| Category | Package | Started | Completed | Duration | Log(s) |
|---|---|---|---|---|---|
| FILE | exe | 2026-04-18 21:57:44 | 2026-04-18 22:01:30 | 226 seconds | Show Analysis Log |
2025-11-20 02:03:38,744 [root] INFO: Date set to: 20260418T21:57:43, timeout set to: 200
2026-04-18 21:57:43,066 [root] DEBUG: Starting analyzer from: C:\wry749yf
2026-04-18 21:57:43,067 [root] DEBUG: Storing results at: C:\PiogNHme
2026-04-18 21:57:43,068 [root] DEBUG: Pipe server name: \\.\PIPE\zmUaLn
2026-04-18 21:57:43,068 [root] DEBUG: Python path: C:\Users\Admin\AppData\Local\Programs\Python\Python313-32
2026-04-18 21:57:43,068 [root] INFO: analysis running as an admin
2026-04-18 21:57:43,068 [root] INFO: analysis package specified: "exe"
2026-04-18 21:57:43,068 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2026-04-18 21:57:43,090 [root] DEBUG: imported analysis package "exe"
2026-04-18 21:57:43,091 [root] DEBUG: initializing analysis package "exe"...
2026-04-18 21:57:43,091 [lib.common.common] INFO: wrapping
2026-04-18 21:57:43,092 [lib.core.compound] INFO: C:\Temp already exists, skipping creation
2026-04-18 21:57:43,092 [root] DEBUG: New location of moved file: C:\Temp\AnyDesk.exe
2026-04-18 21:57:43,093 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2026-04-18 21:57:43,093 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2026-04-18 21:57:43,093 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2026-04-18 21:57:43,107 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2026-04-18 21:57:43,137 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-04-18 21:57:43,180 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-04-18 21:57:43,203 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-04-18 21:57:43,224 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-04-18 21:57:43,232 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-04-18 21:57:43,582 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-04-18 21:57:43,618 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-04-18 21:57:44,012 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance
2026-04-18 21:57:44,012 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-04-18 21:57:44,016 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-04-18 21:57:44,016 [root] DEBUG: Initialized auxiliary module "Browser"
2026-04-18 21:57:44,017 [root] DEBUG: attempting to configure 'Browser' from data
2026-04-18 21:57:44,018 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-04-18 21:57:44,019 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-04-18 21:57:44,020 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-04-18 21:57:44,020 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-04-18 21:57:44,020 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-04-18 21:57:44,021 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-04-18 21:57:44,022 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-04-18 21:57:44,022 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-04-18 21:57:45,020 [modules.auxiliary.digisig] DEBUG: File has a valid signature
2026-04-18 21:57:45,020 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-04-18 21:57:45,035 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-04-18 21:57:45,035 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-04-18 21:57:45,036 [root] DEBUG: attempting to configure 'Disguise' from data
2026-04-18 21:57:45,036 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-04-18 21:57:45,036 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-04-18 21:57:45,037 [modules.auxiliary.disguise] INFO: Disguising GUID to 5f8bb843-bc05-45b1-9282-ed0ebf519e97
2026-04-18 21:57:45,037 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-04-18 21:57:45,038 [root] DEBUG: Initialized auxiliary module "Human"
2026-04-18 21:57:45,038 [root] DEBUG: attempting to configure 'Human' from data
2026-04-18 21:57:45,038 [root] DEBUG: module Human does not support data configuration, ignoring
2026-04-18 21:57:45,038 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-04-18 21:57:45,040 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-04-18 21:57:45,040 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-04-18 21:57:45,041 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-04-18 21:57:45,041 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-04-18 21:57:45,041 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-04-18 21:57:45,043 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-04-18 21:57:45,043 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-04-18 21:57:45,043 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-04-18 21:57:45,044 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-04-18 21:57:45,044 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-04-18 21:57:45,048 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 608
2026-04-18 21:57:45,210 [lib.api.process] INFO: Monitor config for <Process 608 lsass.exe>: C:\wry749yf\dll\608.ini
2026-04-18 21:57:45,212 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-04-18 21:57:45,221 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 21:57:45,245 [root] DEBUG: Loader: Injecting process 608 with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:57:45,269 [root] DEBUG: 608: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 21:57:45,270 [root] DEBUG: 608: Disabling sleep skipping.
2026-04-18 21:57:45,271 [root] DEBUG: 608: TLS secret dump mode enabled.
2026-04-18 21:57:45,318 [root] DEBUG: 608: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0
2026-04-18 21:57:45,319 [root] DEBUG: 608: Monitor initialised: 64-bit capemon loaded in process 608 at 0x00007FFEB6B40000, thread 4256, image base 0x00007FF60EE30000, stack from 0x000000A5F4C72000-0x000000A5F4C80000
2026-04-18 21:57:45,320 [root] DEBUG: 608: Commandline: C:\Windows\system32\lsass.exe
2026-04-18 21:57:45,334 [root] DEBUG: 608: Hooked 5 out of 5 functions
2026-04-18 21:57:45,336 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-18 21:57:45,337 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:57:45,341 [lib.api.process] INFO: Injected into 64-bit <Process 608 lsass.exe>
2026-04-18 21:57:45,341 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-04-18 21:57:45,490 [root] DEBUG: 608: TLS 1.2 secrets logged to: C:\PiogNHme\tlsdump\tlsdump.log
2026-04-18 21:57:48,475 [root] INFO: Restarting WMI Service
2026-04-18 21:57:48,821 [root] DEBUG: package modules.packages.exe does not support configure, ignoring
2026-04-18 21:57:48,822 [root] WARNING: configuration error for package modules.packages.exe: error importing data.packages.exe: No module named 'data.packages'
2026-04-18 21:57:48,823 [lib.core.compound] INFO: C:\Temp already exists, skipping creation
2026-04-18 21:57:48,990 [lib.api.process] INFO: Successfully executed process from path "C:\Temp\AnyDesk.exe" with arguments "" with pid 4908
2026-04-18 21:57:48,991 [lib.api.process] INFO: Monitor config for <Process 4908 AnyDesk.exe>: C:\wry749yf\dll\4908.ini
2026-04-18 21:57:49,002 [lib.api.process] INFO: 32-bit DLL to inject is C:\wry749yf\dll\gjyipYwr.dll, loader C:\wry749yf\bin\PnLZeIX.exe
2026-04-18 21:57:49,026 [root] DEBUG: Loader: Injecting process 4908 (thread 4912) with C:\wry749yf\dll\gjyipYwr.dll.
2026-04-18 21:57:49,028 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 21:57:49,029 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\gjyipYwr.dll.
2026-04-18 21:57:49,033 [lib.api.process] INFO: Injected into 32-bit <Process 4908 AnyDesk.exe>
2026-04-18 21:57:51,046 [lib.api.process] INFO: Successfully resumed <Process 4908 AnyDesk.exe>
2026-04-18 21:57:51,075 [root] DEBUG: 4908: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 21:57:51,076 [root] DEBUG: 4908: Disabling sleep skipping.
2026-04-18 21:57:51,077 [root] DEBUG: 4908: Dropped file limit defaulting to 100.
2026-04-18 21:57:51,096 [root] DEBUG: 4908: YaraInit: Compiled 43 rule files
2026-04-18 21:57:51,099 [root] DEBUG: 4908: YaraInit: Compiled rules saved to file C:\wry749yf\data\yara\capemon.yac
2026-04-18 21:57:51,101 [root] DEBUG: 4908: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:51,330 [root] DEBUG: 4908: Monitor initialised: 32-bit capemon loaded in process 4908 at 0x731a0000, thread 4912, image base 0xc90000, stack from 0x2553000-0x2560000
2026-04-18 21:57:51,331 [root] DEBUG: 4908: Commandline: "C:\Temp\AnyDesk.exe"
2026-04-18 21:57:51,381 [root] DEBUG: 4908: hook_api: LdrpCallInitRoutine export address 0x76FC2B50 obtained via GetFunctionAddress
2026-04-18 21:57:51,412 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-18 21:57:51,413 [root] DEBUG: 4908: set_hooks: Unable to hook GetCommandLineA
2026-04-18 21:57:51,414 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-18 21:57:51,415 [root] DEBUG: 4908: set_hooks: Unable to hook GetCommandLineW
2026-04-18 21:57:51,426 [root] DEBUG: 4908: Hooked 625 out of 627 functions
2026-04-18 21:57:51,621 [root] DEBUG: 4908: Syscall hook installed, syscall logging level 1
2026-04-18 21:57:51,628 [root] DEBUG: 4908: RestoreHeaders: Restored original import table.
2026-04-18 21:57:51,629 [root] INFO: Loaded monitor into process with pid 4908
2026-04-18 21:57:51,682 [root] DEBUG: 4908: caller_dispatch: Added region at 0x00C90000 to tracked regions list (ntdll::LdrGetProcedureAddress returns to 0x00C916DD, thread 4912).
2026-04-18 21:57:51,684 [root] DEBUG: 4908: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:51,941 [root] DEBUG: 4908: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 0.000000e+00)
2026-04-18 21:57:52,492 [root] DEBUG: 4908: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:52,745 [root] DEBUG: 4908: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 7.107542e-05)
2026-04-18 21:57:52,825 [root] DEBUG: 4908: DLL loaded at 0x73520000: C:\Windows\SYSTEM32\WINMM (0x28000 bytes).
2026-04-18 21:57:52,839 [root] DEBUG: 4908: DLL loaded at 0x72F90000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\COMCTL32 (0x210000 bytes).
2026-04-18 21:57:52,849 [root] DEBUG: 4908: InstrumentationCallback: Added region at 0x7654274C (base 0x76520000) to tracked regions list (thread 4912).
2026-04-18 21:57:52,850 [root] DEBUG: 4908: ProcessTrackedRegion: Region at 0x76520000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-18 21:57:52,884 [root] DEBUG: 4908: DLL loaded at 0x72E20000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_d94ec9f9e106bba9\gdiplus (0x167000 bytes).
2026-04-18 21:57:52,927 [root] DEBUG: 4908: DLL loaded at 0x75F60000: C:\Windows\System32\SHELL32 (0x5b7000 bytes).
2026-04-18 21:57:52,931 [root] DEBUG: 4908: DLL loaded at 0x74140000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-04-18 21:57:52,934 [root] DEBUG: 4908: DLL loaded at 0x72D50000: C:\Windows\SYSTEM32\WINHTTP (0xca000 bytes).
2026-04-18 21:57:52,948 [root] DEBUG: 4908: DLL loaded at 0x73510000: C:\Windows\SYSTEM32\Secur32 (0xa000 bytes).
2026-04-18 21:57:52,950 [root] DEBUG: 4908: DLL loaded at 0x73500000: C:\Windows\SYSTEM32\MSIMG32 (0x6000 bytes).
2026-04-18 21:57:52,955 [root] DEBUG: 4908: DLL loaded at 0x734E0000: C:\Windows\SYSTEM32\USP10 (0x17000 bytes).
2026-04-18 21:57:52,961 [root] DEBUG: 4908: DLL loaded at 0x75D60000: C:\Windows\System32\cfgmgr32 (0x3b000 bytes).
2026-04-18 21:57:52,965 [root] DEBUG: 4908: DLL loaded at 0x76730000: C:\Windows\System32\SETUPAPI (0x438000 bytes).
2026-04-18 21:57:52,980 [root] DEBUG: 4908: DLL loaded at 0x75ED0000: C:\Windows\System32\shcore (0x87000 bytes).
2026-04-18 21:57:52,981 [root] DEBUG: 4908: DLL loaded at 0x72CD0000: C:\Windows\SYSTEM32\WINSPOOL.DRV (0x7d000 bytes).
2026-04-18 21:57:52,988 [root] DEBUG: 4908: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:53,308 [root] DEBUG: 4908: ProcessImageBase: Modified image detected at image base 0x00C90000 - new entropy 7.270379e+00 (change 4.757681e+00).
2026-04-18 21:57:53,310 [root] DEBUG: 4908: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-18 21:57:53,310 [root] DEBUG: 4908: DumpProcess: Instantiating PeParser with address: 0x00C90000.
2026-04-18 21:57:53,311 [root] DEBUG: 4908: DumpProcess: Module entry point VA is 0x00001CE5.
2026-04-18 21:57:53,619 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_898023653571818642026 to CAPE\88047e015334b0ad817659573d1340888fcf0340725cfe20767db097c07e852f; Size is 24673792; Max size: 100000000
2026-04-18 21:57:53,785 [root] DEBUG: 4908: DumpProcess: Module image dump success - dump size 0x1787e00.
2026-04-18 21:57:53,831 [root] DEBUG: 4908: InstrumentationCallback: Added region at 0x75A163AC (base 0x758D0000) to tracked regions list (thread 4912).
2026-04-18 21:57:53,832 [root] DEBUG: 4908: ProcessTrackedRegion: Region at 0x758D0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-18 21:57:53,852 [root] DEBUG: 4908: set_hooks_by_export_directory: Hooked 0 out of 627 functions
2026-04-18 21:57:53,853 [root] DEBUG: 4908: DLL loaded at 0x73B80000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-18 21:57:53,865 [root] DEBUG: 4908: DLL loaded at 0x75800000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-18 21:57:53,876 [root] DEBUG: 4908: DLL loaded at 0x739F0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-18 21:57:53,941 [root] DEBUG: 4908: DLL loaded at 0x747A0000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-04-18 21:57:53,942 [root] DEBUG: 4908: DLL loaded at 0x747D0000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-04-18 21:57:53,947 [root] DEBUG: 4908: DLL loaded at 0x73460000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-04-18 21:57:53,967 [root] DEBUG: 4908: DLL loaded at 0x72CA0000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-18 21:57:54,022 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x04630000, size: 0x1000.
2026-04-18 21:57:54,023 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:54,024 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x00C90000.
2026-04-18 21:57:54,025 [root] DEBUG: 4908: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:54,366 [root] DEBUG: 4908: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 6.660770e-04)
2026-04-18 21:57:54,384 [root] DEBUG: 4908: DLL loaded at 0x76BD0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-04-18 21:57:54,427 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Roaming\AnyDesk\user.conf
2026-04-18 21:57:54,483 [root] DEBUG: 4908: ProcessTrackedRegion: Region at 0x76520000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-18 21:57:54,504 [root] DEBUG: 4908: DLL loaded at 0x72B20000: C:\Windows\SYSTEM32\WindowsCodecs (0x171000 bytes).
2026-04-18 21:57:55,095 [root] DEBUG: 4908: DLL loaded at 0x76EA0000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-04-18 21:57:55,105 [root] DEBUG: 4908: DLL loaded at 0x72AD0000: C:\Windows\System32\thumbcache (0x48000 bytes).
2026-04-18 21:57:55,251 [root] DEBUG: 4908: DLL loaded at 0x729D0000: C:\Windows\SYSTEM32\msvcp110_win (0x65000 bytes).
2026-04-18 21:57:55,252 [root] DEBUG: 4908: DLL loaded at 0x72A40000: C:\Windows\SYSTEM32\policymanager (0x83000 bytes).
2026-04-18 21:57:55,479 [root] DEBUG: 4908: DLL loaded at 0x729C0000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2026-04-18 21:57:55,540 [root] DEBUG: 4908: DLL loaded at 0x729B0000: C:\Windows\SYSTEM32\wtsapi32 (0xf000 bytes).
2026-04-18 21:57:55,721 [root] DEBUG: 4908: DLL loaded at 0x73C20000: C:\Windows\SYSTEM32\PROPSYS (0xc2000 bytes).
2026-04-18 21:57:56,046 [root] DEBUG: 4908: DLL loaded at 0x729B0000: C:\Windows\SYSTEM32\LINKINFO (0xb000 bytes).
2026-04-18 21:57:56,074 [root] DEBUG: 4908: DLL loaded at 0x72950000: C:\Windows\SYSTEM32\ntshrui (0x5c000 bytes).
2026-04-18 21:57:56,087 [root] DEBUG: 4908: DLL loaded at 0x72930000: C:\Windows\SYSTEM32\srvcli (0x1d000 bytes).
2026-04-18 21:57:56,100 [root] DEBUG: 4908: DLL loaded at 0x72920000: C:\Windows\SYSTEM32\cscapi (0xe000 bytes).
2026-04-18 21:57:56,195 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\SD35GUN1W5LD1FQK6LJZ.temp
2026-04-18 21:57:56,208 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ᅫ↑¢¢■○ ¬ ¦○¥.
2026-04-18 21:57:56,208 [root] DEBUG: 4908: OpenProcessHandler: Injection info created for process 2552, handle 0x498: Error obtaining target process name
2026-04-18 21:57:56,218 [root] INFO: Announced 64-bit process name: explorer.exe pid: 2552
2026-04-18 21:57:56,219 [lib.api.process] INFO: Monitor config for <Process 2552 explorer.exe>: C:\wry749yf\dll\2552.ini
2026-04-18 21:57:56,223 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 21:57:56,234 [root] DEBUG: Loader: Injecting process 2552 with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:57:56,238 [root] DEBUG: 2552: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 21:57:56,239 [root] DEBUG: 2552: Disabling sleep skipping.
2026-04-18 21:57:56,240 [root] DEBUG: 2552: Dropped file limit defaulting to 100.
2026-04-18 21:57:56,244 [root] DEBUG: 2552: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 21:57:56,271 [root] DEBUG: 2552: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0
2026-04-18 21:57:56,272 [root] DEBUG: 2552: YaraScan: Scanning 0x00007FF735FF0000, size 0x545316
2026-04-18 21:57:56,414 [root] DEBUG: 2552: Monitor initialised: 64-bit capemon loaded in process 2552 at 0x00007FFEB6B40000, thread 4640, image base 0x00007FF735FF0000, stack from 0x0000000002852000-0x0000000002860000
2026-04-18 21:57:56,415 [root] DEBUG: 2552: Commandline: C:\Windows\Explorer.EXE
2026-04-18 21:57:56,438 [root] DEBUG: 2552: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress
2026-04-18 21:57:56,493 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-18 21:57:56,494 [root] DEBUG: 2552: set_hooks: Unable to hook LockResource
2026-04-18 21:57:56,515 [root] DEBUG: 2552: Hooked 619 out of 620 functions
2026-04-18 21:57:56,580 [root] DEBUG: 2552: Syscall hook installed, syscall logging level 1
2026-04-18 21:57:56,592 [root] INFO: Loaded monitor into process with pid 2552
2026-04-18 21:57:56,599 [root] DEBUG: 2552: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-04-18 21:57:56,601 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-18 21:57:56,602 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:57:56,607 [lib.api.process] INFO: Injected into 64-bit <Process 2552 explorer.exe>
2026-04-18 21:57:56,618 [root] DEBUG: 4908: api-rate-cap: memcpy hook disabled due to rate
2026-04-18 21:57:56,667 [root] DEBUG: 4908: CreateProcessHandler: Injection info set for new process 4712: C:\Temp\AnyDesk.exe, ImageBase: 0x00C90000
2026-04-18 21:57:56,668 [root] INFO: Announced 32-bit process name: AnyDesk.exe pid: 4712
2026-04-18 21:57:56,669 [lib.api.process] INFO: Monitor config for <Process 4712 AnyDesk.exe>: C:\wry749yf\dll\4712.ini
2026-04-18 21:57:56,673 [lib.api.process] INFO: 32-bit DLL to inject is C:\wry749yf\dll\gjyipYwr.dll, loader C:\wry749yf\bin\PnLZeIX.exe
2026-04-18 21:57:56,690 [root] DEBUG: Loader: Injecting process 4712 (thread 4904) with C:\wry749yf\dll\gjyipYwr.dll.
2026-04-18 21:57:56,691 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 21:57:56,692 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\gjyipYwr.dll.
2026-04-18 21:57:56,695 [lib.api.process] INFO: Injected into 32-bit <Process 4712 AnyDesk.exe>
2026-04-18 21:57:56,708 [root] DEBUG: 4908: ProcessTrackedRegion: Region at 0x758D0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-18 21:57:56,721 [root] DEBUG: 4908: DLL loaded at 0x72910000: C:\Windows\SYSTEM32\wtsapi32 (0xf000 bytes).
2026-04-18 21:57:56,723 [root] DEBUG: 4712: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 21:57:56,724 [root] DEBUG: 4712: Dropped file limit defaulting to 100.
2026-04-18 21:57:56,728 [root] DEBUG: 4712: Disabling sleep skipping.
2026-04-18 21:57:56,731 [root] DEBUG: 4712: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 21:57:56,731 [root] DEBUG: 4908: CreateProcessHandler: Injection info set for new process 4560: C:\Temp\AnyDesk.exe, ImageBase: 0x00C90000
2026-04-18 21:57:56,732 [root] DEBUG: 4712: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:56,733 [root] INFO: Announced 32-bit process name: AnyDesk.exe pid: 4560
2026-04-18 21:57:56,734 [lib.api.process] INFO: Monitor config for <Process 4560 AnyDesk.exe>: C:\wry749yf\dll\4560.ini
2026-04-18 21:57:56,739 [lib.api.process] INFO: 32-bit DLL to inject is C:\wry749yf\dll\gjyipYwr.dll, loader C:\wry749yf\bin\PnLZeIX.exe
2026-04-18 21:57:56,753 [root] DEBUG: Loader: Injecting process 4560 (thread 4552) with C:\wry749yf\dll\gjyipYwr.dll.
2026-04-18 21:57:56,754 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 21:57:56,755 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\gjyipYwr.dll.
2026-04-18 21:57:56,758 [lib.api.process] INFO: Injected into 32-bit <Process 4560 AnyDesk.exe>
2026-04-18 21:57:56,770 [root] DEBUG: 4908: ProcessTrackedRegion: Region at 0x758D0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-18 21:57:56,787 [root] DEBUG: 4560: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 21:57:56,788 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08CC0000, size: 0x1000.
2026-04-18 21:57:56,788 [root] DEBUG: 4560: Dropped file limit defaulting to 100.
2026-04-18 21:57:56,789 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,791 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x04630000.
2026-04-18 21:57:56,792 [root] DEBUG: 4908: DumpPEsInRange: Scanning range 0x04630000 - 0x04630020.
2026-04-18 21:57:56,792 [root] DEBUG: 4560: Disabling sleep skipping.
2026-04-18 21:57:56,795 [root] DEBUG: 4908: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:57:56,796 [root] DEBUG: 4560: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 21:57:56,797 [root] DEBUG: 4560: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:56,799 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_676587656571818642026 to CAPE\78c42017ba154226a4ade31925b6f58c496bfda19dbcf45cd29570063e99ca81; Size is 32; Max size: 100000000
2026-04-18 21:57:56,811 [root] DEBUG: 4908: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4908_676587656571818642026 (size 32 bytes)
2026-04-18 21:57:56,812 [root] DEBUG: 4908: DumpRegion: Dumped entire allocation from 0x04630000, size 4096 bytes.
2026-04-18 21:57:56,813 [root] DEBUG: 4908: ProcessTrackedRegion: Dumped region at 0x04630000.
2026-04-18 21:57:56,814 [root] DEBUG: 4908: YaraScan: Scanning 0x04630000, size 0x20
2026-04-18 21:57:56,817 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08CD0000, size: 0x1000.
2026-04-18 21:57:56,818 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,819 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08CC0000.
2026-04-18 21:57:56,820 [root] DEBUG: 4908: DumpPEsInRange: Scanning range 0x08CC0000 - 0x08CC0020.
2026-04-18 21:57:56,821 [root] DEBUG: 4908: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:57:56,823 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_1974186456571818642026 to CAPE\2548f0ef6c55fc357be79f959e829f7a0ce646313040a8c685cbc6f81154402f; Size is 32; Max size: 100000000
2026-04-18 21:57:56,842 [root] DEBUG: 4908: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4908_1974186456571818642026 (size 32 bytes)
2026-04-18 21:57:56,843 [root] DEBUG: 4908: DumpRegion: Dumped entire allocation from 0x08CC0000, size 4096 bytes.
2026-04-18 21:57:56,844 [root] DEBUG: 4908: ProcessTrackedRegion: Dumped region at 0x08CC0000.
2026-04-18 21:57:56,845 [root] DEBUG: 4908: YaraScan: Scanning 0x08CC0000, size 0x20
2026-04-18 21:57:56,847 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08CE0000, size: 0x1000.
2026-04-18 21:57:56,847 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,848 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08CD0000.
2026-04-18 21:57:56,849 [root] DEBUG: 4908: DumpPEsInRange: Scanning range 0x08CD0000 - 0x08CD0020.
2026-04-18 21:57:56,850 [root] DEBUG: 4908: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:57:56,853 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_2436756056571818642026 to CAPE\22c77b9e1c9f3674c5d03a4f9858e2647eb23de89ac15073ef5273aba1669769; Size is 32; Max size: 100000000
2026-04-18 21:57:56,857 [root] DEBUG: 4908: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4908_2436756056571818642026 (size 32 bytes)
2026-04-18 21:57:56,858 [root] DEBUG: 4908: DumpRegion: Dumped entire allocation from 0x08CD0000, size 4096 bytes.
2026-04-18 21:57:56,859 [root] DEBUG: 4908: ProcessTrackedRegion: Dumped region at 0x08CD0000.
2026-04-18 21:57:56,860 [root] DEBUG: 4908: YaraScan: Scanning 0x08CD0000, size 0x20
2026-04-18 21:57:56,899 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D00000, size: 0x1000.
2026-04-18 21:57:56,900 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,901 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08CE0000.
2026-04-18 21:57:56,901 [root] DEBUG: 4908: DumpPEsInRange: Scanning range 0x08CE0000 - 0x08CE0020.
2026-04-18 21:57:56,902 [root] DEBUG: 4908: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:57:56,905 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_375232056571818642026 to CAPE\a8f6df4ee37367ac5f0d279a019f6fa56234a5ce118f72998124cbec6c9bf6ea; Size is 32; Max size: 100000000
2026-04-18 21:57:56,920 [root] DEBUG: 4908: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4908_375232056571818642026 (size 32 bytes)
2026-04-18 21:57:56,921 [root] DEBUG: 4908: DumpRegion: Dumped entire allocation from 0x08CE0000, size 4096 bytes.
2026-04-18 21:57:56,922 [root] DEBUG: 4908: ProcessTrackedRegion: Dumped region at 0x08CE0000.
2026-04-18 21:57:56,923 [root] DEBUG: 4908: YaraScan: Scanning 0x08CE0000, size 0x20
2026-04-18 21:57:56,925 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D10000, size: 0x1000.
2026-04-18 21:57:56,926 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,926 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D00000.
2026-04-18 21:57:56,927 [root] DEBUG: 4908: DumpPEsInRange: Scanning range 0x08D00000 - 0x08D00020.
2026-04-18 21:57:56,928 [root] DEBUG: 4908: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:57:56,930 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_1447686056571818642026 to CAPE\d3828d2b1016d52062c81ea45241f7cf346e204cf4320247ba8d0ae4ff294f4a; Size is 32; Max size: 100000000
2026-04-18 21:57:56,936 [root] DEBUG: 4908: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4908_1447686056571818642026 (size 32 bytes)
2026-04-18 21:57:56,936 [root] DEBUG: 4908: DumpRegion: Dumped entire allocation from 0x08D00000, size 4096 bytes.
2026-04-18 21:57:56,937 [root] DEBUG: 4908: ProcessTrackedRegion: Dumped region at 0x08D00000.
2026-04-18 21:57:56,938 [root] DEBUG: 4908: YaraScan: Scanning 0x08D00000, size 0x20
2026-04-18 21:57:56,940 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D20000, size: 0x1000.
2026-04-18 21:57:56,941 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,942 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D10000.
2026-04-18 21:57:56,943 [root] DEBUG: 4908: DumpPEsInRange: Scanning range 0x08D10000 - 0x08D10020.
2026-04-18 21:57:56,943 [root] DEBUG: 4908: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:57:56,946 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_405481856571818642026 to CAPE\43743300f272617c6ef9d4aaa3e1da06e78cafadc3abd32210780b0e8c9298a6; Size is 32; Max size: 100000000
2026-04-18 21:57:56,951 [root] DEBUG: 4908: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4908_405481856571818642026 (size 32 bytes)
2026-04-18 21:57:56,952 [root] DEBUG: 4908: DumpRegion: Dumped entire allocation from 0x08D10000, size 4096 bytes.
2026-04-18 21:57:56,952 [root] DEBUG: 4908: ProcessTrackedRegion: Dumped region at 0x08D10000.
2026-04-18 21:57:56,953 [root] DEBUG: 4908: YaraScan: Scanning 0x08D10000, size 0x20
2026-04-18 21:57:56,954 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D30000, size: 0x1000.
2026-04-18 21:57:56,955 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,956 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D20000.
2026-04-18 21:57:56,957 [root] DEBUG: 4908: DumpPEsInRange: Scanning range 0x08D20000 - 0x08D20020.
2026-04-18 21:57:56,957 [root] DEBUG: 4908: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:57:56,960 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_2448325156571818642026 to CAPE\a92f336be56f90889cf6366a60a5de9b646ecb668e2e8c78ac2848bda4e67793; Size is 32; Max size: 100000000
2026-04-18 21:57:56,967 [root] DEBUG: 4908: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4908_2448325156571818642026 (size 32 bytes)
2026-04-18 21:57:56,967 [root] DEBUG: 4908: DumpRegion: Dumped entire allocation from 0x08D20000, size 4096 bytes.
2026-04-18 21:57:56,969 [root] DEBUG: 4908: ProcessTrackedRegion: Dumped region at 0x08D20000.
2026-04-18 21:57:56,969 [root] DEBUG: 4908: YaraScan: Scanning 0x08D20000, size 0x20
2026-04-18 21:57:56,972 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D40000, size: 0x1000.
2026-04-18 21:57:56,973 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,973 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D30000.
2026-04-18 21:57:56,974 [root] DEBUG: 4908: DumpPEsInRange: Scanning range 0x08D30000 - 0x08D30020.
2026-04-18 21:57:56,975 [root] DEBUG: 4908: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:57:56,978 [root] DEBUG: 4712: Monitor initialised: 32-bit capemon loaded in process 4712 at 0x731a0000, thread 4904, image base 0xc90000, stack from 0x765000-0x770000
2026-04-18 21:57:56,978 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4908_1485907056571818642026 to CAPE\be4e8a1c5683220813f2dbfc07375f9a227691c3676c48d15ac7fc3172efa786; Size is 32; Max size: 100000000
2026-04-18 21:57:56,979 [root] DEBUG: 4712: Commandline: "C:\Temp\AnyDesk.exe" --local-service
2026-04-18 21:57:56,982 [root] DEBUG: 4908: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4908_1485907056571818642026 (size 32 bytes)
2026-04-18 21:57:56,983 [root] DEBUG: 4908: DumpRegion: Dumped entire allocation from 0x08D30000, size 4096 bytes.
2026-04-18 21:57:56,983 [root] DEBUG: 4908: ProcessTrackedRegion: Dumped region at 0x08D30000.
2026-04-18 21:57:56,984 [root] DEBUG: 4908: YaraScan: Scanning 0x08D30000, size 0x20
2026-04-18 21:57:56,986 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D50000, size: 0x1000.
2026-04-18 21:57:56,987 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,988 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D40000.
2026-04-18 21:57:56,989 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D40000 skipped due to dump limit 10
2026-04-18 21:57:56,989 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D40000.
2026-04-18 21:57:56,990 [root] DEBUG: 4908: YaraScan: Scanning 0x08D40000, size 0x20
2026-04-18 21:57:56,991 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D60000, size: 0x1000.
2026-04-18 21:57:56,992 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,993 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D50000.
2026-04-18 21:57:56,994 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D50000 skipped due to dump limit 10
2026-04-18 21:57:56,995 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D50000.
2026-04-18 21:57:56,996 [root] DEBUG: 4908: YaraScan: Scanning 0x08D50000, size 0x20
2026-04-18 21:57:56,997 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D70000, size: 0x1000.
2026-04-18 21:57:56,998 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:56,999 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D60000.
2026-04-18 21:57:57,000 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D60000 skipped due to dump limit 10
2026-04-18 21:57:57,001 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D60000.
2026-04-18 21:57:57,001 [root] DEBUG: 4908: YaraScan: Scanning 0x08D60000, size 0x20
2026-04-18 21:57:57,003 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D80000, size: 0x1000.
2026-04-18 21:57:57,003 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,004 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D70000.
2026-04-18 21:57:57,005 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D70000 skipped due to dump limit 10
2026-04-18 21:57:57,006 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D70000.
2026-04-18 21:57:57,007 [root] DEBUG: 4908: YaraScan: Scanning 0x08D70000, size 0x20
2026-04-18 21:57:57,008 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08D90000, size: 0x1000.
2026-04-18 21:57:57,008 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,009 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D80000.
2026-04-18 21:57:57,010 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D80000 skipped due to dump limit 10
2026-04-18 21:57:57,011 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D80000.
2026-04-18 21:57:57,012 [root] DEBUG: 4908: YaraScan: Scanning 0x08D80000, size 0x20
2026-04-18 21:57:57,013 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08DA0000, size: 0x1000.
2026-04-18 21:57:57,014 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,015 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08D90000.
2026-04-18 21:57:57,015 [root] DEBUG: 4712: hook_api: LdrpCallInitRoutine export address 0x76FC2B50 obtained via GetFunctionAddress
2026-04-18 21:57:57,016 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D90000 skipped due to dump limit 10
2026-04-18 21:57:57,017 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D90000.
2026-04-18 21:57:57,018 [root] DEBUG: 4908: YaraScan: Scanning 0x08D90000, size 0x20
2026-04-18 21:57:57,020 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08DB0000, size: 0x1000.
2026-04-18 21:57:57,020 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,021 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08DA0000.
2026-04-18 21:57:57,022 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DA0000 skipped due to dump limit 10
2026-04-18 21:57:57,023 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DA0000.
2026-04-18 21:57:57,023 [root] DEBUG: 4908: YaraScan: Scanning 0x08DA0000, size 0x20
2026-04-18 21:57:57,030 [root] DEBUG: 4560: Monitor initialised: 32-bit capemon loaded in process 4560 at 0x731a0000, thread 4552, image base 0xc90000, stack from 0x2556000-0x2560000
2026-04-18 21:57:57,031 [root] DEBUG: 4560: Commandline: "C:\Temp\AnyDesk.exe" --local-control
2026-04-18 21:57:57,048 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-18 21:57:57,049 [root] DEBUG: 4712: set_hooks: Unable to hook GetCommandLineA
2026-04-18 21:57:57,050 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-18 21:57:57,051 [root] DEBUG: 4712: set_hooks: Unable to hook GetCommandLineW
2026-04-18 21:57:57,060 [root] DEBUG: 4712: Hooked 625 out of 627 functions
2026-04-18 21:57:57,067 [root] DEBUG: 4560: hook_api: LdrpCallInitRoutine export address 0x76FC2B50 obtained via GetFunctionAddress
2026-04-18 21:57:57,070 [root] DEBUG: 4908: DLL loaded at 0x72880000: C:\Windows\SYSTEM32\TextShaping (0x95000 bytes).
2026-04-18 21:57:57,092 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x095B0000, size: 0x1000.
2026-04-18 21:57:57,093 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,094 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08DB0000.
2026-04-18 21:57:57,094 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DB0000 skipped due to dump limit 10
2026-04-18 21:57:57,095 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DB0000.
2026-04-18 21:57:57,096 [root] DEBUG: 4908: YaraScan: Scanning 0x08DB0000, size 0x20
2026-04-18 21:57:57,097 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x095C0000, size: 0x1000.
2026-04-18 21:57:57,098 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,099 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x095B0000.
2026-04-18 21:57:57,099 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-04-18 21:57:57,100 [root] DEBUG: 4908: DumpRegion: Dump at 0x095B0000 skipped due to dump limit 10
2026-04-18 21:57:57,101 [root] DEBUG: 4560: set_hooks: Unable to hook GetCommandLineA
2026-04-18 21:57:57,102 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095B0000.
2026-04-18 21:57:57,102 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-04-18 21:57:57,103 [root] DEBUG: 4560: set_hooks: Unable to hook GetCommandLineW
2026-04-18 21:57:57,104 [root] DEBUG: 4908: YaraScan: Scanning 0x095B0000, size 0x20
2026-04-18 21:57:57,105 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x095D0000, size: 0x1000.
2026-04-18 21:57:57,106 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,107 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x095C0000.
2026-04-18 21:57:57,108 [root] DEBUG: 4908: DumpRegion: Dump at 0x095C0000 skipped due to dump limit 10
2026-04-18 21:57:57,108 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095C0000.
2026-04-18 21:57:57,109 [root] DEBUG: 4908: YaraScan: Scanning 0x095C0000, size 0x20
2026-04-18 21:57:57,110 [root] DEBUG: 4560: Hooked 625 out of 627 functions
2026-04-18 21:57:57,114 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x095E0000, size: 0x1000.
2026-04-18 21:57:57,115 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,116 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x095D0000.
2026-04-18 21:57:57,117 [root] DEBUG: 4908: DumpRegion: Dump at 0x095D0000 skipped due to dump limit 10
2026-04-18 21:57:57,118 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095D0000.
2026-04-18 21:57:57,119 [root] DEBUG: 4908: YaraScan: Scanning 0x095D0000, size 0x20
2026-04-18 21:57:57,120 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x095F0000, size: 0x1000.
2026-04-18 21:57:57,122 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,123 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x095E0000.
2026-04-18 21:57:57,123 [root] DEBUG: 4908: DumpRegion: Dump at 0x095E0000 skipped due to dump limit 10
2026-04-18 21:57:57,124 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095E0000.
2026-04-18 21:57:57,125 [root] DEBUG: 4908: YaraScan: Scanning 0x095E0000, size 0x20
2026-04-18 21:57:57,127 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09600000, size: 0x1000.
2026-04-18 21:57:57,128 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,128 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x095F0000.
2026-04-18 21:57:57,129 [root] DEBUG: 4908: DumpRegion: Dump at 0x095F0000 skipped due to dump limit 10
2026-04-18 21:57:57,130 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095F0000.
2026-04-18 21:57:57,131 [root] DEBUG: 4908: YaraScan: Scanning 0x095F0000, size 0x20
2026-04-18 21:57:57,132 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09610000, size: 0x1000.
2026-04-18 21:57:57,133 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,134 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09600000.
2026-04-18 21:57:57,135 [root] DEBUG: 4908: DumpRegion: Dump at 0x09600000 skipped due to dump limit 10
2026-04-18 21:57:57,136 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09600000.
2026-04-18 21:57:57,136 [root] DEBUG: 4908: YaraScan: Scanning 0x09600000, size 0x20
2026-04-18 21:57:57,138 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09620000, size: 0x1000.
2026-04-18 21:57:57,139 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,140 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09610000.
2026-04-18 21:57:57,140 [root] DEBUG: 4908: DumpRegion: Dump at 0x09610000 skipped due to dump limit 10
2026-04-18 21:57:57,141 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09610000.
2026-04-18 21:57:57,142 [root] DEBUG: 4908: YaraScan: Scanning 0x09610000, size 0x20
2026-04-18 21:57:57,180 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09730000, size: 0x1000.
2026-04-18 21:57:57,181 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,182 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09620000.
2026-04-18 21:57:57,183 [root] DEBUG: 4908: DumpRegion: Dump at 0x09620000 skipped due to dump limit 10
2026-04-18 21:57:57,184 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09620000.
2026-04-18 21:57:57,185 [root] DEBUG: 4908: YaraScan: Scanning 0x09620000, size 0x20
2026-04-18 21:57:57,186 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09740000, size: 0x1000.
2026-04-18 21:57:57,187 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,188 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09730000.
2026-04-18 21:57:57,188 [root] DEBUG: 4908: DumpRegion: Dump at 0x09730000 skipped due to dump limit 10
2026-04-18 21:57:57,189 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09730000.
2026-04-18 21:57:57,190 [root] DEBUG: 4908: YaraScan: Scanning 0x09730000, size 0x20
2026-04-18 21:57:57,192 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09750000, size: 0x1000.
2026-04-18 21:57:57,193 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,193 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09740000.
2026-04-18 21:57:57,194 [root] DEBUG: 4908: DumpRegion: Dump at 0x09740000 skipped due to dump limit 10
2026-04-18 21:57:57,195 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09740000.
2026-04-18 21:57:57,196 [root] DEBUG: 4908: YaraScan: Scanning 0x09740000, size 0x20
2026-04-18 21:57:57,199 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09760000, size: 0x1000.
2026-04-18 21:57:57,200 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,201 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09750000.
2026-04-18 21:57:57,202 [root] DEBUG: 4908: DumpRegion: Dump at 0x09750000 skipped due to dump limit 10
2026-04-18 21:57:57,203 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09750000.
2026-04-18 21:57:57,204 [root] DEBUG: 4908: YaraScan: Scanning 0x09750000, size 0x20
2026-04-18 21:57:57,208 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09770000, size: 0x1000.
2026-04-18 21:57:57,209 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,210 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09760000.
2026-04-18 21:57:57,211 [root] DEBUG: 4908: DumpRegion: Dump at 0x09760000 skipped due to dump limit 10
2026-04-18 21:57:57,212 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09760000.
2026-04-18 21:57:57,213 [root] DEBUG: 4908: YaraScan: Scanning 0x09760000, size 0x20
2026-04-18 21:57:57,225 [root] DEBUG: 2552: caller_dispatch: Added region at 0x00007FF735FF0000 to tracked regions list (user32::MsgWaitForMultipleObjectsEx returns to 0x00007FF73606ABE9, thread 2768).
2026-04-18 21:57:57,226 [root] DEBUG: 2552: YaraScan: Scanning 0x00007FF735FF0000, size 0x545316
2026-04-18 21:57:57,266 [root] DEBUG: 4712: Syscall hook installed, syscall logging level 1
2026-04-18 21:57:57,272 [root] DEBUG: 4712: RestoreHeaders: Restored original import table.
2026-04-18 21:57:57,273 [root] INFO: Loaded monitor into process with pid 4712
2026-04-18 21:57:57,301 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09780000, size: 0x1000.
2026-04-18 21:57:57,302 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,302 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09770000.
2026-04-18 21:57:57,303 [root] DEBUG: 4908: DumpRegion: Dump at 0x09770000 skipped due to dump limit 10
2026-04-18 21:57:57,304 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09770000.
2026-04-18 21:57:57,305 [root] DEBUG: 4908: YaraScan: Scanning 0x09770000, size 0x20
2026-04-18 21:57:57,307 [root] DEBUG: 2552: ProcessImageBase: Main module image at 0x00007FF735FF0000 unmodified (entropy change 0.000000e+00)
2026-04-18 21:57:57,308 [root] DEBUG: 4560: Syscall hook installed, syscall logging level 1
2026-04-18 21:57:57,313 [root] DEBUG: 4560: RestoreHeaders: Restored original import table.
2026-04-18 21:57:57,314 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09790000, size: 0x1000.
2026-04-18 21:57:57,314 [root] INFO: Loaded monitor into process with pid 4560
2026-04-18 21:57:57,316 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,317 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09780000.
2026-04-18 21:57:57,318 [root] DEBUG: 4908: DumpRegion: Dump at 0x09780000 skipped due to dump limit 10
2026-04-18 21:57:57,319 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09780000.
2026-04-18 21:57:57,320 [root] DEBUG: 4908: YaraScan: Scanning 0x09780000, size 0x20
2026-04-18 21:57:57,322 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x097A0000, size: 0x1000.
2026-04-18 21:57:57,323 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,324 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09790000.
2026-04-18 21:57:57,325 [root] DEBUG: 4908: DumpRegion: Dump at 0x09790000 skipped due to dump limit 10
2026-04-18 21:57:57,325 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09790000.
2026-04-18 21:57:57,326 [root] DEBUG: 4908: YaraScan: Scanning 0x09790000, size 0x20
2026-04-18 21:57:57,327 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x097B0000, size: 0x1000.
2026-04-18 21:57:57,328 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,329 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x097A0000.
2026-04-18 21:57:57,329 [root] DEBUG: 4908: DumpRegion: Dump at 0x097A0000 skipped due to dump limit 10
2026-04-18 21:57:57,330 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097A0000.
2026-04-18 21:57:57,331 [root] DEBUG: 4908: YaraScan: Scanning 0x097A0000, size 0x20
2026-04-18 21:57:57,334 [root] DEBUG: 4712: caller_dispatch: Added region at 0x00C90000 to tracked regions list (ntdll::LdrGetProcedureAddress returns to 0x00C916DD, thread 4904).
2026-04-18 21:57:57,336 [root] DEBUG: 4712: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:57,342 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x097C0000, size: 0x1000.
2026-04-18 21:57:57,343 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,344 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x097B0000.
2026-04-18 21:57:57,345 [root] DEBUG: 4908: DumpRegion: Dump at 0x097B0000 skipped due to dump limit 10
2026-04-18 21:57:57,345 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097B0000.
2026-04-18 21:57:57,346 [root] DEBUG: 4908: YaraScan: Scanning 0x097B0000, size 0x20
2026-04-18 21:57:57,368 [root] DEBUG: 4560: caller_dispatch: Added region at 0x00C90000 to tracked regions list (ntdll::LdrGetProcedureAddress returns to 0x00C916DD, thread 4552).
2026-04-18 21:57:57,370 [root] DEBUG: 4560: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:57,380 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x097D0000, size: 0x1000.
2026-04-18 21:57:57,381 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,382 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x097C0000.
2026-04-18 21:57:57,383 [root] DEBUG: 4908: DumpRegion: Dump at 0x097C0000 skipped due to dump limit 10
2026-04-18 21:57:57,384 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097C0000.
2026-04-18 21:57:57,385 [root] DEBUG: 4908: YaraScan: Scanning 0x097C0000, size 0x20
2026-04-18 21:57:57,390 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x097E0000, size: 0x1000.
2026-04-18 21:57:57,391 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,391 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x097D0000.
2026-04-18 21:57:57,392 [root] DEBUG: 4908: DumpRegion: Dump at 0x097D0000 skipped due to dump limit 10
2026-04-18 21:57:57,393 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097D0000.
2026-04-18 21:57:57,394 [root] DEBUG: 4908: YaraScan: Scanning 0x097D0000, size 0x20
2026-04-18 21:57:57,396 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x097F0000, size: 0x1000.
2026-04-18 21:57:57,396 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,397 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x097E0000.
2026-04-18 21:57:57,398 [root] DEBUG: 4908: DumpRegion: Dump at 0x097E0000 skipped due to dump limit 10
2026-04-18 21:57:57,399 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097E0000.
2026-04-18 21:57:57,400 [root] DEBUG: 4908: YaraScan: Scanning 0x097E0000, size 0x20
2026-04-18 21:57:57,401 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09800000, size: 0x1000.
2026-04-18 21:57:57,402 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,403 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x097F0000.
2026-04-18 21:57:57,403 [root] DEBUG: 4908: DumpRegion: Dump at 0x097F0000 skipped due to dump limit 10
2026-04-18 21:57:57,404 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097F0000.
2026-04-18 21:57:57,405 [root] DEBUG: 4908: YaraScan: Scanning 0x097F0000, size 0x20
2026-04-18 21:57:57,409 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09810000, size: 0x1000.
2026-04-18 21:57:57,410 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,411 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09800000.
2026-04-18 21:57:57,412 [root] DEBUG: 4908: DumpRegion: Dump at 0x09800000 skipped due to dump limit 10
2026-04-18 21:57:57,413 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09800000.
2026-04-18 21:57:57,413 [root] DEBUG: 4908: YaraScan: Scanning 0x09800000, size 0x20
2026-04-18 21:57:57,416 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09820000, size: 0x1000.
2026-04-18 21:57:57,417 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,418 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09810000.
2026-04-18 21:57:57,419 [root] DEBUG: 4908: DumpRegion: Dump at 0x09810000 skipped due to dump limit 10
2026-04-18 21:57:57,419 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09810000.
2026-04-18 21:57:57,420 [root] DEBUG: 4908: YaraScan: Scanning 0x09810000, size 0x20
2026-04-18 21:57:57,444 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09830000, size: 0x1000.
2026-04-18 21:57:57,445 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,446 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09820000.
2026-04-18 21:57:57,447 [root] DEBUG: 4908: DumpRegion: Dump at 0x09820000 skipped due to dump limit 10
2026-04-18 21:57:57,492 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09820000.
2026-04-18 21:57:57,493 [root] DEBUG: 4908: YaraScan: Scanning 0x09820000, size 0x20
2026-04-18 21:57:57,496 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08DC0000, size: 0x1000.
2026-04-18 21:57:57,497 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,498 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09830000.
2026-04-18 21:57:57,500 [root] DEBUG: 4908: DumpRegion: Dump at 0x09830000 skipped due to dump limit 10
2026-04-18 21:57:57,522 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09830000.
2026-04-18 21:57:57,523 [root] DEBUG: 4908: YaraScan: Scanning 0x09830000, size 0x20
2026-04-18 21:57:57,550 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08DD0000, size: 0x1000.
2026-04-18 21:57:57,552 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,552 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08DC0000.
2026-04-18 21:57:57,553 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DC0000 skipped due to dump limit 10
2026-04-18 21:57:57,554 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DC0000.
2026-04-18 21:57:57,555 [root] DEBUG: 4908: YaraScan: Scanning 0x08DC0000, size 0x20
2026-04-18 21:57:57,556 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08DE0000, size: 0x1000.
2026-04-18 21:57:57,557 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,558 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08DD0000.
2026-04-18 21:57:57,559 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DD0000 skipped due to dump limit 10
2026-04-18 21:57:57,560 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DD0000.
2026-04-18 21:57:57,561 [root] DEBUG: 4908: YaraScan: Scanning 0x08DD0000, size 0x20
2026-04-18 21:57:57,563 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08DF0000, size: 0x1000.
2026-04-18 21:57:57,564 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,565 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08DE0000.
2026-04-18 21:57:57,565 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DE0000 skipped due to dump limit 10
2026-04-18 21:57:57,566 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DE0000.
2026-04-18 21:57:57,571 [root] DEBUG: 4908: YaraScan: Scanning 0x08DE0000, size 0x20
2026-04-18 21:57:57,580 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08E00000, size: 0x1000.
2026-04-18 21:57:57,581 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,582 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08DF0000.
2026-04-18 21:57:57,583 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DF0000 skipped due to dump limit 10
2026-04-18 21:57:57,584 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DF0000.
2026-04-18 21:57:57,585 [root] DEBUG: 4908: YaraScan: Scanning 0x08DF0000, size 0x20
2026-04-18 21:57:57,586 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08E10000, size: 0x1000.
2026-04-18 21:57:57,587 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,588 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08E00000.
2026-04-18 21:57:57,589 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E00000 skipped due to dump limit 10
2026-04-18 21:57:57,590 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E00000.
2026-04-18 21:57:57,590 [root] DEBUG: 4908: YaraScan: Scanning 0x08E00000, size 0x20
2026-04-18 21:57:57,592 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08E20000, size: 0x1000.
2026-04-18 21:57:57,593 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,593 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08E10000.
2026-04-18 21:57:57,594 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E10000 skipped due to dump limit 10
2026-04-18 21:57:57,595 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E10000.
2026-04-18 21:57:57,596 [root] DEBUG: 4908: YaraScan: Scanning 0x08E10000, size 0x20
2026-04-18 21:57:57,598 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08E30000, size: 0x1000.
2026-04-18 21:57:57,599 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,600 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08E20000.
2026-04-18 21:57:57,601 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E20000 skipped due to dump limit 10
2026-04-18 21:57:57,602 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E20000.
2026-04-18 21:57:57,603 [root] DEBUG: 4908: YaraScan: Scanning 0x08E20000, size 0x20
2026-04-18 21:57:57,603 [root] DEBUG: 4712: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 0.000000e+00)
2026-04-18 21:57:57,606 [root] DEBUG: 4908: DLL loaded at 0x72850000: C:\Windows\SYSTEM32\dwmapi (0x26000 bytes).
2026-04-18 21:57:57,609 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08E40000, size: 0x1000.
2026-04-18 21:57:57,609 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,610 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08E30000.
2026-04-18 21:57:57,611 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E30000 skipped due to dump limit 10
2026-04-18 21:57:57,612 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E30000.
2026-04-18 21:57:57,612 [root] DEBUG: 4908: YaraScan: Scanning 0x08E30000, size 0x20
2026-04-18 21:57:57,615 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08E50000, size: 0x1000.
2026-04-18 21:57:57,616 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,616 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08E40000.
2026-04-18 21:57:57,617 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E40000 skipped due to dump limit 10
2026-04-18 21:57:57,618 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E40000.
2026-04-18 21:57:57,619 [root] DEBUG: 4908: YaraScan: Scanning 0x08E40000, size 0x20
2026-04-18 21:57:57,621 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08E60000, size: 0x1000.
2026-04-18 21:57:57,622 [root] DEBUG: 4560: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 0.000000e+00)
2026-04-18 21:57:57,622 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,623 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08E50000.
2026-04-18 21:57:57,624 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E50000 skipped due to dump limit 10
2026-04-18 21:57:57,625 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E50000.
2026-04-18 21:57:57,626 [root] DEBUG: 4908: YaraScan: Scanning 0x08E50000, size 0x20
2026-04-18 21:57:57,627 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08E70000, size: 0x1000.
2026-04-18 21:57:57,628 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:57:57,629 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08E60000.
2026-04-18 21:57:57,629 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E60000 skipped due to dump limit 10
2026-04-18 21:57:57,630 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E60000.
2026-04-18 21:57:57,631 [root] DEBUG: 4908: YaraScan: Scanning 0x08E60000, size 0x20
2026-04-18 21:57:57,752 [root] DEBUG: 2552: OpenProcessHandler: Injection info created for process 4908, handle 0x17fc: C:\Temp\AnyDesk.exe
2026-04-18 21:57:57,837 [root] DEBUG: 4908: DLL loaded at 0x72470000: C:\Windows\System32\CoreMessaging (0x9b000 bytes).
2026-04-18 21:57:57,839 [root] DEBUG: 4908: DLL loaded at 0x72390000: C:\Windows\SYSTEM32\wintypes (0xdc000 bytes).
2026-04-18 21:57:57,840 [root] DEBUG: 4908: DLL loaded at 0x72510000: C:\Windows\System32\CoreUIComponents (0x27f000 bytes).
2026-04-18 21:57:57,841 [root] DEBUG: 4908: DLL loaded at 0x72790000: C:\Windows\SYSTEM32\textinputframework (0xb9000 bytes).
2026-04-18 21:57:57,930 [root] DEBUG: 4908: DLL loaded at 0x721C0000: C:\Windows\system32\explorerframe (0x1cb000 bytes).
2026-04-18 21:57:58,273 [root] DEBUG: 4712: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:58,279 [root] DEBUG: 4560: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:58,344 [root] DEBUG: 2552: OpenProcessHandler: Image base for process 4908 (handle 0xd30): 0x0000000000C90000.
2026-04-18 21:57:58,366 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
2026-04-18 21:57:58,443 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ᅫ↑¢¢■○ ¬ ¦○¥.
2026-04-18 21:57:58,444 [root] DEBUG: 2552: OpenProcessHandler: Injection info created for process 1432, handle 0x1eac: Error obtaining target process name
2026-04-18 21:57:58,445 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ᅫ↑¢¢■○ ¬ ¦○¥.
2026-04-18 21:57:58,446 [root] DEBUG: 2552: OpenProcessHandler: Injection info created for process 3464, handle 0xdc8: Error obtaining target process name
2026-04-18 21:57:58,451 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ᅫ↑¢¢■○ ¬ ¦○¥.
2026-04-18 21:57:58,452 [root] DEBUG: 2552: OpenProcessHandler: Injection info created for process 3100, handle 0xdb4: Error obtaining target process name
2026-04-18 21:57:58,606 [root] DEBUG: 4712: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 6.989782e-05)
2026-04-18 21:57:58,607 [root] DEBUG: 4560: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 7.107432e-05)
2026-04-18 21:57:58,674 [root] DEBUG: 4712: DLL loaded at 0x73520000: C:\Windows\SYSTEM32\WINMM (0x28000 bytes).
2026-04-18 21:57:58,675 [root] DEBUG: 4560: DLL loaded at 0x73520000: C:\Windows\SYSTEM32\WINMM (0x28000 bytes).
2026-04-18 21:57:58,686 [root] DEBUG: 4712: DLL loaded at 0x72F90000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\COMCTL32 (0x210000 bytes).
2026-04-18 21:57:58,688 [root] DEBUG: 4560: DLL loaded at 0x72F90000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\COMCTL32 (0x210000 bytes).
2026-04-18 21:57:58,696 [root] DEBUG: 4712: InstrumentationCallback: Added region at 0x7654274C (base 0x76520000) to tracked regions list (thread 4904).
2026-04-18 21:57:58,696 [root] DEBUG: 4712: ProcessTrackedRegion: Region at 0x76520000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-18 21:57:58,699 [root] DEBUG: 4560: InstrumentationCallback: Added region at 0x7654274C (base 0x76520000) to tracked regions list (thread 4552).
2026-04-18 21:57:58,700 [root] DEBUG: 4560: ProcessTrackedRegion: Region at 0x76520000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-18 21:57:58,727 [root] DEBUG: 4712: DLL loaded at 0x72E20000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_d94ec9f9e106bba9\gdiplus (0x167000 bytes).
2026-04-18 21:57:58,737 [root] DEBUG: 4560: DLL loaded at 0x72E20000: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_d94ec9f9e106bba9\gdiplus (0x167000 bytes).
2026-04-18 21:57:58,770 [root] DEBUG: 4560: DLL loaded at 0x75F60000: C:\Windows\System32\SHELL32 (0x5b7000 bytes).
2026-04-18 21:57:58,771 [root] DEBUG: 4712: DLL loaded at 0x75F60000: C:\Windows\System32\SHELL32 (0x5b7000 bytes).
2026-04-18 21:57:58,774 [root] DEBUG: 4560: DLL loaded at 0x74140000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-04-18 21:57:58,774 [root] DEBUG: 4712: DLL loaded at 0x74140000: C:\Windows\SYSTEM32\IPHLPAPI (0x32000 bytes).
2026-04-18 21:57:58,777 [root] DEBUG: 4560: DLL loaded at 0x72D50000: C:\Windows\SYSTEM32\WINHTTP (0xca000 bytes).
2026-04-18 21:57:58,777 [root] DEBUG: 4712: DLL loaded at 0x72D50000: C:\Windows\SYSTEM32\WINHTTP (0xca000 bytes).
2026-04-18 21:57:58,779 [root] DEBUG: 4560: DLL loaded at 0x73510000: C:\Windows\SYSTEM32\Secur32 (0xa000 bytes).
2026-04-18 21:57:58,780 [root] DEBUG: 4712: DLL loaded at 0x73510000: C:\Windows\SYSTEM32\Secur32 (0xa000 bytes).
2026-04-18 21:57:58,781 [root] DEBUG: 4560: DLL loaded at 0x73500000: C:\Windows\SYSTEM32\MSIMG32 (0x6000 bytes).
2026-04-18 21:57:58,782 [root] DEBUG: 4712: DLL loaded at 0x73500000: C:\Windows\SYSTEM32\MSIMG32 (0x6000 bytes).
2026-04-18 21:57:58,784 [root] DEBUG: 4560: DLL loaded at 0x734E0000: C:\Windows\SYSTEM32\USP10 (0x17000 bytes).
2026-04-18 21:57:58,785 [root] DEBUG: 4712: DLL loaded at 0x734E0000: C:\Windows\SYSTEM32\USP10 (0x17000 bytes).
2026-04-18 21:57:58,786 [root] DEBUG: 4560: DLL loaded at 0x75D60000: C:\Windows\System32\cfgmgr32 (0x3b000 bytes).
2026-04-18 21:57:58,787 [root] DEBUG: 4712: DLL loaded at 0x75D60000: C:\Windows\System32\cfgmgr32 (0x3b000 bytes).
2026-04-18 21:57:58,787 [root] DEBUG: 4560: DLL loaded at 0x76730000: C:\Windows\System32\SETUPAPI (0x438000 bytes).
2026-04-18 21:57:58,789 [root] DEBUG: 4712: DLL loaded at 0x76730000: C:\Windows\System32\SETUPAPI (0x438000 bytes).
2026-04-18 21:57:58,790 [root] DEBUG: 4560: DLL loaded at 0x75ED0000: C:\Windows\System32\shcore (0x87000 bytes).
2026-04-18 21:57:58,791 [root] DEBUG: 4560: DLL loaded at 0x72CD0000: C:\Windows\SYSTEM32\WINSPOOL.DRV (0x7d000 bytes).
2026-04-18 21:57:58,792 [root] DEBUG: 4712: DLL loaded at 0x75ED0000: C:\Windows\System32\shcore (0x87000 bytes).
2026-04-18 21:57:58,793 [root] DEBUG: 4712: DLL loaded at 0x72CD0000: C:\Windows\SYSTEM32\WINSPOOL.DRV (0x7d000 bytes).
2026-04-18 21:57:58,794 [root] DEBUG: 4560: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:58,796 [root] DEBUG: 4712: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:57:59,080 [root] DEBUG: 4712: ProcessImageBase: Modified image detected at image base 0x00C90000 - new entropy 7.270381e+00 (change 4.757683e+00).
2026-04-18 21:57:59,081 [root] DEBUG: 4712: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-18 21:57:59,081 [root] DEBUG: 4712: DumpProcess: Instantiating PeParser with address: 0x00C90000.
2026-04-18 21:57:59,082 [root] DEBUG: 4712: DumpProcess: Module entry point VA is 0x00001CE5.
2026-04-18 21:57:59,088 [root] DEBUG: 4560: ProcessImageBase: Modified image detected at image base 0x00C90000 - new entropy 7.270382e+00 (change 4.757683e+00).
2026-04-18 21:57:59,089 [root] DEBUG: 4560: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-04-18 21:57:59,089 [root] DEBUG: 4560: DumpProcess: Instantiating PeParser with address: 0x00C90000.
2026-04-18 21:57:59,090 [root] DEBUG: 4560: DumpProcess: Module entry point VA is 0x00001CE5.
2026-04-18 21:57:59,192 [root] DEBUG: Error 32 (0x20) - savePeFileToDisk: There was a problem renaming the file: ᅬ○¥ ■¥ ↓○₩¥ ○→│ ¦○ ↑ ¢←→, ¢↑ ↑¢↑ �○ ¢←→ ¢■ ¦ ̄│↓ ○¥○↓.
2026-04-18 21:57:59,193 [root] DEBUG: Error 32 (0x20) - savePeFileToDisk: There was a problem deleting the file: C:\PiogNHme\CAPE\CapeOutput.bin: ᅬ○¥ ■¥ ↓○₩¥ ○→│ ¦○ ↑ ¢←→, ¢↑ ↑¢↑ �○ ¢←→ ¢■ ¦ ̄│↓ ○¥○↓.
2026-04-18 21:57:59,194 [root] DEBUG: 4712: DumpProcess: Failed to dump image at 0x00C90000.
2026-04-18 21:57:59,196 [root] DEBUG: 4712: DumpImageInCurrentProcess: Failed to dump virtual PE image from 0x00C90000, dumping memory region.
2026-04-18 21:57:59,425 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4560_183278159571818642026 to CAPE\e83eecc6f75a22781d7eef1cff4971d65b1d39def086ef3af063726f62515fcb; Size is 24673792; Max size: 100000000
2026-04-18 21:57:59,515 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4712_427896059571818642026 to CAPE\e94f682b038043179fa5313770372f4d0c5a43a7bebd982757b8448a862eb3d6; Size is 24965258; Max size: 100000000
2026-04-18 21:57:59,793 [root] DEBUG: 4560: DumpProcess: Module image dump success - dump size 0x1787e00.
2026-04-18 21:57:59,883 [root] DEBUG: 4560: InstrumentationCallback: Added region at 0x75A163AC (base 0x758D0000) to tracked regions list (thread 4552).
2026-04-18 21:57:59,884 [root] DEBUG: 4712: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4712_427896059571818642026 (size 24965258 bytes)
2026-04-18 21:57:59,885 [root] DEBUG: 4560: ProcessTrackedRegion: Region at 0x758D0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-18 21:57:59,897 [root] DEBUG: 4560: set_hooks_by_export_directory: Hooked 0 out of 627 functions
2026-04-18 21:57:59,898 [root] DEBUG: 4560: DLL loaded at 0x73B80000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-18 21:57:59,903 [root] DEBUG: 4712: InstrumentationCallback: Added region at 0x75A163AC (base 0x758D0000) to tracked regions list (thread 4904).
2026-04-18 21:57:59,904 [root] DEBUG: 4712: ProcessTrackedRegion: Region at 0x758D0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-18 21:57:59,905 [root] DEBUG: 4560: DLL loaded at 0x75800000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-18 21:57:59,913 [root] DEBUG: 4560: DLL loaded at 0x739F0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-18 21:57:59,918 [root] DEBUG: 4712: set_hooks_by_export_directory: Hooked 0 out of 627 functions
2026-04-18 21:57:59,919 [root] DEBUG: 4712: DLL loaded at 0x73B80000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-04-18 21:57:59,926 [root] DEBUG: 4712: DLL loaded at 0x75800000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-04-18 21:57:59,934 [root] DEBUG: 4712: DLL loaded at 0x739F0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-04-18 21:57:59,968 [root] DEBUG: 4560: DLL loaded at 0x747A0000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-04-18 21:57:59,969 [root] DEBUG: 4560: DLL loaded at 0x747D0000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-04-18 21:57:59,973 [root] DEBUG: 4560: DLL loaded at 0x73460000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-04-18 21:57:59,988 [root] DEBUG: 4712: DLL loaded at 0x747A0000: C:\Windows\SYSTEM32\Wldp (0x24000 bytes).
2026-04-18 21:57:59,989 [root] DEBUG: 4712: DLL loaded at 0x747D0000: C:\Windows\SYSTEM32\windows.storage (0x613000 bytes).
2026-04-18 21:57:59,992 [root] DEBUG: 4560: DLL loaded at 0x72CA0000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-18 21:57:59,993 [root] DEBUG: 4712: DLL loaded at 0x73460000: C:\Windows\SYSTEM32\profapi (0x1c000 bytes).
2026-04-18 21:58:00,012 [root] DEBUG: 4712: DLL loaded at 0x72CA0000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-04-18 21:58:00,017 [root] DEBUG: 4560: AllocationHandler: Adding allocation to tracked region list: 0x04440000, size: 0x1000.
2026-04-18 21:58:00,018 [root] DEBUG: 4560: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:00,019 [root] DEBUG: 4560: AllocationHandler: Processing previous tracked region at: 0x00C90000.
2026-04-18 21:58:00,021 [root] DEBUG: 4560: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:58:00,041 [root] DEBUG: 4712: DLL loaded at 0x76EA0000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-04-18 21:58:00,055 [root] DEBUG: 4712: DLL loaded at 0x720C0000: C:\Windows\System32\DNSAPI (0x90000 bytes).
2026-04-18 21:58:00,056 [root] DEBUG: 4712: DLL loaded at 0x72150000: C:\Windows\System32\FirewallAPI (0x65000 bytes).
2026-04-18 21:58:00,057 [root] DEBUG: 4712: DLL loaded at 0x76B70000: C:\Windows\System32\NSI (0x7000 bytes).
2026-04-18 21:58:00,063 [root] DEBUG: 4712: DLL loaded at 0x72090000: C:\Windows\System32\fwbase (0x2b000 bytes).
2026-04-18 21:58:00,072 [root] DEBUG: 4712: DLL loaded at 0x72050000: C:\Windows\System32\FWPolicyIOMgr (0x3f000 bytes).
2026-04-18 21:58:00,077 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Roaming\AnyDesk\system.conf
2026-04-18 21:58:00,085 [root] DEBUG: 4712: AllocationHandler: Adding allocation to tracked region list: 0x05920000, size: 0x1000.
2026-04-18 21:58:00,086 [root] DEBUG: 4712: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:00,087 [root] DEBUG: 4712: AllocationHandler: Processing previous tracked region at: 0x00C90000.
2026-04-18 21:58:00,088 [root] DEBUG: 4712: YaraScan: Scanning 0x00C90000, size 0x17cf08a
2026-04-18 21:58:00,324 [root] DEBUG: 4560: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 6.491697e-04)
2026-04-18 21:58:00,335 [root] DEBUG: 4560: DLL loaded at 0x76BD0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-04-18 21:58:00,339 [root] DEBUG: 2552: OpenProcessHandler: Injection info created for process 4560, handle 0xd5c: C:\Temp\AnyDesk.exe
2026-04-18 21:58:00,395 [root] DEBUG: 4712: ProcessImageBase: Main module image at 0x00C90000 unmodified (entropy change 6.969342e-04)
2026-04-18 21:58:00,402 [root] DEBUG: 4560: ProcessTrackedRegion: Region at 0x76520000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-04-18 21:58:00,425 [root] DEBUG: 4712: DLL loaded at 0x76BD0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-04-18 21:58:00,427 [root] DEBUG: 4560: DLL loaded at 0x72B20000: C:\Windows\SYSTEM32\WindowsCodecs (0x171000 bytes).
2026-04-18 21:58:00,429 [root] DEBUG: 2552: OpenProcessHandler: Injection info created for process 4712, handle 0xd5c: C:\Temp\AnyDesk.exe
2026-04-18 21:58:00,504 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 4908 (handle 0x408): 0x00C90000.
2026-04-18 21:58:00,505 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 4908, handle 0x408: C:\Temp\AnyDesk.exe
2026-04-18 21:58:00,506 [root] DEBUG: 4712: OpenProcessHandler: Image base for process 4560 (handle 0x40c): 0x00C90000.
2026-04-18 21:58:00,507 [root] DEBUG: 4712: OpenProcessHandler: Injection info created for process 4560, handle 0x40c: C:\Temp\AnyDesk.exe
2026-04-18 21:58:00,524 [root] DEBUG: 4712: DLL loaded at 0x72030000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-04-18 21:58:00,526 [root] DEBUG: 4712: DLL loaded at 0x72000000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2026-04-18 21:58:00,531 [root] DEBUG: 4712: DLL loaded at 0x71FE0000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-04-18 21:58:00,532 [root] DEBUG: 4712: DLL loaded at 0x71FD0000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-04-18 21:58:00,541 [root] DEBUG: 4712: DLL loaded at 0x71FB0000: C:\Windows\SYSTEM32\wkscli (0x11000 bytes).
2026-04-18 21:58:00,557 [root] DEBUG: 4712: DLL loaded at 0x72930000: C:\Windows\SYSTEM32\srvcli (0x1d000 bytes).
2026-04-18 21:58:00,721 [root] DEBUG: 4712: api-cap: memcpy hook disabled due to count: 5000
2026-04-18 21:58:00,956 [root] DEBUG: 4560: DLL loaded at 0x76EA0000: C:\Windows\System32\clbcatq (0x7e000 bytes).
2026-04-18 21:58:00,960 [root] DEBUG: 4560: DLL loaded at 0x72AD0000: C:\Windows\System32\thumbcache (0x48000 bytes).
2026-04-18 21:58:01,118 [root] DEBUG: 4560: DLL loaded at 0x71FF0000: C:\Windows\SYSTEM32\wtsapi32 (0xf000 bytes).
2026-04-18 21:58:01,124 [root] DEBUG: 4560: AllocationHandler: Adding allocation to tracked region list: 0x045E0000, size: 0x1000.
2026-04-18 21:58:01,124 [root] DEBUG: 4560: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:01,125 [root] DEBUG: 4560: AllocationHandler: Processing previous tracked region at: 0x04440000.
2026-04-18 21:58:01,126 [root] DEBUG: 4560: DumpPEsInRange: Scanning range 0x04440000 - 0x04440020.
2026-04-18 21:58:01,127 [root] DEBUG: 4560: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:58:01,130 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4560_12670801581818642026 to CAPE\7ae42631e49c8da65cb215841291ef1a512365a3067b5da63bc5e3edc081281b; Size is 32; Max size: 100000000
2026-04-18 21:58:01,140 [root] DEBUG: 4560: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4560_12670801581818642026 (size 32 bytes)
2026-04-18 21:58:01,141 [root] DEBUG: 4560: DumpRegion: Dumped entire allocation from 0x04440000, size 4096 bytes.
2026-04-18 21:58:01,142 [root] DEBUG: 4560: ProcessTrackedRegion: Dumped region at 0x04440000.
2026-04-18 21:58:01,142 [root] DEBUG: 4560: YaraScan: Scanning 0x04440000, size 0x20
2026-04-18 21:58:01,144 [root] DEBUG: 4560: AllocationHandler: Adding allocation to tracked region list: 0x045F0000, size: 0x1000.
2026-04-18 21:58:01,145 [root] DEBUG: 4560: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:01,146 [root] DEBUG: 4560: AllocationHandler: Processing previous tracked region at: 0x045E0000.
2026-04-18 21:58:01,146 [root] DEBUG: 4560: DumpPEsInRange: Scanning range 0x045E0000 - 0x045E0020.
2026-04-18 21:58:01,147 [root] DEBUG: 4560: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:58:01,149 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4560_33281551581818642026 to CAPE\c8249a9e5bef121892a8a34e27810f4b69cef4b6ba895fd1c58da1d8bd08f8dc; Size is 32; Max size: 100000000
2026-04-18 21:58:01,153 [root] DEBUG: 4560: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4560_33281551581818642026 (size 32 bytes)
2026-04-18 21:58:01,153 [root] DEBUG: 4560: DumpRegion: Dumped entire allocation from 0x045E0000, size 4096 bytes.
2026-04-18 21:58:01,154 [root] DEBUG: 4560: ProcessTrackedRegion: Dumped region at 0x045E0000.
2026-04-18 21:58:01,155 [root] DEBUG: 4560: YaraScan: Scanning 0x045E0000, size 0x20
2026-04-18 21:58:01,158 [root] DEBUG: 4560: AllocationHandler: Adding allocation to tracked region list: 0x05FF0000, size: 0x1000.
2026-04-18 21:58:01,159 [root] DEBUG: 4560: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:01,160 [root] DEBUG: 4560: AllocationHandler: Processing previous tracked region at: 0x045F0000.
2026-04-18 21:58:01,160 [root] DEBUG: 4560: DumpPEsInRange: Scanning range 0x045F0000 - 0x045F0020.
2026-04-18 21:58:01,161 [root] DEBUG: 4560: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:58:01,163 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4560_20289871581818642026 to CAPE\b963ae92f3689686a6a5e8873f094ebfbd27d4d37a0db034eb7029bc84d213a9; Size is 32; Max size: 100000000
2026-04-18 21:58:01,168 [root] DEBUG: 4560: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4560_20289871581818642026 (size 32 bytes)
2026-04-18 21:58:01,169 [root] DEBUG: 4560: DumpRegion: Dumped entire allocation from 0x045F0000, size 4096 bytes.
2026-04-18 21:58:01,170 [root] DEBUG: 4560: ProcessTrackedRegion: Dumped region at 0x045F0000.
2026-04-18 21:58:01,171 [root] DEBUG: 4560: YaraScan: Scanning 0x045F0000, size 0x20
2026-04-18 21:58:01,178 [root] DEBUG: 4560: DLL loaded at 0x729C0000: C:\Windows\SYSTEM32\DPAPI (0x8000 bytes).
2026-04-18 21:58:01,224 [root] DEBUG: 4560: ProcessTrackedRegion: Region at 0x758D0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-04-18 21:58:01,238 [root] DEBUG: 4560: OpenProcessHandler: Image base for process 4712 (handle 0x4e0): 0x00C90000.
2026-04-18 21:58:01,238 [root] DEBUG: 4560: OpenProcessHandler: Injection info created for process 4712, handle 0x4e0: C:\Temp\AnyDesk.exe
2026-04-18 21:58:01,261 [root] DEBUG: 4712: api-cap: NtAllocateVirtualMemory hook disabled due to count: 5000
2026-04-18 21:58:01,439 [root] DEBUG: 2552: OpenProcessHandler: Image base for process 4560 (handle 0xd5c): 0x0000000000C90000.
2026-04-18 21:58:01,461 [lib.api.process] INFO: Monitor config for <Process 740 svchost.exe>: C:\wry749yf\dll\740.ini
2026-04-18 21:58:01,466 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 21:58:01,477 [root] DEBUG: Loader: Injecting process 740 with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:58:01,480 [root] DEBUG: 740: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 21:58:01,481 [root] DEBUG: 740: Disabling sleep skipping.
2026-04-18 21:58:01,482 [root] DEBUG: 740: Dropped file limit defaulting to 100.
2026-04-18 21:58:01,484 [root] DEBUG: 740: Services hook set enabled
2026-04-18 21:58:01,488 [root] DEBUG: 740: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 21:58:01,514 [root] DEBUG: 740: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0
2026-04-18 21:58:01,515 [root] DEBUG: 740: Monitor initialised: 64-bit capemon loaded in process 740 at 0x00007FFEB6B40000, thread 6752, image base 0x00007FF630560000, stack from 0x000000A00B875000-0x000000A00B880000
2026-04-18 21:58:01,516 [root] DEBUG: 740: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-04-18 21:58:01,534 [root] DEBUG: 740: Hooked 69 out of 69 functions
2026-04-18 21:58:01,535 [root] INFO: Loaded monitor into process with pid 740
2026-04-18 21:58:01,536 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-18 21:58:01,537 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:58:01,540 [lib.api.process] INFO: Injected into 64-bit <Process 740 svchost.exe>
2026-04-18 21:58:02,330 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Roaming\AnyDesk\service.conf
2026-04-18 21:58:02,386 [root] DEBUG: 4712: DLL loaded at 0x71FB0000: C:\Windows\System32\netprofm (0x32000 bytes).
2026-04-18 21:58:02,406 [root] DEBUG: 4712: DLL loaded at 0x71FA0000: C:\Windows\System32\npmproxy (0xa000 bytes).
2026-04-18 21:58:02,410 [root] DEBUG: 4712: caller_dispatch: Added region at 0x71FB0000 to tracked regions list (ntdll::NtCreateEvent returns to 0x71FC319E, thread 6864).
2026-04-18 21:58:02,411 [root] DEBUG: 4712: ProcessTrackedRegion: Region at 0x71FB0000 mapped as \Device\HarddiskVolume2\Windows\SysWOW64\netprofm.dll is in known range, skipping
2026-04-18 21:58:02,463 [root] DEBUG: 4712: DLL loaded at 0x71F80000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-04-18 21:58:02,465 [root] DEBUG: 4712: DLL loaded at 0x71F60000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-04-18 21:58:02,544 [root] DEBUG: 4712: DLL loaded at 0x73B90000: C:\Windows\system32\mswsock (0x52000 bytes).
2026-04-18 21:58:02,557 [root] DEBUG: 4712: DLL loaded at 0x71F50000: C:\Windows\System32\rasadhlp (0x8000 bytes).
2026-04-18 21:58:02,586 [root] DEBUG: 4712: DLL loaded at 0x71EF0000: C:\Windows\System32\fwpuclnt (0x58000 bytes).
2026-04-18 21:58:02,741 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x08FA0000, size: 0x1000.
2026-04-18 21:58:02,744 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,748 [lib.api.process] INFO: Monitor config for <Process 268 svchost.exe>: C:\wry749yf\dll\268.ini
2026-04-18 21:58:02,749 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08E70000.
2026-04-18 21:58:02,751 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E70000 skipped due to dump limit 10
2026-04-18 21:58:02,752 [root] DEBUG: 4908: DLL loaded at 0x71FF0000: C:\Windows\SYSTEM32\wtsapi32 (0xf000 bytes).
2026-04-18 21:58:02,754 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 21:58:02,756 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E70000.
2026-04-18 21:58:02,757 [root] DEBUG: 4908: YaraScan: Scanning 0x08E70000, size 0x20
2026-04-18 21:58:02,759 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09040000, size: 0x1000.
2026-04-18 21:58:02,760 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,762 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x08FA0000.
2026-04-18 21:58:02,763 [root] DEBUG: 4908: DumpRegion: Dump at 0x08FA0000 skipped due to dump limit 10
2026-04-18 21:58:02,764 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08FA0000.
2026-04-18 21:58:02,765 [root] DEBUG: 4908: YaraScan: Scanning 0x08FA0000, size 0x20
2026-04-18 21:58:02,767 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09050000, size: 0x1000.
2026-04-18 21:58:02,767 [root] DEBUG: Loader: Injecting process 268 with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:58:02,768 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,769 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09040000.
2026-04-18 21:58:02,769 [root] DEBUG: 4908: DumpRegion: Dump at 0x09040000 skipped due to dump limit 10
2026-04-18 21:58:02,770 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09040000.
2026-04-18 21:58:02,771 [root] DEBUG: 4908: YaraScan: Scanning 0x09040000, size 0x20
2026-04-18 21:58:02,772 [root] DEBUG: 268: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 21:58:02,773 [root] DEBUG: 268: Disabling sleep skipping.
2026-04-18 21:58:02,774 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09060000, size: 0x1000.
2026-04-18 21:58:02,774 [root] DEBUG: 268: Dropped file limit defaulting to 100.
2026-04-18 21:58:02,775 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,776 [root] DEBUG: 268: Services hook set enabled
2026-04-18 21:58:02,777 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09050000.
2026-04-18 21:58:02,778 [root] DEBUG: 4908: DumpRegion: Dump at 0x09050000 skipped due to dump limit 10
2026-04-18 21:58:02,780 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09050000.
2026-04-18 21:58:02,780 [root] DEBUG: 4908: YaraScan: Scanning 0x09050000, size 0x20
2026-04-18 21:58:02,781 [root] DEBUG: 268: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 21:58:02,785 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09140000, size: 0x1000.
2026-04-18 21:58:02,790 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,791 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09060000.
2026-04-18 21:58:02,792 [root] DEBUG: 4908: DumpRegion: Dump at 0x09060000 skipped due to dump limit 10
2026-04-18 21:58:02,793 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09060000.
2026-04-18 21:58:02,794 [root] DEBUG: 4908: YaraScan: Scanning 0x09060000, size 0x20
2026-04-18 21:58:02,796 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09150000, size: 0x1000.
2026-04-18 21:58:02,797 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,803 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09140000.
2026-04-18 21:58:02,804 [root] DEBUG: 4560: DLL loaded at 0x76B70000: C:\Windows\System32\NSI (0x7000 bytes).
2026-04-18 21:58:02,805 [root] DEBUG: 4908: DumpRegion: Dump at 0x09140000 skipped due to dump limit 10
2026-04-18 21:58:02,806 [root] DEBUG: 4560: DLL loaded at 0x71F80000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x14000 bytes).
2026-04-18 21:58:02,808 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09140000.
2026-04-18 21:58:02,809 [root] DEBUG: 268: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0
2026-04-18 21:58:02,809 [root] DEBUG: 4908: YaraScan: Scanning 0x09140000, size 0x20
2026-04-18 21:58:02,811 [root] DEBUG: 268: Monitor initialised: 64-bit capemon loaded in process 268 at 0x00007FFEB6B40000, thread 7116, image base 0x00007FF630560000, stack from 0x0000009338F75000-0x0000009338F80000
2026-04-18 21:58:02,811 [root] DEBUG: 4560: DLL loaded at 0x71F60000: C:\Windows\SYSTEM32\dhcpcsvc (0x16000 bytes).
2026-04-18 21:58:02,812 [root] DEBUG: 268: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-04-18 21:58:02,814 [root] DEBUG: 4908: api-cap: memcpy hook disabled due to count: 5000
2026-04-18 21:58:02,817 [root] DEBUG: 4908: api-cap: memcpy hook disabled due to count: 5001
2026-04-18 21:58:02,819 [root] DEBUG: 4560: DLL loaded at 0x71ED0000: C:\Windows\system32\OnDemandConnRouteHelper (0x12000 bytes).
2026-04-18 21:58:02,820 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x090A0000, size: 0x1000.
2026-04-18 21:58:02,824 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,825 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09150000.
2026-04-18 21:58:02,826 [root] DEBUG: 4908: DumpRegion: Dump at 0x09150000 skipped due to dump limit 10
2026-04-18 21:58:02,827 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09150000.
2026-04-18 21:58:02,828 [root] DEBUG: 4908: YaraScan: Scanning 0x09150000, size 0x20
2026-04-18 21:58:02,830 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x090B0000, size: 0x1000.
2026-04-18 21:58:02,832 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,832 [root] DEBUG: 268: Hooked 69 out of 69 functions
2026-04-18 21:58:02,833 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x090A0000.
2026-04-18 21:58:02,834 [root] DEBUG: 4908: DumpRegion: Dump at 0x090A0000 skipped due to dump limit 10
2026-04-18 21:58:02,835 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090A0000.
2026-04-18 21:58:02,836 [root] DEBUG: 4908: YaraScan: Scanning 0x090A0000, size 0x20
2026-04-18 21:58:02,837 [root] INFO: Loaded monitor into process with pid 268
2026-04-18 21:58:02,837 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x090C0000, size: 0x1000.
2026-04-18 21:58:02,838 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,839 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-18 21:58:02,839 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x090B0000.
2026-04-18 21:58:02,840 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:58:02,841 [root] DEBUG: 4908: DumpRegion: Dump at 0x090B0000 skipped due to dump limit 10
2026-04-18 21:58:02,842 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090B0000.
2026-04-18 21:58:02,843 [root] DEBUG: 4908: YaraScan: Scanning 0x090B0000, size 0x20
2026-04-18 21:58:02,843 [lib.api.process] INFO: Injected into 64-bit <Process 268 svchost.exe>
2026-04-18 21:58:02,845 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x090D0000, size: 0x1000.
2026-04-18 21:58:02,846 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,846 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x090C0000.
2026-04-18 21:58:02,847 [root] DEBUG: 4908: DumpRegion: Dump at 0x090C0000 skipped due to dump limit 10
2026-04-18 21:58:02,848 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090C0000.
2026-04-18 21:58:02,849 [root] DEBUG: 4908: YaraScan: Scanning 0x090C0000, size 0x20
2026-04-18 21:58:02,850 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x090E0000, size: 0x1000.
2026-04-18 21:58:02,851 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,852 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x090D0000.
2026-04-18 21:58:02,853 [root] DEBUG: 4908: DumpRegion: Dump at 0x090D0000 skipped due to dump limit 10
2026-04-18 21:58:02,853 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090D0000.
2026-04-18 21:58:02,854 [root] DEBUG: 4908: YaraScan: Scanning 0x090D0000, size 0x20
2026-04-18 21:58:02,856 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x090F0000, size: 0x1000.
2026-04-18 21:58:02,857 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,858 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x090E0000.
2026-04-18 21:58:02,859 [root] DEBUG: 4908: DumpRegion: Dump at 0x090E0000 skipped due to dump limit 10
2026-04-18 21:58:02,859 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090E0000.
2026-04-18 21:58:02,861 [root] DEBUG: 4908: YaraScan: Scanning 0x090E0000, size 0x20
2026-04-18 21:58:02,863 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09100000, size: 0x1000.
2026-04-18 21:58:02,864 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,864 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x090F0000.
2026-04-18 21:58:02,865 [root] DEBUG: 4908: DumpRegion: Dump at 0x090F0000 skipped due to dump limit 10
2026-04-18 21:58:02,866 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090F0000.
2026-04-18 21:58:02,867 [root] DEBUG: 4908: YaraScan: Scanning 0x090F0000, size 0x20
2026-04-18 21:58:02,869 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09110000, size: 0x1000.
2026-04-18 21:58:02,870 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,871 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09100000.
2026-04-18 21:58:02,871 [root] DEBUG: 4908: DumpRegion: Dump at 0x09100000 skipped due to dump limit 10
2026-04-18 21:58:02,872 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09100000.
2026-04-18 21:58:02,873 [root] DEBUG: 4908: YaraScan: Scanning 0x09100000, size 0x20
2026-04-18 21:58:02,875 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09120000, size: 0x1000.
2026-04-18 21:58:02,876 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,876 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09110000.
2026-04-18 21:58:02,877 [root] DEBUG: 4908: DumpRegion: Dump at 0x09110000 skipped due to dump limit 10
2026-04-18 21:58:02,878 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09110000.
2026-04-18 21:58:02,879 [root] DEBUG: 4908: YaraScan: Scanning 0x09110000, size 0x20
2026-04-18 21:58:02,896 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09130000, size: 0x1000.
2026-04-18 21:58:02,897 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,898 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09120000.
2026-04-18 21:58:02,900 [root] DEBUG: 4908: DumpRegion: Dump at 0x09120000 skipped due to dump limit 10
2026-04-18 21:58:02,900 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09120000.
2026-04-18 21:58:02,901 [root] DEBUG: 4908: YaraScan: Scanning 0x09120000, size 0x20
2026-04-18 21:58:02,903 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09160000, size: 0x1000.
2026-04-18 21:58:02,904 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:02,904 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09130000.
2026-04-18 21:58:02,905 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:02,965 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:02,966 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:02,970 [root] DEBUG: 4908: FreeHandler: Address: 0x09160000.
2026-04-18 21:58:02,971 [root] DEBUG: 4908: DumpRegion: Dump at 0x09160000 skipped due to dump limit 10
2026-04-18 21:58:02,972 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09160000.
2026-04-18 21:58:02,991 [root] DEBUG: 4908: YaraScan: Scanning 0x09160000, size 0x20
2026-04-18 21:58:02,992 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075DB0A8 prior to its freeing.
2026-04-18 21:58:02,993 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09160000 from the end of the tracked region list.
2026-04-18 21:58:02,994 [root] DEBUG: 4908: FreeHandler: Address: 0x09130000.
2026-04-18 21:58:02,995 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:02,995 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:02,996 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:02,997 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:58:02,998 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09130000 from the end of the tracked region list.
2026-04-18 21:58:03,007 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09130000, size: 0x1000.
2026-04-18 21:58:03,008 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,008 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09160000.
2026-04-18 21:58:03,009 [root] DEBUG: 4908: ReverseScanForNonZero: Error - Supplied size zero.
2026-04-18 21:58:03,010 [root] DEBUG: 4908: GetPageAddress: Error - Supplied address zero.
2026-04-18 21:58:03,012 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09160000, size: 0x1000.
2026-04-18 21:58:03,013 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,013 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09130000.
2026-04-18 21:58:03,014 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,015 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,016 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,018 [root] DEBUG: 4908: FreeHandler: Address: 0x09160000.
2026-04-18 21:58:03,019 [root] DEBUG: 4908: DumpRegion: Dump at 0x09160000 skipped due to dump limit 10
2026-04-18 21:58:03,019 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09160000.
2026-04-18 21:58:03,021 [root] DEBUG: 4908: YaraScan: Scanning 0x09160000, size 0x20
2026-04-18 21:58:03,021 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075DB0A8 prior to its freeing.
2026-04-18 21:58:03,022 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09160000 from the end of the tracked region list.
2026-04-18 21:58:03,023 [root] DEBUG: 4908: FreeHandler: Address: 0x09130000.
2026-04-18 21:58:03,024 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,025 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,026 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,027 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:58:03,028 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09130000 from the end of the tracked region list.
2026-04-18 21:58:03,037 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09130000, size: 0x1000.
2026-04-18 21:58:03,038 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,039 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09160000.
2026-04-18 21:58:03,040 [root] DEBUG: 4908: ReverseScanForNonZero: Error - Supplied size zero.
2026-04-18 21:58:03,040 [root] DEBUG: 4908: GetPageAddress: Error - Supplied address zero.
2026-04-18 21:58:03,042 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09160000, size: 0x1000.
2026-04-18 21:58:03,043 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,044 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09130000.
2026-04-18 21:58:03,045 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,046 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,047 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,050 [root] DEBUG: 4908: FreeHandler: Address: 0x09160000.
2026-04-18 21:58:03,050 [root] DEBUG: 4908: DumpRegion: Dump at 0x09160000 skipped due to dump limit 10
2026-04-18 21:58:03,051 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09160000.
2026-04-18 21:58:03,052 [root] DEBUG: 4908: YaraScan: Scanning 0x09160000, size 0x20
2026-04-18 21:58:03,053 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075DB0A8 prior to its freeing.
2026-04-18 21:58:03,054 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09160000 from the end of the tracked region list.
2026-04-18 21:58:03,056 [root] DEBUG: 4908: FreeHandler: Address: 0x09130000.
2026-04-18 21:58:03,057 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,057 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,058 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,059 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:58:03,060 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09130000 from the end of the tracked region list.
2026-04-18 21:58:03,113 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09130000, size: 0x1000.
2026-04-18 21:58:03,114 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,115 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x0000006D.
2026-04-18 21:58:03,116 [root] DEBUG: 4908: ReverseScanForNonZero: Error - Supplied size zero.
2026-04-18 21:58:03,117 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09160000, size: 0x1000.
2026-04-18 21:58:03,118 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,119 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09130000.
2026-04-18 21:58:03,120 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,121 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,122 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,123 [root] DEBUG: 4908: FreeHandler: Address: 0x09160000.
2026-04-18 21:58:03,124 [root] DEBUG: 4908: DumpRegion: Dump at 0x09160000 skipped due to dump limit 10
2026-04-18 21:58:03,125 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09160000.
2026-04-18 21:58:03,126 [root] DEBUG: 4908: YaraScan: Scanning 0x09160000, size 0x20
2026-04-18 21:58:03,127 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075FDA88 prior to its freeing.
2026-04-18 21:58:03,128 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09160000 from the end of the tracked region list.
2026-04-18 21:58:03,129 [root] DEBUG: 4908: FreeHandler: Address: 0x09130000.
2026-04-18 21:58:03,130 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,130 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,131 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,132 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:58:03,133 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09130000 from the end of the tracked region list.
2026-04-18 21:58:03,142 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09130000, size: 0x1000.
2026-04-18 21:58:03,143 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,144 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x0000006D.
2026-04-18 21:58:03,145 [root] DEBUG: 4908: ReverseScanForNonZero: Error - Supplied size zero.
2026-04-18 21:58:03,146 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09160000, size: 0x1000.
2026-04-18 21:58:03,147 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,148 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09130000.
2026-04-18 21:58:03,149 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,150 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,151 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,153 [root] DEBUG: 4908: FreeHandler: Address: 0x09160000.
2026-04-18 21:58:03,154 [root] DEBUG: 4908: DumpRegion: Dump at 0x09160000 skipped due to dump limit 10
2026-04-18 21:58:03,155 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09160000.
2026-04-18 21:58:03,155 [root] DEBUG: 4908: YaraScan: Scanning 0x09160000, size 0x20
2026-04-18 21:58:03,157 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075FDA88 prior to its freeing.
2026-04-18 21:58:03,157 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09160000 from the end of the tracked region list.
2026-04-18 21:58:03,158 [root] DEBUG: 4908: FreeHandler: Address: 0x09130000.
2026-04-18 21:58:03,159 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,160 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,161 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,162 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:58:03,163 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09130000 from the end of the tracked region list.
2026-04-18 21:58:03,197 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09130000, size: 0x1000.
2026-04-18 21:58:03,198 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,199 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09160000.
2026-04-18 21:58:03,210 [root] DEBUG: 4908: ProcessTrackedRegion: Interesting region at 0x09160000 mapped as \Device\HarddiskVolume2\Windows\System32\C_1252.NLS, dumping
2026-04-18 21:58:03,210 [root] DEBUG: 4908: DumpRegion: Dump at 0x09160000 skipped due to dump limit 10
2026-04-18 21:58:03,211 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09160000.
2026-04-18 21:58:03,212 [root] DEBUG: 4908: YaraScan: Scanning 0x09160000, size 0x10222
2026-04-18 21:58:03,221 [root] INFO: Stopping Task Scheduler Service
2026-04-18 21:58:03,281 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09180000, size: 0x1000.
2026-04-18 21:58:03,282 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,283 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09130000.
2026-04-18 21:58:03,284 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:58:03,284 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:58:03,286 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:58:03,287 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09190000, size: 0x1000.
2026-04-18 21:58:03,288 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,289 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09180000.
2026-04-18 21:58:03,290 [root] DEBUG: 4908: DumpRegion: Dump at 0x09180000 skipped due to dump limit 10
2026-04-18 21:58:03,291 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09180000.
2026-04-18 21:58:03,292 [root] DEBUG: 4908: YaraScan: Scanning 0x09180000, size 0x20
2026-04-18 21:58:03,293 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x091A0000, size: 0x1000.
2026-04-18 21:58:03,294 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,295 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09190000.
2026-04-18 21:58:03,298 [root] DEBUG: 4908: DumpRegion: Dump at 0x09190000 skipped due to dump limit 10
2026-04-18 21:58:03,299 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09190000.
2026-04-18 21:58:03,299 [root] DEBUG: 4908: YaraScan: Scanning 0x09190000, size 0x20
2026-04-18 21:58:03,301 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x091B0000, size: 0x1000.
2026-04-18 21:58:03,302 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,302 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x091A0000.
2026-04-18 21:58:03,303 [root] DEBUG: 4908: DumpRegion: Dump at 0x091A0000 skipped due to dump limit 10
2026-04-18 21:58:03,304 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091A0000.
2026-04-18 21:58:03,305 [root] DEBUG: 4908: YaraScan: Scanning 0x091A0000, size 0x20
2026-04-18 21:58:03,307 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x091C0000, size: 0x1000.
2026-04-18 21:58:03,308 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,308 [root] INFO: Stopped Task Scheduler Service
2026-04-18 21:58:03,309 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x091B0000.
2026-04-18 21:58:03,310 [root] DEBUG: 4908: DumpRegion: Dump at 0x091B0000 skipped due to dump limit 10
2026-04-18 21:58:03,311 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091B0000.
2026-04-18 21:58:03,312 [root] DEBUG: 4908: YaraScan: Scanning 0x091B0000, size 0x20
2026-04-18 21:58:03,313 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x091D0000, size: 0x1000.
2026-04-18 21:58:03,314 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,315 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x091C0000.
2026-04-18 21:58:03,315 [root] DEBUG: 4908: DumpRegion: Dump at 0x091C0000 skipped due to dump limit 10
2026-04-18 21:58:03,316 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091C0000.
2026-04-18 21:58:03,317 [root] DEBUG: 4908: YaraScan: Scanning 0x091C0000, size 0x20
2026-04-18 21:58:03,319 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x091E0000, size: 0x1000.
2026-04-18 21:58:03,320 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,320 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x091D0000.
2026-04-18 21:58:03,321 [root] DEBUG: 4908: DumpRegion: Dump at 0x091D0000 skipped due to dump limit 10
2026-04-18 21:58:03,322 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091D0000.
2026-04-18 21:58:03,322 [root] DEBUG: 4908: YaraScan: Scanning 0x091D0000, size 0x20
2026-04-18 21:58:03,324 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x091F0000, size: 0x1000.
2026-04-18 21:58:03,325 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,326 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x091E0000.
2026-04-18 21:58:03,327 [root] DEBUG: 4908: DumpRegion: Dump at 0x091E0000 skipped due to dump limit 10
2026-04-18 21:58:03,328 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091E0000.
2026-04-18 21:58:03,329 [root] DEBUG: 4908: YaraScan: Scanning 0x091E0000, size 0x20
2026-04-18 21:58:03,330 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09200000, size: 0x1000.
2026-04-18 21:58:03,331 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,332 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x091F0000.
2026-04-18 21:58:03,332 [root] DEBUG: 4908: DumpRegion: Dump at 0x091F0000 skipped due to dump limit 10
2026-04-18 21:58:03,333 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091F0000.
2026-04-18 21:58:03,334 [root] DEBUG: 4908: YaraScan: Scanning 0x091F0000, size 0x20
2026-04-18 21:58:03,335 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09210000, size: 0x1000.
2026-04-18 21:58:03,336 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,337 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09200000.
2026-04-18 21:58:03,338 [root] DEBUG: 4908: DumpRegion: Dump at 0x09200000 skipped due to dump limit 10
2026-04-18 21:58:03,339 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09200000.
2026-04-18 21:58:03,339 [root] DEBUG: 4908: YaraScan: Scanning 0x09200000, size 0x20
2026-04-18 21:58:03,341 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09220000, size: 0x1000.
2026-04-18 21:58:03,342 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,343 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09210000.
2026-04-18 21:58:03,344 [root] DEBUG: 4908: DumpRegion: Dump at 0x09210000 skipped due to dump limit 10
2026-04-18 21:58:03,345 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09210000.
2026-04-18 21:58:03,346 [root] DEBUG: 4908: YaraScan: Scanning 0x09210000, size 0x20
2026-04-18 21:58:03,347 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09230000, size: 0x1000.
2026-04-18 21:58:03,348 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,349 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09220000.
2026-04-18 21:58:03,350 [root] DEBUG: 4908: DumpRegion: Dump at 0x09220000 skipped due to dump limit 10
2026-04-18 21:58:03,351 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09220000.
2026-04-18 21:58:03,352 [root] DEBUG: 4908: YaraScan: Scanning 0x09220000, size 0x20
2026-04-18 21:58:03,353 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09240000, size: 0x1000.
2026-04-18 21:58:03,355 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,355 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09230000.
2026-04-18 21:58:03,356 [root] DEBUG: 4908: DumpRegion: Dump at 0x09230000 skipped due to dump limit 10
2026-04-18 21:58:03,357 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09230000.
2026-04-18 21:58:03,357 [root] DEBUG: 4908: YaraScan: Scanning 0x09230000, size 0x20
2026-04-18 21:58:03,359 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09250000, size: 0x1000.
2026-04-18 21:58:03,360 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,361 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09240000.
2026-04-18 21:58:03,362 [root] DEBUG: 4908: DumpRegion: Dump at 0x09240000 skipped due to dump limit 10
2026-04-18 21:58:03,363 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09240000.
2026-04-18 21:58:03,364 [root] DEBUG: 4908: YaraScan: Scanning 0x09240000, size 0x20
2026-04-18 21:58:03,366 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09260000, size: 0x1000.
2026-04-18 21:58:03,367 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,367 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09250000.
2026-04-18 21:58:03,369 [root] DEBUG: 4908: DumpRegion: Dump at 0x09250000 skipped due to dump limit 10
2026-04-18 21:58:03,370 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09250000.
2026-04-18 21:58:03,371 [root] DEBUG: 4908: YaraScan: Scanning 0x09250000, size 0x20
2026-04-18 21:58:03,372 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09270000, size: 0x1000.
2026-04-18 21:58:03,373 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,374 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09260000.
2026-04-18 21:58:03,375 [root] DEBUG: 4908: DumpRegion: Dump at 0x09260000 skipped due to dump limit 10
2026-04-18 21:58:03,376 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09260000.
2026-04-18 21:58:03,376 [root] DEBUG: 4908: YaraScan: Scanning 0x09260000, size 0x20
2026-04-18 21:58:03,378 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09280000, size: 0x1000.
2026-04-18 21:58:03,379 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,380 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09270000.
2026-04-18 21:58:03,380 [root] DEBUG: 4908: DumpRegion: Dump at 0x09270000 skipped due to dump limit 10
2026-04-18 21:58:03,381 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09270000.
2026-04-18 21:58:03,382 [root] DEBUG: 4908: YaraScan: Scanning 0x09270000, size 0x20
2026-04-18 21:58:03,383 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x09290000, size: 0x1000.
2026-04-18 21:58:03,384 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,385 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09280000.
2026-04-18 21:58:03,386 [root] DEBUG: 4908: DumpRegion: Dump at 0x09280000 skipped due to dump limit 10
2026-04-18 21:58:03,387 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09280000.
2026-04-18 21:58:03,387 [root] INFO: Starting Task Scheduler Service
2026-04-18 21:58:03,389 [root] DEBUG: 4908: YaraScan: Scanning 0x09280000, size 0x20
2026-04-18 21:58:03,392 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x092A0000, size: 0x1000.
2026-04-18 21:58:03,393 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,394 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x09290000.
2026-04-18 21:58:03,395 [root] DEBUG: 4908: DumpRegion: Dump at 0x09290000 skipped due to dump limit 10
2026-04-18 21:58:03,397 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09290000.
2026-04-18 21:58:03,400 [root] DEBUG: 4908: YaraScan: Scanning 0x09290000, size 0x20
2026-04-18 21:58:03,421 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x092B0000, size: 0x1000.
2026-04-18 21:58:03,423 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:58:03,424 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x092A0000.
2026-04-18 21:58:03,425 [root] DEBUG: 4908: DumpRegion: Dump at 0x092A0000 skipped due to dump limit 10
2026-04-18 21:58:03,426 [root] DEBUG: 4908: DLL loaded at 0x71FF0000: C:\Windows\SYSTEM32\wtsapi32 (0xf000 bytes).
2026-04-18 21:58:03,427 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x092A0000.
2026-04-18 21:58:03,428 [root] DEBUG: 4908: YaraScan: Scanning 0x092A0000, size 0x20
2026-04-18 21:58:03,481 [root] INFO: Started Task Scheduler Service
2026-04-18 21:58:03,482 [lib.api.process] INFO: Monitor config for <Process 268 svchost.exe>: C:\wry749yf\dll\268.ini
2026-04-18 21:58:03,485 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 21:58:03,500 [root] DEBUG: Loader: Injecting process 268 with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:58:03,501 [root] DEBUG: 4908: DLL loaded at 0x71A90000: C:\Windows\system32\dxgi (0xc2000 bytes).
2026-04-18 21:58:03,502 [root] DEBUG: 4908: DLL loaded at 0x71CD0000: C:\Windows\system32\d3d11 (0x1e0000 bytes).
2026-04-18 21:58:03,503 [root] DEBUG: 4908: DLL loaded at 0x71B60000: C:\Windows\system32\dcomp (0x164000 bytes).
2026-04-18 21:58:03,503 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-04-18 21:58:03,504 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 21:58:03,505 [root] DEBUG: 4908: DLL loaded at 0x71EB0000: C:\Windows\system32\dataexchange (0x31000 bytes).
2026-04-18 21:58:03,508 [lib.api.process] INFO: Injected into 64-bit <Process 268 svchost.exe>
2026-04-18 21:58:03,514 [root] DEBUG: 4908: DLL loaded at 0x718F0000: C:\Windows\system32\twinapi.appcore (0x191000 bytes).
2026-04-18 21:58:03,956 [root] INFO: Added new file to list with pid None and path C:\Temp\gcapi.dll
2026-04-18 21:58:04,052 [lib.common.results] INFO: Uploading file C:\Temp\gcapi.dll to files\73170761d6776c0debacfbbc61b6988cb8270a20174bf5c049768a264bb8ffaf; Size is 394240; Max size: 100000000
2026-04-18 21:58:04,849 [root] DEBUG: 4908: DLL loaded at 0x71870000: C:\Windows\SYSTEM32\wbemcomn (0x70000 bytes).
2026-04-18 21:58:04,850 [root] DEBUG: 4908: DLL loaded at 0x718E0000: C:\Windows\system32\wbem\wbemprox (0xd000 bytes).
2026-04-18 21:58:04,865 [root] DEBUG: 4908: DLL loaded at 0x71860000: C:\Windows\system32\wbem\wbemsvc (0x10000 bytes).
2026-04-18 21:58:04,945 [root] DEBUG: 4908: DLL loaded at 0x71790000: C:\Windows\system32\wbem\fastprox (0xc9000 bytes).
2026-04-18 21:58:04,994 [root] DEBUG: 4908: DLL loaded at 0x734B0000: C:\Windows\SYSTEM32\amsi (0x18000 bytes).
2026-04-18 21:58:05,003 [root] DEBUG: 4908: DLL loaded at 0x73480000: C:\Windows\SYSTEM32\USERENV (0x25000 bytes).
2026-04-18 21:58:05,513 [root] DEBUG: 268: DLL loaded at 0x00007FFEDC430000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-04-18 21:58:06,106 [root] DEBUG: 2552: set_hooks_by_export_directory: Hooked 0 out of 620 functions
2026-04-18 21:58:06,108 [root] DEBUG: 2552: DLL loaded at 0x00007FFECE180000: C:\Windows\System32\Windows.CloudStore.Schema.Shell (0xf4000 bytes).
2026-04-18 21:58:06,238 [root] DEBUG: 268: DLL loaded at 0x00007FFECF070000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-04-18 21:58:08,507 [root] DEBUG: 268: DLL loaded at 0x00007FFED96A0000: C:\Windows\system32\sqmapi (0xe000 bytes).
2026-04-18 21:58:08,510 [root] DEBUG: 268: DLL loaded at 0x00007FFED96A0000: C:\Windows\system32\sqmapi (0xe000 bytes).
2026-04-18 21:59:37,756 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x00C80000, size: 0x1000.
2026-04-18 21:59:37,757 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:59:37,758 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x092B0000.
2026-04-18 21:59:37,759 [root] DEBUG: 4908: DumpRegion: Dump at 0x092B0000 skipped due to dump limit 10
2026-04-18 21:59:37,760 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x092B0000.
2026-04-18 21:59:37,761 [root] DEBUG: 4908: YaraScan: Scanning 0x092B0000, size 0x20
2026-04-18 21:59:37,764 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x02570000, size: 0x1000.
2026-04-18 21:59:37,765 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:59:37,766 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x00C80000.
2026-04-18 21:59:37,767 [root] DEBUG: 4908: DumpRegion: Dump at 0x00C80000 skipped due to dump limit 10
2026-04-18 21:59:37,768 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x00C80000.
2026-04-18 21:59:37,769 [root] DEBUG: 4908: YaraScan: Scanning 0x00C80000, size 0x20
2026-04-18 21:59:37,772 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x02580000, size: 0x1000.
2026-04-18 21:59:37,773 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:59:37,773 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x02570000.
2026-04-18 21:59:37,774 [root] DEBUG: 4908: DumpRegion: Dump at 0x02570000 skipped due to dump limit 10
2026-04-18 21:59:37,775 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x02570000.
2026-04-18 21:59:37,776 [root] DEBUG: 4908: YaraScan: Scanning 0x02570000, size 0x20
2026-04-18 21:59:37,801 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x02590000, size: 0x1000.
2026-04-18 21:59:37,802 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:59:37,803 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x02580000.
2026-04-18 21:59:37,804 [root] DEBUG: 4908: DumpRegion: Dump at 0x02580000 skipped due to dump limit 10
2026-04-18 21:59:37,805 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x02580000.
2026-04-18 21:59:37,805 [root] DEBUG: 4908: YaraScan: Scanning 0x02580000, size 0x20
2026-04-18 21:59:37,809 [root] DEBUG: 4908: AllocationHandler: Adding allocation to tracked region list: 0x025C0000, size: 0x1000.
2026-04-18 21:59:37,811 [root] DEBUG: 4908: AddTrackedRegion: GetEntropy failed.
2026-04-18 21:59:37,812 [root] DEBUG: 4908: AllocationHandler: Processing previous tracked region at: 0x02590000.
2026-04-18 21:59:37,813 [root] DEBUG: 4908: DumpRegion: Dump at 0x02590000 skipped due to dump limit 10
2026-04-18 21:59:37,814 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x02590000.
2026-04-18 21:59:37,814 [root] DEBUG: 4908: YaraScan: Scanning 0x02590000, size 0x20
2026-04-18 21:59:38,113 [root] DEBUG: 4908: FreeHandler: Address: 0x09130000.
2026-04-18 21:59:38,115 [root] DEBUG: 4908: DumpRegion: Dump at 0x09130000 skipped due to dump limit 10
2026-04-18 21:59:38,117 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09130000.
2026-04-18 21:59:38,117 [root] DEBUG: 4908: YaraScan: Scanning 0x09130000, size 0x20
2026-04-18 21:59:38,118 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716BFB8 prior to its freeing.
2026-04-18 21:59:38,119 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09130000 from tracked region list.
2026-04-18 21:59:38,131 [root] DEBUG: 4908: FreeHandler: Address: 0x02590000.
2026-04-18 21:59:38,132 [root] DEBUG: 4908: DumpRegion: Dump at 0x02590000 skipped due to dump limit 10
2026-04-18 21:59:38,133 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x02590000.
2026-04-18 21:59:38,134 [root] DEBUG: 4908: YaraScan: Scanning 0x02590000, size 0x20
2026-04-18 21:59:38,136 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710D2E0 prior to its freeing.
2026-04-18 21:59:38,140 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x02590000 from tracked region list.
2026-04-18 21:59:38,142 [root] DEBUG: 4908: FreeHandler: Address: 0x025C0000.
2026-04-18 21:59:38,143 [root] DEBUG: 4908: DumpRegion: Dump at 0x025C0000 skipped due to dump limit 10
2026-04-18 21:59:38,144 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x025C0000.
2026-04-18 21:59:38,144 [root] DEBUG: 4908: YaraScan: Scanning 0x025C0000, size 0x20
2026-04-18 21:59:38,145 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710DEE8 prior to its freeing.
2026-04-18 21:59:38,146 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x025C0000 from the end of the tracked region list.
2026-04-18 21:59:38,147 [root] DEBUG: 4908: FreeHandler: Address: 0x02580000.
2026-04-18 21:59:38,148 [root] DEBUG: 4908: DumpRegion: Dump at 0x02580000 skipped due to dump limit 10
2026-04-18 21:59:38,149 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x02580000.
2026-04-18 21:59:38,149 [root] DEBUG: 4908: YaraScan: Scanning 0x02580000, size 0x20
2026-04-18 21:59:38,150 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07627A50 prior to its freeing.
2026-04-18 21:59:38,152 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x02580000 from the end of the tracked region list.
2026-04-18 21:59:38,156 [root] DEBUG: 4908: FreeHandler: Address: 0x02570000.
2026-04-18 21:59:38,157 [root] DEBUG: 4908: DumpRegion: Dump at 0x02570000 skipped due to dump limit 10
2026-04-18 21:59:38,157 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x02570000.
2026-04-18 21:59:38,159 [root] DEBUG: 4908: YaraScan: Scanning 0x02570000, size 0x20
2026-04-18 21:59:38,160 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710DC80 prior to its freeing.
2026-04-18 21:59:38,160 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x02570000 from the end of the tracked region list.
2026-04-18 21:59:38,164 [root] DEBUG: 4908: FreeHandler: Address: 0x00C80000.
2026-04-18 21:59:38,164 [root] DEBUG: 4908: DumpRegion: Dump at 0x00C80000 skipped due to dump limit 10
2026-04-18 21:59:38,165 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x00C80000.
2026-04-18 21:59:38,167 [root] DEBUG: 4908: YaraScan: Scanning 0x00C80000, size 0x20
2026-04-18 21:59:38,167 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710D7B0 prior to its freeing.
2026-04-18 21:59:38,168 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x00C80000 from the end of the tracked region list.
2026-04-18 21:59:38,170 [root] DEBUG: 4908: FreeHandler: Address: 0x09120000.
2026-04-18 21:59:38,171 [root] DEBUG: 4908: DumpRegion: Dump at 0x09120000 skipped due to dump limit 10
2026-04-18 21:59:38,171 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09120000.
2026-04-18 21:59:38,172 [root] DEBUG: 4908: YaraScan: Scanning 0x09120000, size 0x20
2026-04-18 21:59:38,173 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:38,174 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09120000 from tracked region list.
2026-04-18 21:59:38,175 [root] DEBUG: 4908: FreeHandler: Address: 0x09110000.
2026-04-18 21:59:38,176 [root] DEBUG: 4908: DumpRegion: Dump at 0x09110000 skipped due to dump limit 10
2026-04-18 21:59:38,177 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09110000.
2026-04-18 21:59:38,178 [root] DEBUG: 4908: YaraScan: Scanning 0x09110000, size 0x20
2026-04-18 21:59:38,179 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07121F18 prior to its freeing.
2026-04-18 21:59:38,180 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09110000 from tracked region list.
2026-04-18 21:59:38,181 [root] DEBUG: 4908: FreeHandler: Address: 0x09100000.
2026-04-18 21:59:38,182 [root] DEBUG: 4908: DumpRegion: Dump at 0x09100000 skipped due to dump limit 10
2026-04-18 21:59:38,185 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09100000.
2026-04-18 21:59:38,186 [root] DEBUG: 4908: YaraScan: Scanning 0x09100000, size 0x20
2026-04-18 21:59:38,187 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710D078 prior to its freeing.
2026-04-18 21:59:38,188 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09100000 from tracked region list.
2026-04-18 21:59:38,190 [root] DEBUG: 4908: FreeHandler: Address: 0x090F0000.
2026-04-18 21:59:38,190 [root] DEBUG: 4908: DumpRegion: Dump at 0x090F0000 skipped due to dump limit 10
2026-04-18 21:59:38,191 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090F0000.
2026-04-18 21:59:38,192 [root] DEBUG: 4908: YaraScan: Scanning 0x090F0000, size 0x20
2026-04-18 21:59:38,193 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07120A80 prior to its freeing.
2026-04-18 21:59:38,194 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x090F0000 from tracked region list.
2026-04-18 21:59:38,195 [root] DEBUG: 4908: FreeHandler: Address: 0x090E0000.
2026-04-18 21:59:38,196 [root] DEBUG: 4908: DumpRegion: Dump at 0x090E0000 skipped due to dump limit 10
2026-04-18 21:59:38,197 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090E0000.
2026-04-18 21:59:38,197 [root] DEBUG: 4908: YaraScan: Scanning 0x090E0000, size 0x20
2026-04-18 21:59:38,198 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710CE10 prior to its freeing.
2026-04-18 21:59:38,199 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x090E0000 from tracked region list.
2026-04-18 21:59:38,200 [root] DEBUG: 4908: FreeHandler: Address: 0x090D0000.
2026-04-18 21:59:38,201 [root] DEBUG: 4908: DumpRegion: Dump at 0x090D0000 skipped due to dump limit 10
2026-04-18 21:59:38,206 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090D0000.
2026-04-18 21:59:38,207 [root] DEBUG: 4908: YaraScan: Scanning 0x090D0000, size 0x20
2026-04-18 21:59:38,208 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0711F5E8 prior to its freeing.
2026-04-18 21:59:38,209 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x090D0000 from tracked region list.
2026-04-18 21:59:38,210 [root] DEBUG: 4908: FreeHandler: Address: 0x090C0000.
2026-04-18 21:59:38,211 [root] DEBUG: 4908: DumpRegion: Dump at 0x090C0000 skipped due to dump limit 10
2026-04-18 21:59:38,211 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090C0000.
2026-04-18 21:59:38,212 [root] DEBUG: 4908: YaraScan: Scanning 0x090C0000, size 0x20
2026-04-18 21:59:38,213 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710DA18 prior to its freeing.
2026-04-18 21:59:38,214 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x090C0000 from tracked region list.
2026-04-18 21:59:38,215 [root] DEBUG: 4908: FreeHandler: Address: 0x090B0000.
2026-04-18 21:59:38,216 [root] DEBUG: 4908: DumpRegion: Dump at 0x090B0000 skipped due to dump limit 10
2026-04-18 21:59:38,217 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090B0000.
2026-04-18 21:59:38,218 [root] DEBUG: 4908: YaraScan: Scanning 0x090B0000, size 0x20
2026-04-18 21:59:38,219 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0711E150 prior to its freeing.
2026-04-18 21:59:38,219 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x090B0000 from tracked region list.
2026-04-18 21:59:38,221 [root] DEBUG: 4908: FreeHandler: Address: 0x090A0000.
2026-04-18 21:59:38,221 [root] DEBUG: 4908: DumpRegion: Dump at 0x090A0000 skipped due to dump limit 10
2026-04-18 21:59:38,222 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x090A0000.
2026-04-18 21:59:38,223 [root] DEBUG: 4908: YaraScan: Scanning 0x090A0000, size 0x20
2026-04-18 21:59:38,224 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710EAF0 prior to its freeing.
2026-04-18 21:59:38,224 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x090A0000 from tracked region list.
2026-04-18 21:59:38,226 [root] DEBUG: 4908: FreeHandler: Address: 0x09150000.
2026-04-18 21:59:38,226 [root] DEBUG: 4908: DumpRegion: Dump at 0x09150000 skipped due to dump limit 10
2026-04-18 21:59:38,227 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09150000.
2026-04-18 21:59:38,228 [root] DEBUG: 4908: YaraScan: Scanning 0x09150000, size 0x20
2026-04-18 21:59:38,229 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0711CCB8 prior to its freeing.
2026-04-18 21:59:38,229 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09150000 from tracked region list.
2026-04-18 21:59:38,231 [root] DEBUG: 4908: FreeHandler: Address: 0x09140000.
2026-04-18 21:59:38,231 [root] DEBUG: 4908: DumpRegion: Dump at 0x09140000 skipped due to dump limit 10
2026-04-18 21:59:38,232 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09140000.
2026-04-18 21:59:38,312 [root] DEBUG: 4908: YaraScan: Scanning 0x09140000, size 0x20
2026-04-18 21:59:38,314 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710E888 prior to its freeing.
2026-04-18 21:59:38,315 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09140000 from tracked region list.
2026-04-18 21:59:38,316 [root] DEBUG: 4908: FreeHandler: Address: 0x092B0000.
2026-04-18 21:59:38,317 [root] DEBUG: 4908: DumpRegion: Dump at 0x092B0000 skipped due to dump limit 10
2026-04-18 21:59:38,318 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x092B0000.
2026-04-18 21:59:38,319 [root] DEBUG: 4908: YaraScan: Scanning 0x092B0000, size 0x20
2026-04-18 21:59:38,320 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716B618 prior to its freeing.
2026-04-18 21:59:38,321 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x092B0000 from the end of the tracked region list.
2026-04-18 21:59:38,323 [root] DEBUG: 4908: FreeHandler: Address: 0x092A0000.
2026-04-18 21:59:38,324 [root] DEBUG: 4908: DumpRegion: Dump at 0x092A0000 skipped due to dump limit 10
2026-04-18 21:59:38,325 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x092A0000.
2026-04-18 21:59:38,326 [root] DEBUG: 4908: YaraScan: Scanning 0x092A0000, size 0x20
2026-04-18 21:59:38,327 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07615F08 prior to its freeing.
2026-04-18 21:59:38,328 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x092A0000 from the end of the tracked region list.
2026-04-18 21:59:38,334 [root] DEBUG: 4908: FreeHandler: Address: 0x09290000.
2026-04-18 21:59:38,358 [root] DEBUG: 4908: DumpRegion: Dump at 0x09290000 skipped due to dump limit 10
2026-04-18 21:59:38,359 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09290000.
2026-04-18 21:59:38,360 [root] DEBUG: 4908: YaraScan: Scanning 0x09290000, size 0x20
2026-04-18 21:59:38,361 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716A598 prior to its freeing.
2026-04-18 21:59:38,362 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09290000 from the end of the tracked region list.
2026-04-18 21:59:38,367 [root] DEBUG: 4908: FreeHandler: Address: 0x09280000.
2026-04-18 21:59:38,367 [root] DEBUG: 4908: DumpRegion: Dump at 0x09280000 skipped due to dump limit 10
2026-04-18 21:59:38,383 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09280000.
2026-04-18 21:59:38,384 [root] DEBUG: 4908: YaraScan: Scanning 0x09280000, size 0x20
2026-04-18 21:59:38,386 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x076149F0 prior to its freeing.
2026-04-18 21:59:38,387 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09280000 from the end of the tracked region list.
2026-04-18 21:59:38,388 [root] DEBUG: 4908: FreeHandler: Address: 0x09270000.
2026-04-18 21:59:38,389 [root] DEBUG: 4908: DumpRegion: Dump at 0x09270000 skipped due to dump limit 10
2026-04-18 21:59:38,390 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09270000.
2026-04-18 21:59:38,392 [root] DEBUG: 4908: YaraScan: Scanning 0x09270000, size 0x20
2026-04-18 21:59:38,393 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716B568 prior to its freeing.
2026-04-18 21:59:38,394 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09270000 from the end of the tracked region list.
2026-04-18 21:59:38,397 [root] DEBUG: 4908: FreeHandler: Address: 0x09260000.
2026-04-18 21:59:38,401 [root] DEBUG: 4908: DumpRegion: Dump at 0x09260000 skipped due to dump limit 10
2026-04-18 21:59:38,403 [root] DEBUG: 2552: api-cap: memcpy hook disabled due to count: 5000
2026-04-18 21:59:38,404 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09260000.
2026-04-18 21:59:38,405 [root] DEBUG: 4908: YaraScan: Scanning 0x09260000, size 0x20
2026-04-18 21:59:38,406 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x076134D8 prior to its freeing.
2026-04-18 21:59:38,407 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09260000 from the end of the tracked region list.
2026-04-18 21:59:38,409 [root] DEBUG: 4908: FreeHandler: Address: 0x09250000.
2026-04-18 21:59:38,410 [root] DEBUG: 4908: DumpRegion: Dump at 0x09250000 skipped due to dump limit 10
2026-04-18 21:59:38,410 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09250000.
2026-04-18 21:59:38,411 [root] DEBUG: 4908: YaraScan: Scanning 0x09250000, size 0x20
2026-04-18 21:59:38,412 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716A4E8 prior to its freeing.
2026-04-18 21:59:38,412 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09250000 from the end of the tracked region list.
2026-04-18 21:59:38,414 [root] DEBUG: 4908: FreeHandler: Address: 0x09240000.
2026-04-18 21:59:38,414 [root] DEBUG: 4908: DumpRegion: Dump at 0x09240000 skipped due to dump limit 10
2026-04-18 21:59:38,415 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09240000.
2026-04-18 21:59:38,416 [root] DEBUG: 4908: YaraScan: Scanning 0x09240000, size 0x20
2026-04-18 21:59:38,417 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07611FC0 prior to its freeing.
2026-04-18 21:59:38,418 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09240000 from the end of the tracked region list.
2026-04-18 21:59:38,419 [root] DEBUG: 4908: FreeHandler: Address: 0x09230000.
2026-04-18 21:59:38,420 [root] DEBUG: 4908: DumpRegion: Dump at 0x09230000 skipped due to dump limit 10
2026-04-18 21:59:38,420 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09230000.
2026-04-18 21:59:38,421 [root] DEBUG: 4908: YaraScan: Scanning 0x09230000, size 0x20
2026-04-18 21:59:38,422 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716A438 prior to its freeing.
2026-04-18 21:59:38,424 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09230000 from the end of the tracked region list.
2026-04-18 21:59:38,425 [root] DEBUG: 4908: FreeHandler: Address: 0x09220000.
2026-04-18 21:59:38,426 [root] DEBUG: 4908: DumpRegion: Dump at 0x09220000 skipped due to dump limit 10
2026-04-18 21:59:38,426 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09220000.
2026-04-18 21:59:38,427 [root] DEBUG: 4908: YaraScan: Scanning 0x09220000, size 0x20
2026-04-18 21:59:38,428 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07610AA8 prior to its freeing.
2026-04-18 21:59:38,429 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09220000 from the end of the tracked region list.
2026-04-18 21:59:38,430 [root] DEBUG: 4908: FreeHandler: Address: 0x09210000.
2026-04-18 21:59:38,431 [root] DEBUG: 4908: DumpRegion: Dump at 0x09210000 skipped due to dump limit 10
2026-04-18 21:59:38,431 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09210000.
2026-04-18 21:59:38,432 [root] DEBUG: 4908: YaraScan: Scanning 0x09210000, size 0x20
2026-04-18 21:59:38,433 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716B4B8 prior to its freeing.
2026-04-18 21:59:38,434 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09210000 from the end of the tracked region list.
2026-04-18 21:59:38,435 [root] DEBUG: 4908: FreeHandler: Address: 0x09200000.
2026-04-18 21:59:38,436 [root] DEBUG: 4908: DumpRegion: Dump at 0x09200000 skipped due to dump limit 10
2026-04-18 21:59:38,436 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09200000.
2026-04-18 21:59:38,437 [root] DEBUG: 4908: YaraScan: Scanning 0x09200000, size 0x20
2026-04-18 21:59:38,438 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0760F590 prior to its freeing.
2026-04-18 21:59:38,439 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09200000 from the end of the tracked region list.
2026-04-18 21:59:38,439 [root] DEBUG: 4908: FreeHandler: Address: 0x091F0000.
2026-04-18 21:59:38,440 [root] DEBUG: 4908: DumpRegion: Dump at 0x091F0000 skipped due to dump limit 10
2026-04-18 21:59:38,441 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091F0000.
2026-04-18 21:59:38,442 [root] DEBUG: 4908: YaraScan: Scanning 0x091F0000, size 0x20
2026-04-18 21:59:38,442 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716B778 prior to its freeing.
2026-04-18 21:59:38,443 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x091F0000 from the end of the tracked region list.
2026-04-18 21:59:38,444 [root] DEBUG: 4908: FreeHandler: Address: 0x091E0000.
2026-04-18 21:59:38,445 [root] DEBUG: 4908: DumpRegion: Dump at 0x091E0000 skipped due to dump limit 10
2026-04-18 21:59:38,446 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091E0000.
2026-04-18 21:59:38,447 [root] DEBUG: 4908: YaraScan: Scanning 0x091E0000, size 0x20
2026-04-18 21:59:38,447 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075FD598 prior to its freeing.
2026-04-18 21:59:38,448 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x091E0000 from the end of the tracked region list.
2026-04-18 21:59:38,449 [root] DEBUG: 4908: FreeHandler: Address: 0x091D0000.
2026-04-18 21:59:38,450 [root] DEBUG: 4908: DumpRegion: Dump at 0x091D0000 skipped due to dump limit 10
2026-04-18 21:59:38,455 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091D0000.
2026-04-18 21:59:38,456 [root] DEBUG: 4908: YaraScan: Scanning 0x091D0000, size 0x20
2026-04-18 21:59:38,457 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716B8D8 prior to its freeing.
2026-04-18 21:59:38,458 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x091D0000 from the end of the tracked region list.
2026-04-18 21:59:38,459 [root] DEBUG: 4908: FreeHandler: Address: 0x091C0000.
2026-04-18 21:59:38,460 [root] DEBUG: 4908: DumpRegion: Dump at 0x091C0000 skipped due to dump limit 10
2026-04-18 21:59:38,461 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091C0000.
2026-04-18 21:59:38,462 [root] DEBUG: 4908: YaraScan: Scanning 0x091C0000, size 0x20
2026-04-18 21:59:38,462 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075FC080 prior to its freeing.
2026-04-18 21:59:38,463 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x091C0000 from the end of the tracked region list.
2026-04-18 21:59:38,464 [root] DEBUG: 4908: FreeHandler: Address: 0x091B0000.
2026-04-18 21:59:38,465 [root] DEBUG: 4908: DumpRegion: Dump at 0x091B0000 skipped due to dump limit 10
2026-04-18 21:59:38,466 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091B0000.
2026-04-18 21:59:38,467 [root] DEBUG: 4908: YaraScan: Scanning 0x091B0000, size 0x20
2026-04-18 21:59:38,468 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716AB18 prior to its freeing.
2026-04-18 21:59:38,468 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x091B0000 from the end of the tracked region list.
2026-04-18 21:59:38,469 [root] DEBUG: 4908: FreeHandler: Address: 0x091A0000.
2026-04-18 21:59:38,470 [root] DEBUG: 4908: DumpRegion: Dump at 0x091A0000 skipped due to dump limit 10
2026-04-18 21:59:38,471 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x091A0000.
2026-04-18 21:59:38,472 [root] DEBUG: 4908: YaraScan: Scanning 0x091A0000, size 0x20
2026-04-18 21:59:38,473 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075DABB8 prior to its freeing.
2026-04-18 21:59:38,473 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x091A0000 from the end of the tracked region list.
2026-04-18 21:59:38,474 [root] DEBUG: 4908: FreeHandler: Address: 0x09190000.
2026-04-18 21:59:38,475 [root] DEBUG: 4908: DumpRegion: Dump at 0x09190000 skipped due to dump limit 10
2026-04-18 21:59:38,476 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09190000.
2026-04-18 21:59:38,477 [root] DEBUG: 4908: YaraScan: Scanning 0x09190000, size 0x20
2026-04-18 21:59:38,477 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716BAE8 prior to its freeing.
2026-04-18 21:59:38,478 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09190000 from the end of the tracked region list.
2026-04-18 21:59:38,480 [root] DEBUG: 4908: FreeHandler: Address: 0x09180000.
2026-04-18 21:59:38,480 [root] DEBUG: 4908: DumpRegion: Dump at 0x09180000 skipped due to dump limit 10
2026-04-18 21:59:38,481 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09180000.
2026-04-18 21:59:38,482 [root] DEBUG: 4908: YaraScan: Scanning 0x09180000, size 0x20
2026-04-18 21:59:38,483 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075D96A0 prior to its freeing.
2026-04-18 21:59:38,484 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09180000 from the end of the tracked region list.
2026-04-18 21:59:38,485 [root] DEBUG: 4908: FreeHandler: Address: 0x09060000.
2026-04-18 21:59:38,486 [root] DEBUG: 4908: DumpRegion: Dump at 0x09060000 skipped due to dump limit 10
2026-04-18 21:59:38,487 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09060000.
2026-04-18 21:59:38,488 [root] DEBUG: 4908: YaraScan: Scanning 0x09060000, size 0x20
2026-04-18 21:59:38,489 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07118070 prior to its freeing.
2026-04-18 21:59:38,489 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09060000 from the end of the tracked region list.
2026-04-18 21:59:38,491 [root] DEBUG: 4908: FreeHandler: Address: 0x09050000.
2026-04-18 21:59:38,491 [root] DEBUG: 4908: DumpRegion: Dump at 0x09050000 skipped due to dump limit 10
2026-04-18 21:59:38,492 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09050000.
2026-04-18 21:59:38,493 [root] DEBUG: 4908: YaraScan: Scanning 0x09050000, size 0x20
2026-04-18 21:59:38,494 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710D548 prior to its freeing.
2026-04-18 21:59:38,495 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09050000 from the end of the tracked region list.
2026-04-18 21:59:38,496 [root] DEBUG: 4908: FreeHandler: Address: 0x09040000.
2026-04-18 21:59:38,497 [root] DEBUG: 4908: DumpRegion: Dump at 0x09040000 skipped due to dump limit 10
2026-04-18 21:59:38,498 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09040000.
2026-04-18 21:59:38,499 [root] DEBUG: 4908: YaraScan: Scanning 0x09040000, size 0x20
2026-04-18 21:59:38,500 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07115FC0 prior to its freeing.
2026-04-18 21:59:38,501 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09040000 from the end of the tracked region list.
2026-04-18 21:59:38,502 [root] DEBUG: 4908: FreeHandler: Address: 0x08FA0000.
2026-04-18 21:59:38,503 [root] DEBUG: 4908: DumpRegion: Dump at 0x08FA0000 skipped due to dump limit 10
2026-04-18 21:59:38,503 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08FA0000.
2026-04-18 21:59:38,504 [root] DEBUG: 4908: YaraScan: Scanning 0x08FA0000, size 0x20
2026-04-18 21:59:38,505 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0710E620 prior to its freeing.
2026-04-18 21:59:38,506 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08FA0000 from the end of the tracked region list.
2026-04-18 21:59:38,572 [root] DEBUG: 4908: DLL loaded at 0x71770000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-04-18 21:59:38,574 [root] DEBUG: 4908: DLL loaded at 0x71760000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-04-18 21:59:38,578 [root] DEBUG: 4908: DLL loaded at 0x71740000: C:\Windows\SYSTEM32\wkscli (0x11000 bytes).
2026-04-18 21:59:38,593 [root] DEBUG: 4908: DLL loaded at 0x72030000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-04-18 21:59:38,596 [root] DEBUG: 4908: DLL loaded at 0x72000000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2026-04-18 21:59:39,287 [root] DEBUG: 4908: api-cap: NtAllocateVirtualMemory hook disabled due to count: 5000
2026-04-18 21:59:40,040 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NIRYUO8B8C3ZJ8QS8IWC.temp
2026-04-18 21:59:40,078 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF630f6.TMP to files\f00c78d05edc5f33df432abcc9352161ebb1b855b22d98fa3285d45536bfe15e; Size is 3228; Max size: 100000000
2026-04-18 21:59:40,222 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XWKH5OWQQ9FDQYRKJQ73.temp
2026-04-18 21:59:40,252 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF631a1.TMP to files\8f55fc1dd43acf4f55412d3cf78c659ba7f4d4e10fccc0b182e4ad339600772c; Size is 3228; Max size: 100000000
2026-04-18 21:59:40,316 [root] DEBUG: 4908: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-04-18 21:59:40,318 [root] DEBUG: 4908: FreeHandler: Address: 0x08E70000.
2026-04-18 21:59:40,319 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E70000 skipped due to dump limit 10
2026-04-18 21:59:40,319 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E70000.
2026-04-18 21:59:40,320 [root] DEBUG: 4908: YaraScan: Scanning 0x08E70000, size 0x20
2026-04-18 21:59:40,321 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070F7AE0 prior to its freeing.
2026-04-18 21:59:40,322 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08E70000 from the end of the tracked region list.
2026-04-18 21:59:40,324 [root] DEBUG: 4908: FreeHandler: Address: 0x08E60000.
2026-04-18 21:59:40,325 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E60000 skipped due to dump limit 10
2026-04-18 21:59:40,326 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E60000.
2026-04-18 21:59:40,326 [root] DEBUG: 4908: YaraScan: Scanning 0x08E60000, size 0x20
2026-04-18 21:59:40,327 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070F78A0 prior to its freeing.
2026-04-18 21:59:40,328 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08E60000 from the end of the tracked region list.
2026-04-18 21:59:40,330 [root] DEBUG: 4908: FreeHandler: Address: 0x08E50000.
2026-04-18 21:59:40,330 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E50000 skipped due to dump limit 10
2026-04-18 21:59:40,331 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E50000.
2026-04-18 21:59:40,332 [root] DEBUG: 4908: YaraScan: Scanning 0x08E50000, size 0x20
2026-04-18 21:59:40,333 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07187960 prior to its freeing.
2026-04-18 21:59:40,334 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08E50000 from the end of the tracked region list.
2026-04-18 21:59:40,335 [root] DEBUG: 4908: FreeHandler: Address: 0x08E40000.
2026-04-18 21:59:40,336 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E40000 skipped due to dump limit 10
2026-04-18 21:59:40,337 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E40000.
2026-04-18 21:59:40,338 [root] DEBUG: 4908: YaraScan: Scanning 0x08E40000, size 0x20
2026-04-18 21:59:40,338 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07187710 prior to its freeing.
2026-04-18 21:59:40,339 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08E40000 from the end of the tracked region list.
2026-04-18 21:59:40,342 [root] DEBUG: 4908: FreeHandler: Address: 0x08E30000.
2026-04-18 21:59:40,343 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E30000 skipped due to dump limit 10
2026-04-18 21:59:40,343 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E30000.
2026-04-18 21:59:40,344 [root] DEBUG: 4908: YaraScan: Scanning 0x08E30000, size 0x20
2026-04-18 21:59:40,345 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716BA38 prior to its freeing.
2026-04-18 21:59:40,346 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08E30000 from the end of the tracked region list.
2026-04-18 21:59:40,347 [root] DEBUG: 4908: FreeHandler: Address: 0x08E20000.
2026-04-18 21:59:40,348 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E20000 skipped due to dump limit 10
2026-04-18 21:59:40,348 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E20000.
2026-04-18 21:59:40,349 [root] DEBUG: 4908: YaraScan: Scanning 0x08E20000, size 0x20
2026-04-18 21:59:40,350 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x071874C0 prior to its freeing.
2026-04-18 21:59:40,351 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08E20000 from the end of the tracked region list.
2026-04-18 21:59:40,353 [root] DEBUG: 4908: FreeHandler: Address: 0x08E10000.
2026-04-18 21:59:40,353 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E10000 skipped due to dump limit 10
2026-04-18 21:59:40,354 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E10000.
2026-04-18 21:59:40,355 [root] DEBUG: 4908: YaraScan: Scanning 0x08E10000, size 0x20
2026-04-18 21:59:40,356 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070F63A8 prior to its freeing.
2026-04-18 21:59:40,357 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08E10000 from the end of the tracked region list.
2026-04-18 21:59:40,358 [root] DEBUG: 4908: FreeHandler: Address: 0x08E00000.
2026-04-18 21:59:40,359 [root] DEBUG: 4908: DumpRegion: Dump at 0x08E00000 skipped due to dump limit 10
2026-04-18 21:59:40,360 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08E00000.
2026-04-18 21:59:40,361 [root] DEBUG: 4908: YaraScan: Scanning 0x08E00000, size 0x20
2026-04-18 21:59:40,362 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070F5168 prior to its freeing.
2026-04-18 21:59:40,364 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08E00000 from the end of the tracked region list.
2026-04-18 21:59:40,366 [root] DEBUG: 4908: FreeHandler: Address: 0x08DF0000.
2026-04-18 21:59:40,367 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DF0000 skipped due to dump limit 10
2026-04-18 21:59:40,367 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DF0000.
2026-04-18 21:59:40,368 [root] DEBUG: 4908: YaraScan: Scanning 0x08DF0000, size 0x20
2026-04-18 21:59:40,369 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070F4578 prior to its freeing.
2026-04-18 21:59:40,370 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08DF0000 from the end of the tracked region list.
2026-04-18 21:59:40,371 [root] DEBUG: 4908: FreeHandler: Address: 0x08DE0000.
2026-04-18 21:59:40,372 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DE0000 skipped due to dump limit 10
2026-04-18 21:59:40,373 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DE0000.
2026-04-18 21:59:40,374 [root] DEBUG: 4908: YaraScan: Scanning 0x08DE0000, size 0x20
2026-04-18 21:59:40,375 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07187270 prior to its freeing.
2026-04-18 21:59:40,375 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08DE0000 from the end of the tracked region list.
2026-04-18 21:59:40,376 [root] DEBUG: 4908: FreeHandler: Address: 0x08DD0000.
2026-04-18 21:59:40,377 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DD0000 skipped due to dump limit 10
2026-04-18 21:59:40,378 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DD0000.
2026-04-18 21:59:40,378 [root] DEBUG: 4908: YaraScan: Scanning 0x08DD0000, size 0x20
2026-04-18 21:59:40,379 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,380 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08DD0000 from the end of the tracked region list.
2026-04-18 21:59:40,381 [root] DEBUG: 4908: FreeHandler: Address: 0x08DC0000.
2026-04-18 21:59:40,382 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DC0000 skipped due to dump limit 10
2026-04-18 21:59:40,383 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DC0000.
2026-04-18 21:59:40,384 [root] DEBUG: 4908: YaraScan: Scanning 0x08DC0000, size 0x20
2026-04-18 21:59:40,385 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070F2E58 prior to its freeing.
2026-04-18 21:59:40,386 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08DC0000 from the end of the tracked region list.
2026-04-18 21:59:40,387 [root] DEBUG: 4908: FreeHandler: Address: 0x09830000.
2026-04-18 21:59:40,388 [root] DEBUG: 4908: DumpRegion: Dump at 0x09830000 skipped due to dump limit 10
2026-04-18 21:59:40,389 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09830000.
2026-04-18 21:59:40,390 [root] DEBUG: 4908: YaraScan: Scanning 0x09830000, size 0x20
2026-04-18 21:59:40,391 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07187020 prior to its freeing.
2026-04-18 21:59:40,391 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09830000 from the end of the tracked region list.
2026-04-18 21:59:40,394 [root] DEBUG: 4908: FreeHandler: Address: 0x09820000.
2026-04-18 21:59:40,395 [root] DEBUG: 4908: DumpRegion: Dump at 0x09820000 skipped due to dump limit 10
2026-04-18 21:59:40,396 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09820000.
2026-04-18 21:59:40,396 [root] DEBUG: 4908: YaraScan: Scanning 0x09820000, size 0x20
2026-04-18 21:59:40,397 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070F0FA8 prior to its freeing.
2026-04-18 21:59:40,398 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09820000 from the end of the tracked region list.
2026-04-18 21:59:40,400 [root] DEBUG: 4908: FreeHandler: Address: 0x09810000.
2026-04-18 21:59:40,401 [root] DEBUG: 4908: DumpRegion: Dump at 0x09810000 skipped due to dump limit 10
2026-04-18 21:59:40,402 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09810000.
2026-04-18 21:59:40,402 [root] DEBUG: 4908: YaraScan: Scanning 0x09810000, size 0x20
2026-04-18 21:59:40,403 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716E4E0 prior to its freeing.
2026-04-18 21:59:40,404 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09810000 from the end of the tracked region list.
2026-04-18 21:59:40,406 [root] DEBUG: 4908: FreeHandler: Address: 0x09800000.
2026-04-18 21:59:40,407 [root] DEBUG: 4908: DumpRegion: Dump at 0x09800000 skipped due to dump limit 10
2026-04-18 21:59:40,407 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09800000.
2026-04-18 21:59:40,408 [root] DEBUG: 4908: YaraScan: Scanning 0x09800000, size 0x20
2026-04-18 21:59:40,409 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070EED08 prior to its freeing.
2026-04-18 21:59:40,410 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09800000 from the end of the tracked region list.
2026-04-18 21:59:40,411 [root] DEBUG: 4908: FreeHandler: Address: 0x097F0000.
2026-04-18 21:59:40,412 [root] DEBUG: 4908: DumpRegion: Dump at 0x097F0000 skipped due to dump limit 10
2026-04-18 21:59:40,413 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097F0000.
2026-04-18 21:59:40,414 [root] DEBUG: 4908: YaraScan: Scanning 0x097F0000, size 0x20
2026-04-18 21:59:40,415 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070EEAE0 prior to its freeing.
2026-04-18 21:59:40,416 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x097F0000 from the end of the tracked region list.
2026-04-18 21:59:40,417 [root] DEBUG: 4908: FreeHandler: Address: 0x097E0000.
2026-04-18 21:59:40,418 [root] DEBUG: 4908: DumpRegion: Dump at 0x097E0000 skipped due to dump limit 10
2026-04-18 21:59:40,419 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097E0000.
2026-04-18 21:59:40,420 [root] DEBUG: 4908: YaraScan: Scanning 0x097E0000, size 0x20
2026-04-18 21:59:40,421 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0715FFE0 prior to its freeing.
2026-04-18 21:59:40,422 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x097E0000 from the end of the tracked region list.
2026-04-18 21:59:40,423 [root] DEBUG: 4908: FreeHandler: Address: 0x097D0000.
2026-04-18 21:59:40,424 [root] DEBUG: 4908: DumpRegion: Dump at 0x097D0000 skipped due to dump limit 10
2026-04-18 21:59:40,425 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097D0000.
2026-04-18 21:59:40,426 [root] DEBUG: 4908: YaraScan: Scanning 0x097D0000, size 0x20
2026-04-18 21:59:40,427 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,428 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x097D0000 from the end of the tracked region list.
2026-04-18 21:59:40,429 [root] DEBUG: 4908: FreeHandler: Address: 0x097C0000.
2026-04-18 21:59:40,430 [root] DEBUG: 4908: DumpRegion: Dump at 0x097C0000 skipped due to dump limit 10
2026-04-18 21:59:40,431 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097C0000.
2026-04-18 21:59:40,432 [root] DEBUG: 4908: YaraScan: Scanning 0x097C0000, size 0x20
2026-04-18 21:59:40,433 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716BE58 prior to its freeing.
2026-04-18 21:59:40,434 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x097C0000 from the end of the tracked region list.
2026-04-18 21:59:40,435 [root] DEBUG: 4908: FreeHandler: Address: 0x097B0000.
2026-04-18 21:59:40,436 [root] DEBUG: 4908: DumpRegion: Dump at 0x097B0000 skipped due to dump limit 10
2026-04-18 21:59:40,437 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097B0000.
2026-04-18 21:59:40,437 [root] DEBUG: 4908: YaraScan: Scanning 0x097B0000, size 0x20
2026-04-18 21:59:40,438 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070DDD60 prior to its freeing.
2026-04-18 21:59:40,439 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x097B0000 from the end of the tracked region list.
2026-04-18 21:59:40,441 [root] DEBUG: 4908: FreeHandler: Address: 0x097A0000.
2026-04-18 21:59:40,441 [root] DEBUG: 4908: DumpRegion: Dump at 0x097A0000 skipped due to dump limit 10
2026-04-18 21:59:40,442 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x097A0000.
2026-04-18 21:59:40,443 [root] DEBUG: 4908: YaraScan: Scanning 0x097A0000, size 0x20
2026-04-18 21:59:40,443 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070DDB38 prior to its freeing.
2026-04-18 21:59:40,444 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x097A0000 from the end of the tracked region list.
2026-04-18 21:59:40,445 [root] DEBUG: 4908: FreeHandler: Address: 0x09790000.
2026-04-18 21:59:40,446 [root] DEBUG: 4908: DumpRegion: Dump at 0x09790000 skipped due to dump limit 10
2026-04-18 21:59:40,447 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09790000.
2026-04-18 21:59:40,447 [root] DEBUG: 4908: YaraScan: Scanning 0x09790000, size 0x20
2026-04-18 21:59:40,448 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x075DC578 prior to its freeing.
2026-04-18 21:59:40,449 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09790000 from the end of the tracked region list.
2026-04-18 21:59:40,451 [root] DEBUG: 4908: FreeHandler: Address: 0x09780000.
2026-04-18 21:59:40,451 [root] DEBUG: 4908: DumpRegion: Dump at 0x09780000 skipped due to dump limit 10
2026-04-18 21:59:40,452 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09780000.
2026-04-18 21:59:40,453 [root] DEBUG: 4908: YaraScan: Scanning 0x09780000, size 0x20
2026-04-18 21:59:40,454 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,455 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09780000 from the end of the tracked region list.
2026-04-18 21:59:40,456 [root] DEBUG: 4908: FreeHandler: Address: 0x09770000.
2026-04-18 21:59:40,457 [root] DEBUG: 4908: DumpRegion: Dump at 0x09770000 skipped due to dump limit 10
2026-04-18 21:59:40,458 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09770000.
2026-04-18 21:59:40,459 [root] DEBUG: 4908: YaraScan: Scanning 0x09770000, size 0x20
2026-04-18 21:59:40,460 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716BCF8 prior to its freeing.
2026-04-18 21:59:40,461 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09770000 from the end of the tracked region list.
2026-04-18 21:59:40,462 [root] DEBUG: 4908: FreeHandler: Address: 0x09760000.
2026-04-18 21:59:40,462 [root] DEBUG: 4908: DumpRegion: Dump at 0x09760000 skipped due to dump limit 10
2026-04-18 21:59:40,463 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09760000.
2026-04-18 21:59:40,464 [root] DEBUG: 4908: YaraScan: Scanning 0x09760000, size 0x20
2026-04-18 21:59:40,465 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0716BC48 prior to its freeing.
2026-04-18 21:59:40,466 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09760000 from the end of the tracked region list.
2026-04-18 21:59:40,467 [root] DEBUG: 4908: FreeHandler: Address: 0x09750000.
2026-04-18 21:59:40,468 [root] DEBUG: 4908: DumpRegion: Dump at 0x09750000 skipped due to dump limit 10
2026-04-18 21:59:40,468 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09750000.
2026-04-18 21:59:40,469 [root] DEBUG: 4908: YaraScan: Scanning 0x09750000, size 0x20
2026-04-18 21:59:40,470 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07175DA0 prior to its freeing.
2026-04-18 21:59:40,471 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09750000 from the end of the tracked region list.
2026-04-18 21:59:40,472 [root] DEBUG: 4908: FreeHandler: Address: 0x09740000.
2026-04-18 21:59:40,474 [root] DEBUG: 4908: DumpRegion: Dump at 0x09740000 skipped due to dump limit 10
2026-04-18 21:59:40,474 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09740000.
2026-04-18 21:59:40,475 [root] DEBUG: 4908: YaraScan: Scanning 0x09740000, size 0x20
2026-04-18 21:59:40,476 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070CC4F8 prior to its freeing.
2026-04-18 21:59:40,477 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09740000 from the end of the tracked region list.
2026-04-18 21:59:40,478 [root] DEBUG: 4908: FreeHandler: Address: 0x09730000.
2026-04-18 21:59:40,479 [root] DEBUG: 4908: DumpRegion: Dump at 0x09730000 skipped due to dump limit 10
2026-04-18 21:59:40,480 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09730000.
2026-04-18 21:59:40,480 [root] DEBUG: 4908: YaraScan: Scanning 0x09730000, size 0x20
2026-04-18 21:59:40,482 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070CB2B8 prior to its freeing.
2026-04-18 21:59:40,482 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09730000 from the end of the tracked region list.
2026-04-18 21:59:40,485 [root] DEBUG: 4908: FreeHandler: Address: 0x09620000.
2026-04-18 21:59:40,486 [root] DEBUG: 4908: DumpRegion: Dump at 0x09620000 skipped due to dump limit 10
2026-04-18 21:59:40,486 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09620000.
2026-04-18 21:59:40,487 [root] DEBUG: 4908: YaraScan: Scanning 0x09620000, size 0x20
2026-04-18 21:59:40,488 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,489 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09620000 from the end of the tracked region list.
2026-04-18 21:59:40,490 [root] DEBUG: 4908: FreeHandler: Address: 0x09610000.
2026-04-18 21:59:40,491 [root] DEBUG: 4908: DumpRegion: Dump at 0x09610000 skipped due to dump limit 10
2026-04-18 21:59:40,491 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09610000.
2026-04-18 21:59:40,492 [root] DEBUG: 4908: YaraScan: Scanning 0x09610000, size 0x20
2026-04-18 21:59:40,493 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07175B50 prior to its freeing.
2026-04-18 21:59:40,494 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09610000 from the end of the tracked region list.
2026-04-18 21:59:40,495 [root] DEBUG: 4908: FreeHandler: Address: 0x09600000.
2026-04-18 21:59:40,496 [root] DEBUG: 4908: DumpRegion: Dump at 0x09600000 skipped due to dump limit 10
2026-04-18 21:59:40,496 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x09600000.
2026-04-18 21:59:40,497 [root] DEBUG: 4908: YaraScan: Scanning 0x09600000, size 0x20
2026-04-18 21:59:40,498 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,499 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x09600000 from the end of the tracked region list.
2026-04-18 21:59:40,500 [root] DEBUG: 4908: FreeHandler: Address: 0x095F0000.
2026-04-18 21:59:40,501 [root] DEBUG: 4908: DumpRegion: Dump at 0x095F0000 skipped due to dump limit 10
2026-04-18 21:59:40,502 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095F0000.
2026-04-18 21:59:40,502 [root] DEBUG: 4908: YaraScan: Scanning 0x095F0000, size 0x20
2026-04-18 21:59:40,503 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0714E3D0 prior to its freeing.
2026-04-18 21:59:40,504 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x095F0000 from the end of the tracked region list.
2026-04-18 21:59:40,506 [root] DEBUG: 4908: FreeHandler: Address: 0x095E0000.
2026-04-18 21:59:40,506 [root] DEBUG: 4908: DumpRegion: Dump at 0x095E0000 skipped due to dump limit 10
2026-04-18 21:59:40,507 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095E0000.
2026-04-18 21:59:40,508 [root] DEBUG: 4908: YaraScan: Scanning 0x095E0000, size 0x20
2026-04-18 21:59:40,509 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,510 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x095E0000 from the end of the tracked region list.
2026-04-18 21:59:40,511 [root] DEBUG: 4908: FreeHandler: Address: 0x095D0000.
2026-04-18 21:59:40,512 [root] DEBUG: 4908: DumpRegion: Dump at 0x095D0000 skipped due to dump limit 10
2026-04-18 21:59:40,512 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095D0000.
2026-04-18 21:59:40,514 [root] DEBUG: 4908: YaraScan: Scanning 0x095D0000, size 0x20
2026-04-18 21:59:40,515 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x07169F58 prior to its freeing.
2026-04-18 21:59:40,516 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x095D0000 from the end of the tracked region list.
2026-04-18 21:59:40,519 [root] DEBUG: 4908: FreeHandler: Address: 0x095C0000.
2026-04-18 21:59:40,520 [root] DEBUG: 4908: DumpRegion: Dump at 0x095C0000 skipped due to dump limit 10
2026-04-18 21:59:40,521 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095C0000.
2026-04-18 21:59:40,522 [root] DEBUG: 4908: YaraScan: Scanning 0x095C0000, size 0x20
2026-04-18 21:59:40,523 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,523 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x095C0000 from the end of the tracked region list.
2026-04-18 21:59:40,569 [root] DEBUG: 4908: FreeHandler: Address: 0x095B0000.
2026-04-18 21:59:40,570 [root] DEBUG: 4908: DumpRegion: Dump at 0x095B0000 skipped due to dump limit 10
2026-04-18 21:59:40,571 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x095B0000.
2026-04-18 21:59:40,572 [root] DEBUG: 4908: YaraScan: Scanning 0x095B0000, size 0x20
2026-04-18 21:59:40,573 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,574 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x095B0000 from the end of the tracked region list.
2026-04-18 21:59:40,576 [root] DEBUG: 4908: FreeHandler: Address: 0x08DB0000.
2026-04-18 21:59:40,577 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DB0000 skipped due to dump limit 10
2026-04-18 21:59:40,577 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DB0000.
2026-04-18 21:59:40,578 [root] DEBUG: 4908: YaraScan: Scanning 0x08DB0000, size 0x20
2026-04-18 21:59:40,597 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,598 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08DB0000 from the end of the tracked region list.
2026-04-18 21:59:40,599 [root] DEBUG: 4908: FreeHandler: Address: 0x08DA0000.
2026-04-18 21:59:40,600 [root] DEBUG: 4908: DumpRegion: Dump at 0x08DA0000 skipped due to dump limit 10
2026-04-18 21:59:40,601 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08DA0000.
2026-04-18 21:59:40,601 [root] DEBUG: 4908: YaraScan: Scanning 0x08DA0000, size 0x20
2026-04-18 21:59:40,602 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x0714E180 prior to its freeing.
2026-04-18 21:59:40,604 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08DA0000 from the end of the tracked region list.
2026-04-18 21:59:40,606 [root] DEBUG: 4908: FreeHandler: Address: 0x08D90000.
2026-04-18 21:59:40,607 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D90000 skipped due to dump limit 10
2026-04-18 21:59:40,607 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D90000.
2026-04-18 21:59:40,608 [root] DEBUG: 4908: YaraScan: Scanning 0x08D90000, size 0x20
2026-04-18 21:59:40,609 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x070C0800 prior to its freeing.
2026-04-18 21:59:40,610 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D90000 from the end of the tracked region list.
2026-04-18 21:59:40,611 [root] DEBUG: 4908: FreeHandler: Address: 0x08D80000.
2026-04-18 21:59:40,612 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D80000 skipped due to dump limit 10
2026-04-18 21:59:40,612 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D80000.
2026-04-18 21:59:40,613 [root] DEBUG: 4908: YaraScan: Scanning 0x08D80000, size 0x20
2026-04-18 21:59:40,614 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,615 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D80000 from the end of the tracked region list.
2026-04-18 21:59:40,616 [root] DEBUG: 4908: FreeHandler: Address: 0x08D70000.
2026-04-18 21:59:40,617 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D70000 skipped due to dump limit 10
2026-04-18 21:59:40,618 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D70000.
2026-04-18 21:59:40,619 [root] DEBUG: 4908: YaraScan: Scanning 0x08D70000, size 0x20
2026-04-18 21:59:40,620 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,620 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D70000 from the end of the tracked region list.
2026-04-18 21:59:40,621 [root] DEBUG: 4908: FreeHandler: Address: 0x08D60000.
2026-04-18 21:59:40,622 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D60000 skipped due to dump limit 10
2026-04-18 21:59:40,623 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D60000.
2026-04-18 21:59:40,624 [root] DEBUG: 4908: YaraScan: Scanning 0x08D60000, size 0x20
2026-04-18 21:59:40,625 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,625 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D60000 from the end of the tracked region list.
2026-04-18 21:59:40,627 [root] DEBUG: 4908: FreeHandler: Address: 0x08D50000.
2026-04-18 21:59:40,627 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D50000 skipped due to dump limit 10
2026-04-18 21:59:40,628 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D50000.
2026-04-18 21:59:40,629 [root] DEBUG: 4908: YaraScan: Scanning 0x08D50000, size 0x20
2026-04-18 21:59:40,630 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,631 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D50000 from the end of the tracked region list.
2026-04-18 21:59:40,632 [root] DEBUG: 4908: FreeHandler: Address: 0x08D40000.
2026-04-18 21:59:40,633 [root] DEBUG: 4908: DumpRegion: Dump at 0x08D40000 skipped due to dump limit 10
2026-04-18 21:59:40,634 [root] DEBUG: 4908: ProcessTrackedRegion: Failed to dump region at 0x08D40000.
2026-04-18 21:59:40,634 [root] DEBUG: 4908: YaraScan: Scanning 0x08D40000, size 0x20
2026-04-18 21:59:40,635 [root] DEBUG: 4908: FreeHandler: failed to dump executable memory range at 0x00000000 prior to its freeing.
2026-04-18 21:59:40,636 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D40000 from the end of the tracked region list.
2026-04-18 21:59:40,637 [root] DEBUG: 4908: FreeHandler: Address: 0x08D30000.
2026-04-18 21:59:40,638 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D30000 from the end of the tracked region list.
2026-04-18 21:59:40,639 [root] DEBUG: 4908: FreeHandler: Address: 0x08D20000.
2026-04-18 21:59:40,640 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D20000 from the end of the tracked region list.
2026-04-18 21:59:40,641 [root] DEBUG: 4908: FreeHandler: Address: 0x08D10000.
2026-04-18 21:59:40,642 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D10000 from the end of the tracked region list.
2026-04-18 21:59:40,644 [root] DEBUG: 4908: FreeHandler: Address: 0x08D00000.
2026-04-18 21:59:40,644 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08D00000 from the end of the tracked region list.
2026-04-18 21:59:40,646 [root] DEBUG: 4908: FreeHandler: Address: 0x08CE0000.
2026-04-18 21:59:40,647 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08CE0000 from the end of the tracked region list.
2026-04-18 21:59:40,648 [root] DEBUG: 4908: FreeHandler: Address: 0x08CD0000.
2026-04-18 21:59:40,650 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08CD0000 from the end of the tracked region list.
2026-04-18 21:59:40,651 [root] DEBUG: 4908: FreeHandler: Address: 0x08CC0000.
2026-04-18 21:59:40,652 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x08CC0000 from the end of the tracked region list.
2026-04-18 21:59:40,701 [root] DEBUG: 4908: FreeHandler: Address: 0x04630000.
2026-04-18 21:59:40,702 [root] DEBUG: 4908: DropTrackedRegion: removed region at 0x04630000 from the end of the tracked region list.
2026-04-18 21:59:40,706 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-04-18 21:59:40,709 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-04-18 21:59:40,737 [root] DEBUG: 4908: DLL loaded at 0x72850000: C:\Windows\SYSTEM32\dxcore (0x2c000 bytes).
2026-04-18 21:59:40,752 [root] INFO: Added new file to list with pid None and path C:\Users\Admin\AppData\Roaming\AnyDesk\ad.trace
2026-04-18 21:59:40,762 [root] DEBUG: 4908: Dropped file limit reached.
2026-04-18 21:59:40,763 [root] DEBUG: 4908: NtTerminateProcess hook: Attempting to dump process 4908
2026-04-18 21:59:40,764 [root] DEBUG: 4908: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 21:59:40,772 [root] DEBUG: 4908: ReverseScanForNonZero: Error - Supplied size zero.
2026-04-18 21:59:40,773 [root] DEBUG: 4908: GetPageAddress: Error - Supplied address zero.
2026-04-18 21:59:40,778 [root] DEBUG: 4908: DLL loaded at 0x72380000: C:\Windows\SYSTEM32\netutils (0xb000 bytes).
2026-04-18 21:59:40,787 [root] INFO: Process with pid 4908 has terminated
2026-04-18 21:59:50,005 [root] DEBUG: 4560: DLL loaded at 0x72AB0000: C:\Windows\SYSTEM32\NETAPI32 (0x14000 bytes).
2026-04-18 21:59:50,006 [root] DEBUG: 4560: DLL loaded at 0x72AA0000: C:\Windows\SYSTEM32\NETUTILS (0xb000 bytes).
2026-04-18 21:59:50,016 [root] DEBUG: 4560: DLL loaded at 0x72A80000: C:\Windows\SYSTEM32\wkscli (0x11000 bytes).
2026-04-18 21:59:50,030 [root] DEBUG: 4560: DLL loaded at 0x72A60000: C:\Windows\SYSTEM32\srvcli (0x1d000 bytes).
2026-04-18 21:59:50,031 [root] DEBUG: 4712: FreeHandler: Address: 0x05920000.
2026-04-18 21:59:50,032 [root] DEBUG: 4712: DumpPEsInRange: Scanning range 0x05920000 - 0x05920020.
2026-04-18 21:59:50,033 [root] DEBUG: 4712: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:59:50,036 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4712_55132550591818642026 to CAPE\ec0648510d50b186865b2fc800332d8eea771ef9228b7abbde2b682bece992ac; Size is 32; Max size: 100000000
2026-04-18 21:59:50,039 [root] DEBUG: 4712: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4712_55132550591818642026 (size 32 bytes)
2026-04-18 21:59:50,040 [root] DEBUG: 4712: DumpRegion: Dumped entire allocation from 0x05920000, size 4096 bytes.
2026-04-18 21:59:50,041 [root] DEBUG: 4712: ProcessTrackedRegion: Dumped region at 0x05920000.
2026-04-18 21:59:50,042 [root] DEBUG: 4712: YaraScan: Scanning 0x05920000, size 0x20
2026-04-18 21:59:50,044 [root] DEBUG: 4712: FreeHandler: Dumped executable range containing 0x05920000.
2026-04-18 21:59:50,044 [root] DEBUG: 4712: DropTrackedRegion: removed region at 0x05920000 from tracked region list.
2026-04-18 21:59:50,047 [root] DEBUG: 4560: DLL loaded at 0x72030000: C:\Windows\SYSTEM32\CRYPTSP (0x13000 bytes).
2026-04-18 21:59:50,049 [root] DEBUG: 4560: DLL loaded at 0x72000000: C:\Windows\system32\rsaenh (0x2f000 bytes).
2026-04-18 21:59:50,089 [root] DEBUG: 4712: NtTerminateProcess hook: Attempting to dump process 4712
2026-04-18 21:59:50,091 [root] DEBUG: 4712: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 21:59:50,097 [root] DEBUG: 4712: CAPEExceptionFilter: Exception 0xc0000005 accessing 0x4310000 caught at RVA 0x3ae7 in capemon (expected in memory scans), passing to next handler.
2026-04-18 21:59:50,098 [root] DEBUG: 4712: GetEntropy: Exception occurred attempting to get PE entropy at 0x04310000
2026-04-18 21:59:50,099 [root] DEBUG: 4712: DumpPEsInRange: Scanning range 0x03F10000 - 0x03FC2FFF.
2026-04-18 21:59:50,105 [root] DEBUG: 4712: ScanForDisguisedPE: No PE image located in range 0x03F10000-0x03FC2FFF.
2026-04-18 21:59:50,117 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4712_52653650591818642026 to CAPE\35cce05ac46c47a657b9a932be741354578b6b65d9682f70570e482dc91d90d4; Size is 733183; Max size: 100000000
2026-04-18 21:59:50,128 [root] DEBUG: 4712: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4712_52653650591818642026 (size 733183 bytes)
2026-04-18 21:59:50,129 [root] DEBUG: 4712: DumpRegion: Dumped entire allocation from 0x03F10000, size -3414376 bytes.
2026-04-18 21:59:50,130 [root] DEBUG: 4712: ProcessTrackedRegion: Dumped region at 0x04304968.
2026-04-18 21:59:50,131 [root] DEBUG: 4712: YaraScan: Scanning 0x04304968, size 0xffcbe697
2026-04-18 21:59:50,132 [root] DEBUG: 4712: CAPEExceptionFilter: Exception 0xc0000005 accessing 0x4310000 caught at RVA 0x77003 in capemon (expected in memory scans), passing to next handler.
2026-04-18 21:59:50,138 [root] INFO: Process with pid 4712 has terminated
2026-04-18 21:59:50,733 [root] DEBUG: 4560: api-cap: NtAllocateVirtualMemory hook disabled due to count: 5000
2026-04-18 21:59:51,264 [root] DEBUG: 4560: caller_dispatch: Added region at 0x063C0000 to tracked regions list (user32::ChangeWindowMessageFilter returns to 0x06493580, thread 4552).
2026-04-18 21:59:51,265 [root] DEBUG: 4560: DumpPEsInRange: Scanning range 0x063C0000 - 0x063F7FFF.
2026-04-18 21:59:51,268 [root] DEBUG: 4560: ScanForDisguisedPE: No PE image located in range 0x063C0000-0x063F7FFF.
2026-04-18 21:59:51,275 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4560_650569851591818642026 to CAPE\1919e891a20dc7cc0e5f541c7bc06041001965bf0e14c366cf576b5efffb4f75; Size is 229375; Max size: 100000000
2026-04-18 21:59:51,293 [root] DEBUG: 4560: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4560_650569851591818642026 (size 229375 bytes)
2026-04-18 21:59:51,295 [root] DEBUG: 4560: DumpRegion: Dumped entire allocation from 0x063C0000, size 229376 bytes.
2026-04-18 21:59:51,297 [root] DEBUG: 4560: ProcessTrackedRegion: Dumped region at 0x063C0000.
2026-04-18 21:59:51,298 [root] DEBUG: 4560: YaraScan: Scanning 0x063C0000, size 0x37fff
2026-04-18 21:59:51,356 [root] DEBUG: 4560: FreeHandler: Address: 0x05FF0000.
2026-04-18 21:59:51,358 [root] DEBUG: 4560: DumpPEsInRange: Scanning range 0x05FF0000 - 0x05FF0020.
2026-04-18 21:59:51,360 [root] DEBUG: 4560: ScanForDisguisedPE: Size too small: 0x20 bytes
2026-04-18 21:59:51,365 [lib.common.results] INFO: Uploading file C:\PiogNHme\CAPE\4560_336679251591818642026 to CAPE\1d05dc15b6c009b2351b93917f044b349ecb1f40becfbd39454bc04720fd1aad; Size is 32; Max size: 100000000
2026-04-18 21:59:51,438 [root] DEBUG: 4560: DumpMemory: Payload successfully created: C:\PiogNHme\CAPE\4560_336679251591818642026 (size 32 bytes)
2026-04-18 21:59:51,440 [root] DEBUG: 4560: DumpRegion: Dumped entire allocation from 0x05FF0000, size 4096 bytes.
2026-04-18 21:59:51,442 [root] DEBUG: 4560: ProcessTrackedRegion: Dumped region at 0x05FF0000.
2026-04-18 21:59:51,443 [root] DEBUG: 4560: YaraScan: Scanning 0x05FF0000, size 0x20
2026-04-18 21:59:51,468 [root] DEBUG: 4560: FreeHandler: Dumped executable range containing 0x05FF0000.
2026-04-18 21:59:51,470 [root] DEBUG: 4560: DropTrackedRegion: removed region at 0x05FF0000 from tracked region list.
2026-04-18 21:59:51,472 [root] DEBUG: 4560: FreeHandler: Address: 0x045F0000.
2026-04-18 21:59:51,473 [root] DEBUG: 4560: DropTrackedRegion: removed region at 0x045F0000 from tracked region list.
2026-04-18 21:59:51,474 [root] DEBUG: 4560: FreeHandler: Address: 0x045E0000.
2026-04-18 21:59:51,475 [root] DEBUG: 4560: DropTrackedRegion: removed region at 0x045E0000 from tracked region list.
2026-04-18 21:59:51,647 [root] DEBUG: 4560: FreeHandler: Address: 0x04440000.
2026-04-18 21:59:51,648 [root] DEBUG: 4560: DropTrackedRegion: removed region at 0x04440000 from tracked region list.
2026-04-18 21:59:51,663 [root] DEBUG: 4560: FreeHandler: Address: 0x063C0000.
2026-04-18 21:59:51,664 [root] DEBUG: 4560: DropTrackedRegion: removed region at 0x063C0000 from the end of the tracked region list.
2026-04-18 21:59:51,672 [root] DEBUG: 4560: NtTerminateProcess hook: Attempting to dump process 4560
2026-04-18 21:59:51,673 [root] DEBUG: 4560: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 21:59:51,679 [root] DEBUG: 4560: ReverseScanForNonZero: Error - Supplied size zero.
2026-04-18 21:59:51,688 [root] INFO: Process with pid 4560 has terminated
2026-04-18 22:01:00,182 [root] INFO: Announced starting service "b'WSearch'"
2026-04-18 22:01:00,183 [lib.api.process] INFO: Monitor config for <Process 600 services.exe>: C:\wry749yf\dll\600.ini
2026-04-18 22:01:00,193 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:00,205 [root] DEBUG: Loader: Injecting process 600 with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:00,208 [root] DEBUG: Loader: Copied config file C:\wry749yf\dll\600.ini to system path C:\600.ini
2026-04-18 22:01:00,215 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 600 C:\wry749yf\dll\zsCiBd.dll
2026-04-18 22:01:00,216 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:00,220 [lib.api.process] INFO: Injected into 64-bit <Process 600 services.exe>
2026-04-18 22:01:03,306 [root] INFO: Process with pid 2552 appears to have terminated
2026-04-18 22:01:03,506 [root] INFO: Announced starting service "b'WSearch'"
2026-04-18 22:01:03,818 [root] INFO: Announced starting service "b'TrustedInstaller'"
2026-04-18 22:01:04,446 [root] DEBUG: 268: CreateProcessHandler: Injection info set for new process 12152: C:\Windows\system32\taskhostw.exe, ImageBase: 0x00007FF7133E0000
2026-04-18 22:01:04,448 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 12152
2026-04-18 22:01:04,449 [lib.api.process] INFO: Monitor config for <Process 12152 taskhostw.exe>: C:\wry749yf\dll\12152.ini
2026-04-18 22:01:04,458 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:04,471 [root] DEBUG: Loader: Injecting process 12152 (thread 1436) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,472 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:04,473 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,476 [lib.api.process] INFO: Injected into 64-bit <Process 12152 taskhostw.exe>
2026-04-18 22:01:04,479 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 12152
2026-04-18 22:01:04,480 [lib.api.process] INFO: Monitor config for <Process 12152 taskhostw.exe>: C:\wry749yf\dll\12152.ini
2026-04-18 22:01:04,487 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:04,498 [root] DEBUG: Loader: Injecting process 12152 (thread 1436) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,500 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:04,501 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,505 [lib.api.process] INFO: Injected into 64-bit <Process 12152 taskhostw.exe>
2026-04-18 22:01:04,507 [root] INFO: Announced 64-bit process name: taskhostw.exe pid: 12152
2026-04-18 22:01:04,508 [lib.api.process] INFO: Monitor config for <Process 12152 taskhostw.exe>: C:\wry749yf\dll\12152.ini
2026-04-18 22:01:04,515 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:04,527 [root] DEBUG: Loader: Injecting process 12152 (thread 1436) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,529 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-04-18 22:01:04,530 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,533 [lib.api.process] INFO: Injected into 64-bit <Process 12152 taskhostw.exe>
2026-04-18 22:01:04,547 [root] DEBUG: 12152: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 22:01:04,548 [root] DEBUG: 12152: Dropped file limit defaulting to 100.
2026-04-18 22:01:04,555 [root] DEBUG: 12152: Disabling sleep skipping.
2026-04-18 22:01:04,558 [root] DEBUG: 12152: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 22:01:04,585 [root] DEBUG: 12152: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0
2026-04-18 22:01:04,587 [root] DEBUG: 12152: YaraScan: Scanning 0x00007FF7133E0000, size 0x192fc
2026-04-18 22:01:04,590 [root] DEBUG: 12152: Monitor initialised: 64-bit capemon loaded in process 12152 at 0x00007FFEB6B40000, thread 1436, image base 0x00007FF7133E0000, stack from 0x0000003F8D5B5000-0x0000003F8D5C0000
2026-04-18 22:01:04,591 [root] DEBUG: 12152: Commandline: taskhostw.exe
2026-04-18 22:01:04,604 [root] DEBUG: 12152: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress
2026-04-18 22:01:04,663 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-18 22:01:04,664 [root] DEBUG: 12152: set_hooks: Unable to hook LockResource
2026-04-18 22:01:04,676 [root] DEBUG: 12152: Hooked 619 out of 620 functions
2026-04-18 22:01:04,679 [root] DEBUG: 12152: Syscall hook installed, syscall logging level 1
2026-04-18 22:01:04,687 [root] DEBUG: 12152: RestoreHeaders: Restored original import table.
2026-04-18 22:01:04,688 [root] INFO: Loaded monitor into process with pid 12152
2026-04-18 22:01:04,691 [root] DEBUG: 12152: caller_dispatch: Added region at 0x00007FF7133E0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7133E5CA1, thread 1436).
2026-04-18 22:01:04,692 [root] DEBUG: 12152: YaraScan: Scanning 0x00007FF7133E0000, size 0x192fc
2026-04-18 22:01:04,696 [root] DEBUG: 12152: ProcessImageBase: Main module image at 0x00007FF7133E0000 unmodified (entropy change 0.000000e+00)
2026-04-18 22:01:04,698 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE1DA0000: C:\Windows\System32\imm32 (0x30000 bytes).
2026-04-18 22:01:04,707 [root] DEBUG: 12152: set_hooks_by_export_directory: Hooked 0 out of 620 functions
2026-04-18 22:01:04,708 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDEA70000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-04-18 22:01:04,710 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE1390000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-04-18 22:01:04,730 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 3140: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe, ImageBase: 0x00007FF7A10E0000
2026-04-18 22:01:04,733 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 3596: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe, ImageBase: 0x00007FF60B440000
2026-04-18 22:01:04,736 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 3140
2026-04-18 22:01:04,738 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 3596
2026-04-18 22:01:04,739 [lib.api.process] INFO: Monitor config for <Process 3140 StartMenuExperienceHost.exe>: C:\wry749yf\dll\3140.ini
2026-04-18 22:01:04,739 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE2C20000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-04-18 22:01:04,740 [lib.api.process] INFO: Monitor config for <Process 3596 TextInputHost.exe>: C:\wry749yf\dll\3596.ini
2026-04-18 22:01:04,768 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE2330000: C:\Windows\System32\shell32 (0x745000 bytes).
2026-04-18 22:01:04,784 [root] DEBUG: 12152: DLL loaded at 0x00007FFED9790000: C:\Windows\System32\TaskSchdPS (0x12000 bytes).
2026-04-18 22:01:04,794 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 2656: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6F8170000
2026-04-18 22:01:04,796 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2656
2026-04-18 22:01:04,798 [lib.api.process] INFO: Monitor config for <Process 2656 dllhost.exe>: C:\wry749yf\dll\2656.ini
2026-04-18 22:01:04,809 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:04,822 [root] DEBUG: Loader: Injecting process 2656 (thread 2744) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,824 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:04,825 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,829 [lib.api.process] INFO: Injected into 64-bit <Process 2656 dllhost.exe>
2026-04-18 22:01:04,832 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 2656
2026-04-18 22:01:04,834 [lib.api.process] INFO: Monitor config for <Process 2656 dllhost.exe>: C:\wry749yf\dll\2656.ini
2026-04-18 22:01:04,844 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:04,860 [root] DEBUG: Loader: Injecting process 2656 (thread 2744) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,863 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:04,865 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:04,866 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 3776: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe, ImageBase: 0x00007FF7A8A50000
2026-04-18 22:01:04,868 [root] INFO: Announced 64-bit process name: TiWorker.exe pid: 3776
2026-04-18 22:01:04,869 [lib.api.process] INFO: Injected into 64-bit <Process 2656 dllhost.exe>
2026-04-18 22:01:04,871 [lib.api.process] INFO: Monitor config for <Process 3776 TiWorker.exe>: C:\wry749yf\dll\3776.ini
2026-04-18 22:01:04,886 [root] DEBUG: 2656: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 22:01:04,891 [root] DEBUG: 2656: Dropped file limit defaulting to 100.
2026-04-18 22:01:04,898 [root] DEBUG: 2656: Disabling sleep skipping.
2026-04-18 22:01:04,901 [root] DEBUG: 2656: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 22:01:04,929 [root] DEBUG: 2656: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0
2026-04-18 22:01:04,931 [root] DEBUG: 2656: YaraScan: Scanning 0x00007FF6F8170000, size 0x8026
2026-04-18 22:01:04,934 [root] DEBUG: 2656: Monitor initialised: 64-bit capemon loaded in process 2656 at 0x00007FFEB6B40000, thread 2744, image base 0x00007FF6F8170000, stack from 0x0000000F9D3B5000-0x0000000F9D3C0000
2026-04-18 22:01:04,935 [root] DEBUG: 2656: Commandline: C:\Windows\system32\DllHost.exe /Processid:{133EAC4F-5891-4D04-BADA-D84870380A80}
2026-04-18 22:01:04,949 [root] DEBUG: 2656: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress
2026-04-18 22:01:05,001 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-18 22:01:05,003 [root] DEBUG: 2656: set_hooks: Unable to hook LockResource
2026-04-18 22:01:05,018 [root] DEBUG: 2656: Hooked 619 out of 620 functions
2026-04-18 22:01:05,021 [root] DEBUG: 2656: Syscall hook installed, syscall logging level 1
2026-04-18 22:01:05,030 [root] DEBUG: 2656: RestoreHeaders: Restored original import table.
2026-04-18 22:01:05,032 [root] INFO: Loaded monitor into process with pid 2656
2026-04-18 22:01:05,035 [root] DEBUG: 2656: caller_dispatch: Added region at 0x00007FF6F8170000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F81712F2, thread 2744).
2026-04-18 22:01:05,037 [root] DEBUG: 2656: YaraScan: Scanning 0x00007FF6F8170000, size 0x8026
2026-04-18 22:01:05,041 [root] DEBUG: 2656: ProcessImageBase: Main module image at 0x00007FF6F8170000 unmodified (entropy change 0.000000e+00)
2026-04-18 22:01:05,048 [root] DEBUG: 2656: set_hooks_by_export_directory: Hooked 0 out of 620 functions
2026-04-18 22:01:05,050 [root] DEBUG: 2656: DLL loaded at 0x00007FFEDEA70000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-04-18 22:01:05,053 [root] DEBUG: 2656: DLL loaded at 0x00007FFEE1390000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-04-18 22:01:05,060 [root] DEBUG: 2656: DLL loaded at 0x00007FFEE2C20000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-04-18 22:01:05,171 [root] DEBUG: 2656: DLL loaded at 0x00007FFEE2330000: C:\Windows\System32\shell32 (0x745000 bytes).
2026-04-18 22:01:05,193 [root] DEBUG: 2656: DLL loaded at 0x00007FFED9790000: C:\Windows\System32\TaskSchdPS (0x12000 bytes).
2026-04-18 22:01:05,220 [root] DEBUG: 2656: DLL loaded at 0x00007FFEDC720000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-04-18 22:01:05,239 [root] DEBUG: 2656: DLL loaded at 0x00007FFEE1880000: C:\Windows\System32\shcore (0xad000 bytes).
2026-04-18 22:01:05,242 [root] DEBUG: 2656: DLL loaded at 0x00007FFEE0AC0000: C:\Windows\system32\profapi (0x25000 bytes).
2026-04-18 22:01:05,243 [root] DEBUG: 2656: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:05,245 [root] DEBUG: 2656: DLL loaded at 0x00007FFED7060000: C:\Windows\system32\windows.ui.immersive (0x139000 bytes).
2026-04-18 22:01:05,260 [root] DEBUG: 2656: DLL loaded at 0x00007FFED4F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-04-18 22:01:06,775 [lib.api.process] INFO: Potential dll side-loading detected in local directory: wdscore.dll
2026-04-18 22:01:06,776 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:06,776 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msdelta.dll
2026-04-18 22:01:06,777 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:06,778 [lib.api.process] INFO: Potential dll side-loading detected in local directory: dpx.dll
2026-04-18 22:01:06,779 [lib.api.process] INFO: Potential dll side-loading detected in local directory: drvstore.dll
2026-04-18 22:01:06,780 [lib.api.process] INFO: Potential dll side-loading detected in local directory: mspatcha.dll
2026-04-18 22:01:06,790 [root] DEBUG: Loader: Injecting process 3140 (thread 12280) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:06,792 [root] DEBUG: Loader: Injecting process 3596 (thread 11548) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:06,794 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:06,795 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:06,797 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:06,798 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:06,801 [lib.api.process] INFO: Injected into 64-bit <Process 3140 StartMenuExperienceHost.exe>
2026-04-18 22:01:06,802 [lib.api.process] INFO: Injected into 64-bit <Process 3596 TextInputHost.exe>
2026-04-18 22:01:06,803 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:06,805 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 3140
2026-04-18 22:01:06,806 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 3596
2026-04-18 22:01:06,808 [lib.api.process] INFO: Monitor config for <Process 3596 TextInputHost.exe>: C:\wry749yf\dll\3596.ini
2026-04-18 22:01:06,808 [lib.api.process] INFO: Monitor config for <Process 3140 StartMenuExperienceHost.exe>: C:\wry749yf\dll\3140.ini
2026-04-18 22:01:06,815 [root] DEBUG: Loader: Injecting process 3776 (thread 2576) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:06,817 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:06,818 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:06,822 [lib.api.process] INFO: Injected into 64-bit <Process 3776 TiWorker.exe>
2026-04-18 22:01:06,825 [root] INFO: Announced 64-bit process name: TiWorker.exe pid: 3776
2026-04-18 22:01:06,826 [lib.api.process] INFO: Monitor config for <Process 3776 TiWorker.exe>: C:\wry749yf\dll\3776.ini
2026-04-18 22:01:08,105 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:08,110 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:08,114 [lib.api.process] INFO: Potential dll side-loading detected in local directory: wdscore.dll
2026-04-18 22:01:08,114 [lib.api.process] INFO: Potential dll side-loading detected in local directory: msdelta.dll
2026-04-18 22:01:08,115 [lib.api.process] INFO: Potential dll side-loading detected in local directory: dpx.dll
2026-04-18 22:01:08,115 [lib.api.process] INFO: Potential dll side-loading detected in local directory: drvstore.dll
2026-04-18 22:01:08,115 [lib.api.process] INFO: Potential dll side-loading detected in local directory: mspatcha.dll
2026-04-18 22:01:08,118 [root] DEBUG: Loader: Injecting process 3140 (thread 12280) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:08,119 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:08,120 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:08,122 [root] DEBUG: Loader: Injecting process 3596 (thread 11548) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:08,123 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:08,124 [lib.api.process] INFO: Injected into 64-bit <Process 3140 StartMenuExperienceHost.exe>
2026-04-18 22:01:08,125 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:08,128 [root] INFO: Announced 64-bit process name: StartMenuExperienceHost.exe pid: 3140
2026-04-18 22:01:08,129 [lib.api.process] INFO: Injected into 64-bit <Process 3596 TextInputHost.exe>
2026-04-18 22:01:08,130 [lib.api.process] INFO: Monitor config for <Process 3140 StartMenuExperienceHost.exe>: C:\wry749yf\dll\3140.ini
2026-04-18 22:01:08,132 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:08,132 [root] INFO: Announced 64-bit process name: TextInputHost.exe pid: 3596
2026-04-18 22:01:08,133 [lib.api.process] INFO: Monitor config for <Process 3596 TextInputHost.exe>: C:\wry749yf\dll\3596.ini
2026-04-18 22:01:08,142 [root] DEBUG: Loader: Injecting process 3776 (thread 2576) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:08,144 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:08,145 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:08,148 [lib.api.process] INFO: Injected into 64-bit <Process 3776 TiWorker.exe>
2026-04-18 22:01:08,161 [root] DEBUG: 3776: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 22:01:08,163 [root] DEBUG: 3776: Dropped file limit defaulting to 100.
2026-04-18 22:01:08,169 [root] DEBUG: 3776: Disabling sleep skipping.
2026-04-18 22:01:08,172 [root] DEBUG: 3776: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 22:01:08,196 [root] DEBUG: 3776: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0
2026-04-18 22:01:08,197 [root] DEBUG: 3776: YaraScan: Scanning 0x00007FF7A8A50000, size 0x43128
2026-04-18 22:01:08,206 [root] DEBUG: 3776: Monitor initialised: 64-bit capemon loaded in process 3776 at 0x00007FFEB6B40000, thread 2576, image base 0x00007FF7A8A50000, stack from 0x00000031B2495000-0x00000031B24A0000
2026-04-18 22:01:08,208 [root] DEBUG: 3776: Commandline: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\TiWorker.exe -Embedding
2026-04-18 22:01:08,224 [root] DEBUG: 3776: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress
2026-04-18 22:01:08,277 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-18 22:01:08,279 [root] DEBUG: 3776: set_hooks: Unable to hook LockResource
2026-04-18 22:01:08,292 [root] DEBUG: 3776: Hooked 619 out of 620 functions
2026-04-18 22:01:08,297 [root] DEBUG: 3776: Syscall hook installed, syscall logging level 1
2026-04-18 22:01:08,305 [root] DEBUG: 3776: RestoreHeaders: Restored original import table.
2026-04-18 22:01:08,307 [root] INFO: Loaded monitor into process with pid 3776
2026-04-18 22:01:08,310 [root] DEBUG: 3776: caller_dispatch: Added region at 0x00007FF7A8A50000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7A8A6D4C2, thread 2576).
2026-04-18 22:01:08,314 [root] DEBUG: 3776: YaraScan: Scanning 0x00007FF7A8A50000, size 0x43128
2026-04-18 22:01:08,321 [root] DEBUG: 3776: ProcessImageBase: Main module image at 0x00007FF7A8A50000 unmodified (entropy change 0.000000e+00)
2026-04-18 22:01:08,324 [root] DEBUG: 3776: DLL loaded at 0x00007FFED84A0000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\wdscore (0x43000 bytes).
2026-04-18 22:01:08,332 [root] DEBUG: 3776: DLL loaded at 0x00007FFED2990000: C:\Windows\system32\dbghelp (0x1e4000 bytes).
2026-04-18 22:01:08,335 [root] DEBUG: 3776: DLL loaded at 0x00007FFED2920000: C:\Windows\SYSTEM32\dbgcore (0x34000 bytes).
2026-04-18 22:01:08,350 [root] DEBUG: 3776: set_hooks_by_export_directory: Hooked 0 out of 620 functions
2026-04-18 22:01:08,352 [root] DEBUG: 3776: DLL loaded at 0x00007FFEDEA70000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-04-18 22:01:08,354 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE1390000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-04-18 22:01:08,364 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE2C20000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-04-18 22:01:08,435 [root] DEBUG: 3776: DLL loaded at 0x00007FFED9480000: C:\Windows\servicing\CbsApi (0x12000 bytes).
2026-04-18 22:01:08,445 [root] DEBUG: 3776: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:08,451 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE0450000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-04-18 22:01:08,452 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE0A80000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2026-04-18 22:01:08,455 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE1470000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-04-18 22:01:08,457 [root] DEBUG: 3776: DLL loaded at 0x00007FFED8200000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\cbscore (0x295000 bytes).
2026-04-18 22:01:08,459 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE0690000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-04-18 22:01:08,484 [root] DEBUG: 3776: DLL loaded at 0x00007FFED8140000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\dpx (0xb9000 bytes).
2026-04-18 22:01:08,489 [root] DEBUG: 3776: DLL loaded at 0x00007FFED7D80000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\wcp (0x3be000 bytes).
2026-04-18 22:01:08,499 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE1420000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2026-04-18 22:01:08,500 [root] DEBUG: 3776: DLL loaded at 0x00007FFED7D10000: C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3745_none_7ded3f327ca60a41\DrUpdate (0x61000 bytes).
2026-04-18 22:01:08,506 [root] DEBUG: 3776: DLL loaded at 0x00007FFEC9D30000: C:\Windows\SYSTEM32\VssTrace (0x18000 bytes).
2026-04-18 22:01:08,508 [root] DEBUG: 3776: DLL loaded at 0x00007FFEC9D50000: C:\Windows\SYSTEM32\VSSAPI (0x19e000 bytes).
2026-04-18 22:01:08,509 [root] DEBUG: 3776: DLL loaded at 0x00007FFED7CA0000: C:\Windows\SYSTEM32\SPP (0x4b000 bytes).
2026-04-18 22:01:08,510 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE09F0000: C:\Windows\SYSTEM32\POWRPROF (0x4b000 bytes).
2026-04-18 22:01:08,511 [root] DEBUG: 3776: DLL loaded at 0x00007FFED7CF0000: C:\Windows\SYSTEM32\SrClient (0x17000 bytes).
2026-04-18 22:01:08,515 [root] DEBUG: 3776: DLL loaded at 0x00007FFEE09D0000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-04-18 22:01:08,527 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ᅫ↑¢¢■○ ¬ ¦○¥.
2026-04-18 22:01:08,528 [root] DEBUG: 3776: OpenProcessHandler: Injection info created for process 2556, handle 0x30c: Error obtaining target process name
2026-04-18 22:01:09,208 [root] DEBUG: 268: DLL loaded at 0x00007FFED7C70000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-04-18 22:01:09,217 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 560: C:\Windows\System32\mousocoreworker.exe, ImageBase: 0x00007FF7F40C0000
2026-04-18 22:01:09,219 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 560
2026-04-18 22:01:09,220 [lib.api.process] INFO: Monitor config for <Process 560 MoUsoCoreWorker.exe>: C:\wry749yf\dll\560.ini
2026-04-18 22:01:09,235 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:09,248 [root] DEBUG: Loader: Injecting process 560 (thread 2648) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:09,250 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:09,252 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:09,255 [lib.api.process] INFO: Injected into 64-bit <Process 560 MoUsoCoreWorker.exe>
2026-04-18 22:01:09,258 [root] INFO: Announced 64-bit process name: MoUsoCoreWorker.exe pid: 560
2026-04-18 22:01:09,259 [lib.api.process] INFO: Monitor config for <Process 560 MoUsoCoreWorker.exe>: C:\wry749yf\dll\560.ini
2026-04-18 22:01:09,272 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:09,278 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:09,287 [root] DEBUG: Loader: Injecting process 560 (thread 2648) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:09,288 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-04-18 22:01:09,290 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:09,291 [root] DEBUG: Loader: Injecting process 3140 (thread 12280) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:09,292 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-04-18 22:01:09,293 [lib.api.process] INFO: Injected into 64-bit <Process 560 MoUsoCoreWorker.exe>
2026-04-18 22:01:09,294 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:09,302 [lib.api.process] INFO: Injected into 64-bit <Process 3140 StartMenuExperienceHost.exe>
2026-04-18 22:01:09,311 [root] DEBUG: 560: Python path set to 'C:\Users\Admin\AppData\Local\Programs\Python\Python313-32'.
2026-04-18 22:01:09,312 [root] DEBUG: 560: Dropped file limit defaulting to 100.
2026-04-18 22:01:09,319 [root] DEBUG: 560: VerifyCodeSection: Exception rebasing image from 0x00007FF7F40C0000 to 0x0000000140000000.
2026-04-18 22:01:09,328 [root] DEBUG: 560: Disabling sleep skipping.
2026-04-18 22:01:09,330 [root] DEBUG: 560: YaraInit: Compiled rules loaded from existing file C:\wry749yf\data\yara\capemon.yac
2026-04-18 22:01:09,359 [root] DEBUG: 560: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0
2026-04-18 22:01:09,361 [root] DEBUG: 560: YaraScan: Scanning 0x00007FF7F40C0000, size 0x1ad000
2026-04-18 22:01:09,371 [lib.api.process] INFO: 64-bit DLL to inject is C:\wry749yf\dll\zsCiBd.dll, loader C:\wry749yf\bin\RnqswnIX.exe
2026-04-18 22:01:09,385 [root] DEBUG: 560: Monitor initialised: 64-bit capemon loaded in process 560 at 0x00007FFEB6B40000, thread 2648, image base 0x00007FF7F40C0000, stack from 0x0000008FD0335000-0x0000008FD0340000
2026-04-18 22:01:09,387 [root] DEBUG: 560: Commandline: C:\Windows\System32\mousocoreworker.exe -Embedding
2026-04-18 22:01:09,388 [root] DEBUG: Loader: Injecting process 3596 (thread 11548) with C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:09,390 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-04-18 22:01:09,392 [root] DEBUG: Successfully injected DLL C:\wry749yf\dll\zsCiBd.dll.
2026-04-18 22:01:09,399 [lib.api.process] INFO: Injected into 64-bit <Process 3596 TextInputHost.exe>
2026-04-18 22:01:09,401 [root] DEBUG: 560: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress
2026-04-18 22:01:09,486 [root] WARNING: b'Unable to place hook on LockResource'
2026-04-18 22:01:09,491 [root] DEBUG: 560: set_hooks: Unable to hook LockResource
2026-04-18 22:01:09,524 [root] DEBUG: 560: Hooked 619 out of 620 functions
2026-04-18 22:01:09,530 [root] DEBUG: 268: DLL loaded at 0x00007FFED32D0000: C:\Windows\System32\Windows.StateRepositoryPS (0x146000 bytes).
2026-04-18 22:01:09,548 [root] DEBUG: 560: Syscall hook installed, syscall logging level 1
2026-04-18 22:01:09,563 [root] DEBUG: 560: RestoreHeaders: Restored original import table.
2026-04-18 22:01:09,565 [root] INFO: Loaded monitor into process with pid 560
2026-04-18 22:01:09,580 [root] DEBUG: 560: caller_dispatch: Added region at 0x00007FF7F40C0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF7F41DF712, thread 2648).
2026-04-18 22:01:09,582 [root] DEBUG: 560: YaraScan: Scanning 0x00007FF7F40C0000, size 0x1ad000
2026-04-18 22:01:09,608 [root] DEBUG: 560: ProcessImageBase: Main module image at 0x00007FF7F40C0000 unmodified (entropy change 0.000000e+00)
2026-04-18 22:01:09,615 [root] DEBUG: 560: set_hooks_by_export_directory: Hooked 0 out of 620 functions
2026-04-18 22:01:09,616 [root] DEBUG: 560: DLL loaded at 0x00007FFEDEA70000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-04-18 22:01:09,618 [root] DEBUG: 560: DLL loaded at 0x00007FFEE1390000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-04-18 22:01:09,652 [root] DEBUG: 560: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-04-18 22:01:09,683 [root] DEBUG: 560: DLL loaded at 0x00007FFEE2C20000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-04-18 22:01:09,721 [root] DEBUG: 560: DLL loaded at 0x00007FFED9780000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-04-18 22:01:09,726 [root] DEBUG: 268: DLL loaded at 0x00007FFED9780000: C:\Windows\System32\usocoreps (0xd000 bytes).
2026-04-18 22:01:09,789 [root] DEBUG: 560: DLL loaded at 0x00007FFED8A20000: C:\Windows\System32\WINHTTP (0x10a000 bytes).
2026-04-18 22:01:09,791 [root] DEBUG: 560: DLL loaded at 0x00007FFEE08B0000: C:\Windows\System32\DPAPI (0xa000 bytes).
2026-04-18 22:01:09,792 [root] DEBUG: 560: DLL loaded at 0x00007FFEC9B10000: C:\Windows\System32\UPShared (0xb2000 bytes).
2026-04-18 22:01:09,814 [root] DEBUG: 560: DLL loaded at 0x00007FFECCD00000: C:\Windows\System32\wuapi (0xf0000 bytes).
2026-04-18 22:01:09,819 [root] DEBUG: 560: DLL loaded at 0x00007FFED7510000: C:\Windows\SYSTEM32\wups (0x1a000 bytes).
2026-04-18 22:01:09,825 [root] DEBUG: 560: DLL loaded at 0x00007FFEDC880000: C:\Windows\SYSTEM32\wtsapi32 (0x14000 bytes).
2026-04-18 22:01:09,830 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0970000: C:\Windows\System32\WINSTA (0x5b000 bytes).
2026-04-18 22:01:09,884 [root] DEBUG: 560: DLL loaded at 0x00007FFEDFC20000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-04-18 22:01:09,886 [root] DEBUG: 560: DLL loaded at 0x00007FFEDB030000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-04-18 22:01:09,910 [root] DEBUG: 560: DLL loaded at 0x00007FFED7C70000: C:\Windows\System32\usoapi (0x26000 bytes).
2026-04-18 22:01:09,913 [root] DEBUG: 560: DLL loaded at 0x00007FFEC97F0000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-04-18 22:01:09,922 [root] DEBUG: 560: DLL loaded at 0x00007FFED7200000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-04-18 22:01:09,925 [root] DEBUG: 560: DLL loaded at 0x00007FFECBA50000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-04-18 22:01:09,937 [root] DEBUG: 560: DLL loaded at 0x00007FFED5EB0000: C:\Windows\System32\wosc (0x4e000 bytes).
2026-04-18 22:01:09,944 [root] DEBUG: 560: DLL loaded at 0x00007FFECFD80000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-04-18 22:01:09,956 [root] DEBUG: 560: DLL loaded at 0x00007FFED74C0000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-04-18 22:01:09,972 [root] DEBUG: 560: DLL loaded at 0x00007FFEDC8A0000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-04-18 22:01:09,977 [root] DEBUG: 560: DLL loaded at 0x00007FFEE2110000: C:\Windows\System32\NSI (0x8000 bytes).
2026-04-18 22:01:09,987 [root] DEBUG: 560: DLL loaded at 0x00007FFED7510000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-04-18 22:01:10,115 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0070000: C:\Windows\System32\logoncli (0x43000 bytes).
2026-04-18 22:01:10,117 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0060000: C:\Windows\System32\netutils (0xc000 bytes).
2026-04-18 22:01:10,118 [root] DEBUG: 560: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:10,120 [root] DEBUG: 560: DLL loaded at 0x00007FFED4CB0000: C:\Windows\System32\dcntel (0xbf000 bytes).
2026-04-18 22:01:10,137 [root] DEBUG: 560: DLL loaded at 0x00007FFED74F0000: C:\Windows\System32\utcutil (0x1f000 bytes).
2026-04-18 22:01:10,188 [root] DEBUG: 560: DLL loaded at 0x00007FFEDF6A0000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-04-18 22:01:10,190 [root] DEBUG: 560: DLL loaded at 0x00007FFEDF6D0000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-04-18 22:01:10,613 [root] DEBUG: 560: api-rate-cap: ReadProcessMemory hook disabled due to rate
2026-04-18 22:01:10,908 [root] DEBUG: 560: DLL loaded at 0x00007FFED5E60000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-04-18 22:01:10,910 [root] DEBUG: 560: DLL loaded at 0x00007FFEDCA00000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-04-18 22:01:10,961 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0870000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-04-18 22:01:10,963 [root] DEBUG: 560: DLL loaded at 0x00007FFECC980000: C:\Windows\SYSTEM32\dmEnrollEngine (0xdf000 bytes).
2026-04-18 22:01:10,965 [root] DEBUG: 560: DLL loaded at 0x00007FFED5760000: C:\Windows\SYSTEM32\enrollmentapi (0x11000 bytes).
2026-04-18 22:01:11,025 [root] DEBUG: 560: DLL loaded at 0x00007FFED4D30000: C:\Windows\System32\OneSettingsClient (0x32000 bytes).
2026-04-18 22:01:11,040 [root] DEBUG: 560: DLL loaded at 0x00007FFEDB350000: C:\Windows\system32\OnDemandConnRouteHelper (0x17000 bytes).
2026-04-18 22:01:11,045 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0260000: C:\Windows\system32\mswsock (0x6a000 bytes).
2026-04-18 22:01:11,050 [root] DEBUG: 560: DLL loaded at 0x00007FFEDAE00000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2026-04-18 22:01:11,056 [root] DEBUG: 560: DLL loaded at 0x00007FFEDADE0000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2026-04-18 22:01:11,059 [root] DEBUG: 560: DLL loaded at 0x00007FFED9820000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2026-04-18 22:01:11,065 [root] DEBUG: 560: DLL loaded at 0x00007FFEC7790000: C:\Windows\System32\webio (0x98000 bytes).
2026-04-18 22:01:11,089 [root] DEBUG: 560: DLL loaded at 0x00007FFEDFF90000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2026-04-18 22:01:11,096 [root] DEBUG: 560: DLL loaded at 0x00007FFED87C0000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2026-04-18 22:01:11,122 [root] DEBUG: 560: DLL loaded at 0x00007FFED8CB0000: C:\Windows\System32\fwpuclnt (0x80000 bytes).
2026-04-18 22:01:11,269 [root] DEBUG: 560: DLL loaded at 0x00007FFEDFAA0000: C:\Windows\system32\schannel (0x97000 bytes).
2026-04-18 22:01:11,389 [root] INFO: Analysis timeout hit, terminating analysis
2026-04-18 22:01:11,391 [lib.api.process] INFO: Terminate event set for <Process 740 svchost.exe>
2026-04-18 22:01:11,393 [root] DEBUG: 740: Terminate Event: Attempting to dump process 740
2026-04-18 22:01:11,394 [root] DEBUG: 740: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 22:01:11,399 [lib.api.process] INFO: Termination confirmed for <Process 740 svchost.exe>
2026-04-18 22:01:11,400 [root] INFO: Terminate event set for process 740
2026-04-18 22:01:11,401 [root] DEBUG: 740: Terminate Event: monitor shutdown complete for process 740
2026-04-18 22:01:11,402 [lib.api.process] INFO: Terminate event set for <Process 268 svchost.exe>
2026-04-18 22:01:11,402 [root] DEBUG: 268: Terminate Event: Attempting to dump process 268
2026-04-18 22:01:11,405 [root] DEBUG: 268: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 22:01:11,417 [root] INFO: Added new file to list with pid None and path C:\ProgramData\Microsoft\Network\Downloader\edb.chk
2026-04-18 22:01:11,428 [lib.api.process] INFO: Termination confirmed for <Process 268 svchost.exe>
2026-04-18 22:01:11,429 [root] INFO: Terminate event set for process 268
2026-04-18 22:01:11,431 [lib.api.process] INFO: Terminate event set for <Process 12152 taskhostw.exe>
2026-04-18 22:01:11,431 [root] DEBUG: 268: Terminate Event: monitor shutdown complete for process 268
2026-04-18 22:01:11,433 [root] DEBUG: 12152: Terminate Event: Attempting to dump process 12152
2026-04-18 22:01:11,435 [root] DEBUG: 12152: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 22:01:11,447 [lib.api.process] INFO: Termination confirmed for <Process 12152 taskhostw.exe>
2026-04-18 22:01:11,447 [root] INFO: Terminate event set for process 12152
2026-04-18 22:01:11,448 [root] DEBUG: 12152: Terminate Event: monitor shutdown complete for process 12152
2026-04-18 22:01:11,450 [lib.api.process] INFO: Terminate event set for <Process 2656 dllhost.exe>
2026-04-18 22:01:11,452 [root] DEBUG: 2656: Terminate Event: Attempting to dump process 2656
2026-04-18 22:01:11,454 [root] DEBUG: 2656: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 22:01:11,465 [lib.api.process] INFO: Termination confirmed for <Process 2656 dllhost.exe>
2026-04-18 22:01:11,466 [root] DEBUG: 2656: Terminate Event: monitor shutdown complete for process 2656
2026-04-18 22:01:11,467 [root] INFO: Terminate event set for process 2656
2026-04-18 22:01:11,467 [lib.api.process] INFO: Terminate event set for <Process 3776 TiWorker.exe>
2026-04-18 22:01:11,509 [root] DEBUG: 3776: Terminate Event: Attempting to dump process 3776
2026-04-18 22:01:11,514 [root] DEBUG: 3776: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 22:01:11,527 [root] INFO: Added new file to list with pid None and path C:\Windows\Logs\CBS\CBS.log
2026-04-18 22:01:11,528 [lib.api.process] INFO: Termination confirmed for <Process 3776 TiWorker.exe>
2026-04-18 22:01:11,529 [root] INFO: Terminate event set for process 3776
2026-04-18 22:01:11,530 [lib.api.process] INFO: Terminate event set for <Process 560 MoUsoCoreWorker.exe>
2026-04-18 22:01:11,530 [root] DEBUG: 3776: Terminate Event: monitor shutdown complete for process 3776
2026-04-18 22:01:11,531 [root] DEBUG: 560: Terminate Event: Attempting to dump process 560
2026-04-18 22:01:11,533 [root] DEBUG: 560: DLL loaded at 0x00007FFECB060000: C:\Windows\SYSTEM32\mskeyprotect (0x15000 bytes).
2026-04-18 22:01:11,535 [root] DEBUG: 560: VerifyCodeSection: Exception rebasing image from 0x00007FF7F40C0000 to 0x0000000140000000.
2026-04-18 22:01:11,536 [root] DEBUG: 560: DLL loaded at 0x00007FFECB1A0000: C:\Windows\system32\ncryptsslp (0x26000 bytes).
2026-04-18 22:01:11,537 [root] DEBUG: 560: DoProcessDump: Skipping process dump as code is identical on disk.
2026-04-18 22:01:11,552 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db
2026-04-18 22:01:11,554 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOShared\Logs\System\WuProvider.1478a7c4-b926-4c90-8f63-d00de411c7d4.1.etl
2026-04-18 22:01:11,555 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.2616b066-5ee3-4c33-ae11-929dc40c3e64.1.etl
2026-04-18 22:01:11,557 [lib.api.process] INFO: Termination confirmed for <Process 560 MoUsoCoreWorker.exe>
2026-04-18 22:01:11,557 [root] DEBUG: 560: Terminate Event: monitor shutdown complete for process 560
2026-04-18 22:01:11,557 [root] INFO: Terminate event set for process 560
2026-04-18 22:01:11,558 [root] INFO: Created shutdown mutex
2026-04-18 22:01:11,576 [root] DEBUG: 560: DLL loaded at 0x00007FFECAF40000: C:\Windows\System32\cryptnet (0x31000 bytes).
2026-04-18 22:01:12,036 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0450000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-04-18 22:01:12,037 [root] DEBUG: 12152: DLL loaded at 0x00007FFED5EB0000: C:\Windows\System32\wosc (0x4e000 bytes).
2026-04-18 22:01:12,043 [root] DEBUG: 560: DLL loaded at 0x00007FFEDC430000: C:\Windows\System32\taskschd (0xac000 bytes).
2026-04-18 22:01:12,048 [root] DEBUG: 12152: DLL loaded at 0x00007FFEC97F0000: C:\Windows\System32\FlightSettings (0xe6000 bytes).
2026-04-18 22:01:12,055 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE1880000: C:\Windows\System32\shcore (0xad000 bytes).
2026-04-18 22:01:12,056 [root] DEBUG: 12152: DLL loaded at 0x00007FFECFD80000: C:\Windows\System32\Windows.Networking.Connectivity (0xb9000 bytes).
2026-04-18 22:01:12,068 [root] DEBUG: 12152: DLL loaded at 0x00007FFED74C0000: C:\Windows\System32\npmproxy (0x10000 bytes).
2026-04-18 22:01:12,083 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDC8A0000: C:\Windows\System32\WinTypes (0x155000 bytes).
2026-04-18 22:01:12,085 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:12,092 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\2f93d385581e7040686de3f547714eb259f539938ed100d74318962486be95ce; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,093 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDFF50000: C:\Windows\System32\IPHLPAPI (0x3b000 bytes).
2026-04-18 22:01:12,097 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE2110000: C:\Windows\System32\NSI (0x8000 bytes).
2026-04-18 22:01:12,106 [root] DEBUG: 560: DLL loaded at 0x00007FFEDB970000: C:\Windows\System32\twinapi.appcore (0x203000 bytes).
2026-04-18 22:01:12,107 [root] DEBUG: 12152: DLL loaded at 0x00007FFED7510000: C:\Windows\System32\dusmapi (0x11000 bytes).
2026-04-18 22:01:12,114 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0AC0000: C:\Windows\System32\profapi (0x25000 bytes).
2026-04-18 22:01:12,118 [root] DEBUG: 12152: DLL loaded at 0x00007FFED9750000: C:\Windows\System32\Cabinet (0x29000 bytes).
2026-04-18 22:01:12,119 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:12,120 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0A80000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-04-18 22:01:12,123 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE1470000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2026-04-18 22:01:12,125 [root] DEBUG: 12152: DLL loaded at 0x00007FFEC9BD0000: C:\Windows\System32\UpdatePolicy (0x43000 bytes).
2026-04-18 22:01:12,126 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\dba9c9a4d3cd226fff5bae8161f64e692c350fc2f6aa2dfed35353bb52a856ce; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,128 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0690000: C:\Windows\System32\MSASN1 (0x12000 bytes).
2026-04-18 22:01:12,138 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDFC20000: C:\Windows\System32\msvcp110_win (0x8a000 bytes).
2026-04-18 22:01:12,140 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDB030000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-04-18 22:01:12,152 [root] DEBUG: 12152: DLL loaded at 0x00007FFED7200000: C:\Windows\System32\iertutil (0x2bc000 bytes).
2026-04-18 22:01:12,153 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:12,154 [root] DEBUG: 12152: DLL loaded at 0x00007FFECBA50000: C:\Windows\System32\Windows.Web (0xc3000 bytes).
2026-04-18 22:01:12,160 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\59018dba654d9882c9186049e959db628ec7495c3f9059b7571597f804796279; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,163 [root] DEBUG: 560: DLL loaded at 0x00007FFED19F0000: C:\Windows\System32\Windows.ApplicationModel (0xe9000 bytes).
2026-04-18 22:01:12,188 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0070000: C:\Windows\System32\logoncli (0x43000 bytes).
2026-04-18 22:01:12,192 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0060000: C:\Windows\System32\netutils (0xc000 bytes).
2026-04-18 22:01:12,194 [root] DEBUG: 560: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:12,197 [root] DEBUG: 560: DLL loaded at 0x00007FFECC9A0000: C:\Windows\System32\dcntel (0xbf000 bytes).
2026-04-18 22:01:12,215 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\3c7d5d867c60afbfa5fd7a89d30e19d5d26770bee016ab8dd4cd0d63ccb4a82b; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,242 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:12,249 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\93b7444270a356aebe5daddd69fb142ced13d7b03fbd67333fcd2678412dd4d4; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,272 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:12,276 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0070000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-04-18 22:01:12,278 [root] DEBUG: 12152: DLL loaded at 0x00007FFED74F0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-04-18 22:01:12,283 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\0d6b11a145b94b387c6b0c4b3f34bc845fd552f64db67115112f3cc71923e5d2; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,310 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE09F0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-04-18 22:01:12,310 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:12,312 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0060000: C:\Windows\system32\netutils (0xc000 bytes).
2026-04-18 22:01:12,317 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\10f9e357444960b2c977dd37ac96b62b87b57a30f4a6eb73e50b797e9528ed2d; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,318 [root] DEBUG: 12152: DLL loaded at 0x00007FFED8A20000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-04-18 22:01:12,319 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:12,321 [root] DEBUG: 12152: DLL loaded at 0x00007FFECC9A0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-04-18 22:01:12,324 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE09D0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-04-18 22:01:12,331 [root] DEBUG: 12152: DLL loaded at 0x00007FFECFCE0000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-04-18 22:01:12,339 [root] DEBUG: 12152: DLL loaded at 0x00007FFED5760000: C:\Windows\System32\Windows.System.Profile.PlatformDiagnosticsAndUsageDataSettings (0x16000 bytes).
2026-04-18 22:01:12,352 [root] DEBUG: 12152: DLL loaded at 0x00007FFED4CE0000: C:\Windows\system32\fcon (0x45000 bytes).
2026-04-18 22:01:12,369 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDFB90000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-04-18 22:01:12,439 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0070000: C:\Windows\System32\logoncli (0x43000 bytes).
2026-04-18 22:01:12,441 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0060000: C:\Windows\System32\netutils (0xc000 bytes).
2026-04-18 22:01:12,442 [root] DEBUG: 560: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:12,444 [root] DEBUG: 560: DLL loaded at 0x00007FFECC9A0000: C:\Windows\System32\dcntel (0xbf000 bytes).
2026-04-18 22:01:12,450 [root] DEBUG: 560: DLL loaded at 0x00007FFED74F0000: C:\Windows\System32\utcutil (0x1f000 bytes).
2026-04-18 22:01:12,455 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0070000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-04-18 22:01:12,457 [root] DEBUG: 12152: DLL loaded at 0x00007FFED74F0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-04-18 22:01:12,476 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE09F0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-04-18 22:01:12,477 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0060000: C:\Windows\system32\netutils (0xc000 bytes).
2026-04-18 22:01:12,478 [root] DEBUG: 12152: DLL loaded at 0x00007FFED8A20000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-04-18 22:01:12,480 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:12,481 [root] DEBUG: 12152: DLL loaded at 0x00007FFECC9A0000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-04-18 22:01:12,483 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE09D0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-04-18 22:01:12,488 [root] DEBUG: 12152: DLL loaded at 0x00007FFECFCE0000: C:\Windows\SYSTEM32\AEPIC (0x92000 bytes).
2026-04-18 22:01:12,490 [root] DEBUG: 560: DLL loaded at 0x00007FFEDF6A0000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-04-18 22:01:12,491 [root] DEBUG: 560: DLL loaded at 0x00007FFEDF6D0000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-04-18 22:01:12,542 [root] DEBUG: 560: api-rate-cap: NtReadVirtualMemory hook disabled due to rate
2026-04-18 22:01:12,570 [root] INFO: Shutting down package
2026-04-18 22:01:12,570 [root] INFO: Stopping auxiliary modules
2026-04-18 22:01:12,571 [root] INFO: Stopping auxiliary module: Browser
2026-04-18 22:01:12,572 [root] INFO: Stopping auxiliary module: Human
2026-04-18 22:01:12,775 [root] DEBUG: 560: DLL loaded at 0x00007FFED5E60000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-04-18 22:01:12,797 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0070000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-04-18 22:01:12,803 [root] DEBUG: 560: DLL loaded at 0x00007FFEDCA00000: C:\Windows\SYSTEM32\DSREG (0x141000 bytes).
2026-04-18 22:01:12,811 [root] DEBUG: 12152: DLL loaded at 0x00007FFED74F0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-04-18 22:01:12,833 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0870000: C:\Windows\SYSTEM32\DEVOBJ (0x33000 bytes).
2026-04-18 22:01:12,836 [root] DEBUG: 560: DLL loaded at 0x00007FFECBB90000: C:\Windows\SYSTEM32\dmEnrollEngine (0xdf000 bytes).
2026-04-18 22:01:12,838 [root] DEBUG: 560: DLL loaded at 0x00007FFED4F40000: C:\Windows\SYSTEM32\enrollmentapi (0x11000 bytes).
2026-04-18 22:01:12,928 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:12,934 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\619d2f051e8285d0b99ca1edbc923a9f612448ec7253eb5306661649718f7783; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,958 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:12,966 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\eff2e367d0df2846391c6f0149caeda29f616ce41071b33a50545e8f45c61a9e; Size is 12824; Max size: 100000000
2026-04-18 22:01:12,990 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:13,099 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 13264: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe, ImageBase: 0x00007FF69CB60000
2026-04-18 22:01:13,101 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\963ae03d29d7baa8aecbc623b49380da88462c52f3eebdf4b7158b30a1074d4e; Size is 12824; Max size: 100000000
2026-04-18 22:01:13,123 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:13,129 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\eb3f95ec682f4c79032eae54171ede6f322c33e3653de074145be28087257854; Size is 12824; Max size: 100000000
2026-04-18 22:01:13,155 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:13,175 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\d5fd9eaed235ecb8d03146931883ebc49a47fa2deb46c78d8380d45607ea266b; Size is 12824; Max size: 100000000
2026-04-18 22:01:13,197 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:13,206 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\beb5485a9babc2f9aeb816beff0136d0d4e081207f83a5398f1d15070cbc6446; Size is 12824; Max size: 100000000
2026-04-18 22:01:13,285 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:13,304 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\78744b8b702886473781767ef4d06109255da2edf19740dc67bf0dcee3b3ccd8; Size is 12824; Max size: 100000000
2026-04-18 22:01:13,593 [root] INFO: Added new file to list with pid None and path C:\ProgramData\USOPrivate\UpdateStore\store.db-journal
2026-04-18 22:01:13,597 [root] INFO: Stopping auxiliary module: Screenshots
2026-04-18 22:01:13,603 [root] DEBUG: 608: DLL loaded at 0x00007FFED4F60000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-04-18 22:01:13,940 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db-journal to files\2c0305838b2d414762a57a31f0d4e84bb105e6002faa8b1fc164015590768f19; Size is 12824; Max size: 100000000
2026-04-18 22:01:14,115 [root] DEBUG: 268: DLL loaded at 0x00007FFECF070000: C:\Windows\System32\vaultcli (0x51000 bytes).
2026-04-18 22:01:14,148 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0070000: C:\Windows\System32\logoncli (0x43000 bytes).
2026-04-18 22:01:14,149 [root] DEBUG: 268: DLL loaded at 0x00007FFEDB3C0000: C:\Windows\System32\IDStore (0x31000 bytes).
2026-04-18 22:01:14,165 [root] DEBUG: 560: DLL loaded at 0x00007FFEE0060000: C:\Windows\System32\netutils (0xc000 bytes).
2026-04-18 22:01:14,169 [root] DEBUG: 268: DLL loaded at 0x00007FFED1620000: C:\Windows\System32\AppContracts (0xe0000 bytes).
2026-04-18 22:01:14,175 [root] DEBUG: 560: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:14,180 [root] DEBUG: 560: DLL loaded at 0x00007FFEC7C70000: C:\Windows\System32\dcntel (0xbf000 bytes).
2026-04-18 22:01:14,181 [root] DEBUG: 268: DLL loaded at 0x00007FFED44A0000: C:\Windows\System32\wlidprov (0xaa000 bytes).
2026-04-18 22:01:14,189 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE09F0000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-04-18 22:01:14,192 [root] DEBUG: 560: DLL loaded at 0x00007FFECB0F0000: C:\Windows\System32\utcutil (0x1f000 bytes).
2026-04-18 22:01:14,193 [root] INFO: Finishing auxiliary modules
2026-04-18 22:01:14,193 [root] INFO: Shutting down pipe server and dumping dropped files
2026-04-18 22:01:14,194 [root] DEBUG: 268: DLL loaded at 0x00007FFED4100000: c:\windows\system32\OnDemandBrokerClient (0x10000 bytes).
2026-04-18 22:01:14,196 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Roaming\AnyDesk\user.conf to files\ccf3f3232b145b6ea00a4568d1190984e7d4ff1a3354ba98dc9ba2e6fdd1dea1; Size is 8359; Max size: 100000000
2026-04-18 22:01:14,198 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0070000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-04-18 22:01:14,204 [lib.common.results] INFO: Uploading file c:\users\admin\appdata\roaming\microsoft\windows\recent\customdestinations\75fdacd8330bac18.customdestinations-ms to files\8f55fc1dd43acf4f55412d3cf78c659ba7f4d4e10fccc0b182e4ad339600772c; Size is 3228; Max size: 100000000
2026-04-18 22:01:14,208 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat to files\6586576636c32b62bba99fd20f705217c27b120bf01be66f06414c291f7bc691; Size is 1022; Max size: 100000000
2026-04-18 22:01:14,211 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE0060000: C:\Windows\system32\netutils (0xc000 bytes).
2026-04-18 22:01:14,220 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Roaming\AnyDesk\system.conf to files\9dedbb10e2b6c30d714fae338f42d9b697211addb2a18664915a9d67bff8c4f0; Size is 738; Max size: 100000000
2026-04-18 22:01:14,224 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Roaming\AnyDesk\service.conf to files\6445cb7262af2f238e91973e51554eec17d84b1b699333095504b10ea3051fd6; Size is 3334; Max size: 100000000
2026-04-18 22:01:14,227 [root] WARNING: File at path c:\users\admin\appdata\roaming\microsoft\windows\recent\customdestinations\niryuo8b8c3zj8qs8iwc.temp does not exist, skipping
2026-04-18 22:01:14,228 [root] WARNING: File at path c:\users\admin\appdata\roaming\microsoft\windows\recent\customdestinations\xwkh5owqq9fdqyrkjq73.temp does not exist, skipping
2026-04-18 22:01:14,242 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db to files\56fe0ea987cea4841e1f1b039e4e0be3123570ce7910861754b5ad767fd45398; Size is 1048576; Max size: 100000000
2026-04-18 22:01:14,243 [root] DEBUG: 12152: DLL loaded at 0x00007FFED8A20000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-04-18 22:01:14,245 [root] DEBUG: 560: DLL loaded at 0x00007FFEDF6A0000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-04-18 22:01:14,256 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDFCB0000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-04-18 22:01:14,258 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db to files\813c9e15448ce06a4d7f9645b5b91708dec4b4063c1a414dbf915ec1c82d367f; Size is 14688; Max size: 100000000
2026-04-18 22:01:14,261 [root] DEBUG: 560: DLL loaded at 0x00007FFEDF6D0000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-04-18 22:01:14,267 [lib.common.results] INFO: Uploading file C:\Users\Admin\AppData\Roaming\AnyDesk\ad.trace to files\118eb4c898600ac8ab2441e33666678bb6f2e5555b546e474e5a3f4fe223e09e; Size is 40277; Max size: 100000000
2026-04-18 22:01:14,274 [lib.common.results] INFO: Uploading file C:\ProgramData\Microsoft\Network\Downloader\edb.chk to files\774cef5293136d50f417613c13b6107bb627a2c415ac0482a6e747b18044df66; Size is 8192; Max size: 100000000
2026-04-18 22:01:14,277 [root] DEBUG: 12152: DLL loaded at 0x00007FFEC7C70000: C:\Windows\system32\dcntel (0xbf000 bytes).
2026-04-18 22:01:14,288 [root] DEBUG: 12152: DLL loaded at 0x00007FFEE09D0000: C:\Windows\system32\UMPDC (0x12000 bytes).
2026-04-18 22:01:14,291 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 13748: C:\Windows\system32\BackgroundTaskHost.exe, ImageBase: 0x00007FF767EF0000
2026-04-18 22:01:14,295 [root] DEBUG: 12152: DLL loaded at 0x00007FFECB0F0000: C:\Windows\system32\utcutil (0x1f000 bytes).
2026-04-18 22:01:14,335 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDF6A0000: C:\Windows\SYSTEM32\sppc (0x25000 bytes).
2026-04-18 22:01:14,337 [root] DEBUG: 12152: DLL loaded at 0x00007FFEDF6D0000: C:\Windows\SYSTEM32\slc (0x29000 bytes).
2026-04-18 22:01:14,387 [lib.common.results] INFO: Uploading file C:\Windows\Logs\CBS\CBS.log to files\8404d49d85cc62f8296283c022ed44d4d25c12aac40cd6b3263f58d8c97f283c; Size is 1472336; Max size: 100000000
2026-04-18 22:01:14,413 [lib.common.results] INFO: Uploading file C:\ProgramData\USOPrivate\UpdateStore\store.db to files\aeafe6fc3a0cad506f6fb3d838fd6263129588e7c85eb57a17ccaa3714458f8d; Size is 61440; Max size: 100000000
2026-04-18 22:01:14,420 [lib.common.results] INFO: Uploading file C:\ProgramData\USOShared\Logs\System\WuProvider.1478a7c4-b926-4c90-8f63-d00de411c7d4.1.etl to files\1222ab90dadc558dc0e364841027e86754d70620a855132f0637467ed30120bf; Size is 4096; Max size: 100000000
2026-04-18 22:01:14,443 [lib.common.results] INFO: Uploading file C:\ProgramData\USOShared\Logs\System\MoUsoCoreWorker.2616b066-5ee3-4c33-ae11-929dc40c3e64.1.etl to files\854a50611437c2243898c7122e9b7ab32251092793010716c520781438a0a10d; Size is 32768; Max size: 100000000
2026-04-18 22:01:14,450 [root] WARNING: Folder at path "C:\PiogNHme\debugger" does not exist, skipping
2026-04-18 22:01:14,452 [root] INFO: Uploading files at path "C:\PiogNHme\tlsdump"
2026-04-18 22:01:14,454 [lib.common.results] INFO: Uploading file C:\PiogNHme\tlsdump\tlsdump.log to tlsdump\tlsdump.log; Size is 5206; Max size: 100000000
2026-04-18 22:01:14,477 [root] DEBUG: 560: DLL loaded at 0x00007FFED5E60000: C:\Windows\SYSTEM32\netapi32 (0x19000 bytes).
2026-04-18 22:01:14,614 [root] WARNING: Monitor injection attempted but failed for process 3140
2026-04-18 22:01:14,614 [root] WARNING: Monitor injection attempted but failed for process 3596
2026-04-18 22:01:14,614 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| MalwareGuest | MalwareGuest | Proxmox | 2026-04-18 21:57:44 | 2026-04-18 22:01:29 | internet |
| File Name |
AnyDesk.exe
|
|---|---|
| File Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| File Size | 5525576 bytes |
| MD5 | 75eecc3a8b215c465f541643e9c4f484 |
| SHA1 | 3ad1f800b63640128bfdcc8dbee909554465ee11 |
| SHA256 | ec33d8ee9c3881b8fcea18f9f862d5926d994553aec1b65081d925afd3e8b028 [VT] [MWDB] [Bazaar] |
| SHA3-384 | 18a61e08504cc24c97f970f954d7c8211a4bd28e6355f546f0d9ef47fd266ed5af8942a034149d629c5bec0b96e1c37f |
| CRC32 | 96B63EF9 |
| TLSH | T11D46330D77F01AE1CEB786B99E43A623B5A79FF10D6211024DD5270C9277AC83FA7A05 |
| Ssdeep | 98304:j5ObAu2pmits24nYhQCWQdaQQo/mJPv4KYZPKBhYI5RuN4OL2wIjcsJWNg3:IAnRu24nR5QcTvYdmPuWOL2TcQWe3 |
| PE | File Strings BinGraph Vba2Graph overlay (0.00) |
| Engine | Result | Engine | Result | Engine | Result |
|---|
| Filename |
db5b4eec5a58a9679590c372b08b7ab7bdca48728dc13d509e9387c78b8d24e4
|
|---|---|
| File Type | data |
| Associated Filenames |
overlay
|
| File Size | 17992 bytes |
| MD5 | 04637d7b2ef7fec3788a0cdbc43ed96f |
| SHA1 | 14695c110155aa8a54daee2b9166019862d84e60 |
| SHA256 | db5b4eec5a58a9679590c372b08b7ab7bdca48728dc13d509e9387c78b8d24e4 [VT] [MWDB] [Bazaar] |
| SHA3-384 | b29c39c17e9dd9188a5941578b3e9b94767e860dcc983aa834ea44c7fc477951545d272faa8122882fb0d8486d7b5aaa |
| CRC32 | F1CC79B3 |
| TLSH | T1768239A78A186C05DE479E4071D4D63EADB5B386A9D0C0D6226DC2528FC57823FED0FD |
| Ssdeep | 384:tNyb8E9VF6IYinAM+oJtFRMOc+M4IYiztFRMOKV5W8JN77hhrLZj:JEpYinAMxPFTMhYi5F+5x3hFNj |
| File Strings Bingraph Vba2Graph |
| Image Base | Entry Point | Reported Checksum | Actual Checksum | Minimum OS Version | PDB Path | Compile Time | Icon | Icon Exact Hash | Icon Similarity Hash | Icon DHash |
|---|---|---|---|---|---|---|---|---|---|---|
| 0x00400000 | 0x00001ce5 | 0x005479da | 0x005479da | 5.1 | C:\Buildbot\ad-windows-32\build\release\app-32\win_loader\AnyDesk.pdb | 2023-11-09 07:48:10 | 70500930137dd0cf36f6aeff7e90af3c | 5f1056e3ea0715b75a116d24d9c97bb8 | 489669d8d8699648 |
| CompanyName | AnyDesk Software GmbH |
|---|---|
| FileDescription | AnyDesk |
| FileVersion | 8.0.6 |
| ProductName | AnyDesk |
| ProductVersion | 8.0 |
| LegalCopyright | (C) 2022 AnyDesk Software GmbH |
| Translation | 0x0409 0x04e4 |
| Name | RAW Address | Virtual Address | Virtual Size | Size of Raw Data | Characteristics | Entropy |
|---|---|---|---|---|---|---|
| .text | 0x00000400 | 0x00001000 | 0x00002877 | 0x00002a00 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.54 |
| .itext | 0x00000000 | 0x00004000 | 0x0128b800 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.00 |
| .rdata | 0x00002e00 | 0x01290000 | 0x000002fa | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.64 |
| .data | 0x00003200 | 0x01291000 | 0x00538cb4 | 0x00538a00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 8.00 |
| .rsrc | 0x0053bc00 | 0x017ca000 | 0x00004850 | 0x00004a00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 6.02 |
| .reloc | 0x00540600 | 0x017cf000 | 0x00000300 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 1.22 |
| Offset | 0x00540a00 |
| Size | 0x00004648 |
| Name | Offset | Size | Language | Sub-language | Entropy | File type |
|---|---|---|---|---|---|---|
| RT_ICON | 0x017ca280 | 0x00001b8e | LANG_ENGLISH | SUBLANG_ENGLISH_US | 7.84 | None |
| RT_ICON | 0x017cbe10 | 0x00000668 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.30 | None |
| RT_ICON | 0x017cc478 | 0x000002e8 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.67 | None |
| RT_ICON | 0x017cc760 | 0x000001e8 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.74 | None |
| RT_ICON | 0x017cc948 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.69 | None |
| RT_ICON | 0x017ccac0 | 0x000010a8 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.83 | None |
| RT_ICON | 0x017cdb68 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.12 | None |
| RT_GROUP_ICON | 0x017cca70 | 0x0000004c | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.79 | None |
| RT_GROUP_ICON | 0x017cdfd0 | 0x00000022 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.36 | None |
| RT_VERSION | 0x017cdff8 | 0x0000024c | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.34 | None |
| RT_MANIFEST | 0x017ce248 | 0x00000605 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 5.40 | None |
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| N | 208.115.231.138 [VT] | unknown | |
| N | 57.128.101.75 [VT] | unknown | |
| Y | 98.66.133.184 [VT] | unknown |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| mozilla.map.fastly.net [VT] |
A 151.101.193.91
[VT]
A 151.101.65.91 [VT] A 151.101.129.91 [VT] A 151.101.1.91 [VT] |
151.101.193.91 [VT] |
| mozilla.map.fastly.net [VT] |
AAAA 2a04:4e42::347
[VT]
AAAA 2a04:4e42:400::347 [VT] AAAA 2a04:4e42:200::347 [VT] AAAA 2a04:4e42:600::347 [VT] |
151.101.193.91 [VT] |
| boot.net.anydesk.com [VT] |
A 57.128.101.75
[VT]
A 57.128.101.78 [VT] A 57.128.101.74 [VT] A 195.181.174.174 [VT] CNAME boot-relays.net.anydesk.com [VT] A 37.59.29.33 [VT] A 57.128.101.77 [VT] A 195.181.174.173 [VT] A 141.95.145.210 [VT] |
195.181.174.173 [VT] |
| relay-0704c0e0.net.anydesk.com [VT] | A 208.115.231.138 [VT] | 208.115.231.138 [VT] |
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP