2024-11-25 13:37:15,850 [root] INFO: Date set to: 20250613T09:46:42, timeout set to: 1800
2025-06-13 10:46:42,011 [root] DEBUG: Starting analyzer from: C:\tmp_gell1p8
2025-06-13 10:46:42,011 [root] DEBUG: Storing results at: C:\pvZafqQC
2025-06-13 10:46:42,011 [root] DEBUG: Pipe server name: \\.\PIPE\xVrVnxQMgC
2025-06-13 10:46:42,011 [root] DEBUG: Python path: C:\Users\Packager\AppData\Local\Programs\Python\Python310-32
2025-06-13 10:46:42,011 [root] INFO: analysis running as an admin
2025-06-13 10:46:42,011 [root] INFO: analysis package specified: "exe"
2025-06-13 10:46:42,011 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2025-06-13 10:46:43,011 [root] DEBUG: imported analysis package "exe"
2025-06-13 10:46:43,011 [root] DEBUG: initializing analysis package "exe"...
2025-06-13 10:46:43,011 [lib.common.common] INFO: wrapping
2025-06-13 10:46:43,011 [lib.core.compound] INFO: C:\Users\Packager\AppData\Local\Temp already exists, skipping creation
2025-06-13 10:46:43,011 [root] DEBUG: New location of moved file: C:\Users\Packager\AppData\Local\Temp\HostedNetworkStarter.exe
2025-06-13 10:46:43,011 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2025-06-13 10:46:43,011 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2025-06-13 10:46:43,011 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2025-06-13 10:46:43,011 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2025-06-13 10:46:43,370 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-06-13 10:46:43,386 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2025-06-13 10:46:43,433 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-06-13 10:46:43,433 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-06-13 10:46:43,449 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-06-13 10:46:43,449 [lib.api.screenshot] ERROR: No module named 'PIL'
2025-06-13 10:46:43,449 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-06-13 10:46:43,464 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-06-13 10:46:43,464 [root] DEBUG: Initialized auxiliary module "Browser"
2025-06-13 10:46:43,464 [root] DEBUG: attempting to configure 'Browser' from data
2025-06-13 10:46:43,464 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-06-13 10:46:43,464 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-06-13 10:46:43,464 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-06-13 10:46:43,464 [root] DEBUG: Initialized auxiliary module "DigiSig"
2025-06-13 10:46:43,464 [root] DEBUG: attempting to configure 'DigiSig' from data
2025-06-13 10:46:43,464 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2025-06-13 10:46:43,464 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2025-06-13 10:46:43,464 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2025-06-13 10:47:05,933 [modules.auxiliary.digisig] DEBUG: File has a valid signature
2025-06-13 10:47:05,933 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2025-06-13 10:47:05,933 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2025-06-13 10:47:05,933 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-06-13 10:47:05,933 [root] DEBUG: attempting to configure 'Disguise' from data
2025-06-13 10:47:05,933 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-06-13 10:47:05,933 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-06-13 10:47:05,933 [modules.auxiliary.disguise] INFO: Disguising GUID to e814d3e1-5b30-4eac-90d1-5340f2022e3d
2025-06-13 10:47:05,933 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2025-06-13 10:47:05,933 [root] DEBUG: Initialized auxiliary module "Human"
2025-06-13 10:47:05,933 [root] DEBUG: attempting to configure 'Human' from data
2025-06-13 10:47:05,933 [root] DEBUG: module Human does not support data configuration, ignoring
2025-06-13 10:47:05,933 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-06-13 10:47:05,933 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-06-13 10:47:05,933 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-06-13 10:47:05,933 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-06-13 10:47:05,933 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-06-13 10:47:05,933 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-06-13 10:47:05,949 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2025-06-13 10:47:05,949 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-06-13 10:47:05,949 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-06-13 10:47:05,949 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-06-13 10:47:05,949 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-06-13 10:47:05,949 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-06-13 10:47:05,949 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 696
2025-06-13 10:47:05,964 [lib.api.process] INFO: Monitor config for <Process 696 lsass.exe>: C:\tmp_gell1p8\dll\696.ini
2025-06-13 10:47:05,964 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2025-06-13 10:47:05,964 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2025-06-13 10:47:05,964 [lib.api.process] INFO: Option 'unpacker' with value '2' sent to monitor
2025-06-13 10:47:05,980 [lib.api.process] INFO: Option 'norefer' with value '1' sent to monitor
2025-06-13 10:47:05,980 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2025-06-13 10:47:05,980 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2025-06-13 10:47:05,980 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmp_gell1p8\dll\lTUiRm.dll, loader C:\tmp_gell1p8\bin\uQchymxO.exe
2025-06-13 10:47:06,042 [root] DEBUG: Loader: IAT patching disabled.
2025-06-13 10:47:06,042 [root] DEBUG: Loader: Injecting process 696 with C:\tmp_gell1p8\dll\lTUiRm.dll.
2025-06-13 10:47:06,042 [root] DEBUG: 696: Python path set to 'C:\Users\Packager\AppData\Local\Programs\Python\Python310-32'.
2025-06-13 10:47:06,042 [root] INFO: Disabling sleep skipping.
2025-06-13 10:47:06,042 [root] DEBUG: 696: Full process memory dumps enabled.
2025-06-13 10:47:06,042 [root] DEBUG: 696: Import reconstruction of process dumps enabled.
2025-06-13 10:47:06,042 [root] DEBUG: 696: Active unpacking of payloads enabled
2025-06-13 10:47:06,042 [root] DEBUG: 696: CAPE debug - unrecognised key norefer.
2025-06-13 10:47:06,058 [root] DEBUG: 696: TLS secret dump mode enabled.
2025-06-13 10:47:06,058 [root] DEBUG: 696: InternalYaraScan: Scanning 0x00007FF84A790000, size 0x1f4542
2025-06-13 10:47:06,058 [root] DEBUG: 696: InternalYaraScan hit: RtlInsertInvertedFunctionTable
2025-06-13 10:47:06,073 [root] DEBUG: 696: RtlInsertInvertedFunctionTable 0x00007FF84A7A090E, LdrpInvertedFunctionTableSRWLock 0x00007FF84A8FB4F0
2025-06-13 10:47:06,073 [root] DEBUG: 696: Monitor initialised: 64-bit capemon loaded in process 696 at 0x00007FF822E30000, thread 6620, image base 0x00007FF60D500000, stack from 0x0000008EFABF4000-0x0000008EFAC00000
2025-06-13 10:47:06,073 [root] DEBUG: 696: Commandline: C:\Windows\system32\lsass.exe
2025-06-13 10:47:06,073 [root] DEBUG: 696: Hooked 5 out of 5 functions
2025-06-13 10:47:06,089 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-06-13 10:47:06,089 [root] DEBUG: Successfully injected DLL C:\tmp_gell1p8\dll\lTUiRm.dll.
2025-06-13 10:47:06,089 [lib.api.process] INFO: Injected into 64-bit <Process 696 lsass.exe>
2025-06-13 <truncated>