| Category | Package | Started | Completed | Duration | Options | Log(s) | MalScore |
|---|---|---|---|---|---|---|---|
| FILE | 2025-12-08 14:03:54 | 2025-12-08 14:07:19 | 205 seconds | Show Options | Show Analysis Log | 4.9 |
vnc_port=5901
2025-12-06 18:31:42,082 [root] INFO: Date set to: 20251208T05:52:09, timeout set to: 180
2025-12-06 18:31:42,082 [root] DEBUG: Starting analyzer from: C:\tmpw7hn3wdo
2025-12-06 18:31:42,082 [root] DEBUG: Storing results at: C:\HNxZeWN
2025-12-06 18:31:42,082 [root] DEBUG: Pipe server name: \\.\PIPE\BsJripN
2025-12-06 18:31:42,082 [root] DEBUG: Python path: C:\Python38
2025-12-06 18:31:42,082 [root] INFO: analysis running as a normal user
2025-12-06 18:31:42,082 [root] INFO: analysis package specified: "pdf"
2025-12-06 18:31:42,082 [root] DEBUG: importing analysis package module: "modules.packages.pdf"...
2025-12-06 18:31:42,082 [root] DEBUG: imported analysis package "pdf"
2025-12-06 18:31:42,082 [root] DEBUG: initializing analysis package "pdf"...
2025-12-06 18:31:42,082 [lib.common.common] INFO: wrapping
2025-12-06 18:31:42,082 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-06 18:31:42,082 [root] DEBUG: New location of moved file: C:\Users\user\AppData\Local\Temp\file
2025-12-06 18:31:42,082 [root] INFO: Analyzer: Package modules.packages.pdf does not specify a DLL option
2025-12-06 18:31:42,082 [root] INFO: Analyzer: Package modules.packages.pdf does not specify a DLL_64 option
2025-12-06 18:31:42,082 [root] INFO: Analyzer: Package modules.packages.pdf does not specify a loader option
2025-12-06 18:31:42,082 [root] INFO: Analyzer: Package modules.packages.pdf does not specify a loader_64 option
2025-12-06 18:31:42,113 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-12-06 18:31:42,113 [root] DEBUG: Imported auxiliary module "modules.auxiliary.curtain"
2025-12-06 18:31:42,113 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-12-06 18:31:42,113 [root] DEBUG: Imported auxiliary module "modules.auxiliary.during_script"
2025-12-06 18:31:42,113 [root] DEBUG: Imported auxiliary module "modules.auxiliary.end_noisy_tasks"
2025-12-06 18:31:42,113 [root] DEBUG: Imported auxiliary module "modules.auxiliary.evtx"
2025-12-06 18:31:42,129 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-12-06 18:31:42,129 [root] DEBUG: Imported auxiliary module "modules.auxiliary.pre_script"
2025-12-06 18:31:42,129 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-12-06 18:31:42,144 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2025-12-06 18:31:42,144 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2025-12-06 18:31:42,160 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-12-06 18:31:42,160 [root] DEBUG: Imported auxiliary module "modules.auxiliary.sysmon"
2025-12-06 18:31:42,160 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-12-06 18:31:42,160 [root] DEBUG: Imported auxiliary module "modules.auxiliary.usage"
2025-12-06 18:31:42,160 [root] DEBUG: Initialized auxiliary module "Browser"
2025-12-06 18:31:42,160 [root] DEBUG: attempting to configure 'Browser' from data
2025-12-06 18:31:42,160 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-12-06 18:31:42,160 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-12-06 18:31:42,160 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-12-06 18:31:42,160 [root] DEBUG: Initialized auxiliary module "Curtain"
2025-12-06 18:31:42,160 [root] DEBUG: attempting to configure 'Curtain' from data
2025-12-06 18:31:42,160 [root] DEBUG: module Curtain does not support data configuration, ignoring
2025-12-06 18:31:42,160 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.curtain"...
2025-12-06 18:31:42,160 [root] DEBUG: Started auxiliary module modules.auxiliary.curtain
2025-12-06 18:31:42,160 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-12-06 18:31:42,160 [root] DEBUG: attempting to configure 'Disguise' from data
2025-12-06 18:31:42,160 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-12-06 18:31:42,160 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-12-06 18:31:42,160 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.disguise: [WinError 5] Access is denied
2025-12-06 18:31:42,160 [root] DEBUG: Initialized auxiliary module "End_noisy_tasks"
2025-12-06 18:31:42,160 [root] DEBUG: attempting to configure 'End_noisy_tasks' from data
2025-12-06 18:31:42,160 [root] DEBUG: module End_noisy_tasks does not support data configuration, ignoring
2025-12-06 18:31:42,160 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.end_noisy_tasks"...
2025-12-06 18:31:42,160 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wuauclt.exe
2025-12-06 18:31:42,160 [root] DEBUG: Started auxiliary module modules.auxiliary.end_noisy_tasks
2025-12-06 18:31:42,160 [root] DEBUG: Initialized auxiliary module "Evtx"
2025-12-06 18:31:42,160 [root] DEBUG: attempting to configure 'Evtx' from data
2025-12-06 18:31:42,160 [root] DEBUG: module Evtx does not support data configuration, ignoring
2025-12-06 18:31:42,160 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.evtx"...
2025-12-06 18:31:42,160 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security State Change" /success:enable /failure:enable
2025-12-06 18:31:42,160 [root] DEBUG: Started auxiliary module modules.auxiliary.evtx
2025-12-06 18:31:42,160 [root] DEBUG: Initialized auxiliary module "Human"
2025-12-06 18:31:42,160 [root] DEBUG: attempting to configure 'Human' from data
2025-12-06 18:31:42,160 [root] DEBUG: module Human does not support data configuration, ignoring
2025-12-06 18:31:42,160 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-12-06 18:31:42,160 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-12-06 18:31:42,160 [root] DEBUG: Initialized auxiliary module "Pre_script"
2025-12-06 18:31:42,160 [root] DEBUG: attempting to configure 'Pre_script' from data
2025-12-06 18:31:42,160 [root] DEBUG: module Pre_script does not support data configuration, ignoring
2025-12-06 18:31:42,160 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.pre_script"...
2025-12-06 18:31:42,176 [root] DEBUG: Started auxiliary module modules.auxiliary.pre_script
2025-12-06 18:31:42,176 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-12-06 18:31:42,176 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-12-06 18:31:42,176 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-12-06 18:31:42,176 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-12-06 18:31:42,176 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-12-06 18:31:42,176 [root] DEBUG: Initialized auxiliary module "Sysmon"
2025-12-06 18:31:42,176 [root] DEBUG: attempting to configure 'Sysmon' from data
2025-12-06 18:31:42,176 [root] DEBUG: module Sysmon does not support data configuration, ignoring
2025-12-06 18:31:42,176 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.sysmon"...
2025-12-06 18:31:42,269 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security System Extension" /success:enable /failure:enable
2025-12-06 18:31:42,301 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wusa.exe
2025-12-06 18:31:42,332 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.sysmon: In order to use the Sysmon functionality, it is required to have the SMaster(64|32).exe file and sysmonconfig-export.xml file in the bin path. Note that the SMaster(64|32).exe files are just the standard Sysmon binaries renamed to avoid anti-analysis detection techniques.
2025-12-06 18:31:42,332 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-12-06 18:31:42,332 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-12-06 18:31:42,332 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-12-06 18:31:42,332 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-12-06 18:31:42,332 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 668
2025-12-06 18:31:42,332 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,332 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,332 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,332 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:42,332 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,332 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:42,332 [lib.api.process] DEBUG: Failed getting exit code for <Process 668 ???>
2025-12-06 18:31:42,332 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"System Integrity" /success:enable /failure:enable
2025-12-06 18:31:42,332 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,332 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:42,332 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:42,332 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:42,332 [lib.api.process] WARNING: the <Process 668 ???> is not alive, injection aborted
2025-12-06 18:31:42,332 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2025-12-06 18:31:42,332 [root] DEBUG: Initialized auxiliary module "Usage"
2025-12-06 18:31:42,332 [root] DEBUG: attempting to configure 'Usage' from data
2025-12-06 18:31:42,332 [root] DEBUG: module Usage does not support data configuration, ignoring
2025-12-06 18:31:42,332 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.usage"...
2025-12-06 18:31:42,332 [root] DEBUG: Started auxiliary module modules.auxiliary.usage
2025-12-06 18:31:42,332 [root] DEBUG: Initialized auxiliary module "During_script"
2025-12-06 18:31:42,332 [root] DEBUG: attempting to configure 'During_script' from data
2025-12-06 18:31:42,332 [root] DEBUG: module During_script does not support data configuration, ignoring
2025-12-06 18:31:42,332 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.during_script"...
2025-12-06 18:31:42,332 [root] DEBUG: Started auxiliary module modules.auxiliary.during_script
2025-12-06 18:31:42,379 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Driver" /success:disable /failure:disable
2025-12-06 18:31:42,379 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM WindowsUpdate.exe
2025-12-06 18:31:42,426 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other System Events" /success:disable /failure:enable
2025-12-06 18:31:42,457 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM GoogleUpdate.exe
2025-12-06 18:31:42,472 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logon" /success:enable /failure:enable
2025-12-06 18:31:42,503 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logoff" /success:enable /failure:enable
2025-12-06 18:31:42,535 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM MicrosoftEdgeUpdate.exe
2025-12-06 18:31:42,550 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Account Lockout" /success:enable /failure:enable
2025-12-06 18:31:42,582 [root] INFO: Restarting WMI Service
2025-12-06 18:31:42,597 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Main Mode" /success:disable /failure:disable
2025-12-06 18:31:42,629 [root] DEBUG: package modules.packages.pdf does not support configure, ignoring
2025-12-06 18:31:42,629 [root] WARNING: configuration error for package modules.packages.pdf: error importing data.packages.pdf: No module named 'data.packages'
2025-12-06 18:31:42,644 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DisableWindowsUpdateAccess /t REG_DWORD /d 1 /f
2025-12-06 18:31:42,644 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Quick Mode" /success:disable /failure:disable
2025-12-06 18:31:42,691 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Extended Mode" /success:disable /failure:disable
2025-12-06 18:31:42,707 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f
2025-12-06 18:31:42,722 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-06 18:31:42,754 [lib.api.process] INFO: Successfully executed process from path "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" with arguments ""C:\Users\user\AppData\Local\Temp\file"" with pid 6736
2025-12-06 18:31:42,754 [lib.api.process] INFO: Monitor config for <Process 6736 Acrobat.exe>: C:\tmpw7hn3wdo\dll\6736.ini
2025-12-06 18:31:42,754 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Logon/Logoff Events" /success:enable /failure:enable
2025-12-06 18:31:42,769 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v EnableICMPRedirect /t REG_DWORD /d 0 /f
2025-12-06 18:31:42,785 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable
2025-12-06 18:31:42,816 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Special Logon" /success:enable /failure:enable
2025-12-06 18:31:42,847 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File System" /success:enable /failure:enable
2025-12-06 18:31:42,879 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Registry" /success:enable /failure:enable
2025-12-06 18:31:42,910 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kernel Object" /success:enable /failure:enable
2025-12-06 18:31:42,941 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"SAM" /success:disable /failure:disable
2025-12-06 18:31:42,973 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Certification Services" /success:enable /failure:enable
2025-12-06 18:31:43,019 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Handle Manipulation" /success:disable /failure:disable
2025-12-06 18:31:43,050 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable
2025-12-06 18:31:43,082 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File Share" /success:enable /failure:enable
2025-12-06 18:31:43,113 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Packet Drop" /success:disable /failure:disable
2025-12-06 18:31:43,144 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Connection" /success:disable /failure:disable
2025-12-06 18:31:43,175 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Object Access Events" /success:disable /failure:disable
2025-12-06 18:31:43,207 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Sensitive Privilege Use" /success:disable /failure:disable
2025-12-06 18:31:43,238 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Non Sensitive Privilege Use" /success:disable /failure:disable
2025-12-06 18:31:43,269 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Privilege Use Events" /success:disable /failure:disable
2025-12-06 18:31:43,285 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"RPC Events" /success:enable /failure:enable
2025-12-06 18:31:43,332 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Audit Policy Change" /success:enable /failure:enable
2025-12-06 18:31:43,363 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Authentication Policy Change" /success:enable /failure:enable
2025-12-06 18:31:43,394 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"MPSSVC Rule-Level Policy Change" /success:disable /failure:disable
2025-12-06 18:31:43,426 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Policy Change" /success:disable /failure:disable
2025-12-06 18:31:43,457 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Policy Change Events" /success:disable /failure:enable
2025-12-06 18:31:43,473 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"User Account Management" /success:enable /failure:enable
2025-12-06 18:31:43,504 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Computer Account Management" /success:enable /failure:enable
2025-12-06 18:31:43,535 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,582 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Distribution Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,598 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Group Management" /success:enable /failure:enable
2025-12-06 18:31:43,629 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Management Events" /success:enable /failure:enable
2025-12-06 18:31:43,660 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable
2025-12-06 18:31:43,691 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable
2025-12-06 18:31:43,723 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Replication" /success:disable /failure:enable
2025-12-06 18:31:43,754 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Detailed Directory Service Replication" /success:disable /failure:disable
2025-12-06 18:31:43,770 [lib.api.process] INFO: Option 'pdf' with value '1' sent to monitor
2025-12-06 18:31:43,770 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:31:43,785 [root] DEBUG: Loader: Injecting process 6736 (thread 1168) with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:43,785 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-06 18:31:43,785 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:43,785 [lib.api.process] INFO: Injected into 64-bit <Process 6736 Acrobat.exe>
2025-12-06 18:31:43,785 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Credential Validation" /success:enable /failure:enable
2025-12-06 18:31:43,816 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Service Ticket Operations" /success:enable /failure:enable
2025-12-06 18:31:43,847 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Logon Events" /success:enable /failure:enable
2025-12-06 18:31:43,878 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Authentication Service" /success:enable /failure:enable
2025-12-06 18:31:43,910 [modules.auxiliary.evtx] DEBUG: Wiping Application
2025-12-06 18:31:43,941 [modules.auxiliary.evtx] DEBUG: Wiping HardwareEvents
2025-12-06 18:31:43,957 [modules.auxiliary.evtx] DEBUG: Wiping Internet Explorer
2025-12-06 18:31:43,988 [modules.auxiliary.evtx] DEBUG: Wiping Key Management Service
2025-12-06 18:31:44,019 [modules.auxiliary.evtx] DEBUG: Wiping OAlerts
2025-12-06 18:31:44,050 [modules.auxiliary.evtx] DEBUG: Wiping Security
2025-12-06 18:31:44,082 [modules.auxiliary.evtx] DEBUG: Wiping Setup
2025-12-06 18:31:44,113 [modules.auxiliary.evtx] DEBUG: Wiping System
2025-12-06 18:31:44,144 [modules.auxiliary.evtx] DEBUG: Wiping Windows PowerShell
2025-12-06 18:31:44,176 [modules.auxiliary.evtx] DEBUG: Wiping Microsoft-Windows-Sysmon/Operational
2025-12-06 18:31:45,801 [lib.api.process] INFO: Successfully resumed <Process 6736 Acrobat.exe>
2025-12-06 18:31:45,816 [root] DEBUG: 6736: Python path set to 'C:\Python38'.
2025-12-06 18:31:45,816 [root] INFO: Disabling sleep skipping.
2025-12-06 18:31:45,816 [root] DEBUG: 6736: PDF (Adobe) settings enabled.
2025-12-06 18:31:45,816 [root] DEBUG: 6736: Dropped file limit defaulting to 100.
2025-12-06 18:31:45,832 [root] DEBUG: 6736: YaraInit: Compiled 41 rule files
2025-12-06 18:31:45,832 [root] DEBUG: 6736: YaraInit: Compiled rules saved to file C:\tmpw7hn3wdo\data\yara\capemon.yac
2025-12-06 18:31:45,832 [root] DEBUG: 6736: GetAddressByYara: ModuleBase 0x00007FFAEACB0000 FunctionName RtlInsertInvertedFunctionTable
2025-12-06 18:31:45,848 [root] DEBUG: 6736: RtlInsertInvertedFunctionTable 0x00007FFAEACC090E, LdrpInvertedFunctionTableSRWLock 0x00007FFAEAE1D510
2025-12-06 18:31:45,848 [root] DEBUG: 6736: YaraScan: Scanning 0x00007FF732EF0000, size 0x56d710
2025-12-06 18:31:45,863 [root] DEBUG: Error 5 (0x5) - AmsiDumper: Is CAPE agent running elevated? Initialisation failed: Access is denied.
2025-12-06 18:31:45,863 [root] DEBUG: 6736: Monitor initialised: 64-bit capemon loaded in process 6736 at 0x00007FFAC6D60000, thread 1168, image base 0x00007FF732EF0000, stack from 0x00000092E49F5000-0x00000092E4A00000
2025-12-06 18:31:45,863 [root] DEBUG: 6736: Commandline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\file"
2025-12-06 18:31:45,863 [root] DEBUG: 6736: hook_api: LdrpCallInitRoutine export address 0x00007FFAEACC99BC obtained via GetFunctionAddress
2025-12-06 18:31:45,863 [root] DEBUG: 6736: hook_api: Warning - CoCreateInstance export address 0x00007FFAE9AE42CB differs from GetProcAddress -> 0x00007FFAE912A420 (combase.dll::0x2a420)
2025-12-06 18:31:45,863 [root] DEBUG: 6736: hook_api: Warning - CoCreateInstanceEx export address 0x00007FFAE9AE430A differs from GetProcAddress -> 0x00007FFAE91A4180 (combase.dll::0xa4180)
2025-12-06 18:31:45,863 [root] DEBUG: 6736: hook_api: Warning - CoGetClassObject export address 0x00007FFAE9AE489A differs from GetProcAddress -> 0x00007FFAE912EB00 (combase.dll::0x2eb00)
2025-12-06 18:31:45,879 [root] DEBUG: 6736: hook_api: Warning - CLSIDFromProgID export address 0x00007FFAE9AE3B16 differs from GetProcAddress -> 0x00007FFAE91A8570 (combase.dll::0xa8570)
2025-12-06 18:31:45,879 [root] DEBUG: 6736: hook_api: Warning - CLSIDFromProgIDEx export address 0x00007FFAE9AE3B53 differs from GetProcAddress -> 0x00007FFAE91A8A40 (combase.dll::0xa8a40)
2025-12-06 18:31:45,879 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-06 18:31:45,879 [root] DEBUG: 6736: set_hooks: Unable to hook LockResource
2025-12-06 18:31:45,879 [root] DEBUG: 6736: Hooked 605 out of 606 functions
2025-12-06 18:31:45,879 [root] DEBUG: 6736: Syscall hook installed, syscall logging level 1
2025-12-06 18:31:45,879 [root] INFO: Loaded monitor into process with pid 6736
2025-12-06 18:31:45,879 [root] DEBUG: 6736: YaraScan: Scanning 0x00007FF732EF0000, size 0x56d710
2025-12-06 18:31:45,926 [root] DEBUG: 6736: caller_dispatch: Added region at 0x00007FF732EF0000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x00007FF733205111, thread 1168).
2025-12-06 18:31:45,926 [root] DEBUG: 6736: YaraScan: Scanning 0x00007FF732EF0000, size 0x56d710
2025-12-06 18:31:45,941 [root] DEBUG: 6736: ProcessImageBase: Main module image at 0x00007FF732EF0000 unmodified (entropy change 0.000000e+00)
2025-12-06 18:31:45,941 [root] DEBUG: 6736: DLL loaded at 0x00007FFADAC70000: C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_60b5254171f9507e\Comctl32 (0x29a000 bytes).
2025-12-06 18:31:45,941 [root] DEBUG: 6736: DLL loaded at 0x00007FFAEA620000: C:\Windows\System32\shcore (0xad000 bytes).
2025-12-06 18:31:45,957 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7510000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2025-12-06 18:31:45,957 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD3520000: C:\Windows\SYSTEM32\KBDUS (0x9000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3E50000: C:\Windows\SYSTEM32\VCRUNTIME140 (0x1b000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE5990000: C:\Windows\SYSTEM32\VCRUNTIME140_1 (0xc000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD9580000: C:\Windows\SYSTEM32\MSVCP140 (0x8e000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE83C0000: C:\Windows\System32\cfgmgr32 (0x4e000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAEA800000: C:\Windows\System32\SETUPAPI (0x468000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC5E60000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AGM (0x703000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3E00000: C:\Program Files\Adobe\Acrobat DC\Acrobat\BIB (0x24000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE9E00000: C:\Windows\System32\SHELL32 (0x744000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC6930000: C:\Program Files\Adobe\Acrobat DC\Acrobat\CoolType (0x42a000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD5D90000: C:\Windows\SYSTEM32\dbghelp (0x1e4000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE5F70000: C:\Windows\SYSTEM32\dwmapi (0x2f000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFADF420000: C:\Windows\SYSTEM32\Secur32 (0xc000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC6800000: C:\Program Files\Adobe\Acrobat DC\Acrobat\ACE (0x12e000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3DF0000: C:\Windows\SYSTEM32\SensApi (0xa000 bytes).
2025-12-06 18:31:46,269 [root] DEBUG: 6736: DLL loaded at 0x00000000559D0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat (0x3c27000 bytes).
2025-12-06 18:31:46,285 [root] DEBUG: 6736: DLL loaded at 0x00007FFAEA620000: C:\Windows\System32\shcore (0xad000 bytes).
2025-12-06 18:31:46,285 [root] DEBUG: 6736: set_hooks_by_export_directory: Hooked 0 out of 606 functions
2025-12-06 18:31:46,285 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE6260000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2025-12-06 18:31:46,285 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE8900000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2025-12-06 18:31:46,301 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE5D70000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2025-12-06 18:31:46,301 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE9D30000: C:\Windows\System32\OLEAUT32 (0xcd000 bytes).
2025-12-06 18:31:46,301 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE9B30000: C:\Windows\System32\MSCTF (0x114000 bytes).
2025-12-06 18:31:46,332 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7D70000: C:\Windows\SYSTEM32\Wldp (0x2e000 bytes).
2025-12-06 18:31:46,332 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE6460000: C:\Windows\SYSTEM32\windows.storage (0x793000 bytes).
2025-12-06 18:31:46,332 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE82D0000: C:\Windows\SYSTEM32\profapi (0x1f000 bytes).
2025-12-06 18:31:46,348 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE0D80000: C:\Windows\SYSTEM32\iertutil (0x2b1000 bytes).
2025-12-06 18:31:46,348 [root] DEBUG: 6736: hook_api: NetUserGetInfo export address 0x00007FFADE681F5E obtained via GetFunctionAddress
2025-12-06 18:31:46,348 [root] DEBUG: 6736: hook_api: Warning - NetGetJoinInformation export address 0x00007FFADE680FB3 differs from GetProcAddress -> 0x00007FFAE75516F0 (WKSCLI.DLL::0x16f0)
2025-12-06 18:31:46,348 [root] DEBUG: 6736: hook_api: NetUserGetLocalGroups export address 0x00007FFADE681F8A obtained via GetFunctionAddress
2025-12-06 18:31:46,348 [root] DEBUG: 6736: hook_api: DsEnumerateDomainTrustsW export address 0x00007FFADE67FA1F obtained via GetFunctionAddress
2025-12-06 18:31:46,348 [root] DEBUG: 6736: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:31:46,348 [root] DEBUG: 6736: DLL loaded at 0x00007FFADFE80000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2025-12-06 18:31:46,348 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE8250000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2025-12-06 18:31:46,348 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:31:46,348 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:31:46,363 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:31:46,394 [root] DEBUG: 6736: DLL loaded at 0x00007FFAEA570000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2025-12-06 18:31:46,394 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3EC0000: C:\Windows\SYSTEM32\XmlLite (0x36000 bytes).
2025-12-06 18:31:46,441 [root] DEBUG: 6736: api-rate-cap: RegQueryValueExW hook disabled due to rate
2025-12-06 18:31:46,441 [root] DEBUG: 6736: api-rate-cap: RegEnumValueA hook disabled due to rate
2025-12-06 18:31:46,441 [root] DEBUG: 6736: api-rate-cap: RegQueryValueExW hook disabled due to rate
2025-12-06 18:31:46,457 [root] DEBUG: 6736: api-rate-cap: RegEnumValueA hook disabled due to rate
2025-12-06 18:31:46,457 [root] DEBUG: 6736: api-rate-cap: NtQueryValueKey hook disabled due to rate
2025-12-06 18:31:46,457 [root] DEBUG: 6736: api-rate-cap: NtEnumerateValueKey hook disabled due to rate
2025-12-06 18:31:46,473 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE8250000: C:\Windows\SYSTEM32\USERENV (0x2e000 bytes).
2025-12-06 18:31:46,473 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE2E20000: C:\Windows\SYSTEM32\ColorAdapterClient (0x11000 bytes).
2025-12-06 18:31:46,473 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE2E40000: C:\Windows\SYSTEM32\mscms (0xae000 bytes).
2025-12-06 18:31:46,504 [root] DEBUG: 6736: api-rate-cap: GetKeyboardLayout hook disabled due to rate
2025-12-06 18:31:46,519 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD8CD0000: C:\Windows\SYSTEM32\TextShaping (0xac000 bytes).
2025-12-06 18:31:46,551 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE6C40000: C:\Windows\system32\dxgi (0xf3000 bytes).
2025-12-06 18:31:46,566 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE44C0000: C:\Windows\system32\d3d11 (0x263000 bytes).
2025-12-06 18:31:46,566 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE4E70000: C:\Windows\system32\dcomp (0x1e3000 bytes).
2025-12-06 18:31:46,566 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD1B90000: C:\Windows\system32\dataexchange (0x3e000 bytes).
2025-12-06 18:31:46,582 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3080000: C:\Windows\system32\twinapi.appcore (0x207000 bytes).
2025-12-06 18:31:46,582 [root] DEBUG: 6736: GetEntropy: Error - Supplied address inaccessible: 0x00007DF5BB030000
2025-12-06 18:31:46,582 [root] DEBUG: 6736: AddTrackedRegion: GetEntropy failed.
2025-12-06 18:31:46,582 [root] DEBUG: 6736: caller_dispatch: Added region at 0x00007DF5BB030000 to tracked regions list (ntdll::NtProtectVirtualMemory returns to 0x00007E90ED677BD9, thread 1168).
2025-12-06 18:31:46,582 [root] DEBUG: 6736: ReverseScanForNonZero: Error - Supplied size zero.
2025-12-06 18:31:46,645 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD1880000: C:\Windows\system32\explorerframe (0x220000 bytes).
2025-12-06 18:31:46,645 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE4730000: C:\Windows\SYSTEM32\PROPSYS (0xf6000 bytes).
2025-12-06 18:31:46,660 [root] DEBUG: 6736: DLL loaded at 0x00000000559A0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AXE8SharedExpat (0x2b000 bytes).
2025-12-06 18:31:46,660 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7AD0000: C:\Windows\system32\mswsock (0x6a000 bytes).
2025-12-06 18:31:46,691 [root] DEBUG: 6736: DLL loaded at 0x00007FFACCAC0000: C:\Windows\SYSTEM32\Msftedit (0x348000 bytes).
2025-12-06 18:31:46,707 [root] DEBUG: 6736: DLL loaded at 0x00007FFADD8A0000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2025-12-06 18:31:46,707 [root] DEBUG: 6736: DLL loaded at 0x00007FFADD830000: C:\Windows\System32\bcp47mrm (0x2d000 bytes).
2025-12-06 18:31:46,707 [root] DEBUG: 6736: DLL loaded at 0x00007FFADA610000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2025-12-06 18:31:46,707 [root] DEBUG: 6736: DLL loaded at 0x00007FFADD780000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2025-12-06 18:31:46,722 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE5890000: C:\Windows\System32\CoreMessaging (0xf2000 bytes).
2025-12-06 18:31:46,722 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3F00000: C:\Windows\SYSTEM32\wintypes (0x154000 bytes).
2025-12-06 18:31:46,722 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE51B0000: C:\Windows\System32\CoreUIComponents (0x35e000 bytes).
2025-12-06 18:31:46,722 [root] DEBUG: 6736: DLL loaded at 0x00007FFADCD00000: C:\Windows\SYSTEM32\textinputframework (0xf9000 bytes).
2025-12-06 18:31:46,738 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json
2025-12-06 18:31:47,004 [root] DEBUG: 6736: api-rate-cap: NtQueryKey hook disabled due to rate
2025-12-06 18:31:47,800 [root] DEBUG: 6736: api-rate-cap: NtQueryPerformanceCounter hook disabled due to rate
2025-12-06 18:31:47,847 [root] DEBUG: 6736: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2025-12-06 18:31:47,847 [root] DEBUG: 6736: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2025-12-06 18:31:47,847 [root] DEBUG: 6736: api-rate-cap: NtWaitForSingleObject hook disabled due to rate
2025-12-06 18:31:47,910 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:47,910 [root] DEBUG: 6736: OpenProcessHandler: Injection info created for process 4596, handle 0x67c: Error obtaining target process name
2025-12-06 18:31:49,379 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3DC0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\BIBUtils (0x2b000 bytes).
2025-12-06 18:31:49,394 [root] DEBUG: 6736: api-rate-cap: GetSystemTimeAsFileTime hook disabled due to rate
2025-12-06 18:31:50,348 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD8930000: C:\Program Files\Adobe\Acrobat DC\Acrobat\sqlite (0xa9000 bytes).
2025-12-06 18:31:50,363 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
2025-12-06 18:31:50,363 [root] DEBUG: 6736: CreateProcessHandler: Injection info set for new process 4856: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe, ImageBase: 0x00007FF6A0B60000
2025-12-06 18:31:50,363 [root] INFO: Announced 64-bit process name: AcroCEF.exe pid: 4856
2025-12-06 18:31:50,363 [lib.api.process] INFO: Monitor config for <Process 4856 AcroCEF.exe>: C:\tmpw7hn3wdo\dll\4856.ini
2025-12-06 18:31:50,363 [lib.api.process] INFO: Option 'pdf' with value '1' sent to monitor
2025-12-06 18:31:50,363 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:31:50,363 [root] DEBUG: Loader: Injecting process 4856 (thread 1032) with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:50,363 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-06 18:31:50,363 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:50,363 [lib.api.process] INFO: Injected into 64-bit <Process 4856 AcroCEF.exe>
2025-12-06 18:31:50,363 [root] INFO: Announced 64-bit process name: AcroCEF.exe pid: 4856
2025-12-06 18:31:50,363 [lib.api.process] INFO: Monitor config for <Process 4856 AcroCEF.exe>: C:\tmpw7hn3wdo\dll\4856.ini
2025-12-06 18:31:50,379 [lib.api.process] INFO: Option 'pdf' with value '1' sent to monitor
2025-12-06 18:31:50,379 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:31:50,379 [root] DEBUG: Loader: Injecting process 4856 (thread 1032) with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:50,379 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2025-12-06 18:31:50,379 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:50,379 [lib.api.process] INFO: Injected into 64-bit <Process 4856 AcroCEF.exe>
2025-12-06 18:31:50,379 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7CC0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2025-12-06 18:31:50,379 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE73F0000: C:\Windows\system32\rsaenh (0x34000 bytes).
2025-12-06 18:31:50,394 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE8120000: C:\Windows\SYSTEM32\DPAPI (0xa000 bytes).
2025-12-06 18:31:50,410 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_store
2025-12-06 18:31:50,410 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei
2025-12-06 18:31:50,441 [root] DEBUG: 6736: DLL loaded at 0x00007FFADB390000: C:\Windows\SYSTEM32\msi (0x336000 bytes).
2025-12-06 18:31:50,457 [root] DEBUG: 6736: DLL loaded at 0x0000000055960000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Updater.api (0x31000 bytes).
2025-12-06 18:31:50,473 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING
2025-12-06 18:31:50,473 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE8560000: C:\Windows\System32\WINTRUST (0x67000 bytes).
2025-12-06 18:31:50,488 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7F00000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2025-12-06 18:31:50,504 [root] DEBUG: 6736: DLL loaded at 0x00007FFAEA550000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2025-12-06 18:31:50,566 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE6C10000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2025-12-06 18:31:50,660 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents
2025-12-06 18:31:50,722 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Temp\acroNGLLog.txt
2025-12-06 18:31:50,722 [root] INFO: Announced 64-bit process name: explorer.exe pid: 4596
2025-12-06 18:31:50,722 [lib.api.process] INFO: Monitor config for <Process 4596 explorer.exe>: C:\tmpw7hn3wdo\dll\4596.ini
2025-12-06 18:31:50,722 [lib.api.process] INFO: Option 'pdf' with value '1' sent to monitor
2025-12-06 18:31:50,722 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpw7hn3wdo\dll\nyyFcapj.dll, loader C:\tmpw7hn3wdo\bin\efkAHrkR.exe
2025-12-06 18:31:50,738 [root] DEBUG: Loader: Injecting process 4596 with C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:50,738 [root] DEBUG: 4596: Python path set to 'C:\Python38'.
2025-12-06 18:31:50,738 [root] DEBUG: 4596: Dropped file limit defaulting to 100.
2025-12-06 18:31:50,738 [root] INFO: Disabling sleep skipping.
2025-12-06 18:31:50,738 [root] DEBUG: 4596: YaraInit: Compiled rules loaded from existing file C:\tmpw7hn3wdo\data\yara\capemon.yac
2025-12-06 18:31:50,738 [root] DEBUG: 4596: GetAddressByYara: ModuleBase 0x00007FFAEACB0000 FunctionName RtlInsertInvertedFunctionTable
2025-12-06 18:31:50,754 [root] DEBUG: 4596: RtlInsertInvertedFunctionTable 0x00007FFAEACC090E, LdrpInvertedFunctionTableSRWLock 0x00007FFAEAE1D510
2025-12-06 18:31:50,754 [root] DEBUG: 4596: YaraScan: Scanning 0x00007FF71EBE0000, size 0x50b15a
2025-12-06 18:31:50,785 [root] DEBUG: Error 5 (0x5) - AmsiDumper: Is CAPE agent running elevated? Initialisation failed: Access is denied.
2025-12-06 18:31:50,785 [root] DEBUG: 4596: Monitor initialised: 64-bit capemon loaded in process 4596 at 0x00007FFAC6D60000, thread 4140, image base 0x00007FF71EBE0000, stack from 0x0000000008FE2000-0x0000000008FF0000
2025-12-06 18:31:50,785 [root] DEBUG: 4596: Commandline: C:\Windows\Explorer.EXE
2025-12-06 18:31:50,801 [root] DEBUG: 4596: hook_api: LdrpCallInitRoutine export address 0x00007FFAEACC99BC obtained via GetFunctionAddress
2025-12-06 18:31:50,801 [root] DEBUG: 4596: hook_api: Warning - CoCreateInstance export address 0x00007FFAE9AE42CB differs from GetProcAddress -> 0x00007FFAE912A420 (combase.dll::0x2a420)
2025-12-06 18:31:50,801 [root] DEBUG: 4596: hook_api: Warning - CoCreateInstanceEx export address 0x00007FFAE9AE430A differs from GetProcAddress -> 0x00007FFAE91A4180 (combase.dll::0xa4180)
2025-12-06 18:31:50,801 [root] DEBUG: 4596: hook_api: Warning - CoGetClassObject export address 0x00007FFAE9AE489A differs from GetProcAddress -> 0x00007FFAE912EB00 (combase.dll::0x2eb00)
2025-12-06 18:31:50,816 [root] DEBUG: 4596: hook_api: Warning - CLSIDFromProgID export address 0x00007FFAE9AE3B16 differs from GetProcAddress -> 0x00007FFAE91A8570 (combase.dll::0xa8570)
2025-12-06 18:31:50,816 [root] DEBUG: 4596: hook_api: Warning - CLSIDFromProgIDEx export address 0x00007FFAE9AE3B53 differs from GetProcAddress -> 0x00007FFAE91A8A40 (combase.dll::0xa8a40)
2025-12-06 18:31:50,816 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-06 18:31:50,816 [root] DEBUG: 4596: set_hooks: Unable to hook LockResource
2025-12-06 18:31:50,816 [root] DEBUG: 4596: hook_api: Warning - NetUserGetInfo export address 0x00007FFADE681F5E differs from GetProcAddress -> 0x00007FFADE692C40 (samcli.dll::0x2c40)
2025-12-06 18:31:50,816 [root] DEBUG: 4596: hook_api: Warning - NetGetJoinInformation export address 0x00007FFADE680FB3 differs from GetProcAddress -> 0x00007FFAE75516F0 (wkscli.dll::0x16f0)
2025-12-06 18:31:50,816 [root] DEBUG: 4596: hook_api: Warning - NetUserGetLocalGroups export address 0x00007FFADE681F8A differs from GetProcAddress -> 0x00007FFADE691C60 (samcli.dll::0x1c60)
2025-12-06 18:31:50,816 [root] DEBUG: 4596: hook_api: Warning - DsEnumerateDomainTrustsW export address 0x00007FFADE67FA1F differs from GetProcAddress -> 0x00007FFAE78F8780 (LOGONCLI.DLL::0x18780)
2025-12-06 18:31:50,832 [root] DEBUG: 4596: Hooked 605 out of 606 functions
2025-12-06 18:31:50,832 [root] DEBUG: 4596: Syscall hook installed, syscall logging level 1
2025-12-06 18:31:50,832 [root] INFO: Loaded monitor into process with pid 4596
2025-12-06 18:31:50,832 [root] DEBUG: 4596: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2025-12-06 18:31:50,832 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-12-06 18:31:50,832 [root] DEBUG: Successfully injected DLL C:\tmpw7hn3wdo\dll\nyyFcapj.dll.
2025-12-06 18:31:50,832 [lib.api.process] INFO: Injected into 64-bit <Process 4596 explorer.exe>
2025-12-06 18:31:50,832 [root] DEBUG: 6736: DLL loaded at 0x00007FFADFE80000: C:\Windows\system32\version (0xa000 bytes).
2025-12-06 18:31:50,848 [root] DEBUG: 6736: DLL loaded at 0x00007FFADFE80000: C:\Windows\system32\version (0xa000 bytes).
2025-12-06 18:31:50,848 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:50,848 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:50,848 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:50,848 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:50,848 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:50,848 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:50,848 [lib.api.process] DEBUG: Failed getting exit code for <Process 792 ???>
2025-12-06 18:31:50,848 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:50,848 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:50,848 [lib.api.process] WARNING: failed to open process 792
2025-12-06 18:31:50,848 [lib.api.process] DEBUG: Failed getting image name for pid 792
2025-12-06 18:31:50,848 [lib.api.process] WARNING: the <Process 792 ???> is not alive, injection aborted
2025-12-06 18:31:50,863 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
2025-12-06 18:31:50,879 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal to files\42b3d3d1c522c941afa2a17526c67e8a621cd0518b71d4a69955a67459745fc7; Size is 8720; Max size: 100000000
2025-12-06 18:31:50,879 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
2025-12-06 18:31:50,879 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal to files\0b089a4321ffcadbffe08cef993081a292d1e517fcd86786200a19eb17fa80d0; Size is 8720; Max size: 100000000
2025-12-06 18:31:50,895 [root] DEBUG: 6736: DLL loaded at 0x00007FFADE550000: C:\Windows\SYSTEM32\wbemcomn (0x90000 bytes).
2025-12-06 18:31:50,895 [root] DEBUG: 6736: DLL loaded at 0x00007FFADEBB0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2025-12-06 18:31:50,910 [root] DEBUG: 4596: caller_dispatch: Added region at 0x00007FF71EBE0000 to tracked regions list (msvcrt::memcpy returns to 0x00007FF71EC5A573, thread 4776).
2025-12-06 18:31:50,910 [root] DEBUG: 4596: YaraScan: Scanning 0x00007FF71EBE0000, size 0x50b15a
2025-12-06 18:31:50,910 [root] DEBUG: 6736: DLL loaded at 0x00007FFADD760000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2025-12-06 18:31:50,925 [root] DEBUG: 6736: DLL loaded at 0x00007FFADD900000: C:\Windows\system32\wbem\fastprox (0x10b000 bytes).
2025-12-06 18:31:50,925 [root] DEBUG: 6736: DLL loaded at 0x00007FFADB800000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2025-12-06 18:31:50,925 [root] DEBUG: 6736: DLL loaded at 0x00007FFADB7B0000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2025-12-06 18:31:50,925 [root] DEBUG: 4596: ProcessImageBase: Main module image at 0x00007FF71EBE0000 unmodified (entropy change 0.000000e+00)
2025-12-06 18:31:50,925 [root] DEBUG: 6736: DLL loaded at 0x00007FFADFE80000: C:\Windows\system32\version (0xa000 bytes).
2025-12-06 18:31:50,957 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 6736, handle 0x1f40: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
2025-12-06 18:31:51,913 [root] DEBUG: 6736: api-cap: NtSetInformationFile hook disabled due to count: 5000
2025-12-06 18:31:51,966 [root] DEBUG: 6736: api-cap: NtWriteFile hook disabled due to count: 5000
2025-12-06 18:31:52,410 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD65B0000: C:\Windows\System32\msxml6 (0x25f000 bytes).
2025-12-06 18:31:52,410 [root] DEBUG: 6736: api-rate-cap: memcpy hook disabled due to rate
2025-12-06 18:31:52,527 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Color\Profiles\wscRGB.icc
2025-12-06 18:31:52,558 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Color\Profiles\wsRGB.icc
2025-12-06 18:31:52,558 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Color\ACECache11.lst to files\491c8efdc1b6d519b917ee84b90ec9913a1ac1607b05563da5ff3e4654ea1554; Size is 598; Max size: 100000000
2025-12-06 18:31:52,589 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Adobe\Color\ACECache11.lst
2025-12-06 18:31:52,854 [root] DEBUG: 6736: Dropped file limit reached.
2025-12-06 18:31:52,870 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:52,870 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:52,870 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:52,870 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:52,870 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:52,870 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:52,870 [lib.api.process] DEBUG: Failed getting exit code for <Process 2664 ???>
2025-12-06 18:31:52,870 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:52,870 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:52,870 [lib.api.process] WARNING: failed to open process 2664
2025-12-06 18:31:52,870 [lib.api.process] DEBUG: Failed getting image name for pid 2664
2025-12-06 18:31:52,870 [lib.api.process] WARNING: the <Process 2664 ???> is not alive, injection aborted
2025-12-06 18:31:53,124 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC50E0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeXMP (0x135000 bytes).
2025-12-06 18:31:53,182 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC7780000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.2251_none_91a40448cc8846c1\gdiplus (0x1a5000 bytes).
2025-12-06 18:31:53,186 [root] DEBUG: 6736: DLL loaded at 0x0000000054EF0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Annots.api (0xa67000 bytes).
2025-12-06 18:31:53,213 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE0D80000: C:\Windows\SYSTEM32\iertutil (0x2b1000 bytes).
2025-12-06 18:31:53,214 [root] DEBUG: 6736: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:31:53,216 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:31:53,219 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:31:53,221 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:31:53,233 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE0D80000: C:\Windows\SYSTEM32\iertutil (0x2b1000 bytes).
2025-12-06 18:31:53,234 [root] DEBUG: 6736: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:31:53,238 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:31:53,241 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:31:53,244 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:31:53,273 [root] DEBUG: 6736: DLL loaded at 0x0000000054EA0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\IA32.api (0x44000 bytes).
2025-12-06 18:31:53,279 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD8F00000: C:\Windows\SYSTEM32\WININET (0x4d6000 bytes).
2025-12-06 18:31:53,284 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE0D80000: C:\Windows\SYSTEM32\iertutil (0x2b1000 bytes).
2025-12-06 18:31:53,297 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD7DD0000: C:\Windows\SYSTEM32\ondemandconnroutehelper (0x17000 bytes).
2025-12-06 18:31:53,313 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE77C0000: C:\Windows\SYSTEM32\IPHLPAPI (0x3c000 bytes).
2025-12-06 18:31:53,328 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE9B20000: C:\Windows\System32\NSI (0x8000 bytes).
2025-12-06 18:31:53,330 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE2CB0000: C:\Windows\SYSTEM32\WINNSI (0xb000 bytes).
2025-12-06 18:31:53,334 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE0D10000: C:\Windows\SYSTEM32\dhcpcsvc6 (0x17000 bytes).
2025-12-06 18:31:53,336 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE1640000: C:\Windows\SYSTEM32\dhcpcsvc (0x1d000 bytes).
2025-12-06 18:31:58,287 [root] DEBUG: 4596: api-cap: GetSystemMetrics hook disabled due to count: 5000
2025-12-06 18:31:58,622 [root] DEBUG: 4596: OpenProcessHandler: Image base for process 6736 (handle 0x1f20): 0x00007FF732EF0000.
2025-12-06 18:31:58,622 [root] INFO: Added new file to list with pid None and path C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
2025-12-06 18:31:58,638 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,638 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5976, handle 0x1f4c: Error obtaining target process name
2025-12-06 18:31:58,638 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,638 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 6696, handle 0x1e94: Error obtaining target process name
2025-12-06 18:31:58,638 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,638 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5192, handle 0xffc: Error obtaining target process name
2025-12-06 18:31:58,638 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,638 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5636, handle 0x1edc: Error obtaining target process name
2025-12-06 18:31:58,638 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2025-12-06 18:31:58,638 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 6704, handle 0x1eac: Error obtaining target process name
2025-12-06 18:32:02,022 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 5700, handle 0x1d74: C:\Windows\System32\conhost.exe
2025-12-06 18:32:02,022 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:02,022 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:03,053 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 1572, handle 0x1d74: C:\Windows\System32\conhost.exe
2025-12-06 18:32:03,053 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:03,053 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:04,085 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 1280, handle 0x1208: C:\Windows\System32\conhost.exe
2025-12-06 18:32:04,085 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:04,085 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:05,116 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 4768, handle 0x1f40: C:\Windows\System32\conhost.exe
2025-12-06 18:32:05,132 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:05,132 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:06,163 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 6300, handle 0x1d74: C:\Windows\System32\conhost.exe
2025-12-06 18:32:06,163 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:06,163 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:07,179 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7800000: C:\Windows\SYSTEM32\DNSAPI (0xca000 bytes).
2025-12-06 18:32:07,179 [root] DEBUG: 6736: DLL loaded at 0x00007FFADB2D0000: C:\Windows\System32\rasadhlp (0xa000 bytes).
2025-12-06 18:32:07,538 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 1520, handle 0x1d74: C:\Windows\System32\conhost.exe
2025-12-06 18:32:07,538 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:07,538 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:08,569 [root] DEBUG: 4596: OpenProcessHandler: Injection info created for process 1312, handle 0x1f20: C:\Windows\System32\conhost.exe
2025-12-06 18:32:08,569 [root] INFO: Announced starting service "b'WinHttpAutoProxySvc'"
2025-12-06 18:32:08,569 [root] ERROR: Unable to monitor service b'WinHttpAutoProxySvc'
2025-12-06 18:32:46,553 [root] DEBUG: 4596: OpenProcessHandler: Image base for process 6696 (handle 0x1f2c): 0x00007FF6A14B0000.
2025-12-06 18:32:48,037 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3380000: C:\Windows\System32\WindowManagementAPI (0xa1000 bytes).
2025-12-06 18:32:48,053 [root] DEBUG: 6736: DLL loaded at 0x00007FFADCBA0000: C:\Windows\System32\InputHost (0x152000 bytes).
2025-12-06 18:32:48,053 [root] DEBUG: 6736: DLL loaded at 0x00007FFADCE00000: C:\Windows\System32\Windows.UI (0x141000 bytes).
2025-12-06 18:32:48,631 [root] DEBUG: 6736: DLL loaded at 0x0000025AF4A90000: C:\Program Files\Adobe\Acrobat DC\Acrobat\icudt69 (0x1b87000 bytes).
2025-12-06 18:32:48,646 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC4E60000: C:\Program Files\Adobe\Acrobat DC\Acrobat\icuuc69 (0x27d000 bytes).
2025-12-06 18:32:48,646 [root] DEBUG: 6736: DLL loaded at 0x00007FFAD2010000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeLinguistic (0x8a000 bytes).
2025-12-06 18:32:48,646 [root] DEBUG: 6736: DLL loaded at 0x0000000054E30000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Spelling.api (0x64000 bytes).
2025-12-06 18:32:48,725 [root] DEBUG: 6736: DLL loaded at 0x0000000053BF0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\AXSLE (0xa7000 bytes).
2025-12-06 18:32:48,725 [root] DEBUG: 6736: DLL loaded at 0x0000000053CA0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\AcroForm.api (0x118e000 bytes).
2025-12-06 18:32:48,725 [root] DEBUG: 6736: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:32:48,725 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:32:48,725 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:32:48,740 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:32:48,740 [root] DEBUG: 6736: DLL loaded at 0x00007FFADE670000: C:\Windows\SYSTEM32\NETAPI32 (0x19000 bytes).
2025-12-06 18:32:48,740 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE78D0000: C:\Windows\SYSTEM32\NETUTILS (0xc000 bytes).
2025-12-06 18:32:48,740 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE7550000: C:\Windows\SYSTEM32\WKSCLI (0x19000 bytes).
2025-12-06 18:32:48,740 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC79C0000: C:\Windows\system32\ieframe (0x768000 bytes).
2025-12-06 18:32:48,756 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC4CC0000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\DigSig.api (0x191000 bytes).
2025-12-06 18:32:48,803 [root] DEBUG: 6736: DLL loaded at 0x00007FFAE3DB0000: C:\Windows\SYSTEM32\WSOCK32 (0x9000 bytes).
2025-12-06 18:32:48,803 [root] DEBUG: 6736: DLL loaded at 0x0000000053190000: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\PPKLite.api (0xa5d000 bytes).
2025-12-06 18:32:48,897 [root] DEBUG: 6736: DLL loaded at 0x00007FFAC44D0000: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Providers\Plugins2\AdobeHunspellPlugin\AdobeHunspellPlugin (0x7e7000 bytes).
2025-12-06 18:32:49,694 [root] DEBUG: 4596: api-cap: memcpy hook disabled due to count: 5000
2025-12-06 18:33:51,037 [root] DEBUG: 4596: DLL loaded at 0x00007FFAC7110000: C:\Windows\System32\cdprt (0x1bc000 bytes).
2025-12-06 18:33:51,037 [root] DEBUG: 4596: DLL loaded at 0x00007FFADA610000: C:\Windows\System32\Windows.Globalization (0x1a6000 bytes).
2025-12-06 18:33:51,037 [root] DEBUG: 4596: DLL loaded at 0x00007FFACA650000: C:\Windows\System32\icu (0x22e000 bytes).
2025-12-06 18:34:46,506 [root] INFO: Analysis timeout hit, terminating analysis
2025-12-06 18:34:46,506 [lib.api.process] INFO: Terminate event set for <Process 6736 Acrobat.exe>
2025-12-06 18:34:46,506 [root] DEBUG: 6736: Terminate Event: Attempting to dump process 6736
2025-12-06 18:34:46,506 [root] DEBUG: 6736: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-06 18:34:46,522 [root] DEBUG: 6736: Terminate Event: Current region empty
2025-12-06 18:34:46,522 [lib.api.process] INFO: Termination confirmed for <Process 6736 Acrobat.exe>
2025-12-06 18:34:46,522 [root] INFO: Terminate event set for process 6736
2025-12-06 18:34:46,522 [root] DEBUG: 6736: Terminate Event: CAPE shutdown complete for process 6736
2025-12-06 18:34:46,522 [lib.api.process] INFO: Terminate event set for <Process 4596 explorer.exe>
2025-12-06 18:34:46,522 [root] DEBUG: 4596: Terminate Event: Attempting to dump process 4596
2025-12-06 18:34:46,522 [root] DEBUG: 4596: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-06 18:34:46,522 [root] DEBUG: 4596: Terminate Event: Current region empty
2025-12-06 18:34:46,522 [lib.api.process] INFO: Termination confirmed for <Process 4596 explorer.exe>
2025-12-06 18:34:46,522 [root] DEBUG: 4596: Terminate Event: CAPE shutdown complete for process 4596
2025-12-06 18:34:46,522 [root] INFO: Terminate event set for process 4596
2025-12-06 18:34:46,522 [root] INFO: Created shutdown mutex
2025-12-06 18:34:47,553 [root] INFO: Shutting down package
2025-12-06 18:34:47,553 [root] INFO: Stopping auxiliary modules
2025-12-06 18:34:47,553 [root] INFO: Stopping auxiliary module: Browser
2025-12-06 18:34:47,553 [root] INFO: Stopping auxiliary module: Curtain
2025-12-06 18:34:47,553 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [Errno 13] Permission denied: 'C:\\curtain.log'
2025-12-06 18:34:47,553 [modules.auxiliary.curtain] ERROR: Curtain log file not found!
2025-12-06 18:34:47,553 [root] INFO: Stopping auxiliary module: End_noisy_tasks
2025-12-06 18:34:47,553 [root] INFO: Stopping auxiliary module: Evtx
2025-12-06 18:34:47,553 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Application.evtx to zip dump
2025-12-06 18:34:47,553 [root] WARNING: Cannot terminate auxiliary module Evtx: [Errno 13] Permission denied: 'C:/windows/Sysnative/winevt/Logs\\Application.evtx'
2025-12-06 18:34:47,553 [root] INFO: Stopping auxiliary module: Human
2025-12-06 18:34:57,553 [root] WARNING: Failed to join {aux} thread.
2025-12-06 18:34:57,553 [root] INFO: Stopping auxiliary module: Pre_script
2025-12-06 18:34:57,553 [root] INFO: Stopping auxiliary module: Screenshots
2025-12-06 18:34:59,084 [root] INFO: Stopping auxiliary module: Usage
2025-12-06 18:35:00,006 [root] INFO: Stopping auxiliary module: During_script
2025-12-06 18:35:00,006 [root] INFO: Finishing auxiliary modules
2025-12-06 18:35:00,006 [root] INFO: Shutting down pipe server and dumping dropped files
2025-12-06 18:35:00,006 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json to files\f887b4c2f249b4dab2ea099043477cb8f9dedf6d52a2f4922eb2e251d1813d95; Size is 138; Max size: 100000000
2025-12-06 18:35:00,006 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages to files\83be4623d80ffb402fbdec4125671df532845a3828a1b378d99bd243a4fd8ff2; Size is 57344; Max size: 100000000
2025-12-06 18:35:00,006 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_store to files\5a70a9d1b526743c71c5c2540249f45afbd9bfdced207d483bb917aa37e6636c; Size is 10240; Max size: 100000000
2025-12-06 18:35:00,022 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei to files\f0ea757bad7a1d57600522d4b43b0f6e5a469e73afb08db21dad71b396540888; Size is 24152; Max size: 100000000
2025-12-06 18:35:00,037 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING to files\81ff65efc4487853bdb4625559e69ab44f19e0f5efbd6d5b2af5e3ab267c8e06; Size is 4; Max size: 100000000
2025-12-06 18:35:00,053 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents to files\8497cdbbe1a45567f31b46bdbceafd15a84729aaf6d613979aabac88321fd69b; Size is 12288; Max size: 100000000
2025-12-06 18:35:00,068 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Temp\acroNGLLog.txt to files\0c06d95cc5df3a59b7a64fae3d19d5975b18e14e732d0a14a4433bc152b2c2bc; Size is 5876; Max size: 100000000
2025-12-06 18:35:00,084 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Color\Profiles\wscRGB.icc to files\543ffc63adf5ac065e4aaa417e137c9e58f2a5bc7e1bec8e2cb2bf34f1e5bec3; Size is 66208; Max size: 100000000
2025-12-06 18:35:00,084 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Color\Profiles\wsRGB.icc to files\7222bb8fe431161aea660aa8645d6d4ffbe21af0f5b733a2a48ee0c83a122d36; Size is 2676; Max size: 100000000
2025-12-06 18:35:00,100 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Adobe\Color\ACECache11.lst to files\e0d363bde73b4bcc62f5318ad3223c7c721bc716174a19800c2b8a82b2905fd3; Size is 1148; Max size: 100000000
2025-12-06 18:35:00,115 [lib.common.results] INFO: Uploading file C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat to files\7ab4047101e2ba8d04f95bdc33242687832ad63d7c2fcc899bd36065e6e48d9c; Size is 996; Max size: 100000000
2025-12-06 18:35:00,131 [root] WARNING: Folder at path "C:\HNxZeWN\debugger" does not exist, skipping
2025-12-06 18:35:00,131 [root] WARNING: Folder at path "C:\HNxZeWN\tlsdump" does not exist, skipping
2025-12-06 18:35:00,131 [root] WARNING: Monitor injection attempted but failed for process 4856
2025-12-06 18:35:00,131 [root] INFO: Analysis completed
| Name | Label | Manager | Started On | Shutdown On |
|---|---|---|---|---|
| win10-64bit-tiny-3 | win10-64bit-tiny-3 | KVM | 2025-12-08 14:03:54 | 2025-12-08 14:07:19 |
| File Name |
file
|
|---|---|
| File Type | PDF document, version 1.5 (zip deflate encoded) |
| File Size | 2700109 bytes |
| MD5 | 0d63763441645a884899516f81d284f0 |
| SHA1 | fd1327f2538796d1511cb8a73c7186205294ec69 |
| SHA256 | dd3e1f42d3bf33138068a403e3d673fcb8a993d62fa970321db0e9c822421b43 [VT] [MWDB] [Bazaar] |
| SHA3-384 | 84426106e4143d63bc4ed269ffe943b26cbe87b2971f17c7d91eba86127b33efbf2c894e878c24c37eb099c858493210 |
| CRC32 | 75EB5C3B |
| TLSH | T1A5C5125B8C188B4BE46993F4BF074E9C5B52271CA5C736EB161A8EDF3E502620CCC56E |
| Ssdeep | 49152:9FFgnKwtgXjkQUFUN/VF6bqdOCrb7KTI9eUmQ+RuOZ/:LFgKwt6TUFs/62AwDwUmQ+RuOd |
| File Strings BinGraph Vba2Graph |
| Total Entropy | 7.987597 |
|---|---|
| Entropy In Streams | 7.987247 |
| Entropy Out of Streams | 0.000000 |
| Count of "%% EOF" | 1 |
| PDF Header | %PDF-1.5 |
| Data After EOF | 0 bytes |
| File Size | 2700109 bytes |
| Number of Pages | 4 |
| Keyword | Count |
|---|---|
| obj | 128 |
| endobj | 128 |
| stream | 122 |
| endstream | 122 |
| xref | 0 |
| trailer | 0 |
| startxref | 1 |
| /Page | 4 |
| /Encrypt | 0 |
| /ObjStm | 7 |
| /JS | 0 |
| /JavaScript | 0 |
| /AA | 0 |
| /OpenAction | 0 |
| /AcroForm | 0 |
| /JBIG2Decode | 0 |
| /RichMedia | 0 |
| /Launch | 0 |
| /EmbeddedFile | 0 |
| /XFA | 0 |
| /Colors > 2^24 | 0 |
| Credential Access | Discovery | Defense Evasion | Privilege Escalation | Execution |
|
|
|
|
|---|
No hosts contacted.
No domains contacted.
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP(s) requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP