      },
      {
        "src": "192.168.1.100",
        "sport": 54744,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 7014556,
        "time": 191.96456217765808
      },
      {
        "src": "192.168.1.100",
        "sport": 60723,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 116534641,
        "time": 247.38235020637512
      },
      {
        "src": "192.168.1.100",
        "sport": 52622,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 116542781,
        "time": 247.65054416656494
      },
      {
        "src": "192.168.1.100",
        "sport": 53151,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 117926021,
        "time": 289.2802460193634
      },
      {
        "src": "192.168.1.100",
        "sport": 58050,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 117942245,
        "time": 290.89588499069214
      }
    ],
    "icmp": [
      {
        "src": "192.168.1.100",
        "dst": "8.8.8.8",
        "type": 3,
        "data": ""
      },
      {
        "src": "192.168.1.100",
        "dst": "8.8.8.8",
        "type": 3,
        "data": ""
      },
      {
        "src": "192.168.1.100",
        "dst": "8.8.4.4",
        "type": 3,
        "data": ""
      },
      {
        "src": "192.168.1.100",
        "dst": "8.8.4.4",
        "type": 3,
        "data": ""
      }
    ],
    "http": [
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /gsr1.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/gsr1.crt",
        "body": "",
        "path": "/gsr1.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776379481.656071
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /r4.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/r4.crt",
        "body": "",
        "path": "/r4.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776379481.679261
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /we2.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/we2.crt",
        "body": "",
        "path": "/we2.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776379481.702322
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /gsr4.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/gsr4.crt",
        "body": "",
        "path": "/gsr4.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776379481.726802
      },
      {
        "count": 1,
        "host": "46.149.110.67",
        "port": 80,
        "data": "GET /filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Microsoft-Delivery-Optimization/10.0\r\nMS-CV: DfR3kAMZVUq8MYf6lNahBQ.0.2.3.1.1\r\nContent-Length: 0\r\nHost: 46.149.110.67\r\n\r\n",
        "uri": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com",
        "body": "",
        "path": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com",
        "user-agent": "Microsoft-Delivery-Optimization/10.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776379607.355485
      },
      {
        "count": 1,
        "host": "46.149.110.67",
        "port": 80,
        "data": "GET /filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nRange: bytes=0-1\r\nUser-Agent: Microsoft-Delivery-Optimization/10.0\r\nMS-CV: DfR3kAMZVUq8MYf6lNahBQ.0.2.6.1.1.1\r\nContent-Length: 0\r\nHost: 46.149.110.67\r\n\r\n",
        "uri": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "body": "",
        "path": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "user-agent": "Microsoft-Delivery-Optimization/10.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776379609.085331
      },
      {
        "count": 1,
        "host": "46.149.110.67",
        "port": 80,
        "data": "GET /filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nRange: bytes=0-1048575\r\nUser-Agent: Microsoft-Delivery-Optimization/10.0\r\nMS-CV: DfR3kAMZVUq8MYf6lNahBQ.0.2.6.1.1.2\r\nContent-Length: 0\r\nHost: 46.149.110.67\r\n\r\n",
        "uri": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "body": "",
        "path": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "user-agent": "Microsoft-Delivery-Optimization/10.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776379609.163759
      },
      {
        "count": 1,
        "host": "46.149.110.67",
        "port": 80,
        "data": "GET /filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nRange: bytes=1048576-1697335\r\nUser-Agent: Microsoft-Delivery-Optimization/10.0\r\nMS-CV: DfR3kAMZVUq8MYf6lNahBQ.0.2.6.1.1.3\r\nContent-Length: 0\r\nHost: 46.149.110.67\r\n\r\n",
        "uri": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "body": "",
        "path": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "user-agent": "Microsoft-Delivery-Optimization/10.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776379609.223843
      }
    ],
    "dns": [
      {
        "request": "i.pki.goog",
        "type": "A",
        "answers": [
          {
            "type": "A",
            "data": "173.194.73.94"
          },
          {
            "type": "CNAME",
            "data": "pki-goog.l.google.com"
          }
        ],
        "first_seen": 1776379481.614169
      }
    ],
    "smtp": [],
    "irc": [],
    "dead_hosts": [
      [
        "52.123.242.97",
        443
      ],
      [
        "72.154.7.109",
        443
      ],
      [
        "72.154.7.98",
        443
      ],
      [
        "72.154.7.101",
        443
      ],
      [
        "72.154.7.102",
        443
      ],
      [
        "72.154.7.105",
        443
      ],
      [
        "72.154.7.100",
        443
      ],
      [
        "72.154.7.108",
        443
      ],
      [
        "72.154.7.16",
        443
      ]
    ]
  },
  "suricata": {
    "alerts": [],
    "tls": [
      {
        "srcport": 49823,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-16 22:44:41.658033+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "87c36e0efdb847c153954b9f4778e764",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,45-13-43-51-23-0-65037-65281-5-27-10-11-35-18-16-17613,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      },
      {
        "srcport": 49825,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-16 22:44:41.878815+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "eca10cbdddc3be37612b1d322437c105",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,51-23-5-45-27-65281-0-35-16-65037-43-10-17613-13-18-11,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      },
      {
        "srcport": 49860,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-16 22:45:14.953419+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "00cf290bd02b8f31a70af6a46e70e981",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,18-10-16-17613-11-65037-13-0-51-5-27-43-45-23-35-65281,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      }
    ],
    "perf": [],
    "files": [],
    "http": [
      {
        "srcport": 49824,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:44:41.675189+0000",
        "uri": "/gsr1.crt",
        "length": 797,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49824,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:44:41.702322+0000",
        "uri": "/r4.crt",
        "length": 455,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49824,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:44:41.726802+0000",
        "uri": "/we2.crt",
        "length": 582,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49824,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:44:41.754628+0000",
        "uri": "/gsr4.crt",
        "length": 480,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49824,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:44:41.773305+0000",
        "uri": "/gsr1.crt",
        "length": 797,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49824,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:44:41.797682+0000",
        "uri": "/r4.crt",
        "length": 455,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49824,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:44:41.823509+0000",
        "uri": "/we2.crt",
        "length": 582,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49824,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:44:41.884310+0000",
        "uri": "/gsr4.crt",
        "length": 480,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49915,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "46.149.110.67",
        "timestamp": "2026-04-16 22:46:47.447910+0000",
        "uri": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com",
        "length": 246,
        "hostname": "46.149.110.67",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/octet-stream",
        "ua": "Microsoft-Delivery-Optimization/10.0",
        "referrer": null
      },
      {
        "srcport": 49916,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "46.149.110.67",
        "timestamp": "2026-04-16 22:46:49.163759+0000",
        "uri": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "length": 2,
        "hostname": "46.149.110.67",
        "status": 206,
        "http_method": "GET",
        "contenttype": "application/octet-stream",
        "ua": "Microsoft-Delivery-Optimization/10.0",
        "referrer": null
      },
      {
        "srcport": 49918,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "46.149.110.67",
        "timestamp": "2026-04-16 22:46:50.260167+0000",
        "uri": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "length": 648760,
        "hostname": "46.149.110.67",
        "status": 206,
        "http_method": "GET",
        "contenttype": "application/octet-stream",
        "ua": "Microsoft-Delivery-Optimization/10.0",
        "referrer": null
      },
      {
        "srcport": 49916,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "46.149.110.67",
        "timestamp": "2026-04-16 22:46:53.431656+0000",
        "uri": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "length": 1048576,
        "hostname": "46.149.110.67",
        "status": 206,
        "http_method": "GET",
        "contenttype": "application/octet-stream",
        "ua": "Microsoft-Delivery-Optimization/10.0",
        "referrer": null
      }
    ],
    "dns": [
      {
        "timestamp": "2026-04-16T22:44:41.613895+0000",
        "flow_id": 384861990339374,
        "pcap_cnt": 550,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 62931,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "query",
          "id": 10042,
          "rrname": "i.pki.goog",
          "rrtype": "HTTPS",
          "tx_id": 0,
          "opcode": 0
        }
      },
      {
        "timestamp": "2026-04-16T22:44:41.614169+0000",
        "flow_id": 386039360553432,
        "pcap_cnt": 551,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 51508,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "query",
          "id": 45301,
          "rrname": "i.pki.goog",
          "rrtype": "A",
          "tx_id": 0,
          "opcode": 0
        }
      },
      {
        "timestamp": "2026-04-16T22:44:41.631811+0000",
        "flow_id": 384861990339374,
        "pcap_cnt": 557,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 62931,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "answer",
          "id": 10042,
          "flags": "8180",
          "qr": true,
          "rd": true,
          "ra": true,
          "opcode": 0,
          "rrname": "i.pki.goog",
          "rrtype": "HTTPS",
          "rcode": "NOERROR",
          "answers": [
            {
              "rrname": "i.pki.goog",
              "rrtype": "CNAME",
              "ttl": 177,
              "rdata": "pki-goog.l.google.com"
            }
          ],
          "grouped": {
            "CNAME": [
              "pki-goog.l.google.com"
            ]
          },
          "authorities": [
            {
              "rrname": "l.google.com",
              "rrtype": "SOA",
              "ttl": 60,
              "soa": {
                "mname": "ns1.google.com",
                "rname": "dns-admin.google.com",
                "serial": 900627266,
                "refresh": 900,
                "retry": 900,
                "expire": 1800,
                "minimum": 60
              }
            }
          ]
        }
      },
      {
        "timestamp": "2026-04-16T22:44:41.635831+0000",
        "flow_id": 386039360553432,
        "pcap_cnt": 559,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 51508,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "answer",
          "id": 45301,
          "flags": "8180",
          "qr": true,
          "rd": true,
          "ra": true,
          "opcode": 0,
          "rrname": "i.pki.goog",
          "rrtype": "A",
          "rcode": "NOERROR",
          "answers": [
            {
              "rrname": "i.pki.goog",
              "rrtype": "CNAME",
              "ttl": 299,
              "rdata": "pki-goog.l.google.com"
            },
            {
              "rrname": "pki-goog.l.google.com",
              "rrtype": "A",
              "ttl": 300,
              "rdata": "173.194.73.94"
            }
          ],
          "grouped": {
            "CNAME": [
              "pki-goog.l.google.com"
            ],
            "A": [
              "173.194.73.94"
            ]
          }
        }
      }
    ],
    "ssh": [],
    "fileinfo": [],
    "eve_log_full_path": "/opt/CAPEv2/storage/analyses/39/logs/eve.json",
    "alert_log_full_path": null,
    "tls_log_full_path": null,
    "http_log_full_path": null,
    "file_log_full_path": null,
    "ssh_log_full_path": null,
    "dns_log_full_path": null
  },
  "url_analysis": {},
  "procmemory": [],
  "signatures": [
    {
      "name": "stealth_network",
      "description": "Network activity detected but not expressed in monitor API logs",
      "categories": [
        "stealth"
      ],
      "severity": 1,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "ip": "20.93.72.182"
        },
        {
          "ip": "46.149.110.67"
        },
        {
          "ip": "72.154.7.16"
        },
        {
          "ip": "72.154.7.108"
        },
        {
          "ip": "72.154.7.100"
        },
        {
          "ip": "72.154.7.105"
        },
        {
          "ip": "72.154.7.102"
        },
        {
          "ip": "72.154.7.98"
        },
        {
          "ip": "72.154.7.101"
        },
        {
          "ip": "72.154.7.107"
        },
        {
          "ip": "72.154.7.109"
        },
        {
          "ip": "20.165.94.54"
        },
        {
          "ip": "13.107.6.156"
        },
        {
          "ip": "84.47.178.41"
        },
        {
          "ip": "150.171.27.11"
        },
        {
          "ip": "173.194.73.94"
        },
        {
          "ip": "84.47.178.49"
        },
        {
          "ip": "52.123.242.97"
        },
        {
          "ip": "40.126.53.14"
        },
        {
          "ip": "20.42.65.93"
        },
        {
          "ip": "4.207.247.139"
        },
        {
          "ip": "84.47.178.56"
        },
        {
          "ip": "20.189.173.2"
        },
        {
          "domain": "i.pki.goog"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "network_cnc_http",
      "description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
      "categories": [
        "network",
        "c2"
      ],
      "severity": 2,
      "weight": 1,
      "confidence": 30,
      "references": [],
      "data": [
        {
          "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
        },
        {
          "suspicious_request": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com"
        },
        {
          "suspicious_request": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "network_http",
      "description": "Performs some HTTP requests",
      "categories": [
        "network"
      ],
      "severity": 2,
      "weight": 1,
      "confidence": 30,
      "references": [],
      "data": [
        {
          "url": "http://i.pki.goog/gsr1.crt"
        },
        {
          "url": "http://i.pki.goog/r4.crt"
        },
        {
          "url": "http://i.pki.goog/we2.crt"
        },
        {
          "url": "http://i.pki.goog/gsr4.crt"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "binary_yara",
      "description": "Binary file triggered multiple YARA rules",
      "categories": [
        "static"
      ],
      "severity": 3,
      "weight": 1,
      "confidence": 80,
      "references": [],
      "data": [
        {
          "Binary triggered YARA rule": "DITEKSHEN_MALWARE_Win_Nanocore"
        },
        {
          "Binary triggered YARA rule": "Windows_Trojan_Nanocore_d8c4e3c5"
        },
        {
          "Binary triggered YARA rule": "Nanocore_RAT_Gen_2"
        },
        {
          "Binary triggered YARA rule": "NETDLLMicrosoft"
        },
        {
          "Binary triggered YARA rule": "IsPE32"
        },
        {
          "Binary triggered YARA rule": "IsNET_DLL"
        },
        {
          "Binary triggered YARA rule": "IsDLL"
        },
        {
          "Binary triggered YARA rule": "IsWindowsGUI"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_Studio_NET"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_v70_Basic_NET_additional"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_Basic_NET"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_Studio_NET_additional"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_v70_Basic_NET"
        },
        {
          "Binary triggered YARA rule": "NET_executable_"
        },
        {
          "Binary triggered YARA rule": "NET_executable"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "network_questionable_http_path",
      "description": "Makes a suspicious HTTP request to a commonly exploitable directory with questionable file ext",
      "categories": [
        "network"
      ],
      "severity": 3,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984406&P2=404&P3=2&P4=WQc6A4LAYc7walY%2fNjZu6hBzJ19RMgcc%2foz0E1v%2bBwY9F2pYAOS3WPepVN4pAj46d1Lal9ss1LJwi2V%2fiY%2ba0Q%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "procmem_yara",
      "description": "Yara detections observed in process dumps, payloads or dropped files",
      "categories": [
        "malware"
      ],
      "severity": 3,
      "weight": 4,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "Hit": "PID 1568 triggered the Yara rule 'DITEKSHEN_MALWARE_Win_Nanocore' with data '['NanoCore.ClientPlugin', 'NanoCore.ClientPluginHost', 'IClientApp', 'IClientData', 'IClientNetwork', 'IClientAppHost', 'IClientDataHost', 'IClientLoggingHost', 'IClientNetworkHost', 'IClientUIHost', 'IClientNameObjectCollection', 'IClientReadOnlyNameObjectCollection', 'ClientPlugin', 'get_ClientSettings', 'get_Connected']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'Windows_Trojan_Nanocore_d8c4e3c5' with data '['NanoCore.ClientPluginHost', 'NanoCore.ClientPlugin', 'get_BuilderSettings', 'IClientAppHost', 'AddHostEntry', 'LogClientException', 'PipeExists', 'IClientLoggingHost']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'Nanocore_RAT_Gen_2' with data '['NanoCore.ClientPluginHost', 'IClientNetworkHost']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'NETDLLMicrosoft' with data '['{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'IsPE32' with data '[]'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'IsNET_DLL' with data '[]'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'IsDLL' with data '[]'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'IsWindowsGUI' with data '[]'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'Microsoft_Visual_Studio_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'Microsoft_Visual_C_v70_Basic_NET_additional' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'Microsoft_Visual_C_Basic_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'Microsoft_Visual_Studio_NET_additional' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'Microsoft_Visual_C_v70_Basic_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'NET_executable_' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 1568 triggered the Yara rule 'NET_executable' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    }
  ],
  "malscore": 8.0,
  "ttps": [
    {
      "signature": "network_cnc_http",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OB0004",
        "B0033",
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "network_http",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "network_questionable_http_path",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "procmem_yara",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002"
      ]
    }
  ],
  "malstatus": "Malicious"
}