2024-11-25 13:37:15,131 [root] INFO: Date set to: 20250614T06:48:11, timeout set to: 1800
2025-06-14 07:48:11,203 [root] DEBUG: Starting analyzer from: C:\tmpjeo7jmad
2025-06-14 07:48:11,203 [root] DEBUG: Storing results at: C:\YrpKBC
2025-06-14 07:48:11,203 [root] DEBUG: Pipe server name: \\.\PIPE\MhEpmg
2025-06-14 07:48:11,203 [root] DEBUG: Python path: C:\Users\Packager\AppData\Local\Programs\Python\Python310-32
2025-06-14 07:48:11,203 [root] INFO: analysis running as an admin
2025-06-14 07:48:11,203 [root] INFO: analysis package specified: "exe"
2025-06-14 07:48:11,203 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2025-06-14 07:48:12,219 [root] DEBUG: imported analysis package "exe"
2025-06-14 07:48:12,219 [root] DEBUG: initializing analysis package "exe"...
2025-06-14 07:48:12,219 [lib.common.common] INFO: wrapping
2025-06-14 07:48:12,219 [lib.core.compound] INFO: C:\Users\Packager\AppData\Local\Temp already exists, skipping creation
2025-06-14 07:48:12,235 [root] DEBUG: New location of moved file: C:\Users\Packager\AppData\Local\Temp\Tango_Logger.exe
2025-06-14 07:48:12,235 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2025-06-14 07:48:12,235 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2025-06-14 07:48:12,235 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2025-06-14 07:48:12,235 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2025-06-14 07:48:12,485 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2025-06-14 07:48:12,532 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2025-06-14 07:48:12,579 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2025-06-14 07:48:12,579 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2025-06-14 07:48:12,594 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2025-06-14 07:48:12,594 [lib.api.screenshot] ERROR: No module named 'PIL'
2025-06-14 07:48:12,594 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2025-06-14 07:48:12,610 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2025-06-14 07:48:12,610 [root] DEBUG: Initialized auxiliary module "Browser"
2025-06-14 07:48:12,610 [root] DEBUG: attempting to configure 'Browser' from data
2025-06-14 07:48:12,610 [root] DEBUG: module Browser does not support data configuration, ignoring
2025-06-14 07:48:12,610 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2025-06-14 07:48:12,610 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2025-06-14 07:48:12,610 [root] DEBUG: Initialized auxiliary module "DigiSig"
2025-06-14 07:48:12,610 [root] DEBUG: attempting to configure 'DigiSig' from data
2025-06-14 07:48:12,610 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2025-06-14 07:48:12,610 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2025-06-14 07:48:12,610 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2025-06-14 07:48:12,750 [modules.auxiliary.digisig] DEBUG: File is not signed
2025-06-14 07:48:12,750 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2025-06-14 07:48:12,750 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2025-06-14 07:48:12,750 [root] DEBUG: Initialized auxiliary module "Disguise"
2025-06-14 07:48:12,750 [root] DEBUG: attempting to configure 'Disguise' from data
2025-06-14 07:48:12,750 [root] DEBUG: module Disguise does not support data configuration, ignoring
2025-06-14 07:48:12,750 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2025-06-14 07:48:12,750 [modules.auxiliary.disguise] INFO: Disguising GUID to 6c9dc8a0-dfe1-440a-b432-2c024a10a5ce
2025-06-14 07:48:12,766 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2025-06-14 07:48:12,766 [root] DEBUG: Initialized auxiliary module "Human"
2025-06-14 07:48:12,766 [root] DEBUG: attempting to configure 'Human' from data
2025-06-14 07:48:12,766 [root] DEBUG: module Human does not support data configuration, ignoring
2025-06-14 07:48:12,766 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2025-06-14 07:48:12,766 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2025-06-14 07:48:12,766 [root] DEBUG: Initialized auxiliary module "Screenshots"
2025-06-14 07:48:12,766 [root] DEBUG: attempting to configure 'Screenshots' from data
2025-06-14 07:48:12,766 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2025-06-14 07:48:12,766 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2025-06-14 07:48:12,766 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2025-06-14 07:48:12,766 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2025-06-14 07:48:12,766 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2025-06-14 07:48:12,766 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2025-06-14 07:48:12,766 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2025-06-14 07:48:12,766 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2025-06-14 07:48:12,766 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 696
2025-06-14 07:48:12,797 [lib.api.process] INFO: Monitor config for <Process 696 lsass.exe>: C:\tmpjeo7jmad\dll\696.ini
2025-06-14 07:48:12,797 [lib.api.process] INFO: Option 'procmemdump' with value '1' sent to monitor
2025-06-14 07:48:12,797 [lib.api.process] INFO: Option 'import_reconstruction' with value '1' sent to monitor
2025-06-14 07:48:12,797 [lib.api.process] INFO: Option 'unpacker' with value '2' sent to monitor
2025-06-14 07:48:12,797 [lib.api.process] INFO: Option 'norefer' with value '1' sent to monitor
2025-06-14 07:48:12,797 [lib.api.process] INFO: Option 'no-iat' with value '1' sent to monitor
2025-06-14 07:48:12,797 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2025-06-14 07:48:12,797 [lib.api.process] INFO: 64-bit DLL to inject is C:\tmpjeo7jmad\dll\xwFPXTB.dll, loader C:\tmpjeo7jmad\bin\cBEDKeKs.exe
2025-06-14 07:48:12,876 [root] DEBUG: Loader: IAT patching disabled.
2025-06-14 07:48:12,876 [root] DEBUG: Loader: Injecting process 696 with C:\tmpjeo7jmad\dll\xwFPXTB.dll.
2025-06-14 07:48:12,922 [root] DEBUG: 696: Python path set to 'C:\Users\Packager\AppData\Local\Programs\Python\Python310-32'.
2025-06-14 07:48:12,922 [root] INFO: Disabling sleep skipping.
2025-06-14 07:48:12,922 [root] DEBUG: 696: Full process memory dumps enabled.
2025-06-14 07:48:12,922 [root] DEBUG: 696: Import reconstruction of process dumps enabled.
2025-06-14 07:48:12,922 [root] DEBUG: 696: Active unpacking of payloads enabled
2025-06-14 07:48:12,922 [root] DEBUG: 696: CAPE debug - unrecognised key norefer.
2025-06-14 07:48:12,922 [root] DEBUG: 696: TLS secret dump mode enabled.
2025-06-14 07:48:12,922 [root] DEBUG: 696: InternalYaraScan: Scanning 0x00007FF84A790000, size 0x1f4542
2025-06-14 07:48:12,938 [root] DEBUG: 696: InternalYaraScan hit: RtlInsertInvertedFunctionTable
2025-06-14 07:48:12,938 [root] DEBUG: 696: RtlInsertInvertedFunctionTable 0x00007FF84A7A090E, LdrpInvertedFunctionTableSRWLock 0x00007FF84A8FB4F0
2025-06-14 07:48:12,938 [root] DEBUG: 696: Monitor initialised: 64-bit capemon loaded in process 696 at 0x00007FF8234D0000, thread 4792, image base 0x00007FF60D500000, stack from 0x0000008EFAA74000-0x0000008EFAA80000
2025-06-14 07:48:12,938 [root] DEBUG: 696: Commandline: C:\Windows\system32\lsass.exe
2025-06-14 07:48:12,953 [root] DEBUG: 696: Hooked 5 out of 5 functions
2025-06-14 07:48:12,953 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2025-06-14 07:48:12,953 [root] DEBUG: Successfully injected DLL C:\tmpjeo7jmad\dll\xwFPXTB.dll.
2025-06-14 07:48:12,953 [lib.api.process] INFO: Injected into 64-bit <Process 696 lsass.exe>
2025-06-14 07:48:12,953 [root] <truncated>