2024-11-25 13:37:15,678 [root] INFO: Date set to: 20250611T17:34:19, timeout set to: 1800
2025-06-11 18:34:19,177 [root] DEBUG: Starting analyzer from: C:\tmpjeo7jmad
2025-06-11 18:34:19,177 [root] DEBUG: Storing results at: C:\uyHCokWh
2025-06-11 18:34:19,177 [root] DEBUG: Pipe server name: \\.\PIPE\IpEgLKC
2025-06-11 18:34:19,192 [root] DEBUG: Python path: C:\Users\Packager\AppData\Local\Programs\Python\Python310-32
2025-06-11 18:34:19,192 [root] INFO: analysis running as an admin
2025-06-11 18:34:19,192 [root] INFO: analysis package specified: "exe"
2025-06-11 18:34:19,192 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2025-06-11 18:34:20,067 [root] DEBUG: imported analysis package "exe"
2025-06-11 18:34:20,067 [root] DEBUG: initializing analysis package "exe"...
2025-06-11 18:34:20,067 [lib.common.common] INFO: wrapping
2025-06-11 18:34:20,067 [lib.core.compound] INFO: C:\Users\Packager\AppData\Local\Temp already exists, skipping creation
2025-06-11 18:34:20,067 [root] DEBUG: New location of moved file: C:\Users\Packager\AppData\Local\Temp\BluetoothLogView.exe
2025-06-11 18:34:20,067 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2025-06-11 18:34:20,067 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2025-06-11 18:34:20,067 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2025-06-11 18:34:20,067 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2025-06-11 18:34:20,223 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-06-11 18:34:20,317 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2025-06-11 18:34:20,349 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-06-11 18:34:20,364 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-06-11 18:34:20,380 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-06-11 18:34:20,380 [lib.api.screenshot] ERROR: No module named 'PIL'
2025-06-11 18:34:20,380 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-06-11 18:34:20,396 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-06-11 18:34:20,396 [root] DEBUG: Initialized auxiliary module "Browser"
2025-06-11 18:34:20,396 [root] DEBUG: attempting to configure 'Browser' from data
2025-06-11 18:34:20,396 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-06-11 18:34:20,396 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-06-11 18:34:20,396 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-06-11 18:34:20,396 [root] DEBUG: Initialized auxiliary module "DigiSig"
2025-06-11 18:34:20,396 [root] DEBUG: attempting to configure 'DigiSig' from data
2025-06-11 18:34:20,396 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2025-06-11 18:34:20,396 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2025-06-11 18:34:20,396 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2025-06-11 18:34:42,770 [modules.auxiliary.digisig] DEBUG: File has a valid signature
2025-06-11 18:34:42,770 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2025-06-11 18:34:42,770 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2025-06-11 18:34:42,770 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-06-11 18:34:42,770 [root] DEBUG: attempting to configure 'Disguise' from data
2025-06-11 18:34:42,770 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-06-11 18:34:42,786 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-06-11 18:34:42,786 [modules.auxiliary.disguise] INFO: Disguising GUID to 88063f41-cb09-49fe-8433-82e8a31757b9
2025-06-11 18:34:42,786 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2025-06-11 18:34:42,786 [root] DEBUG: Initialized auxiliary module "Human"
2025-06-11 18:34:42,786 [root] DEBUG: attempting to configure 'Human' from data
2025-06-11 18:34:42,786 [root] DEBUG: module Human does not support data configuration, ignoring
2025-06-11 18:34:42,786 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-06-11 18:34:42,786 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-06-11 18:34:42,786 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-06-11 18:34:42,786 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-06-11 18:34:42,786 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-06-11 18:34:42,786 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-06-11 18:34:42,786 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2025-06-11 18:34:42,786 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-06-11 18:34:42,786 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-06-11 18:34:42,786 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-06-11 18:34:42,786 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-06-11 18:34:42,786 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-06-11 18:34:42,786 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 696
2025-06-11 18:34:42,817 [lib.api.process] INFO: Monitor config for <Process 696 lsass.exe>: C:\tmpjeo7jmad\dll\696.ini
2025-06-11 18:34:42,817 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2025-06-11 18:34:42,817 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2025-06-11 18:34:42,817 [lib.api.process] INFO: Option 'unpacker' with value '2' sent to monitor
2025-06-11 18:34:42,817 [lib.api.process] INFO: Option 'norefer' with value '1' sent to monitor
2025-06-11 18:34:42,817 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2025-06-11 18:34:42,817 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2025-06-11 18:34:42,817 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpjeo7jmad\dll\pQxbIz.dll, loader C:\tmpjeo7jmad\bin\EPCPTrhb.exe
2025-06-11 18:34:42,880 [root] DEBUG: Loader: IAT patching disabled.
2025-06-11 18:34:42,880 [root] DEBUG: Loader: Injecting process 696 with C:\tmpjeo7jmad\dll\pQxbIz.dll.
2025-06-11 18:34:42,880 [root] DEBUG: 696: Python path set to 'C:\Users\Packager\AppData\Local\Programs\Python\Python310-32'.
2025-06-11 18:34:42,880 [root] INFO: Disabling sleep skipping.
2025-06-11 18:34:42,880 [root] DEBUG: 696: Full process memory dumps enabled.
2025-06-11 18:34:42,880 [root] DEBUG: 696: Import reconstruction of process dumps enabled.
2025-06-11 18:34:42,880 [root] DEBUG: 696: Active unpacking of payloads enabled
2025-06-11 18:34:42,880 [root] DEBUG: 696: CAPE debug - unrecognised key norefer.
2025-06-11 18:34:42,880 [root] DEBUG: 696: TLS secret dump mode enabled.
2025-06-11 18:34:42,880 [root] DEBUG: 696: InternalYaraScan: Scanning 0x00007FF84A790000, size 0x1f4542
2025-06-11 18:34:42,895 [root] DEBUG: 696: InternalYaraScan hit: RtlInsertInvertedFunctionTable
2025-06-11 18:34:42,895 [root] DEBUG: 696: RtlInsertInvertedFunctionTable 0x00007FF84A7A090E, LdrpInvertedFunctionTableSRWLock 0x00007FF84A8FB4F0
2025-06-11 18:34:42,895 [root] DEBUG: 696: Monitor initialised: 64-bit capemon loaded in process 696 at 0x00007FF822E30000, thread 3612, image base 0x00007FF60D500000, stack from 0x0000008EFABF4000-0x0000008EFAC00000
2025-06-11 18:34:42,895 [root] DEBUG: 696: Commandline: C:\Windows\system32\lsass.exe
2025-06-11 18:34:42,911 [root] DEBUG: 696: Hooked 5 out of 5 functions
2025-06-11 18:34:42,911 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-06-11 18:34:42,911 [root] DEBUG: Successfully injected DLL C:\tmpjeo7jmad\dll\pQxbIz.dll.
2025-06-11 18:34:42,911 [lib.api.process] INFO: Injected into 64-bit <Process 696 lsass.exe>
2025-06-11 18:34:4 <truncated>