{
  "statistics": {
    "processing": [
      {
        "name": "CAPE",
        "time": 1.395
      },
      {
        "name": "AnalysisInfo",
        "time": 0.015
      },
      {
        "name": "BehaviorAnalysis",
        "time": 0.01
      },
      {
        "name": "Debug",
        "time": 0.001
      },
      {
        "name": "NetworkAnalysis",
        "time": 11.542
      },
      {
        "name": "Suricata",
        "time": 9.859
      },
      {
        "name": "UrlAnalysis",
        "time": 0.0
      },
      {
        "name": "script_log_processing",
        "time": 0.0
      },
      {
        "name": "ProcessMemory",
        "time": 0.0
      }
    ],
    "signatures": [
      {
        "name": "packer_themida",
        "time": 0.0
      },
      {
        "name": "stealth_network",
        "time": 0.0
      },
      {
        "name": "disable_driver_via_blocklist",
        "time": 0.0
      },
      {
        "name": "disable_driver_via_hvcidisallowedimages",
        "time": 0.0
      },
      {
        "name": "disable_hypervisor_protected_code_integrity",
        "time": 0.0
      },
      {
        "name": "pendingfilerenameoperations_Operations",
        "time": 0.0
      },
      {
        "name": "anomalous_deletefile",
        "time": 0.0
      },
      {
        "name": "antiav_360_libs",
        "time": 0.0
      },
      {
        "name": "antiav_ahnlab_libs",
        "time": 0.0
      },
      {
        "name": "antiav_avast_libs",
        "time": 0.0
      },
      {
        "name": "antiav_bitdefender_libs",
        "time": 0.0
      },
      {
        "name": "antiav_bullguard_libs",
        "time": 0.0
      },
      {
        "name": "antiav_emsisoft_libs",
        "time": 0.0
      },
      {
        "name": "antiav_qurb_libs",
        "time": 0.0
      },
      {
        "name": "antiav_servicestop",
        "time": 0.0
      },
      {
        "name": "antiav_apioverride_libs",
        "time": 0.0
      },
      {
        "name": "antidebug_guardpages",
        "time": 0.0
      },
      {
        "name": "antiav_nthookengine_libs",
        "time": 0.0
      },
      {
        "name": "antidebug_outputdebugstring",
        "time": 0.0
      },
      {
        "name": "antidebug_windows",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoo",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoocrash",
        "time": 0.0
      },
      {
        "name": "antisandbox_foregroundwindows",
        "time": 0.0
      },
      {
        "name": "mouse_movement_detect",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_libs",
        "time": 0.0
      },
      {
        "name": "antisandbox_script_timer",
        "time": 0.0
      },
      {
        "name": "antisandbox_sleep",
        "time": 0.0
      },
      {
        "name": "antisandbox_sunbelt_libs",
        "time": 0.0
      },
      {
        "name": "antisandbox_unhook",
        "time": 0.0
      },
      {
        "name": "antivm_directory_objects",
        "time": 0.0
      },
      {
        "name": "antivm_display",
        "time": 0.0
      },
      {
        "name": "antivm_generic_disk",
        "time": 0.0
      },
      {
        "name": "antivm_generic_system",
        "time": 0.0
      },
      {
        "name": "antivm_checks_available_memory",
        "time": 0.0
      },
      {
        "name": "detect_virtualization_via_recent_files",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_libs",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_events",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_libs",
        "time": 0.0
      },
      {
        "name": "antivm_wmi",
        "time": 0.0
      },
      {
        "name": "api_spamming",
        "time": 0.0
      },
      {
        "name": "api_uuidfromstringa",
        "time": 0.0
      },
      {
        "name": "bcdedit_command",
        "time": 0.0
      },
      {
        "name": "bootkit",
        "time": 0.0
      },
      {
        "name": "direct_hdd_access",
        "time": 0.0
      },
      {
        "name": "physical_drive_access",
        "time": 0.0
      },
      {
        "name": "potential_overwrite_mbr",
        "time": 0.0
      },
      {
        "name": "read_file_raw_disk_access",
        "time": 0.0
      },
      {
        "name": "suspicious_iocontrol_codes",
        "time": 0.0
      },
      {
        "name": "browser_needed",
        "time": 0.0
      },
      {
        "name": "regsvr32_squiblydoo_dll_load",
        "time": 0.0
      },
      {
        "name": "uac_bypass_cmstp",
        "time": 0.0
      },
      {
        "name": "uac_bypass_eventvwr",
        "time": 0.0
      },
      {
        "name": "uac_bypass_windows_Backup",
        "time": 0.0
      },
      {
        "name": "dotnet_code_compile",
        "time": 0.0
      },
      {
        "name": "queries_computer_name",
        "time": 0.0
      },
      {
        "name": "queries_user_name",
        "time": 0.0
      },
      {
        "name": "creates_largekey",
        "time": 0.0
      },
      {
        "name": "creates_nullvalue",
        "time": 0.0
      },
      {
        "name": "access_windows_passwords_vault",
        "time": 0.0
      },
      {
        "name": "lsass_credential_dumping",
        "time": 0.0
      },
      {
        "name": "critical_process",
        "time": 0.0
      },
      {
        "name": "cryptopool_domains",
        "time": 0.0
      },
      {
        "name": "dead_connect",
        "time": 0.0
      },
      {
        "name": "dead_link",
        "time": 0.0
      },
      {
        "name": "decoy_document",
        "time": 0.0
      },
      {
        "name": "decoy_image",
        "time": 0.0
      },
      {
        "name": "deletes_consolehost_history",
        "time": 0.0
      },
      {
        "name": "dep_bypass",
        "time": 0.0
      },
      {
        "name": "dep_disable",
        "time": 0.0
      },
      {
        "name": "disables_wfp",
        "time": 0.0
      },
      {
        "name": "add_windows_defender_exclusions",
        "time": 0.0
      },
      {
        "name": "mountpoints_volume_discovery",
        "time": 0.0
      },
      {
        "name": "dll_load_uncommon_file_types",
        "time": 0.0
      },
      {
        "name": "document_script_exe_drop",
        "time": 0.0
      },
      {
        "name": "guloader_apis",
        "time": 0.0
      },
      {
        "name": "driver_load",
        "time": 0.0
      },
      {
        "name": "dynamic_function_loading",
        "time": 0.0
      },
      {
        "name": "encrypted_ioc",
        "time": 0.0
      },
      {
        "name": "exec_crash",
        "time": 0.0
      },
      {
        "name": "process_creation_suspicious_location",
        "time": 0.0
      },
      {
        "name": "exploit_getbasekerneladdress",
        "time": 0.0
      },
      {
        "name": "exploit_gethaldispatchtable",
        "time": 0.0
      },
      {
        "name": "exploit_heapspray",
        "time": 0.0
      },
      {
        "name": "koadic_apis",
        "time": 0.0
      },
      {
        "name": "koadic_network_activity",
        "time": 0.0
      },
      {
        "name": "downloads_from_filehosting",
        "time": 0.0
      },
      {
        "name": "generic_phish",
        "time": 0.0
      },
      {
        "name": "http_request",
        "time": 0.0
      },
      {
        "name": "infostealer_browser",
        "time": 0.0
      },
      {
        "name": "infostealer_browser_password",
        "time": 0.0
      },
      {
        "name": "infostealer_cookies",
        "time": 0.0
      },
      {
        "name": "cryptbot_network",
        "time": 0.0
      },
      {
        "name": "purplewave_network_activity",
        "time": 0.0
      },
      {
        "name": "quilclipper_behavior",
        "time": 0.0
      },
      {
        "name": "raccoon_behavior",
        "time": 0.0
      },
      {
        "name": "captures_screenshot",
        "time": 0.0
      },
      {
        "name": "vidar_behavior",
        "time": 0.0
      },
      {
        "name": "injection_createremotethread",
        "time": 0.0
      },
      {
        "name": "creates_suspended_process",
        "time": 0.0
      },
      {
        "name": "injection_explorer",
        "time": 0.0
      },
      {
        "name": "injection_network_traffic",
        "time": 0.0
      },
      {
        "name": "injection_runpe",
        "time": 0.0
      },
      {
        "name": "injection_rwx",
        "time": 0.0
      },
      {
        "name": "injection_themeinitapihook",
        "time": 0.0
      },
      {
        "name": "resumethread_remote_process",
        "time": 0.0
      },
      {
        "name": "injection_write_exe_process",
        "time": 0.0
      },
      {
        "name": "injection_write_process",
        "time": 0.0
      },
      {
        "name": "internet_dropper",
        "time": 0.0
      },
      {
        "name": "escalate_privilege_via_named_pipe",
        "time": 0.0
      },
      {
        "name": "ipc_namedpipe",
        "time": 0.0
      },
      {
        "name": "js_phish",
        "time": 0.0
      },
      {
        "name": "js_suspicious_redirect",
        "time": 0.0
      },
      {
        "name": "loader_alien",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_internet_explorer_exporter",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_run_exe_helper_utility",
        "time": 0.0
      },
      {
        "name": "execute_ps_via_syncappvpublishingserver",
        "time": 0.0
      },
      {
        "name": "malicious_dynamic_function_loading",
        "time": 0.0
      },
      {
        "name": "encrypt_pcinfo",
        "time": 0.0
      },
      {
        "name": "encrypt_data_agenttesla_http",
        "time": 0.0
      },
      {
        "name": "encrypt_data_agentteslat2_http",
        "time": 0.0
      },
      {
        "name": "encrypt_data_nanocore",
        "time": 0.0
      },
      {
        "name": "reads_memory_remote_process",
        "time": 0.0
      },
      {
        "name": "mimics_filetime",
        "time": 0.0
      },
      {
        "name": "amsi_bypass_via_com_registry",
        "time": 0.0
      },
      {
        "name": "access_auto_logons_via_registry",
        "time": 0.0
      },
      {
        "name": "access_boot_key_via_registry",
        "time": 0.0
      },
      {
        "name": "create_suspicious_lnk_files",
        "time": 0.0
      },
      {
        "name": "credential_access_via_windows_credential_history",
        "time": 0.0
      },
      {
        "name": "dll_hijacking_via_microsoft_exchange",
        "time": 0.0
      },
      {
        "name": "dll_hijacking_via_waas_medic_svc_com_typelib",
        "time": 0.0
      },
      {
        "name": "execute_file_downloaded_via_openssh",
        "time": 0.0
      },
      {
        "name": "execute_safe_mode_from_suspicious_process",
        "time": 0.0
      },
      {
        "name": "execute_scripts_via_microsoft_management_console",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_processes_via_windows_mssql_service",
        "time": 0.0
      },
      {
        "name": "execution_from_self_extracting_archive",
        "time": 0.0
      },
      {
        "name": "ip_address_discovery_via_trusted_program",
        "time": 0.0
      },
      {
        "name": "load_dll_via_control_panel",
        "time": 0.0
      },
      {
        "name": "network_connection_via_suspicious_process",
        "time": 0.0
      },
      {
        "name": "potential_location_discovery_via_unusual_process",
        "time": 0.0
      },
      {
        "name": "store_executable_registry",
        "time": 0.0
      },
      {
        "name": "Suspicious_Execution_Via_MicrosoftExchangeTransportAgent",
        "time": 0.0
      },
      {
        "name": "suspicious_java_execution_via_win_scripts",
        "time": 0.0
      },
      {
        "name": "Suspicious_Scheduled_Task_Creation_Via_Masqueraded_XML_File",
        "time": 0.0
      },
      {
        "name": "uses_restart_manager_for_suspicious_activities",
        "time": 0.0
      },
      {
        "name": "modify_desktop_wallpaper",
        "time": 0.0
      },
      {
        "name": "move_file_on_reboot",
        "time": 0.0
      },
      {
        "name": "multiple_useragents",
        "time": 0.0
      },
      {
        "name": "network_anomaly",
        "time": 0.0
      },
      {
        "name": "network_bind",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_archive",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_free_webhosting",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_generic",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_interactsh",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_opensource",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_pastesite",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_payload",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_serviceinterface",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_socialmedia",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_telegram",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_tempstorage",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_temp_urldns",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_urlshortener",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_useragent",
        "time": 0.0
      },
      {
        "name": "network_cnc_smtps_exfil",
        "time": 0.0
      },
      {
        "name": "network_cnc_smtps_generic",
        "time": 0.0
      },
      {
        "name": "network_dns_idn",
        "time": 0.0
      },
      {
        "name": "network_dns_suspicious_querytype",
        "time": 0.0
      },
      {
        "name": "network_dns_tunneling_request",
        "time": 0.0
      },
      {
        "name": "network_document_http",
        "time": 0.0
      },
      {
        "name": "explorer_http",
        "time": 0.0
      },
      {
        "name": "network_fake_useragent",
        "time": 0.0
      },
      {
        "name": "legitimate_domain_abuse",
        "time": 0.0
      },
      {
        "name": "suspicious_communication_trusted_site",
        "time": 0.0
      },
      {
        "name": "network_tor",
        "time": 0.0
      },
      {
        "name": "office_com_load",
        "time": 0.0
      },
      {
        "name": "office_dotnet_load",
        "time": 0.0
      },
      {
        "name": "office_mshtml_load",
        "time": 0.0
      },
      {
        "name": "office_vb_load",
        "time": 0.0
      },
      {
        "name": "office_wmi_load",
        "time": 0.0
      },
      {
        "name": "office_cve2017_11882",
        "time": 0.0
      },
      {
        "name": "office_cve2017_11882_network",
        "time": 0.0
      },
      {
        "name": "office_cve_2021_40444",
        "time": 0.0
      },
      {
        "name": "office_cve_2021_40444_m2",
        "time": 0.0
      },
      {
        "name": "office_flash_load",
        "time": 0.0
      },
      {
        "name": "office_postscript",
        "time": 0.0
      },
      {
        "name": "office_suspicious_processes",
        "time": 0.0
      },
      {
        "name": "office_write_exe",
        "time": 0.0
      },
      {
        "name": "persistence_via_autodial_dll_registry",
        "time": 0.0
      },
      {
        "name": "persistence_autorun",
        "time": 0.0
      },
      {
        "name": "persistence_autorun_tasks",
        "time": 0.0
      },
      {
        "name": "persistence_bootexecute",
        "time": 0.0
      },
      {
        "name": "persistence_registry_script",
        "time": 0.0
      },
      {
        "name": "powershell_network_connection",
        "time": 0.0
      },
      {
        "name": "powershell_download",
        "time": 0.0
      },
      {
        "name": "powershell_request",
        "time": 0.0
      },
      {
        "name": "createtoolhelp32snapshot_module_enumeration",
        "time": 0.0
      },
      {
        "name": "enumerates_running_processes",
        "time": 0.0
      },
      {
        "name": "process_interest",
        "time": 0.0
      },
      {
        "name": "process_needed",
        "time": 0.0
      },
      {
        "name": "mass_data_encryption",
        "time": 0.0
      },
      {
        "name": "ransomware_file_modifications",
        "time": 0.0
      },
      {
        "name": "ransomware_message",
        "time": 0.0
      },
      {
        "name": "nemty_network_activity",
        "time": 0.0
      },
      {
        "name": "nemty_note",
        "time": 0.0
      },
      {
        "name": "sodinokibi_behavior",
        "time": 0.0
      },
      {
        "name": "stop_ransomware_registry",
        "time": 0.0
      },
      {
        "name": "blackrat_apis",
        "time": 0.0
      },
      {
        "name": "blackrat_network_activity",
        "time": 0.0
      },
      {
        "name": "blackrat_registry_keys",
        "time": 0.0
      },
      {
        "name": "dcrat_behavior",
        "time": 0.0
      },
      {
        "name": "karagany_system_event_objects",
        "time": 0.0
      },
      {
        "name": "rat_luminosity",
        "time": 0.0
      },
      {
        "name": "rat_nanocore",
        "time": 0.0
      },
      {
        "name": "netwire_behavior",
        "time": 0.0
      },
      {
        "name": "obliquerat_network_activity",
        "time": 0.0
      },
      {
        "name": "orcusrat_behavior",
        "time": 0.0
      },
      {
        "name": "trochilusrat_apis",
        "time": 0.0
      },
      {
        "name": "reads_self",
        "time": 0.0
      },
      {
        "name": "recon_beacon",
        "time": 0.0
      },
      {
        "name": "recon_programs",
        "time": 0.0
      },
      {
        "name": "recon_systeminfo",
        "time": 0.0
      },
      {
        "name": "accesses_recyclebin",
        "time": 0.0
      },
      {
        "name": "remcos_shell_code_dynamic_wrapper_x",
        "time": 0.0
      },
      {
        "name": "script_created_process",
        "time": 0.0
      },
      {
        "name": "script_network_activity",
        "time": 0.0
      },
      {
        "name": "suspicious_js_script",
        "time": 0.0
      },
      {
        "name": "javascript_timer",
        "time": 0.0
      },
      {
        "name": "secure_login_phishing",
        "time": 0.0
      },
      {
        "name": "securityxploded_modules",
        "time": 0.0
      },
      {
        "name": "get_clipboard_data",
        "time": 0.0
      },
      {
        "name": "sets_autoconfig_url",
        "time": 0.0
      },
      {
        "name": "spoofs_procname",
        "time": 0.0
      },
      {
        "name": "stack_pivot",
        "time": 0.0
      },
      {
        "name": "stack_pivot_file_created",
        "time": 0.0
      },
      {
        "name": "stack_pivot_process_create",
        "time": 0.0
      },
      {
        "name": "set_clipboard_data",
        "time": 0.0
      },
      {
        "name": "stealth_childproc",
        "time": 0.0
      },
      {
        "name": "stealth_file",
        "time": 0.0
      },
      {
        "name": "stealth_timeout",
        "time": 0.0
      },
      {
        "name": "stealth_window",
        "time": 0.0
      },
      {
        "name": "queries_keyboard_layout",
        "time": 0.0
      },
      {
        "name": "queries_locale_api",
        "time": 0.0
      },
      {
        "name": "terminates_remote_process",
        "time": 0.0
      },
      {
        "name": "uiautomationcore_load",
        "time": 0.0
      },
      {
        "name": "user_enum",
        "time": 0.0
      },
      {
        "name": "mmc_dll_script_load",
        "time": 0.0
      },
      {
        "name": "mmc_dotnet_load",
        "time": 0.0
      },
      {
        "name": "virus",
        "time": 0.0
      },
      {
        "name": "neshta_files",
        "time": 0.0
      },
      {
        "name": "neshta_regkeys",
        "time": 0.0
      },
      {
        "name": "webmail_phish",
        "time": 0.0
      },
      {
        "name": "persists_dev_util",
        "time": 0.0
      },
      {
        "name": "spawns_dev_util",
        "time": 0.0
      },
      {
        "name": "alters_windows_utility",
        "time": 0.0
      },
      {
        "name": "overwrites_accessibility_utility",
        "time": 0.0
      },
      {
        "name": "Potential_Lateral_Movement_Via_SMBEXEC",
        "time": 0.0
      },
      {
        "name": "potential_WebShell_Via_ScreenConnectServer",
        "time": 0.0
      },
      {
        "name": "uses_Microsoft_HTML_Help_Executable",
        "time": 0.0
      },
      {
        "name": "wiper_zeroedbytes",
        "time": 0.0
      },
      {
        "name": "wmi_create_process",
        "time": 0.0
      },
      {
        "name": "wmi_script_process",
        "time": 0.0
      },
      {
        "name": "antianalysis_tls_section",
        "time": 0.0
      },
      {
        "name": "antivirus_clamav",
        "time": 0.0
      },
      {
        "name": "antivirus_virustotal",
        "time": 0.0
      },
      {
        "name": "bad_certs",
        "time": 0.0
      },
      {
        "name": "bad_ssl_certs",
        "time": 0.0
      },
      {
        "name": "banker_zeus_p2p",
        "time": 0.0
      },
      {
        "name": "banker_zeus_url",
        "time": 0.0
      },
      {
        "name": "binary_yara",
        "time": 0.0
      },
      {
        "name": "bot_athenahttp",
        "time": 0.0
      },
      {
        "name": "bot_dirtjumper",
        "time": 0.0
      },
      {
        "name": "bot_drive",
        "time": 0.0
      },
      {
        "name": "bot_drive2",
        "time": 0.0
      },
      {
        "name": "bot_madness",
        "time": 0.0
      },
      {
        "name": "phishing_kit_detected",
        "time": 0.0
      },
      {
        "name": "family_proxyback",
        "time": 0.0
      },
      {
        "name": "flare_capa_antianalysis",
        "time": 0.0
      },
      {
        "name": "flare_capa_collection",
        "time": 0.0
      },
      {
        "name": "flare_capa_communication",
        "time": 0.0
      },
      {
        "name": "flare_capa_compiler",
        "time": 0.0
      },
      {
        "name": "flare_capa_datamanipulation",
        "time": 0.0
      },
      {
        "name": "flare_capa_executable",
        "time": 0.0
      },
      {
        "name": "flare_capa_hostinteraction",
        "time": 0.0
      },
      {
        "name": "flare_capa_impact",
        "time": 0.0
      },
      {
        "name": "flare_capa_lib",
        "time": 0.0
      },
      {
        "name": "flare_capa_linking",
        "time": 0.0
      },
      {
        "name": "flare_capa_loadcode",
        "time": 0.0
      },
      {
        "name": "flare_capa_malwarefamily",
        "time": 0.0
      },
      {
        "name": "flare_capa_nursery",
        "time": 0.0
      },
      {
        "name": "flare_capa_persistence",
        "time": 0.0
      },
      {
        "name": "flare_capa_runtime",
        "time": 0.0
      },
      {
        "name": "flare_capa_targeting",
        "time": 0.0
      },
      {
        "name": "threatfox",
        "time": 0.0
      },
      {
        "name": "log4shell",
        "time": 0.0
      },
      {
        "name": "mimics_extension",
        "time": 0.0
      },
      {
        "name": "network_country_distribution",
        "time": 0.0
      },
      {
        "name": "network_cnc_http",
        "time": 0.004
      },
      {
        "name": "network_ip_exe",
        "time": 0.0
      },
      {
        "name": "network_dga",
        "time": 0.0
      },
      {
        "name": "network_dga_fraunhofer",
        "time": 0.0
      },
      {
        "name": "network_dyndns",
        "time": 0.003
      },
      {
        "name": "network_excessive_udp",
        "time": 0.0
      },
      {
        "name": "network_http",
        "time": 0.002
      },
      {
        "name": "network_icmp",
        "time": 0.0
      },
      {
        "name": "network_irc",
        "time": 0.0
      },
      {
        "name": "network_open_proxy",
        "time": 0.001
      },
      {
        "name": "network_questionable_http_path",
        "time": 0.0
      },
      {
        "name": "network_questionable_https_path",
        "time": 0.0
      },
      {
        "name": "network_smtp",
        "time": 0.0
      },
      {
        "name": "network_torgateway",
        "time": 0.001
      },
      {
        "name": "origin_langid",
        "time": 0.0
      },
      {
        "name": "origin_resource_langid",
        "time": 0.0
      },
      {
        "name": "overlay",
        "time": 0.0
      },
      {
        "name": "packer_unknown_pe_section_name",
        "time": 0.0
      },
      {
        "name": "packer_aspack",
        "time": 0.0
      },
      {
        "name": "packer_aspirecrypt",
        "time": 0.0
      },
      {
        "name": "packer_bedsprotector",
        "time": 0.0
      },
      {
        "name": "packer_confuser",
        "time": 0.0
      },
      {
        "name": "packer_enigma",
        "time": 0.0
      },
      {
        "name": "packer_entropy",
        "time": 0.0
      },
      {
        "name": "packer_mpress",
        "time": 0.0
      },
      {
        "name": "packer_nate",
        "time": 0.0
      },
      {
        "name": "packer_nspack",
        "time": 0.0
      },
      {
        "name": "packer_smartassembly",
        "time": 0.0
      },
      {
        "name": "packer_spices",
        "time": 0.0
      },
      {
        "name": "packer_themida",
        "time": 0.0
      },
      {
        "name": "packer_titan",
        "time": 0.0
      },
      {
        "name": "packer_upx",
        "time": 0.0
      },
      {
        "name": "packer_vmprotect",
        "time": 0.0
      },
      {
        "name": "packer_yoda",
        "time": 0.0
      },
      {
        "name": "pdf_annot_urls_checker",
        "time": 0.0
      },
      {
        "name": "polymorphic",
        "time": 0.0
      },
      {
        "name": "punch_plus_plus_pcres",
        "time": 0.0
      },
      {
        "name": "procmem_yara",
        "time": 0.0
      },
      {
        "name": "recon_checkip",
        "time": 0.0
      },
      {
        "name": "static_authenticode",
        "time": 0.0
      },
      {
        "name": "invalid_authenticode_signature",
        "time": 0.0
      },
      {
        "name": "static_dotnet_anomaly",
        "time": 0.0
      },
      {
        "name": "static_java",
        "time": 0.0
      },
      {
        "name": "static_pdf",
        "time": 0.0
      },
      {
        "name": "contains_pe_overlay",
        "time": 0.0
      },
      {
        "name": "static_pe_anomaly",
        "time": 0.0
      },
      {
        "name": "pe_compile_timestomping",
        "time": 0.0
      },
      {
        "name": "static_pe_pdbpath",
        "time": 0.0
      },
      {
        "name": "static_rat_config",
        "time": 0.0
      },
      {
        "name": "static_versioninfo_anomaly",
        "time": 0.0
      },
      {
        "name": "suricata_alert",
        "time": 0.0
      },
      {
        "name": "suspicious_html_body",
        "time": 0.0
      },
      {
        "name": "suspicious_html_name",
        "time": 0.0
      },
      {
        "name": "suspicious_html_title",
        "time": 0.0
      },
      {
        "name": "volatility_devicetree_1",
        "time": 0.0
      },
      {
        "name": "volatility_handles_1",
        "time": 0.0
      },
      {
        "name": "volatility_ldrmodules_1",
        "time": 0.0
      },
      {
        "name": "volatility_ldrmodules_2",
        "time": 0.0
      },
      {
        "name": "volatility_malfind_1",
        "time": 0.0
      },
      {
        "name": "volatility_malfind_2",
        "time": 0.0
      },
      {
        "name": "volatility_modscan_1",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_1",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_2",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_3",
        "time": 0.0
      },
      {
        "name": "whois_create",
        "time": 0.0
      },
      {
        "name": "accesses_mailslot",
        "time": 0.0
      },
      {
        "name": "accesses_netlogon_regkey",
        "time": 0.0
      },
      {
        "name": "accesses_public_folder",
        "time": 0.0
      },
      {
        "name": "accesses_sysvol",
        "time": 0.0
      },
      {
        "name": "writes_sysvol",
        "time": 0.0
      },
      {
        "name": "adds_admin_user",
        "time": 0.0
      },
      {
        "name": "adds_user",
        "time": 0.0
      },
      {
        "name": "overwrites_admin_password",
        "time": 0.0
      },
      {
        "name": "antianalysis_detectfile",
        "time": 0.002
      },
      {
        "name": "antianalysis_detectreg",
        "time": 0.001
      },
      {
        "name": "modify_attachment_manager",
        "time": 0.0
      },
      {
        "name": "antiav_detectfile",
        "time": 0.004
      },
      {
        "name": "antiav_detectreg",
        "time": 0.005
      },
      {
        "name": "antiav_srp",
        "time": 0.0
      },
      {
        "name": "antiav_whitespace",
        "time": 0.0
      },
      {
        "name": "antidebug_devices",
        "time": 0.001
      },
      {
        "name": "antiemu_windefend",
        "time": 0.0
      },
      {
        "name": "antiemu_wine_reg",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoo_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_fortinet_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_joe_anubis_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_mutex",
        "time": 0.0
      },
      {
        "name": "antisandbox_sunbelt_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_threattrack_files",
        "time": 0.0
      },
      {
        "name": "antivm_bochs_keys",
        "time": 0.0
      },
      {
        "name": "antivm_generic_bios",
        "time": 0.0
      },
      {
        "name": "antivm_generic_diskreg",
        "time": 0.0
      },
      {
        "name": "antivm_hyperv_keys",
        "time": 0.0
      },
      {
        "name": "antivm_parallels_keys",
        "time": 0.0
      },
      {
        "name": "antivm_recentdocs",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_devices",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_files",
        "time": 0.002
      },
      {
        "name": "antivm_vbox_keys",
        "time": 0.001
      },
      {
        "name": "antivm_vmware_devices",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_files",
        "time": 0.001
      },
      {
        "name": "antivm_vmware_keys",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_mutexes",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_files",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_keys",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_mutex",
        "time": 0.0
      },
      {
        "name": "antivm_xen_keys",
        "time": 0.0
      },
      {
        "name": "asyncrat_mutex",
        "time": 0.0
      },
      {
        "name": "gulpix_behavior",
        "time": 0.0
      },
      {
        "name": "ketrican_regkeys",
        "time": 0.0
      },
      {
        "name": "okrum_mutexes",
        "time": 0.0
      },
      {
        "name": "banker_cridex",
        "time": 0.0
      },
      {
        "name": "geodo_banking_trojan",
        "time": 0.001
      },
      {
        "name": "banker_spyeye_mutexes",
        "time": 0.0
      },
      {
        "name": "banker_zeus_mutex",
        "time": 0.0
      },
      {
        "name": "bitcoin_opencl",
        "time": 0.0
      },
      {
        "name": "enumerates_physical_drives",
        "time": 0.0
      },
      {
        "name": "bot_russkill",
        "time": 0.0
      },
      {
        "name": "browser_addon",
        "time": 0.0
      },
      {
        "name": "chromium_browser_extension_directory",
        "time": 0.0
      },
      {
        "name": "browser_helper_object",
        "time": 0.0
      },
      {
        "name": "browser_security",
        "time": 0.001
      },
      {
        "name": "browser_startpage",
        "time": 0.0
      },
      {
        "name": "ie_disables_process_tab",
        "time": 0.0
      },
      {
        "name": "odbcconf_bypass",
        "time": 0.0
      },
      {
        "name": "squiblydoo_bypass",
        "time": 0.0
      },
      {
        "name": "squiblytwo_bypass",
        "time": 0.0
      },
      {
        "name": "bypass_chromium_protection",
        "time": 0.0
      },
      {
        "name": "bypass_firewall",
        "time": 0.0
      },
      {
        "name": "checks_uac_status",
        "time": 0.0
      },
      {
        "name": "uac_bypass_cmstpcom",
        "time": 0.0
      },
      {
        "name": "uac_bypass_delegateexecute_sdclt",
        "time": 0.0
      },
      {
        "name": "uac_bypass_fodhelper",
        "time": 0.0
      },
      {
        "name": "cape_extracted_content",
        "time": 0.0
      },
      {
        "name": "carberp_mutex",
        "time": 0.0
      },
      {
        "name": "clears_logs",
        "time": 0.0
      },
      {
        "name": "cmdline_obfuscation",
        "time": 0.0
      },
      {
        "name": "cmdline_switches",
        "time": 0.0
      },
      {
        "name": "cmdline_terminate",
        "time": 0.0
      },
      {
        "name": "cmdline_forfiles_wildcard",
        "time": 0.0
      },
      {
        "name": "cmdline_http_link",
        "time": 0.0
      },
      {
        "name": "cmdline_long_string",
        "time": 0.0
      },
      {
        "name": "cmdline_reversed_http_link",
        "time": 0.0
      },
      {
        "name": "long_commandline",
        "time": 0.0
      },
      {
        "name": "powershell_renamed_commandline",
        "time": 0.0
      },
      {
        "name": "copies_self",
        "time": 0.0
      },
      {
        "name": "credwiz_credentialaccess",
        "time": 0.0
      },
      {
        "name": "enables_wdigest",
        "time": 0.0
      },
      {
        "name": "vaultcmd_credentialaccess",
        "time": 0.0
      },
      {
        "name": "file_credential_store_access",
        "time": 0.0
      },
      {
        "name": "file_credential_store_write",
        "time": 0.0
      },
      {
        "name": "kerberos_credential_access_via_rubeus",
        "time": 0.0
      },
      {
        "name": "registry_credential_dumping",
        "time": 0.0
      },
      {
        "name": "registry_credential_store_access",
        "time": 0.0
      },
      {
        "name": "registry_lsa_secrets_access",
        "time": 0.0
      },
      {
        "name": "comsvcs_credentialdump",
        "time": 0.0
      },
      {
        "name": "cryptomining_stratum_command",
        "time": 0.0
      },
      {
        "name": "cypherit_mutexes",
        "time": 0.0
      },
      {
        "name": "darkcomet_regkeys",
        "time": 0.0
      },
      {
        "name": "datop_loader",
        "time": 0.0
      },
      {
        "name": "deepfreeze_mutex",
        "time": 0.0
      },
      {
        "name": "deletes_executed_files",
        "time": 0.0
      },
      {
        "name": "disables_app_launch",
        "time": 0.0
      },
      {
        "name": "disables_auto_app_termination",
        "time": 0.0
      },
      {
        "name": "disables_appv_virtualization",
        "time": 0.0
      },
      {
        "name": "disables_backups",
        "time": 0.001
      },
      {
        "name": "disables_browser_warn",
        "time": 0.001
      },
      {
        "name": "disables_context_menus",
        "time": 0.0
      },
      {
        "name": "disables_cpl_disable",
        "time": 0.0
      },
      {
        "name": "disables_crashdumps",
        "time": 0.0
      },
      {
        "name": "disables_event_logging",
        "time": 0.0
      },
      {
        "name": "disables_folder_options",
        "time": 0.0
      },
      {
        "name": "disables_notificationcenter",
        "time": 0.0
      },
      {
        "name": "disables_power_options",
        "time": 0.001
      },
      {
        "name": "disables_restore_default_state",
        "time": 0.0
      },
      {
        "name": "disables_run_command",
        "time": 0.0
      },
      {
        "name": "disables_smartscreen",
        "time": 0.0
      },
      {
        "name": "disables_startmenu_search",
        "time": 0.0
      },
      {
        "name": "disables_system_restore",
        "time": 0.0
      },
      {
        "name": "disables_uac",
        "time": 0.0
      },
      {
        "name": "disables_wer",
        "time": 0.0
      },
      {
        "name": "disables_windows_defender",
        "time": 0.0
      },
      {
        "name": "disables_windows_defender_logging",
        "time": 0.0
      },
      {
        "name": "removes_windows_defender_contextmenu",
        "time": 0.0
      },
      {
        "name": "removes_windows_defender_updates",
        "time": 0.0
      },
      {
        "name": "windows_defender_powershell",
        "time": 0.0
      },
      {
        "name": "disables_windows_file_protection",
        "time": 0.0
      },
      {
        "name": "disables_windowsupdate",
        "time": 0.0
      },
      {
        "name": "disables_winfirewall",
        "time": 0.0
      },
      {
        "name": "discover_registry_mount_points",
        "time": 0.0
      },
      {
        "name": "adfind_domain_enumeration",
        "time": 0.0
      },
      {
        "name": "domain_enumeration_commands",
        "time": 0.0
      },
      {
        "name": "andromut_mutexes",
        "time": 0.0
      },
      {
        "name": "downloader_cabby",
        "time": 0.0
      },
      {
        "name": "phorpiex_mutexes",
        "time": 0.0
      },
      {
        "name": "protonbot_mutexes",
        "time": 0.0
      },
      {
        "name": "driver_filtermanager",
        "time": 0.0
      },
      {
        "name": "dropper",
        "time": 0.0
      },
      {
        "name": "dll_archive_execution",
        "time": 0.0
      },
      {
        "name": "lnk_archive_execution",
        "time": 0.0
      },
      {
        "name": "script_archive_execution",
        "time": 0.0
      },
      {
        "name": "excel4_macro_urls",
        "time": 0.0
      },
      {
        "name": "escalate_privilege_via_ntlm_relay",
        "time": 0.0
      },
      {
        "name": "spooler_access",
        "time": 0.0
      },
      {
        "name": "spooler_svc_start",
        "time": 0.0
      },
      {
        "name": "mapped_drives_uac",
        "time": 0.0
      },
      {
        "name": "hides_recycle_bin_icon",
        "time": 0.0
      },
      {
        "name": "apocalypse_stealer_file_behavior",
        "time": 0.0
      },
      {
        "name": "arkei_files",
        "time": 0.0
      },
      {
        "name": "azorult_mutexes",
        "time": 0.001
      },
      {
        "name": "infostealer_bitcoin",
        "time": 0.002
      },
      {
        "name": "cryptbot_files",
        "time": 0.0
      },
      {
        "name": "echelon_files",
        "time": 0.001
      },
      {
        "name": "infostealer_ftp",
        "time": 0.003
      },
      {
        "name": "infostealer_im",
        "time": 0.002
      },
      {
        "name": "infostealer_mail",
        "time": 0.002
      },
      {
        "name": "masslogger_files",
        "time": 0.0
      },
      {
        "name": "poullight_files",
        "time": 0.001
      },
      {
        "name": "purplewave_mutexes",
        "time": 0.0
      },
      {
        "name": "quilclipper_mutexes",
        "time": 0.0
      },
      {
        "name": "qulab_files",
        "time": 0.001
      },
      {
        "name": "qulab_mutexes",
        "time": 0.0
      },
      {
        "name": "asyncrat_mutex",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_ASPNet_Compiler",
        "time": 0.0
      },
      {
        "name": "Evade_Execute_Via_DeviceCredentialDeployment",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_Filter_Manager_Control",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_Intel_GFXDownloadWrapper",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_appvlp",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_pcalua",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_OpenSSH",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_pcalua",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_PesterPSModule",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_ScriptRunner",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_ttdinject",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_VisualStudioLiveShare",
        "time": 0.0
      },
      {
        "name": "Execute_Msiexec_Via_Explorer",
        "time": 0.0
      },
      {
        "name": "execute_remote_msi",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_powershell_via_runscripthelper",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_powershell_via_sqlps",
        "time": 0.0
      },
      {
        "name": "Indirect_Command_Execution_Via_ConsoleWindowHost",
        "time": 0.0
      },
      {
        "name": "Perform_Malicious_Activities_Via_Headless_Browser",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_CertOC",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_MSIEXEC",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_Odbcconf",
        "time": 0.0
      },
      {
        "name": "Scriptlet_Proxy_Execution_Via_Pubprn",
        "time": 0.0
      },
      {
        "name": "ie_martian_children",
        "time": 0.0
      },
      {
        "name": "office_martian_children",
        "time": 0.0
      },
      {
        "name": "mimics_icon",
        "time": 0.0
      },
      {
        "name": "masquerade_process_name",
        "time": 0.002
      },
      {
        "name": "mimikatz_modules",
        "time": 0.0
      },
      {
        "name": "ms_office_cmd_rce",
        "time": 0.0
      },
      {
        "name": "mount_copy_to_webdav_share",
        "time": 0.0
      },
      {
        "name": "potential_protocol_tunneling_via_legit_utilities",
        "time": 0.0
      },
      {
        "name": "potential_protocol_tunneling_via_qemu",
        "time": 0.0
      },
      {
        "name": "suspicious_execution_via_dotnet_remoting",
        "time": 0.0
      },
      {
        "name": "modify_certs",
        "time": 0.0
      },
      {
        "name": "dotnet_clr_usagelog_regkeys",
        "time": 0.0
      },
      {
        "name": "modify_hostfile",
        "time": 0.0
      },
      {
        "name": "modify_oem_information",
        "time": 0.0
      },
      {
        "name": "modify_security_center_warnings",
        "time": 0.0
      },
      {
        "name": "modify_uac_prompt",
        "time": 0.0
      },
      {
        "name": "network_dns_blockchain",
        "time": 0.0
      },
      {
        "name": "network_dns_opennic",
        "time": 0.001
      },
      {
        "name": "network_dns_paste_site",
        "time": 0.001
      },
      {
        "name": "network_dns_reverse_proxy",
        "time": 0.0
      },
      {
        "name": "network_dns_temp_file_storage",
        "time": 0.001
      },
      {
        "name": "network_dns_temp_urldns",
        "time": 0.0
      },
      {
        "name": "network_dns_url_shortener",
        "time": 0.009
      },
      {
        "name": "network_dns_doh_tls",
        "time": 0.001
      },
      {
        "name": "suspicious_tld",
        "time": 0.006
      },
      {
        "name": "network_tor_service",
        "time": 0.0
      },
      {
        "name": "office_code_page",
        "time": 0.0
      },
      {
        "name": "office_addinloading",
        "time": 0.0
      },
      {
        "name": "office_perfkey",
        "time": 0.0
      },
      {
        "name": "office_macro",
        "time": 0.0
      },
      {
        "name": "changes_trust_center_settings",
        "time": 0.0
      },
      {
        "name": "disables_vba_trust_access",
        "time": 0.0
      },
      {
        "name": "office_macro_autoexecution",
        "time": 0.0
      },
      {
        "name": "office_macro_ioc",
        "time": 0.0
      },
      {
        "name": "office_macro_malicious_prediction",
        "time": 0.0
      },
      {
        "name": "office_macro_suspicious",
        "time": 0.0
      },
      {
        "name": "rtf_aslr_bypass",
        "time": 0.0
      },
      {
        "name": "rtf_anomaly_characterset",
        "time": 0.0
      },
      {
        "name": "rtf_anomaly_version",
        "time": 0.0
      },
      {
        "name": "rtf_embedded_content",
        "time": 0.0
      },
      {
        "name": "rtf_embedded_office_file",
        "time": 0.0
      },
      {
        "name": "rtf_exploit_static",
        "time": 0.0
      },
      {
        "name": "office_security",
        "time": 0.0
      },
      {
        "name": "accesses_office_username",
        "time": 0.0
      },
      {
        "name": "office_anomalous_feature",
        "time": 0.0
      },
      {
        "name": "office_dde_command",
        "time": 0.0
      },
      {
        "name": "packer_armadillo_mutex",
        "time": 0.0
      },
      {
        "name": "packer_armadillo_regkey",
        "time": 0.0
      },
      {
        "name": "persistence_ads",
        "time": 0.0
      },
      {
        "name": "persistence_safeboot",
        "time": 0.0
      },
      {
        "name": "persistence_ifeo",
        "time": 0.0
      },
      {
        "name": "persistence_silent_process_exit",
        "time": 0.0
      },
      {
        "name": "persistence_rdp_registry",
        "time": 0.0
      },
      {
        "name": "persistence_rdp_shadowing",
        "time": 0.0
      },
      {
        "name": "persistence_service",
        "time": 0.0
      },
      {
        "name": "persistence_shim_database",
        "time": 0.0
      },
      {
        "name": "powerpool_mutexes",
        "time": 0.0
      },
      {
        "name": "powershell_scriptblock_logging",
        "time": 0.0
      },
      {
        "name": "powershell_command_suspicious",
        "time": 0.0
      },
      {
        "name": "powershell_history_save_mod",
        "time": 0.0
      },
      {
        "name": "powershell_renamed",
        "time": 0.0
      },
      {
        "name": "powershell_reversed",
        "time": 0.0
      },
      {
        "name": "powershell_variable_obfuscation",
        "time": 0.0
      },
      {
        "name": "prevents_safeboot",
        "time": 0.0
      },
      {
        "name": "cmdline_process_discovery",
        "time": 0.0
      },
      {
        "name": "cryptomix_mutexes",
        "time": 0.0
      },
      {
        "name": "dharma_mutexes",
        "time": 0.0
      },
      {
        "name": "ransomware_extensions_generic",
        "time": 0.0
      },
      {
        "name": "ransomware_extensions_known",
        "time": 0.004
      },
      {
        "name": "ransomware_files",
        "time": 0.006
      },
      {
        "name": "fonix_mutexes",
        "time": 0.0
      },
      {
        "name": "gandcrab_mutexes",
        "time": 0.0
      },
      {
        "name": "germanwiper_mutexes",
        "time": 0.0
      },
      {
        "name": "medusalocker_mutexes",
        "time": 0.0
      },
      {
        "name": "medusalocker_regkeys",
        "time": 0.0
      },
      {
        "name": "nemty_mutexes",
        "time": 0.0
      },
      {
        "name": "nemty_regkeys",
        "time": 0.0
      },
      {
        "name": "pysa_mutexes",
        "time": 0.0
      },
      {
        "name": "ransomware_radamant",
        "time": 0.0
      },
      {
        "name": "ransomware_recyclebin",
        "time": 0.0
      },
      {
        "name": "revil_mutexes",
        "time": 0.001
      },
      {
        "name": "ransomware_revil_regkey",
        "time": 0.0
      },
      {
        "name": "satan_mutexes",
        "time": 0.0
      },
      {
        "name": "snake_ransom_mutexes",
        "time": 0.0
      },
      {
        "name": "stop_ransom_mutexes",
        "time": 0.0
      },
      {
        "name": "stop_ransomware_cmd",
        "time": 0.0
      },
      {
        "name": "ransomware_stopdjvu",
        "time": 0.0
      },
      {
        "name": "rat_beebus_mutexes",
        "time": 0.0
      },
      {
        "name": "blacknet_mutexes",
        "time": 0.0
      },
      {
        "name": "blackrat_mutexes",
        "time": 0.0
      },
      {
        "name": "crat_mutexes",
        "time": 0.0
      },
      {
        "name": "dcrat_files",
        "time": 0.0
      },
      {
        "name": "dcrat_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_fynloski_mutexes",
        "time": 0.0
      },
      {
        "name": "limerat_mutexes",
        "time": 0.0
      },
      {
        "name": "limerat_regkeys",
        "time": 0.0
      },
      {
        "name": "lodarat_file_behavior",
        "time": 0.0
      },
      {
        "name": "modirat_behavior",
        "time": 0.0
      },
      {
        "name": "njrat_regkeys",
        "time": 0.0
      },
      {
        "name": "obliquerat_files",
        "time": 0.0
      },
      {
        "name": "obliquerat_mutexes",
        "time": 0.0
      },
      {
        "name": "parallax_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_pcclient",
        "time": 0.0
      },
      {
        "name": "rat_plugx_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_poisonivy_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_quasar_mutexes",
        "time": 0.0
      },
      {
        "name": "ratsnif_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_spynet",
        "time": 0.0
      },
      {
        "name": "venomrat_mutexes",
        "time": 0.0
      },
      {
        "name": "warzonerat_files",
        "time": 0.0
      },
      {
        "name": "warzonerat_regkeys",
        "time": 0.0
      },
      {
        "name": "xpertrat_files",
        "time": 0.0
      },
      {
        "name": "xpertrat_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_xtreme_mutexes",
        "time": 0.0
      },
      {
        "name": "reads_password_database",
        "time": 0.0
      },
      {
        "name": "recon_fingerprint",
        "time": 0.0
      },
      {
        "name": "remcos_files",
        "time": 0.0
      },
      {
        "name": "remcos_mutexes",
        "time": 0.0
      },
      {
        "name": "remcos_regkeys",
        "time": 0.0
      },
      {
        "name": "rdptcp_key",
        "time": 0.0
      },
      {
        "name": "uses_rdp_clip",
        "time": 0.0
      },
      {
        "name": "uses_remote_desktop_session",
        "time": 0.0
      },
      {
        "name": "removes_networking_icon",
        "time": 0.0
      },
      {
        "name": "removes_pinned_programs",
        "time": 0.0
      },
      {
        "name": "removes_security_maintenance_icon",
        "time": 0.0
      },
      {
        "name": "removes_startmenu_defaults",
        "time": 0.0
      },
      {
        "name": "removes_username_startmenu",
        "time": 0.0
      },
      {
        "name": "spicyhotpot_behavior",
        "time": 0.0
      },
      {
        "name": "sniffer_winpcap",
        "time": 0.0
      },
      {
        "name": "spreading_autoruninf",
        "time": 0.0
      },
      {
        "name": "stealth_hidden_extension",
        "time": 0.0
      },
      {
        "name": "stealth_hiddenreg",
        "time": 0.0
      },
      {
        "name": "stealth_hide_notifications",
        "time": 0.0
      },
      {
        "name": "stealth_webhistory",
        "time": 0.0
      },
      {
        "name": "sysinternals_psexec",
        "time": 0.0
      },
      {
        "name": "sysinternals_tools",
        "time": 0.0
      },
      {
        "name": "language_check_registry",
        "time": 0.0
      },
      {
        "name": "tampers_etw",
        "time": 0.0
      },
      {
        "name": "lsa_tampering",
        "time": 0.0
      },
      {
        "name": "tampers_powershell_logging",
        "time": 0.0
      },
      {
        "name": "targeted_flame",
        "time": 0.0
      },
      {
        "name": "territorial_disputes_sigs",
        "time": 0.003
      },
      {
        "name": "trickbot_mutex",
        "time": 0.0
      },
      {
        "name": "fleercivet_mutex",
        "time": 0.0
      },
      {
        "name": "lokibot_mutexes",
        "time": 0.0
      },
      {
        "name": "ursnif_behavior",
        "time": 0.001
      },
      {
        "name": "uses_adfind",
        "time": 0.0
      },
      {
        "name": "uses_ms_protocol",
        "time": 0.0
      },
      {
        "name": "neshta_mutexes",
        "time": 0.0
      },
      {
        "name": "renamer_mutexes",
        "time": 0.0
      },
      {
        "name": "owa_web_shell_files",
        "time": 0.0
      },
      {
        "name": "web_shell_files",
        "time": 0.0
      },
      {
        "name": "web_shell_processes",
        "time": 0.0
      },
      {
        "name": "dotnet_csc_build",
        "time": 0.0
      },
      {
        "name": "mavinject_lolbin",
        "time": 0.0
      },
      {
        "name": "multiple_explorer_instances",
        "time": 0.0
      },
      {
        "name": "script_tool_executed",
        "time": 0.0
      },
      {
        "name": "suspicious_certutil_use",
        "time": 0.0
      },
      {
        "name": "suspicious_command_tools",
        "time": 0.0
      },
      {
        "name": "suspicious_mpcmdrun_use",
        "time": 0.0
      },
      {
        "name": "suspicious_ping_use",
        "time": 0.0
      },
      {
        "name": "uses_powershell_copyitem",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_appcmd",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_csvde_ldifde",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_cipher",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_clickonce",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_curl",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_dsquery",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_esentutl",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_finger",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_mode",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_ntdsutil",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_nltest",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_setx",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_xcopy",
        "time": 0.0
      },
      {
        "name": "wmic_command_suspicious",
        "time": 0.0
      },
      {
        "name": "scrcons_wmi_script_consumer",
        "time": 0.0
      },
      {
        "name": "allaple_mutexes",
        "time": 0.0
      }
    ],
    "reporting": [
      {
        "name": "BinGraph",
        "time": 0.0
      }
    ]
  },
  "target": {
    "category": "file",
    "file": {
      "name": "ServerPlugin.dll",
      "path": "/opt/CAPEv2/storage/binaries/2e5fbfb7932b117a2f6093dc346cdee4a5702e39739d9c40d27bfd1580f6f0d7",
      "guest_paths": "",
      "size": 29184,
      "crc32": "55FCF2F0",
      "md5": "952c62ec830c63380beb72ad923d35dc",
      "sha1": "6700baa1fb1877129e79402dfe237f0b84221b69",
      "sha256": "2e5fbfb7932b117a2f6093dc346cdee4a5702e39739d9c40d27bfd1580f6f0d7",
      "sha512": "5dc19d7d6ab7670ded766f357e481328c8df4a96ac3c2a00194a5ccea8c34bca0e34cfea3d9d17934db384d302446be2fec9853438371561d70580665bffe121",
      "rh_hash": null,
      "ssdeep": "384:7LmAEURVWGSCyo6/NLoqwXEsZmLTdFuoKy:vm1izOlg0ZKy",
      "type": "PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows",
      "yara": [
        {
          "name": "NETDLLMicrosoft",
          "meta": {
            "author": "malware-lu"
          },
          "strings": [
            "{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }"
          ],
          "addresses": {
            "a0": 16154
          }
        },
        {
          "name": "IsPE32",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsNET_DLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsDLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsWindowsGUI",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "Microsoft_Visual_Studio_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 16190
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 16190
          }
        },
        {
          "name": "Microsoft_Visual_C_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 16190
          }
        },
        {
          "name": "Microsoft_Visual_Studio_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 16190
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 16190
          }
        },
        {
          "name": "NET_executable_",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 16190
          }
        },
        {
          "name": "NET_executable",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 16190
          }
        }
      ],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T159D2A31B96CE7EE9D9B816743B7347C1D768CE005643DA2E55C83129E9BE2433A833D8",
      "sha3_384": "47b8fbed3e0be8948398ab60d955f7056567cd9c06fa8b2b74ba771fb012d380adfc8a211d6bad188d51db80a168fa46",
      "yara_hash": "b833150b13e1662cfeb7589959edd288cf4e73710395ec5c5f2123f39a668f4d",
      "options_hash": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
      "pe": {
        "guest_signers": {
          "aux_sha1": null,
          "aux_timestamp": null,
          "aux_valid": false,
          "aux_error": true,
          "aux_error_desc": "No signature found.",
          "aux_signers": []
        },
        "digital_signers": [],
        "imagebase": "0x00400000",
        "entrypoint": "0x00005d3e",
        "ep_bytes": "ff250020400000000000000000000000",
        "peid_signatures": null,
        "reported_checksum": "0x00000000",
        "actual_checksum": "0x0000b533",
        "osversion": "4.0",
        "machine_type": "IMAGE_FILE_MACHINE_I386",
        "pdbpath": null,
        "imports": {
          "mscoree": {
            "dll": "mscoree.dll",
            "imports": [
              {
                "address": "0x402000",
                "name": "_CorDllMain"
              }
            ]
          }
        },
        "exported_dll_name": null,
        "exports": [],
        "dirents": [
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
            "virtual_address": "0x00005cec",
            "size": "0x0000004f"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
            "virtual_address": "0x00006000",
            "size": "0x00002f58"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
            "virtual_address": "0x0000a000",
            "size": "0x0000000c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_TLS",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IAT",
            "virtual_address": "0x00002000",
            "size": "0x00000008"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
            "virtual_address": "0x00002008",
            "size": "0x00000048"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          }
        ],
        "sections": [
          {
            "name": ".text",
            "raw_address": "0x00000200",
            "virtual_address": "0x00002000",
            "virtual_size": "0x00003d44",
            "size_of_data": "0x00003e00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x60000020",
            "entropy": "5.46"
          },
          {
            "name": ".rsrc",
            "raw_address": "0x00004000",
            "virtual_address": "0x00006000",
            "virtual_size": "0x00002f58",
            "size_of_data": "0x00003000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x40000040",
            "entropy": "3.31"
          },
          {
            "name": ".reloc",
            "raw_address": "0x00007000",
            "virtual_address": "0x0000a000",
            "virtual_size": "0x0000000c",
            "size_of_data": "0x00000200",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "0.08"
          }
        ],
        "overlay": null,
        "resources": [
          {
            "name": "RT_ICON",
            "offset": "0x00006468",
            "size": "0x000002e8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.71"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00006750",
            "size": "0x00000128",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.08"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00006878",
            "size": "0x000008a8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.72"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00007120",
            "size": "0x00000568",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.05"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00007688",
            "size": "0x00000353",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "4.05"
          },
          {
            "name": "RT_ICON",
            "offset": "0x000079e0",
            "size": "0x000010a8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.72"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00008a88",
            "size": "0x00000468",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.76"
          },
          {
            "name": "RT_GROUP_ICON",
            "offset": "0x00008ef0",
            "size": "0x00000068",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.69"
          },
          {
            "name": "RT_VERSION",
            "offset": "0x00006208",
            "size": "0x0000025c",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "3.24"
          }
        ],
        "versioninfo": [
          {
            "name": "Translation",
            "value": "0x0000 0x04b0"
          },
          {
            "name": "FileDescription",
            "value": " "
          },
          {
            "name": "FileVersion",
            "value": "1.2.0.0"
          },
          {
            "name": "InternalName",
            "value": "ServerPlugin.dll"
          },
          {
            "name": "LegalCopyright",
            "value": " "
          },
          {
            "name": "OriginalFilename",
            "value": "ServerPlugin.dll"
          },
          {
            "name": "ProductVersion",
            "value": "1.2.0.0"
          },
          {
            "name": "Assembly Version",
            "value": "1.2.0.0"
          }
        ],
        "imphash": "dae02f32a21e03ce65412f6e56942daa",
        "timestamp": "2014-11-23 01:09:02",
        "icon": "iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAY0lEQVR4nO3XIQ6AMBBE0YH0eGuAcwKmZ1sLCkHRZUj4o9qaeVmzqfT3DJl5OAGjs1ySynWIiFeLa62SPjABAABK+7Cte9fCeZlud/sEAAAAAAAAADvgsY7bddk79gnwMSH2nLDUDvNx5OJLAAAAAElFTkSuQmCC",
        "icon_hash": "f66c7c86e9ab59ef3f289acd613a3738",
        "icon_fuzzy": "c3ca946d749a15ad18efd3e5d7b0d8f5",
        "icon_dhash": "454545d4d4d44503",
        "imported_dll_count": 1
      },
      "data": null,
      "strings": [
        "target",
        "clients",
        "mscoree.dll",
        "IServerFileTransferHost",
        "IServerDataHost",
        "Connections",
        "ClickedCallback",
        "m_Context",
        "EndPoint",
        "set_Value",
        "1.2.0.0",
        "BytesPerSecond",
        "Priority",
        "message",
        "_AllowGrouping",
        "_CorDllMain",
        "#Blob",
        "EnableListener",
        "duration",
        "Canceled",
        "CancelFileTransfer",
        "BeginInvoke",
        "set_UserControl",
        "CreateClientPipe",
        "_StateChangedCallback",
        "set_StateChangedCallback",
        "CheckState",
        "VarFileInfo",
        "transfer",
        "IServerFileTransfer",
        "System.Runtime.CompilerServices",
        "ApplyTheme",
        "set_Name",
        "IAsyncResult",
        "EscapeSQLQuery",
        "EndInvoke",
        "wwwwww",
        "Queued",
        "set_GetCheckStateCallback",
        ".text",
        "ApplicationIcon",
        "get_Icon",
        "GuidAttribute",
        "NanoCore",
        "get_Width",
        "AssemblyTrademarkAttribute",
        "DelegateAsyncState",
        "ProductVersion",
        "FileDescription",
        "@.reloc",
        "DisconnectClient",
        "FocusClient",
        "actions",
        "listener",
        "PortNumber",
        "get_ThemeSettings",
        "8.0.0.0",
        "000004b0",
        "_CategoryName",
        "get_Connections",
        "Translation",
        "mscorlib",
        "RuntimeHelpers",
        "set_Locked",
        "FileName",
        "HideModuleNameAttribute",
        "PreBuild",
        "connected",
        "GetClients",
        "IServerDatabaseHost",
        "Binding",
        "Incoming",
        "background",
        "get_FileName",
        "Exception",
        "index",
        "TimeSpan",
        "get_BytesPerSecond",
        "FileSize",
        "#GUID",
        "ColumnEntry",
        "AssemblyDescriptionAttribute",
        "categoryName",
        "Microsoft.VisualBasic.Devices",
        "BuilderSettings",
        "m_ComputerObjectProvider",
        "StandardModuleAttribute",
        "GetTypeFromHandle",
        "get_State",
        "set_CategoryName",
        "System.Net",
        "_UserControl",
        "Disabled",
        "EntryExists",
        "checked",
        "IServerNetworkHost",
        "TableExists",
        "Microsoft.VisualBasic.CompilerServices",
        "Paused",
        "AutoPropertyValue",
        "_Callback",
        "System",
        "Cancel",
        "Activate",
        "AllowGrouping",
        "Selected",
        "MyApplication",
        "MyGroupCollectionAttribute",
        "NanoCore.ServerPlugin",
        "ParamArrayAttribute",
        "TabStateChangedDelegate",
        "get_TimeRemaining",
        "tableName",
        "Status",
        "IPEndPoint",
        "compress",
        "CategoryName",
        "ThreadSafeObjectProvider`1",
        "Close",
        "IServerData",
        "Medium",
        "System.ComponentModel",
        "ToString",
        "DelegateCallback",
        "instance",
        "wwwwwwwwwwwwww",
        "LegalCopyright",
        "GetInstance",
        "Completed",
        "FileTransferStatus",
        "CompilerGeneratedAttribute",
        "Equals",
        "get_GetCheckStateCallback",
        "ContextValue`1",
        "SetValue",
        "get_Children",
        "TabEntry",
        "WebServices",
        "logColor",
        "v2.0.50727",
        "#Strings",
        "System.Collections.Generic",
        "IServerApp",
        "ThemeSettings",
        "get_FileSize",
        "query",
        "UploadFile",
        "ClientStateChanged",
        "client",
        "!This program cannot be run in DOS mode.",
        "set_State",
        "TargetObject",
        "GetValue",
        "IServerReadOnlyNameObjectCollection",
        "ExecuteNonQuery",
        "value__",
        "Value",
        "RuntimeCompatibilityAttribute",
        "CompilationRelaxationsAttribute",
        "Deselected",
        "LogBuilderException",
        "param",
        "state",
        "PluginUninstalling",
        "ExecuteQuery",
        "_GetCheckStateCallback",
        "FocusTab",
        "get_User",
        "CreateInstance",
        "ServerPlugin",
        "TabState",
        "NotificationAction",
        "BuilderSettingChanged",
        "NextResultSet",
        "get_AllowGrouping",
        "CancelReason",
        "ListenerFailed",
        "System.Windows.Forms",
        "Active",
        "SettingEntry",
        "Callback",
        "ListenerStateChanged",
        "AddClientColumnEntry",
        "HelpKeywordAttribute",
        "NextRecord",
        "SetClientColumnValue",
        "PostBuild",
        "defaultValue",
        "System.Reflection",
        "get_BuilderSettings",
        "AddHint",
        "get_Listeners",
        "Direction",
        "get_Name",
        "LogServerException",
        "DelegateAsyncResult",
        "LogServerMessage",
        "RuntimeTypeHandle",
        "WrapNonExceptionThrows",
        "GetType",
        "Warning",
        "get_PortNumber",
        "EditorBrowsableState",
        "Persistent",
        "Microsoft.VisualBasic.MyServices.Internal",
        "Removed",
        "System.CodeDom.Compiler",
        "get_Persistent",
        "params",
        "RemoveListener",
        "Assembly Version",
        "get_Direction",
        "KeyValuePair`2",
        "My.Application",
        "ClientVariableChanged",
        "NanoCore.My",
        "IDATx",
        "InternalName",
        "State",
        "set_Persistent",
        "IServerUI",
        "ExecuteScalar",
        "MulticastDelegate",
        "title",
        "RestartFileTransfer",
        "ComVisibleAttribute",
        "clientFileName",
        "GetFileTransfers",
        "EditorBrowsableAttribute",
        "ServerPlugin.dll",
        "FileTransferStateChanged",
        "pipeName",
        "FindClient",
        "get_BytesTransferred",
        "get_UserControl",
        "IServerNameObjectCollection",
        "get_Id",
        "EscapeSQLParam",
        "DebuggerHiddenAttribute",
        "_ClickedCallback",
        "Error",
        "5%7&:'<",
        "GetEntries",
        "MyTemplate",
        "Outgoing",
        "set_AllowGrouping",
        "AddListener",
        "StateChangedCallback",
        "IServerBuildHost",
        "Information",
        "My.User",
        "Listening",
        "Control",
        "_Icon",
        "control",
        "ListenerAdded",
        "get_WebServices",
        "ClientPipeClosed",
        "Normal",
        "FileTransferAdded",
        "CreateDatabase",
        "Invoke",
        "System.ComponentModel.Design",
        "get_EndPoint",
        "Width",
        "set_Width",
        "contextEntry",
        "get_ClickedCallback",
        "Initializing",
        "Background",
        "FileTransferDirection",
        "MyWebServices",
        "My.WebServices",
        "Variables",
        "_Children",
        "TimeRemaining",
        "get_Background",
        "AssemblyCompanyAttribute",
        "Children",
        "GetCheckStateCallback",
        "m_UserObjectProvider",
        "FindFileTransfer",
        "Dispose__Instance__",
        "set_Children",
        "IFileTransfer",
        "ClientFileName",
        "Compile",
        "DatabaseExists",
        "IServerBuild",
        "get_ServerSettings",
        "ThemeChanged",
        "Locked",
        "get_Item",
        "get_Status",
        "get_Variables",
        "get_Cancel",
        "AssemblyTitleAttribute",
        "ListenerStatus",
        "fileName",
        "AddWidgetEntry",
        "get_ApplicationIcon",
        "LogColor",
        "m_MyWebServicesObjectProvider",
        "GeneratedCodeAttribute",
        "get_Computer",
        "AddServerSettingEntry",
        "AddContextEntry",
        "DownloadFile",
        "ISQLReader",
        "Failed",
        "ClientReadPacket",
        "serverFileName",
        "get_ServerFileName",
        "ClientPipeCreated",
        "GetObjectValue",
        "UserControl",
        "NotificationDelegate",
        "TargetMethod",
        "widgetEntry",
        "ServerInvokeDelegate",
        "ServerSettings",
        "ContextEntry",
        "tabEntry",
        "System.Diagnostics",
        "StartFileTransfer",
        "set_Icon",
        "MyComputer",
        ".ctor",
        "MyProject",
        "get_CancelReason",
        "set_ClickedCallback",
        "AddTabEntry",
        "My.Computer",
        "AsyncCallback",
        "m_AppObjectProvider",
        "<Module>",
        "get_GetInstance",
        "FileVersion",
        "IServerUIHost",
        "get_Initializing",
        "get_Locked",
        "ShowToastNotification",
        "set_Cancel",
        "set_Priority",
        "CloseClientPipe",
        "`.rsrc",
        "AssemblyFileVersionAttribute",
        "imageName",
        "StringFileInfo",
        "set_CancelReason",
        "get_Client",
        "AssemblyProductAttribute",
        "Microsoft.VisualBasic",
        "IBuildEventArgs",
        "NanoCore.ServerPluginHost",
        "SendToClient",
        "ListenerRemoved",
        "AddBuilderSettingEntry",
        "VariableChanged",
        "get_Callback",
        "GetHashCode",
        "$8af4df77-9055-41ab-92ee-84a854449c8d",
        "get_CategoryName",
        "columnEntry",
        "get_Application",
        "settingEntry",
        "Activator",
        "Application",
        "ContextClickedDelegate",
        "FileTransferPriority",
        "OriginalFilename",
        "RemoveValue",
        "IServerLoggingHost",
        "set_Callback",
        "System.Drawing",
        "DisableListener",
        "ContextGetCheckStateDelegate",
        "get_ClientFileName",
        "columnName",
        "System.Runtime.InteropServices",
        "ClientPipeExists",
        "value",
        "VS_VERSION_INFO",
        "WidgetEntry",
        "Create__Instance__",
        "IServerNetwork",
        "Computer",
        "PauseFileTransfer",
        "get_StateChangedCallback",
        "ApplicationBase",
        "LogBuilderMessage",
        "BytesTransferred",
        "_Name",
        "Client",
        "get_Priority",
        "ServerSettingChanged",
        "Object",
        "AssemblyCopyrightAttribute",
        "get_Value",
        "IListener",
        "4System.Web.Services.Protocols.SoapHttpClientProtocol",
        "DeleteDatabase",
        ".cctor",
        "_Width",
        "IClient",
        "ServerFileName",
        "Listeners",
        "_Locked",
        "databaseName",
        "FileTransferRemoved",
        "Microsoft.VisualBasic.ApplicationServices"
      ],
      "virustotal": {
        "error": true,
        "msg": "VT File lookup disabled in processing.conf"
      },
      "executed_tools": [
        "overlay",
        "msi_extract",
        "kixtart_extract",
        "vbe_extract",
        "batch_extract",
        "UnAutoIt_extract",
        "UPX_unpack",
        "RarSFX_extract",
        "Inno_extract",
        "SevenZip_unpack",
        "de4dot_deobfuscate",
        "eziriz_deobfuscate",
        "office_one"
      ],
      "cape_type_code": 0,
      "cape_type": ""
    }
  },
  "procdump": [
    {
      "name": "c2800550f928a910a9337cd2013e97a03b2da584b8522843804197fc2aa23634",
      "path": "/opt/CAPEv2/storage/analyses/41/procdump/c2800550f928a910a9337cd2013e97a03b2da584b8522843804197fc2aa23634",
      "guest_paths": "1;?C:\\Windows\\SysWOW64\\rundll32.exe;?C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll;?",
      "size": 16896,
      "crc32": "43513DD4",
      "md5": "d2df94ab3d51576ef1469211058a6b1b",
      "sha1": "e29ce1b7b3a8e113c23de64b5297d906e5fc9d54",
      "sha256": "c2800550f928a910a9337cd2013e97a03b2da584b8522843804197fc2aa23634",
      "sha512": "86906e2f2e2188e64b242d9b43fa7e160dcaa47c9223c6001f31d2aebd663f5a462656daa47d8808720fa1c428ad7a4e2f922d1dbaf434c1dde19e41f871290d",
      "rh_hash": null,
      "ssdeep": "384:FLmAEURVWGSCyo6/NLoqwXEsZmLTdFuoK:Fm1izOlg0ZK",
      "type": "PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows",
      "yara": [
        {
          "name": "NETDLLMicrosoft",
          "meta": {
            "author": "malware-lu"
          },
          "strings": [
            "{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }"
          ],
          "addresses": {
            "a0": 16666
          }
        },
        {
          "name": "IsPE32",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsNET_DLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsDLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsWindowsGUI",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "Microsoft_Visual_Studio_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 16702
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 16702
          }
        },
        {
          "name": "Microsoft_Visual_C_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 16702
          }
        },
        {
          "name": "Microsoft_Visual_Studio_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 16702
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 16702
          }
        },
        {
          "name": "NET_executable_",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 16702
          }
        },
        {
          "name": "NET_executable",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 16702
          }
        }
      ],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T10472094EEBC4A37DCFB91B7A04A50A102BB0C344B6C3EF56590450BBDDC674513971EA",
      "sha3_384": "9a6f2b6a47afe4ce69298141b6cbb2a5b43fb47834f3fff1f37afd5927b7d7158a321e17efe38a5a79355211b6e17b99",
      "yara_hash": "b833150b13e1662cfeb7589959edd288cf4e73710395ec5c5f2123f39a668f4d",
      "options_hash": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
      "pe": {
        "guest_signers": {
          "aux_sha1": null,
          "aux_timestamp": null,
          "aux_valid": false,
          "aux_error": true,
          "aux_error_desc": "No signature found.",
          "aux_signers": []
        },
        "digital_signers": [],
        "imagebase": "0x00400000",
        "entrypoint": "0x00005d3e",
        "ep_bytes": "ff250020400000000000000000000000",
        "peid_signatures": null,
        "reported_checksum": "0x00000000",
        "actual_checksum": "0x000063e5",
        "osversion": "4.0",
        "machine_type": "IMAGE_FILE_MACHINE_I386",
        "pdbpath": null,
        "imports": {
          "mscoree": {
            "dll": "mscoree.dll",
            "imports": [
              {
                "address": "0x402000",
                "name": "_CorDllMain"
              }
            ]
          }
        },
        "exported_dll_name": null,
        "exports": [],
        "dirents": [
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
            "virtual_address": "0x00005cec",
            "size": "0x0000004f"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
            "virtual_address": "0x00006000",
            "size": "0x00002f58"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
            "virtual_address": "0x0000a000",
            "size": "0x0000000c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_TLS",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IAT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
            "virtual_address": "0x00002008",
            "size": "0x00000048"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          }
        ],
        "sections": [
          {
            "name": ".text",
            "raw_address": "0x00000400",
            "virtual_address": "0x00002000",
            "virtual_size": "0x00004000",
            "size_of_data": "0x00003e00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
            "characteristics_raw": "0xe0000020",
            "entropy": "5.46"
          },
          {
            "name": ".rsrc",
            "raw_address": "0x00004200",
            "virtual_address": "0x00006000",
            "virtual_size": "0x00004000",
            "size_of_data": "0x00000000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x40000040",
            "entropy": "0.00"
          },
          {
            "name": ".reloc",
            "raw_address": "0x00004200",
            "virtual_address": "0x0000a000",
            "virtual_size": "0x00002000",
            "size_of_data": "0x00000000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "0.00"
          }
        ],
        "overlay": null,
        "resources": [],
        "versioninfo": [],
        "imphash": "dae02f32a21e03ce65412f6e56942daa",
        "timestamp": "2014-11-23 01:09:02",
        "icon": null,
        "icon_hash": null,
        "icon_fuzzy": null,
        "icon_dhash": null,
        "imported_dll_count": 1
      },
      "data": null,
      "strings": [
        "target",
        "clients",
        "mscoree.dll",
        "IServerFileTransferHost",
        "IServerDataHost",
        "Connections",
        "ClickedCallback",
        "m_Context",
        "EndPoint",
        "set_Value",
        "1.2.0.0",
        "BytesPerSecond",
        "Priority",
        "message",
        "_AllowGrouping",
        "_CorDllMain",
        "#Blob",
        "EnableListener",
        "duration",
        "Canceled",
        "CancelFileTransfer",
        "BeginInvoke",
        "set_UserControl",
        "CreateClientPipe",
        "_StateChangedCallback",
        "set_StateChangedCallback",
        "CheckState",
        "transfer",
        "IServerFileTransfer",
        "System.Runtime.CompilerServices",
        "ApplyTheme",
        "set_Name",
        "IAsyncResult",
        "EscapeSQLQuery",
        "EndInvoke",
        "Queued",
        "set_GetCheckStateCallback",
        ".text",
        "ApplicationIcon",
        "get_Icon",
        "GuidAttribute",
        "NanoCore",
        "get_Width",
        "AssemblyTrademarkAttribute",
        "DelegateAsyncState",
        "@.reloc",
        "DisconnectClient",
        "FocusClient",
        "actions",
        "listener",
        "PortNumber",
        "get_ThemeSettings",
        "8.0.0.0",
        "_CategoryName",
        "get_Connections",
        "mscorlib",
        "RuntimeHelpers",
        "set_Locked",
        "FileName",
        "HideModuleNameAttribute",
        "PreBuild",
        "connected",
        "GetClients",
        "IServerDatabaseHost",
        "Binding",
        "Incoming",
        "background",
        "get_FileName",
        "Exception",
        "index",
        "TimeSpan",
        "get_BytesPerSecond",
        "FileSize",
        "#GUID",
        "ColumnEntry",
        "AssemblyDescriptionAttribute",
        "categoryName",
        "Microsoft.VisualBasic.Devices",
        "BuilderSettings",
        "m_ComputerObjectProvider",
        "StandardModuleAttribute",
        "GetTypeFromHandle",
        "get_State",
        "set_CategoryName",
        "System.Net",
        "_UserControl",
        "Disabled",
        "EntryExists",
        "checked",
        "IServerNetworkHost",
        "TableExists",
        "Microsoft.VisualBasic.CompilerServices",
        "Paused",
        "AutoPropertyValue",
        "_Callback",
        "System",
        "Cancel",
        "Activate",
        "AllowGrouping",
        "Selected",
        "MyApplication",
        "MyGroupCollectionAttribute",
        "NanoCore.ServerPlugin",
        "ParamArrayAttribute",
        "TabStateChangedDelegate",
        "get_TimeRemaining",
        "tableName",
        "Status",
        "IPEndPoint",
        "compress",
        "CategoryName",
        "ThreadSafeObjectProvider`1",
        "Close",
        "IServerData",
        "Medium",
        "System.ComponentModel",
        "ToString",
        "DelegateCallback",
        "instance",
        "GetInstance",
        "Completed",
        "FileTransferStatus",
        "CompilerGeneratedAttribute",
        "Equals",
        "get_GetCheckStateCallback",
        "ContextValue`1",
        "SetValue",
        "get_Children",
        "TabEntry",
        "WebServices",
        "logColor",
        "v2.0.50727",
        "#Strings",
        "System.Collections.Generic",
        "IServerApp",
        "ThemeSettings",
        "get_FileSize",
        "query",
        "UploadFile",
        "ClientStateChanged",
        "client",
        ".rsrc",
        "!This program cannot be run in DOS mode.",
        "set_State",
        "TargetObject",
        "GetValue",
        "IServerReadOnlyNameObjectCollection",
        "ExecuteNonQuery",
        "value__",
        "Value",
        "RuntimeCompatibilityAttribute",
        "CompilationRelaxationsAttribute",
        "Deselected",
        "LogBuilderException",
        "param",
        "state",
        "PluginUninstalling",
        "ExecuteQuery",
        "_GetCheckStateCallback",
        "FocusTab",
        "get_User",
        "CreateInstance",
        "ServerPlugin",
        "TabState",
        "NotificationAction",
        "BuilderSettingChanged",
        "NextResultSet",
        "get_AllowGrouping",
        "CancelReason",
        "ListenerFailed",
        "System.Windows.Forms",
        "Active",
        "SettingEntry",
        "Callback",
        "ListenerStateChanged",
        "AddClientColumnEntry",
        "HelpKeywordAttribute",
        "NextRecord",
        "SetClientColumnValue",
        "PostBuild",
        "defaultValue",
        "System.Reflection",
        "get_BuilderSettings",
        "AddHint",
        "get_Listeners",
        "Direction",
        "get_Name",
        "LogServerException",
        "DelegateAsyncResult",
        "LogServerMessage",
        "RuntimeTypeHandle",
        "WrapNonExceptionThrows",
        "GetType",
        "Warning",
        "get_PortNumber",
        "EditorBrowsableState",
        "Persistent",
        "Microsoft.VisualBasic.MyServices.Internal",
        "Removed",
        "System.CodeDom.Compiler",
        "get_Persistent",
        "params",
        "RemoveListener",
        "get_Direction",
        "KeyValuePair`2",
        "My.Application",
        "ClientVariableChanged",
        "NanoCore.My",
        "State",
        "set_Persistent",
        "IServerUI",
        "ExecuteScalar",
        "MulticastDelegate",
        "title",
        "RestartFileTransfer",
        "ComVisibleAttribute",
        "clientFileName",
        "GetFileTransfers",
        "EditorBrowsableAttribute",
        "ServerPlugin.dll",
        "FileTransferStateChanged",
        "pipeName",
        "FindClient",
        "get_BytesTransferred",
        "get_UserControl",
        "IServerNameObjectCollection",
        "get_Id",
        "EscapeSQLParam",
        "DebuggerHiddenAttribute",
        "_ClickedCallback",
        "Error",
        "5%7&:'<",
        "GetEntries",
        "MyTemplate",
        "Outgoing",
        "set_AllowGrouping",
        "AddListener",
        "StateChangedCallback",
        "IServerBuildHost",
        "Information",
        "My.User",
        "Listening",
        "Control",
        "_Icon",
        "control",
        "ListenerAdded",
        "get_WebServices",
        "ClientPipeClosed",
        "Normal",
        "FileTransferAdded",
        "CreateDatabase",
        "Invoke",
        "System.ComponentModel.Design",
        "get_EndPoint",
        "Width",
        "set_Width",
        "contextEntry",
        "get_ClickedCallback",
        "Initializing",
        "Background",
        "FileTransferDirection",
        "MyWebServices",
        "My.WebServices",
        "Variables",
        "_Children",
        "TimeRemaining",
        "get_Background",
        "AssemblyCompanyAttribute",
        "Children",
        "GetCheckStateCallback",
        "m_UserObjectProvider",
        "FindFileTransfer",
        "Dispose__Instance__",
        "set_Children",
        "IFileTransfer",
        "ClientFileName",
        "Compile",
        "DatabaseExists",
        "IServerBuild",
        "get_ServerSettings",
        "ThemeChanged",
        "Locked",
        "get_Item",
        "get_Status",
        "get_Variables",
        "get_Cancel",
        "AssemblyTitleAttribute",
        "ListenerStatus",
        "fileName",
        "AddWidgetEntry",
        "get_ApplicationIcon",
        "LogColor",
        "m_MyWebServicesObjectProvider",
        "GeneratedCodeAttribute",
        "get_Computer",
        "AddServerSettingEntry",
        "AddContextEntry",
        "DownloadFile",
        "ISQLReader",
        "Failed",
        "ClientReadPacket",
        "serverFileName",
        "get_ServerFileName",
        "ClientPipeCreated",
        "GetObjectValue",
        "UserControl",
        "NotificationDelegate",
        "TargetMethod",
        "widgetEntry",
        "ServerInvokeDelegate",
        "ServerSettings",
        "ContextEntry",
        "tabEntry",
        "System.Diagnostics",
        "StartFileTransfer",
        "set_Icon",
        "MyComputer",
        ".ctor",
        "MyProject",
        "get_CancelReason",
        "set_ClickedCallback",
        "AddTabEntry",
        "My.Computer",
        "AsyncCallback",
        "m_AppObjectProvider",
        "<Module>",
        "get_GetInstance",
        "IServerUIHost",
        "get_Initializing",
        "get_Locked",
        "ShowToastNotification",
        "set_Cancel",
        "set_Priority",
        "CloseClientPipe",
        "AssemblyFileVersionAttribute",
        "imageName",
        "set_CancelReason",
        "get_Client",
        "AssemblyProductAttribute",
        "Microsoft.VisualBasic",
        "IBuildEventArgs",
        "NanoCore.ServerPluginHost",
        "SendToClient",
        "ListenerRemoved",
        "AddBuilderSettingEntry",
        "VariableChanged",
        "get_Callback",
        "GetHashCode",
        "$8af4df77-9055-41ab-92ee-84a854449c8d",
        "get_CategoryName",
        "columnEntry",
        "get_Application",
        "settingEntry",
        "Activator",
        "Application",
        "ContextClickedDelegate",
        "FileTransferPriority",
        "RemoveValue",
        "IServerLoggingHost",
        "set_Callback",
        "System.Drawing",
        "DisableListener",
        "ContextGetCheckStateDelegate",
        "get_ClientFileName",
        "columnName",
        "System.Runtime.InteropServices",
        "ClientPipeExists",
        "value",
        "WidgetEntry",
        "Create__Instance__",
        "IServerNetwork",
        "Computer",
        "PauseFileTransfer",
        "get_StateChangedCallback",
        "ApplicationBase",
        "LogBuilderMessage",
        "BytesTransferred",
        "_Name",
        "Client",
        "get_Priority",
        "ServerSettingChanged",
        "Object",
        "AssemblyCopyrightAttribute",
        "get_Value",
        "IListener",
        "4System.Web.Services.Protocols.SoapHttpClientProtocol",
        "DeleteDatabase",
        ".cctor",
        "_Width",
        "IClient",
        "ServerFileName",
        "Listeners",
        "_Locked",
        "databaseName",
        "FileTransferRemoved",
        "Microsoft.VisualBasic.ApplicationServices"
      ],
      "virustotal": {
        "error": true,
        "msg": "VT File lookup disabled in processing.conf"
      },
      "executed_tools": [
        "overlay",
        "msi_extract",
        "kixtart_extract",
        "vbe_extract",
        "batch_extract",
        "UnAutoIt_extract",
        "UPX_unpack",
        "RarSFX_extract",
        "Inno_extract",
        "SevenZip_unpack",
        "de4dot_deobfuscate",
        "eziriz_deobfuscate",
        "office_one"
      ],
      "cape_type_code": 1,
      "cape_type": "",
      "process_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
      "process_name": "rundll32.exe",
      "module_path": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll",
      "pid": 4344
    }
  ],
  "CAPE": {
    "payloads": [],
    "configs": []
  },
  "info": {
    "version": "2.5",
    "started": "2026-04-16 22:52:52",
    "ended": "2026-04-16 22:58:10",
    "duration": 318,
    "id": 41,
    "category": "file",
    "custom": "",
    "machine": {
      "id": 34,
      "status": "stopping",
      "name": "win10x64",
      "label": "win10x64",
      "platform": "windows",
      "manager": "KVM",
      "started_on": "2026-04-16 22:52:52",
      "shutdown_on": "2026-04-16 22:58:09"
    },
    "package": "dll",
    "timeout": true,
    "tlp": null,
    "parent_sample": {
      "id": 23,
      "file_size": 13850813,
      "file_type": "7-zip archive data, version 0.3",
      "md5": "a17189d956c6d1975717256a6e6418cb",
      "crc32": "97AFA081",
      "sha1": "970e16de1d07a90dd285e84b59c0a77e8992ed9f",
      "sha256": "f9cef6944196d5d27ca99a9c6287d9718b658add797e9cb770789a0c4dbf2bcd",
      "sha512": "3105fa5d4d6914fe69f4d4ab9e517eab55d225bbdfa199f37f3c9f103805b1b5c587fe5e985a87ea60e2e7d511a0f872619343014233791ef63859130065e9f1",
      "ssdeep": null,
      "source_url": null
    },
    "options": {},
    "source_url": null,
    "route": "",
    "user_id": 0,
    "CAPE_current_commit": "a9a0887dab232f52c59e955b9984dd494c47ce6b"
  },
  "behavior": {
    "processes": [
      {
        "process_id": 4344,
        "process_name": "rundll32.exe",
        "parent_id": 3592,
        "module_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
        "first_seen": "2026-04-16 19:54:36,218",
        "calls": [
          {
            "timestamp": "2026-04-16 19:54:36,921",
            "thread_id": "6616",
            "caller": "0x77274faa",
            "parentcaller": "0x77514cce",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetThreadContext"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ae38d0"
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetThreadTimes"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad1f70"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "IsProcessorFeaturePresent"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0b70"
              }
            ],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "OpenThread"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76acf5b0"
              }
            ],
            "repeated": 0,
            "id": 4
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "ProcessIdToSessionId"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0b90"
              }
            ],
            "repeated": 0,
            "id": 5
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "SetProcessShutdownParameters"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ac9540"
              }
            ],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "SetThreadContext"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ae4d20"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetProcessId"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0c20"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x77274faa",
            "parentcaller": "0x77514d2f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x77274faa",
            "parentcaller": "0x77514cce",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x77274faa",
            "parentcaller": "0x77514d2f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x77e7007d",
            "parentcaller": "0x7726648d",
            "category": "system",
            "api": "NtQueryLicenseValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Name",
                "value": "TerminalServices-RemoteConnectionManager-AllowAppServerMode"
              },
              {
                "name": "Type",
                "value": "0x00000004"
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x77e7007d",
            "parentcaller": "0x7726648d",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume1\\Windows\\SysWOW64\\imagehlp"
              },
              {
                "name": "BaseAddress",
                "value": "0x77510000"
              },
              {
                "name": "InitRoutine",
                "value": "0x77516560"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4432",
            "caller": "0x77e91c0e",
            "parentcaller": "0x77e8dbb1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000007c"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x001a5f1a",
            "parentcaller": "0x001a5fdd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ee3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x001a5f1a",
            "parentcaller": "0x001a5fdd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ee4000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4524",
            "caller": "0x77e80857",
            "parentcaller": "0x77e8055f",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ee5000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4524",
            "caller": "0x77e80857",
            "parentcaller": "0x77e8055f",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ee7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4524",
            "caller": "0x77e7138f",
            "parentcaller": "0x77e7110a",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000009",
                "pretty_value": "KEY_QUERY_VALUE|KEY_ENUMERATE_SUB_KEYS"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\Session Manager"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4524",
            "caller": "0x77e713ac",
            "parentcaller": "0x77e7110a",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c0"
              },
              {
                "name": "ValueName",
                "value": "ResourcePolicies"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\ResourcePolicies"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4524",
            "caller": "0x77e713c2",
            "parentcaller": "0x77e7110a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4524",
            "caller": "0x77e6f04b",
            "parentcaller": "0x77e6ef40",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ec0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00008000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x001a59c5",
            "parentcaller": "0x001a42a3",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll.manifest"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4520",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4520",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4432",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "4432",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-04-16 19:54:36,936",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002ac"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ed0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000c000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c0"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll.123.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-04-16 19:54:37,265",
            "thread_id": "6616",
            "caller": "0x001a5a1d",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ed0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002ac"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ed0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000c000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c4"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll.124.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a3e",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ed0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ed0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000c000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c4"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll.2.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5a5f",
            "parentcaller": "0x001a42a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02ed0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5abb",
            "parentcaller": "0x001a42a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5abb",
            "parentcaller": "0x001a42a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5abb",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-04-16 19:54:37,280",
            "thread_id": "6616",
            "caller": "0x001a5abb",
            "parentcaller": "0x001a42a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00120089",
                "pretty_value": "FILE_GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\rundll32.exe"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-04-16 19:54:37,296",
            "thread_id": "6616",
            "caller": "0x001a5abb",
            "parentcaller": "0x001a42a3",
            "category": "__notification__",
            "api": "sysenter",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadIdentifier",
                "value": "6616"
              },
              {
                "name": "Module",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "Return Address",
                "value": "0x76ad24ac"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a5abb",
            "parentcaller": "0x001a42a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a5d94",
            "parentcaller": "0x001a42ae",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a5d1d",
            "parentcaller": "0x001a5db9",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "18"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a5d42",
            "parentcaller": "0x001a5db9",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "20"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a5dc4",
            "parentcaller": "0x001a42ae",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3c8d",
            "parentcaller": "0x001a3e97",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin"
              },
              {
                "name": "DllBase",
                "value": "0x05b20000"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3c8d",
            "parentcaller": "0x001a3e97",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x05b20000"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3d51",
            "parentcaller": "0x001a3e97",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "34",
                "pretty_value": "ProcessExecuteFlags"
              },
              {
                "name": "ProcessInformation",
                "value": "13"
              }
            ],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3da6",
            "parentcaller": "0x001a3eb2",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": false,
            "return": "0xffffffffc0000138",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ServerPlugin.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x05b20000"
              },
              {
                "name": "FunctionName",
                "value": ""
              },
              {
                "name": "Ordinal",
                "value": "1"
              },
              {
                "name": "FunctionAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02af0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f8"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000f8"
              },
              {
                "name": "ValueName",
                "value": "Latest"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-04-16 19:54:37,311",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f8"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-04-16 19:54:37,327",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-04-16 19:54:37,327",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-04-16 19:54:37,327",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02af0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x0276e6a0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-04-16 19:54:37,327",
            "thread_id": "6616",
            "caller": "0x001a3924",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-04-16 19:54:37,327",
            "thread_id": "6616",
            "caller": "0x001a5e77",
            "parentcaller": "0x001a69af",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x001ab000"
              },
              {
                "name": "ModuleName",
                "value": "rundll32.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-04-16 19:54:37,327",
            "thread_id": "6616",
            "caller": "0x001a5e77",
            "parentcaller": "0x001a69af",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x001ab000"
              },
              {
                "name": "ModuleName",
                "value": "rundll32.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-04-16 19:54:37,436",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "__notification__",
            "api": "sysenter",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadIdentifier",
                "value": "6616"
              },
              {
                "name": "Module",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "Return Address",
                "value": "0x772833ec"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-04-16 19:54:38,608",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\TextShaping"
              },
              {
                "name": "DllBase",
                "value": "0x73af0000"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-04-16 19:54:39,780",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\uxtheme"
              },
              {
                "name": "DllBase",
                "value": "0x745d0000"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-04-16 19:54:39,780",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\uxtheme.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x745d0000"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-04-16 19:54:40,108",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\MSCTF"
              },
              {
                "name": "DllBase",
                "value": "0x76ba0000"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-04-16 19:54:41,452",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\kernel.appcore"
              },
              {
                "name": "DllBase",
                "value": "0x75250000"
              }
            ],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-04-16 19:54:41,468",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\bcryptPrimitives"
              },
              {
                "name": "DllBase",
                "value": "0x76d80000"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-04-16 19:55:11,546",
            "thread_id": "2680",
            "caller": "0x77e91c0e",
            "parentcaller": "0x77e8dbb1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000007c"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 1,
            "id": 92
          },
          {
            "timestamp": "2026-04-16 19:55:23,390",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\ntmarta"
              },
              {
                "name": "DllBase",
                "value": "0x74190000"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-04-16 19:55:23,405",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\CoreMessaging"
              },
              {
                "name": "DllBase",
                "value": "0x73710000"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-04-16 19:55:23,405",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\wintypes"
              },
              {
                "name": "DllBase",
                "value": "0x73630000"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-04-16 19:55:23,421",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\CoreUIComponents"
              },
              {
                "name": "DllBase",
                "value": "0x737b0000"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-04-16 19:55:23,436",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\textinputframework"
              },
              {
                "name": "DllBase",
                "value": "0x73a30000"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-04-16 19:55:24,718",
            "thread_id": "2680",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-04-16 19:55:24,718",
            "thread_id": "2680",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-04-16 19:55:24,718",
            "thread_id": "2680",
            "caller": "0x77271454",
            "parentcaller": "0x7693b5fa",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000344"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-04-16 19:55:24,718",
            "thread_id": "2680",
            "caller": "0x76938f18",
            "parentcaller": "0x76938dcd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-04-16 19:55:24,718",
            "thread_id": "1772",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-04-16 19:55:24,718",
            "thread_id": "1772",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-04-16 19:55:24,999",
            "thread_id": "6616",
            "caller": "0x001a3a40",
            "parentcaller": "0x001a3f58",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76ab0000"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-04-16 19:55:35,468",
            "thread_id": "1788",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "1788"
              }
            ],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-04-16 19:55:35,468",
            "thread_id": "1788",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-04-16 19:55:35,468",
            "thread_id": "1796",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "1796"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-04-16 19:55:35,468",
            "thread_id": "1796",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-04-16 19:56:47,890",
            "thread_id": "1772",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "1772"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-04-16 19:56:47,890",
            "thread_id": "2680",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "2680"
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-04-16 19:56:47,890",
            "thread_id": "1772",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-04-16 19:56:47,890",
            "thread_id": "2680",
            "caller": "0x7726269a",
            "parentcaller": "0x7693c192",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 112
          },
          {
            "timestamp": "2026-04-16 19:56:47,890",
            "thread_id": "2680",
            "caller": "0x7726269a",
            "parentcaller": "0x7693c214",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 113
          },
          {
            "timestamp": "2026-04-16 19:56:47,890",
            "thread_id": "2680",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 114
          }
        ],
        "threads": [
          "6616",
          "4432",
          "4524",
          "4520",
          "2680",
          "1772",
          "1788",
          "1796"
        ],
        "environ": {
          "UserName": "cape",
          "ComputerName": "DESKTOP-PC01",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Users\\cape\\AppData\\Local\\Temp\\",
          "CommandLine": "\"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll\",#1",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "7c6d-8d48",
          "SystemVolumeGUID": "c48439d1-0000-0000-0000-100000000000",
          "MachineGUID": "",
          "MainExeBase": "0x001a0000",
          "MainExeSize": "0x00014000",
          "Bitness": "32-bit",
          "DllBase": "0x05b20000"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      }
    ],
    "anomaly": [],
    "processtree": [
      {
        "name": "rundll32.exe",
        "pid": 4344,
        "parent_id": 3592,
        "module_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
        "children": [],
        "threads": [
          "6616",
          "4432",
          "4524",
          "4520",
          "2680",
          "1772",
          "1788",
          "1796"
        ],
        "environ": {
          "UserName": "cape",
          "ComputerName": "DESKTOP-PC01",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Users\\cape\\AppData\\Local\\Temp\\",
          "CommandLine": "\"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll\",#1",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "7c6d-8d48",
          "SystemVolumeGUID": "c48439d1-0000-0000-0000-100000000000",
          "MachineGUID": "",
          "MainExeBase": "0x001a0000",
          "MainExeSize": "0x00014000",
          "Bitness": "32-bit",
          "DllBase": "0x05b20000"
        }
      }
    ],
    "summary": {
      "files": [
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll.manifest",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll.123.Manifest",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll.124.Manifest",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll.2.Manifest",
        "C:\\Windows\\SysWOW64\\rundll32.exe",
        "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
      ],
      "read_files": [],
      "write_files": [],
      "delete_files": [],
      "keys": [
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\ResourcePolicies",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
      ],
      "read_keys": [
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\ResourcePolicies",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
      ],
      "write_keys": [],
      "delete_keys": [],
      "executed_commands": [],
      "resolved_apis": [],
      "mutexes": [],
      "created_services": [],
      "started_services": []
    },
    "enhanced": [
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:54:36,936",
        "eid": 1,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\ResourcePolicies",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:54:37,265",
        "eid": 2,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:54:37,280",
        "eid": 3,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:54:37,280",
        "eid": 4,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:54:37,280",
        "eid": 5,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-16 19:54:37,311",
        "eid": 6,
        "data": {
          "file": "C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll",
          "pathtofile": null,
          "moduleaddress": "0x05b20000"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-16 19:54:37,311",
        "eid": 7,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest",
          "content": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-16 19:54:39,780",
        "eid": 8,
        "data": {
          "file": "C:\\Windows\\System32\\uxtheme.dll",
          "pathtofile": null,
          "moduleaddress": "0x745d0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-16 19:55:24,999",
        "eid": 9,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76ab0000"
        }
      }
    ],
    "encryptedbuffers": [],
    "network_map": {
      "endpoint_map": {},
      "http_host_map": {},
      "dns_intents": {},
      "http_requests": [],
      "winhttp_sessions": []
    }
  },
  "debug": {
    "log": "2026-03-05 20:34:43,241 [root] INFO: Date set to: 20260416T22:53:20, timeout set to: 200\n2026-04-16 22:53:20,344 [root] DEBUG: Starting analyzer from: C:\\ltb6yatm\n2026-04-16 22:53:20,422 [root] DEBUG: Storing results at: C:\\ErkGjXZSW\n2026-04-16 22:53:20,453 [root] DEBUG: Pipe server name: \\\\.\\PIPE\\pyNDmeTCC\n2026-04-16 22:53:20,469 [root] DEBUG: Python path: C:\\Python310\n2026-04-16 22:53:20,469 [root] INFO: analysis running as an admin\n2026-04-16 22:53:20,484 [root] INFO: analysis package specified: \"dll\"\n2026-04-16 22:53:20,484 [root] DEBUG: importing analysis package module: \"modules.packages.dll\"...\n2026-04-16 22:53:20,500 [root] DEBUG: imported analysis package \"dll\"\n2026-04-16 22:53:20,500 [root] DEBUG: initializing analysis package \"dll\"...\n2026-04-16 22:53:20,500 [lib.common.common] INFO: wrapping\n2026-04-16 22:53:20,718 [lib.core.compound] INFO: C:\\Users\\cape\\AppData\\Local\\Temp already exists, skipping creation\n2026-04-16 22:53:20,734 [root] DEBUG: New location of moved file: C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll\n2026-04-16 22:53:20,734 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL option\n2026-04-16 22:53:20,734 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL_64 option\n2026-04-16 22:53:20,734 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader option\n2026-04-16 22:53:20,734 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader_64 option\n2026-04-16 22:53:20,906 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.browser\"\n2026-04-16 22:53:21,562 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.digisig\"\n2026-04-16 22:53:21,625 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.disguise\"\n2026-04-16 22:53:21,640 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.human\"\n2026-04-16 22:53:21,703 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'\n2026-04-16 22:53:21,718 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'\n2026-04-16 22:53:21,922 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'\n2026-04-16 22:53:23,453 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance\n2026-04-16 22:53:23,453 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.screenshots\"\n2026-04-16 22:53:23,469 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.tlsdump\"\n2026-04-16 22:53:23,469 [root] DEBUG: Initialized auxiliary module \"Browser\"\n2026-04-16 22:53:23,469 [root] DEBUG: attempting to configure 'Browser' from data\n2026-04-16 22:53:23,469 [root] DEBUG: module Browser does not support data configuration, ignoring\n2026-04-16 22:53:23,469 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.browser\"...\n2026-04-16 22:53:23,469 [root] DEBUG: Started auxiliary module modules.auxiliary.browser\n2026-04-16 22:53:23,469 [root] DEBUG: Initialized auxiliary module \"DigiSig\"\n2026-04-16 22:53:23,469 [root] DEBUG: attempting to configure 'DigiSig' from data\n2026-04-16 22:53:23,484 [root] DEBUG: module DigiSig does not support data configuration, ignoring\n2026-04-16 22:53:23,484 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.digisig\"...\n2026-04-16 22:53:23,484 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature\n2026-04-16 22:54:19,859 [modules.auxiliary.digisig] DEBUG: File is not signed\n2026-04-16 22:54:19,875 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json\n2026-04-16 22:54:19,875 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig\n2026-04-16 22:54:19,875 [root] DEBUG: Initialized auxiliary module \"Disguise\"\n2026-04-16 22:54:19,875 [root] DEBUG: attempting to configure 'Disguise' from data\n2026-04-16 22:54:19,890 [root] DEBUG: module Disguise does not support data configuration, ignoring\n2026-04-16 22:54:19,890 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.disguise\"...\n2026-04-16 22:54:19,953 [modules.auxiliary.disguise] INFO: Disguising GUID to 3edd1f36-5c52-4bb2-8439-a3ed6ce40e23\n2026-04-16 22:54:19,953 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise\n2026-04-16 22:54:19,969 [root] DEBUG: Initialized auxiliary module \"Human\"\n2026-04-16 22:54:19,969 [root] DEBUG: attempting to configure 'Human' from data\n2026-04-16 22:54:19,969 [root] DEBUG: module Human does not support data configuration, ignoring\n2026-04-16 22:54:19,969 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.human\"...\n2026-04-16 22:54:19,969 [root] DEBUG: Started auxiliary module modules.auxiliary.human\n2026-04-16 22:54:19,969 [root] DEBUG: Initialized auxiliary module \"Screenshots\"\n2026-04-16 22:54:19,984 [root] DEBUG: attempting to configure 'Screenshots' from data\n2026-04-16 22:54:19,984 [root] DEBUG: module Screenshots does not support data configuration, ignoring\n2026-04-16 22:54:19,984 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.screenshots\"...\n2026-04-16 22:54:20,000 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots\n2026-04-16 22:54:20,000 [root] DEBUG: Initialized auxiliary module \"TLSDumpMasterSecrets\"\n2026-04-16 22:54:20,078 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data\n2026-04-16 22:54:20,078 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring\n2026-04-16 22:54:20,078 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.tlsdump\"...\n2026-04-16 22:54:20,093 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644\n2026-04-16 22:54:20,250 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\\ltb6yatm\\dll\\644.ini\n2026-04-16 22:54:20,250 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor\n2026-04-16 22:54:20,281 [lib.api.process] INFO: 64-bit DLL to inject is C:\\ltb6yatm\\dll\\vlsdJF.dll, loader C:\\ltb6yatm\\bin\\xwjOEbSl.exe\n2026-04-16 22:54:20,609 [root] DEBUG: Loader: Injecting process 644 with C:\\ltb6yatm\\dll\\vlsdJF.dll.\n2026-04-16 22:54:21,515 [root] DEBUG: 644: Python path set to 'C:\\Python310'.\n2026-04-16 22:54:21,593 [root] DEBUG: 644: Disabling sleep skipping.\n2026-04-16 22:54:21,593 [root] DEBUG: 644: TLS secret dump mode enabled.\n2026-04-16 22:54:22,344 [root] DEBUG: 644: RtlInsertInvertedFunctionTable 0x00007FFEFE86090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEFE9BD500\n2026-04-16 22:54:22,359 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABB00000, thread 6084, image base 0x00007FF7C23E0000, stack from 0x0000008E4C9F2000-0x0000008E4CA00000\n2026-04-16 22:54:22,359 [root] DEBUG: 644: Commandline: C:\\Windows\\system32\\lsass.exe\n2026-04-16 22:54:22,406 [root] DEBUG: 644: Hooked 5 out of 5 functions\n2026-04-16 22:54:22,406 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.\n2026-04-16 22:54:22,406 [root] DEBUG: Successfully injected DLL C:\\ltb6yatm\\dll\\vlsdJF.dll.\n2026-04-16 22:54:22,406 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>\n2026-04-16 22:54:22,406 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump\n2026-04-16 22:54:22,547 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\\ErkGjXZSW\\tlsdump\\tlsdump.log\n2026-04-16 22:54:31,172 [root] INFO: Restarting WMI Service\n2026-04-16 22:54:31,281 [root] DEBUG: package modules.packages.dll does not support configure, ignoring\n2026-04-16 22:54:31,281 [root] WARNING: configuration error for package modules.packages.dll: error importing data.packages.dll: No module named 'data.packages'\n2026-04-16 22:54:31,281 [lib.core.compound] INFO: C:\\Users\\cape\\AppData\\Local\\Temp already exists, skipping creation\n2026-04-16 22:54:31,297 [lib.api.process] INFO: Successfully executed process from path \"C:\\Windows\\System32\\rundll32.exe\" with arguments \"\"C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll\",#1\" with pid 4344\n2026-04-16 22:54:31,297 [lib.api.process] INFO: Monitor config for <Process 4344 rundll32.exe>: C:\\ltb6yatm\\dll\\4344.ini\n2026-04-16 22:54:31,312 [lib.api.process] INFO: 32-bit DLL to inject is C:\\ltb6yatm\\dll\\bNmKpkjG.dll, loader C:\\ltb6yatm\\bin\\NvwgoPM.exe\n2026-04-16 22:54:31,687 [root] DEBUG: Loader: Injecting process 4344 (thread 6616) with C:\\ltb6yatm\\dll\\bNmKpkjG.dll.\n2026-04-16 22:54:31,828 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-04-16 22:54:31,843 [root] DEBUG: Successfully injected DLL C:\\ltb6yatm\\dll\\bNmKpkjG.dll.\n2026-04-16 22:54:31,843 [lib.api.process] INFO: Injected into 32-bit <Process 4344 rundll32.exe>\n2026-04-16 22:54:33,875 [lib.api.process] INFO: Successfully resumed <Process 4344 rundll32.exe>\n2026-04-16 22:54:36,203 [root] DEBUG: 4344: Python path set to 'C:\\Python310'.\n2026-04-16 22:54:36,203 [root] DEBUG: 4344: Disabling sleep skipping.\n2026-04-16 22:54:36,218 [root] DEBUG: 4344: Dropped file limit defaulting to 100.\n2026-04-16 22:54:36,484 [root] DEBUG: 4344: YaraInit: Compiled 44 rule files\n2026-04-16 22:54:36,484 [root] DEBUG: 4344: YaraInit: Compiled rules saved to file C:\\ltb6yatm\\data\\yara\\capemon.yac\n2026-04-16 22:54:36,484 [root] DEBUG: 4344: YaraScan: Scanning 0x001A0000, size 0x136e8\n2026-04-16 22:54:36,500 [root] DEBUG: 4344: Monitor initialised: 32-bit capemon loaded in process 4344 at 0x73b90000, thread 6616, image base 0x1a0000, stack from 0x2762000-0x2770000\n2026-04-16 22:54:36,500 [root] DEBUG: 4344: Commandline: \"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin.dll\",#1\n2026-04-16 22:54:36,687 [root] DEBUG: 4344: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress\n2026-04-16 22:54:36,687 [root] DEBUG: 4344: hook_api: Warning - CreateProcessA export address 0x76AE2D90 differs from GetProcAddress -> 0x73EF22A0 (AcLayers.DLL::0xfd4422a0)\n2026-04-16 22:54:36,687 [root] DEBUG: 4344: hook_api: Warning - CreateProcessW export address 0x76AC88E0 differs from GetProcAddress -> 0x73EF24E0 (AcLayers.DLL::0xfd4424e0)\n2026-04-16 22:54:36,703 [root] DEBUG: 4344: hook_api: Warning - WinExec export address 0x76B0CF20 differs from GetProcAddress -> 0x73EF27A0 (AcLayers.DLL::0xfd4427a0)\n2026-04-16 22:54:36,828 [root] WARNING: b'Unable to place hook on GetCommandLineA'\n2026-04-16 22:54:36,828 [root] DEBUG: 4344: set_hooks: Unable to hook GetCommandLineA\n2026-04-16 22:54:36,843 [root] WARNING: b'Unable to place hook on GetCommandLineW'\n2026-04-16 22:54:36,843 [root] DEBUG: 4344: set_hooks: Unable to hook GetCommandLineW\n2026-04-16 22:54:36,906 [root] DEBUG: 4344: Hooked 630 out of 632 functions\n2026-04-16 22:54:36,906 [root] DEBUG: 4344: Syscall hook installed, syscall logging level 1\n2026-04-16 22:54:36,922 [root] DEBUG: 4344: RestoreHeaders: Restored original import table.\n2026-04-16 22:54:36,922 [root] INFO: Loaded monitor into process with pid 4344\n2026-04-16 22:54:36,937 [root] DEBUG: 4344: caller_dispatch: Added region at 0x001A0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x001A5F1A, thread 6616).\n2026-04-16 22:54:36,937 [root] DEBUG: 4344: YaraScan: Scanning 0x001A0000, size 0x136e8\n2026-04-16 22:54:36,937 [root] DEBUG: 4344: ProcessImageBase: Main module image at 0x001A0000 unmodified (entropy change 0.000000e+00)\n2026-04-16 22:54:37,297 [root] DEBUG: 4344: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 6616).\n2026-04-16 22:54:37,312 [root] DEBUG: 4344: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \\Device\\HarddiskVolume1\\Windows\\SysWOW64\\kernel32.dll is in known range, skipping\n2026-04-16 22:54:37,312 [root] DEBUG: 4344: Target DLL loaded at 0x05B20000: C:\\Users\\cape\\AppData\\Local\\Temp\\ServerPlugin (0xc000 bytes).\n2026-04-16 22:54:37,312 [root] DEBUG: 4344: YaraScan: Scanning 0x05B20000, size 0x1f0\n2026-04-16 22:54:37,531 [root] DEBUG: 4344: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 6616).\n2026-04-16 22:54:37,531 [root] DEBUG: 4344: ProcessTrackedRegion: Region at 0x77150000 mapped as \\Device\\HarddiskVolume1\\Windows\\SysWOW64\\KernelBase.dll is in known range, skipping\n2026-04-16 22:54:38,610 [root] DEBUG: 4344: DLL loaded at 0x73AF0000: C:\\Windows\\SYSTEM32\\TextShaping (0x94000 bytes).\n2026-04-16 22:54:39,781 [root] DEBUG: 4344: DLL loaded at 0x745D0000: C:\\Windows\\system32\\uxtheme (0x74000 bytes).\n2026-04-16 22:54:40,109 [root] DEBUG: 4344: DLL loaded at 0x76BA0000: C:\\Windows\\System32\\MSCTF (0xd4000 bytes).\n2026-04-16 22:54:41,453 [root] DEBUG: 4344: set_hooks_by_export_directory: Hooked 0 out of 632 functions\n2026-04-16 22:54:41,468 [root] DEBUG: 4344: DLL loaded at 0x75250000: C:\\Windows\\SYSTEM32\\kernel.appcore (0xf000 bytes).\n2026-04-16 22:54:41,468 [root] DEBUG: 4344: DLL loaded at 0x76D80000: C:\\Windows\\System32\\bcryptPrimitives (0x5f000 bytes).\n2026-04-16 22:55:23,406 [root] DEBUG: 4344: DLL loaded at 0x74190000: C:\\Windows\\SYSTEM32\\ntmarta (0x29000 bytes).\n2026-04-16 22:55:23,406 [root] DEBUG: 4344: DLL loaded at 0x73710000: C:\\Windows\\System32\\CoreMessaging (0x9b000 bytes).\n2026-04-16 22:55:23,422 [root] DEBUG: 4344: DLL loaded at 0x73630000: C:\\Windows\\SYSTEM32\\wintypes (0xdb000 bytes).\n2026-04-16 22:55:23,437 [root] DEBUG: 4344: DLL loaded at 0x737B0000: C:\\Windows\\System32\\CoreUIComponents (0x27e000 bytes).\n2026-04-16 22:55:23,437 [root] DEBUG: 4344: DLL loaded at 0x73A30000: C:\\Windows\\SYSTEM32\\textinputframework (0xb9000 bytes).\n2026-04-16 22:57:54,825 [root] INFO: Analysis timeout hit, terminating analysis\n2026-04-16 22:57:54,825 [lib.api.process] INFO: Terminate event set for <Process 4344 rundll32.exe>\n2026-04-16 22:57:54,825 [root] DEBUG: 4344: Terminate Event: Attempting to dump process 4344\n2026-04-16 22:57:54,825 [root] DEBUG: 4344: VerifyCodeSection: Executable code does not match, 0x3d42 of 0x3d43 matching\n2026-04-16 22:57:54,841 [root] DEBUG: 4344: DoProcessDump: Code modification detected, dumping Imagebase at 0x05B20000.\n2026-04-16 22:57:54,841 [root] DEBUG: 4344: DumpImageInCurrentProcess: Attempting to dump virtual PE image.\n2026-04-16 22:57:54,841 [root] DEBUG: 4344: DumpProcess: Instantiating PeParser with address: 0x05B20000.\n2026-04-16 22:57:54,856 [root] DEBUG: 4344: DumpProcess: Module entry point VA is 0x05B25D3E.\n2026-04-16 22:57:54,856 [root] DEBUG: 4344: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x05B26000, section 2\n2026-04-16 22:57:54,872 [root] DEBUG: 4344: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x05B2A000, section 3\n2026-04-16 22:57:55,200 [lib.common.results] INFO: Uploading file C:\\ErkGjXZSW\\CAPE\\4344_820055571916442026 to procdump\\c2800550f928a910a9337cd2013e97a03b2da584b8522843804197fc2aa23634; Size is 16896; Max size: 100000000\n2026-04-16 22:57:55,200 [root] DEBUG: 4344: DumpProcess: Module image dump success - dump size 0x4200.\n2026-04-16 22:57:55,215 [lib.api.process] INFO: Termination confirmed for <Process 4344 rundll32.exe>\n2026-04-16 22:57:55,215 [root] INFO: Terminate event set for process 4344\n2026-04-16 22:57:55,215 [root] INFO: Created shutdown mutex\n2026-04-16 22:57:55,215 [root] DEBUG: 4344: Terminate Event: monitor shutdown complete for process 4344\n2026-04-16 22:57:56,231 [root] INFO: Shutting down package\n2026-04-16 22:57:56,231 [root] INFO: Stopping auxiliary modules\n2026-04-16 22:57:56,231 [root] INFO: Stopping auxiliary module: Browser\n2026-04-16 22:57:56,231 [root] INFO: Stopping auxiliary module: Human\n2026-04-16 22:57:58,090 [root] INFO: Stopping auxiliary module: Screenshots\n2026-04-16 22:57:58,872 [root] INFO: Finishing auxiliary modules\n2026-04-16 22:57:58,872 [root] INFO: Shutting down pipe server and dumping dropped files\n2026-04-16 22:57:58,872 [root] WARNING: Folder at path \"C:\\ErkGjXZSW\\debugger\" does not exist, skipping\n2026-04-16 22:57:58,872 [root] INFO: Uploading files at path \"C:\\ErkGjXZSW\\tlsdump\"\n2026-04-16 22:57:58,887 [lib.common.results] INFO: Uploading file C:\\ErkGjXZSW\\tlsdump\\tlsdump.log to tlsdump\\tlsdump.log; Size is 18358; Max size: 100000000\n2026-04-16 22:57:58,903 [root] INFO: Analysis completed\n",
    "errors": []
  },
  "network": {
    "pcap_sha256": "999f1c17e6b8612d919a0e01f85690a8726fe2cc67b29de54bb6a3ef13abe7c3",
    "hosts": [
      {
        "ip": "188.43.72.25",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.93.72.182",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "46.149.110.67",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          80
        ]
      },
      {
        "ip": "135.232.92.34",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.16",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.108",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.100",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.105",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.102",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.98",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.107",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.101",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.109",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.165.94.54",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "150.171.109.51",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "13.107.6.156",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "84.47.178.41",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "150.171.27.11",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "173.194.73.94",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "i.pki.goog",
        "inaddrarpa": "",
        "ports": [
          80
        ]
      },
      {
        "ip": "84.47.178.49",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "52.123.242.97",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "40.126.53.14",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.42.65.93",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "4.207.247.139",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "84.47.178.56",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.189.173.2",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      }
    ],
    "domains": [
      {
        "domain": "i.pki.goog",
        "ip": "216.58.201.227"
      },
      {
        "domain": "dns.google",
        "ip": "8.8.4.4"
      }
    ],
    "tcp": [
      {
        "src": "192.168.1.100",
        "sport": 49723,
        "dst": "20.189.173.2",
        "dport": 443,
        "offset": 24,
        "time": 0.0
      },
      {
        "src": "192.168.1.100",
        "sport": 49724,
        "dst": "20.189.173.2",
        "dport": 443,
        "offset": 95,
        "time": 0.9218969345092773
      },
      {
        "src": "192.168.1.100",
        "sport": 49718,
        "dst": "84.47.178.56",
        "dport": 443,
        "offset": 236,
        "time": 4.827488899230957
      },
      {
        "src": "192.168.1.100",
        "sport": 49806,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 752,
        "time": 5.249616861343384
      },
      {
        "src": "192.168.1.100",
        "sport": 49784,
        "dst": "40.126.53.14",
        "dport": 443,
        "offset": 8879,
        "time": 9.09975290298462
      },
      {
        "src": "192.168.1.100",
        "sport": 49810,
        "dst": "52.123.129.14",
        "dport": 443,
        "offset": 31523,
        "time": 9.735204935073853
      },
      {
        "src": "192.168.1.100",
        "sport": 49813,
        "dst": "84.47.178.49",
        "dport": 443,
        "offset": 53379,
        "time": 9.975008964538574
      },
      {
        "src": "192.168.1.100",
        "sport": 49814,
        "dst": "194.158.198.23",
        "dport": 80,
        "offset": 303222,
        "time": 10.647841930389404
      },
      {
        "src": "192.168.1.100",
        "sport": 49815,
        "dst": "40.126.53.14",
        "dport": 443,
        "offset": 304461,
        "time": 10.687643051147461
      },
      {
        "src": "192.168.1.100",
        "sport": 49817,
        "dst": "23.11.40.157",
        "dport": 80,
        "offset": 311524,
        "time": 11.080904960632324
      },
      {
        "src": "192.168.1.100",
        "sport": 49819,
        "dst": "40.126.53.14",
        "dport": 443,
        "offset": 313018,
        "time": 11.155070066452026
      },
      {
        "src": "192.168.1.100",
        "sport": 49822,
        "dst": "8.8.8.8",
        "dport": 443,
        "offset": 323653,
        "time": 11.412719964981079
      },
      {
        "src": "192.168.1.100",
        "sport": 49820,
        "dst": "23.11.40.157",
        "dport": 80,
        "offset": 326099,
        "time": 11.42589807510376
      },
      {
        "src": "192.168.1.100",
        "sport": 49825,
        "dst": "8.8.8.8",
        "dport": 443,
        "offset": 375881,
        "time": 11.718791961669922
      },
      {
        "src": "192.168.1.100",
        "sport": 49826,
        "dst": "173.194.73.94",
        "dport": 80,
        "offset": 389899,
        "time": 11.725558042526245
      },
      {
        "src": "192.168.1.100",
        "sport": 49728,
        "dst": "150.171.27.11",
        "dport": 443,
        "offset": 431565,
        "time": 12.079355955123901
      },
      {
        "src": "192.168.1.100",
        "sport": 49829,
        "dst": "150.171.27.11",
        "dport": 443,
        "offset": 434174,
        "time": 12.121839046478271
      },
      {
        "src": "192.168.1.100",
        "sport": 49831,
        "dst": "40.119.249.228",
        "dport": 443,
        "offset": 478064,
        "time": 12.7450430393219
      },
      {
        "src": "192.168.1.100",
        "sport": 49833,
        "dst": "20.42.65.93",
        "dport": 443,
        "offset": 626107,
        "time": 13.529000997543335
      },
      {
        "src": "192.168.1.100",
        "sport": 49710,
        "dst": "84.47.178.41",
        "dport": 443,
        "offset": 648522,
        "time": 39.71566700935364
      },
      {
        "src": "192.168.1.100",
        "sport": 49716,
        "dst": "84.47.178.56",
        "dport": 443,
        "offset": 648663,
        "time": 39.79383587837219
      },
      {
        "src": "192.168.1.100",
        "sport": 49720,
        "dst": "8.8.4.4",
        "dport": 443,
        "offset": 648945,
        "time": 40.98124098777771
      },
      {
        "src": "192.168.1.100",
        "sport": 49708,
        "dst": "13.107.6.156",
        "dport": 443,
        "offset": 649086,
        "time": 41.01237392425537
      },
      {
        "src": "192.168.1.100",
        "sport": 49712,
        "dst": "84.47.178.41",
        "dport": 443,
        "offset": 649227,
        "time": 42.21572399139404
      },
      {
        "src": "192.168.1.100",
        "sport": 49824,
        "dst": "173.194.73.94",
        "dport": 80,
        "offset": 650026,
        "time": 57.51117205619812
      },
      {
        "src": "150.171.109.51",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49919,
        "offset": 650179,
        "time": 59.818625926971436
      },
      {
        "src": "192.168.1.100",
        "sport": 49838,
        "dst": "20.44.239.154",
        "dport": 443,
        "offset": 676926,
        "time": 68.12752985954285
      },
      {
        "src": "192.168.1.100",
        "sport": 49840,
        "dst": "74.179.77.204",
        "dport": 443,
        "offset": 1044864,
        "time": 68.6112630367279
      },
      {
        "src": "192.168.1.100",
        "sport": 49843,
        "dst": "199.232.210.172",
        "dport": 80,
        "offset": 1058316,
        "time": 69.00246500968933
      },
      {
        "src": "192.168.1.100",
        "sport": 49845,
        "dst": "74.179.77.204",
        "dport": 443,
        "offset": 1083773,
        "time": 69.28339505195618
      },
      {
        "src": "192.168.1.100",
        "sport": 49848,
        "dst": "20.165.94.54",
        "dport": 443,
        "offset": 1119611,
        "time": 70.33142495155334
      },
      {
        "src": "192.168.1.100",
        "sport": 49849,
        "dst": "74.179.77.204",
        "dport": 443,
        "offset": 1120592,
        "time": 70.45524501800537
      },
      {
        "src": "192.168.1.100",
        "sport": 49851,
        "dst": "20.190.147.3",
        "dport": 443,
        "offset": 1133266,
        "time": 70.67621302604675
      },
      {
        "src": "192.168.1.100",
        "sport": 49853,
        "dst": "74.179.77.204",
        "dport": 443,
        "offset": 1496425,
        "time": 71.2370228767395
      },
      {
        "src": "192.168.1.100",
        "sport": 49855,
        "dst": "40.119.249.228",
        "dport": 443,
        "offset": 1524485,
        "time": 71.7066900730133
      },
      {
        "src": "192.168.1.100",
        "sport": 49858,
        "dst": "204.79.197.203",
        "dport": 80,
        "offset": 1533797,
        "time": 72.11843085289001
      },
      {
        "src": "192.168.1.100",
        "sport": 49860,
        "dst": "40.119.249.228",
        "dport": 443,
        "offset": 1544377,
        "time": 72.53807306289673
      },
      {
        "src": "192.168.1.100",
        "sport": 49864,
        "dst": "128.251.127.23",
        "dport": 443,
        "offset": 1589703,
        "time": 73.89589595794678
      },
      {
        "src": "192.168.1.100",
        "sport": 49865,
        "dst": "8.8.8.8",
        "dport": 443,
        "offset": 1618327,
        "time": 74.65166807174683
      },
      {
        "src": "192.168.1.100",
        "sport": 49867,
        "dst": "194.158.198.23",
        "dport": 80,
        "offset": 1635504,
        "time": 74.7672529220581
      },
      {
        "src": "192.168.1.100",
        "sport": 49870,
        "dst": "52.137.106.217",
        "dport": 443,
        "offset": 1667468,
        "time": 76.05946707725525
      },
      {
        "src": "192.168.1.100",
        "sport": 49873,
        "dst": "128.75.237.184",
        "dport": 443,
        "offset": 1691401,
        "time": 76.8688690662384
      },
      {
        "src": "192.168.1.100",
        "sport": 49876,
        "dst": "52.137.106.217",
        "dport": 443,
        "offset": 1838589,
        "time": 78.81822299957275
      },
      {
        "src": "192.168.1.100",
        "sport": 49879,
        "dst": "52.123.129.14",
        "dport": 443,
        "offset": 1851857,
        "time": 79.39921593666077
      },
      {
        "src": "192.168.1.100",
        "sport": 49884,
        "dst": "23.46.118.69",
        "dport": 443,
        "offset": 2005664,
        "time": 82.42851495742798
      },
      {
        "src": "192.168.1.100",
        "sport": 49887,
        "dst": "52.137.106.217",
        "dport": 443,
        "offset": 2029390,
        "time": 84.53864192962646
      },
      {
        "src": "192.168.1.100",
        "sport": 49888,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 2039654,
        "time": 85.77991986274719
      },
      {
        "src": "4.207.247.139",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49881,
        "offset": 2063440,
        "time": 86.07203102111816
      },
      {
        "src": "192.168.1.100",
        "sport": 49894,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 2076605,
        "time": 89.64507794380188
      },
      {
        "src": "135.232.92.34",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49913,
        "offset": 2089110,
        "time": 91.89183306694031
      },
      {
        "src": "192.168.1.100",
        "sport": 49898,
        "dst": "23.11.40.157",
        "dport": 80,
        "offset": 2691487,
        "time": 93.62132787704468
      },
      {
        "src": "192.168.1.100",
        "sport": 49901,
        "dst": "23.11.40.157",
        "dport": 80,
        "offset": 110466922,
        "time": 132.45046305656433
      },
      {
        "src": "192.168.1.100",
        "sport": 49904,
        "dst": "23.11.40.157",
        "dport": 80,
        "offset": 110477551,
        "time": 134.1823239326477
      },
      {
        "src": "192.168.1.100",
        "sport": 49910,
        "dst": "48.199.12.1",
        "dport": 443,
        "offset": 111200275,
        "time": 143.87451887130737
      },
      {
        "src": "192.168.1.100",
        "sport": 49913,
        "dst": "74.178.76.44",
        "dport": 443,
        "offset": 112153299,
        "time": 149.18714690208435
      },
      {
        "src": "192.168.1.100",
        "sport": 49915,
        "dst": "51.11.168.232",
        "dport": 443,
        "offset": 112490926,
        "time": 151.51097893714905
      },
      {
        "src": "192.168.1.100",
        "sport": 49917,
        "dst": "46.149.110.67",
        "dport": 80,
        "offset": 112510170,
        "time": 151.7876980304718
      },
      {
        "src": "192.168.1.100",
        "sport": 49919,
        "dst": "46.149.110.67",
        "dport": 80,
        "offset": 112514110,
        "time": 152.1112859249115
      },
      {
        "src": "192.168.1.100",
        "sport": 49920,
        "dst": "46.149.110.67",
        "dport": 80,
        "offset": 112520643,
        "time": 152.24245595932007
      },
      {
        "src": "192.168.1.100",
        "sport": 49922,
        "dst": "72.154.7.110",
        "dport": 443,
        "offset": 114354175,
        "time": 153.72931694984436
      },
      {
        "src": "192.168.1.100",
        "sport": 49923,
        "dst": "72.154.7.107",
        "dport": 443,
        "offset": 114354467,
        "time": 153.73002195358276
      },
      {
        "src": "192.168.1.100",
        "sport": 49925,
        "dst": "72.154.7.106",
        "dport": 443,
        "offset": 114355355,
        "time": 153.7529900074005
      },
      {
        "src": "192.168.1.100",
        "sport": 49927,
        "dst": "23.197.162.102",
        "dport": 80,
        "offset": 114377405,
        "time": 154.25523900985718
      },
      {
        "src": "192.168.1.100",
        "sport": 49929,
        "dst": "23.197.162.102",
        "dport": 80,
        "offset": 114397909,
        "time": 154.76370096206665
      },
      {
        "src": "192.168.1.100",
        "sport": 49931,
        "dst": "2.23.90.38",
        "dport": 443,
        "offset": 114403100,
        "time": 155.03345799446106
      },
      {
        "src": "192.168.1.100",
        "sport": 49933,
        "dst": "52.185.211.133",
        "dport": 443,
        "offset": 114435582,
        "time": 155.76171708106995
      },
      {
        "src": "192.168.1.100",
        "sport": 49936,
        "dst": "20.190.147.3",
        "dport": 443,
        "offset": 114740927,
        "time": 170.57343292236328
      },
      {
        "src": "8.8.8.8",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49862,
        "offset": 114879185,
        "time": 186.1306459903717
      },
      {
        "src": "192.168.1.100",
        "sport": 49940,
        "dst": "128.75.237.184",
        "dport": 443,
        "offset": 115257030,
        "time": 198.20346784591675
      },
      {
        "src": "192.168.1.100",
        "sport": 49942,
        "dst": "2.23.90.148",
        "dport": 443,
        "offset": 115696579,
        "time": 200.01242589950562
      },
      {
        "src": "192.168.1.100",
        "sport": 49944,
        "dst": "199.232.210.172",
        "dport": 80,
        "offset": 115993516,
        "time": 210.1600968837738
      },
      {
        "src": "192.168.1.100",
        "sport": 49945,
        "dst": "52.123.243.117",
        "dport": 443,
        "offset": 116441147,
        "time": 233.07751297950745
      },
      {
        "src": "192.168.1.100",
        "sport": 49947,
        "dst": "13.89.179.10",
        "dport": 443,
        "offset": 116467969,
        "time": 242.10830307006836
      },
      {
        "src": "188.43.72.25",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49942,
        "offset": 116493094,
        "time": 259.637179851532
      }
    ],
    "udp": [
      {
        "src": "192.168.1.100",
        "sport": 52659,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 51482,
        "time": 9.922343015670776
      },
      {
        "src": "192.168.1.100",
        "sport": 64351,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 310447,
        "time": 10.950783014297485
      },
      {
        "src": "192.168.1.100",
        "sport": 59720,
        "dst": "8.8.8.8",
        "dport": 443,
        "offset": 318777,
        "time": 11.360283851623535
      },
      {
        "src": "192.168.1.100",
        "sport": 55932,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 335796,
        "time": 11.446083068847656
      },
      {
        "src": "192.168.1.100",
        "sport": 53697,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 428445,
        "time": 11.961246013641357
      },
      {
        "src": "192.168.1.100",
        "sport": 63870,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 498194,
        "time": 13.009068965911865
      },
      {
        "src": "192.168.1.100",
        "sport": 138,
        "dst": "192.168.1.255",
        "dport": 138,
        "offset": 648263,
        "time": 31.664785861968994
      },
      {
        "src": "192.168.1.100",
        "sport": 61050,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 656816,
        "time": 67.89764595031738
      },
      {
        "src": "192.168.1.100",
        "sport": 61691,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 682035,
        "time": 68.40072798728943
      },
      {
        "src": "192.168.1.100",
        "sport": 63059,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1057004,
        "time": 68.92775297164917
      },
      {
        "src": "192.168.1.100",
        "sport": 53933,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1120335,
        "time": 70.45028805732727
      },
      {
        "src": "192.168.1.100",
        "sport": 58400,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1447536,
        "time": 71.00862097740173
      },
      {
        "src": "192.168.1.100",
        "sport": 60042,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1525349,
        "time": 71.86950087547302
      },
      {
        "src": "192.168.1.100",
        "sport": 50445,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1617419,
        "time": 74.61173987388611
      },
      {
        "src": "192.168.1.100",
        "sport": 56095,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1665903,
        "time": 75.85364389419556
      },
      {
        "src": "192.168.1.100",
        "sport": 61474,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1687294,
        "time": 76.66144800186157
      },
      {
        "src": "192.168.1.100",
        "sport": 58657,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1999427,
        "time": 82.08114004135132
      },
      {
        "src": "192.168.1.100",
        "sport": 58275,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2064111,
        "time": 86.73164701461792
      },
      {
        "src": "192.168.1.100",
        "sport": 53441,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2096969,
        "time": 93.51445984840393
      },
      {
        "src": "192.168.1.100",
        "sport": 57174,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 110469905,
        "time": 133.44738793373108
      },
      {
        "src": "192.168.1.100",
        "sport": 54709,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 110476906,
        "time": 134.0530309677124
      },
      {
        "src": "192.168.1.100",
        "sport": 50392,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 112143412,
        "time": 146.58321690559387
      },
      {
        "src": "192.168.1.100",
        "sport": 55480,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 112477783,
        "time": 151.0449550151825
      },
      {
        "src": "192.168.1.100",
        "sport": 61543,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 112489729,
        "time": 151.43548393249512
      },
      {
        "src": "192.168.1.100",
        "sport": 54953,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 112491212,
        "time": 151.54958701133728
      },
      {
        "src": "192.168.1.100",
        "sport": 51001,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 112512550,
        "time": 151.92631602287292
      },
      {
        "src": "192.168.1.100",
        "sport": 61615,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 114352100,
        "time": 153.52108788490295
      },
      {
        "src": "192.168.1.100",
        "sport": 58013,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 114352689,
        "time": 153.54754900932312
      },
      {
        "src": "192.168.1.100",
        "sport": 56856,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 114371999,
        "time": 154.1818768978119
      },
      {
        "src": "192.168.1.100",
        "sport": 57362,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 114384899,
        "time": 154.54138493537903
      },
      {
        "src": "192.168.1.100",
        "sport": 54887,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 114442250,
        "time": 159.47692584991455
      },
      {
        "src": "192.168.1.100",
        "sport": 54360,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 114751380,
        "time": 170.7596218585968
      },
      {
        "src": "192.168.1.100",
        "sport": 50488,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 115694743,
        "time": 199.40383291244507
      },
      {
        "src": "192.168.1.100",
        "sport": 57039,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 115703246,
        "time": 200.10763001441956
      },
      {
        "src": "192.168.1.100",
        "sport": 52458,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 116439405,
        "time": 232.9733898639679
      },
      {
        "src": "192.168.1.100",
        "sport": 60508,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 116467385,
        "time": 241.93557500839233
      },
      {
        "src": "192.168.1.100",
        "sport": 50286,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 116493615,
        "time": 261.4332070350647
      }
    ],
    "icmp": [
      {
        "src": "192.168.1.100",
        "dst": "8.8.8.8",
        "type": 3,
        "data": ""
      },
      {
        "src": "192.168.1.100",
        "dst": "8.8.4.4",
        "type": 3,
        "data": ""
      },
      {
        "src": "192.168.1.100",
        "dst": "8.8.8.8",
        "type": 3,
        "data": ""
      },
      {
        "src": "192.168.1.100",
        "dst": "8.8.4.4",
        "type": 3,
        "data": ""
      }
    ],
    "http": [
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /gsr1.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/gsr1.crt",
        "body": "",
        "path": "/gsr1.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776380012.511223
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /r4.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/r4.crt",
        "body": "",
        "path": "/r4.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776380012.539753
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /we2.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/we2.crt",
        "body": "",
        "path": "/we2.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776380012.564561
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /gsr4.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/gsr4.crt",
        "body": "",
        "path": "/gsr4.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776380012.593511
      },
      {
        "count": 1,
        "host": "46.149.110.67",
        "port": 80,
        "data": "GET /filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Microsoft-Delivery-Optimization/10.0\r\nMS-CV: hQvm4s4odU6T1XyD1PAeog.0.2.3.1.1\r\nContent-Length: 0\r\nHost: 46.149.110.67\r\n\r\n",
        "uri": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com",
        "body": "",
        "path": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com",
        "user-agent": "Microsoft-Delivery-Optimization/10.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776380152.573363
      },
      {
        "count": 1,
        "host": "46.149.110.67",
        "port": 80,
        "data": "GET /filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nRange: bytes=0-1\r\nUser-Agent: Microsoft-Delivery-Optimization/10.0\r\nMS-CV: hQvm4s4odU6T1XyD1PAeog.0.2.6.1.1.1\r\nContent-Length: 0\r\nHost: 46.149.110.67\r\n\r\n",
        "uri": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "body": "",
        "path": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "user-agent": "Microsoft-Delivery-Optimization/10.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776380152.896951
      },
      {
        "count": 1,
        "host": "46.149.110.67",
        "port": 80,
        "data": "GET /filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nRange: bytes=1048576-1697335\r\nUser-Agent: Microsoft-Delivery-Optimization/10.0\r\nMS-CV: hQvm4s4odU6T1XyD1PAeog.0.2.6.1.1.2\r\nContent-Length: 0\r\nHost: 46.149.110.67\r\n\r\n",
        "uri": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "body": "",
        "path": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "user-agent": "Microsoft-Delivery-Optimization/10.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776380152.979535
      },
      {
        "count": 1,
        "host": "46.149.110.67",
        "port": 80,
        "data": "GET /filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nRange: bytes=0-1048575\r\nUser-Agent: Microsoft-Delivery-Optimization/10.0\r\nMS-CV: hQvm4s4odU6T1XyD1PAeog.0.2.6.1.1.3\r\nContent-Length: 0\r\nHost: 46.149.110.67\r\n\r\n",
        "uri": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "body": "",
        "path": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "user-agent": "Microsoft-Delivery-Optimization/10.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1776380153.028121
      }
    ],
    "dns": [
      {
        "request": "i.pki.goog",
        "type": "A",
        "answers": [
          {
            "type": "A",
            "data": "173.194.73.94"
          },
          {
            "type": "CNAME",
            "data": "pki-goog.l.google.com"
          }
        ],
        "first_seen": 1776380012.232004
      },
      {
        "request": "dns.google",
        "type": "A",
        "answers": [
          {
            "type": "A",
            "data": "8.8.8.8"
          },
          {
            "type": "A",
            "data": "8.8.4.4"
          }
        ],
        "first_seen": 1776380075.397691
      }
    ],
    "smtp": [],
    "irc": [],
    "dead_hosts": [
      [
        "52.123.242.97",
        443
      ],
      [
        "150.171.109.51",
        443
      ],
      [
        "72.154.7.109",
        443
      ],
      [
        "72.154.7.98",
        443
      ],
      [
        "72.154.7.101",
        443
      ],
      [
        "72.154.7.102",
        443
      ],
      [
        "72.154.7.105",
        443
      ],
      [
        "72.154.7.100",
        443
      ],
      [
        "72.154.7.108",
        443
      ],
      [
        "72.154.7.16",
        443
      ]
    ]
  },
  "suricata": {
    "alerts": [],
    "tls": [
      {
        "srcport": 49822,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-16 22:53:32.220485+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "87c36e0efdb847c153954b9f4778e764",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,45-13-43-51-23-0-65037-65281-5-27-10-11-35-18-16-17613,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      },
      {
        "srcport": 49825,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-16 22:53:32.519706+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "eca10cbdddc3be37612b1d322437c105",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,51-23-5-45-27-65281-0-35-16-65037-43-10-17613-13-18-11,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      },
      {
        "srcport": 49865,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-16 22:54:35.459531+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "00cf290bd02b8f31a70af6a46e70e981",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,18-10-16-17613-11-65037-13-0-51-5-27-43-45-23-35-65281,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      }
    ],
    "perf": [],
    "files": [],
    "http": [
      {
        "srcport": 49826,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:53:32.532571+0000",
        "uri": "/gsr1.crt",
        "length": 797,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49826,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:53:32.564561+0000",
        "uri": "/r4.crt",
        "length": 455,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49826,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:53:32.593511+0000",
        "uri": "/we2.crt",
        "length": 582,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49826,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:53:32.626161+0000",
        "uri": "/gsr4.crt",
        "length": 480,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49826,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:53:32.647504+0000",
        "uri": "/gsr1.crt",
        "length": 797,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49826,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:53:32.676190+0000",
        "uri": "/r4.crt",
        "length": 455,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49826,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:53:32.708259+0000",
        "uri": "/we2.crt",
        "length": 582,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49826,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "173.194.73.94",
        "timestamp": "2026-04-16 22:53:32.784457+0000",
        "uri": "/gsr4.crt",
        "length": 480,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49917,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "46.149.110.67",
        "timestamp": "2026-04-16 22:55:52.661085+0000",
        "uri": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com",
        "length": 246,
        "hostname": "46.149.110.67",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/octet-stream",
        "ua": "Microsoft-Delivery-Optimization/10.0",
        "referrer": null
      },
      {
        "srcport": 49919,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "46.149.110.67",
        "timestamp": "2026-04-16 22:55:52.979535+0000",
        "uri": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "length": 2,
        "hostname": "46.149.110.67",
        "status": 206,
        "http_method": "GET",
        "contenttype": "application/octet-stream",
        "ua": "Microsoft-Delivery-Optimization/10.0",
        "referrer": null
      },
      {
        "srcport": 49919,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "46.149.110.67",
        "timestamp": "2026-04-16 22:55:54.285732+0000",
        "uri": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "length": 648760,
        "hostname": "46.149.110.67",
        "status": 206,
        "http_method": "GET",
        "contenttype": "application/octet-stream",
        "ua": "Microsoft-Delivery-Optimization/10.0",
        "referrer": null
      },
      {
        "srcport": 49920,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "46.149.110.67",
        "timestamp": "2026-04-16 22:55:54.316869+0000",
        "uri": "/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "length": 1048576,
        "hostname": "46.149.110.67",
        "status": 206,
        "http_method": "GET",
        "contenttype": "application/octet-stream",
        "ua": "Microsoft-Delivery-Optimization/10.0",
        "referrer": null
      }
    ],
    "dns": [
      {
        "timestamp": "2026-04-16T22:53:32.232004+0000",
        "flow_id": 1277928462902438,
        "pcap_cnt": 473,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 59378,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "query",
          "id": 51226,
          "rrname": "i.pki.goog",
          "rrtype": "A",
          "tx_id": 0,
          "opcode": 0
        }
      },
      {
        "timestamp": "2026-04-16T22:53:32.231748+0000",
        "flow_id": 1276825904406826,
        "pcap_cnt": 472,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 55932,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "query",
          "id": 30694,
          "rrname": "i.pki.goog",
          "rrtype": "HTTPS",
          "tx_id": 0,
          "opcode": 0
        }
      },
      {
        "timestamp": "2026-04-16T22:53:32.253935+0000",
        "flow_id": 1277928462902438,
        "pcap_cnt": 483,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 59378,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "answer",
          "id": 51226,
          "flags": "8180",
          "qr": true,
          "rd": true,
          "ra": true,
          "opcode": 0,
          "rrname": "i.pki.goog",
          "rrtype": "A",
          "rcode": "NOERROR",
          "answers": [
            {
              "rrname": "i.pki.goog",
              "rrtype": "CNAME",
              "ttl": 272,
              "rdata": "pki-goog.l.google.com"
            },
            {
              "rrname": "pki-goog.l.google.com",
              "rrtype": "A",
              "ttl": 300,
              "rdata": "173.194.73.94"
            }
          ],
          "grouped": {
            "CNAME": [
              "pki-goog.l.google.com"
            ],
            "A": [
              "173.194.73.94"
            ]
          }
        }
      },
      {
        "timestamp": "2026-04-16T22:53:32.253812+0000",
        "flow_id": 1276825904406826,
        "pcap_cnt": 482,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 55932,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "answer",
          "id": 30694,
          "flags": "8180",
          "qr": true,
          "rd": true,
          "ra": true,
          "opcode": 0,
          "rrname": "i.pki.goog",
          "rrtype": "HTTPS",
          "rcode": "NOERROR",
          "answers": [
            {
              "rrname": "i.pki.goog",
              "rrtype": "CNAME",
              "ttl": 112,
              "rdata": "pki-goog.l.google.com"
            }
          ],
          "grouped": {
            "CNAME": [
              "pki-goog.l.google.com"
            ]
          },
          "authorities": [
            {
              "rrname": "l.google.com",
              "rrtype": "SOA",
              "ttl": 60,
              "soa": {
                "mname": "ns1.google.com",
                "rname": "dns-admin.google.com",
                "serial": 900627266,
                "refresh": 900,
                "retry": 900,
                "expire": 1800,
                "minimum": 60
              }
            }
          ]
        }
      },
      {
        "timestamp": "2026-04-16T22:54:35.397691+0000",
        "flow_id": 863646471516391,
        "pcap_cnt": 2298,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 57742,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "query",
          "id": 14919,
          "rrname": "dns.google",
          "rrtype": "A",
          "tx_id": 0,
          "opcode": 0
        }
      },
      {
        "timestamp": "2026-04-16T22:54:35.414635+0000",
        "flow_id": 863646471516391,
        "pcap_cnt": 2302,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 57742,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "answer",
          "id": 14919,
          "flags": "8180",
          "qr": true,
          "rd": true,
          "ra": true,
          "opcode": 0,
          "rrname": "dns.google",
          "rrtype": "A",
          "rcode": "NOERROR",
          "answers": [
            {
              "rrname": "dns.google",
              "rrtype": "A",
              "ttl": 852,
              "rdata": "8.8.8.8"
            },
            {
              "rrname": "dns.google",
              "rrtype": "A",
              "ttl": 852,
              "rdata": "8.8.4.4"
            }
          ],
          "grouped": {
            "A": [
              "8.8.8.8",
              "8.8.4.4"
            ]
          }
        }
      },
      {
        "timestamp": "2026-04-16T22:54:35.397405+0000",
        "flow_id": 862419785925285,
        "pcap_cnt": 2297,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 50445,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "query",
          "id": 17646,
          "rrname": "dns.google",
          "rrtype": "HTTPS",
          "tx_id": 0,
          "opcode": 0
        }
      },
      {
        "timestamp": "2026-04-16T22:54:35.414311+0000",
        "flow_id": 862419785925285,
        "pcap_cnt": 2301,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 50445,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "answer",
          "id": 17646,
          "flags": "8180",
          "qr": true,
          "rd": true,
          "ra": true,
          "opcode": 0,
          "rrname": "dns.google",
          "rrtype": "HTTPS",
          "rcode": "NOERROR",
          "authorities": [
            {
              "rrname": "dns.google",
              "rrtype": "SOA",
              "ttl": 178,
              "soa": {
                "mname": "ns1.zdns.google",
                "rname": "cloud-dns-hostmaster.google.com",
                "serial": 1,
                "refresh": 21600,
                "retry": 3600,
                "expire": 259200,
                "minimum": 300
              }
            }
          ]
        }
      }
    ],
    "ssh": [],
    "fileinfo": [],
    "eve_log_full_path": "/opt/CAPEv2/storage/analyses/41/logs/eve.json",
    "alert_log_full_path": null,
    "tls_log_full_path": null,
    "http_log_full_path": null,
    "file_log_full_path": null,
    "ssh_log_full_path": null,
    "dns_log_full_path": null
  },
  "url_analysis": {},
  "procmemory": [],
  "signatures": [
    {
      "name": "stealth_network",
      "description": "Network activity detected but not expressed in monitor API logs",
      "categories": [
        "stealth"
      ],
      "severity": 1,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "ip": "188.43.72.25"
        },
        {
          "ip": "20.93.72.182"
        },
        {
          "ip": "46.149.110.67"
        },
        {
          "ip": "135.232.92.34"
        },
        {
          "ip": "72.154.7.16"
        },
        {
          "ip": "72.154.7.108"
        },
        {
          "ip": "72.154.7.100"
        },
        {
          "ip": "72.154.7.105"
        },
        {
          "ip": "72.154.7.102"
        },
        {
          "ip": "72.154.7.98"
        },
        {
          "ip": "72.154.7.107"
        },
        {
          "ip": "72.154.7.101"
        },
        {
          "ip": "72.154.7.109"
        },
        {
          "ip": "20.165.94.54"
        },
        {
          "ip": "150.171.109.51"
        },
        {
          "ip": "13.107.6.156"
        },
        {
          "ip": "84.47.178.41"
        },
        {
          "ip": "150.171.27.11"
        },
        {
          "ip": "173.194.73.94"
        },
        {
          "ip": "84.47.178.49"
        },
        {
          "ip": "52.123.242.97"
        },
        {
          "ip": "40.126.53.14"
        },
        {
          "ip": "20.42.65.93"
        },
        {
          "ip": "4.207.247.139"
        },
        {
          "ip": "84.47.178.56"
        },
        {
          "ip": "20.189.173.2"
        },
        {
          "domain": "i.pki.goog"
        },
        {
          "domain": "dns.google"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "network_cnc_http",
      "description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
      "categories": [
        "network",
        "c2"
      ],
      "severity": 2,
      "weight": 1,
      "confidence": 30,
      "references": [],
      "data": [
        {
          "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
        },
        {
          "suspicious_request": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com"
        },
        {
          "suspicious_request": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "network_http",
      "description": "Performs some HTTP requests",
      "categories": [
        "network"
      ],
      "severity": 2,
      "weight": 1,
      "confidence": 30,
      "references": [],
      "data": [
        {
          "url": "http://i.pki.goog/gsr1.crt"
        },
        {
          "url": "http://i.pki.goog/r4.crt"
        },
        {
          "url": "http://i.pki.goog/we2.crt"
        },
        {
          "url": "http://i.pki.goog/gsr4.crt"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "binary_yara",
      "description": "Binary file triggered multiple YARA rules",
      "categories": [
        "static"
      ],
      "severity": 3,
      "weight": 1,
      "confidence": 80,
      "references": [],
      "data": [
        {
          "Binary triggered YARA rule": "NETDLLMicrosoft"
        },
        {
          "Binary triggered YARA rule": "IsPE32"
        },
        {
          "Binary triggered YARA rule": "IsNET_DLL"
        },
        {
          "Binary triggered YARA rule": "IsDLL"
        },
        {
          "Binary triggered YARA rule": "IsWindowsGUI"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_Studio_NET"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_v70_Basic_NET_additional"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_Basic_NET"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_Studio_NET_additional"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_v70_Basic_NET"
        },
        {
          "Binary triggered YARA rule": "NET_executable_"
        },
        {
          "Binary triggered YARA rule": "NET_executable"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "network_questionable_http_path",
      "description": "Makes a suspicious HTTP request to a commonly exploitable directory with questionable file ext",
      "categories": [
        "network"
      ],
      "severity": 3,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee/pieceshash?cacheHostOrigin=msedge.f.dl.delivery.mp.microsoft.com"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        },
        {
          "url": "http://46.149.110.67/filestreamingservice/files/c92e95cf-27b9-4ea9-a961-5f08d3174bee?P1=1776984951&P2=404&P3=2&P4=dTcAsbSjvag54XwyHINIogEyitdBULDSjv%2fXiN94fPAsjc9p%2bVBPlQUGxgDg1ReAI5z8oNDujPM7tczrEk3rAA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "procmem_yara",
      "description": "Yara detections observed in process dumps, payloads or dropped files",
      "categories": [
        "malware"
      ],
      "severity": 3,
      "weight": 4,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "Hit": "PID 4344 triggered the Yara rule 'NETDLLMicrosoft' with data '['{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }']'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'IsPE32' with data '[]'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'IsNET_DLL' with data '[]'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'IsDLL' with data '[]'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'IsWindowsGUI' with data '[]'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'Microsoft_Visual_Studio_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'Microsoft_Visual_C_v70_Basic_NET_additional' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'Microsoft_Visual_C_Basic_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'Microsoft_Visual_Studio_NET_additional' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'Microsoft_Visual_C_v70_Basic_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'NET_executable_' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 4344 triggered the Yara rule 'NET_executable' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    }
  ],
  "malscore": 8.0,
  "ttps": [
    {
      "signature": "stealth_network",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002",
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "binary_yara",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002",
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "network_cnc_http",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OB0004",
        "B0033",
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "network_http",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "network_questionable_http_path",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002",
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "procmem_yara",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002",
        "OC0006",
        "C0002"
      ]
    }
  ],
  "malstatus": "Malicious"
}