2025-12-06 18:31:41,676 [root] INFO: Date set to: 20251208T05:45:24, timeout set to: 180
2025-12-06 18:31:41,676 [root] DEBUG: Starting analyzer from: C:\tmpet5am7x7
2025-12-06 18:31:41,676 [root] DEBUG: Storing results at: C:\jcVWCJPBR
2025-12-06 18:31:41,676 [root] DEBUG: Pipe server name: \\.\PIPE\rZGssUMRJ
2025-12-06 18:31:41,676 [root] DEBUG: Python path: C:\Python38
2025-12-06 18:31:41,676 [root] INFO: analysis running as a normal user
2025-12-06 18:31:41,676 [root] INFO: analysis package specified: "exe"
2025-12-06 18:31:41,676 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2025-12-06 18:31:41,676 [root] DEBUG: imported analysis package "exe"
2025-12-06 18:31:41,676 [root] DEBUG: initializing analysis package "exe"...
2025-12-06 18:31:41,676 [lib.common.common] INFO: wrapping
2025-12-06 18:31:41,676 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-06 18:31:41,676 [root] DEBUG: New location of moved file: C:\Users\user\AppData\Local\Temp\notepad.exe
2025-12-06 18:31:41,676 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2025-12-06 18:31:41,676 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2025-12-06 18:31:41,676 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2025-12-06 18:31:41,676 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2025-12-06 18:31:41,692 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-12-06 18:31:41,707 [root] DEBUG: Imported auxiliary module "modules.auxiliary.curtain"
2025-12-06 18:31:41,707 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-12-06 18:31:41,707 [root] DEBUG: Imported auxiliary module "modules.auxiliary.during_script"
2025-12-06 18:31:41,707 [root] DEBUG: Imported auxiliary module "modules.auxiliary.end_noisy_tasks"
2025-12-06 18:31:41,707 [root] DEBUG: Imported auxiliary module "modules.auxiliary.evtx"
2025-12-06 18:31:41,707 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-12-06 18:31:41,707 [root] DEBUG: Imported auxiliary module "modules.auxiliary.pre_script"
2025-12-06 18:31:41,707 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-12-06 18:31:41,723 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2025-12-06 18:31:41,723 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2025-12-06 18:31:41,739 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-12-06 18:31:41,739 [root] DEBUG: Imported auxiliary module "modules.auxiliary.sysmon"
2025-12-06 18:31:41,739 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-12-06 18:31:41,739 [root] DEBUG: Imported auxiliary module "modules.auxiliary.usage"
2025-12-06 18:31:41,739 [root] DEBUG: Initialized auxiliary module "Browser"
2025-12-06 18:31:41,739 [root] DEBUG: attempting to configure 'Browser' from data
2025-12-06 18:31:41,739 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-12-06 18:31:41,739 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-12-06 18:31:41,739 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-12-06 18:31:41,739 [root] DEBUG: Initialized auxiliary module "Curtain"
2025-12-06 18:31:41,739 [root] DEBUG: attempting to configure 'Curtain' from data
2025-12-06 18:31:41,739 [root] DEBUG: module Curtain does not support data configuration, ignoring
2025-12-06 18:31:41,739 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.curtain"...
2025-12-06 18:31:41,739 [root] DEBUG: Started auxiliary module modules.auxiliary.curtain
2025-12-06 18:31:41,739 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-12-06 18:31:41,739 [root] DEBUG: attempting to configure 'Disguise' from data
2025-12-06 18:31:41,739 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-12-06 18:31:41,739 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-12-06 18:31:41,739 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.disguise: [WinError 5] Access is denied
2025-12-06 18:31:41,739 [root] DEBUG: Initialized auxiliary module "End_noisy_tasks"
2025-12-06 18:31:41,739 [root] DEBUG: attempting to configure 'End_noisy_tasks' from data
2025-12-06 18:31:41,739 [root] DEBUG: module End_noisy_tasks does not support data configuration, ignoring
2025-12-06 18:31:41,739 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.end_noisy_tasks"...
2025-12-06 18:31:41,739 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wuauclt.exe
2025-12-06 18:31:41,739 [root] DEBUG: Started auxiliary module modules.auxiliary.end_noisy_tasks
2025-12-06 18:31:41,739 [root] DEBUG: Initialized auxiliary module "Evtx"
2025-12-06 18:31:41,739 [root] DEBUG: attempting to configure 'Evtx' from data
2025-12-06 18:31:41,739 [root] DEBUG: module Evtx does not support data configuration, ignoring
2025-12-06 18:31:41,739 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.evtx"...
2025-12-06 18:31:41,739 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security State Change" /success:enable /failure:enable
2025-12-06 18:31:41,739 [root] DEBUG: Started auxiliary module modules.auxiliary.evtx
2025-12-06 18:31:41,739 [root] DEBUG: Initialized auxiliary module "Human"
2025-12-06 18:31:41,739 [root] DEBUG: attempting to configure 'Human' from data
2025-12-06 18:31:41,739 [root] DEBUG: module Human does not support data configuration, ignoring
2025-12-06 18:31:41,739 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-12-06 18:31:41,739 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-12-06 18:31:41,739 [root] DEBUG: Initialized auxiliary module "Pre_script"
2025-12-06 18:31:41,739 [root] DEBUG: attempting to configure 'Pre_script' from data
2025-12-06 18:31:41,739 [root] DEBUG: module Pre_script does not support data configuration, ignoring
2025-12-06 18:31:41,739 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.pre_script"...
2025-12-06 18:31:41,739 [root] DEBUG: Started auxiliary module modules.auxiliary.pre_script
2025-12-06 18:31:41,739 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-12-06 18:31:41,739 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-12-06 18:31:41,739 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-12-06 18:31:41,739 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-12-06 18:31:41,754 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-12-06 18:31:41,754 [root] DEBUG: Initialized auxiliary module "Sysmon"
2025-12-06 18:31:41,754 [root] DEBUG: attempting to configure 'Sysmon' from data
2025-12-06 18:31:41,754 [root] DEBUG: module Sysmon does not support data configuration, ignoring
2025-12-06 18:31:41,754 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.sysmon"...
2025-12-06 18:31:41,817 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security System Extension" /success:enable /failure:enable
2025-12-06 18:31:41,848 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM wusa.exe
2025-12-06 18:31:41,864 [root] WARNING: Cannot execute auxiliary module modules.auxiliary.sysmon: In order to use the Sysmon functionality, it is required to have the SMaster(64|32).exe file and sysmonconfig-export.xml file in the bin path. Note that the SMaster(64|32).exe files are just the standard Sysmon binaries renamed to avoid anti-analysis detection techniques.
2025-12-06 18:31:41,864 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-12-06 18:31:41,864 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-12-06 18:31:41,864 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-12-06 18:31:41,864 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-12-06 18:31:41,864 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 668
2025-12-06 18:31:41,864 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,864 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,864 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,864 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:41,864 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,864 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:41,864 [lib.api.process] DEBUG: Failed getting exit code for <Process 668 ???>
2025-12-06 18:31:41,864 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,864 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:41,864 [lib.api.process] WARNING: failed to open process 668
2025-12-06 18:31:41,864 [lib.api.process] DEBUG: Failed getting image name for pid 668
2025-12-06 18:31:41,864 [lib.api.process] WARNING: the <Process 668 ???> is not alive, injection aborted
2025-12-06 18:31:41,864 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2025-12-06 18:31:41,864 [root] DEBUG: Initialized auxiliary module "Usage"
2025-12-06 18:31:41,864 [root] DEBUG: attempting to configure 'Usage' from data
2025-12-06 18:31:41,864 [root] DEBUG: module Usage does not support data configuration, ignoring
2025-12-06 18:31:41,864 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.usage"...
2025-12-06 18:31:41,864 [root] DEBUG: Started auxiliary module modules.auxiliary.usage
2025-12-06 18:31:41,864 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"System Integrity" /success:enable /failure:enable
2025-12-06 18:31:41,864 [root] DEBUG: Initialized auxiliary module "During_script"
2025-12-06 18:31:41,864 [root] DEBUG: attempting to configure 'During_script' from data
2025-12-06 18:31:41,864 [root] DEBUG: module During_script does not support data configuration, ignoring
2025-12-06 18:31:41,864 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.during_script"...
2025-12-06 18:31:41,864 [root] DEBUG: Started auxiliary module modules.auxiliary.during_script
2025-12-06 18:31:41,911 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Driver" /success:disable /failure:disable
2025-12-06 18:31:41,911 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM WindowsUpdate.exe
2025-12-06 18:31:41,958 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other System Events" /success:disable /failure:enable
2025-12-06 18:31:41,973 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM GoogleUpdate.exe
2025-12-06 18:31:42,004 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logon" /success:enable /failure:enable
2025-12-06 18:31:42,035 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Logoff" /success:enable /failure:enable
2025-12-06 18:31:42,035 [modules.auxiliary.end_noisy_tasks] DEBUG: taskkill /f /IM MicrosoftEdgeUpdate.exe
2025-12-06 18:31:42,067 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Account Lockout" /success:enable /failure:enable
2025-12-06 18:31:42,082 [root] INFO: Restarting WMI Service
2025-12-06 18:31:42,113 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Main Mode" /success:disable /failure:disable
2025-12-06 18:31:42,113 [root] DEBUG: package modules.packages.exe does not support configure, ignoring
2025-12-06 18:31:42,129 [root] WARNING: configuration error for package modules.packages.exe: error importing data.packages.exe: No module named 'data.packages'
2025-12-06 18:31:42,129 [lib.core.compound] INFO: C:\Users\user\AppData\Local\Temp already exists, skipping creation
2025-12-06 18:31:42,129 [lib.api.process] INFO: Successfully executed process from path "C:\Users\user\AppData\Local\Temp\notepad.exe" with arguments "" with pid 5680
2025-12-06 18:31:42,129 [lib.api.process] INFO: Monitor config for <Process 5680 notepad.exe>: C:\tmpet5am7x7\dll\5680.ini
2025-12-06 18:31:42,129 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpet5am7x7\dll\IklxUPDo.dll, loader C:\tmpet5am7x7\bin\GFMSQHhy.exe
2025-12-06 18:31:42,145 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DisableWindowsUpdateAccess /t REG_DWORD /d 1 /f
2025-12-06 18:31:42,145 [root] DEBUG: Loader: Injecting process 5680 (thread 3564) with C:\tmpet5am7x7\dll\IklxUPDo.dll.
2025-12-06 18:31:42,145 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2025-12-06 18:31:42,145 [root] DEBUG: Successfully injected DLL C:\tmpet5am7x7\dll\IklxUPDo.dll.
2025-12-06 18:31:42,145 [lib.api.process] INFO: Injected into 64-bit <Process 5680 notepad.exe>
2025-12-06 18:31:42,145 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Quick Mode" /success:disable /failure:disable
2025-12-06 18:31:42,176 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f
2025-12-06 18:31:42,176 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"IPsec Extended Mode" /success:disable /failure:disable
2025-12-06 18:31:42,207 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Logon/Logoff Events" /success:enable /failure:enable
2025-12-06 18:31:42,223 [modules.auxiliary.end_noisy_tasks] DEBUG: Command executed with exit code 1: reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters" /v EnableICMPRedirect /t REG_DWORD /d 0 /f
2025-12-06 18:31:42,238 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable
2025-12-06 18:31:42,270 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Special Logon" /success:enable /failure:enable
2025-12-06 18:31:42,301 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File System" /success:enable /failure:enable
2025-12-06 18:31:42,317 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Registry" /success:enable /failure:enable
2025-12-06 18:31:42,348 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kernel Object" /success:enable /failure:enable
2025-12-06 18:31:42,379 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"SAM" /success:disable /failure:disable
2025-12-06 18:31:42,410 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Certification Services" /success:enable /failure:enable
2025-12-06 18:31:42,442 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Handle Manipulation" /success:disable /failure:disable
2025-12-06 18:31:42,457 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable
2025-12-06 18:31:42,489 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"File Share" /success:enable /failure:enable
2025-12-06 18:31:42,520 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Packet Drop" /success:disable /failure:disable
2025-12-06 18:31:42,551 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Connection" /success:disable /failure:disable
2025-12-06 18:31:42,567 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Object Access Events" /success:disable /failure:disable
2025-12-06 18:31:42,598 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Sensitive Privilege Use" /success:disable /failure:disable
2025-12-06 18:31:42,629 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Non Sensitive Privilege Use" /success:disable /failure:disable
2025-12-06 18:31:42,645 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Privilege Use Events" /success:disable /failure:disable
2025-12-06 18:31:42,676 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"RPC Events" /success:enable /failure:enable
2025-12-06 18:31:42,707 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Audit Policy Change" /success:enable /failure:enable
2025-12-06 18:31:42,739 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Authentication Policy Change" /success:enable /failure:enable
2025-12-06 18:31:42,770 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"MPSSVC Rule-Level Policy Change" /success:disable /failure:disable
2025-12-06 18:31:42,785 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Filtering Platform Policy Change" /success:disable /failure:disable
2025-12-06 18:31:42,817 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Policy Change Events" /success:disable /failure:enable
2025-12-06 18:31:42,848 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"User Account Management" /success:enable /failure:enable
2025-12-06 18:31:42,879 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Computer Account Management" /success:enable /failure:enable
2025-12-06 18:31:42,895 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Security Group Management" /success:enable /failure:enable
2025-12-06 18:31:42,926 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Distribution Group Management" /success:enable /failure:enable
2025-12-06 18:31:42,957 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Application Group Management" /success:enable /failure:enable
2025-12-06 18:31:42,989 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Management Events" /success:enable /failure:enable
2025-12-06 18:31:43,004 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Access" /success:enable /failure:enable
2025-12-06 18:31:43,036 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Changes" /success:enable /failure:enable
2025-12-06 18:31:43,067 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Directory Service Replication" /success:disable /failure:enable
2025-12-06 18:31:43,098 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Detailed Directory Service Replication" /success:disable /failure:disable
2025-12-06 18:31:43,114 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Credential Validation" /success:enable /failure:enable
2025-12-06 18:31:43,145 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Service Ticket Operations" /success:enable /failure:enable
2025-12-06 18:31:43,176 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Other Account Logon Events" /success:enable /failure:enable
2025-12-06 18:31:43,192 [modules.auxiliary.evtx] DEBUG: Enabling advanced logging -> auditpol /set /subcategory:"Kerberos Authentication Service" /success:enable /failure:enable
2025-12-06 18:31:43,223 [modules.auxiliary.evtx] DEBUG: Wiping Application
2025-12-06 18:31:43,254 [modules.auxiliary.evtx] DEBUG: Wiping HardwareEvents
2025-12-06 18:31:43,270 [modules.auxiliary.evtx] DEBUG: Wiping Internet Explorer
2025-12-06 18:31:43,301 [modules.auxiliary.evtx] DEBUG: Wiping Key Management Service
2025-12-06 18:31:43,332 [modules.auxiliary.evtx] DEBUG: Wiping OAlerts
2025-12-06 18:31:43,348 [modules.auxiliary.evtx] DEBUG: Wiping Security
2025-12-06 18:31:43,379 [modules.auxiliary.evtx] DEBUG: Wiping Setup
2025-12-06 18:31:43,410 [modules.auxiliary.evtx] DEBUG: Wiping System
2025-12-06 18:31:43,426 [modules.auxiliary.evtx] DEBUG: Wiping Windows PowerShell
2025-12-06 18:31:43,457 [modules.auxiliary.evtx] DEBUG: Wiping Microsoft-Windows-Sysmon/Operational
2025-12-06 18:31:44,160 [lib.api.process] INFO: Successfully resumed <Process 5680 notepad.exe>
2025-12-06 18:31:44,176 [root] DEBUG: 5680: Python path set to 'C:\Python38'.
2025-12-06 18:31:44,176 [root] INFO: Disabling sleep skipping.
2025-12-06 18:31:44,176 [root] DEBUG: 5680: Dropped file limit defaulting to 100.
2025-12-06 18:31:44,176 [root] DEBUG: 5680: YaraInit: Compiled 41 rule files
2025-12-06 18:31:44,176 [root] DEBUG: 5680: YaraInit: Compiled rules saved to file C:\tmpet5am7x7\data\yara\capemon.yac
2025-12-06 18:31:44,176 [root] DEBUG: 5680: GetAddressByYara: ModuleBase 0x00007FF978DB0000 FunctionName RtlInsertInvertedFunctionTable
2025-12-06 18:31:44,192 [root] DEBUG: 5680: RtlInsertInvertedFunctionTable 0x00007FF978DC090E, LdrpInvertedFunctionTableSRWLock 0x00007FF978F1D510
2025-12-06 18:31:44,192 [root] DEBUG: 5680: YaraScan: Scanning 0x00007FF792220000, size 0x372d6
2025-12-06 18:31:44,192 [root] DEBUG: Error 5 (0x5) - AmsiDumper: Is CAPE agent running elevated? Initialisation failed: Access is denied.
2025-12-06 18:31:44,192 [root] DEBUG: 5680: Monitor initialised: 64-bit capemon loaded in process 5680 at 0x00007FF9550C0000, thread 3564, image base 0x00007FF792220000, stack from 0x0000009C5586F000-0x0000009C55880000
2025-12-06 18:31:44,192 [root] DEBUG: 5680: Commandline: "C:\Users\user\AppData\Local\Temp\notepad.exe"
2025-12-06 18:31:44,207 [root] DEBUG: 5680: hook_api: LdrpCallInitRoutine export address 0x00007FF978DC99BC obtained via GetFunctionAddress
2025-12-06 18:31:44,207 [root] DEBUG: 5680: hook_api: Warning - CoCreateInstance export address 0x00007FF9775F42CB differs from GetProcAddress -> 0x00007FF97782A420 (combase.dll::0x2a420)
2025-12-06 18:31:44,207 [root] DEBUG: 5680: hook_api: Warning - CoCreateInstanceEx export address 0x00007FF9775F430A differs from GetProcAddress -> 0x00007FF9778A4180 (combase.dll::0xa4180)
2025-12-06 18:31:44,207 [root] DEBUG: 5680: hook_api: Warning - CoGetClassObject export address 0x00007FF9775F489A differs from GetProcAddress -> 0x00007FF97782EB00 (combase.dll::0x2eb00)
2025-12-06 18:31:44,207 [root] DEBUG: 5680: hook_api: Warning - CLSIDFromProgID export address 0x00007FF9775F3B16 differs from GetProcAddress -> 0x00007FF9778A8570 (combase.dll::0xa8570)
2025-12-06 18:31:44,207 [root] DEBUG: 5680: hook_api: Warning - CLSIDFromProgIDEx export address 0x00007FF9775F3B53 differs from GetProcAddress -> 0x00007FF9778A8A40 (combase.dll::0xa8a40)
2025-12-06 18:31:44,207 [root] WARNING: b'Unable to place hook on LockResource'
2025-12-06 18:31:44,207 [root] DEBUG: 5680: set_hooks: Unable to hook LockResource
2025-12-06 18:31:44,223 [root] DEBUG: 5680: Hooked 605 out of 606 functions
2025-12-06 18:31:44,223 [root] DEBUG: 5680: Syscall hook installed, syscall logging level 1
2025-12-06 18:31:44,223 [root] INFO: Loaded monitor into process with pid 5680
2025-12-06 18:31:44,223 [root] DEBUG: 5680: caller_dispatch: Added region at 0x00007FF792220000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF7922439C9, thread 3564).
2025-12-06 18:31:44,223 [root] DEBUG: 5680: YaraScan: Scanning 0x00007FF792220000, size 0x372d6
2025-12-06 18:31:44,223 [root] DEBUG: 5680: ProcessImageBase: Main module image at 0x00007FF792220000 unmodified (entropy change 0.000000e+00)
2025-12-06 18:31:44,223 [root] DEBUG: 5680: DLL loaded at 0x00007FF976A00000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2025-12-06 18:31:44,223 [root] DEBUG: 5680: set_hooks_by_export_directory: Hooked 0 out of 606 functions
2025-12-06 18:31:44,223 [root] DEBUG: 5680: DLL loaded at 0x00007FF974360000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2025-12-06 18:31:44,223 [root] DEBUG: 5680: DLL loaded at 0x00007FF973E70000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2025-12-06 18:31:44,223 [root] DEBUG: 5680: DLL loaded at 0x00007FF977E40000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2025-12-06 18:31:44,238 [root] DEBUG: 5680: DLL loaded at 0x00007FF96A6C0000: C:\Windows\System32\MrmCoreR (0xf4000 bytes).
2025-12-06 18:31:44,254 [root] DEBUG: 5680: NtTerminateProcess hook: Attempting to dump process 5680
2025-12-06 18:31:44,254 [root] DEBUG: 5680: DoProcessDump: Skipping process dump as code is identical on disk.
2025-12-06 18:31:44,254 [root] INFO: Process with pid 5680 has terminated
2025-12-06 18:31:50,254 [root] INFO: Process list is empty, terminating analysis
2025-12-06 18:31:51,270 [root] INFO: Created shutdown mutex
2025-12-06 18:31:52,285 [root] INFO: Shutting down package
2025-12-06 18:31:52,285 [root] INFO: Stopping auxiliary modules
2025-12-06 18:31:52,285 [root] INFO: Stopping auxiliary module: Browser
2025-12-06 18:31:52,285 [root] INFO: Stopping auxiliary module: Curtain
2025-12-06 18:31:52,285 [modules.auxiliary.curtain] ERROR: Curtain - Error collecting PowerShell events - [Errno 13] Permission denied: 'C:\\curtain.log'
2025-12-06 18:31:52,285 [modules.auxiliary.curtain] ERROR: Curtain log file not found!
2025-12-06 18:31:52,285 [root] INFO: Stopping auxiliary module: End_noisy_tasks
2025-12-06 18:31:52,285 [root] INFO: Stopping auxiliary module: Evtx
2025-12-06 18:31:52,285 [modules.auxiliary.evtx] DEBUG: Adding C:/windows/Sysnative/winevt/Logs\Application.evtx to zip dump
2025-12-06 18:31:52,285 [root] WARNING: Cannot terminate auxiliary module Evtx: [Errno 13] Permission denied: 'C:/windows/Sysnative/winevt/Logs\\Application.evtx'
2025-12-06 18:31:52,285 [root] INFO: Stopping auxiliary module: Human
2025-12-06 18:31:54,160 [root] INFO: Stopping auxiliary module: Pre_script
2025-12-06 18:31:54,160 [root] INFO: Stopping auxiliary module: Screenshots
2025-12-06 18:31:56,879 [root] INFO: Stopping auxiliary module: Usage
2025-12-06 18:31:57,989 [root] INFO: Stopping auxiliary module: During_script
2025-12-06 18:31:57,989 [root] INFO: Finishing auxiliary modules
2025-12-06 18:31:57,989 [root] INFO: Shutting down pipe server and dumping dropped files
2025-12-06 18:31:57,989 [root] WARNING: Folder at path "C:\jcVWCJPBR\debugger" does not exist, skipping
2025-12-06 18:31:57,989 [root] WARNING: Folder at path "C:\jcVWCJPBR\tlsdump" does not exist, skipping
2025-12-06 18:31:57,989 [root] INFO: Analysis completed