{
  "statistics": {
    "processing": [
      {
        "name": "CAPE",
        "time": 7.009
      },
      {
        "name": "AnalysisInfo",
        "time": 0.051
      },
      {
        "name": "BehaviorAnalysis",
        "time": 0.009
      },
      {
        "name": "Debug",
        "time": 0.001
      },
      {
        "name": "NetworkAnalysis",
        "time": 1.795
      },
      {
        "name": "Suricata",
        "time": 8.883
      },
      {
        "name": "UrlAnalysis",
        "time": 0.0
      },
      {
        "name": "script_log_processing",
        "time": 0.0
      },
      {
        "name": "ProcessMemory",
        "time": 0.0
      }
    ],
    "signatures": [
      {
        "name": "packer_themida",
        "time": 0.0
      },
      {
        "name": "stealth_network",
        "time": 0.0
      },
      {
        "name": "disable_driver_via_blocklist",
        "time": 0.0
      },
      {
        "name": "disable_driver_via_hvcidisallowedimages",
        "time": 0.0
      },
      {
        "name": "disable_hypervisor_protected_code_integrity",
        "time": 0.0
      },
      {
        "name": "pendingfilerenameoperations_Operations",
        "time": 0.0
      },
      {
        "name": "anomalous_deletefile",
        "time": 0.0
      },
      {
        "name": "antiav_360_libs",
        "time": 0.0
      },
      {
        "name": "antiav_ahnlab_libs",
        "time": 0.0
      },
      {
        "name": "antiav_avast_libs",
        "time": 0.0
      },
      {
        "name": "antiav_bitdefender_libs",
        "time": 0.0
      },
      {
        "name": "antiav_bullguard_libs",
        "time": 0.0
      },
      {
        "name": "antiav_emsisoft_libs",
        "time": 0.0
      },
      {
        "name": "antiav_qurb_libs",
        "time": 0.0
      },
      {
        "name": "antiav_servicestop",
        "time": 0.0
      },
      {
        "name": "antiav_apioverride_libs",
        "time": 0.0
      },
      {
        "name": "antidebug_guardpages",
        "time": 0.0
      },
      {
        "name": "antiav_nthookengine_libs",
        "time": 0.0
      },
      {
        "name": "antidebug_outputdebugstring",
        "time": 0.0
      },
      {
        "name": "antidebug_windows",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoo",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoocrash",
        "time": 0.0
      },
      {
        "name": "antisandbox_foregroundwindows",
        "time": 0.0
      },
      {
        "name": "mouse_movement_detect",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_libs",
        "time": 0.0
      },
      {
        "name": "antisandbox_script_timer",
        "time": 0.0
      },
      {
        "name": "antisandbox_sleep",
        "time": 0.0
      },
      {
        "name": "antisandbox_sunbelt_libs",
        "time": 0.0
      },
      {
        "name": "antisandbox_unhook",
        "time": 0.0
      },
      {
        "name": "antivm_directory_objects",
        "time": 0.0
      },
      {
        "name": "antivm_display",
        "time": 0.0
      },
      {
        "name": "antivm_generic_disk",
        "time": 0.0
      },
      {
        "name": "antivm_generic_system",
        "time": 0.0
      },
      {
        "name": "antivm_checks_available_memory",
        "time": 0.0
      },
      {
        "name": "detect_virtualization_via_recent_files",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_libs",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_events",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_libs",
        "time": 0.0
      },
      {
        "name": "antivm_wmi",
        "time": 0.0
      },
      {
        "name": "api_spamming",
        "time": 0.0
      },
      {
        "name": "api_uuidfromstringa",
        "time": 0.0
      },
      {
        "name": "bcdedit_command",
        "time": 0.0
      },
      {
        "name": "bootkit",
        "time": 0.0
      },
      {
        "name": "direct_hdd_access",
        "time": 0.0
      },
      {
        "name": "physical_drive_access",
        "time": 0.0
      },
      {
        "name": "potential_overwrite_mbr",
        "time": 0.0
      },
      {
        "name": "read_file_raw_disk_access",
        "time": 0.0
      },
      {
        "name": "suspicious_iocontrol_codes",
        "time": 0.0
      },
      {
        "name": "browser_needed",
        "time": 0.0
      },
      {
        "name": "regsvr32_squiblydoo_dll_load",
        "time": 0.0
      },
      {
        "name": "uac_bypass_cmstp",
        "time": 0.0
      },
      {
        "name": "uac_bypass_eventvwr",
        "time": 0.0
      },
      {
        "name": "uac_bypass_windows_Backup",
        "time": 0.0
      },
      {
        "name": "dotnet_code_compile",
        "time": 0.0
      },
      {
        "name": "queries_computer_name",
        "time": 0.0
      },
      {
        "name": "queries_user_name",
        "time": 0.0
      },
      {
        "name": "creates_largekey",
        "time": 0.0
      },
      {
        "name": "creates_nullvalue",
        "time": 0.0
      },
      {
        "name": "access_windows_passwords_vault",
        "time": 0.0
      },
      {
        "name": "lsass_credential_dumping",
        "time": 0.0
      },
      {
        "name": "critical_process",
        "time": 0.0
      },
      {
        "name": "cryptopool_domains",
        "time": 0.0
      },
      {
        "name": "dead_connect",
        "time": 0.0
      },
      {
        "name": "dead_link",
        "time": 0.0
      },
      {
        "name": "decoy_document",
        "time": 0.0
      },
      {
        "name": "decoy_image",
        "time": 0.0
      },
      {
        "name": "deletes_consolehost_history",
        "time": 0.0
      },
      {
        "name": "dep_bypass",
        "time": 0.0
      },
      {
        "name": "dep_disable",
        "time": 0.0
      },
      {
        "name": "disables_wfp",
        "time": 0.0
      },
      {
        "name": "add_windows_defender_exclusions",
        "time": 0.0
      },
      {
        "name": "mountpoints_volume_discovery",
        "time": 0.0
      },
      {
        "name": "dll_load_uncommon_file_types",
        "time": 0.0
      },
      {
        "name": "document_script_exe_drop",
        "time": 0.0
      },
      {
        "name": "guloader_apis",
        "time": 0.0
      },
      {
        "name": "driver_load",
        "time": 0.0
      },
      {
        "name": "dynamic_function_loading",
        "time": 0.0
      },
      {
        "name": "encrypted_ioc",
        "time": 0.0
      },
      {
        "name": "exec_crash",
        "time": 0.0
      },
      {
        "name": "process_creation_suspicious_location",
        "time": 0.0
      },
      {
        "name": "exploit_getbasekerneladdress",
        "time": 0.0
      },
      {
        "name": "exploit_gethaldispatchtable",
        "time": 0.0
      },
      {
        "name": "exploit_heapspray",
        "time": 0.0
      },
      {
        "name": "koadic_apis",
        "time": 0.0
      },
      {
        "name": "koadic_network_activity",
        "time": 0.0
      },
      {
        "name": "downloads_from_filehosting",
        "time": 0.0
      },
      {
        "name": "generic_phish",
        "time": 0.0
      },
      {
        "name": "http_request",
        "time": 0.0
      },
      {
        "name": "infostealer_browser",
        "time": 0.0
      },
      {
        "name": "infostealer_browser_password",
        "time": 0.0
      },
      {
        "name": "infostealer_cookies",
        "time": 0.0
      },
      {
        "name": "cryptbot_network",
        "time": 0.0
      },
      {
        "name": "purplewave_network_activity",
        "time": 0.0
      },
      {
        "name": "quilclipper_behavior",
        "time": 0.0
      },
      {
        "name": "raccoon_behavior",
        "time": 0.0
      },
      {
        "name": "captures_screenshot",
        "time": 0.0
      },
      {
        "name": "vidar_behavior",
        "time": 0.0
      },
      {
        "name": "injection_createremotethread",
        "time": 0.0
      },
      {
        "name": "creates_suspended_process",
        "time": 0.0
      },
      {
        "name": "injection_explorer",
        "time": 0.0
      },
      {
        "name": "injection_network_traffic",
        "time": 0.0
      },
      {
        "name": "injection_runpe",
        "time": 0.0
      },
      {
        "name": "injection_rwx",
        "time": 0.0
      },
      {
        "name": "injection_themeinitapihook",
        "time": 0.0
      },
      {
        "name": "resumethread_remote_process",
        "time": 0.0
      },
      {
        "name": "injection_write_exe_process",
        "time": 0.0
      },
      {
        "name": "injection_write_process",
        "time": 0.0
      },
      {
        "name": "internet_dropper",
        "time": 0.0
      },
      {
        "name": "escalate_privilege_via_named_pipe",
        "time": 0.0
      },
      {
        "name": "ipc_namedpipe",
        "time": 0.0
      },
      {
        "name": "js_phish",
        "time": 0.0
      },
      {
        "name": "js_suspicious_redirect",
        "time": 0.0
      },
      {
        "name": "loader_alien",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_internet_explorer_exporter",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_run_exe_helper_utility",
        "time": 0.0
      },
      {
        "name": "execute_ps_via_syncappvpublishingserver",
        "time": 0.0
      },
      {
        "name": "malicious_dynamic_function_loading",
        "time": 0.0
      },
      {
        "name": "encrypt_pcinfo",
        "time": 0.0
      },
      {
        "name": "encrypt_data_agenttesla_http",
        "time": 0.0
      },
      {
        "name": "encrypt_data_agentteslat2_http",
        "time": 0.0
      },
      {
        "name": "encrypt_data_nanocore",
        "time": 0.0
      },
      {
        "name": "reads_memory_remote_process",
        "time": 0.0
      },
      {
        "name": "mimics_filetime",
        "time": 0.0
      },
      {
        "name": "amsi_bypass_via_com_registry",
        "time": 0.0
      },
      {
        "name": "access_auto_logons_via_registry",
        "time": 0.0
      },
      {
        "name": "access_boot_key_via_registry",
        "time": 0.0
      },
      {
        "name": "create_suspicious_lnk_files",
        "time": 0.0
      },
      {
        "name": "credential_access_via_windows_credential_history",
        "time": 0.0
      },
      {
        "name": "dll_hijacking_via_microsoft_exchange",
        "time": 0.0
      },
      {
        "name": "dll_hijacking_via_waas_medic_svc_com_typelib",
        "time": 0.0
      },
      {
        "name": "execute_file_downloaded_via_openssh",
        "time": 0.0
      },
      {
        "name": "execute_safe_mode_from_suspicious_process",
        "time": 0.0
      },
      {
        "name": "execute_scripts_via_microsoft_management_console",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_processes_via_windows_mssql_service",
        "time": 0.0
      },
      {
        "name": "execution_from_self_extracting_archive",
        "time": 0.0
      },
      {
        "name": "ip_address_discovery_via_trusted_program",
        "time": 0.0
      },
      {
        "name": "load_dll_via_control_panel",
        "time": 0.0
      },
      {
        "name": "network_connection_via_suspicious_process",
        "time": 0.0
      },
      {
        "name": "potential_location_discovery_via_unusual_process",
        "time": 0.0
      },
      {
        "name": "store_executable_registry",
        "time": 0.0
      },
      {
        "name": "Suspicious_Execution_Via_MicrosoftExchangeTransportAgent",
        "time": 0.0
      },
      {
        "name": "suspicious_java_execution_via_win_scripts",
        "time": 0.0
      },
      {
        "name": "Suspicious_Scheduled_Task_Creation_Via_Masqueraded_XML_File",
        "time": 0.0
      },
      {
        "name": "uses_restart_manager_for_suspicious_activities",
        "time": 0.0
      },
      {
        "name": "modify_desktop_wallpaper",
        "time": 0.0
      },
      {
        "name": "move_file_on_reboot",
        "time": 0.0
      },
      {
        "name": "multiple_useragents",
        "time": 0.0
      },
      {
        "name": "network_anomaly",
        "time": 0.0
      },
      {
        "name": "network_bind",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_archive",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_free_webhosting",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_generic",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_interactsh",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_opensource",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_pastesite",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_payload",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_serviceinterface",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_socialmedia",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_telegram",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_tempstorage",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_temp_urldns",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_urlshortener",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_useragent",
        "time": 0.0
      },
      {
        "name": "network_cnc_smtps_exfil",
        "time": 0.0
      },
      {
        "name": "network_cnc_smtps_generic",
        "time": 0.0
      },
      {
        "name": "network_dns_idn",
        "time": 0.0
      },
      {
        "name": "network_dns_suspicious_querytype",
        "time": 0.0
      },
      {
        "name": "network_dns_tunneling_request",
        "time": 0.0
      },
      {
        "name": "network_document_http",
        "time": 0.0
      },
      {
        "name": "explorer_http",
        "time": 0.0
      },
      {
        "name": "network_fake_useragent",
        "time": 0.0
      },
      {
        "name": "legitimate_domain_abuse",
        "time": 0.0
      },
      {
        "name": "suspicious_communication_trusted_site",
        "time": 0.0
      },
      {
        "name": "network_tor",
        "time": 0.0
      },
      {
        "name": "office_com_load",
        "time": 0.0
      },
      {
        "name": "office_dotnet_load",
        "time": 0.0
      },
      {
        "name": "office_mshtml_load",
        "time": 0.0
      },
      {
        "name": "office_vb_load",
        "time": 0.0
      },
      {
        "name": "office_wmi_load",
        "time": 0.0
      },
      {
        "name": "office_cve2017_11882",
        "time": 0.0
      },
      {
        "name": "office_cve2017_11882_network",
        "time": 0.0
      },
      {
        "name": "office_cve_2021_40444",
        "time": 0.0
      },
      {
        "name": "office_cve_2021_40444_m2",
        "time": 0.0
      },
      {
        "name": "office_flash_load",
        "time": 0.0
      },
      {
        "name": "office_postscript",
        "time": 0.0
      },
      {
        "name": "office_suspicious_processes",
        "time": 0.0
      },
      {
        "name": "office_write_exe",
        "time": 0.0
      },
      {
        "name": "persistence_via_autodial_dll_registry",
        "time": 0.0
      },
      {
        "name": "persistence_autorun",
        "time": 0.0
      },
      {
        "name": "persistence_autorun_tasks",
        "time": 0.0
      },
      {
        "name": "persistence_bootexecute",
        "time": 0.0
      },
      {
        "name": "persistence_registry_script",
        "time": 0.0
      },
      {
        "name": "powershell_network_connection",
        "time": 0.0
      },
      {
        "name": "powershell_download",
        "time": 0.0
      },
      {
        "name": "powershell_request",
        "time": 0.0
      },
      {
        "name": "createtoolhelp32snapshot_module_enumeration",
        "time": 0.0
      },
      {
        "name": "enumerates_running_processes",
        "time": 0.0
      },
      {
        "name": "process_interest",
        "time": 0.0
      },
      {
        "name": "process_needed",
        "time": 0.0
      },
      {
        "name": "mass_data_encryption",
        "time": 0.0
      },
      {
        "name": "ransomware_file_modifications",
        "time": 0.0
      },
      {
        "name": "ransomware_message",
        "time": 0.0
      },
      {
        "name": "nemty_network_activity",
        "time": 0.0
      },
      {
        "name": "nemty_note",
        "time": 0.0
      },
      {
        "name": "sodinokibi_behavior",
        "time": 0.0
      },
      {
        "name": "stop_ransomware_registry",
        "time": 0.0
      },
      {
        "name": "blackrat_apis",
        "time": 0.0
      },
      {
        "name": "blackrat_network_activity",
        "time": 0.0
      },
      {
        "name": "blackrat_registry_keys",
        "time": 0.0
      },
      {
        "name": "dcrat_behavior",
        "time": 0.0
      },
      {
        "name": "karagany_system_event_objects",
        "time": 0.0
      },
      {
        "name": "rat_luminosity",
        "time": 0.0
      },
      {
        "name": "rat_nanocore",
        "time": 0.0
      },
      {
        "name": "netwire_behavior",
        "time": 0.0
      },
      {
        "name": "obliquerat_network_activity",
        "time": 0.0
      },
      {
        "name": "orcusrat_behavior",
        "time": 0.0
      },
      {
        "name": "trochilusrat_apis",
        "time": 0.0
      },
      {
        "name": "reads_self",
        "time": 0.0
      },
      {
        "name": "recon_beacon",
        "time": 0.0
      },
      {
        "name": "recon_programs",
        "time": 0.0
      },
      {
        "name": "recon_systeminfo",
        "time": 0.0
      },
      {
        "name": "accesses_recyclebin",
        "time": 0.0
      },
      {
        "name": "remcos_shell_code_dynamic_wrapper_x",
        "time": 0.0
      },
      {
        "name": "script_created_process",
        "time": 0.0
      },
      {
        "name": "script_network_activity",
        "time": 0.0
      },
      {
        "name": "suspicious_js_script",
        "time": 0.0
      },
      {
        "name": "javascript_timer",
        "time": 0.0
      },
      {
        "name": "secure_login_phishing",
        "time": 0.0
      },
      {
        "name": "securityxploded_modules",
        "time": 0.0
      },
      {
        "name": "get_clipboard_data",
        "time": 0.0
      },
      {
        "name": "sets_autoconfig_url",
        "time": 0.0
      },
      {
        "name": "spoofs_procname",
        "time": 0.0
      },
      {
        "name": "stack_pivot",
        "time": 0.0
      },
      {
        "name": "stack_pivot_file_created",
        "time": 0.0
      },
      {
        "name": "stack_pivot_process_create",
        "time": 0.0
      },
      {
        "name": "set_clipboard_data",
        "time": 0.0
      },
      {
        "name": "stealth_childproc",
        "time": 0.0
      },
      {
        "name": "stealth_file",
        "time": 0.0
      },
      {
        "name": "stealth_timeout",
        "time": 0.0
      },
      {
        "name": "stealth_window",
        "time": 0.0
      },
      {
        "name": "queries_keyboard_layout",
        "time": 0.0
      },
      {
        "name": "queries_locale_api",
        "time": 0.0
      },
      {
        "name": "terminates_remote_process",
        "time": 0.0
      },
      {
        "name": "uiautomationcore_load",
        "time": 0.0
      },
      {
        "name": "user_enum",
        "time": 0.0
      },
      {
        "name": "mmc_dll_script_load",
        "time": 0.0
      },
      {
        "name": "mmc_dotnet_load",
        "time": 0.0
      },
      {
        "name": "virus",
        "time": 0.0
      },
      {
        "name": "neshta_files",
        "time": 0.0
      },
      {
        "name": "neshta_regkeys",
        "time": 0.0
      },
      {
        "name": "webmail_phish",
        "time": 0.0
      },
      {
        "name": "persists_dev_util",
        "time": 0.0
      },
      {
        "name": "spawns_dev_util",
        "time": 0.0
      },
      {
        "name": "alters_windows_utility",
        "time": 0.0
      },
      {
        "name": "overwrites_accessibility_utility",
        "time": 0.0
      },
      {
        "name": "Potential_Lateral_Movement_Via_SMBEXEC",
        "time": 0.0
      },
      {
        "name": "potential_WebShell_Via_ScreenConnectServer",
        "time": 0.0
      },
      {
        "name": "uses_Microsoft_HTML_Help_Executable",
        "time": 0.0
      },
      {
        "name": "wiper_zeroedbytes",
        "time": 0.0
      },
      {
        "name": "wmi_create_process",
        "time": 0.0
      },
      {
        "name": "wmi_script_process",
        "time": 0.0
      },
      {
        "name": "antianalysis_tls_section",
        "time": 0.0
      },
      {
        "name": "antivirus_clamav",
        "time": 0.0
      },
      {
        "name": "antivirus_virustotal",
        "time": 0.0
      },
      {
        "name": "bad_certs",
        "time": 0.0
      },
      {
        "name": "bad_ssl_certs",
        "time": 0.0
      },
      {
        "name": "banker_zeus_p2p",
        "time": 0.0
      },
      {
        "name": "banker_zeus_url",
        "time": 0.0
      },
      {
        "name": "binary_yara",
        "time": 0.0
      },
      {
        "name": "bot_athenahttp",
        "time": 0.0
      },
      {
        "name": "bot_dirtjumper",
        "time": 0.0
      },
      {
        "name": "bot_drive",
        "time": 0.0
      },
      {
        "name": "bot_drive2",
        "time": 0.0
      },
      {
        "name": "bot_madness",
        "time": 0.0
      },
      {
        "name": "phishing_kit_detected",
        "time": 0.0
      },
      {
        "name": "family_proxyback",
        "time": 0.0
      },
      {
        "name": "flare_capa_antianalysis",
        "time": 0.0
      },
      {
        "name": "flare_capa_collection",
        "time": 0.0
      },
      {
        "name": "flare_capa_communication",
        "time": 0.0
      },
      {
        "name": "flare_capa_compiler",
        "time": 0.0
      },
      {
        "name": "flare_capa_datamanipulation",
        "time": 0.0
      },
      {
        "name": "flare_capa_executable",
        "time": 0.0
      },
      {
        "name": "flare_capa_hostinteraction",
        "time": 0.0
      },
      {
        "name": "flare_capa_impact",
        "time": 0.0
      },
      {
        "name": "flare_capa_lib",
        "time": 0.0
      },
      {
        "name": "flare_capa_linking",
        "time": 0.0
      },
      {
        "name": "flare_capa_loadcode",
        "time": 0.0
      },
      {
        "name": "flare_capa_malwarefamily",
        "time": 0.0
      },
      {
        "name": "flare_capa_nursery",
        "time": 0.0
      },
      {
        "name": "flare_capa_persistence",
        "time": 0.0
      },
      {
        "name": "flare_capa_runtime",
        "time": 0.0
      },
      {
        "name": "flare_capa_targeting",
        "time": 0.0
      },
      {
        "name": "threatfox",
        "time": 0.0
      },
      {
        "name": "log4shell",
        "time": 0.0
      },
      {
        "name": "mimics_extension",
        "time": 0.0
      },
      {
        "name": "network_country_distribution",
        "time": 0.0
      },
      {
        "name": "network_cnc_http",
        "time": 0.003
      },
      {
        "name": "network_ip_exe",
        "time": 0.001
      },
      {
        "name": "network_dga",
        "time": 0.0
      },
      {
        "name": "network_dga_fraunhofer",
        "time": 0.0
      },
      {
        "name": "network_dyndns",
        "time": 0.003
      },
      {
        "name": "network_excessive_udp",
        "time": 0.0
      },
      {
        "name": "network_http",
        "time": 0.001
      },
      {
        "name": "network_icmp",
        "time": 0.0
      },
      {
        "name": "network_irc",
        "time": 0.0
      },
      {
        "name": "network_open_proxy",
        "time": 0.001
      },
      {
        "name": "network_questionable_http_path",
        "time": 0.0
      },
      {
        "name": "network_questionable_https_path",
        "time": 0.0
      },
      {
        "name": "network_smtp",
        "time": 0.0
      },
      {
        "name": "network_torgateway",
        "time": 0.001
      },
      {
        "name": "origin_langid",
        "time": 0.0
      },
      {
        "name": "origin_resource_langid",
        "time": 0.0
      },
      {
        "name": "overlay",
        "time": 0.0
      },
      {
        "name": "packer_unknown_pe_section_name",
        "time": 0.0
      },
      {
        "name": "packer_aspack",
        "time": 0.0
      },
      {
        "name": "packer_aspirecrypt",
        "time": 0.0
      },
      {
        "name": "packer_bedsprotector",
        "time": 0.0
      },
      {
        "name": "packer_confuser",
        "time": 0.0
      },
      {
        "name": "packer_enigma",
        "time": 0.0
      },
      {
        "name": "packer_entropy",
        "time": 0.0
      },
      {
        "name": "packer_mpress",
        "time": 0.0
      },
      {
        "name": "packer_nate",
        "time": 0.0
      },
      {
        "name": "packer_nspack",
        "time": 0.0
      },
      {
        "name": "packer_smartassembly",
        "time": 0.0
      },
      {
        "name": "packer_spices",
        "time": 0.0
      },
      {
        "name": "packer_themida",
        "time": 0.0
      },
      {
        "name": "packer_titan",
        "time": 0.0
      },
      {
        "name": "packer_upx",
        "time": 0.0
      },
      {
        "name": "packer_vmprotect",
        "time": 0.0
      },
      {
        "name": "packer_yoda",
        "time": 0.0
      },
      {
        "name": "pdf_annot_urls_checker",
        "time": 0.0
      },
      {
        "name": "polymorphic",
        "time": 0.0
      },
      {
        "name": "punch_plus_plus_pcres",
        "time": 0.0
      },
      {
        "name": "procmem_yara",
        "time": 0.0
      },
      {
        "name": "recon_checkip",
        "time": 0.0
      },
      {
        "name": "static_authenticode",
        "time": 0.0
      },
      {
        "name": "invalid_authenticode_signature",
        "time": 0.0
      },
      {
        "name": "static_dotnet_anomaly",
        "time": 0.0
      },
      {
        "name": "static_java",
        "time": 0.0
      },
      {
        "name": "static_pdf",
        "time": 0.0
      },
      {
        "name": "contains_pe_overlay",
        "time": 0.0
      },
      {
        "name": "static_pe_anomaly",
        "time": 0.0
      },
      {
        "name": "pe_compile_timestomping",
        "time": 0.0
      },
      {
        "name": "static_pe_pdbpath",
        "time": 0.0
      },
      {
        "name": "static_rat_config",
        "time": 0.0
      },
      {
        "name": "static_versioninfo_anomaly",
        "time": 0.0
      },
      {
        "name": "suricata_alert",
        "time": 0.0
      },
      {
        "name": "suspicious_html_body",
        "time": 0.0
      },
      {
        "name": "suspicious_html_name",
        "time": 0.0
      },
      {
        "name": "suspicious_html_title",
        "time": 0.0
      },
      {
        "name": "volatility_devicetree_1",
        "time": 0.0
      },
      {
        "name": "volatility_handles_1",
        "time": 0.0
      },
      {
        "name": "volatility_ldrmodules_1",
        "time": 0.0
      },
      {
        "name": "volatility_ldrmodules_2",
        "time": 0.0
      },
      {
        "name": "volatility_malfind_1",
        "time": 0.0
      },
      {
        "name": "volatility_malfind_2",
        "time": 0.0
      },
      {
        "name": "volatility_modscan_1",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_1",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_2",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_3",
        "time": 0.0
      },
      {
        "name": "whois_create",
        "time": 0.0
      },
      {
        "name": "accesses_mailslot",
        "time": 0.0
      },
      {
        "name": "accesses_netlogon_regkey",
        "time": 0.0
      },
      {
        "name": "accesses_public_folder",
        "time": 0.0
      },
      {
        "name": "accesses_sysvol",
        "time": 0.0
      },
      {
        "name": "writes_sysvol",
        "time": 0.0
      },
      {
        "name": "adds_admin_user",
        "time": 0.0
      },
      {
        "name": "adds_user",
        "time": 0.0
      },
      {
        "name": "overwrites_admin_password",
        "time": 0.0
      },
      {
        "name": "antianalysis_detectfile",
        "time": 0.002
      },
      {
        "name": "antianalysis_detectreg",
        "time": 0.001
      },
      {
        "name": "modify_attachment_manager",
        "time": 0.0
      },
      {
        "name": "antiav_detectfile",
        "time": 0.004
      },
      {
        "name": "antiav_detectreg",
        "time": 0.005
      },
      {
        "name": "antiav_srp",
        "time": 0.0
      },
      {
        "name": "antiav_whitespace",
        "time": 0.0
      },
      {
        "name": "antidebug_devices",
        "time": 0.001
      },
      {
        "name": "antiemu_windefend",
        "time": 0.0
      },
      {
        "name": "antiemu_wine_reg",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoo_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_fortinet_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_joe_anubis_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_mutex",
        "time": 0.0
      },
      {
        "name": "antisandbox_sunbelt_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_threattrack_files",
        "time": 0.0
      },
      {
        "name": "antivm_bochs_keys",
        "time": 0.0
      },
      {
        "name": "antivm_generic_bios",
        "time": 0.0
      },
      {
        "name": "antivm_generic_diskreg",
        "time": 0.0
      },
      {
        "name": "antivm_hyperv_keys",
        "time": 0.0
      },
      {
        "name": "antivm_parallels_keys",
        "time": 0.0
      },
      {
        "name": "antivm_recentdocs",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_devices",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_files",
        "time": 0.002
      },
      {
        "name": "antivm_vbox_keys",
        "time": 0.001
      },
      {
        "name": "antivm_vmware_devices",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_files",
        "time": 0.001
      },
      {
        "name": "antivm_vmware_keys",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_mutexes",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_files",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_keys",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_mutex",
        "time": 0.0
      },
      {
        "name": "antivm_xen_keys",
        "time": 0.0
      },
      {
        "name": "asyncrat_mutex",
        "time": 0.0
      },
      {
        "name": "gulpix_behavior",
        "time": 0.0
      },
      {
        "name": "ketrican_regkeys",
        "time": 0.0
      },
      {
        "name": "okrum_mutexes",
        "time": 0.0
      },
      {
        "name": "banker_cridex",
        "time": 0.0
      },
      {
        "name": "geodo_banking_trojan",
        "time": 0.001
      },
      {
        "name": "banker_spyeye_mutexes",
        "time": 0.0
      },
      {
        "name": "banker_zeus_mutex",
        "time": 0.0
      },
      {
        "name": "bitcoin_opencl",
        "time": 0.0
      },
      {
        "name": "enumerates_physical_drives",
        "time": 0.0
      },
      {
        "name": "bot_russkill",
        "time": 0.0
      },
      {
        "name": "browser_addon",
        "time": 0.0
      },
      {
        "name": "chromium_browser_extension_directory",
        "time": 0.0
      },
      {
        "name": "browser_helper_object",
        "time": 0.0
      },
      {
        "name": "browser_security",
        "time": 0.001
      },
      {
        "name": "browser_startpage",
        "time": 0.0
      },
      {
        "name": "ie_disables_process_tab",
        "time": 0.0
      },
      {
        "name": "odbcconf_bypass",
        "time": 0.0
      },
      {
        "name": "squiblydoo_bypass",
        "time": 0.0
      },
      {
        "name": "squiblytwo_bypass",
        "time": 0.0
      },
      {
        "name": "bypass_chromium_protection",
        "time": 0.0
      },
      {
        "name": "bypass_firewall",
        "time": 0.0
      },
      {
        "name": "checks_uac_status",
        "time": 0.0
      },
      {
        "name": "uac_bypass_cmstpcom",
        "time": 0.0
      },
      {
        "name": "uac_bypass_delegateexecute_sdclt",
        "time": 0.0
      },
      {
        "name": "uac_bypass_fodhelper",
        "time": 0.0
      },
      {
        "name": "cape_extracted_content",
        "time": 0.0
      },
      {
        "name": "carberp_mutex",
        "time": 0.0
      },
      {
        "name": "clears_logs",
        "time": 0.0
      },
      {
        "name": "cmdline_obfuscation",
        "time": 0.0
      },
      {
        "name": "cmdline_switches",
        "time": 0.0
      },
      {
        "name": "cmdline_terminate",
        "time": 0.0
      },
      {
        "name": "cmdline_forfiles_wildcard",
        "time": 0.0
      },
      {
        "name": "cmdline_http_link",
        "time": 0.0
      },
      {
        "name": "cmdline_long_string",
        "time": 0.0
      },
      {
        "name": "cmdline_reversed_http_link",
        "time": 0.0
      },
      {
        "name": "long_commandline",
        "time": 0.0
      },
      {
        "name": "powershell_renamed_commandline",
        "time": 0.0
      },
      {
        "name": "copies_self",
        "time": 0.0
      },
      {
        "name": "credwiz_credentialaccess",
        "time": 0.0
      },
      {
        "name": "enables_wdigest",
        "time": 0.0
      },
      {
        "name": "vaultcmd_credentialaccess",
        "time": 0.0
      },
      {
        "name": "file_credential_store_access",
        "time": 0.0
      },
      {
        "name": "file_credential_store_write",
        "time": 0.0
      },
      {
        "name": "kerberos_credential_access_via_rubeus",
        "time": 0.0
      },
      {
        "name": "registry_credential_dumping",
        "time": 0.0
      },
      {
        "name": "registry_credential_store_access",
        "time": 0.0
      },
      {
        "name": "registry_lsa_secrets_access",
        "time": 0.0
      },
      {
        "name": "comsvcs_credentialdump",
        "time": 0.0
      },
      {
        "name": "cryptomining_stratum_command",
        "time": 0.0
      },
      {
        "name": "cypherit_mutexes",
        "time": 0.001
      },
      {
        "name": "darkcomet_regkeys",
        "time": 0.0
      },
      {
        "name": "datop_loader",
        "time": 0.0
      },
      {
        "name": "deepfreeze_mutex",
        "time": 0.0
      },
      {
        "name": "deletes_executed_files",
        "time": 0.0
      },
      {
        "name": "disables_app_launch",
        "time": 0.0
      },
      {
        "name": "disables_auto_app_termination",
        "time": 0.0
      },
      {
        "name": "disables_appv_virtualization",
        "time": 0.0
      },
      {
        "name": "disables_backups",
        "time": 0.001
      },
      {
        "name": "disables_browser_warn",
        "time": 0.001
      },
      {
        "name": "disables_context_menus",
        "time": 0.001
      },
      {
        "name": "disables_cpl_disable",
        "time": 0.0
      },
      {
        "name": "disables_crashdumps",
        "time": 0.0
      },
      {
        "name": "disables_event_logging",
        "time": 0.0
      },
      {
        "name": "disables_folder_options",
        "time": 0.0
      },
      {
        "name": "disables_notificationcenter",
        "time": 0.0
      },
      {
        "name": "disables_power_options",
        "time": 0.001
      },
      {
        "name": "disables_restore_default_state",
        "time": 0.0
      },
      {
        "name": "disables_run_command",
        "time": 0.0
      },
      {
        "name": "disables_smartscreen",
        "time": 0.0
      },
      {
        "name": "disables_startmenu_search",
        "time": 0.001
      },
      {
        "name": "disables_system_restore",
        "time": 0.0
      },
      {
        "name": "disables_uac",
        "time": 0.0
      },
      {
        "name": "disables_wer",
        "time": 0.0
      },
      {
        "name": "disables_windows_defender",
        "time": 0.0
      },
      {
        "name": "disables_windows_defender_logging",
        "time": 0.0
      },
      {
        "name": "removes_windows_defender_contextmenu",
        "time": 0.0
      },
      {
        "name": "removes_windows_defender_updates",
        "time": 0.0
      },
      {
        "name": "windows_defender_powershell",
        "time": 0.0
      },
      {
        "name": "disables_windows_file_protection",
        "time": 0.0
      },
      {
        "name": "disables_windowsupdate",
        "time": 0.0
      },
      {
        "name": "disables_winfirewall",
        "time": 0.0
      },
      {
        "name": "discover_registry_mount_points",
        "time": 0.0
      },
      {
        "name": "adfind_domain_enumeration",
        "time": 0.0
      },
      {
        "name": "domain_enumeration_commands",
        "time": 0.0
      },
      {
        "name": "andromut_mutexes",
        "time": 0.0
      },
      {
        "name": "downloader_cabby",
        "time": 0.0
      },
      {
        "name": "phorpiex_mutexes",
        "time": 0.0
      },
      {
        "name": "protonbot_mutexes",
        "time": 0.0
      },
      {
        "name": "driver_filtermanager",
        "time": 0.0
      },
      {
        "name": "dropper",
        "time": 0.0
      },
      {
        "name": "dll_archive_execution",
        "time": 0.0
      },
      {
        "name": "lnk_archive_execution",
        "time": 0.0
      },
      {
        "name": "script_archive_execution",
        "time": 0.0
      },
      {
        "name": "excel4_macro_urls",
        "time": 0.0
      },
      {
        "name": "escalate_privilege_via_ntlm_relay",
        "time": 0.0
      },
      {
        "name": "spooler_access",
        "time": 0.0
      },
      {
        "name": "spooler_svc_start",
        "time": 0.0
      },
      {
        "name": "mapped_drives_uac",
        "time": 0.0
      },
      {
        "name": "hides_recycle_bin_icon",
        "time": 0.001
      },
      {
        "name": "apocalypse_stealer_file_behavior",
        "time": 0.0
      },
      {
        "name": "arkei_files",
        "time": 0.0
      },
      {
        "name": "azorult_mutexes",
        "time": 0.001
      },
      {
        "name": "infostealer_bitcoin",
        "time": 0.002
      },
      {
        "name": "cryptbot_files",
        "time": 0.0
      },
      {
        "name": "echelon_files",
        "time": 0.001
      },
      {
        "name": "infostealer_ftp",
        "time": 0.003
      },
      {
        "name": "infostealer_im",
        "time": 0.002
      },
      {
        "name": "infostealer_mail",
        "time": 0.002
      },
      {
        "name": "masslogger_files",
        "time": 0.0
      },
      {
        "name": "poullight_files",
        "time": 0.001
      },
      {
        "name": "purplewave_mutexes",
        "time": 0.0
      },
      {
        "name": "quilclipper_mutexes",
        "time": 0.0
      },
      {
        "name": "qulab_files",
        "time": 0.0
      },
      {
        "name": "qulab_mutexes",
        "time": 0.0
      },
      {
        "name": "asyncrat_mutex",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_ASPNet_Compiler",
        "time": 0.0
      },
      {
        "name": "Evade_Execute_Via_DeviceCredentialDeployment",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_Filter_Manager_Control",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_Intel_GFXDownloadWrapper",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_appvlp",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_pcalua",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_OpenSSH",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_pcalua",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_PesterPSModule",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_ScriptRunner",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_ttdinject",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_VisualStudioLiveShare",
        "time": 0.0
      },
      {
        "name": "Execute_Msiexec_Via_Explorer",
        "time": 0.0
      },
      {
        "name": "execute_remote_msi",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_powershell_via_runscripthelper",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_powershell_via_sqlps",
        "time": 0.0
      },
      {
        "name": "Indirect_Command_Execution_Via_ConsoleWindowHost",
        "time": 0.0
      },
      {
        "name": "Perform_Malicious_Activities_Via_Headless_Browser",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_CertOC",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_MSIEXEC",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_Odbcconf",
        "time": 0.0
      },
      {
        "name": "Scriptlet_Proxy_Execution_Via_Pubprn",
        "time": 0.0
      },
      {
        "name": "ie_martian_children",
        "time": 0.0
      },
      {
        "name": "office_martian_children",
        "time": 0.0
      },
      {
        "name": "mimics_icon",
        "time": 0.0
      },
      {
        "name": "masquerade_process_name",
        "time": 0.002
      },
      {
        "name": "mimikatz_modules",
        "time": 0.0
      },
      {
        "name": "ms_office_cmd_rce",
        "time": 0.0
      },
      {
        "name": "mount_copy_to_webdav_share",
        "time": 0.0
      },
      {
        "name": "potential_protocol_tunneling_via_legit_utilities",
        "time": 0.0
      },
      {
        "name": "potential_protocol_tunneling_via_qemu",
        "time": 0.0
      },
      {
        "name": "suspicious_execution_via_dotnet_remoting",
        "time": 0.0
      },
      {
        "name": "modify_certs",
        "time": 0.0
      },
      {
        "name": "dotnet_clr_usagelog_regkeys",
        "time": 0.0
      },
      {
        "name": "modify_hostfile",
        "time": 0.0
      },
      {
        "name": "modify_oem_information",
        "time": 0.0
      },
      {
        "name": "modify_security_center_warnings",
        "time": 0.0
      },
      {
        "name": "modify_uac_prompt",
        "time": 0.0
      },
      {
        "name": "network_dns_blockchain",
        "time": 0.0
      },
      {
        "name": "network_dns_opennic",
        "time": 0.001
      },
      {
        "name": "network_dns_paste_site",
        "time": 0.001
      },
      {
        "name": "network_dns_reverse_proxy",
        "time": 0.0
      },
      {
        "name": "network_dns_temp_file_storage",
        "time": 0.001
      },
      {
        "name": "network_dns_temp_urldns",
        "time": 0.0
      },
      {
        "name": "network_dns_url_shortener",
        "time": 0.008
      },
      {
        "name": "network_dns_doh_tls",
        "time": 0.0
      },
      {
        "name": "suspicious_tld",
        "time": 0.006
      },
      {
        "name": "network_tor_service",
        "time": 0.0
      },
      {
        "name": "office_code_page",
        "time": 0.0
      },
      {
        "name": "office_addinloading",
        "time": 0.0
      },
      {
        "name": "office_perfkey",
        "time": 0.0
      },
      {
        "name": "office_macro",
        "time": 0.0
      },
      {
        "name": "changes_trust_center_settings",
        "time": 0.0
      },
      {
        "name": "disables_vba_trust_access",
        "time": 0.0
      },
      {
        "name": "office_macro_autoexecution",
        "time": 0.0
      },
      {
        "name": "office_macro_ioc",
        "time": 0.0
      },
      {
        "name": "office_macro_malicious_prediction",
        "time": 0.0
      },
      {
        "name": "office_macro_suspicious",
        "time": 0.0
      },
      {
        "name": "rtf_aslr_bypass",
        "time": 0.0
      },
      {
        "name": "rtf_anomaly_characterset",
        "time": 0.0
      },
      {
        "name": "rtf_anomaly_version",
        "time": 0.0
      },
      {
        "name": "rtf_embedded_content",
        "time": 0.0
      },
      {
        "name": "rtf_embedded_office_file",
        "time": 0.0
      },
      {
        "name": "rtf_exploit_static",
        "time": 0.0
      },
      {
        "name": "office_security",
        "time": 0.0
      },
      {
        "name": "accesses_office_username",
        "time": 0.0
      },
      {
        "name": "office_anomalous_feature",
        "time": 0.0
      },
      {
        "name": "office_dde_command",
        "time": 0.0
      },
      {
        "name": "packer_armadillo_mutex",
        "time": 0.0
      },
      {
        "name": "packer_armadillo_regkey",
        "time": 0.0
      },
      {
        "name": "persistence_ads",
        "time": 0.0
      },
      {
        "name": "persistence_safeboot",
        "time": 0.0
      },
      {
        "name": "persistence_ifeo",
        "time": 0.0
      },
      {
        "name": "persistence_silent_process_exit",
        "time": 0.0
      },
      {
        "name": "persistence_rdp_registry",
        "time": 0.0
      },
      {
        "name": "persistence_rdp_shadowing",
        "time": 0.0
      },
      {
        "name": "persistence_service",
        "time": 0.0
      },
      {
        "name": "persistence_shim_database",
        "time": 0.0
      },
      {
        "name": "powerpool_mutexes",
        "time": 0.0
      },
      {
        "name": "powershell_scriptblock_logging",
        "time": 0.0
      },
      {
        "name": "powershell_command_suspicious",
        "time": 0.0
      },
      {
        "name": "powershell_history_save_mod",
        "time": 0.0
      },
      {
        "name": "powershell_renamed",
        "time": 0.0
      },
      {
        "name": "powershell_reversed",
        "time": 0.0
      },
      {
        "name": "powershell_variable_obfuscation",
        "time": 0.0
      },
      {
        "name": "prevents_safeboot",
        "time": 0.0
      },
      {
        "name": "cmdline_process_discovery",
        "time": 0.0
      },
      {
        "name": "cryptomix_mutexes",
        "time": 0.0
      },
      {
        "name": "dharma_mutexes",
        "time": 0.0
      },
      {
        "name": "ransomware_extensions_generic",
        "time": 0.0
      },
      {
        "name": "ransomware_extensions_known",
        "time": 0.004
      },
      {
        "name": "ransomware_files",
        "time": 0.006
      },
      {
        "name": "fonix_mutexes",
        "time": 0.0
      },
      {
        "name": "gandcrab_mutexes",
        "time": 0.0
      },
      {
        "name": "germanwiper_mutexes",
        "time": 0.0
      },
      {
        "name": "medusalocker_mutexes",
        "time": 0.0
      },
      {
        "name": "medusalocker_regkeys",
        "time": 0.0
      },
      {
        "name": "nemty_mutexes",
        "time": 0.0
      },
      {
        "name": "nemty_regkeys",
        "time": 0.0
      },
      {
        "name": "pysa_mutexes",
        "time": 0.0
      },
      {
        "name": "ransomware_radamant",
        "time": 0.0
      },
      {
        "name": "ransomware_recyclebin",
        "time": 0.0
      },
      {
        "name": "revil_mutexes",
        "time": 0.001
      },
      {
        "name": "ransomware_revil_regkey",
        "time": 0.0
      },
      {
        "name": "satan_mutexes",
        "time": 0.0
      },
      {
        "name": "snake_ransom_mutexes",
        "time": 0.0
      },
      {
        "name": "stop_ransom_mutexes",
        "time": 0.0
      },
      {
        "name": "stop_ransomware_cmd",
        "time": 0.0
      },
      {
        "name": "ransomware_stopdjvu",
        "time": 0.0
      },
      {
        "name": "rat_beebus_mutexes",
        "time": 0.0
      },
      {
        "name": "blacknet_mutexes",
        "time": 0.0
      },
      {
        "name": "blackrat_mutexes",
        "time": 0.0
      },
      {
        "name": "crat_mutexes",
        "time": 0.0
      },
      {
        "name": "dcrat_files",
        "time": 0.0
      },
      {
        "name": "dcrat_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_fynloski_mutexes",
        "time": 0.0
      },
      {
        "name": "limerat_mutexes",
        "time": 0.0
      },
      {
        "name": "limerat_regkeys",
        "time": 0.0
      },
      {
        "name": "lodarat_file_behavior",
        "time": 0.0
      },
      {
        "name": "modirat_behavior",
        "time": 0.0
      },
      {
        "name": "njrat_regkeys",
        "time": 0.0
      },
      {
        "name": "obliquerat_files",
        "time": 0.0
      },
      {
        "name": "obliquerat_mutexes",
        "time": 0.0
      },
      {
        "name": "parallax_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_pcclient",
        "time": 0.0
      },
      {
        "name": "rat_plugx_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_poisonivy_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_quasar_mutexes",
        "time": 0.0
      },
      {
        "name": "ratsnif_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_spynet",
        "time": 0.0
      },
      {
        "name": "venomrat_mutexes",
        "time": 0.0
      },
      {
        "name": "warzonerat_files",
        "time": 0.0
      },
      {
        "name": "warzonerat_regkeys",
        "time": 0.0
      },
      {
        "name": "xpertrat_files",
        "time": 0.0
      },
      {
        "name": "xpertrat_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_xtreme_mutexes",
        "time": 0.0
      },
      {
        "name": "reads_password_database",
        "time": 0.0
      },
      {
        "name": "recon_fingerprint",
        "time": 0.0
      },
      {
        "name": "remcos_files",
        "time": 0.0
      },
      {
        "name": "remcos_mutexes",
        "time": 0.0
      },
      {
        "name": "remcos_regkeys",
        "time": 0.0
      },
      {
        "name": "rdptcp_key",
        "time": 0.0
      },
      {
        "name": "uses_rdp_clip",
        "time": 0.0
      },
      {
        "name": "uses_remote_desktop_session",
        "time": 0.0
      },
      {
        "name": "removes_networking_icon",
        "time": 0.0
      },
      {
        "name": "removes_pinned_programs",
        "time": 0.001
      },
      {
        "name": "removes_security_maintenance_icon",
        "time": 0.0
      },
      {
        "name": "removes_startmenu_defaults",
        "time": 0.0
      },
      {
        "name": "removes_username_startmenu",
        "time": 0.0
      },
      {
        "name": "spicyhotpot_behavior",
        "time": 0.0
      },
      {
        "name": "sniffer_winpcap",
        "time": 0.0
      },
      {
        "name": "spreading_autoruninf",
        "time": 0.0
      },
      {
        "name": "stealth_hidden_extension",
        "time": 0.0
      },
      {
        "name": "stealth_hiddenreg",
        "time": 0.0
      },
      {
        "name": "stealth_hide_notifications",
        "time": 0.0
      },
      {
        "name": "stealth_webhistory",
        "time": 0.0
      },
      {
        "name": "sysinternals_psexec",
        "time": 0.0
      },
      {
        "name": "sysinternals_tools",
        "time": 0.0
      },
      {
        "name": "language_check_registry",
        "time": 0.0
      },
      {
        "name": "tampers_etw",
        "time": 0.0
      },
      {
        "name": "lsa_tampering",
        "time": 0.0
      },
      {
        "name": "tampers_powershell_logging",
        "time": 0.0
      },
      {
        "name": "targeted_flame",
        "time": 0.0
      },
      {
        "name": "territorial_disputes_sigs",
        "time": 0.003
      },
      {
        "name": "trickbot_mutex",
        "time": 0.0
      },
      {
        "name": "fleercivet_mutex",
        "time": 0.0
      },
      {
        "name": "lokibot_mutexes",
        "time": 0.0
      },
      {
        "name": "ursnif_behavior",
        "time": 0.001
      },
      {
        "name": "uses_adfind",
        "time": 0.0
      },
      {
        "name": "uses_ms_protocol",
        "time": 0.0
      },
      {
        "name": "neshta_mutexes",
        "time": 0.0
      },
      {
        "name": "renamer_mutexes",
        "time": 0.0
      },
      {
        "name": "owa_web_shell_files",
        "time": 0.0
      },
      {
        "name": "web_shell_files",
        "time": 0.0
      },
      {
        "name": "web_shell_processes",
        "time": 0.0
      },
      {
        "name": "dotnet_csc_build",
        "time": 0.0
      },
      {
        "name": "mavinject_lolbin",
        "time": 0.0
      },
      {
        "name": "multiple_explorer_instances",
        "time": 0.0
      },
      {
        "name": "script_tool_executed",
        "time": 0.0
      },
      {
        "name": "suspicious_certutil_use",
        "time": 0.0
      },
      {
        "name": "suspicious_command_tools",
        "time": 0.0
      },
      {
        "name": "suspicious_mpcmdrun_use",
        "time": 0.0
      },
      {
        "name": "suspicious_ping_use",
        "time": 0.0
      },
      {
        "name": "uses_powershell_copyitem",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_appcmd",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_csvde_ldifde",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_cipher",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_clickonce",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_curl",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_dsquery",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_esentutl",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_finger",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_mode",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_ntdsutil",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_nltest",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_setx",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_xcopy",
        "time": 0.0
      },
      {
        "name": "wmic_command_suspicious",
        "time": 0.0
      },
      {
        "name": "scrcons_wmi_script_consumer",
        "time": 0.0
      },
      {
        "name": "allaple_mutexes",
        "time": 0.0
      }
    ],
    "reporting": [
      {
        "name": "BinGraph",
        "time": 0.0
      }
    ]
  },
  "target": {
    "category": "file",
    "file": {
      "name": "61e9d5c0727665e9ef3f3281",
      "path": "/opt/CAPEv2/storage/binaries/61e9d5c0727665e9ef3f328141397be47c65ed11ab621c644b5bbf1d67138403",
      "guest_paths": "",
      "size": 19968,
      "crc32": "BE3B83AB",
      "md5": "bdc8945f1d799c845408522e372d1dbd",
      "sha1": "874b7c3c97cc5b13b9dd172fec5a54bc1f258005",
      "sha256": "61e9d5c0727665e9ef3f328141397be47c65ed11ab621c644b5bbf1d67138403",
      "sha512": "4fa0ed4ef66e4c442f5fc628e8bfc8a4f84cb213210643996d9387027edb619c054f6104ac889ae77cece09f0304f95d5f20e14d66847e2d382ef51eecec0962",
      "rh_hash": null,
      "ssdeep": "192:VYLQui6h6p5WW3tZVTnlYJL/eLYLTr2/C8:VYLQu/6/fKqLYLTR",
      "type": "PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows",
      "yara": [
        {
          "name": "DITEKSHEN_MALWARE_Win_Nanocore",
          "meta": {
            "description": "Detects NanoCore",
            "author": "ditekSHen",
            "id": "931b98f6-df2b-538b-bc49-ecbbd24334da",
            "date": "2020-11-06",
            "modified": "2024-11-01",
            "reference": "https://github.com/ditekshen/detection",
            "source_url": "https://github.com/ditekshen/detection/blob/e76c93dcdedff04076380ffc60ea54e45b313635/yara/malware.yar#L7654-L7681",
            "license_url": "https://github.com/ditekshen/detection/blob/e76c93dcdedff04076380ffc60ea54e45b313635/LICENSE.txt",
            "logic_hash": "6336260e0af2b4b51338ee066f41b7c58aa134a6c03ca110db7e088edf2b65a7",
            "score": 75,
            "quality": 75,
            "tags": "FILE"
          },
          "strings": [
            "NanoCore.ClientPlugin",
            "NanoCore.ClientPluginHost",
            "IClientApp",
            "IClientData",
            "IClientNetwork",
            "IClientAppHost",
            "IClientDataHost",
            "IClientLoggingHost",
            "IClientNetworkHost",
            "IClientUIHost",
            "IClientNameObjectCollection",
            "IClientReadOnlyNameObjectCollection",
            "ClientPlugin",
            "get_ClientSettings",
            "get_Connected"
          ],
          "addresses": {
            "x2": 3640,
            "x3": 3701,
            "i1": 3674,
            "i2": 3662,
            "i3": 3625,
            "i4": 3779,
            "i5": 3685,
            "i6": 3760,
            "i7": 3727,
            "i8": 3746,
            "i9": 3794,
            "i10": 3831,
            "s1": 6025,
            "s6": 4601,
            "s7": 4681
          }
        },
        {
          "name": "Windows_Trojan_Nanocore_d8c4e3c5",
          "meta": {
            "author": "Elastic Security",
            "id": "d8c4e3c5-8bcc-43d2-9104-fa3774282da5",
            "fingerprint": "e5c284f14c1c650ef8ddd7caf314f5318e46a811addc2af5e70890390c7307d4",
            "creation_date": "2021-06-13",
            "last_modified": "2021-08-23",
            "threat_name": "Windows.Trojan.Nanocore",
            "reference_sample": "b2262126a955e306dc68487333394dc08c4fbd708a19afeb531f58916ddb1cfd",
            "severity": 100,
            "arch_context": "x86, arm64",
            "scan_context": "file, memory",
            "license": "Elastic License v2",
            "os": "windows"
          },
          "strings": [
            "NanoCore.ClientPluginHost",
            "NanoCore.ClientPlugin",
            "get_BuilderSettings",
            "IClientAppHost",
            "AddHostEntry",
            "LogClientException",
            "PipeExists",
            "IClientLoggingHost"
          ],
          "addresses": {
            "a1": 3701,
            "a2": 3640,
            "b1": 4620,
            "b4": 3779,
            "b6": 4733,
            "b7": 4844,
            "b8": 4705,
            "b9": 3760
          }
        },
        {
          "name": "Nanocore_RAT_Gen_2",
          "meta": {
            "description": "Detetcs the Nanocore RAT",
            "author": "Florian Roth",
            "score": 100,
            "reference": "https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/",
            "date": "2016-04-22",
            "hash1": "755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050"
          },
          "strings": [
            "NanoCore.ClientPluginHost",
            "IClientNetworkHost"
          ],
          "addresses": {
            "x1": 3701,
            "x2": 3727
          }
        },
        {
          "name": "NETDLLMicrosoft",
          "meta": {
            "author": "malware-lu"
          },
          "strings": [
            "{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }"
          ],
          "addresses": {
            "a0": 6858
          }
        },
        {
          "name": "IsPE32",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsNET_DLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsDLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsWindowsGUI",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "Microsoft_Visual_Studio_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 6894
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 6894
          }
        },
        {
          "name": "Microsoft_Visual_C_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 6894
          }
        },
        {
          "name": "Microsoft_Visual_Studio_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 6894
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 6894
          }
        },
        {
          "name": "NET_executable_",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 6894
          }
        },
        {
          "name": "NET_executable",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 6894
          }
        }
      ],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T1CA924D1362CE7DE6E5B916303B3387C1C72DDE041653DA2E16D87629E97E2833A523D8",
      "sha3_384": "34e76812c5bbcc4e39114f9560b049a9e8ac0f74800b55f33641134edf5dfb32ff8a420a55be3ca4c294e8d1f69db255",
      "yara_hash": "b833150b13e1662cfeb7589959edd288cf4e73710395ec5c5f2123f39a668f4d",
      "options_hash": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
      "pe": {
        "guest_signers": {
          "aux_sha1": null,
          "aux_timestamp": null,
          "aux_valid": false,
          "aux_error": true,
          "aux_error_desc": "No signature found.",
          "aux_signers": []
        },
        "digital_signers": [],
        "imagebase": "0x00400000",
        "entrypoint": "0x000038ee",
        "ep_bytes": "ff250020400000000000000000000000",
        "peid_signatures": null,
        "reported_checksum": "0x00000000",
        "actual_checksum": "0x0000721e",
        "osversion": "4.0",
        "machine_type": "IMAGE_FILE_MACHINE_I386",
        "pdbpath": null,
        "imports": {
          "mscoree": {
            "dll": "mscoree.dll",
            "imports": [
              {
                "address": "0x402000",
                "name": "_CorDllMain"
              }
            ]
          }
        },
        "exported_dll_name": null,
        "exports": [],
        "dirents": [
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
            "virtual_address": "0x0000389c",
            "size": "0x0000004f"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
            "virtual_address": "0x00004000",
            "size": "0x00002f58"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
            "virtual_address": "0x00008000",
            "size": "0x0000000c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_TLS",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IAT",
            "virtual_address": "0x00002000",
            "size": "0x00000008"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
            "virtual_address": "0x00002008",
            "size": "0x00000048"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          }
        ],
        "sections": [
          {
            "name": ".text",
            "raw_address": "0x00000200",
            "virtual_address": "0x00002000",
            "virtual_size": "0x000018f4",
            "size_of_data": "0x00001a00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x60000020",
            "entropy": "5.26"
          },
          {
            "name": ".rsrc",
            "raw_address": "0x00001c00",
            "virtual_address": "0x00004000",
            "virtual_size": "0x00002f58",
            "size_of_data": "0x00003000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x40000040",
            "entropy": "3.31"
          },
          {
            "name": ".reloc",
            "raw_address": "0x00004c00",
            "virtual_address": "0x00008000",
            "virtual_size": "0x0000000c",
            "size_of_data": "0x00000200",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "0.08"
          }
        ],
        "overlay": null,
        "resources": [
          {
            "name": "RT_ICON",
            "offset": "0x00004468",
            "size": "0x000002e8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.71"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00004750",
            "size": "0x00000128",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.08"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00004878",
            "size": "0x000008a8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.72"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00005120",
            "size": "0x00000568",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "1.05"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00005688",
            "size": "0x00000353",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "4.05"
          },
          {
            "name": "RT_ICON",
            "offset": "0x000059e0",
            "size": "0x000010a8",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.72"
          },
          {
            "name": "RT_ICON",
            "offset": "0x00006a88",
            "size": "0x00000468",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.76"
          },
          {
            "name": "RT_GROUP_ICON",
            "offset": "0x00006ef0",
            "size": "0x00000068",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "2.69"
          },
          {
            "name": "RT_VERSION",
            "offset": "0x00004208",
            "size": "0x0000025c",
            "filetype": null,
            "language": "LANG_NEUTRAL",
            "sublanguage": "SUBLANG_NEUTRAL",
            "entropy": "3.23"
          }
        ],
        "versioninfo": [
          {
            "name": "Translation",
            "value": "0x0000 0x04b0"
          },
          {
            "name": "FileDescription",
            "value": " "
          },
          {
            "name": "FileVersion",
            "value": "1.2.0.0"
          },
          {
            "name": "InternalName",
            "value": "ClientPlugin.dll"
          },
          {
            "name": "LegalCopyright",
            "value": " "
          },
          {
            "name": "OriginalFilename",
            "value": "ClientPlugin.dll"
          },
          {
            "name": "ProductVersion",
            "value": "1.2.0.0"
          },
          {
            "name": "Assembly Version",
            "value": "1.2.0.0"
          }
        ],
        "imphash": "dae02f32a21e03ce65412f6e56942daa",
        "timestamp": "2014-11-23 01:09:01",
        "icon": "iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAY0lEQVR4nO3XIQ6AMBBE0YH0eGuAcwKmZ1sLCkHRZUj4o9qaeVmzqfT3DJl5OAGjs1ySynWIiFeLa62SPjABAABK+7Cte9fCeZlud/sEAAAAAAAAADvgsY7bddk79gnwMSH2nLDUDvNx5OJLAAAAAElFTkSuQmCC",
        "icon_hash": "f66c7c86e9ab59ef3f289acd613a3738",
        "icon_fuzzy": "c3ca946d749a15ad18efd3e5d7b0d8f5",
        "icon_dhash": "454545d4d4d44503",
        "imported_dll_count": 1
      },
      "data": null,
      "strings": [
        "System.CodeDom.Compiler",
        "get_ClientSettings",
        "RestoreProtection",
        "mscoree.dll",
        "EntryExists",
        "params",
        "Assembly Version",
        "ClientPlugin.dll",
        "SendToServer",
        "RebuildHostCache",
        "m_Context",
        "KeyValuePair`2",
        "GetObjectValue",
        "set_Value",
        "TargetMethod",
        "My.Application",
        "1.2.0.0",
        "NanoCore.My",
        "IDATx",
        "Microsoft.VisualBasic.CompilerServices",
        "InternalName",
        "message",
        "System",
        "#Blob",
        "_CorDllMain",
        "System.Diagnostics",
        "MulticastDelegate",
        "ClientPlugin",
        "ComVisibleAttribute",
        "MyApplication",
        "IClientNameObjectCollection",
        "MyGroupCollectionAttribute",
        "EditorBrowsableAttribute",
        "pipeName",
        "AddHostEntry",
        "ParamArrayAttribute",
        "MyComputer",
        "BeginInvoke",
        ".ctor",
        "MyProject",
        "compress",
        "ThreadSafeObjectProvider`1",
        "LogClientException",
        "ConnectionStateChanged",
        "DebuggerHiddenAttribute",
        "System.ComponentModel",
        "ToString",
        "DelegateCallback",
        "instance",
        "wwwwwwwwwwwwww",
        "VarFileInfo",
        "LegalCopyright",
        "My.Computer",
        "get_Connected",
        "GetEntries",
        "AsyncCallback",
        "MyTemplate",
        "m_AppObjectProvider",
        "Restart",
        "System.Runtime.CompilerServices",
        "<Module>",
        "GetInstance",
        "Uninstall",
        "get_GetInstance",
        "Equals",
        "IAsyncResult",
        "wwwwww",
        "ClientSettingChanged",
        "EndInvoke",
        "My.User",
        "FileVersion",
        "ClientInvokeDelegate",
        "ContextValue`1",
        "SetValue",
        "IClientNetwork",
        "get_WebServices",
        "PipeCreated",
        "`.rsrc",
        ".text",
        "AssemblyFileVersionAttribute",
        "WebServices",
        "Invoke",
        "StringFileInfo",
        "LogClientMessage",
        "GuidAttribute",
        "NanoCore",
        "AssemblyTrademarkAttribute",
        "DelegateAsyncState",
        "v2.0.50727",
        "ProductVersion",
        "#Strings",
        "System.Collections.Generic",
        "System.ComponentModel.Design",
        "Microsoft.VisualBasic",
        "AssemblyProductAttribute",
        "ClientSettings",
        "FileDescription",
        "@.reloc",
        "ConnectionFailed",
        "IClientUIHost",
        "$d6e3c4d8-8560-4021-a765-fad7362f3388",
        "VariableChanged",
        "MyWebServices",
        "!This program cannot be run in DOS mode.",
        "ClosePipe",
        "My.WebServices",
        "Variables",
        "IClientLoggingHost",
        "GetHashCode",
        "IClientNetworkHost",
        "TargetObject",
        "AssemblyCompanyAttribute",
        "BuildingHostCache",
        "GetValue",
        "m_UserObjectProvider",
        "Connected",
        "IClientApp",
        "RuntimeCompatibilityAttribute",
        "Dispose__Instance__",
        "8.0.0.0",
        "CompilationRelaxationsAttribute",
        "get_Application",
        "IClientData",
        "Activator",
        "000004b0",
        "PipeExists",
        "state",
        "PluginUninstalling",
        "Application",
        "Translation",
        "mscorlib",
        "OriginalFilename",
        "RuntimeHelpers",
        "RemoveValue",
        "IClientReadOnlyNameObjectCollection",
        "get_User",
        "CreateInstance",
        "IClientAppHost",
        "HideModuleNameAttribute",
        "connected",
        "ReadPacket",
        "System.Runtime.InteropServices",
        "value",
        "VS_VERSION_INFO",
        "HelpKeywordAttribute",
        "get_Variables",
        "Create__Instance__",
        "Computer",
        "Disconnect",
        "Exception",
        "AssemblyTitleAttribute",
        "defaultValue",
        "ApplicationBase",
        "#GUID",
        "ClientUninstalling",
        "AssemblyDescriptionAttribute",
        "NanoCore.ClientPlugin",
        "IClientDataHost",
        "Object",
        "get_BuilderSettings",
        "method",
        "System.Reflection",
        "AssemblyCopyrightAttribute",
        "DisableProtection",
        "get_Value",
        "Microsoft.VisualBasic.Devices",
        "4System.Web.Services.Protocols.SoapHttpClientProtocol",
        "m_MyWebServicesObjectProvider",
        "m_ComputerObjectProvider",
        "BuilderSettings",
        "GeneratedCodeAttribute",
        "NanoCore.ClientPluginHost",
        "Shutdown",
        "DelegateAsyncResult",
        "RuntimeTypeHandle",
        "WrapNonExceptionThrows",
        "get_Computer",
        ".cctor",
        "GetType",
        "StandardModuleAttribute",
        "GetTypeFromHandle",
        "PipeClosed",
        "EditorBrowsableState",
        "Microsoft.VisualBasic.ApplicationServices",
        "Microsoft.VisualBasic.MyServices.Internal"
      ],
      "virustotal": {
        "error": true,
        "msg": "VT File lookup disabled in processing.conf"
      },
      "executed_tools": [
        "overlay",
        "msi_extract",
        "kixtart_extract",
        "vbe_extract",
        "batch_extract",
        "UnAutoIt_extract",
        "UPX_unpack",
        "RarSFX_extract",
        "Inno_extract",
        "SevenZip_unpack",
        "de4dot_deobfuscate",
        "eziriz_deobfuscate",
        "office_one"
      ],
      "cape_type_code": 0,
      "cape_type": ""
    }
  },
  "procdump": [
    {
      "name": "9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3",
      "path": "/opt/CAPEv2/storage/analyses/50/procdump/9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3",
      "guest_paths": "1;?C:\\Windows\\SysWOW64\\rundll32.exe;?C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll;?",
      "size": 7680,
      "crc32": "A45BF1B0",
      "md5": "08586ab761ab859d6860a2c7de3bebd2",
      "sha1": "8cea2f8166202b243f70ded0b9dfb7fce1518365",
      "sha256": "9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3",
      "sha512": "7ab3fd442e35dd3140aef27abe78bd2374623b9d4794c6325977ad4c35943861ff79a7d8e0dd361660d2bed1a8618379cbfa8aa7254b16021a934071a6560ba0",
      "rh_hash": null,
      "ssdeep": "96:QYLIkUui+Nqih6pe+WWLTtZE2F6lYlnlYJnLEM/m3bViL0KfrneR1P7ZXmrI:QYLQui6h6p5WW3tZVTnlYJL/eLYLTr2",
      "type": "PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows",
      "yara": [
        {
          "name": "DITEKSHEN_MALWARE_Win_Nanocore",
          "meta": {
            "description": "Detects NanoCore",
            "author": "ditekSHen",
            "id": "931b98f6-df2b-538b-bc49-ecbbd24334da",
            "date": "2020-11-06",
            "modified": "2024-11-01",
            "reference": "https://github.com/ditekshen/detection",
            "source_url": "https://github.com/ditekshen/detection/blob/e76c93dcdedff04076380ffc60ea54e45b313635/yara/malware.yar#L7654-L7681",
            "license_url": "https://github.com/ditekshen/detection/blob/e76c93dcdedff04076380ffc60ea54e45b313635/LICENSE.txt",
            "logic_hash": "6336260e0af2b4b51338ee066f41b7c58aa134a6c03ca110db7e088edf2b65a7",
            "score": 75,
            "quality": 75,
            "tags": "FILE"
          },
          "strings": [
            "NanoCore.ClientPlugin",
            "NanoCore.ClientPluginHost",
            "IClientApp",
            "IClientData",
            "IClientNetwork",
            "IClientAppHost",
            "IClientDataHost",
            "IClientLoggingHost",
            "IClientNetworkHost",
            "IClientUIHost",
            "IClientNameObjectCollection",
            "IClientReadOnlyNameObjectCollection",
            "ClientPlugin",
            "get_ClientSettings",
            "get_Connected"
          ],
          "addresses": {
            "x2": 4152,
            "x3": 4213,
            "i1": 4186,
            "i2": 4174,
            "i3": 4137,
            "i4": 4291,
            "i5": 4197,
            "i6": 4272,
            "i7": 4239,
            "i8": 4258,
            "i9": 4306,
            "i10": 4343,
            "s1": 6537,
            "s6": 5113,
            "s7": 5193
          }
        },
        {
          "name": "Windows_Trojan_Nanocore_d8c4e3c5",
          "meta": {
            "author": "Elastic Security",
            "id": "d8c4e3c5-8bcc-43d2-9104-fa3774282da5",
            "fingerprint": "e5c284f14c1c650ef8ddd7caf314f5318e46a811addc2af5e70890390c7307d4",
            "creation_date": "2021-06-13",
            "last_modified": "2021-08-23",
            "threat_name": "Windows.Trojan.Nanocore",
            "reference_sample": "b2262126a955e306dc68487333394dc08c4fbd708a19afeb531f58916ddb1cfd",
            "severity": 100,
            "arch_context": "x86, arm64",
            "scan_context": "file, memory",
            "license": "Elastic License v2",
            "os": "windows"
          },
          "strings": [
            "NanoCore.ClientPluginHost",
            "NanoCore.ClientPlugin",
            "get_BuilderSettings",
            "IClientAppHost",
            "AddHostEntry",
            "LogClientException",
            "PipeExists",
            "IClientLoggingHost"
          ],
          "addresses": {
            "a1": 4213,
            "a2": 4152,
            "b1": 5132,
            "b4": 4291,
            "b6": 5245,
            "b7": 5356,
            "b8": 5217,
            "b9": 4272
          }
        },
        {
          "name": "Nanocore_RAT_Gen_2",
          "meta": {
            "description": "Detetcs the Nanocore RAT",
            "author": "Florian Roth",
            "score": 100,
            "reference": "https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/",
            "date": "2016-04-22",
            "hash1": "755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050"
          },
          "strings": [
            "NanoCore.ClientPluginHost",
            "IClientNetworkHost"
          ],
          "addresses": {
            "x1": 4213,
            "x2": 4239
          }
        },
        {
          "name": "NETDLLMicrosoft",
          "meta": {
            "author": "malware-lu"
          },
          "strings": [
            "{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }"
          ],
          "addresses": {
            "a0": 7370
          }
        },
        {
          "name": "IsPE32",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsNET_DLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsDLL",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "IsWindowsGUI",
          "meta": {},
          "strings": [],
          "addresses": {}
        },
        {
          "name": "Microsoft_Visual_Studio_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 7406
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 7406
          }
        },
        {
          "name": "Microsoft_Visual_C_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 7406
          }
        },
        {
          "name": "Microsoft_Visual_Studio_NET_additional",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 7406
          }
        },
        {
          "name": "Microsoft_Visual_C_v70_Basic_NET",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 7406
          }
        },
        {
          "name": "NET_executable_",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "a": 7406
          }
        },
        {
          "name": "NET_executable",
          "meta": {},
          "strings": [
            "{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }"
          ],
          "addresses": {
            "b": 7406
          }
        }
      ],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T1F5F1D71AE3C0D2B6CF6A2372490399405BB2CB0932CBEF57159C9376C8D6B990B67167",
      "sha3_384": "db7d891351ab061a15580b9b986a987f3ad831454033bbe28ee8a1054c75e623a25d3c90c295d68347270bb4ff07ebee",
      "yara_hash": "b833150b13e1662cfeb7589959edd288cf4e73710395ec5c5f2123f39a668f4d",
      "options_hash": "44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a",
      "pe": {
        "guest_signers": {
          "aux_sha1": null,
          "aux_timestamp": null,
          "aux_valid": false,
          "aux_error": true,
          "aux_error_desc": "No signature found.",
          "aux_signers": []
        },
        "digital_signers": [],
        "imagebase": "0x00400000",
        "entrypoint": "0x000038ee",
        "ep_bytes": "ff250020400000000000000000000000",
        "peid_signatures": null,
        "reported_checksum": "0x00000000",
        "actual_checksum": "0x000069a1",
        "osversion": "4.0",
        "machine_type": "IMAGE_FILE_MACHINE_I386",
        "pdbpath": null,
        "imports": {
          "mscoree": {
            "dll": "mscoree.dll",
            "imports": [
              {
                "address": "0x402000",
                "name": "_CorDllMain"
              }
            ]
          }
        },
        "exported_dll_name": null,
        "exports": [],
        "dirents": [
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
            "virtual_address": "0x0000389c",
            "size": "0x0000004f"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
            "virtual_address": "0x00004000",
            "size": "0x00002f58"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
            "virtual_address": "0x00008000",
            "size": "0x0000000c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_TLS",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IAT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
            "virtual_address": "0x00002008",
            "size": "0x00000048"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          }
        ],
        "sections": [
          {
            "name": ".text",
            "raw_address": "0x00000400",
            "virtual_address": "0x00002000",
            "virtual_size": "0x00002000",
            "size_of_data": "0x00001a00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
            "characteristics_raw": "0xe0000020",
            "entropy": "5.26"
          },
          {
            "name": ".rsrc",
            "raw_address": "0x00001e00",
            "virtual_address": "0x00004000",
            "virtual_size": "0x00004000",
            "size_of_data": "0x00000000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x40000040",
            "entropy": "0.00"
          },
          {
            "name": ".reloc",
            "raw_address": "0x00001e00",
            "virtual_address": "0x00008000",
            "virtual_size": "0x00002000",
            "size_of_data": "0x00000000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "0.00"
          }
        ],
        "overlay": null,
        "resources": [],
        "versioninfo": [],
        "imphash": "dae02f32a21e03ce65412f6e56942daa",
        "timestamp": "2014-11-23 01:09:01",
        "icon": null,
        "icon_hash": null,
        "icon_fuzzy": null,
        "icon_dhash": null,
        "imported_dll_count": 1
      },
      "data": null,
      "strings": [
        "System.CodeDom.Compiler",
        "get_ClientSettings",
        "RestoreProtection",
        "mscoree.dll",
        "EntryExists",
        "params",
        "ClientPlugin.dll",
        "SendToServer",
        "RebuildHostCache",
        "m_Context",
        "KeyValuePair`2",
        "GetObjectValue",
        "set_Value",
        "TargetMethod",
        "My.Application",
        "1.2.0.0",
        "NanoCore.My",
        "Microsoft.VisualBasic.CompilerServices",
        "message",
        "System",
        "#Blob",
        "_CorDllMain",
        "System.Diagnostics",
        "MulticastDelegate",
        "ClientPlugin",
        "ComVisibleAttribute",
        "MyApplication",
        "IClientNameObjectCollection",
        "MyGroupCollectionAttribute",
        "EditorBrowsableAttribute",
        "pipeName",
        "AddHostEntry",
        "ParamArrayAttribute",
        "MyComputer",
        "BeginInvoke",
        ".ctor",
        "MyProject",
        "compress",
        "ThreadSafeObjectProvider`1",
        "LogClientException",
        "ConnectionStateChanged",
        "DebuggerHiddenAttribute",
        "System.ComponentModel",
        "ToString",
        "DelegateCallback",
        "instance",
        "My.Computer",
        "get_Connected",
        "GetEntries",
        "AsyncCallback",
        "MyTemplate",
        "m_AppObjectProvider",
        "Restart",
        "System.Runtime.CompilerServices",
        "<Module>",
        "GetInstance",
        "Uninstall",
        "get_GetInstance",
        "Equals",
        "IAsyncResult",
        "ClientSettingChanged",
        "EndInvoke",
        "My.User",
        "ClientInvokeDelegate",
        "ContextValue`1",
        "SetValue",
        "IClientNetwork",
        "get_WebServices",
        "PipeCreated",
        ".text",
        "AssemblyFileVersionAttribute",
        "WebServices",
        "Invoke",
        "LogClientMessage",
        "GuidAttribute",
        "NanoCore",
        "AssemblyTrademarkAttribute",
        "DelegateAsyncState",
        "v2.0.50727",
        "#Strings",
        "System.Collections.Generic",
        "System.ComponentModel.Design",
        "Microsoft.VisualBasic",
        "AssemblyProductAttribute",
        "ClientSettings",
        "@.reloc",
        "ConnectionFailed",
        "IClientUIHost",
        "$d6e3c4d8-8560-4021-a765-fad7362f3388",
        ".rsrc",
        "VariableChanged",
        "MyWebServices",
        "!This program cannot be run in DOS mode.",
        "ClosePipe",
        "My.WebServices",
        "Variables",
        "IClientLoggingHost",
        "GetHashCode",
        "IClientNetworkHost",
        "TargetObject",
        "AssemblyCompanyAttribute",
        "BuildingHostCache",
        "GetValue",
        "m_UserObjectProvider",
        "Connected",
        "IClientApp",
        "RuntimeCompatibilityAttribute",
        "Dispose__Instance__",
        "8.0.0.0",
        "CompilationRelaxationsAttribute",
        "get_Application",
        "IClientData",
        "Activator",
        "PipeExists",
        "state",
        "Application",
        "PluginUninstalling",
        "mscorlib",
        "RuntimeHelpers",
        "RemoveValue",
        "IClientReadOnlyNameObjectCollection",
        "get_User",
        "CreateInstance",
        "IClientAppHost",
        "HideModuleNameAttribute",
        "connected",
        "ReadPacket",
        "System.Runtime.InteropServices",
        "value",
        "HelpKeywordAttribute",
        "get_Variables",
        "Create__Instance__",
        "Computer",
        "Disconnect",
        "Exception",
        "AssemblyTitleAttribute",
        "defaultValue",
        "ApplicationBase",
        "#GUID",
        "ClientUninstalling",
        "AssemblyDescriptionAttribute",
        "NanoCore.ClientPlugin",
        "IClientDataHost",
        "Object",
        "get_BuilderSettings",
        "method",
        "System.Reflection",
        "AssemblyCopyrightAttribute",
        "DisableProtection",
        "get_Value",
        "Microsoft.VisualBasic.Devices",
        "4System.Web.Services.Protocols.SoapHttpClientProtocol",
        "m_MyWebServicesObjectProvider",
        "m_ComputerObjectProvider",
        "BuilderSettings",
        "GeneratedCodeAttribute",
        "NanoCore.ClientPluginHost",
        "Shutdown",
        "DelegateAsyncResult",
        "RuntimeTypeHandle",
        "WrapNonExceptionThrows",
        "get_Computer",
        ".cctor",
        "GetType",
        "StandardModuleAttribute",
        "GetTypeFromHandle",
        "PipeClosed",
        "EditorBrowsableState",
        "Microsoft.VisualBasic.ApplicationServices",
        "Microsoft.VisualBasic.MyServices.Internal"
      ],
      "virustotal": {
        "error": true,
        "msg": "VT File lookup disabled in processing.conf"
      },
      "executed_tools": [
        "overlay",
        "msi_extract",
        "kixtart_extract",
        "vbe_extract",
        "batch_extract",
        "UnAutoIt_extract",
        "UPX_unpack",
        "RarSFX_extract",
        "Inno_extract",
        "SevenZip_unpack",
        "de4dot_deobfuscate",
        "eziriz_deobfuscate",
        "office_one"
      ],
      "cape_type_code": 1,
      "cape_type": "",
      "process_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
      "process_name": "rundll32.exe",
      "module_path": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll",
      "pid": 2200
    }
  ],
  "CAPE": {
    "payloads": [],
    "configs": []
  },
  "info": {
    "version": "2.5",
    "started": "2026-04-28 01:00:26",
    "ended": "2026-04-28 01:05:34",
    "duration": 308,
    "id": 50,
    "category": "file",
    "custom": "",
    "machine": {
      "id": 43,
      "status": "stopping",
      "name": "win10x64",
      "label": "win10x64",
      "platform": "windows",
      "manager": "KVM",
      "started_on": "2026-04-28 01:00:26",
      "shutdown_on": "2026-04-28 01:05:34"
    },
    "package": "dll",
    "timeout": true,
    "tlp": null,
    "parent_sample": null,
    "options": {},
    "source_url": null,
    "route": "",
    "user_id": 0,
    "CAPE_current_commit": "a9a0887dab232f52c59e955b9984dd494c47ce6b"
  },
  "behavior": {
    "processes": [
      {
        "process_id": 2200,
        "process_name": "rundll32.exe",
        "parent_id": 3592,
        "module_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
        "first_seen": "2026-04-27 22:03:17,629",
        "calls": [
          {
            "timestamp": "2026-04-27 22:03:18,363",
            "thread_id": "1416",
            "caller": "0x77274faa",
            "parentcaller": "0x77514cce",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-04-27 22:03:18,363",
            "thread_id": "1416",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetThreadContext"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ae38d0"
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-04-27 22:03:18,363",
            "thread_id": "1416",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetThreadTimes"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad1f70"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "IsProcessorFeaturePresent"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0b70"
              }
            ],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "OpenThread"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76acf5b0"
              }
            ],
            "repeated": 0,
            "id": 4
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "ProcessIdToSessionId"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0b90"
              }
            ],
            "repeated": 0,
            "id": 5
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "SetProcessShutdownParameters"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ac9540"
              }
            ],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "SetThreadContext"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ae4d20"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x772696ea",
            "parentcaller": "0x77514c2c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76ab0000"
              },
              {
                "name": "FunctionName",
                "value": "GetProcessId"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76ad0c20"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x77274faa",
            "parentcaller": "0x77514d2f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x77274faa",
            "parentcaller": "0x77514cce",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x77274faa",
            "parentcaller": "0x77514d2f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x77525000"
              },
              {
                "name": "ModuleName",
                "value": "imagehlp.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x77e7007d",
            "parentcaller": "0x7726648d",
            "category": "system",
            "api": "NtQueryLicenseValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Name",
                "value": "TerminalServices-RemoteConnectionManager-AllowAppServerMode"
              },
              {
                "name": "Type",
                "value": "0x00000004"
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x77e7007d",
            "parentcaller": "0x7726648d",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume1\\Windows\\SysWOW64\\imagehlp"
              },
              {
                "name": "BaseAddress",
                "value": "0x77510000"
              },
              {
                "name": "InitRoutine",
                "value": "0x77516560"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1684",
            "caller": "0x77e91c0e",
            "parentcaller": "0x77e8dbb1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000007c"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 3,
            "id": 16
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x00085f1a",
            "parentcaller": "0x00085fdd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x035b3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x00085f1a",
            "parentcaller": "0x00085fdd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x035b4000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "3888",
            "caller": "0x77e80857",
            "parentcaller": "0x77e8055f",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x035b5000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x00084168",
            "parentcaller": "0x00086078",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "34",
                "pretty_value": "ProcessExecuteFlags"
              },
              {
                "name": "ProcessInformation",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "1416",
            "caller": "0x000840d8",
            "parentcaller": "0x000841fe",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "3888",
            "caller": "0x77e7138f",
            "parentcaller": "0x77e7110a",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000009",
                "pretty_value": "KEY_QUERY_VALUE|KEY_ENUMERATE_SUB_KEYS"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\Session Manager"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-04-27 22:03:18,379",
            "thread_id": "3888",
            "caller": "0x77e713ac",
            "parentcaller": "0x77e7110a",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c4"
              },
              {
                "name": "ValueName",
                "value": "ResourcePolicies"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\ResourcePolicies"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "3888",
            "caller": "0x77e713c2",
            "parentcaller": "0x77e7110a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "3888",
            "caller": "0x77e6f04b",
            "parentcaller": "0x77e6ef40",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x032e0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00008000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "3888",
            "caller": "0x77e6f092",
            "parentcaller": "0x77e6ef40",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x032e0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "3888",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "3888",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "1684",
            "caller": "0x77e80857",
            "parentcaller": "0x77e8055f",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x035b9000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "1684",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "1684",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "5676",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "5676",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "5404",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-04-27 22:03:18,394",
            "thread_id": "5404",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03580000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000a000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b4"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll.123.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-04-27 22:03:18,551",
            "thread_id": "1416",
            "caller": "0x00085a1d",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03580000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03580000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000a000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll.124.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a3e",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03580000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002b8"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x40000003",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03580000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x0000a000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-04-27 22:03:18,566",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll.2.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085a5f",
            "parentcaller": "0x000842a3",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03580000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085abb",
            "parentcaller": "0x000842a3",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085abb",
            "parentcaller": "0x000842a3",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c4"
              },
              {
                "name": "ValueName",
                "value": "PreferExternalManifest"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085abb",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-04-27 22:03:18,582",
            "thread_id": "1416",
            "caller": "0x00085abb",
            "parentcaller": "0x000842a3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00120089",
                "pretty_value": "FILE_GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\rundll32.exe"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-04-27 22:03:18,597",
            "thread_id": "1416",
            "caller": "0x00085abb",
            "parentcaller": "0x000842a3",
            "category": "__notification__",
            "api": "sysenter",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadIdentifier",
                "value": "1416"
              },
              {
                "name": "Module",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "Return Address",
                "value": "0x76ad24ac"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00085abb",
            "parentcaller": "0x000842a3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00085d94",
            "parentcaller": "0x000842ae",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00085d1d",
            "parentcaller": "0x00085db9",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "18"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00085d42",
            "parentcaller": "0x00085db9",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "20"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00085dc4",
            "parentcaller": "0x000842ae",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083c8d",
            "parentcaller": "0x00083e97",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281"
              },
              {
                "name": "DllBase",
                "value": "0x03590000"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083c8d",
            "parentcaller": "0x00083e97",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x03590000"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083d51",
            "parentcaller": "0x00083e97",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "34",
                "pretty_value": "ProcessExecuteFlags"
              },
              {
                "name": "ProcessInformation",
                "value": "13"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083da6",
            "parentcaller": "0x00083eb2",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": false,
            "return": "0xffffffffc0000138",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "61e9d5c0727665e9ef3f3281.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x03590000"
              },
              {
                "name": "FunctionName",
                "value": ""
              },
              {
                "name": "Ordinal",
                "value": "1"
              },
              {
                "name": "FunctionAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031e0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000fc"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000fc"
              },
              {
                "name": "ValueName",
                "value": "Latest"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-04-27 22:03:18,629",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000fc"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-04-27 22:03:18,644",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-04-27 22:03:18,644",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-04-27 22:03:18,644",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031e0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x0307ea38"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-04-27 22:03:18,644",
            "thread_id": "1416",
            "caller": "0x00083924",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-04-27 22:03:18,644",
            "thread_id": "1416",
            "caller": "0x00085e77",
            "parentcaller": "0x000869af",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x0008b000"
              },
              {
                "name": "ModuleName",
                "value": "rundll32.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-04-27 22:03:18,644",
            "thread_id": "1416",
            "caller": "0x00085e77",
            "parentcaller": "0x000869af",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x0008b000"
              },
              {
                "name": "ModuleName",
                "value": "rundll32.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-04-27 22:03:18,722",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "__notification__",
            "api": "sysenter",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadIdentifier",
                "value": "1416"
              },
              {
                "name": "Module",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "Return Address",
                "value": "0x772833ec"
              }
            ],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-04-27 22:03:18,879",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\TextShaping"
              },
              {
                "name": "DllBase",
                "value": "0x73ac0000"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-04-27 22:03:18,988",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\uxtheme"
              },
              {
                "name": "DllBase",
                "value": "0x745d0000"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-04-27 22:03:18,988",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\uxtheme.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x745d0000"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-04-27 22:03:19,144",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\MSCTF"
              },
              {
                "name": "DllBase",
                "value": "0x76ba0000"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-04-27 22:03:19,191",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\kernel.appcore"
              },
              {
                "name": "DllBase",
                "value": "0x75250000"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-04-27 22:03:19,285",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\bcryptPrimitives"
              },
              {
                "name": "DllBase",
                "value": "0x76d80000"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-04-27 22:03:19,472",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\ntmarta"
              },
              {
                "name": "DllBase",
                "value": "0x736b0000"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-04-27 22:03:19,472",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\CoreMessaging"
              },
              {
                "name": "DllBase",
                "value": "0x736e0000"
              }
            ],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-04-27 22:03:19,488",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\wintypes"
              },
              {
                "name": "DllBase",
                "value": "0x735d0000"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-04-27 22:03:19,488",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\CoreUIComponents"
              },
              {
                "name": "DllBase",
                "value": "0x73780000"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-04-27 22:03:19,488",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\textinputframework"
              },
              {
                "name": "DllBase",
                "value": "0x73a00000"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-04-27 22:03:19,566",
            "thread_id": "1416",
            "caller": "0x00083a40",
            "parentcaller": "0x00083f58",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76ab0000"
              }
            ],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-04-27 22:03:49,379",
            "thread_id": "7348",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-04-27 22:03:49,379",
            "thread_id": "7348",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-04-27 22:03:49,379",
            "thread_id": "7348",
            "caller": "0x77271454",
            "parentcaller": "0x7693b5fa",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000348"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-04-27 22:03:49,379",
            "thread_id": "7348",
            "caller": "0x76938f18",
            "parentcaller": "0x76938dcd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-04-27 22:03:49,379",
            "thread_id": "2480",
            "caller": "0x77ea64d6",
            "parentcaller": "0x77ea63e1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-04-27 22:03:49,379",
            "thread_id": "2480",
            "caller": "0x00000000",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "RtlUserThreadStart",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "StartAddress",
                "value": "0x00000000"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-04-27 22:04:17,176",
            "thread_id": "3060",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "3060"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-04-27 22:04:17,176",
            "thread_id": "3060",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-04-27 22:04:17,176",
            "thread_id": "6936",
            "caller": "0x77eab5a6",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "6936"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-04-27 22:04:17,176",
            "thread_id": "6936",
            "caller": "0x77eab5c9",
            "parentcaller": "0x77e760fc",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 112
          }
        ],
        "threads": [
          "1416",
          "1684",
          "3888",
          "5676",
          "5404",
          "7348",
          "2480",
          "3060",
          "6936"
        ],
        "environ": {
          "UserName": "cape",
          "ComputerName": "DESKTOP-PC01",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Users\\cape\\AppData\\Local\\Temp\\",
          "CommandLine": "\"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll\",#1",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "7c6d-8d48",
          "SystemVolumeGUID": "c48439d1-0000-0000-0000-100000000000",
          "MachineGUID": "",
          "MainExeBase": "0x00080000",
          "MainExeSize": "0x00014000",
          "Bitness": "32-bit",
          "DllBase": "0x03590000"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      }
    ],
    "anomaly": [],
    "processtree": [
      {
        "name": "rundll32.exe",
        "pid": 2200,
        "parent_id": 3592,
        "module_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
        "children": [],
        "threads": [
          "1416",
          "1684",
          "3888",
          "5676",
          "5404",
          "7348",
          "2480",
          "3060",
          "6936"
        ],
        "environ": {
          "UserName": "cape",
          "ComputerName": "DESKTOP-PC01",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Users\\cape\\AppData\\Local\\Temp\\",
          "CommandLine": "\"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll\",#1",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "7c6d-8d48",
          "SystemVolumeGUID": "c48439d1-0000-0000-0000-100000000000",
          "MachineGUID": "",
          "MainExeBase": "0x00080000",
          "MainExeSize": "0x00014000",
          "Bitness": "32-bit",
          "DllBase": "0x03590000"
        }
      }
    ],
    "summary": {
      "files": [
        "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll.123.Manifest",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll.124.Manifest",
        "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll.2.Manifest",
        "C:\\Windows\\SysWOW64\\rundll32.exe",
        "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\\Windows\\System32\\ru-RU\\rundll32.exe.mui"
      ],
      "read_files": [],
      "write_files": [],
      "delete_files": [],
      "keys": [
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\ResourcePolicies",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\SideBySide",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
      ],
      "read_keys": [
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\ResourcePolicies",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest"
      ],
      "write_keys": [],
      "delete_keys": [],
      "executed_commands": [],
      "resolved_apis": [],
      "mutexes": [],
      "created_services": [],
      "started_services": []
    },
    "enhanced": [
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-27 22:03:18,379",
        "eid": 1,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\ResourcePolicies",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-27 22:03:18,551",
        "eid": 2,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-27 22:03:18,566",
        "eid": 3,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-27 22:03:18,582",
        "eid": 4,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-27 22:03:18,582",
        "eid": 5,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\SideBySide\\PreferExternalManifest",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-27 22:03:18,629",
        "eid": 6,
        "data": {
          "file": "C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll",
          "pathtofile": null,
          "moduleaddress": "0x03590000"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-04-27 22:03:18,629",
        "eid": 7,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU\\Latest",
          "content": "C:\\Program Files\\WindowsApps\\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-27 22:03:18,988",
        "eid": 8,
        "data": {
          "file": "C:\\Windows\\System32\\uxtheme.dll",
          "pathtofile": null,
          "moduleaddress": "0x745d0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-04-27 22:03:19,566",
        "eid": 9,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76ab0000"
        }
      }
    ],
    "encryptedbuffers": [],
    "network_map": {
      "endpoint_map": {},
      "http_host_map": {},
      "dns_intents": {},
      "http_requests": [],
      "winhttp_sessions": []
    }
  },
  "debug": {
    "log": "2026-03-05 20:34:41,335 [root] INFO: Date set to: 20260428T01:01:36, timeout set to: 120\n2026-04-28 01:01:36,257 [root] DEBUG: Starting analyzer from: C:\\ltb6yatm\n2026-04-28 01:01:36,319 [root] DEBUG: Storing results at: C:\\sQCNRNV\n2026-04-28 01:01:36,335 [root] DEBUG: Pipe server name: \\\\.\\PIPE\\nBCsDBR\n2026-04-28 01:01:36,335 [root] DEBUG: Python path: C:\\Python310\n2026-04-28 01:01:36,351 [root] INFO: analysis running as an admin\n2026-04-28 01:01:36,351 [root] INFO: analysis package specified: \"dll\"\n2026-04-28 01:01:36,351 [root] DEBUG: importing analysis package module: \"modules.packages.dll\"...\n2026-04-28 01:01:36,366 [root] DEBUG: imported analysis package \"dll\"\n2026-04-28 01:01:36,366 [root] DEBUG: initializing analysis package \"dll\"...\n2026-04-28 01:01:36,366 [lib.common.common] INFO: wrapping\n2026-04-28 01:01:37,210 [lib.core.compound] INFO: C:\\Users\\cape\\AppData\\Local\\Temp already exists, skipping creation\n2026-04-28 01:01:37,226 [root] DEBUG: New location of moved file: C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281\n2026-04-28 01:01:37,226 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL option\n2026-04-28 01:01:37,226 [root] INFO: Analyzer: Package modules.packages.dll does not specify a DLL_64 option\n2026-04-28 01:01:37,226 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader option\n2026-04-28 01:01:37,226 [root] INFO: Analyzer: Package modules.packages.dll does not specify a loader_64 option\n2026-04-28 01:01:37,241 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.browser\"\n2026-04-28 01:01:38,007 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.digisig\"\n2026-04-28 01:01:38,038 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.disguise\"\n2026-04-28 01:01:38,085 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.human\"\n2026-04-28 01:01:38,163 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'\n2026-04-28 01:01:38,570 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'\n2026-04-28 01:01:38,633 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'\n2026-04-28 01:01:41,194 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance\n2026-04-28 01:01:41,194 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.screenshots\"\n2026-04-28 01:01:41,194 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.tlsdump\"\n2026-04-28 01:01:41,194 [root] DEBUG: Initialized auxiliary module \"Browser\"\n2026-04-28 01:01:41,194 [root] DEBUG: attempting to configure 'Browser' from data\n2026-04-28 01:01:41,210 [root] DEBUG: module Browser does not support data configuration, ignoring\n2026-04-28 01:01:41,210 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.browser\"...\n2026-04-28 01:01:41,210 [root] DEBUG: Started auxiliary module modules.auxiliary.browser\n2026-04-28 01:01:41,210 [root] DEBUG: Initialized auxiliary module \"DigiSig\"\n2026-04-28 01:01:41,210 [root] DEBUG: attempting to configure 'DigiSig' from data\n2026-04-28 01:01:41,210 [root] DEBUG: module DigiSig does not support data configuration, ignoring\n2026-04-28 01:01:41,210 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.digisig\"...\n2026-04-28 01:01:41,210 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature\n2026-04-28 01:01:42,195 [modules.auxiliary.digisig] DEBUG: File is not signed\n2026-04-28 01:01:42,195 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json\n2026-04-28 01:01:42,226 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig\n2026-04-28 01:01:42,226 [root] DEBUG: Initialized auxiliary module \"Disguise\"\n2026-04-28 01:01:42,226 [root] DEBUG: attempting to configure 'Disguise' from data\n2026-04-28 01:01:42,226 [root] DEBUG: module Disguise does not support data configuration, ignoring\n2026-04-28 01:01:42,226 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.disguise\"...\n2026-04-28 01:01:42,335 [modules.auxiliary.disguise] INFO: Disguising GUID to 80383195-5b8c-41eb-a60c-d69b37821b65\n2026-04-28 01:01:42,335 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise\n2026-04-28 01:01:42,351 [root] DEBUG: Initialized auxiliary module \"Human\"\n2026-04-28 01:01:42,351 [root] DEBUG: attempting to configure 'Human' from data\n2026-04-28 01:01:42,351 [root] DEBUG: module Human does not support data configuration, ignoring\n2026-04-28 01:01:42,351 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.human\"...\n2026-04-28 01:01:42,351 [root] DEBUG: Started auxiliary module modules.auxiliary.human\n2026-04-28 01:01:42,351 [root] DEBUG: Initialized auxiliary module \"Screenshots\"\n2026-04-28 01:01:42,351 [root] DEBUG: attempting to configure 'Screenshots' from data\n2026-04-28 01:01:42,351 [root] DEBUG: module Screenshots does not support data configuration, ignoring\n2026-04-28 01:01:42,351 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.screenshots\"...\n2026-04-28 01:01:42,538 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots\n2026-04-28 01:01:42,538 [root] DEBUG: Initialized auxiliary module \"TLSDumpMasterSecrets\"\n2026-04-28 01:01:42,554 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data\n2026-04-28 01:01:42,570 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring\n2026-04-28 01:01:42,570 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.tlsdump\"...\n2026-04-28 01:01:42,585 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644\n2026-04-28 01:01:42,710 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\\ltb6yatm\\dll\\644.ini\n2026-04-28 01:01:42,710 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor\n2026-04-28 01:01:42,741 [lib.api.process] INFO: 64-bit DLL to inject is C:\\ltb6yatm\\dll\\Elzpnma.dll, loader C:\\ltb6yatm\\bin\\tAVrvhgN.exe\n2026-04-28 01:01:42,882 [root] DEBUG: Loader: Injecting process 644 with C:\\ltb6yatm\\dll\\Elzpnma.dll.\n2026-04-28 01:01:59,367 [root] DEBUG: 644: Python path set to 'C:\\Python310'.\n2026-04-28 01:01:59,367 [root] DEBUG: 644: Disabling sleep skipping.\n2026-04-28 01:01:59,382 [root] DEBUG: 644: TLS secret dump mode enabled.\n2026-04-28 01:02:01,429 [root] DEBUG: 644: Yara error: Scanning timed out\n2026-04-28 01:02:01,429 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABE10000, thread 5048, image base 0x00007FF7C23E0000, stack from 0x0000008E4CA71000-0x0000008E4CA80000\n2026-04-28 01:02:01,460 [root] DEBUG: 644: Commandline: C:\\Windows\\system32\\lsass.exe\n2026-04-28 01:02:01,523 [root] DEBUG: 644: Hooked 5 out of 5 functions\n2026-04-28 01:02:01,523 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.\n2026-04-28 01:02:01,538 [root] DEBUG: Successfully injected DLL C:\\ltb6yatm\\dll\\Elzpnma.dll.\n2026-04-28 01:02:01,538 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>\n2026-04-28 01:02:01,538 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump\n2026-04-28 01:02:06,382 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\\sQCNRNV\\tlsdump\\tlsdump.log\n2026-04-28 01:02:40,726 [root] INFO: Restarting WMI Service\n2026-04-28 01:02:42,835 [root] DEBUG: package modules.packages.dll does not support configure, ignoring\n2026-04-28 01:02:42,835 [root] WARNING: configuration error for package modules.packages.dll: error importing data.packages.dll: No module named 'data.packages'\n2026-04-28 01:03:14,335 [lib.common.common] INFO: Submitted file is missing extension, adding .dll\n2026-04-28 01:03:14,413 [lib.core.compound] INFO: C:\\Users\\cape\\AppData\\Local\\Temp already exists, skipping creation\n2026-04-28 01:03:14,663 [lib.api.process] INFO: Successfully executed process from path \"C:\\Windows\\System32\\rundll32.exe\" with arguments \"\"C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll\",#1\" with pid 2200\n2026-04-28 01:03:14,663 [lib.api.process] INFO: Monitor config for <Process 2200 rundll32.exe>: C:\\ltb6yatm\\dll\\2200.ini\n2026-04-28 01:03:14,679 [lib.api.process] INFO: 32-bit DLL to inject is C:\\ltb6yatm\\dll\\iteBJUYL.dll, loader C:\\ltb6yatm\\bin\\njAvMNz.exe\n2026-04-28 01:03:14,976 [root] DEBUG: Loader: Injecting process 2200 (thread 1416) with C:\\ltb6yatm\\dll\\iteBJUYL.dll.\n2026-04-28 01:03:15,022 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-04-28 01:03:15,022 [root] DEBUG: Successfully injected DLL C:\\ltb6yatm\\dll\\iteBJUYL.dll.\n2026-04-28 01:03:15,038 [lib.api.process] INFO: Injected into 32-bit <Process 2200 rundll32.exe>\n2026-04-28 01:03:17,053 [lib.api.process] INFO: Successfully resumed <Process 2200 rundll32.exe>\n2026-04-28 01:03:17,511 [root] DEBUG: 2200: Python path set to 'C:\\Python310'.\n2026-04-28 01:03:17,543 [root] DEBUG: 2200: Disabling sleep skipping.\n2026-04-28 01:03:17,551 [root] DEBUG: 2200: Dropped file limit defaulting to 100.\n2026-04-28 01:03:17,650 [root] DEBUG: 2200: YaraInit: Compiled 44 rule files\n2026-04-28 01:03:17,672 [root] DEBUG: 2200: YaraInit: Compiled rules saved to file C:\\ltb6yatm\\data\\yara\\capemon.yac\n2026-04-28 01:03:17,672 [root] DEBUG: 2200: YaraScan: Scanning 0x00080000, size 0x136e8\n2026-04-28 01:03:17,683 [root] DEBUG: 2200: Monitor initialised: 32-bit capemon loaded in process 2200 at 0x73b60000, thread 1416, image base 0x80000, stack from 0x3072000-0x3080000\n2026-04-28 01:03:17,693 [root] DEBUG: 2200: Commandline: \"C:\\Windows\\System32\\rundll32.exe\" \"C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281.dll\",#1\n2026-04-28 01:03:17,948 [root] DEBUG: 2200: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress\n2026-04-28 01:03:18,017 [root] DEBUG: 2200: hook_api: Warning - CreateProcessA export address 0x76AE2D90 differs from GetProcAddress -> 0x73EF22A0 (AcLayers.DLL::0xfd4422a0)\n2026-04-28 01:03:18,017 [root] DEBUG: 2200: hook_api: Warning - CreateProcessW export address 0x76AC88E0 differs from GetProcAddress -> 0x73EF24E0 (AcLayers.DLL::0xfd4424e0)\n2026-04-28 01:03:18,017 [root] DEBUG: 2200: hook_api: Warning - WinExec export address 0x76B0CF20 differs from GetProcAddress -> 0x73EF27A0 (AcLayers.DLL::0xfd4427a0)\n2026-04-28 01:03:18,134 [root] WARNING: b'Unable to place hook on GetCommandLineA'\n2026-04-28 01:03:18,166 [root] DEBUG: 2200: set_hooks: Unable to hook GetCommandLineA\n2026-04-28 01:03:18,166 [root] WARNING: b'Unable to place hook on GetCommandLineW'\n2026-04-28 01:03:18,181 [root] DEBUG: 2200: set_hooks: Unable to hook GetCommandLineW\n2026-04-28 01:03:18,336 [root] DEBUG: 2200: Hooked 630 out of 632 functions\n2026-04-28 01:03:18,352 [root] DEBUG: 2200: Syscall hook installed, syscall logging level 1\n2026-04-28 01:03:18,368 [root] DEBUG: 2200: RestoreHeaders: Restored original import table.\n2026-04-28 01:03:18,368 [root] INFO: Loaded monitor into process with pid 2200\n2026-04-28 01:03:18,383 [root] DEBUG: 2200: caller_dispatch: Added region at 0x00080000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00085F1A, thread 1416).\n2026-04-28 01:03:18,383 [root] DEBUG: 2200: YaraScan: Scanning 0x00080000, size 0x136e8\n2026-04-28 01:03:18,383 [root] DEBUG: 2200: ProcessImageBase: Main module image at 0x00080000 unmodified (entropy change 0.000000e+00)\n2026-04-28 01:03:18,601 [root] DEBUG: 2200: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 1416).\n2026-04-28 01:03:18,616 [root] DEBUG: 2200: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \\Device\\HarddiskVolume1\\Windows\\SysWOW64\\kernel32.dll is in known range, skipping\n2026-04-28 01:03:18,623 [root] DEBUG: 2200: Target DLL loaded at 0x03590000: C:\\Users\\cape\\AppData\\Local\\Temp\\61e9d5c0727665e9ef3f3281 (0xa000 bytes).\n2026-04-28 01:03:18,623 [root] DEBUG: 2200: YaraScan: Scanning 0x03590000, size 0x1f0\n2026-04-28 01:03:18,856 [root] DEBUG: 2200: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 1416).\n2026-04-28 01:03:18,856 [root] DEBUG: 2200: ProcessTrackedRegion: Region at 0x77150000 mapped as \\Device\\HarddiskVolume1\\Windows\\SysWOW64\\KernelBase.dll is in known range, skipping\n2026-04-28 01:03:18,871 [root] DEBUG: 2200: DLL loaded at 0x73AC0000: C:\\Windows\\SYSTEM32\\TextShaping (0x94000 bytes).\n2026-04-28 01:03:18,987 [root] DEBUG: 2200: DLL loaded at 0x745D0000: C:\\Windows\\system32\\uxtheme (0x74000 bytes).\n2026-04-28 01:03:19,142 [root] DEBUG: 2200: DLL loaded at 0x76BA0000: C:\\Windows\\System32\\MSCTF (0xd4000 bytes).\n2026-04-28 01:03:19,259 [root] DEBUG: 2200: set_hooks_by_export_directory: Hooked 0 out of 632 functions\n2026-04-28 01:03:19,274 [root] DEBUG: 2200: DLL loaded at 0x75250000: C:\\Windows\\SYSTEM32\\kernel.appcore (0xf000 bytes).\n2026-04-28 01:03:19,290 [root] DEBUG: 2200: DLL loaded at 0x76D80000: C:\\Windows\\System32\\bcryptPrimitives (0x5f000 bytes).\n2026-04-28 01:03:19,476 [root] DEBUG: 2200: DLL loaded at 0x736B0000: C:\\Windows\\SYSTEM32\\ntmarta (0x29000 bytes).\n2026-04-28 01:03:19,476 [root] DEBUG: 2200: DLL loaded at 0x736E0000: C:\\Windows\\System32\\CoreMessaging (0x9b000 bytes).\n2026-04-28 01:03:19,492 [root] DEBUG: 2200: DLL loaded at 0x735D0000: C:\\Windows\\SYSTEM32\\wintypes (0xdb000 bytes).\n2026-04-28 01:03:19,492 [root] DEBUG: 2200: DLL loaded at 0x73780000: C:\\Windows\\System32\\CoreUIComponents (0x27e000 bytes).\n2026-04-28 01:03:19,492 [root] DEBUG: 2200: DLL loaded at 0x73A00000: C:\\Windows\\SYSTEM32\\textinputframework (0xb9000 bytes).\n2026-04-28 01:05:18,034 [root] INFO: Analysis timeout hit, terminating analysis\n2026-04-28 01:05:18,034 [lib.api.process] INFO: Terminate event set for <Process 2200 rundll32.exe>\n2026-04-28 01:05:18,034 [root] DEBUG: 2200: Terminate Event: Attempting to dump process 2200\n2026-04-28 01:05:18,050 [root] DEBUG: 2200: VerifyCodeSection: Executable code does not match, 0x18f2 of 0x18f3 matching\n2026-04-28 01:05:18,050 [root] DEBUG: 2200: DoProcessDump: Code modification detected, dumping Imagebase at 0x03590000.\n2026-04-28 01:05:18,050 [root] DEBUG: 2200: DumpImageInCurrentProcess: Attempting to dump virtual PE image.\n2026-04-28 01:05:18,050 [root] DEBUG: 2200: DumpProcess: Instantiating PeParser with address: 0x03590000.\n2026-04-28 01:05:18,065 [root] DEBUG: 2200: DumpProcess: Module entry point VA is 0x035938EE.\n2026-04-28 01:05:18,065 [root] DEBUG: 2200: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x03594000, section 2\n2026-04-28 01:05:18,065 [root] DEBUG: 2200: PeParser: readPeSectionsFromProcess: readSectionFromProcess failed address 0x03598000, section 3\n2026-04-28 01:05:18,253 [lib.common.results] INFO: Uploading file C:\\sQCNRNV\\CAPE\\2200_84461852227142026 to procdump\\9d7c7de83cb3527f377d51220f8a046ac9c72bce4389ade3d7d133b7a31ea3d3; Size is 7680; Max size: 100000000\n2026-04-28 01:05:18,268 [root] DEBUG: 2200: DumpProcess: Module image dump success - dump size 0x1e00.\n2026-04-28 01:05:18,284 [lib.api.process] INFO: Termination confirmed for <Process 2200 rundll32.exe>\n2026-04-28 01:05:18,284 [root] INFO: Terminate event set for process 2200\n2026-04-28 01:05:18,284 [root] INFO: Created shutdown mutex\n2026-04-28 01:05:18,299 [root] DEBUG: 2200: Terminate Event: monitor shutdown complete for process 2200\n2026-04-28 01:05:19,300 [root] INFO: Shutting down package\n2026-04-28 01:05:19,300 [root] INFO: Stopping auxiliary modules\n2026-04-28 01:05:19,300 [root] INFO: Stopping auxiliary module: Browser\n2026-04-28 01:05:19,300 [root] INFO: Stopping auxiliary module: Human\n2026-04-28 01:05:24,612 [root] INFO: Stopping auxiliary module: Screenshots\n2026-04-28 01:05:25,237 [root] INFO: Finishing auxiliary modules\n2026-04-28 01:05:25,237 [root] INFO: Shutting down pipe server and dumping dropped files\n2026-04-28 01:05:25,237 [root] WARNING: Folder at path \"C:\\sQCNRNV\\debugger\" does not exist, skipping\n2026-04-28 01:05:25,237 [root] INFO: Uploading files at path \"C:\\sQCNRNV\\tlsdump\"\n2026-04-28 01:05:25,252 [lib.common.results] INFO: Uploading file C:\\sQCNRNV\\tlsdump\\tlsdump.log to tlsdump\\tlsdump.log; Size is 24660; Max size: 100000000\n2026-04-28 01:05:25,252 [root] INFO: Analysis completed\n",
    "errors": []
  },
  "network": {
    "pcap_sha256": "c389804bb406845ad491f7d1d68ccbd2ecaba024cf36664d5001c541b2f367da",
    "hosts": [
      {
        "ip": "20.93.72.182",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "46.149.110.67",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          80
        ]
      },
      {
        "ip": "72.154.7.16",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.108",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.100",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.105",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.102",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.98",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.101",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.107",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "72.154.7.109",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "74.179.77.204",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.165.94.54",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "13.107.6.156",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "84.47.178.41",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "150.171.27.11",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "84.47.178.49",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "52.123.242.97",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.42.65.93",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "4.207.247.139",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "209.85.233.94",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "i.pki.goog",
        "inaddrarpa": "",
        "ports": [
          80
        ]
      },
      {
        "ip": "84.47.178.56",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      },
      {
        "ip": "20.189.173.2",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": [
          443
        ]
      }
    ],
    "domains": [
      {
        "domain": "i.pki.goog",
        "ip": "209.85.233.94"
      }
    ],
    "tcp": [
      {
        "src": "192.168.1.100",
        "sport": 49723,
        "dst": "20.189.173.2",
        "dport": 443,
        "offset": 24,
        "time": 0.0
      },
      {
        "src": "192.168.1.100",
        "sport": 49724,
        "dst": "20.189.173.2",
        "dport": 443,
        "offset": 95,
        "time": 0.9203610420227051
      },
      {
        "src": "192.168.1.100",
        "sport": 49718,
        "dst": "84.47.178.56",
        "dport": 443,
        "offset": 166,
        "time": 4.8265039920806885
      },
      {
        "src": "192.168.1.100",
        "sport": 49806,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 822,
        "time": 5.244833946228027
      },
      {
        "src": "192.168.1.100",
        "sport": 49810,
        "dst": "52.123.129.14",
        "dport": 443,
        "offset": 23130,
        "time": 7.5544469356536865
      },
      {
        "src": "192.168.1.100",
        "sport": 49812,
        "dst": "13.107.253.44",
        "dport": 443,
        "offset": 38001,
        "time": 8.373996019363403
      },
      {
        "src": "192.168.1.100",
        "sport": 49814,
        "dst": "93.191.15.162",
        "dport": 80,
        "offset": 63522,
        "time": 9.036006927490234
      },
      {
        "src": "192.168.1.100",
        "sport": 49815,
        "dst": "84.47.178.49",
        "dport": 443,
        "offset": 64983,
        "time": 9.052452087402344
      },
      {
        "src": "192.168.1.100",
        "sport": 49818,
        "dst": "93.191.15.162",
        "dport": 80,
        "offset": 191143,
        "time": 9.34384298324585
      },
      {
        "src": "192.168.1.100",
        "sport": 49817,
        "dst": "40.119.249.228",
        "dport": 443,
        "offset": 221156,
        "time": 9.533900022506714
      },
      {
        "src": "192.168.1.100",
        "sport": 49813,
        "dst": "84.47.178.49",
        "dport": 443,
        "offset": 221676,
        "time": 9.609839916229248
      },
      {
        "src": "192.168.1.100",
        "sport": 49821,
        "dst": "209.85.233.94",
        "dport": 80,
        "offset": 369632,
        "time": 11.169934034347534
      },
      {
        "src": "192.168.1.100",
        "sport": 49823,
        "dst": "194.158.198.23",
        "dport": 80,
        "offset": 392744,
        "time": 11.486938953399658
      },
      {
        "src": "192.168.1.100",
        "sport": 49728,
        "dst": "150.171.27.11",
        "dport": 443,
        "offset": 394427,
        "time": 11.531032085418701
      },
      {
        "src": "192.168.1.100",
        "sport": 49824,
        "dst": "150.171.27.11",
        "dport": 443,
        "offset": 396886,
        "time": 11.576189994812012
      },
      {
        "src": "192.168.1.100",
        "sport": 49825,
        "dst": "20.42.65.93",
        "dport": 443,
        "offset": 410690,
        "time": 11.71737003326416
      },
      {
        "src": "192.168.1.100",
        "sport": 49827,
        "dst": "204.79.197.203",
        "dport": 80,
        "offset": 422238,
        "time": 11.953059911727905
      },
      {
        "src": "192.168.1.100",
        "sport": 49830,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 434585,
        "time": 20.4794659614563
      },
      {
        "src": "192.168.1.100",
        "sport": 49833,
        "dst": "172.66.2.5",
        "dport": 80,
        "offset": 452669,
        "time": 30.555311918258667
      },
      {
        "src": "192.168.1.100",
        "sport": 49837,
        "dst": "199.232.214.172",
        "dport": 80,
        "offset": 482958,
        "time": 38.24238109588623
      },
      {
        "src": "192.168.1.100",
        "sport": 49840,
        "dst": "40.126.53.9",
        "dport": 443,
        "offset": 490705,
        "time": 38.82623291015625
      },
      {
        "src": "192.168.1.100",
        "sport": 49842,
        "dst": "40.126.53.9",
        "dport": 443,
        "offset": 491681,
        "time": 38.82727003097534
      },
      {
        "src": "192.168.1.100",
        "sport": 49843,
        "dst": "40.126.53.9",
        "dport": 443,
        "offset": 492435,
        "time": 38.828113079071045
      },
      {
        "src": "192.168.1.100",
        "sport": 49846,
        "dst": "52.137.106.217",
        "dport": 443,
        "offset": 555698,
        "time": 39.30026292800903
      },
      {
        "src": "192.168.1.100",
        "sport": 49710,
        "dst": "84.47.178.41",
        "dport": 443,
        "offset": 654334,
        "time": 39.714163064956665
      },
      {
        "src": "192.168.1.100",
        "sport": 49716,
        "dst": "84.47.178.56",
        "dport": 443,
        "offset": 661259,
        "time": 39.792505979537964
      },
      {
        "src": "192.168.1.100",
        "sport": 49851,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 667582,
        "time": 39.845407009124756
      },
      {
        "src": "192.168.1.100",
        "sport": 49852,
        "dst": "52.137.106.217",
        "dport": 443,
        "offset": 809517,
        "time": 40.34500002861023
      },
      {
        "src": "192.168.1.100",
        "sport": 49720,
        "dst": "8.8.4.4",
        "dport": 443,
        "offset": 1180158,
        "time": 40.97996497154236
      },
      {
        "src": "192.168.1.100",
        "sport": 49708,
        "dst": "13.107.6.156",
        "dport": 443,
        "offset": 1180299,
        "time": 41.01117706298828
      },
      {
        "src": "192.168.1.100",
        "sport": 49855,
        "dst": "40.126.53.9",
        "dport": 443,
        "offset": 1182496,
        "time": 41.395633935928345
      },
      {
        "src": "192.168.1.100",
        "sport": 49857,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 1202108,
        "time": 41.88977408409119
      },
      {
        "src": "192.168.1.100",
        "sport": 49712,
        "dst": "84.47.178.41",
        "dport": 443,
        "offset": 1265588,
        "time": 42.198402881622314
      },
      {
        "src": "192.168.1.100",
        "sport": 49860,
        "dst": "8.8.8.8",
        "dport": 443,
        "offset": 1301889,
        "time": 42.34640908241272
      },
      {
        "src": "192.168.1.100",
        "sport": 49862,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 1388178,
        "time": 43.25899410247803
      },
      {
        "src": "192.168.1.100",
        "sport": 49865,
        "dst": "135.236.137.174",
        "dport": 443,
        "offset": 1401014,
        "time": 45.387118101119995
      },
      {
        "src": "192.168.1.100",
        "sport": 49864,
        "dst": "20.165.94.54",
        "dport": 443,
        "offset": 1411722,
        "time": 45.472506046295166
      },
      {
        "src": "192.168.1.100",
        "sport": 49867,
        "dst": "20.106.86.13",
        "dport": 443,
        "offset": 1430825,
        "time": 45.67700791358948
      },
      {
        "src": "192.168.1.100",
        "sport": 49869,
        "dst": "74.178.76.128",
        "dport": 443,
        "offset": 1466080,
        "time": 46.25414204597473
      },
      {
        "src": "192.168.1.100",
        "sport": 49872,
        "dst": "20.42.65.85",
        "dport": 443,
        "offset": 1774083,
        "time": 49.21575403213501
      },
      {
        "src": "192.168.1.100",
        "sport": 49874,
        "dst": "20.106.86.13",
        "dport": 443,
        "offset": 1790896,
        "time": 50.31803894042969
      },
      {
        "src": "74.179.77.204",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49945,
        "offset": 2781159,
        "time": 55.26457691192627
      },
      {
        "src": "192.168.1.100",
        "sport": 49877,
        "dst": "184.86.14.126",
        "dport": 443,
        "offset": 2788509,
        "time": 56.849859952926636
      },
      {
        "src": "192.168.1.100",
        "sport": 49879,
        "dst": "20.44.239.154",
        "dport": 443,
        "offset": 2804192,
        "time": 63.07177495956421
      },
      {
        "src": "192.168.1.100",
        "sport": 49884,
        "dst": "172.66.2.5",
        "dport": 80,
        "offset": 2818385,
        "time": 66.85660195350647
      },
      {
        "src": "192.168.1.100",
        "sport": 49886,
        "dst": "2.23.88.9",
        "dport": 443,
        "offset": 2868331,
        "time": 67.62783694267273
      },
      {
        "src": "192.168.1.100",
        "sport": 49888,
        "dst": "52.137.106.217",
        "dport": 443,
        "offset": 3596983,
        "time": 68.51716089248657
      },
      {
        "src": "192.168.1.100",
        "sport": 49891,
        "dst": "199.232.214.172",
        "dport": 80,
        "offset": 3605864,
        "time": 69.81238603591919
      },
      {
        "src": "192.168.1.100",
        "sport": 49893,
        "dst": "4.207.247.139",
        "dport": 443,
        "offset": 3619136,
        "time": 70.19946599006653
      },
      {
        "src": "4.207.247.139",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49929,
        "offset": 3629674,
        "time": 70.46492910385132
      },
      {
        "src": "192.168.1.100",
        "sport": 49896,
        "dst": "52.137.106.217",
        "dport": 443,
        "offset": 3641532,
        "time": 72.37813401222229
      },
      {
        "src": "192.168.1.100",
        "sport": 49902,
        "dst": "52.167.17.97",
        "dport": 443,
        "offset": 3707869,
        "time": 106.92774295806885
      },
      {
        "src": "192.168.1.100",
        "sport": 49908,
        "dst": "52.123.243.170",
        "dport": 443,
        "offset": 3720085,
        "time": 111.7589819431305
      },
      {
        "src": "192.168.1.100",
        "sport": 49910,
        "dst": "20.189.173.18",
        "dport": 443,
        "offset": 4032803,
        "time": 113.12264394760132
      },
      {
        "src": "192.168.1.100",
        "sport": 49912,
        "dst": "2.23.90.38",
        "dport": 443,
        "offset": 4055946,
        "time": 114.32597208023071
      },
      {
        "src": "192.168.1.100",
        "sport": 49917,
        "dst": "150.171.109.53",
        "dport": 443,
        "offset": 4077619,
        "time": 116.98031806945801
      },
      {
        "src": "192.168.1.100",
        "sport": 49919,
        "dst": "93.191.15.200",
        "dport": 443,
        "offset": 4099083,
        "time": 117.24215888977051
      },
      {
        "src": "192.168.1.100",
        "sport": 49921,
        "dst": "204.79.197.203",
        "dport": 80,
        "offset": 4628842,
        "time": 122.48343205451965
      },
      {
        "src": "8.8.8.8",
        "sport": 443,
        "dst": "192.168.1.100",
        "dport": 49872,
        "offset": 6573976,
        "time": 145.56670498847961
      },
      {
        "src": "192.168.1.100",
        "sport": 49926,
        "dst": "199.232.214.172",
        "dport": 80,
        "offset": 6580135,
        "time": 165.42890095710754
      },
      {
        "src": "192.168.1.100",
        "sport": 49930,
        "dst": "72.154.7.17",
        "dport": 443,
        "offset": 8407662,
        "time": 166.15804409980774
      },
      {
        "src": "192.168.1.100",
        "sport": 49929,
        "dst": "72.154.7.107",
        "dport": 443,
        "offset": 8408106,
        "time": 166.16277694702148
      },
      {
        "src": "192.168.1.100",
        "sport": 49931,
        "dst": "72.154.7.106",
        "dport": 443,
        "offset": 8408994,
        "time": 166.18497800827026
      },
      {
        "src": "192.168.1.100",
        "sport": 49933,
        "dst": "2.23.90.38",
        "dport": 443,
        "offset": 8443709,
        "time": 167.49387288093567
      },
      {
        "src": "192.168.1.100",
        "sport": 49935,
        "dst": "2.23.90.38",
        "dport": 443,
        "offset": 8467413,
        "time": 167.75309205055237
      },
      {
        "src": "192.168.1.100",
        "sport": 49937,
        "dst": "40.126.53.9",
        "dport": 443,
        "offset": 8493723,
        "time": 174.6105830669403
      },
      {
        "src": "192.168.1.100",
        "sport": 49939,
        "dst": "52.168.117.170",
        "dport": 443,
        "offset": 8524581,
        "time": 193.75231289863586
      },
      {
        "src": "192.168.1.100",
        "sport": 49941,
        "dst": "150.171.22.17",
        "dport": 443,
        "offset": 8550621,
        "time": 214.57239508628845
      },
      {
        "src": "192.168.1.100",
        "sport": 49943,
        "dst": "135.232.92.34",
        "dport": 443,
        "offset": 8576631,
        "time": 217.87918710708618
      },
      {
        "src": "192.168.1.100",
        "sport": 49945,
        "dst": "2.23.90.38",
        "dport": 443,
        "offset": 8622607,
        "time": 218.97088599205017
      }
    ],
    "udp": [
      {
        "src": "192.168.1.100",
        "sport": 62931,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 36810,
        "time": 7.996453046798706
      },
      {
        "src": "192.168.1.100",
        "sport": 60692,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 75893,
        "time": 9.252305030822754
      },
      {
        "src": "192.168.1.100",
        "sport": 53478,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 195045,
        "time": 9.441037893295288
      },
      {
        "src": "192.168.1.100",
        "sport": 52629,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 362154,
        "time": 11.130515098571777
      },
      {
        "src": "192.168.1.100",
        "sport": 61689,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 391394,
        "time": 11.41675591468811
      },
      {
        "src": "192.168.1.100",
        "sport": 52491,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 421655,
        "time": 11.912322998046875
      },
      {
        "src": "192.168.1.100",
        "sport": 138,
        "dst": "192.168.1.255",
        "dport": 138,
        "offset": 471721,
        "time": 31.663055896759033
      },
      {
        "src": "192.168.1.100",
        "sport": 60891,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 652639,
        "time": 39.58503293991089
      },
      {
        "src": "192.168.1.100",
        "sport": 57722,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 816743,
        "time": 40.78466200828552
      },
      {
        "src": "192.168.1.100",
        "sport": 55936,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1197136,
        "time": 41.71886706352234
      },
      {
        "src": "192.168.1.100",
        "sport": 64967,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1400116,
        "time": 45.18530201911926
      },
      {
        "src": "192.168.1.100",
        "sport": 57649,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1431111,
        "time": 45.73057007789612
      },
      {
        "src": "192.168.1.100",
        "sport": 53511,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 1773280,
        "time": 49.067774057388306
      },
      {
        "src": "192.168.1.100",
        "sport": 51400,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2781778,
        "time": 56.57266688346863
      },
      {
        "src": "192.168.1.100",
        "sport": 63923,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2803608,
        "time": 62.83471989631653
      },
      {
        "src": "192.168.1.100",
        "sport": 55152,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 2820383,
        "time": 66.91117405891418
      },
      {
        "src": "192.168.1.100",
        "sport": 65367,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 3604978,
        "time": 69.74040699005127
      },
      {
        "src": "192.168.1.100",
        "sport": 63426,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 3707290,
        "time": 106.77060008049011
      },
      {
        "src": "192.168.1.100",
        "sport": 51285,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 3737912,
        "time": 112.11642289161682
      },
      {
        "src": "192.168.1.100",
        "sport": 54315,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 4043344,
        "time": 113.57323694229126
      },
      {
        "src": "192.168.1.100",
        "sport": 55616,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 4076967,
        "time": 116.89370608329773
      },
      {
        "src": "192.168.1.100",
        "sport": 54159,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 5003022,
        "time": 127.45039987564087
      },
      {
        "src": "192.168.1.100",
        "sport": 54408,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 6574455,
        "time": 148.4359130859375
      },
      {
        "src": "192.168.1.100",
        "sport": 55146,
        "dst": "8.8.4.4",
        "dport": 53,
        "offset": 6578040,
        "time": 148.82661294937134
      },
      {
        "src": "192.168.1.100",
        "sport": 57032,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 8406569,
        "time": 165.959125995636
      },
      {
        "src": "192.168.1.100",
        "sport": 52431,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 8429428,
        "time": 166.9597339630127
      },
      {
        "src": "192.168.1.100",
        "sport": 53075,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 8523790,
        "time": 193.60771298408508
      },
      {
        "src": "192.168.1.100",
        "sport": 55022,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 8550030,
        "time": 214.4504749774933
      },
      {
        "src": "192.168.1.100",
        "sport": 54709,
        "dst": "8.8.8.8",
        "dport": 53,
        "offset": 8621933,
        "time": 218.92470288276672
      }
    ],
    "icmp": [
      {
        "src": "192.168.1.100",
        "dst": "8.8.4.4",
        "type": 3,
        "data": ""
      }
    ],
    "http": [
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /gsr1.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/gsr1.crt",
        "body": "",
        "path": "/gsr1.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1777338108.144587
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /r4.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/r4.crt",
        "body": "",
        "path": "/r4.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1777338108.167845
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /we2.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/we2.crt",
        "body": "",
        "path": "/we2.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1777338108.189279
      },
      {
        "count": 2,
        "host": "i.pki.goog",
        "port": 80,
        "data": "GET /gsr4.crt HTTP/1.1\r\nHost: i.pki.goog\r\nConnection: keep-alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0\r\nAccept-Encoding: gzip, deflate\r\n\r\n",
        "uri": "http://i.pki.goog/gsr4.crt",
        "body": "",
        "path": "/gsr4.crt",
        "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "version": "1.1",
        "method": "GET",
        "first_seen": 1777338108.217704
      }
    ],
    "dns": [
      {
        "request": "i.pki.goog",
        "type": "A",
        "answers": [
          {
            "type": "CNAME",
            "data": "pki-goog.l.google.com"
          },
          {
            "type": "A",
            "data": "209.85.233.94"
          }
        ],
        "first_seen": 1777338108.105434
      }
    ],
    "smtp": [],
    "irc": [],
    "dead_hosts": [
      [
        "52.123.242.97",
        443
      ],
      [
        "72.154.7.109",
        443
      ],
      [
        "72.154.7.101",
        443
      ],
      [
        "72.154.7.98",
        443
      ],
      [
        "72.154.7.102",
        443
      ],
      [
        "72.154.7.105",
        443
      ],
      [
        "72.154.7.100",
        443
      ],
      [
        "72.154.7.108",
        443
      ],
      [
        "72.154.7.16",
        443
      ],
      [
        "46.149.110.67",
        80
      ]
    ]
  },
  "suricata": {
    "alerts": [],
    "tls": [
      {
        "srcport": 49820,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-28 01:01:48.142964+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "87c36e0efdb847c153954b9f4778e764",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,45-13-43-51-23-0-65037-65281-5-27-10-11-35-18-16-17613,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      },
      {
        "srcport": 49822,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-28 01:01:48.390226+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "eca10cbdddc3be37612b1d322437c105",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,51-23-5-45-27-65281-0-35-16-65037-43-10-17613-13-18-11,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      },
      {
        "srcport": 49860,
        "srcip": "192.168.1.100",
        "dstport": 443,
        "dstip": "8.8.8.8",
        "timestamp": "2026-04-28 01:02:19.339533+0000",
        "version": "TLS 1.3",
        "sni": "dns.google",
        "ja3": {
          "hash": "00cf290bd02b8f31a70af6a46e70e981",
          "string": "771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,18-10-16-17613-11-65037-13-0-51-5-27-43-45-23-35-65281,4588-29-23-24,0"
        },
        "ja3s": {
          "hash": "eb1d94daa7e0344597e756a1fb6e7054",
          "string": "771,4865,51-43"
        }
      }
    ],
    "perf": [],
    "files": [],
    "http": [
      {
        "srcport": 49821,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "209.85.233.94",
        "timestamp": "2026-04-28 01:01:48.163471+0000",
        "uri": "/gsr1.crt",
        "length": 797,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49821,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "209.85.233.94",
        "timestamp": "2026-04-28 01:01:48.189279+0000",
        "uri": "/r4.crt",
        "length": 455,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49821,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "209.85.233.94",
        "timestamp": "2026-04-28 01:01:48.217704+0000",
        "uri": "/we2.crt",
        "length": 582,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49821,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "209.85.233.94",
        "timestamp": "2026-04-28 01:01:48.255549+0000",
        "uri": "/gsr4.crt",
        "length": 480,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49821,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "209.85.233.94",
        "timestamp": "2026-04-28 01:01:48.274538+0000",
        "uri": "/gsr1.crt",
        "length": 797,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49821,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "209.85.233.94",
        "timestamp": "2026-04-28 01:01:48.300471+0000",
        "uri": "/r4.crt",
        "length": 455,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49821,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "209.85.233.94",
        "timestamp": "2026-04-28 01:01:48.324564+0000",
        "uri": "/we2.crt",
        "length": 582,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      },
      {
        "srcport": 49821,
        "srcip": "192.168.1.100",
        "dstport": 80,
        "dstip": "209.85.233.94",
        "timestamp": "2026-04-28 01:01:48.393863+0000",
        "uri": "/gsr4.crt",
        "length": 480,
        "hostname": "i.pki.goog",
        "status": 200,
        "http_method": "GET",
        "contenttype": "application/pkix-cert",
        "ua": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0",
        "referrer": null
      }
    ],
    "dns": [
      {
        "timestamp": "2026-04-28T01:01:48.105168+0000",
        "flow_id": 1296120364628845,
        "pcap_cnt": 521,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 52629,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "query",
          "id": 30694,
          "rrname": "i.pki.goog",
          "rrtype": "HTTPS",
          "tx_id": 0,
          "opcode": 0
        }
      },
      {
        "timestamp": "2026-04-28T01:01:48.105434+0000",
        "flow_id": 1297260772953577,
        "pcap_cnt": 522,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 64925,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "query",
          "id": 51226,
          "rrname": "i.pki.goog",
          "rrtype": "A",
          "tx_id": 0,
          "opcode": 0
        }
      },
      {
        "timestamp": "2026-04-28T01:01:48.124066+0000",
        "flow_id": 1296120364628845,
        "pcap_cnt": 526,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 52629,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "answer",
          "id": 30694,
          "flags": "8180",
          "qr": true,
          "rd": true,
          "ra": true,
          "opcode": 0,
          "rrname": "i.pki.goog",
          "rrtype": "HTTPS",
          "rcode": "NOERROR",
          "answers": [
            {
              "rrname": "i.pki.goog",
              "rrtype": "CNAME",
              "ttl": 264,
              "rdata": "pki-goog.l.google.com"
            }
          ],
          "grouped": {
            "CNAME": [
              "pki-goog.l.google.com"
            ]
          },
          "authorities": [
            {
              "rrname": "l.google.com",
              "rrtype": "SOA",
              "ttl": 60,
              "soa": {
                "mname": "ns1.google.com",
                "rname": "dns-admin.google.com",
                "serial": 906246128,
                "refresh": 900,
                "retry": 900,
                "expire": 1800,
                "minimum": 60
              }
            }
          ]
        }
      },
      {
        "timestamp": "2026-04-28T01:01:48.124016+0000",
        "flow_id": 1297260772953577,
        "pcap_cnt": 525,
        "event_type": "dns",
        "src_ip": "192.168.1.100",
        "src_port": 64925,
        "dest_ip": "8.8.8.8",
        "dest_port": 53,
        "proto": "UDP",
        "pkt_src": "wire/pcap",
        "dns": {
          "version": 2,
          "type": "answer",
          "id": 51226,
          "flags": "8180",
          "qr": true,
          "rd": true,
          "ra": true,
          "opcode": 0,
          "rrname": "i.pki.goog",
          "rrtype": "A",
          "rcode": "NOERROR",
          "answers": [
            {
              "rrname": "i.pki.goog",
              "rrtype": "CNAME",
              "ttl": 260,
              "rdata": "pki-goog.l.google.com"
            },
            {
              "rrname": "pki-goog.l.google.com",
              "rrtype": "A",
              "ttl": 300,
              "rdata": "209.85.233.94"
            }
          ],
          "grouped": {
            "A": [
              "209.85.233.94"
            ],
            "CNAME": [
              "pki-goog.l.google.com"
            ]
          }
        }
      }
    ],
    "ssh": [],
    "fileinfo": [],
    "eve_log_full_path": "/opt/CAPEv2/storage/analyses/50/logs/eve.json",
    "alert_log_full_path": null,
    "tls_log_full_path": null,
    "http_log_full_path": null,
    "file_log_full_path": null,
    "ssh_log_full_path": null,
    "dns_log_full_path": null
  },
  "url_analysis": {},
  "procmemory": [],
  "signatures": [
    {
      "name": "stealth_network",
      "description": "Network activity detected but not expressed in monitor API logs",
      "categories": [
        "stealth"
      ],
      "severity": 1,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "ip": "20.93.72.182"
        },
        {
          "ip": "46.149.110.67"
        },
        {
          "ip": "72.154.7.16"
        },
        {
          "ip": "72.154.7.108"
        },
        {
          "ip": "72.154.7.100"
        },
        {
          "ip": "72.154.7.105"
        },
        {
          "ip": "72.154.7.102"
        },
        {
          "ip": "72.154.7.98"
        },
        {
          "ip": "72.154.7.101"
        },
        {
          "ip": "72.154.7.107"
        },
        {
          "ip": "72.154.7.109"
        },
        {
          "ip": "74.179.77.204"
        },
        {
          "ip": "20.165.94.54"
        },
        {
          "ip": "13.107.6.156"
        },
        {
          "ip": "84.47.178.41"
        },
        {
          "ip": "150.171.27.11"
        },
        {
          "ip": "84.47.178.49"
        },
        {
          "ip": "52.123.242.97"
        },
        {
          "ip": "20.42.65.93"
        },
        {
          "ip": "4.207.247.139"
        },
        {
          "ip": "209.85.233.94"
        },
        {
          "ip": "84.47.178.56"
        },
        {
          "ip": "20.189.173.2"
        },
        {
          "domain": "i.pki.goog"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "network_http",
      "description": "Performs some HTTP requests",
      "categories": [
        "network"
      ],
      "severity": 2,
      "weight": 1,
      "confidence": 30,
      "references": [],
      "data": [
        {
          "url": "http://i.pki.goog/gsr1.crt"
        },
        {
          "url": "http://i.pki.goog/r4.crt"
        },
        {
          "url": "http://i.pki.goog/we2.crt"
        },
        {
          "url": "http://i.pki.goog/gsr4.crt"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "binary_yara",
      "description": "Binary file triggered multiple YARA rules",
      "categories": [
        "static"
      ],
      "severity": 3,
      "weight": 1,
      "confidence": 80,
      "references": [],
      "data": [
        {
          "Binary triggered YARA rule": "DITEKSHEN_MALWARE_Win_Nanocore"
        },
        {
          "Binary triggered YARA rule": "Windows_Trojan_Nanocore_d8c4e3c5"
        },
        {
          "Binary triggered YARA rule": "Nanocore_RAT_Gen_2"
        },
        {
          "Binary triggered YARA rule": "NETDLLMicrosoft"
        },
        {
          "Binary triggered YARA rule": "IsPE32"
        },
        {
          "Binary triggered YARA rule": "IsNET_DLL"
        },
        {
          "Binary triggered YARA rule": "IsDLL"
        },
        {
          "Binary triggered YARA rule": "IsWindowsGUI"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_Studio_NET"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_v70_Basic_NET_additional"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_Basic_NET"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_Studio_NET_additional"
        },
        {
          "Binary triggered YARA rule": "Microsoft_Visual_C_v70_Basic_NET"
        },
        {
          "Binary triggered YARA rule": "NET_executable_"
        },
        {
          "Binary triggered YARA rule": "NET_executable"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "procmem_yara",
      "description": "Yara detections observed in process dumps, payloads or dropped files",
      "categories": [
        "malware"
      ],
      "severity": 3,
      "weight": 4,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "Hit": "PID 2200 triggered the Yara rule 'DITEKSHEN_MALWARE_Win_Nanocore' with data '['NanoCore.ClientPlugin', 'NanoCore.ClientPluginHost', 'IClientApp', 'IClientData', 'IClientNetwork', 'IClientAppHost', 'IClientDataHost', 'IClientLoggingHost', 'IClientNetworkHost', 'IClientUIHost', 'IClientNameObjectCollection', 'IClientReadOnlyNameObjectCollection', 'ClientPlugin', 'get_ClientSettings', 'get_Connected']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'Windows_Trojan_Nanocore_d8c4e3c5' with data '['NanoCore.ClientPluginHost', 'NanoCore.ClientPlugin', 'get_BuilderSettings', 'IClientAppHost', 'AddHostEntry', 'LogClientException', 'PipeExists', 'IClientLoggingHost']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'Nanocore_RAT_Gen_2' with data '['NanoCore.ClientPluginHost', 'IClientNetworkHost']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'NETDLLMicrosoft' with data '['{ 00 00 00 00 00 00 00 00 5F 43 6F 72 44 6C 6C 4D 61 69 6E 00 6D 73 63 6F 72 65 65 2E 64 6C 6C 00 00 00 00 00 FF 25 }']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'IsPE32' with data '[]'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'IsNET_DLL' with data '[]'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'IsDLL' with data '[]'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'IsWindowsGUI' with data '[]'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'Microsoft_Visual_Studio_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'Microsoft_Visual_C_v70_Basic_NET_additional' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'Microsoft_Visual_C_Basic_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'Microsoft_Visual_Studio_NET_additional' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'Microsoft_Visual_C_v70_Basic_NET' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'NET_executable_' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        },
        {
          "Hit": "PID 2200 triggered the Yara rule 'NET_executable' with data '['{ FF 25 00 20 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }']'"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    }
  ],
  "malscore": 8.0,
  "ttps": [
    {
      "signature": "stealth_network",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002",
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "binary_yara",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002",
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "network_http",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "procmem_yara",
      "ttps": [
        "T1071"
      ],
      "mbcs": [
        "OC0006",
        "C0002",
        "OC0006",
        "C0002"
      ]
    }
  ],
  "malstatus": "Malicious"
}